Dynamic risk assessment method and system in multi-factor authentication process
By building an authentication ecosystem and using an automated orchestration engine, combining environmental trust and multi-factor authentication mode, the authentication process is dynamically adjusted, and the problem of poor user experience in multi-factor authentication is solved, and the security and user experience are improved.
Patent Information
- Application Number
- CN202510429268.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-04
AI Technical Summary
The existing multi-factor authentication methods cannot dynamically adjust the authentication process according to real-time risks, resulting in poor user experience.
By building an authentication ecosystem, combining environmental trust and multi-factor authentication mode, using upper and lower-level perception and automated orchestration engines, dynamically adjusting the authentication process, generating dynamic risk sequences and managing user operation permissions.
Real-time monitoring and adaptive adjustments are achieved in the multi-factor authentication process, improving security and optimizing user experience.
Smart Images

Figure CN120263483A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly to a dynamic risk assessment method and system in the process of multi-factor authentication. Background Art
[0002] With the continuous evolution and sophistication of network attack means, traditional static identity authentication methods, such as the username / password method, can no longer effectively cope with the increasing security threats. To solve this problem, the prior art has proposed multi-factor authentication methods, which greatly enhance the account security by combining multiple verification factors such as knowledge, ownership, and biometric recognition. However, there are still problems such as high complexity in the implementation and management of multi-factor authentication methods and poor user experience, especially in scenarios where identity verification needs to be performed frequently.
[0003] In the prior art, multi-factor authentication cannot dynamically adjust the authentication process according to real-time risks, resulting in the technical problem of poor user experience. Summary of the Invention
[0004] This application provides a dynamic risk assessment method and system in the process of multi-factor authentication, which is used to solve the technical problem that in the prior art, multi-factor authentication cannot adjust the authentication process according to real-time risks and has a poor user experience.
[0005] In view of the above problems, this application provides a dynamic risk assessment method and system in the process of multi-factor authentication.
[0006] In the first aspect of this application, a dynamic risk assessment method in the process of multi-factor authentication is provided. The method includes: taking the upper and lower position perception as the dynamic risk assessment method and the automated orchestration engine as the authentication decision method according to the environmental trust and multi-factor authentication mode, constructing an authentication ecosystem and deploying it on the information platform, where the multi-factor authentication mode is determined based on the coupling of the fixed state and the random state; based on the authentication ecosystem, performing a first authentication according to the initial environmental trust degree to determine a first authentication portrait, where the first authentication portrait is determined based on environmental risks, user risks, and authentication information; using the first authentication portrait as a baseline, tracking the user operation chain, triggering the automated orchestration engine to generate an authentication response pop-up window through the upper and lower position dynamic perception evaluation based on the operation chain nodes, iteratively updating the first authentication portrait according to the authentication results, and generating a dynamic risk sequence based on the user operation chain, where user operation permission management is performed by introducing dynamic permission constraints.
[0007] In the second aspect of the present application, a dynamic risk assessment system in a multi-factor authentication process is provided. The system includes: an authentication ecosystem construction module, which is used to take the upper and lower position perception as a dynamic risk assessment method and the automated orchestration engine as an authentication decision-making method according to environmental trust and the multi-factor authentication mode, construct an authentication ecosystem and deploy it on the information platform, wherein the multi-factor authentication mode is determined based on the coupling of the fixed state and the random state; an authentication portrait determination module, which is used to perform a first authentication based on the initial environmental trust degree according to the authentication ecosystem to determine a first authentication portrait, wherein the first authentication portrait is determined based on environmental risk, user risk, and authentication information; a dynamic risk sequence generation module, which is used to take the first authentication portrait as a baseline, track the user operation chain, trigger the automated orchestration engine to generate an authentication response pop-up window through the upper and lower position dynamic perception evaluation based on the operation chain nodes, iteratively update the first authentication portrait according to the authentication result, and generate a dynamic risk sequence based on the user operation chain, wherein user operation permission management is carried out by introducing dynamic permission constraints.
[0008] One or more technical solutions provided in the present application have at least the following technical effects or advantages:
[0009] The method provided in the embodiment of the present application takes the upper and lower position perception as a dynamic risk assessment method and the automated orchestration engine as an authentication decision-making method according to environmental trust and the multi-factor authentication mode, constructs an authentication ecosystem and deploys it on the information platform, wherein the multi-factor authentication mode is determined based on the coupling of the fixed state and the random state; performs a first authentication based on the initial environmental trust degree according to the authentication ecosystem to determine a first authentication portrait; takes the first authentication portrait as a baseline, tracks the user operation chain, triggers the automated orchestration engine to generate an authentication response pop-up window through the upper and lower position dynamic perception evaluation based on the operation chain nodes, iteratively update the first authentication portrait according to the authentication result, and generate a dynamic risk sequence based on the user operation chain, wherein user operation permission management is carried out by introducing dynamic permission constraints. It achieves the technical effect of carrying out dynamic risk assessment in the multi-factor authentication process, realizing the monitoring and adaptive adjustment of the authentication process, improving security, and optimizing the user experience at the same time. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0011] Figure 1 It is a schematic flowchart of the dynamic risk assessment method in the multi-factor authentication process provided by the present application;
[0012] Figure 2 This is a schematic structural diagram of the dynamic risk assessment system in the multi-factor authentication process provided by this application.
