Multi-party data sharing trusted data space identity authentication system and method

Through the trusted data space identity authentication system shared by multi-party data, the problem of insufficient security and adaptability of traditional identity authentication is solved, and the security and reliability are improved and the authentication efficiency is improved, and the high requirements of multi-party data sharing scenarios are adapted.

CN120238340AActive Publication Date: 2025-07-01LINGSHU TECH CO LTD

Patent Information

Application Number
CN202510353954.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-07-01
Estimated Expiration
2045-03-25

AI Technical Summary

Technical Problem

Traditional identity authentication relies on a single factor and has poor security, which cannot meet the high requirements of multi-party data sharing scenarios. The existing technology has shortcomings in security, adaptability and efficiency.

Method used

A trusted data space identity authentication system is adopted for multi-party data sharing, including an authentication attribute acquisition module, an authentication factor matching module, a hierarchical authentication module and an authentication verification module. By identifying user authentication attributes, multi-factor authentication factor matching and hierarchical authentication are carried out, security labels are generated, authentication strategies are dynamically adjusted, and authentication flexibility and adaptability are enhanced.

Benefits of technology

It improves the security and reliability of identity authentication, enhances the flexibility and adaptability of authentication, improves the authentication efficiency, and meets the high requirements of multi-party data sharing scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238340A_ABST
    Figure CN120238340A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-party data sharing trusted data space identity authentication system and method, and relates to the technical field of data security, and the system comprises an authentication attribute acquisition module which is used for connecting a user authentication channel and identifying a user authentication attribute; the authentication factor matching module is used for carrying out identity authentication factor matching according to the user authentication attribute and a multi-factor authentication mechanism, and determining the authentication matching status and factor fusion proportion of each factor authentication; the hierarchical authentication module is used for performing hierarchical authentication on the user feedback identity data according to the authentication matching status of each factor authentication and the factor fusion proportion, and tracking and recording the authentication process; and the authentication verification module is used for performing identity authentication collaborative verification according to the grading authentication result and the authentication tracking record, and the user meeting the verification result accesses the trusted data space. Therefore, the technical effects of improving the security and reliability of identity authentication, enhancing the flexibility and adaptability of authentication and improving the authentication efficiency are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to a trusted data space identity authentication system and method for multi-party data sharing. Background Art

[0002] Traditional identity authentication mostly relies on a single factor such as a username and password, which is easily cracked and has poor security. In the case of complex networks and diverse access devices, multi-factor authentication still has imperfect attribute recognition, factor matching, and process tracking, and cannot meet the high requirements of multi-party data sharing scenarios, affecting data security sharing and user convenience. The existing technologies as a whole have deficiencies in terms of security, adaptability, and efficiency, and it is difficult to balance security and convenience in multi-party data sharing. Summary of the Invention

[0003] The present invention provides a trusted data space identity authentication system and method for multi-party data sharing, so as to solve the technical problems of single factor, poor authentication flexibility and adaptability, and affecting identity recognition security in the prior art, and achieve the technical effects of improving the security and reliability of identity authentication, enhancing the flexibility and adaptability of authentication, and improving authentication efficiency.

[0004] In a first aspect, the present invention provides a trusted data space identity authentication system for multi-party data sharing, wherein the trusted data space identity authentication system for multi-party data sharing includes:

[0005] An authentication attribute acquisition module, configured to connect to a user authentication channel and identify user authentication attributes.

[0006] An authentication factor matching module, configured to match identity authentication elements according to the user authentication attributes and a multi-factor authentication mechanism, and determine the authentication matching status and factor fusion ratio of each factor authentication.

[0007] A hierarchical authentication module, configured to perform hierarchical authentication on user feedback identity data according to the authentication matching status and factor fusion ratio of each factor authentication, and track and record the authentication process.

[0008] An authentication verification module, configured to perform identity authentication collaborative verification according to the hierarchical authentication result and the authentication tracking record, and allow users who meet the verification result to access the trusted data space.

[0009] In a feasible implementation manner, the authentication attribute acquisition module includes:

[0010] A user access information recognition unit, configured to identify a user access device and an access network path according to the user authentication channel.

[0011] An access device security and feature analysis unit, which is used to analyze the security status and user features of user access device information according to the user access device, and determine the access device security information and device attribute features.

[0012] A network path security and feature analysis unit, which is used to analyze the user access network path and obtain the network path security information and network attribute features.

[0013] A user authentication attribute and security evaluation unit, which is used to identify and match user authentication attributes according to the device attribute features and the network attribute features, obtain user authentication attributes, and use the access device security information and the network path security information to evaluate the access security, and generate a security label for the user authentication attributes.

[0014] In a feasible implementation manner, the network path security and feature analysis unit includes:

[0015] A network basic parameter identification subunit, which is used to identify network basic parameters, including IP addresses and access network types.

[0016] A network path security and feature acquisition subunit, which is used to perform routing path tracing based on the IP address and the access network type, perform risk assessment on each node of the routing path and determine the consistency of attribute features, and obtain the network path security information and network attribute features.

[0017] In a feasible implementation manner, the user authentication attribute and security evaluation unit further includes:

[0018] A request event acquisition subunit, which is used to obtain the request event corresponding to user authentication.

[0019] A request event risk evaluation subunit, which is used to perform risk evaluation according to the request event and obtain request event risk information.

[0020] A security label generation subunit, which is used to use the request event risk information as an incremental identification feature, perform comprehensive security information evaluation with the access device security information and the network path security information, obtain access security evaluation information, and generate a security label for the user authentication attributes.

[0021] In a feasible implementation manner, the authentication factor matching module includes:

[0022] A core authentication element determination unit, which is used to analyze user attribute features according to the user authentication attributes and determine core authentication elements.

[0023] An authentication matching certainty acquisition unit is configured to perform identity authentication element matching between the core authentication elements and the multi-factor authentication mechanism to obtain an authentication matching certainty, where the authentication matching certainty describes the authentication certainty of the matching factor authentication mechanism for the core authentication elements.

[0024] A central authentication mechanism configuration unit is configured to perform a matching maximization search based on the authentication matching certainty of the multi-factor authentication mechanism to obtain a central authentication mechanism, and configure the central authentication mechanism to have the primary authentication status.

[0025] An auxiliary authentication mechanism and fusion ratio determination unit is configured to determine a security authentication target based on the security label of the user authentication attribute, and search in the multi-factor authentication mechanism based on the security authentication target to obtain an auxiliary authentication mechanism and a factor fusion ratio.

