Multi-node multi-factor security authentication method and system
By dynamically evaluating user behavior, building a zero-knowledge proof R1CS constraint and distributed verification mechanism, the problems of redundant and unsafe authentication in the static multi-factor authentication method are solved, and the reliability and immutability of the adaptive authentication strength adjustment and authentication process are realized.
Patent Information
- Application Number
- CN202510918693.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-07-04
AI Technical Summary
The existing multi-factor authentication method is static authentication, and the authentication strength cannot be dynamically adjusted according to the user's behavior status, resulting in redundant authentication or unsafe authentication, affecting user experience and system efficiency.
By receiving the authentication behavior of the user, the proportion of malicious authentication samples of similar behavior samples and the average proportion of multi-time window trigger frequency are counted, the exception weight is calculated, the proportion of malicious authentication samples weighted based on the exception weight is weighted, the zero-knowledge proof R1CS constraint is constructed, the distributed node network is used for BLS signature aggregation verification, and the authentication log is written to the blockchain to achieve dynamic adjustment of the authentication strength.
It realizes dynamic assessment of authentication risks based on user behavior, adaptive adjustment of authentication strength, avoids redundant authentication and unsafe authentication, improves the reliability of authentication results and the system's fault tolerance, and ensures the traceability of the authentication process and the immutability of audit data.
Smart Images

Figure CN120415752A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security authentication, and particularly to a multi-factor security authentication method and system for multiple nodes. Background Art
[0002] With the rapid development of information technology and the increasing network security threats, identity authentication, as the first line of defense for information system security, has become increasingly prominent. As an effective identity verification mechanism, multi-factor authentication has been widely applied to various information systems by combining multiple authentication factors (such as passwords, biometric features, hardware tokens, etc.) to improve the security of information systems.
[0003] However, existing multi-factor authentication methods generally adopt static authentication strategies, that is, regardless of how the user's behavior state changes, identity verification is performed according to a preset fixed authentication process. When the user is in a low-risk environment or normal behavior mode, the information system still requires the user to complete all preset authentication steps, resulting in redundant authentication, which not only increases the user's operation burden but also reduces the user experience and system efficiency. When the user's behavior is abnormal or in a high-risk environment, the static authentication strength may not be sufficient to cope with potential security threats, and insecure authentication is likely to occur, thus bringing security risks to the information system. Summary of the Invention
[0004] Aiming at the technical problem that the multi-factor authentication method in the prior art is static authentication and cannot dynamically adjust the authentication strength according to the user's behavior state, resulting in redundant authentication or insecure authentication, the present invention provides a multi-factor security authentication method and system for multiple nodes to solve this problem.
[0005] The technical solution of the present invention to solve the above technical problems is as follows:
[0006] In a first aspect, the present invention provides a multi-factor security authentication method for multiple nodes, including: receiving an authentication behavior of a user terminal, retrieving the proportion of malicious authentication samples in the same type of behavior samples; statistically calculating the average proportion of the trigger frequencies of the authentication behavior in multiple time windows of the user terminal, and using 1 minus the average proportion of the trigger frequencies in the multiple time windows as the abnormal weight; weighting the proportion of the malicious authentication samples based on the abnormal weight to obtain an authentication strength evaluation value; when the authentication strength evaluation value is greater than or equal to an authentication strength threshold, constructing a zero-knowledge proof R1CS constraint based on a preset authentication factor array; performing BLS signature aggregation verification on the zero-knowledge proof R1CS constraint through a distributed node network to obtain an authentication log; writing the Merkle root of the authentication log into a blockchain to complete audit and deposit.
[0007] In a second aspect, the present invention provides a multi-node multi-factor security authentication system, comprising: a malicious sample statistics module, configured to receive an authentication behavior of a user terminal, retrieve similar behavior samples, and statistically calculate the proportion of malicious authentication samples; an abnormal weight determination module, configured to statistically calculate the average proportion of the triggering frequencies of the authentication behavior in multiple time windows of the user terminal, and subtract the average proportion of the triggering frequencies in the multiple time windows from 1, which is set as the abnormal weight; an authentication strength evaluation module, configured to weight the proportion of the malicious authentication samples based on the abnormal weight to obtain an authentication strength evaluation value; a constraint construction module, configured to, when the authentication strength evaluation value is greater than or equal to an authentication strength threshold, construct a zero-knowledge proof R1CS constraint based on a preset authentication factor array; a signature verification module, configured to perform BLS signature aggregation verification on the zero-knowledge proof R1CS constraint through a distributed node network to obtain an authentication log; and an audit and storage module, configured to write the Merkle root of the authentication log into a blockchain to complete audit and storage.
[0008] The beneficial effects of the present invention are as follows:
[0009] Receive the authentication behavior of the user terminal, retrieve similar behavior samples, and statistically calculate the proportion of malicious authentication samples, so as to establish a risk benchmark for the current authentication behavior through historical data analysis; statistically calculate the average proportion of the triggering frequencies of the authentication behavior in multiple time windows of the user terminal, subtract the average proportion of the triggering frequencies in the multiple time windows from 1, which is set as the abnormal weight, so as to quantify the degree of behavior abnormality by analyzing the time distribution characteristics of the user behavior; weight the proportion of the malicious authentication samples based on the abnormal weight to obtain an authentication strength evaluation value, combine the historical risk data with the current degree of behavior abnormality, and dynamically calculate the authentication strength requirement adapted to the current situation; when the authentication strength evaluation value is greater than or equal to the authentication strength threshold, construct a zero-knowledge proof R1CS constraint based on a preset authentication factor array, start a multi-factor authentication mechanism when high-strength authentication is required, and at the same time protect the user's private information through zero-knowledge proof technology; perform BLS signature aggregation verification on the zero-knowledge proof R1CS constraint through a distributed node network to obtain an authentication log, and use a multi-node collaborative verification mechanism to improve the reliability of the authentication result and the fault tolerance of the system; write the Merkle root of the authentication log into a blockchain to complete audit and storage, and ensure the traceability of the authentication process and the immutability of the audit data.
[0010] Through the above technical solutions, the purpose of dynamically evaluating the authentication risk according to the user behavior and adaptively adjusting the authentication strength is achieved, effectively avoiding the problems of redundant authentication and insecure authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1 It is a schematic flowchart of a multi-node multi-factor security authentication method provided by the present invention;
[0012] Figure 2Schematic diagram of a multi - node multi - factor security authentication system provided by the present invention.
[0013] In the accompanying drawings, the components represented by each reference numeral are as follows:
[0014] Malicious sample statistics module 11, abnormal weight determination module 12, authentication strength evaluation module 13, constraint construction module 14, signature verification module 15, audit and evidence preservation module 16. Specific implementation manners
[0015] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts fall within the protection scope of the present invention.