[0013] Explanation of the reference numerals in the drawings: Authentication ecosystem construction module 11, authentication portrait determination module 12, dynamic risk sequence generation module 13. Specific implementation manners
[0014] This application provides a dynamic risk assessment method and system in the multi-factor authentication process, which is used to solve the technical problem that in the prior art, multi-factor authentication cannot adjust the authentication process according to real-time risks, resulting in poor user experience. It achieves the technical effect of carrying out dynamic risk assessment in the multi-factor authentication process, realizing monitoring and adaptive adjustment of the authentication process, improving security while optimizing the user experience.
[0015] Next, the technical solutions in the present invention will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments of the present invention. It should be understood that the present invention is not limited by the exemplary embodiments described herein. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention. Additionally, it should be noted that for the sake of description, only the parts related to the present invention are shown in the drawings rather than all of them.
[0016] Embodiment 1, as Figure 1 shown, this application provides a dynamic risk assessment method in the multi-factor authentication process, and this method includes:
[0017] Based on environmental trust and the multi-factor authentication mode, taking the up-down perception as the dynamic risk assessment method and the automated orchestration engine as the authentication decision-making method, constructing an authentication ecosystem and deploying it on the information platform, wherein the multi-factor authentication mode is determined based on the coupling of the fixed state and the random state.
[0018] Specifically, the multi-factor authentication process refers to a security mechanism that verifies a user's identity by combining two or more different types of authentication factors. First, based on various factors in the current environment, such as device type, operating network, etc., the current environmental trust level is evaluated. Environmental trust refers to the assessment of the trust level of the user's current environment during the authentication process, and the factors considered include device credibility, network environment, geographical environment, etc. A high environmental trust level indicates a secure and reliable environment, while a low level indicates a higher risk. For example, in a trusted internal network environment, the trust level is relatively high, while when accessing from an unfamiliar IP or a high-risk area, the trust level decreases. At the same time, a multi-factor authentication mode is obtained. The multi-factor authentication mode adopts a hybrid authentication strategy that couples a fixed state and a random state. The fixed state refers to preset static authentication factors, such as passwords and user IDs, to ensure basic security. The random state refers to dynamically generated authentication factors, such as dynamic verification codes and geographical locations, to increase the difficulty of prediction by attackers. The proportion of the fixed state and the random state is dynamically adjusted according to the environmental trust level for coupling to determine the multi-factor authentication mode. For example, in a zero-trust environment, such as when logging in to an unfamiliar device for the first time, the proportion of the random state increases, requiring more stringent authentication; while in a high-trust environment, such as the company's internal network, the authentication frequency can be reduced, mainly relying on the fixed state, thereby improving security. Then, based on environmental trust and the multi-factor authentication mode, the up-down perception is used as a dynamic risk assessment method. The up-down perception refers to evaluating the authentication risk of users through information perception and data analysis at the upper and lower levels, including monitoring the upper-level environment and analyzing the lower-level user behavior. Through the up-down perception mechanism, the solution not only focuses on the authentication factors themselves but also analyzes the user's operating environment and behavior. The upper perception mainly focuses on the security of the entire environment, such as devices, networks, geographical locations, etc., while the lower perception focuses on the user's current operating behavior, such as login time, resources attempted to access, etc. For example, if a user's operation shows abnormalities during login, such as frequently attempting incorrect passwords, it will immediately trigger the lower perception for risk assessment and strengthen the authentication check, such as two-factor verification. If the user's operation is carried out in a trusted environment and the behavior is normal, a relatively simple authentication may be passed.
[0019] Moreover, through the automated orchestration engine, it is possible to automatically decide which authentication method to adopt based on the results of environmental trust and context awareness. The automated orchestration engine is an automated tool used to automatically select and execute various parts of the authentication process, such as verification methods, evaluation criteria, etc., according to predefined rules and input data, so as to achieve adaptive authentication decisions. Finally, the context awareness and authentication decision-making method of the dynamic risk assessment method determined according to environmental trust and the multi-factor authentication mode are integrated with the automated orchestration engine to form an authentication ecosystem, which is deployed on the information platform. The information platform refers to the basic platform for deploying the authentication ecosystem and is responsible for carrying and executing all aspects of authentication decisions, including authentication data collection, risk assessment, dynamic adjustment of authentication policies, and result feedback. The authentication ecosystem is an authentication system composed of various authentication means and dynamic assessment methods, including components such as authentication decision-making methods, environmental trust, multi-factor authentication modes, and dynamic risk assessment methods, jointly ensuring the security and flexibility of authentication. Based on the environmental trust level and the multi-factor authentication mode, combined with context awareness and the automated orchestration engine, a dynamic and flexible authentication platform is constructed, which can carry out dynamic risk assessment during the multi-factor authentication process, realize monitoring and adaptive adjustment, and improve the efficiency and accuracy of risk assessment.
[0020] Furthermore, taking the automated orchestration engine as the authentication decision-making method includes: traversing multiple authentication factors, determining multiple authentication engine nodes by executing deployments based on fixed states and random states; using the coupled decision based on fixed states and random states as the first-order training objective and the collaborative decision among multiple authentication factors as the second-order training objective, and performing data-driven training on the multiple authentication engine nodes to determine the automated orchestration engine.
