Optimization method based on mobile communication key security
By generating the exception index Yczs and combining preset threshold comparison, multiple levels of abnormal risk strategy solutions are formed, which solves security threats such as man-in-the-middle attacks and weak passwords in Bluetooth payments, and effectively monitors and protects user transactions and assets.
Patent Information
- Application Number
- CN202411908847.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-05-30
AI Technical Summary
During the Bluetooth payment process, the existing technology has security threats such as man-in-the-middle attacks and weak passwords, resulting in the risk of leakage of users' payment information and personal information.
Through steps such as data collection, processing, abnormal matching and risk calculation, anomaly index Yczs is generated, combined with preset threshold comparison, anomaly risk strategy schemes of multiple levels are formed, and users are reminded and secondary verification, as well as related transaction restrictions to realize monitoring and early warning of transaction activities.
Effectively respond to the security problems that may arise in the Bluetooth payment process by users, protect the security of users' transactions more targetedly, and reduce the risk of property and personal information leakage.
Smart Images

Figure CN120075803A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of mobile communication, and specifically to an optimization method based on the security of mobile communication keys. Background Art
[0002] With the popularization and development of the Internet, the communication methods in the digital society are becoming increasingly diverse and complex. In this digital age, the Internet connects the world and provides people with convenient information transmission and communication channels. However, this convenience is accompanied by security risks. As the amount of information transmission increases, the opportunities to threaten network security also increase. Mobile communication, as an important part of the Internet, carries people's communication needs and has gradually become the core of life and business. In mobile communication, ensuring the security of communication is crucial, and communication keys play a key role.
[0003] Among them, Bluetooth payment is a convenient payment method. Although the key method provides security in mobile communication, in specific situations, there are still potential vulnerabilities and deficiencies that may lead to security threats. Bluetooth connections may be threatened by man-in-the-middle attacks. Attackers may try to intervene during Bluetooth communication, including intercepting or tampering with payment data, and the key exchange and authentication between the two parties are not sufficient to prevent this situation.
[0004] Secondly, Bluetooth payment may be threatened by weak passwords and insecure key management. If users choose weak passwords or mismanage keys, attackers may easily guess or crack the passwords, thereby gaining access to payment information and stealing users' property or personal sensitive information. Summary of the Invention
[0005] (I) Technical Problems to be Solved
[0006] In view of the deficiencies of the prior art, the present invention provides an optimization method based on the security of mobile communication keys, which solves the problems mentioned in the background art.
[0007] (II) Technical Solutions
[0008] To achieve the above objectives, the present invention is implemented through the following technical solutions: An optimization method based on the security of mobile communication keys, including the following steps:
[0009] S1. Data collection: Transaction details, user information, device information, and network information. Integrate transaction details and user information into a user transaction information set, and integrate device information and network information into a user device information set;
[0010] S2. Data Processing: Obtain the user transaction information set and the user device information set for data processing, including outlier monitoring and normalization processing, to form a first transaction data set and a second device data set;
[0011] S3. Anomaly Matching: Obtain the first transaction data set and the second device data set, and use preset tags to match them to identify the anomaly behavior frequency value, and obtain a transaction frequency data set and a device frequency data set;
[0012] S4. Risk Calculation: Obtain the transaction frequency data set and the device frequency data set, select a risk model, establish a model for the transaction frequency data set and the device frequency data set, and perform training and calculation to obtain: an anomaly index Yczs;
[0013] The anomaly index Yczs is obtained through the following formula:
[0014] Yczs = [(Jyxs * A ) + ( Sbxs * B)] * 100% + C;
[0015] In the formula, Jyxs represents the transaction coefficient, Sbxs represents the device coefficient, A represents the weight value of the transaction coefficient Jyxs, B represents the weight value of the device coefficient Sbxs, and C represents the correction constant;
[0016] The transaction coefficient Jyxs is calculated through the transaction frequency data set;
[0017] The device coefficient Sbxs is calculated through the device frequency data set;
[0018] S5. Anomaly Evaluation: Compare the obtained anomaly index Yczs with a preset threshold to obtain a hierarchical anomaly risk strategy plan;
[0019] S6. Execution Record: Obtain the content of the hierarchical anomaly risk strategy plan, and according to the content, give reminders and verifications to the user, as well as impose relevant transaction restrictions.
