Identity authentication method, system and device based on scheduling service, medium and product

By adopting a multi-factor identity authentication method in the scheduling business, combining passwords, hardware tokens, biometric identification and digital certificates, and using blockchain to analyze the behavioral characteristics of authentication information, the problems of identity authentication security risks and difficulty in identifying malicious attacks in the existing technology are solved, and higher identity authentication security and power grid stability are achieved.

CN120090876AActive Publication Date: 2025-06-03INNOVATION & INNOVATION CENT OF STATE GRID ZHEJIANG ELECTRIC POWER CO LTD +2
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510560367.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-06-03
Estimated Expiration
2045-04-30

AI Technical Summary

Technical Problem

In the scheduling business, the existing technology identity authentication method has security risks. The security of a single voiceprint authentication is not high, and it is difficult to effectively identify malicious attacks.

Method used

A multi-factor identity authentication method is adopted, combining passwords, hardware tokens, biometric identification and digital certificates, and recording authentication information through blockchain, and the behavioral characteristics of the authentication information are analyzed to identify malicious attacks.

Benefits of technology

It effectively improves the security of identity authentication, can identify and resist malicious attacks, and ensures the safe and stable operation of the power grid.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090876A_ABST
    Figure CN120090876A_ABST
Patent Text Reader

Abstract

The invention discloses an identity authentication method, system, device, medium and product based on scheduling business, and the method comprises the steps: obtaining the first identity information of a target user according to an account number and a password if the account number and the password input by the target user are received, and carrying out the account number and password authentication according to the first identity information; after the account password is successfully authenticated, sequentially authenticating a hardware token, a biological feature and a digital certificate; after the two kinds of authentication are passed, the identity of the target user is confirmed, the authentication process is ended, failure analysis is carried out on authentication information with failed authentication, and a failure analysis result is sent to the user terminal; and if only the account password authentication is passed, hostile attack detection is carried out on the account of the target user. According to the method, multi-factor identity authentication of a password, a hardware token, biological characteristics and a digital certificate can be combined, the authentication information is recorded through the block chain, the behavior characteristics of the authentication information are analyzed, malicious attack behaviors can be effectively identified, and the security of identity authentication is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of identity authentication, and in particular, to an identity authentication method, system, device, medium and product based on dispatching services. Background Art

[0002] Dispatchers and on-duty personnel of operating units who conduct dispatching services must pass the certification training organized by the institution and the order-receiving qualification assessment, and obtain the order-receiving qualification before they can conduct dispatching services. Currently, dispatching services generally confirm identities by phone calls. If there are situations such as falsely reporting the identity of a dispatcher, wrongly contacting a dispatcher, or performing wrong power grid dispatching tasks, there will be significant potential safety hazards, which may affect the safe and stable operation of the power grid. Or confirm the identity of the dispatcher through voiceprint authentication, which is a relatively single authentication method with low security. Summary of the Invention

[0003] The present invention provides an identity authentication method, system, device, medium and product based on dispatching services. Through multi-factor identity authentication combining passwords, hardware tokens, biometric recognition, and digital certificates, and recording authentication information through blockchain and analyzing the behavioral characteristics of the authentication information, malicious attack behaviors can be effectively identified, and the security of identity authentication can be improved.

[0004] To achieve the above object, an embodiment of the present invention provides an identity authentication method based on dispatching services, which is applied to a server terminal. The method includes: If an account and password input by a target user are received, first identity information of the target user is obtained according to the account and password, and account password authentication is performed according to the first identity information; After the account password authentication is successful, second identity information of the hardware token is read from the hardware token accessing the target user; hardware token authentication is performed according to the first identity information and the second identity information; If the hardware token authentication fails, the token authentication information of the hardware token authentication is written into the blockchain, and biometric authentication is performed on the target user; If the biometric authentication fails, the biometric authentication information of the biometric authentication is written into the blockchain, and digital certificate authentication is performed on the target user; If the digital certificate authentication fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and malicious attack detection is performed on the account of the target user.

[0005] As an improvement of the above solution, after performing hardware token authentication according to the first identity information and the second identity information, the method further includes: If the hardware token authentication is successful, the identity authentication process of the target user is ended; After performing biometric authentication on the target user, the method further includes: If the biometric authentication is successful, end the identity authentication process of the target user, and after performing a failure analysis on the token authentication information, send the token failure analysis result to the user terminal; After performing digital certificate authentication on the target user, the method further includes: If the digital certificate authentication is successful, end the identity authentication process of the target user, and after performing a failure analysis on the token authentication information and the biometric authentication information, send the token failure analysis result and the biometric failure analysis result to the user terminal.

[0006] As an improvement to the above solution, the identity authentication method based on scheduling services further includes: After the account password authentication fails, write the account authentication information of the account password authentication into the blockchain, and perform biometric authentication and digital certificate authentication on the target user; If only the biometric authentication fails or only the digital certificate authentication fails, write the biometric authentication information or the certificate authentication information into the blockchain, and re-perform the account password authentication on the target user; If the new account password authentication fails, write the new account authentication information into the blockchain, and perform a malicious attack detection on the account of the target user; If the biometric authentication fails and the digital certificate authentication fails, write the biometric authentication information and the certificate authentication information into the blockchain, and perform a malicious attack detection on the account of the target user.

[0007] As an improvement to the above solution, after performing biometric authentication and digital certificate authentication on the target user, the method further includes: If the biometric authentication is successful and the digital certificate authentication is successful, end the identity authentication process of the target user, and after performing a failure analysis on the account authentication information, send the account failure analysis result to the user terminal; After re-performing the account password authentication on the target user, the method further includes: If the new account password authentication is successful, end the identity authentication process of the target user, and after performing a failure analysis on the biometric authentication information or the certificate authentication information, and the account authentication information, send the biometric failure analysis result or the certificate failure analysis result, and the account failure analysis result to the user terminal.

[0008] As an improvement to the above solution, the hardware token authentication according to the first identity information and the second identity information includes: Match the first identity information and the second identity information; If the first identity information is the same as the second identity information, the hardware token authentication is successful; If the first identity information is different from the second identity information, the hardware token authentication fails.

