Computer remote login identification system based on artificial intelligence

Through multimodal identity authentication and dynamic behavior analysis based on artificial intelligence, the automatic unlocking of the computer remote login system in the lock screen state is realized, solving the troublesome problems of manual unlocking in the existing technology, and improving the automation and security of the system.

CN120223409AInactive Publication Date: 2025-06-27CHANGZHOU VOCATIONAL INST OF ENG
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510453762.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-06-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When the existing computer remote login system is in the locked state, it requires manual clicking to unlock, which leads to troublesome operation, especially when the screen unlock password is provided.

Method used

Using an artificial intelligence-based computer remote login recognition system, the multi-modal identity authentication module, dynamic behavior analysis engine and intelligent unlocking decision tree are used to automatically identify and unlock devices.

Benefits of technology

It improves the automation and security of remote login, reduces the need for manual operations, especially in the locked screen state, ensuring a more efficient and convenient remote access experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223409A_ABST
    Figure CN120223409A_ABST
Patent Text Reader

Abstract

The invention discloses a computer remote login identification system based on artificial intelligence, and the system comprises a remote login request receiving and processing module which is responsible for receiving a remote login request of a user, and carrying out the preliminary processing and verification; the multi-mode identity authentication module adopts a three-factor verification matrix of biological characteristics, behavior characteristics and equipment fingerprints, and adjusts weights of different authentication dimensions according to security requirements and user requirements; the lock screen state sensing module is responsible for sensing a lock screen state; the dynamic behavior analysis engine is used for monitoring behavior characteristics of the user in real time and comparing the behavior characteristics with a preset abnormal behavior mode so as to find abnormal login behaviors in time; the intelligent unlocking decision tree is used for making an intelligent unlocking decision according to the authentication score, the equipment environment and the behavior abnormality; and the security execution module is responsible for automatically filling a password and executing an unlocking operation after the user identity authentication is passed, and monitoring an abnormal condition in the unlocking process in real time in combination with equipment environment monitoring and an abnormal detection model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer remote login, and particularly to a computer remote login recognition system based on artificial intelligence. Background Art

[0002] Computer remote login refers to the process of accessing and controlling another computer from one computer through the Internet or other networks using specific software or built-in tools. In modern work and daily life, computer remote login technology has been increasingly valued for its convenience and efficiency. This technology can not only help people work from home but also enable IT professionals to remotely solve computer problems, greatly improving work efficiency and the flexibility to solve problems.

[0003] In the prior art, common computer remote login software includes Microsoft Remote Desktop, Windows Remote Assistance, AOMEI Remote Desktop, Google Remote Desktop, Sunlogin Remote, etc. Generally, they are used for remote office assistance of computers. Sometimes, if the computer has not been operated for a long time, it will enter the screen-off and lock-screen state, and manual clicking operations are required to unlock and turn on the screen again. For example, it is very troublesome when there is a screen unlock password. Therefore, a computer remote login recognition system based on artificial intelligence is proposed. Summary of the Invention

[0004] The purpose of the present invention is to solve the deficiencies in the prior art, and a computer remote login recognition system based on artificial intelligence is proposed.

[0005] To achieve the above purpose, the present invention adopts the following technical solutions:

[0006] A computer remote login recognition system based on artificial intelligence, comprising:

[0007] A remote login request receiving and processing module: responsible for receiving the user's remote login request, performing preliminary processing and verification, and combining the device fingerprint library and the biometric library to authenticate the identity of the requesting device to prevent the access of illegal devices;

[0008] A multimodal identity authentication module: adopting a three-factor verification matrix of biometrics, behavioral characteristics, and device fingerprints, and adjusting the weights of different authentication dimensions according to security requirements and user needs;

[0009] A lock-screen state perception module: responsible for perceiving the lock-screen state;

[0010] A dynamic behavior analysis engine: by real-time monitoring the user's behavioral characteristics and comparing them with the preset abnormal behavior patterns, abnormal login behaviors can be detected in a timely manner;

[0011] Intelligent Unlock Decision Tree: Make intelligent unlock decisions based on authentication scores, device environments, and behavior anomaly levels;

[0012] Security Execution Module: Responsible for, after the user's identity authentication is passed, adopting a password filling security protocol to automatically fill in the password and execute the unlock operation. At the same time, combined with device environment monitoring and anomaly detection models, it monitors abnormal situations during the unlock process in real time to ensure the security of the unlock operation;

[0013] Log Audit Center: Responsible for recording all operation logs during the system operation process, auditing and analyzing them, and combined with intelligent analysis algorithms, deeply mining and analyzing the log data to discover potential security threats and abnormal behaviors.