[0020] Preferably, the transaction details include transaction amount, frequent transactions, transaction timestamp, transaction location, transaction type, and the number of daily transactions with the same payee;
[0021] User information includes user ID, account history, and login location;
[0022] Device information includes device ID, device type, operating system version, emulator running status, device lock status, and device health status;
[0023] Network information includes Wi-Fi connection, cellular data connection, and mobile network connection.
[0024] Preferably, outlier detection is performed on the user transaction information set to identify and process abnormal transaction behaviors, including payment anomalies, transaction time anomalies, transaction frequency anomalies, and geographical location anomalies, and normalization processing is performed to form the first transaction data set;
[0025] Outlier detection is performed on the user device information set to identify and process device-related abnormal behaviors, including network anomalies, device anomalies, operating system anomalies, and running anomalies, and normalization processing is performed to form the second device data set.
[0026] Preferably, the transaction frequency data set includes: the payment anomaly label frequency value Zfyc, the transaction time anomaly label frequency value Jysj, the transaction frequency label frequency value Jypl, and the geographical location label frequency value Dlwz;
[0027] The device frequency data set includes: the network anomaly label frequency value Wlyc, the device anomaly label frequency value Sbyc, the operating system anomaly label frequency value Czxt, and the running anomaly label frequency value Yxyc.
[0028] Preferably, the risk model includes decision trees, random forests, neural networks, logistic regression, cluster analysis, and time series models;
[0029] Calculations are performed on the transaction frequency data set and the device frequency data set through the selected model to obtain: the transaction coefficient Jyxs and the device coefficient Sbxs, and then calculations are performed on the transaction coefficient Jyxs and the device coefficient Sbxs to obtain: the anomaly index Yczs.
[0030] Preferably, the transaction coefficient Jyxs is obtained through the following formula:
[0031] Jyxs = [(Zfyc * n)+(Jysj * x)+(Jypl * z)+(Dlwz * d)] * 100% + E;
[0032] In the formula, n, x, z, and d respectively represent the weight values of the payment anomaly label frequency value Zfyc, the transaction time anomaly label frequency value Jysj, the transaction frequency label frequency value Jypl, and the geographical location label frequency value Dlwz;
[0033] Among them, 0.16 ≤ n ≤ 0.25, 0.12 ≤ x ≤ 0.28, 0.13 ≤ z ≤ 0.22, 0.14 ≤ d ≤ 0.25, where n + x + z + d ≤ 1.0, and E represents a correction constant.
[0034] Preferably, the device coefficient Sbxs is obtained through the following formula:
[0035] Sbxs = [(Wlyc * f) + (Sbyc * g) + (Czxt * h) + (Yxyc * j)] * 100% + M;
[0036] In the formula, f, g, h, and j respectively represent the weight values of the network anomaly label frequency value Wlyc, the device anomaly label frequency value Sbyc, the operating system anomaly label frequency value Czxt, and the running anomaly label frequency value Yxyc;
[0037] Among them, 0.13 ≤ f ≤ 0.25, 0.15 ≤ g ≤ 0.25, 0.16 ≤ h ≤ 0.26, 0.14 ≤ j ≤ 0.24, and f + g + h + j ≤ 1.0. M represents the correction constant.
[0038] Preferably, by comparing the anomaly index Yczs with the preset threshold Q and the preset threshold V, multiple levels of anomaly risk strategy solutions are formed;
[0039] When the anomaly index Yczs < the preset threshold Q, a low-risk evaluation is obtained, and the transaction and the device are regarded as low-risk. In this case, the transaction and device information are monitored, and normal trading activities continue without restrictions or reminders;
[0040] When the preset threshold Q ≤ the anomaly index Yczs ≤ the preset threshold V, a medium-risk evaluation is obtained, and the transaction and the device are regarded as medium-risk. In this case, the transaction and device information are monitored, a pop-up window appears for the trading activity, and the reading of the trading security protocol is restricted. After six seconds, click to close;
[0041] When the preset threshold V < the anomaly index Yczs, a high-risk evaluation is obtained, and the user is notified by an emergency pop-up window, and the reading of the trading security protocol is restricted, informing them of serious security problems, immediately stopping or rejecting the trading activity, temporarily freezing the user's account, and prompting to change the user password and payment password.
