Mobile application security access method based on randomness

A dynamic risk assessment system using deep learning and real-time threat intelligence adapts security challenges based on risk levels, addressing the inefficiencies of uniform verification in mobile applications, enhancing security and user satisfaction.

CN120320979AInactive Publication Date: 2025-07-15STATE GRID HENAN INFORMATION & TELECOMM CO
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510382256.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing random inquiry mechanism has excessive verification during low-risk operations in mobile applications, resulting in waste of resources and loss of users. It is difficult to dynamically adjust the complexity of the inquiry to adapt to different risk scenarios.

Method used

The user identity, operation type and context information are evaluated through deep learning algorithms, combined with real-time security threat intelligence, dynamic response encoding characteristics are generated, the query complexity is dynamically adjusted, and random questions are generated and sent to match the risk level.

Benefits of technology

It realizes the quantification of risks in millisecond time, optimizes the balance between security protection and user experience, dynamically adjusts the complexity of the question to adapt to different risk scenarios, and improves the security and user experience of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120320979A_ABST
    Figure CN120320979A_ABST
Patent Text Reader

Abstract

The invention provides a mobile application security access method based on randomness, and relates to the field of mobile application security, and the method comprises the steps: firstly, sending request information to a server through a client, and then carrying out the risk assessment of the request information through the server by using a deep learning algorithm, including the extraction of a user identity, an operation type and context information; and in combination with real-time security threat intelligence, dynamic response coding characteristics are generated by utilizing structured and semantic coding technologies, and the risk level of the request is calculated, so that the challenge complexity is dynamically adjusted, and random challenges are generated and sent to the client. And after the client responds, the server verifies the correctness so as to decide whether to continue service processing or deny access. Thus, risks can be quantified within milliseconds, the delay and stiffness problems of a traditional static strategy are solved, and efficient safety protection and good user experience balance are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of mobile application security, and more particularly, to a mobile application security access method based on randomness in the embodiments of this application. Background Art

[0002] As the business scenarios carried by mobile applications become increasingly complex, a security access mechanism is required to protect operations ranging from basic information browsing to sensitive operations involving fund transfers and biometric invocations. Due to its dynamic defense characteristics, randomness-based security verification technology has gradually become the core means to address new types of attacks such as identity forgery and session hijacking. Its core value lies in generating non-reproducible challenge information in each session, breaking the predictability defects of traditional fixed verification codes and static passwords. Especially for replay attack scenarios, the one-time feature of random challenges can effectively block secondary penetration by attackers intercepting verification data.

[0003] However, existing random challenge mechanisms mostly adopt a design paradigm with a constant complexity. This "one-size-fits-all" security strategy has led to significant contradictions in actual operation: when users perform low-risk operations (such as viewing news), the system still forces them to complete high-intensity verification involving multi-factor authentication, which not only wastes computing resources but also increases the user churn rate due to frequent interruptive verifications. On the contrary, when processing high-risk transaction requests (such as large transfers), some systems still use basic digital verification codes, enabling attackers to attempt brute-force cracking tens of thousands of times in a short period through automated scripts, posing a great threat to users' financial security.

[0004] Therefore, an optimized mobile application security access solution based on randomness is desired. Summary of the Invention

[0005] To solve the above technical problems, this application is proposed. The embodiments of this application provide a mobile application security access method based on randomness. First, the client sends a request message to the server, and then the server uses a deep learning algorithm to perform a risk assessment on the request message, including extracting user identity, operation type, and context information, and combining real-time security threat intelligence. Using structured and semantic coding techniques, dynamic response coding features are generated, and the risk level of the request is calculated to dynamically adjust the challenge complexity, generate, and send a random challenge to the client. After the client responds, the server verifies its correctness to decide whether to continue business processing or deny access. In this way, risks can be quantified within milliseconds, overcoming the latency and rigidity problems of traditional static strategies, and achieving a balance between efficient security protection and a good user experience.

[0006] According to one aspect of this application, a mobile application security access method based on randomness is provided, which includes:

[0007] The client sends request information to the application server;

[0008] The application server conducts a risk assessment on the request information to obtain a request risk assessment result, including: obtaining real-time security threat intelligence; performing real-time dynamic response encoding based on the request and the real-time security threat intelligence to obtain a request-security intelligence real-time dynamic response encoding feature; and obtaining the request risk assessment result based on the request-security intelligence real-time dynamic response encoding feature;

[0009] The application server dynamically selects a challenge complexity level based on the request risk assessment result;

[0010] The application server generates a random challenge that matches the complexity level based on the determined challenge complexity level and sends the random challenge to the client;

[0011] The client responds to the random challenge and sends response information to the application server;

[0012] The application server conducts a response verification on the response information. If the verification is successful, it performs business processing and access control based on the request information. If the verification fails, it rejects the access and issues a security alert.

[0013] Compared with the prior art, a randomness-based mobile application security access method provided by the present application first sends request information from the client to the server, and then the server uses a deep learning algorithm to conduct a risk assessment on the request information, including extracting user identity, operation type, and context information, and combining real-time security threat intelligence, using structured and semantic encoding technologies to generate dynamic response encoding features, and calculating the risk level of the request, so as to dynamically adjust the challenge complexity accordingly, generate and send a random challenge to the client. After the client responds, the server verifies its correctness to decide whether to continue business processing or reject access. In this way, the risk can be quantified within milliseconds, overcoming the latency and rigidity problems of traditional static policies, and achieving a balance between efficient security protection and good user experience. Description of the Drawings

[0014] By describing the embodiments of the present application in more detail in combination with the drawings, the above and other purposes, features, and advantages of the present application will become more obvious. The drawings are used to provide a further understanding of the embodiments of the present application, and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation to the present application. In the drawings, the same reference numerals generally represent the same components or steps.

[0015] Figure 1Flowchart of a randomness-based mobile application security access method according to an embodiment of the present application.

[0016] Figure 2 Flowchart of the application server in the randomness-based mobile application security access method according to an embodiment of the present application for risk assessment of the request information to obtain a request risk assessment result.

[0017] Figure 3 Schematic diagram of data flow of the application server in the randomness-based mobile application security access method according to an embodiment of the present application for risk assessment of the request information to obtain a request risk assessment result.

[0018] Figure 4 Flowchart of performing request-security intelligence real-time dynamic response encoding on the request information and the real-time security threat intelligence in the randomness-based mobile application security access method according to an embodiment of the present application to obtain request-security intelligence real-time dynamic response encoding features.

[0019] Figure 5 Flowchart of performing request-security intelligence real-time soft constraint-driven dynamic response analysis on the structured encoding vector of the request basic information and the semantic encoding vector of the real-time security threat intelligence in the randomness-based mobile application security access method according to an embodiment of the present application to obtain a request-security intelligence real-time dynamic response encoding vector.

[0020] Figure 6 Flowchart of performing soft constraint factor weighted dynamic adaptive aggregation on the set of the structured encoding vector of the request basic information and the semantic principal component linear transformation encoding vector of the real-time security threat intelligence in the randomness-based mobile application security access method according to an embodiment of the present application to obtain the request-security intelligence real-time dynamic response encoding vector. Detailed implementation manners

[0021] Various exemplary embodiments, features, and aspects of the present application will be described in detail below with reference to the accompanying drawings. The same reference numerals in the drawings denote elements with the same or similar functions. Although various aspects of the embodiments are shown in the drawings, the drawings do not have to be drawn to scale unless otherwise specified.

