Identity authentication and access control system and method for 5G-A terminal
The system streamlines 5G-A terminal authentication by analyzing user habits to classify and control access, improving efficiency and security through automated identity authentication.
Patent Information
- Application Number
- CN202510778657.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-07-15
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing 5G-A terminal's identity authentication and access control systems require separate identity authentication operations when users enter the operating system, resulting in inefficiency and increased operational complexity, and the risk of password forgetting.
By obtaining multiple historical user usage data, analyzing user operations similarity, marking common operations and weights, creating a boot identity authentication cycle, combining real-time user operations to calculate the identity authentication coefficient, dividing user types and executing permission control.
It improves the operating efficiency and security of 5G-A terminals, improves the user experience, and realizes the intelligence of identity authentication.
Smart Images

Figure CN120321032A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security, relates to identity authentication technology, and specifically is an identity authentication and access control system and method for 5G-A terminals. Background Art
[0002] When the existing identity authentication and access control system for 5G-A terminals performs identity authentication and access control, it has the following specific defects: 1. The existing identity authentication and access control system for 5G-A terminals needs to perform a separate identity authentication operation when the user enters the operating system, resulting in low efficiency for the user to enter the operating system, and thus being unfavorable for improving the working efficiency of 5G-A terminals; 2. The existing identity authentication and access control system for 5G-A terminals needs to perform a separate account password login operation when the user enters the operating system, increasing the complexity of user operations and having the risk of forgetting the password.
[0003] Therefore, we propose an identity authentication and access control system and method for 5G-A terminals. Summary of the Invention
[0004] Aiming at the deficiencies of the existing technology, the purpose of the present invention is to provide an identity authentication and access control system and method for 5G-A terminals. The present invention is based on respectively obtaining a plurality of historical user usage data, marking a user identity authentication cycle in each historical user usage data, obtaining a plurality of common operations and the corresponding common operation weights and common operation reference durations for each common operation by performing user operation similarity analysis on each user identity authentication cycle to obtain historical user cycle collection data, creating a power-on identity authentication cycle, performing identity authentication on the real-time user by analyzing the operations of the real-time user within the power-on identity authentication cycle and combining the historical user cycle collection data to obtain the identity authentication coefficient of the real-time user within the power-on identity authentication cycle, obtaining an identity authentication coefficient threshold and performing a numerical comparison with the identity authentication coefficient of the real-time user within the power-on identity authentication cycle, classifying the real-time user into a first identity type user and a second identity type user according to the numerical comparison, performing login password verification on the second identity type user, further refining the identity of the second identity type user according to the verification result to obtain real-time user identity classification data, and performing permission control on the real-time user according to the real-time user identity classification data.
[0005] In order to achieve the above purpose, the present invention adopts the following technical solution: An identity authentication and access control system for 5G-A terminals, and the specific working processes of each module are as follows: Data acquisition module: used to respectively acquire multiple historical user usage data, mark a user identity authentication period in each historical user usage data, and obtain multiple common operations, the corresponding common operation weights, and the corresponding common operation benchmark durations for each common operation by performing user operation similarity analysis on each user identity authentication period, so as to obtain historical user cycle acquisition data; Identity authentication module: used to create a power-on identity authentication period, authenticate the real-time user by analyzing the operations of the real-time user during the power-on identity authentication period and combining the historical user cycle acquisition data, so as to obtain the identity authentication coefficient of the real-time user during the power-on identity authentication period; Access control module: used to compare the obtained identity authentication coefficient threshold with the identity authentication coefficient of the real-time user during the power-on identity authentication period numerically, divide the real-time user into a first identity type user and a second identity type user according to the numerical comparison, verify the login password of the second identity type user, further refine the identity of the second identity type user according to the verification result to obtain real-time user identity classification data, and perform permission control on the real-time user according to the real-time user identity classification data.
[0006] Further, the data acquisition module acquires the historical user cycle acquisition data as follows: Acquire multiple historical user usage data corresponding to the target 5G-A terminal, and randomly select one historical user usage data from the multiple historical user usage data as the sample historical user usage data; In the sample historical user usage data, mark the time point when the customer initially accesses the 5G-A terminal as the first characteristic time point, mark the time point corresponding to the next characteristic access period after the first characteristic time point as the second characteristic time point, mark the period between the first characteristic time point and the second characteristic time point as the user identity authentication period corresponding to the sample historical user usage data, and name the user identity authentication period corresponding to the sample historical user usage data as the sample user identity authentication period; Repeat the process of obtaining the user identity authentication period corresponding to the sample historical user usage data, respectively obtain the user identity authentication periods corresponding to each historical user usage data, and obtain multiple user identity authentication periods; Count the number of the obtained multiple user identity authentication periods to obtain the user cycle quantity value; Obtain the first common operation to the a-th common operation; Obtain the first common operation weight to the a-th common operation weight; Obtain the first common operation benchmark duration to the a-th common operation benchmark duration; Define the first common operation to the a-th common operation, the first common operation weight to the a-th common operation weight, and the first common operation benchmark duration to the a-th common operation benchmark duration as historical user cycle collection data.
