Secondary login verification method and system

By introducing user security level mechanism and multi-level security level improvement mechanism, dynamically adjusting the verification code verification intensity, solving the problems of brute-force cracking and automated cracking of attacks faced by traditional login methods, achieving efficient security protection and excellent user experience.

CN120012058APending Publication Date: 2025-05-16ZHUHAI GOTECH INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411939243.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Traditional login methods face severe security challenges in brute-force cracking attacks, and traditional verification code technology is difficult to effectively resist automated cracking attacks, and affects the user experience.

Method used

By introducing a user security level mechanism, the security level is dynamically adjusted according to the user's login behavior and habits, and a multi-level security level improvement mechanism is adopted to provide verification code verification of different strengths to ensure that malicious attacks are effectively prevented without affecting the normal user experience.

Benefits of technology

It has achieved significant improvement in system security without increasing operational costs and affecting user experience, effectively preventing brute-force cracking and automated attacks, and reducing the overall security risks of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012058A_ABST
    Figure CN120012058A_ABST
Patent Text Reader

Abstract

The invention provides a secondary login verification method and system, and the method comprises the steps: detecting the ID or access IP of a user when the user attempts to log in, and carrying out the preliminary verification of the user according to a user grade verification rule; performing behavior analysis on the user to identify an abnormal operation, adjusting the security level of the user according to an analysis result, and defining a plurality of rule timers and a multi-level security level improvement mechanism; automatically adjusting the safety level of the user according to the result of the behavior analysis, and implementing safety verification with different intensities on the user according to the adjusted safety level; for the user whose abnormal behavior is reduced or the behavior performance is normal, the security level is automatically reduced according to a preset time interval; when the user logs in again, the verification code with the corresponding strength is returned for secondary verification according to the current security level of the user. According to the invention, different users and hostile attack users can be distinguished, and hostile attacks can be effectively prevented on the premise of not influencing the login of common users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer network security technology, and in particular to a secondary login verification method and system for preventing the use of tools to maliciously and violently crack a registered user account password. Background Art

[0002] In computer software systems, the login mechanism, as the core link of permission management, plays a vital role in ensuring system security and preventing unauthorized access. Users verify their identities to the system by submitting authentication information such as username and password, and then obtain the permission to access and use system resources. This process is essentially an authentication mechanism that aims to ensure that only legitimate users can enter the system.

[0003] However, with the continuous development of network technology and the increasing sophistication of hacker attack methods, traditional login methods are facing severe security challenges. In particular, brute force attacks using specific programs attempt to crack system login passwords by exhaustively enumerating a large number of user name and password combinations, posing a serious threat to system security.

[0004] In order to defend against such attacks, the industry generally adopts verification code technology. As a human-computer interaction test method, verification code shows users a piece of information that is difficult for computer programs to automatically recognize (such as images, text, numbers or their combination), and requires users to enter or select the correct answer, thereby determining whether the operation request comes from a human user. The introduction of verification codes effectively increases the difficulty of automated cracking by attackers and provides an important line of defense for system security.

[0005] However, traditional verification code technology also has many shortcomings. On the one hand, in order to increase the difficulty of cracking, the design of verification codes tends to be complex, which poses a greater challenge to computer programs, but also reduces the accuracy of manual recognition. When users are faced with verification codes that are too complex, distorted, or lack contrast, they often need to refresh multiple times to correctly recognize them, which not only increases the difficulty of users' login, but also damages the user experience.

[0006] On the other hand, the traditional verification code recognition method is relatively fixed. Attackers can collect a large number of verification code samples and use machine learning and other technologies to train the recognition model to gradually improve the accuracy of automatic recognition. Once the model is trained, the attacker can bypass the protection of the verification code and conduct large-scale brute force attacks on the system. Traditional technology cannot handle malicious login and password cracking methods well. The general method is to increase the difficulty of the verification code for the first login, making it more difficult to crack the verification code by image recognition and other methods, but this will also affect the login experience of ordinary users.

[0007] Therefore, a new type of verification code technology is urgently needed, which can effectively resist automated cracking attacks while ensuring the accuracy of manual recognition and user experience. This technology needs to be dynamic, difficult to model, and highly customizable to adapt to the ever-changing network security environment and user needs. Summary of the invention

[0008] In order to solve the problems existing in the prior art, the present invention provides a secondary login verification method and system. The purpose of this method and system is to divide the login difficulty of users with different security levels according to the user's login behavior and login habits, so as to distinguish different users and users who attack maliciously, and effectively prevent malicious attacks without affecting the login of ordinary users.