[0014] The above technical solution further includes:

[0015] Furthermore, the multi-modal identity authentication module adopts a three-factor verification matrix, including the following steps;

[0016] Separate evaluations of three authentication dimensions:

[0017] Biometric Evaluation: Collect biometric data: When the user attempts to remotely log in, capture the user's face information through a 3D structured light camera and obtain the user's palmprint information using a vein scanner; Preprocessing and feature extraction: Preprocess the collected biometric data, and then extract key features, such as the shape and size of the face's contour, eyes, nose, etc., and the texture and detailed features of the palmprint; Feature comparison and authentication: Compare the extracted biometric data with the data in the biometric database to determine the authenticity of the user's identity. If the match is successful, proceed to the next authentication dimension; If the match fails, reject the login request;

[0018] Behavioral Feature Evaluation:

[0019] Behavioral data collection: When the user remotely logs in, the system collects data such as the user's mouse movement trajectory and keyboard typing rhythm in real time.

[0020] Behavioral feature extraction: Use a convolutional neural network (CNN) to classify the mouse trajectory and extract key features such as speed, acceleration, and direction; At the same time, use a long short-term memory network (LSTM) to model the keyboard typing rhythm and extract features such as typing frequency, intensity, and interval time; Behavioral pattern comparison and evaluation: Compare the extracted behavioral features with the preset abnormal behavioral patterns to evaluate whether the user's behavior conforms to the normal behavioral pattern. If the behavioral pattern is abnormal, trigger a security alarm; If the behavioral pattern is normal, proceed to the next authentication dimension;

[0021] Device Fingerprint Evaluation:

[0022] Device information acquisition: Obtain the user's MAC address and IPv6 address through the network interface, and at the same time read the CPU serial number and hard disk serial number of the device; Device fingerprint generation: Combine the obtained device information and perform encryption processing using a hash algorithm to generate a unique device fingerprint; Device fingerprint comparison and verification: Compare the generated device fingerprint with the data in the device fingerprint library to verify whether the user is using a trusted device for login. If the device fingerprint matches successfully, it indicates that the user is using a trusted device; if it fails, additional security verification measures are triggered;

[0023] After completing the individual evaluations of the above three authentication dimensions, a comprehensive evaluation of the three-factor verification matrix is carried out;

[0024] Logging and auditing: Whether the unlocking is successful or not, record the user's login attempts in the log audit center.

[0025] Furthermore, when the user attempts to log in remotely, first determine the lock screen state of the current device through the lock screen state perception module. For the Windows system, the lock screen state perception module monitors the desktop state by calling GetForegroundWindow through user32.dll. For the macOS system, the lock screen state perception module uses the CGSSessionScreenIsLocked API to detect the lock screen. For the Linux system, the lock screen state perception module parses the output state of loginctl show-session.

[0026] Furthermore, the steps for classifying the mouse trajectory using the MouseCNN network and extracting key features include the following:

[0027] Data preparation and preprocessing: Collect mouse trajectory data during the user's normal login, including information such as the coordinate points and timestamps of the mouse movement path. Clean the data to remove noise and invalid data, convert the mouse trajectory data into an image format for input into the MouseCNN network, connect the trajectory points into lines, and draw them on a canvas of a fixed size;

[0028] Construct the MouseCNN network: Design the structure of the MouseCNN network, including the input layer, convolutional layer, pooling layer, fully connected layer, and output layer, and select the activation function, loss function, and optimization algorithm;

[0029] Output layer: Use the softmax function for classification, and the number of categories is the preset number of abnormal behavior patterns.

[0030] Model Training: Use the collected normal and abnormal mouse trajectory image datasets to train the MouseCNN network. Set training parameters such as learning rate, batch size, number of iterations, etc. Monitor the loss value and accuracy during the training process, and adjust the model structure or training parameters to improve performance;

[0031] Feature Extraction and Classification: After the model training is completed, use the trained MouseCNN network to classify new mouse trajectory images, and extract the outputs of the convolutional layer or fully connected layer in the MouseCNN network as the key feature representations.