[0026] In a feasible implementation, the authentication matching certainty acquisition unit includes:

[0027] An authentication experiment data establishment subunit is configured to establish authentication experiment data between the core authentication elements and the multi-factor authentication mechanism.

[0028] An authentication matching certainty calculation subunit is configured to calculate the entropy value of the authentication output result of each factor authentication mechanism for the core authentication elements based on the authentication experiment data, and determine the certainty of the corresponding factor authentication mechanism for authenticating the core authentication elements based on the entropy value of the output result.

[0029] In a feasible implementation, the hierarchical authentication module includes:

[0030] An authentication level construction unit is configured to establish a primary authentication level based on the central authentication mechanism, establish a secondary authentication level based on the auxiliary authentication mechanism and the factor fusion ratio, and connect the primary authentication level and the secondary authentication level.

[0031] A core authentication execution unit is configured to perform core authentication element authentication on the user feedback identity data through the primary authentication level to obtain a central authentication result.

[0032] A fusion authentication execution unit is configured to perform element authentication on the corresponding authentication elements of the user feedback identity data through the secondary authentication level to obtain a secondary authentication result. Based on the central authentication result and the secondary authentication result, a fusion authentication result is obtained.

[0033] In a feasible implementation, the fusion authentication execution unit further includes:

[0034] A certainty threshold subunit is configured to determine an authentication certainty threshold based on the security label of the user authentication attribute.

[0035] The fusion authentication result determination subunit is configured to perform comprehensive calculation of the authentication certainty based on the central authentication result and the secondary authentication result, and determine whether the authentication certainty threshold is met by using the comprehensive calculation result. When the threshold is met, the fusion authentication result is set as identity authentication passed, and all authentication results are recorded and stored.

[0036] In a feasible implementation manner, the execution steps of the fusion authentication result determination subunit further include:

[0037] Based on the security authentication objective, configure the element authentication proportion weights of the central authentication mechanism and the auxiliary authentication mechanism.

[0038] When the central authentication result is authentication passed, obtain the auxiliary authentication mechanisms that are authentication passed in the secondary authentication result.

[0039] Perform weighted calculation by using the authentication certainty corresponding to the central authentication mechanism and the auxiliary authentication mechanisms that are authentication passed in the secondary authentication result and the authentication proportion weights to obtain the comprehensive calculation result.

[0040] In a second aspect, the present invention further provides a multi-party data sharing trusted data space identity authentication method. Among them, the multi-party data sharing trusted data space identity authentication method includes:

[0041] Connect the user authentication channel and identify the user authentication attributes.

[0042] Match the identity authentication elements with the multi-factor authentication mechanism according to the user authentication attributes, and determine the authentication matching status and factor fusion ratio of each factor authentication.

[0043] Perform hierarchical authentication on the user feedback identity data according to the authentication matching status and factor fusion ratio of each factor authentication, and track and record the authentication process.

[0044] Perform identity authentication collaborative verification according to the hierarchical authentication result and the authentication tracking record, and users who meet the verification result are allowed to access the trusted data space.

[0045] The present invention discloses a trusted data space identity authentication system and method for multi-party data sharing, including: an authentication attribute acquisition module, configured to connect to a user authentication channel and identify user authentication attributes; an authentication factor matching module, configured to match identity authentication elements with a multi-factor authentication mechanism according to the user authentication attributes, and determine the authentication matching status and factor fusion ratio of each factor authentication; a hierarchical authentication module, configured to perform hierarchical authentication on user feedback identity data according to the authentication matching status and factor fusion ratio of each factor authentication, and track and record the authentication process; an authentication verification module, configured to perform identity authentication collaborative verification according to the hierarchical authentication result and the authentication tracking record, and users meeting the verification result are allowed to access the trusted data space. The trusted data space identity authentication system and method for multi-party data sharing disclosed by the present invention solve the technical problems of single factor, poor authentication flexibility and adaptability, and affecting identity recognition security, and achieve the technical effects of improving the security and reliability of identity authentication, enhancing the flexibility and adaptability of authentication, and improving the authentication efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 FIG. is a schematic structural diagram of the trusted data space identity authentication system for multi-party data sharing of the present invention.

[0047] Figure 2 FIG. is a schematic flow diagram of the trusted data space identity authentication method for multi-party data sharing of the present invention.

[0048] Description of reference numerals: authentication attribute acquisition module 11, authentication factor matching module 12, hierarchical authentication module 13, authentication verification module 14. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] The following will describe the above technical solutions in detail in conjunction with the accompanying drawings of the specification and specific embodiments to better understand the above technical solutions. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments of the present invention. It should be understood that the present invention is not limited to the example embodiments used to explain the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention. In addition, it should be noted that, for the sake of description, only parts related to the present invention are shown in the drawings rather than all.

[0050] Embodiment 1, as Figure 1 FIG. is a schematic structural diagram of the trusted data space identity authentication system for multi-party data sharing of the present invention, wherein the trusted data space identity authentication system for multi-party data sharing includes:

[0051] An authentication attribute acquisition module 11, configured to connect to a user authentication channel and identify user authentication attributes.

[0052] Specifically, connecting the user authentication channel means establishing a communication link between the user and the identity authentication system to ensure that the user can send authentication requests to the system through specific interfaces or protocols; identifying user authentication attributes refers to the identity characteristic information of the user obtained by the system through technical means, which may include the knowledge elements of the user (information the user knows, such as username, password, or personal identification number), possession elements (items the user holds, such as USB Key, security token), inherent elements (biometric features of the user, such as fingerprint, facial recognition, or voice recognition), etc. These are the basic data for the subsequent authentication process and are used to judge the identity of the user and the security of the access environment.

[0053] Exemplarily, first, a connection channel between the user and the authentication system is established, and then information such as the user's access device and network path is identified through technical means; specifically, the system will detect the type of device the user uses (such as laptop, mobile phone, etc.) and the type of network accessed (such as enterprise intranet, public Wi-Fi, etc.). In addition, the system will also conduct a preliminary detection of the security status of the device, such as checking whether the necessary security software is installed on the device and whether there are abnormalities in the network path, to ensure the security of the user authentication channel, thereby providing basic data support and decision-making basis for subsequent identity authentication.

[0054] In some embodiments, the authentication attribute acquisition module 11 includes:

[0055] A user access information identification unit for identifying the user access device and access network path according to the user authentication channel; an access device security and feature analysis unit for analyzing the security status and user features of the user access device information according to the user access device to determine the access device security information and device attribute features; a network path security and feature analysis unit for analyzing the user access network path to obtain network path security information and network attribute features; a user authentication attribute and security evaluation unit for identifying and matching user authentication attributes according to the device attribute features and the network attribute features to obtain user authentication attributes, and using the access device security information and the network path security information to conduct an access security evaluation and generate a security label for the user authentication attributes.