[0009] The present invention achieves the above-mentioned purpose through the following technical solutions:

[0010] A secondary login verification method, comprising:

[0011] When a user attempts to log in, the user's ID or access IP is detected, and the user is initially verified according to the preset user level verification rules;

[0012] If the preliminary verification result is that the user verification level is Level 1, the user is allowed to log in normally, and the user's login information and all operations after the user logs in are recorded in the log module;

[0013] Read the log data in the log module regularly, analyze the user's behavior to identify abnormal operations; dynamically adjust the user's security level based on the analysis results, and define multiple rule timers and multi-level security level improvement mechanisms to analyze logs at different frequencies;

[0014] Automatically adjust the user's security level based on the results of behavioral analysis, and implement different levels of security checks on the user based on the adjusted security level; automatically lower the security level of users whose abnormal behavior has decreased or whose behavior is normal at preset time intervals;

[0015] When the user logs in again, a verification code of corresponding strength is returned for secondary verification based on the user's current security level;

[0016] Among them, for any abnormal users or IPs detected, a higher level of security verification will be immediately implemented when the user logs in again.

[0017] According to a secondary login verification method provided by the present invention, the preset user level verification rules are divided into five security levels, and verification codes of different complexity are assigned to each security level, specifically including:

[0018] Level 1: For ordinary users, that is, users with no abnormal behavior, they use the normal verification code of the website for login verification, and no secondary verification is required;

[0019] Level 2: When a user enters the wrong login password multiple times, or uses a different IP address than usual, a secondary login verification is enabled. The verification code used at this time is the second most difficult verification mode.

[0020] Level 3: Through user access behavior analysis, if abnormal user operation behavior is found, and the user has passed the Level 2 login verification, the third difficulty verification mode will be enabled;

[0021] Level 4: If the user has passed the Level 3 login verification, but his / her behavior is still abnormal, the Block IP / ID X hours mode is enabled, which means that a certain IP or user ID of the user is denied access to the system within X hours.

[0022] Level 5: For users who have triggered Level 4 interception operations multiple times, their user IDs or IP addresses are added to the blacklist, permanently or long-term prohibiting them from accessing the system.

[0023] According to a secondary login verification method provided by the present invention, when an attacker registers for the first time and attempts to log in, the attacker is treated as a normal user without secondary verification and is allowed to access normally.

[0024] If the attacker enters the wrong account and password multiple times on the login page, the security level will be raised to Level 2 and the secondary verification mechanism will be triggered. The verification code used at this time is the second difficulty verification mode;

[0025] If it is detected that an attacker uses image recognition tools or other automated means to try to identify and crack the verification code composed of a combination of numbers and letters, indicating that they may be performing brute force or automated attacks, the security level will be immediately raised to Level 3, and the third difficulty verification mode will be enabled;

[0026] If the attacker continues to attack under Level 3 verification, the security measures will be further upgraded to Level 4 to restrict their access rights;

[0027] If an attacker triggers Level 4 restrictions multiple times, or their behavior is judged to be highly malicious and continuous, the most stringent security measures will be implemented, that is, their user ID or IP address will be blacklisted and their access to the system will be prohibited according to Level 5 standards.

[0028] According to a secondary login verification method provided by the present invention, the definition of multiple rule timers and a multi-level security level enhancement mechanism specifically includes:

[0029] Preset multiple behavior analysis rules and configure corresponding timers for each rule;

[0030] The behavior analysis module periodically obtains login log data within a specified time period from the MySQL database according to the timer setting; for each log record, it groups by user ID and counts the number of incorrect account and password inputs by each user within the time period or the number of incorrect verification code inputs under a specific security level;

[0031] If the behavior analysis module finds that a user enters incorrect account and password more than 5 times within 5 minutes, the user's security level will be automatically upgraded from Level 1 to Level 2, and the user will be required to enter the corresponding Level 2 verification code to unlock the login;

[0032] If further analysis finds that a user enters the Level 2 verification code incorrectly more than 5 times within 10 minutes, the user's security level will be immediately raised from Level 2 to Level 3, and the third level of difficulty verification mode will be enabled;

[0033] The behavior analysis module continuously monitors the user's login behavior and verification code input, and dynamically adjusts the user's security level according to preset rules.

[0034] According to a secondary login verification method provided by the present invention, a user session management mechanism based on multi-IP abnormal behavior detection is also implemented, and the specific implementation steps include:

[0035] The integrated behavior detection module and behavior analysis module are used to monitor and analyze the user's login and operation behavior in real time. When it is detected that the same user performs operations on different IP addresses at the same time or alternately within a short period of time, it is regarded as abnormal behavior and the security response mechanism is immediately triggered. In response, the user is forced to exit all current sessions and is required to re-login to ensure that the account is secure and has not been illegally exploited.

[0036] The behavior analysis module analyzes the user's operation logs regularly or in real time according to preset rules and algorithms to evaluate the safety of their behavior. If the user behavior analysis results show that abnormal operations have decreased and no security alarms have been triggered for a period of time, the security level downgrade process will be automatically initiated to gradually reduce the user's security level to the level corresponding to its normal state.