[0032] Furthermore, the steps for modeling the keyboard tapping rhythm using the GRU network and extracting the tapping features are as follows:

[0033] Data Preparation and Preprocessing: Collect the keyboard tapping data when the user logs in normally, including tapping timestamps, key types (such as letters, numbers, special characters, etc.), and tapping force. Preprocess the collected data to convert the keyboard tapping sequence into a format suitable for input to the GRU network;

[0034] Feature Engineering: Extract basic features from the keyboard tapping data, such as tapping intervals, key type distributions, tapping force distributions, etc. Construct the tapping data into time series features, such as the number of taps within each time window, the change rate of tapping speed, etc. These features will be used as the input to the GRU network;

[0035] GRU Network Modeling: Design a neural network structure containing GRU layers. The GRU layers are responsible for capturing the temporal dependencies in the keyboard tapping sequence. Add fully connected layers after the GRU layers for feature extraction and classification;

[0036] Input Data Format: Convert the preprocessed keyboard tapping data into a format suitable for input to the neural network;

[0037] Model Training: Use the labeled normal and abnormal login data to train the GRU network. During the training process, update the network weights by optimizing the loss function;

[0038] Feature Extraction: After the training is completed, the GRU network extracts the feature representations from the keyboard tapping sequence;

[0039] Anomaly Detection: Set a threshold for anomaly detection. During the real-time monitoring stage, input the user's keyboard tapping data into the trained GRU network to obtain the feature representations. Then, calculate the Euclidean distance between these feature representations and the normal behavior pattern. If the Euclidean distance exceeds the set threshold, it is determined as an abnormal login behavior.

[0040] Furthermore, the intelligent unlocking decision tree makes an intelligent unlocking decision based on the authentication score, device environment, and behavior anomaly degree. By checking in real time whether the IP address is in the trusted list, analyzing the behavior anomaly degree, and integrating other authentication information, it judges the legitimacy and security of the user, and thus makes a decision on whether to unlock, including the following steps:

[0041] Data collection and preprocessing: Collect data when the user logs in, including the user's authentication score, device environment information, and user behavior data;

[0042] Feature extraction and evaluation: Directly obtain the user's authentication score from the authentication system. The authentication score reflects the credibility of the user identity authentication. Extract the user's IP address and compare it with the preset trusted IP list to determine whether the user is using a trusted network environment. Real-time monitor the user's behavior through the dynamic behavior analysis engine and compare it with the preset abnormal behavior patterns to calculate the user's behavior anomaly degree;

[0043] Construct an intelligent unlocking decision tree: Node setting: Each node of the decision tree represents an evaluation factor, including the authentication score, device environment, or behavior anomaly degree. Each node contains multiple branches, representing different value ranges or categories of this factor;

[0044] Threshold setting: Set a threshold for each node to judge whether the user meets the conditions of this node;

[0045] Execute the decision tree and make a decision: When the user attempts to log in, collect the user's data and evaluate it according to the process of the decision tree. Starting from the root node, according to the user's data and the set threshold, judge in turn whether the user meets the conditions of each node. If the conditions are met, continue to traverse downwards; if the conditions are not met, make corresponding decisions according to the rules of the decision tree (such as refusing to unlock, requiring secondary authentication, etc.);

[0046] Response and record: Once the decision tree makes a decision, immediately trigger the corresponding response mechanism. For example, if the decision is to unlock, allow the user to access the system; if the decision is to refuse to unlock, display an error message to the user and may trigger an alarm mechanism. The system records the detailed information of each login attempt, including the user ID, login time, authentication score, device environment, behavior anomaly degree, and the final decision result, etc., for subsequent analysis and auditing.

[0047] Furthermore, after the user's identity authentication is passed, the security execution module adopts the password filling security protocol to automatically fill in the password and execute the unlocking operation. At the same time, combined with the device environment monitoring and the abnormal detection model, it real-time monitors the abnormal situations during the unlocking process, including the following steps:

[0048] User identity authentication: When a user attempts to remotely log in to the system, identity authentication is performed. The system verifies whether the authentication information provided by the user matches the preset authentication information. If the match is successful, the user's identity authentication passes; if the match fails, the user's login request is rejected;

[0049] Trigger the password filling security protocol: Once the user's identity authentication passes, the security execution module triggers the password filling security protocol. The password filling security protocol is used to automatically perform password filling and unlocking operations after the user authentication is successful. According to the user's authentication information and preset rules, determine the target device or service that needs to fill in the password;

[0050] Automatically fill in the password: According to the requirements of the target device or service, automatically retrieve the corresponding password from the password manager. The password manager is used to store various passwords and sensitive information of the user, and automatically fill the retrieved password into the login interface of the target device or service without the user having to enter it manually;

[0051] Perform the unlocking operation: After the password is successfully filled, simulate the user's operation, automatically perform the unlocking operation, monitor the result of the unlocking operation, and feedback to the user the information whether the login is successful according to the result.