[0007] Further, the data acquisition module acquires the first common operation to the a-th common operation as follows: Obtain the operation names corresponding to the first function operation in each user identity authentication cycle respectively, to get multiple function operation names, and count the number of name repetitions of the obtained multiple function operation names. Mark the function operation name with the highest repetition number as the first common operation; Obtain the operation names corresponding to the second function operation in each user identity authentication cycle respectively, to get multiple function operation names, and count the name repetition rate of the obtained multiple function operation names. Mark the function operation name with the highest repetition number as the second common operation; By analogy, obtain the operation names corresponding to the a-th function operation in each user identity authentication cycle respectively, to get multiple function operation names, and count the name repetition rate of the obtained multiple function operation names. Mark the function operation name with the highest repetition number as the a-th common operation.
[0008] Further, the data acquisition module acquires the first common operation weight to the a-th common operation weight as follows: Obtain the number of name repetitions corresponding to the first common operation to get the first repetition number, and calculate the ratio of the first repetition number to the user cycle quantity value to obtain the first common operation weight; Obtain the number of name repetitions corresponding to the second common operation to get the second repetition number, and calculate the ratio of the second repetition number to the user cycle quantity value to obtain the second common operation weight; By analogy, obtain the number of name repetitions corresponding to the a-th common operation to get the a-th repetition number, and calculate the ratio of the a-th repetition number to the user cycle quantity value to obtain the a-th common operation weight.
[0009] Further, the data acquisition module acquires the first common operation benchmark duration to the a-th common operation benchmark duration as follows: Respectively obtain the operation durations corresponding to the first common operation in each user identity authentication cycle to get multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the first common operation benchmark duration; Respectively obtain the operation durations corresponding to the second common operation in each user identity authentication cycle to get multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the second common operation benchmark duration; By analogy, obtain the operation duration corresponding to the a-th common operation in each user identity authentication cycle respectively, obtain multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the a-th common operation benchmark duration.
[0010] Furthermore, the identity authentication module obtains the identity authentication coefficient as follows: Obtain the historical user cycle collection data, and respectively obtain the first common operation to the a-th common operation, the first common operation weight to the a-th common operation weight, and the first common operation benchmark duration to the a-th common operation benchmark duration according to the historical user cycle collection data; Mark the time point when the target 5G-A terminal enters the working state from the standby state as the identity authentication start time point, mark the time point corresponding to a characteristic working duration after the identity authentication start time point as the identity authentication end time point, and mark the interval period between the identity authentication start time point and the identity authentication end time point as the boot identity authentication cycle; During the boot identity authentication cycle, obtain several device operations of the 5G-A terminal by the real-time user, and respectively name the several device operations as the first device operation to the a-th device operation according to the sequence of the device operation time; Obtain the first device operation weight to the a-th device operation weight; Respectively obtain the device operation durations corresponding to the first device operation to the a-th device operation during the boot identity authentication cycle to obtain the first device operation duration to the a-th device operation duration; Calculate the identity authentication coefficient of the real-time user during the boot identity authentication cycle by calculating the first common operation benchmark duration to the a-th common operation benchmark duration, the first device operation duration to the a-th device operation duration, and the first device operation weight to the a-th device operation weight; Calculate the identity authentication coefficient, and the specific formula is as follows: ; Wherein, Rzx is the identity authentication coefficient of the real-time user during the boot identity authentication cycle, Sj c1 to Sj ca are respectively the first device operation duration to the a-th device operation duration, Sj j1 to Sj ja are respectively the first common operation benchmark duration to the a-th common operation benchmark duration, and Cq z1 to Cq za are respectively the first device operation weight to the a-th device operation weight.
[0011] Furthermore, the identity authentication module obtains the first device operation weight to the a-th device operation weight as follows: When the operation of the first device is the same as the first common operation, the weight of the first common operation is marked as the weight of the first device operation. When the operation of the first device is not the same as the first common operation, the weight of the first device operation is parameter-assigned with the value 0 to obtain the weight of the first device operation; When the operation of the second device is the same as the second common operation, the weight of the second common operation is marked as the weight of the second device operation. When the operation of the second device is not the same as the second common operation, the weight of the second device operation is parameter-assigned with the value 0 to obtain the weight of the second device operation; By analogy, when the operation of the a-th device is the same as the a-th common operation, the weight of the a-th common operation is marked as the weight of the a-th device operation. When the operation of the a-th device is not the same as the a-th common operation, the weight of the a-th device operation is parameter-assigned with the value 0 to obtain the weight of the a-th device operation.
[0012] Furthermore, the access control module performs permission control on real-time users as follows: Obtain the identity authentication coefficient of the real-time user within the power-on identity authentication cycle; Obtain the historical user cycle collection data, and respectively obtain the first common operation weight to the a-th common operation weight and the first common operation reference duration to the a-th common operation reference duration according to the historical user cycle collection data; Obtain the identity authentication coefficient threshold; Specifically as follows: Obtain the first device operation reference duration to the a-th device operation reference duration; Calculate the identity authentication coefficient threshold through the first device operation reference duration to the a-th device operation reference duration, the first common operation weight to the a-th common operation weight, and the first common operation reference duration to the a-th common operation reference duration; Calculate the identity authentication coefficient threshold, and the specific formula is as follows: ; Among them, Rzxy is the identity authentication coefficient threshold, Spc1 to Spca are respectively the first device operation reference duration to the a-th device operation reference duration, Sjj1 to Sjja are respectively the first common operation reference duration to the a-th common operation reference duration, and Cgz1 to Cgza are respectively the first common operation weight to the a-th common operation weight; Compare the identity authentication coefficient with the identity authentication coefficient threshold, and obtain the real-time classification data of the user identity according to the result of the numerical comparison; Perform permission control on the real-time user according to the real-time classification data of the user identity; Specifically as follows: When the real-time user is a user of the first identity type, access permission to the target 5G-A terminal is provided to the real-time user; When the real-time user is a user of the second identity type, access permission to the target 5G-A terminal is closed for the real-time user.
