Account authentication method and system and storage medium

Through dynamic fingerprint construction and key projection simulation of user input information and terminal device IP positioning, security and privacy protection issues in traditional industrial terminal device account authentication are solved, and an efficient and flexible authentication mechanism is achieved.

CN120165876AActive Publication Date: 2025-06-17陈志福

Patent Information

Application Number
CN202510321178.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-06-17
Estimated Expiration
2045-03-18

AI Technical Summary

Technical Problem

The account authentication method of traditional industrial terminal equipment has problems such as static passwords that are easily attacked, single-factor authentication is difficult to cope with advanced persistent threats, lack of dynamic and adaptive capabilities of the authentication system, frequent changes in IP positioning lead to difficulty in identity identification, and insufficient privacy protection.

Method used

By collecting user input information, character error removal and standardization processing are performed, dynamic fingerprints are generated based on the IP positioning of terminal equipment, key matrix projection and disturbance offset simulation, layered authentication codes and dynamic token data are constructed, and dynamic rules checksum permission control is realized.

Benefits of technology

It improves the security and flexibility of account authentication, enhances the ability to capture user behavior patterns, ensures the randomness and adaptability of the authentication process, protects user privacy, and improves the security management capabilities of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165876A_ABST
    Figure CN120165876A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of account authentication, in particular to an account authentication method and system and a storage medium. The method comprises the following steps of collecting account and password information of a user, detecting synchronous reaction of equipment for the account and password information of the user, performing character error elimination and structure standardization on the account of the user based on a detection result, generating account block data, obtaining IP positioning of terminal equipment and performing longitude and latitude mapping. Generating a positioning area number to construct a dynamic fingerprint, performing key matrix projection based on the dynamic fingerprint of a user, generating projection fingerprint data, constructing a layered authentication code, performing disturbance offset simulation on the layered authentication code, generating an offset authentication key, performing dynamic rule verification, and generating dynamic token data; and constructing a terminal equipment trust link by using the dynamic token data, and performing authority control mapping, thereby constructing an authentication account session. According to the invention, a safer and more flexible account authentication method is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of account authentication, and particularly to an account authentication method, system and storage medium. Background Art

[0002] There are many deficiencies in the traditional remote operation and maintenance account authentication method for industrial terminal devices. First of all, static passwords are easily exploited by malicious attackers through brute force cracking, dictionary attacks or social engineering means, resulting in serious intrusion risks for industrial control systems (ICS, Industrial Control System). Secondly, single-factor authentication is difficult to effectively cope with advanced persistent threats (APT, Advanced Persistent Threat) in the industrial Internet environment. Since industrial terminal devices are running online for a long time, once the credentials are leaked, attackers can penetrate remotely for a long time, thereby affecting the stability of the entire production control system. In addition, there are major security risks in the existing account authentication technology for remote access management of industrial terminal devices. For example, traditional authentication mechanisms mainly rely on static credentials and lack in-depth analysis of device environment, operation behavior and network access patterns, making it difficult to achieve dynamic adaptive authentication. There are still multiple technical difficulties in the existing remote authentication system for industrial terminal devices. First of all, the existing authentication methods mainly rely on fixed password policies and preset authentication mechanisms, lacking dynamics and adaptability. In the industrial remote operation and maintenance scenario, the devices are widely distributed and the network environment is complex, and fixed identity authentication policies are difficult to adapt to the changing remote access requirements. Secondly, traditional authentication systems often ignore the recognition of operation behavior characteristics when processing user input information, such as factors like the input habits of operators, the geographical location of accessed devices, and access frequencies, resulting in the inability of the authentication system to effectively distinguish normal users from malicious attackers when dealing with illegal intrusions. In addition, the existing authentication methods have limited technical means in IP positioning and dynamic fingerprint construction, making it difficult to achieve accurate user identity recognition. Industrial terminal devices are often in a changing network environment, and IP addresses change frequently due to network switching. Identity authentication methods based on static IPs are difficult to meet the requirements of high security and high reliability for industrial remote operation and maintenance. At the same time, there are still major deficiencies in the current identity authentication technology in terms of privacy protection, and it is unable to minimize the exposure of private data while ensuring identity security, resulting in the risk of data leakage during industrial operation and maintenance. Summary of the Invention

[0003] Based on this, it is necessary to provide an account authentication method, system and storage medium to solve at least one of the above technical problems.

[0004] To achieve the above object, an account authentication method includes the following steps:

[0005] Step S1: Collect the user input account information and the user input password information; eliminate the character errors in the user input account information to obtain the standardized input data; perform structure standardization processing on the standardized input data and perform block mapping to generate account block data;

[0006] Step S2: Obtain the IP location of the terminal device; perform longitude and latitude mapping on the IP location of the terminal device and perform the last digit superposition of longitude and latitude to obtain the location area number; based on the location area number, construct a dynamic fingerprint for the user input password information and the account block data to generate the user dynamic fingerprint;

[0007] Step S3: Perform key matrix projection based on the user dynamic fingerprint to generate projection fingerprint data; construct a hierarchical authentication code based on the projection fingerprint data;

[0008] Step S4: Perform perturbation offset simulation on the hierarchical authentication code to generate an offset authentication key; perform dynamic rule verification on the offset authentication key and perform adaptive key fitting based on the rule verification result to generate dynamic token data;

[0009] Step S5: Construct a trust link for the terminal device based on the dynamic token data; perform permission control mapping according to the trust link of the terminal device and construct an authenticated account session.

[0010] The present invention provides the basic data for identity authentication for the system by collecting the user input account information and password information. The implementation of character error elimination ensures the accuracy of the input data. The generated standardized input data provides a clear basis for subsequent processing. The structure standardization processing and block mapping improve the data manageability and analysis ability. Obtaining the IP location of the terminal device introduces geographical information for user identity authentication. The longitude and latitude mapping and the last digit superposition enhance the data privacy protection. The generated location area number provides geographical features for dynamic fingerprint construction. Constructing a dynamic fingerprint for the user input password information and the account block data based on the location area number can capture the unique behavior patterns of the user. The generated user dynamic fingerprint provides multi-dimensional features for subsequent security verification. Performing perturbation offset simulation based on the user dynamic fingerprint ensures the randomness and unpredictability of the offset authentication key. The implementation of dynamic rule verification improves the adaptability and flexibility of the key. The dynamic token data generated by adaptive key fitting provides security guarantee for real-time verification. The construction of the trust link for the terminal device ensures the security of data transmission. The implementation of permission control mapping enhances the security management ability of the system. The construction of the authenticated account session provides a stable basis for the interaction between the user and the system.

[0011] Preferably, step S1 includes the following steps:

[0012] Step S11: Collect the user input account information and user input password information, and at the same time monitor the device mouse and keyboard behavior data; perform input behavior sequence recognition on the device mouse and keyboard behavior data to generate an input behavior feature vector; perform input behavior reverse derivation on the user input account information and user input password information to generate the required input behavior features;

[0013] Step S12: Based on the required input behavior features, perform synchronous reaction detection on the input behavior feature vector to obtain the input behavior synchronization result. When the input behavior synchronization result is determined to be an asynchronous input behavior, directly return to the terminal home page and record the account authentication error process; when the input behavior synchronization result is determined to be a synchronous input behavior, execute the subsequent steps;

[0014] Step S13: Perform rasterization processing on the user input account information to obtain rasterized input account information; identify special characters in the rasterized input account information; perform character error elimination on the rasterized input account information based on the special characters, where the character error determination threshold is set to a character error rate of 2%-5% to obtain standardized input data;

[0015] Step S14: Perform length standardization on the standardized input data, and the target length range is set to 12-20 characters. If the character length is less than 12 characters, fill in "0" in the tail padding method. If it exceeds 20 characters, intercept the first 20 characters to generate a standardized account data; perform character set encoding processing on the standardized account data to obtain account encoding data;

[0016] Step S15: Perform forward padding on the account encoding data to generate account padding data; perform block segmentation on the account padding data to generate account block data.

[0017] The present invention can improve the accurate extraction ability of user operation features through input behavior sequence recognition. Input behavior reverse derivation can perform feature matching according to the actual input habits of users, enabling more accurate verification of the authenticity of account input behavior. Input behavior synchronous response detection can identify remote attack scenarios, prevent malicious programs from bypassing the local input verification mechanism, and improve the security of account authentication. Rasterization processing can effectively decompose the spatial distribution features of account input data, making the positioning of special characters more accurate. The character error elimination strategy combines rasterized data, making the character error determination process more stable. Setting the character error rate within the range of 2%-5% can ensure the fault tolerance of input data and avoid data distortion caused by excessive correction. Length standardization can ensure the consistency of account data during storage and authentication. Using the method of padding at the end and truncating at the front can ensure that all account data maintains a fixed length. Character set encoding processing can enhance the uniqueness of account data, improve the efficiency and security of data processing. Forward padding processing can reduce information loss during data transmission and improve data integrity. Block segmentation processing can enhance the scalability of data storage and calculation, enabling account authentication to still be efficient in a large-scale user environment.

