Identity authentication system and method based on multiple devices and multiple factors
By analyzing user historical authentication data and behavioral data, dynamically adjusting identity authentication strategies, and using machine learning to build a risk identification model, the existing multi-factor identity authentication system is solved, and the problem that the existing multi-factor identity authentication system cannot adapt to different users and scenarios is achieved, achieving higher security and user experience.
Patent Information
- Application Number
- CN202510174824.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-02-18
AI Technical Summary
The existing multi-factor identity authentication system cannot dynamically adjust the authentication strategy to adapt to different users and usage scenarios, resulting in poor user experience.
By collecting and analyzing user historical authentication data, the security value of each identity authentication method is calculated, and the adaptation method set is constructed based on user behavior data, and the authentication strategy is dynamically adjusted. At the same time, machine learning is used to build a risk identification model, analyze dangerous data in real time, and adjust identity authentication methods to improve security and user experience.
It realizes dynamic adjustment of identity authentication strategies based on user characteristics and scenarios, improving the security and efficiency of user experience and identity authentication.
Smart Images

Figure CN120046136A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of identity authentication, and specifically provides an identity authentication system and method based on multiple devices and multiple factors. Background Art
[0002] With the rapid development of technologies such as the Internet, Internet of Things, and mobile terminals, the network environment has become increasingly complex, and various network attack methods have emerged in an endless stream, such as phishing, password cracking, data theft, etc. Traditional single identity authentication methods, such as username and password authentication, are no longer sufficient to ensure the security of user information and systems. In recent years, with the development of technologies such as the Internet of Things and smart homes, multi-factor identity authentication with multi-device collaboration has become a research and application hotspot. For example, in the HarmonyOS Next system, the multi-factor authentication solution based on FIDO authentication allows users to use biometric recognition on a smartphone as the first factor, and then interact with a smartwatch as the second factor, using FIDO authentication technology to ensure the security and convenience of the entire verification process.
[0003] However, in today's multi-factor identity authentication, the mode is relatively fixed, and it cannot make dynamic adjustments for different users, different usage scenarios, and situations. Moreover, due to different user usage habits, the same authentication strategy has different usage effects for different users, which greatly affects the user experience. Summary of the Invention
[0004] The purpose of the present invention is to provide an identity authentication system and method based on multiple devices and multiple factors to solve the problems raised in the prior art.
[0005] To achieve the above purpose, the present invention provides the following technical solutions: An identity authentication method based on multiple devices and multiple factors, the method comprising the following steps: S100. Collect all identity authentication methods existing in the device. For each identity authentication method, collect historical authentication records, extract all authentication data, and calculate the security value of each identity authentication method according to the historical authentication data; Further, the specific steps for calculating the security value of each identity authentication method according to the historical authentication data are as follows: S101. Collect all identity authentication methods existing in the device. For each identity authentication method, collect historical authentication records, and extract all authentication data as {S 1 、S 2 、S 3 、...、S n}, S 1 、S 2 、S 3 、...、Sn Denote the extracted 1st, 2nd, 3rd, …, nth authentication data, where n is a positive integer; assume the historical authentication records collected are M times, screen out the successful and failed authentication records, compare the same authentication data in the successful and failed authentication records, and subtract the authentication data of failed authentication from that of successful authentication; when the difference of the same authentication data between successful and failed authentication is not zero, determine the corresponding authentication data as influencing data; and judge the sign of the difference of the influencing data. When the difference sign is positive, it is defined as positive influencing data; when the difference sign is negative, it is defined as negative influencing data. S102. Extract influencing data for different identity authentication methods, and calculate the security value of different identity authentication methods. The formula is: ; In the formula, An represents the security value of the identity authentication method, and S + i represents the ith positive influencing data, and S - j represents the jth negative influencing data, a represents the total number of positive influencing data, and b represents the total number of negative influencing data; S103. Use the same method to calculate the security degrees of all identity authentication methods collected as {An 1 、An 2 、An 3 、...、An c}, where An 1 、An 2 、An 3 、...、An c represent the security values of the 1st, 2nd, 3rd, …, cth identity authentication methods calculated, and c is a positive integer.
[0006] Calculating the security value of each identity authentication method based on the authentication data when users perform identity authentication in history can clearly express the security of each identity authentication method. When users perform identity authentication, an authentication strategy with a combination of multiple authentication methods can be reasonably formulated according to the security, which greatly ensures the efficiency and security of user identity authentication.
