Dynamic identity verification system and method based on private container cloud
By adopting a dynamic authentication system in a cloud computing environment, comprehensively assessing multiple security factors, calculating the security weight of user identity, and selecting the verification method based on the weight, the problem that traditional static authentication methods are difficult to meet complex security needs is solved, and the accuracy and security of access control are improved.
Patent Information
- Application Number
- CN202510033932.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-05-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional static authentication methods are difficult to meet increasingly complex security needs, and there is a risk of being cracked or bypassed, especially in cloud computing environments.
A dynamic identity verification system based on private container cloud is adopted to comprehensively evaluate user behavior consistency, authentication method security, environmental security, device security and time factors, and dynamically calculate the security weight (ISV) of the user's identity, and select the corresponding security verification method based on this weight.
It significantly improves the access control accuracy and security in the cloud computing environment, effectively prevents various security threats, and ensures the security of information access.
Smart Images

Figure CN120017319A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and in particular relates to a dynamic identity authentication system and method based on a private container cloud. Background Art
[0002] With the rapid development of cloud computing technology, private container cloud has been widely used in enterprise applications due to its advantages such as high resource isolation and flexible deployment. However, traditional static identity authentication methods can no longer meet the increasingly complex security requirements and are at risk of being cracked or bypassed. Therefore, it is particularly important to develop a verification method that can dynamically evaluate the security of user identities. Summary of the invention
[0003] In view of the shortcomings of the prior art, the present invention proposes a dynamic identity authentication system and method based on a private container cloud. By comprehensively considering multiple dimensions such as user behavior consistency, authentication method security, environmental security, device security, and time factors, the security weight (ISV) of the user identity is dynamically calculated, and the corresponding security verification method is selected according to the weight, thereby improving the access control accuracy and security in the cloud computing environment.
[0004] To achieve the above object, the present invention provides the following solutions:
[0005] A dynamic identity authentication system based on a private container cloud comprises the following steps: a user behavior consistency assessment module, an authentication method security assessment module, an environmental security assessment module, an equipment security assessment module, a time factor assessment module, a comprehensive assessment module, a security level determination module and an identity authentication module;
[0006] The user behavior consistency evaluation module is used to evaluate the consistency of user behavior and obtain a user behavior consistency score;
[0007] The authentication method security assessment module is used to assess the security of the authentication method and obtain an authentication method security score;
[0008] The environmental safety assessment module is used to assess environmental safety and obtain an environmental safety score;
[0009] The device safety assessment module is used to assess the safety of the device and obtain a device safety score;
[0010] The time factor evaluation module is used to evaluate the time factor and obtain a time factor score;
[0011] The comprehensive evaluation module is used to calculate the security weight ISV of the user identity based on the user behavior consistency score, the authentication method security score, the environment security score, the device security score, and the time factor score;
[0012] The security level determination module is used to determine the security level of the security weight ISV of the user identity based on the security verification strategy;
[0013] The identity verification module is used to take different security verification measures for users of different security levels based on a dynamically adjusted identity verification strategy.
[0014] Preferably, in the user behavior consistency evaluation module, the process of evaluating the user behavior consistency and obtaining the user behavior consistency score includes:
[0015] By comparing the similarity between the user's historical behavior data and the current behavior data, the user behavior consistency score is calculated:
[0016]
[0017] in, is the historical behavior vector, is the current behavior vector, n is the type of operation, h represents the vector i mold, c represents the vector i Module, h i is a vector The i-th component of i is a vector The i-th component of .
[0018] Preferably, in the authentication method security assessment module, the process of assessing the security of the authentication method and obtaining the authentication method security score includes:
[0019] Analyze information submitted or actions taken by users when logging in or authenticating;
[0020] When a user attempts to access private container cloud resources, the system will ask the user to authenticate;
[0021] When users select different authentication methods, the system will determine the authentication method used by the user based on the user's selection and the preset authentication method security level table, and assign a corresponding security score;
[0022] The security score is used as part of the assessment of the security of the user's identity, along with other dimensions in the system, to ultimately determine the user's access rights and security verification methods.
[0023] Preferably, in the environmental safety assessment module, the process of assessing environmental safety and obtaining an environmental safety score includes:
[0024] The system performs security checks on the user's operating environment, mainly by detecting the user's current network connection status and whether there are potential network attacks or security threats in the environment;
[0025] The specific process is as follows: the system collects information about the network where the user's device is located, and compares it with a known security database to identify whether there are any abnormal or suspicious network activities; at the same time, the system also monitors the security of the network environment, mainly: the validity of SSL / TLS certificates, the security of DNS resolution, and whether there are security risks at the network level such as man-in-the-middle attacks.
