A Continuous User Authentication Method Based on Location Information
Through the data fusion of multi-source location information and Kalman filtering algorithm, combined with user behavior characteristics and LSTM neural network, the problem of traditional positioning authentication methods being susceptible to environmental interference and difficult to detect forged identities is solved, and high-precision continuous user authentication and dynamic risk assessment are achieved.
Patent Information
- Application Number
- CN202510457862.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-04-14
AI Technical Summary
Traditional GPS or WiFi-based positioning authentication methods are susceptible to environmental factors, resulting in large positioning errors, affecting authentication accuracy, and it is difficult to detect forged identity authentication based on user's mobile mode and behavioral characteristics.
Multi-source location information (GPS, Wifi, cellular network and Bluetooth beacon) is used for continuous identity authentication, data fusion and trajectory smoothing are performed through Kalman filtering algorithm, user behavior feature vector is constructed, and LSTM long and short-term memory neural network is used for historical behavior learning, detect abnormal trajectories and forged identity behaviors.
It improves the accuracy of user location information, effectively detects abnormal trajectories and forges of identity, reduces the risk of illegal authentication attacks by malicious visitors, and builds an accurate and stable authentication system that supports real-time identity authentication and dynamic risk assessment.
Smart Images

Figure CN119996083B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of user identity authentication, and particularly to a continuous user authentication method based on location information. Background Art
[0002] With the development of digitalization and intelligence, user identity authentication has become one of the core technologies for ensuring the security of information systems. Traditional identity authentication methods mainly include password authentication, biometric recognition (such as fingerprint, face recognition), and device-based identity verification (such as SMS verification code, hardware token). However, most of these methods are static authentication, that is, users are verified once when logging in, and the legitimacy of users cannot be continuously monitored, and they are vulnerable to attacks such as session hijacking and identity impersonation during the session.
[0003] To solve the above problems, in recent years, continuous identity authentication technology based on behavioral characteristics and environmental information has become a research hotspot. Especially identity authentication based on location information, by continuously collecting the movement trajectories of users and combining behavioral feature analysis, realizes more accurate user identity verification, and has broad application prospects in fields such as financial security, military security, enterprise information system security, and Internet of Things security.
[0004] However, traditional location-based authentication methods based on GPS or WiFi are vulnerable to environmental factors such as signal occlusion, reflection, and multipath effects, resulting in large positioning errors and affecting the authentication accuracy.
[0005] In addition, most existing systems are only based on geographical location matching and do not combine the movement patterns and behavioral characteristics of users, making it difficult to detect forged identity authentication. For example, attackers may bypass the authentication system through location spoofing technology.
[0006] In view of the above problems, it is necessary to propose a continuous user authentication method based on location information. Summary of the Invention
[0007] The purpose of the present invention is to solve the problems existing in the background art and propose a continuous user authentication method based on location information.
[0008] The purpose of the present invention can be achieved through the following technical solutions:
[0009] A continuous user authentication method based on location information includes the following steps:
[0010] Step 1: Location data collection and preprocessing;
[0011] At every preset time interval Δt, multi-source location information from each user i is collected, including GPS, Wifi, cellular network, and Bluetooth beacon, to obtain the location information Xgps(i, t) = (x1t, y1t, z1t) provided by GPS, the location information Xwifi(i, t) = (x2t, y2t, z2t) provided by Wifi, the location information Xcell(i, t) = (x3t, y3t, z3t) provided by the cellular network, and the location information Xble(i, t) = (x4t, y4t, z4t) provided by the Bluetooth beacon.
[0012] Construct a spatio-temporal trajectory dataset: . Where N is the total number of target users.
[0013] Use the Kalman filter algorithm to smooth and fuse the multi-source location information, reduce errors and noise interference, and improve the positioning accuracy. The specific process is as follows:
[0014] Perform state space modeling. For each user i, construct its state vector at time t , which is used to describe the true coordinates and true speed of each user at time t; where, is the true coordinate of the user at time t, is the true speed vector of the user at time t. For each user, construct its observation vector at time t , which is used to describe the multi-source location information of each user at time t.