[0009] As an improvement of the above solution, the malicious attack detection on the account of the target user includes: Obtain the authentication information corresponding to the authentication failure from the blockchain; wherein, the authentication information includes an authentication result, a timestamp, and a reason for failure; According to the authentication information, construct a two-dimensional vector of the authentication information, and use the two-dimensional vector as the behavior feature of the target user; Extract features from the behavior feature, calculate the probability of the behavior feature according to the feature extraction result, and judge whether there is a malicious attack behavior on the account of the target user according to the probability of the behavior feature.

[0010] As an improvement of the above solution, the digital certificate authentication for the target user includes: Obtain the public key of the certificate issuing authority and the signature of the digital certificate uploaded by the target user; Verify the signature according to the public key. If the signature is valid and within the valid period, the digital certificate authentication is successful; If the signature is invalid or not within the valid period, the digital certificate authentication fails.

[0011] To achieve the above object, an embodiment of the present invention provides an identity authentication system based on a scheduling service, including: An account password authentication module, configured to, if receiving an account and a password input by a target user, obtain first identity information of the target user according to the account and the password, and perform account password authentication according to the first identity information; A hardware token authentication module, configured to, after the account password authentication is successful, read second identity information of the hardware token from the hardware token accessing the target user; perform hardware token authentication according to the first identity information and the second identity information; A biometric authentication module, configured to, if the hardware token authentication fails, write the token authentication information of the hardware token authentication into the blockchain, and perform biometric authentication on the target user; A digital certificate authentication module, configured to, if the biometric authentication fails, write the biometric authentication information of the biometric authentication into the blockchain, and perform digital certificate authentication on the target user; The first malicious detection module is used to write the certificate authentication information of the digital certificate authentication into the blockchain if the digital certificate authentication fails, and perform malicious attack detection on the account of the target user.

[0012] As an improvement to the above solution, the identity authentication system based on scheduling services further includes: The identity authentication end module is used to end the identity authentication process of the target user if the hardware token authentication is successful; The token failure analysis module is used to end the identity authentication process of the target user if the biometric authentication is successful, and after performing failure analysis on the token authentication information, send the token failure analysis result to the user terminal; The authentication information analysis module is used to end the identity authentication process of the target user if the digital certificate authentication is successful, and after performing failure analysis on the token authentication information and the biometric authentication information, send the token failure analysis result and the biometric failure analysis result to the user terminal.

[0013] As an improvement to the above solution, the identity authentication system based on scheduling services further includes: The biometric certificate authentication module is used to write the account authentication information of the account password authentication into the blockchain after the account password authentication fails, and perform biometric authentication and digital certificate authentication on the target user; The account re-authentication module is used to write the biometric authentication information or the certificate authentication information into the blockchain if only the biometric authentication fails or only the digital certificate authentication fails, and re-perform account password authentication on the target user; The second malicious detection module is used to write the new account authentication information into the blockchain if the new account password authentication fails, and perform malicious attack detection on the account of the target user; The third malicious detection module is used to write the biometric authentication information and the certificate authentication information into the blockchain if the biometric authentication fails and the digital certificate authentication fails, and perform malicious attack detection on the account of the target user.

[0014] As an improvement to the above solution, the identity authentication system based on scheduling services further includes: The account failure analysis module is used to end the identity authentication process of the target user if the biometric authentication is successful and the digital certificate authentication is successful, and after performing failure analysis on the account authentication information, send the account failure analysis result to the user terminal; The authentication failure analysis module is used to end the identity authentication process of the target user if the new account password authentication is successful, and after performing failure analysis on the biometric authentication information or the certificate authentication information, and the account authentication information, send the biometric failure analysis result or the certificate failure analysis result, and the account failure analysis result to the user terminal.

[0015] As an improvement to the above solution, the hardware token authentication based on the first identity information and the second identity information includes: Match the first identity information and the second identity information; If the first identity information and the second identity information are the same, the hardware token authentication is successful; If the first identity information and the second identity information are different, the hardware token authentication fails.

[0016] As an improvement to the above solution, the malicious attack detection on the account of the target user includes: Obtain the authentication information corresponding to the authentication failure from the blockchain; wherein, the authentication information includes the authentication result, the timestamp, and the reason for failure; According to the authentication information, construct a two-dimensional vector of the authentication information, and use the two-dimensional vector as the behavior feature of the target user; Extract features from the behavior feature, calculate the probability of the behavior feature according to the feature extraction result, and judge whether there is a malicious attack behavior on the account of the target user according to the probability of the behavior feature.

[0017] As an improvement to the above solution, the digital certificate authentication for the target user includes: Obtain the public key of the certificate issuing authority and the signature of the digital certificate uploaded by the target user; Verify the signature according to the public key. If the signature is valid and within the valid period, the digital certificate authentication is successful; If the signature is invalid or not within the valid period, the digital certificate authentication fails.

[0018] To achieve the above object, an embodiment of the present invention correspondingly provides an identity authentication device based on a scheduling service, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the above identity authentication method based on a scheduling service is implemented.

[0019] To achieve the above object, an embodiment of the present invention further provides a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the above identity authentication method based on scheduling services.

[0020] To achieve the above object, an embodiment of the present invention further provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the steps of the above identity authentication method based on scheduling services.

