Network Security Verification Method and System for Security Systems
Through multimodal biometric dynamic modeling and distributed timestamp perturbation encryption technology, the security risks of existing authentication systems in complex network environments are solved, dynamic layered defense and high security verification are achieved, and defense capabilities for counterfeiting and replay attacks are improved, ensuring the security and reliability of the verification process and user experience.
Patent Information
- Application Number
- CN202510481140.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-04-17
AI Technical Summary
The existing identity verification system poses security risks in high-precision biometric forgery, replay attacks and changes in dynamic network environments. It lacks the ability to evaluate the dynamic association of real-time network environment parameters and user behavior, resulting in overloading of the verification process or blind spots in defense, making it difficult to resist attacks in cross-regional access and device replacement scenarios.
Multimodal biometric dynamic modeling, risk heat map-driven multi-factor verification strategy and distributed timestamp perturbation encryption technology are adopted to synchronously collect biometric and dynamic behavior data, generate behavioral signature codes, combine time-frequency domain fusion analysis, dynamic adjustment of verification strategies, and synchronous matching verification of encryption tokens between distributed nodes.
It significantly improves the defense capabilities of counterfeit biometrics and replay attacks, ensures the non-replicability of verification information, balances security and efficiency, adapts to complex network attack scenarios, blocks illegal replay attacks and man-in-the-middle hijacking, and provides high security and smooth user experience.
Smart Images

Figure CN119996092B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security verification method and system for security systems. Background Art
[0002] In the field of network security protocols, existing authentication systems mostly adopt the method of single biometric recognition or static passwords combined with SMS verification codes. Such methods rely on the static collection of biometric features or pre-allocated fixed credentials, and cannot effectively cope with the security risks brought by high-precision biometric forgery, replay attacks, and dynamic network environment changes. Especially in scenarios of cross-regional access or device replacement, there is a lack of continuous behavior monitoring mechanism after a single verification is passed, which is easily exploited by attackers to initiate malicious operations through short-term security windows.
[0003] Traditional solutions mainly enhance security by adding multi-factor authentication links, such as combining biometric features with hardware tokens, geographical location verification, etc. However, multi-factor authentication strategies often execute verification using fixed logic and lack the ability to evaluate the dynamic association between real-time network environment parameters and user behavior. This results in the coexistence of overloaded verification processes and defense blind spots: redundant verification steps in low-risk scenarios affect efficiency, while sudden abnormal behaviors may lead to security vulnerabilities due to insufficiently strong verification strategies not being triggered.
[0004] The main drawbacks of the existing technology lie in the separation of biometric verification and network environment monitoring, and the insufficient adaptability of static encryption mechanisms to spatio-temporal condition changes. For example, traditional dynamic tokens rely on one-way time synchronization algorithms and do not consider the impact of physical clock deviations between distributed nodes, and are easily interfered by time zone tampering or network delays. In addition, the lack of fusion verification of hardware-level non-replicable features and behavioral data makes it difficult to resist supply chain attacks or penetration by emulated devices. These defects pose major security hazards in scenarios with high security requirements such as financial transactions and remote control. Summary of the Invention
[0005] To solve the above problems, the present invention provides a network security verification method and system for security systems, which adopt multi-modal biometric dynamic modeling, risk heat map-driven multi-factor verification strategies, and distributed timestamp perturbation encryption technology, and can enhance the anti-counterfeiting ability of biometric features while achieving dynamic hierarchical defense, adapting to complex network attack scenarios, blocking illegal replay attacks and man-in-the-middle hijacking, and ensuring the security and reliability of the verification process and the smoothness of the user experience in high-security scenarios.
[0006] The above objectives can be achieved through the following solutions:
[0007] A network security verification method for a security system, including obtaining a biometric recognition request triggered by a user on a terminal device, where the biometric recognition request includes an encrypted transmission instruction for the user's fingerprint grayscale image and iris texture data; synchronously collecting dynamic behavior trajectory data of the user when initiating the biometric recognition request to generate a behavior feature code; inputting the physiological feature data in the biometric recognition request and the behavior feature code into a pre-trained feature verification model for matrix convolution calculation to output a biobehavior correlation index, where the physiological feature data includes a fingerprint grayscale image and iris texture data; when the biobehavior correlation index is lower than a first preset threshold, triggering a dynamic verification strategy adjustment instruction; based on the dynamic verification strategy adjustment instruction, obtaining device parameters and analyzing the abnormal correlation of each parameter to generate a multi-dimensional verification overlay strategy; performing at least two verification operations in the multi-dimensional verification overlay strategy and inputting the verification results into a distributed time synchronization node to generate an encrypted token; when the synchronization matching degree of the encrypted token between different nodes exceeds a second preset threshold, outputting a security verification pass instruction.
[0008] Optionally, the synchronously collecting dynamic behavior trajectory data of the user when initiating the biometric recognition request to generate a behavior feature code includes: real-time monitoring of the capacitance change gradient sequence of the user's touch screen operation; collecting the three-dimensional space acceleration fluctuation map of the device through a gyroscope sensor; performing time-frequency domain fusion processing on the capacitance change gradient sequence and the acceleration fluctuation map to generate a dynamic behavior feature vector; and obtaining a behavior feature code after normalizing the dynamic behavior feature vector.
[0009] Optionally, the obtaining device parameters and analyzing the abnormal correlation of each parameter to generate a multi-dimensional verification overlay strategy includes: periodically obtaining a network environment parameter set including IP address jump strength, SSL certificate validity mark, and SIM card information matching degree; performing topological analysis on the abnormal correlation of at least three parameters in the network environment parameter set to generate a risk distribution heat map; and determining additional verification methods to be enhanced according to the risk area of the risk distribution heat map to generate a multi-dimensional verification overlay strategy.
[0010] Optionally, the multi-dimensional verification overlay strategy includes: generating a first verification factor based on the comparison with the historical database of the Wi-Fi BSSID currently connected to the device; generating a second verification factor through the calculation of the spatial difference degree between the operator base station location and the GPS positioning information; generating a third verification factor by combining the physical fingerprint characteristics of the SIM card integrated circuit; and performing multi-level cascaded verification on the first verification factor, the second verification factor, and the third verification factor according to the weight distribution of the risk distribution heat map.
[0011] Optionally, the step of generating the encryption token specifically includes: reading the original feature encoding after biometric verification passes; inserting a millisecond-level timestamp and performing segmented hashing calculation on the original feature encoding; incorporating the local time calibration error value of each node as a hashing perturbation factor into the encryption calculation to generate a dynamically variable token.
[0012] Optionally, the verification step of the distributed time synchronization node specifically includes: comparing the absolute deviation values of the bank server timestamp, the user terminal device timestamp, and the operator gateway timestamp; automatically triggering the session key revocation program when the absolute deviation value exceeds the preset time threshold; using the transmission delay value of the encryption token between each node as an additional verification parameter for session legitimacy.
[0013] Optionally, the method for updating the feature verification model includes: collecting the verification log data of legitimate users in an abnormal network environment; extracting the attenuation pattern of the correlation between biometric features and behavioral features in the verification log data; updating the kernel function weight matrix of the matrix convolution calculation through an online incremental learning algorithm.
[0014] Optionally, before the output of the security verification pass instruction, it further includes: collecting the policy execution time-consuming data in the current verification process; dynamically adjusting the verification intensity level of subsequent sessions according to the time-consuming data; performing gradient binding processing on the adjusted verification intensity level and the user credit score.
[0015] Optionally, the following pre-judgment steps are performed simultaneously when the biometric recognition request is triggered: detecting whether the battery temperature of the terminal device is in an abnormally rising range; when it is detected that the battery temperature change rate exceeds the preset critical value, temporarily turning off the wireless communication module and starting the device authenticity diagnosis program.