[0007] S200. Collect the behavior data of different users when they perform identity authentication in history, calculate the adaptability of each identity authentication method to different users, and construct an adaptation method set for each user; Furthermore, the specific steps for constructing an adaptation method set for each user are: S201. Collect the behavioral data of different users during historical identity authentication. The behavioral data includes the number of times different identity authentication methods are used, authentication time, and authentication success rate in the user's history. Calculate the fitness by weighted summation of the three behavioral data. The formula is: ; In the formula, Fit represents the fitness of the identity authentication method, α 1 , α 2 and α 3 represent the weights of the number of times used, authentication time, and authentication success rate respectively. C represents the number of times used, T represents the authentication time, and P represents the authentication success rate; S202. For the same user, calculate the fitness of the user with different identity authentication methods as {Fit 1 , Fit 2 , Fit 3 ,..., Fit c}. Fit 1 , Fit 2 , Fit 3 ,..., Fit c represent the fitness of the user and the 1st, 2nd, 3rd,..., cth identity authentication methods. Arrange the fitness of all identity authentication methods in ascending order, calculate the difference between adjacent fitness values, and obtain c - 1 fitness differences. Select the fitness value immediately before the largest difference as the fitness threshold, and construct the set of suitable methods using all identity authentication methods with fitness greater than the fitness threshold as {SH 1 , SH 2 , SH 3 ,..., SH d}. SH 1 , SH 2 , SH 3 ,..., SH d represent the 1st, 2nd, 3rd,..., dth identity authentication methods in the set of suitable methods, where d is a positive integer and d ≤ c; S203. Calculate the behavioral data of all users' historical identity authentication on the used device, and construct the set of suitable methods for each user.
[0008] Based on the behavioral data in the user's history, construct the set of suitable methods for each type of user, find the identity authentication method suitable for each user, make it more user - friendly when specifying the identity authentication policy, enhance the user experience, and achieve personalized authentication methods.
[0009] S300. Collect the device data during historical user identity authentication, compare the device data at the time of successful and failed authentication, and extract the dangerous data affecting user identity verification from the device data; Furthermore, the specific steps for extracting the dangerous data affecting identity authentication are as follows: S301. Collect the device data during historical user identity authentication, and calculate the difference between each device data when the identity authentication is successful and when it fails as {Zc 1 、Zc 2 、Zc 3 、...、Zc u}, where Zc 1 、Zc 2 、Zc 3 、...、Zc u represent the differences between the 1st, 2nd, 3rd, ..., u-th device data when the identity authentication is successful and when it fails, and u is a positive integer; calculate the standard deviation of the u differences as IZc; S302. Use the calculated difference standard deviation to judge the differences of all devices. When Zc > IZc, judge the corresponding device data as dangerous data; when Zc ≤ IZc, judge it as non-dangerous data; after judging all device data, the dangerous data obtained is {W 1 、W 2 、W 3 、...、W r}, where W 1 、W 2 、W 3 、...、W r represent the 1st, 2nd, 3rd, ..., r-th dangerous data obtained by judgment, r is a positive integer, and r < u.
[0010] S400. Process the extracted dangerous data, transform it into a feature vector of the same dimension, map the security value of each identity authentication method, analyze the influence of the feature vector on the security value of each identity authentication method, and use machine learning to construct a risk identification model; Furthermore, the specific steps for constructing a risk identification model using machine learning are as follows: S401. Process the extracted dangerous data, transform it into a feature vector of the same dimension, and the formula is: ; In the formula, Wn represents the transformed feature vector, W represents the extracted dangerous data, min(W) represents the minimum value in the extracted dangerous data, and max(W) represents the maximum value in the extracted dangerous data; S402. Map the security value of each identity authentication method, analyze the influence of the feature vector on the security value of each identity authentication method, use the feature vector as the independent variable and the security value of each identity authentication method as the variable, draw a curve graph, fit the curve graph, and obtain the influence polynomial of the feature vector on the security value of each identity authentication method. Assume the form of the polynomial is , β 0 is the constant term, and β 0 to β r represent the coefficients of the 1st to the rth feature vectors; S403. Repeat the steps for each identity authentication method to obtain the polynomial for each identity authentication method; collect the security values when identity authentication fails in history, calculate the average value and the standard deviation, subtract the standard deviation from the average value to obtain the danger threshold, and construct the risk identification model as: , where Ay represents the danger threshold.
