Power transaction login management system and method based on multi-dimensional identity verification

Through a multi-dimensional identity authentication system, multi-level verification credential data is generated by combining facial images, historical behavior data and user attribute information, which solves the problem of insufficient security of traditional power trading login systems and achieves higher security and reliability.

CN120639348AInactive Publication Date: 2025-09-12GUANGZHOU ELECTRIC POWER TRADING CENT CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510692314.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-09-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The traditional electricity trading login system is not secure enough and cannot meet high security requirements. The existing identity authentication method only uses single-dimensional verification, resulting in low reliability.

Method used

A multi-dimensional identity authentication system is adopted, including the first identity authentication based on facial images, transaction stability characteristic value analysis of historical behavior data, and user attribute information verification. By combining multiple identity authentication methods, multi-level verification credential data is generated to determine user permissions.

Benefits of technology

It improves the security and reliability of the power trading login system, increases the difficulty for attackers to crack identity authentication, prevents illegal users from entering the system, and ensures the security and integrity of power trading data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639348A_ABST
    Figure CN120639348A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of identity verification, in particular to a power transaction login management system and method based on multi-dimensional identity verification. The method comprises the following steps: responding to an identity verification request, verifying first identity verification information, generating first verification credential data, receiving and analyzing the first verification credential data to obtain a first analysis result, and judging whether to grant a first power transaction authority to a user based on the first analysis result; analyzing the historical behavior data to obtain a transaction stable characteristic value, collecting second identity verification information of the user based on the transaction stable characteristic value, verifying the second identity verification information, and generating second verification credential data; and receiving and analyzing the second verification credential data to obtain a second analysis result, and judging whether to grant a second power transaction authority to the user based on the second analysis result, so that the difficulty of attackers in cracking identity authentication can be increased by combining a plurality of identity authentication modes, and the security and integrity of power transaction data are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of identity authentication, and in particular to an electricity transaction login management system and method based on multi-dimensional identity authentication. Background Art

[0002] With the continuous deepening of power market reform and the rapid development of power trading, the power trading system has become the core platform for power market operations. However, with the continuous increase in the number of system users and the increasing complexity of trading operations, the security, convenience, and reliability of power trading login management systems face unprecedented challenges.

[0003] Traditional identity authentication methods, such as username / password authentication and dynamic password authentication, are easy to operate, but most of them allow users to directly obtain corresponding high-level permissions after a single identity authentication. This results in the power trading login system being vulnerable to a cyber attack. After one identity authentication is successful, no further identity authentication is performed, resulting in insufficient security for the power trading login system and making it difficult to meet the high security requirements of the power trading system.

[0004] Therefore, there is an urgent need for an electricity trading login management system and method based on multi-dimensional identity authentication to solve the above problems. Summary of the Invention

[0005] The purpose of the present invention is to provide an electricity trading login management system and method based on multi-dimensional identity authentication: it aims to solve the problem that the traditional electricity trading login identity authentication method only adopts a single-dimensional identity authentication method, resulting in insufficient security and low reliability of the electricity trading login system.

[0006] The purpose of the present invention can be achieved through the following technical solutions:

[0007] On the one hand, the power transaction login management system based on multi-dimensional identity authentication includes:

[0008] a first identity authentication unit, configured to respond to the identity authentication request and collect first identity authentication information of the user, verify the first identity authentication information, and generate first authentication credential data, wherein the first identity authentication information includes a facial image of the user;

[0009] an electricity trading login unit, configured to receive and parse the first verification credential data to obtain a first parsing result, and determine whether to grant the user the first electricity trading authority based on the first parsing result;

[0010] a second identity authentication unit configured to collect historical behavior data of the user under the first power trading authority, parse the historical behavior data to obtain a transaction stability characteristic value, collect second identity authentication information of the user based on the transaction stability characteristic value, verify the second identity authentication information, and generate second verification credential data;

[0011] The power transaction management unit is configured to receive and parse the second verification credential data to obtain a second parsing result, and determine whether to grant the user the second power transaction authority based on the second parsing result.