[0016] In the description of the present invention, the terms "first" and "second" are only used for descriptive purposes, and cannot be construed as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of the described features. In the description of the present invention, "a plurality of" means two or more, unless otherwise specifically defined.
[0017] In the description of the present invention, the term "for example" is used to mean "used as an example, illustration, or explanation". Any embodiment described as "for example" in the present invention is not necessarily construed as being more preferred or having more advantages than other embodiments. In order for any person skilled in the art to implement and use the present invention, the following description is given. In the following description, details are set forth for purposes of explanation. It should be understood that those skilled in the art can recognize that the present invention can be implemented without using these specific details. In other instances, well - known structures and processes are not elaborated in detail to avoid unnecessary details from obscuring the description of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown, but is consistent with the broadest scope that conforms to the principles and features disclosed in the present invention.
[0018] Embodiment 1, as Figure 1 shown, the embodiment of the present invention provides a multi - node multi - factor security authentication method, including:
[0019] S1. Receive the authentication behavior of the user terminal, and retrieve the proportion of malicious authentication samples in the same - type behavior samples.
[0020] Specifically, first, an authentication behavior request from the user side is received. The authentication behavior includes, but is not limited to, authentication-related interaction behaviors such as the user's login operation, request to access sensitive resources, permission change application, etc. After receiving the authentication behavior, a retrieval mechanism for similar behavior samples is started. Specifically, feature extraction is performed on the received authentication behavior to obtain the feature parameters of the current authentication behavior, such as authentication timestamp, source IP address, device features, user agent identifier, authentication type, access resource path, session duration, operation sequence pattern, network environment parameters, etc.; according to the feature parameters of the current authentication behavior, a set of similar behavior samples that match its attributes is retrieved from the pre-established historical behavior sample database. The matching criteria for the similar behavior samples include, but are not limited to, the similarity of multi-dimensional attributes such as authentication type, time characteristics, geographical location, device features, operation mode, etc.
[0021] After obtaining the set of similar behavior samples, security label identification is performed on the samples in the set of similar behavior samples, the number of samples marked as malicious authentication is counted, and the proportion of malicious authentication samples in the total number of similar behavior samples is calculated to obtain the proportion of malicious authentication samples. The proportion of malicious authentication samples reflects the historical security risk level of the current authentication behavior type and provides basic data support for subsequent authentication strength evaluation.
[0022] Through the above processing process, a preliminary risk quantification assessment of the current authentication behavior can be performed based on historical data, laying a data foundation for dynamically adjusting the authentication strategy.
[0023] S2. Statistically calculate the average proportion of the triggering frequencies of the authentication behavior in multiple time windows on the user side, and subtract the average proportion of the triggering frequencies in multiple time windows from 1, which is set as the anomaly weight.
[0024] Specifically, a multi-time window statistical analysis is performed on the historical triggering pattern of the authentication behavior on the user side. Specifically, according to the preset time window division strategy, the historical time period is divided into multiple consecutive time windows, each time window having the same time span. Within each time window, the triggering frequency of the authentication behavior is counted, and the proportion of the triggering frequency in the total triggering frequency of all authentication behaviors within the corresponding time window is calculated, so as to obtain the triggering frequency proportion of a single time window. Subsequently, statistical processing is performed on the triggering frequency proportions of multiple time windows, and the arithmetic mean of the triggering frequency proportions in multiple time windows is calculated to obtain the average proportion of the triggering frequencies in multiple time windows, which reflects the normalized triggering degree of the authentication behavior on the user side.
[0025] Based on the reverse thinking of user behavior anomaly detection, subtract the average proportion of trigger frequencies in multiple time windows from 1 to calculate the anomaly weight. The calculation logic of this anomaly weight is as follows: when the average proportion of trigger frequencies of a certain authentication behavior is higher, it indicates that this behavior is more in line with the user's normal usage pattern, and its anomaly degree is lower; on the contrary, the authentication behavior with a lower average proportion of trigger frequencies has a higher degree of deviation from the normal pattern, and the anomaly weight is larger.
[0026] By determining the above anomaly weight, the degree of deviation of the current authentication behavior from the user's historical behavior pattern can be quantified, providing a numerical basis for the dynamic adjustment of the subsequent authentication strength in terms of behavior anomaly degree.
[0027] S3. Based on the above anomaly weight, weight the proportion of malicious authentication samples to obtain an authentication strength evaluation value.
[0028] Specifically, use the anomaly weight as a risk amplification factor and perform a mathematical operation with the proportion of malicious authentication samples. Among them, the calculation formula for the weighting process is: authentication strength evaluation value = anomaly weight × proportion of malicious authentication samples. Through this weighted calculation, the organic integration of historical risk data and the current behavior anomaly degree is achieved.
[0029] The principle of the above weighting mechanism is as follows: when the user's authentication behavior deviates from its historical normal pattern (the anomaly weight is large), even if the historical proportion of malicious samples of this type of behavior is relatively low, the risk assessment level of this authentication behavior will still be improved; on the contrary, when the user's authentication behavior conforms to its historical usage habits (the anomaly weight is small), even if there is a certain historical security risk for this type of behavior, the risk assessment level will be appropriately reduced.
[0030] The authentication strength evaluation value obtained through the above weighted calculation comprehensively reflects the dual risk characteristics of the current authentication behavior. On the one hand, it reflects the historical security risk level of this type of authentication behavior, and on the other hand, it reflects the anomaly degree of the current behavior relative to the user's individual behavior pattern. This authentication strength evaluation value provides a quantitative decision-making basis for dynamically adjusting the authentication strength to achieve an adaptive authentication strategy based on the risk level.
[0031] S4. When the authentication strength evaluation value is greater than or equal to the authentication strength threshold, based on a preset array of authentication factors, construct a zero-knowledge proof R1CS constraint.
[0032] Specifically, according to the obtained authentication strength evaluation value, start a dynamic authentication mechanism based on threshold judgment. Specifically, first, compare the authentication strength evaluation value with the preset authentication strength threshold. When the authentication strength evaluation value is greater than or equal to the authentication strength threshold, it indicates that the current authentication behavior has a relatively high security risk, and it is determined that an enhanced authentication process needs to be started.