[0016] Based on the same inventive concept, the present invention also provides a network security verification system for a security system. The system includes: a biometric acquisition module for obtaining a biometric recognition request triggered by a user on a terminal device, where the biometric recognition request includes an encrypted transmission instruction for the user's fingerprint grayscale image and iris texture data; a behavior trajectory capture module for synchronously collecting dynamic behavior trajectory data of the user when initiating the biometric recognition request and generating a behavior feature code; a correlation calculation module for inputting the physiological feature data in the biometric recognition request and the behavior feature code into a pre-trained feature verification model for matrix convolution calculation and outputting a biobehavior correlation index, where the physiological feature data includes a fingerprint grayscale image and iris texture data; a policy trigger module for triggering a dynamic verification policy adjustment instruction when the biobehavior correlation index is lower than a first preset threshold; a verification policy generation module for obtaining device parameters based on the dynamic verification policy adjustment instruction and analyzing the abnormal correlation of each parameter to generate a multi-dimensional verification overlay policy; an encryption token generation module for performing at least two verification operations in the multi-dimensional verification overlay policy and inputting the verification results into a distributed time synchronization node to generate an encryption token; and a security verification module for outputting a security verification pass instruction when the synchronization matching degree of the encryption token between different nodes exceeds a second preset threshold.
[0017] Compared with the prior art, the present invention has the following advantages:
[0018] 1. By synchronously collecting biometric and dynamic behavior data and combining time-frequency domain fusion analysis to generate a behavior feature code, the present invention extends traditional static biometric verification to spatio-temporal associated multi-dimensional identity verification, significantly enhancing the defense capabilities against counterfeited biometrics, replay attacks, and device cloning, and ensuring the non-replicability of verification information.
[0019] 2. Dynamically generate a risk heat map based on the abnormal correlation topology analysis of network environment parameters, and intelligently trigger multi-factor verification logic according to different risk levels to balance security and efficiency; streamline the verification process in low-risk scenarios and automatically overlay hardware-level verification factors when detecting suspicious behaviors to form a precise hierarchical security barrier.
[0020] 3. Adopt millisecond-level timestamp segmented hashing and distributed node time error perturbation technology, making the generation of the encryption token dependent on real-time physical environment parameters, and introducing double verification of transmission delay and timing deviation in cross-node synchronization verification, effectively curbing cross-regional replay attacks and network man-in-the-middle hijacking, and ensuring that the token is only valid under legal spatio-temporal conditions.
[0021] 4. Continuously optimize the feature verification model through the incremental learning mechanism, quickly adapt when the user behavior pattern changes or the network environment mutates, and avoid frequent verification failures caused by traditional fixed thresholds; combine credit scoring to dynamically adjust the verification intensity, so that high-credit users can enjoy seamless verification during legal operations and reduce interference with normal business processes.
[0022] Other features and advantages of the present invention will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be realized and obtained through the structures pointed out in the specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0024] Figure 1 is a schematic flowchart of the network security verification method for the security system according to an embodiment of the present invention.
[0025] Figure 2 is a schematic structural diagram of the risk distribution heat map according to an embodiment of the present invention.
[0026] Figure 3 is a schematic structural diagram of the network security verification system for the security system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0028] Refer to Figure 1 , an embodiment of the present invention proposes a network security verification method for a security system, which adopts a multi-modal biometric dynamic modeling, a multi-factor verification strategy driven by a risk heat map, and a distributed timestamp perturbation encryption technology, and can achieve dynamic hierarchical defense while enhancing the anti-counterfeiting ability of biometrics, adapt to complex network attack scenarios, and block illegal replay attacks and man-in-the-middle hijacking, ensuring the security and reliability of the verification process and the smoothness of the user experience in high-security scenarios.
[0029] The method of this embodiment specifically includes:
[0030] Obtain a biometric recognition request triggered by a user on a terminal device, where the biometric recognition request includes an encrypted transmission instruction for the user's fingerprint grayscale image and iris texture data;
[0031] Specifically, when the user conducts identity authentication on the biometric collection module of the terminal device, a request signal is automatically generated. The signal is intercepted through the hardware driver layer and a secure transmission channel is established. The biometric collection module is, for example, a fingerprint sensor or an iris scanner; among them, the terminal device is an intelligent terminal device integrated with biometric collection hardware and connected to a security network; the biometric recognition request is an encrypted transmission instruction containing the user's fingerprint grayscale image or iris texture data.
[0032] Synchronously collect the dynamic behavior trajectory data of the user when initiating the biometric recognition request, and generate a behavior feature code;
[0033] Specifically, at the moment when the user triggers biometric recognition, the system records the change sequence of the pressure value of the fingertip sliding through the touch screen capacitance sensor, and collects the acceleration vector and angular velocity vector of the device in three-dimensional space through the gyroscope; the two types of data are processed through a time-frequency domain fusion algorithm, such as the short-time Fourier transform, to generate a hybrid spectrum containing time-series correlation features, and then compressed into a fixed-length feature code through a normalization coding algorithm. The dynamic behavior trajectory data includes, but is not limited to, the fingertip pressure gradient change sequence monitored in real time by the touch capacitance sensor, with a sampling rate ≥ 100Hz, and the standard deviation of the X / Y / Z axis acceleration collected by the gyroscope. Through time-frequency domain fusion technology, such as the short-time Fourier transform, the two types of data are mapped into a hybrid feature vector.
[0034] Among them, the capacitance change gradient sequence is a set of mapping relationships between the capacitance value change rate of each contact point per second and the spatial coordinates during a touch operation; the acceleration fluctuation spectrum is a motion feature matrix composed of the instantaneous acceleration and standard deviation of the device in the X / Y / Z axis directions; the time-frequency domain fusion processing is an analysis method that converts time-series data into frequency-domain energy distribution and superimposes it with the time-domain trend.
[0035] Input the physiological feature data in the biometric recognition request and the behavior feature code into a pre-trained feature verification model for matrix convolution calculation, and output a biometric behavior correlation index, where the physiological feature data includes a fingerprint grayscale image and iris texture data;
[0036] Specifically, the model converts the user's fingerprint image and the behavioral feature code into 768-dimensional vectors respectively, and performs layer-by-layer convolutional calculations on the spatial correlation of the two types of vectors through three convolutional kernels, and finally outputs a correlation score within the range of 0-1; the initial weights of the model kernel function are obtained by training a large number of biological behavior samples of legitimate users; for the biological behavior correlation index , there are
[0037] ,
[0038] In the formula, is the weight matrix of the th convolutional kernel, is the input feature matrix, ⊗ represents the convolutional operation, is the Sigmoid activation function, is the bias term.
[0039] When the biological behavior correlation index is lower than the first preset threshold, a dynamic verification policy adjustment instruction is triggered;
[0040] Specifically, the first preset threshold can be 0.6. When the score is lower than the first preset threshold, it is determined that there is an abnormality in the current verification environment. By calling the device hardware parameter scanning module and performing multi-dimensional security analysis according to the network environment parameters.
[0041] Based on the dynamic verification policy adjustment instruction, device parameters are obtained and the abnormal correlation of each parameter is analyzed to generate a multi-dimensional verification overlay policy;
[0042] Specifically, the system obtains parameters such as the device's Wi-Fi historical connection record, the current GPS position offset, and the SIM card ICCID serial number, and constructs a parameter correlation map; uses graph theory algorithms to analyze abnormal nodes, such as abnormal jumps of the IP address across 3 countries within 5 minutes, so as to generate a heat map containing high-risk area markings, and selects an overlay verification method accordingly; for example, when it is detected that the IP address attribution of a certain device suddenly switches from Beijing to overseas, while the GPS positioning still shows in Beijing, the system marks this area as a red high-risk area, triggering a dual strategy of SIM card physical chip fingerprint verification and base station triangulation verification.
[0043] Execute at least two verification operations in the multi-dimensional verification overlay policy, and input the verification results into the distributed time synchronization node to generate an encrypted token;
[0044] Specifically, the verification process includes comparing the Wi-Fi BSSID that the device was historically connected to, i.e., the first factor, calculating the distance difference between the base station and the GPS coordinates, i.e., the second factor, and performing hash encryption on the physical characteristics of the SIM card chip, i.e., the third factor; the data packet that passes the consistency check will be appended with a millisecond-level timestamp and a dynamic token will be generated through the consensus of three distributed nodes; for example, in a certain verification, the second factor detects that the base station distance difference is 300 meters, exceeding the preset threshold of 200 meters, and the system forces the addition of the third factor verification, i.e., the SIM card chip coding verification, and finally generates a token "TKN=7D4A..." with the timestamp "TS=1625000000123", and synchronizes it to the bank server and the operator gateway node.