[0056] Specifically, the user access information identification unit is used to detect the device type and network path through which the user accesses the system, such as identifying whether the user accesses through a mobile phone or a computer, and whether the accessed network is an enterprise intranet or public Wi-Fi; the access device security and feature analysis unit is responsible for analyzing the security status and features of the user device, such as checking whether the security software is installed on the device, the hardware information of the device (whether it supports specific encryption instruction sets or algorithms), etc.

[0057] Specifically, the network path security and feature analysis unit analyzes the security and features of the user's access network. Exemplarily, the network path security information includes: the stability of the network path, whether it is a trusted network, and whether there is a man-in-the-middle attack risk; the network attribute features include various network attributes with different security levels such as the enterprise's internal network, the security network of the alliance, and strange or external networks, corresponding to different levels of security risks.

[0058] Specifically, the user authentication attribute and security evaluation unit comprehensively analyzes the features and security information of the device and the network, and generates a security label for the user authentication attribute, which is used for the decision-making of the subsequent authentication process.

[0059] Exemplarily, according to the device attribute features (including device model, operating system, hardware fingerprint, MAC address, application installation status, etc.) and network attribute features (including IP address, geographical location, access method (Wi-Fi, 4G, VPN), historical access records), multi-factor authentication (MFA) is used for matching to ensure the authenticity of the user's identity. Optionally, the matching methods include rule matching (presetting white lists / black lists to restrict untrusted devices or networks), behavior analysis (comparing based on the user's historical access habits (such as frequently used devices, frequently used IPs), and triggering additional authentication in case of abnormal situations), and biometric matching (such as face recognition, fingerprint, voiceprint verification, etc.).

[0060] Exemplarily, based on the device and network security information, the risk level of the access behavior is comprehensively evaluated, including device security detection, such as checking whether there is a jailbreak / Root operation, whether malicious software or tampered applications are installed, and whether the device complies with the enterprise security policy (such as encryption storage not being enabled); network security detection, such as whether it is a public Wi-Fi or an insecure network (such as an open HTTP request), whether it accesses through a proxy or an anonymous tool such as Tor, and whether the IP address belongs to a high-risk area or a known attack source.

[0061] Furthermore, according to the authentication matching and security assessment results, a security label is generated for dynamically adjusting the access permission. Exemplarily, if the matching is successful and the device and network are secure and normal access is allowed, it is considered that the current risk is low (green label); if there are minor anomalies (such as a new device login, IP change), secondary verification (such as SMS verification code, two-factor authentication) is required, and it can be considered that the current risk is medium (yellow label); if there are serious anomalies (such as an unknown device, blacklisted IP, Root device), access is denied or administrator approval is required, and at this time, it can be considered that there is a high risk (red label).

[0062] In some implementation manners, the network path security and feature analysis unit includes:

[0063] The network basic parameter identification subunit is used to identify network basic parameters, including IP addresses and access network types; the network path security and feature acquisition subunit is used to perform routing path tracing based on the IP addresses and access network types, conduct risk assessment on each node of the routing path and determine the consistency of attribute features, so as to obtain the network path security information and network attribute features.

[0064] Specifically, network basic parameters refer to the basic information when a user accesses the network, such as IP addresses and access network types (such as wired networks, wireless networks, VPNs, etc.). Routing path tracing refers to the process of determining each network node that a data packet passes through by analyzing the network path from the origin point of a user request to the target server, which helps to identify risk factors in the path, such as insecure nodes.

[0065] Exemplarily, using Traceroute or similar technologies, trace the complete routing path from the user device to the target server and analyze each network node (such as routers, gateways); assume that user A (home Wi-Fi) and user B (VPN access) access the same target server (example.com), the tracing results can be expressed as follows:

[0066] Table 1 Exemplary routing path tracing results

[0067]

[0068]

[0069] Specifically, conduct a security analysis on each network node in the routing path to determine whether the node is suspicious and whether there are security risks (such as high-risk IPs, proxy servers, Tor networks, etc.).

[0070] Specifically, conduct a consistency determination on the attribute features of the network path to ensure that the network path conforms to the preset security policy, such as comparing the user's common access paths and detecting whether there are abnormal path jumps.

[0071] Table 2 Exemplary network path security information and network attribute features

[0072] Evaluation item User A (Home Wi-Fi) User B (VPN) IP Reputation Low risk (Home IP) High risk (VPN data center) Network type Wi-Fi (Trusted) VPN (Needs further inspection) Path hop count 4 hops (Normal) 5 hops (One more VPN proxy) Suspicious node None Yes (Data center IP) Path stability High (Frequently used) Low (New path) Risk score 10 / 100 (Low) 80 / 100 (High)

[0073] Through the above process, the system can obtain the security information and attribute features of the network path, provide an important basis for subsequent access security evaluation, ensure the security of the user's access network path, and prevent data leakage or identity authentication failure caused by potential risks in the network path.

[0074] In some implementation manners, the user authentication attribute and security evaluation unit further includes:

[0075] A request event acquisition subunit for obtaining a request event corresponding to user authentication; a request event risk evaluation subunit for performing a risk evaluation based on the request event to obtain request event risk information; a security label generation subunit for using the request event risk information as an incremental identification feature and performing a comprehensive security evaluation on the access device security information and the network path security information to obtain access security evaluation information and generate a security label for the user authentication attribute.

[0076] Specifically, a request event refers to the specific operation behavior or context information when a user initiates an authentication request, which is collected through log analysis. For example, the type of resource accessed by the user, the time and frequency of the request, etc. By evaluating the security risk of the request event, it is possible to determine whether there are abnormalities or potential threats for the user, such as whether it is an access during non-normal working hours, whether it is an access to a highly sensitive resource, etc., and generate request event risk information. Exemplarily, the request event risk information includes abnormal high-frequency access and the corresponding access frequency, frequent changes in the IP address and the change situation (change rate), high-frequency access requests exceeding permissions, etc.

[0077] Specifically, the risk information of the request event is used as an additional security evaluation dimension, that is, an incremental identification feature, and combined with the security information of the device and the network to more comprehensively evaluate the security of the access environment and generate a security label for the user authentication attribute. This label not only reflects the security of the device and the network, but also takes into account the riskiness of the user's behavior, thus providing a more comprehensive decision-making basis for subsequent identity authentication.