[0021] Compared with the prior art, an identity authentication method, system, device, medium and product based on scheduling services disclosed in an embodiment of the present invention, if the account and password input by the target user are received, then according to the account and password, the first identity information of the target user is obtained, and account password authentication is performed according to the first identity information; after the account password authentication is successful, the second identity information of the hardware token is read from the hardware token accessing the target user; hardware token authentication is performed according to the first identity information and the second identity information; if the hardware token authentication fails, the token authentication information of the hardware token authentication is written into the blockchain, and biometric authentication is performed on the target user; if the biometric authentication fails, the biometric authentication information of the biometric authentication is written into the blockchain, and digital certificate authentication is performed on the target user; if the digital certificate authentication fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and malicious attack detection is performed on the account of the target user. It can combine multi-factor identity authentication of passwords, hardware tokens, biometric recognition and digital certificates, record authentication information through the blockchain, analyze the behavioral characteristics of the authentication information, and can effectively identify malicious attack behaviors and improve the security of identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 It is a schematic flowchart of an identity authentication method based on scheduling services provided by an embodiment of the present invention; Figure 2 It is a schematic structural diagram of an identity authentication system based on scheduling services provided by an embodiment of the present invention; Figure 3 It is a schematic structural diagram of an identity authentication device based on scheduling services provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0023] Next, in combination with the accompanying drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0024] It should be noted that the terms "include" and "specific" in the present invention and any of their deformations are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily limit to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0025] Please refer to Figure 1 , Figure 1 is a schematic flowchart of an identity authentication method based on scheduling services provided by an embodiment of the present invention. The identity authentication method based on scheduling services is applied to a server terminal, and the method includes: S1. If the account and password input by the target user are received, the first identity information of the target user is obtained according to the account and password, and account password authentication is performed according to the first identity information; S2. After the account password authentication is successful, the second identity information of the hardware token is read from the hardware token accessing the target user; hardware token authentication is performed according to the first identity information and the second identity information; S3. If the hardware token authentication fails, the token authentication information of the hardware token authentication is written into the blockchain, and biometric authentication is performed on the target user; S4. If the biometric authentication fails, the biometric authentication information of the biometric authentication is written into the blockchain, and digital certificate authentication is performed on the target user; S5. If the digital certificate authentication fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and malicious attack detection is performed on the account of the target user.

[0026] Further, after performing hardware token authentication according to the first identity information and the second identity information, the method further includes: S6. If the hardware token authentication is successful, the identity authentication process of the target user is ended; After performing biometric authentication on the target user, the method further includes: S7. If the biometric authentication is successful, the identity authentication process of the target user is ended, and after performing failure analysis on the token authentication information, the token failure analysis result is sent to the user terminal; After performing digital certificate authentication on the target user, the method further includes: S8. If the digital certificate authentication is successful, end the identity authentication process of the target user, and after performing failure analysis on the token authentication information and the biometric authentication information, send the token failure analysis result and the biometric failure analysis result to the user terminal.

[0027] Exemplarily, the identity authentication method based on scheduling services described in the embodiments of the present invention can be implemented by an identity authentication server. The identity authentication server (authentication terminal) can interact with the target user and the blockchain. If the identity authentication server receives the account number and password input by the target user, it obtains the first identity information of the target user (such as data on personal information, responsibilities, permissions, accessible functions, data scope, and operation types, etc.) from the data center according to the account number and password, analyzes the first identity information, and determines whether the target user has the responsibilities and permissions to perform scheduling services for account password authentication. It should be noted that the data center stores the hardware token number and identity information of the hardware token, and associates the token number and identity information. The data center also records the latest identity information of the target user. When the identity information of the target user, such as responsibilities and permissions, changes, the data center will synchronously update the identity information of the target user. When the hardware token is connected to the authentication terminal, the token number of the hardware token is read, and the token number and access time are written into the access record. After the account password authentication is successful, the second identity information of the hardware token (such as data on personal information, responsibilities, permissions, accessible functions, data scope, and operation types, etc.) is read from the hardware token accessed by the target user. If the first identity information matches the second identity information, the hardware token authentication is successful, and the identity of the target user is confirmed and the identity authentication process ends. If the first identity information does not match the second identity information, for example, the responsibilities of the first identity information are different from those of the second identity information, the hardware token authentication fails. The reason for this situation may be that the responsibilities of the target user have changed, but the identity information of the hardware token has not been updated in time, or it may be due to a malicious attack. The token authentication information of the hardware token authentication is written into the blockchain, and biometric authentication is performed on the target user (such as existing voice recognition, fingerprint recognition, face recognition, etc.). If the biometric authentication is successful, the identity authentication process of the target user ends, and after the token authentication information is analyzed for failure, the token failure analysis result is sent to the user terminal. If the biometric authentication also fails, the biometric authentication information of the biometric authentication is written into the blockchain, and digital certificate authentication is performed on the target user. If the digital certificate authentication is successful, the identity authentication process ends, and after the token authentication information and the biometric authentication information are analyzed for failure, the token failure analysis result and the biometric failure analysis result are sent to the user terminal. The target user can solve the corresponding problems according to the failure analysis result so that the authentication can be successful next time. If the digital certificate authentication also fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and malicious attack detection is performed on the account of the target user (for example, feature extraction and analysis are performed on the token authentication information, the biometric authentication information, and the certificate authentication information, and according to the analysis result, it is determined whether the account of the target user has been maliciously attacked).The embodiments of the present invention adopt a multi-factor identity authentication method, which combines passwords, hardware tokens, biometric recognition, and digital certificates, effectively resists malicious attacks, and greatly improves the security of identity authentication. When a problem occurs with a certain authentication method, authentication can be performed through other methods, ensuring the flexibility of authentication and the continuity of services, facilitating identity authentication management, and improving the overall operation efficiency and reliability.

[0028] Further, the identity authentication method based on scheduling services further includes: S9, after the account password authentication fails, write the account authentication information of the account password authentication into the blockchain, and perform biometric authentication and digital certificate authentication on the target user; S10, if only the biometric authentication fails or only the digital certificate authentication fails, write the biometric authentication information or the certificate authentication information into the blockchain, and re-perform the account password authentication on the target user; S11, if the new account password authentication fails, write the new account authentication information into the blockchain, and perform malicious attack detection on the account of the target user; S12, if the biometric authentication fails and the digital certificate authentication fails, write the biometric authentication information and the certificate authentication information into the blockchain, and perform malicious attack detection on the account of the target user.