[0045] When the synchronization matching degree of the encrypted token between different nodes exceeds the second preset threshold, a security verification passed instruction is output.
[0046] Specifically, after generating the encrypted token, it is distributed to the distributed time synchronization nodes for cross-node consistency check. The distributed time synchronization nodes are such as the bank server, the user terminal device, and the operator gateway. The local time calibration error value of each node is used as a hash perturbation factor to participate in the token generation to ensure that the token contains a millisecond-level timestamp and a segmented hash value. The millisecond-level timestamp is such as TS=1625000000123, and the segmented hash value is such as TKN=7D4A.... Subsequently, the absolute deviation value of the timestamps of each node is calculated , where When it exceeds the preset time threshold, the session key is revoked. In each node, the received encrypted token is compared with the locally generated token. If the hash values are the same and the timestamp deviation is within the allowable range, it is regarded as a successful match. The matching degree , in the formula, is the number of nodes with successful matches, is the total number of nodes. When the matching degree is greater than the second preset threshold, it is determined that the cross-node verification is passed and a security verification passed instruction is output; otherwise, secondary verification or an alarm is triggered. Through the above steps, the system ensures the uniqueness and consistency of the encrypted token in the time and space dimensions, and realizes high-strength distributed security verification.
[0047] Through the time-frequency domain fusion analysis of biometric and dynamic behavior data, the present invention constructs multi-dimensional verification factors and a distributed time lock to realize the adaptive hierarchical defense of network security verification. The coupling of physiological characteristics and hardware-level physical fingerprints raises the forgery threshold, and the timestamp perturbation mechanism ensures the uniqueness of verification from the time and space dimensions. The verification example shows that the system can distinguish natural operations from attack behaviors, significantly reduce the risks of man-in-the-middle attacks and device cloning in high-risk scenarios such as cross-border payments and remote authorizations, and at the same time maintain a smooth experience for legitimate users through incremental learning.
[0048] Optionally, the dynamic behavior trajectory data of the user when initiating the biometric recognition request is synchronously collected, and generating a behavior feature code includes:
[0049] Real-time monitoring of the capacitance change gradient sequence of the user's touch screen operation;
[0050] Specifically, at the moment when the user touches the touch screen of the terminal, the system captures the capacitance value change sequence of the contact area through the surface capacitance sensor at a sampling rate of 100 times per second. Record each sampling point in the touch screen coordinate system The capacitance intensity at the position , forming a capacitance gradient matrix containing time stamps . Among them, in the capacitance gradient matrix The capacitance value change rate per millisecond is used as the calculation unit. Among them, the touch screen operation is the electrostatic coupling effect generated when the user's finger or stylus touches the capacitive screen; the capacitance change gradient sequence is a set of mapping relationships between the capacitance value increment and the spatial coordinates of the contact point within a unit time, characterizing the force distribution characteristics of the user's operation.
[0051] Collect the three-dimensional space acceleration fluctuation map of the device through the gyroscope sensor;
[0052] Specifically, the built-in MEMS gyroscope of the device collects the acceleration vector components of the X / Y / Z axes at a frequency of 2KHz , and calculates the standard deviation of the acceleration of each axis within a 200ms sliding window 、 、 , generating a three-dimensional acceleration fluctuation map . At the same time, record the modulus change period of the angular velocity vector . Among them, the gyroscope sensor is a three-axis motion detection device based on microelectromechanical systems; the acceleration fluctuation map is a distribution map of the severity of the device's motion in each axial direction, and the device jitter characteristics are quantified through the standard deviation.
[0053] Perform time-frequency domain fusion processing on the capacitance change gradient sequence and the acceleration fluctuation map to generate a dynamic behavior feature vector;
[0054] Specifically, short-time Fourier transform is used to perform time-frequency analysis on the two types of data: perform 256-point FFT calculation on the component of the capacitance gradient matrix to obtain the frequency domain energy spectrum , perform wavelet transform on the standard deviation sequence of the acceleration fluctuation to extract the band energy . Through the fusion layer, and are superimposed according to the frequency band weights to form a mixed spectrum matrix , where is the confidence adjustment coefficient of the gyroscope data, is the frequency component corresponding to the n-th frequency point. For example, when the FFT frequency points of the capacitance data correspond to the low-frequency band of 8 - 10 Hz, the energy of the same frequency band output by the acceleration wavelet transform is also mapped to , and the proportion of the acceleration data in the fusion is adjusted through parameters. Assuming , then .
[0055] Expand into a one-dimensional vector and perform PCA dimensionality reduction to 128 dimensions. Among them, the time-frequency domain fusion processing is to convert the waveform features of the time series into the frequency domain energy distribution, and highlight the fingerprint features of the human operation behavior through a weighted method.
[0056] After normalizing the dynamic behavior feature vector, a behavior feature code is obtained.
[0057] Specifically, the minimum-maximum normalization method is used to perform a linear transformation on each dimension of the 128-dimensional feature vector, and compress the numerical interval to [0, 1]. The normalized vector is converted into a hexadecimal string with a fixed length of 64 bytes through the SHA-256 hash algorithm as the final behavior feature code. Among them, the normalization process is a data standardization operation to eliminate the dimensional differences of different sensors; the behavior feature code is a digital fingerprint representing the uniqueness of the user's operation mode.
[0058] Specifically, a dynamic behavior feature code is constructed through multi-dimensional sensing data fusion, combining biological features with operation behavior features, breaking through the technical limitations of traditional static biometric verification. The capacitance gradient sequence quantifies the change in touch force, and the acceleration map reflects the motion mode of the device naturally held by the human body. The time-frequency domain fusion enhances the spatio-temporal correlation of features. The finally generated encrypted feature code has the characteristics of anti-replay and anti-simulation attack, while improving the verification security and maintaining the smoothness of the user experience. Through the continuous learning of the dynamic behavior model, the system can adaptively identify the evolution of the user behavior pattern.
[0059] Optionally, the obtaining device parameters and analyzing the abnormal correlation of each parameter to generate a multi-dimensional verification superposition strategy includes:
[0060] Periodically obtain a set of network environment parameters including the IP address jump strength, SSL certificate validity mark, and SIM card information matching degree;
[0061] Specifically, a set of network environment parameters including the IP address hopping intensity, SSL certificate validity flag, and SIM card information matching degree is obtained from the device network layer and security components at a 5-minute interval. The IP address hopping intensity is calculated by parsing the TCP / IP protocol stack logs and computing the ratio of the number of switches in the geographical location of the device's external network IP address per unit time to the number of autonomous systems crossed. The SSL certificate validity flag is obtained by extracting the certificate fingerprint of the currently connected HTTPS server and comparing it with the public certificate transparency logs to mark the status of expired, revoked, or untrusted certificates. The SIM card information matching degree is calculated by reading the unique integrated circuit code (ICCID) of the SIM card and the affiliated operator code and computing the similarity with the white list database preset at the time of device factory production.
[0062] Among them, the IP address hopping intensity is a quantitative indicator characterizing the abnormal transition of the network connection geographical location; the SSL certificate validity flag is a binary label for the trusted status of the server identity; the SIM card information matching degree is a consistency score of the current SIM card with the device's historical binding records.