[0021] Specifically, obtain all available authentication factors, which include fixed and random ones. Fixed authentication factors such as passwords and user IDs, and random authentication factors such as dynamic verification codes, geographical locations, login times, etc. By traversing these factors, multiple authentication engine nodes are determined. An authentication engine node refers to some independent authentication modules or judgment nodes involved in the multi-factor authentication process. Multiple authentication engine nodes represent different authentication means and verification methods, and each node plays an independent role in the authentication process. For example, it may first authenticate through the fixed-state authentication password verification method. If it passes, then perform secondary verification through the random-state dynamic verification code. During the authentication process, by combining fixed-state and random-state factors, a comprehensive authentication decision model is formed. The fixed state provides basic trust, while the random state introduces additional security evaluations for dynamic factors. Use the coupled decision of the fixed state and the random state as the first-order training objective to train the decision model, aiming to optimize the combination of these fixed and dynamic factors to improve the security and efficiency of authentication. Through the first-order training, learn from the data set how to improve authentication security through the combination of the fixed state and the random state. For example, fixed-state factors may include device types and operating systems, while random-state factors may include the user's current geographical location, network environment, or behavior patterns. By analyzing the historical data of these factors, build a basic training model to identify the performance and weights of different authentication factors in different environments. This stage mainly uses supervised learning methods to train the model by inputting known authentication data, such as cases of successful or failed authentication, adjust the weight coefficients, and optimize the authentication decision. After completing the first-order training, enter the second-order training objective. The focus of the second-order training is the collaborative decision-making among multiple authentication factors. By considering how multiple authentication factors affect the final authentication result together, optimize the decision-making process, and further enhance the flexibility of authentication. For example, to determine whether a user logs in from an uncommon location and device simultaneously, it is necessary to comprehensively consider the combination of password verification, device information, and location data. Through the second-order training, the decision model will learn how to balance and optimize decisions among multiple authentication factors. For example, when a user logs in in a normal working environment, the password is entered correctly and the device identity is confirmed without error. However, if the login location changes, the matching situation of the location and the device will be automatically analyzed comprehensively to confirm the authenticity of the user's identity. The second-order training objective aims to optimize the model through methods such as reinforcement learning, using a large amount of historical data and authentication requests, to achieve the best collaborative decision-making among multiple authentication factors, thereby improving the overall security and accuracy of authentication. Finally, according to the first-order training objective and the second-order training objective, through the training of multiple authentication engine nodes, a data-driven automated orchestration engine is generated. For example, one engine node is responsible for password verification, another is responsible for biometric identification, and the third is responsible for location-based dynamic verification, etc. After each engine node is trained, it can automatically select an appropriate authentication strategy according to the input data and execute the corresponding authentication steps.Through continuous iterative training, the model can optimize the collaborative work among various nodes, ensuring accuracy and efficiency in different authentication environments. Eventually, these trained authentication engine nodes will be integrated into the automated orchestration engine, which is responsible for automatically selecting and executing appropriate authentication strategies. It can determine which authentication method to use in real time based on different factors such as user behavior, environmental risk, and device security. The output of this engine is not just an authentication decision but an optimized authentication strategy for a specific situation, capable of dynamically adjusting and responding in real time to different security requirements. For example, under normal circumstances, a user may only need to enter a password for authentication; while in case of suspicious behavior, additional biometric identification or SMS verification codes may be required. Through training, the automated orchestration engine that flexibly selects authentication methods and authentication factors can make more accurate authentication decisions according to different environments and behavior risks, achieving a highly secure and efficient authentication mechanism and significantly enhancing the flexibility and security of the authentication process.
[0022] Furthermore, by performing deployments based on fixed states and random states, including: determining fixed-state authentication features and random-state authentication features for the first authentication factor; constructing a first authentication block according to the fixed-state authentication features, constructing a second authentication block according to the random-state authentication features, coupling the first authentication block and the second authentication block, and deploying the first authentication engine node.
[0023] Specifically, first, based on the authenticated environment and risk situation, each authentication factor in the first authentication factor is judged to determine which authentication factors belong to the fixed state and which belong to the random state, and the fixed-state authentication features and random-state authentication features are determined. The first authentication factor is all available authentication factors. For example, taking the SMS verification code as an example, it is usually dynamic, so it belongs to the random-state authentication feature. On the contrary, a simple digital password authentication, usually with a fixed length and content that does not change over time, belongs to the fixed-state authentication feature. In the design, the fixed-state features such as the number of characters in the password and the type of password composition, such as numbers, letters, etc. are predefined, while the random-state features such as the dynamically generated verification code will change dynamically according to the risk assessment. After determining the fixed-state and random-state authentication features, two authentication blocks are respectively constructed according to the type of authentication factors. The first authentication block is constructed according to the fixed-state authentication features, and the first authentication block is responsible for processing the fixed-state authentication features. The second authentication block is constructed according to the random-state authentication features, and the second authentication block is responsible for processing the random-state authentication features. And the first authentication block and the second authentication block are coupled to establish a dynamic balance between the first block and the second block, so that the decision-making can flexibly adjust the authentication method according to the environmental risk to ensure the integrity of the authentication process. After completing the design and coupling of the authentication block, the first authentication engine node is deployed into the authentication decision-making method, which is responsible for executing the authentication task, can dynamically select the authentication block according to the actual situation, and verify according to the authentication features. By introducing the combination of fixed-state and random-state authentication features, it is possible to select an appropriate authentication method in different risk environments, improve the flexibility of the authentication strategy, and ensure the security of authentication.
[0024] Further, coupling the first authentication block and the second authentication block includes: taking the zero-trust environment as a benchmark to determine the first coupling ratio; taking the trusted environment as a benchmark to determine the second coupling ratio; setting a multi-level coupling relaxation degree for the multi-level trust nodes from the zero-trust environment to the trusted environment with the first coupling ratio and the second coupling ratio as boundaries, where the coupling relaxation degree is determined by balancing the fixed state and the random state; determining the coupling method of the first authentication factor with the first coupling ratio, the multi-level coupling relaxation degree, and the second coupling ratio.