[0013] Furthermore, the access control module obtains real-time classification data of user identities as follows: When the identity authentication coefficient is less than or equal to the identity authentication coefficient threshold, the real-time user is classified as a user of the first identity type; When the identity authentication coefficient is greater than the identity authentication coefficient threshold, the real-time user is classified as a user of the second identity type; When the real-time user is a user of the second identity type, the target 5G-A terminal provides a password input window to verify the password of the real-time user. If the password verification is passed, the user of the second identity type is reclassified as a user of the first identity type. If the password verification fails, the real-time user continues to be classified as a user of the second identity type.
[0014] An identity authentication and access control method for a 5G-A terminal includes the following specific steps: Step S1: Obtain multiple historical user usage data respectively, mark a user identity authentication cycle in each historical user usage data, and obtain multiple common operations, the corresponding common operation weights, and the common operation benchmark durations of each common operation by analyzing the user operation similarity of each user identity authentication cycle, so as to obtain historical user cycle collection data; Step S2: Create a power-on identity authentication cycle, authenticate the real-time user by analyzing the operations of the real-time user during the power-on identity authentication cycle and combining the historical user cycle collection data, and obtain the identity authentication coefficient of the real-time user during the power-on identity authentication cycle; Step S3: Compare the identity authentication coefficient threshold with the identity authentication coefficient of the real-time user during the power-on identity authentication cycle through numerical comparison, classify the real-time user into a user of the first identity type and a user of the second identity type according to the numerical comparison, verify the login password of the user of the second identity type, further refine the identity of the user of the second identity type according to the verification result, obtain real-time classification data of user identities, and perform permission control on the real-time user according to the real-time classification data of user identities.
[0015] In summary, due to the adoption of the above technical solutions, the beneficial effects of the present invention are: 1. The present invention collects user operation habits by obtaining historical user cycle collection data, and performs identity authentication and access control system control according to user operation habits, which can improve the operation efficiency and use security of the 5G-A terminal; 2. The present invention performs identity authentication and access control by analyzing the identity authentication coefficient of real-time users within the boot identity authentication cycle, which can improve the terminal experience of users and realize the intelligent identity authentication of 5G-A terminals. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] For the convenience of those skilled in the art to understand, the present invention will be further described below with reference to the accompanying drawings.
[0017] Figure 1 is the overall system block diagram of the present invention; Figure 2 is the implementation step diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0019] Embodiment 1 Please refer to Figure 1 , the present invention provides a technical solution: an identity authentication and access control system for 5G-A terminals, including a data acquisition module, an identity authentication module, an access control module, and a server. The data acquisition module, the identity authentication module, and the access control module are respectively connected to the server, and the server controls the data acquisition module, the identity authentication module, and the access control module respectively; The data acquisition module respectively acquires a plurality of historical user usage data, marks a user identity authentication cycle in each historical user usage data, and obtains a plurality of common operations, the corresponding common operation weights, and the common operation reference durations of each common operation by analyzing the user operation similarity of each user identity authentication cycle, so as to obtain historical user cycle acquisition data.
[0020] Acquire a plurality of historical user usage data corresponding to the target 5G-A terminal, and randomly select one historical user usage data from the plurality of historical user usage data as the sample historical user usage data; In the sample historical user usage data, mark the time point when the customer initially accesses the 5G-A terminal as the first characteristic time point, mark the time point corresponding to the next characteristic access period after the first characteristic time point as the second characteristic time point, mark the period between the first characteristic time point and the second characteristic time point as the user identity authentication cycle corresponding to the sample historical user usage data, and name the user identity authentication cycle corresponding to the sample historical user usage data as the sample user identity authentication cycle; It should be noted here that: In this application, the 5G-A terminal involved here is specifically a terminal device that applies advanced 5G technology in the office field. The 5G-A terminal involved here includes but is not limited to enterprise public computers, shared network printers, and integrated development environments; Multiple pieces of sample historical user usage data involved here are all target user access data corresponding to the target 5G-A terminal; Repeat the process of obtaining the user identity authentication period corresponding to the sample historical user usage data, and obtain the user identity authentication periods corresponding to each piece of historical user usage data respectively, to obtain multiple user identity authentication periods; Count the number of the obtained multiple user identity authentication periods to obtain the user cycle quantity value; Obtain the first common operation to the a-th common operation; Specifically as follows: Obtain the operation names corresponding to the first function operation in each user identity authentication period respectively, to obtain multiple function operation names, and count the name repetition times of the obtained multiple function operation names, and mark the function operation name with the highest repetition times as the first common operation; Obtain the operation names corresponding to the second function operation in each user identity authentication period respectively, to obtain multiple function operation names, and count the name repetition rate of the obtained multiple function operation names, and mark the function operation name with the highest repetition times as the second common operation; By analogy, obtain the operation names corresponding to the a-th function operation in each user identity authentication period respectively, to obtain multiple function operation names, and count the name repetition rate of the obtained multiple function operation names, and mark the function operation name with the highest repetition times as the a-th common operation; It should be noted here that: In this application, a is the quantity value corresponding to the counted common operations, and a is an integer greater than 0; Obtain the first common operation weight to the a-th common operation weight; Specifically as follows: Obtain the name repetition times corresponding to the first common operation to obtain the first repetition times, calculate the ratio of the first repetition times to the user cycle quantity value, and obtain the first common operation weight; Obtain the name repetition times corresponding to the second common operation to obtain the second repetition times, calculate the ratio of the second repetition times to the user cycle quantity value, and obtain the second common operation weight; By analogy, obtain the name