[0063] Perform topological analysis on the abnormal correlations of at least three parameters in the set of network environment parameters to generate a risk distribution heat map;
[0064] Specifically, construct a network environment parameter relationship graph, where the nodes represent parameter types and the edge weights are determined by the abnormal correlations between the parameters. Use an improved PageRank algorithm to calculate the risk values of the parameter nodes. For the risk value of the th parameter node, there is
[0065] ,
[0066] In the formula, is the influence weight of neighbor nodes, taking an empirical value of 0.85, indicating the transmission ratio of the risk of the current node affected by the risks of adjacent nodes and reflecting the propagation characteristics of the attack chain; represents the set of neighbor nodes directly connected to node . For example, when analyzing the IP address hopping intensity node, its neighbors may include the SSL validity node and the SIM matching degree node; is the Pearson correlation coefficient between node and ; it reflects the statistical correlation between two parameters in historical abnormal events. When the two parameters are often abnormal at the same time, tends to approach 1; is the risk score of neighbor node , updated through an iterative algorithm, and the initial value is assigned by the original abnormal score of the parameter; is the inherent risk coefficient of entity parameters, taking 0.15, which represents the basic risk weight of non-topological association, such as the contribution of an independent abnormal event of a certain node; represents a node the set of entity parameters it contains. For example, when analyzing the node of SIM card information matching degree, it contains sub-parameters such as ICCID validity and operator binding status; parameter 's original abnormal score. Map the risk value to the network topology layer where the device is located, and use red, orange, and yellow to mark high-risk, medium-risk, and low-risk areas.
[0067] Among them, topological analysis is a network parameter relationship modeling method based on graph theory; the risk distribution heat map is a visualization atlas that expresses the attack probability of different regions with color depth, such as Figure 2 the two-dimensional grid shown, where each grid point represents a geographical location or a network area, and each grid point has a risk value.
[0068] Determine the additional verification methods to be enhanced according to the risk areas of the risk distribution heat map, and generate a multi-dimensional verification overlay strategy.
[0069] Specifically, trigger three-factor verification in high-risk areas, Wi-Fi BSSID historical track backtracking: query the physical address sequence of the wireless APs connected by the device in the past 24 hours. Base station positioning and GPS coordinate difference verification: calculate the actual distance between the base station corresponding to the operator LAC cell number and the device GPS. SIM card chip physical fingerprint extraction: read the hash value of the microscopic defect characteristics formed by the manufacturing process of the SIM card silicon wafer. Adopt two-factor verification in medium-risk areas, and only append single-factor verification in low-risk areas.
[0070] Among them, the multi-dimensional verification overlay strategy is a defense mechanism that dynamically combines multiple verification methods according to the real-time risk level; the additional verification method is an auxiliary identity verification means based on device hardware characteristics or network behavior characteristics.
[0071] Exemplarily, a certain user device continuously switches its external network IP three times within 10 minutes. For example, it changes from Beijing, China to Moscow, Russia and then to Frankfurt, Germany. At the same time, it is detected that the HTTPS certificate issuing authority is not in the ICANN authorized list, and the matching degree between the SIM card ICCID and the device IMEI binding record is only 35%. Therefore, parameter collection is carried out to obtain that the IP jump intensity becomes 3 times / 10 minutes, crossing 3 AS numbers, obtaining that the SSL certificate validity is marked as 0, that is, invalid, and obtaining a SIM matching degree of 0.35. Construct a parameter node relationship graph and calculate to obtain , indicating high risk, , indicating high risk, , indicating medium risk, the generated heat map shows that the high-risk areas cover the network connection layer (red) and the device identification layer (orange). The high-risk areas trigger three-factor verification, checking whether the Wi-Fi AP that the device was recently connected to is the historical track of "00:1A:2B:XX", calculating the distance difference between the location of base station LAC12345 (latitude 39.90° north) and the device's GPS (latitude 52.52° north) reaches 1250 km, and extracting the physical fingerprint hash of the SIM card "9f86d081..." fails to match the pre-stored value. Through multi-parameter joint topology analysis, cross-border springboard attacks disguised as normal users can be effectively identified. The strong correlation between IP hopping and invalid certificates triggers the highest-level verification strategy, and the abnormal SIM card matching further confirms that the attacker uses an unauthorized device. The heat map dynamic guidance system focuses on protecting the network connection layer, avoiding misjudgment of single-point parameters, and ensuring accurate interception of illegal access in complex network attack scenarios.
[0072] Optionally, the multi-dimensional verification overlay strategy includes:
[0073] Generating a first verification factor based on the comparison of the historical database of the Wi-Fi BSSID currently connected by the device;
[0074] Specifically, the system queries the physical address (BSSID) sequence of the Wi-Fi access points connected by the device in the past 30 days, and calculates the similarity score between the currently connected BSSID and the historical record through the Levenshtein distance algorithm to obtain the first verification factor. For the first verification factor , there is
[0075] ,
[0076] In the formula, is the Levenshtein edit distance, is the current BSSID string, is the last 10 valid BSSIDs recorded in the historical database. If the first verification factor is greater than 0.8, it is marked as a legal factor. Among them, the Wi-Fi BSSID historical database is a library of physical address sequences of wireless access points regularly encrypted and stored by the device.
[0077] Generating a second verification factor by calculating the spatial difference degree between the location of the operator's base station and the GPS positioning information;
[0078] Specifically, based on the longitude and latitude coordinates of the LAC cell provided by the operator and the device's GPS coordinates , the spatial difference degree is calculated using the Haversine formula to obtain the second verification factor. For the second verification factor , there is
[0079] ,
[0080] In the formula, is the radius of the earth, which is 6371 km, , . When the second verification factor exceeds the 200-meter threshold, secondary verification is triggered.
[0081] Among them, the spatial difference degree is calculated as a dynamic positioning inspection method that quantifies the deviation between the base station signal coverage range and the physical position through spherical trigonometry.
[0082] Generate the third verification factor by combining the physical fingerprint features of the SIM card integrated circuit;
[0083] Specifically, read the startup voltage curve of the SIM card chip , extract the characteristic peak-valley value sequence in the time period of t = 0 - 10 ms, generate a unique fingerprint through the chaotic hashing algorithm, and obtain the third verification factor. For the third verification factor , there is
[0084] ,
[0085] In the formula, is the maximum startup voltage, is the lowest regulated voltage value, is the peak value of the second derivative of the voltage curve. Among them, the physical fingerprint feature of the integrated circuit is a hardware uniqueness identifier generated by the microscopic differences in semiconductor manufacturing processes; the third verification factor is a non-replicable hardware-level identity authentication parameter.
[0086] Perform multi-level series verification on the first verification factor, the second verification factor, and the third verification factor according to the weight distribution of the risk distribution heat map.
[0087] Specifically, set the verification process branch according to the risk level of the heat map. The forced series verification order in the high-risk area, i.e., the red area, is to to , and all factors are required to match. In the medium-risk area, i.e., the orange area, parallel verification is performed and , and any one passing triggers verification. In the low-risk area, i.e., the yellow area, only or any one passing is required. Among them, multi-level series verification is a verification logic orchestration method based on dynamic risk assessment, which reduces the execution frequency of highly trusted verification links through weight allocation and balances security and efficiency.
[0088] Exemplarily, a user uses a mobile device to access a sensitive system at a business trip location. In the system detection risk heat map, the network connection layer is marked orange, indicating medium risk, and the device physical layer is marked yellow, indicating low risk. The BSSID of the currently connected hotel Wi-Fi (00:1A:2B:XX:YY) has a Levenshtein distance of 2 / 12 from the last 10 records in the historical database, including APs of other hotels in the same city. The first verification factor is 0.83, passing the verification. The coordinates of the operator's base station are (34.0522°N, 118.2437°W), and the Haversine calculated distance from the device's GPS coordinates (34.0505°N, 118.2419°W) gives a second verification factor of 185 meters, which is lower than the threshold. According to the policy, the third factor is skipped and direct authorization for access is granted. In subsequent attack simulations, an attacker forged the same GPS coordinates but tried to log in using a different SIM card. The system triggered a secondary verification process due to the mismatch of the SIM physical fingerprint hash, i.e., the difference in the third verification factor, and finally intercepted the attack. This method innovatively increments the defense dimension by constructing a dynamic combination verification system of multiple heterogeneous verification factors. Wi-Fi historical comparison reveals device usage habits, base station-GPS spatial verification guards against location forgery, and SIM physical fingerprint breaks through the limitations of pure logical verification. The multiple factors are intelligently arranged according to risk scenarios, ensuring a smooth experience in low-risk scenarios and exposing the contradictions in advanced attacks where it is impossible to simultaneously disguise the network environment, physical location, and hardware fingerprint. Compared with traditional fixed multi-factor authentication, this method solves the penetration problem after an attacker obtains some verification elements through social engineering, and can significantly reduce the risks of man-in-the-middle attacks and device cloning, especially in mobile payment and remote office scenarios.