[0022] With the complexity of mobile application business scenarios, the security access mechanism becomes particularly important, especially for sensitive operations involving fund transfer and biometric invocation. The random security verification technology, due to its dynamic defense characteristics, has become a key means to prevent identity forgery and session hijacking. By generating non-reproducible challenge information for each session, it effectively resists replay attacks. However, the current random challenge mechanism generally adopts a constant complexity design, resulting in over-verification during low-risk operations, causing resource waste and user loss; while in high-risk transactions, users may face financial security threats due to the use of simple digital verification codes. This "one-size-fits-all" security strategy shows significant contradictions in actual operation and requires more flexible and hierarchical security measures to balance user experience and security.

[0023] Based on this, the present application proposes a randomness-based mobile application security access method, which constructs an adaptive security verification system through a design architecture that links dynamic risk assessment with random challenge complexity, to protect users' sensitive information and property security.

[0024] The present application proposes a randomness-based mobile application security access method. Figure 1 The flowchart of the randomness-based mobile application security access method according to an embodiment of the present application is as follows. Figure 1 As shown, the randomness-based mobile application security access method according to an embodiment of the present application includes: S110, the client sends request information to the application server; S120, the application server performs a risk assessment on the request information to obtain a request risk assessment result; S130, the application server dynamically selects a challenge complexity level based on the request risk assessment result; S140, the application server generates a random challenge matching the complexity level based on the determined challenge complexity level and sends the random challenge to the client; S150, the client responds to the random challenge and sends response information to the application server; S160, the application server performs a response verification on the response information. If the verification is successful, it performs business processing and access control based on the request information. If the verification fails, it rejects the access and issues a security warning.

[0025] In the above-mentioned randomness-based mobile application security access method, in step S110, the client sends request information to the application server. It should be understood that the request information generated by the client mainly stems from the user's operation behavior on the mobile application. When using the mobile application, users have various needs, such as viewing news, making fund transfers, and invoking biometric unlocking functions. These operations will trigger the client to generate corresponding request information. For example, when a user wants to view a newly released news article, the client will generate a request containing relevant information such as the news page identifier and the user identity identifier based on the user's click on the news link, so as to obtain the corresponding news content data from the application server. Technically speaking, as the front-end for user-application interaction, the client itself does not have the ability to store and process all data and must rely on the powerful computing and storage resources of the application server to meet user needs. Therefore, it is necessary to send the request to the server, so that the user's intentions and needs can be conveyed to the server, enabling the server to clarify the specific operations the user wants to perform.

[0026] In the above-mentioned randomness-based mobile application security access method, in step S120, the application server conducts a risk assessment on the request information to obtain a request risk assessment result. It should be understood that as the business scenarios of mobile applications become increasingly complex, the types of security threats faced are numerous and constantly changing. Different user requests may pose different levels of risk. For example, a simple news viewing request has a relatively low risk level; while requests involving fund transfers, access to sensitive information, or biometric invocations, if maliciously exploited, may lead to serious consequences such as user information leakage and financial losses. In addition, attackers may disguise normal requests through various means and attempt to bypass security mechanisms for illegal operations. Therefore, the application server needs to conduct a risk assessment on each received request information to identify potential risks and distinguish normal requests from abnormal requests. However, due to the lack of the ability to quantify risks in the request context, traditional random challenge mechanisms often adopt a unified security strength standard, resulting in both over-verification in low-risk scenarios and weak protection in high-risk scenarios. This lack of risk perception ability is essentially a direct manifestation of the inability of static security policies to adapt to the dynamic threat environment.

[0027] Based on this, the technical concept of this application is to use data analysis and coding algorithms based on deep learning to first extract user identity, operation type and context information from the request information, and simultaneously obtain real-time security threat intelligence, and then convert discrete user identity and operation type into computable vector representations through structured coding, and use semantic coding technology to perform deep feature extraction on unstructured context information. Subsequently, through the real-time dynamic response of request-security intelligence, a deep coupling analysis of the semantic features of the request features and the real-time threat intelligence is realized. Finally, based on the fused dynamic response coding features, an accurate risk level assessment result is output. This solution enables the system to dynamically perceive changes in threat situations and complete risk quantification within milliseconds of the user initiating the request, fundamentally solving the defects of traditional static strategies in risk perception hysteresis, rigid verification strength, etc., and achieving the optimal balance between security protection and user experience.

[0028] Figure 2 This is a flowchart of the application server performing risk assessment on the request information to obtain a request risk assessment result in the randomness-based mobile application security admission method according to an embodiment of the present application. Figure 3 The data flow diagram is a diagram showing that the application server performs risk assessment on the request information to obtain the request risk assessment result in the randomness-based mobile application security admission method according to the embodiment of the present application. Figure 2 and Figure 3 As shown, in an embodiment of the present application, the step S120 includes: S121, obtaining real-time security threat intelligence; S122, encoding the request information and the real-time security threat intelligence in real-time dynamic response based on the request-security situation to obtain the request-security intelligence real-time dynamic response coding feature; S123, obtaining the request risk assessment result based on the request-security intelligence real-time dynamic response coding feature.

[0029] Specifically, in step S121, real-time security threat intelligence is obtained. It should be understood that real-time security threat intelligence includes a data set that reflects the latest attack patterns, malicious IP address libraries, vulnerability exploitation trends, and other information in the current network environment. These data provide information on the possible behavior patterns and technical means used by attackers. To effectively defend against constantly evolving security threats, it is necessary to obtain and analyze security threat intelligence in a timely manner. Specifically, the acquisition of real-time security threat intelligence is a multi-dimensional process. First, the acquisition of real-time threat intelligence can be achieved by connecting to professional network security service providers. These service providers usually deploy monitoring networks globally and generate detailed threat intelligence reports after in-depth analysis by collecting data from all corners of the Internet, including but not limited to malware samples, botnet activities, phishing website lists, etc. In addition, updates can also be obtained by subscribing to public or private threat intelligence platforms. These platforms are often maintained by the cybersecurity community or professional institutions and provide information such as verified security incidents, vulnerability warnings, and the evolution of attack techniques to help users keep abreast of the latest security situation. In addition to relying on external resources, internal network logs and audit records are also important sources of threat intelligence. By regularly analyzing the log files of internal systems (such as firewall logs, intrusion detection system logs, application access logs, etc.), abnormal behavior patterns or potential security hazards can be discovered. For example, frequent failed login attempts from a specific IP address within a certain period, or a sudden surge in the volume of a certain type of request within a certain time period, may be signals of an attack. Combining the log data generated internally with the threat intelligence obtained externally helps to more comprehensively understand the current security challenges and formulate corresponding protection strategies.

[0030] Figure 4 A flowchart for obtaining the request-security intelligence real-time dynamic response coding feature by performing request-security intelligence real-time dynamic response coding on the request information and the real-time security threat intelligence in the mobile application security access method based on randomness according to an embodiment of the present application. As Figure 4As shown, in the embodiment of the present application, the step S122 of performing request-security intelligence real-time dynamic response encoding on the request information and the real-time security threat intelligence to obtain request-security intelligence real-time dynamic response encoding features includes: S1221, extracting the user identity identifier, request operation type, and request context information from the request information; S1222, performing structured encoding on the user identity identifier, the request operation type, and the request context information to obtain a one-hot encoding vector of the user identity identifier, a one-hot encoding vector of the request operation type, and a semantic encoding vector of the request context information, and cascading the one-hot encoding vector of the user identity identifier, the one-hot encoding vector of the request operation type, and the semantic encoding vector of the request context information to obtain a structured encoding vector of the request basic information; S1223, performing semantic encoding on the real-time security threat intelligence to obtain a semantic encoding vector of the real-time security threat intelligence; S1224, performing request-security intelligence real-time soft constraint-driven dynamic response analysis on the structured encoding vector of the request basic information and the semantic encoding vector of the real-time security threat intelligence to obtain a request-security intelligence real-time dynamic response encoding vector as the request-security intelligence real-time dynamic response encoding feature.