[0033] After determining that the authentication strength evaluation value is greater than or equal to the authentication strength threshold, construct the R1CS constraints of zero-knowledge proof based on a preset authentication factor array. The preset authentication factor array includes various authentication elements, such as biometric data, dynamic tokens, digital certificates, hardware identifiers and other multi-factor authentication components. Select an appropriate combination of authentication factors from the preset authentication factor array according to the current risk level and user characteristics. The construction process of the R1CS constraints of zero-knowledge proof includes: First, convert the selected authentication factors from the preset authentication factor array into an arithmetic circuit representation form; Second, establish corresponding constraint equations for each authentication factor according to the arithmetic circuit to ensure the correctness of the verification process; After that, combine multiple constraint equations to form a complete R1CS constraint of zero-knowledge proof. The R1CS constraint of zero-knowledge proof has the zero-knowledge property and can prove that the user meets the corresponding authentication requirements without revealing the specific authentication information of the user.
[0034] Through the construction of the above R1CS constraints, the balance between privacy protection and security authentication is achieved. It can not only dynamically adjust the authentication strength according to the risk level, but also protect the sensitive information of users from being leaked during the authentication process, laying a technical foundation for the subsequent distributed verification process.
[0035] S5. Perform BLS signature aggregation verification on the R1CS constraints of the zero-knowledge proof through a distributed node network to obtain an authentication log.
[0036] Specifically, first, distribute the R1CS constraints of the zero-knowledge proof and its related proof data to multiple verification nodes in a pre-configured distributed node network. The distributed node network adopts a decentralized architecture and is composed of multiple independent verification nodes. Each node has the ability to verify zero-knowledge proof and the function of generating BLS signatures. After receiving the R1CS constraints of the zero-knowledge proof, each verification node independently executes the zero-knowledge proof verification algorithm to verify whether the proof submitted by the user meets the preset constraint conditions.
[0037] After the verification is completed, each verification node generates a corresponding BLS signature based on its verification result. The BLS signature has the aggregable property and supports combining the signatures of multiple nodes into a single aggregated signature. Collect the BLS signatures of each verification node and execute the signature aggregation algorithm to combine multiple independent signatures into a compact aggregated signature.
[0038] At the same time, according to the preset consensus mechanism, count the number of nodes that pass the verification. When the number of nodes that pass the verification reaches the preset threshold requirement, determine that the authentication verification is successful. Generate an authentication log containing key information such as authentication timestamp, verification node information, aggregated signature data, and verification status based on the verification result and the aggregated signature.
[0039] Through the above - mentioned distributed verification mechanism, the decentralization and fault tolerance of the authentication process are realized, avoiding the risk of single - point failure. At the same time, the verification efficiency is improved through the BLS signature aggregation technology, providing a reliable authentication record for subsequent blockchain evidence deposit.
[0040] Furthermore, receive the authentication behavior of the user - end, retrieve the statistical proportion of malicious authentication samples in the same - type behavior samples, including:
[0041] S11: Extract the first authentication behavior to the Nth authentication behavior from the authentication behavior;
[0042] S12: Retrieve the first same - type behavior samples within the preset time window of the first authentication behavior, and count the proportion of the first malicious authentication samples in the first same - type behavior samples;
[0043] S13: Until retrieving the Nth same - type behavior samples within the preset time window of the Nth authentication behavior, and count the proportion of the Nth malicious authentication samples in the Nth same - type behavior samples;
[0044] S14: Add the proportion of the first malicious authentication samples to the proportion of the Nth malicious authentication samples into the proportion of malicious authentication samples.
[0045] In a feasible implementation manner, first, decompose the received authentication behavior, and split the composite authentication behavior into multiple independent authentication behaviors. Specifically, according to the preset behavior classification rules, sequentially extract the first authentication behavior, the second authentication behavior until the Nth authentication behavior from the authentication behavior, where N is a positive integer representing the total number of authentication behaviors included in this authentication process. Among them, the authentication behavior includes, but is not limited to, independent authentication operations such as password input, fingerprint recognition, token verification, device binding verification, etc.
[0046] Then, start the same - type sample retrieval mechanism for the first authentication behavior. Within the preset time window range, retrieve the set of the first same - type behavior samples that match the characteristics of the first authentication behavior from the historical behavior sample database. Then, perform a security label analysis on the set of the first same - type behavior samples, identify the number of samples marked as malicious authentication, and calculate the proportion of the first malicious authentication samples in the total number of the first same - type behavior samples to obtain the proportion of the first malicious authentication samples. In the same processing manner as step S12, sequentially perform the same - type sample retrieval and malicious sample proportion statistics on the second authentication behavior to the Nth authentication behavior. The specific process is: retrieve the Nth same - type behavior samples within the preset time window of the Nth authentication behavior, and count the proportion of the Nth malicious authentication samples in the Nth same - type behavior samples until the calculation of the proportion of malicious samples for all N authentication behaviors is completed.
[0047] After that, perform set operations on the obtained first malicious authentication sample ratio, second malicious authentication sample ratio, up to the Nth malicious authentication sample ratio, and uniformly add these N ratio values to the malicious authentication sample ratio to provide multi-dimensional malicious behavior probability data support for subsequent comprehensive risk assessment.
[0048] Through the above decomposition and malicious authentication sample statistics, it is possible to conduct refined risk quantification analysis on complex authentication behaviors, improving the accuracy and comprehensiveness of malicious behavior recognition.
[0049] Furthermore, retrieve the first type of behavior samples within the preset time window of the first authentication behavior, and count the ratio of the first malicious authentication samples in the first type of behavior samples, including:
[0050] S121. Obtain a predefined high-risk behavior library;
[0051] S122. When the first authentication behavior belongs to the high-risk behavior library, the ratio of the first malicious authentication samples is equal to 1;
[0052] S123. When the first authentication behavior does not belong to the high-risk behavior library, count the ratio of the first malicious authentication samples in the first type of behavior samples.
[0053] In a preferred implementation manner, first, obtain a pre-constructed high-risk behavior library. This high-risk behavior library is a malicious authentication behavior feature database established based on historical security event analysis, threat intelligence collection, and expert knowledge accumulation. This high-risk behavior library contains authentication behavior patterns that have been confirmed as high-risk or malicious, such as typical malicious authentication behavior characteristics like abnormal geographical location logins, accesses at unconventional times, suspicious device authentications, brute-force cracking attempts, privilege escalation attacks, etc. This high-risk behavior library adopts a dynamic update mechanism and is regularly supplemented and optimized according to the latest security threat information.
[0054] Then, extract the characteristic parameters of the first authentication behavior, such as authentication timestamp, source IP address, device characteristics, user agent identifier, authentication type, access resource path, session duration, operation sequence pattern, network environment parameters, etc. Compare the characteristic parameters of the first authentication behavior with the behavior patterns in the high-risk behavior library. When it is determined that the characteristics of the first authentication behavior completely match or are highly similar to a certain malicious behavior pattern in the high-risk behavior library, set the ratio of the first malicious authentication samples to the value 1, that is, a malicious probability of 100%. This processing mechanism is based on the deterministic judgment of known malicious behaviors and does not require complex statistical analysis, capable of quickly identifying clear threat behaviors.