[0012] Furthermore, verifying the first identity verification information and generating the first verification credential data specifically includes the following process:

[0013] Extract feature vectors from the user's face image, perform preliminary clustering on the feature vectors based on the k-means algorithm, and obtain the category and cluster center corresponding to each feature vector;

[0014] Constrain the distance between the feature vector and its class center based on the intra-class tight constraint:

[0015]

[0016] Among them, L C is the compact constraint within the class, the eigenvector x i ∈R K , R represents a real vector, K represents the dimension of the eigenvector, y i represents the eigenvector x i Category, represents the class center vector, N represents the number of eigenvectors, and ||·||2 represents the modulo operation of the two-norm;

[0017] Separate the cluster centers based on inter-cluster repulsion:

[0018] Among them, L A is the inter-class repulsive force, cos(θ j ) represents the cluster center and the eigenvector x i The cosine similarity between is the eigenvector x i With the eigenvector x i Category y i The angle between them, s is the scaling factor, n is the total number of categories, and m is the angle margin;

[0019] L C With L A The sum of is used as the loss function to learn the feature vector and obtain the fusion feature to be identified;

[0020] A similarity calculation is performed between the fused feature to be identified and the preset fused feature stored in the feature access stack of the first identity verification unit to obtain a similarity, and the similarity is recorded as the first verification credential data.

[0021] Furthermore, similarity calculation is performed between the fused feature to be identified and the preset fused feature stored in the feature access stack of the first identity verification unit to obtain the similarity, specifically including the following process:

[0022]

[0023] Among them, Dist represents the similarity, Represents the i-th eigenvector value of the fusion feature to be identified, Represents the i-th eigenvector value of the preset fusion feature, and K is the dimension size of the feature vector.

[0024] Furthermore, receiving and parsing the first verification credential data to obtain a first parsing result, and determining whether to grant the user the first power trading authority based on the first parsing result specifically includes the following process:

[0025] Loading a similarity threshold, comparing the similarity with the similarity threshold, and obtaining a first parsing result;

[0026] If the first analysis result shows that the similarity does not exceed the similarity threshold, determining that the first identity authentication information of the user fails the verification, generating a verification failure signal, not granting the user the first power trading authority, and storing the verification failure signal;

[0027] If the first analysis result shows that the similarity exceeds the similarity threshold, it is determined that the first identity authentication information of the user has passed the verification, a verification success signal is generated, and the user is granted the first electricity trading authority.

[0028] Furthermore, parsing historical behavior data to obtain transaction stability feature values ​​specifically includes the following process:

[0029] Based on the historical behavior data, the user's first transaction information, second transaction information, and Gth transaction information are obtained, wherein the first transaction information includes a first browsing time redundancy, a first quotation number redundancy, and a first repeated quotation number; the Gth transaction information includes a Gth browsing time redundancy, a Gth quotation number redundancy, and a Gth repeated quotation number, wherein the browsing time redundancy is the difference between the time the user browses the power trading market before the transaction and a preset time, the quotation number redundancy is the difference between the number of quotations the user makes to the power generation manufacturer or power user before the transaction and the preset quotation number, and the repeated quotation number is the number of times the user modifies the quotation to the power generation manufacturer or power user before the transaction;

[0030] Substitute the first browsing time redundancy, the first quotation number redundancy and the first repeated quotation number into the first transaction stability coefficient calculation formula to obtain the first transaction stability coefficient. The first transaction stability coefficient calculation formula is: Where LMS is the first transaction stability coefficient, SC is the first browsing time redundancy, BJ is the first quotation number redundancy, and CB is the first repeated quotation number, until the Gth transaction stability coefficient is calculated;

[0031] Set a transaction stability coefficient threshold, compare each transaction stability coefficient with the transaction stability coefficient threshold, record transaction stability coefficients that are higher than the transaction stability coefficient threshold as positive data, and record transaction stability coefficients that are lower than or equal to the preset transaction stability coefficient threshold as abnormal data;

[0032] Count the number of abnormal data YC and the number of positive data PT, substitute YC and PT into the transaction stability characteristic value calculation formula: GL = (PT × γ - YC × δ) / (γ + δ), and calculate the transaction stability characteristic value GL, where γ is the positive data coefficient and δ is the abnormal data, and their values ​​are 0.6 and 0.25 respectively.

[0033] Furthermore, collecting the user's second identity verification information based on the transaction stability feature value specifically includes the following process:

[0034] The transaction stability characteristic value threshold is loaded, and it is determined whether the transaction stability characteristic value exceeds the stability characteristic value threshold. If so, a collection signal is generated to collect the user's second identity authentication information; if not, no collection signal is generated.

[0035] Furthermore, verifying the second identity verification information and generating the second verification credential data specifically includes the following process:

[0036] The second authentication information includes the user's identity identifier and identity attribute information. The identity attribute file in the storage system is queried based on the user's identity identifier, and the identity attribute information is compared and verified with the identity attribute file. The identity attribute information includes the user's IP address information, the user's node code information, the user's geographic location information, and the user's permissions.

