Network security verification method and system for security system

Through the multi-modal biometric dynamic modeling and risk heat map driven multi-factor verification strategy, combined with distributed timestamp perturbation encryption technology, the security risks of the existing technology in the face of high-precision biometric forgery and changes in the dynamic network environment are solved, and the dynamic layered defense and high security verification process is realized.

CN119996092AActive Publication Date: 2025-05-13SHENYANG SHENGDA TECH CO LTD

Patent Information

Application Number
CN202510481140.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-05-13
Estimated Expiration
2045-04-17

AI Technical Summary

Technical Problem

The existing network security verification system is difficult to effectively deal with security risks when facing high-precision biometric forgery, playback attacks and changes in dynamic network environments, and the static encryption mechanism is not adaptable to changes in space-time conditions.

Method used

Multi-modal biometric dynamic modeling, risk heat map-driven multi-factor verification strategy and distributed timestamp perturbation encryption technology are adopted to obtain users' biometrics and dynamic behavior data, generate behavior feature codes, and combine network environment parameters to perform multi-dimensional verification and superposition to generate encryption tokens.

Benefits of technology

Enhanced biometric anti-counterfeiting capabilities, realize dynamic layered defense, adapt to complex network attack scenarios, block illegal replay attacks and man-in-the-middle hijacking, and ensure the safe and reliable verification process in high-security scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996092A_ABST
    Figure CN119996092A_ABST
Patent Text Reader

Abstract

The invention discloses a network security verification method and system for a security system, and belongs to the technical field of network security, and the method comprises the steps: obtaining a biological feature recognition request triggered by a user on terminal equipment, synchronously collecting dynamic behavior track data, and generating a behavior feature code; inputting physiological feature data and behavior feature codes in the biological feature recognition request into a feature verification model, when an output biological behavior correlation index is lower than a first preset threshold value, triggering a dynamic verification strategy adjustment instruction, generating a multi-dimensional verification superposition strategy, and executing at least two verification operations in the multi-dimensional verification superposition strategy, the verification result is input into the distributed time synchronization node to generate an encryption token; and when the synchronous matching degree of the encryption token among different nodes exceeds a second preset threshold value, outputting a security verification passing instruction. According to the method, multi-modal feature fusion, dynamic hierarchical verification and time-space encryption technologies are adopted, replay attacks are prevented, an adaptive defense system is constructed, and reliable authentication of a high-security network scene is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a network security verification method and system for a security system. Background Art

[0002] In the field of network security protocols, existing identity authentication systems mostly use a single biometric recognition or static password combined with a text message verification code. Such methods rely on static collection of biometrics or pre-assigned fixed credentials, and cannot effectively deal with security risks brought about by high-precision biometric forgery, replay attacks, and dynamic network environment changes. Especially in cross-regional access or device replacement scenarios, there is a lack of continuous behavior monitoring mechanism after a single verification, which makes it easy for attackers to use short-term security windows to launch malicious operations.

[0003] Traditional solutions mainly enhance security by adding multi-factor authentication links, such as combining biometrics with hardware tokens, geolocation verification, etc. However, multi-factor authentication strategies often use fixed logic to perform verification, lacking the ability to evaluate the dynamic association between real-time network environment parameters and user behavior. This leads to the coexistence of verification process overload or defense blind spots: redundant verification steps in low-risk scenarios affect efficiency, and sudden abnormal behavior may cause security vulnerabilities due to failure to trigger sufficiently strong verification strategies.

[0004] The main drawbacks of existing technologies are the separation of biometric verification and network environment monitoring, and the lack of adaptability of static encryption mechanisms to changes in temporal and spatial conditions. For example, traditional dynamic tokens rely on a one-way time synchronization algorithm, which does not consider the impact of physical clock deviations between distributed nodes and is easily tampered with by time zones or network delays. In addition, the lack of fusion verification of hardware-level non-replicable features and behavioral data makes it difficult to resist supply chain attacks or simulated device penetration. These defects pose a major security risk in scenarios such as financial transactions and remote control with high security requirements. Summary of the invention

[0005] To solve the above problems, the present invention provides a network security verification method and system for a security system, which adopts multimodal biometric dynamic modeling, a risk heat map-driven multi-factor verification strategy and distributed timestamp perturbation encryption technology. It can achieve dynamic layered defense while enhancing the anti-counterfeiting capability of biometrics, adapt to complex network attack scenarios, and block illegal replay attacks and man-in-the-middle hijacking, ensuring the security and reliability of the verification process and a smooth user experience in high-security scenarios.

[0006] The above objectives can be achieved through the following solutions: A network security verification method for a security system includes obtaining a biometric identification request triggered by a user on a terminal device, wherein the biometric identification request includes an encrypted transmission instruction for a user's fingerprint grayscale image and iris texture data; synchronously collecting dynamic behavior trajectory data of the user when initiating the biometric identification request to generate a behavior feature code; inputting physiological feature data in the biometric identification request and the behavior feature code into a pre-trained feature verification model for matrix convolution calculation, and outputting a bio-behavior correlation index, wherein the physiological feature data includes a fingerprint grayscale image and iris texture data; when the bio-behavior correlation index is lower than a first preset threshold, triggering a dynamic verification strategy adjustment instruction; based on the dynamic verification strategy adjustment instruction, obtaining device parameters and analyzing the abnormal correlation of each parameter to generate a multi-dimensional verification superposition strategy; executing at least two verification operations in the multi-dimensional verification superposition strategy, and inputting the verification results into a distributed time synchronization node to generate an encrypted token; and outputting a security verification pass instruction when the synchronization matching degree of the encrypted token between different nodes exceeds a second preset threshold.

[0007] Optionally, the synchronous collection of the dynamic behavior trajectory data of the user when initiating the biometric identification request to generate the behavior feature code includes: real-time monitoring of the capacitance change gradient sequence of the user's touch screen operation; collecting the three-dimensional space acceleration fluctuation spectrum of the device through a gyroscope sensor; performing time-frequency domain fusion processing on the capacitance change gradient sequence and the acceleration fluctuation spectrum to generate a dynamic behavior feature vector; and obtaining the behavior feature code after normalizing the dynamic behavior feature vector.

[0008] Optionally, the obtaining of device parameters and analyzing the abnormal correlation of each parameter to generate a multi-dimensional verification superposition strategy includes: periodically obtaining a set of network environment parameters including IP address jump strength, SSL certificate validity mark, and SIM card information matching degree; performing a topological analysis on the abnormal correlation of at least three parameters in the network environment parameter set to generate a risk distribution heat map; determining additional verification methods to be enhanced based on the risk area of ​​the risk distribution heat map to generate a multi-dimensional verification superposition strategy.

[0009] Optionally, the multi-dimensional verification superposition strategy includes: generating a first verification factor based on a comparison with a historical database of the Wi-Fi BSSID to which the device is currently connected; generating a second verification factor by calculating the spatial difference between the operator's base station location and the GPS positioning information; generating a third verification factor in combination with the physical fingerprint feature of the SIM card integrated circuit; and performing multi-level series verification on the first verification factor, the second verification factor, and the third verification factor according to the weight distribution of the risk distribution heat map.

[0010] Optionally, the steps of generating the encrypted token specifically include: reading the original feature code after the biometric verification is passed; inserting a millisecond timestamp and performing segmented hash calculation on the original feature code; incorporating the local time calibration error value of each node as a hash perturbation factor into the encryption calculation to generate a dynamically variable token.

[0011] Optionally, the verification steps of the distributed time synchronization node specifically include: comparing the absolute deviation values ​​of the bank server timestamp, the user terminal device timestamp and the operator gateway timestamp; when the absolute deviation value exceeds a preset time threshold, automatically triggering the session key revocation procedure; using the transmission delay value of the encrypted token between each node as an additional verification parameter for the legitimacy of the session.