[0011] S500. Extract the identity authentication method with the highest adaptation degree in the adaptation method set of each user as the default method for the corresponding user. When the user performs identity authentication using the default method, collect real-time danger data and input it into the risk identification model to judge the user's real-time identity authentication; Furthermore, the specific steps for judging the user's real-time identity authentication are as follows: S501. Extract the identity authentication method with the highest adaptation degree in the adaptation method set of each user as the default method for the corresponding user. When the user performs identity authentication using the default method, collect real-time danger data and input it into the risk identification model to calculate the real-time security values {Ans 1 , Ans 2 , Ans 3 ,..., Ans d} of all identity authentication methods in the user's adaptation method set. Ans 1 , Ans 2 , Ans 3 ,..., Ans d represent the real-time security values of the 1st, 2nd, 3rd,..., dth identity authentication methods in the user's adaptation method set. Extract the real-time security value Mans of the user's default method and judge the real-time security value of the default method in the risk identification model. When Mans < Ay, it is judged that there is a risk in the user's real-time identity authentication; when Mans ≥ Ay, it is judged that there is no risk in the user's real-time identity authentication.
[0012] Judging the real-time security value using the security threshold to obtain whether there is a security risk during the user's real-time identity authentication can not only check the security of the user's identity authentication, but also formulate different authentication strategies for different authentication situations according to the specific real-time scenarios and conditions; greatly increasing the diversity and universality of user identity authentication.
[0013] S600. According to the analysis result of the user's real-time danger data by the risk identification model, adjust the user's identity authentication method using the user's adaptation method set and the security value of each identity authentication.
[0014] Further, the specific steps for adjusting the user's identity authentication method by using the user's adaptation method set and the security value of each identity authentication are as follows: S601. After determining that there is a risk in the user's real-time identity authentication, add identity authentication methods in the user's adaptation method set according to the order of adaptation degree, and calculate the real-time security value after addition. The formula is: ; In the formula, TAn represents the security value after adding the identity authentication method, tAn represents the security value of the added identity authentication method, and add identity authentication methods in turn until TAn is greater than Ay and ends.
[0015] When adding the user's real-time identity authentication method, not only consider whether there is a risk, but also consider whether it is suitable for the user. Add identity authentication methods in both aspects, which increases the user's usage sense on the basis of ensuring identity authentication security.
[0016] An identity authentication system based on multiple devices and multiple factors, the identity authentication system includes a data collection module, a security value calculation module, an adaptation method set construction module, a dangerous data search module, a model construction module, a real-time calculation module, and a method addition module; The data collection module is used to collect the records when the user conducts identity authentication in history; The security value calculation module is used to extract all authentication data and calculate the security value of each identity authentication method according to the historical authentication data; The adaptation method set construction module is used to calculate the adaptation degree of each identity authentication method and different users, and construct the adaptation method set of each user; The dangerous data search module is used to compare the device data when authentication is successful and failed, and extract the dangerous data that affects the user's identity verification from the device data; The model construction module is used to analyze the influence of feature vectors on the security value of each identity authentication method, and construct a risk identification model by using machine learning; The real-time calculation module is used to collect real-time dangerous data and input it into the risk identification model, and calculate the real-time security value of all identity authentication methods in the adaptation method set; The method addition module is used to judge the real-time security value and add the method of the user's real-time identity authentication.
[0017] The model construction module includes a polynomial calculation unit and a model construction unit; The polynomial calculation unit is used to map the security value of each identity authentication method, analyze the influence of feature vectors on the security value of each identity authentication method, draw a curve and fit to obtain a polynomial of the influence of dangerous data on the security value; The model construction unit is used to collect the security values when identity authentication fails in history, calculate the average value and standard deviation, subtract the standard deviation from the average value to obtain the danger threshold, and construct a risk identification model.
[0018] The real-time calculation module includes a real-time security value calculation unit and a judgment unit; The real-time security value calculation unit is used to collect real-time danger data and calculate the real-time security values of all identity authentication methods by using the polynomial calculation adaptation method; The judgment unit is used to extract the real-time security value of the default method and judge the real-time security value of the default method by using the security threshold.
[0019] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. According to the authentication data when the user performs identity authentication in history, the security value of each identity authentication method is calculated, which can clearly express the security of each identity authentication method. When the user performs identity authentication, an authentication strategy with a combination of multiple authentication methods is reasonably formulated according to the security, which greatly ensures the efficiency and security of user identity authentication.