[0037] When a user is forced to log out due to abnormal behavior of multiple IP addresses and is required to log in again, a notification is sent to the user to explain the reason and provide instructions for logging in again.

[0038] According to a secondary login verification method provided by the present invention, a dynamic secondary verification strength adjustment mechanism based on the user security level and login time interval is also implemented, and the specific implementation steps include:

[0039] Maintain a user security level database to record each user's current security level information; when user A attempts to log in, first query his security level; record the time of the user's last successful login, and calculate the time interval between the last successful login attempt and the current login attempt. This time interval will be used to determine the strength of the secondary verification;

[0040] According to the security level and time interval of user A, a secondary verification method of corresponding strength is dynamically selected; if the security level of user A is higher or the time interval is longer, a higher strength verification method is selected for verification;

[0041] When user A correctly enters the verification code required for the secondary verification, its validity is verified and the user is allowed to successfully log in to the system. At the same time, the user's security level and time interval records are updated to provide a basis for adjusting the verification strength at the next login;

[0042] Continuously monitor the user's login behavior and verification results, and dynamically adjust the user's security level based on preset rules and algorithms; if the user successfully passes the verification for multiple consecutive times without triggering a security alarm, gradually lower their security level; conversely, if the user frequently triggers verification failures or has other abnormal behaviors, raise their security level.

[0043] According to a secondary login verification method provided by the present invention, a behavior detection module is used to monitor the user's behavior data in real time, and a behavior analysis module is used to perform behavior analysis on the behavior data, and dynamically adjust the verification strategy according to the analysis results; a data exchange channel is established between the behavior detection module and the behavior analysis module; during the user login process, the behavior detection module first monitors the user's behavior in real time, and when the behavior detection module captures the user's behavior, the relevant data is sent to the behavior analysis module for processing; once abnormal behavior is found, the security response mechanism is immediately triggered, and the behavior analysis module is notified to perform further analysis; the behavior analysis module evaluates the user's security level and potential risks based on the received behavior data, and dynamically adjusts the verification strategy according to the analysis results; at the same time, the behavior analysis module promptly feeds back the user's security level, abnormal behavior warning information and potential risks obtained through the analysis to the behavior detection module, so that it can adjust the monitoring strategy according to the latest situation.

[0044] According to a secondary login verification method provided by the present invention, the following steps are further performed:

[0045] An intelligent learning engine is integrated in the behavior detection module and the behavior analysis module to continuously learn and analyze user behavior data and build a user behavior profile. The intelligent learning engine dynamically updates the rule base and algorithm model in the behavior detection module and the behavior analysis module based on the learned user behavior patterns and system security requirements. The intelligent learning engine is also used to monitor the performance indicators of the behavior detection module and the behavior analysis module.

[0046] A secondary login verification system, which is applied to the above secondary login verification method, comprises:

[0047] User login module, used to receive user login request;

[0048] Behavior detection module, used to monitor user behavior data in real time;

[0049] Behavior analysis module, used to detect user login behavior and classify security levels;

[0050] A verification code generation module is used to generate a verification code of corresponding difficulty according to the user's security level;

[0051] Verification module, used to verify whether the verification code entered by the user is correct;

[0052] The log module is used to record user login information and behavior logs.

[0053] It can be seen that compared with the prior art, the present invention has the following beneficial effects:

[0054] 1. Reduce operating costs: In the traditional SMS secondary verification method, the service provider needs to bear the cost of sending each SMS. In the face of malicious attacks or frequent login attempts, the SMS fee will increase sharply, causing unnecessary economic burden. The present invention implements a SMS verification-free strategy for low-risk users through user security level assessment, significantly reducing the amount of SMS sent, thereby greatly reducing the operating costs of the enterprise.

[0055] 2. Improve international adaptability: For service providers operating across borders, the traditional SMS verification method requires docking with SMS service providers in various countries, which not only has a complicated development process but also high maintenance costs. The present invention does not rely on SMS services, completely avoiding the complexity and high costs of international SMS sending, and improving the global deployment efficiency and economy of services.

[0056] 3. Enhance user experience: The process of receiving and inputting SMS verification codes often brings inconvenience to users, especially in an environment with network delay or poor signal. The present invention dynamically adjusts the security level according to user behavior. For users with a higher security level, they can complete the login without additionally inputting SMS verification codes, which greatly simplifies the login process and improves the user experience.

[0057] 4. Improved security: Compared with static SMS verification codes, the user security level mechanism of the present invention comprehensively considers multiple factors such as user behavior and login environment, dynamically adjusts the verification strategy, and is more difficult to be simulated or cracked by malicious programs. This intelligent security strategy effectively prevents security threats such as brute force login cracking and enhances the overall security protection capability of the system.