[0012] Optionally, the updating method of the feature verification model includes: collecting verification log data of legitimate users in an abnormal network environment; extracting the correlation attenuation pattern between biometric features and behavioral features in the verification log data; and updating the kernel function weight matrix of the matrix convolution calculation through an online incremental learning algorithm.

[0013] Optionally, before the security verification passes the instruction output, it also includes: collecting policy execution time consumption data in the current verification process; dynamically adjusting the verification strength level of subsequent sessions according to the time consumption data; and gradient binding the adjusted verification strength level with the user credit score.

[0014] Optionally, the following pre-judgment steps are performed simultaneously with the triggering of the biometric identification request: detecting whether the battery temperature of the terminal device is in an abnormally elevated range; when it is detected that the battery temperature change rate exceeds a preset critical value, temporarily shutting down the wireless communication module and starting the device authenticity diagnosis program.

[0015] Based on the same inventive concept, the present invention also provides a network security verification system for a security system, the system comprising: a biometric feature acquisition module, used to obtain a biometric feature recognition request triggered by a user on a terminal device, the biometric feature recognition request comprising an encrypted transmission instruction of a user's fingerprint grayscale image and iris texture data; a behavior trajectory capture module, used to synchronously acquire the dynamic behavior trajectory data of the user when initiating the biometric feature recognition request, and generate a behavior feature code; a correlation calculation module, used to input the physiological feature data in the biometric feature recognition request and the behavior feature code into a pre-trained feature verification model for matrix convolution calculation, and output a bio-behavior correlation index, the The physiological characteristic data include fingerprint grayscale images and iris texture data; a policy triggering module is used to trigger a dynamic verification policy adjustment instruction when the biological behavior correlation index is lower than a first preset threshold; a verification policy generation module is used to obtain device parameters and analyze the abnormal correlation of each parameter based on the dynamic verification policy adjustment instruction to generate a multi-dimensional verification overlay strategy; an encryption token generation module is used to execute at least two verification operations in the multi-dimensional verification overlay strategy, and input the verification results into a distributed time synchronization node to generate an encryption token; a security verification module is used to output a security verification pass instruction when the synchronization matching degree of the encryption token between different nodes exceeds a second preset threshold.

[0016] Compared with the prior art, the present invention has the following advantages: 1. The present invention simultaneously collects biometrics and dynamic behavior data, and generates behavioral feature codes by combining time-frequency domain fusion analysis, thus expanding traditional static biometric verification into multi-dimensional identity verification associated with time and space, significantly improving the defense capability against counterfeit biometrics, replay attacks, and device cloning, and ensuring the non-replicability of verification information; 2. Dynamically generate risk heat maps based on abnormal correlation topology analysis of network environment parameters, intelligently trigger multi-factor verification logic according to different risk levels, and balance security and efficiency; streamline the verification process in low-risk scenarios, and automatically superimpose hardware-level verification factors when suspicious behavior is detected to form a precise layered security barrier; 3. The millisecond-level timestamp segmented hashing and distributed node time error perturbation technology are used to make the generation of encrypted tokens dependent on real-time physical environment parameters, and dual verification of transmission delay and timing deviation is introduced in cross-node synchronization verification, effectively curbing cross-regional replay attacks and network middleman hijacking, and ensuring that the token is only effective under legal time and space conditions; 4. Continuously optimize the feature verification model through the incremental learning mechanism, quickly adapt when the user behavior pattern changes or the network environment changes suddenly, and avoid frequent verification failures caused by traditional fixed thresholds; dynamically adjust the verification strength based on the credit score, so that high-credit users can enjoy seamless verification in legal operations, reducing interference with normal business processes.

[0017] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0019] Figure 1 It is a flowchart of a network security verification method for a security system according to an embodiment of the present invention.

[0020] Figure 2 It is a schematic diagram of the structure of the risk distribution heat map of an embodiment of the present invention.

[0021] Figure 3 It is a structural diagram of a network security verification system for a security system according to an embodiment of the present invention. DETAILED DESCRIPTION

[0022] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0023] Reference Figure 1 An embodiment of the present invention proposes a network security verification method for a security system, which adopts multimodal biometric dynamic modeling, a risk heat map-driven multi-factor verification strategy and distributed timestamp perturbation encryption technology. It can enhance the anti-counterfeiting ability of biometrics while realizing dynamic layered defense, adapt to complex network attack scenarios, and block illegal replay attacks and man-in-the-middle hijacking, ensuring the security and reliability of the verification process and smooth user experience in high-security scenarios.

[0024] The method of this embodiment specifically includes: Obtaining a biometric feature recognition request triggered by a user on a terminal device, wherein the biometric feature recognition request includes an encrypted transmission instruction of a grayscale image of a fingerprint and iris texture data of the user; Specifically, when the user performs identity authentication on the biometric acquisition module of the terminal device, a request signal is automatically generated, the signal is intercepted by the hardware driver layer and a secure transmission channel is established. The biometric acquisition module is such as a fingerprint sensor or an iris scanner; wherein the terminal device is an intelligent terminal device that integrates biometric acquisition hardware and is connected to a security network; the biometric identification request is an encrypted transmission instruction containing a grayscale image of the user's fingerprint or iris texture data.

[0025] Synchronously collecting dynamic behavior trajectory data of the user when initiating the biometric identification request, and generating a behavior feature code; Specifically, at the moment when the user triggers biometric recognition, the system records the pressure value change sequence of the fingertip sliding through the touch screen capacitive sensor, and collects the acceleration vector and angular velocity vector of the device in three-dimensional space through the gyroscope; the two types of data are fused through the time-frequency domain algorithm, such as short-time Fourier transform to generate a mixed map containing time-series correlation features, and then compressed into a fixed-length feature code through a normalized coding algorithm. The dynamic behavior trajectory data includes but is not limited to the fingertip pressure gradient change sequence monitored in real time by the touch capacitive sensor, with a sampling rate of ≥100Hz, and the standard deviation of the X / Y / Z axis acceleration collected by the gyroscope. Through time-frequency domain fusion technology, such as short-time Fourier transform, the two types of data are mapped into a mixed feature vector.

[0026] Among them, the capacitance change gradient sequence is a set of mapping relationships between the capacitance value change rate of the touch point per second and the spatial coordinates in the touch operation; the acceleration fluctuation spectrum is a motion feature matrix composed of the instantaneous acceleration and standard deviation of the device in the X / Y / Z axis direction; the time-frequency domain fusion processing is an analysis method that converts time series data into frequency domain energy distribution and superimposes it with the time domain trend.

[0027] Input the physiological feature data in the biometric identification request and the behavioral feature code into a pre-trained feature verification model for matrix convolution calculation, and output a bio-behavior correlation index, wherein the physiological feature data includes a fingerprint grayscale image and iris texture data; Specifically, the model converts the user's fingerprint image and behavioral feature code into 768-dimensional vectors respectively, and performs layer-by-layer convolution calculations on the spatial correlation of the two types of vectors through three layers of convolution kernels, and finally outputs a correlation score in the range of 0-1; the initial weights of the model kernel function are trained by a large number of biological behavior samples of legitimate users; for the biological behavior correlation index ,have , In the formula, For the The weight matrix of the convolution kernel of the layer, is the input feature matrix, ⊗ represents the convolution operation, is the Sigmoid activation function, is the bias term.

[0028] When the biological behavior correlation index is lower than a first preset threshold, a dynamic verification strategy adjustment instruction is triggered; Specifically, the first preset threshold may be 0.6. When the score is lower than the first preset threshold, it is determined that the current verification environment is abnormal. The device hardware parameter scanning module is called and a multi-dimensional security analysis is performed based on the network environment parameters.