[0020] 2. The real-time security value is judged by using the security threshold to obtain whether there is a security risk during the user's real-time identity authentication. It can not only check the security of the user's identity authentication, but also formulate different authentication strategies according to the specific real-time scenarios and situations for different authentication situations; greatly increasing the diversity and universality of user identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a module distribution diagram of an identity authentication system based on multiple devices and multiple factors of the present invention; Figure 2 It is a step schematic diagram of an identity authentication method based on multiple devices and multiple factors of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the protection scope of the present invention.
[0023] Embodiment: As Figure 1 - Figure 2 shown, the present invention provides a technical solution, An identity authentication method based on multiple devices and multiple factors, the method includes the following steps: S100. For all the identity authentication methods in the acquisition device, for each identity authentication method, collect the historical authentication records, extract all the authentication data, and calculate the security value of each identity authentication method based on the historical authentication data; The specific steps for calculating the security value of each identity authentication method based on the historical authentication data are as follows: S101. For all the identity authentication methods in the acquisition device, for each identity authentication method, collect the historical authentication records, and extract all the authentication data as {S 1 、S 2 、S 3 、...、S n}, where S 1 、S 2 、S 3 、...、S n represent the 1st, 2nd, 3rd,..., nth kinds of authentication data extracted, and n is a positive integer; assume that the number of historical authentication records collected is M times, screen out the records of successful authentication and failed authentication, compare the same kind of authentication data in the records of successful authentication and failed authentication, and subtract the authentication data of failed authentication from the authentication data of successful authentication; when the difference of the same kind of authentication data between successful authentication and failed authentication is not zero, determine the corresponding authentication data as the influencing data; and judge the sign of the difference of the influencing data. When the difference sign is positive, it is defined as positive influencing data; when the difference sign is negative, it is defined as negative influencing data; S102. Extract the influencing data for different identity authentication methods, and calculate the security value of different identity authentication methods. The formula is: ; In the formula, An represents the security value of the identity authentication method, S + i represents the ith kind of positive influencing data, S - j represents the jth kind of negative influencing data, a represents the total number of positive influencing data, and b represents the total number of negative influencing data; S103. Use the same method to calculate the security degrees of all the identity authentication methods collected as {An 1 、An 2 、An 3 、...、An c}, where An 1 、An 2 、An 3 、...、An c represent the security values of the 1st, 2nd, 3rd,..., cth kinds of identity authentication methods calculated, and c is a positive integer.
[0024] Calculate the security value of each authentication method based on the authentication data when users authenticate their identities in history, which can clearly express the security of each authentication method. When users authenticate their identities, formulate an authentication strategy that combines multiple authentication methods reasonably according to the security, which greatly ensures the efficiency and security of user identity authentication.
[0025] S200. Collect the behavior data of different users when they authenticate their identities in history, calculate the adaptability of each authentication method to different users, and construct an adaptation method set for each user; The specific steps to construct the adaptation method set for each user are as follows: S201. Collect the behavior data of different users when they authenticate their identities in history. The behavior data includes the number of times of using different authentication methods, authentication time, and authentication success rate in the user's history; calculate the adaptability by weighted summation of the three behavior data, and the formula is: ; In the formula, Fit represents the adaptability of the authentication method, α 1 、α 2 and α 3 respectively represent the weights of the number of times of use, authentication time, and authentication success rate, C represents the number of times of use, T represents the authentication time, and P represents the authentication success rate; S202. For the same user, calculate the adaptability of the user to different authentication methods as {Fit 1 、Fit 2 、Fit 3 、...、Fit c}, Fit 1 、Fit 2 、Fit 3 、...、Fit c represent the adaptability of the user to the 1st, 2nd, 3rd,..., cth authentication methods. Arrange the adaptability of all authentication methods in ascending order, calculate the difference between adjacent adaptabilities, and obtain c - 1 adaptability differences. Select the adaptability threshold as the previous adaptability in the largest difference, and construct an adaptation method set using all authentication methods with adaptability greater than the adaptability threshold as {SH 1 、SH 2 、SH 3 、...、SH d}, SH 1 、SH 2 、SH 3 、...、SH d represent the 1st, 2nd, 3rd,..., dth authentication methods in the adaptation method set, where d is a positive integer and d ≤ c; S203. Calculate the behavioral data of all user histories during identity authentication for the devices used, and construct an adaptation method set for each user.
[0026] Based on the behavioral data in the user history, construct an adaptation method set for each type of user, find the identity authentication method suitable for each user, make it more user-oriented when specifying the identity authentication policy, enhance the user experience, and achieve a personalized authentication method.