[0055] When it is determined that the first authentication behavior does not belong to the known malicious patterns in the high-risk behavior library, a statistical analysis mechanism based on historical data is started. Specifically, in the first set of homogeneous behavior samples, identify and count the number of samples marked as malicious authentication, calculate its proportion in the total number of the first set of homogeneous behavior samples, and obtain the proportion of the first malicious authentication samples. This statistical method can provide a probabilistic risk assessment for authentication behaviors that are not clearly defined based on historical experience data.
[0056] Through the above hierarchical judgment mechanism, an organic combination of deterministic identification and probabilistic assessment is achieved. It can not only quickly process known high-risk behaviors but also reasonably quantify the risks of unknown behaviors, improving the accuracy and efficiency of the overall risk assessment.
[0057] Furthermore, statistically calculate the average proportion of the trigger frequencies of the authentication behavior in multiple time windows on the client side, and use 1 minus the average proportion of the trigger frequencies in multiple time windows, which is set as the anomaly weight, including:
[0058] S21. Divide the preset time zone equally according to the set time window width to obtain a number of time windows;
[0059] S22. Based on the number of time windows, statistically calculate the total sum of the trigger frequencies of all authentication behaviors;
[0060] S23. Based on the number of time windows, statistically calculate the trigger frequencies of the first authentication behavior of the authentication behavior;
[0061] S24. Calculate the ratio of the trigger frequencies of the first authentication behavior to the total sum of the trigger frequencies to obtain the proportion of the trigger frequencies of the first authentication behavior;
[0062] S25. Statistically calculate the average value of the proportion of the trigger frequencies of the first authentication behavior to obtain the average proportion of the trigger frequencies in multiple time windows.
[0063] In a preferred embodiment, first, perform an equally spaced division process on the preset time zone according to the preset time window width. Specifically, evenly divide the total duration of the preset time zone according to the set time window width to generate a number of consecutive and non-overlapping time windows. For example, if the preset time zone is 30 days and the time window width is set to 3 days, then 10 time windows will be generated, and each window covers a time range of 3 days. Among them, the number and width of the time windows can be flexibly configured according to the actual application scenario and user behavior characteristics.
[0064] Subsequently, based on a number of time windows, the trigger frequencies of all the user's authentication behaviors within each time window are statistically counted. Specifically, each time window is traversed, and the trigger counts of all types of authentication behaviors initiated by the user within that window are counted, including various authentication operations such as login authentication, resource access authentication, and permission change authentication. The trigger frequencies of all the authentication behaviors within each time window are aggregated to obtain a number of trigger frequency totals, which reflect the overall authentication activity of the user at different time periods. At the same time, for a specific authentication behavior that needs to be analyzed currently (such as the first authentication behavior of the authentication behavior), a special frequency statistic is performed within a number of time windows. Each time window is retrieved one by one, and the specific trigger count of the first authentication behavior within that window is counted to form the trigger frequency of this authentication behavior within each time window, denoted as a number of first authentication behavior trigger frequencies.
[0065] Subsequently, a frequency ratio calculation process is performed. Specifically, the trigger frequency of the first authentication behavior within each time window is calculated as a ratio to the total trigger frequency of all the authentication behaviors within the corresponding time window to obtain the relative ratio of the trigger frequency of the first authentication behavior within that time window. The same ratio calculation is performed for all time windows to obtain a number of first authentication behavior trigger frequency ratios. After that, statistical processing is performed on the number of first authentication behavior trigger frequency ratios. The arithmetic mean of the number of first authentication behavior trigger frequency ratios is calculated to obtain the mean of the trigger frequency ratios over multiple time windows. This mean reflects the average relative importance and normalization level of the first authentication behavior in the user's historical behavior pattern.
[0066] Through the above multi-level time window analysis mechanism, the normalization degree of a specific authentication behavior in the user behavior pattern can be accurately quantified, providing a reliable statistical basis for subsequent abnormal weight calculation.
[0067] Further, obtaining the mean of the trigger frequency ratios of the first authentication behaviors over multiple time windows includes:
[0068] S251. Calculate the time spans between the median times of the number of time windows and the current time;
[0069] S252. Calculate the ratios of the number of time spans to the preset time zone duration to obtain a number of time window weights;
[0070] S253. Based on the number of time window weights, perform a weighted mean statistic on the number of first authentication behavior trigger frequency ratios to obtain the mean of the trigger frequency ratios over multiple time windows.
[0071] In a preferred embodiment, in the specific implementation process of statistically calculating the weighted mean of the trigger frequency ratios of several first authentication behaviors, a weight allocation mechanism based on time decay is adopted to more accurately reflect the timeliness characteristics of the user behavior pattern.
[0072] First, calculate the time span of several time windows. Specifically, first determine the median moment of each time window, that is, the midpoint moment between the start time and the end time of the time window. Then, calculate the time difference between the median moment of each time window and the current moment to obtain several time span arrays. The time span reflects the time distance of each time window relative to the current moment, providing basic data in the time dimension for subsequent weight calculation.
[0073] Then, perform the normalization calculation of the time window weights. Divide the time span corresponding to each time window by the total duration of the preset time zone to obtain several normalized time distance ratios. Based on the principle that the user behavior credibility decays with time, adopt a reverse weight allocation strategy: the smaller the time span (i.e., the closer to the current moment) of the time window, the larger the corresponding weight value; the larger the time span (i.e., the farther from the current moment) of the time window, the smaller the corresponding weight value. For example, adopt the reverse calculation formula, that is, weight value = 1 - time distance ratio, to obtain several time window weights, which reflects the influence degree of behavior data in different time periods on the current authentication decision.
[0074] Subsequently, based on several time window weights, perform a weighted average calculation on the trigger frequency ratios of several first authentication behaviors. The specific calculation formula is: the mean value of the trigger frequency ratios of multiple time windows = Σ (the trigger frequency ratio of the i-th time window × the weight of the i-th time window) / Σ (time window weights). Through this weighted statistical mechanism, the importance of the recent behavior pattern can be highlighted, and at the same time, the reference value of historical behaviors can be appropriately considered to obtain the mean value of the trigger frequency ratios of multiple time windows that is more in line with the current behavior characteristics of the user.
[0075] Through the above weighted statistics, the authentication verification of behavior pattern analysis and privacy protection based on time decay is realized, providing a reliable support for dynamic authentication strength adjustment.