[0029] Based on the dynamic verification strategy adjustment instruction, the device parameters are obtained and the abnormal correlation of each parameter is analyzed to generate a multi-dimensional verification superposition strategy; Specifically, the system obtains the device's Wi-Fi historical connection records, current GPS position offset, SIM card ICCID serial number and other parameters to build a parameter association map; it uses graph theory algorithms to analyze abnormal nodes, such as the abnormal jump of IP addresses across 3 countries within 5 minutes, to generate a heat map containing high-risk area markers, and selects an overlay verification method accordingly; for example, if it detects that the IP address of a device suddenly switches from Beijing to abroad, and the GPS positioning still shows Beijing, the system will mark this area as a red high-risk area, triggering the dual strategy of SIM card physical chip fingerprint verification and base station triangulation verification.

[0030] Perform at least two verification operations in the multi-dimensional verification overlay strategy, and input the verification results into the distributed time synchronization node to generate an encrypted token; Specifically, the verification process includes comparing the Wi-Fi BSSID of the device's historical connection, which is the first factor, calculating the distance difference between the base station and the GPS coordinates, which is the second factor, and hashing the physical characteristics of the SIM card chip, which is the third factor; data packets that pass the consistency check will be attached with millisecond timestamps, and a dynamic token will be generated by consensus of three distributed nodes; for example, in a certain verification, the second factor detects that the base station distance difference is 300 meters, exceeding the preset 200-meter threshold, and the system forces the third factor verification to be superimposed, that is, the SIM card chip encoding verification, and finally generates a token "TKN=7D4A..." with a timestamp "TS=1625000000123", which is synchronized to the bank server and the operator gateway node.

[0031] When the synchronization matching degree of the encrypted token between different nodes exceeds a second preset threshold, a security verification pass instruction is output.

[0032] Specifically, after the encrypted token is generated, it is distributed to distributed time synchronization nodes for cross-node consistency verification, such as bank servers, user terminal devices, and operator gateways. The local time calibration error value of each node is used as a hash perturbation factor to participate in token generation, ensuring that the token contains millisecond timestamps and segmented hash values. The millisecond timestamp is such as TS=1625000000123, and the segmented hash value is such as TKN=7D4A…. Then, the absolute deviation value of the timestamp of each node is calculated. ,in When the preset time threshold is exceeded, the session key is revoked. In each node, the received encrypted token is compared with the locally generated token. If the hash values ​​are consistent and the timestamp deviation is within the allowed range, the match is considered successful. , where is the number of nodes that are successfully matched, is the total number of nodes. When the matching degree is greater than the second preset threshold, it is determined that the cross-node verification is passed, and the security verification pass instruction is output; otherwise, secondary verification or alarm is triggered. Through the above steps, the system ensures the uniqueness and consistency of the encrypted token in the space-time dimension, and realizes high-intensity distributed security verification.

[0033] The present invention constructs multi-dimensional verification factors and distributed time locks through time-frequency domain fusion analysis of biometrics and dynamic behavior data, and realizes adaptive layered defense of network security verification. The coupling of physiological characteristics and hardware-level physical fingerprints increases the threshold of forgery, and the timestamp perturbation mechanism ensures the uniqueness of verification from the time and space dimensions. The verification example shows that the system can distinguish between natural operations and attack behaviors, significantly reduce the risks of man-in-the-middle attacks and device cloning in high-risk scenarios such as cross-border payments and remote authorization, and maintain a smooth experience for legitimate users through incremental learning.

[0034] Optionally, the synchronously collecting the dynamic behavior trajectory data of the user when initiating the biometric feature recognition request to generate the behavior feature code includes: Real-time monitoring of the capacitance change gradient sequence of the user's touch screen operation; Specifically, when the user touches the touch screen of the terminal, the system captures the capacitance value change sequence of the touch area through the surface capacitance sensor at a sampling rate of 100 times per second. Each sampling point is recorded in the touch screen coordinate system. Capacitance strength of position , forming a capacitance gradient matrix containing time stamps Among them, the capacitance gradient matrix The calculation unit is the rate of change of capacitance value per millisecond. Among them, the touch screen operation is the electrostatic coupling effect generated when the user's finger or stylus touches the capacitive screen; the capacitance change gradient sequence is the mapping relationship set between the capacitance value increment and the spatial coordinates of the touch point in unit time, which represents the force distribution characteristics of the user operation.

[0035] The gyroscope sensor is used to collect the three-dimensional acceleration fluctuation map of the device; Specifically, the device's built-in MEMS gyroscope collects the acceleration vector components of the X / Y / Z axes at a frequency of 2KHz , and calculate the standard deviation of the acceleration of each axis within a 200ms sliding window , , , generating a three-dimensional acceleration fluctuation map . At the same time, the angular velocity vector The modulus length change cycle. Among them, the gyroscope sensor is a three-axis motion detection device based on a micro-electromechanical system; the acceleration fluctuation spectrum is a distribution diagram of the intensity of the device's motion in each axis, and the device jitter characteristics are quantified through the standard deviation.

[0036] Performing time-frequency domain fusion processing on the capacitance change gradient sequence and the acceleration fluctuation spectrum to generate a dynamic behavior feature vector; Specifically, short-time Fourier transform is used to perform time-frequency analysis on two types of data: The component is calculated by 256-point FFT to obtain the frequency domain energy spectrum , the standard deviation sequence of acceleration fluctuations is subjected to wavelet transform to extract the frequency band energy Through the fusion layer and Superposition by frequency band weights to form a mixed spectrum matrix ,in is the gyroscope data confidence adjustment coefficient, For the For example, when the FFT frequency of the capacitance data is Corresponding to the 8-10Hz low frequency band, the energy in the same frequency band output by the acceleration wavelet transform is Also mapped to ,pass The parameter adjusts the weight of acceleration data in the fusion, assuming ,but .

[0037] Will Expand it into a one-dimensional vector and perform PCA dimensionality reduction to 128 dimensions. The time-frequency domain fusion process converts the waveform characteristics of the time series into frequency domain energy distribution, and highlights the fingerprint characteristics of human operation behavior through weighting.

[0038] After the dynamic behavior feature vector is normalized, a behavior feature code is obtained.

[0039] Specifically, the minimum-maximum normalization method is used to perform linear transformation on each dimension of the 128-dimensional feature vector, and the numerical range is compressed to [0,1]. The normalized vector is converted into a hexadecimal string with a fixed length of 64 bytes through the SHA-256 hash algorithm as the final behavioral feature code. Among them, the normalization process is a data standardization operation to eliminate the differences in the dimensions of different sensors; the behavioral feature code is a digital fingerprint that characterizes the uniqueness of the user's operation mode.

[0040] Specifically, dynamic behavior signature codes are constructed through multi-dimensional sensor data fusion, combining biological features with operational behavioral features, breaking through the technical limitations of traditional static biometric verification. The capacitance gradient sequence quantifies the change in touch force, the acceleration spectrum reflects the movement pattern of the device naturally held by the human body, and the time-frequency domain fusion enhances the spatiotemporal correlation of the features. The encrypted signature code finally generated has the characteristics of anti-replay and anti-simulation attacks, which improves the security of verification while maintaining the smoothness of user experience. Through the continuous learning of the dynamic behavior model, the system can adaptively identify the evolution of user behavior patterns.

[0041] Optionally, the acquiring of device parameters and analyzing the abnormal correlation of each parameter to generate a multi-dimensional verification superposition strategy includes: Periodically obtain a set of network environment parameters including IP address jump strength, SSL certificate validity mark, and SIM card information matching degree; Specifically, a set of network environment parameters including IP address jump strength, SSL certificate validity mark, and SIM card information matching degree is obtained from the device network layer and security components in a 5-minute cycle. The IP address jump strength is calculated by parsing the TCP / IP protocol stack log and calculating the number of switches of the device's external network IP address geographical location and the ratio of the number of cross-AS autonomous systems per unit time. The SSL certificate validity mark is to extract the certificate fingerprint of the current connection to the HTTPS server, and compare it with the public certificate transparency log to mark the expired, revoked or untrusted certificate status. The SIM card information matching degree is to read the SIM card integrated circuit unique code (ICCID) and the operator code to which it belongs, and calculate the similarity with the whitelist database preset by the device at the factory.