[0089] Optionally, the specific steps for generating the encryption token include:
[0090] Read the original feature encoding after successful biometric verification;
[0091] Specifically, after completing biometric recognition such as fingerprint or iris, the system extracts the successfully verified feature template from the decoding chip, such as extracting fingerprint ridge intersection coordinates or iris texture Fourier descriptors. The original feature encoding is a binary sequence containing the user's unique biometric feature, usually stored with a length of 256 bits. Before transmission, this encoding is converted into differential Manchester code by an analog-to-digital converter to enhance the anti-electromagnetic interference ability. Among them, the original feature encoding is the digital identity identifier output by the biometric recognition algorithm; the differential Manchester code is an encoding method that represents logic 0 / 1 through level jumps, and the preamble uses CRC-8 checksum.
[0092] Insert a millisecond-level timestamp and perform segmented hashing calculation on the original feature encoding;
[0093] Specifically, the system obtains the millisecond-level accuracy of the current time from the Beidou time service module. For example, TS = 1625000000123, which is converted into a 56-bit integer data in the format of "year-month-day-hour-minute-second-millisecond" and inserted into the 64th to 119th bytes of the original feature encoding. Then, the entire data packet is divided into 8 blocks according to the length of 32 bytes, and the SHA-3 hash calculation is performed on each block in turn:
[0094] ,
[0095] where is the hash value of the th block, is the th 32-byte data block, is a 1-byte slice of the corresponding block in the timestamp. For example, the th block takes the th bit of the millisecond value. Finally, the hash values of each block are merged into the final hash digest through the XOR operation. Among them, the millisecond-level timestamp is the global time synchronization encoding accurate to 1 / 1000 second; the segmented hash calculation is a processing method that independently hashes and then fuses the long data after segmentation, increasing the complexity of the intermediate state; TS_slice is the segmented embedding parameter of the timestamp to prevent local tampering of the hash value.
[0096] Exemplarily, assume that the original feature encoding is a 64-byte hexadecimal string "A1B2C3…", the timestamp TS = 1625000000123, and the intercepted 56-bit time encoding is "3F2A01". The first block after segmentation is "A1B2C3…31" (32 bytes), and the first is the first bit of the last byte "23" (the first two bits 00 are taken from the binary 00100011 of 0x23). After performing the SHA3-256 calculation, = "5E8F…". Similarly, other blocks are processed, and the final combined hash is "7D4A…". The segmented embedding of the timestamp slice makes the hash calculation have spatio-temporal correlation, and attackers cannot crack the hash chain by tampering with a single time field, ensuring the instant uniqueness of the token.
[0097] The local time calibration error values of each node are incorporated into the encryption calculation as hash perturbation factors to generate dynamically variable tokens.
[0098] Specifically, after receiving the time synchronization signal, the distributed nodes respectively calculate the error values between the local clock and the UTC reference time, in microseconds. For example, the error of node A is +120 μs, that of node B is -80 μs, and that of node C is +50 μs. The absolute value of the error value is converted into a 4-byte floating-point number, and the perturbation factor is generated according to the formula. For the perturbation factor , there are:
[0099] ,
[0100] Use this as the initialization vector of the AES-256 algorithm to participate in the re-encryption of the hash value, and finally generate a token:
[0101] ,
[0102] Among them, the local time calibration error value is the timing deviation between each node's atomic clock and the Beidou time reference; the hash perturbation factor is an encryption parameter generated by the non-linear combination of time errors; the dynamic variable token is a real-time change voucher affected by multiple node time parameters.
[0103] Exemplarily, assume the node time error is is +253 μs, is -142 μs, is +65 μs, then the perturbation factor . Encrypt the hash digest with 40161 as the key to generate the token "TKN = 7D4A...". If the attacker replays the token after a 1-second delay, due to the change in time error, Seed changes and the decryption fails. Dynamically perturb the encryption key through the time errors of distributed nodes, making the token valid only in a specific time window, blocking replay attacks and cross-timezone replay attacks, and enhancing the ability to resist man-in-the-middle hijacking.
[0104] Exemplarily, when a user of a certain bank APP logs in, a feature code containing the timestamp "TS = 1625001234567" is generated. After segmented hash processing, the digest "Hash = 9F86..." is obtained. The time errors of three nodes is +153 μs, is -92 μs, is +17 μs, and the perturbation factor Seed = 14365 is generated. The encrypted token is "TKN = 3E7B...". The attacker intercepts and replays the token after 1 minute. Due to the change in the node time error value, becomes +212 μs, becomes -43 μs, becomes +85 μs, and Seed then becomes 16341. After decryption, an invalid scrambled code is obtained and the attack fails. The synergistic effect of dynamic time parameters and multi-node errors makes it impossible for the attacker to crack the token generation rule through external observation, ensuring that the encryption factor changes randomly for each session and achieving zero-day vulnerability immunity.
[0105] This method realizes dynamic anti-counterfeiting protection for biometric verification through timestamp segmented embedding and distributed node time error perturbation mechanism. The millisecond-level timestamp ensures that each generated hash value has a unique timing mark, preventing pre-computation attacks; the segmented processing combined with spatio-temporal parameters enhances the collision resistance of the hash chain. Using the non-linear relationship of multi-node time errors as an encryption factor makes the token depend on real-time environmental parameters and unable to be statically replicated. This method breaks through the limitation of traditional biometric verification relying on a single static feature code, synchronously integrates physical variables such as hardware clock differences, and forms a multi-dimensional dynamic defense system. In high-risk scenarios such as mobile payment and remote authorization, it can effectively resist biometric replication, network sniffing, and replay attacks, and significantly improve the active protection ability of the security system.
[0106] Optionally, the verification steps of the distributed time synchronization node specifically include:
[0107] Comparing the absolute deviation values of the bank server timestamp, the user terminal device timestamp, and the operator gateway timestamp;
[0108] Specifically, the distributed time synchronization node receives the local timestamp data of the bank server, the user device, and the operator gateway. The bank server timestamp is synchronized to the cesium atomic clock time source through the PTP protocol of the financial private network, and the user terminal device timestamp is obtained from the device system clock and marked with microsecond-level accuracy, and the operator gateway timestamp is taken from the GPS / Beidou dual-mode timing module. Calculate the cross-node time consistency through the absolute deviation formula:
[0109] ,
[0110] In the formula, is the total time deviation of the three nodes, is the UTC time of the bank server, such as 1625000000123μs, is the local time of the user terminal, such as 1625000000150μs, is the gateway clock time, such as 1625000000130μs. When exceeds the preset time threshold, for example, 150μs, it is determined that the time is not synchronized. Among them, the absolute deviation value is the cumulative difference of different time sources, reflecting the clock synchronization accuracy of the whole network; the distributed time synchronization node is a time calibration server cluster deployed in banks, user devices, and operator networks, and maintains the unity of the time reference through the NTP / 1588 protocol.
[0111] When the absolute deviation value exceeds the preset time threshold, the session key revocation procedure is automatically triggered;
[0112] Specifically, the system preset time threshold is dynamically adjusted according to the network topology, and the initial threshold value is 150 μs. If exceeds the threshold, the security management module immediately sends a revocation instruction to the key distribution center. The revocation instruction includes the session ID, timestamp, and node signature. The key distribution center calls the national cryptographic SM2 algorithm to irreversibly revoke the current session key, and the new key needs to be re - negotiated and generated after it returns within the threshold. The key revocation process includes three - way handshakes: revocation request broadcast, node signature verification, and key status update. If any node does not respond to the revocation instruction, it automatically switches to the backup key channel. Among them, the session key revocation process is a blockchain - based key lifecycle management mechanism, and the preset time threshold is the upper tolerance limit dynamically calculated according to the network delay model; the dynamic threshold generation algorithm is an exponentially weighted moving average function fitted from historical time deviation data.