[0037] Determine whether the user's IP address information, the user's node code information, and the user's geographic location information are abnormal. If not, the security verification parameter YZ is 1; if so, the security verification parameter YZ is 0;

[0038] Obtain the user's transaction stability characteristic values ​​over several historical periods, with the execution time of the historical period as the X-axis and the transaction stability characteristic value as the Y-axis. Mark all transaction stability characteristic values ​​as points in a rectangular coordinate system, connect adjacent points in the rectangular coordinate system to generate a transaction stability characteristic curve, draw perpendicular lines from both ends of the transaction stability characteristic curve to the X-axis to obtain two start and end line segments, and form a closed figure with the transaction stability characteristic curve, the two start and end line segments, and the X-axis. Mark the total area of ​​the closed figure as the second verification representation value;

[0039] The product of the security verification parameter and the second verification representation value is recorded as the second verification credential data.

[0040] Furthermore, determining whether the user's IP address information, the user's node code information, and the user's geographic location information are abnormal specifically includes the following process:

[0041] Compare the user's IP address information with the user's historical IP address information to determine whether the two are consistent. If so, the user's IP address information is normal; if not, the user's IP address information is abnormal; compare the user's client node coding information with the registered node coding information to determine whether the user's client node coding information is included in the registered node coding information. If so, the user's client node coding information is normal; otherwise, it is abnormal; compare the user's geographic location information with the user's registered geographic location information to determine whether the two are consistent. If so, the user's geographic location information is normal; otherwise, it is abnormal. When the user's IP address information, the user's node coding information and the user's geographic location information are all normal, the security verification parameter R is 1. When at least one of the user's IP address information, the user's node coding information and the user's geographic location information is abnormal, the security verification parameter R is 0.

[0042] Furthermore, parsing the second verification credential data to obtain a second parsing result, and determining whether to grant the user the second power trading authority based on the second parsing result specifically includes the following process:

[0043] A product threshold is loaded to determine whether the product of the security verification parameter and the second verification characterization value exceeds the product threshold. If so, the user is granted the second power trading authority; if not, the user is not granted the second power trading authority.

[0044] On the other hand, a method for managing power transaction login based on multi-dimensional identity authentication includes:

[0045] Responding to the identity authentication request and collecting first identity authentication information of the user, verifying the first identity authentication information, and generating first authentication credential data, wherein the first identity authentication information includes a facial image of the user;

[0046] receiving and parsing first verification credential data to obtain a first parsing result, and determining whether to grant the user a first power trading authority based on the first parsing result;

[0047] Collecting historical behavior data of the user under the first power trading authority, parsing the historical behavior data to obtain a transaction stability characteristic value, collecting second identity authentication information of the user based on the transaction stability characteristic value, verifying the second identity authentication information, and generating second verification credential data;

[0048] The second verification credential data is received and parsed to obtain a second parsing result, and based on the second parsing result, it is determined whether to grant the user the second power trading authority.

[0049] Compared with the existing solutions, the present invention achieves the following beneficial effects:

[0050] The present invention responds to an identity authentication request and collects the user's first identity authentication information, verifies the first identity authentication information, generates first verification credential data, receives and parses the first verification credential data to obtain a first parsing result, and determines whether to grant the user the first electricity trading authority based on the first parsing result; collects the user's historical behavior data under the first electricity trading authority, parses the historical behavior data to obtain a transaction stability characteristic value, collects the user's second identity authentication information based on the transaction stability characteristic value, verifies the second identity authentication information, and generates second verification credential data; receives and parses the second verification credential data to obtain a second parsing result, and determines whether to grant the user the second electricity trading authority based on the second parsing result. By combining multiple identity authentication methods, the difficulty of attackers cracking identity authentication can be increased, thereby effectively preventing illegal users from entering the system and ensuring the security and integrity of electricity trading data.