[0018] Preferably, step S2 includes the following steps:

[0019] Step S21: Obtain the IP location of the terminal device; perform reverse geographical resolution on the IP location of the terminal device to generate location reference data;

[0020] Step S22: Perform coordinate system conversion on the location reference data to obtain original geographical coordinate data; extract longitude and latitude values based on the original geographical coordinate data; perform fuzzy superposition of the last digits of the longitude and latitude values to obtain a location area number;

[0021] Step S23: Extract the password behavior features of the user input password information; perform tensor construction on the password behavior features and account block data, and perform data integration to generate identity feature data;

[0022] Step S24: Perform timestamp fusion on the location area number according to the preset timestamp data to obtain spatio-temporal anchor point data;

[0023] Step S25: Perform dynamic fingerprint mapping on the identity feature data based on the spatio-temporal anchor point data to generate a user dynamic fingerprint.

[0024] The present invention improves the accuracy of user authentication by obtaining the IP location of the terminal device. The location reference data generated by reverse parsing of the geographical location provides important geographical information support for authentication. Coordinate system conversion of the location reference data can standardize the data, and the obtained original geographical coordinate data provides a basis for subsequent analysis. The implementation of extracting longitude and latitude values enables the system to more accurately locate the user's position. The process of fuzzy superposition of the last digit values enhances the privacy protection of geographical information. The generated location area number adds dynamic features to user authentication. Extracting the password behavior characteristics of the user input password information can capture the user's interaction pattern. The implementation of constructing tensors and integrating data makes the identity feature data richer, integrating multiple information sources. Timestamp fusion enhances the timeliness of the location area number, and the obtained spatio-temporal anchor data provides support in the time dimension for subsequent authentication. The implementation of dynamic fingerprint mapping of the identity feature data based on the spatio-temporal anchor data ensures the consistency and security of the user's identity in different times and spaces, and overall improves the multi-dimensional security and flexibility of account authentication, providing more comprehensive technical guarantee for user authentication.

[0025] Preferably, the key matrix projection based on the user's dynamic fingerprint in step S3 includes:

[0026] Perform multi-dimensional tensor expansion on the user's dynamic fingerprint and extract fingerprint space features;

[0027] Perform non-linear transformation on the fingerprint space features to generate feature transformation data;

[0028] Perform orthogonal basis mapping on the characteristic transformation data and construct an orthogonal feature matrix;

[0029] Perform key space projection on the orthogonal feature matrix to generate projected fingerprint data.

[0030] The present invention enhances the expressive ability and richness of information by performing multi-dimensional tensor expansion on the user's dynamic fingerprint, enabling the user identity characteristics to be analyzed in multiple dimensions, enhancing the comprehensive understanding of the user's behavior patterns and identity characteristics, facilitating the identification of the uniqueness and variability of the user, and extracting the fingerprint spatial characteristics not only captures the user's behavior characteristics in a specific environment but also provides basic data for subsequent feature processing. The feature transformation data generated by the non-linear transformation can better adapt to the changes in the user's dynamic behavior by introducing complexity and non-linear relationships, ensuring the flexibility and diversity of the feature data. The implementation of the orthogonal basis mapping ensures the independence and separability of the features, reduces the interference between different features, and helps improve the accuracy of subsequent analysis. The constructed orthogonal feature matrix provides a solid foundation for the projection in the key space, enabling the feature data to exhibit stronger discrimination ability in higher dimensions. The projection fingerprint data generated by the projection in the key space not only enhances the security and uniqueness of the authentication process but also provides high protection for the authentication information by mapping the user's dynamic features into the key space. Overall, it improves the accuracy and effectiveness of the account authentication, provides strong technical support for realizing efficient user authentication, and ensures the system's response ability and adaptability in the face of security threats.

[0031] Preferably, constructing a hierarchical authentication code based on the projection fingerprint data in step S3 includes:

[0032] Performing hierarchical slicing on the projection fingerprint data, where the slicing level is 3 - 5 layers, to obtain multi-level feature slices;

[0033] Performing cross-validation fusion on the multi-level feature slices, with the fusion times being 5 - 10 times, to generate inter-layer correlation data;

[0034] Performing hash rotation processing based on the inter-layer correlation data to obtain a rotated hash value;

[0035] Performing alternating permutation processing on the rotated hash value, where the number of permutation operations ranges from 2 to 4 times, to generate a permutation authentication basic unit;

[0036] Performing hierarchical encoding integration on the permutation authentication basic unit to obtain a hierarchical authentication code.

[0037] Through the hierarchical slicing process of the projected fingerprint data, the present invention can split complex feature information into multiple levels, enabling each level to be independently analyzed and processed. The obtained multi-level feature slices provide a basis for subsequent feature fusion. The implementation of cross-validation fusion enhances the complementarity and correlation between features at each level. The generated inter-level correlation data provides an important basis for constructing a more complex and secure authentication code. Performing hash rotation processing based on the inter-level correlation data can effectively obfuscate and protect the data. The obtained rotated hash value improves the anti-attack ability, making it difficult for external intruders to recover the original data. Performing alternating permutation processing on the rotated hash value further enhances the security and complexity of the data. The generated permutation authentication basic unit realizes multiple protections of the data and reduces the risk of being attacked. The implementation of hierarchical coding integration makes the authentication code more compact and efficient in structure. The finally obtained hierarchical authentication code not only has high security but also can perform flexible identity verification at different levels, overall enhancing the security and reliability of account authentication and providing a more solid technical guarantee for the protection of user information.

[0038] Preferably, the perturbation offset simulation of the hierarchical authentication code in step S4 includes:

[0039] Performing time-domain frequency spectrum transformation on the hierarchical authentication code to obtain authentication spectrum data;

[0040] Performing hierarchical scattering transformation on the authentication spectrum data and performing distribution matrix conversion to generate a scattering distribution matrix;

[0041] Performing multi-axis vector rotation simulation on the scattering distribution matrix to obtain rotation perturbation data;

[0042] Performing convolution fusion processing on the rotation perturbation data and the hierarchical authentication code to generate offset preparation data;

[0043] Performing gradient flow adjustment based on the offset preparation data and performing key integration processing to generate an offset authentication key.

[0044] The present invention enhances the depth and complexity of data processing by performing time-domain spectral transformation on the hierarchical authentication code, enabling the authentication code to exhibit richer information features in the spectral domain. The obtained authentication spectral data provides a multi-dimensional perspective for subsequent scattering transformation. The implementation of hierarchical scattering transformation enhances the data representation ability at different levels. The generated scattering distribution matrix lays the foundation for data diversity and anti-interference ability. Performing multi-axis vector rotation simulation on the scattering distribution matrix can effectively increase the randomness and unpredictability of the data. The obtained rotation perturbation data improves the security of the authentication code and reduces the risk of being attacked. Performing convolution fusion processing on the rotation perturbation data and the hierarchical authentication code realizes the deep integration of the data. The generated offset preparation data provides a strong foundation for subsequent key generation. The implementation of gradient flow adjustment based on the offset preparation data can optimize the data structure and ensure that the generated key achieves the best balance between security and effectiveness. The application of key integration processing finally generates an offset authentication key with higher security and flexibility, overall enhancing the protection ability and intelligent level of account authentication and providing more solid technical support for the security of user information.

[0045] Preferably, the dynamic rule verification of the offset authentication key and the adaptive key fitting based on the rule verification result in step S4 include:

[0046] Performing differential integrity detection on the offset authentication key to obtain an integrity verification index;

[0047] Constructing a multi-dimensional decision tree based on the integrity index and performing rule verification on the offset authentication key based on the multi-dimensional decision tree to obtain a rule verification result;

[0048] When the rule verification result is that the verification fails, directly return to the terminal home page and record the account authentication error process;

[0049] When the rule verification result is that the verification passes, perform elliptic curve mapping on the offset authentication key to obtain a curve mapping key;

[0050] Performing high-order polynomial approximation processing on the curve mapping key to obtain a continuous correction key;

[0051] Performing mixed hashing processing on the continuous correction key based on preset external state factors to obtain adaptive key metadata;

[0052] Performing recursive compression encoding on the adaptive key metadata to obtain dynamic token data.

[0053] The present invention enhances the security of the key by performing differential integrity detection on the offset authentication key. The obtained integrity verification index provides an important reference for subsequent rule verification. Constructing a multi-dimensional decision tree can analyze the effectiveness and security of the key in multiple dimensions. The implementation of rule verification on the offset authentication key based on the multi-dimensional decision tree enhances the intelligent management of the authentication process. The generation of the rule verification result provides a clear decision basis for the system. When the rule verification result fails, the system can quickly respond, return to the terminal, and record the account authentication error process, providing data support for subsequent security audits. When the rule verification result passes, performing elliptic curve mapping enhances the complexity and security of the key. The obtained curve mapping key has stronger anti-cracking ability. High-order polynomial approximation processing enables the generated continuous correction key to maintain stability in a changing environment. Performing mixed hashing on the continuous correction key based on preset external state factors can introduce external information into the key generation process. The obtained adaptive key metadata enhances the system's adaptability to dynamic environments. The implementation of recursive compression encoding on the adaptive key metadata makes the finally obtained dynamic token data more efficient during storage and transmission. Overall, it enhances the flexibility and security of account authentication, providing a more reliable technical guarantee for user identity verification.