[0029] Further, after performing biometric authentication and digital certificate authentication on the target user, the method further includes: S13, if the biometric authentication is successful and the digital certificate authentication is successful, end the identity authentication process of the target user, and after performing failure analysis on the account authentication information, send the account failure analysis result to the user terminal; S14, if the new account password authentication is successful, end the identity authentication process of the target user, and after performing failure analysis on the biometric authentication information or the certificate authentication information, and the account authentication information, send the biometric failure analysis result or the certificate failure analysis result, and the account failure analysis result to the user terminal.

[0030] Exemplarily, if the target user enters an incorrect password due to a slip of the hand or other reasons, resulting in the failure of account password authentication. Since the hardware token authentication requires the use of the target user's first identity information, and this first identity information needs to be obtained based on the correct account password, after the account password authentication fails, the hardware token authentication cannot be initiated. The target user needs to authenticate their identity through other means, such as biometric authentication and digital certificate authentication. If both biometric authentication and digital certificate authentication are successful, the identity authentication process ends. After performing a failure analysis on the account authentication information, the account failure analysis result is sent to the user terminal. If biometric authentication is successful and digital certificate authentication fails, or biometric authentication fails and digital certificate authentication is successful, the authentication information of the failed authentication is written into the blockchain, and the target user is re-authenticated for the account password. If the new account password authentication is successful, the identity authentication process ends. After performing a failure analysis on the biometric authentication information or the certificate authentication information, and performing a failure analysis on the account authentication information, the biometric failure analysis result or the certificate failure analysis result, and the account failure analysis result are sent to the user terminal; if the new account password authentication fails, the authentication information of the failed authentication (the new account authentication information, biometric authentication information, or the certificate authentication information) is written into the blockchain, and a malicious attack detection is performed on the target user's account.

[0031] In a specific implementation, user A accidentally enters an incorrect password. The authentication terminal determines that the account password authentication fails. Although the hardware token is successfully connected, the authentication terminal does not initiate the hardware token authentication due to the incorrect password. User A performs fingerprint authentication, and due to a fingerprint sensor failure, the biometric authentication fails. User A uploads a digital certificate, and uses the CA public key to verify that the certificate signature is valid, extracts the user public key, generates a random number, encrypts the public key and sends it to user A's user terminal, so that user A decrypts the public key using the private key. If the decryption is successful, the digital certificate authentication is successful. Since only the digital certificate authentication is passed, the authentication terminal requests a secondary verification of the account password: User A re-enters the correct password, and the new account password authentication is successful, then the identity authentication process ends, and user A is allowed to access the basic scheduling function. The blockchain records the failure of the initial account password authentication and the success of the digital certificate authentication. The recording format is as follows: "User terminal number": "R14", "Account password authentication": "Failed", "Digital certificate authentication": "Successful", "Timestamp": "20250101T10:05:00", "Token number": "User A2025-001", Security analysis result: Regular mistake (incorrect password input), no risky operation.

[0032] Specifically, the hardware token authentication based on the first identity information and the second identity information includes: Matching the first identity information and the second identity information; If the first identity information and the second identity information are the same, the hardware token authentication is successful; If the first identity information and the second identity information are different, the hardware token authentication fails.

[0033] Exemplarily, the target user inputs their account password on the authentication terminal and connects the hardware token to the authentication terminal. At this time, the authentication terminal obtains the first identity information of the target user according to the input account password and authenticates the target user. If there are insufficient permissions or incorrect responsibilities in the first identity information, the account password authentication fails; otherwise, the account password authentication is successful. The first identity information includes data such as the personal information, responsibilities, permissions, accessible functions, data scope, and operation type of the target user, and can be stored in the cloud server or local memory for the authentication terminal to perform identity matching. After the account password authentication is successful, the authentication terminal reads the second identity information in the hardware token through the token number. If the second identity information does not match the first identity information obtained from the data center through the account password, the hardware token authentication fails; if they match, the hardware token authentication is successful. After both the account password and hardware token authentications pass, the authentication terminal opens the corresponding data scope and functions according to the responsibilities of the target user and the corresponding functions and data scope, and no further authentication is performed. The authentication processes of the account password and the hardware token are used by the processor of the hardware token to write status information in the time schedule.

[0034] It should be noted that the hardware token has a memory and a processor. The memory stores the identity information of the target user and a time schedule for the processor to read and write. Each hardware token has a unique, unchangeable token number that is available since its manufacture and can be parsed and read by the terminal. The setting of the token number can prevent the forgery of the hardware token and enhance the security of the hardware token. The identity information includes data such as personal information, responsibilities, permissions, accessible functions, data scope, and operation type. The time schedule includes status information such as the terminal connected to the hardware token, the timestamp, and the status. For example, 20250101, 09:13AM, R14, failed (code 0011) is a piece of data written in the time schedule. The number of the connected terminal is R14, the access time is January 1, 2025, 9:13 AM, the access fails, and the code number of the failure reason is 0011.

[0035] In another embodiment, a random number generator and a timer can also be integrated on the hardware token. After the hardware token is connected to the authentication terminal, it receives an instruction sent by the authentication terminal and generates a random number. The timer records the system time and generates a time parameter at the same time as generating the random number, which is used to record the current time. The random number and the time parameter are encrypted to generate a password and displayed to the target user, and the encrypted password is output to the authentication terminal. The authentication terminal synchronizes the time with the hardware token and starts timing according to the time parameter. The target user inputs the encrypted password on the authentication terminal. The authentication terminal decrypts the encrypted password and compares the encrypted password input by the target user with the password input by the hardware token. If they are the same, the account password authentication is successful; otherwise, if the password is not input or is not correctly input before the time threshold is reached, the account password authentication fails. After the account password authentication is successful, the authentication terminal reads the identity information in the hardware token. If the identity information does not match the identity information obtained from the data center through the account and password, the hardware token authentication fails; if they match, the hardware token authentication is successful.