repetition times corresponding to the a-th common operation to obtain the a-th repetition times, calculate the ratio of the a-th repetition times to the user cycle quantity value, and obtain the a-th common operation weight; Obtain the first common operation reference duration to the a-th common operation reference duration; Specifically as follows: Respectively obtain the operation duration corresponding to the first common operation in each user authentication cycle, obtain multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the first common operation reference duration; Respectively obtain the operation duration corresponding to the second common operation in each user authentication cycle, obtain multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the second common operation reference duration; And so on, respectively obtain the operation duration corresponding to the a-th common operation in each user authentication cycle, obtain multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the a-th common operation reference duration; Define the first common operation to the a-th common operation, the first common operation weight to the a-th common operation weight, and the first common operation reference duration to the a-th common operation reference duration as historical user cycle collection data; The data acquisition module acquires the historical user cycle collection data and transports it to the identity authentication module; The identity authentication module creates a power-on identity authentication cycle, authenticates the real-time user by analyzing the operations of the real-time user during the power-on identity authentication cycle and combining the historical user cycle collection data, and obtains the identity authentication coefficient of the real-time user during the power-on identity authentication cycle; Obtain the historical user cycle collection data, and respectively obtain the first common operation to the a-th common operation, the first common operation weight to the a-th common operation weight, and the first common operation reference duration to the a-th common operation reference duration according to the historical user cycle collection data; Mark the time point when the target 5G-A terminal enters the working state from the standby state as the identity authentication start time point, mark the time point corresponding to a characteristic working duration after the identity authentication start time point as the identity authentication end time point, and mark the interval period between the identity authentication start time point and the identity authentication end time point as the power-on identity authentication cycle; It should be noted here that: The standby state involved here is a state where there is no user operating the device, and the working state involved here is a state where there is a user operating the device; During the power-on identity authentication cycle, obtain several device operations of the real-time user on the 5G-A terminal, and respectively name the several device operations as the first device operation to the a-th device operation according to the sequence of the device operation time; It should be noted here that: In this application, a is the value of the number of device operations of the real-time user within the boot identity authentication cycle, and a is an integer greater than 0, and the value of the number of device operations here is the same as the corresponding value of the number of common operations; When the first device operation and the first common operation are the same operation, then mark the weight of the first common operation as the weight of the first device operation. When the first device operation and the first common operation are not the same operation, then assign the parameter of the weight of the first device operation with the value 0 to obtain the weight of the first device operation; When the second device operation and the second common operation are the same operation, then mark the weight of the second common operation as the weight of the second device operation. When the second device operation and the second common operation are not the same operation, then assign the parameter of the weight of the second device operation with the value 0 to obtain the weight of the second device operation; And so on. When the a-th device operation and the a-th common operation are the same operation, then mark the weight of the a-th common operation as the weight of the a-th device operation. When the a-th device operation and the a-th common operation are not the same operation, then assign the parameter of the weight of the a-th device operation with the value 0 to obtain the weight of the a-th device operation; Respectively obtain the device operation durations corresponding to the first device operation to the a-th device operation within the boot identity authentication cycle to obtain the first device operation duration to the a-th device operation duration; Calculate the identity authentication coefficient of the real-time user within the boot identity authentication cycle through the first common operation reference duration to the a-th common operation reference duration, the first device operation duration to the a-th device operation duration, and the first device operation weight to the a-th device operation weight.
[0021] Calculate the identity authentication coefficient, and the specific formula is as follows: ; Among them, Rzx is the identity authentication coefficient of the real-time user within the boot identity authentication cycle, Sj c1 to Sj ca are the first device operation duration to the a-th device operation duration respectively, Sj j1 to Sj ja are the first common operation reference duration to the a-th common operation reference duration respectively, and Cq z1 to Cq za are the first device operation weight to the a-th device operation weight respectively; The identity authentication module obtains the identity authentication coefficient and transmits it to the access control module; The access control module compares the obtained identity authentication coefficient threshold with the identity authentication coefficient of the real-time user within the power-on identity authentication cycle. Based on the numerical comparison, the real-time user is classified into the first identity type user and the second identity type user. The login password of the second identity type user is verified, and based on the verification result, the second identity type user is further refined in terms of identity to obtain real-time user identity classification data, and the real-time user is controlled for permissions according to the real-time user identity classification data; Obtain the identity authentication coefficient of the real-time user within the power-on identity authentication cycle; Obtain the historical user cycle collection data, and respectively obtain the first common operation weight to the a-th common operation weight and the first common operation reference duration to the a-th common operation reference duration according to the historical user cycle collection data; Obtain the identity authentication coefficient threshold; Specifically as follows: Obtain the first device operation reference duration to the a-th device operation reference duration; Calculate the identity authentication coefficient threshold from the first device operation reference duration to the a-th device operation reference duration, the first common operation weight to the a-th common operation weight, and the first common operation reference duration to the a-th common operation reference duration; Calculate the identity authentication coefficient threshold, and the specific formula is as follows: ; Among them, Rzxy is the identity authentication coefficient threshold, Spc1 to Spca are the first device operation reference duration to the a-th device operation reference duration respectively, Sjj1 to Sjja are the first common operation reference duration to the a-th common operation reference duration respectively, and Cgz1 to Cgza are the first common operation weight to the a-th common operation weight respectively; Compare the identity authentication coefficient with the identity authentication coefficient threshold, and obtain the real-time user identity classification data according to the numerical comparison result.