[0031] Specifically, the step S1221 extracts the user identity, the requested operation type and the request context information from the request information. It should be understood that accurately obtaining and parsing the user identity can help the system quickly locate the specific user who initiated the request, and then make a preliminary risk judgment based on the user's past behavior record, account status and other factors. Among them, the user identity usually includes but is not limited to unique identifiers such as user name and encrypted user ID. Through these identifiers, users can be matched with pre-stored identity authentication data to ensure that only authorized users can perform specific operations. In addition, combined with machine learning algorithms, the user's behavior trajectory can also be modeled, such as analyzing their login time, geographical location distribution, etc., to further enhance the security and accuracy of identity authentication. Secondly, different types of operations are often accompanied by different degrees of security risks. For example, low-risk operations such as viewing news information do not require the same level of security protection measures as high-risk operations involving fund transfer or access to personal sensitive information. Therefore, clarifying the type of request operation helps the system adjust the response method according to the preset security policy, which not only ensures security but also improves user experience. Furthermore, the request context covers unstructured data such as device fingerprints, network environment, and geographic location, which together describe the specific scenario when the user makes a request. Taking device fingerprints as an example, it includes a series of hardware and software features such as device model, operating system version, and browser type. These detailed information can help the system identify whether there is abnormal login behavior, such as a new device trying to access important resources for the first time or an old device suddenly appearing in an unfamiliar place. As for the network environment, it is possible to detect whether a malicious attack is taking place by monitoring changes in parameters such as network latency and IP address. For example, a DDoS attack may cause a sharp increase in network traffic. Geographic location information is also of great reference value, especially in cross-regional transactions or access to restricted content. Sudden changes in geographic location may be an early warning signal of fraud. Specifically, for the extraction of user identity, the user's encrypted ID or other forms of identity proof can be directly obtained by calling the authentication service interface. Next, in the extraction of request operation types, in addition to using unique hot encoding, more advanced technologies such as label propagation algorithms can be introduced to automatically annotate operation types that are not clearly classified to improve the accuracy of classification. As for the extraction of request context information, it relies more on sensor data collection, log file analysis and other means. By monitoring various client activities in real time and streaming the collected data to the server for centralized processing, timely updating and accurate analysis of context information can be ensured.

[0032] In an embodiment of the present application, the step S1222 of performing structured encoding on the user identity identifier, the request operation type, and the request context information to obtain a one-hot encoded vector of the user identity identifier, a one-hot encoded vector of the request operation type, and a semantic encoded vector of the request context information, and concatenating the one-hot encoded vector of the user identity identifier, the one-hot encoded vector of the request operation type, and the semantic encoded vector of the request context information to obtain a structured encoded vector of the request basic information includes: S1222-1, performing one-hot encoding on the user identity identifier and the request operation type to obtain a one-hot encoded vector of the user identity identifier and a one-hot encoded vector of the request operation type; S1222-2, performing semantic encoding on the request context information based on Bert to obtain a semantic encoded vector of the request context information; S1222-3, concatenating the one-hot encoded vector of the user identity identifier, the one-hot encoded vector of the request operation type, and the semantic encoded vector of the request context information to obtain the structured encoded vector of the request basic information. It should be understood that considering the multi-dimensional heterogeneous characteristics of user request information (such as discrete identifier data and semantic context information), it is difficult to be effectively parsed by a machine learning model directly. Traditional risk assessment methods often adopt simple rule matching or single-dimensional feature extraction, and this processing method will lose the cross-modal association features hidden in the request information. For example, the user identity identifier (such as the encrypted user ID) belongs to high-cardinality discrete data, and directly inputting it into the model will cause dimensional explosion; while the request context information (such as device fingerprint, network latency fluctuation) contains complex semantic features such as temporality and spatiality, and special representation methods are required to reveal its potential association with security risks. In addition, the user operation type (such as transfer, information query) as a key risk indicator, its combined relationship with the user identity and device environment (such as a new device initiating a sensitive operation) often reflects the essence of the risk better than a single feature. Therefore, it is necessary to convert heterogeneous data into a computable and associable unified representation through structured encoding in order to provide effective feature input for subsequent dynamic risk assessment. Based on this, the present application performs structured encoding on the user identity identifier, the request operation type, and the request context information to obtain a one-hot encoded vector of the user identity identifier, a one-hot encoded vector of the request operation type, and a semantic encoded vector of the request context information. In particular, in a specific example of the present application, one-hot encoding is performed on the user identity identifier and the request operation type to obtain a one-hot encoded vector of the user identity identifier and a one-hot encoded vector of the request operation type; semantic encoding is performed on the request context information based on Bert to obtain a semantic encoded vector of the request context information.That is to say, for discrete high-cardinality features such as user identity, one-hot encoding is used to map them into sparse vectors to ensure that each independent user has a unique and mutually exclusive vector representation; for predefined request operation types (such as fund transfers, biometric calls), one-hot encoding is also used to generate dimensionally controllable category vectors to clearly distinguish the risk attributes of different operations; and for unstructured data such as request context information (such as device model, geographic location, network environment), semantic coding technology is used to extract its deep semantic features, and compress complex information such as hardware parameters of device fingerprints and fluctuation patterns of network delays into dense vectors. Afterwards, the user identity one-hot encoding vector, the request operation type one-hot encoding vector, and the request context information semantic encoding vector are cascaded to merge the three types of encoding results into a unified structured encoding feature of the request basic information, and obtain the structured encoding vector of the request basic information. In this way, the vector cascade operation is finally performed. For example, when a user uses a newly registered device to initiate a transfer request in a public WiFi environment, this step will concatenate the one-hot vector of the user ID, the one-hot vector of the transfer operation, and the context encoding vector containing the semantics of "unfamiliar device + public network" to form a multi-dimensional vector expression that fully reflects the characteristics of the current request.

[0033] In an embodiment of the present application, the step S1223, semantically encoding the real-time security threat intelligence to obtain the real-time security threat intelligence semantic encoding vector, includes: performing the Bert-based semantic encoding on the real-time security threat intelligence to obtain the real-time security threat intelligence semantic encoding vector. It should be understood that, considering the complex and diverse forms of real-time security threat intelligence (such as new attack features, malicious IP address libraries, vulnerability exploitation trends), it includes unstructured natural language reports (such as vulnerability warnings issued by security vendors), etc. If such intelligence is usually processed by rule matching or keyword filtering, for example, the malicious IP list is directly compared with the client IP in the request, only shallow threat identification can be achieved, and the implicit context association in the threat intelligence (such as the association between a certain type of phishing attack and a specific device model) cannot be captured. Therefore, in order to effectively associate the fragmented threat information with the contextual features of the current user request and identify new composite attack patterns (such as the combination of cross-site scripting attacks launched by real-time vulnerabilities and disguised normal requests), the present application obtains a real-time security threat intelligence semantic encoding vector by semantically encoding the real-time security threat intelligence. In particular, in a specific example of the present application, the real-time security threat intelligence is subjected to the Bert-based semantic encoding to perform context-aware encoding of unstructured threat text (such as vulnerability descriptions in security bulletins), extract semantic features such as implicit attack methods and impact scope, and obtain the real-time security threat intelligence semantic encoding vector.