[0036] It can be understood that the first identity information is updated in real time by the data center. However, since the hardware token needs to be carried by the target user, when the data center updates the first identity information and the target user does not update the second identity information in the hardware token, the hardware token authentication will fail. At this time, the target user can perform biometric identification. If the account password authentication is passed and the biometric identification authentication is passed, the target user can enter the system normally. That is to say, among password authentication, hardware token authentication, and biometric identification authentication, the target user must pass at least two types of authentication to be able to enter the terminal for scheduling services. Biometric identification includes voiceprint identification, fingerprint identification, face recognition, etc. The biometric features of the target user can be collected through a collection device, such as a camera to collect the facial features of the target user, a microphone to collect the voiceprint of the target user, and a fingerprint sensor to collect the fingerprint of the target user.

[0037] In a specific implementation, user A inputs the account (user A001) and the correct password. The authentication terminal obtains the first identity information of user A from the data center and confirms that the permission is that of a dispatcher (able to access grid topology data and operate circuit breakers), and the account password authentication is successful. User A connects the hardware token (token number: user A2025-001), and the authentication terminal reads the second identity information stored in the token. Since the data center recently updated the permissions of user A (adding the "emergency operation" permission), but the hardware token has not been synchronized and updated, the token permissions do not match those of the data center (failure code 0011: identity information expired), and the hardware token authentication fails; 20250101, 09:13AM, R14, failure (0011) is written into the hardware token schedule. User A uses fingerprint recognition to match the biometric template stored in the data center, and the biometric authentication is successful. It is comprehensively determined that user A's authentication is passed, and the authentication terminal opens the permissions: display grid topology data, but hides the "emergency operation" function (due to the token not being updated). The blockchain records the successful account password authentication, the failed hardware token authentication, and the successful biometric authentication, and the recording form is as follows: "user terminal number": "R14", "account password authentication": "success", "hardware token authentication": "failure (0011)", "biometric authentication": "success", "timestamp": "20250101T09:13:00", "hardware token number": "user A2025-001", and the security analysis result: the reason for the extraction failure is 0011, marked as a regular mistake (permissions not synchronized), and a notification is automatically sent to the user terminal, requesting the update of the hardware token information.

[0038] Specifically, the malicious attack detection on the account of the target user includes: Obtaining the authentication information corresponding to the authentication failure from the blockchain; wherein, the authentication information includes the authentication result, the timestamp, and the reason for failure; According to the authentication information, constructing a two-dimensional vector of the authentication information, and using the two-dimensional vector as the behavior feature of the target user; Performing feature extraction on the behavior feature, calculating the probability of the behavior feature according to the feature extraction result, and judging whether there is a malicious attack behavior on the account of the target user according to the probability of the behavior feature.

[0039] Exemplarily, the authentication terminal writes the authentication information into the blockchain, and the authentication information includes the password authentication result, the hardware token authentication result, the timestamp, the token number, the reason for failure, etc. By obtaining the authentication information from the blockchain, screening the authentication information of the authentication failure and constructing a two-dimensional vector , indicating the group of failure information, indicating the Timestamp of the group failure information, where the failure information includes the failure reason and the order number. The two-dimensional vector is used as the behavioral feature , and is input into a self-attention mechanism containing self-attention mechanisms. Each self-attention mechanism performs a linear transformation on the input user behavioral feature . The construction formula is: , , , Calculate the query vector , key vector , and value vector in the -th self-attention mechanism. In the formula, is the weight matrix for generating the query vector ; is the weight matrix for generating the key vector ; is the weight matrix for generating the value vector .

[0040] And according to the formula: , calculate the attention score . In the formula, is the factor of the model feature scale and the number of self-attention mechanisms, is the transpose identifier. By concatenating all the output attention scores, the attention weight vector is obtained. The product of the attention weight vector and the behavioral feature is the behavioral feature encoding .

[0041] Extract the key behavior encoding through the Transformer encoder according to the preset high-priority behavior. Use a convolutional kernel with a large receptive field to perform a convolution operation on the behavioral feature encoding to capture global information and obtain the global feature . The size of the receptive field can be adjusted to be close to or slightly smaller than the size of so as to be able to capture most of the global information. Use a convolutional kernel with a smaller receptive field to perform a convolution operation on the key behavior encoding to capture local information. Consider using multiple convolutional kernels and taking the maximum response at each position as the local feature to obtain the local feature ; Combine the global feature and the local feature Splicing: , to achieve comprehensive extraction of behavioral features; through analysis algorithms such as neural networks and logistic regression, calculate the probabilities of different behaviors, and select the behavior with the highest probability as the behavior determination result. Behaviors include illegal operations, routine mistakes, malicious attacks, etc. The security system outputs the determination result and the processing method to the user terminal according to the preset processing method and the determination result. By judging the behavior of the target user, the working condition of the authentication terminal can be understood in time, and timely processing can be carried out for malicious attacks, etc.

[0042] Specifically, the digital certificate authentication for the target user includes: Obtain the public key of the certificate issuing authority and the signature of the digital certificate uploaded by the target user; Verify the signature according to the public key. If the signature is valid and within the validity period, the digital certificate authentication is successful; If the signature is invalid or not within the validity period, the digital certificate authentication fails.

[0043] Exemplarily, if the target user only passes one of the account password authentication, hardware token, and biometric recognition authentication, the digital certificate can also be uploaded to the authentication terminal. The authentication terminal obtains the corresponding public key from the certificate issuing authority (CA) according to the input digital certificate, verifies the signature of the digital certificate according to the public key of the certificate issuing authority. If the signature is valid and within the validity period, extract the user public key corresponding to the target user from the signature, generate a random number and encrypt it with the user public key, send the encrypted result to the target user for parsing. The target user decrypts the random number with the private key and writes the decrypted result into the authentication terminal. The authentication terminal obtains the random number input by the target user. If it is the same as the generated random number, the digital certificate authentication passes, otherwise the digital certificate authentication fails.