[0042] Among them, the IP address jump intensity is a quantitative indicator that characterizes the abnormal jump of the geographical location of the network connection; the SSL certificate validity mark is a binary label of the server identity trust status; the SIM card information matching degree is the consistency score between the current SIM card and the device's historical binding records.

[0043] Performing topological analysis on abnormal correlations of at least three parameters in the network environment parameter set to generate a risk distribution heat map; Specifically, we construct a network environment parameter relationship graph, where nodes represent parameter types and edge weights are determined by the abnormal correlation between parameters. We use the improved PageRank algorithm to calculate the risk value of parameter nodes. The risk value of parameter nodes is , In the formula, is the neighbor node influence weight, with an empirical value of 0.85, which indicates the proportion of the current node risk being affected by the adjacent node risk, reflecting the propagation characteristics of the attack chain; Representation and Node A set of directly connected neighbor nodes. For example, when analyzing an IP address hopping intensity node, its neighbors may include an SSL validity node and a SIM matching node. For Node and Pearson correlation coefficient; reflects the statistical correlation between two parameters in historical abnormal events. The value approaches 1; Neighbor node The risk score is updated through an iterative algorithm, and the initial value is determined by the parameter original anomaly score Assignment; is the inherent risk coefficient of the entity parameter, which is set to 0.15 and represents the basic risk weight of non-topological associations, such as the contribution of independent abnormal events of a certain node; Representation Node The entity parameter set included, such as when analyzing the SIM card information matching node, Contains sub-parameters such as ICCID validity and operator binding status; parameter The risk value is mapped to the network topology layer where the device is located, and high-risk, medium-risk, and low-risk areas are marked with red, orange, and yellow.

[0044] Among them, topological analysis is a network parameter relationship modeling method based on graph theory; risk distribution heat map is a visualization map that expresses the attack probability of different areas with color depth, such as Figure 2 The two-dimensional grid shown, each grid point represents a geographical location or network area, and each grid point has a risk value.

[0045] The additional verification method to be enhanced is determined according to the risk area of ​​the risk distribution heat map, and a multi-dimensional verification superposition strategy is generated.

[0046] Specifically, in high-risk areas, three-factor authentication is triggered, and Wi-Fi BSSID historical trajectory is traced back: query the physical address sequence of the wireless AP that the device has connected to in the past 24 hours. Base station positioning and GPS coordinate difference verification: calculate the actual distance between the base station corresponding to the operator's LAC cell number and the device GPS. SIM card chip physical fingerprint extraction: read the hash value of the microscopic defect feature formed by the SIM card silicon wafer manufacturing process. Two-factor authentication is used in medium-risk areas, and only single-factor authentication is added in low-risk areas.

[0047] Among them, the multi-dimensional verification overlay strategy is a defense mechanism that dynamically combines multiple verification methods according to the real-time risk level; the additional verification method is an auxiliary identity verification method based on device hardware characteristics or network behavior characteristics.

[0048] For example, a user device switches external network IP three times in 10 minutes, for example, from Beijing, China to Moscow, Russia, and then to Frankfurt, Germany. At the same time, it is detected that the HTTPS certificate issuing authority is not in the ICANN authorized list, and the matching degree between the SIM card ICCID and the device IMEI binding record is only 35%. Therefore, parameter collection is performed to obtain that the IP jump intensity becomes 3 times / 10 minutes, across 3 AS numbers, and the SSL certificate validity mark is 0, that is, invalid, and the SIM matching degree is 0.35. Construct a parameter node relationship diagram and calculate to obtain , indicating high risk, , indicating high risk, , indicating medium risk, generating a heat map with high-risk areas covering the network connection layer (red) and the device identification layer (orange). High-risk areas trigger three-factor authentication, verify whether the Wi-Fi AP that the device has recently connected to is the "00:1A:2B:XX" historical track, calculate the distance difference between the base station LAC12345 location (39.90° north latitude) and the device GPS (52.52° north latitude) to be 1250km, and extract the SIM card physical fingerprint hash "9f86d081..." and compare it with the pre-stored value. Through multi-parameter joint topology analysis, cross-border springboard attacks disguised as normal users can be effectively identified. The strong association between IP hopping and invalid certificates triggers the highest level of verification strategy, and the SIM card matching anomaly further confirms that the attacker uses an unauthorized device. The heat map dynamically guides the system to focus on protecting the network connection layer, avoid single-point parameter misjudgment, and ensure accurate interception of illegal access in complex network attack scenarios.

[0049] Optionally, the multi-dimensional verification superposition strategy includes: Generate a first authentication factor based on a comparison with a historical database of the Wi-Fi BSSID to which the device is currently connected; Specifically, the system queries the physical address (BSSID) sequence of the Wi-Fi access point that the device has connected to in the past 30 days, and calculates the similarity score between the currently connected BSSID and the historical record using the Levenshtein distance algorithm to obtain the first verification factor. ,have , In the formula, is the Levenshtein edit distance, is the current BSSID string, The most recent 10 valid BSSIDs recorded in the history database. If the first verification factor is greater than 0.8, it is marked as a legal factor. The Wi-Fi BSSID history database is a library of wireless access point physical addresses that are encrypted and stored regularly by the device.

[0050] The second verification factor is generated by calculating the spatial difference between the operator base station location and the GPS positioning information; Specifically, based on the latitude and longitude coordinates of the LAC cell provided by the operator and device GPS coordinates , use the Haversine formula to calculate the spatial difference and get the second verification factor. ,have , In the formula, is the radius of the Earth, which is 6371km, , Secondary verification is triggered when the second verification factor exceeds the 200-meter threshold.

[0051] Among them, the spatial difference calculation is a dynamic positioning verification method that quantifies the deviation between the base station signal coverage range and the physical position through spherical trigonometry.

[0052] Generate a third authentication factor by combining the physical fingerprint characteristics of the SIM card integrated circuit; Specifically, read the startup voltage curve of the SIM card chip , extract the characteristic peak-valley value sequence in the time period of t=0-10ms, generate a unique fingerprint through the chaotic hash algorithm, and obtain the third verification factor. ,have , In the formula, is the maximum starting voltage, is the minimum voltage regulation value, is the peak value of the second derivative of the voltage curve. Among them, the physical fingerprint feature of the integrated circuit is a hardware unique identifier generated by the microscopic differences in the semiconductor manufacturing process; the third verification factor is a non-replicable hardware-level identity authentication parameter.

[0053] The first verification factor, the second verification factor and the third verification factor are subjected to multi-level serial verification according to the weight distribution of the risk distribution heat map.

[0054] Specifically, the verification process branches are set according to the risk level of the heat map. The mandatory serial verification order for high-risk (red) areas is as follows: to to , and all factors are required to match. Medium risk, i.e. orange area, is verified in parallel and , any one of them will trigger Check. Low risk or yellow area only needs or Any one of them passes. Among them, multi-level serial verification is a verification logic arrangement method based on dynamic risk assessment, which reduces the execution frequency of high-trust verification links through weight distribution and balances security and efficiency.

[0055] For example, a user uses a mobile device to access a sensitive system on a business trip. In the system detection risk heat map, the network connection layer is marked as orange, which means medium risk, and the device physical layer is marked as yellow, which means low risk. The Levenstein distance between the currently connected hotel Wi-Fi BSSID (00:1A:2B:XX:YY) and the most recent 10 records in the history library, including other hotel APs in the same city, is 2 / 12, and the first verification factor is 0.83, which passes the verification. The Haversine calculation distance between the operator base station coordinates (34.0522°N, 118.2437°W) and the device GPS coordinates (34.0505°N, 118.2419°W) is 185 meters, which is lower than the threshold. According to the policy, the third factor is skipped and access is directly authorized. In the subsequent attack simulation, the attacker forged the same GPS coordinates but tried to log in using another SIM card. The system triggered the secondary verification process because the SIM physical fingerprint hash did not match, that is, the difference in the third verification factor, and finally intercepted the attack. This method innovates the incremental defense dimension by constructing a dynamic combination verification system of multiple heterogeneous verification factors. Wi-Fi history comparison reveals device usage habits, base station-GPS spatial verification prevents location forgery, and SIM physical fingerprint breaks through the limitations of pure logical verification. Multiple factors are intelligently arranged according to risk scenarios, which not only ensures a smooth experience in low-risk scenarios, but also exposes the contradiction that the network environment, physical location and hardware fingerprint cannot be disguised at the same time in advanced attacks. Compared with traditional fixed multi-factor authentication, this method solves the penetration problem after the attacker obtains some verification factors through social engineering, especially in mobile payment and remote office scenarios, it can significantly reduce the risks of man-in-the-middle attacks and device cloning.