[0078] Optionally, a weighted scoring method is adopted to fuse the access device security information, the network path security information and the incremental identification feature, calculate the overall security level, and assign a security label for the user authentication attribute according to the calculated security level result.

[0079] In the whole solution, the role of this process is to further refine the access security evaluation, ensure that the authentication system can dynamically adapt to different user behaviors and access scenarios, and enhance the flexibility and security of the system.

[0080] An authentication factor matching module 12 for matching the user authentication attribute with a multi-factor authentication mechanism to determine the authentication matching status and factor fusion ratio of each factor authentication.

[0081] Specifically, based on the user authentication attributes, analyze the user's identity characteristics, determine a suitable multi-factor authentication mechanism, match the user authentication attributes with the multi-factor authentication mechanism, and determine the matching status of each authentication factor. For example, if the security of the user's access device is high, the system may assign a higher priority to the authentication factor based on device fingerprint; if there are risks in the network path, the weight of SMS verification code or two-factor authentication may be increased.

[0082] Specifically, the authentication matching status refers to the importance or priority of a certain authentication factor relative to other factors in multi-factor authentication; the factor fusion ratio refers to the weight ratio of each authentication factor in the comprehensive authentication process, which is used to determine their contribution degree in the final authentication result. For example, for a high-risk access environment, the system may increase the weight of biometric recognition (such as fingerprint or face recognition) to 70%, while reducing the weight of password verification to 30%.

[0083] By matching the identity authentication elements according to the user authentication attributes and the multi-factor authentication mechanism, the system can dynamically determine the matching status and fusion ratio of each authentication factor. This process significantly enhances the flexibility and adaptability of identity authentication, enabling it to adjust the authentication strategy according to the user's access environment and behavior characteristics.

[0084] In some embodiments, the authentication factor matching module 12 includes:

[0085] A core authentication element determination unit for analyzing the user attribute characteristics according to the user authentication attributes and determining the core authentication element; an authentication matching determination degree acquisition unit for obtaining the authentication matching determination degree by matching the identity authentication elements with the multi-factor authentication mechanism using the core authentication element, where the authentication matching determination degree describes the authentication determination degree of the matching factor authentication mechanism for the core authentication element; a central authentication mechanism configuration unit for performing a matching maximization search according to the authentication matching determination degree of the multi-factor authentication mechanism to obtain the central authentication mechanism and configure the central authentication mechanism to have the primary authentication status; an auxiliary authentication mechanism and fusion ratio determination unit for determining the security authentication target according to the security label of the user authentication attributes and searching in the multi-factor authentication mechanism based on the security authentication target to obtain the auxiliary authentication mechanism and the factor fusion ratio.

[0086] Specifically, by matching the user authentication attributes with the multi-factor authentication mechanism, the authentication status and fusion ratio of each authentication factor are determined, thereby enhancing the authentication security and optimizing the authentication experience. Among them, the core authentication element refers to the attributes or characteristics that play a key role in the user authentication process, such as the user's job number, fingerprint, facial recognition, etc.; the authentication matching certainty refers to the accuracy and reliability degree of the matching between a certain authentication factor and the core authentication element, and is used to measure the effectiveness of this authentication factor in verifying the core authentication element.

[0087] Specifically, the central authentication mechanism refers to the authentication method that occupies the primary position in multi-factor authentication, such as the main verification means of the core authentication element; the auxiliary authentication mechanism refers to other authentication methods used to enhance the authentication reliability and security outside the central authentication mechanism; the factor fusion ratio refers to the weight ratio of the central authentication mechanism and the auxiliary authentication mechanism in the comprehensive authentication process, and is used to balance the contributions of different authentication factors.

[0088] Specifically, first, the core authentication element determination unit analyzes the user attribute characteristics according to the user authentication attributes to determine the core authentication element, such as the user's job number or biometric characteristics. Then, the authentication matching certainty acquisition unit uses the core authentication element to match with the multi-factor authentication mechanism and calculates the matching certainty of each authentication factor with the core authentication element. For example, the output result entropy value of each authentication factor is calculated through experimental data to determine its authentication certainty degree for the core authentication element. Then, the central authentication mechanism configuration unit performs a matching maximization search according to the authentication matching certainty, selects the authentication factor with the highest certainty as the central authentication mechanism, and configures it to have the primary authentication status. Finally, the auxiliary authentication mechanism and fusion ratio determination unit determines the security authentication target according to the security label of the user authentication attributes, and searches for a suitable auxiliary authentication mechanism and its fusion ratio in the multi-factor authentication mechanism. For example, if the security label shows that there is a risk in the user access environment, the weight of the auxiliary authentication mechanism may be increased.

[0089] Exemplarily, according to the user authentication attributes, the user identity characteristics are analyzed to extract the core authentication element:

[0090] Table 3 Exemplary Core Authentication Elements

[0091] User type Core authentication factor Ordinary user Device information, network characteristics Enterprise user Device security policy, VPN authentication High-risk user Behavior pattern, geographical location

[0092] Exemplarily, the core authentication element is matched with the multi-factor authentication mechanism to calculate the matching certainty (i.e., the adaptability of the authentication factor to the core authentication element). The matching certainty calculation formula is as follows:

[0093] AMC(F i ,A j )=W i ×R(Fi , A j );

[0094] Among them, F i represents the i-th core authentication factor (such as device fingerprint, biometric feature, IP address, etc.); A j represents the j-th multi-factor authentication method (such as password, SMS verification code, fingerprint recognition, etc.); W i represents the weight of the authentication factor, which is set based on system policies (such as biometric recognition weight is higher than that of password); R(F i , A j ) is the factor adaptation degree between the i-th core authentication factor and the j-th multi-factor authentication method, which is calculated based on historical authentication data, user behavior, and environmental factors, and takes values from 0 to 1.

[0095] Suppose user A accesses the financial service platform, and the system detects the core authentication factors: device fingerprint, IP address, biometric feature; the authentication mechanisms: password, SMS verification code, biometric recognition, device fingerprint. Then the corresponding matching certainty calculation table is as follows:

[0096] Table 4 Exemplary matching certainty calculation table

[0097]

[0098] Analyzing the matching certainty, it can be seen that the device fingerprint authentication (0.855) is the highest, and this method is preferentially selected as the central authentication mechanism; the biometric recognition (0.72) has a relatively high adaptability and can be used as an auxiliary authentication method; the SMS verification code (0.28) has a relatively low adaptability and is only used for additional security verification.