[0044] In a specific implementation, the attacker uses the stolen account user A001 and password to connect to a forged hardware token (token number: TKN-illegal); the attacker inputs the account (user A001) and the correct password, and the authentication terminal obtains the first identity information of this account from the data center, confirms that the permission is a dispatcher (able to access grid topology data and operate circuit breakers), and the account password authentication is successful; the authentication terminal reads the forged token number TKN-illegal, and this token does not exist in the data center, so the hardware token authentication fails (failure code 0022: invalid token); the attacker cannot pass the fingerprint verification, and the blockchain records high-frequency failures. The same account attempts multiple times on terminals R14 and R15 within a short period. For example: (1) "Timestamp": "20250101T11:00:00", "Terminal": "R14", "Failure reason": "0022"; (2) "Timestamp": "20250101T11:00:01", "Terminal": "R14", "Failure reason": "0022"; (3) "Timestamp": "20250101T11:01:00", "Terminal": "R15", "Failure reason": "0022"; (4) "Timestamp": "20250101T11:01:01", "Terminal": "R15", "Failure reason": "0022"; Security analysis result: Global feature ( ): High-frequency failures across terminals with a short time interval; Local feature ( ): Illegal token number, continuous login failures, determined to be a malicious attack (probability 98%), automatically lock the account: user A001, and send an alarm: A malicious attack on the account: user A001 is detected. Please immediately check terminals R14 and R15.

[0045] An identity authentication method based on scheduling services disclosed in an embodiment of the present invention, if an account and password input by a target user are received, then according to the account and password, the first identity information of the target user is obtained, and account password authentication is performed according to the first identity information; after the account password authentication is successful, the second identity information of the hardware token is read from the hardware token accessing the target user; hardware token authentication is performed according to the first identity information and the second identity information; if the hardware token authentication fails, the token authentication information of the hardware token authentication is written into the blockchain, and biometric authentication is performed on the target user; if the biometric authentication fails, the biometric authentication information of the biometric authentication is written into the blockchain, and digital certificate authentication is performed on the target user; if the digital certificate authentication fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and malicious attack detection is performed on the account of the target user. It can combine multi-factor identity authentication of passwords, hardware tokens, biometric recognition, and digital certificates, record authentication information through the blockchain, analyze the behavioral characteristics of the authentication information, effectively identify malicious attack behaviors, and improve the security of identity authentication.

[0046] See Figure 2 , Figure 2 FIG. 7 is a schematic structural diagram of an identity authentication system 10 based on scheduling services provided by an embodiment of the present invention. The identity authentication system 10 based on scheduling services includes: An account password authentication module 11, configured to, if an account and password input by a target user are received, then according to the account and password, obtain the first identity information of the target user, and perform account password authentication according to the first identity information; A hardware token authentication module 12, configured to, after the account password authentication is successful, read the second identity information of the hardware token from the hardware token accessing the target user; perform hardware token authentication according to the first identity information and the second identity information; A biometric authentication module 13, configured to, if the hardware token authentication fails, write the token authentication information of the hardware token authentication into the blockchain, and perform biometric authentication on the target user; A digital certificate authentication module 14, configured to, if the biometric authentication fails, write the biometric authentication information of the biometric authentication into the blockchain, and perform digital certificate authentication on the target user; A first malicious detection module 15, configured to, if the digital certificate authentication fails, write the certificate authentication information of the digital certificate authentication into the blockchain, and perform malicious attack detection on the account of the target user.

[0047] Further, the identity authentication system 10 based on scheduling services further includes: An identity authentication end module, which is used to end the identity authentication process of the target user if the hardware token authentication is successful; A token failure analysis module, which is used to end the identity authentication process of the target user if the biometric authentication is successful, and after performing a failure analysis on the token authentication information, send the token failure analysis result to the user terminal; An authentication information analysis module, which is used to end the identity authentication process of the target user if the digital certificate authentication is successful, and after performing a failure analysis on the token authentication information and the biometric authentication information, send the token failure analysis result and the biometric failure analysis result to the user terminal.

[0048] Furthermore, the identity authentication system 10 based on scheduling services further includes: A biometric certificate authentication module, which is used to write the account authentication information of the account password authentication into the blockchain after the account password authentication fails, and perform biometric authentication and digital certificate authentication on the target user; An account re-authentication module, which is used to write the biometric authentication information or the certificate authentication information into the blockchain if only the biometric authentication fails or only the digital certificate authentication fails, and re-perform the account password authentication on the target user; A second malicious detection module, which is used to write the new account authentication information into the blockchain if the new account password authentication fails, and perform a malicious attack detection on the account of the target user; A third malicious detection module, which is used to write the biometric authentication information and the certificate authentication information into the blockchain if the biometric authentication fails and the digital certificate authentication fails, and perform a malicious attack detection on the account of the target user.

[0049] Furthermore, the identity authentication system 10 based on scheduling services further includes: An account failure analysis module, which is used to end the identity authentication process of the target user if the biometric authentication is successful and the digital certificate authentication is successful, and after performing a failure analysis on the account authentication information, send the account failure analysis result to the user terminal; An authentication failure analysis module, which is used to end the identity authentication process of the target user if the new account password authentication is successful, and after performing a failure analysis on the biometric authentication information or the certificate authentication information, and the account authentication information, send the biometric failure analysis result or the certificate failure analysis result, and the account failure analysis result to the user terminal.

[0050] Specifically, the hardware token authentication according to the first identity information and the second identity information includes: Matching the first identity information and the second identity information; If the first identity information and the second identity information are the same, the hardware token authentication is successful; If the first identity information and the second identity information are different, the hardware token authentication fails.

[0051] Specifically, the malicious attack detection on the account of the target user includes: Obtain the authentication information corresponding to the authentication failure from the blockchain; wherein, the authentication information includes an authentication result, a timestamp, and a reason for failure; According to the authentication information, construct a two-dimensional vector of the authentication information, and use the two-dimensional vector as the behavior feature of the target user; Perform feature extraction on the behavior feature, calculate the probability of the behavior feature according to the feature extraction result, and determine whether there is a malicious attack behavior on the account of the target user according to the probability of the behavior feature.