[0034] Figure 5 It is a flowchart for performing request-security intelligence real-time soft constraint-driven dynamic response analysis on the request basic information structured coding vector and the real-time security threat intelligence semantic coding vector in the randomness-based mobile application security access method according to an embodiment of the present application to obtain a request-security intelligence real-time dynamic response coding vector. As Figure 5As shown, in the embodiment of the present application, in step S1224, a request-security intelligence real-time soft constraint-driven dynamic response analysis is performed on the request basic information structured encoding vector and the real-time security threat intelligence semantic encoding vector to obtain a request-security intelligence real-time dynamic response encoding vector, including: S1224-1, performing principal component analysis on the real-time security threat intelligence semantic encoding vector to obtain a set of real-time security threat intelligence semantic principal component encoding vectors; S1224-2, performing linear transformation on each real-time security threat intelligence semantic principal component encoding vector in the set of real-time security threat intelligence semantic principal component encoding vectors to obtain a set of real-time security threat intelligence semantic principal component linear transformation encoding vectors; S1224-3, performing dynamic adaptive aggregation based on soft constraint factor weighting on the request basic information structured encoding vector and the set of real-time security threat intelligence semantic principal component linear transformation encoding vectors to obtain the request-security intelligence real-time dynamic response encoding vector. It should be understood that considering that user request information (such as device fingerprint, operation type) and real-time security threat intelligence (such as new attack features, malicious IP library) belong to different modal data sources, there are significant differences in their information structures and semantic representations. Traditional risk assessment methods usually adopt simple feature splicing or weighted fusion, resulting in information redundancy and semantic deviation during the cross-modal feature interaction process. For example, it is difficult to directly associate the hardware parameters (structured data) in user device information with the natural language descriptions (unstructured data) in threat intelligence. If forced to fuse, it may mask key risk signals (such as the relevance between a specific device model and the latest vulnerability). In addition, the heterogeneity of different modal data in terms of feature scale and distribution (such as the discrete encoding of device fingerprints and the continuous semantic vectors of threat intelligence) will undermine the model's ability to identify complex risk patterns, making the system unable to dynamically capture high-risk scenarios such as "user abnormal behavior superimposed with real-time attack trends". Therefore, in the technical solution of the present application, a request-security intelligence real-time soft constraint-driven dynamic response analysis is performed on the request basic information structured encoding vector and the real-time security threat intelligence semantic encoding vector to obtain a request-security intelligence real-time dynamic response encoding vector. Specifically, first, principal component analysis (PCA) is performed on the real-time security threat intelligence semantic encoding vector to extract its core variation features to eliminate redundant noise, and scale alignment with the request basic information vector is achieved through linear transformation. Subsequently, inter-modal independence modeling is used to explicitly quantify the complementary relationship between the two types of modal data: when there is a strong association between the attack pattern in threat intelligence (such as a man-in-the-middle attack on a certain payment interface) and the operation type in the user request (such as large amount transfer), the model automatically enhances the interaction weight of such cross-modal features; conversely, for irrelevant features (such as device screen resolution and DDoS attack features), interference is suppressed through independence constraints.In the fine-grained interaction stage, the model analyzes the short-range dependencies between features (such as the regional matching of device geographical location and malicious IP) and long-range associations (such as the temporal synchronization of abnormal user behavior sequences and attack techniques) through an asymmetric coupling mechanism, and finally generates a response coding vector that fuses cross-modal risk features based on dynamic adaptive aggregation.

[0035] Specifically, in step S1224-1, principal component analysis is performed on the real-time security threat intelligence semantic coding vector to obtain a set of real-time security threat intelligence semantic principal component coding vectors, which is represented by the real-time security threat intelligence principal component analysis formula:

[0036]

[0037] where v2 is the real-time security threat intelligence semantic coding vector, PCA(·) is the principal component analysis operation, n is the number of eigenvalues in v2, C is the real-time security threat intelligence semantic sample covariance matrix, U is the real-time security threat intelligence semantic principal component orthogonal matrix, that is, the set of real-time security threat intelligence semantic principal component coding vectors, v 21 , v 22 , v 2i and v 2m are the 1st, 2nd, i-th, and m-th real-time security threat intelligence semantic principal component coding vectors in the set of real-time security threat intelligence semantic principal component coding vectors respectively, Λ is the real-time security threat intelligence semantic diagonal matrix, diag(λ 21 , λ 22 ,… λ 2i ,…, λ 2m ) is the real-time security threat intelligence semantic diagonal matrix with the elements on the diagonal being λ 21 , λ 22 , λ 2i and λ 2m , λ 21 , λ 22 , λ 2i and λ 2m are the eigenvalues corresponding to v 21 , v 22 , v 2i and v 2mThe corresponding eigenvalue, and T represents the transpose operation. It should be understood that performing principal component analysis on the semantic encoding vector of real-time security threat intelligence can reconstruct the feature space through orthogonal transformation, project the original high-dimensional semantic encoding vector of real-time security threat intelligence onto a set of orthogonal principal component axes, so that a small number of leading principal components can capture the main variation information in the features of real-time security threat intelligence. This process not only achieves dimensionality reduction, but more importantly, by eliminating the collinearity relationship between features, it reveals the potential attack pattern associations hidden under the surface data, thereby purifying the information. For example, principal component analysis may find that two seemingly unrelated features, "malicious IP address" and "frequent login failures", are strongly correlated in an attack scenario. This implicit knowledge representation is crucial for subsequent dynamic risk assessment. At the same time, the compactness of the feature space helps to improve the efficiency of subsequent cross-modal interactions.

[0038] Specifically, in step S1224-2, a linear transformation is performed on each real-time security threat intelligence semantic principal component encoding vector in the set of real-time security threat intelligence semantic principal component encoding vectors to obtain a set of real-time security threat intelligence semantic principal component linearly transformed encoding vectors, which is represented by the real-time security threat intelligence semantic principal component linear transformation formula as:

[0039] X = L i (U) = [x 21 , x 22 , … x 2i , …, x 2m

[0040] where L i (U) is the linear transformation operation on the set of real-time security threat intelligence semantic principal component encoding vectors, x 21 , x 22 , x 2i and x 2m ​They are the 1st, 2nd, ith, and mth real-time security threat intelligence semantic principal component linear transformation coding vectors in the set of real-time security threat intelligence semantic principal component linear transformation coding vectors, and X is the set of real-time security threat intelligence semantic principal component linear transformation coding vectors. It should be understood that considering that each real-time security threat intelligence semantic principal component coding vector in the set of real-time security threat intelligence semantic principal component coding vectors has a different scale, direct combination may lead to uneven contributions, thus causing information deviation. Linear transformation can build a fair interaction basis for cross-modal features. In this step, by applying an adaptive scaling factor and rotation transformation, not only are different modal features uniformly mapped to the standard normal distribution interval, but more importantly, through the reconstruction of the feature direction, the model can focus on the complementarity between modalities rather than the absolute values of a single modality. For example, when a user initiates a low-risk request of "viewing news", the linear transformation will suppress the high-dimensional feature weights related to financial attacks in the real-time security threat intelligence. When a "large amount transfer" operation is detected, it will enhance the feature expression related to payment hijacking. This dynamic weight adjustment mechanism effectively avoids the problem of "long-tail features drowning out short-head signals" in traditional feature splicing, promotes the initial alignment of the cross-modal feature space, and enables the subsequent independent modeling between modalities to accurately quantify the synergistic effect of the two types of data.