[0099] The above process can dynamically adjust the authentication strategy through the determination of core authentication factors, the acquisition of authentication matching certainty, the configuration of the central authentication mechanism, and the determination of the auxiliary authentication mechanism and the fusion ratio, so as to adapt to different user access environments and security requirements. Among them, the determination of core authentication factors ensures the reliability and pertinence of the authentication process, while the calculation of authentication matching certainty provides a scientific basis for selecting the optimal authentication mechanism. The combination of the central authentication mechanism and the auxiliary authentication mechanism, as well as the dynamic adjustment of the factor fusion ratio, further enhances the flexibility and adaptability of the authentication. For example, in a high-risk access environment, the system can increase the weight of the auxiliary authentication mechanism to improve security; while in a low-risk environment, the authentication steps can be simplified to improve the user experience.

[0100] The above dynamic adjustment mechanism not only improves the security and reliability of identity authentication, but also optimizes the authentication efficiency, meeting the high requirements for identity authentication in the scenario of multi-party data sharing.

[0101] In some implementation manners, the authentication matching certainty acquisition unit includes:

[0102] An authentication experiment data establishment subunit for establishing the authentication experiment data of the core authentication elements and the multi-factor authentication mechanism; an authentication matching certainty calculation subunit for calculating, according to the authentication experiment data, the entropy value of the authentication output result of each factor authentication mechanism for the core authentication elements, and determining the certainty of the corresponding factor authentication mechanism for authenticating the core authentication elements based on the entropy value of the output result.

[0103] Optionally, during the authentication process, the uncertainty of each authentication factor is evaluated in real time, such as by calculating the entropy value or confidence level of the output result of each authentication factor to measure its uncertainty.

[0104] Specifically, the authentication experiment data refers to the data collected through experiments or simulated authentication scenarios, which is used to evaluate the matching effect of the multi-factor authentication mechanism on the core authentication elements; the entropy value is used to measure the uncertainty of information. In identity authentication, the higher the entropy value, the greater the uncertainty of the authentication result, and vice versa; through entropy value calculation, the authentication matching certainty can be obtained, which can quantitatively represent the matching accuracy and reliability degree of a certain authentication factor for the core authentication elements.

[0105] Specifically, first, the authentication experiment data establishment subunit collects the authentication data of the core authentication elements and the multi-factor authentication mechanism through experiments or simulated authentication scenarios. This data includes the output results of different authentication factors in different environments, such as the matching success rate of biometric identification and the error rate of password verification. Then, the authentication matching certainty calculation subunit calculates the entropy value of the output result of each authentication factor according to the authentication experiment data. For example, for a biometric authentication factor, if its output results are highly consistent (low entropy value) in multiple experiments, it indicates that the matching certainty of this authentication factor for the core authentication elements is relatively high; if the output results vary greatly (high entropy value), the matching certainty is relatively low. Based on the entropy value of the output result, the system can determine the matching certainty of each authentication factor for the core authentication elements.

[0106] By establishing the authentication experiment data and using information entropy to calculate the uncertainty of the output results of each authentication factor, the matching certainty is determined, providing data support for the system to dynamically adjust the authentication mechanism.

[0107] A hierarchical authentication module 13 for performing hierarchical authentication on the user feedback identity data according to the authentication matching status and factor fusion ratio of each factor authentication, and tracking and recording the authentication process;

[0108] Specifically, according to the matching status and fusion ratio of each authentication factor, the authentication process is divided into multiple levels to verify the identity data feedback by the user. Among them, the authentication matching status refers to the priority or importance of a certain authentication factor in the authentication process, and the factor fusion ratio refers to the weight distribution of each authentication factor in the comprehensive authentication result.

[0109] Optionally, the core authentication factor (such as biometric identification or job number verification) is used as the primary authentication level, and the auxiliary authentication factor (such as SMS verification code or device fingerprint) is used as the secondary authentication level. According to the identity data feedback by the user, authentication is performed at the primary authentication level and the secondary authentication level respectively, and the primary authentication level result and the secondary authentication level result are comprehensively calculated according to the factor fusion ratio to obtain the fusion authentication result. Through hierarchical authentication and tracking records of the authentication process, the system can flexibly adjust the authentication strategy according to the matching status and fusion ratio of each authentication factor to ensure that the authentication process is both efficient and secure.

[0110] Specifically, record each step and result in the authentication process for subsequent auditing and analysis.

[0111] In some embodiments, the hierarchical authentication module 13 includes:

[0112] An authentication level construction unit, configured to establish a primary authentication level according to the central authentication mechanism, establish a secondary authentication level according to the auxiliary authentication mechanism and the factor fusion ratio, and connect the primary authentication level and the secondary authentication level; a core authentication execution unit, configured to perform core authentication element authentication on the identity data feedback by the user through the primary authentication level to obtain a central authentication result; a fusion authentication execution unit, configured to perform element authentication on the corresponding authentication elements of the identity data feedback by the user through the secondary authentication level to obtain a secondary authentication result; and obtain a fusion authentication result according to the central authentication result and the secondary authentication result.

[0113] Specifically, the primary authentication level refers to the authentication stage that verifies the core elements of the user identity based on the central authentication mechanism, and usually has a higher priority and weight; the secondary authentication level refers to the authentication stage that verifies other elements of the user identity based on the auxiliary authentication mechanism, and is usually used to enhance the reliability and security of the authentication.

[0114] Specifically, first, the authentication level construction unit establishes the primary authentication level according to the central authentication mechanism, which focuses on verifying the core authentication elements in the user feedback identity data. For example, if the core authentication element is the user's fingerprint information, the system will verify the fingerprint through biometric technology to obtain the central authentication result. Then, the authentication level construction unit establishes the secondary authentication level according to the auxiliary authentication mechanism and the factor fusion ratio, which verifies other authentication elements in the user feedback identity data. For example, the auxiliary authentication mechanism may be a SMS verification code or a device fingerprint, and these elements are verified to obtain the secondary authentication result. Then, the authentication level construction unit connects the results of the primary authentication level and the secondary authentication level, and comprehensively calculates the central authentication result and the secondary authentication result according to the factor fusion ratio to finally obtain the fusion authentication result. Through the above hierarchical authentication and weight allocation, the flexibility and security of the authentication process are ensured, and at the same time, the reliability and adaptability of the authentication are improved.

[0115] In some implementation manners, the fusion authentication execution unit further includes:

[0116] The determination threshold subunit is configured to determine an authentication determination threshold according to the security label of the user authentication attribute; the fusion authentication result determination subunit is configured to perform comprehensive calculation of the authentication determination according to the central authentication result and the secondary authentication result, and use the comprehensive calculation result to determine whether the authentication determination threshold is satisfied. When it is satisfied, the fusion authentication result is set as the identity authentication passed, and all authentication results are recorded and stored.