[0026] Preferably, in the device safety assessment module, the process of assessing device safety and obtaining a device safety score includes:
[0027] Comprehensive assessment based on device model, operating system version, and security software configuration information:
[0028] DS=w1×DS model +w2×DS os +w3×DS software
[0029] Among them, w1, w2, and w3 are the weights of device model, operating system version, and security software configuration, which are 0.3, 0.3, and 0.4 respectively. model DS is the security score determined by the system based on the device model knowledge base. os DS is the security score of the operating system. software Configures a composite score for security software that is calculated through a weighted sum.
[0030] Preferably, in the time factor evaluation module, the process of evaluating the time factor and obtaining the time factor score includes:
[0031] The score is determined by analyzing the matching degree between the user's login time and frequency and the regular login pattern. The regular login pattern refers to the pattern of login activities performed by the user in a certain period of time according to habitual or preset behavioral rules:
[0032] TF=w time ×TF time +w freq ×TF freq
[0033] Among them, w time is the login time matching score weight, w freq is the login frequency matching score weight, TFtime is the login time matching score, TF freq The login frequency matching score.
[0034] Preferably, in the comprehensive evaluation module, the process of calculating the security weight ISV of the user identity based on the user behavior consistency score, the authentication method security score, the environment security score, the device security score, and the time factor score includes:
[0035] Dynamically assign weights to each assessment module based on its importance in overall identity security;
[0036] The evaluation results of each evaluation module are integrated into the security weight ISV by weighted summation;
[0037] The specific expression is:
[0038] ISV=w1×BC+w2×AS+w3×ES+w4×DS+w5×TF;
[0039] Among them, BC is the user behavior consistency score; AS is the authentication method security score; ES is the environment security score; DS is the device security score; TF is the time factor score; w1, w2, w3, w4, w5 are the weights of the corresponding factors.
[0040] The present invention also provides a dynamic identity authentication method based on a private container cloud, comprising the following steps:
[0041] Evaluate the consistency of user behavior and obtain a user behavior consistency score;
[0042] Evaluate the security of the authentication method and obtain a security score for the authentication method;
[0043] Assess environmental safety and obtain environmental safety scores;
[0044] Evaluate the security of the device and obtain a device security score;
[0045] Evaluate the time factor and obtain the time factor score;
[0046] Calculate the security weight ISV of the user identity based on the user behavior consistency score, authentication method security score, environment security score, device security score, and time factor score;
[0047] Based on the security verification strategy, the ISV determines the security level of the user's identity security weight;
[0048] Based on dynamically adjusted identity authentication strategies, different security verification measures are taken for users with different security levels.
[0049] Compared with the prior art, the present invention has the following beneficial effects:
[0050] The present invention integrates private container cloud technology with a multi-dimensional dynamic identity authentication mechanism, creatively defines a user identity security weight calculation model, and significantly improves access control accuracy and security level.
[0051] The present invention adopts multi-level verification means, comprehensively evaluates user behavior, authentication method, environment, equipment and time, effectively defends against various security threats and ensures the security of information access. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] In order to more clearly illustrate the technical solution of the present invention, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0053] Figure 1 The present invention is a schematic diagram of a dynamic identity authentication system based on a private container cloud according to an embodiment of the present invention. DETAILED DESCRIPTION
[0054] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0055] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0056] Embodiment 1
[0057] like Figure 1 As shown, the present invention provides a dynamic identity authentication system based on a private container cloud, comprising the following steps: a user behavior consistency assessment module, an authentication method security assessment module, an environmental security assessment module, an equipment security assessment module, a time factor assessment module, a comprehensive assessment module, a security level determination module and an identity authentication module;
[0058] The user behavior consistency evaluation module is used to evaluate the consistency of user behavior and obtain the user behavior consistency score;
[0059] The authentication method security assessment module is used to assess the security of the authentication method and obtain the authentication method security score;
[0060] The environmental safety assessment module is used to assess environmental safety and obtain environmental safety scores;
[0061] The device safety assessment module is used to assess the safety of the device and obtain the device safety score;
[0062] The time factor evaluation module is used to evaluate the time factor and obtain the time factor score;
[0063] The comprehensive evaluation module is used to calculate the security weight ISV of the user identity based on the user behavior consistency score, authentication method security score, environment security score, device security score, and time factor score;
[0064] The security level determination module is used to determine the security level of the security weight ISV of the user identity based on the security verification strategy;
[0065] The identity authentication module is used to take different security verification measures for users of different security levels based on dynamically adjusted identity authentication strategies.