[0025] Specifically, the calculation of the coupling ratio is dynamically adjusted according to the trust level of the current authentication environment. First, the zero-trust environment is taken as the benchmark. In the zero-trust environment, there is no default trust, that is, each request needs to be strictly verified. In this environment, the requirements for authentication factors are very high, and it is necessary to ensure that all possible authentication factors are fully verified. At this time, the first coupling ratio between the first authentication block and the second authentication block is determined. The first coupling ratio represents the degree of combination of fixed-state and random-state authentication factors in the zero-trust environment, and is a quantitative indicator of the security assessment result of the environment, which helps to define the strictness of the authentication policy in this environment. The first coupling ratio adopts a combination of higher fixed-state authentication features and random-state authentication features. Then, in the trusted environment, the second coupling ratio between the first authentication block and the second authentication block is determined. The second coupling ratio represents the degree of combination of fixed-state and random-state authentication factors in the trusted environment. In the trusted environment, the trust level is relatively high, and fewer random-state authentication features may be required. For example, if an employee logs in using a fixed device on the company's internal network, the company may only require the employee to enter the username and password (fixed-state authentication features) without requiring the input of a SMS verification code or dynamic token (random-state authentication features). Therefore, the second coupling ratio is relatively low, indicating a relatively high trust in the device and the environment.
[0026] After determining the first coupling ratio and the second coupling ratio, according to the defined boundaries of these two ratios, multi-level trust nodes are set, and multi-level coupling relaxation degrees are set. The defined boundary means that by setting the first coupling ratio and the second coupling ratio, the usage scope and application ratio of authentication factors in different trust environments are clarified. The role of the defined boundary is to ensure that the authentication strategy is neither too strict nor too loose during the transition from a zero-trust environment to a trust environment by delimiting the applicable scope and strength of fixed-state authentication factors and random-state authentication factors in the authentication process, so as to achieve the goal of balancing security and user experience. The multi-level trust nodes represent multiple stages from a zero-trust environment to a trust environment. Each stage has different trust levels and authentication requirements. For example, the initial stage may be in a zero-trust environment and requires strict authentication. As the trust level gradually increases, the authentication intensity can be reduced and gradually transition to a trust environment. The coupling relaxation degree refers to the flexibility and looseness of the authentication process during the transition from a zero-trust environment to a trust environment. When the relaxation degree is higher, more dynamic factors can be allowed to make authentication decisions. When the relaxation degree is lower, the authentication process will be more strict. By adjusting the coupling relaxation degree, the use of fixed-state authentication features and random-state authentication features in the authentication process can be balanced. For example, when a user tries to log in to the company system from an external network of the company, the system first requires multi-factor authentication, such as a combination of password and SMS verification code. However, once the user's environmental trust level gradually increases, such as when the user frequently logs in from company devices, the system can gradually reduce the coupling relaxation degree and reduce the dependence on random-state authentication features. Furthermore, based on the first coupling ratio, the second coupling ratio combined with the multi-level coupling relaxation degree, the coupling method of the first authentication factor is determined. The coupling method is used to determine the application ratio of fixed-state and random-state authentication factors in each authentication link and dynamically select different authentication strategies. For example, in a zero-trust environment, the first coupling ratio will be higher, and both fixed-state authentication factors and random-state authentication factors will frequently participate in the authentication process to ensure multi-level verification of each request. In a trust environment, the second coupling ratio is lower, and more reliance is placed on fixed-state authentication features. On this basis, the introduction of the multi-level coupling relaxation degree enables the authentication process to be flexibly adjusted as the trust environment changes. Optionally, the weighted average method is used to adjust the first and second coupling ratios according to the environmental trust level. For example, assume that a higher combination of authentication factors is required in a zero-trust environment, and a lower combination is required in a trust environment. The calculation formula for the coupling ratio can be as follows: coupling ratio = α × weight of fixed-state factor + (1 - α) × weight of random-state factor, where α represents a coefficient that changes dynamically according to the environmental trust level (ranging from 0 to 1). In a zero-trust environment, α is close to 1, and in a trust environment, it is close to 0. Through the comparison between the zero-trust environment and the trust environment, as well as the settings of the coupling ratio and the relaxation degree, a mechanism for dynamically adjusting the authentication strategy is provided, which can achieve the selection of appropriate authentication strategies according to different security requirements and improve the security and efficiency of authentication.
[0027] Based on the authentication ecosystem, perform a first authentication according to the initial environmental trust level to determine a first authentication profile, where the first authentication profile is determined based on environmental risks, user risks, and authentication information.
[0028] Specifically, based on the authentication ecosystem deployed on the information platform, perform a first authentication on the initial environmental trust level of the current authentication environment. The initial environmental trust level is evaluated based on factors such as the user's behavior pattern, device security, network reliability, geographical location, etc. Optionally, set a scoring standard for each factor, and based on expert experience or historical data, assign a weight to each factor according to the degree of influence of each factor on environmental trust. The weights sum up to 1. Multiply the score of each factor by its weight, and then sum the weighted scores to obtain the comprehensive environmental trust level score. A high environmental trust level indicates that the system considers the current environment to be safe, while a low environmental trust level indicates that there may be risks or anomalies in the environment. For example, based on factors such as whether the device is a known device and whether the operating system is updated, the device trust level score is 10 points. Based on the security of the current network, the network trust level score is 8 points. By comparing the user's current geographical location with their usual login location, the geographical location score is 9 points. Analyze the user's login behavior to obtain a behavior trust level score of 9 points, and assign weights to multiple factors: device trust level weight: 0.4, network trust level weight: 0.3, geographical location weight: 0.2, behavior trust level weight: 0.1. Calculate the final environmental trust level: Environmental trust level = (0.4×10) + (0.3×8) + (0.2×9) + (0.1×9) = 9.1 points, indicating that the current authentication environment is very trustworthy. Furthermore, through the analysis of environmental trust level, environmental risks, user risks, and authentication information, generate the first authentication profile using a weighted scoring or fuzzy logic algorithm. The first authentication profile reflects the user's current authentication status, and the authentication profile will be updated in real time according to the user's behavior and environmental changes, thus ensuring that the authentication process always maintains the latest security state. By evaluating the environment and user risks in real time and intelligently, it is possible to optimize the flexibility of the authentication process while maintaining high security and avoid overly interfering with the user experience.