[0027] S300. Collect the device data during historical user identity authentication, compare the device data when authentication is successful and failed, and extract the dangerous data that affects user identity verification from the device data; The specific steps to extract the dangerous data that affects identity authentication are as follows: S301. Collect the device data during historical user identity authentication, and calculate the difference between each device data when identity authentication is successful and failed as {Zc 1 、Zc 2 、Zc 3 、...、Zc u}, Zc 1 、Zc 2 、Zc 3 、...、Zc u represents the differences between the 1st, 2nd, 3rd,..., u-th types of device data when identity authentication is successful and failed, where u is a positive integer; calculate the standard deviation of the u differences as IZc; S302. Use the calculated difference standard deviation to judge the differences of all devices. When Zc > IZc, judge the corresponding device data as dangerous data. When Zc ≤ IZc, judge it as non-dangerous data; after judging all device data, the dangerous data obtained is {W 1 、W 2 、W 3 、...、W r}, W 1 、W 2 、W 3 、...、W r represents the 1st, 2nd, 3rd,..., r-th types of dangerous data obtained by judgment, where r is a positive integer and r < u.
[0028] S400. Process the extracted dangerous data, convert it into a feature vector of the same dimension, map the security value of each identity authentication method, analyze the influence of the feature vector on the security value of each identity authentication method, and use machine learning to construct a risk identification model; The specific steps to construct a risk identification model using machine learning are as follows: S401. Process the extracted dangerous data and convert it into a feature vector of the same dimension. The formula is: ; In the formula, Wn represents the transformed feature vector, W represents the extracted dangerous data, min(W) represents the minimum value among the extracted dangerous data, and max(W) represents the maximum value among the extracted dangerous data; S402. Map the security values of each identity authentication method, analyze the influence of the feature vector on the security values of each identity authentication method. Take the feature vector as the independent variable and the security value of each identity authentication method as the variable, plot a curve graph, and fit the curve graph to obtain the influence polynomial of the feature vector on the security value of each identity authentication method. Assume the form of the polynomial is , β 0 is the constant term, and β 0 to β r represent the coefficients of the 1st to the rth feature vectors; S403. Repeat the steps for each identity authentication method to obtain the polynomial for each identity authentication method; collect the security values at the time of identity authentication failure in history, calculate the average value and the standard deviation, subtract the standard deviation from the average value to obtain the danger threshold, and construct the risk identification model as: , where Ay represents the danger threshold.
[0029] S500. Extract the identity authentication method with the highest adaptability in the adaptation method set of each user as the default method for the corresponding user. When the user performs identity authentication using the default method, collect real-time dangerous data and input it into the risk identification model to judge the user's real-time identity authentication; The specific steps for judging the user's real-time identity authentication are as follows: S501. Extract the identity authentication method with the highest adaptability in the adaptation method set of each user as the default method for the corresponding user. When the user performs identity authentication using the default method, collect real-time dangerous data and input it into the risk identification model, and calculate the real-time security values {Ans 1 , Ans 2 , Ans 3 ,..., Ans d} of all identity authentication methods in the user's adaptation method set. Ans 1 , Ans 2 , Ans 3 ,..., Ans d represent the real-time security values of the 1st, 2nd, 3rd,..., dth identity authentication methods in the user's adaptation method set. Extract the real-time security value Mans of the user's default method, and judge the real-time security value of the default method in the risk identification model. When Mans < Ay, it is judged that there is a risk in the user's real-time identity authentication; when Mans ≥ Ay, it is judged that there is no risk in the user's real-time identity authentication.
[0030] Judging the real-time security value using a security threshold to obtain whether there is a security risk during the user's real-time identity authentication can not only check the security of the user's identity authentication, but also formulate different authentication strategies for different authentication situations according to the specific real-time scenarios and circumstances, greatly increasing the diversity and universality of user identity authentication.
[0031] S600. According to the analysis result of the user's real-time dangerous data by the risk identification model, adjust the user's identity authentication method using the user's adaptation method set and the security value of each identity authentication.
[0032] The specific steps of adjusting the user's identity authentication method using the user's adaptation method set and the security value of each identity authentication are as follows: S601. After judging that there is a risk in the user's real-time identity authentication, add identity authentication methods in the user's adaptation method set according to the order of adaptation degree, and calculate the real-time security value after addition. The formula is: ; In the formula, TAn represents the security value after adding the identity authentication method, tAn represents the security value of the added identity authentication method, and add identity authentication methods in sequence until TAn is greater than Ay to end.