[0058] To sum up, the present invention introduces a user security level mechanism to replace the traditional SMS secondary login verification, which not only effectively reduces the operating costs, but also significantly enhances the user experience and system security, achieves a dual improvement in economic benefits and security protection, and has broad market application prospects and significant social value.

[0059] The present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] Figure 1 It is a flow chart of an embodiment of a secondary login verification method of the present invention.

[0061] Figure 2 It is a schematic diagram of a user level verification rule in an embodiment of a secondary login verification method of the present invention.

[0062] Figure 3 It is a schematic diagram of an embodiment of a secondary login verification system of the present invention. DETAILED DESCRIPTION

[0063] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0064] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0065] See also Figure 1 and Figure 2 This embodiment provides a secondary login verification method, including the following steps:

[0066] Step S1, when a user attempts to log in, the user's ID or access IP is detected, and the user is preliminarily verified according to the preset user level verification rules;

[0067] Step S2: If the preliminary verification result shows that the user verification level is Level 1, the user is allowed to log in normally, and the user's login information and all operations after the user logs in are recorded in the log module;

[0068] Step S3, regularly read the log data in the log module, analyze the user's behavior to identify abnormal operations; dynamically adjust the user's security level according to the analysis results, and define multiple rule timers and multi-level security level improvement mechanisms to analyze the logs at different frequencies;

[0069] Step S4, automatically adjusting the user's security level according to the results of the behavior analysis, and implementing different levels of security checks on the user according to the adjusted security level; for users whose abnormal behavior has decreased or whose behavior is normal, automatically lowering their security level according to a preset time interval;

[0070] Step S5: When the user logs in again, a verification code of corresponding strength is returned for secondary verification according to the user's current security level.

[0071] For abnormal users or IP addresses detected, a higher level of security verification will be immediately implemented when the user logs in again. Specifically, when an abnormal user or access IP logs in again, for example, if the current security level of user A is Level 2, a Level 2 level verification code will be returned first, that is, a longer string verification code for the customer to input and verify. If the input is correct, the user can successfully log in to the system. The user's login will return the strength of the secondary verification according to the security level time.

[0072] Therefore, this embodiment effectively intercepts abnormal access through the above-mentioned dynamic adjustment of user security level and verification mechanism, thereby protecting the security of user accounts.

[0073] In this embodiment, the preset user level verification rules are divided into five security levels, and verification codes of different complexity are assigned to each security level, specifically including:

[0074] Level 1: For ordinary users, that is, users with no abnormal behavior, they use the normal verification code of the website for login verification, and no secondary verification is required.

[0075] Level 2: When a user enters the wrong login password multiple times, or uses an IP address that is different from the usual login IP address, a secondary login verification is enabled. The verification code used at this time is the second level of difficulty verification mode.

[0076] Level 3: Through user access behavior analysis, if abnormal user operation behavior is found, and the user has passed the Level 2 login verification, the third difficulty verification mode will be turned on, including but not limited to the use of reflection watermark verification code, voice verification code, black dot verification code, drag verification code, angle verification code and mathematical formula calculation verification code and other verification codes are randomly returned.

[0077] Level 4: If the user has passed the Level 3 login verification but his / her behavior is still abnormal, the Block IP / ID X hours mode is enabled, which means that a certain IP or user ID of the user is denied access to the system within X hours.

[0078] Level 5: For users who have triggered Level 4 interception operations multiple times, their user IDs or IP addresses are added to the blacklist, permanently or long-term prohibiting them from accessing the system.

[0079] Through the above-mentioned five security levels and the setting of the corresponding verification code difficulty, this embodiment can more accurately implement security verification of corresponding strength according to the risk level of user behavior, thereby effectively improving the defense capabilities against abnormal access and potential attacks without affecting the normal user experience.

[0080] In this embodiment, when the system logs in, the user is generally verified to have the right to enter the system through the three pieces of information: user name, password, and verification code. The secondary verification difficulty can be divided into five security levels by recording the user ID and IP, and verification codes of different complexity are used at different levels. For example, when an attacker registers for the first time and tries to log in, it is processed according to the standard of ordinary users, without secondary verification, and is allowed to access normally; if the attacker enters the account and password incorrectly for many times on the login page, its security level is raised to Level 2, and the secondary verification mechanism is triggered. At this time, the verification code difficulty used is the second difficulty verification mode, and a secondary verification code with a longer length of characters, such as 8 digits (the length of ordinary login is 4 digits) can be popped up for him to enter, and he can log in again only if the input is correct.

[0081] If it is detected that the attacker uses image recognition tools or other automated means to try to identify and crack the verification code composed of a combination of numbers and letters, indicating that he may be performing brute force or automated attacks, the security level will be immediately raised to Level 3, and the third difficulty verification mode will be turned on. The verification code of Level 3 is more difficult to recognize than the ordinary string verification code, which can prevent multiple attacks.