[0052] The present invention has the following beneficial effects:

[0053] In the present invention, a multi-modal identity authentication module is proposed, including authentication methods in three dimensions of biometric features, behavioral features, and device fingerprints, and specific scoring formulas and threshold settings are given. A dynamic behavior analysis engine is introduced, and behavior analysis is carried out through technical means such as mouse behavior feature extraction and keyboard rhythm model. An intelligent unlocking decision tree is set up, and unlocking decisions are made according to factors such as authentication scores and device environments. The security and accuracy of the system are improved. Brief Description of the Drawings

[0054] Figure 1 It is a system block diagram of the computer remote login recognition system based on artificial intelligence proposed by the present invention. Detailed Embodiments

[0055] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0056] Please refer to Figure 1 As shown, the present invention is a computer remote login recognition system based on artificial intelligence, including:

[0057] Remote Login Request Receiving and Processing Module: Responsible for receiving users' remote login requests, performing preliminary processing and verification, and combining with the device fingerprint library and biometric library to authenticate the requested device to prevent the access of illegal devices;

[0058] Multi-modal Identity Authentication Module: Adopts a three-factor verification matrix of biometrics, behavioral characteristics, and device fingerprints, and adjusts the weights of different authentication dimensions according to security requirements and user needs;

[0059] Lock Screen State Sensing Module: Responsible for sensing the lock screen state;

[0060] Dynamic Behavior Analysis Engine: By real-time monitoring of users' behavioral characteristics and comparing with preset abnormal behavior patterns, it can detect abnormal login behaviors in a timely manner;

[0061] Intelligent Unlock Decision Tree: Makes intelligent unlock decisions based on authentication scores, device environments, and behavior abnormality levels;

[0062] Security Execution Module: After the user's identity authentication is passed, it adopts the password filling security protocol to automatically fill in the password and perform the unlock operation. At the same time, combined with device environment monitoring and anomaly detection models, it monitors abnormal situations during the unlock process in real time to ensure the security of the unlock operation;

[0063] Log Audit Center: Responsible for recording all operation logs during the system operation, auditing and analyzing them, and combining with intelligent analysis algorithms to deeply mine and analyze the log data to discover potential security threats and abnormal behaviors.

[0064] In one embodiment, the multi-modal identity authentication module adopts a three-factor verification matrix, including the following steps;

[0065] Separate evaluation of three authentication dimensions:

[0066] Biometric evaluation: Collect biometric data: When the user attempts to remotely log in, capture the user's face information through a 3D structured light camera and obtain the user's palmprint information using a vein scanner; Preprocessing and feature extraction: Preprocess the collected biometric data and then extract key features, such as the shape and size of the face's contour, eyes, nose, etc., and the texture and detailed features of the palmprint; Feature comparison and authentication: Compare the extracted biometric data with the data in the biometric library to determine the authenticity of the user's identity. If the match is successful, proceed to the next authentication dimension; if the match fails, reject the login request;

[0067] Behavioral characteristic evaluation:

[0068] Behavior data collection: When a user remotely logs in, the system collects data such as the user's mouse movement trajectory and keyboard typing rhythm in real time.

[0069] Behavior feature extraction: Use a Convolutional Neural Network (CNN) to classify the mouse trajectory and extract key features such as speed, acceleration, and direction. At the same time, use a Long Short-Term Memory Network (LSTM) to model the keyboard typing rhythm and extract features such as typing frequency, intensity, and interval time. Behavior pattern comparison and evaluation: Compare the extracted behavior features with preset abnormal behavior patterns to evaluate whether the user's behavior conforms to the normal behavior pattern. If the behavior pattern is abnormal, trigger a security alarm; if the behavior pattern is normal, proceed to the next authentication dimension.

[0070] Device fingerprint evaluation:

[0071] Device information acquisition: Obtain the user's MAC address and IPv6 address through a network interface, and at the same time read the CPU serial number and hard disk serial number of the device. Device fingerprint generation: Combine the obtained device information and perform encryption processing using a hash algorithm to generate a unique device fingerprint. Device fingerprint comparison and verification: Compare the generated device fingerprint with the data in the device fingerprint library to verify whether the user is logging in using a trusted device. If the device fingerprint matches successfully, it indicates that the user is using a trusted device; if it fails, trigger additional security verification measures.

[0072] After completing the individual evaluations of the above three authentication dimensions, conduct a comprehensive evaluation of the three-factor verification matrix.