[0022] Specifically as follows: When the identity authentication coefficient is less than or equal to the identity authentication coefficient threshold, the real-time user is classified into the first identity type user; When the identity authentication coefficient is greater than the identity authentication coefficient threshold, the real-time user is classified into the second identity type user; When the real-time user is a second identity type user, the target 5G-A terminal provides a password input window to verify the password of the real-time user. If the password verification is passed, the second identity type user is reclassified into the first identity type user. If the password verification fails, the real-time user is continued to be classified into the second identity type user; Control the permissions of the real-time user according to the real-time user identity classification data.
[0023] The details are as follows: When the real-time user is a user of the first identity type, access permission to the target 5G-A terminal is provided to the real-time user; When the real-time user is a user of the second identity type, access permission to the target 5G-A terminal is closed for the real-time user.
[0024] In this application, if there are corresponding calculation formulas, the above calculation formulas are all dimensionless and take their numerical values for calculation. Coefficients such as weight coefficients and proportionality coefficients in the formulas are set to obtain a result value by quantifying each parameter. Regarding the magnitudes of the weight coefficients and proportionality coefficients, as long as the proportional relationship between the parameters and the result value is not affected.
[0025] Embodiment 2 Please refer to Figure 2 , based on another concept of the same invention, a method for identity authentication and access control of a 5G-A terminal is proposed, including the following steps: Step S1: Obtain multiple historical user usage data respectively, mark a user identity authentication cycle in each historical user usage data, and obtain multiple common operations, the corresponding common operation weights, and the common operation reference duration for each common operation by analyzing the similarity of user operations for each user identity authentication cycle, so as to obtain historical user cycle collection data; Step S11: Obtain multiple historical user usage data corresponding to the target 5G-A terminal, and randomly select one historical user usage data from the multiple historical user usage data as the sample historical user usage data; Step S12: In the sample historical user usage data, mark the time point when the customer initially accesses the 5G-A terminal as the first characteristic time point, mark the time point corresponding to the next characteristic access period after the first characteristic time point as the second characteristic time point, mark the period between the first characteristic time point and the second characteristic time point as the user identity authentication cycle corresponding to the sample historical user usage data, and name the user identity authentication cycle corresponding to the sample historical user usage data as the sample user identity authentication cycle; Step S13: Repeat the process of obtaining the user identity authentication cycle corresponding to the sample historical user usage data, and obtain the user identity authentication cycles corresponding to each historical user usage data respectively, so as to obtain multiple user identity authentication cycles; Step S14: Count the number of the obtained multiple user identity authentication cycles to obtain the user cycle quantity value; Step S15: Obtain the first common operation to the a-th common operation; The details are as follows: Step S151: Obtain the operation names corresponding to the first functional operations in each user authentication cycle respectively, to get multiple functional operation names, and count the number of name repetitions of the obtained multiple functional operation names. Mark the functional operation name with the highest repetition number as the first common operation; Step S152: Obtain the operation names corresponding to the second functional operations in each user authentication cycle respectively, to get multiple functional operation names, and count the name repetition rate of the obtained multiple functional operation names. Mark the functional operation name with the highest repetition number as the second common operation; By analogy, for step S153, obtain the operation names corresponding to the a-th functional operations in each user authentication cycle respectively, to get multiple functional operation names, and count the name repetition rate of the obtained multiple functional operation names. Mark the functional operation name with the highest repetition number as the a-th common operation.
[0026] Step S16: Obtain the weights of the first common operation to the a-th common operation; Specifically as follows: Step S161: Obtain the number of name repetitions corresponding to the first common operation to get the first repetition number, and calculate the ratio of the first repetition number to the number value of the user cycle to obtain the weight of the first common operation; Step S162: Obtain the number of name repetitions corresponding to the second common operation to get the second repetition number, and calculate the ratio of the second repetition number to the number value of the user cycle to obtain the weight of the second common operation; By analogy, for step S164, obtain the number of name repetitions corresponding to the a-th common operation to get the a-th repetition number, and calculate the ratio of the a-th repetition number to the number value of the user cycle to obtain the weight of the a-th common operation; Step S17: Obtain the reference durations of the first common operation to the a-th common operation.