[0041] It is worth mentioning that in the embodiments of the present application, each real-time security threat intelligence semantic principal component linear transformation coding vector in the set of real-time security threat intelligence semantic principal component linear transformation coding vectors has the same feature scale as the request basic information structured coding vector.

[0042] Figure 6 It is a flowchart for dynamically adaptively aggregating the request basic information structured coding vector and the set of real-time security threat intelligence semantic principal component linear transformation coding vectors based on a soft constraint factor weighting to obtain the request-security intelligence real-time dynamic response coding vector in the randomness-based mobile application security access method according to the embodiments of the present application. As Figure 6As shown, in the embodiment of the present application, step S1224-3, performing dynamic adaptive aggregation based on a soft constraint factor weighting on the set of the request basic information structured encoding vector and the real-time security threat intelligence semantic principal component linear transformation encoding vector to obtain the request-security intelligence real-time dynamic response encoding vector, includes: S1224-31, performing inter-modal independence modeling on each real-time security threat intelligence semantic principal component linear transformation encoding vector in the set of the request basic information structured encoding vector and the real-time security threat intelligence semantic principal component linear transformation encoding vector to obtain a set of request-security intelligence principal component inter-modal independence semantic encoding matrices; S1224-32, calculating a set of request-security intelligence principal component inter-modal independence semantic soft constraint factors based on the set of the request-security intelligence principal component inter-modal independence semantic encoding matrices; S1224-33, performing semantic feature interaction response on each real-time security threat intelligence semantic principal component linear transformation encoding vector in the set of the request basic information structured encoding vector and the real-time security threat intelligence semantic principal component linear transformation encoding vector to obtain a set of request-security intelligence principal component inter-modal fine-grained semantic response interaction encoding vectors; S1224-34, performing dynamic adaptive aggregation on the set of the request-security intelligence principal component inter-modal fine-grained semantic response interaction encoding vectors based on the set of the request-security intelligence principal component inter-modal independence semantic soft constraint factors to obtain the request-security intelligence real-time dynamic response encoding vector.

[0043] Specifically, step S1224-31, performing inter-modal independence modeling on each real-time security threat intelligence semantic principal component linear transformation encoding vector in the set of the request basic information structured encoding vector and the real-time security threat intelligence semantic principal component linear transformation encoding vector to obtain a set of request-security intelligence principal component inter-modal independence semantic encoding matrices, is represented by the request-security intelligence principal component inter-modal independence modeling formula as:

[0044]

[0045] Wherein, and Φ(·) is a feature mapping function, such as a linear mapping or a non-linear kernel function, v1 is the request basic information structured encoding vector, L is the length of v1, and IM i is v1 and x 2iThe semantic encoding matrix of inter-modal independence between the request and the security intelligence principal component. It should be understood that the structured encoding vector of the request basic information and the linear transformation encoding vector of the semantic principal component of the real-time security threat intelligence are respectively derived from data sources in different cognitive dimensions. Among them, the structured encoding vector of the request basic information represents discrete structured attributes such as user identity and operation type, and the linear transformation encoding vector of the semantic principal component of the real-time security threat intelligence contains unstructured threat intelligence such as attack features and malicious IPs. Traditional fusion methods lead to the failure of feature interaction due to modal heterogeneity. For example, the discrete encoding of device fingerprints and the natural language semantics of threat descriptions are difficult to directly map. If simple concatenation is used, key risk signals may be diluted (such as the spatio-temporal correlation between vulnerabilities of specific models and transfer operations). This step explicitly deconstructs the complementary relationship between the two types of data through inter-modal independence modeling, and its essence is to construct a "feature isolation - correlation enhancement" dual-channel mechanism at the cognitive level. This explicit modeling transforms the complementarity originally hidden in the data into optimizable mathematical constraint conditions, enabling dynamic adjustment of the feature interaction weights, generating a semantic encoding matrix of inter-modal independence between the request and the security intelligence principal component that not only retains the integrity of the risk features but also avoids redundant calculations, thereby providing an input representation with both discriminative power and robustness for subsequent risk assessment.

[0046] In an embodiment of the present application, in step S1224 - 32, based on the set of semantic encoding matrices of inter-modal independence between the request and the security intelligence principal component, calculate the set of semantic soft constraint factors of inter-modal independence between the request and the security intelligence principal component, including: S1224 - 321, perform global correlation optimization based on the topological gauge field on each semantic encoding matrix of inter-modal independence between the request and the security intelligence principal component in the set of semantic encoding matrices of inter-modal independence between the request and the security intelligence principal component to obtain a set of optimized semantic encoding matrices of inter-modal independence between the request and the security intelligence principal component; S1224 - 322, calculate the square of the Frobenius norm of each optimized semantic encoding matrix of inter-modal independence between the request and the security intelligence principal component in the set of optimized semantic encoding matrices of inter-modal independence between the request and the security intelligence principal component to obtain the set of semantic soft constraint factors of inter-modal independence between the request and the security intelligence principal component.

[0047] Specifically, in step S1224 - 321, perform global correlation optimization based on the topological gauge field on each semantic encoding matrix of inter-modal independence between the request and the security intelligence principal component in the set of semantic encoding matrices of inter-modal independence between the request and the security intelligence principal component to obtain a set of optimized semantic encoding matrices of inter-modal independence between the request and the security intelligence principal component, which is represented by the request - security intelligence global correlation optimization formula as:

[0048] V λi =(λ i1 ,λ i2 ,…,λin )

[0049]

[0050] Among them, λ i1 ,λ i2 ,…,λ in is IM i Each eigenvalue of V λi is IM i The corresponding eigenvectors, It is added by location point. is the matrix multiplication, V 1i is IM i The corresponding topological gauge field vector, IM' i is IM i The optimized semantic coding matrix of inter-modal independence of the principal component of request-security intelligence. It should be understood that based on the topological generation framework of the semantic coding matrix of inter-modal independence of the principal component of request-security intelligence, the global representation of the network topology is achieved through the deconstruction analysis of the coupling characteristics of the feature space basis vector and the multi-scale feature distribution pattern (covering local-global feature interactions) combined with the asymmetric interaction mechanism. In order to ensure the modal fusion accuracy of the asymmetric architecture in a dynamic coupling environment, the intrinsic gauge field representation of the semantic coding matrix of inter-modal independence of the principal component of request-security intelligence is used as the topological invariant benchmark, and the eigenvector V corresponding to the semantic coding matrix of inter-modal independence of the principal component of request-security intelligence is derived based on the gauge field theory framework. λi In the specific implementation process, the eigenvector V corresponding to the semantic encoding matrix of the independence between the principal component modalities of the request-security intelligence is extracted. λi After that, the high-order edge effect perturbation terms outside the limit distribution conditions are eliminated, and the first-order gauge field component The topological normative field vector V corresponding to the semantic encoding matrix of the independence between the principal components of the request-security intelligence modality 1i Construct an explicit mapping relationship of characteristic basis vectors. According to the perturbation structural stability condition under the regulation of the gauge field, the topological gauge field vector V corresponding to the semantic encoding matrix of the independence between the principal component modalities of the request-security intelligence is adopted. 1i The self-correlation matrix of the request-security intelligence principal component modality independence semantic encoding matrix IM i Topology optimization is performed to achieve the optimal topological convergence of the asymmetric structure under the perturbation stability threshold constraint.

