Security protection method for computer equipment

By embedding implicit frequency domain watermark signals in user operation data and combining deep learning models to generate behavior confidence, the problem of traditional authentication mechanisms being vulnerable to counterfeit attacks is solved, and the security and user experience balance in complex attack scenarios is achieved, and the security protection capabilities of the equipment are improved.

CN120493230AInactive Publication Date: 2025-08-15QINGDAO HAIKUOTIANGAO INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510725081.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-08-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional static authentication mechanisms are vulnerable to counterfeiting attacks. The security and user experience of a single behavior monitoring model are difficult to balance in complex attack scenarios. It is difficult for existing methods to effectively identify risk scenarios with legal identity but abnormal behaviors.

Method used

By embedding implicit frequency domain watermark signals in user operation data, combining deep learning models to generate behavior confidence, building behavior continuity index, and dynamic security decisions are made through collaborative analysis of multi-dimensional data to achieve lock screen or unlock control.

Benefits of technology

It enhances the system's resistance to complex attack scenarios, reduces the screen lock rate, improves the ability to identify illegal users, and ensures the security of the device in the case of hijacking or counterfeiting and the smoothness of normal use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120493230A_ABST
    Figure CN120493230A_ABST
Patent Text Reader

Abstract

The invention relates to the field of information security, and discloses a security protection method for computer equipment, which comprises the following steps of: embedding an implicit frequency domain watermark signal in user operation data, generating behavior confidence in real time through a deep learning model, and constructing a behavior continuity index in combination with equipment motion sensor data; synchronously extracting a watermark signal in the current operation data to carry out identity matching degree calculation; and designing a dynamic threshold adjustment mechanism to carry out collaborative analysis on the behavior confidence, the watermark matching degree and the behavior continuity index, establishing a hierarchical security decision logic, triggering active screen locking when an operation mode abnormity, an identity mismatching or an equipment motion abnormity is detected, and executing security unlocking when multi-condition cross validation is satisfied. According to the method, through dynamic coupling verification of identity authentication and behavior modes, the defect that a traditional static authentication mechanism is prone to counterfeit attacks is overcome, and the security protection strength in a complex attack scene and the operation smoothness in a normal use scene are both considered.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a security protection method for computer equipment. Background Art

[0002] Current security mechanisms for smart terminal devices rely heavily on static identity authentication and fixed-rule behavior monitoring, which presents significant limitations when responding to complex attack scenarios. Traditional authentication technologies typically rely on single-dimensional information such as preset passwords, biometrics, or hardware identifiers. While they can verify initial identity, they lack the ability to dynamically detect ongoing operational activity, making it difficult to effectively identify risky scenarios where legitimate identities may exhibit unusual behavior, such as involuntary manipulation after device hijacking or highly forged biometric attacks.

[0003] On the other hand, existing behavior monitoring solutions often rely on simple threshold determination or rule engines to analyze isolated operational characteristics. These methods lack the ability to model the correlation between temporal behavioral patterns, making them susceptible to interference from automated scripts or replay attacks. Furthermore, they struggle to distinguish between brief behavioral deviations and malicious attacks, leading to increased false positives. Furthermore, existing methods lack a deep coupling between authentication factors and behavioral characteristics, allowing attackers to exploit device fingerprint forgery and mimic operational patterns to breach the protection system in stages.

[0004] How to achieve real-time coordination between identity verification and behavior pattern analysis to improve the detection rate of complex attacks while reducing interference with normal use has become a technical problem that needs to be solved urgently. Summary of the Invention

[0005] In response to the shortcomings of the existing technology, the present invention provides a security protection method for computer equipment to solve the technical problems that traditional static authentication mechanisms are vulnerable to counterfeit attacks and single behavior monitoring models are difficult to balance security and user experience in complex attack scenarios.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: A computer device security protection method, characterized by comprising the following steps: Collect multi-dimensional behavioral data generated by user operations and embed implicit watermarks during the collection process; The following processing is performed based on the multi-dimensional behavior data after embedding the watermark: Calculate the behavioral continuity index; Generate behavior confidence through pre-trained dynamic behavior model; extracting and verifying the implicit watermark to generate a watermark match; Screen lock control or unlock control is performed according to the combination conditions of the behavior continuity index, behavior confidence and watermark matching degree.