[0054] Preferably, step S5 includes the following steps:

[0055] Step S51: Perform key deconstruction based on the dynamic token data. The key length range is set to 128 - 256 bits, and vector space mapping is performed. The vector dimension is set to 32 - 128 dimensions to obtain a link initialization vector.

[0056] Step S52: Construct a terminal device trust link based on the link initialization vector; perform authentication user matching on the terminal device trust link according to the preset user information library to obtain authentication user information.

[0057] Step S53: Perform permission mapping processing based on the authentication user information to obtain permission control data.

[0058] Step S54: Construct an account session for the terminal device trust link according to the permission control data to obtain an authenticated account session.

[0059] Through key deconstruction based on dynamic token data, the present invention can extract core security information. The implementation of vector space mapping enhances the data expression ability, making the link initialization vector more adaptable and flexible. The process of constructing a trust link for terminal devices enhances the system's trust in terminal devices. The implementation of authenticating user matching ensures the effective docking of user identity information with the system. The obtained authenticated user information provides a basis for subsequent permission control. The process of performing permission mapping based on the authenticated user information enables precise division of user permissions. The obtained permission control data ensures that the operation scope and permissions of users in the system are reasonably restricted. The implementation of constructing an account session for the terminal device trust link in combination with the permission control data enables the authenticated account session to have a clear permission structure, improving the security and reliability of account authentication as a whole, providing efficient technical support for user identity verification and permission management, and effectively preventing unauthorized access and operations.

[0060] The present invention also provides an account authentication system for executing the above-mentioned account authentication method. The account authentication system includes:

[0061] An account processing module, configured to collect user input account information and user input password information; eliminate character errors from the user input account information to obtain standardized input data; perform structure standardization processing on the standardized input data and perform block mapping to generate account block data;

[0062] A location fingerprint module, configured to obtain the IP location of the terminal device; perform longitude and latitude mapping on the IP location of the terminal device and perform last digit superposition of longitude and latitude to obtain a location area number; construct a dynamic fingerprint of the user based on the location area number for the user input password information and the account block data to generate a user dynamic fingerprint;

[0063] A key projection module, configured to perform key matrix projection based on the user dynamic fingerprint to generate projection fingerprint data; construct a hierarchical authentication code based on the projection fingerprint data;

[0064] A key perturbation module, configured to perform perturbation offset simulation on the hierarchical authentication code to generate an offset authentication key; perform dynamic rule verification on the offset authentication key and perform adaptive key fitting based on the rule verification result to generate dynamic token data;

[0065] A trust authentication module, configured to construct a trust link for the terminal device based on the dynamic token data; perform permission control mapping according to the trust link of the terminal device and construct an authenticated account session.

[0066] The present invention ensures the accuracy and consistency of user input information through the implementation of the account processing module. The elimination of character errors improves the quality of input data. The generation of standardized input data provides a reliable basis for subsequent processing. The structural standardization processing and block mapping enhance the organization and management efficiency of data. The application of the positioning fingerprint module ensures the correlation between user authentication and geographical information. The processing of longitude and latitude mapping and end-digit superposition improves the positioning accuracy. The implementation of dynamic fingerprint construction increases the security and uniqueness of authentication. The key projection module enhances the complexity and security of the authentication process through the application of user dynamic fingerprints. The construction of hierarchical authentication codes provides multiple protections for authentication. The perturbation offset simulation of the key perturbation module ensures the randomness and unpredictability of authentication keys. The implementation of dynamic rule verification enhances the adaptability and flexibility of keys. The generated dynamic token data provides security for real-time authentication. The construction of the trust authentication module ensures the security and reliability of data transmission. The implementation of permission control mapping enhances the security management ability of the system. The construction of the authenticated account session provides a stable basis and guarantee for the interaction between users and the system.

[0067] The present invention also provides a computer-readable storage medium storing a computer program, and when the computer program is executed, it implements the account authentication method described in any one of the above.

[0068] The use of the computer-readable storage medium in the present invention ensures the efficient storage and convenient acquisition of the account authentication method. The stored computer program realizes the automation and standardization of the authentication process. When the program is executed, it improves the response speed and processing efficiency of the system, provides reusable authentication logic, enhances the flexibility and adaptability of the system. The reliability of the storage medium reduces the risk of data loss. The scalability of the program supports future function upgrades and optimizations, ensuring the security and privacy protection of user information processing. The execution of the computer program reduces human operation errors, improves the accuracy and consistency of the overall authentication process, provides support for system integration and interoperability, and provides a basis for cooperation between different platforms and devices, ultimately forming an efficient, secure, and convenient account authentication mechanism. BRIEF DESCRIPTION OF THE DRAWINGS

[0069] Figure 1 It is a schematic diagram of the step flow of an account authentication method;

[0070] Figure 2 It is a schematic diagram of the detailed implementation step flow of step S2;

[0071] The realization of the object, functional features, and advantages of the present invention will be further described in conjunction with embodiments with reference to the drawings. DETAILED IMPLEMENTATION MANNER

[0072] The technical method of the present invention is described clearly and completely below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by technicians in this field without creative work are within the scope of protection of the present invention.

[0073] In addition, the accompanying drawings are only schematic illustrations of the present invention and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor methods and / or microcontroller methods.

[0074] It should be understood that, although the terms "first", "second", etc. may be used herein to describe various units, these units should not be limited by these terms. These terms are used only to distinguish one unit from another unit. For example, without departing from the scope of the exemplary embodiments, the first unit may be referred to as the second unit, and similarly the second unit may be referred to as the first unit. The term "and / or" used herein includes any and all combinations of one or more of the listed associated items.

[0075] To achieve this, please refer to Figures 1 to 2 , an account authentication method, comprising the following steps:

[0076] Step S1: collecting account information and password information input by the user; removing character errors from the account information input by the user to obtain standardized input data; performing structural standardization on the standardized input data, and performing block mapping to generate account block data;

[0077] Step S2: Obtain the IP location of the terminal device; perform latitude and longitude mapping on the IP location of the terminal device, and perform latitude and longitude end digit superposition to obtain the location area number; perform dynamic fingerprint construction on the user input password information and account block data based on the location area number to generate a user dynamic fingerprint;

[0078] Step S3: Perform key matrix projection based on the user's dynamic fingerprint to generate projected fingerprint data; construct a hierarchical authentication code based on the projected fingerprint data;

[0079] Step S4: performing disturbance shift simulation on the layered authentication code to generate a shift authentication key; performing dynamic rule verification on the shift authentication key, and performing adaptive key fitting based on the rule verification result to generate dynamic token data;

[0080] Step S5: Build a trust link for the terminal device based on the dynamic token data; perform permission control mapping according to the trust link of the terminal device, and build an authenticated account session.

[0081] The present invention provides basic data for identity authentication for the system by collecting user input account information and password information. The implementation of character error elimination ensures the accuracy of the input data. The generated standardized input data provides a clear basis for subsequent processing. The structure standardization processing and block mapping improve the data manageability and analysis ability. Obtaining the IP location of the terminal device introduces geographical information for user identity authentication. The longitude and latitude mapping and the last digit superposition enhance the data privacy protection. The generated location area number provides geographical features for the dynamic fingerprint construction. Building a dynamic fingerprint for the user input password information and the account block data based on the location area number can capture the unique behavior patterns of the user. The generated user dynamic fingerprint provides multi-dimensional features for subsequent security verification. Performing a dynamic offset simulation based on the user dynamic fingerprint ensures the randomness and unpredictability of the offset authentication key. The implementation of the dynamic rule verification improves the adaptability and flexibility of the key. The dynamic token data generated by the adaptive key fitting provides security guarantee for real-time verification. The construction of the trust link of the terminal device ensures the security of data transmission. The implementation of the permission control mapping enhances the security management ability of the system. The construction of the authenticated account session provides a stable basis for the interaction between the user and the system.

[0082] In the embodiment of the present invention, the account authentication method includes the following steps:

[0083] Step S1: Collect user input account information and user input password information; perform character error elimination on the user input account information to obtain standardized input data; perform structure standardization processing on the standardized input data, and perform block mapping to generate account block data;

[0084] In this embodiment, when collecting the user input account information and the user input password information, the character parsing module is used to perform character decomposition processing on the input data, the character matching rule library is used to perform character-by-character verification on the input characters, and the invalid characters are deleted through the error elimination algorithm to form the standardized input data. The standardized input data is input to the data structure conversion module. The data structure conversion module performs data reconstruction according to the preset formatting rules, and performs byte-level data splitting according to the set block strategy to generate account block data. The account block data is stored in the temporary buffer, and an integrity identifier is attached. The integrity identifier is calculated through the hash verification algorithm and is used for subsequent data integrity detection.