[0051] Specifically, in step S1224-322, calculate the square of the Frobenius norm of each optimized request-security intelligence principal component modal independence semantic coding matrix in the set of optimized request-security intelligence principal component modal independence semantic coding matrices to obtain the set of request-security intelligence principal component modal independence semantic soft constraint factors, which is represented by the request-security intelligence principal component modal independence semantic soft constraint calculation formula as follows:

[0052]

[0053] Wherein, is for calculating the square of the Frobenius norm, and SM i is the request-security intelligence principal component modal independence semantic soft constraint factor corresponding to IM' i It should be understood that the optimized request-security intelligence principal component modal independence semantic coding matrix characterizes the complementary relationship between different modal data (user request features and real-time threat intelligence features) after principal component analysis, linear transformation, and independence modeling. By calculating the square of the Frobenius norm, the overall energy distribution of the high-dimensional optimized request-security intelligence principal component modal independence semantic coding matrix can be compressed into the request-security intelligence principal component modal independence semantic soft constraint factor, which can flexibly guide the model for information fusion instead of rigidly excluding dependency relationships, realizing fine-grained control of the modal fusion strategy. In this way, the abstract modal interaction relationship can be transformed into a numerical request-security intelligence principal component modal independence semantic soft constraint factor, which is used as the basis for dynamically adjusting the modal fusion strategy. When the norm square is large, it indicates that there is a significant non-independence between the modalities (such as a high correlation between a specific device fingerprint and a known attack method). At this time, the request-security intelligence principal component modal independence semantic soft constraint factor will increase the weight allocation for relevant features, prompting the model to focus on capturing such high-risk associations; conversely, if the norm square is small, it means that the information between the modalities is relatively independent, and the request-security intelligence principal component modal independence semantic soft constraint factor will reduce the constraint intensity to avoid over-suppressing the flow of effective information. This can accurately balance the sensitivity of security verification and the smoothness of the user experience, so that neither high-risk operations will be allowed to pass due to ignoring key threat signals, nor redundant verification will be imposed on low-risk behaviors due to excessive sensitivity, thus achieving the optimal decoupling of security protection and business efficiency.

[0054] Specifically, in step S1224-33, semantic feature interaction responses are performed on each real-time security threat intelligence semantic principal component linear transformation coding vector in the set of the request basic information structured coding vector and the real-time security threat intelligence semantic principal component linear transformation coding vector to obtain a set of request-security intelligence principal component inter-modal fine-grained semantic response interaction coding vectors, which is expressed by the request-security intelligence semantic feature interaction response formula as follows:

[0055]

[0056] where ⊙ is element-wise multiplication, is element-wise division, concat{·;·;·} is a concatenation operation, W i and b i are the interaction response weight matrix and the interaction response bias vector corresponding to x 2i respectively, and SF i is the request-security intelligence principal component inter-modal fine-grained semantic response interaction coding vector between v1 and x 2i It should be understood that this step adopts a multi-granularity semantic feature interaction response strategy, and an association channel is established at the feature dimension level through an asymmetric coupling mechanism. This interaction not only focuses on explicit feature associations, but also mines deep implicit associations through a multi-layer perceptron, such as the overlap degree between the user's high-frequency operation period and the recent network attack time window. During the interaction process, by dynamically adjusting the fusion weights of different feature channels, the model can adjust the focus of attention according to the real-time risk situation. For example, when detecting a distributed denial-of-service attack, the network delay feature and the DDoS attack feature in the threat intelligence are preferentially fused. This fine-grained interaction delves into the feature dimension level, mines non-linear and hierarchical interaction associations, thereby achieving precise identification of complex risks.

[0057] Specifically, in step S1224-34, based on the set of request-security intelligence principal component inter-modal independence semantic soft constraint factors, dynamic adaptive aggregation is performed on the set of request-security intelligence principal component inter-modal fine-grained semantic response interaction coding vectors to obtain the request-security intelligence real-time dynamic response coding vector, which is expressed by the request-security intelligence dynamic adaptive aggregation formula as follows:

[0058]

[0059] where softmax is a normalization function, m is the number of the set of request-security intelligence principal component inter-modal fine-grained semantic response interaction coding vectors, and v rIt is the request - security intelligence real - time dynamic response coding vector. It should be understood that based on the semantic soft - constraint factor of the independence between the principal components of the request - security intelligence, in this step, by differentially integrating multi - dimensional fine - grained interaction response features, a dynamic response coding representation with situational awareness ability is constructed. The dynamic adaptive aggregation process is guided by the inter - modal independence quantification index, and dynamically adjusts the weight distribution of different interaction features according to the semantic soft - constraint factor of the independence between the principal components of the request - security intelligence, focusing on enhancing the salience of cross - modal complementary features and simultaneously suppressing the interference of redundant features. Compared with the traditional arithmetic - mean fusion method, this step adopts a non - linear weighting strategy, enabling high - independence features (such as the match between device fingerprint anomalies and known attack patterns) to obtain exponentially increased weight, while low - correlation features (such as user device color preference and phishing attacks) are attenuated through the semantic soft - constraint threshold mechanism of the independence between the principal components of the request - security intelligence. The finally generated request - security intelligence real - time dynamic response coding vector not only retains the deep association between the temporal features of the user behavior sequence and the spatial distribution of threat intelligence, but also eliminates the inter - modal feature scale difference through adaptive normalization processing, forming an interpretable compact semantic representation.

[0060] In the embodiment of the present application, in step S123, based on the request - security intelligence real - time dynamic response coding features, the request risk assessment result is obtained, including: inputting the request - security intelligence real - time dynamic response coding vector into a risk assessment engine based on a classifier to obtain the request risk assessment result. That is, the request - security intelligence real - time dynamic response coding vector obtained by dynamically responding with the request basic information structured coding vector and the real - time security threat intelligence semantic coding vector is classified to accurately obtain the request risk assessment result. It should be understood that a classifier is a trained model that can classify or evaluate data according to the input feature vector. The request - security intelligence real - time dynamic response coding vector contains rich feature information. By inputting it into the risk assessment engine based on a classifier, the learning ability and pattern recognition ability of the classifier can be used to accurately assess and judge the risk of the request.

[0061] In summary, it is elucidated that the application server based on the embodiments of the present application performs risk assessment on the request information to obtain the request risk assessment result. It uses data analysis and coding algorithms based on deep learning to first extract user identity, operation type, and context information from the request information, synchronously obtains real-time security threat intelligence, and then converts the discrete user identity and operation type into computable vector representations through structured coding. At the same time, semantic coding technology is adopted to perform deep feature extraction on the unstructured context information. Subsequently, through real-time dynamic response of request-security intelligence, in-depth coupling analysis of the semantic features of the request features and real-time threat intelligence is realized. Finally, based on the fused dynamic response coding features, an accurate risk level assessment result is output. This solution enables the system to dynamically perceive changes in the threat situation, complete risk quantification within milliseconds when the user initiates a request, fundamentally solves the defects of traditional static policies in aspects such as lag in risk perception and rigidity of verification intensity, and achieves the optimal balance between security protection and user experience.