[0015] Establish a state transition model to describe the actual movement process of the user. The state transition model formula is: ; where is the state vector of the previous preset time interval; where A is the state transition matrix, which describes the influence of the true speed vector on the true coordinates; ; where is the process noise, which follows a Gaussian distribution: ; where is the covariance matrix of the process noise of user i.
[0016] Establish an observation model to describe the relationship between the movement process shown in the multi-source location information of the user and the actual movement process. The observation model formula is: ; where H is the multi-source location transfer matrix, ; where is the multi-source location data measurement noise of user i at time t, which follows a Gaussian distribution: ; where is the covariance matrix of the measurement noise of user i, representing the error of the location information obtained through GPS, Wifi, cellular network, and Bluetooth beacon.
[0017] Establish a prediction step operation program: ; where is the predicted state vector of user i at time t, representing the optimal estimated values of the user's coordinates and velocity vector obtained through filtering. Where is the predicted covariance matrix of user i at time t, representing the uncertainty and error of the state estimation by the user before time t; where is the error propagation caused by state transition.
[0018] Establish a Kalman gain, state update, and covariance update program: ; where is the Kalman gain matrix, representing the weights of the measurement values of multi-source location information including GPS, Wifi, cellular network, and Bluetooth beacon in the state estimation. The greater the weight, the greater the influence of the measurement value; where I is the identity matrix.
[0019] After Kalman filtering, obtain the predicted state vector of each user i at time t: ; where, is the estimated coordinate of user i at time t, is the estimated velocity vector of user i at time t.
[0020] At every preset time interval, obtain the distance between the estimated coordinates of each user i and the estimated coordinates at the previous preset time interval to obtain the first criterion for user authentication.
[0021] Step 2: User behavior pattern analysis;
[0022] Construct a user behavior feature vector based on the predicted state vector of each user i at time t, including speed, moving direction, and residence time.
[0023] Calculate the resultant velocity of each user i at time t: ;
[0024] Calculate the moving angle of each user in the horizontal direction at time t: ;
[0025] Calculate the moving angle of each user in the vertical direction at time t: ;
[0026] Calculate the continuous residence time of each user at time t. Whenever a change in the position of the user at time t and the previous preset time interval, i.e., time t - Δt, is detected If it is less than the preset distance interval Lmin, it is determined that the state of user i between the time t - Δt and the time t is staying. At each preset time interval, the total staying time of user i up to the current time t, which is determined to be in the staying state, is statistically calculated and denoted as the total staying time. ; At each preset time interval, the total moving time of user i up to the current time t, which is not determined to be in the staying state, is statistically calculated and denoted as the total moving time. . Calculate the total staying time and the total moving time . The ratio of the total staying time and the total moving time is denoted as the staying - moving ratio of the user up to the current time.
[0027] Construct the behavior feature vector of the user: ;
[0028] At each preset time interval, calculate the matching degree between the current behavior feature vector and the historical behavior feature vector, and use cosine similarity for feature comparison:
[0029] Obtain the historical behavior feature vectors of each user i, that is, the collected at each preset time interval, and calculate the average values of the specific values of the resultant velocity, the moving angle in the horizontal direction, the moving angle in the vertical direction, and the staying - moving ratio at each preset time interval: 、 、 and , and generate the historical mean vector of the behavior features of the user up to the current time t .
[0030] As a preferred embodiment of the present invention, calculate the cosine similarity between the historical mean vector of the behavior features of each user i and the behavior feature vector at the current time ; where and are the norms of the behavior feature vector at the current time and the historical mean vector of the behavior features respectively.
[0031] Obtain the second criterion for identity authentication of each user i at the current time t . The specific value of the second criterion for identity authentication represents the continuity of the user's behavior features. The larger the value, the more similar the resultant velocity, the moving angle in the horizontal direction, the moving angle in the vertical direction, and the staying - moving ratio at the current time are to the historical data.