[0073] Logging and auditing: Whether the unlocking is successful or not, record the user's login attempt in the log audit center.

[0074] In one embodiment, when a user attempts to remotely log in, first determine the lock screen state of the current device through a lock screen state sensing module. For the Windows system, the lock screen state sensing module monitors the desktop state by calling GetForegroundWindow through user32.dll. For the macOS system, the lock screen state sensing module uses the CGSSessionScreenIsLocked API to detect the lock screen. For the Linux system, the lock screen state sensing module parses the output state of loginctl show-session.

[0075] In one embodiment, the steps of using the MouseCNN network to classify the mouse trajectory and extract key features include the following:

[0076] Data Preparation and Preprocessing: Collect the mouse trajectory data when the user logs in normally, including information such as the coordinate points and timestamps of the mouse movement path, clean the data to remove noise and invalid data, convert the mouse trajectory data into an image format for input into the MouseCNN network, connect the trajectory points into lines, and draw them on a canvas of a fixed size;

[0077] Construct the MouseCNN Network: Design the structure of the MouseCNN network, including the input layer, convolutional layer, pooling layer, fully connected layer, and output layer, and select the activation function, loss function, and optimization algorithm;

[0078] MouseCNN Network Structure:

[0079] Input Layer: Accept the mouse trajectory image, with a size of 100x100x3 (assuming the image is in RGB three channels).

[0080] Convolutional Layer 1: Use 32 3x3 convolutional kernels, with a stride of 1, and the activation function is ReLU.

[0081] Pooling Layer 1: Use 2x2 max pooling, with a stride of 2.

[0082] Convolutional Layer 2: Use 64 3x3 convolutional kernels, with a stride of 1, and the activation function is ReLU.

[0083] Pooling Layer 2: Use 2x2 max pooling, with a stride of 2.

[0084] Fully Connected Layer 1: Flatten the output of the convolutional layer and use 128 neurons, and the activation function is ReLU.

[0085] Output Layer: Use the softmax function for classification, and the number of classes is the preset number of abnormal behavior patterns.

[0086] Model Training: Use the collected normal and abnormal mouse trajectory image datasets to train the MouseCNN network, set the training parameters such as the learning rate, batch size, number of iterations, etc., monitor the loss value and accuracy during the training process, and adjust the model structure or training parameters to improve the performance;

[0087] Feature Extraction and Classification: After the model training is completed, use the trained MouseCNN network to classify the new mouse trajectory images, and extract the output of the convolutional layer or fully connected layer in the MouseCNN network as the key feature representation.

[0088] In one embodiment, the modeling of the keyboard tapping rhythm using the GRU network and the extraction of the tapping features include the following steps:

[0089] Data Preparation and Preprocessing: Collect keyboard tapping data when the user logs in normally, including tapping timestamps, key types (such as letters, numbers, special characters, etc.), and tapping force. Preprocess the collected data to convert the keyboard tapping sequence into a format suitable for input to the GRU network;

[0090] Feature Engineering: Extract basic features from the keyboard tapping data, such as tapping intervals, key type distributions, tapping force distributions, etc. Construct the tapping data into time series features, such as the number of taps within each time window, the change rate of tapping speed, etc. These features will be used as the input to the GRU network;

[0091] GRU Network Modeling: Design a neural network structure containing a GRU layer. The GRU layer is responsible for capturing the temporal dependencies in the keyboard tapping sequence. Add a fully connected layer after the GRU layer for feature extraction and classification;

[0092] Input Data Format: Convert the preprocessed keyboard tapping data into a format suitable for input to the neural network;

[0093] Model Training: Use the labeled normal and abnormal login data to train the GRU network. During the training process, update the network weights by optimizing the loss function;

[0094] Feature Extraction: After training is completed, the GRU network extracts feature representations from the keyboard tapping sequence;

[0095] Anomaly Detection: Set a threshold for anomaly detection. During the real-time monitoring stage, input the user's keyboard tapping data into the trained GRU network to obtain feature representations. Then, calculate the Euclidean distance between these feature representations and the normal behavior pattern. If the Euclidean distance exceeds the set threshold, it is determined as an abnormal login behavior.