[0062] In the above-mentioned mobile application security access method based on randomness, in step S130, the application server dynamically selects the challenge complexity level based on the request risk assessment result. It should be understood that different requests have different risk levels. Specifically, when a user performs a low-risk operation (such as browsing public information), if a high-intensity verification (such as multi-factor biometric authentication) is forced, it will not only cause waste of computing resources and increase the server load, but also trigger user resistance due to frequent interruptive verification processes, reducing the stickiness of application use. On the contrary, for high-risk operations (such as large-amount fund transfers), if only a low-complexity challenge (such as a four-digit verification code) is used, it is easily bypassed by brute-force cracking of automated scripts or phishing attacks, forming a serious security vulnerability. This contradiction stems from the fact that static policies cannot perceive the dynamic changes in risks, making it difficult to cope with the rapid evolution of attack means and unable to adapt to the flexible expansion needs of business scenarios. Therefore, on the basis of accurately quantifying risks, a dynamic mapping mechanism between the challenge complexity and the risk level must be established to achieve the optimal allocation of security resources. In particular, in a specific example of this application, the dynamic complexity levels for different risk degrees include low risk, medium risk, and high risk. Among them, low-risk requests usually do not require challenges or only use simple implicit challenges, such as behavioral verification analysis. The risks of such requests are relatively low and may involve routine operations such as browsing news and information. Therefore, the system can simplify the verification process and improve the user experience. Medium-risk requests use challenges of medium complexity, such as simple digital verification codes, sliding verification codes, etc. The risks of such requests are moderate and may involve some sensitive but not highly sensitive operations, such as modifying non-critical information. Through challenges of medium complexity, the system can ensure basic security while avoiding causing too much inconvenience to users. High-risk requests use challenges of high complexity, such as complex graphic verification codes, multi-factor authentication (MFA), hardware key authentication, device fingerprint verification, etc. The risks of such requests are relatively high and may involve key operations such as fund transfer and access to personal sensitive information. Through challenges of high complexity, the system can effectively resist potential attacks and ensure the security of these key operations. This mechanism of dynamically selecting the challenge complexity level not only improves the security of the system but also optimizes the user experience. For low-risk requests, the system simplifies the verification process, reduces the waiting time and operation steps of users, thereby improving the overall use experience. For high-risk requests, the system effectively prevents potential security threats by increasing the verification complexity, protecting the privacy and property security of users. In this way, the application server can flexibly adjust the verification strategy in different risk scenarios, ensuring both the security of the system and taking into account the user experience, achieving the dual goals of security and convenience.

[0063] In the above-described mobile application security access method based on randomness, in step S140, the application server generates a random challenge that matches the determined challenge complexity level and sends the random challenge to the client. It should be understood that after determining the challenge complexity level based on the request risk assessment result, generating a matching random challenge is to achieve a balance between security protection and user experience. Different complexity levels correspond to different challenge generation algorithms and parameters. For high-risk requests, high-complexity random challenges can effectively resist potential attacks, such as complex multi-factor authentication problems and high-intensity verification codes, to ensure the security of the system and user data; while for low-risk requests, low-complexity random challenges can reduce the user operation burden, improve the usability, and prevent user churn caused by excessive verification. After that, the application server sends the matching random challenge to the client, which sends the generated random challenge, including the random challenge information and the challenge type indication (indicating which response method the client needs), to the mobile application client through a secure channel (HTTPS). The challenge type indicates which method the client needs to use for response, for example: entering a verification code, sliding verification, fingerprint recognition, hardware key operation, etc. The client guides the user to perform corresponding operations according to the received challenge type indication. In a specific embodiment of the present application, once the challenge complexity level is determined, the application server will select a corresponding challenge generation algorithm according to this level. For example, for low-complexity challenges, such as simple numeric verification codes or sliding verification, the challenge generator only needs to call a basic random number generation algorithm to generate a specific-length string of numbers or define the initial state and target position of the sliding bar. The design of such challenges aims to ensure the smoothness of user operations while providing basic security. For medium-complexity challenges, such as graphic verification codes, the challenge generator needs to select a picture from a preset image library and add interference elements, such as lines and noise points, on this basis to increase the difficulty of machine recognition. In addition, to further enhance security, the challenge generator also introduces technical means such as text distortion and color change to ensure that the generated graphic verification code can be accurately recognized by the human eye and is sufficient to resist the cracking attempts of automated attack tools. For high-complexity challenges, such as multi-factor authentication (MFA) or hardware key verification, when the challenge generator generates a one-time password (OTP), it needs to ensure that the password has sufficient randomness and timeliness, usually using a time-based one-time password algorithm (TOTP) or an event-based one-time password algorithm (HOTP). These algorithms rely on a shared key and a time / event counter to generate a unique and unpredictable verification code, thus greatly enhancing the security of the system. After completing the challenge generation, the application server encapsulates the generated random challenge into a specific data packet and sends it to the client through a network transmission protocol.After the client receives the challenge, the user needs to complete the corresponding verification operations according to the prompts, such as entering the verification code, scanning the QR code, or providing the hardware key, etc. This process not only improves security but also optimizes the user experience, ensuring flexible adjustment of the verification strategy in different risk scenarios, achieving the dual goals of ensuring system security and taking into account the user experience, realizing the dual goals of security and convenience.

[0064] In the above mobile application security access method based on randomness, in step S150, the client responds to the random challenge and sends the response information to the application server. That is to say, the client guides the user to perform corresponding operations according to the received challenge type indication. For example: if it is a simple verification code, the user is prompted to enter the verification code; if it is a graphic verification code, the graphic verification code is displayed for the user to identify; if it is hardware key authentication, the hardware key API is called for authentication. After that, after the client completes the user interaction, it sends the response information (the user's response and the response type) back to the application server.

[0065] In the above-mentioned randomness-based mobile application security access method, in step S160, the application server performs response verification on the response information. If the verification is successful, it performs service processing and access control based on the request information. If the verification fails, access is denied and a security alert is issued. It should be understood that in the mobile application environment, there are various potential security threats, such as identity forgery, malicious attacks, etc. The application server's verification of the client's response information is a crucial link to ensure that only legitimate users can access system resources and perform operations. Through a strict verification mechanism, illegal user intrusion can be effectively blocked, protecting the security of the system and user data. Only when the client's identity and permissions are confirmed can service processing based on the request information be accurate and reliable. If response verification is not performed, it may lead to incorrect service processing. For example, an unauthorized user performing a fund transfer operation will cause serious losses to users and the system. Specifically, after receiving the client's response information, the application server will first check the authenticity and validity of this information. This includes comparing the response provided by the user with the random challenge previously sent to the client. Once the verification is successful, that is, after confirming the user's legitimacy, it becomes possible to perform service processing and access control based on the request information. At this time, the application server will decide the next operation based on the specific request content initiated by the user and their identity information. For example, if the user requests to view personal information, the server will extract relevant information from the database and present it to the user; if it involves high-risk operations such as fund transfer, the server will further verify the user's identity and record all operation details for subsequent auditing. However, when the verification fails, it means that there may be some form of security threat or abnormal behavior. In this case, denying access and issuing a security alert are necessary measures. This can not only prevent further actions by illegal users but also promptly notify system administrators and relevant personnel to take emergency response measures. For example, when detecting multiple consecutive failed login attempts, the server can temporarily lock the account and send a warning email or text message to the user to remind them of account security. In addition, for some suspected DDoS attack situations, the server can also activate protection mechanisms, such as restricting traffic from specific IP addresses or enabling CDN acceleration services to disperse the pressure. In addition, to ensure the efficiency of the entire verification process, the application server also needs to optimize its internal workflow. For example, a distributed architecture can be used to share the load to ensure that even under high concurrency, it can quickly respond to user requests. At the same time, caching technology and pre-computation methods are adopted to reduce the cost of repeated calculations and improve overall performance. In the design, the issue of user experience also needs to be considered, minimizing unnecessary verification links as much as possible so that legitimate users can use various services smoothly. In this way, the security of the system can be significantly improved, providing users with a more secure and convenient service experience.