[0042] Preferably, according to the content of the anomaly risk strategy solution, specific reminders and verifications are carried out for the user, including: in-app messages, real-time pop-up windows, emails, and text messages to notify the user, and for secondary verification: re-entering the trading password, and related trading restrictions to protect the user's assets, including: suspending transactions: temporarily stopping all transactions to prevent further potential risks;
[0043] Assisting the user: According to the provided emergency contact information, send relevant information to the emergency contact to remind the emergency contact to assist the user in distinguishing abnormal activities;
[0044] Freezing the account: During a detailed security investigation, freeze the user's account to prevent unauthorized access;
[0045] Restoring access: When the abnormal problem is solved, help the user restore normal access and trading.
[0046] Preferably, through the key method of mobile network communication, first, a unique password is used for identity confirmation. Then, during the Bluetooth payment activity, we obtain relevant information and use this information for abnormal detection to warn and monitor transaction activities. The key method of mobile network communication is used as a prerequisite in this process. In terms of determining the signal for network registration, this process ensures the security of payment and identifies potential risks in a timely manner to protect users' transactions and assets. The specific steps include:
[0047] Process 1: A new SIM card appears;
[0048] Process 2: SIM card registration and base station location signal location determination;
[0049] Process 3: Determine SIM uniqueness: Enter the system, query the SIM card track, and query the uniqueness;
[0050] Process 4: Determine whether it is a new SIM card. If it is a new SIM card: if it matches the track in the system, the SIM card is brought online and marked. If it is not a new SIM card, it is marked as an abnormal SIM, thereby preventing network access.
[0051] (III) Beneficial effects
[0052] The present invention provides an optimization method based on mobile communication key security, which has the following beneficial effects:
[0053] (1) In the method of the present invention, through steps S1 to S6, information data is collected on the process of users performing Bluetooth payment, and the user transaction information set and the user device information set are integrated. The obtained user transaction information set and the user device information set are then subjected to data monitoring and normalization processing to form a first transaction data set and a second device data set, and matched with preset tags to obtain abnormal behavior frequency values. The transaction frequency data set and the device frequency data set are integrated, and then a model is established and calculated to obtain: an abnormality index Yczs. By comparing the abnormality index Yczs with a preset threshold, a graded abnormality risk strategy solution is obtained, and according to the content of the graded abnormality risk strategy solution, the user is reminded and verified twice, and related transaction restrictions are imposed to achieve monitoring and early warning of transaction activities, thereby protecting the property safety and personal information security of the user.
[0054] (2) Through the use of multiple levels of abnormal risk strategy solutions, it is possible to effectively deal with security issues that may arise when users make Bluetooth payments. The strategy solution content covers situations with different risk levels, thereby protecting the user's transaction security in a more targeted manner, thereby protecting the user's transaction security and minimizing the possibility of property and personal information leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] Figure 1 Schematic diagram of the steps of the optimization method based on mobile communication key security of the present invention;
[0056] Figure 2 Schematic diagram of the steps of the mobile communication key network access registration process of the present invention; Detailed implementation manners
[0057] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0058] With the popularization and development of the Internet, the communication methods in the digital society are becoming increasingly diverse and complex. In this digital age, the Internet connects the world and provides people with convenient information transmission and communication channels. However, this convenience is also accompanied by security risks. As the amount of information transmission increases, the opportunities threatening network security also increase. Mobile communication, as an important part of the Internet, bears people's communication needs and gradually becomes the core of life and business. In mobile communication, ensuring the security of communication is crucial, and the communication key plays a key role among them.
[0059] Among them, Bluetooth payment is a convenient payment method. Although the key method provides security in mobile communication, in specific situations, there are still potential vulnerabilities and deficiencies, which may lead to security threats. Bluetooth connections may be threatened by man-in-the-middle attacks. An attacker may try to insert himself in the middle of the Bluetooth communication, intercept or tamper with payment data, and the key exchange and authentication between the two parties are not sufficient to prevent this situation.