[0085] Step S2: Obtain the IP location of the terminal device; perform longitude and latitude mapping on the IP location of the terminal device, and perform the addition of the last digits of longitude and latitude to obtain the location area number; based on the location area number, construct a dynamic fingerprint for the user input password information and account block data to generate the user dynamic fingerprint;

[0086] In this embodiment, the IP address corresponding to the terminal device of the user input account information is extracted by the IP parsing module, and the extracted IP address is input to the geographical location mapping module. The geographical location mapping module calls the longitude and latitude conversion algorithm to obtain the longitude and latitude data. The longitude and latitude data performs the last digit truncation operation through the data processing module, and the truncated values are added and calculated to obtain the location area number. The location area number is input to the dynamic fingerprint generation module. The dynamic fingerprint generation module receives the location area number, the user input password information and the account block data, and uses the hash function to perform feature encoding on the three. The encoding result generates multiple independent feature vectors through the feature decomposition processing module. The feature vectors are input to the fingerprint mapping module to perform multi-layer fingerprint construction, and finally generate the user dynamic fingerprint.

[0087] Step S3: Perform a key matrix projection based on the user dynamic fingerprint to generate projection fingerprint data; construct a hierarchical authentication code based on the projection fingerprint data;

[0088] In this embodiment, the user dynamic fingerprint is input to the key matrix projection module. After receiving the dynamic fingerprint data, the key matrix projection module performs matrix transformation according to the projection matrix parameters. The data after matrix transformation performs non-linear projection through the projection mapping module to generate projection fingerprint data. The projection fingerprint data is input to the hierarchical authentication code construction module. The hierarchical authentication code construction module divides the projection fingerprint data layer by layer according to the authentication level rule, and each layer of data performs an independent hash operation. The data after the hash operation is combined to form a hierarchical authentication code. The hierarchical authentication code is stored in the secure storage unit and a unique authentication identifier is assigned.

[0089] Step S4: Perform a perturbation offset simulation on the hierarchical authentication code to generate an offset authentication key; perform a dynamic rule check on the offset authentication key, and perform an adaptive key fitting based on the rule check result to generate dynamic token data;

[0090] In this embodiment, the hierarchical authentication code is input into the perturbation offset module. After receiving the hierarchical authentication code, the perturbation offset module calls the perturbation vector generation algorithm to construct a perturbation vector. The perturbation vector is input into the offset matrix calculation module. The offset matrix calculation module uses the offset mapping model to perform a perturbation transformation on the authentication code. The data after the perturbation transformation forms an offset authentication key. The offset authentication key is input into the dynamic rule verification module. The dynamic rule verification module performs a matching calculation according to a preset rule template. The matching result is input into the key fitting module. The key fitting module performs a key fitting operation according to the fitting calculation model, and finally generates dynamic token data. The dynamic token data is stored in the token management unit and bound to the user device.

[0091] Step S5: Construct a terminal device trust link based on the dynamic token data; perform permission control mapping according to the terminal device trust link, and construct an authenticated account session.

[0092] In this embodiment, the dynamic token data is input into the terminal device trust link construction module. The terminal device trust link construction module performs an integrity check on the token data according to the token verification mechanism. After the verification passes, it performs a trust link establishment operation. After the trust link is established, it is input into the permission control mapping module. The permission control mapping module calculates the terminal permissions according to the permission configuration rules. The calculated permission data is input into the authentication session management module. The authentication session management module constructs an authenticated account session according to the permission data. The authenticated account session is stored in the session management unit and the session status is monitored in real time.

[0093] Preferably, step S1 includes the following steps:

[0094] Step S11: Collect the user input account information and the user input password information, and at the same time monitor the device mouse and keyboard behavior data; perform an input behavior sequence recognition on the device mouse and keyboard behavior data to generate an input behavior feature vector; perform an input behavior reverse derivation on the user input account information and the user input password information to generate the required input behavior features;

[0095] Step S12: Perform a synchronous reaction detection on the input behavior feature vector based on the required input behavior features to obtain an input behavior synchronization result. When the input behavior synchronization result is determined to be an asynchronous input behavior, directly return to the terminal home page and record the account authentication error process; when the input behavior synchronization result is determined to be a synchronous input behavior, perform the subsequent steps;

[0096] Step S13: Perform a rasterization process on the user input account information to obtain rasterized input account information; identify the special characters in the rasterized input account information; perform a character error elimination on the rasterized input account information based on the special characters, where the character error determination threshold is set to a character error rate of 2%-5%, so as to obtain standardized input data;

[0097] Step S14: Perform length standardization on the standardized input data. The target length range is set to 12 - 20 characters. If the character length is less than 12 characters, fill in "0" in the tail padding method. If it exceeds 20 characters, intercept the first 20 characters to generate the standardized account data; perform character set encoding processing on the standardized account data to obtain the account encoding data;

[0098] Step S15: Perform forward padding on the account encoding data to generate the account padding data; perform block segmentation on the account padding data to generate the account block data.

[0099] In this embodiment, when collecting the user input account information and the user input password information, the input monitoring module of the terminal device is used to synchronously capture the keyboard input and mouse click behaviors, associate and store the input content with the user operation time to obtain the complete user input sequence data. At the same time, the kernel-level input monitoring tool is used to record the keyboard scan code (Scan Code) and the character input time interval, so as to generate the user input behavior time series, convert the time series data into a high-dimensional behavior feature vector, and store it in the behavior analysis buffer. On this basis, the input account information and password information are inversely deduced. By comparing the user's past input patterns and comparing similar input behaviors, the expected feature set corresponding to the current input behavior is deduced. When synchronously comparing the input behavior feature vector with the expected input behavior feature set, the time window sliding matching method is adopted. The sliding window size is set to 500 ms, and the sliding step is 50 ms. The time difference distribution of the input behavior is calculated within this time window, and the timing synchronization degree of the user input is extracted. If the sliding matching score is lower than the set synchronization threshold of 75%, it is determined as an asynchronous input behavior. In the case of determining an asynchronous input behavior, the device remote control interface is called to return to the terminal home page, and the current input behavior characteristics and authentication error logs are stored in the exception database. If the sliding matching score is greater than or equal to 75%, the next step of processing is entered. When rasterizing the user input account information, the input string is slid and cut at a fixed step. The step is set to 3 characters. Each sliding generates a set of raster data, and the characters are converted to ASCII codes and stored in a two-dimensional array. Subsequently, special characters in the rasterized data are identified, including symbols, numbers, and mixed cases of uppercase and lowercase letters. The character distribution offset is calculated based on the detected special character positions, and error correction is performed in combination with the character error determination threshold. The error determination threshold is set to 2%-5%, that is, if the character similarity is higher than 95%, the original character is retained; if it is lower than 95% but higher than 90%, fuzzy matching replacement is performed; if it is lower than 90%, the character is removed. In this way, the standardized input data is obtained. When performing length standardization on the standardized input data, the target character length range is set to 12-20 characters. If the character length is less than 12 characters, the character '0' is filled at the end in a fixed filling manner to ensure that the data reaches the minimum length. If the character length exceeds 20 characters, the first 20 characters are intercepted, and the excess part is deleted to make it meet the maximum length limit. Subsequently, character set encoding processing is performed on the normalized account data. The UTF-8 encoding method is adopted to convert all characters into the standard encoding format, and the byte distribution characteristics of each character are calculated and stored in the account data storage structure. When performing forward padding processing on the encoded account data, first calculate the highest bit data of its binary representation. If the highest bit is 0, '1' is filled at the front end of the data; if the highest bit is 1, '0' is filled at the front end of the data to ensure that the first character after data filling forms a binary anti-correlation relationship with the original data.This enhances the uniqueness of the data. Subsequently, the filled data is segmented into blocks, adopting a fixed segmentation strategy. The length of each data segment is set to 4 bytes, and they are sequentially split and stored in the block storage unit, finally completing the construction of the account block data.

[0100] Preferably, step S2 includes the following steps:

[0101] Step S21: Obtain the IP location of the terminal device; perform reverse geographical location resolution on the IP location of the terminal device to generate location reference data;

[0102] Step S22: Perform coordinate system conversion on the location reference data to obtain the original geographical coordinate data; extract the longitude and latitude values based on the original geographical coordinate data; perform fuzzy superposition on the last digit of the longitude and latitude values to obtain the location area number;

[0103] Step S23: Extract the password behavior characteristics of the password information input by the user; perform tensor construction on the password behavior characteristics and the account block data, and perform data integration to generate identity characteristic data;

[0104] Step S24: Perform timestamp fusion on the location area number according to the preset timestamp data to obtain the spatio-temporal anchor point data;

[0105] Step S25: Perform dynamic fingerprint mapping on the identity characteristic data based on the spatio-temporal anchor point data to generate the user's dynamic fingerprint.