[0029] Taking the first authentication profile as the baseline, track the user operation chain. By performing up and down dynamic perception evaluation based on the nodes of the operation chain, trigger the automated orchestration engine to generate an authentication response pop-up window, iterate and update the first authentication profile according to the authentication result, and generate a dynamic risk sequence based on the user operation chain, where user operation permission management is carried out by introducing dynamic permission constraints.
[0030] Specifically, taking the first authentication image as a benchmark, the subsequent operation chain of the user is traced. The operation chain nodes refer to each specific action or behavior of the user during the operation process, such as logging in, accessing an application, submitting sensitive data, etc. Different risks may exist at each node. By monitoring the user's behavior, collecting information about the operations, analyzing these nodes, evaluating the upper and lower dynamic risks of the user's operations, and adjusting the authentication strategy according to the changes in risks. The upper and lower dynamic perception assessment based on the operation chain nodes refers to risk assessment based on real-time monitoring of the user's behavior patterns and combined with environmental changes, and real-time understanding of the risk status of the user's operations.
[0031] When potential risks are found in the user's operations according to the upper and lower dynamic perception assessment, the automated orchestration engine is triggered to generate an authentication response pop-up window. For example, when the user logs in from an uncommon device or location, or attempts to access sensitive data, the automated orchestration engine will be triggered to automatically generate an authentication response pop-up window, requiring the user to perform additional authentication steps, such as entering a verification code, performing face recognition, etc. According to the user's authentication results, the first authentication image will be iteratively updated, incorporating the new risk assessment results into the authentication image to make more accurate security decisions for the user's subsequent behaviors, thus ensuring the security of the authentication process. By evaluating each node in the user's operation chain, a dynamic risk sequence is generated. The dynamic risk sequence reflects the risk changes experienced by the user during the entire authentication process, helping to accurately judge the user's security status. For example, under normal circumstances, the risk of the user's operation chain is relatively low, but if the user's behavior is abnormal, the authentication strategy can be adjusted in a timely manner to prevent potential security threats. During the authentication process, the dynamic permission constraint will adjust the user's operation permissions in real time according to the user's operation behavior and risk assessment results. For example, if the user's operation risk is relatively high, the user's access to certain sensitive resources can be restricted, or further authentication can be required to ensure the security of the operation permissions. Through this method, while ensuring the user experience, the authentication security can be strengthened, and the authentication process can be automatically adjusted according to the risks, thus achieving a good balance between security and user experience.
[0032] Furthermore, by performing the upper and lower dynamic perception assessment based on the operation chain nodes, triggering the automated orchestration engine to generate an authentication response pop-up window includes: tracing the user operation chain, positioning the lower-level operation nodes according to the trend change of the operation environment and the trend change of the operation mechanism; based on the upper-level operation node and the lower-level operation node, conducting a risk assessment to determine the assessment result, where the upper-level operation node is the previous authentication node; and performing authentication trigger management according to the assessment result.
[0033] Specifically, first, continuously track the user's operation chain and record the behavior of each user operation. Each node in the operation chain represents an operation performed by the user during the authentication process, which may include logging in, entering a password, selecting an authentication method, clicking an authentication button, etc. As the user's operations proceed, monitor changes in the operation environment and operation mechanism. Changes in the operation environment include devices, network status, geographical location, etc., and changes in the operation mechanism include changes in the user authentication method. By real-time monitoring of the operation chain, locate the user's next operation step, that is, the lower-level operation node. The lower-level operation node is an action that the user is about to perform during the authentication process, which may be accessing sensitive resources or submitting an authentication request, etc. Then, conduct a risk-oriented assessment based on the upper-level operation node and the lower-level operation node in the user operation process. The upper-level operation node refers to an operation performed by the user in the current authentication process, such as the previous authentication or operation behavior; the lower-level operation node is an operation or behavior that the user is about to perform, such as accessing sensitive data or submitting a request. By comparing the environmental / behavior changes of the upper and lower nodes, determine whether there is a risk deviation in the operation chain and obtain the evaluation result, where the evaluation result refers to the risk assessment result. Furthermore, based on the result of the risk-oriented assessment, decide whether to trigger an authentication response through an automated orchestration engine for authentication trigger management. If the evaluation result indicates a relatively high risk, a user will be required to perform additional authentication steps, such as entering a verification code, biometric identification, or other authentication methods, through an authentication response pop-up window. These additional steps will be dynamically adjusted according to the user's operation behavior and authentication environment to ensure the security of the authentication process. Through dynamic perception of the upper and lower levels and risk assessment based on operation chain nodes, it is possible to real-time monitor and evaluate the risks in the authentication process. Based on the risk assessment, it is possible to intelligently decide whether to enable additional authentication measures such as multi-factor authentication and verification codes, and achieve dynamic control of user operations, thereby ensuring authentication security.