[0056] Optionally, the step of generating the encrypted token specifically includes: Read the original feature code after the biometric feature verification is passed; Specifically, after completing the biometric identification of fingerprints or irises, the system will extract the successfully verified feature template from the decoding chip, such as the coordinates of the intersection of fingerprint ridges or the Fourier descriptor of iris texture. The original feature code is a binary sequence containing the user's unique biological features, usually stored in a length of 256 bits. Before transmission, the code is converted into a differential Manchester code by an analog-to-digital converter to enhance the ability to resist electromagnetic interference. Among them, the original feature code is the digital identity output by the biometric recognition algorithm; the differential Manchester code is a coding method that represents logical 0 / 1 through level jumps, and the leading code uses CRC-8 verification.

[0057] Inserting a millisecond timestamp and performing segmented hash calculation on the original feature code; Specifically, the system obtains the millisecond accuracy of the current time from the Beidou timing module, such as TS=1625000000123, converts it into a 56-bit integer data in the format of "year-month-day-hour-minute-second-millisecond", and inserts it into the 64th to 119th bytes of the original feature code. Then the entire data packet is divided into 8 blocks of 32 bytes in length, and SHA-3 hash calculation is performed on each block in turn: , In the formula, For the The hash value of each block, For the 32-byte data blocks, is a 1-byte slice of the corresponding block in the timestamp, for example The block takes the millisecond value of bits. Finally, the hash values ​​of each block are combined into the final hash summary through XOR operation. Among them, the millisecond timestamp is a global time synchronization code accurate to 1 / 1000 second; the segmented hash calculation is a processing method that divides long data into blocks and then independently hashes and merges them, which increases the complexity of the intermediate state; TS_slice is the segmented embedding parameter of the timestamp to prevent local tampering of the hash value.

[0058] For example, assume that the original feature code is a 64-byte hexadecimal string "A1B2C3...", the timestamp TS=1625000000123, and the 56-bit time code after truncation is "3F2A01". After segmentation, the first block is "A1B2C3...31" (32 bytes), and the first The first bit of the last byte "23" (the first two bits 00 in the binary 00100011 of 0x23). After executing SHA3-256 calculation, we get = "5E8F...". The other blocks are processed in the same way, and the final hash is "7D4A...". The segmented embedded timestamp slices make the hash calculation have time and space correlation. Attackers cannot crack the hash chain by tampering with a single time field, ensuring the instantaneous uniqueness of the token.

[0059] The local time calibration error value of each node is incorporated into the encryption calculation as a hash perturbation factor to generate a dynamically variable token.

[0060] Specifically, after receiving the time synchronization signal, the distributed nodes calculate the error between the local clock and the UTC reference time. , in microseconds. For example, the error of node A is +120μs, that of node B is -80μs, and that of node C is +50μs. Convert to a 4-byte floating point number and generate the disturbance factor according to the formula. ,have: , The As the initialization vector of the AES-256 algorithm, it participates in the re-encryption of the hash value and finally generates a token: , Among them, the local time calibration error value is the timing deviation between the atomic clock of each node and the Beidou time base; the hash perturbation factor is the encryption parameter generated by the nonlinear combination of time errors; the dynamically variable token is a real-time changing certificate affected by the time parameters of multiple nodes.

[0061] For example, let the node time error be +253μs, -142μs, is +65μs, then the disturbance factor . The hash digest is encrypted with 40161 as the key to generate the token "TKN=7D4A...". If the attacker replays the token after a delay of 1 second, the Seed will change due to the change in time error, and the decryption will fail. The encryption key is dynamically disturbed by the time error of distributed nodes, so that the token is only valid in a specific time window, blocking copy attacks and cross-time zone replay attacks, and enhancing the ability to resist man-in-the-middle hijacking.

[0062] For example, when a user of a bank APP logs in, a feature code containing a timestamp "TS=1625001234567" is generated, and after segmented hashing, the digest "Hash=9F86..." is obtained. Time error of three nodes +153μs, -92μs, = +17μs, generating a perturbation factor Seed = 14365. The encrypted token is "TKN = 3E7B...". The attacker intercepts the token and replays it after 1 minute. Since the node time error value has changed, becomes +212μs, becomes -43μs, The synergy of dynamic time parameters and multi-node errors makes it impossible for attackers to crack the token generation rules through external observation, ensuring that the encryption factor of each session changes randomly, achieving zero-day vulnerability immunity.

[0063] This method realizes dynamic anti-counterfeiting protection of biometric verification through segmented timestamp embedding and distributed node time error perturbation mechanism. The millisecond timestamp ensures that each generated hash value has a unique timing mark to prevent pre-calculation attacks; segmented processing combined with spatiotemporal parameters enhances the anti-collision ability of the hash chain. The nonlinear relationship of multi-node time errors is used as an encryption factor, so that the token depends on real-time environmental parameters and cannot be statically copied. This method breaks through the limitation of traditional biometric verification relying on a single static feature code, synchronously integrates physical variables such as hardware clock differences, and forms a multi-dimensional dynamic defense system. In high-risk scenarios such as mobile payment and remote authorization, it can effectively resist biometric replication, network sniffing and replay attacks, and significantly improve the active protection capability of the security system.

[0064] Optionally, the verification step of the distributed time synchronization node specifically includes: Compare the absolute deviation values ​​of the bank server timestamp, the user terminal device timestamp and the operator gateway timestamp; Specifically, the distributed time synchronization node receives local timestamp data from the bank server, user equipment and operator gateway. Bank server timestamp Synchronize to the cesium atomic clock source through the PTP protocol of the financial private network, and the user terminal device timestamp Obtained and marked with microsecond accuracy by the device system clock, the timestamp of the operator gateway Taken from the GPS / Beidou dual-mode timing module. The cross-node time consistency is calculated using the absolute deviation formula: , In the formula, is the total time deviation of the three nodes, is the UTC time of the bank server, such as 1625000000123μs, The local time of the user terminal, such as 1625000000150μs, is the gateway clock time, such as 1625000000130μs. When the preset time threshold is exceeded, for example, 150μs, the time is considered out of sync. The absolute deviation value is the cumulative difference between different time sources, reflecting the clock synchronization accuracy of the entire network; the distributed time synchronization node is a time server cluster deployed in banks, user devices, and operator networks, which maintains a unified time base through the NTP / 1588 protocol.

[0065] When the absolute deviation value exceeds a preset time threshold, a session key revocation procedure is automatically triggered; Specifically, the system preset time threshold is dynamically adjusted according to the network topology, and the initial value of the threshold is 150μs. If the threshold is exceeded, the security management module immediately sends a cancellation instruction to the key distribution center, which contains the session ID, timestamp and node signature. The key distribution center uses the national secret SM2 algorithm to irreversibly revoke the current session key. The new key needs to wait for the next revocation. After recovering to within the threshold, the key is renegotiated. The key revocation procedure includes three handshakes: revocation request broadcast, node signature verification, and key status update. If any node does not respond to the revocation instruction, it automatically switches to the backup key channel. Among them, the session key revocation procedure is a key lifecycle management mechanism based on blockchain. The preset time threshold is the tolerance upper limit dynamically calculated according to the network delay model; the dynamic threshold generation algorithm is an exponentially weighted moving average function generated by fitting historical time deviation data.