[0106] In this embodiment, when obtaining the IP location of the terminal device, the public IP address of the current device is obtained through the network interface of the industrial terminal device, and the WHOIS database interface is called to query the IP address ownership information, including the allocated operator, registered region, and autonomous system number ASN (Autonomous System Number) of the IP address. By cross-comparing the IP address ownership information with the historical access IP records of the industrial terminal device, secondary traceability analysis is performed on addresses outside the known IP range. The GeoIP database is used to obtain the detailed geographical information of the IP, including country, city, longitude and latitude information. At the same time, the DNS resolution server is combined to trace back the suspicious IP address to confirm whether the IP address belongs to a proxy server. When performing geographical location reverse analysis on the IP location of the terminal device, the IP reverse analysis technology is used to query the host name and subnet information corresponding to the IP. The global BGP (Border Gateway Protocol) routing table data is used to cross-verify the reachability and possible routing paths of the IP address. The longitude and latitude coordinates of the IP address are obtained by combining the geographical information database (such as MaxMind GeoIP2 or IP2Location), and compared with the IP address geographical location data provided by the basic telecommunications operator to improve the analysis accuracy. Finally, the basic location information such as country, city, and region is extracted and converted into standardized geographical information structure data to form the positioning reference data. When performing coordinate system conversion on the positioning reference data, first, normalization processing is performed according to the global navigation satellite system GNSS (Global Navigation Satellite System) reference coordinates. If the input data uses the WGS-84 coordinate system (World Geodetic System 1984), it is applied to the ellipsoid parameter conversion to GCJ-02 (Mars coordinate system) to adapt to the domestic map service system. If CGCS2000 (China Geodetic Coordinate System 2000) is used, projection transformation is performed to the UTM (Universal Transverse Mercator) coordinate system to ensure the consistency of geographical coordinates. Subsequently, the converted longitude and latitude values are extracted, and numerical fuzzy superposition processing is performed, that is, the last digit of the longitude and latitude values is subjected to floating weighted perturbation, and Gaussian Noise is used to perturb the values to generate a positioning area number to ensure the privacy security of different device locations while maintaining the relative accuracy of the device location. When extracting the password behavior characteristics of the user input password information, the keyboard input monitoring module is used to record the key sequence data when the user inputs the password.It includes the key press time, release time, key interval time, and key duration. At the same time, the mouse input trajectory analysis module is used to analyze the mouse movement path, speed, and click position distribution of the user near the password input box. Furthermore, biometric recognition technology is adopted to analyze the gesture stability, tapping force, and acceleration characteristics during touch input in the user input process. Combining historical input behavior data, a long short-term memory network (LSTM, Long Short-Term Memory) based on time series modeling is used to construct a password behavior feature vector. After normalizing it, it is used as part of the identity feature data, and the discrimination of key behavior features is enhanced through a feature weighting mechanism. When constructing tensors for password behavior features and account chunk data, first, the password behavior feature data is vectorized. The key press time series features, mouse trajectory features, and gesture stability features are respectively encoded as multi-dimensional feature vectors. A three-dimensional tensor (Tensor) is used to store the feature data at different time steps and is rectified based on the time window mechanism. At the same time, the account data is chunked according to the hash index, and the account historical login pattern, device usage record, and account change trajectory data are extracted to construct a multi-dimensional behavior feature tensor. The password behavior tensor and the account chunk tensor are concatenated, and a convolutional neural network (CNN, Convolutional Neural Network) is used to extract the deep pattern after feature fusion to enhance the correlation between different features. Finally, the identity feature data is obtained. When performing timestamp fusion on the positioning area number according to the preset timestamp data, the current login time of the device is recorded with a millisecond-level timestamp, and the network time protocol (NTP, Network Time Protocol) is synchronized for calibration. The historical login time series data is extracted, and the login behavior is segmented using the time window sliding mechanism. The login records within the same time window are clustered to identify short-term high-frequency access patterns, and the time feature mean is calculated based on the weighted time smoothing method. The time feature vector is combined with the positioning area number to generate spatio-temporal anchor data. When performing dynamic fingerprint mapping on the identity feature data based on the spatio-temporal anchor data, a hash mapping technology is adopted to combine the time dimension information of the spatio-temporal anchor data with the behavior pattern information of the identity feature data to construct a multi-dimensional identity fingerprint dataset. A multi-head attention mechanism (Multi-Head Attention) is used to calculate the matching degree between the spatio-temporal anchor data and the historical identity feature data. The identity features with a matching degree lower than the preset threshold are marked as abnormal, and a Gaussian mixture model (GMM, Gaussian Mixture Model) is used for clustering to extract the identity fingerprint features with high confidence. Finally, the user dynamic fingerprint is constructed.,

[0107] Preferably, the key matrix projection based on the user's dynamic fingerprint in step S3 includes:

[0108] Perform multi-dimensional tensor expansion on the user's dynamic fingerprint and extract fingerprint space features;

[0109] Perform a non-linear transformation on the fingerprint space features to generate feature transformation data;

[0110] Perform orthogonal basis mapping on the characteristic transformation data and construct an orthogonal feature matrix;

[0111] Perform key space projection on the orthogonal feature matrix to generate projected fingerprint data.

[0112] In this embodiment, when performing multi-dimensional tensor expansion on the user's dynamic fingerprint, the tensor decomposition technology is used to expand the user's dynamic fingerprint data. The user's dynamic fingerprint data is represented by a three-dimensional tensor. The first dimension represents the time series index, the second dimension represents the behavior feature channel, and the third dimension represents the feature value. The higher-order singular value decomposition (HOSVD) method is used to perform dimensionality reduction decomposition on the dynamic fingerprint tensor. First, the main direction component of the dynamic fingerprint tensor is calculated, and the singular value decomposition is performed on the main direction component. The eigenvectors corresponding to the first k singular values are retained as the expanded low-dimensional fingerprint features. The expanded fingerprint feature data is stored in a matrix structure. The rows of the matrix represent the time index, and the columns represent the behavior feature values. When performing a non-linear transformation on the fingerprint space features, a multi-layer perceptron (MLP) is used to perform a non-linear mapping on the fingerprint feature matrix. The fingerprint feature matrix is input into a three-layer neural network. The first layer is a fully connected layer, and the activation function uses ReLU (Rectified Linear Unit) to extract non-linear features. The second layer is a normalization layer, and the batch normalization method is used to make the distribution of the input data uniform. The third layer is a feature transformation layer, and the Tanh (hyperbolic tangent) activation function is used to perform a non-linear mapping on the data. The dimension of the transformed data remains the same as that of the input data. The non-linear transformation data is stored in a sparse matrix format. When performing an orthogonal basis mapping on the characteristic transformation data, the Gram-Schmidt orthogonalization method is used to perform an orthogonal transformation on the characteristic transformation data matrix. First, the first column of the characteristic transformation matrix is selected as the initial basis vector, and the subsequent column vectors are gradually projected. The projection components on the constructed orthogonal basis are calculated and normalized. Finally, a set of mutually orthogonal basis vectors is obtained. The orthonormalized data is stored as an orthogonal feature matrix. Each column of this matrix represents an orthogonal feature component, and each row represents a time index. When performing a key space projection on the orthogonal feature matrix, a linear transformation method is used to project the orthogonal feature matrix into the key space. First, a key matrix is constructed. The dimension of the key matrix is the same as the number of columns of the orthogonal feature matrix. Each key vector is generated by a pseudo-random number generator, and the random number generator uses the Mersenne Twister algorithm to generate a high-quality random sequence. The key matrix and the orthogonal feature matrix are multiplied matrix-wise to obtain the projected fingerprint data, and the projected fingerprint data is stored in an encrypted format.

[0113] Preferably, constructing a hierarchical authentication code based on the projected fingerprint data in step S3 includes:

[0114] Perform hierarchical slicing on the projected fingerprint data, where the slicing level is 3 - 5 layers, to obtain multi-level feature slices;

[0115] Perform cross-validation fusion on the multi-level feature slices, with the fusion times being 5 - 10 times, to generate inter-layer correlation data;

[0116] Perform hash rotation processing based on the inter-layer correlation data to obtain a rotated hash value;

[0117] Perform alternating permutation processing on the rotated hash value, where the number of permutation operations ranges from 2 - 4 times, to generate a permutation authentication basic unit;

[0118] Perform hierarchical encoding integration on the permutation authentication basic unit to obtain a hierarchical authentication code.