[0034] Furthermore, the evaluation result is a risk reduction or risk increase; according to the evaluation result, determine a risk trend change vector, and guided by the risk trend change vector, make a trigger decision and an authentication decision for the automated orchestration engine.
[0035] Specifically, according to the upper operation node and the lower operation node of the user operation chain, the evaluation result of the user operation risk is obtained in real time. The evaluation result refers to the judgment result for judging the change direction of the risk in the current user authentication process, including the risk decreasing direction or the risk increasing direction. The risk decreasing direction indicates that the risk in the authentication process decreases, indicating that the user is in a safer environment or behavior pattern, while the risk increasing direction indicates that the risk increases, indicating that there are unsafe changes in the user's behavior or environment. After obtaining the evaluation result, the risk change vector is calculated. The risk change vector reflects the direction and degree of risk change, quantifies the trend of risk change in the authentication process, and provides a basis for dynamically adjusting the authentication strategy. If the risk decreasing direction is large, the change vector will indicate a risk reduction and suggest that the authentication process can be moderately simplified. If the risk is reduced enough, authentication may not be required. If the evaluation result is the risk increasing direction, the change vector will indicate a risk increase, and more stringent authentication measures will be taken to cope with these changes. Decisions on the combination of authentication factors and specific authentication information will be made according to different change scales and operation states. Furthermore, under the guidance of the risk change vector, the automated orchestration engine automatically makes trigger decisions and authentication decisions based on the risk situation. For example, when a user logs in, after multiple authentications, the trust level of the device increases, the login behavior pattern is normal, and the environment is relatively safe (such as the company's internal network). In this case, the evaluated risk decreases and a risk change vector is generated, indicating a significant reduction in risk. The automated orchestration engine may decide, based on the evaluation result, that there is no need to enter the verification code again and only a simple password verification is required, thus simplifying the authentication process. Through the dynamic adjustment of the risk change vector, it is possible to optimize or increase the authentication process in real time according to changes in the environment and user behavior, achieve real-time monitoring and adaptive adjustment, as well as dynamic control of user operations, improving the user experience while ensuring security.
[0036] Further, making the trigger decision and authentication decision of the automated orchestration engine includes: if the automated orchestration engine is triggered, making a collaborative decision based on authentication factors and a coupled decision based on the fixed state and random state to determine the authentication information; and generating the authentication response pop-up window according to the authentication information.
[0037] Specifically, when potential risks are detected based on dynamic risk assessment or user behavior, the automated orchestration engine is triggered. The automated orchestration engine makes collaborative decisions according to real-time authentication requirements and authentication factors that change with the environment, combining fixed-state and random-state coupling decisions, and finally determines the required authentication information, which refers to the specific authentication methods used by users during the authentication process. Finally, an authentication response pop-up window is generated based on the authentication information to prompt the user to perform the authentication operation. The authentication response pop-up window is a system interface where users input or confirm authentication information. According to user behavior and the authentication environment, the user is prompted to perform certain authentication operations through the pop-up window, such as entering a verification code, performing fingerprint recognition, or other authentication information. Through the automated orchestration engine, the user experience can be optimized while ensuring security. In the case of low risks, the authentication process is simplified to avoid unnecessary authentication steps, while in the case of high risks, more stringent authentication measures are taken to ensure high security through multi-factor authentication.
[0038] Furthermore, user operation permission management is carried out by introducing dynamic permission constraints, including: introducing dynamic permission constraints; determining the user permissions of the user at the first operation node; adjusting the user permissions according to the first authentication profile to determine the first dynamic user permissions; and performing user permission constraints according to the first dynamic user permissions.
[0039] Specifically, during the authentication process, the user's operation permissions are dynamically adjusted according to the real-time environment, user behavior, and authentication status. That is, by introducing dynamic permission constraints, the access resources and operations that the user can perform can be flexibly controlled based on the user's authentication status and risk assessment. During the authentication process, the user's permissions at the first operation node are determined. The first operation node may be when the user enters a password, submits an authentication request, or performs other preliminary operations. Based on factors such as the user's input information, device environment, and geographical location, preliminary operation permissions are assigned to the user. For example, when the user logs in on the company network, after successful login, the user is granted some basic permissions, such as viewing personal files and accessing common applications. At this time, the user's permissions are preliminary permissions based on a normal environment and behavior. Then, through the first authentication portrait, that is, the preliminary evaluation result of the user during the authentication process, the user's permissions are adjusted to determine the first dynamic user permissions. The first dynamic user permissions refer to the evaluation result based on the first authentication portrait. According to the user's status and risk during the authentication process, the user's permissions are dynamically adjusted. The first dynamic user permissions are a dynamic permission based on real-time risk, reflecting the security of the user's current authentication status. For example, if after the user logs in, the authentication portrait shows a high environmental trust level and normal behavior, the user can be granted permission to access more resources, such as accessing shared files or modifying configuration settings. If the user's authentication portrait shows that there are risks in the authentication information, such as using an uncommon device, the user's permissions may be restricted to avoid accessing sensitive information. Finally, the user's operation permissions are restricted based on the first dynamic user permissions. Through user permission constraints, it can be ensured that in a high-risk environment, the user can only perform operations that have been strictly verified, reducing potential security threats. Through refined dynamic permission constraints based on real-time risk assessment, the user's permissions can be dynamically adjusted according to the risk situation of user authentication, realizing dynamic control of user operations, thereby effectively reducing potential security threats and ensuring secure access to resources.
[0040] Further, the method further includes restoring the first dynamic user permissions when entering the lower-level operation node.