[0032] Step 3: Extract the historical features of the behavior pattern features;
[0033] Use the LSTM long - short - term memory neural network to train the historical trajectory, learn the user's movement pattern, and capture the potential rules and features in the resultant velocity, the moving angle in the horizontal direction, the moving angle in the vertical direction, and the staying - moving ratio.
[0034] For each user i, the behavioral feature vector at each preset time interval is manually labeled to predict the label representing the behavioral feature vector corresponding determination result, with a value of 1 representing a normal user, and a value of 0 representing an abnormal user.
[0035] Take the behavioral feature vector and its corresponding predicted label as the training data of the LSTM long short-term memory neural network, and carry out training and learning through the backpropagation and gradient descent algorithms. Save the weight matrices and bias terms of the forget gate, input gate, output gate, and memory update unit obtained from the training, and save them as the calculation parameters of the LSTM long short-term memory neural network.
[0036] Substitute the weight matrices and bias terms of the forget gate, input gate, output gate, and memory update unit obtained from the training back into the LSTM long short-term memory neural network to obtain the LSTM model for behavioral pattern feature extraction.
[0037] At each preset time interval, input the behavioral feature vector of each user i into the LSTM long short-term memory neural network to obtain the output predicted label , and record it as the third criterion for user i's identity authentication at the current moment.
[0038] Step 4: Anomaly detection and risk assessment;
[0039] Based on the first, second, and third criteria for identity authentication obtained in Steps 1 to 3, perform identity authentication anomaly detection.
[0040] At each preset time interval, perform the first-level identity authentication for each user. Obtain the first criterion for each user's identity authentication. When it is detected that the first criterion for user i's identity authentication is greater than the preset threshold, it is determined that the user has a trajectory jump and fails the first-level identity authentication;
[0041] When it is determined that user i fails the first-level authentication, further perform the second-level identity authentication for this user. Obtain the second criterion for this user's identity authentication. When the second criterion for this user's identity authentication is less than the preset threshold, it is determined that the user's behavioral features are discontinuous and the user fails the second-level identity authentication;
[0042] When it is determined that user i fails the third-level identity authentication, further perform the third-level identity authentication for this user. Obtain the third criterion for this user's identity authentication. When the third criterion for this user's identity authentication is less than the preset threshold, it is determined that the matching result of the potential rules and features in the user's behavioral features is abnormal and the user fails the third-level identity authentication.
[0043] Step Five: User Authentication;
[0044] When it is recognized that the user passes one or more combinations of the first-level authentication, the second-level authentication, and the third-level authentication, no redundant operations are performed.
[0045] When it is recognized that user i fails the first-level authentication, stop the user authentication service for this user and request a SMS verification code from this user. When the verification result of the SMS verification code is passed, restart the user authentication service for this user.
[0046] When it is recognized that user i fails the second-level authentication, log out of the account login status of this user, stop the user authentication service for this user, and request the account and password submitted during registration from this user. When the verification result of the account and password is passed, restart the user authentication service for this user.
[0047] When it is recognized that user i fails the third-level authentication, log out of the account login status of this user, request biometric verification information from this user, including fingerprint, facial recognition information, and voiceprint. Remind the administrator to pay attention to the user movement trajectory of this user i. When the verification result of the biometric verification information is passed, restart the user authentication service for this user.