[0051] The present invention can calculate transaction stability characteristic values ​​based on user historical behavior data and realize dynamic adjustment of authority granting. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments described in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0053] Figure 1 This is a system block diagram of a power transaction login management system based on multi-dimensional identity authentication according to an embodiment of the present invention;

[0054] Figure 2 This is a workflow diagram of a power transaction login management system based on multi-dimensional identity authentication according to an embodiment of the present invention;

[0055] Figure 3 This is a workflow diagram of another power transaction login management system based on multi-dimensional identity authentication according to an embodiment of the present invention;

[0056] Figure 4 This is a workflow diagram of a power transaction login management method based on multi-dimensional identity authentication according to an embodiment of the present invention. DETAILED DESCRIPTION

[0057] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0058] In addition, the described features, structures or characteristics can be combined in any suitable manner in one or more example embodiments. In the following description, many specific details are provided to provide a full understanding of the example embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure can be practiced while omitting one or more of the specific details, or other methods, components, steps, etc. can be adopted. In other cases, well-known structures, methods, implementations or operations are not shown or described in detail to avoid obscuring various aspects of the present disclosure.

[0059] This embodiment provides a power transaction login management system based on multi-dimensional identity authentication. Figure 1 This is a system block diagram of a power transaction login management system based on multi-dimensional identity authentication according to an embodiment of the present invention. Figure 1 As shown, the system includes:

[0060] a first identity authentication unit, configured to respond to the identity authentication request and collect first identity authentication information of the user, verify the first identity authentication information, and generate first authentication credential data, wherein the first identity authentication information includes a facial image of the user;

[0061] an electricity trading login unit, configured to receive and parse the first verification credential data to obtain a first parsing result, and determine whether to grant the user the first electricity trading authority based on the first parsing result;

[0062] a second identity authentication unit configured to collect historical behavior data of the user under the first power trading authority, parse the historical behavior data to obtain a transaction stability characteristic value, collect second identity authentication information of the user based on the transaction stability characteristic value, verify the second identity authentication information, and generate second verification credential data;

[0063] The power transaction management unit is configured to receive and parse the second verification credential data to obtain a second parsing result, and determine whether to grant the user the second power transaction authority based on the second parsing result.

[0064] In summary, the present invention responds to an identity authentication request and collects the user's first identity authentication information, verifies the first identity authentication information, generates first verification credential data, receives and parses the first verification credential data to obtain a first parsing result, and determines whether to grant the user the first electricity trading authority based on the first parsing result; collects the user's historical behavior data under the first electricity trading authority, parses the historical behavior data to obtain a transaction stability characteristic value, collects the user's second identity authentication information based on the transaction stability characteristic value, verifies the second identity authentication information, and generates second verification credential data; receives and parses the second verification credential data to obtain a second parsing result, and determines whether to grant the user the second electricity trading authority based on the second parsing result. This can increase the difficulty for attackers to crack identity authentication by combining multiple identity authentication methods, effectively prevent illegal users from entering the system, and ensure the security and integrity of electricity trading data.

[0065] Furthermore, transaction stability feature values ​​are calculated based on user historical behavior data to achieve dynamic adjustment of permission granting.

[0066] It is worth noting that the modules in the system can achieve two-to-two communication connections.

[0067] In some embodiments, verifying the first identity verification information and generating the first verification credential data specifically includes the following process:

[0068] Extract feature vectors from the user's face image, perform preliminary clustering on the feature vectors based on the k-means algorithm, and obtain the category and cluster center corresponding to each feature vector; specifically:

[0069] A feature vector is randomly selected as the initial centroid. It is worth noting that a given face image can include features such as posture, expression, makeup, and skin color;

[0070] When the number of initial centroids is less than k, let x i is the feature vector dataset, μj (j=1,2…k) is the initial centroid;

[0071] Based on the objective function Calculate the distance D(x) from each data point in the dataset to the existing initial centroid, where j = 1, 2…k;

[0072] The data point corresponding to the maximum value in D(x) is used as the next initial centroid;

[0073] K initial centroids are obtained in turn, and the data set is clustered based on the k initial centroids to obtain the category and class center corresponding to each eigenvector.

[0074] Constrain the distance between the feature vector and its class center based on the intra-class tight constraint:

[0075]

[0076] Among them, L C is the compact constraint within the class, the eigenvector x i ∈R K , R represents a real vector, K represents the dimension of the eigenvector, y i represents the eigenvector x i Category, represents the class center vector, N represents the number of eigenvectors, and ||·||2 represents the modulo operation of the two-norm;

[0077] Separate the cluster centers based on inter-cluster repulsion:

[0078] Among them, L A is the inter-class repulsive force, cos(θ j ) represents the cluster center and the eigenvector x i The cosine similarity between is the eigenvector x i With the eigenvector x i Category y i The angle between them, s is the scaling factor, n is the total number of categories, and m is the angle margin;

[0079] L C With L A The sum of is used as the loss function to learn the feature vector and obtain the fusion feature to be identified;

[0080] A similarity calculation is performed between the fused feature to be identified and the preset fused feature stored in the feature access stack of the first identity verification unit to obtain a similarity, and the similarity is recorded as the first verification credential data.