[0027] Specifically as follows: Step S171: Respectively obtain the operation durations corresponding to the first common operation in each user authentication cycle to get multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the reference duration of the first common operation; Step S172: Respectively obtain the operation durations corresponding to the second common operation in each user authentication cycle to get multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the reference duration of the second common operation; Step S173: By analogy, obtain the operation duration corresponding to the a-th common operation in each user identity authentication cycle respectively, get multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the a-th common operation benchmark duration; Step S18: Define the first common operation to the a-th common operation, the first common operation weight to the a-th common operation weight, and the first common operation benchmark duration to the a-th common operation benchmark duration as historical user cycle collection data; Step S2: Create a power-on identity authentication cycle, authenticate the real-time user by analyzing the operations of the real-time user during the power-on identity authentication cycle and combining the historical user cycle collection data, and obtain the identity authentication coefficient of the real-time user during the power-on identity authentication cycle; Step S21: Obtain the historical user cycle collection data, and respectively obtain the first common operation to the a-th common operation, the first common operation weight to the a-th common operation weight, and the first common operation benchmark duration to the a-th common operation benchmark duration according to the historical user cycle collection data; Step S22: Mark the time point when the target 5G-A terminal enters the working state from the standby state as the identity authentication start time point, mark the time point corresponding to a characteristic working duration after the identity authentication start time point as the identity authentication end time point, and mark the interval period between the identity authentication start time point and the identity authentication end time point as the power-on identity authentication cycle; Step S23: During the power-on identity authentication cycle, obtain several device operations of the real-time user on the 5G-A terminal, and name the several device operations as the first device operation to the a-th device operation in sequence according to the time order of the device operations; Step S24: Obtain the first device operation weight to the a-th device operation weight.
[0028] Specifically as follows: Step S241: When the first device operation is the same as the first common operation, mark the first common operation weight as the first device operation weight. When the first device operation is not the same as the first common operation, assign the parameter value 0 to the first device operation weight to obtain the first device operation weight; Step S242: When the second device operation is the same as the second common operation, mark the second common operation weight as the second device operation weight. When the second device operation is not the same as the second common operation, assign the parameter value 0 to the second device operation weight to obtain the second device operation weight; Step S243: And so on. When the operation of the a-th device is the same as the a-th common operation, mark the weight of the a-th common operation as the weight of the a-th device operation. When the operation of the a-th device is not the same as the a-th common operation, assign the parameter of the weight of the a-th device operation with the value 0 to obtain the weight of the a-th device operation; Step S25: Respectively obtain the device operation durations corresponding to the first device operation to the a-th device operation within the boot identity authentication cycle, and obtain the first device operation duration to the a-th device operation duration; Step S26: Calculate the identity authentication coefficient of the real-time user within the boot identity authentication cycle through the first common operation reference duration to the a-th common operation reference duration, the first device operation duration to the a-th device operation duration, and the first device operation weight to the a-th device operation weight.
[0029] Calculate the identity authentication coefficient. The specific formula is as follows: ; Among them, Rzx is the identity authentication coefficient of the real-time user within the boot identity authentication cycle, Sj c1 to Sj ca are the first device operation duration to the a-th device operation duration respectively, Sj j1 to Sj ja are the first common operation reference duration to the a-th common operation reference duration respectively, and Cq z1 to Cq za are the first device operation weight to the a-th device operation weight respectively; Step S3: Compare the obtained identity authentication coefficient threshold with the identity authentication coefficient of the real-time user within the boot identity authentication cycle. According to the numerical comparison, divide the real-time user into the first identity type user and the second identity type user, verify the login password of the second identity type user, further refine the identity of the second identity type user according to the verification result to obtain the real-time user identity classification data, and perform permission control on the real-time user according to the real-time user identity classification data; Step S31: Obtain the identity authentication coefficient of the real-time user within the boot identity authentication cycle; Step S32: Obtain the historical user cycle collection data, and respectively obtain the first common operation weight to the a-th common operation weight and the first common operation reference duration to the a-th common operation reference duration according to the historical user cycle collection data; Step S33: Obtain the identity authentication coefficient threshold.
[0030] Specifically as follows: Step S331: Obtain the first device operation reference duration to the a-th device operation reference duration; Step S332: Calculate the identity authentication coefficient threshold by using the first device operation reference duration up to the a-th device operation reference duration, the first common operation weight up to the a-th common operation weight, and the first common operation reference duration up to the a-th common operation reference duration; Calculate the identity authentication coefficient threshold, and the specific formula is as follows: ; Wherein, Rzxy is the identity authentication coefficient threshold, Spc1 to Spca are respectively the first device operation reference duration up to the a-th device operation reference duration, Sjj1 to Sjja are respectively the first common operation reference duration up to the a-th common operation reference duration, and Cgz1 to Cgza are respectively the first common operation weight up to the a-th common operation weight; Step S34: Compare the identity authentication coefficient with the identity authentication coefficient threshold, and obtain the real-time classification data of the user identity according to the result of the numerical comparison; Specifically as follows: Step S341: When the identity authentication coefficient is less than or equal to the identity authentication coefficient threshold, classify the real-time user as a user of the first identity type; Step S342: When the identity authentication coefficient is greater than the identity authentication coefficient threshold, classify the real-time user as a user of the second identity type; Step S343: When the real-time user is a user of the second identity type, the target 5G-A terminal provides a password input window to verify the password of the real-time user. If the password verification is passed, re-classify the user of the second identity type as a user of the first identity type. If the password verification fails, continue to classify the real-time user as a user of the second identity type; Step S35: Perform permission control on the real-time user according to the real-time classification data of the user identity; Specifically as follows: Step S351: When the real-time user is a user of the first identity type, provide the access permission of the target 5G-A terminal to the real-time user; Step S352: When the real-time user is a user of the second identity type, close the access permission of the target 5G-A terminal to the real-time user.