[0007] The present invention also provides a computer equipment security protection device, comprising: The data collection and embedding module is used to collect multi-dimensional behavioral data generated by user operations in real time and embed implicit watermarks into the behavioral data during the collection process; Behavioral analysis module, which performs the following operations: Calculating a behavior continuity index based on the multi-dimensional behavior data; Processing the behavior data using a pre-trained dynamic behavior model to generate behavior confidence; A watermark verification module, configured to extract an implicit watermark from the behavioral data and verify the watermark matching degree; The security decision module is used to trigger the lock screen or unlock operation according to the combined logical conditions of the behavior continuity index, behavior confidence and watermark matching degree.

[0008] The present invention also provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned method when executing the computer program.

[0009] The present invention also provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the method described above is implemented.

[0010] The present invention provides a computer device security protection method having the following beneficial effects: 1. This invention builds a multi-dimensional cross-validation system by integrating the identity verification mechanism of implicit watermarks with the real-time monitoring capabilities of dynamic behavioral models. The watermark signal is generated based on the dynamic binding of device fingerprints and user identity factors, ensuring that unauthorized users cannot forge a valid identity through a single means. The behavioral confidence and continuity indexes capture subtle anomalies in dimensions such as operational rhythm and interaction patterns, compensating for the vulnerability of traditional static passwords or biometrics to counterfeit attacks. The dual authentication mechanism forms a defense-in-depth defense, significantly enhancing the system's resistance to complex attack scenarios such as identity forgery and device hijacking.

[0011] 2. This invention utilizes dynamic threshold adjustment and multi-condition hierarchical decision-making logic, enabling the system to adaptively adjust its judgment criteria based on real-time environmental noise and changes in user behavior. Compared to fixed threshold solutions, this design significantly reduces the false lock rate in scenarios with low signal-to-noise ratios or brief behavioral deviations, preventing frequent verification from interfering with normal user operations. Furthermore, through the coordinated analysis of watermark matching and device motion parameters, the system can quickly identify high-risk anomalies and trigger emergency protection, achieving a balance between security and user experience.

[0012] 3. Against emerging threats such as replay attacks and automated script attacks, the dynamic time-sensitive binding of implicit watermarks and the temporal correlation learning of behavioral models provide dual protection. The time sensitivity of the watermark signal prevents it from being intercepted and reused, and the behavioral model's deep perception of operational consistency effectively identifies mechanical operation characteristics. The combined judgment criteria of multimodal parameters prevents system failure caused by tampering or bypassing of a single feature, ensuring stable and reliable security protection in scenarios such as device loss and unauthorized access. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 Schematic diagram of the method flow of the present invention; Figure 2 Schematic diagram of the device structure of the present invention; Figure 3 Schematic diagram of the computer device structure of the present invention.

[0014] Among them, 100, data collection and embedding module; 200, behavior analysis module; 300, watermark verification module; 400, security decision module; 40, computer equipment; 41, processor; 42, memory; 43, storage medium. DETAILED DESCRIPTION

[0015] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the present specification. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0016] Please see the attached Figure 1 The present invention provides a security protection method for computer equipment, which realizes dynamic security protection through a multimodal collaborative mechanism that integrates user behavior pattern analysis, implicit identity watermarking and physical state verification.

[0017] like Figure 1 As shown, the computer device security protection method may include the following steps: S1. Real-time collection of multi-dimensional behavioral data generated by user operations, and simultaneous embedding of implicit watermarks during the data collection process; S2. Based on the multi-dimensional behavior data after embedding the watermark, the behavior continuity index is calculated through a preset algorithm to quantify the temporal continuity characteristics of user operations; S3, input the multi-dimensional behavior data after embedding the watermark into the pre-trained dynamic behavior model and output the user behavior confidence; S4, extracting the implicit watermark from the multi-dimensional behavioral data after the watermark is embedded, and generating a watermark matching parameter; S5. The combined logical conditions of the comprehensive behavior continuity index, behavior confidence and watermark matching degree trigger the lock screen or unlock control command.