[0081] Specifically, the similarity calculation between the fusion feature to be identified and the preset fusion feature stored in the feature access stack of the first identity verification unit is performed, and the similarity is obtained by specifically including the following process:

[0082]

[0083] Among them, Dist represents the similarity, Represents the i-th eigenvector value of the fusion feature to be identified, Represents the i-th eigenvector value of the preset fusion feature, and K is the dimension size of the feature vector.

[0084] In summary, by generating a loss function through intra-class tight constraints and inter-class repulsive forces to learn the feature vector, the fusion features to be identified are obtained, which can improve the learning efficiency and accuracy of facial features, improve the accuracy and robustness of face recognition, and further improve the efficiency of power trading login management.

[0085] In some embodiments, receiving and parsing the first verification credential data to obtain a first parsing result, and determining whether to grant the user the first power trading authority based on the first parsing result specifically includes the following process:

[0086] Loading a similarity threshold, comparing the similarity with the similarity threshold, and obtaining a first parsing result;

[0087] If the first analysis result shows that the similarity does not exceed the similarity threshold, determining that the first identity authentication information of the user fails the verification, generating a verification failure signal, not granting the user the first power trading authority, and storing the verification failure signal;

[0088] If the first analysis result shows that the similarity exceeds the similarity threshold, it is determined that the first identity authentication information of the user has passed the verification, a verification success signal is generated, and the user is granted the first electricity trading authority.

[0089] In some embodiments, Figure 2 This is a workflow diagram of a power transaction login management system based on multi-dimensional identity authentication according to an embodiment of the present invention. Figure 2 As shown in the figure, parsing historical behavior data to obtain transaction stability feature values ​​specifically includes the following process:

[0090] Step S201: Obtain the user's first transaction information, second transaction information, and G transaction information based on historical behavior data;

[0091] The first transaction information includes the first browsing time redundancy, the first quotation number redundancy, and the first repeated quotation number; the G-th transaction information includes the G-th browsing time redundancy, the G-th quotation number redundancy, and the G-th repeated quotation number. The browsing time redundancy is the difference between the time the user browses the power trading market before the transaction and the preset time, the quotation number redundancy is the difference between the number of quotations the user submits to the power generation manufacturer or power user before the transaction and the preset number of quotations, and the repeated quotation number is the number of times the user modifies the quotation to the power generation manufacturer or power user before the transaction.

[0092] Step S202: Substitute the first browsing time redundancy, the first quotation number redundancy and the first repeated quotation number into the first transaction stability coefficient calculation formula to obtain the first transaction stability coefficient. The first transaction stability coefficient calculation formula is: Where LMS is the first transaction stability coefficient, SC is the first browsing time redundancy, BJ is the first quotation number redundancy, and CB is the first repeated quotation number, until the Gth transaction stability coefficient is calculated;

[0093] Step S203: Setting a transaction stability coefficient threshold, comparing each transaction stability coefficient with the transaction stability coefficient threshold, recording transaction stability coefficients that are higher than the transaction stability coefficient threshold as positive data, and recording transaction stability coefficients that are lower than or equal to the preset transaction stability coefficient threshold as abnormal data;

[0094] Step S204: Count the number of abnormal data YC and the number of positive data PT, substitute YC and PT into the transaction stability characteristic value calculation formula to calculate the transaction stability characteristic value GL, which is: GL = (PT×γ-YC×δ) / (γ+δ), where γ is the positive data coefficient and δ is the abnormal data, and their values ​​are 0.6 and 0.25 respectively.

[0095] Furthermore, collecting the user's second identity verification information based on the transaction stability feature value specifically includes the following process:

[0096] The transaction stability characteristic value threshold is loaded, and it is determined whether the transaction stability characteristic value exceeds the stability characteristic value threshold. If so, a collection signal is generated to collect the user's second identity authentication information; if not, no collection signal is generated.

[0097] In some embodiments, Figure 3 This is another workflow diagram of a power transaction login management system based on multi-dimensional identity authentication according to an embodiment of the present invention. Figure 3 As shown, verifying the second identity verification information and generating the second verification credential data specifically includes the following process:

[0098] Step S301: The second identity authentication information includes a user identity identifier and identity attribute information. An identity attribute file in a storage system is searched based on the user identity identifier, and the identity attribute information is compared and verified with the identity attribute file.