[0060] Secondly, Bluetooth payment may be threatened by weak passwords and insecure key management. If users choose weak passwords or mismanage keys, attackers may easily guess or crack the passwords, thereby obtaining access to payment information and stealing users' property or personal sensitive information.
[0061] Embodiment 1
[0062] The present invention provides an optimization method based on mobile communication key security. Please refer to Figure 1 , including the following steps:
[0063] S1. Data collection: Transaction details, user information, device information, and network information. Integrate the transaction details and user information into a user transaction information set, and integrate the device information and network information into a user device information set;
[0064] S2. Data processing: Obtain the user transaction information set and the user device information set for data processing, including outlier monitoring and normalization processing, to form a first transaction data set and a second device data set;
[0065] S3. Anomaly matching: Obtain the first transaction data set and the second device data set, and use preset tags to match them to identify the anomaly behavior frequency value, and obtain a transaction frequency data set and a device frequency data set;
[0066] S4. Risk calculation: Obtain the transaction frequency data set and the device frequency data set, select a risk model, establish a model for the transaction frequency data set and the device frequency data set, and perform training and calculation to obtain: an anomaly index Yczs;
[0067] The anomaly index Yczs is obtained through the following formula:
[0068] Yczs = [(Jyxs * A ) + ( Sbxs * B)] * 100% + C;
[0069] In the formula, Jyxs represents the transaction coefficient, Sbxs represents the device coefficient, A represents the weight value of the transaction coefficient Jyxs, B represents the weight value of the device coefficient Sbxs, and C represents the correction constant;
[0070] Among them, 0.35 ≤ A ≤ 0.68, 0.21 ≤ B ≤ 0.32, and among them, A + B ≤ 1.0;
[0071] The transaction coefficient Jyxs is calculated through the transaction frequency data set;
[0072] The device coefficient Sbxs is calculated through the device frequency data set;
[0073] S5. Anomaly evaluation: Compare the obtained anomaly index Yczs with a preset threshold to obtain a hierarchical anomaly risk strategy plan;
[0074] S6. Execution record: Obtain the content of the hierarchical anomaly risk strategy plan, and according to the content, give reminders and verifications to the user, as well as relevant transaction restrictions.
[0075] In the method of the present invention, through steps S1 to S6, information data is collected during the process of the user's Bluetooth payment, and the user transaction information set and the user device information set are integrated. The obtained user transaction information set and user device information set are then subjected to data monitoring and normalization processing to form a transaction first data set and a device second data set, and are matched with preset tags to obtain the abnormal behavior frequency value. The transaction frequency data set and the device frequency data set are integrated, and then a model is established and calculated to obtain: the abnormal index Yczs. By comparing the abnormal index Yczs with a preset threshold, a hierarchical abnormal risk strategy plan is obtained, and according to the content of the hierarchical abnormal risk strategy plan, the user is reminded, secondarily verified, and relevant transaction restrictions are imposed to realize the monitoring and early warning of transaction activities, thereby protecting the user's property safety and personal information safety.
[0076] Embodiment 2
[0077] This embodiment is an explanatory description carried out in Embodiment 1. Please refer to Figure 1 , specifically: Transaction details, including transaction amount, frequent transactions, transaction timestamp, transaction location, transaction type, and the number of daily transactions with the same payee;
[0078] User information, including user ID, account history, and login location;
[0079] Device information, including device ID, device type, operating system version, emulator running status, device lock status, and device health status;
[0080] Network information, including Wi-Fi connection, cellular data connection, and mobile network connection.
[0081] Outlier detection is performed on the user transaction information set to identify and process abnormal transaction behaviors, including payment anomalies, transaction time anomalies, transaction frequency anomalies, and geographical location anomalies, and normalization processing is carried out to form the transaction first data set;
[0082] Payment anomalies include: large payments and frequent small payments;
[0083] Transaction time anomalies include: sudden changes in transaction time and abnormal transaction times;
[0084] Transaction frequency anomalies include: sudden increases in the number of transactions and sudden drops in the number of transactions;
[0085] Geographical location anomalies include: transactions at different geographical locations in a short period of time;
[0086] Outlier detection is performed on the user device information set to identify and process device-related abnormal behaviors, including network anomalies, device anomalies, operating system anomalies, and running anomalies, and normalization processing is carried out to form the device second data set;
[0087] Network anomalies include: abnormal network, abnormal VPN connection, and abnormal public WI-Fi connection;
[0088] Device anomalies include: presence of malware and unknown processes running in the background;
[0089] Operating system anomalies include: outdated operating system version, presence of known security vulnerabilities, and running of an unauthorized operating system version;
[0090] Running anomalies include: the device has been rooted or jailbroken and the security settings of the device have been disabled or turned off.