[0018] The following is a detailed description of each step in the method of the present invention, which comprehensively explains the specific implementation principles, technical details and processes of each step.

[0019] Regarding step S1, in this embodiment, the real-time data collection and watermark embedding steps achieve a complete record of user operation characteristics and covert binding of identity identification through the synchronous capture of multi-dimensional behavioral data and the imperceptible embedding of implicit watermarks. The specific technical implementation is as follows: In this embodiment, the collection scope of multi-dimensional behavioral data covers the timing, kinematics and physical state characteristics of the device generated during the user operation process, and high-precision data acquisition is achieved through the collaborative capture and signal preprocessing mechanism of multi-source heterogeneous sensors.

[0020] Preferably, the multi-dimensional behavior data includes a keyboard input time interval sequence, a mouse movement acceleration sequence, and a device acceleration vector.

[0021] Keyboard operation data captures the precise timestamp of key events in real time through the underlying driver interface of the operating system. The time difference between two adjacent key events is defined as the time interval sequence element: in, For the The system clock count value of the key event occurs, preferably, the timing accuracy is not less than 1 millisecond. The time interval sequence is output after the sliding window cache is The window length is dynamically adjusted according to the application scenario. Preferably, the window contains 10 to 50 consecutive key events.

[0022] Mouse operation data is processed by the second differential of the cursor displacement trajectory to obtain acceleration characteristics. First, the coordinate sequence of the cursor in the two-dimensional plane is recorded. , calculate the instantaneous velocity vector: Then the acceleration vector is calculated by time difference: in, is the sampling interval (preferably, ), and finally generate the mouse acceleration amplitude sequence .

[0023] The device's built-in inertial measurement unit (IMU) acquires three-dimensional acceleration data in real time. The three-axis acceleration in the device coordinate system is defined as: The acceleration data of each axis is low-pass filtered to remove high-frequency noise (preferably, the cutoff frequency is set to 15 Hz), and gravity acceleration compensation is performed: In the formula is the gravity component estimated by the Kalman filter. The processed acceleration vector is used to characterize the unsteady motion characteristics of the device.

[0024] Sensor data is collected and synchronized using hardware interrupts or high-precision timers. A cross-device clock calibration mechanism based on the Network Time Protocol (NTP) is preferably used to ensure that keyboard, mouse, and IMU data timestamps are within 1 millisecond of each other. After the raw data stream is temporarily stored in a circular buffer, it is interpolated and aligned according to a unified time base to generate a multimodal behavioral data matrix with consistent temporal dimensions.

[0025] In this embodiment, the implicit watermark generation and encoding process converts the user identity into a frequency domain characteristic signal and uses the spectrum redundancy characteristics of human operation behavior to achieve covert embedding. The specific technical implementation is as follows: Generate a fixed-length binary watermark sequence based on the unique characteristic information of the device (such as the hash value of the hardware serial number or the account token). Use the hash function to irreversibly map the original identification information to generate the initial binary sequence. ,in Preferably, the SHA-256 algorithm is used to generate a 256-bit hash value, and the bits as a watermark sequence (preferably, ), while ensuring uniqueness and reducing computational complexity.

[0026] Convert the binary sequence into a complex signal component in the frequency domain to achieve energy diffusion of the watermark information in the frequency domain. Specifically, for each binary bit Perform discrete Fourier transform to generate frequency domain watermark signal components: in, The frequency parameter is preset and its value range is limited to the interval [0.5 Hz, 2 Hz]. This frequency band is selected based on the timing characteristics of natural human operation behavior. The frequency fluctuation of key intervals in conventional keyboard operations usually falls within this range. This causes the spectral characteristics of the watermark signal to overlap with the actual operation data, reducing the probability of anomaly detection.

[0027] In order to avoid watermark leakage caused by excessive energy at a single frequency point, energy normalization is performed on the watermark signal: The normalized watermark signal is further compared with the random phase matrix Perform convolution operation to generate the final frequency domain watermark signal: Among them, the introduction of random phase matrix is used to destroy the regularity of the watermark signal and enhance the resistance to frequency domain analysis.