[0117] Specifically, the authentication determination threshold is a preset threshold for determining whether the user's identity authentication is passed. Each authentication process sets different authentication determination thresholds according to different risk levels (the security label of the user authentication attribute), and further sets different authentication passing criteria. For example, in a low-risk scenario, the determination threshold for authentication passing is relatively low; in a high-risk scenario, the determination threshold for authentication passing is relatively high.

[0118] Specifically, first, determine the authentication certainty threshold according to the security label of the user authentication attribute. This security label reflects the risk level of the user access environment. For example, if there is a high risk in the user access environment (such as accessing through public Wi-Fi), the system will set a relatively high authentication certainty threshold; if the access environment is secure (such as accessing through the enterprise intranet), a relatively low threshold can be set. Then, perform a comprehensive calculation of the authentication certainty based on the central authentication result and the secondary authentication result. For example, the weight of the central authentication mechanism (such as fingerprint recognition) may be 70%, and the weight of the auxiliary authentication mechanism (such as SMS verification code) is 30%. The system multiplies the authentication certainty of the two results by their respective weights and then adds them together to obtain the comprehensive authentication certainty. Then, use the comprehensive calculation result to determine whether the authentication certainty threshold is met. If the comprehensive authentication certainty reaches or exceeds the threshold, the fused authentication result is set as the identity authentication passed; if it does not reach the threshold, the authentication fails.

[0119] Exemplarily, if the core authentication elements (such as biometric recognition, digital certificate, etc.) are verified to pass, the authentication result is regarded as relatively reliable and usually obtains a relatively high authentication certainty. If the core authentication elements do not pass, but the authentication certainty after comprehensive calculation reaches the set threshold, it may still pass the authentication.

[0120] Furthermore, record and store all authentication results, including the failed authentication results, for subsequent verification of their compliance.

[0121] The above process ensures that the system can flexibly determine whether the user identity authentication passes while considering the risk of the user access environment by setting the authentication certainty threshold and performing comprehensive calculations. This mechanism allows the user identity authentication to still be determined as passed as long as the comprehensive authentication certainty reaches the threshold in the case where the core authentication elements pass but the auxiliary authentication elements do not pass, improving the flexibility and adaptability of the authentication, optimizing the user experience, and avoiding the overall failure of the authentication due to the failure of a single factor.

[0122] In some implementation manners, the execution steps of the fused authentication result determination subunit further include:

[0123] Based on the security authentication target, configure the element authentication proportion weights of the central authentication mechanism and the auxiliary authentication mechanism; when the central authentication result is authentication passed, obtain the auxiliary authentication mechanisms that are authentication passed in the secondary authentication result; use the authentication certainty corresponding to the central authentication mechanism and the auxiliary authentication mechanisms that are authentication passed in the secondary authentication result and the authentication proportion weights to perform weighted calculation to obtain the comprehensive calculation result.

[0124] Specifically, the weight of element authentication ratio refers to the weight assigned to each authentication factor (central authentication mechanism and auxiliary authentication mechanism) when comprehensively calculating the authentication certainty, which is used to reflect its importance in the authentication process.

[0125] Specifically, when the core authentication element (central authentication) passes the verification, the fusion authentication result determination subunit will further evaluate whether the auxiliary authentication elements (such as dynamic passwords, SMS verification codes, etc.) pass. For each auxiliary authentication element, if it passes the verification (for example, the SMS verification code passes the verification), it is marked as authenticated; then, according to the authenticated elements in the central authentication mechanism and the secondary authentication mechanism, the weighted calculation is performed using the authentication ratio weight to obtain the final comprehensive authentication certainty.

[0126] Exemplarily, assume that the certainty of core authentication (fingerprint authentication) is 0.85 and the weight is 0.7; the certainty of secondary authentication (SMS verification code) is 0.75 and the weight is 0.3. Then the comprehensive authentication certainty = (0.85 × 0.7) + (0.75 × 0.3)) = 0.595 + 0.225 = 0.82.

[0127] By configuring the authentication ratio weight based on the security authentication target and performing weighted calculation according to the central authentication result and the passed auxiliary authentication result, the system can flexibly adjust the authentication strategy to ensure the reliability and adaptability of the authentication result. For example, when the core authentication element passes, even if some auxiliary authentication elements do not pass, the system can still make a comprehensive judgment according to the weight and certainty of the passed auxiliary authentication mechanism, thus avoiding the overall failure of authentication due to the failure of a single factor.

[0128] The authentication verification module 14 is used to perform identity authentication collaborative verification according to the hierarchical authentication result and the authentication tracking record, and the user who meets the verification result can access the trusted data space.

[0129] Specifically, the tracking record will generate a detailed authentication record during each user authentication, including the authentication status of each authentication element, the uncertainty during the authentication process (such as entropy value, confidence level), the result of weighted calculation, etc.

[0130] Specifically, when the user attempts to access the trusted data space, the system will initiate an identity authentication verification request, extract the previously generated hierarchical authentication result and the authentication tracking record for comprehensive evaluation. Exemplarily, if the user's identity authentication passes and the tracking record shows no potential risks (such as multiple failed attempts, abnormal authentication time, etc.), the verification process will enter the next step, that is, the user is allowed to access the trusted data space; if the tracking record shows potential risks or the authentication fails, the risk will be evaluated according to the security label of the tracking record to decide whether to allow re-verification or reject access.

[0131] Through the collaborative verification of the hierarchical authentication result and the authentication tracking record, the system can comprehensively and meticulously verify the user's authentication process to ensure that only legitimate users can access the trusted data space. This mechanism not only enhances the reliability and security of identity authentication but also provides an important basis for the security audit of the system.

[0132] In summary, the identity authentication system for the trusted data space of multi-party data sharing provided by the present invention has the following technical effects:

[0133] Through the authentication attribute acquisition module, connect to the user authentication channel to identify the user authentication attributes; the authentication factor matching module matches the identity authentication elements according to the user authentication attributes and the multi-factor authentication mechanism to determine the authentication matching status and factor fusion ratio of each factor authentication; the hierarchical authentication module performs hierarchical authentication on the user feedback identity data according to the authentication matching status and factor fusion ratio of each factor authentication and tracks and records the authentication process; the authentication verification module performs identity authentication collaborative verification according to the hierarchical authentication result and the authentication tracking record, and users who meet the verification result can access the trusted data space, thereby achieving the technical effects of improving the security and reliability of identity authentication, enhancing the flexibility and adaptability of authentication, and improving the authentication efficiency.