[0066] In this embodiment, the core of the technical solution of the present invention is to build an efficient and comprehensive dynamic identity authentication mechanism, which deeply integrates the characteristics of private container cloud technology, and realizes accurate evaluation and dynamic adjustment of user identity security through comprehensive consideration of multi-dimensional factors. The present invention innovatively proposes a user identity security calculation method based on multi-dimensional evaluation factors. The method first defines five key evaluation dimensions: user behavior consistency (BC), authentication method security (AS), environmental security (ES), device security (DS) and time factor (TF). Each dimension represents a different aspect that affects the security of user identity. Through detailed analysis and quantitative evaluation of these dimensions, the authenticity and security of user identity can be fully and deeply revealed.
[0067] In terms of user behavior consistency, the present invention determines whether the user behavior is consistent and reasonable by analyzing the similarities and differences between the user's historical behavior data and current behavior data. This analysis helps to identify abnormal behavior patterns, thereby discovering potential security threats in a timely manner.
[0068] The security of authentication methods focuses on the security strength of the authentication methods used by users. From simple password authentication to complex biometrics, the security levels of different authentication methods vary significantly. The present invention assigns corresponding weights according to the security strength of the authentication methods to ensure that the security contribution of the authentication methods can be accurately reflected during the evaluation process.
[0069] Environmental security is another important dimension that cannot be ignored. Whether the user's operating environment is secure is directly related to the security of the authentication process. Device security is equally important. With the popularity of mobile devices, more and more users choose to access private container clouds through devices such as smartphones and tablets. Therefore, factors such as the physical security of the device, software security, and whether it is authorized have also become key factors in evaluating the security of user identities. Finally, the time factor also plays an important role in dynamic authentication. By analyzing the time and frequency of user logins and the correlation with other users' login behaviors, potential security risks can be revealed.
[0070] Based on the comprehensive evaluation of the above five dimensions, the present invention defines a formula (Identity Safety Value, ISV) to calculate the security weight of the user identity. This formula integrates the evaluation results of each dimension into a comprehensive indicator by weighted summation to reflect the security level of the user identity. According to different ISV value ranges, the present invention also designs a multi-level dynamic identity authentication method weight table to divide users into different security levels and take different security verification measures for users of different levels. This dynamically adjusted identity authentication strategy not only improves the accuracy and security of access control, but also realizes efficient utilization and flexible configuration of resources.
[0071] This formula can be based on the following factors:
[0072] User behavior consistency (BC): the consistency between the user's current behavior and historical behavior.
[0073] Authentication Security (AS): The security level of the authentication method used.
[0074] Environmental Security (ES): The environmental security of user operations, such as the security of network connections.
[0075] Device Security (DS): The security of devices used by users.
[0076] Time Factor (TF): Whether the time when the user logs in conforms to the normal pattern.
[0077] In this embodiment, in the user behavior consistency evaluation module, the process of evaluating the user behavior consistency and obtaining the user behavior consistency score includes:
[0078] It is mainly based on the comparative analysis of the user's historical behavior data and current behavior data. The system collects the user's historical operation habits, access frequency, access path and other data, and compares them with the current user's operation behavior, and uses the similarity algorithm to calculate the difference between the two. The smaller the difference, the more consistent the user behavior, and the higher the BC score; otherwise, the lower the BC score. This calculation process is designed to identify abnormal behavior patterns and determine the authenticity of the user's identity.
[0079] The specific process of comparing similarities (BS): The system collects historical behavior data of users over a period of time (for example, the past month), including operating habits, access frequency, and access path information. For operating habits, the various types of operations performed by users on the container cloud platform (including file upload, download, edit, container start, stop, etc.) and the order and frequency of operations are recorded. The access frequency data records the number of times and time intervals that users access different resources (including specific folders and applications). The access path data collects the user's operating flow from one functional module to another in the platform, expressed in a sequence form. At the same time, the user's behavior data in the current session is obtained in real time, and the format is consistent with the historical behavior data.
[0080] Convert the collected data into vector form. For example, suppose there are n different types of operations on the platform, and for each user, create an n-dimensional vector (historical behavior vector) and (Current behavior vector). If the user has performed the i-th operation x times in the historical data, then The value of the i-th dimension of is x; similarly, for the current behavior data construction vector.
[0081] The historical behavior vector is
[0082]
[0083] The current behavior vector is
[0084]
[0085] Calculated according to the cosine similarity formula
[0086]
[0087] in, Represents the modulus of a vector, and its calculation formula is Here h i is a vector The i-th component of ; c represents the vector i mold, Here c iis a vector The i-th component of .
[0088] In this embodiment, in the authentication method security evaluation module, the process of evaluating the security of the authentication method and obtaining the authentication method security score includes:
[0089] Analyze information submitted or actions taken by users when logging in or authenticating;
[0090] When a user attempts to access private container cloud resources, the system will ask the user to authenticate;
[0091] When users select different authentication methods, the system will determine the authentication method used by the user based on the user's selection and the preset authentication method security level table, and assign a corresponding security score;
[0092] The security score is used as part of the assessment of the security of the user's identity, along with other dimensions in the system, to ultimately determine the user's access rights and security verification methods.