[0048] Compared with the prior art, the beneficial effects of the present invention are:
[0049] 1. The present invention uses multi-source location information for continuous identity authentication, performs data fusion and trajectory smoothing processing through the Kalman filtering algorithm to ensure the accuracy of user location information. At the same time, by constructing a user behavior feature vector and combining with the LSTM long short-term memory neural network for historical behavior learning, it can effectively detect abnormal trajectories and forged identity behaviors. Once an anomaly is detected, such as trajectory jumps, sudden changes in behavior patterns, or potential abnormal pattern matching failures, the system will immediately take security measures to effectively prevent illegal authentication attacks by malicious visitors;
[0050] 2. The present invention constructs an accurate and stable authentication system through a multi-level identity authentication strategy (trajectory comparison, behavior feature analysis, deep learning pattern recognition). First, the positioning data processed by the Kalman filter reduces noise interference and improves the reliability of location data. Secondly, the cosine similarity is used to calculate the matching degree between the user's current behavior and historical behavior patterns, enabling the system to effectively distinguish legitimate users from potential attackers. Finally, the LSTM neural network is used to further learn the user's movement pattern to ensure accurate user identity recognition even in complex dynamic environments, reduce the false positive rate, and improve the robustness of authentication;
[0051] 3. The present invention supports real-time identity authentication and dynamic risk assessment. The system can automatically collect and analyze the location information and behavioral characteristics of users at each preset time interval, and immediately trigger a multi-level security authentication mechanism when abnormalities are detected. By means of hierarchical authentication, the flexibility and real-time nature of the authentication process are ensured, enabling legitimate users to pass authentication quickly, while malicious visitors are difficult to bypass security detection, thereby improving overall security and user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] For the convenience of those skilled in the art to understand, the present invention will be further described below in conjunction with the accompanying drawings:
[0053] Figure 1 is the flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0054] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0055] First Embodiment:
[0056] Please refer to Figure 1 shown, a continuous user authentication method based on location information, comprising the following steps:
[0057] Step 1: Location data collection and preprocessing;
[0058] At each preset time interval Δt, multi-source location information from each user i is collected, including GPS, Wifi, cellular network, and Bluetooth beacon, to obtain the location information Xgps(i, t)=(x1t, y1t, z1t) provided by GPS, the location information Xwifi(i, t)=(x2t, y2t, z2t) provided by Wifi, the location information Xcell(i, t)=(x3t, y3t, z3t) provided by the cellular network, and the location information Xble(i, t)=(x4t, y4t, z4t) provided by the Bluetooth beacon.
[0059] Construct a spatio-temporal trajectory data set: . Where N is the total number of target users.
[0060] It should be noted that assuming the true three-dimensional coordinates of the user's location at time t are (xt, yt, zt), due to noise and measurement errors, the location information of different data sources directly collected has different accuracies and error distributions. The true location coordinates of the user can be approximately deduced by fusing multi-source location information.
[0061] The Kalman filtering algorithm is used to smooth and fuse multi-source location information, reduce errors and noise interference, and improve positioning accuracy. The specific process is as follows:
[0062] Perform state-space modeling. For each user i, construct the state vector at time t , which is used to describe the true coordinates and true velocity of each user at time t; where is the true coordinate of the user at time t, is the true velocity vector of the user at time t. For each user, construct the observation vector at time t , which is used to describe the multi-source location information of each user at time t.
[0063] Establish a state transition model to describe the actual movement process of the user. The state transition model formula is: ; where is the state vector of the previous preset time interval; where A is the state transition matrix, which describes the influence of the true velocity vector on the true coordinates; ; where is the process noise, which follows a Gaussian distribution: ; where is the covariance matrix of the process noise of user i.
[0064] It should be noted that the physical meaning of the state transition model is to reflect the mapping relationship between the position information of the user at the previous moment and the position information at the next moment.
[0065] Establish an observation model to describe the relationship between the movement process shown by the user in the multi-source location information and the actual movement process. The observation model formula is: ; where H is the multi-source location transition matrix, ; where is the multi-source location data measurement noise of user i at time t, which follows a Gaussian distribution: ; where is the covariance matrix of the measurement noise of user i, representing the error of the position information obtained through GPS, Wifi, cellular network, and Bluetooth beacon.
[0066] It should be noted that the physical meaning of the observation model is to reflect the mapping relationship between the true position information of the user and the position information obtained through GPS, Wifi, cellular network, and Bluetooth beacon.
[0067] Establish a prediction step operation program: ; where is the predicted state vector of user i at time t, representing the optimal estimated values of the user's coordinates and velocity vector obtained through filtering. Where is the predicted covariance matrix for user i at time t, representing the uncertainty and error of the user's state estimation before time t; where is the error propagation caused by the state transition.
[0068] Establish the Kalman gain, state update, and covariance update procedures: ; where is the Kalman gain matrix, representing the weight of the measurements of multi-source location information including GPS, Wifi, cellular network, and Bluetooth beacons in the state estimation. The greater the weight, the greater the influence of the measurement; where I is the identity matrix.