[0134] Embodiment 2, as Figure 2 is a schematic flowchart of the identity authentication method for the trusted data space of multi-party data sharing of the present invention. For example, Figure 1 the structure of the identity authentication system for the trusted data space of multi-party data sharing of the present invention in Figure 2 can be used to implement the process as shown in

[0135] Based on the same concept as the identity authentication system for the trusted data space of multi-party data sharing in the above embodiment, the identity authentication method for the trusted data space of multi-party data sharing provided by the present invention further includes:

[0136] Connect to the user authentication channel to identify the user authentication attributes.

[0137] Match the identity authentication elements according to the user authentication attributes and the multi-factor authentication mechanism to determine the authentication matching status and factor fusion ratio of each factor authentication.

[0138] Perform hierarchical authentication on the user feedback identity data according to the authentication matching status and factor fusion ratio of each factor authentication, and track and record the authentication process.

[0139] Perform identity authentication collaborative verification according to the hierarchical authentication result and the authentication tracking record, and users who meet the verification result can access the trusted data space.

[0140] In some embodiments, the connecting to the user authentication channel to identify the user authentication attributes includes:

[0141] Identify the user access device and the access network path according to the user authentication channel.

[0142] Analyze the security status and user characteristics of the user access device information based on the user access device to determine the access device security information and device attribute characteristics.

[0143] Analyze the user access network path to obtain network path security information and network attribute characteristics.

[0144] Perform user authentication attribute identification and matching according to the device attribute characteristics and the network attribute characteristics to obtain user authentication attributes, and use the access device security information and the network path security information to evaluate the access security and generate a security label for the user authentication attributes.

[0145] In some implementation manners, analyzing the user access network path to obtain network path security information and network attribute characteristics includes:

[0146] Identify network basic parameters, including IP address and access network type.

[0147] Based on the IP address and the access network type, perform routing path tracing, and perform risk assessment on each node of the routing path and consistency determination of attribute characteristics to obtain the network path security information and network attribute characteristics.

[0148] In some implementation manners, using the access device security information and the network path security information to evaluate the access security and generate a security label for the user authentication attributes further includes:

[0149] Obtain the request event corresponding to the user authentication.

[0150] Perform risk assessment according to the request event to obtain request event risk information.

[0151] Use the request event risk information as an incremental identification feature, and perform comprehensive security information evaluation with the access device security information and the network path security information to obtain access security evaluation information and generate the security label for the user authentication attributes.

[0152] In some embodiments, perform identity authentication element matching according to the user authentication attributes and a multi-factor authentication mechanism to determine the authentication matching status and factor fusion ratio of each factor authentication, including:

[0153] Analyze the user attribute characteristics according to the user authentication attributes to determine the core authentication elements.

[0154] Match the identity authentication elements using the core authentication elements and the multi-factor authentication mechanism to obtain an authentication matching certainty, where the authentication matching certainty describes the authentication certainty of the matching factor authentication mechanism for the core authentication elements.

[0155] Perform a matching maximization search based on the authentication matching certainty of the multi-factor authentication mechanism to obtain a central authentication mechanism, and configure the central authentication mechanism to have the primary authentication status.

[0156] Determine a security authentication target based on the security label of the user authentication attribute, and search in the multi-factor authentication mechanism based on the security authentication target to obtain an auxiliary authentication mechanism and a factor fusion ratio.

[0157] In some implementation manners, matching the identity authentication elements using the core authentication elements and the multi-factor authentication mechanism to obtain an authentication matching certainty includes:

[0158] Establish authentication experimental data of the core authentication elements and the multi-factor authentication mechanism.

[0159] According to the authentication experimental data, calculate the entropy value of the authentication output result of each factor authentication mechanism for the core authentication elements, and determine the certainty of the corresponding factor authentication mechanism for authenticating the core authentication elements based on the entropy value of the output result.

[0160] In some embodiments, hierarchical authentication of the user feedback identity data according to the authentication matching status of each factor authentication and the factor fusion ratio includes:

[0161] Establish a primary authentication level according to the central authentication mechanism, establish a secondary authentication level according to the auxiliary authentication mechanism and the factor fusion ratio, and connect the primary authentication level and the secondary authentication level.

[0162] Perform core authentication element authentication on the user feedback identity data through the primary authentication level to obtain a central authentication result.

[0163] Perform element authentication on the corresponding authentication elements of the user feedback identity data through the secondary authentication level to obtain a secondary authentication result.

[0164] Obtain a fusion authentication result according to the central authentication result and the secondary authentication result.

[0165] In some implementation manners, obtaining a fusion authentication result includes:

[0166] Determine an authentication certainty threshold according to the security label of the user authentication attribute.

[0167] Based on the central authentication result and the secondary authentication result, perform comprehensive calculation of the authentication certainty. Use the comprehensive calculation result to determine whether the authentication certainty threshold is met. When it is met, the fusion authentication result is set to identity authentication passed, and all authentication results are recorded and stored.

[0168] In some implementation manners, performing comprehensive calculation of the authentication certainty based on the central authentication result and the secondary authentication result includes:

[0169] Based on the security authentication target, configure the element authentication proportion weight values of the central authentication mechanism and the auxiliary authentication mechanism.

[0170] When the central authentication result is authentication passed, obtain the auxiliary authentication mechanisms that are authentication passed in the secondary authentication result.

[0171] Use the authentication certainty corresponding to the central authentication mechanism and the auxiliary authentication mechanisms that are authentication passed in the secondary authentication result and the authentication proportion weight values to perform weighted calculation to obtain the comprehensive calculation result.

[0172] It should be understood that the embodiments mentioned in this specification focus on their differences from other embodiments. The specific embodiments in the foregoing Embodiment 1 are equally applicable to the identity authentication method for the trusted data space of multi-party data sharing described in Embodiment 2. For the sake of brevity of the specification, no further elaboration is made here.

[0173] It should be understood that the disclosed embodiments of the present invention and the above descriptions can enable those skilled in the art to implement the present invention using the present invention. At the same time, the present invention is not limited to the above-mentioned part of the embodiments. It should be understood that those of ordinary skill in the art can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.

Claims

1. A trusted data space identity authentication system for multi-party data sharing, characterized in that: include: The authentication attribute acquisition module is used to connect to the user authentication channel and identify the user authentication attributes; An authentication factor matching module is used to match the identity authentication elements according to the user authentication attributes and the multi-factor authentication mechanism, and determine the authentication matching status of each factor authentication and the factor fusion ratio; A hierarchical authentication module, used to perform hierarchical authentication on the user feedback identity data according to the authentication matching status of each authentication factor and the factor fusion ratio, and to track and record the authentication process; The authentication and verification module is used to perform collaborative identity authentication based on the hierarchical authentication results and authentication tracking records, so that users who meet the verification results can access the trusted data space.