[0082] If the attacker continues to attack under Level 3 verification, the security measures will be further upgraded to Level 4 to restrict their access rights. If the attacker triggers the Level 4 restriction measures multiple times, or their behavior is judged to be highly malicious and continuous, the most stringent security measures will be implemented, that is, their user ID or IP address will be added to the blacklist and their access to the system will be prohibited according to the Level 5 standards.

[0083] In this embodiment, multiple rule timers and a multi-level security level enhancement mechanism are defined, specifically including:

[0084] Preset multiple behavior analysis rules and configure corresponding timers for each rule. For example, define the first rule as "The number of incorrect login account password input exceeds 5 times within 5 minutes", and set the timer to perform analysis every 5 minutes; define the second rule as "The number of incorrect Level 2 verification code input exceeds 5 times within 10 minutes", and set the timer to perform analysis every 10 minutes.

[0085] The behavior analysis module periodically obtains login log data within a specified time period from the MySQL database according to the timer setting; for each log record, it is grouped by user ID, and the number of incorrect account and password input errors or the number of incorrect verification code input errors under a specific security level for each user within the time period are counted.

[0086] If the behavior analysis module finds that a user has entered the wrong account and password more than 5 times within 5 minutes, the user's security level will be automatically raised from Level 1 to Level 2, and the user will be required to enter the corresponding Level 2 verification code to unlock the login.

[0087] If further analysis finds that a user enters the Level 2 verification code incorrectly more than 5 times within 10 minutes, the user's security level will be immediately raised from Level 2 to Level 3, and the third difficulty verification mode will be enabled.

[0088] The behavior analysis module continuously monitors the user's login behavior and verification code input, dynamically adjusts the user's security level according to preset rules, and takes more stringent defense measures when necessary, such as restricting access, temporarily blocking accounts or IP addresses, etc., to ensure system security.

[0089] Specifically, the behavior analysis module will periodically read the log data stored in the log module, analyze and discover abnormal behaviors, such as multiple login attempts in a short period of time, or the access IP does not belong to the common login IP range, or some brute force cracking attempts after logging into the system. The behavior analysis module performs statistical analysis based on the collected data and changes the user's security level. Behavior analysis can define multiple rule timers to execute analysis logs. For example, the system logs are stored in the Mysql database. Define a rule that the number of incorrect login account and password input exceeds 5 times within 5 minutes. The behavior analysis module will go to the database every 5 minutes to obtain the log data of logins in this time period, group them by user ID, and count the number of errors. If the number of incorrect inputs exceeds 5 times, the user's security level will be prompted from Level 1 to Level 2, and the user needs to enter the correct verification code of this level to unlock the login. Define a rule that the number of incorrect Level 2 verification codes entered exceeds 5 times in 10 minutes. The behavior analysis module collects logs of logins every 10 minutes. If user A enters the wrong verification code for Level 2 more than 5 times, the security verification level of user A is raised from Level 2 to Level 3, and a watermark verification code, voice verification code, black dot verification code, drag verification code, angle verification code, and mathematical formula verification code are randomly returned to the user. The user can continue to log in only if the input is correct. The behavior of attackers is varied, and the behavior analysis rules need to analyze the data collected by the log module and define specific behavior detection rules.

[0090] Of course, the behavior detection module will not only check during login, but also define detection rules during the use of the system. For example, in a payment system, if a user enters the wrong payment password multiple times, this behavior will be detected and a secondary verification code will pop up on the page, requiring the user to enter the correct code before continuing the operation.

[0091] In this embodiment, a user session management mechanism based on multi-IP abnormal behavior detection is also implemented, and the specific implementation steps include:

[0092] The integrated behavior detection module and behavior analysis module are used to monitor and analyze the user's login and operation behavior in real time. When it is detected that the same user performs operations on different IP addresses at the same time or alternately within a short period of time, it is regarded as abnormal behavior and the security response mechanism is immediately triggered. In response, the user is forced to exit all current sessions and is required to re-login to ensure that the account is secure and has not been illegally exploited.

[0093] The behavior analysis module analyzes the user's operation log regularly or in real time according to preset rules and algorithms to evaluate the security of their behavior. These rules include but are not limited to login frequency, operation habits, geographic location changes, etc., to comprehensively judge the normality of user behavior. If the user behavior analysis results show that abnormal operations have decreased and have continued for a period of time (such as no security alarms have been triggered for X consecutive days / hours), the security level downgrade process will be automatically initiated to gradually reduce the user's security level to the level corresponding to its normal state.

[0094] When a user is forced to log out due to abnormal behavior of multiple IPs and is required to log in again, a notification will be sent to the user to explain the reason and provide instructions for logging in again. At the same time, users are advised to check their account security settings, such as changing passwords, enabling two-factor authentication, etc., to enhance account security.