[0113] Exemplarily, assume that the bank server timestamp = 1625000000100 μs, the user device = 1625000000300 μs (maliciously tampered), and the gateway = 1625000000150 μs. Calculate . Since 400 μs exceeds the preset 150 μs threshold, the revocation process is triggered: a revocation instruction is broadcast to the three nodes. After node signature verification, the current session key is revoked, and the attacker cannot use the stolen key to continue communication. Through the dynamic detection of the time deviation of the three nodes, device time tampering behavior can be effectively identified. The automatic revocation mechanism blocks the attack link and prevents the key from being maliciously exploited within an abnormal time window.
[0114] Take the transmission delay value of the encrypted token between nodes as an additional verification parameter for session legitimacy.
[0115] Specifically, record the transmission delay data of the encrypted token from the user device to the bank server and then to the operator gateway, denoted as and in milliseconds. Use the normal distribution model to verify the delay fluctuation range. The legal delay should satisfy:
[0116] ,
[0117] where, is the average delay of the historical token to the bank server, such as 5 ms, is the standard deviation of the average delay of the historical token to the bank server, such as 0.8 ms; is the average delay to the gateway, such as 7 ms, is the standard deviation of the average latency to the gateway, such as 1.2 ms. When the actual latency exceeds the range of 3 times the standard deviation, it is determined as an abnormal transmission path and the overlay verification fails. The update period of the verification logic is 30 minutes, dynamically adapting to changes in the network environment. Among them, the transmission latency value is the time taken for a data packet to be unidirectionally transmitted between nodes; the normal distribution model is a statistical verification framework constructed based on historical latency data, used to identify sudden path hijacking or man-in-the-middle attacks.
[0118] Exemplarily, an attacker hijacks a user device and copies a legitimate token to attempt a transfer. Since the device clock is maliciously slowed down by 200 μs, resulting in = 400 μs exceeding the threshold, triggering key revocation. The attacker switches to using a proxy server to send the token, and the latency to the bank node is 12 ms, is 5 ms, is 0.8, exceeding the range of 3 times the standard deviation. Synchronously trigger a time deviation warning and a latency anomaly interception to prevent the transaction. The cross-verification in time and space forms a three-dimensional defense. An attacker cannot simultaneously forge clock synchronization and the physical network path, greatly increasing the attack cost and complexity, and ensuring the chain-like trusted verification of critical services.
[0119] This method constructs a dual protection barrier in the time and space dimensions through a dual verification mechanism of cross-node time synchronization and transmission path. The comparison of timestamps among three nodes eliminates the risk of single-point clock offset, and the dynamic threshold adapts to different network environments; the analysis of transmission latency modeling identifies illegal path injection and prevents replay attacks. The legitimacy of the encrypted token not only depends on biometrics and key strength, but also needs to meet strict time and space consistency conditions, effectively defending against complex attack scenarios such as time tampering, key replication, and proxy hijacking. In services such as cross-border payment and remote authorization, it can ensure the real-time credibility of transaction data and enhance the system's active defense ability against advanced persistent threats.
[0120] Optionally, the update method of the feature verification model includes:
[0121] Collect verification log data of legitimate users in an abnormal network environment;
[0122] Specifically, the system retrieves the verification records of users in abnormal network environments from the security audit module every day. An abnormal network environment is defined as a scenario that simultaneously meets the following conditions: the IP address jump frequency exceeds 3 times per minute, the SSL certificate validity is marked as 0 (invalid), and the GPS positioning differs from the base station location by more than 1 kilometer. The log data includes the fingerprint image hash value during biometric verification, the touch screen capacitance gradient sequence, the device three-dimensional space acceleration spectrum, and the corresponding verification result mark. The data is stored in encrypted form in distributed blockchain nodes, with the upper limit of each block capacity being 1MB, and the PBFT consensus mechanism is used to ensure the immutability of the data. Among them, the verification log data is the full-dimensional operation sequence recording the user identity verification process; the abnormal network environment is the set of network connection states that meet the preset high-risk conditions, such as cross-border proxy, fake base station and other scenarios.
[0123] Extract the correlation attenuation pattern between biometric and behavioral characteristics in the verification log data;
[0124] Specifically, the sliding window analysis method is used to calculate the correlation degree of the log data. The window span is 7 days, and the attenuation slope of the Pearson correlation coefficient between biometric characteristics (such as fingerprint matching degree) and behavioral characteristics (such as capacitance fluctuation value) is analyzed every day to construct a time series model:
[0125] ,
[0126] In the formula, is the correlation attenuation intensity on the th day, is the correlation coefficient of biometric and behavioral characteristics on that day, is the derivative of the change in the correlation coefficient of biometric and behavioral characteristics between two adjacent days, is the weight coefficient, such as 0.65, is the attenuation acceleration coefficient, such as 0.35. When is continuously in the negative value range for three consecutive days, it is determined that the attenuation pattern is established. For example, when the user logs in under a public Wi-Fi environment drops from 0.85 to 0.72, and is -0.04, substituting into the formula gives =0.65×0.72 + 0.35×(-0.04)=0.463, and continuous decline triggers pattern recognition. Among them, the correlation attenuation pattern is the decreasing trend of the correlation between biometric characteristics and dynamic behavior data over time or environment, and the sliding window analysis is used to quantify the decline rate; the Pearson correlation coefficient is a statistical indicator of the linear relationship between two variables, with a value range of [-1, 1].
[0127] Exemplarily, due to a user replacing the mobile phone, the fluctuation frequency of the capacitance gradient sequence increases, and the log data shows that for three consecutive days are 0.82, 0.75, 0.68, are calculated as -0.07 and -0.08. Take the third day = 0.65×0.68 + 0.35×(-0.08) = 0.442 - 0.028 = 0.414. Although the single-day is positive, the correlation degree continues to decline due to equipment replacement, and the system still determines it as a mild attenuation mode. Through the dynamic trend analysis within the time window, false judgments caused by single-day data mutations are avoided, and the progressive attenuation of the correlation degree caused by hardware changes is accurately captured.
[0128] Update the kernel function weight matrix of the matrix convolution calculation through an online incremental learning algorithm.
[0129] Specifically, the weights are updated using the online stochastic gradient descent method, and only the newly added log data is used to adjust the model. For the kernel function weight matrix, the update formula is:
[0130] ,
[0131] In the formula, is the weight matrix of the th iteration, is the learning rate, which can be preset to 0.001, is the gradient of the loss function with respect to the weight matrix, is 100 groups of biological behavior feature vectors extracted from the newly added logs, is the corresponding label vector, where 0 / 1 indicates whether the verification result is legal. Each update selects Mini-Batch data for local adjustment of the convolution kernel. For example, if the newly added logs indicate that a certain user uses a stylus resulting in a variation in the capacitance gradient feature, the model specifically adjusts the weights of the second-layer convolution kernel to make it pay more attention to the gyroscope acceleration feature. Among them, the online incremental learning algorithm is a model optimization method that does not require retraining with all data; the kernel function weight matrix is a set of feature extraction parameters for the convolution operation in the feature verification model, with a dimension of 3×3×64.
[0132] Exemplarily, the newly added logs contain 50 verification records of a certain user in a high-speed rail scenario: due to equipment shaking, the peak of the acceleration spectrum shifts, and the misjudgment rate of the original model rises to 12%. Extract from the data , calculate the gradient = -0.34. Let the initial weight matrix have a certain kernel weight of 0.72, and the learning rate If it is 0.001, it becomes 0.72034 after update. After 100 iterations, the response weight of this convolution kernel to the acceleration spectrum is increased by 17%, and the misjudgment rate of the model in such scenarios is reduced to less than 5%. The incremental learning mechanism can quickly optimize the model for subdivided scenarios, avoid system performance degradation caused by environmental changes, and reduce the computational cost of full-scale training at the same time.