[0041] Specifically, during the authentication process, the authentication process is traced based on the user's operation behavior, and each operation node is clarified. The lower-level operation node refers to the user's next operation step. For example, if the user completes the login step, the next step may be to enter the verification code or perform secondary authentication. The lower-level operation node is determined by judging the position of the current authentication step. Before entering the lower-level operation node, the user's current permission status is evaluated. This status is generated based on the user's performance in the previous operation node, authentication risk assessment, and authentication portrait. The first dynamic user permission is adjusted according to these factors. When the user enters the lower-level operation node, the user's authentication status is evaluated again. If there are no new risks in the user's operation behavior or environment, a restoration operation will be performed, that is, the first dynamic user permission of the user will be restored to make the permission return to a normal and secure state. By monitoring the lower-level operation node, it is determined whether to perform permission restoration. If the user's authentication environment becomes more trustworthy, for example, the user passes biometric authentication or the device status is normal, the user's permission is restored. If it is detected that the risk is still relatively high, for example, the user behaves abnormally during multiple authentications, the restriction on the user's permission may continue to be maintained. By monitoring each node in the user operation chain, the permission can be flexibly adjusted according to the user's actual operation situation, realizing the dynamic control of the user's operation, ensuring that the user enjoys full permissions in a safe environment and is subject to appropriate permission restrictions in a high-risk environment, thereby optimizing the user experience while ensuring security.
[0042] Embodiment 2, based on the same inventive concept as the dynamic risk assessment method in the multi-factor authentication process in the foregoing embodiment, as Figure 2 shown, the present application provides a dynamic risk assessment system in the multi-factor authentication process, wherein the system includes:
[0043] An authentication ecosystem construction module 11, configured to use upper and lower position perception as a dynamic risk assessment method and an automated orchestration engine as an authentication decision-making method according to environmental trust and the multi-factor authentication mode, construct an authentication ecosystem and deploy it on an information platform, wherein the multi-factor authentication mode is determined based on the coupling of a fixed state and a random state; an authentication portrait determination module 12, configured to perform primary authentication based on the authentication ecosystem according to the initial environmental trust degree to determine a first authentication portrait, wherein the first authentication portrait is determined based on environmental risk, user risk, and authentication information; a dynamic risk sequence generation module 13, configured to use the first authentication portrait as a baseline, trace the user operation chain, trigger the automated orchestration engine to generate an authentication response pop-up window through upper and lower position dynamic perception evaluation based on the operation chain nodes, iteratively update the first authentication portrait according to the authentication result, and generate a dynamic risk sequence based on the user operation chain, wherein user operation permission management is performed by introducing dynamic permission constraints.
[0044] Further, the authentication ecosystem construction module 11 is further configured to perform the following steps: traverse multiple authentication factors, determine multiple authentication engine nodes by performing deployment based on the fixed state and the random state; use the coupled decision based on the fixed state and the random state as the first-order training objective, and use the collaborative decision among multiple authentication factors as the second-order training objective, perform data-driven training on the multiple authentication engine nodes, and determine the automated orchestration engine.
[0045] Further, the authentication ecosystem construction module 11 is further configured to perform the following steps: for the first authentication factor, determine the fixed-state authentication feature and the random-state authentication feature; construct the first authentication block according to the fixed-state authentication feature, construct the second authentication block according to the random-state authentication feature, couple the first authentication block and the second authentication block, and deploy the first authentication engine node.
[0046] Further, the authentication ecosystem construction module 11 is further configured to perform the following steps: use the zero-trust environment as a benchmark to determine the first coupling ratio; use the trusted environment as a benchmark to determine the second coupling ratio; use the first coupling ratio and the second coupling ratio to define the boundary, set multi-level coupling relaxation degrees for the multi-level trusted nodes from the zero-trust environment to the trusted environment, where the coupling relaxation degree is determined by balancing the fixed state and the random state; use the first coupling ratio, the multi-level coupling relaxation degrees, and the second coupling ratio to determine the coupling method of the first authentication factor.
[0047] Further, the dynamic risk sequence generation module 13 is further configured to perform the following steps: track the user operation chain, locate the lower-level operation node based on the change of the operation environment and the change of the operation mechanism; perform risk assessment based on the upper-level operation node and the lower-level operation node to determine the assessment result, where the upper-level operation node is the previous authentication node; perform authentication trigger management according to the assessment result.
[0048] Further, the dynamic risk sequence generation module 13 is further configured to perform the following steps: the assessment result is a risk decrease or a risk increase; according to the assessment result, determine the risk change vector, and use the risk change vector as a guide to perform the trigger decision and authentication decision of the automated orchestration engine.
[0049] Further, the dynamic risk sequence generation module 13 is further configured to perform the following steps: if the automated orchestration engine is triggered, perform collaborative decision based on authentication factors and coupled decision based on the fixed state and the random state to determine the authentication information; generate the authentication response pop-up window according to the authentication information.
[0050] Further, the dynamic risk sequence generation module 13 is further configured to perform the following steps: introduce dynamic permission constraints; determine the user permissions at the first operation node; adjust the user permissions according to the first authentication portrait to determine the first dynamic user permissions; and perform user permission constraints according to the first dynamic user permissions.
[0051] Further, the dynamic risk sequence generation module 13 is further configured to perform the following steps: when entering the lower-level operation node, restore the first dynamic user permissions.
[0052] The foregoing are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
[0053] This specification and the drawings are only exemplary descriptions of the present application and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and deformations to the present application without departing from the scope of the present application. Thus, if these modifications and deformations of the present application fall within the scope of the present application and its equivalent technologies, the present application is intended to include these changes and deformations.