[0028] In this embodiment, after the frequency domain watermark signal is generated, the frequency domain watermark signal is converted into a time domain real part signal through inverse Fourier transform: in, is the discrete time index, is the preset frequency point. The reconstructed time domain watermark signal Sequence with original keyboard time interval Aligned in time dimension.

[0029] The time domain watermark signal is embedded into the keyboard time interval sequence in a linear superposition manner to generate a watermarked data sequence: in, is the watermark strength coefficient, and its value range is set according to the human perception threshold. Preferably, it is determined by the Weber-Fechner law. The upper limit of the value of is set to ensure that the timing fluctuation caused by the watermark does not exceed 10% of the natural fluctuation range of the original data, so as to avoid users' perception of operation delay.

[0030] This embodiment uses keyboard time interval sequences as the watermark embedding medium. Compared to mouse trajectory or device acceleration data, the discrete and discontinuous nature of keyboard operations makes time interval data inherently more noise-tolerant, effectively masking minor perturbations introduced by watermark embedding. Furthermore, keyboard data is primarily used in the subsequent behavior analysis module to calculate the behavior continuity index. Its macro-statistical properties (such as mean and variance) are less sensitive to micro-time series fluctuations, ensuring that watermark embedding does not significantly impact the accuracy of behavior analysis results.

[0031] On the other hand, watermark signals are embedded only in non-critical keyboard operation intervals. By identifying pauses between consecutive input events (e.g., intervals where the interval between two keystrokes is greater than 200 milliseconds), watermark superposition is prioritized in these low-sensitivity intervals. This strategy avoids introducing additional perturbations during periods of high-frequency user operation, further minimizing the potential impact of the watermark on normal operation.

[0032] Regarding step S2, in this embodiment, the calculation of the behavior continuity index quantifies the temporal continuity characteristics of the user's operation behavior to construct an indicator parameter reflecting the stability of the operation habit. The specific technical implementation method is as follows: First, based on the keyboard time interval sequence after embedding the watermark , perform normalization to eliminate the impact of dimensional differences on subsequent calculations. The normalization formula is defined as: in, is the arithmetic mean of the time interval data in the current sliding window, Preferably, a dynamic sliding window mechanism is adopted, and the window length is adaptively adjusted according to the user's historical operating habits to ensure the timeliness of the statistical parameters.

[0033] In this embodiment, the determination of the effective operation period is achieved through dynamic threshold segmentation technology, which aims to distinguish the boundary between continuous operation behavior and user-initiated pause. , a sliding window mechanism is used to detect the continuous operation interval in real time. Less than threshold , it is determined to be a valid operation event. The cumulative duration of the valid operation period All satisfaction through points The length of the continuous interval is obtained.

[0034] When the time interval between keyboard or mouse operations exceeds the preset threshold When , it is determined to be an operation pause event. The total number of pause events in the cumulative monitoring period is .

[0035] Based on the statistical results of effective operation duration and pause times, a composite index is constructed to quantify the continuity characteristics of user operations. The calculation formula of the behavior continuity index is defined as: in, The effective operation time is defined as the continuous keyboard or mouse operation time; is the total duration of the monitoring period, is the natural logarithm function.

[0036] The first term in the formula reflects the proportion of effective operation time, and the second term uses a logarithmic function to suppress the excessive attenuation effect of high-frequency pauses on the index value, so that the final index is continuously distributed in the interval [0,1].

[0037] Preferably, the threshold parameter and Periodic updates are performed based on historical user operation data. The update rules are: Dynamic Threshold Based on the user's historical operation mode self-learning generation, the initial value is set to the global default value (preferably, 2 seconds), and then exponentially weighted update is performed based on the user's recent operation data: in, is the weighted average of the last N valid operation durations. is the forgetting factor, which is used to balance the changes in historical data and current operating mode.

[0038] Regarding step S3, in this embodiment, the dynamic behavior model inference step uses a pre-trained deep learning network to extract multi-scale temporal features from user operation data to generate confidence parameters that represent the legitimacy of the behavior. The specific technical implementation is as follows: The multimodal input data is constructed as follows: The keyboard time interval sequence after embedding the watermark With mouse acceleration sequence Perform time series alignment and feature splicing to generate a joint input matrix Preferably, a sliding window mechanism is used to segment the original data, and the window length is adaptively adjusted according to the user operation frequency (including 50 to 200 consecutive sampling points). The window step is set to 1 / 4 of the window length to balance computational efficiency and feature continuity.