[0096] In one embodiment, the intelligent unlocking decision tree makes an intelligent unlocking decision based on the authentication score, device environment, and behavior anomaly degree. By real-time checking whether the IP address is in the trusted list, analyzing the behavior anomaly degree, and integrating other authentication information, it judges the legitimacy and security of the user, and thus makes a decision on whether to unlock, including the following steps:

[0097] Data Collection and Preprocessing: Collect data when the user logs in, including the user's authentication score, device environment information, and user behavior data;

[0098] Feature Extraction and Evaluation: Directly obtain the user's authentication score from the authentication system. The authentication score reflects the credibility of user identity authentication. Extract the user's IP address and compare it with a preset list of trusted IPs to determine whether the user is using a trusted network environment. Real-time monitor the user's behavior through a dynamic behavior analysis engine and compare it with a preset abnormal behavior pattern to calculate the user's behavior abnormality degree;

[0099] Construct an Intelligent Unlock Decision Tree: Node Setting: Each node of the decision tree represents an evaluation factor, including authentication score, device environment, or behavior abnormality degree. Each node contains multiple branches, representing different value ranges or categories of this factor;

[0100] Threshold Setting: Set a threshold for each node to determine whether the user meets the conditions of this node;

[0101] Execute the Decision Tree and Make a Decision: When the user attempts to log in, collect the user's data and evaluate it according to the process of the decision tree. Starting from the root node, based on the user's data and the set threshold, successively determine whether the user meets the conditions of each node. If the conditions are met, continue to traverse downwards; if the conditions are not met, make corresponding decisions according to the rules of the decision tree (such as refusing to unlock, requiring secondary authentication, etc.);

[0102] Response and Recording: Once the decision tree makes a decision, immediately trigger the corresponding response mechanism. For example, if the decision is to unlock, allow the user to access the system; if the decision is to refuse to unlock, display an error message to the user and may trigger an alarm mechanism. The system records the detailed information of each login attempt, including user ID, login time, authentication score, device environment, behavior abnormality degree, and the final decision result, etc., for subsequent analysis and auditing.

[0103] Example Illustration:

[0104] Data Collection and Preprocessing: The system collects the user's authentication score of 90 points (indicating high credibility), IP address of 192.168.1.100, and the user's behavior data (such as mouse movement trajectory, keyboard typing habits, etc.).

[0105] Feature Extraction and Evaluation: The system extracts the authentication score feature as 90 points, the device environment feature as the IP address being within the trusted list (because 192.168.1.100 is in the preset trusted IP list), and the behavior abnormality degree feature as low (because the user's behavior does not match the preset abnormal behavior pattern).

[0106] Execute decision tree: Starting from the root node, first determine whether the user's authentication score is higher than the set threshold (e.g., 85 points). Since the user's authentication score is 90 points, which is higher than the threshold, continue to traverse downwards. Then determine whether the user's IP address is within the trusted list. Since the user's IP address is within the trusted list, continue to traverse downwards. Finally, determine whether the user's behavior anomaly degree is lower than the set threshold (e.g., 10%). Since the user's behavior anomaly degree is low, lower than the threshold, the system makes an unlocking decision.

[0107] Response and record: The system allows the user to access their account and records the detailed information of this login attempt, including user ID, login time, authentication score, device environment, behavior anomaly degree, and the final decision result, etc.

[0108] In one embodiment, after the user identity authentication is passed, the security execution module adopts a password filling security protocol to automatically fill in the password and perform the unlocking operation. At the same time, combined with device environment monitoring and anomaly detection models, it real-time monitors the abnormal situations during the unlocking process, including the following steps:

[0109] User identity authentication: When the user attempts to remotely log in to the system, identity authentication is performed. The system verifies whether the authentication information provided by the user matches the preset authentication information. If the match is successful, the user identity authentication is passed; if the match fails, the user's login request is rejected;

[0110] Trigger the password filling security protocol: Once the user identity authentication is passed, the security execution module triggers the password filling security protocol. The password filling security protocol is used to automatically perform password filling and unlocking operations after the user authentication is successful. According to the user's authentication information and preset rules, determine the target device or service that needs to fill in the password;

[0111] Automatically fill in the password: According to the requirements of the target device or service, automatically retrieve the corresponding password from the password manager. The password manager is used to store various passwords and sensitive information of the user, and automatically fill the retrieved password into the login interface of the target device or service without the user having to manually input it;

[0112] Perform the unlocking operation: After the password is successfully filled, simulate the user's operation, automatically perform the unlocking operation, monitor the result of the unlocking operation, and feedback the information of whether the login is successful to the user according to the result.