[0119] In this embodiment, when performing hierarchical slicing on the projected fingerprint data, the number of hierarchical slices is first determined. The hierarchical slice range is set to 3 - 5 layers. When setting the hierarchical slice boundaries, the dynamic window segmentation method is used. According to the numerical distribution of the projected fingerprint data, the uniformity of the numerical interval is calculated, and the data is partitioned through the sliding window technique. The step size of each window is dynamically adjusted according to the mean square deviation of the data, so that the data distribution within each hierarchical slice remains relatively balanced. The sliced data is stored as a hierarchical matrix, where each matrix represents a hierarchical slice. The rows represent the time index, and the columns represent the eigenvalues. All slice matrices are stored in independent data channels. After slicing, the data at each level is verified. When performing cross - validation fusion on the multi - level feature slices, the block - random sampling method is used to select the data of different hierarchical slices. 10% - 15% of the data samples are randomly selected from each slice, and the Euclidean distance between each slice is calculated to measure the similarity of the data at different levels. When calculating the similarity, the K - Nearest Neighbors (KNN) method is used, and the nearest 5 - 10 neighbor data points are selected for weighted averaging to generate the inter - layer correlation data. During the fusion process, the feature weighting method is used to perform dimensionality reduction on the features with lower weights, making the fused data more compact. The fused inter - layer correlation data is stored in the format of a feature vector. When performing hash rotation processing based on the inter - layer correlation data, first, the inter - layer correlation data is hashed. The SHA - 256 (Secure Hash Algorithm 256) is used to calculate the hash value of each data block. To increase the complexity of the hash result, the hash rotation technique is used to perform a cyclic shift on each hash value. The direction and length of the shift are determined according to the mean value of the inter - layer correlation data. If the mean value is greater than a certain threshold, it rotates to the left, otherwise, it rotates to the right. The rotated hash values are stored in the hash index table, and a mapping relationship from the hash value to the original data is established. When performing alternating permutation processing on the rotated hash values, the grouped permutation method is used to rearrange the hash values in the hash index table. The number of permutations is set to 2 - 4 times. Each time a permutation is performed, the bidirectional permutation strategy is used. First, two hash values are randomly selected from the index table for exchange, and then four consecutive hash values are selected for cyclic shift to ensure the balanced distribution of the permuted data. After alternating permutation, the position of each hash value in the index table changes. The permuted data is stored as the authentication basic unit. When performing hierarchical coding integration on the permuted authentication basic unit, the block - coding method is used to divide the permuted data into fixed - size coding blocks. The length of each coding block is calculated according to the entropy value of the projected fingerprint data. The Bose - Chaudhuri - Hocquenghem (BCH) coding method is used to code the data blocks, and the coded data is stored in the authentication code database, finally obtaining the hierarchical authentication code.

[0120] Preferably, the perturbation offset simulation of the hierarchical authentication code in step S4 includes:

[0121] Performing time-domain frequency spectrum transformation on the hierarchical authentication code to obtain authentication spectrum data;

[0122] Performing hierarchical scattering transformation on the authentication spectrum data and performing distribution matrix conversion to generate a scattering distribution matrix;

[0123] Performing multi-axis vector rotation simulation on the scattering distribution matrix to obtain rotation perturbation data;

[0124] Performing convolution fusion processing on the rotation perturbation data and the hierarchical authentication code to generate offset preparation data;

[0125] Based on the offset preparation data, performing gradient flow adjustment and performing key integration processing to generate an offset authentication key.

[0126] In this embodiment, when performing time-domain spectral transformation on the hierarchical authentication code, first, the fast Fourier transform (FFT) algorithm is used to transform the numerical sequence of the hierarchical authentication code, extracting the amplitude and phase information of the time-domain signal on different frequency components. During the FFT calculation, zero-padding is performed on the input data to expand the data length to a power of 2 to improve the calculation efficiency. After the FFT transformation, the spectral data is stored as a complex matrix, where the rows of the matrix represent frequency components and the columns represent time frames. Each matrix element stores the amplitude and phase information of the corresponding frequency component on the corresponding time frame. To avoid the influence of high-frequency noise on the signal quality, a low-pass filter is used to smooth the spectral data. The cut-off frequency of the filter is determined according to the frequency distribution characteristics of the hierarchical authentication code. The processed authentication spectral data is stored in a three-dimensional tensor structure. When performing hierarchical scattering transformation on the authentication spectral data, first, the wavelet scattering transform method is used to perform multi-scale expansion on the spectral data. During the wavelet scattering process, the Morlet wavelet is selected as the mother wavelet, and hierarchical convolution operations are performed on the spectral data. After each layer of convolution, scattering features are extracted, and the scattering energy is calculated to generate a hierarchical scattering matrix. To improve the stability of feature extraction, the local mean normalization method is used to process the scattering matrix, making the eigenvalues of different levels in the same numerical range. Subsequently, a distribution matrix transformation is performed on the hierarchical scattering matrix. The transformation method uses the principal component analysis (PCA) method to reduce the dimension of the matrix, projecting the high-dimensional features into a low-dimensional space while retaining the maximum variance information, and finally generating a scattering distribution matrix. When performing multi-axis vector rotation simulation on the scattering distribution matrix, first, the matrix is eigen-decomposed to extract the principal component vectors. The number of rotation axes is set, and the number of rotation axes is determined according to the number of principal components of the matrix. The random rotation matrix generation method is used to construct a rotation transformation matrix. The random rotation matrix is in the form of an orthogonal matrix to ensure that the norm of the rotated matrix remains unchanged. During the actual calculation process, the Givens rotation method is selected for single-axis rotation operations, and the Householder transformation is used to perform high-dimensional rotation on the matrix to simulate the perturbation effects at different angles. The rotated data is stored as a rotation perturbation data matrix, and the logarithmic normalization method is used to standardize the data range. When performing convolution fusion processing on the rotation perturbation data and the hierarchical authentication code, the convolutional neural network (CNN) method is used for feature fusion. First, the rotation perturbation data and the hierarchical authentication code are expanded to the same dimension and channel alignment is performed. In the convolution operation, a 3×3 convolution kernel is selected.The convolution stride is set to 1, and the padding mode is used to keep the size of the output data unchanged. During the convolution process, the correlation between data channels is calculated, and the ReLU (Rectified Linear Unit) activation function is used to enhance the non-linear features. To avoid overfitting, a batch normalization layer is added after the convolution layer to standardize the data, and finally, offset preparation data is generated. When adjusting the gradient flow based on the offset preparation data, the Adam (Adaptive Moment Estimation) method is used to dynamically adjust the gradient direction. First, the gradient matrix of the offset preparation data is calculated, and the first-order moment estimation and second-order moment estimation are calculated. During the gradient calculation process, the exponential decay average method is used to smooth the historical gradients to reduce gradient oscillation. After the gradient adjustment, a key integration method is used for key reconstruction. The key integration method uses a key derivation algorithm based on a hash tree to perform a hash mapping on the adjusted gradient data to generate a key branch structure, and finally, an offset authentication key is obtained.

[0127] Preferably, the dynamic rule verification of the offset authentication key and the adaptive key fitting based on the rule verification result in step S4 include:

[0128] Perform differential integrity detection on the offset authentication key to obtain an integrity verification index;

[0129] Construct a multi-dimensional decision tree based on the integrity index and perform rule verification on the offset authentication key based on the multi-dimensional decision tree to obtain a rule verification result;

[0130] When the rule verification result is that the verification fails, directly return to the terminal home page and record the account authentication error process;

[0131] When the rule verification result is that the verification passes, perform an elliptic curve mapping on the offset authentication key to obtain a curve mapping key;

[0132] Perform high-order polynomial approximation processing on the curve mapping key to obtain a continuous correction key;

[0133] Perform mixed hashing on the continuous correction key based on preset external state factors to obtain adaptive key metadata;

[0134] Perform recursive compression encoding on the adaptive key metadata to obtain dynamic token data.

[0135] In this embodiment, when performing differential integrity detection on the offset authentication key, first, the hash integrity verification method is used to calculate the hash of the key data. During the calculation process, SHA-256 (Secure Hash Algorithm 256-bit) is used to perform a one-way mapping on the offset authentication key to generate hash digest data of a fixed length. After the hash calculation is completed, the block comparison method is used to compare the current hash value with the stored reference hash value. The granularity of the block comparison is set to 32 bytes to ensure that the detection process can be accurate to the level of individual data blocks. To detect data changes, the Hamming Distance between the hash values is calculated. If the Hamming Distance exceeds the preset threshold, it is determined that the integrity of the offset authentication key is abnormal. When constructing a multi-dimensional decision tree based on the integrity index, the CART (Classification and Regression Tree) algorithm is used to construct a decision model. First, decision variables are defined, including integrity hash deviation, data block differential ratio, key matching degree, etc. The integrity index data set is stratified by samples, and the stratification standard is set according to the key differential integrity characteristics. The Gini Index is used as the splitting criterion to calculate the impurity of the data set in different feature dimensions, and the feature with the smallest impurity is selected as the splitting point. The decision sub-tree is recursively constructed to generate the final multi-dimensional decision tree. During the rule verification process, the offset authentication key data is input, and based on the splitting path of the multi-dimensional decision tree, the key data is judged step by step, and finally the rule verification result is obtained. The rule verification result is stored as a binary flag, where the value of 0 indicates that the verification fails, and the value of 1 indicates that the verification passes. When the rule verification result is that the verification fails, the terminal home page is directly returned, and the account authentication error process is recorded. The error record uses the log storage method, and the log format includes the authentication timestamp, the hash value of the key data, the error type, and the system status information. To ensure the integrity of the log, the log data is encrypted using AES-256 (Advanced Encryption Standard 256-bit), and the encryption key is stored in the Secure Storage Module. At the same time, the authentication failure count is accumulated, and the account freezing mechanism is triggered based on the number of failures. If the number of authentication failures exceeds the preset threshold, the automatic locking logic is triggered, and the account status flag is updated in the database. When the rule verification result is that the verification passes, when performing elliptic curve mapping on the offset authentication key, the Elliptic Curve Cryptography (ECC) method is used. First, the elliptic curve parameters are selected, and the curve equation is set to y2 = x 3+ax + b, where the parameters a and b are set according to the recommendations of NIST (National Institute of Standards and Technology). During the mapping process, first, the offset authentication key is converted into the point coordinates on the elliptic curve. Using the base point generation method, the key data is used as the input of the curve parameters to calculate the corresponding elliptic curve point. Finally, the curve mapping key is generated and stored as a set of coordinate points. When performing high-order polynomial approximation processing on the curve mapping key, the Legendre Polynomial expansion method is used to fit the curve data. The order of the Legendre polynomial is set to 5 - 7 to ensure the fitting accuracy. The least squares method is used to calculate the polynomial coefficients and perform high-order fitting on the curve mapping key. During the calculation process, the QR decomposition method is used for matrix decomposition to improve the calculation stability. The fitted data is stored as the continuous correction key. When performing mixed hashing processing on the continuous correction key based on the preset external state factors, first, the external state factor variables are defined, including system time, device ID (Device ID), user behavior patterns, etc. The SHA-512 (Secure Hash Algorithm 512-bit) is used to perform one-way hashing conversion on the continuous correction key, and the external state factors are used as the hashing input parameters to generate the final adaptive key metadata. To improve the key security, the HMAC (Hash-based Message Authentication Code) method is used to perform secondary verification on the hashing result. When performing recursive compression encoding on the adaptive key metadata, the idempotent Huffman coding method is used to perform variable-length encoding on the key data. First, the occurrence frequencies of each character in the key data are counted to construct the Huffman tree, and the encoding is assigned according to the weights. The encoding is optimized recursively. During the encoding process, the redundancy of the data block is detected, and the highly redundant data blocks are repeatedly compressed to finally generate the dynamic token data.