[0093] Specifically, it depends on the evaluation of the security strength of the authentication method. The system maintains an authentication method security level table. According to the authentication method adopted by the user (such as password, SMS verification code, biometrics, etc.), the corresponding security level is found in the table and the corresponding AS score is assigned. Generally speaking, the more complex and difficult it is to crack the authentication method, the higher its security level and AS score. As shown in Table 1.
[0094] Table 1
[0095]
[0096] In this embodiment, in the environmental safety assessment module, the process of assessing environmental safety and obtaining an environmental safety score includes:
[0097] Involves security checks on the user's operating environment. The system scans the user's network environment to detect potential security threats such as network attacks and malware, and evaluates the stability and encryption of the network connection. At the same time, the system also considers the security of the user's physical environment, such as whether it is in a public or untrusted network environment. Combining these factors, the system will give an ES score that reflects the security impact of the environment on the authentication process.
[0098] The specific process is as follows: the system collects information about the network where the user's device is located, and compares it with a known security database to identify whether there are any abnormal or suspicious network activities; at the same time, the system also monitors the security of the network environment, mainly: the validity of SSL / TLS certificates, the security of DNS resolution, and whether there are security risks at the network level such as man-in-the-middle attacks.
[0099] In this embodiment, in the device security assessment module, the process of assessing device security and obtaining a device security score includes:
[0100] Comprehensive assessment of user devices. The system determines whether the device meets the preset security requirements by identifying the device model, operating system version, security software configuration, etc. For example, the system will check whether the device has the latest security patches installed, whether the firewall and antivirus software are enabled, etc. Based on this information, the system will calculate the DS score to evaluate the security contribution of the device to the authentication process.
[0101] The process of comprehensive evaluation based on device model, operating system version, and security software configuration information:
[0102] Device model assessment: Establish a complete device model knowledge base. If the device has a hardware encryption engine and a perfect secure boot mechanism, and has a reliable physical anti-tampering design, it will be classified as a high-security device model category, and the basic security score range is set to [80,100]. If it only has some hardware security features, such as only basic secure boot functions, it will be classified as a medium-security device model category, and the basic security score range is set to [50,70]. For device models that lack key hardware security features, they are classified as low-security categories, and the score range is [0,40]. The system determines the security score DS based on the device model knowledge base. model
[0103] Operating system version evaluation: For the operating system kernel, analyze whether it uses advanced memory isolation technology and whether the process permission management mechanism is strict. If the operating system kernel has advanced memory isolation technology and strict process permission management, and has a good security patch management record (timely release and repair of critical security vulnerabilities), its initial security score range is set to [70,90]; if there is room for improvement in the kernel security mechanism and the security patch management is average, the score range is adjusted to [40,60]; for old operating system versions that are no longer actively maintained and updated with security patches, the score range is [0,30]. The system obtains the operating system version of the user's device in real time and compares it with the security database. Check whether the system has the latest security patches installed. If all critical security patches have been installed and are in the latest stable version, add 8 points to the initial score; if some critical security patches are not installed, each missing critical patch will be reduced by 6 points; if there are unfixed serious security vulnerabilities (determined by the vulnerability rating issued by the security agency), it will be reduced by 10-15 points according to the severity of the vulnerability. This results in the operating system security score DS os .
[0104] Security software configuration assessment: The system comprehensively scans the security software installed on the device. If the software has multi-engine detection and responds quickly to new threats and can completely remove malicious software, it can get 35-45 points. For firewalls, the flexibility and sophistication of their network access control rules (whether they can customize strict access rules according to different applications and network environments) and their real-time defense capabilities against network attacks (such as the effective blocking rate of DDoS attacks, port scans and other attacks) are examined. Firewalls with highly flexible access control rules and a success rate of more than 90% in defending against common network attacks can get 30-40 points. IDS / IPS are scored based on the accuracy of their detection algorithms (false positive rate and false negative rate) and the timeliness of the update of the attack signature library. IDS / IPS with accurate detection algorithms and daily updated signature libraries can get 25-35 points. Encryption software is evaluated based on the strength of its encryption algorithm (whether it complies with international security standards) and the security of key management (key length, key storage and exchange security). Encryption software that uses high-strength encryption algorithms and has secure and reliable key management can get 20-30 points. Check the update status of security software, including the update frequency of virus database, attack signature database, encryption algorithm database, etc. If the security software is updated within 48 hours, 6 points will be added to the functional score; if it is not updated for more than 48 hours, 2 points will be reduced for each additional day. According to the importance of various types of security software in overall security protection, the weight of antivirus software is set to 0.35, the weight of firewall is set to 0.3, the weight of IDS / IPS is set to 0.2, and the weight of encryption software is set to 0.15 (the total weight is 1). The comprehensive score DS of the security software configuration is calculated by weighted summation software
[0105] DS=w1×DS model +w2×DS os +w3×DS software
[0106] Among them, w1, w2, and w3 are the weights of device model, operating system version, and security software configuration, which are 0.3, 0.3, and 0.4 respectively.