2. The trusted data space identity authentication system for multi-party data sharing according to claim 1 is characterized in that: The authentication attribute acquisition module includes: A user access information identification unit, used to identify a user access device and an access network path according to the user authentication channel; The access device security and feature analysis unit is used to analyze the security status and user features of the user access device information according to the user access device, and determine the access device security information and device attribute features; A network path security and feature analysis unit is used to analyze the user's access network path and obtain network path security information and network attribute features; The user authentication attribute and security evaluation unit is used to identify and match the user authentication attribute according to the device attribute characteristics and the network attribute characteristics, obtain the user authentication attribute, use the access device security information and the network path security information to perform access security evaluation, and generate a security label for the user authentication attribute.

3. The trusted data space identity authentication system for multi-party data sharing according to claim 2 is characterized in that: The network path security and feature analysis unit includes: A network basic parameter identification subunit is used to identify network basic parameters, including IP address and access network type; The network path security and feature acquisition subunit is used to track the routing path based on the IP address and access network type, conduct risk assessment of each node in the routing path and determine the consistency of attribute features, and obtain the network path security information and network attribute features.

4. The trusted data space identity authentication system for multi-party data sharing according to claim 2, characterized in that: The user authentication attribute and security evaluation unit further includes: The request event acquisition subunit is used to obtain the request event corresponding to the user authentication; A request event risk assessment subunit, used to perform risk assessment according to the request event and obtain request event risk information; A security label generation subunit is used to use the request event risk information as an incremental identification feature, perform a comprehensive security information evaluation with the access device security information and the network path security information, obtain access security evaluation information, and generate a security label for the user authentication attribute.

5. The trusted data space identity authentication system for multi-party data sharing according to claim 2, characterized in that: The authentication factor matching module includes: A core authentication factor determination unit, configured to perform user attribute feature analysis based on the user authentication attributes to determine core authentication factors; an authentication match certainty acquisition unit, configured to use the core authentication element to match the identity authentication element with the multi-factor authentication mechanism to obtain an authentication match certainty, wherein the authentication match certainty describes the authentication certainty degree of the matching factor authentication mechanism for the core authentication element; A central authentication mechanism configuration unit, configured to perform a match maximization search according to the authentication match certainty of the multi-factor authentication mechanism, obtain a central authentication mechanism, and configure the central authentication mechanism to have authentication primacy; The auxiliary authentication mechanism and fusion ratio determination unit is used to determine the security authentication target according to the security label of the user authentication attribute, search in the multi-factor authentication mechanism based on the security authentication target, and obtain the auxiliary authentication mechanism and factor fusion ratio.

6. The trusted data space identity authentication system for multi-party data sharing according to claim 5, characterized in that: The authentication matching certainty acquisition unit includes: An authentication experiment data establishment subunit, used to establish authentication experiment data of the core authentication elements and the multi-factor authentication mechanism; The authentication matching certainty calculation subunit is used to calculate the entropy value of the authentication output result of each factor authentication mechanism for the core authentication element according to the authentication experiment data, and determine the certainty of the corresponding factor authentication mechanism for authenticating the core authentication element based on the entropy value of the output result.

7. The trusted data space identity authentication system for multi-party data sharing according to claim 5, characterized in that: The hierarchical authentication module comprises: An authentication level construction unit, used to establish a primary authentication level according to a central authentication mechanism, establish a secondary authentication level according to the auxiliary authentication mechanism and a factor fusion ratio, and connect the primary authentication level with the secondary authentication level; A core authentication execution unit, used to perform core authentication element authentication on the user feedback identity data through the primary authentication level to obtain a central authentication result; The fusion authentication execution unit is used to perform element authentication on the authentication element corresponding to the user feedback identity data through the secondary authentication level to obtain the secondary authentication result; and obtain the fusion authentication result based on the central authentication result and the secondary authentication result.

8. The trusted data space identity authentication system for multi-party data sharing according to claim 7, characterized in that: The fusion authentication execution unit further includes: A certainty threshold subunit, used to determine an authentication certainty threshold according to the security label of the user authentication attribute; The fusion authentication result determination subunit is used to perform a comprehensive calculation of the authentication certainty based on the central authentication result and the secondary authentication result, and use the comprehensive calculation result to determine whether the authentication certainty threshold is met. When it is met, the fusion authentication result is set as identity authentication passed, and all authentication results are recorded and stored.

9. The trusted data space identity authentication system for multi-party data sharing according to claim 8, characterized in that: The execution steps of the fusion authentication result determination subunit also include: Based on the security authentication target, configure the element authentication ratio weights of the central authentication mechanism and the auxiliary authentication mechanism; When the central authentication result is authentication passed, obtaining the auxiliary authentication mechanism that is authentication passed in the secondary authentication result; The comprehensive calculation result is obtained by performing weighted calculation on the authentication certainty corresponding to the auxiliary authentication mechanism that has passed the authentication in the secondary authentication result and the authentication proportion weight.

10. A trusted data space identity authentication method for multi-party data sharing, characterized in that: The trusted data space identity authentication system for multi-party data sharing according to any one of claims 1 to 9, wherein the trusted data space identity authentication method for multi-party data sharing comprises: Connect to the user authentication channel and identify the user authentication attributes; Matching the identity authentication elements with the multi-factor authentication mechanism according to the user authentication attributes, and determining the authentication matching status of each factor authentication and the factor fusion ratio; Perform hierarchical authentication on the user's feedback identity data according to the authentication matching status of each authentication factor and the factor fusion ratio, and track and record the authentication process; Identity authentication is collaboratively verified based on the hierarchical authentication results and authentication tracking records, and users who meet the verification results have access to the trusted data space.

Citation Information

Patent Citations

  • Identity information fusion system based on multiple features

    CN111539471A

  • Transaction request processing method, device and equipment

    CN116934340A

  • Smart home remote monitoring data sharing authentication system with multi-level verification

    CN118590245A

  • Multi-factor dynamic identity verification and access control system

    CN119272259A

  • Secure electronic transaction authentication

    US20180336554A1

Cited By

  • Invoice automatic registration system and method based on multi-factor authentication

    CN121258718A

  • Invoice automatic registration system and method based on multi-factor authentication

    CN121258718B