[0069] After Kalman filtering, the predicted state vector of each user i at time t is obtained: ; where, is the estimated coordinate of user i at time t, is the estimated velocity vector of user i at time t.
[0070] At every preset time interval, obtain the distance between the estimated coordinates of each user i and the estimated coordinates at the previous preset time interval to obtain the first criterion for user authentication.
[0071] It should be noted that the estimated coordinates of the same user are continuous. Under good network conditions, the data transmission of GPS, Wifi, cellular network, and Bluetooth beacons of the same user will not cause delays and packet losses, and the estimated coordinates of the same user will not have position drift and trajectory jumps within a very short time interval, which can be used as the basic criterion for continuous user authentication.
[0072] Step 2: User behavior pattern analysis;
[0073] Construct a user behavior feature vector based on the predicted state vector of each user i at time t, including speed, moving direction, and residence time.
[0074] Calculate the resultant velocity of each user i at time t: ;
[0075] Calculate the moving angle of each user in the horizontal direction at time t: ;
[0076] Calculate the moving angle of each user in the vertical direction at time t: ;
[0077] Calculate the continuous residence time of each user at time t. Whenever a change in the position of the user at time t and the previous preset time interval, i.e., time t - Δt, is detected If it is less than the preset distance interval Lmin, it is determined that the state of user i between the time t - Δt and the time t is staying. At each preset time interval, the total staying time of user i determined to be in the staying state up to the current time t is statistically calculated and recorded as the total staying time. ; At each preset time interval, the total moving time of user i determined not to be in the staying state up to the current time t is statistically calculated and recorded as the total moving time. . Calculate the total staying time and the total moving time . The ratio of the total staying time
[0078] to the total moving time is recorded as the staying - moving ratio of the user up to the current time. ;
[0079] At each preset time interval, calculate the matching degree between the current behavior feature vector and the historical behavior feature vector, and use cosine similarity for feature comparison:
[0080] Obtain the historical behavior feature vectors of each user i, that is, the collected at each preset time interval, and calculate the average values of the specific values of the resultant velocity, the moving angle along the horizontal direction, the moving angle along the vertical direction, and the staying - moving ratio at each preset time interval: 、 、 and , and generate the historical mean vector of the behavior features of the user up to the current time t .
[0081] Furthermore, calculate the cosine similarity between the historical mean vector of the behavior features of each user i and the behavior feature vector at the current time ; where and are the norms of the behavior feature vector at the current time and the historical mean vector of the behavior features respectively.
[0082] Obtain the second criterion for identity authentication of each user i at the current time t . The specific value of the second criterion for identity authentication represents the continuity of the user's behavior features. The larger the value, the more similar the resultant velocity, the moving angle along the horizontal direction, the moving angle along the vertical direction, and the staying - moving ratio at the current time are to the historical data.
[0083] It should be noted that due to delays and packet losses during the transmission of data signals, the specific position coordinates of the user may experience position jumps, which affects the continuous identity authentication of the user. However, the behavioral characteristics of the user, including speed, moving direction, and stagnation ratio, are continuous and similar. Therefore, different users can be distinguished based on their behavioral characteristics, and users with similar behavioral characteristics can be marked to provide reference data for continuous user authentication.
[0084] For example, assume that the daily activity range of a certain user is concentrated on the same floor. Then, the average value of the specific values of the moving angle of this user in the vertical direction at each preset time interval will tend to 0. If the account and personal information of this user are leaked, invaded, or replaced by an attacker, and the activity range of the attacker spans multiple floors, then the moving angle of this user in the vertical direction will change rapidly within a short period of time, which will affect the specific value of the second criterion for user authentication, resulting in a decrease.
[0085] Step 3: Extract the historical features of the behavior pattern features;
[0086] Use the LSTM long short-term memory neural network to train the historical trajectory, learn the user's movement pattern, and capture the potential rules and features in the combined speed, moving angle in the horizontal direction, moving angle in the vertical direction, and stagnation ratio.