[0031] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the present invention to only the specific implementation manners. Obviously, many modifications and changes can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principle and practical application of the present invention, so that those skilled in the art in the relevant technical field can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. An identity authentication and access control system for a 5G-A terminal, characterized in that, Including: A data acquisition module: used to respectively acquire multiple historical user usage data, mark a user identity authentication cycle in each historical user usage data, and obtain multiple common operations, the corresponding common operation weights, and the corresponding common operation benchmark durations for each common operation by performing user operation similarity analysis on each user identity authentication cycle, so as to obtain historical user cycle acquisition data; An identity authentication module: used to create a boot identity authentication cycle, authenticate the real-time user by analyzing the operations of the real-time user within the boot identity authentication cycle and combining the historical user cycle acquisition data, and obtain the identity authentication coefficient of the real-time user within the boot identity authentication cycle; An access control module: used to compare the obtained identity authentication coefficient threshold with the identity authentication coefficient of the real-time user within the boot identity authentication cycle numerically, divide the real-time user into a first identity type user and a second identity type user according to the numerical comparison, verify the login password of the second identity type user, further refine the identity of the second identity type user according to the verification result to obtain real-time user identity classification data, and perform permission control on the real-time user according to the real-time user identity classification data.
2. The identity authentication and access control system for a 5G-A terminal according to claim 1, characterized in that, The data acquisition module acquires the historical user cycle acquisition data as follows: Acquire multiple historical user usage data corresponding to the target 5G-A terminal, and randomly select one historical user usage data from the multiple historical user usage data as the sample historical user usage data; In the sample historical user usage data, mark the time point when the customer initially accesses the 5G-A terminal as the first characteristic time point, mark the time point corresponding to one characteristic access period after the first characteristic time point as the second characteristic time point, mark the period between the first characteristic time point and the second characteristic time point as the user identity authentication cycle corresponding to the sample historical user usage data, and name the user identity authentication cycle corresponding to the sample historical user usage data as the sample user identity authentication cycle; Repeat the process of obtaining the user identity authentication cycle corresponding to the sample historical user usage data, and respectively obtain the user identity authentication cycles corresponding to each historical user usage data to obtain multiple user identity authentication cycles; Count the number of the obtained multiple user identity authentication cycles to obtain the user cycle quantity value; Obtain the first common operation to the a-th common operation; Obtain the first common operation weight to the a-th common operation weight; Obtain the first common operation benchmark duration to the a-th common operation benchmark duration; Define the first common operation to the a-th common operation, the first common operation weight to the a-th common operation weight, and the first common operation benchmark duration to the a-th common operation benchmark duration as the historical user cycle acquisition data.
3. The identity authentication and access control system for a 5G-A terminal according to claim 2, characterized in that, The data acquisition module acquires the first common operation to the a-th common operation as follows: Respectively obtain the operation names corresponding to the first function operation in each user identity authentication cycle to obtain multiple function operation names, count the number of times the names are repeated for the obtained multiple function operation names, and mark the function operation name with the highest repetition number as the first common operation; Obtain the operation names corresponding to the second functional operations in each user authentication cycle respectively, to obtain multiple functional operation names, and perform a name duplication rate statistics on the obtained multiple functional operation names, and mark the functional operation name with the highest number of repetitions as the second common operation; And so on, obtain the operation names corresponding to the a-th functional operation in each user authentication cycle respectively, to obtain multiple functional operation names, and perform a name duplication rate statistics on the obtained multiple functional operation names, and mark the functional operation name with the highest number of repetitions as the a-th common operation.
4. The identity authentication and access control system for a 5G-A terminal according to claim 2, wherein The data acquisition module obtains the first common operation weight to the a-th common operation weight, specifically as follows: Obtain the number of repetitions of the name corresponding to the first common operation to obtain the first number of repetitions, calculate the ratio of the first number of repetitions to the user cycle quantity value, and obtain the first common operation weight; Obtain the number of repetitions of the name corresponding to the second common operation to obtain the second number of repetitions, calculate the ratio of the second number of repetitions to the user cycle quantity value, and obtain the second common operation weight; And so on, obtain the number of repetitions of the name corresponding to the a-th common operation to obtain the a-th number of repetitions, calculate the ratio of the a-th number of repetitions to the user cycle quantity value, and obtain the a-th common operation weight.
5. The identity authentication and access control system for a 5G-A terminal according to claim 2, characterized in that, The data acquisition module obtains the first common operation reference duration to the a-th common operation reference duration, specifically as follows: Respectively obtain the operation durations corresponding to the first common operation in each user authentication cycle to obtain multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the first common operation reference duration; Respectively obtain the operation durations corresponding to the second common operation in each user authentication cycle to obtain multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the second common operation reference duration; And so on, respectively obtain the operation durations corresponding to the a-th common operation in each user authentication cycle to obtain multiple operation durations, and calculate the average of the obtained multiple operation durations to obtain the a-th common operation reference duration.