[0091] The transaction frequency dataset includes: payment anomaly label frequency value Zfyc, transaction time anomaly label frequency value Jysj, transaction frequency label frequency value Jypl, and geographical location label frequency value Dlwz;
[0092] The device frequency dataset includes: network anomaly label frequency value Wlyc, device anomaly label frequency value Sbyc, operating system anomaly label frequency value Czxt, and running anomaly label frequency value Yxyc.
[0093] The risk model includes decision tree, random forest, neural network, logistic regression, cluster analysis, and time series model;
[0094] Calculating the transaction frequency dataset and the device frequency dataset through the selected model to obtain: the transaction coefficient Jyxs and the device coefficient Sbxs, and then calculating the transaction coefficient Jyxs and the device coefficient Sbxs to obtain: the anomaly index Yczs.
[0095] Embodiment 3
[0096] This embodiment is an explanatory description carried out in Embodiment 1, please refer to Figure 1 , specifically: the transaction coefficient Jyxs is obtained through the following formula:
[0097] Jyxs = [(Zfyc * n) + (Jysj * x) + (Jypl * z) + (Dlwz * d)] * 100% + E;
[0098] In the formula, n, x, z, and d respectively represent the weight values of the payment anomaly label frequency value Zfyc, the transaction time anomaly label frequency value Jysj, the transaction frequency label frequency value Jypl, and the geographical location label frequency value Dlwz;
[0099] Among them, 0.16 ≤ n ≤ 0.25, 0.12 ≤ x ≤ 0.28, 0.13 ≤ z ≤ 0.22, 0.14 ≤ d ≤ 0.25, where a + b + c + d ≤ 1.0, and E represents a correction constant.
[0100] The equipment coefficient Sbxs is obtained by the following formula:
[0101] Sbxs=[(Wlyc*f)+(Sbyc*g)+(Czxt*h)+(Yxyc*j)]*100%+M;
[0102] Where, f, g, h and j represent the weight values of the network abnormal label frequency value Wlyc, the device abnormal label frequency value Sbyc, the operating system abnormal label frequency value Czxt and the operation abnormal label frequency value Yxyc respectively;
[0103] Among them, 0.13≤f≤0.25, 0.15≤g≤0.25, 0.16≤h≤0.26, 0.14≤j≤0.24, among which, f+g+h+j≤1.0, and M represents a correction constant.
[0104] By comparing the abnormal index Yczs with the preset threshold Q and the preset threshold V, multiple levels of abnormal risk strategy solutions are formed;
[0105] Abnormal index Yczs < preset threshold Q, low risk evaluation is obtained, and the transaction and equipment are considered low risk. In this case, the transaction and equipment information are monitored, and normal transaction activities continue without restrictions or reminders;
[0106] If the preset threshold Q≤abnormal index Yczs≤preset threshold V, the medium risk assessment is obtained, and the transaction and equipment are considered to be medium risk. In this case, the transaction and equipment information are monitored, and a pop-up window is displayed for the transaction activity. Please read the notification content carefully and ensure the security of your transaction activities. Please read the transaction security agreement and ensure that you understand your rights and obligations. After six seconds, click the close button to continue the transaction;
[0107] The preset threshold V < abnormal index Yczs, obtains a high-risk assessment, an emergency pop-up window notifies the user, and restricts reading of the transaction security agreement. The agreement details the security measures, informs them that there are serious security issues, immediately stops or refuses trading activities, and temporarily freezes the user's account, which will prevent any unauthorized access and transactions, and prompts to change the user password and payment password. It is strongly recommended to change the user password and payment password immediately to increase the security of the account. Please make sure that the new password is strong enough and is different from the previous password.