[0099] Among them, identity attribute information includes user's IP address information, user's node code information, user's geographic location information, and user permissions;

[0100] Step S302: Determine whether the user's IP address information, the user's node code information, and the user's geographic location information are abnormal. If not, the security verification parameter YZ is 1; if so, the security verification parameter YZ is 0;

[0101] Specifically, the user's IP address information is compared with the user's historical IP address information to determine whether the two are consistent. If so, the user's IP address information is normal; if not, the user's IP address information is abnormal; the user's client node coding information is compared with the registered node coding information to determine whether the user's client node coding information is included in the registered node coding information. If so, the user's client node coding information is normal; otherwise, it is abnormal; the user's geographic location information is compared with the user's registered geographic location information to determine whether the two are consistent. If so, the user's geographic location information is normal; otherwise, it is abnormal. When the user's IP address information, the user's node coding information and the user's geographic location information are all normal, the security verification parameter R is 1. When at least one of the user's IP address information, the user's node coding information and the user's geographic location information is abnormal, the security verification parameter R is 0.

[0102] Step S303: Obtain the transaction stability characteristic values ​​of the user in several historical periods. With the execution time of the historical period as the X-axis and the transaction stability characteristic value as the Y-axis, all transaction stability characteristic values ​​are marked as points in a rectangular coordinate system. Adjacent points in the rectangular coordinate system are connected to generate a transaction stability characteristic curve.

[0103] Step S304: Draw perpendicular lines from both ends of the transaction stability characteristic curve to the X-axis to obtain two start and end line segments. The transaction stability characteristic curve, the two start and end line segments, and the X-axis form a closed figure. The total area of ​​the closed figure is marked as the second verification characteristic value.

[0104] Step S305: Record the product of the security verification parameter and the second verification representation value as the second verification credential data.

[0105] In some embodiments, parsing the second verification credential data to obtain a second parsing result, and determining whether to grant the user the second power trading authority based on the second parsing result specifically includes the following process:

[0106] A product threshold is loaded to determine whether the product of the security verification parameter and the second verification characterization value exceeds the product threshold. If so, the user is granted the second power trading authority; if not, the user is not granted the second power trading authority.

[0107] Among them, the first power trading authority includes:

[0108] Enterprise information maintenance authority: can maintain the enterprise's basic information, account number, qualifications, etc.

[0109] Business operation permissions: Depending on the specific system design, some specific business operation permissions may also be included, such as submitting transaction applications, making transaction quotes, modifying transaction quotes, and viewing transaction records.

[0110] Second power trading authority:

[0111] U-key binding and use: Wholesale market users need to apply for a U-key from a third-party electronic certification service agency and bind it to the operator's account to achieve secure login and transactions.

[0112] Cross-market role restrictions: To ensure transaction fairness, the roles of the same user in different markets must follow the principle of uniqueness.

[0113] User authorization management: Although users are not directly involved in business operations, they can perform authorization management for ordinary users to achieve the separation of authority allocation and business operations.

[0114] User group permission configuration: The system can divide user groups and assign operation permissions. Each user group contains one or more end users. User group permissions determine the operation scope of users in the group.

[0115] In some embodiments, the present invention further provides a method for managing power transaction login based on multi-dimensional identity authentication. Figure 4 This is a workflow diagram of a power transaction login management method based on multi-dimensional identity authentication according to an embodiment of the present invention. Figure 4 As shown, the method includes the following steps:

[0116] Step S401: responding to an identity authentication request and collecting first identity authentication information of a user, verifying the first identity authentication information, and generating first authentication credential data, wherein the first identity authentication information includes a facial image of the user;

[0117] Step S402: receiving and parsing first verification credential data to obtain a first parsing result, and determining whether to grant the user a first power trading authority based on the first parsing result;

[0118] Step S403: collecting historical behavior data of the user under the first power trading authority, parsing the historical behavior data to obtain a transaction stability characteristic value, collecting the user's second identity authentication information based on the transaction stability characteristic value, verifying the second identity authentication information, and generating second verification credential data;

[0119] Step S404: receiving and parsing the second verification credential data to obtain a second parsing result, and determining whether to grant the user the second electricity trading authority based on the second parsing result.