[0107] In this embodiment, in the time factor evaluation module, the process of evaluating the time factor and obtaining the time factor score includes:
[0108] Involves analysis of user login time patterns. The system collects user login records and analyzes the user's regular login time, frequency, and the correlation with other users' login behaviors. If the user's login time or frequency does not match the regular pattern (such as frequent logins at night, logins from other locations, etc.), it will be considered abnormal behavior and the TF score will be reduced accordingly. Through this calculation process, the system can identify potential abnormal login attempts, thereby improving the security of identity authentication.
[0109] The specific comprehensive evaluation process to determine the score is by analyzing the match between the user's login time, frequency and regular login pattern:
[0110] The system records the user's login data in the past month, including each login time (accurate to the hour) and login date, and calculates the total number of logins N. A day is divided into four time periods: early morning (0-6 am), morning (6-12 pm), afternoon (12-18 pm), and evening (18-24 pm). Count the number of logins in each time period n1, n2, n3, and n4, and calculate the login ratio in each time period Calculate average login frequency
[0111] Login time matching evaluation:
[0112] When a user logs in, determine the time period to which the current login time belongs.
[0113] If the current login time is in the morning, afternoon or evening, and the historical login ratio p in this period is ≥ 0.3, the login time matching score TF time =70 points.
[0114] If the current login time is in the morning, afternoon or evening, and the historical login ratio of this period |0.1≤p<0.3, then TF time =40 points.
[0115] If the current login time is in the early morning hours, TF time =20 points.
[0116] Login frequency matching evaluation:
[0117] Calculate the current login frequency F current (Number of logins on the day) and average login frequency F avg The deviation ratio
[0118] If d < 0.2, the login frequency matching score TF freq =80 points.
[0119] If 0.2≤p<0.5, TFf req =50 points.
[0120] If d>0.5, TFf req =10 points.
[0121] Calculation of comprehensive time factor score:
[0122] Set the login time matching score weight w time =0.6, login frequency matching score weight w freq =0.4.
[0123] TF=w time ×TF time +w freq ×TF freq .
[0124] In this embodiment, in the comprehensive evaluation module, the process of calculating the security weight ISV of the user identity based on the user behavior consistency score, the authentication method security score, the environment security score, the device security score, and the time factor score includes:
[0125] Dynamically assign weights to each assessment module based on its importance in overall identity security;
[0126] The evaluation results of each evaluation module are integrated into the security weight ISV by weighted summation;
[0127] The specific expression is:
[0128] ISV=w1×BC+w2×AS+w3×ES+w4×DS+w5×TF;
[0129] Among them, BC is the user behavior consistency score; AS is the authentication method security score; ES is the environment security score; DS is the device security score; TF is the time factor score; w1, w2, w3, w4, w5 are the weights of the corresponding factors.
[0130] Embodiment 2
[0131] The present invention also provides a dynamic identity authentication method based on a private container cloud, comprising the following steps:
[0132] Evaluate the consistency of user behavior and obtain a user behavior consistency score;
[0133] Evaluate the security of the authentication method and obtain a security score for the authentication method;
[0134] Assess environmental safety and obtain environmental safety scores;
[0135] Evaluate the security of the device and obtain a device security score;
[0136] Evaluate the time factor and obtain the time factor score;
[0137] Calculate the security weight ISV of the user identity based on the user behavior consistency score, authentication method security score, environment security score, device security score, and time factor score;
[0138] Based on the security verification strategy, the ISV determines the security level of the user's identity security weight;
[0139] Based on dynamically adjusted identity authentication strategies, different security verification measures are taken for users with different security levels.
[0140] In this embodiment, first, the system needs to establish a comprehensive user identity security assessment system, which covers multiple dimensions such as user behavior consistency (BC), authentication method security (AS), environmental security (ES), device security (DS) and time factor (TF).
[0141] Among them, the definition of user behavior consistency (BC) is: User behavior consistency refers to the similarity and coherence between the user's current behavior and historical behavior. During the dynamic identity authentication process, the system analyzes the user's historical behavior data and current behavior data to determine whether the user's behavior pattern is consistent, so as to evaluate the authenticity of the user's identity. If the current behavior is significantly different from the historical behavior or does not conform to the normal pattern, it may indicate a potential security threat.