[0095] In this embodiment, a dynamic secondary verification strength adjustment mechanism based on the user security level and login time interval is also implemented, and the specific implementation steps include:

[0096] Maintain a user security level database to record each user's current security level information; when user A attempts to log in, first query his security level, such as Level 2. Record the time of the user's last successful login and calculate the time interval between the last successful login attempt and the current login attempt. This time interval will be used to determine the strength of the secondary verification.

[0097] According to the security level of user A (such as Level 2) and the time interval, a secondary verification method of corresponding strength is dynamically selected; if the security level of user A is higher or the time interval is longer, a higher strength verification method is selected for verification. For example, for a Level 2 user, if the time interval is within the preset threshold (such as within 24 hours), a longer string verification code is returned for secondary verification, requiring the user to enter it to verify his identity.

[0098] When user A correctly enters the verification code required for the secondary verification, its validity is verified and the user is allowed to successfully log in to the system; at the same time, the user's security level and time interval records are updated to provide a basis for adjusting the verification strength at the next login.

[0099] Continuously monitor the user's login behavior and verification results, and dynamically adjust the user's security level based on preset rules and algorithms; if the user successfully passes the verification for multiple consecutive times without triggering a security alarm, gradually lower their security level; conversely, if the user frequently triggers verification failures or has other abnormal behaviors, raise their security level.

[0100] For example, if the behavior detection module detects that a user has performed different operations on two different IP addresses, the user will be logged out of the system and asked to log in again. The behavior analysis module will periodically calculate the user's operation behavior based on the defined rules to improve the user's secure login. If the number of abnormal operations decreases, the level will be slowly lowered. For example, the current security level of user A is Level 3. During the operation of the system on that day, no abnormal operations were detected, and the operation behavior was consistent with normal user use. At 00:00 the next day, the security level of user A will be downgraded from Level 3 to Level 2. If the behavior is normal within a week, it will be downgraded from Level 2 to Level 1. The time interval for reducing the security level can be flexibly adjusted as needed.

[0101] In this embodiment, the behavior detection module and the behavior analysis module are seamlessly integrated into the login verification process, such as the user login module, as important components of the system. The behavior detection module is used to monitor the user's behavior data in real time, and the behavior analysis module is used to analyze the behavior data and dynamically adjust the verification strategy according to the analysis results; a data exchange channel is established between the behavior detection module and the behavior analysis module; during the user login process, the behavior detection module first monitors the user's behavior in real time, and when the behavior detection module captures the user's behavior, it sends the relevant data to the behavior analysis module for processing; once abnormal behavior is found (such as multiple failed login attempts, abnormal IP address access, etc.), the security response mechanism is immediately triggered, and the behavior analysis module is notified for further analysis; the behavior analysis module evaluates the user's security level and potential risks based on the received behavior data, and dynamically adjusts the verification strategy based on the analysis results, such as requiring the user to enter a higher strength verification code, restricting access rights, etc. At the same time, the behavior analysis module will promptly feedback the user's security level, abnormal behavior warning information and potential risks obtained from the analysis to the behavior detection module, so that it can adjust the monitoring strategy according to the latest situation, so as to achieve collaborative work and mutual enhancement between the two modules.

[0102] In this embodiment, the following is also performed: integrating an intelligent learning engine in the behavior detection module and the behavior analysis module, continuously learning and analyzing user behavior data, and constructing a user behavior portrait. Through the user behavior portrait, the system can more comprehensively understand the user's login habits and behavior patterns, and provide strong support for the formulation of personalized verification strategies. At the same time, user behavior portraits can also be used to identify potential security risks and high-risk users, providing additional protection for system security. The intelligent learning engine dynamically updates the rule base and algorithm model in the behavior detection module and the behavior analysis module based on the learned user behavior patterns and system security requirements; the intelligent learning engine is also used to monitor the performance indicators of the behavior detection module and the behavior analysis module, such as processing speed, accuracy, etc., and optimize performance based on feedback results. Through continuous iterative optimization, the system can gradually improve the overall performance and user experience.

[0103] Therefore, this embodiment divides security checks into different levels, so as to achieve secondary verification and interception for abnormal access without affecting normal access of ordinary users, thereby preventing attacks.

[0104] A secondary login verification system embodiment

[0105] like Figure 3 As shown, this embodiment provides a secondary login verification system, which is applied to the above-mentioned secondary login verification method, and the system includes:

[0106] User login module, used to receive user login request;

[0107] Behavior detection module, used to monitor user behavior data in real time;

[0108] Behavior analysis module, used to detect user login behavior and classify security levels;

[0109] A verification code generation module is used to generate a verification code of corresponding difficulty according to the user's security level;

[0110] Verification module, used to verify whether the verification code entered by the user is correct;

[0111] The log module is used to record user login information and behavior logs.