[0066] For example, assuming that the bank server timestamp =1625000000100μs, user equipment =1625000000300μs (maliciously tampered with), gateway =1625000000150μs. Calculation . Because 400μs exceeds the preset 150μs threshold, the revocation procedure is triggered: the revocation instruction is broadcast to the three nodes. After the node signature is verified, the current session key is revoked, and the attacker cannot continue to communicate using the stolen key. Through the dynamic detection of the time deviation of the three nodes, the device time tampering behavior can be effectively identified. The automatic revocation mechanism blocks the attack link and prevents the key from being maliciously used in the abnormal time window.

[0067] The transmission delay value of the encrypted token between the nodes is used as an additional verification parameter for the legitimacy of the session.

[0068] Specifically, the transmission delay data of the encrypted token from the user device to the bank server and then to the operator gateway is recorded as and The unit is ms. The normal distribution model is used to verify the delay fluctuation range. The legal delay should meet the following requirements: , In the formula, is the average latency from historical tokens to bank servers, such as 5ms. is the standard deviation of the average delay from the historical token to the bank server, such as 0.8ms; is the average delay to the gateway, such as 7ms, is the standard deviation of the average delay to the gateway, such as 1.2ms. When the actual delay exceeds the range of 3 times the standard deviation, it is determined to be an abnormal transmission path and the superposition verification fails. The update cycle of the verification logic is 30 minutes, dynamically adapting to changes in the network environment. Among them, the transmission delay value is the time it takes for a data packet to be transmitted one-way between nodes; the normal distribution model is a statistical verification framework built based on historical delay data, which is used to identify sudden path hijacking or man-in-the-middle attacks.

[0069] For example, an attacker hijacks a user's device and copies a legitimate token to try to transfer money. =400μs exceeds the threshold, triggering key revocation. The attacker uses a proxy server to send tokens, and the delay to the bank node is 12ms, 5ms, The value is 0.8, which is beyond the range of 3 standard deviations. The time deviation alarm and delay anomaly interception are triggered synchronously to prevent transactions. The cross-verification of time and space forms a three-dimensional defense. Attackers cannot forge clock synchronization and physical network paths at the same time, which greatly increases the cost and complexity of attacks and ensures chain-based trusted verification of key businesses.

[0070] This method builds a dual protection barrier in the space-time dimension through a dual verification mechanism of cross-node time synchronization and transmission path. The three-node timestamp comparison eliminates the risk of single-point clock offset, and the dynamic threshold adapts to different network environments; transmission delay modeling analysis identifies illegal path injection and prevents replay attacks. The legitimacy of the encrypted token not only depends on biometrics and key strength, but also needs to meet strict space-time consistency conditions to effectively defend against complex attack scenarios such as time tampering, key duplication, and proxy hijacking. In cross-border payment, remote authorization and other businesses, it can ensure the real-time credibility of transaction data and enhance the system's active defense capabilities against advanced persistent threats.

[0071] Optionally, the method for updating the feature verification model includes: Collect verification log data of legitimate users in abnormal network environments; Specifically, the system obtains the user's verification records in abnormal network environments from the security audit module every day. An abnormal network environment is defined as a scenario that meets the following conditions at the same time: the IP address jump frequency exceeds 3 times / minute, the SSL certificate validity mark is 0 (invalid), and the GPS positioning differs from the base station location by more than 1 km. The log data contains the fingerprint image hash value, touch screen capacitance gradient sequence, device three-dimensional space acceleration spectrum, and corresponding verification result mark during biometric verification. The data is stored in a distributed blockchain node in ciphertext form, and the capacity of each block is capped at 1MB. The PBFT consensus mechanism is used to ensure that the data cannot be tampered with. Among them, the verification log data is a full-dimensional operation sequence that records the user's identity authentication process; the abnormal network environment is a set of network connection states that meet the preset high-risk conditions, such as cross-border agents, counterfeit base stations and other scenarios.

[0072] Extracting a correlation attenuation pattern between biological features and behavioral features in the verification log data; Specifically, the sliding window analysis method is used to calculate the correlation of log data. The window span is 7 days, and the attenuation slope of the Pearson correlation coefficient between biometric features (such as fingerprint matching) and behavioral features (such as capacitance fluctuation value) is analyzed every day to construct a time series model: , In the formula, For the The correlation decay strength of the day, is the correlation coefficient of biological behavior characteristics of the day, is the derivative of the change in the correlation coefficient of the biological behavior characteristics on two consecutive days, is the weight coefficient, such as 0.65, is the attenuation acceleration coefficient, such as 0.35. When the value is in the negative range for three consecutive days, it is determined that the decay mode is established. For example, when a user logs in in a public Wi-Fi environment From 0.85 to 0.72, and = -0.04, substituting into the formula we get =0.65×0.72+0.35×(-0.04)=0.463, and a continuous decrease triggers pattern recognition. Among them, the correlation decay mode is the decreasing trend of the correlation between biological characteristics and dynamic behavior data with time or environmental changes, and the decline rate is quantified by sliding window analysis; the Pearson correlation coefficient is a statistical indicator of the linear relationship between two variables, and the value range is [-1,1].

[0073] For example, a user changed his mobile phone, which caused the capacitance gradient sequence fluctuation frequency to increase. The log data showed that for three consecutive days 0.82, 0.75, 0.68, Calculated as -0.07 and -0.08. Take the third day =0.65×0.68+0.35×(-0.08)=0.442-0.028=0.414. The value is positive, but the correlation continues to decrease due to equipment replacement, and the system still determines it as a mild attenuation mode. Through dynamic trend analysis within the time window, we can avoid misjudgments caused by sudden changes in single-day data and accurately capture the gradual attenuation of correlation caused by hardware changes.

[0074] The kernel function weight matrix of the matrix convolution calculation is updated through an online incremental learning algorithm.

[0075] Specifically, the weights are updated using the online stochastic gradient descent method, and only the newly added log data is used to adjust the model. For the kernel function weight matrix, the update formula is: , In the formula, For the The weight matrix of the iteration, is the learning rate, which can be preset to 0.001. is the gradient of the loss function with respect to the weight matrix, 100 sets of biological behavior feature vectors extracted from the newly added logs, is the corresponding label vector, 0 / 1 indicates whether the verification result is legal. Mini-Batch data is selected for local adjustment of the convolution kernel each time it is updated. For example, if a new log indicates that a user uses a stylus pen, which causes the capacitance gradient feature to mutate, the model will adjust the weight of the second-layer convolution kernel to pay more attention to the gyroscope acceleration feature. Among them, the online incremental learning algorithm is a model optimization method that does not require full data retraining; the kernel function weight matrix is ​​a set of feature extraction parameters for the convolution operation in the feature verification model, with a dimension of 3×3×64.

[0076] For example, the newly added log contains 50 verification records of a user in a high-speed rail scenario: due to the vibration of the device, the peak value of the acceleration spectrum shifted, and the misjudgment rate of the original model increased to 12%. , calculate the gradient =-0.34. Assume that the initial weight matrix The weight of a kernel is 0.72, and the learning rate If the value is 0.001, it will be 0.72034 after updating. After 100 iterations, the response weight of the convolution kernel to the acceleration spectrum increased by 17%, and the misjudgment rate of the model in such scenarios dropped to less than 5%. The incremental learning mechanism can quickly optimize the model for segmented scenarios, avoid system performance degradation caused by environmental changes, and reduce the computational cost of full training.

[0077] For example, employees of a multinational company need to frequently switch VPN access systems. The original model misjudged due to IP hopping and network delay. 30 overseas verification logs were collected and extracted. From 0.78 to 0.63, then =-0.12, triggering attenuation pattern recognition. The incremental learning module uses this data to update the third-layer convolution kernel, increasing its weight for touch behavior features under network delay by 22%. In subsequent verification, the employee's relevance score in the same scenario was restored to 0.71, and misjudgment was reduced. The dynamic update mechanism enables the model to adapt to the behavioral evolution of legitimate users, avoiding frequent verification failures caused by fixed thresholds, improving the user experience while ensuring security, and is especially suitable for mobile business scenarios with high frequency and multiple environmental changes.