[0033] When adding the user's real-time identity authentication method, not only consider whether there is a risk, but also consider whether it is suitable for the user. Add identity authentication methods from both aspects, increasing the user's usage experience on the basis of ensuring the security of identity authentication.
[0034] An identity authentication system based on multiple devices and multiple factors. The identity authentication system includes a data collection module, a security value calculation module, an adaptation method set construction module, a dangerous data search module, a model construction module, a real-time calculation module, and a method addition module; The data collection module is used to collect the records of the user's identity authentication in history; The security value calculation module is used to extract all authentication data and calculate the security value of each identity authentication method according to the historical authentication data; The adaptation method set construction module is used to calculate the adaptation degree of each identity authentication method and different users, and construct the adaptation method set of each user; The dangerous data search module is used to compare the device data when authentication is successful and failed, and extract the dangerous data that affects the user's identity verification from the device data; The model construction module is used to analyze the influence of the feature vector on the security value of each identity authentication method, and construct a risk identification model using machine learning; The real-time calculation module is used to collect real-time dangerous data and input it into the risk identification model, and calculate the real-time security values of all identity authentication methods in the adaptation method set; The method addition module is used to judge the real-time security value and add the method of real-time identity authentication of the user.
[0035] The model construction module includes a polynomial calculation unit and a model construction unit; The polynomial calculation unit is used to map the security values of each identity authentication method, analyze the influence of the feature vector on the security value of each identity authentication method, draw a curve and fit to obtain a polynomial for the influence of dangerous data on the security value; The model construction unit is used to collect the security values at the time of identity authentication failure in history, calculate the average value and the standard deviation, subtract the standard deviation from the average value to obtain a danger threshold, and construct a risk identification model.
[0036] The real-time calculation module includes a real-time security value calculation unit and a judgment unit; The real-time security value calculation unit is used to collect real-time dangerous data and calculate the real-time security values of all identity authentication methods in the adaptation method set by using polynomials; The judgment unit is used to extract the real-time security value of the default method and judge the real-time security value of the default method by using the security threshold.
[0037] Embodiment: Now analyze the identity authentication of a certain device. Suppose there are three methods for the device: SMS authentication, fingerprint authentication, and face authentication; according to the authentication data of users in history, the influencing data are complexity and information volume; construct a security value calculation method for the three authentication methods, and calculate the security values of the three authentication methods under the same device data; First, there is a user 1. Calculate the adaptation degrees of the three authentication methods, and obtain that the adaptation method set of user 1 includes SMS authentication and face authentication; Collect the device data in historical authentication, and find that the dangerous data are the number of authenticated devices and the authentication frequency; calculate the polynomials of the three authentication methods. For example, the polynomial of SMS authentication is An = 1.2 + 2.3×Wn 1 +0.3×Wn 2 ; Suppose the default method of user 1 is SMS authentication, and calculate the real-time security values in the adaptation method set to be 18 and 25; where the SMS authentication is 18, and the calculated security threshold is 30; judge that there is a risk in the real-time identity authentication of user 1; Add face authentication in the adaptation method set, and calculate the security value after addition to be 43; judge that it is greater than the security threshold and can be authenticated.
[0038] It is obvious to those skilled in the art that the present invention is not limited to the details of the above-described exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention. Therefore, in any respect, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be embraced within the present invention. Any reference signs in the claims should not be construed as limiting the claims involved.
Claims
1. A multi-device multi-factor identity authentication method, characterized in that: The method comprises the following steps: S100, collecting all identity authentication methods existing in the device, collecting historical authentication records for each identity authentication method, extracting all authentication data, and calculating the security value of each identity authentication method based on the historical authentication data; S200, collecting the behavior data of different users during identity authentication in history, calculating the suitability of each identity authentication method and different users, and constructing a set of adaptation methods for each user; S300, collecting device data during historical user identity authentication, comparing device data during successful authentication and failed authentication, and extracting dangerous data that affects user identity authentication from the device data; S400, processing the extracted risk data, converting it into a feature vector of the same dimension, mapping the security value of each identity authentication method, analyzing the impact of the feature vector on the security value of each identity authentication method, and building a risk identification model using machine learning; S500, extracting the identity authentication method with the highest adaptability from the set of adaptation methods for each user as the default method for the corresponding user, and when the user uses the default method for identity authentication, collecting real-time risk data and inputting it into the risk identification model to judge the user's real-time identity authentication; S600: According to the analysis result of the risk identification model on the real-time risk data of the user, the user's identity authentication method is adjusted by using the user's adaptation method set and the security value of each identity authentication.