[0113] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A computer remote login recognition system based on artificial intelligence, characterized in that: include: Remote login request receiving and processing module: responsible for receiving the user's remote login request, and performing preliminary processing and verification, and authenticating the requested device in combination with the device fingerprint library and biometric library; Multimodal identity authentication module: It uses a three-factor authentication matrix of biometrics, behavioral characteristics, and device fingerprints, and adjusts the weights of different authentication dimensions according to security requirements and user needs; Lock screen status perception module: responsible for sensing the lock screen status; Dynamic behavior analysis engine: By monitoring the user's behavior characteristics in real time and comparing them with the preset abnormal behavior patterns, abnormal login behavior can be discovered in a timely manner; Smart unlock decision tree: Make smart unlock decisions based on authentication scores, device environment, and behavioral abnormality; Security execution module: responsible for automatically filling in the password and performing the unlocking operation using the password filling security protocol after the user identity authentication is passed. At the same time, combined with the device environment monitoring and anomaly detection model, it monitors the abnormal situation in the unlocking process in real time; Log Audit Center: Responsible for recording all operation logs during system operation, and conducting audits and analyses. Combined with intelligent analysis algorithms, it conducts in-depth mining and analysis of log data to discover potential security threats and abnormal behaviors.

2. The computer remote login recognition system based on artificial intelligence according to claim 1 is characterized in that: The multimodal identity authentication module adopts a three-factor authentication matrix, including the following steps: Separate assessments across three certification dimensions: Biometric assessment: Collecting biometric data: When a user attempts to log in remotely, the user's face information is captured through a 3D structured light camera, and the user's palm print information is obtained using a vein scanner; Preprocessing and feature extraction: The collected biometric data is preprocessed and then key features are extracted; feature Comparison and authentication: The extracted biometric data is compared with the data in the biometric database to determine the authenticity of the user's identity. If the match is successful, it proceeds to the next authentication dimension; If this fails, the login request is rejected; Behavioral profile assessment: Behavioral data collection: When a user logs in remotely, the system collects data such as the user's mouse movement trajectory and keyboard typing rhythm in real time. Behavioral feature extraction: MouseCNN network is used to classify mouse trajectories and extract key features. At the same time, GRU network is used to model keyboard tapping rhythm and extract tapping features. Behavior pattern comparison and evaluation: The extracted behavior features are compared with the preset abnormal behavior patterns to evaluate whether the user's behavior is consistent with the normal behavior pattern. If the behavior pattern is abnormal, a security alarm is triggered; If the behavior pattern is normal, then proceed to the next authentication dimension; Device Fingerprint Assessment: Device information acquisition: obtain the user's MAC address and IPv6 address through the network interface, and read the device's CPU serial number and hard disk serial number at the same time; device fingerprint generation: combine the acquired device information and encrypt it using a hash algorithm to generate a unique device fingerprint; device fingerprint comparison and verification: compare the generated device fingerprint with the data in the device fingerprint library to verify whether the user has used a trusted device to log in. If the device fingerprint matches successfully, it means that the user is using a trusted device; if it fails, additional security verification measures are triggered; After completing the individual assessments of the three authentication dimensions above, conduct a comprehensive assessment of the three-factor authentication matrix; Logging and auditing: Regardless of whether the unlocking is successful or not, the user's login attempt will be recorded in the log audit center.

3. The computer remote login recognition system based on artificial intelligence according to claim 1 is characterized in that: According to the actual application scenarios and user needs, the system can intelligently adjust the weights of different authentication dimensions. In highly secure scenarios, the weight of biometrics is increased; in scenarios with higher convenience requirements, the weight of behavioral characteristics or device fingerprints is increased.

4. The computer remote login recognition system based on artificial intelligence according to claim 1 is characterized in that: When a user attempts to log in remotely, the lock screen status of the current device is first determined through the lock screen status perception module.

5. The computer remote login recognition system based on artificial intelligence according to claim 2 is characterized in that: The method of using the MouseCNN network to classify mouse trajectories and extract key features includes the following steps: Data preparation and preprocessing: Collect the mouse trajectory data when the user logs in normally, clean the data, remove noise and invalid data, and convert the mouse trajectory data into image format; Build MouseCNN network: Design the structure of MouseCNN network, including input layer, convolution layer, pooling layer, fully connected layer and output layer, and select activation function, loss function and optimization algorithm; Model training: Use the collected normal and abnormal mouse trajectory image datasets to train the MouseCNN network, set training parameters, monitor the loss value and accuracy during training, and adjust the model structure or training parameters; Feature extraction and classification: After the model training is completed, the trained MouseCNN network is used to classify the new mouse trajectory images, and the output of the convolutional layer or fully connected layer in the MouseCNN network is extracted as the key feature representation.