[0142] Authentication Security (AS) Glossary: Authentication security refers to the security strength of the authentication method used by the user. Different authentication methods have different security levels, ranging from simple password authentication to complex biometrics. In dynamic identity authentication, the system will assign a corresponding security weight based on the authentication method used by the user to reflect the security contribution of the method in the identity authentication process.
[0143] Environmental Security (ES) Glossary: Environmental security refers to whether the environment in which the user operates is safe. This includes the security of the network environment, such as whether there are potential network attacks, whether data transmission is encrypted, etc. During the dynamic identity authentication process, the system will perform a security check on the environment in which the user operates to ensure that the identity authentication process is not affected by external threats.
[0144] Device Security (DS) Glossary: Device security refers to whether the device used by the user meets security requirements. With the popularity of mobile devices, more and more users access private container clouds through devices such as smartphones and tablets. Therefore, factors such as the physical security of the device, software security, and whether it is authorized have become key factors in evaluating the security of the user's identity. The system will evaluate the security of the device by identifying information such as the device model, operating system version, and security software configuration.
[0145] Time Factor (TF) Glossary: Time factor refers to whether the time of user login conforms to the regular pattern. In dynamic identity authentication, the system analyzes the time and frequency of user logins and the correlation with other users' login behaviors to reveal potential security risks. For example, abnormal situations such as frequent logins at night and logins from other locations may indicate that the user's identity is at risk of being misused. By considering the time factor, the system can more comprehensively evaluate the security of the user's identity.
[0146] Each dimension is quantitatively evaluated through a preset algorithm or rule and assigned a corresponding weight (w1 to w5). The specific steps can be summarized as follows: First, define clear evaluation criteria and quantitative indicators for each dimension, such as BC, which calculates the score by comparing the similarity between the user's historical behavior data and the current behavior data; AS, which scores according to the preset level table of security strength of the authentication method (such as password, biometrics, etc.); ES, which involves security checks on the network environment, such as whether it is subject to potential network attacks; DS, which is based on comprehensive evaluation of information such as device model, operating system version, and security software configuration; TF, which determines the score by analyzing the matching degree of user login time, frequency, and regular patterns. Then, according to the importance of each dimension in the overall identity security, dynamically assign weights (w1 to w5), which can be determined by expert evaluation, historical data analysis, and other methods. Finally, the evaluation results of each dimension are integrated into Identity Safety Value (ISV) by weighted summation, which is used as a quantitative indicator of user identity security, and the subsequent security verification method is determined accordingly.
[0147] These weights are dynamically adjusted based on the importance of each factor in overall security. When a user tries to access resources in a private container cloud, the system immediately starts the authentication process. First, the system collects and analyzes the user's current behavior data, such as operating habits and access frequency, compares it with the user's historical behavior records, and calculates the user's behavior consistency (BC) score. The specific steps can be summarized as follows: the system can collect the user's behavior data in the current session in real time, and compare and analyze it in combination with the user's behavior patterns in the historical database. In the evaluation of user behavior consistency, the weight of each feature can be dynamically adjusted according to the stability and reliability of different behavioral features. For example, a higher weight can be given to access frequencies and common function usage habits with higher stability; while a lower weight can be given to single operations that are easily interfered with or misjudged.
[0148] Subsequently, the system confirms the authentication method used by the user, such as password, SMS verification code, biometrics, etc., and gives a score for the authentication method security (AS) according to the preset authentication method security level table, as shown in Table 1. The specific steps can be summarized as follows: The system confirms the authentication method used by the user, mainly by analyzing the information submitted or the operations performed by the user when logging in or performing identity authentication. When the user tries to access private container cloud resources, the system will require the user to authenticate. The user can choose different authentication methods, such as entering a password, receiving and entering an SMS verification code, using biometric technology (such as fingerprint, facial recognition), etc. The system will determine the authentication method used by the user based on the user's selection and the preset authentication method security level table, and assign a corresponding security score. This score will be considered as part of the assessment of user identity security, together with other dimensions in the system (such as user behavior consistency, environmental security, device security, and time factors), and ultimately determine the user's access rights and security verification methods.
[0149] Table 1
[0150]
[0151] At the same time, the system will also conduct a security check on the environment in which the user operates, including the security status of the network environment, whether there are potential network attacks, etc., so as to obtain an assessment result of the environmental security (ES). The specific steps can be summarized as follows: the system conducts a security check on the environment in which the user operates, mainly by detecting the user's current network connection status and whether there are potential network attacks or security threats in the environment. One specific way is that the system collects information about the network where the user's device is located, such as IP address, geographic location, network proxy usage, etc., and compares it with a known security database to identify whether there are abnormal or suspicious network activities. At the same time, the system also monitors the security of the network environment, such as the validity of SSL / TLS certificates, the security of DNS resolution, and whether there are network-level security risks such as man-in-the-middle attacks. These checks will help the system evaluate the security of the user's operating environment (ES) and serve as part of a comprehensive assessment of the security of the user's identity.