[0066] In summary, the randomness-based mobile application security access method according to the embodiments of the present application is elucidated. First, the client sends request information to the server, and then the server uses a deep learning algorithm to perform a risk assessment on the request information, including extracting user identity, operation type, and context information, and combining real-time security threat intelligence. Structured and semantic coding technologies are used to generate dynamic response coding features, and the risk level of the request is calculated to dynamically adjust the challenge complexity accordingly, generate and send a random challenge to the client. After the client responds, the server verifies its correctness to determine whether to continue business processing or deny access. In this way, risks can be quantified within milliseconds, overcoming the latency and rigidity problems of traditional static policies, and achieving a balance between efficient security protection and good user experience.

Claims

1. A mobile application security access method based on randomness, characterized in that, Including: The client sends request information to the application server; The application server conducts a risk assessment on the request information to obtain a request risk assessment result, including: obtaining real-time security threat intelligence; performing request-security intelligence real-time dynamic response encoding on the request information and the real-time security threat intelligence to obtain request-security intelligence real-time dynamic response encoding features; obtaining the request risk assessment result based on the request-security intelligence real-time dynamic response encoding features; The application server dynamically selects a challenge complexity level based on the request risk assessment result; The application server generates a random challenge matching the complexity level based on the determined challenge complexity level and sends the random challenge to the client; The client responds to the random challenge and sends response information to the application server; The application server conducts response verification on the response information. If the verification is successful, it performs service processing and access control based on the request information. If the verification fails, it rejects access and issues a security alert.

2. The randomness-based mobile application secure access method according to claim 1, wherein Performing request-security intelligence real-time dynamic response encoding on the request information and the real-time security threat intelligence to obtain request-security intelligence real-time dynamic response encoding features includes: Extracting the user identity identifier, request operation type, and request context information from the request information; Performing structured encoding on the user identity identifier, the request operation type, and the request context information to obtain a user identity identifier one-hot encoding vector, a request operation type one-hot encoding vector, and a request context information semantic encoding vector, and cascading the user identity identifier one-hot encoding vector, the request operation type one-hot encoding vector, and the request context information semantic encoding vector to obtain a request basic information structured encoding vector; Performing semantic encoding on the real-time security threat intelligence to obtain a real-time security threat intelligence semantic encoding vector; Performing request-security intelligence real-time soft constraint-driven dynamic response analysis on the request basic information structured encoding vector and the real-time security threat intelligence semantic encoding vector to obtain a request-security intelligence real-time dynamic response encoding vector as the request-security intelligence real-time dynamic response encoding feature.

3. The method for secure access to mobile applications based on randomness according to claim 2, wherein Performing structured encoding on the user identity identifier, the request operation type, and the request context information to obtain a user identity identifier one-hot encoding vector, a request operation type one-hot encoding vector, and a request context information semantic encoding vector, and cascading the user identity identifier one-hot encoding vector, the request operation type one-hot encoding vector, and the request context information semantic encoding vector to obtain a request basic information structured encoding vector includes: Performing one-hot encoding on the user identity identifier and the request operation type to obtain a user identity identifier one-hot encoding vector and a request operation type one-hot encoding vector; Performing semantic encoding on the request context information based on Bert to obtain a request context information semantic encoding vector; Cascade the user identity one-hot encoded vector, the request operation type one-hot encoded vector, and the request context information semantic encoded vector to obtain the request basic information structured encoded vector.

4. The method for secure access to mobile applications based on randomness according to claim 3, characterized in that, Semantically encode the real-time security threat intelligence to obtain a real-time security threat intelligence semantic encoded vector, including: performing the semantic encoding based on Bert on the real-time security threat intelligence to obtain the real-time security threat intelligence semantic encoded vector.

5. The randomness-based mobile application security access method according to claim 4, wherein Perform request-security intelligence real-time soft constraint-driven dynamic response analysis on the request basic information structured encoded vector and the real-time security threat intelligence semantic encoded vector to obtain a request-security intelligence real-time dynamic response encoded vector, including: Perform principal component analysis on the real-time security threat intelligence semantic encoded vector to obtain a set of real-time security threat intelligence semantic principal component encoded vectors; Perform linear transformation on each real-time security threat intelligence semantic principal component encoded vector in the set of real-time security threat intelligence semantic principal component encoded vectors to obtain a set of real-time security threat intelligence semantic principal component linear transformation encoded vectors; Perform dynamic adaptive aggregation based on soft constraint factor weighting on the request basic information structured encoded vector and the set of real-time security threat intelligence semantic principal component linear transformation encoded vectors to obtain the request-security intelligence real-time dynamic response encoded vector.

6. The randomness-based mobile application security access method according to claim 5, wherein Each real-time security threat intelligence semantic principal component linear transformation encoded vector in the set of real-time security threat intelligence semantic principal component linear transformation encoded vectors has the same feature scale as the request basic information structured encoded vector.

7. The randomness-based mobile application security access method according to claim 6, characterized in that Perform dynamic adaptive aggregation based on soft constraint factor weighting on the request basic information structured encoded vector and the set of real-time security threat intelligence semantic principal component linear transformation encoded vectors to obtain the request-security intelligence real-time dynamic response encoded vector, including: Perform inter-modal independence modeling on each real-time security threat intelligence semantic principal component linear transformation encoded vector in the set of the request basic information structured encoded vector and the real-time security threat intelligence semantic principal component linear transformation encoded vectors to obtain a set of request-security intelligence principal component inter-modal independence semantic encoded matrices; Based on the set of request-security intelligence principal component inter-modal independence semantic encoded matrices, calculate a set of request-security intelligence principal component inter-modal independence semantic soft constraint factors; Perform semantic feature interaction response on each real-time security threat intelligence semantic principal component linear transformation encoded vector in the set of the request basic information structured encoded vector and the real-time security threat intelligence semantic principal component linear transformation encoded vectors to obtain a set of request-security intelligence principal component inter-modal fine-grained semantic response interaction encoded vectors; Based on the set of request-security intelligence principal component inter-modal independence semantic soft constraint factors, perform dynamic adaptive aggregation on the set of request-security intelligence principal component inter-modal fine-grained semantic response interaction encoded vectors to obtain the request-security intelligence real-time dynamic response encoded vector.

8. The method for secure access to a mobile application based on randomness according to claim 7, wherein Based on the set of request-security intelligence principal component modal independence semantic encoding matrices, calculate the set of request-security intelligence principal component modal independence semantic soft constraint factors, including: Perform global association optimization based on topological gauge fields on each request-security intelligence principal component modal independence semantic encoding matrix in the set of request-security intelligence principal component modal independence semantic encoding matrices to obtain a set of optimized request-security intelligence principal component modal independence semantic encoding matrices; Calculate the square of the Frobenius norm of each optimized request-security intelligence principal component modal independence semantic encoding matrix in the set of optimized request-security intelligence principal component modal independence semantic encoding matrices to obtain the set of request-security intelligence principal component modal independence semantic soft constraint factors.

9. The method for secure access to a mobile application based on randomness according to claim 8, characterized in that, Based on the request-security intelligence real-time dynamic response encoding features, obtain the request risk assessment result, including: inputting the request-security intelligence real-time dynamic response encoding vector into a risk assessment engine based on a classifier to obtain the request risk assessment result.

Citation Information

Cited By

  • Automatic sensor calibration management system and method based on data visualization

    CN120313759A

  • Power equipment operation state monitoring method and system based on automatic operation and maintenance

    CN120316569A

  • System and method for dynamically evaluating social risk of community correction object

    CN120851612A