[0108] In this embodiment, through multiple levels of abnormal risk strategy solutions, it is possible to effectively deal with security issues that may arise when users make Bluetooth payments. The strategy solution content covers situations with different risk levels, thereby more specifically protecting the user's transaction security, and further protecting the user's transaction security and minimizing the occurrence of property and personal information leakage.
[0109] Example 4
[0110] The explanation in this example is based on Example 1. Please refer to Figure 1-2 , specifically: According to the content of the abnormal risk strategy plan, specific reminders and verifications are carried out for users, including: in-app messages, real-time pop-ups, email, and SMS to notify users, and for secondary verification: re-entering the transaction password, as well as related transaction restrictions to protect users' assets;
[0111] The transaction restrictions include: The relevant transaction restrictions include: Suspending transactions: Temporarily stopping all transactions to prevent further potential risks;
[0112] Assisting users: According to the provided emergency contact information, relevant information is sent to the emergency contact to remind the emergency contact to assist the user in distinguishing abnormal activities;
[0113] Freezing the account: During a detailed security investigation, the user's account is frozen to prevent unauthorized access;
[0114] Restoring access: Once the abnormal problem is resolved, help the user restore normal access and transactions.
[0115] Through the key method of mobile network communication, first, identity confirmation is performed using a unique password. Subsequently, during the Bluetooth payment activity, we obtain relevant information and use this information for abnormal detection to warn and monitor transaction activities. The key method of mobile network communication serves as a prerequisite in this process. In terms of determining the signal for network access registration, this process ensures the security of payments and promptly identifies potential risks to protect users' transactions and assets. The specific process includes:
[0116] Process 1: When a new SIM card is added, the mobile communication network first detects whether a new SIM card is inserted, which is completed through physical detection of the SIM card slot;
[0117] Process 2: SIM card registration and determination of the base station location signal. Once a new SIM card is detected, the system will require the SIM card to be registered. The SIM card will communicate with the network communication base station to establish a connection. At the same time, the base station will obtain the location signal of the SIM card to determine its current location to ensure that the SIM card is inserted into a regular device;
[0118] Process 3: Determine the uniqueness of the SIM card: Enter the system, query the SIM card track, and query the uniqueness. The system will check the uniqueness of the SIM card. Each SIM card has a unique identification number IMSI. The system will use this identification number to query the SIM card track and uniqueness to ensure that the SIM card is not stolen or copied;
[0119] Process 4: Determine whether it is a new SIM card. If it is a new SIM card: It matches the track in the system, perform SIM online activation and mark confirmation. The new SIM card will be authorized to go online, allowed to connect to the mobile communication network, and enjoy network services. If it is not a new SIM card, mark it as an abnormal SIM. For the case of an abnormal SIM card marked, block access to the mobile communication network to ensure security and prevent unauthorized use.
[0120] Specific example: An optimization method based on mobile communication key security used by a certain mobile terminal user will use some specific parameters and values to demonstrate how to calculate: Abnormal index Yczs, Transaction coefficient Jyxs, and Device coefficient Sbxs;
[0121] Assume the following parameter values: Assume we have the following integer parameters and values:
[0122] Zfyc Payment abnormal label frequency value = 6, Jysj Transaction time abnormal label frequency value = 7, Jypl Transaction frequency label frequency value = 5, Dlwz Geographic location label frequency value = 8, n = 0.2, x = 0.25, z = 0.2, d = 0.22, Correction constant E = 0.3;
[0123] According to the formula for calculating the transaction coefficient Jyxs:
[0124] Jyxs = [(6 * 0.2) + (7 * 0.25) + (5 * 0.2) + (8 * 0.22)] * 100% + 0.3 = 6;
[0125] Wlyc Network abnormal label frequency value = 6, Sbyc Device abnormal label frequency value = 7, Czxt Operating system abnormal label frequency value = 5, Yxyc Running abnormal label frequency value = 8, f = 0.25, g = 0.25, h = 0.23, j = 0.21, Correction constant M = 0.4;
[0126] According to the formula for calculating the device coefficient Sbxs:
[0127] Sbxs = [(6 * 0.25) + (7 * 0.325) + (5 * 0.23) + (8 * 0.21)] * 100% + 0.4 = 7;
[0128] A Transaction coefficient weight value = 0.65, B Device coefficient weight value = 0.31, Correction constant C = 0.6;
[0129] According to the calculation formula of the abnormal index Yczs:
[0130] Yczs = [(6 * 0.65) + (7 * 0.31)] * 100% + 0.6 = 6;
[0131] The above result is rounded to two decimal places;
[0132] Set the preset threshold Q to 7 and the preset threshold V to 15. Compare the abnormal index Yczs with the preset thresholds to obtain: preset threshold Q ≤ abnormal index Yczs ≤ preset threshold V, and obtain a medium - risk evaluation. The transaction and the device are regarded as medium - risk. In this case, the transaction and device information are monitored, a pop - up window is shown for the transaction activity, and reading the transaction security protocol is restricted. After six seconds, click to close.