[0039] In this embodiment, the dynamic behavior model adopts a depthwise separable convolutional structure, which includes the following core components: Input layer: The receiving dimension is A time series data matrix, where is the number of sampling points in the window, 2 corresponds to the dual-channel characteristics of keyboard and mouse.

[0040] Multi-scale convolution group: Three sets of convolution kernels are deployed in parallel, with their sizes set to the short (3 points), medium (5 points), and long (7 points) ranges to capture the correlation of operation modes at different time spans. Each set of convolution kernels performs depth-wise separable convolution operations: in, is the depth convolution kernel weight, is the point-by-point convolution kernel weight, Represents the convolution group index.

[0041] Feature fusion layer: concatenates the three sets of convolution outputs along the channel dimension and implements cross-scale feature interaction through 1×1 convolution: Temporal Attention Mechanism: Introducing the self-attention module to assign dynamic weights to key time points: in, They are query and key-value matrices respectively, and are transformed from feature maps through linear transformation Generated in.

[0042] Global pooling and fully connected layer: Use maximum pooling to compress the time series dimension, output 128-dimensional high-level feature vector, and generate behavior confidence through Sigmoid activation function .

[0043] In this embodiment, the training process of the dynamic behavior model is implemented based on a supervised learning framework, and network parameters are optimized by fusing multimodal behavior data with annotation information. The specific technical implementation is as follows: Training data construction: 1. Positive sample collection: Collect the target user's keyboard time interval sequence in normal operation state and mouse acceleration sequence , after being intercepted by the sliding window, a time series sample is generated , marked as a legal operation ( ).

[0044] 2. Negative sample synthesis: Synthesize abnormal behavior data through the following methods: Cross-user data migration: Use other users’ legitimate operation data as abnormal samples of the current user ( ); Temporal pattern destruction: Random interval insertion, local sequence flipping, or acceleration amplitude scaling are applied to positive samples to generate negative samples that deviate significantly from the original pattern.

[0045] A class-balanced binary cross entropy loss function is used to solve the problem of imbalance in the number of positive and negative samples: in, is the negative sample weight coefficient, The confidence level of the behavior output by the model.

[0046] The optimization strategy is as follows: Adaptive learning rate scheduling: The initial learning rate is set to a preset value (preferably 0.001), and is dynamically adjusted based on the training loss curve: if the loss does not decrease over multiple training cycles, the learning rate is proportionally decayed (preferably with a decay factor of 0.1).

[0047] Gradient normalization: Perform L2 norm clipping on the gradient tensor during backpropagation to limit the gradient update amplitude (preferably, the maximum norm is 5.0) to avoid violent parameter fluctuations.

[0048] Regularization constraint: Introduce the L2 weight decay term (preferably, the decay coefficient is 0.0001) in the fully connected layer to suppress the risk of overfitting.

[0049] The training process is as follows: 1. Network parameter initialization: The weights of the depthwise separable convolution kernel are initialized using the He normal distribution, and the bias term is initialized to zero; the attention module query matrix QQ and the key-value matrix K, V are initialized using the Xavier uniform distribution.

[0050] 2. Forward propagation: The input matrix X is passed through the multi-scale convolution group, feature fusion layer and time-series attention module in sequence to generate high-level feature vectors and calculate the behavior confidence .

[0051] 3. Loss calculation and backpropagation: Calculate the loss value based on the prediction confidence and the true label, update the network parameters using the chain derivative rule, and prioritize optimizing the parameters of the classification head layer to accelerate convergence.

[0052] 4. Iteration termination condition: Training is terminated when the validation set loss does not decrease for a preset number of cycles (preferably 10 cycles) or the total number of training cycles reaches a preset upper limit (preferably 100 cycles).

[0053] Model validation and deployment: Early stopping mechanism: retains the model parameter snapshot with the best performance on the validation set to avoid overfitting noisy data.

[0054] Precision compression: Convert the trained floating-point model to a fixed-point format (preferably INT8 quantization) to reduce computing resource consumption while ensuring that the prediction error is less than a preset threshold (preferably 2%).