[0076] Furthermore, when the authentication strength evaluation value is greater than or equal to the authentication strength threshold, based on the preset authentication factor array, construct a zero-knowledge proof R1CS constraint, including:
[0077] S41. Obtain the mandatory authentication factor array and the set of authentication factors to be optimized;
[0078] S42. Based on the authentication behavior, mine the frequent authentication factor combinations for the set of authentication factors to be optimized to obtain a frequent authentication factor combination set;
[0079] S43. Add the set of frequently - authenticated factor combinations to the taboo combination space, and perform optimization search for authenticated factor combinations according to the expected number of authenticated factors to obtain the target authenticated factor combination.
[0080] S44. Based on the mandatory authenticated factor array and the target authenticated factor combination, construct the zero - knowledge proof R1CS constraint.
[0081] In a preferred implementation manner, during the specific implementation process of constructing the zero - knowledge proof R1CS constraint, a multi - level optimized selection mechanism for authenticated factors is adopted to ensure the best balance between authentication strength and user experience.
[0082] First, obtain the pre - configured mandatory authenticated factor array, which contains the core authentication elements required by force, such as indispensable authentication components like user identity identification and basic password verification. At the same time, obtain the set of authenticated factors to be optimized, which contains authentication elements that can be dynamically selected according to the risk level, such as optional authentication components like biometric recognition, hardware tokens, digital certificates, device binding verification, and geographical location verification. This set of authenticated factors to be optimized provides a flexible space for adjusting the authentication strength. Then, based on the current authentication behavior, perform frequent - pattern mining processing on the set of authenticated factors to be optimized. For example, use the association - rule mining algorithm to analyze the combination occurrence frequency of each authenticated factor in the historical authentication records, and identify the combination patterns of authenticated factors that are often used simultaneously in similar authentication scenarios. By setting the minimum support threshold, filter out the frequently - occurring authenticated factor combinations in the historical data to form the set of frequently - authenticated factor combinations. This set of frequently - authenticated factor combinations reflects the user's regular authentication habits and historical authentication strategies.
[0083] Then, add the set of frequently - authenticated factor combinations to the taboo combination space, aiming to avoid selecting the authentication combinations that users are too familiar with and prevent the reduction of authentication strength due to habitual operations. According to the preset expected number of authenticated factors, perform combined optimization search on the set of authenticated factors to be optimized under the constraint of excluding the taboo combination space. Use a heuristic algorithm to comprehensively consider multi - dimensional evaluation indicators such as authentication strength, user convenience, and system resource consumption, and select the optimal authenticated factor combination as the target authenticated factor combination. Subsequently, based on the mandatory authenticated factor array and the target authenticated factor combination, construct the complete zero - knowledge proof R1CS constraint. Convert all selected authenticated factors into corresponding arithmetic - circuit representations, and establish corresponding constraint equations for each authenticated factor to obtain the zero - knowledge proof R1CS constraint.
[0084] For example, assume that a certain user is performing access authentication for the enterprise core system, and the specific implementation process is as follows: First, obtain the mandatory authenticated factor array, which includes biometric hash verification (SHA256 fingerprint, 256 bits) and dynamic token verification Two mandatory authentication factors (HMAC-SHA256 output, 256 bits). At the same time, obtain the set of authentication factors to be optimized, including various optional authentication components such as PUF response verification, digital certificate verification, device binding verification, and geographical location verification. Then, analyze the historical authentication records and find that in similar high-risk authentication scenarios, the combination of "biometric verification + PUF response verification" appears with a frequency of 82%, and the combination of "dynamic token + PUF response" appears with a frequency of 75%. By setting the minimum support threshold to 70%, these two frequent authentication factor combinations are screened out to form a set of frequent authentication factor combinations. Subsequently, the frequently occurring combinations of "biometric verification + PUF response verification" and "dynamic token + PUF response" are added to the taboo combination space to avoid selecting overly conventional authentication modes. Based on the requirement that the expected number of authentication factors is 3, optimization is carried out under the constraint of excluding taboo combinations, and finally, the triple authentication combination of "biometric verification + dynamic token verification + PUF response verification" is selected as the target authentication factor combination. Subsequently, based on the mandatory authentication factor array and the target authentication factor combination, zero-knowledge proof R1CS constraints are constructed.
[0085] For example, define the expected verification value based on the mandatory authentication factor array (biometric hash expected value), (dynamic token expected value), and define the user authentication credentials based on the target authentication factor combination, which are respectively (heartbeat phase modulation feature), (true random number seed), (PUF response stable bit string). Among them, the heartbeat phase modulation feature is a non-contact acquisition of the user's heartbeat signal through a millimeter-wave radar array, and the extracted heartbeat timing phase change pattern reflects the microscopic time interval change and intensity modulation law of the user's heart beating, with individual biological uniqueness and liveness detection ability, and can effectively prevent forgery attacks such as recording and playback; the true random number seed is a high-quality random bit sequence generated by obtaining a hardware-level physical entropy source through a quantum noise acquisition component and compressing it through a Toeplitz matrix. This seed is generated based on physical random processes such as quantum tunneling effect, with unpredictability and irreproducibility, providing cryptographic strength randomness guarantee for the authentication process; the PUF response stable bit string is a unique device identifier generated by a physical unclonable function (PUF) hardware module based on microscopic physical differences in the integrated circuit manufacturing process. This bit string uses uncontrollable physical characteristics such as transistor threshold voltage changes and wire delay differences, and forms a stable device fingerprint after error correction coding, with device-level uniqueness and anti-cloning characteristics. Subsequently, three constraint equations are established, namely the biometric hash correctness SHA256( ) = <( ), dynamic token validity HMAC-SHA256( ,"TOKEN") = 、PUF response stability HD(ECC( ), PUF_reg) ≤ ⌊n / 8⌋. By converting these constraint equations into the standard R1CS matrix form, the complete zero-knowledge proof R1CS constraints are finally constructed, enabling the user to prove that they meet the triple authentication requirements without revealing specific authentication information.
[0086] Furthermore, obtain the mandatory authentication factor array, including:
[0087] S411. Perform Toeplitz matrix compression on the hardware entropy source data obtained by the quantum noise acquisition component to generate a true random number seed;
[0088] S412. Collect the user's vital sign signals through the millimeter-wave radar array and extract the heartbeat phase modulation features;
[0089] S413. Generate a PUF response stable bit string through the PUF (Physical Unclonable Function);
[0090] S414. Add the true random number seed, the heartbeat phase modulation feature, and the PUF response stable bit string into the mandatory authentication factor array.
[0091] In a preferred implementation, during the specific implementation process of obtaining the mandatory authentication factor array, an authentication factor generation mechanism based on hardware-level security features is adopted to ensure the non-forgeability and high-entropy characteristics of the authentication factors.