[0133] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. An optimization method based on mobile communication key security, characterized in that: The following steps are involved: S1. Data collection: transaction details, user information, device information and network information. Transaction details and user information are integrated into a user transaction information set, and device information and network information are integrated into a user device information set. S2, data processing: obtaining the user transaction information set and the user device information set for data processing, including outlier monitoring and normalization processing, to form a first transaction data set and a second device data set; S3, abnormal matching: obtaining the first transaction data set and the second device data set, matching them using preset tags to identify abnormal behavior frequency values, and obtaining a transaction frequency data set and a device frequency data set; S4, risk calculation: obtain the transaction frequency data set and the device frequency data set, select a risk model, establish a model for the transaction frequency data set and the device frequency data set, and perform training and calculation to obtain: anomaly index Yczs; The abnormal index Yczs is obtained by the following formula: Yczs=[(Jyxs*A ) + ( Sbxs*B)]*100|+C\ In the formula, Jyxs represents the transaction coefficient, Sbxs represents the equipment coefficient, A represents the weight value of the transaction coefficient Jyxs, B represents the weight value of the equipment coefficient Sbxs, and C represents the correction constant; The transaction coefficient Jyxs is obtained by calculating the transaction frequency data set; The equipment coefficient Sbxs is obtained by calculating the equipment frequency data set; S5, abnormality assessment: compare the obtained abnormality index Yczs with the preset threshold to obtain the level abnormality risk strategy plan; S6. Execution record: Obtain the content of the abnormal risk strategy plan of the level, remind and verify the user according to the content, and impose relevant transaction restrictions to achieve monitoring and early warning of transaction activities.
2. The optimization method based on mobile communication key security according to claim 1, characterized in that: Transaction details, including transaction amounts, frequent transactions, transaction timestamps, transaction locations, transaction types, and the number of daily transactions to the same recipient; User information, including user ID, account history, and login locations; Device information, including device ID, device type, operating system version, simulator running status, device lock status, and device health status; Network information, including Wi-Fi connections, cellular data connections, and mobile network connections.
3. The optimization method based on mobile communication key security according to claim 1, characterized in that: Perform outlier detection on user transaction information sets to identify and handle abnormal transaction behaviors. Including payment anomalies, transaction time anomalies, transaction frequency anomalies and geographical location anomalies, which are normalized to form the first transaction data set; Outlier detection is performed on the user device information to identify and process abnormal behaviors related to the device, including network anomalies, device anomalies, operating system anomalies and operation anomalies, and normalization is performed to form the second data set of the device.
4. The optimization method based on mobile communication key security according to claim 1, characterized in that: The transaction frequency data set includes: payment abnormality label frequency value Zfyc, transaction time abnormality label frequency value Jysj, transaction frequency label frequency value Jypl and geographic location label frequency value Dlwz; The device frequency data set includes: a network abnormality label frequency value Wlyc, a device abnormality label frequency value Sbyc, an operating system abnormality label frequency value Czxt, and an operation abnormality label frequency value Yxyc.
5. The optimization method based on mobile communication key security according to claim 1, characterized in that: The risk models include decision trees, random forests, neural networks, logistic regression, cluster analysis, and time series models; The transaction frequency data set and the equipment frequency data set are calculated by the selected model to obtain: the transaction coefficient Jyxs and the equipment coefficient Sbxs, and then the transaction coefficient Jyxs and the equipment coefficient Sbxs are calculated to obtain: the abnormality index Yczs.