[0055] During the deployment phase, pre-trained model parameters are loaded and forward propagation calculations are performed on the windowed data collected in real time. Preferably, double-precision floating-point operations are used to ensure numerical stability, and the output confidence is filtered by exponential moving average: in, is a smoothing factor used to suppress confidence fluctuations caused by instantaneous noise.

[0056] Regarding step S4, in this embodiment, the implicit watermark extraction and verification step generates a watermark matching parameter representing the legitimacy of the identity by performing frequency domain feature analysis and sequence matching on the operation data after embedding the watermark. The specific technical implementation is as follows: For the watermarked keyboard time interval sequence Perform a discrete Fourier transform (DFT) to convert the time domain signal to the frequency domain: in, is the frequency component index, is the signal length. According to the predefined embedded frequency band range, the complex signal component of the corresponding interval is intercepted in the frequency domain , as the estimated value of the watermark signal to be verified.

[0057] In order to eliminate the interference of inherent noise of operation data on watermark extraction, bandpass filtering and phase randomization are performed on the intercepted frequency domain signal. The pre-stored random phase matrix is used. Perform a deconvolution operation on the estimated signal: in, is the inverse matrix of the random phase matrix, which is used to restore the phase perturbation introduced in the watermark generation stage. Through this operation, the amplitude distribution characteristics of the watermark signal in the frequency domain are restored, while the incoherent noise components are suppressed.

[0058] In this embodiment, the recovery of the binary watermark sequence is achieved through frequency domain signal analysis and adaptive threshold determination technology, which specifically includes the following processing flow: For the phase-corrected frequency domain signal Calculate the real part amplitude at each frequency point: in, The frequency point sequence is a predefined embedded frequency point sequence, and its arrangement order strictly corresponds to the coding rule in the watermark generation stage. Preferably, a pseudo-random frequency hopping mode is used to allocate the frequency point position corresponding to each binary bit to enhance the anti-interference ability of the watermark signal.

[0059] Based on the amplitude of the filtered frequency domain signal, the original binary watermark sequence is restored through dynamic threshold determination. , calculate its actual amplitude and compare it with the decoding threshold Compare: Preferably, the decoding threshold Dynamically adjust based on the signal-to-noise ratio (SNR) of the current frequency band signal: in, and are the mean and standard deviation of the noise frequency band, is the sensitivity coefficient. This dynamic threshold mechanism ensures that the effective watermark bit can be stably extracted in a low signal-to-noise ratio environment.

[0060] In this embodiment, the matching parameter is obtained by statistically analyzing the original watermark sequence. With decoding sequence The spatiotemporal consistency of quantified identity legitimacy is calculated as follows: The binary sequence to be extracted With the pre-registered original watermark sequence Perform similarity measurement. Use the normalized cross-correlation coefficient (NCC) as the matching index: in, and are the means of the original sequence and the extracted sequence, is the watermark matching correlation coefficient, is the preset binary watermark sequence The elements, is the binary watermark sequence extracted from the current operation data The elements, is the total length of the watermark sequence.

[0061] Preferably, a nonlinear transformation is performed on the correlation coefficient to enhance the discrimination: Where, is the slope adjustment factor, The linear correlation coefficient is mapped to the interval [0,1] as the decision center point.