[0087] Manually label the behavior feature vectors of each user i at each preset time interval to predict the label representing the judgment result corresponding to the behavior feature vector where the value of is 1 representing a normal user, and the value of 0 representing an abnormal user.
[0088] Use the behavior feature vector and its corresponding predicted label as the training data of the LSTM long short-term memory neural network, and carry out training and learning through the backpropagation and gradient descent algorithms. Save the weight matrices and bias terms of the forget gate, input gate, output gate, and memory update unit obtained from the training, and save them as the calculation parameters of the LSTM long short-term memory neural network.
[0089] Substitute the weight matrices and bias terms of the forget gate, input gate, output gate, and memory update unit obtained from the training back into the LSTM long short-term memory neural network to obtain the LSTM model for behavior pattern feature extraction.
[0090] At each preset time interval, input the behavior feature vectors of each user i into the LSTM long short-term memory neural network to obtain the output predicted label , and it is denoted as the third criterion for identity authentication of user i at the current moment.
[0091] It should be noted that the actual value of the prediction label is a decimal number between 0 and 1, representing the matching result between the current behavior pattern of the user and the potential rules and characteristics in the historical behavior pattern.
[0092] Step 4: Anomaly detection and risk assessment;
[0093] Based on the first, second, and third criteria for identity authentication obtained in Steps 1 to 3, perform identity authentication anomaly detection.
[0094] At each preset time interval, perform first-level identity authentication for each user. Obtain the first criterion for identity authentication of each user. When it is detected that the first criterion for identity authentication of user i is greater than the preset threshold, it is determined that the user has a trajectory jump and fails the first-level identity authentication;
[0095] After determining that user i fails the first-level authentication, further perform second-level identity authentication for this user. Obtain the second criterion for identity authentication of this user. When the second criterion for identity authentication of this user is less than the preset threshold, it is determined that the behavior characteristics of this user are discontinuous and the user fails the second-level identity authentication;
[0096] After determining that user i fails the third-level identity authentication, further perform third-level identity authentication for this user. Obtain the third criterion for identity authentication of this user. When the third criterion for identity authentication of this user is less than the preset threshold, it is determined that the matching result of the potential rules and characteristics in the behavior characteristics of this user is abnormal and the user fails the third-level identity authentication.
[0097] Step 5: User identity verification;
[0098] When it is recognized that the user passes one or more combinations of the first-level identity authentication, second-level identity authentication, and third-level identity authentication, no redundant operations are performed.
[0099] When it is recognized that user i fails the first-level authentication, stop the user authentication service for this user and request a SMS verification code from this user. When the verification result of the SMS verification code is passed, restart the user authentication service for this user.
[0100] When it is recognized that user i fails the second-level authentication, log out the user's account login status, stop the user authentication service for this user, and request the account and password submitted during registration from this user. When the verification result of the account and password is passed, restart the user authentication service for this user.
[0101] When it is recognized that user i fails the third-level authentication, log out the user's account login status, request biometric verification information from the user, including fingerprints, facial recognition information, and voiceprints. Remind the administrator to pay attention to the user movement trajectory of user i. When the verification result of the biometric verification information is passed, restart the user authentication service for the user.
[0102] Second Embodiment:
[0103] In this embodiment, taking person A as an example, a specific embodiment of discovering abnormal stealing of the user authentication service through data collection and analysis will be described in detail.
[0104] Suppose the working area of person A is a continuous user authentication monitoring area, and it is required to strictly monitor their movement trajectory. However, a malicious visitor managed to steal or forge A's positioning device and illegally obtained person A's user authentication service. This article will describe how to identify this abnormal situation through the continuous user authentication method and promptly prevent unauthorized access in combination with the aforementioned steps 1 to 4.
[0105] The positioning information of person A is collected through multi-source data including GPS, WiFi, cellular network, and Bluetooth beacons. Data is collected and processed at regular time intervals to obtain A's precise movement trajectory. Under normal circumstances, A's trajectory should conform to their daily work pattern, for example, moving regularly around a fixed cleaning route within a specified time period.