[0078] This method achieves a balance between security and adaptability by continuously monitoring the changes in the correlation between user verification features and dynamically optimizing model parameters using online learning technology. Abnormal environment data is collected to build a targeted training set, correlation decay pattern recognition locates model weaknesses, and incremental learning ensures that feature extraction kernel functions adapt to new scenarios. This method breaks through the limitations of traditional static verification models and can maintain high accuracy when user behavior patterns change or the environment suddenly changes, such as when changing devices or when accessing across regions, significantly reducing false rejection rates and security vulnerability risks.

[0079] Optionally, before the security verification passes the instruction output, the method further includes: Collect the strategy execution time consumption data in the current verification process; Specifically, during each security verification process, the system obtains the timestamps of each stage of operation from the scheduling module of the verification engine, including the time of biometric feature extraction, feature code comparison, node communication delay, etc. The start and end time of each step is recorded with microsecond accuracy, and the total time consumption of a single verification process is calculated. Total time spent on verification process ,have: , In the formula, For the The starting time of each step, For the The end time of the steps, is the verification step number, such as =1 corresponds to biometric extraction. The data storage adopts a ring buffer structure to save the time sequence of the last 100 verifications. The historical average time and fluctuation standard deviation are calculated through a sliding window. ,have: , In the formula, is the window sample size, , for the standard deviation of volatility ,have: , in, represents square root operation, and the strategy execution time consumption data is a set of time performance indicators of each verification link; the sliding time window is to retain only the most recent Rolling update mechanism for secondary data; microsecond accuracy is one-millionth of a second resolution of the timestamp.

[0080] Dynamically adjust the verification strength level of subsequent sessions according to the time consumption data; Specifically, the system establishes a dynamic adjustment model based on the mean and standard deviation of the time consumption to verify the intensity level The calculation formula is: , In the formula, The current verification time is is the sensitivity coefficient, the default =2, is the basic strength level, the initial value is 3, is a floor function, for example The result is 4. For example, if the current time =520ms, =500ms, =10ms, then , that is, the strength is increased to level 4. The verification strength level range is preset from 1 to 5. The higher the level, the more additional verification factors are triggered. For example, level 5 requires simultaneous verification of biometrics, SIM card fingerprints, and base station positioning. Among them, the dynamic adjustment model is a feedback adjustment mechanism based on statistical process control; the verification strength level is a quantitative parameter that characterizes the complexity of the verification strategy. Increasing the level will increase the number of verification steps or increase the complexity of the algorithm.

[0081] The adjusted verification strength level is gradient-bound to the user's credit score.

[0082] Specifically, the credit scoring module generates a credit value of 0-1000 based on the user's historical behavior. , user historical behaviors such as verification success rate and risk operation frequency. The gradient binding function maps the credit score to the verification strength correction coefficient. ,have: , In the formula, is the median credit score (set to 500), To adjust the parameters, set it to 200. is a nonlinear activation function. The final actual intensity level Calculated by the following formula: , In the formula, is a rounding function, which rounds a value to the nearest integer, for example Among them, the gradient binding process is to achieve the inverse correlation between credit score and verification strength through function mapping; the user credit score is a multi-dimensional credibility quantification indicator based on the user's historical behavior, and the higher the score, the lower the risk.

[0083] For example, a high-credit user may experience VPN delays during a cross-border business trip, which may cause the verification time to rise to 600ms. , the historical average time , volatility standard deviation . Verification strength level , so the verification strength level is 5, but the verification strength correction factor in gradient binding , so the actual strength level , so the actual strength level is level 0, and level 1 verification is actually performed. The system only requires fingerprint recognition and exempts additional verification such as base station positioning. Verification strength correction factor for low-credit users , so the actual strength level Level, mandatory superposition of SIM card chip verification. Credit gradient binding can intelligently distinguish real users from potential attackers. Even in the same network environment, high-credit users can still enjoy fast verification, while abnormal behavior of low-credit users will trigger strict policies, effectively balancing security and efficiency and reducing interference from erroneous operations of legitimate users.

[0084] Optionally, the following pre-judgment steps are performed simultaneously with the triggering of the biometric feature recognition request: Detect whether the battery temperature of the terminal device is in an abnormally high range; Specifically, the system reads the temperature sensor data in real time through the I2C interface of the battery management chip and records the temperature rise gradient per unit time. The temperature value sequence is obtained at a sampling frequency of 10 times per second, and the temperature change rate is calculated. When the temperature change rate of 5 consecutive sampling points is greater than or equal to 2°C / second, it is determined to be an abnormal increase interval. For example, in a certain detection, the temperature sequence is 32°C, 34.5°C, 37.8°C, 41.2°C, and 45°C, and the corresponding temperature change rates are 2.5°C, 3.3°C, 3.4°C, and 3.8°C, respectively, meeting the four consecutive threshold conditions. Among them, the abnormal battery temperature increase interval is a dangerous state in which the battery heating rate exceeds the safety threshold; the temperature rise gradient is the incremental value of the battery temperature per unit time, reflecting the risk of thermal runaway of the battery.

[0085] When it is detected that the battery temperature change rate exceeds a preset critical value, the wireless communication module is temporarily shut down and the device authenticity diagnosis program is started.

[0086] Specifically, the preset critical value is 3℃ / second, and the preset critical value is an adjustable parameter. When the trigger condition is met, a GPIO interrupt signal is sent to the wireless communication controller to forcibly shut down the Wi-Fi, Bluetooth and mobile data modules. At the same time, the device hardware feature verification algorithm is called to verify the consistency of the IMEI number hash value with the preset whitelist, detect the silicon chip fingerprint hash code of the NAND flash memory chip, and compare the resonant frequency of the motherboard capacitor array. The diagnostic program execution logic is if , then the device is legal, otherwise it is considered a tampered device. For the The difference flag of the test results is 0 for normal and 1 for abnormal. Among them, the device authenticity diagnosis procedure is a detection process that verifies the physical integrity of the device through the hardware uniqueness feature; the silicon chip fingerprint hash code is a hardware-level identifier generated by the microstructure difference in the semiconductor manufacturing process. Through the dual check of temperature fluctuations and hardware fingerprints, device tampering caused by the use of inferior accessories or physical attacks can be identified, and malicious operations through hardware vulnerabilities can be blocked.

[0087] For example, the attacker used a heat gun to heat the battery area of ​​the device to interfere with the biosensor. The system detected that the temperature rose from 25°C to 52°C in just 8 seconds, with a rate of change of 3.375°C / second. Wireless communication was immediately shut down and diagnosis was initiated. And the NAND flash silicon chip fingerprint is abnormal , so the device is deemed illegal. Clear sensitive data in memory and enter hardware lock state to prevent attackers from extracting keys. Combine dynamic temperature monitoring and static hardware fingerprint verification to accurately identify physical attack behaviors. Even if an attacker bypasses software protection, they cannot break through the hardware-level security line, ensuring the integrity of key data in extreme attack scenarios.

[0088] Based on the same inventive concept, the present invention also provides a network security verification system for a security system, the system comprising: A biometric feature acquisition module, used to obtain a biometric feature recognition request triggered by a user on a terminal device, wherein the biometric feature recognition request includes an encrypted transmission instruction of a user's fingerprint grayscale image and iris texture data; A behavior track capture module, used to synchronously collect the dynamic behavior track data of the user when initiating the biometric feature recognition request, and generate a behavior feature code; A correlation calculation module, used to input the physiological feature data in the biometric identification request and the behavioral feature code into a pre-trained feature verification model for matrix convolution calculation, and output a bio-behavior correlation index, wherein the physiological feature data includes a fingerprint grayscale image and iris texture data; A strategy triggering module, used to trigger a dynamic verification strategy adjustment instruction when the biological behavior correlation index is lower than a first preset threshold; A verification strategy generation module, used to obtain device parameters and analyze the abnormal correlation of each parameter based on the dynamic verification strategy adjustment instruction, and generate a multi-dimensional verification superposition strategy; An encrypted token generation module, used to perform at least two verification operations in the multi-dimensional verification superposition strategy, and input the verification results into the distributed time synchronization node to generate an encrypted token; The security verification module is used to output a security verification pass instruction when the synchronization matching degree of the encrypted token between different nodes exceeds a second preset threshold.