[0062] Regarding step S5, in this embodiment, a hierarchical device access control mechanism is constructed by integrating the behavior continuity index, behavior confidence and watermark matching degree. The specific technical implementation is as follows: Lock screen control trigger logic: When the device detects any of the following conditions, it immediately triggers the screen lock operation and starts the identity re-authentication process: The first trigger condition: behavioral confidence Below the first preset threshold , and the standard deviation of device acceleration Higher than the second preset threshold Among them, the calculation formula for the standard deviation of equipment acceleration is: Where, is the average value of the device acceleration amplitude in the current time window, is the number of sampling points. Preferably, the condition is implemented by combining logical operators: Second trigger condition: Behavior continuity index BCI is lower than the third preset threshold , and the watermark matching degree Below the fourth preset threshold The conditional expression is: Unlock control trigger logic: When any of the following authentication conditions is met, the device is unlocked and user access rights are restored: Active unlocking condition: Behavior confidence Above the fifth preset threshold , and the behavioral continuity index BCI is higher than the sixth preset threshold . The threshold relationship satisfies and , ensuring that the unlocking criteria are stricter than the locking criteria. The conditional expression is: Auxiliary unlocking condition: watermark matching Higher than the fourth preset threshold , device acceleration standard deviation Below the seventh preset threshold , and the behavioral confidence Higher than the eighth preset threshold This condition is achieved through a triple joint criterion: The first lock screen condition targets sudden anomalies (such as device theft), quickly identifying involuntary actions through a coordinated assessment of behavioral confidence and the device's physical motion characteristics. The second lock screen condition targets persistent anomalies (such as automated script attacks), leveraging the dual evidence of behavioral continuity degradation and watermark identity failure to enhance identification reliability.

[0063] Active unlocking is based on a high-confidence determination that the user has resumed normal operation and is suitable for routine unlocking scenarios. Auxiliary unlocking is a backup verification channel. When the primary behavioral characteristics are temporarily distorted by environmental interference, secure unlocking is achieved through watermark identity verification and device stability testing, avoiding a degraded user experience caused by accidental locks.

[0064] Preferably, the preset threshold Initialize based on historical user operation data and dynamically fine-tune using sliding window statistics during operation. For example, the update rule is: Where, and are the mean and standard deviation of the confidence of recent behavior, is the smoothing factor, This mechanism allows the decision threshold to dynamically shift as the user's behavior pattern changes, maintaining a balance between detection sensitivity and false alarm rate.

[0065] When both the lock and unlock conditions are met, the lock screen operation is executed based on the principle of security priority. Preferably, a state machine model is used to manage the device control process, defining the "locked" state as the highest priority. The device switches to the "unlocked" state only after the unlock conditions are continuously met for a preset period of time (preferably 5 seconds), preventing control oscillation caused by instantaneous state jumps.

[0066] In general, the present invention uses a deep learning model to extract the multi-scale temporal features of user operation behavior in real time to generate behavior confidence, combines the frequency domain watermark signal decoding embedded in the keyboard operation data to verify the legitimacy of the identity, and integrates the device motion sensor data to construct a behavior continuity index to form a multi-dimensional security assessment parameter; a dynamic threshold adjustment mechanism is used to collaboratively analyze the behavior confidence, watermark matching and behavior continuity index, and a hierarchical decision logic is established. When an abnormal operation mode, identity mismatch or abnormal device movement is detected, an active lock screen is triggered, and a secure unlock is performed when multiple conditions are cross-verified, thereby realizing dual authentication of user identity and behavior pattern, reducing the misjudgment rate while ensuring security.

[0067] The security protection device for a computer device described below and the security protection method for a computer device described above may refer to each other.

[0068] Please see the attached Figure 2 The present invention also provides a computer equipment security protection device, comprising: The data collection and embedding module 100 is used to collect multi-dimensional behavior data generated by user operations in real time and embed implicit watermarks into the behavior data during the collection process; The behavior analysis module 200 is configured to perform the following operations: Calculating a behavior continuity index based on the multi-dimensional behavior data; Processing the behavior data using a pre-trained dynamic behavior model to generate behavior confidence; A watermark verification module 300 is used to extract an implicit watermark from the behavior data and verify the watermark matching degree; The security decision module 400 is used to trigger the screen lock or unlock operation according to the combined logical conditions of the behavior continuity index, behavior confidence and watermark matching degree.

[0069] The device of this embodiment can be used to execute the above method embodiment, and its principles and technical effects are similar, so they will not be repeated here.

[0070] Please see the attached Figure 3The present invention further provides a computer device 40, comprising: a processor 41 and a memory 42, wherein the memory 42 stores a computer program executable by the processor, and when the computer program is executed by the processor, the above method is performed.

[0071] The present invention further provides a storage medium 43 on which a computer program is stored. When the computer program is run by the processor 41 , the above method is executed.

[0072] Among them, the storage medium 43 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.