[0120] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0121] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0122] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0123] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is only for some logical functions. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0124] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0125] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. The power transaction login management system based on multi-dimensional identity authentication is characterized by: The system includes: a first identity authentication unit, configured to respond to the identity authentication request and collect first identity authentication information of the user, verify the first identity authentication information, and generate first authentication credential data, wherein the first identity authentication information includes a facial image of the user; an electricity trading login unit, configured to receive and parse the first verification credential data to obtain a first parsing result, and determine whether to grant the user the first electricity trading authority based on the first parsing result; a second identity authentication unit configured to collect historical behavior data of the user under the first power trading authority, parse the historical behavior data to obtain a transaction stability characteristic value, collect second identity authentication information of the user based on the transaction stability characteristic value, verify the second identity authentication information, and generate second verification credential data; The power transaction management unit is configured to receive and parse the second verification credential data to obtain a second parsing result, and determine whether to grant the user the second power transaction authority based on the second parsing result.

2. The power transaction login management system based on multi-dimensional identity authentication according to claim 1 is characterized in that: Verifying the first identity verification information and generating the first verification credential data specifically includes the following process: Extract feature vectors from the user's face image, perform preliminary clustering on the feature vectors based on the k-means algorithm, and obtain the category and cluster center corresponding to each feature vector; Constrain the distance between the feature vector and its class center based on the intra-class tight constraint: Among them, L C is the compact constraint within the class, the eigenvector x i ∈R K , R represents a real vector, K represents the dimension of the eigenvector, y i represents the eigenvector x i Category, represents the class center vector, N represents the number of eigenvectors, and ||·||2 represents the modulo operation of the two-norm; Separate the cluster centers based on inter-cluster repulsion: Among them, L A is the inter-class repulsive force, cos(θ j ) represents the cluster center and the eigenvector x i The cosine similarity between is the eigenvector x i With the eigenvector x i Category y i The angle between them, s is the scaling factor, n is the total number of categories, and m is the angle margin; L C With L A The sum of is used as the loss function to learn the feature vector and obtain the fusion feature to be identified; A similarity calculation is performed between the fused feature to be identified and the preset fused feature stored in the feature access stack of the first identity verification unit to obtain a similarity, and the similarity is recorded as the first verification credential data.

3. The power transaction login management system based on multi-dimensional identity authentication according to claim 2 is characterized in that: Calculating the similarity between the fused feature to be identified and the preset fused feature stored in the feature access stack of the first identity verification unit to obtain the similarity specifically includes the following process: Among them, Dist represents the similarity, Represents the i-th eigenvector value of the fusion feature to be identified, Represents the i-th eigenvector value of the preset fusion feature, and K is the dimension size of the feature vector.

4. The power transaction login management system based on multi-dimensional identity authentication according to claim 3 is characterized in that: Receive and parse the first verification credential data to obtain a first parsing result, and determine whether to grant the user the first power trading authority based on the first parsing result. The following processes are included: Loading a similarity threshold, comparing the similarity with the similarity threshold, and obtaining a first parsing result; If the first analysis result shows that the similarity does not exceed the similarity threshold, determining that the first identity authentication information of the user fails the verification, generating a verification failure signal, not granting the user the first power trading authority, and storing the verification failure signal; If the first analysis result shows that the similarity exceeds the similarity threshold, it is determined that the first identity authentication information of the user has passed the verification, a verification success signal is generated, and the user is granted the first electricity trading authority.

5. The power transaction login management system based on multi-dimensional identity authentication according to claim 1 is characterized in that: Analyze historical behavior data to obtain specific transaction stability characteristic values The following processes are included: Based on the historical behavior data, the user's first transaction information, second transaction information, and Gth transaction information are obtained, wherein the first transaction information includes a first browsing time redundancy, a first quotation number redundancy, and a first repeated quotation number; the Gth transaction information includes a Gth browsing time redundancy, a Gth quotation number redundancy, and a Gth repeated quotation number, wherein the browsing time redundancy is the difference between the time the user browses the power trading market before the transaction and a preset time, the quotation number redundancy is the difference between the number of quotations the user makes to the power generation manufacturer or power user before the transaction and the preset quotation number, and the repeated quotation number is the number of times the user modifies the quotation to the power generation manufacturer or power user before the transaction; Substitute the first browsing time redundancy, the first quotation number redundancy and the first repeated quotation number into the first transaction stability coefficient calculation formula to obtain the first transaction stability coefficient. The first transaction stability coefficient calculation formula is: Where LMS is the first transaction stability coefficient, SC is the first browsing time redundancy, BJ is the first quotation number redundancy, and CB is the first repeated quotation number, until the Gth transaction stability coefficient is calculated; Set a transaction stability coefficient threshold, compare each transaction stability coefficient with the transaction stability coefficient threshold, record transaction stability coefficients that are higher than the transaction stability coefficient threshold as positive data, and record transaction stability coefficients that are lower than or equal to the preset transaction stability coefficient threshold as abnormal data; Count the number of abnormal data YC and the number of positive data PT, substitute YC and PT into the transaction stability characteristic value calculation formula: GL = (PT × γ - YC × δ) / (γ + δ), and calculate the transaction stability characteristic value GL, where γ is the positive data coefficient and δ is the abnormal data, and their values ​​are 0.6 and 0.25 respectively.