[0106] When a malicious visitor steals or forges A's positioning device and attempts to forge their identity, the following abnormalities will occur in their location information:
[0107] Location information abnormalities that cause the first criterion of identity authentication to increase: loss and mutation of the trajectory, abnormal fluctuations in location information caused by rapid jumps in location coordinates; abnormal fluctuations in the smoothing process and data fusion results using the Kalman filter algorithm due to data delay or packet loss through GPS, Wifi, cellular network, and Bluetooth beacons caused by network environment changes;
[0108] Location information abnormalities that cause the second criterion of identity authentication to increase: Person A usually has stable low-speed movement characteristics during the cleaning process, while an abnormal visitor may show a mutated speed, such as suddenly accelerating and moving to a location far from the daily activity range. Person A's daily movement direction usually follows certain habitual patterns, including trajectory, range, speed, and direction patterns. However, the trajectory of an abnormal visitor may show random and non-habitual direction changes, such as quickly leaving the user authentication monitoring area.
[0109] Abnormal location information that causes an increase in the third criterion for identity authentication: There are significant differences between the new trajectory pattern and the training data. For example, A has never worked at night, but an abnormal visitor uses A's identity to access at midnight; for example, due to A's work nature, A often makes short stops at specific locations at specific times, while the abnormal visitor quickly passes through other areas during this time period.
[0110] At this time, the abnormal visitor will not be able to pass the first-level identity authentication, the second-level identity authentication, and the third-level identity authentication. The user authentication service of A will be temporarily frozen to prevent the abnormal visitor from continuing to use their identity to access sensitive areas. The user will be requested to provide a SMS verification code, account password, and perform biometric verification. The security personnel will be notified for further investigation, and the location of the malicious visitor will be tracked.
[0111] It should be understood that the terms "including" and "comprising" used in the specification and claims of this disclosure indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0112] It should also be understood that the terms used in this disclosure specification are only for the purpose of describing specific embodiments and are not intended to limit this disclosure. As used in this disclosure specification and claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms. It should be further understood that the term "and / or" used in this disclosure specification and claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations;
[0113] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not elaborate on all details and do not limit the present invention to only the specific embodiments. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the present invention, so that those skilled in the art can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A method for continuous user authentication based on location information, characterized in that: The following steps are involved: Step 1: Positioning data collection and preprocessing; Collect multi-source location information of the user, and use the Kalman filter algorithm to smooth and fuse the data of the multi-source location information to obtain the optimal estimate of the user's coordinates and velocity vector to improve the positioning accuracy; obtain the first criterion for user identity authentication based on the change of the optimal estimate of the user's coordinates; Step 2: User behavior pattern analysis; Based on the optimal estimation value of the user coordinates and speed vector, the user's behavior characteristics in terms of combined speed, moving direction and dwell time are extracted, and a behavior feature vector is formed according to the extracted behavior feature data; the second criterion for user identity authentication is obtained by comparing the behavior feature vector with the historical behavior feature vector; And calculate the matching degree between current behavior characteristics and historical behavior characteristics; Step 3: Extract historical features of behavioral pattern characteristics; Extract behavioral pattern features, use LSTM long short-term memory neural network to train the user's movement pattern, obtain the predicted label of user behavior based on the behavioral feature vector, and obtain the third criterion for user identity authentication; Step 4: Anomaly detection and risk assessment; Perform multi-level identity authentication based on the first, second and third criteria of identity authentication, screen abnormal users, and conduct risk assessment; Perform the first level of identity authentication. If the first criterion of identity authentication exceeds the preset threshold, it is determined that the user's trajectory has jumped and the first level of authentication has failed. Enter the second level of identity authentication; Perform the second level identity authentication. If the second criterion of identity authentication is lower than the preset threshold, it is determined that the user behavior characteristics are discontinuous and the second level identity authentication fails. Enter the third level of identity authentication; Perform the third-level identity authentication. If the third criterion of identity authentication is lower than the preset threshold, the user behavior characteristics are judged to be abnormal and the third-level identity authentication fails; Step 5: User identity verification; Conduct graded verification for users who fail multi-level identity authentication, including SMS verification code, account password verification, and biometric verification, to ensure identity authenticity; When it is identified that the user has passed one or more combinations of the first level identity authentication, the second level identity authentication, and the third level identity authentication, no unnecessary operations are performed; When it is identified that the user has not passed the first level authentication, the user authentication service of the user is stopped and the user is asked to send a text message verification code; when the verification result of the text message verification code is passed, the user authentication service of the user is restarted; When it is identified that the user has not passed the second-level authentication, the user's account login status is logged out, the user's user authentication service is stopped, and the user is asked for the account and password submitted during registration; When the account and password verification result is passed, the user authentication service of the user is restarted; When it is identified that the user has not passed the third-level authentication, the user's account login status is logged out, and the user is asked for biometric verification information, including fingerprint, facial recognition information and voiceprint; The administrator is reminded to pay attention to the user movement track of the user i; when the verification result of the biometric verification information is passed, the user authentication service of the user is reopened.