6. The identity authentication and access control system for a 5G-A terminal according to claim 1, characterized in that, The identity authentication module obtains the identity authentication coefficient, specifically as follows: Obtain the historical user cycle collection data, and respectively obtain the first common operation to the a-th common operation, the first common operation weight to the a-th common operation weight, and the first common operation reference duration to the a-th common operation reference duration according to the historical user cycle collection data; Mark the time point when the target 5G-A terminal enters the working state from the standby state as the identity authentication start time point, mark the time point corresponding to a characteristic working duration after the identity authentication start time point as the identity authentication end time point, and mark the interval period between the identity authentication start time point and the identity authentication end time point as the boot identity authentication cycle; During the boot identity authentication cycle, obtain several device operations of the 5G-A terminal by the real-time user, and respectively name the several device operations as the first device operation to the a-th device operation according to the sequence of the device operation time. Obtain the operation weights of the first device to the a-th device; Respectively obtain the device operation durations corresponding to the operations of the first device to the a-th device during the boot identity authentication cycle, and obtain the operation durations of the first device to the a-th device; Calculate the identity authentication coefficient of the real-time user during the boot identity authentication cycle by using the first common operation benchmark durations to the a-th common operation benchmark durations, the operation durations of the first device to the a-th device, and the operation weights of the first device to the a-th device; Calculate the identity authentication coefficient, and the specific formula is as follows: ; Among them, Rzx is the identity authentication coefficient of the real-time user during the boot identity authentication cycle, Sjc1 to Sjca are the operation durations of the first device to the a-th device respectively, Sjj1 to Sjja are the first common operation benchmark durations to the a-th common operation benchmark durations respectively, and Cqz1 to Cqza are the operation weights of the first device to the a-th device respectively.
7. The identity authentication and access control system for a 5G-A terminal according to claim 6, characterized in that, The identity authentication module obtains the operation weights of the first device to the a-th device, specifically as follows: When the operation of the first device is the same as the first common operation, mark the weight of the first common operation as the operation weight of the first device. When the operation of the first device is not the same as the first common operation, assign the parameter value 0 to the operation weight of the first device to obtain the operation weight of the first device; When the operation of the second device is the same as the second common operation, mark the weight of the second common operation as the operation weight of the second device. When the operation of the second device is not the same as the second common operation, assign the parameter value 0 to the operation weight of the second device to obtain the operation weight of the second device; And so on. When the operation of the a-th device is the same as the a-th common operation, mark the weight of the a-th common operation as the operation weight of the a-th device. When the operation of the a-th device is not the same as the a-th common operation, assign the parameter value 0 to the operation weight of the a-th device to obtain the operation weight of the a-th device.
8. The identity authentication and access control system for a 5G-A terminal according to claim 1, characterized in that, The access control module performs permission control on the real-time user, specifically as follows: Obtain the identity authentication coefficient of the real-time user during the boot identity authentication cycle; Obtain the historical user cycle collection data, and respectively obtain the operation weights of the first common operation to the a-th common operation and the first common operation benchmark durations to the a-th common operation benchmark durations according to the historical user cycle collection data; Obtain the identity authentication coefficient threshold; Specifically as follows: Obtain the operation benchmark durations of the first device to the a-th device; Calculate the identity authentication coefficient threshold by using the operation benchmark durations of the first device to the a-th device, the operation weights of the first common operation to the a-th common operation, and the first common operation benchmark durations to the a-th common operation benchmark durations; Compare the identity authentication coefficient with the identity authentication coefficient threshold numerically, and obtain the real-time classification data of the user identity according to the numerical comparison result; Perform permission control on the real-time user according to the real-time classification data of the user identity; Specifically as follows: When the real-time user is a user of the first identity type, provide the access permission to the target 5G-A terminal for the real-time user; When the real-time user is a user of the second identity type, the access permission to the target 5G-A terminal is closed for the real-time user.
9. The identity authentication and access control system for a 5G-A terminal according to claim 8, characterized in that, The access control module obtains the real-time classification data of user identities as follows: When the identity authentication coefficient is less than or equal to the identity authentication coefficient threshold, the real-time user is classified as a user of the first identity type; When the identity authentication coefficient is greater than the identity authentication coefficient threshold, the real-time user is classified as a user of the second identity type; When the real-time user is a user of the second identity type, the target 5G-A terminal provides a password input window to verify the password of the real-time user. If the password verification is passed, the user of the second identity type is reclassified as a user of the first identity type. If the password verification fails, the real-time user continues to be classified as a user of the second identity type.
10. A method for identity authentication and access control of a 5G-A terminal, applicable to an identity authentication and access control system of a 5G-A terminal as described in any one of claims 1-9, characterized in that, The access control method specifically includes the following steps: Step S1: Obtain multiple historical user usage data respectively, mark a user identity authentication cycle in each historical user usage data, and obtain multiple common operations, the corresponding common operation weights, and the common operation benchmark duration for each common operation by analyzing the user operation similarity of each user identity authentication cycle, so as to obtain the historical user cycle collection data; Step S2: Create a power-on identity authentication cycle, authenticate the real-time user by analyzing the operations of the real-time user within the power-on identity authentication cycle and combining the historical user cycle collection data, and obtain the identity authentication coefficient of the real-time user within the power-on identity authentication cycle; Step S3: Compare the obtained identity authentication coefficient threshold with the identity authentication coefficient of the real-time user within the power-on identity authentication cycle numerically. According to the numerical comparison, classify the real-time user into a user of the first identity type and a user of the second identity type, verify the login password of the user of the second identity type, further refine the identity of the user of the second identity type according to the verification result, obtain the real-time classification data of user identities, and perform permission control on the real-time user according to the real-time classification data of user identities.
Citation Information
Patent Citations
Transaction behavior profile establishment and authentication method, system and device, and medium
CN108229964A
User authentication method and device, multimedia content pushing method and device
CN111753266A
Identity authentication method, product, equipment and medium
CN117955730A
White list data record dynamic updating method and system
CN118689892A
Account-free user unification method and system of construction and management system based on multimode authentication
CN119357939A