[0152] For device security (DS), the system evaluates whether the device meets security requirements by identifying information such as the device model, operating system version, and security software configuration used by the user.
[0153] In addition, the system will also consider the time factor (TF), that is, whether the time when the user logs in is consistent with his regular login pattern. Among them, the regular login pattern refers to the pattern of the user's login activities in a certain period of time according to his habits or preset behavior rules. This pattern may include the user's login time period, login frequency, login location (such as IP address range) and other characteristics.
[0154] This step helps to identify potential abnormal login attempts, such as frequent logins at night, logins from other locations, and other abnormal situations.
[0155] After completing the evaluation of all the above dimensions, the system calculates the user's identity security weight according to the Identity Safety Value (ISV) formula, that is, ISV = w1 × BC + w2 × AS + w3 × ES + w4 × DS + w5 × TF. Subsequently, the system compares this weight with the preset security level threshold to determine which level of security verification method to use for subsequent access control. Among them, the security level threshold refers to the numerical boundary used to divide different security levels or risk levels. In the dynamic identity authentication method based on the private container cloud, the security level threshold is used to divide users into different security levels according to the security weight (ISV) of the user's identity. Each security level corresponds to a range of ISV scores, and the security level threshold is the dividing line between these ranges. When the user's ISV score reaches or exceeds a certain threshold, the system will classify the user into the corresponding security level and take corresponding security verification measures. In this way, the system can achieve refined management and dynamic adjustment of user identity security, thereby improving the accuracy and security of access control. Subsequent access control using security verification means that after the user passes the identity verification process, the system selects security verification measures of the corresponding level to control the user's access rights to resources based on the user's identity security assessment results. This access control mechanism ensures that only users who have been strictly verified and whose identity security meets the requirements can access sensitive or important data resources. Security verification methods can include password verification, SMS verification code, biometric technology, device security inspection, and environmental verification. The system will dynamically adjust the required verification level based on the user's identity security value (ISV) and security level threshold to achieve fine control and security of user access behavior.
[0156] Embodiment 3
[0157] In the actual operation of enterprise A, the application of the dynamic identity authentication method based on private container cloud proposed in the present invention can significantly improve the level of information security protection in its cloud computing environment. First, enterprise A needs to conduct a comprehensive security audit and assessment of its existing private container cloud environment to determine the current security level and potential risk points. This step includes but is not limited to checking key elements such as user behavior data, authentication method, network environment, device security, and user login time mode. Through the collection and analysis of this information, enterprise A can establish a detailed user identity security assessment benchmark. Subsequently, enterprise A customizes a dynamic identity authentication strategy suitable for its own business needs according to the formula and weight table defined in the present invention. This strategy will comprehensively consider multiple dimensions such as user behavior consistency, authentication method security, environmental security, device security, and time factors, and set corresponding verification methods for users or information access scenarios with different risk levels. For example, for high-risk users accessing sensitive data, enterprise A can adopt a multiple verification method of biometrics + device security check + environment verification to ensure that the visitor's identity is absolutely reliable. During the implementation process, enterprise A also needs to integrate a dynamic identity authentication system on the private container cloud platform. This system should be able to capture key information such as user behavior, network environment, device status, etc. in real time, and use preset evaluation models and algorithms to analyze this information instantly. Based on the analysis results, the system can automatically adjust the user's identity authentication level and trigger additional verification steps when necessary, thereby achieving dynamic monitoring and timely adjustment of user identity security.
[0158] The embodiments described above are only descriptions of the preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Without departing from the design spirit of the present invention, various modifications and improvements made to the technical solutions of the present invention by ordinary technicians in this field should all fall within the protection scope determined by the claims of the present invention.
Claims
1. A dynamic identity authentication system based on a private container cloud, characterized in that: The following steps are included: user behavior consistency assessment module, authentication method security assessment module, environment security assessment module, equipment security assessment module, time factor assessment module, comprehensive assessment module, security level determination module and identity authentication module; The user behavior consistency evaluation module is used to evaluate the consistency of user behavior and obtain a user behavior consistency score; The authentication method security assessment module is used to assess the security of the authentication method and obtain an authentication method security score; The environmental safety assessment module is used to assess environmental safety and obtain an environmental safety score; The device safety assessment module is used to assess the safety of the device and obtain a device safety score; The time factor evaluation module is used to evaluate the time factor and obtain a time factor score; The comprehensive evaluation module is used to calculate the security weight ISV of the user identity based on the user behavior consistency score, the authentication method security score, the environment security score, the device security score, and the time factor score; The security level determination module is used to determine the security level of the security weight ISV of the user identity based on the security verification strategy; The identity verification module is used to take different security verification measures for users of different security levels based on a dynamically adjusted identity verification strategy.