2. A method for continuous user authentication based on location information according to claim 1, characterized in that: The specific process of collecting multi-source location information of users and smoothing and fusing data is as follows: At preset time intervals, multi-source location information of each user is collected, including GPS, Wi-Fi, cellular network, and Bluetooth beacon, to obtain location information provided by GPS, location information provided by Wi-Fi, location information provided by cellular network, and location information provided by Bluetooth beacon; The Kalman filter algorithm is used to smooth the data, including establishing a state space model, a state transition model and an observation model, to perform state prediction and update, and to improve the accuracy of user positioning.
3. A method for continuous user authentication based on location information according to claim 1, characterized in that: The specific process of obtaining the first criterion of user identity authentication is as follows: The predicted coordinates of the user at the current moment are calculated and compared with the coordinates at the previous moment, and the first criterion for identity authentication is obtained based on the distance difference obtained by the coordinate comparison.
4. The method for continuous user authentication based on location information according to claim 1, characterized in that: The specific process of obtaining the second criterion of user identity authentication is as follows: The cosine similarity is used to calculate the matching degree between the current behavior feature vector and the historical behavior feature vector; the historical mean vector of the user behavior feature is calculated, and its cosine similarity with the current behavior feature vector is used as the second criterion for identity authentication.
5. The method for continuous user authentication based on location information according to claim 1, characterized in that: The specific process of using LSTM long short-term memory neural network to train the user's movement pattern is as follows: The behavior feature vector of each user i at each preset time interval Manual labeling to predict labels Representing behavioral feature vector The corresponding judgment result is A value of 1 represents a normal user. A value of 0 represents an abnormal user; The behavior feature vector and its corresponding prediction label are used as the training data of the LSTM long short-term memory neural network. The training and learning are carried out through the back propagation and gradient descent algorithms. The weight matrix and bias items of the forget gate, input gate, output gate and memory update unit obtained through training are saved and saved as the calculation parameters of the LSTM long short-term memory neural network. Substitute the weight matrix and bias term of the trained forget gate, input gate, output gate and memory update unit back into the LSTM long short-term memory neural network to obtain an LSTM model for behavior pattern feature extraction; At preset time intervals, the behavioral feature vector of each user is input into the LSTM long short-term memory neural network to obtain the output prediction label, which is recorded as the third criterion for identity authentication of user i at the current moment.
6. The method for continuous user authentication based on location information according to claim 1, characterized in that: The total velocity calculation for user behavior pattern analysis is based on the Euclidean distance between the user’s current location and the previous location and converted into a velocity scalar; The movement direction calculation for user behavior pattern analysis is based on the user's speed scalars in the horizontal and vertical directions.
7. The method for continuous user authentication based on location information according to claim 2, characterized in that: The state transition model of the Kalman filter algorithm describes the impact of the user's real velocity vector on the real coordinates, and the process noise follows a Gaussian distribution.
Citation Information
Patent Citations
Mobile device-based mixed identity authentication method
CN106572097A
Continuous identity authentication method and system based on different context environments
CN109871673A