[0136] Preferably, step S5 includes the following steps:

[0137] Step S51: Perform key deconstruction based on the dynamic token data. The key length range is set to 128 - 256 bits, and vector space mapping is performed. The vector dimension is set to 32 - 128 dimensions to obtain the link initialization vector;

[0138] Step S52: Build a trusted link for the terminal device based on the link initialization vector; perform authentication user matching on the trusted link of the terminal device according to the preset user information library to obtain the authenticated user information;

[0139] Step S53: Perform permission mapping processing based on the authenticated user information to obtain permission control data;

[0140] Step S54: Build an account session for the trusted link of the terminal device according to the permission control data to obtain an authenticated account session.

[0141] In this embodiment, when deconstructing the key based on the dynamic token data, first, the dynamic token data is parsed. The parsing process adopts a block parsing method, and the size of each data block is set to 16 bytes. The obtained key data is subjected to hash truncation processing. The truncation method uses the SHA-384 (Secure Hash Algorithm 384-bit) method to calculate the hash of the data block, and the first 128 - 256 bits of the hash result are truncated as the key body data. To ensure the consistency of the key data, the truncated key data is normalized. The normalization method uses min-max normalization to map the key data to the interval [0, 1]. After completing the key normalization, the key data is subjected to vector space mapping based on the Gaussian Random Projection method. During the vector mapping process, first, a projection matrix with a dimension of 128×32 is constructed. This matrix is generated according to the normal distribution N(0, 1) and is orthonormalized to ensure the stability of the vector mapping. The normalized key data is used as the input, and matrix multiplication is used for projection transformation to finally generate the link initialization vector. The data format of the link initialization vector is a floating-point matrix with a dimension of 32 - 128. When constructing the terminal device trust link based on the link initialization vector, first, the unique identifier of the terminal device (UUID, Universally Unique Identifier) is loaded. The UUID data is sourced from the terminal hardware fingerprint information, including the motherboard serial number, network card MAC address (Media Access Control Address), firmware version number, etc. The SHA-512 hash is calculated for the UUID data, and the first 256 bits are truncated as the terminal device identity identifier. The link initialization vector and the terminal device identity identifier are subjected to hash fusion processing. The fusion method uses the HMAC (Hash-based Message Authentication Code) method, and the key is set as the device private key. After the fusion calculation is completed, the terminal device trust link is generated. The data format of the terminal device trust link is a hash value with a fixed length. Subsequently, the user identity is matched based on the terminal device trust link. The matching process uses a data query method based on hash indexing. First, a hash index is constructed for the preset user information library. The index structure uses the B+ tree (B+Tree) data structure to improve the query efficiency. During the user matching process, the hash value of the terminal device trust link is input, and a quick search is performed based on the index structure. If a matching item is found, the corresponding authenticated user information is returned. The storage format of the authenticated user information includes the user ID, permission level, device binding information, etc. When performing permission mapping processing based on the authenticated user information, first, the permission control rule set is loaded. The permission control rule set uses JSON (JavaScript Object Notation,Stored in JavaScript Object Notation (JSON) format, each rule contains user roles, access permissions, operation constraints, etc. For the authenticated user information, rule matching is performed. During the matching process, the user role information is extracted based on the user ID, and the corresponding permission level is found in the permission rule set according to the role information. The permission mapping method adopts the mapping method based on the RBAC (Role-Based Access Control) model. During the mapping process, the corresponding permission set is obtained according to the user role, and a permission control matrix is constructed based on the permission set. The permission control matrix is stored in a two-dimensional array. The rows represent user roles, and the columns represent executable operations. The value of the matrix element being 0 indicates no permission, and the value being 1 indicates having the execution permission. After completing the permission mapping, permission control data is generated. When constructing an account session for the trusted link of the terminal device according to the permission control data, the authenticated user information is first loaded, and the account status is verified according to the permission control data. During the account status verification process, it is checked whether the user account is in a normal state. The status information comes from the user database, including account activation status, login failure count, password expiration date, etc. If the account status is normal, an account session token is generated. The token generation method adopts the JWT (JSON Web Token) mechanism. The token format includes user ID, permission level, issuance time, expiration time, etc. It is signed using HMAC-SHA256 (Hash-based Message Authentication Code Secure Hash Algorithm 256-bit) to ensure the integrity of the token. The generated authenticated account session is stored in the server session management module and cached using Redis (Remote Dictionary Server) to improve access efficiency. After the session is established, the account session token is returned, and the user is allowed to perform subsequent operations.

[0142] The present invention also provides an account authentication system for executing the above-mentioned account authentication method. The account authentication system includes:

[0143] An account processing module for collecting user input account information and user input password information; removing character errors from the user input account information to obtain standardized input data; performing structure standardization processing on the standardized input data and performing block mapping to generate account block data;

[0144] A positioning fingerprint module, which is used to obtain the IP positioning of the terminal device; perform longitude and latitude mapping on the IP positioning of the terminal device, and perform the last digit superposition of longitude and latitude to obtain a positioning area number; dynamically construct a fingerprint based on the positioning area number for the user input password information and account block data to generate a user dynamic fingerprint;

[0145] A key projection module, which is used to perform key matrix projection based on the user dynamic fingerprint to generate projected fingerprint data; construct a hierarchical authentication code based on the projected fingerprint data;

[0146] A key perturbation module, which is used to perform perturbation offset simulation on the hierarchical authentication code to generate an offset authentication key; perform dynamic rule verification on the offset authentication key, and perform adaptive key fitting based on the rule verification result to generate dynamic token data;

[0147] A trust authentication module, which is used to construct a terminal device trust link based on the dynamic token data; perform permission control mapping according to the terminal device trust link, and construct an authenticated account session.

[0148] The present invention ensures the accuracy and consistency of the user input information through the implementation of the account processing module. The character error elimination improves the quality of the input data. The generation of standardized input data provides a reliable basis for subsequent processing. The structure standardization processing and block mapping enhance the organization and management efficiency of the data. The application of the positioning fingerprint module ensures the relevance between user authentication and geographical information. The processing of longitude and latitude mapping and the last digit superposition improve the positioning accuracy. The implementation of dynamic fingerprint construction increases the security and uniqueness of authentication. The key projection module improves the complexity and security of the authentication process through the application of the user dynamic fingerprint. The construction of the hierarchical authentication code provides multiple protections for authentication. The perturbation offset simulation of the key perturbation module ensures the randomness and unpredictability of the authentication key. The implementation of dynamic rule verification enhances the adaptability and flexibility of the key. The generated dynamic token data provides security for real-time authentication. The construction of the trust authentication module ensures the security and reliability of data transmission. The implementation of permission control mapping enhances the security management ability of the system. The construction of the authenticated account session provides a stable basis and guarantee for the interaction between the user and the system.

[0149] The present invention also provides a computer-readable storage medium storing a computer program, and when the computer program is executed, it implements the account authentication method described in any one of the above.