2. The dynamic identity authentication system based on private container cloud according to claim 1, characterized in that: In the user behavior consistency evaluation module, the process of evaluating the user behavior consistency and obtaining the user behavior consistency score includes: By comparing the similarity between the user's historical behavior data and the current behavior data, the user behavior consistency score is calculated: in, is the historical behavior vector, is the current behavior vector, n is the type of operation, h represents the vector i mold, c represents the vector i Module, h i is a vector The i-th component of i is a vector The i-th component of .
3. The dynamic identity authentication system based on private container cloud according to claim 1, characterized in that: In the authentication method security assessment module, the process of assessing the security of the authentication method and obtaining the authentication method security score includes: Analyze information submitted or actions taken by users when logging in or authenticating; When a user attempts to access private container cloud resources, the system will ask the user to authenticate; When users select different authentication methods, the system will determine the authentication method used by the user based on the user's selection and the preset authentication method security level table, and assign a corresponding security score; The security score is used as part of the assessment of the security of the user's identity, along with other dimensions in the system, to ultimately determine the user's access rights and security verification methods.
4. The dynamic identity authentication system based on private container cloud according to claim 1, characterized in that: In the environmental safety assessment module, the process of assessing environmental safety and obtaining an environmental safety score includes: The system performs security checks on the user's operating environment, mainly by detecting the user's current network connection status and whether there are potential network attacks or security threats in the environment; The specific process is as follows: the system collects information about the network where the user's device is located, and compares it with a known security database to identify whether there are any abnormal or suspicious network activities; at the same time, the system also monitors the security of the network environment, mainly: the validity of SSL / TLS certificates, the security of DNS resolution, and whether there are security risks at the network level such as man-in-the-middle attacks.
5. The dynamic identity authentication system based on private container cloud according to claim 1, characterized in that: In the device security assessment module, the process of assessing device security and obtaining a device security score includes: Comprehensive assessment based on device model, operating system version, and security software configuration information: DS=w1×DS model +w2×DS os +w3×DS software Among them, w1, w2, and w3 are the weights of device model, operating system version, and security software configuration, which are 0.3, 0.3, and 0.4 respectively. model DS is the security score determined by the system based on the device model knowledge base. os DS is the operating system security score. software Configures a composite score for security software that is calculated through a weighted sum.
6. The dynamic identity authentication system based on private container cloud according to claim 1, characterized in that: In the time factor evaluation module, the process of evaluating the time factor and obtaining the time factor score includes: The score is determined by analyzing the matching degree between the user's login time and frequency and the regular login pattern. The regular login pattern refers to the pattern of login activities performed by the user in a certain period of time according to habitual or preset behavioral rules: TF=w time ×TF time +w freq ×TF freq Among them, w time is the login time matching score weight, w freq is the login frequency matching score weight, TF time is the login time matching score, TF freq The login frequency matching score.
7. The dynamic identity authentication system based on private container cloud according to claim 1, characterized in that: In the comprehensive evaluation module, the process of calculating the security weight ISV of the user identity based on the user behavior consistency score, the authentication method security score, the environment security score, the device security score, and the time factor score includes: Dynamically assign weights to each assessment module based on its importance in overall identity security; The evaluation results of each evaluation module are integrated into the security weight ISV by weighted summation; The specific expression is: ISV=w1×BC+w2×AS+w3×ES+w4×DS+w5×TF; Among them, BC is the user behavior consistency score; AS is the authentication method security score; ES is the environment security score; DS is the device security score; TF is the time factor score; w1, w2, w3, w4, w5 are the weights of the corresponding factors.
8. A dynamic identity authentication method based on a private container cloud, characterized in that: The following steps are involved: Evaluate the consistency of user behavior and obtain a user behavior consistency score; Evaluate the security of the authentication method and obtain a security score for the authentication method; Assess environmental safety and obtain environmental safety scores; Evaluate the security of the device and obtain a device security score; Evaluate the time factor and obtain the time factor score; Calculate the security weight ISV of the user identity based on the user behavior consistency score, authentication method security score, environment security score, device security score, and time factor score; Based on the security verification strategy, the ISV determines the security level of the user's identity security weight; Based on dynamically adjusted identity authentication strategies, different security verification measures are taken for users with different security levels.
Citation Information
Patent Citations
Risk early warning method
CN114091042A
Secret-free authentication method based on environment monitoring and user behavior analysis
CN116502199A
Internet of Things access scene identity modeling and access control method
CN117155609A
Digital human identity verification method and device, electronic equipment and storage medium
CN119249393A
A system and method for authenticating a user based on user behaviour and environmental factors
WO2016048129A2