[0052] Specifically, the digital certificate authentication for the target user includes: Obtain the public key of the certificate issuing authority and the signature of the digital certificate uploaded by the target user; Verify the signature according to the public key. If the signature is valid and within the valid period, the digital certificate authentication is successful; If the signature is invalid or not within the valid period, the digital certificate authentication fails.

[0053] An identity authentication system 10 based on a scheduling service provided by an embodiment of the present invention can implement all processes of the identity authentication method based on a scheduling service in the above embodiment. The functions of each module in the system and the achieved technical effects respectively correspond to the functions and the achieved technical effects of the identity authentication method based on a scheduling service in the above embodiment, and will not be elaborated here.

[0054] See Figure 3 , Figure 3 is a schematic structural diagram of an identity authentication device 20 based on a scheduling service provided by an embodiment of the present invention. The identity authentication device 20 based on a scheduling service in this embodiment includes: a processor 21, a memory 22, and a computer program stored in the memory 22 and executable on the processor 21. When the processor 21 executes the computer program, the steps in the embodiment of the identity authentication method based on a scheduling service described above are implemented. Or, when the processor 21 executes the computer program, the functions of each module in the embodiment of the identity authentication device based on a scheduling service described above are implemented.

[0055] Exemplarily, the computer program may be divided into one or more modules, and the one or more modules are stored in the memory 22 and executed by the processor 21 to implement the present invention. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the authentication device 20 based on scheduling services.

[0056] The authentication device 20 based on scheduling services may be a computing device such as a desktop computer, a notebook, a palm computer, or a cloud server. The authentication device 20 based on scheduling services may include, but is not limited to, a processor 21 and a memory 22. Those skilled in the art can understand that the schematic diagram is only an example of the authentication device 20 based on scheduling services, and does not constitute a limitation on the authentication device 20 based on scheduling services. It may include more or fewer components than shown in the figure, or combine some components, or different components. For example, the authentication device 20 based on scheduling services may further include input / output devices, network access devices, a bus, etc.

[0057] The so-called processor 21 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor 21 is the control center of the authentication device 20 based on scheduling services, and connects various parts of the entire authentication device 20 based on scheduling services through various interfaces and lines.

[0058] The memory 22 can be used to store the computer programs and / or modules. By running or executing the computer programs and / or modules stored in the memory 22 and calling the data stored in the memory 22, the processor 21 realizes various functions of the authentication device 20 based on scheduling services. The memory 22 mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the mobile phone (such as audio data, phone book, etc.). In addition, the memory 22 can include high-speed random access memory, and can also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0059] Among them, if the modules integrated in the authentication device 20 based on scheduling services are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned embodiment methods of the present invention, it can also be completed by a computer program instructing relevant hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor 21, the steps of the above-mentioned various method embodiments can be realized. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disc, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0060] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the attached drawings of the device embodiments provided by the present invention, the connection relationship between modules indicates that they have a communication connection, which can be specifically implemented as one or more communication buses or signal lines. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0061] An embodiment of the present invention also provides a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the identity authentication method based on scheduling services as described in the above embodiment.

[0062] In addition, an embodiment of the present invention also provides a computer program product, which is stored in a storage medium. The program product is executed by at least one processor to implement the steps of the identity authentication method based on scheduling services as described in the above embodiment.

[0063] The above is the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.

Claims

1. An identity authentication method based on scheduling service, characterized in that: Applied to a server terminal, the method comprises: If the target user inputs an account number and password, obtain the target user's first identity information according to the account number and password, and perform account number and password authentication according to the first identity information; When the account and password authentication is successful, the second identity information of the hardware token is read from the hardware token of the target user; the hardware token authentication is performed according to the first identity information and the second identity information; If the hardware token authentication fails, the token authentication information of the hardware token authentication is written into the blockchain, and the target user is biometrically authenticated; If the biometric authentication fails, the biometric authentication information of the biometric authentication is written into the blockchain, and the target user is digitally authenticated; If the digital certificate authentication fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and the target user's account is detected for malicious attacks.

2. The identity authentication method based on scheduling service as claimed in claim 1, characterized in that: After performing hardware token authentication according to the first identity information and the second identity information, the method further includes: If the hardware token authentication is successful, the identity authentication process of the target user is ended; After performing biometric authentication on the target user, the method further includes: If the biometric authentication is successful, the identity authentication process of the target user is terminated, and after the token authentication information is analyzed for failure, the token failure analysis result is sent to the user terminal; After the target user is authenticated with a digital certificate, the method further includes: If the digital certificate authentication is successful, the identity authentication process of the target user is terminated, and after failure analysis of the token authentication information and the biometric authentication information, the token failure analysis result and the biometric failure analysis result are sent to the user terminal.

3. The identity authentication method based on scheduling service as claimed in claim 1, characterized in that: Also includes: When the account and password authentication fails, the account authentication information of the account and password authentication is written into the blockchain, and the target user is authenticated by biometrics and digital certificates; If only the biometric authentication fails or only the digital certificate authentication fails, the biometric authentication information or the certificate authentication information is written into the blockchain, and the target user is re-authenticated with the account and password; If the new account and password authentication fails, the new account authentication information is written into the blockchain, and malicious attack detection is performed on the target user's account; If the biometric authentication fails and the digital certificate authentication fails, the biometric authentication information and the certificate authentication information are written into the blockchain, and a malicious attack detection is performed on the target user's account.

4. The identity authentication method based on scheduling service as claimed in claim 3, characterized in that: After performing biometric authentication and digital certificate authentication on the target user, the method further includes: If the biometric authentication is successful and the digital certificate authentication is successful, the identity authentication process of the target user is terminated, and after the account authentication information is analyzed for failure, the account failure analysis result is sent to the user terminal; After re-authenticating the target user's account and password, the method further includes: If the new account and password authentication is successful, the identity authentication process of the target user is terminated, and after failure analysis of the biometric authentication information or the certificate authentication information, and the account authentication information, the biometric failure analysis result or the certificate failure analysis result, and the account failure analysis result are sent to the user terminal.