[0133] Exemplarily, an employee of a multinational enterprise needs to frequently switch the VPN to access the system, and the original model is misjudged due to IP jumps and network delays. 30 overseas verification logs of this employee are collected, and If it drops from 0.78 to 0.63, then =-0.12, triggering the decay mode recognition. The incremental learning module uses this data to update the third-layer convolution kernel, increasing the weight of its feature of touch behavior under network delay by 22%. In subsequent verification, the correlation score of this employee in the same scenario is restored to 0.71, and the misjudgment is reduced. The dynamic update mechanism enables the model to adapt to the behavior evolution of legitimate users, avoids frequent verification failures caused by fixed thresholds, improves the fluency of the user experience while ensuring security, and is especially suitable for mobile service scenarios with high frequency and multiple environmental changes.
[0134] This method realizes the balance between security and adaptability by continuously monitoring the change of the correlation between user verification features and dynamically optimizing model parameters by combining online learning technology. Abnormal environment data collection constructs a targeted training set, the correlation decay mode recognition locates the weak links of the model, and the incremental learning ensures that the feature extraction kernel function adapts to the new scenario. This method breaks through the limitations of traditional static verification models and can still maintain high accuracy when the user behavior pattern changes or the environment mutates. The pattern changes such as changing devices, and the environment mutates such as cross-regional access, significantly reducing the false rejection rate and the risk of security vulnerabilities.
[0135] Optionally, before the output of the security verification pass instruction, it further includes:
[0136] Collect the data of the policy execution time consumption in the current verification process;
[0137] Specifically, in each security verification process, the system obtains the timestamp marks of each stage operation from the scheduling module of the verification engine, including biometric extraction time, feature code comparison time, node communication delay, etc. Record the start time and end time of each step with microsecond-level accuracy, calculate the total time consumption of a single verification process, for the total time consumption of the th verification process
[0138] ,
[0139] wherein, is the start time of the th step, is the end time of the th step, where is the verification step number, e.g., = 1 corresponds to biometric extraction. The data storage adopts a circular buffer structure to save the time-consuming sequences of the most recent 100 verifications. The historical average time consumption and the standard deviation of fluctuations are calculated through a sliding window. For the historical average time consumption , there is:
[0140] ,
[0141] In the formula, is the window sample size, , for the standard deviation of fluctuations , there is:
[0142] ,
[0143] where represents the square root operation. The strategy execution time-consuming data is the set of time performance indicators for each verification link; the sliding time window is a rolling update mechanism that only retains the most recent data; the microsecond-level precision is the one-millionth-second resolution of the timestamp.
[0144] Dynamically adjust the verification strength level of subsequent sessions according to the said time-consuming data;
[0145] Specifically, the system establishes a dynamic adjustment model based on the time-consuming mean and standard deviation. The calculation formula for the verification strength level is:
[0146] ,
[0147] In the formula, is the current verification time consumption, is the sensitivity coefficient, default = 2, is the basic strength level, with an initial value of 3, is the floor function. For example, the result of is 4. For example, if the current time consumption = 520 ms, = 500 ms, = 10 ms, then , that is, the strength is increased to level 4. The range of the verification strength level is preset to 1 to 5 levels. The higher the level, the more additional verification factors are triggered. For example, level 5 requires simultaneous verification of biometrics, SIM card fingerprint, and base station positioning. Among them, the dynamic adjustment model is a feedback regulation mechanism based on statistical process control; the verification strength level is a quantitative parameter representing the complexity of the verification strategy, and the increase in the level will increase the number of verification steps or the algorithm complexity.
[0148] Perform a gradient binding process on the adjusted verification strength level and the user credit score.
[0149] Specifically, the credit scoring module generates a credit value ranging from 0 to 1000 points based on the user's historical behavior , such as the verification success rate and the risk operation frequency in the user's historical behavior. The gradient binding function maps the credit score to a verification strength correction coefficient. For the verification strength correction coefficient , there is:
[0150] ,
[0151] In the formula, is the median credit score (set to 500), is the adjustment parameter, set to 200, is the non-linear activation function. The final actual strength level is calculated by the following formula:
[0152] ,
[0153] In the formula, is the rounding function, that is, rounding a numerical value to the nearest integer, for example . Among them, the gradient binding process realizes the inverse correlation between the credit score and the verification strength through function mapping; the user credit score is a multi-dimensional credibility quantification index based on the user's historical behavior, and the higher the score, the lower the risk.
[0154] Exemplarily, for a high-credit user, due to VPN latency during international business trips, the verification time consumption increases to 600 ms. The user's credit value , the historical average time consumption , the standard deviation of fluctuations . The verification strength level , so the verification strength level is 5, but in the gradient binding, the verification strength correction coefficient , so the actual strength level , so the actual strength level is 0, and the system only requires fingerprint recognition and exempts additional verifications such as base station positioning. Under the same time consumption, for a low-credit user with a credit value , the verification strength correction coefficient , so the actual strength level levels, and the SIM card chip verification is forcibly superimposed. Credit gradient binding can intelligently distinguish between real users and potential attackers. Even in the same network environment, high-credit users can still enjoy fast verification, while the abnormal behavior of low-credit users will trigger strict policies, effectively balancing security and efficiency and reducing the interference of misoperations by legitimate users.
[0155] Optionally, the following pre-judgment steps are performed simultaneously when the biometric recognition request is triggered:
[0156] Detect whether the battery temperature of the terminal device is in an abnormally rising range;
[0157] Specifically, the system reads the temperature sensor data in real time through the I2C interface of the battery management chip and records the temperature rise gradient within a unit time. The temperature value sequence is obtained at a sampling frequency of 10 times per second, and the temperature change rate is calculated. When the temperature change rate of 5 consecutive sampling points is greater than or equal to 2 °C / second, it is determined as the abnormally rising range. For example, in a certain detection, the temperature sequence is 32 °C, 34.5 °C, 37.8 °C, 41.2 °C, 45 °C, and the corresponding temperature change rates are 2.5 °C, 3.3 °C, 3.4 °C, 3.8 °C, respectively, meeting the condition of exceeding the threshold four times in a row. Among them, the abnormally rising range of the battery temperature is a dangerous state where the battery heating rate exceeds the safety threshold; the temperature rise gradient is the increment value of the battery temperature within a unit time, reflecting the risk of battery thermal runaway.
[0158] When it is detected that the battery temperature change rate exceeds the preset critical value, the wireless communication module is temporarily turned off and the device authenticity diagnosis program is started.
[0159] Specifically, the preset critical value is 3 °C / second, and the preset critical value is an adjustable parameter. When the trigger condition is established, a GPIO interrupt signal is sent to the wireless communication controller to forcibly turn off the Wi-Fi, Bluetooth, and mobile data modules. At the same time, the device hardware feature verification algorithm is called, that is, the consistency between the IMEI number hash value and the preset whitelist is verified, the silicon wafer fingerprint hash code of the NAND flash chip is detected, and the resonance frequency of the motherboard capacitor array is compared. The execution logic of the diagnosis program is that if , the device is legal, otherwise it is determined as a tampered device. Wherein is the difference flag of the th detection result, 0 means normal, and 1 means abnormal. Among them, the device authenticity diagnosis program is a detection process that verifies the physical integrity of the device through the unique hardware features; the silicon wafer fingerprint hash code is a hardware-level identifier generated by the microstructure differences in the semiconductor manufacturing process. Through the dual checks of temperature anomalies and hardware fingerprints, identify device tampering caused by the use of inferior parts or physical attacks, and block malicious operations through hardware vulnerabilities.
[0160] Exemplarily, an attacker uses a hot air gun to heat the device battery area to interfere with the biosensor. The system detects that the temperature rises from 25 °C to 52 °C in only 8 seconds, and the change rate is 3.375 °C / second. Immediately turn off the wireless communication and start the diagnosis. It is detected that the IMEI hash does not match the pre-stored value, that is and the NAND flash silicon wafer fingerprint is abnormal, that is , the device is thus determined to be illegal. Clear the memory sensitive data and enter the hardware locked state to prevent attackers from extracting the key. Combine dynamic temperature monitoring with static hardware fingerprint verification to accurately identify physical layer attack behaviors. Even if the attacker bypasses the software protection, they cannot break through the hardware-level security defense line, ensuring the integrity of critical data in extreme attack scenarios.