2. The identity authentication method based on multiple devices and multiple factors according to claim 1, characterized in that: The specific steps of calculating the security value of each identity authentication method according to the historical authentication data in S100 are: S101, collect all identity authentication methods existing in the device, collect historical authentication records for each identity authentication method, and extract all authentication data as {S1, S2, S3, ..., S n }, S1, S2, S3, ..., S n represents the first, second, third, ..., nth authentication data extracted, where n is a positive integer; suppose the number of historical authentication records collected is M, filter out the records of successful authentication and failed authentication, compare the same authentication data in the successful authentication and failed authentication records, and subtract the failed authentication data from the successful authentication data; When the difference between the same authentication data when the authentication succeeds and fails is not zero, the corresponding authentication data is judged as the influencing data; and the sign of the influencing data difference is judged. When the difference sign is positive, it is defined as positive influencing data; when the difference sign is negative, it is defined as negative influencing data; S102. Extract impact data for different identity authentication methods and calculate the security values of different identity authentication methods. The formula is: ; In the formula, An represents the security value of the identity authentication method, S + i represents the i-th positive impact data, S - j represents the jth negative impact data, a represents the total number of positive impact data, and b represents the total number of negative impact data; S103, using the same method to calculate the security of all the collected identity authentication methods is {An1, An2, An3, ..., An c }, An1, An2, An3,..., An c Represents the calculated security value of the 1st, 2nd, 3rd, ..., cth identity authentication method, where c is a positive integer.
3. The identity authentication method based on multiple devices and multiple factors according to claim 1, characterized in that: The specific steps of constructing the adaptation mode set for each user in S200 are: S201. Collect the behavior data of different users during identity authentication in history, the behavior data includes the number of times different identity authentication methods are used in the user history, the authentication time and the authentication success rate; calculate the fitness by weighted sum of the three behavior data, the formula is: ; In the formula, Fit represents the fitness of the identity authentication method, α1, α2, and α3 represent the weights of the number of uses, authentication time, and authentication success rate, respectively, C represents the number of uses, T represents the authentication time, and P represents the authentication success rate; S202: For the same user, the degree of fit between the user and different identity authentication methods is calculated as {Fit1, Fit2, Fit3, ..., Fit c }, Fit1, Fit2, Fit3,..., Fit c Represents the fitness of the user and the 1st, 2nd, 3rd, ..., cth identity authentication method. Arrange the fitness of all identity authentication methods in ascending order, calculate the difference of adjacent fitness, get c-1 fitness differences, select the previous fitness in the maximum difference as the fitness threshold, and use all identity authentication methods with fitness greater than the fitness threshold to construct the adaptation method set {SH1, SH2, SH3, ..., SH d }, SH1, SH2, SH3,..., SH d represents the 1st, 2nd, 3rd, ..., dth identity authentication method in the adaptation method set, where d is a positive integer, d≤c; S203: Calculate the behavioral data army for identity authentication in the history of all users who use the device, and construct an adaptation method set for each user.
4. The identity authentication method based on multiple devices and multiple factors according to claim 1, characterized in that: The specific steps of extracting dangerous data that affects identity authentication in S300 are: S301, collect the device data of historical user identity authentication, calculate the difference between each device data when the identity authentication succeeds and fails, and calculate {Zc1, Zc2, Zc3, ..., Zc u }, Zc1, Zc2, Zc3,..., Zc u It represents the calculated difference between the 1st, 2nd, 3rd, ..., uth device data when the identity authentication succeeds and fails, where u is a positive integer; the standard deviation of the calculated uth difference is IZc; S302, using the calculated standard deviation of the difference to judge the difference of all devices, when Zc>IZc, the corresponding device data is judged as dangerous data, when Zc≤IZc, it is judged not to be dangerous data; after judging all the device data, the dangerous data is {W1, W2, W3, ..., W r }, W1, W2, W3, ..., W r represents the first, second, third, ..., rth type of dangerous data obtained by judgment, r is a positive integer, and r <u。 5. The identity authentication method based on multiple devices and multiple factors according to claim 1, characterized in that: The specific steps of using machine learning to build a risk identification model in S400 are: S401. Process the extracted dangerous data and convert it into a feature vector of the same dimension. The formula is: ; In the formula, Wn represents the transformed feature vector, W represents the extracted dangerous data, min(W) represents the minimum value in the extracted dangerous data, and max(W) represents the maximum value in the extracted dangerous data; S402, mapping the security value of each identity authentication method, analyzing the influence of the characteristic vector on the security value of each identity authentication method, taking the characteristic vector as an independent variable and the security value of each identity authentication method as a variable, drawing a curve graph, fitting the curve graph, and obtaining a polynomial of the influence of the characteristic vector on the security value of each identity authentication method, assuming that the form of the polynomial is, β0 is a constant term, β0 to β r Represents the coefficients of the 1st to rth eigenvectors; S403. Repeat the steps for each identity authentication method to obtain a polynomial for each identity authentication method; collect the security values when the identity authentication fails in history, calculate the average value and standard deviation, subtract the standard deviation from the average value to obtain the danger threshold, and construct a risk identification model: , Ay represents the danger threshold.