[0112] The user login module is used to detect whether the user's ID or access IP is in the user level verification. If the verification level is Level 1, the user can log in normally, and the user's login information is recorded in the log module. A series of operations after the user logs in to the system will be uploaded to the log module.

[0113] Among them, the behavior analysis module will periodically read the log data stored in the log module and analyze and discover abnormal behaviors, such as multiple login attempts in a short period of time, or the access IP does not belong to the common login IP range, or some brute force attempts after logging into the system. The behavior analysis module performs statistical analysis based on the collected data and changes the user's security level.

[0114] Among them, the behavior detection module is used to monitor the user's behavior data in real time, and the behavior analysis module is used to perform behavior analysis on these behavior data, and dynamically adjust the verification strategy according to the analysis results; a data exchange channel is established between the behavior detection module and the behavior analysis module; during the user login process, the behavior detection module first monitors the user's behavior in real time, and when the behavior detection module captures the user's behavior, it sends the relevant data to the behavior analysis module for processing; once abnormal behavior is found, the security response mechanism is immediately triggered, and the behavior analysis module is notified for further analysis; the behavior analysis module evaluates the user's security level and potential risks based on the received behavior data, and dynamically adjusts the verification strategy based on the analysis results; at the same time, the behavior analysis module will promptly feedback the user's security level, abnormal behavior warning information and potential risks obtained from the analysis to the behavior detection module so that it can adjust the monitoring strategy according to the latest situation.

[0115] Therefore, this embodiment introduces a user security level mechanism to replace the traditional SMS secondary login verification, which not only effectively reduces operating costs, but also significantly enhances user experience and system security, achieves a dual improvement in economic benefits and security protection, and has broad market application prospects and significant social value.

[0116] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0117] The above-mentioned embodiments are only preferred embodiments of the present invention and cannot be used to limit the scope of protection of the present invention. Any non-substantial changes and substitutions made by technicians in this field on the basis of the present invention shall fall within the scope of protection required by the present invention.

Claims

1. A secondary login verification method, characterized in that: The following steps are involved: When a user attempts to log in, the user's ID or access IP is detected, and the user is initially verified according to the preset user level verification rules; If the preliminary verification result is that the user verification level is Level 1, the user is allowed to log in normally, and the user's login information and all operations after the user logs in are recorded in the log module; Read the log data in the log module regularly, analyze the user's behavior to identify abnormal operations; dynamically adjust the user's security level based on the analysis results, and define multiple rule timers and multi-level security level improvement mechanisms to analyze logs at different frequencies; Automatically adjust the user's security level based on the results of behavioral analysis, and implement different levels of security checks on the user based on the adjusted security level; automatically lower the security level of users whose abnormal behavior has decreased or whose behavior is normal at preset time intervals; When the user logs in again, a verification code of corresponding strength is returned for secondary verification based on the user's current security level; Among them, for any abnormal users or IPs detected, a higher level of security verification will be immediately implemented when the user logs in again.

2. The method according to claim 1, characterized in that: The preset user level verification rules are divided into five security levels, and each security level is assigned a verification code of different complexity, including: Level 1: For ordinary users, that is, users with no abnormal behavior, they use the normal verification code of the website for login verification, and no secondary verification is required; Level 2: When a user enters the wrong login password multiple times, or uses a different IP address than usual, a secondary login verification is enabled. The verification code used at this time is the second most difficult verification mode. Level 3: Through user access behavior analysis, if abnormal user operation behavior is found, and the user has passed the Level 2 login verification, the third difficulty verification mode will be enabled; Level 4: If the user has passed the Level 3 login verification, but his / her behavior is still abnormal, the BlockIP / ID X hours mode is enabled, which means that a certain IP address or user ID of the user is denied access to the system within X hours. Level 5: For users who have triggered Level 4 interception operations multiple times, their user IDs or IP addresses are added to the blacklist, permanently or long-term prohibiting them from accessing the system.

3. The method according to claim 2, characterized in that: When an attacker registers for the first time and tries to log in, they are treated as ordinary users without secondary verification and are allowed to access normally. If the attacker enters the wrong account and password multiple times on the login page, the security level will be raised to Level 2 and the secondary verification mechanism will be triggered. The verification code used at this time is the second difficulty verification mode; If it is detected that an attacker uses image recognition tools or other automated means to try to identify and crack the verification code composed of a combination of numbers and letters, indicating that they may be performing brute force or automated attacks, the security level will be immediately raised to Level 3, and the third difficulty verification mode will be enabled; If the attacker continues to attack under Level 3 verification, the security measures will be further upgraded to Level 4 to restrict their access rights; If an attacker triggers Level 4 restrictions multiple times, or their behavior is judged to be highly malicious and continuous, the most stringent security measures will be implemented, that is, their user ID or IP address will be blacklisted and their access to the system will be prohibited according to Level 5 standards.