[0092] First, obtain high-quality hardware entropy source data through the quantum noise acquisition component. The quantum noise acquisition component collects true random signals generated from physical processes such as quantum tunneling effect and thermal noise based on the principle of quantum physical randomness. Perform Toeplitz matrix compression processing on the collected hardware entropy source data. Through matrix multiplication of the preset Toeplitz matrix and the original entropy source data, the compression and debiasing of the entropy source data are realized. This compression process can effectively eliminate the systematic bias in the hardware acquisition process and extract a high-quality random bit sequence with uniform distribution characteristics to generate a true random number seed. The true random number seed has unpredictability and non-reproducibility, providing cryptographic-strength randomness guarantee for the subsequent authentication process.
[0093] The user's vital signs are then monitored contactlessly using a millimeter-wave radar array. The millimeter-wave radar array emits millimeter-wave signals of a specific frequency and detects changes in the reflected signal caused by the rise and fall of the user's chest, collecting vital signs such as heartbeat and respiration in real time. The collected vital sign signals undergo digital signal processing. Using filtering, denoising, and feature extraction algorithms, the phase modulation characteristics of the heartbeat signal are separated and extracted from the composite vital sign signal. This phase modulation characteristic reflects the microscopic timing characteristics and intensity variation patterns of the user's heartbeat, possessing individual uniqueness and liveness detection capabilities, effectively preventing forgery attacks.
[0094] Subsequently, a unique device identifier (UID) is generated using a PUF (Physical Unclonable Function) hardware module. The PUF module constructs a unique device-level response function based on uncontrollable microscopic physical variations during the integrated circuit manufacturing process, such as variations in transistor threshold voltage and wire delays. A preset stimulus signal is input to the PUF module, which generates a corresponding response signal based on its inherent physical properties. To improve response stability, the original PUF response is error-corrected using algorithms such as BCH or Reed-Solomon codes. This generates a stable PUF response bit string that can tolerate a certain amount of bit errors. This bit string is highly reproducible under the same stimulus conditions and exhibits significant variability between devices.
[0095] Afterwards, the three types of high-security authentication factors generated in the previous steps are integrated. The true random number seed, heartbeat phase modulation feature, and PUF response stable bit string are encapsulated according to a preset data format and added to the array of required authentication factors. Each authentication factor in this array has different security characteristics: the true random number seed provides cryptographic randomness, the heartbeat phase modulation feature provides biological liveness verification, and the PUF response stable bit string provides device hardware binding. The organic combination of these three authentication factors forms a multi-dimensional security authentication foundation covering randomness, biology, and physics, providing high-strength authentication factor support for the subsequent construction of zero-knowledge proofs.
[0096] Furthermore, the frequent authentication factor combination set is added to the taboo combination space, and authentication factor combination optimization is performed according to the expected number of authentication factors to obtain a target authentication factor combination, including:
[0097] S431: Based on the expected number of authentication factors, the set of authentication factors to be optimized is combined while avoiding the taboo combination space to obtain a first authentication factor combination;
[0098] S432. Calculate the square of the mean of the intersection and union ratio of the factor types between the first authentication factor combination and the frequent authentication factor combination set, and set it as the first fitness value.
[0099] S433. When the first fitness value is greater than or equal to the fitness threshold, eliminate the first authentication factor combination.
[0100] S434. When the first fitness value is less than the fitness threshold, add the first authentication factor combination to the set of candidate authentication factor combinations.
[0101] S435. When the number of combinations in the set of candidate authentication factor combinations is greater than or equal to the set number, select the authentication factor combination with the minimum fitness value in the set of candidate authentication factor combinations, and set it as the target authentication factor combination.
[0102] In a preferred embodiment, during the specific implementation process of optimizing the authentication factor combination, an intelligent optimization algorithm based on tabu search and fitness evaluation is adopted to ensure that the selected authentication factor combination not only meets the security strength requirements but also avoids the user's inertial operation mode.
[0103] First, based on the preset expected number of authentication factors, start the combination generation mechanism. Specifically, use the frequent authentication factor combination set as the constraint condition for the tabu combination space to ensure that the subsequent generated combinations do not repeat the user's historical habitual patterns. Adopt a combination algorithm to perform permutation and combination on the set of authentication factors to be optimized according to the expected number of authentication factors. On the premise of avoiding the tabu combination space, randomly or according to a preset rule, select authentication factors for combination to generate a candidate first authentication factor combination. This combination generation process ensures the diversity and novelty of the authentication factors. Subsequently, conduct a similarity quantification evaluation on the first authentication factor combination. Specifically, calculate the intersection and union ratio (Jaccard similarity coefficient) of the factor types between the first authentication factor combination and each combination in the frequent authentication factor combination set. The formula for calculating the intersection and union ratio is: the number of authentication factor types jointly included in the two combinations divided by the union of all authentication factor types included in the two combinations. Calculate the arithmetic mean of the intersection and union ratios between the first authentication factor combination and all combinations in the frequent authentication factor combination set to obtain the mean of the intersection and union ratios, and then square this mean value, which is set as the first fitness value. This fitness value reflects the similarity degree between the first authentication factor combination and the user's historical habitual combination.
[0104] When the first fitness is greater than or equal to the preset fitness threshold, it indicates that the first combination of authentication factors is too similar to the user's historical habitual pattern, and there is a risk of reduced authentication strength due to the user's familiarity with the operation. In this case, the first combination of authentication factors is marked as an unqualified candidate and eliminated, and is not allowed to enter the subsequent optimization process. When the first fitness is less than the fitness threshold, it indicates that the first combination of authentication factors has sufficient differences from the user's historical habitual pattern, can effectively avoid the risk of inertial operation, and meets the authentication strength requirements. The qualified first combination of authentication factors is added to the set of candidate authentication factor combinations as a candidate for the target authentication factor combination. This processing mechanism ensures that all combinations in the candidate combination set have the necessary security features.
[0105] When the number of combinations in the set of candidate authentication factor combinations reaches or exceeds the preset set number, it indicates that enough qualified candidate combinations have been collected. All combinations in the set of candidate authentication factor combinations are sorted in ascending order according to the fitness values, and the authentication factor combination with the smallest fitness value is selected as the final target authentication factor combination. This selection strategy is based on the principle that the smaller the fitness, the greater the difference from the historical habitual pattern, ensuring that the selected combination can avoid the user's operation inertia to the greatest extent and provide the optimal authentication security strength.
[0106] Through the above multi-level screening and optimization mechanism, it is possible to intelligently select the combination of authentication factors with the greatest difference from the user's historical behavior pattern on the premise of ensuring the effectiveness of authentication, realizing the organic unity of authentication security and anti-inertial operation.