5. The identity authentication method based on scheduling service as claimed in claim 1, characterized in that: The performing hardware token authentication according to the first identity information and the second identity information includes: matching the first identity information with the second identity information; If the first identity information and the second identity information are the same, the hardware token authentication is successful; If the first identity information and the second identity information are different, the hardware token authentication fails.

6. The identity authentication method based on scheduling service as claimed in claim 1, characterized in that: The malicious attack detection on the target user's account includes: Obtain authentication information corresponding to the authentication failure from the blockchain; wherein the authentication information includes the authentication result, timestamp and failure reason; constructing a two-dimensional vector of the authentication information according to the authentication information, and using the two-dimensional vector as a behavior feature of the target user; Feature extraction is performed on the behavior feature, and based on the feature extraction result, the probability of the behavior feature is calculated, and based on the probability of the behavior feature, it is determined whether there is malicious attack behavior in the account of the target user.

7. The identity authentication method based on scheduling service as claimed in claim 1, characterized in that: The digital certificate authentication of the target user includes: Obtaining the public key of the certificate authority and the signature of the digital certificate uploaded by the target user; The signature is verified according to the public key. If the signature is valid and within the validity period, the digital certificate authentication is successful; If the signature is invalid or out of validity period, the digital certificate authentication fails.

8. An identity authentication system based on scheduling services, characterized in that: include: An account and password authentication module, configured to, if receiving an account and password input by a target user, obtain the first identity information of the target user according to the account and password, and perform account and password authentication according to the first identity information; A hardware token authentication module, used to read the second identity information of the hardware token from the hardware token connected to the target user after the account and password authentication is successful; Performing hardware token authentication according to the first identity information and the second identity information; A biometric authentication module, used to write the token authentication information of the hardware token authentication into the blockchain if the hardware token authentication fails, and to perform biometric authentication on the target user; A digital certificate authentication module, used to write the biometric authentication information of the biometric authentication into the blockchain if the biometric authentication fails, and to perform digital certificate authentication on the target user; The first malicious detection module is used to write the certificate authentication information of the digital certificate authentication into the blockchain if the digital certificate authentication fails, and perform malicious attack detection on the account of the target user.

9. The identity authentication system based on scheduling service as claimed in claim 8, characterized in that: Also includes: An identity authentication ending module, used to end the identity authentication process of the target user if the hardware token authentication is successful; A token failure analysis module, used to terminate the identity authentication process of the target user if the biometric authentication is successful, and after performing a failure analysis on the token authentication information, send the token failure analysis result to the user terminal; The authentication information analysis module is used to end the identity authentication process of the target user if the digital certificate authentication is successful, and after performing failure analysis on the token authentication information and the biometric authentication information, send the token failure analysis result and the biometric failure analysis result to the user terminal.

10. The identity authentication system based on scheduling service as claimed in claim 8, characterized in that: Also includes: A biometric certificate authentication module, which is used to write the account authentication information of the account and password authentication into the blockchain when the account and password authentication fails, and to perform biometric authentication and digital certificate authentication on the target user; An account re-authentication module, used for writing the biometric authentication information or the certificate authentication information into the blockchain if only the biometric authentication fails or only the digital certificate authentication fails, and re-authenticating the target user’s account and password; A second malicious detection module is used to write the new account authentication information into the blockchain if the new account password authentication fails, and to perform malicious attack detection on the target user's account; The third malicious detection module is used to write the biometric authentication information and the certificate authentication information into the blockchain if the biometric authentication fails and the digital certificate authentication fails, and to perform malicious attack detection on the target user's account.

11. The identity authentication system based on scheduling service as claimed in claim 10, characterized in that: Also includes: An account failure analysis module, used to terminate the identity authentication process of the target user if the biometric authentication is successful and the digital certificate authentication is successful, and after performing failure analysis on the account authentication information, send the account failure analysis result to the user terminal; The authentication failure analysis module is used to end the identity authentication process of the target user if the new account and password authentication is successful, and after performing failure analysis on the biometric authentication information or the certificate authentication information, as well as the account authentication information, the biometric failure analysis result or the certificate failure analysis result, as well as the account failure analysis result are sent to the user terminal.

12. The identity authentication system based on scheduling service as claimed in claim 8, characterized in that: The performing hardware token authentication according to the first identity information and the second identity information includes: matching the first identity information with the second identity information; If the first identity information and the second identity information are the same, the hardware token authentication is successful; If the first identity information and the second identity information are different, the hardware token authentication fails.

13. The identity authentication system based on scheduling service as claimed in claim 8, characterized in that: The malicious attack detection on the target user's account includes: Obtain authentication information corresponding to the authentication failure from the blockchain; wherein the authentication information includes the authentication result, timestamp and failure reason; constructing a two-dimensional vector of the authentication information according to the authentication information, and using the two-dimensional vector as a behavior feature of the target user; Feature extraction is performed on the behavior feature, and based on the feature extraction result, the probability of the behavior feature is calculated, and based on the probability of the behavior feature, it is determined whether there is malicious attack behavior in the account of the target user.

14. The identity authentication system based on scheduling service as claimed in claim 8, characterized in that: The digital certificate authentication of the target user includes: Obtaining the public key of the certificate authority and the signature of the digital certificate uploaded by the target user; The signature is verified according to the public key. If the signature is valid and within the validity period, the digital certificate authentication is successful; If the signature is invalid or out of validity period, the digital certificate authentication fails.

15. An identity authentication device based on a scheduling service, characterized in that: It comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the processor executes the computer program, it implements the scheduling service-based identity authentication method as described in any one of claims 1 to 7.

16. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the scheduling service-based identity authentication method according to any one of claims 1 to 7.

17. A computer program product, characterized in that The computer program product is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the scheduling service-based identity authentication method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Authentication method and authentication system for page visiting

    CN103179195A

  • Threat behavior processing method, device and equipment based on block chain as well as storage medium

    CN108737336A

  • Operation authentication method and device, storage medium and electronic device

    CN111582876A

  • Drug traceability management method and system based on block chain technology

    CN112184268A

  • Account management method and device based on block chain technology

    CN116545725A