[0073] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A computer equipment security protection method, characterized in that: The following steps are involved: Collect multi-dimensional behavioral data generated by user operations and embed implicit watermarks during the collection process; The following processing is performed based on the multi-dimensional behavior data after embedding the watermark: Calculate the behavioral continuity index; Generate behavior confidence through pre-trained dynamic behavior model; extracting and verifying the implicit watermark to generate a watermark match; Screen lock control or unlock control is performed according to the combination conditions of the behavior continuity index, behavior confidence and watermark matching degree.

2. The computer equipment security protection method according to claim 1, characterized in that: The multi-dimensional behavioral data includes: Keyboard input time interval sequence, mouse movement acceleration sequence, and device three-dimensional acceleration data collected by the accelerometer.

3. The computer equipment security protection method according to claim 2, characterized in that: The calculation of the behavioral continuity index includes: Normalize the keyboard input time interval sequence and mouse movement acceleration sequence; Calculate the behavioral continuity index: in, The effective operation time is defined as the continuous keyboard or mouse operation time; is the total monitoring time; The number of operation pauses; is the natural logarithm function.

4. The computer equipment security protection method according to claim 3, characterized in that: The dynamic behavior model is a one-dimensional convolutional neural network that includes multi-scale depth-separable convolution and self-attention mechanism. The input layer receives the concatenation matrix of the keyboard time interval sequence and mouse acceleration sequence embedded with watermarks. After temporal feature extraction and weighting, it is compressed by the global pooling layer and outputs the behavior confidence generated by the Sigmoid function.

5. The computer equipment security protection method according to claim 1, characterized in that: The step of embedding the implicit watermark comprises: Convert the user's unique identity into a binary sequence; Generate frequency domain watermark signal through Fourier transform based on binary sequence; Convert the frequency domain watermark signal into the time domain watermark signal through inverse Fourier transform; Superimpose the time domain watermark signal onto the keyboard input time interval sequence: in, is the watermark strength coefficient, is the original keyboard interval sequence, is the time domain watermark signal.

6. The computer equipment security protection method according to claim 5, characterized in that: The step of extracting and verifying the implicit watermark to generate a watermark matching degree comprises: Perform discrete Fourier transform on the keyboard time interval sequence containing watermark to extract the frequency domain signal component; The signal components are intercepted within the preset embedding frequency band, and the binary sequence is restored by amplitude threshold determination; Calculate the correlation coefficient to generate the match: in, is the watermark matching correlation coefficient, is the preset binary watermark sequence The elements, is the binary watermark sequence extracted from the current operation data The elements, Preset watermark sequence The mean of To extract the watermark sequence The mean of is the total length of the watermark sequence.

7. The computer equipment security protection method according to claim 1, characterized in that: The triggering conditions for the lock screen control include: First trigger condition: the behavior confidence is lower than the first preset threshold and the device acceleration standard deviation is higher than the second preset threshold; Second trigger condition: the behavior continuity index is lower than the third preset threshold and the watermark matching degree is lower than the fourth preset threshold.

8. The computer equipment security protection method according to claim 7, characterized in that: The triggering conditions for the unlocking control include: Active unlocking condition: the behavior confidence level is higher than a fifth preset threshold and the behavior continuity index is higher than a sixth preset threshold, wherein the fifth preset threshold is higher than the first preset threshold, and the sixth preset threshold is higher than the third preset threshold; Auxiliary unlocking conditions: the watermark matching degree is higher than the fourth preset threshold, the device acceleration standard deviation is lower than the seventh preset threshold, and the behavior confidence is higher than the eighth preset threshold.

9. A computer equipment security protection device, used to execute the method according to any one of claims 1 to 8, characterized in that: include: The data collection and embedding module is used to collect multi-dimensional behavioral data generated by user operations in real time and embed implicit watermarks into the behavioral data during the collection process; Behavioral analysis module, which performs the following operations: Calculating a behavior continuity index based on the multi-dimensional behavior data; Processing the behavior data using a pre-trained dynamic behavior model to generate behavior confidence; A watermark verification module, configured to extract an implicit watermark from the behavioral data and verify the watermark matching degree; The security decision module is used to trigger the lock screen or unlock operation according to the combined logical conditions of the behavior continuity index, behavior confidence and watermark matching degree.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.