[0107] Embodiment 2, as Figure 2 shown, based on the same inventive concept as the multi-factor security authentication method with multiple nodes provided in Embodiment 1, the embodiment of the present invention further provides a multi-factor security authentication system with multiple nodes, including:
[0108] The malicious sample statistics module 11 is used to receive the authentication behavior of the user terminal and retrieve the proportion of malicious authentication samples in the same type of behavior samples;
[0109] The abnormal weight determination module 12 is used to count the average proportion of the triggering frequencies of the authentication behavior in multiple time windows of the user terminal, and subtract the average proportion of the triggering frequencies in the multiple time windows from 1, which is set as the abnormal weight;
[0110] The authentication strength evaluation module 13 is used to weight the proportion of the malicious authentication samples based on the abnormal weight to obtain an authentication strength evaluation value;
[0111] The constraint construction module 14 is used to construct a zero-knowledge proof R1CS constraint based on a preset authentication factor array when the authentication strength evaluation value is greater than or equal to the authentication strength threshold;
[0112] The signature verification module 15 is used to perform BLS signature aggregation verification on the zero-knowledge proof R1CS constraints through a distributed node network to obtain an authentication log;
[0113] The audit and evidence storage module 16 is used to write the Merkle root of the authentication log into the blockchain to complete audit and evidence storage.
[0114] Furthermore, the malicious sample statistics module 11 includes the following execution steps:
[0115] Extract the first authentication behavior to the Nth authentication behavior from the authentication behaviors;
[0116] Retrieve the first type of behavior samples within the preset time window of the first authentication behavior, and count the proportion of the first malicious authentication samples in the first type of behavior samples;
[0117] Until retrieving the Nth type of behavior samples within the preset time window of the Nth authentication behavior, and count the proportion of the Nth malicious authentication samples in the Nth type of behavior samples;
[0118] Add the proportion of the first malicious authentication samples to the proportion of the Nth malicious authentication samples to the malicious authentication sample proportion.
[0119] Furthermore, the malicious sample statistics module 11 further includes the following execution steps:
[0120] Obtain a predefined high-risk behavior library;
[0121] When the first authentication behavior belongs to the high-risk behavior library, the proportion of the first malicious authentication samples is equal to 1;
[0122] When the first authentication behavior does not belong to the high-risk behavior library, count the proportion of the first malicious authentication samples in the first type of behavior samples.
[0123] Furthermore, the abnormal weight determination module 12 includes the following execution steps:
[0124] Divide the preset time zone evenly according to the set time window width to obtain a number of time windows;
[0125] Based on the number of time windows, count the total sum of the trigger frequencies of all authentication behaviors;
[0126] Based on the number of time windows, count the trigger frequencies of the first authentication behavior of the authentication behavior;
[0127] Calculate the ratio of the trigger frequencies of the first authentication behavior to the total sum of the trigger frequencies to obtain the proportion of the trigger frequencies of the first authentication behavior;
[0128] Perform a mean statistical analysis on the proportion of trigger frequencies of the several first authentication behaviors to obtain the mean of the trigger frequency proportions in multiple time windows.
[0129] Further, the abnormal weight determination module 12 further includes the following execution steps:
[0130] Calculate the time spans between the median moments of the several time windows and the current moment;
[0131] Calculate the ratios of the several time spans to the preset time zone duration to obtain several time window weights;
[0132] Based on the several time window weights, perform a weighted mean statistical analysis on the proportion of trigger frequencies of the several first authentication behaviors to obtain the mean of the trigger frequency proportions in multiple time windows.
[0133] Further, the constraint construction module 14 includes the following execution steps:
[0134] Obtain the mandatory authentication factor array and the set of authentication factors to be optimized;
[0135] Based on the authentication behaviors, perform mining of frequent authentication factor combinations on the set of authentication factors to be optimized to obtain a set of frequent authentication factor combinations;
[0136] Add the set of frequent authentication factor combinations to the taboo combination space, and perform optimization of authentication factor combinations according to the expected number of authentication factors to obtain the target authentication factor combination;
[0137] Based on the mandatory authentication factor array and the target authentication factor combination, construct the zero-knowledge proof R1CS constraint.
[0138] Further, the constraint construction module 14 further includes the following execution steps:
[0139] Perform Toeplitz matrix compression on the hardware entropy source data acquired by the quantum noise acquisition component to generate a true random number seed;
[0140] Collect user vital sign signals through a millimeter-wave radar array and extract the heartbeat phase modulation characteristics;
[0141] Generate a stable bit string of PUF responses through a PUF (Physical Unclonable Function);
[0142] Add the true random number seed, the heartbeat phase modulation characteristics, and the stable bit string of PUF responses to the mandatory authentication factor array.
[0143] Further, the constraint construction module 14 further includes the following execution steps:
[0144] Based on the expected number of authentication factors, avoid the taboo combination space, combine the set of authentication factors to be optimized, and obtain a first combination of authentication factors;
[0145] Calculate the square of the mean of the intersection and union ratio of the factor types between the first combination of authentication factors and the set of frequently used authentication factor combinations, and set it as the first fitness;
[0146] When the first fitness is greater than or equal to the fitness threshold, eliminate the first combination of authentication factors;
[0147] When the first fitness is less than the fitness threshold, add the first combination of authentication factors to the set of candidate authentication factor combinations;
[0148] When the number of combinations in the set of candidate authentication factor combinations is greater than or equal to the set number, select the authentication factor combination with the minimum fitness in the set of candidate authentication factor combinations, and set it as the target authentication factor combination.
[0149] It should be noted that in the above embodiments, the descriptions of each embodiment have their own emphases. For parts not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0150] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0151] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be realized by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded computers, or other programmable data processing devices to generate a machine, so that the instructions executed by the processors of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one or more flows or multiple flows and / or blocks Figure 1 one or more blocks or multiple blocks.
[0152] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the functions specified in one or more of the procedures Figure 1 and / or blocks Figure 1 specified in one or more of the procedures and / or blocks.
[0153] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one or more of the procedures Figure 1 and / or blocks Figure 1 specified in one or more of the blocks.
[0154] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn of the basic inventive concept.
[0155] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the present invention and its equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. A multi-factor security authentication method for multiple nodes, characterized in that including: Receiving the authentication behavior of the user terminal, retrieving similar behavior samples, and counting the proportion of malicious authentication samples; Counting the average proportion of the triggering frequencies of the authentication behavior in multiple time windows of the user terminal, subtracting the average proportion of the triggering frequencies in the multiple time windows from 1, and setting it as the anomaly weight; Based on the anomaly weight, weighting the proportion of the malicious authentication samples to obtain an authentication strength evaluation value; When the authentication strength evaluation value is greater than or equal to the authentication strength threshold, constructing a zero-knowledge proof R1CS constraint based on a preset authentication factor array; Performing BLS signature aggregation verification on the zero-knowledge proof R1CS constraint through a distributed node network to obtain an authentication log; Writing the Merkle root of the authentication log into the blockchain to complete audit and deposit evidence.