[0150] The present invention ensures the efficient storage and convenient access of the account authentication method through the use of a computer-readable storage medium. The stored computer program realizes the automation and standardization of the authentication process. When the program is executed, it improves the system's response speed and processing efficiency, provides reusable authentication logic, enhances the system's flexibility and adaptability. The reliability of the storage medium reduces the risk of data loss. The scalability of the program supports future function upgrades and optimizations, ensuring the security of user information processing and privacy protection. The execution of the computer program reduces human operation errors, improves the accuracy and consistency of the overall authentication process, provides support for system integration and interoperability, and provides a basis for collaboration between different platforms and devices. Ultimately, an efficient, secure, and convenient account authentication mechanism is formed.

[0151] Therefore, from any perspective, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the application document are intended to be encompassed within the present invention.

[0152] The above description is only a specific implementation manner of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features invented herein.

Claims

1. An account authentication method, characterized in that: Applied to remote operation and maintenance of industrial terminal equipment, including the following steps: Step S1: collecting the account information and password information input by the user; performing device synchronization reaction detection on the account information and password information input by the user, and eliminating character errors of the account information input by the user based on the synchronization reaction detection result to obtain standardized input data; performing structural standardization processing on the standardized input data, and performing block mapping to generate account block data; Step S2: Obtain the IP location of the terminal device; perform latitude and longitude mapping on the IP location of the terminal device, and perform latitude and longitude end digit superposition to obtain the location area number; perform dynamic fingerprint construction on the user input password information and account block data based on the location area number to generate a user dynamic fingerprint; Step S3: Perform key matrix projection based on the user's dynamic fingerprint to generate projected fingerprint data; construct a hierarchical authentication code based on the projected fingerprint data; Step S4: Perform disturbance shift simulation on the layered authentication code to generate a shift authentication key; perform dynamic rule verification on the shift authentication key, and perform adaptive key fitting based on the rule verification result to generate dynamic token data; Step S5: Building a terminal device trust link based on the dynamic token data; performing permission control mapping according to the terminal device trust link, and building an authentication account session.

2. The account authentication method according to claim 1, characterized in that: Step S1 includes the following steps: Step S11: collecting user input account information and user input password information, and monitoring device mouse and keyboard behavior data at the same time; performing input behavior sequence recognition on the device mouse and keyboard behavior data to generate an input behavior feature vector; performing input behavior reverse deduction on the user input account information and user input password information to generate the required input behavior feature; Step S12: Perform synchronous reaction detection on the input behavior feature vector based on the required input behavior feature to obtain the input behavior synchronization result. When the input behavior synchronization result is determined to be an asynchronous input behavior, directly return to the terminal homepage and record the account authentication error process; when the input behavior synchronization result is determined to be a synchronous input behavior, execute the subsequent steps; Step S13: rasterizing the user input account information to obtain rasterized input account information; identifying special characters in the rasterized input account information; and performing character error elimination on the rasterized input account information based on the special characters, wherein the character error determination threshold is set to a character error rate of 2%-5% to obtain standardized input data; Step S14: Standardize the length of the standardized input data, and set the target length range to 12-20 characters. If the character length is less than 12 characters, fill it with "0" at the end. If it exceeds 20 characters, cut off the first 20 characters to generate standardized account data; perform character set encoding on the standardized account data to obtain account code data; Step S15: forward-fill the account code data to generate account filling data; segment the account filling data into blocks to generate account block data.

3. The account authentication method according to claim 1, characterized in that: Step S2 includes the following steps: Step S21: Obtain the IP location of the terminal device; perform reverse analysis of the geographical location of the IP location of the terminal device to generate positioning reference data; Step S22: convert the coordinate system of the positioning reference data to obtain original geographic coordinate data; extract longitude and latitude values ​​based on the original geographic coordinate data; perform fuzzy superposition of the last digit values ​​of the longitude and latitude values ​​to obtain the positioning area number; Step S23: extracting password behavior features of the password information input by the user; constructing a tensor for the password behavior features and account block data, and integrating the data to generate identity feature data; Step S24: performing timestamp fusion on the positioning area number according to the preset timestamp data to obtain spatiotemporal anchor point data; Step S25: Perform dynamic fingerprint mapping on the identity feature data based on the spatiotemporal anchor point data to generate a user dynamic fingerprint.

4. The account authentication method according to claim 1, characterized in that: The key matrix projection based on the user dynamic fingerprint described in step S3 includes: Perform multi-dimensional tensor expansion on user dynamic fingerprints and extract fingerprint space features; Perform nonlinear transformation on fingerprint space features to generate feature transformation data; Perform orthogonal basis mapping on the characteristic transformation data and construct an orthogonal characteristic matrix; The orthogonal feature matrix is ​​projected into the key space to generate the projected fingerprint data.

5. The account authentication method according to claim 1, characterized in that: The step S3 of constructing a hierarchical authentication code based on the projected fingerprint data includes: The projected fingerprint data is sliced ​​hierarchically, where the slice level is 3-5 layers, and multi-level feature slices are obtained; Perform cross-validation fusion on multi-level feature slices, with the fusion times ranging from 5 to 10 times, to generate inter-layer correlation data; Perform hash rotation processing based on inter-layer association data to obtain a rotation hash value; Performing an alternating permutation process on the rotating hash value, wherein the number of permutation operations ranges from 2 to 4 times, to generate a permutation authentication basic unit; The replacement authentication basic units are integrated in a hierarchical coding manner to obtain a hierarchical authentication code.

6. The account authentication method according to claim 1, characterized in that: The perturbation shift simulation of the layered authentication code in step S4 includes: Performing time domain spectrum transformation on the hierarchical authentication code to obtain authentication spectrum data; Performing hierarchical scattering transformation on the certified spectrum data and performing distribution matrix conversion to generate a scattering distribution matrix; Perform multi-axis vector rotation simulation on the scattering distribution matrix to obtain rotation disturbance data; Perform convolution fusion processing on the rotation disturbance data and the layered authentication code to generate offset preparation data; Gradient flow adjustment is performed based on the offset preparation data, and key integration processing is performed to generate an offset authentication key.

7. The account authentication method according to claim 1, characterized in that: The step S4 of dynamically checking the offset authentication key and performing adaptive key fitting based on the rule checking result includes: Perform differential integrity detection on the offset authentication key to obtain an integrity verification indicator; A multidimensional decision tree is constructed according to the integrity index, and a rule verification is performed on the offset authentication key based on the multidimensional decision tree to obtain a rule verification result; When the rule verification result is verification failure, it will directly return to the terminal homepage and record the account authentication error process; When the rule verification result is verification passed, the offset authentication key is mapped by elliptic curve to obtain the curve mapping key; Perform high-order polynomial approximation processing on the curve mapping key to obtain a continuous correction key; Performing mixed hashing on the continuous correction key based on a preset external state factor to obtain adaptive key metadata; The adaptive key metadata is recursively compressed and encoded to obtain dynamic token data.

8. The account authentication method according to claim 1, characterized in that: Step S5 includes the following steps: Step S51: Deconstruct the key based on the dynamic token data, set the key length range to 128-256 bits, and perform vector space mapping, set the vector dimension to 32-128 dimensions, to obtain a link initialization vector; Step S52: constructing a terminal device trust link based on the link initialization vector; performing authentication user matching on the terminal device trust link according to a preset user information database to obtain authentication user information; Step S53: Perform permission mapping based on the authenticated user information to obtain permission control data; Step S54: construct an account session for the terminal device trust link according to the authority control data to obtain an authenticated account session.

9. An account authentication system, characterized in that: Used to execute the account authentication method according to claim 1, the account authentication system comprises: The account processing module is used to collect the account information and password information input by the user; remove character errors from the account information input by the user to obtain standardized input data; perform structural standardization on the standardized input data, and perform block mapping to generate account block data; The positioning fingerprint module is used to obtain the IP location of the terminal device; perform latitude and longitude mapping on the IP location of the terminal device, and perform latitude and longitude end digit superposition to obtain the positioning area number; based on the positioning area number, perform dynamic fingerprint construction on the user input password information and account block data to generate a user dynamic fingerprint; The key projection module is used to perform key matrix projection based on the user's dynamic fingerprint to generate projected fingerprint data; and to construct a hierarchical authentication code based on the projected fingerprint data; The key perturbation module is used to simulate the perturbation offset of the layered authentication code to generate the offset authentication key; perform dynamic rule verification on the offset authentication key, and perform adaptive key fitting based on the rule verification result to generate dynamic token data; The trust authentication module is used to build a terminal device trust link based on dynamic token data; perform permission control mapping according to the terminal device trust link, and build an authentication account session.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed, the account authentication method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Data security verification method of click type dynamic verification code

    CN118118265A

  • One-time password authentication system and method

    JP2006004020A

  • Signature authentication method and apparatus

    WO2024139253A1

Cited By

  • Traceable notarization lottery system and method based on national cryptographic algorithm

    CN120708321A

  • Information encryption management method and system

    CN120785659A

  • Encryption authentication method and system for power monitoring system

    CN120834954A

  • Security access and credibility authentication system for electricity utilization information acquisition terminal

    CN121711167A

  • Electricity information collection terminal secure access and trusted authentication system

    CN121711167B