6. The identity authentication method based on multiple devices and multiple factors according to claim 1, characterized in that: The specific steps of determining the real-time user identity authentication in S500 are: S501. Extract the identity authentication method with the highest adaptation degree in the adaptation method set of each user as the default method for the corresponding user. When the user performs identity authentication using the default method, collect real-time risk data and input it into the risk recognition model, and calculate the real-time security values {Ans1, Ans2, Ans3, ..., Ans d} of all identity authentication methods in the user adaptation method set. Ans1, Ans2, Ans3, ..., Ans d represent the real-time security values of the 1st, 2nd, 3rd, ..., dth identity authentication methods in the user adaptation method set. Extract the real-time security value of the user's default method as Mans, and judge the real-time security value of the default method in the risk recognition model. When Mans < Ay, it is judged that the user's real-time identity authentication is at risk; when Mans ≥ Ay, it is judged that the user's real-time identity authentication is not at risk.
7. The identity authentication method based on multiple devices and multiple factors according to claim 1, characterized in that: The specific steps of adjusting the user's identity authentication method by using the user's adaptation method set and the security value of each identity authentication in S600 are: S601. When it is determined that there is a risk in the real-time identity authentication of the user, the identity authentication method is added to the user's adaptation method set in the order of the size of the adaptation degree, and the real-time security value after the addition is calculated. The formula is: ; In the formula, TAn represents the security value after adding the identity authentication method, tAn represents the security value of the added identity authentication method, and the identity authentication methods are added in sequence until TAn is greater than Ay.
8. An identity authentication system based on multiple devices and multiple factors, characterized by: The identity authentication system includes a data collection module, a security value calculation module, an adaptation mode set construction module, a dangerous data search module, a model construction module, a real-time calculation module and a mode addition module; The data collection module is used to collect historical records of user identity authentication; The security value calculation module is used to extract all authentication data and calculate the security value of each identity authentication method based on the historical authentication data; The adaptation mode set building module is used to calculate the adaptability of each identity authentication mode and different users, and build an adaptation mode set for each user; The dangerous data search module is used to compare the device data when the authentication succeeds and fails, and extract the dangerous data that affects the user's identity authentication from the device data; The model building module is used to analyze the impact of feature vectors on the security value of each identity authentication method and build a risk identification model using machine learning; The real-time calculation module is used to collect real-time danger data and input it into the risk identification model to calculate the real-time security values of all identity authentication methods in the adaptation method set; The method adding module is used to judge the real-time security value and add a method for real-time user identity authentication.
9. The identity authentication system based on multiple devices and multiple factors according to claim 8, characterized in that: The model building module includes a polynomial calculation unit and a model building unit; The polynomial calculation unit is used to map the security value of each identity authentication method, analyze the influence of the characteristic vector on the security value of each identity authentication method, draw a curve and fit to obtain a polynomial of the influence of dangerous data on the security value; The model building unit is used to collect security values when identity authentication fails in history, calculate the average value and standard deviation, subtract the standard deviation from the average value to obtain the danger threshold, and build a risk identification model.
10. The identity authentication system based on multiple devices and multiple factors according to claim 8, characterized in that: The real-time calculation module includes a real-time safety value calculation unit and a judgment unit; The real-time security value calculation unit is used to collect real-time danger data and calculate the real-time security values of all identity authentication methods in the adaptation method set using polynomials; The judgment unit is used to extract the real-time security value of the default mode and judge the real-time security value of the default mode by using the security threshold.
Citation Information
Patent Citations
Transaction method and device
CN110956548A
Web log auditing method and device and medium
CN111314302A
System and method for adaptively determining an optimal authentication scheme
CN113383333A
Network security communication control method and system based on Internet of Things
CN117834301A
Customer identity authentication method based on browser fusion
CN118395419A