[0161] Based on the same inventive concept, the present invention also provides a network security verification system for a security system, the system comprising:
[0162] A biometric collection module, configured to obtain a biometric recognition request triggered by a user on a terminal device, the biometric recognition request including an encrypted transmission instruction for a fingerprint grayscale image and iris texture data of the user;
[0163] A behavior trajectory capture module, configured to synchronously collect dynamic behavior trajectory data of the user when initiating the biometric recognition request, and generate a behavior feature code;
[0164] A correlation calculation module, configured to input the physiological feature data in the biometric recognition request and the behavior feature code into a pre-trained feature verification model for matrix convolution calculation, and output a biometric behavior correlation index, the physiological feature data including a fingerprint grayscale image and iris texture data;
[0165] A policy trigger module, configured to trigger a dynamic verification policy adjustment instruction when the biometric behavior correlation index is lower than a first preset threshold;
[0166] A verification policy generation module, configured to obtain device parameters based on the dynamic verification policy adjustment instruction and analyze the abnormal correlation of each parameter, and generate a multi-dimensional verification overlay policy;
[0167] An encryption token generation module, configured to execute at least two verification operations in the multi-dimensional verification overlay policy, and input the verification results into a distributed time synchronization node to generate an encryption token;
[0168] A security verification module, configured to output a security verification pass instruction when the synchronization matching degree of the encryption token between different nodes exceeds a second preset threshold.
[0169] It should be noted that the electrical connections between the above-mentioned various units do not necessarily represent direct connections of the lines. Indirect connection methods, as long as the purpose of the present invention is achieved, can be applied to the embodiments of the present invention. The above are only exemplary embodiments of the present invention and cannot be used to limit the scope of the present invention.
[0170] That is, any equivalent changes and modifications made in accordance with the teachings of the present invention still fall within the scope covered by the present invention. This application is intended to cover any variations, uses, or adaptations of the present invention, which follow the general principles of the present invention and include the common general knowledge or conventional technical means in the technical field not recorded in the present invention.
Claims
1. A network security verification method for a security system, characterized in that, The method includes: Obtaining a biometric recognition request triggered by a user on a terminal device, where the biometric recognition request includes the user's fingerprint grayscale image and an encrypted transmission instruction for iris texture data; Synchronously collecting dynamic behavior trajectory data of the user when initiating the biometric recognition request to generate a behavior feature code; where it includes: real-time monitoring of the capacitance change gradient sequence of the user's touch screen operation; collecting the three-dimensional space acceleration fluctuation map of the device through a gyroscope sensor; performing time-frequency domain fusion processing on the capacitance change gradient sequence and the acceleration fluctuation map to generate a dynamic behavior feature vector; after normalizing the dynamic behavior feature vector, obtaining a behavior feature code; Inputting the physiological feature data in the biometric recognition request and the behavior feature code into a pre-trained feature verification model for matrix convolution calculation, and outputting a biological behavior correlation index, where the physiological feature data includes a fingerprint grayscale image and iris texture data; When the biological behavior correlation index is lower than a first preset threshold, triggering a dynamic verification policy adjustment instruction; Based on the dynamic verification policy adjustment instruction, obtaining device parameters and analyzing the abnormal correlation of each parameter to generate a multi-dimensional verification overlay policy; where it includes: periodically obtaining a set of network environment parameters including IP address jump strength, SSL certificate validity mark, and SIM card information matching degree; performing topological analysis on the abnormal correlation of at least three parameters in the set of network environment parameters to generate a risk distribution heat map; determining additional verification methods to be enhanced according to the risk area of the risk distribution heat map to generate a multi-dimensional verification overlay policy; Performing at least two verification operations in the multi-dimensional verification overlay policy and inputting the verification results into a distributed time synchronization node to generate an encrypted token; where it includes: reading the original feature code after biometric verification passes; inserting a millisecond-level time stamp and performing segmented hash calculation on the original feature code; taking the local time calibration error value of each node as a hash perturbation factor and incorporating it into the encryption calculation to generate a dynamically variable token; When the synchronization matching degree of the encrypted token between different nodes exceeds a second preset threshold, outputting a security verification passed instruction; Among them, the multi-dimensional verification overlay policy includes: Generating a first verification factor based on comparison with the historical database of the Wi-Fi BSSID currently connected to the device; Generating a second verification factor through the spatial difference degree calculation of the operator base station location and GPS positioning information; Generating a third verification factor by combining the physical fingerprint features of the SIM card integrated circuit; Performing multi-level cascade verification on the first verification factor, the second verification factor, and the third verification factor according to the weight distribution of the risk distribution heat map; Among them, the capacitance change gradient sequence is a set of mapping relationships between the capacitance value change rate of each touch point per second and the spatial coordinates during a touch operation; the acceleration fluctuation map is a motion feature matrix composed of the instantaneous acceleration and standard deviation of the device in the X / Y / Z axis directions; the time-frequency domain fusion processing is an analysis method of converting time series data into frequency domain energy distribution and superimposing it with the time domain trend.
2. The network security verification method for a security system according to claim 1, characterized in that, The verification steps of the distributed time synchronization node specifically include: Compare the absolute deviation values of the bank server timestamp, the user terminal device timestamp, and the operator gateway timestamp; When the absolute deviation value exceeds the preset time threshold, automatically trigger the session key revocation procedure; Use the transmission delay value of the encryption token between nodes as an additional verification parameter for session legitimacy.
3. The network security verification method for a security system according to claim 1, characterized in that, The update method of the feature verification model includes: Collect verification log data of legitimate users in an abnormal network environment; Extract the correlation attenuation pattern between biometric features and behavioral features in the verification log data; Update the kernel function weight matrix of the matrix convolution calculation through an online incremental learning algorithm.
4. The network security verification method for a security system according to claim 1, characterized in that, Before the output of the security verification pass instruction, it also includes: Collect the policy execution time-consuming data in the current verification process; Dynamically adjust the verification intensity level of subsequent sessions according to the time-consuming data; Perform gradient binding processing on the adjusted verification intensity level and the user credit score.
5. The network security verification method for a security system according to claim 1, characterized in that, When the biometric recognition request is triggered, the following pre-judgment steps are executed: Detect whether the battery temperature of the terminal device is in an abnormally rising range; When it is detected that the battery temperature change rate exceeds the preset critical value, temporarily turn off the wireless communication module and start the device authenticity diagnosis program.
6. A cybersecurity verification system for a security system, which is applied to the cybersecurity verification method for a security system according to any one of claims 1-5, characterized in that, The system includes: A biometric collection module, which is used to obtain the biometric recognition request triggered by the user on the terminal device. The biometric recognition request includes the encrypted transmission instructions of the user's fingerprint grayscale image and iris texture data; A behavior trajectory capture module, which is used to synchronously collect the dynamic behavior trajectory data of the user when the biometric recognition request is initiated, and generate a behavior feature code; A correlation calculation module, which is used to input the physiological feature data in the biometric recognition request and the behavior feature code into a pre-trained feature verification model for matrix convolution calculation, and output a biometric behavior correlation index. The physiological feature data includes fingerprint grayscale images and iris texture data; A policy trigger module, which is used to trigger a dynamic verification policy adjustment instruction when the biometric behavior correlation index is lower than the first preset threshold; A verification policy generation module, which is used to obtain device parameters based on the dynamic verification policy adjustment instruction and analyze the abnormal correlation of each parameter to generate a multi-dimensional verification superposition policy; An encryption token generation module, which is used to execute at least two verification operations in the multi-dimensional verification superposition policy and input the verification results into a distributed time synchronization node to generate an encryption token; A security verification module, which is used to output a security verification pass instruction when the synchronization matching degree of the encryption token between different nodes exceeds the second preset threshold.
Citation Information
Patent Citations
Intelligent access control management method and system based on multi-mode identification and Internet of Things technology
CN118968665A
Multi-factor network security authentication method and system based on SDN (Software Defined Network)
CN119520064A