2. The method according to claim 1, wherein, Receiving the authentication behavior of the user terminal, retrieving similar behavior samples, and counting the proportion of malicious authentication samples, including: Extracting the first authentication behavior to the Nth authentication behavior from the authentication behavior; Retrieving the first similar behavior samples in the preset time window of the first authentication behavior, and counting the proportion of the first malicious authentication samples in the first similar behavior samples; Until retrieving the Nth similar behavior samples in the preset time window of the Nth authentication behavior, and counting the proportion of the Nth malicious authentication samples in the Nth similar behavior samples; Adding the proportion of the first malicious authentication samples to the proportion of the Nth malicious authentication samples into the proportion of the malicious authentication samples.
3. The method according to claim 2, wherein Retrieving the first similar behavior samples in the preset time window of the first authentication behavior, and counting the proportion of the first malicious authentication samples in the first similar behavior samples, including: Obtaining a predefined high-risk behavior library; When the first authentication behavior belongs to the high-risk behavior library, the proportion of the first malicious authentication samples is equal to 1; When the first authentication behavior does not belong to the high-risk behavior library, counting the proportion of the first malicious authentication samples in the first similar behavior samples.
4. The method according to claim 1, wherein Counting the average proportion of the triggering frequencies of the authentication behavior in multiple time windows of the user terminal, subtracting the average proportion of the triggering frequencies in the multiple time windows from 1, and setting it as the anomaly weight, including: Dividing the preset time zone evenly according to the set time window width to obtain a number of time windows; Based on the number of time windows, counting the total sum of the triggering frequencies of all authentication behaviors; Based on the number of time windows, counting the number of first authentication behavior triggering frequencies of the authentication behavior; Calculating the ratio of the number of first authentication behavior triggering frequencies to the total sum of the triggering frequencies to obtain the proportion of the number of first authentication behavior triggering frequencies; Performing an average statistical calculation on the proportion of the number of first authentication behavior triggering frequencies to obtain the average proportion of the triggering frequencies in the multiple time windows.
5. The method according to claim 4, wherein Performing an average statistical calculation on the proportion of the number of first authentication behavior triggering frequencies to obtain the average proportion of the triggering frequencies in the multiple time windows, including: Calculating the time spans between the median times of the number of time windows and the current time; Calculating the ratio of the number of time spans to the duration of the preset time zone to obtain the weights of the number of time windows; Based on the weights of the several time windows, perform weighted mean statistics on the proportion of the trigger frequencies of the several first authentication behaviors to obtain the mean proportion of trigger frequencies in multiple time windows.
6. The method according to claim 1, characterized in that, When the authentication strength evaluation value is greater than or equal to the authentication strength threshold, based on a preset authentication factor array, construct a zero-knowledge proof R1CS constraint, including: Obtain a mandatory authentication factor array and a set of authentication factors to be optimized; Based on the authentication behaviors, perform frequent authentication factor combination mining on the set of authentication factors to be optimized to obtain a set of frequent authentication factor combinations; Add the set of frequent authentication factor combinations into the taboo combination space, and perform optimization of authentication factor combinations according to the expected number of authentication factors to obtain a target authentication factor combination; Based on the mandatory authentication factor array and the target authentication factor combination, construct the zero-knowledge proof R1CS constraint.
7. The method according to claim 6, characterized in that, Obtain a mandatory authentication factor array, including: Perform Toeplitz matrix compression on the hardware entropy source data acquired by the quantum noise acquisition component to generate a true random number seed; Collect the user's vital sign signals through a millimeter-wave radar array and extract the heartbeat phase modulation features; Generate a stable bit string of PUF responses through a PUF (Physical Unclonable Function); Add the true random number seed, the heartbeat phase modulation features, and the stable bit string of PUF responses into the mandatory authentication factor array.
8. The method according to claim 6, wherein Add the set of frequent authentication factor combinations into the taboo combination space, and perform optimization of authentication factor combinations according to the expected number of authentication factors to obtain a target authentication factor combination, including: Based on the expected number of authentication factors, avoid the taboo combination space and combine the set of authentication factors to be optimized to obtain a first authentication factor combination; Calculate the square of the mean of the factor type intersection and union ratio between the first authentication factor combination and the set of frequent authentication factor combinations, and set it as the first fitness; When the first fitness is greater than or equal to the fitness threshold, eliminate the first authentication factor combination; When the first fitness is less than the fitness threshold, add the first authentication factor combination into the set of candidate authentication factor combinations; When the number of combinations in the set of candidate authentication factor combinations is greater than or equal to the set number, select the authentication factor combination with the minimum fitness in the set of candidate authentication factor combinations as the target authentication factor combination.
9. A multi-node multi-factor security authentication system, characterized in that, For implementing the method according to any one of claims 1 to 8, the system includes: A malicious sample statistics module, configured to receive the authentication behaviors of the user terminal and retrieve the proportion of malicious authentication samples by statistically analyzing similar behavior samples; An abnormal weight determination module, configured to statistically calculate the mean proportion of trigger frequencies in multiple time windows of the authentication behaviors at the user terminal, and use 1 minus the mean proportion of trigger frequencies in multiple time windows as the abnormal weight; An authentication strength evaluation module, configured to weight the proportion of malicious authentication samples based on the abnormal weight to obtain an authentication strength evaluation value; A constraint construction module, configured to, when the authentication strength evaluation value is greater than or equal to the authentication strength threshold, construct a zero-knowledge proof R1CS constraint based on a preset authentication factor array; Signature verification module, which is used to perform BLS signature aggregation verification on the zero-knowledge proof R1CS constraints through a distributed node network to obtain an authentication log; Audit and evidence storage module, which is used to write the Merkle root of the authentication log into the blockchain to complete audit and evidence storage.
Citation Information
Patent Citations
Multi-factor identity authentication method supporting guaranteed level
CN110661800A
Account-free user unification method and system of construction and management system based on multimode authentication
CN119357939A
Security authentication method and device, equipment, storage medium and computer program product
CN119484063A
Multi-level dynamic network attack detection and response method
CN119966659A
Zero-knowledge proof generation method and device, equipment and storage medium
CN120021191A
Cited By
Authority dynamic authentication management method and system for trusted data space
CN120896792A