Claims
1. A method for dynamic risk assessment in a multi-factor authentication process, characterized in that, The method includes: Based on the environmental trust and multi-factor authentication mode, taking the upper and lower position perception as a dynamic risk assessment method and the automated orchestration engine as an authentication decision-making method, constructing an authentication ecosystem and deploying it on the information platform, wherein the multi-factor authentication mode is determined based on the coupling of the fixed state and the random state; Based on the authentication ecosystem, perform a first authentication according to the initial environmental trust degree to determine a first authentication portrait, wherein the first authentication portrait is determined based on environmental risks, user risks, and authentication information; Using the first authentication portrait as a baseline, track the user operation chain, trigger the automated orchestration engine to generate an authentication response pop-up window through the upper and lower position dynamic perception evaluation based on the operation chain nodes, iteratively update the first authentication portrait according to the authentication results, and generate a dynamic risk sequence based on the user operation chain, wherein user operation permission management is performed by introducing dynamic permission constraints.
2. The dynamic risk assessment method in the multi-factor authentication process according to claim 1, wherein Taking the automated orchestration engine as an authentication decision-making method includes: Traverse multiple authentication factors, and determine multiple authentication engine nodes by performing deployments based on the fixed state and the random state; Taking the coupling decision based on the fixed state and the random state as the first-order training objective and the collaborative decision among multiple authentication factors as the second-order training objective, perform data-driven training on the multiple authentication engine nodes to determine the automated orchestration engine.
3. The dynamic risk assessment method in the multi-factor authentication process according to claim 2, characterized in that, Determining multiple authentication engine nodes by performing deployments based on the fixed state and the random state includes: For the first authentication factor, determine the fixed-state authentication feature and the random-state authentication feature; Construct a first authentication block according to the fixed-state authentication feature, construct a second authentication block according to the random-state authentication feature, couple the first authentication block and the second authentication block, and deploy the first authentication engine node.
4. The dynamic risk assessment method in the multi-factor authentication process according to claim 3, characterized in that Coupling the first authentication block and the second authentication block includes: Taking the zero-trust environment as a benchmark, determine the first coupling ratio; Taking the trusted environment as a benchmark, determine the second coupling ratio; Taking the first coupling ratio and the second coupling ratio as boundaries, set multi-level coupling relaxation degrees for multi-level trust nodes from the zero-trust environment to the trusted environment, wherein the coupling relaxation degree is determined by balancing the fixed state and the random state; Determine the coupling method of the first authentication factor based on the first coupling ratio, the multi-level coupling relaxation degree, and the second coupling ratio.
5. The dynamic risk assessment method in the multi-factor authentication process according to claim 1, wherein Triggering the automated orchestration engine to generate an authentication response pop-up window through the upper and lower position dynamic perception evaluation based on the operation chain nodes includes: Track the user operation chain, and locate the lower-level operation nodes based on the changes in the operation environment and the operation mechanism; Based on the upper-level operation node and the lower-level operation node, perform a risk upward assessment to determine the assessment result, wherein the upper-level operation node is the previous authentication node; According to the assessment result, perform authentication trigger management.
6. The dynamic risk assessment method in the multi-factor authentication process according to claim 5, wherein, The assessment result is a risk downward or a risk upward; According to the assessment result, determine the risk change vector, and use the risk change vector as a guide to perform the trigger decision and authentication decision of the automated orchestration engine.
7. The dynamic risk assessment method in the multi-factor authentication process according to claim 6, wherein Performing the trigger decision and authentication decision of the automated orchestration engine includes: If the automated orchestration engine is triggered, collaborative decision-making based on authentication factors and coupled decision-making based on fixed and random states are performed to determine authentication information; Based on the authentication information, the authentication response pop-up window is generated.
8. The dynamic risk assessment method in the multi-factor authentication process according to claim 1, characterized in that User operation permission management is performed by introducing dynamic permission constraints, including: Introduce dynamic permission constraints; Determine the user permissions at the first operation node; According to the first authentication profile, adjust the user permissions to determine the first dynamic user permissions; According to the first dynamic user permissions, perform user permission constraints.
9. The dynamic risk assessment method in the multi-factor authentication process according to claim 8, wherein When entering the lower-level operation node, restore the first dynamic user permissions.
10. A dynamic risk assessment system in a multi-factor authentication process, characterized in that, Steps for implementing the dynamic risk assessment method in the multi-factor authentication process according to any one of claims 1 to 9, including: An authentication ecosystem construction module, configured to use the upper and lower level perception as a dynamic risk assessment method and the automated orchestration engine as an authentication decision-making method according to environmental trust and multi-factor authentication mode, construct an authentication ecosystem and deploy it on the information platform, wherein the multi-factor authentication mode is determined based on the coupling of fixed and random states; An authentication profile determination module, configured to perform a first authentication based on the initial environmental trust degree based on the authentication ecosystem, and determine a first authentication profile, wherein the first authentication profile is determined based on environmental risk, user risk, and authentication information; A dynamic risk sequence generation module, configured to use the first authentication profile as a baseline, track the user operation chain, trigger the automated orchestration engine to generate an authentication response pop-up window through the upper and lower level dynamic perception evaluation based on the operation chain nodes, iteratively update the first authentication profile according to the authentication results, and generate a dynamic risk sequence based on the user operation chain, wherein user operation permission management is performed by introducing dynamic permission constraints.
Citation Information
Cited By
Invoice automatic registration system and method based on multi-factor authentication
CN121258718A