6. The power transaction login management system based on multi-dimensional identity authentication according to claim 1 is characterized in that: The specific process of collecting the user's second identity verification information based on the transaction stability feature value includes the following: The transaction stability characteristic value threshold is loaded, and it is determined whether the transaction stability characteristic value exceeds the stability characteristic value threshold. If so, a collection signal is generated to collect the user's second identity authentication information; if not, no collection signal is generated.

7. The power transaction login management system based on multi-dimensional identity authentication according to claim 1 is characterized in that: Verifying the second identity verification information and generating the second verification credential data specifically includes the following process: The second authentication information includes the user's identity identifier and identity attribute information. The identity attribute file in the storage system is queried based on the user's identity identifier, and the identity attribute information is compared and verified with the identity attribute file. The identity attribute information includes the user's IP address information, the user's node code information, the user's geographic location information, and the user's permissions. Determine whether the user's IP address information, the user's node code information, and the user's geographic location information are abnormal. If not, the security verification parameter YZ is 1; if so, the security verification parameter YZ is 0; Obtain the user's transaction stability characteristic values ​​over several historical periods, with the execution time of the historical period as the X-axis and the transaction stability characteristic value as the Y-axis. Mark all transaction stability characteristic values ​​as points in a rectangular coordinate system, connect adjacent points in the rectangular coordinate system to generate a transaction stability characteristic curve, draw perpendicular lines from both ends of the transaction stability characteristic curve to the X-axis to obtain two start and end line segments, and form a closed figure with the transaction stability characteristic curve, the two start and end line segments, and the X-axis. Mark the total area of ​​the closed figure as the second verification representation value; The product of the security verification parameter and the second verification representation value is recorded as the second verification credential data.

8. The power transaction login management system based on multi-dimensional identity authentication according to claim 7 is characterized in that: Determining whether the user's IP address information, node code information, and geographic location information are abnormal specifically involves the following process: Compare the user's IP address information with the user's historical IP address information to determine whether the two are consistent. If so, the user's IP address information is normal; if not, the user's IP address information is abnormal; compare the user's client node coding information with the registered node coding information to determine whether the user's client node coding information is included in the registered node coding information. If so, the user's client node coding information is normal; otherwise, it is abnormal; compare the user's geographic location information with the user's registered geographic location information to determine whether the two are consistent. If so, the user's geographic location information is normal; otherwise, it is abnormal. When the user's IP address information, the user's node coding information and the user's geographic location information are all normal, the security verification parameter R is 1. When at least one of the user's IP address information, the user's node coding information and the user's geographic location information is abnormal, the security verification parameter R is 0.

9. The power transaction login management system based on multi-dimensional identity authentication according to claim 7 is characterized in that: Parsing the second verification credential data to obtain a second parsing result, and determining whether to grant the user the second power trading authority based on the second parsing result specifically includes the following process: A product threshold is loaded to determine whether the product of the security verification parameter and the second verification characterization value exceeds the product threshold. If so, the user is granted the second power trading authority; if not, the user is not granted the second power trading authority.

10. The power transaction login management method based on multi-dimensional identity authentication is characterized in that: The power transaction login management system based on multi-dimensional identity authentication according to any one of claims 1 to 9 comprises: Responding to the identity authentication request and collecting first identity authentication information of the user, verifying the first identity authentication information, and generating first authentication credential data, wherein the first identity authentication information includes a facial image of the user; receiving and parsing first verification credential data to obtain a first parsing result, and determining whether to grant the user a first power trading authority based on the first parsing result; Collecting historical behavior data of the user under the first power trading authority, parsing the historical behavior data to obtain a transaction stability characteristic value, collecting second identity authentication information of the user based on the transaction stability characteristic value, verifying the second identity authentication information, and generating second verification credential data; The second verification credential data is received and parsed to obtain a second parsing result, and based on the second parsing result, it is determined whether to grant the user the second power trading authority.