6. The computer remote login recognition system based on artificial intelligence according to claim 2 is characterized in that: The method of using the GRU network to model the keyboard tapping rhythm and extracting the tapping features includes the following steps: Data preparation and preprocessing: Collect the keyboard tapping data of users during normal login, including tapping timestamp, key type, and tapping force, preprocess the collected data, and convert the keyboard tapping sequence into a format suitable for GRU network input; Feature engineering: extract basic features from keyboard tapping data and construct the tapping data into time series features; GRU network modeling: Design a neural network structure containing a GRU layer, which is responsible for capturing the temporal dependencies in the keyboard tapping sequence, and add a fully connected layer after the GRU layer for feature extraction and classification; Input data format: Convert the preprocessed keyboard stroke data into a format suitable for neural network input; Model training: Use the labeled normal and abnormal login data to train the GRU network. During the training process, the network weights are updated by optimizing the loss function. Feature extraction: After training, the GRU network extracts feature representations from the keyboard stroke sequence; Anomaly detection: Set an anomaly detection threshold. In the real-time monitoring stage, input the user's keyboard tapping data into the trained GRU network to obtain feature representation. Then, calculate the Euclidean distance between these feature representations and the normal behavior pattern. If the Euclidean distance exceeds the set threshold, it is judged as abnormal login behavior.

7. The computer remote login recognition system based on artificial intelligence according to claim 1 is characterized in that: The smart unlock decision tree makes smart unlock decisions based on the authentication score, device environment, and behavior abnormality. It determines the legitimacy and security of the user by checking in real time whether the IP address is in the trusted list, analyzing the behavior abnormality, and combining other authentication information, thereby making a decision on whether to unlock. The decision tree includes the following steps: Data collection and preprocessing: Collect data when users log in, including the user's authentication score, device environment information, and user behavior data; Feature extraction and evaluation: directly obtain the user's authentication score from the authentication system, which reflects the credibility of the user's identity authentication, extract the user's IP address, and compare it with the preset trusted IP list to determine whether the user is using a trusted network environment. The user's behavior is monitored in real time through the dynamic behavior analysis engine, and compared with the preset abnormal behavior pattern to calculate the user's behavior abnormality; Constructing a smart unlocking decision tree: Node setting: Each node of the decision tree represents an evaluation factor, including authentication score, device environment or behavior abnormality. Each node contains multiple branches, representing different value ranges or categories of the factor; Threshold setting: Set a threshold for each node to determine whether the user meets the conditions of the node; Execute the decision tree and make a decision: When a user tries to log in, collect the user's data and evaluate it according to the decision tree process. Starting from the root node, determine whether the user meets the conditions of each node in turn based on the user's data and the set threshold. If the conditions are met, continue to traverse downwards; if the conditions are not met, make the corresponding decision according to the rules of the decision tree; Response and Recording: Once the decision tree makes a decision, the corresponding response mechanism is triggered immediately, and the system records the detailed information of each login attempt.

8. The computer remote login recognition system based on artificial intelligence according to claim 1 is characterized in that: After the user identity authentication is passed, the security execution module adopts the password filling security protocol to automatically fill in the password and perform the unlocking operation. At the same time, combined with the device environment monitoring and anomaly detection model, the abnormal situation in the unlocking process is monitored in real time, including the following steps: User identity authentication: When a user attempts to log in to the system remotely, identity authentication is performed. The system verifies whether the authentication information provided by the user matches the preset authentication information. If the match is successful, the user identity authentication is passed; if the match fails, the user's login request is rejected; Triggering the password filling security protocol: Once the user identity authentication is passed, the security execution module triggers the password filling security protocol, which is used to automatically perform password filling and unlocking operations after the user authentication is successful, and determine the target device or service that needs to fill the password according to the user's authentication information and preset rules; Automatically fill in passwords: automatically retrieve corresponding passwords from a password manager that stores various passwords and sensitive information of the user according to the requirements of the target device or service, and automatically fill the retrieved passwords into the login interface of the target device or service; Execute unlock operation: After the password is successfully filled in, simulate the user's operation, automatically execute the unlock operation, monitor the result of the unlock operation, and feedback the user whether the login is successful based on the result.

Citation Information

Cited By

  • User registration and login method based on keyboard tapping

    CN120611368A

  • Fingerprint security login method and system for cloud computer, and medium

    CN120785617A

  • Equipment remote control system and method based on computer network application

    CN121262264A

  • Man-machine on-screen behavior monitoring and identity authentication system based on multi-modal perception

    CN121959539A