[0089] It should be noted that the electrical connection between the above-mentioned units does not necessarily mean direct connection of the lines, and the indirect connection mode can be applied to the embodiments of the present invention as long as the purpose of the present invention is achieved. The above is only an exemplary embodiment of the present invention and cannot be used to limit the scope of the present invention.

[0090] That is, any equivalent changes and modifications made according to the teachings of the present invention are still within the scope of the present invention. This application is intended to cover any variation, use or adaptive change of the present invention, which follows the general principles of the present invention and includes common knowledge or conventional technical means in the technical field not described in the present invention.

Claims

1. A network security verification method for a security system, characterized in that: The method comprises: Obtaining a biometric feature recognition request triggered by a user on a terminal device, wherein the biometric feature recognition request includes an encrypted transmission instruction of a grayscale image of a fingerprint and iris texture data of the user; Synchronously collecting dynamic behavior trajectory data of the user when initiating the biometric identification request, and generating a behavior feature code; Input the physiological feature data in the biometric identification request and the behavioral feature code into a pre-trained feature verification model for matrix convolution calculation, and output a bio-behavior correlation index, wherein the physiological feature data includes a fingerprint grayscale image and iris texture data; When the biological behavior correlation index is lower than a first preset threshold, a dynamic verification strategy adjustment instruction is triggered; Based on the dynamic verification strategy adjustment instruction, the device parameters are obtained and the abnormal correlation of each parameter is analyzed to generate a multi-dimensional verification superposition strategy; Perform at least two verification operations in the multi-dimensional verification overlay strategy, and input the verification results into the distributed time synchronization node to generate an encrypted token; When the synchronization matching degree of the encrypted token between different nodes exceeds a second preset threshold, a security verification pass instruction is output.

2. The network security verification method for a security system according to claim 1, characterized in that: The synchronously collecting the dynamic behavior trajectory data of the user when initiating the biometric feature recognition request and generating the behavior feature code comprises: Real-time monitoring of the capacitance change gradient sequence of the user's touch screen operation; The gyroscope sensor is used to collect the three-dimensional acceleration fluctuation map of the device; Performing time-frequency domain fusion processing on the capacitance change gradient sequence and the acceleration fluctuation spectrum to generate a dynamic behavior feature vector; After the dynamic behavior feature vector is normalized, a behavior feature code is obtained.

3. The network security verification method for a security system according to claim 1, characterized in that: The obtaining of equipment parameters and analyzing the abnormal correlation of each parameter to generate a multi-dimensional verification superposition strategy includes: Periodically obtain a set of network environment parameters including IP address jump strength, SSL certificate validity mark, and SIM card information matching degree; Performing topological analysis on abnormal correlations of at least three parameters in the network environment parameter set to generate a risk distribution heat map; The additional verification method to be enhanced is determined according to the risk area of ​​the risk distribution heat map, and a multi-dimensional verification superposition strategy is generated.

4. The network security verification method for a security system according to claim 3, characterized in that: The multi-dimensional verification superposition strategy includes: Generate a first authentication factor based on a comparison with a historical database of the Wi-Fi BSSID to which the device is currently connected; The second verification factor is generated by calculating the spatial difference between the operator base station location and the GPS positioning information; Generate a third authentication factor by combining the physical fingerprint characteristics of the SIM card integrated circuit; The first verification factor, the second verification factor and the third verification factor are subjected to multi-level serial verification according to the weight distribution of the risk distribution heat map.

5. The network security verification method for a security system according to claim 1, characterized in that: The steps of generating the encrypted token specifically include: Read the original feature code after the biometric feature verification is passed; Inserting a millisecond timestamp and performing segmented hash calculation on the original feature code; The local time calibration error value of each node is incorporated into the encryption calculation as a hash perturbation factor to generate a dynamically variable token.

6. The network security verification method for a security system according to claim 1, characterized in that: The verification step of the distributed time synchronization node specifically includes: Compare the absolute deviation values ​​of the bank server timestamp, the user terminal device timestamp and the operator gateway timestamp; When the absolute deviation value exceeds a preset time threshold, a session key revocation procedure is automatically triggered; The transmission delay value of the encrypted token between the nodes is used as an additional verification parameter for the legitimacy of the session.

7. The network security verification method for a security system according to claim 1, characterized in that: The updating method of the feature verification model includes: Collect verification log data of legitimate users in abnormal network environments; Extracting a correlation attenuation pattern between biological features and behavioral features in the verification log data; The kernel function weight matrix of the matrix convolution calculation is updated through an online incremental learning algorithm.

8. The network security verification method for a security system according to claim 1, characterized in that: Before the safety verification passes the instruction output, the method further includes: Collect the strategy execution time consumption data in the current verification process; Dynamically adjust the verification strength level of subsequent sessions according to the time consumption data; The adjusted verification strength level is gradient-bound to the user's credit score.

9. The network security verification method for a security system according to claim 1, characterized in that: The following pre-judgment steps are performed when the biometric feature recognition request is triggered: Detect whether the battery temperature of the terminal device is in an abnormally high range; When it is detected that the battery temperature change rate exceeds a preset critical value, the wireless communication module is temporarily shut down and the device authenticity diagnosis program is started.

10. A network security verification system for a security system, applied to a network security verification method for a security system as claimed in any one of claims 1 to 9, characterized in that: The system comprises: A biometric feature acquisition module, used to obtain a biometric feature recognition request triggered by a user on a terminal device, wherein the biometric feature recognition request includes an encrypted transmission instruction of a user's fingerprint grayscale image and iris texture data; A behavior track capture module, used to synchronously collect the dynamic behavior track data of the user when initiating the biometric feature recognition request, and generate a behavior feature code; A correlation calculation module, used to input the physiological feature data in the biometric identification request and the behavioral feature code into a pre-trained feature verification model for matrix convolution calculation, and output a bio-behavior correlation index, wherein the physiological feature data includes a fingerprint grayscale image and iris texture data; A strategy triggering module, used to trigger a dynamic verification strategy adjustment instruction when the biological behavior correlation index is lower than a first preset threshold; A verification strategy generation module, used to obtain device parameters and analyze the abnormal correlation of each parameter based on the dynamic verification strategy adjustment instruction, and generate a multi-dimensional verification superposition strategy; An encrypted token generation module, used to perform at least two verification operations in the multi-dimensional verification superposition strategy, and input the verification results into the distributed time synchronization node to generate an encrypted token; The security verification module is used to output a security verification pass instruction when the synchronization matching degree of the encrypted token between different nodes exceeds a second preset threshold.

Citation Information

Patent Citations

  • Intelligent access control management method and system based on multi-mode identification and Internet of Things technology

    CN118968665A

  • Multi-factor network security authentication method and system based on SDN (Software Defined Network)

    CN119520064A

  • An intelligent management method and system for bidding information based on artificial intelligence

    CN119743333A

  • An enhanced AI-powered system for multimodal data processing, dynamic authentication, and secure fintech and IoT transactions.

    DE202025100814U1

Cited By

  • Offshore wind turbine access control system control method and offshore wind turbine access control system

    CN120496207A

  • Power terminal data authentication method and system based on network identifier dynamic binding

    CN120567470A

  • System architecture and method for dynamically deploying network security service

    CN120567538A

  • Multi-level dynamic authorization and access control method and system based on identity token

    CN120567584A

  • Multi-level dynamic authorization and access control method and system based on identity token

    CN120567584B