6. The optimization method based on mobile communication key security according to claim 4 is characterized in that: The transaction coefficient Jyxs is obtained by the following formula: Jyxs=[(Zfyc*n)+(Jysj*x)+(Jypl*z)+(Dlwz*d)]*100%+E; Where n, x, z and d represent the weight values of the payment anomaly label frequency value Zfyc, the transaction time anomaly label frequency value Jysj, the transaction frequency label frequency value Jypl and the geographic location label frequency value Dlwz respectively; Among them, 0.16≤n≤0.25, 0.12≤x≤0.28, 0.13≤z≤0.22, 0.14≤d≤0.25, among which n+x+z+d≤1.0, and E represents a correction constant.
7. The optimization method based on mobile communication key security according to claim 4 is characterized in that: The equipment coefficient Sbxs is obtained by the following formula: Sbxs=[(Wlyc*f)+(Sbyc*g)+(Czxt*h)+(Yxyc*j)]*100%+M; Where, f, g, h and j represent the weight values of the network abnormal label frequency value Wlyc, the device abnormal label frequency value Sbyc, the operating system abnormal label frequency value Czxt and the operation abnormal label frequency value Yxyc respectively; Among them, 0.13≤f≤0.25, 0.15≤g≤0.25, 0.16≤h≤0.26, 0.14≤j≤0.24, among which, f+g+h+j≤1.0, and M represents a correction constant.
8. The optimization method based on mobile communication key security according to claim 1, characterized in that: By comparing the abnormal index Yczs with the preset threshold Q and the preset threshold V, multiple levels of abnormal risk strategy solutions are formed; Abnormal index Yczs < preset threshold Q, low risk evaluation is obtained, and the transaction and equipment are considered low risk. In this case, the transaction and equipment information are monitored, and normal transaction activities continue without restrictions or reminders; If the preset threshold Q ≤ abnormal index Yczs ≤ preset threshold V, the medium risk assessment is obtained, and the transaction and device are considered to be medium risk. In this case, the transaction and device information are monitored, a pop-up window is displayed for transaction activities, and the reading of the transaction security agreement is restricted. Click to close after six seconds; If the preset threshold V is less than the abnormal index Yczs, a high-risk assessment is obtained, an emergency pop-up window is displayed to notify the user, and the user is restricted from reading the transaction security agreement, informing them that there are serious security issues, immediately stopping or rejecting transaction activities, temporarily freezing the user account, and prompting them to change the user password and payment password.
9. The optimization method based on mobile communication key security according to claim 8, characterized in that: According to the abnormal risk strategy plan, specific reminders and verifications are given to users, including: in-app messages, real-time pop-ups, emails and SMS notifications to users, as well as secondary verification: re-entering the transaction password, and related transaction restrictions to protect the user's assets, including: Suspending transactions: temporarily stopping all transactions to prevent further potential risks; Assisting users: Sending relevant information to emergency contacts based on the emergency contact information provided, in order to alert the emergency contacts to assist users in identifying abnormal activities; Freeze Account: Freeze user accounts to prevent unauthorized access during a detailed security investigation; Restoring access: Abnormal issues are resolved, helping users resume normal access and transactions.
10. The optimization method based on mobile communication key security according to claim 1, characterized in that: Through the key method of mobile network communication, first, a unique password is used for identity confirmation. Then, during the Bluetooth payment activity, we obtain relevant information and use this information for abnormal detection to warn and monitor transaction activities. The key method of mobile network communication serves as a prerequisite in this process. In terms of determining the signal for network registration, this process ensures the security of payment and identifies potential risks in a timely manner to protect users' transactions and assets. The specific steps include: Process 1: A new SIM card appears; Process 2: SIM card registration and base station location signal location determination; Process 3: Determine SIM uniqueness: Enter the system, query the SIM card track, and query the uniqueness; Process 4: Determine whether it is a new SIM card. If it is a new SIM card: if it matches the track in the system, the SIM card is brought online and marked. If it is not a new SIM card, it is marked as an abnormal SIM, thereby preventing network access.