4. The method according to claim 2, characterized in that: The definition of multiple rule timers and a multi-level security level enhancement mechanism specifically includes: Preset multiple behavior analysis rules and configure corresponding timers for each rule; The behavior analysis module periodically obtains login log data within a specified time period from the MySQL database according to the timer setting; for each log record, it groups by user ID and counts the number of incorrect account and password inputs by each user within the time period or the number of incorrect verification code inputs under a specific security level; If the behavior analysis module finds that a user enters incorrect account and password more than 5 times within 5 minutes, the user's security level will be automatically upgraded from Level 1 to Level 2, and the user will be required to enter the corresponding Level 2 verification code to unlock the login; If further analysis finds that a user enters the Level 2 verification code incorrectly more than 5 times within 10 minutes, the user's security level will be immediately raised from Level 2 to Level 3, and the third level of difficulty verification mode will be enabled; The behavior analysis module continuously monitors the user's login behavior and verification code input, and dynamically adjusts the user's security level according to preset rules.

5. The method according to claim 1, characterized in that It also implements a user session management mechanism based on multi-IP abnormal behavior detection. The specific implementation steps include: The integrated behavior detection module and behavior analysis module are used to monitor and analyze the user's login and operation behavior in real time. When it is detected that the same user performs operations on different IP addresses at the same time or alternately within a short period of time, it is regarded as abnormal behavior and the security response mechanism is immediately triggered. In response, the user is forced to exit all current sessions and is required to re-login to ensure that the account is safe and not illegally exploited. The behavior analysis module analyzes the user's operation logs regularly or in real time according to preset rules and algorithms to evaluate the safety of their behavior. If the user behavior analysis results show that abnormal operations have decreased and no security alarms have been triggered for a period of time, the security level downgrade process will be automatically initiated to gradually reduce the user's security level to the level corresponding to its normal state. When a user is forced to log out due to abnormal behavior of multiple IP addresses and is required to log in again, a notification is sent to the user to explain the reason and provide instructions for logging in again.

6. The method according to claim 1, characterized in that A dynamic secondary verification strength adjustment mechanism based on user security level and login time interval is also implemented. The specific implementation steps include: Maintain a user security level database to record each user's current security level information; when user A attempts to log in, first query his security level; record the time of the user's last successful login, and calculate the time interval between the last successful login attempt and the current login attempt. This time interval will be used to determine the strength of the secondary verification; According to the security level and time interval of user A, a secondary verification method of corresponding strength is dynamically selected; if the security level of user A is higher or the time interval is longer, a higher strength verification method is selected for verification; When user A correctly enters the verification code required for the secondary verification, its validity is verified and the user is allowed to successfully log in to the system. At the same time, the user's security level and time interval records are updated to provide a basis for adjusting the verification strength at the next login; Continuously monitor the user's login behavior and verification results, and dynamically adjust the user's security level based on preset rules and algorithms; if the user successfully passes the verification for multiple consecutive times without triggering a security alarm, gradually lower their security level; conversely, if the user frequently triggers verification failures or has other abnormal behaviors, raise their security level.

7. The method according to claim 5, characterized in that: The behavior detection module is used to monitor the user's behavior data in real time, and the behavior analysis module is used to analyze the behavior data and dynamically adjust the verification strategy according to the analysis results; a data exchange channel is established between the behavior detection module and the behavior analysis module; During the user login process, the behavior detection module first monitors the user's behavior in real time. When the behavior detection module captures the user's behavior, it sends the relevant data to the behavior analysis module for processing; Once abnormal behavior is detected, the security response mechanism is immediately triggered and the behavior analysis module is notified for further analysis; The behavior analysis module evaluates the user's security level and potential risks based on the received behavior data, and dynamically adjusts the verification strategy based on the analysis results; at the same time, the behavior analysis module promptly feeds back the user's security level, abnormal behavior warning information and potential risks obtained from the analysis to the behavior detection module so that it can adjust the monitoring strategy based on the latest situation.

8. The method according to claim 5, characterized in that Also execute: An intelligent learning engine is integrated in the behavior detection module and the behavior analysis module to continuously learn and analyze user behavior data and build a user behavior profile. The intelligent learning engine dynamically updates the rule base and algorithm model in the behavior detection module and the behavior analysis module based on the learned user behavior patterns and system security requirements. The intelligent learning engine is also used to monitor the performance indicators of the behavior detection module and the behavior analysis module.

9. A secondary login verification system, characterized in that: The system is applied to the secondary login verification method according to any one of claims 1 to 8, and the system comprises: User login module, used to receive user login request; Behavior detection module, used to monitor user behavior data in real time; Behavior analysis module, used to detect user login behavior and classify security levels; A verification code generation module is used to generate a verification code of corresponding difficulty according to the user's security level; Verification module, used to verify whether the verification code entered by the user is correct; The log module is used to record user login information and behavior logs.