AI identity authentication system and method based on user behavior

By obtaining historical authentication records, calculating reliability and bias, and using federated learning technology to establish a collection, the problem of unreliable identity authentication caused by user behavior data deviation is solved, and more reliable identity authentication is achieved.

CN120639506BActive Publication Date: 2025-10-14BEIJING TRUSFORT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511086571.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-05
Publication Date
2025-10-14
Estimated Expiration
2045-08-05

AI Technical Summary

Technical Problem

Existing technologies have data bias when collecting user behavior data, resulting in unreliable identity authentication and frequent misjudgment of verification results.

Method used

By obtaining historical authentication records, calculating reliability, extracting target records and establishing a bias degree set, using federated learning technology to integrate user behavior characteristics, calculating the warning coefficient to judge the rationality of sample data, and providing corresponding prompts.

Benefits of technology

It improves the reliability of identity authentication, ensures the accuracy of verification results, and reduces misjudgments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639506B_ABST
    Figure CN120639506B_ABST
Patent Text Reader

Abstract

The application discloses an AI identity authentication system and method based on user behavior, relates to the technical field of behavior analysis, and comprises the following steps: obtaining authentication records of a historical target account, calculating the reliability of the authentication records, extracting target records and obtaining a target period corresponding to each target record; extracting information areas in webpages browsed by a user in a target period, capturing user behavior of the user in the information areas, and obtaining the degree of bias of each information area of each target record; according to a login device corresponding to a target record, a corresponding first set is established by using a federated learning technology; according to current total behavior data and sample data, a warning coefficient of the sample data is calculated, and it is judged whether the sample data is prompted for warning. The application analyzes historical authentication records, comprehensively considers the degree of bias of a user to each information area, judges whether sample data comprehensively reflects user behavior characteristics, and gives corresponding prompts, so that the reliability of identity authentication is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of behavior analysis technology, and in particular to an AI identity authentication system and method based on user behavior. Background Art

[0002] Identity authentication, as a core link in the information security system, plays an irreplaceable role in preventing scenarios such as account theft and data leakage. By authenticating the account, users' personal information and privacy can be effectively protected, allowing users to use the system with greater confidence and improving user satisfaction. With the advancement of technology, methods of identity authentication based on analysis of user behavior habits are gradually being widely used in the field of information security. However, when collecting user behavior data, due to the huge amount of data, only part of the samples are often analyzed. However, the collected sample data will have data bias, making it difficult to fully reflect the characteristics of user behavior, which will lead to unreliable identity authentication and misjudgment of verification results. Summary of the Invention

[0003] The purpose of the present invention is to provide an AI identity authentication system and method based on user behavior to solve the problems raised in the prior art.

[0004] To achieve the above object, the present invention provides the following technical solutions:

[0005] The AI ​​identity authentication method based on user behavior includes the following steps:

[0006] Step S100: Obtaining historical authentication records for identity authentication when logging into a target account, extracting and analyzing the login device, login time, and authentication duration corresponding to the authentication records, and calculating the reliability of the authentication records; extracting target records from the authentication records based on the reliability, and obtaining the target time period corresponding to each target record based on the login time;

[0007] Step S200: extracting information regions in the webpages browsed by the user during the target period and capturing the user's behavior in the information regions; obtaining the degree of bias of each information region corresponding to each target record based on the number of interactions between the user and the information region in the webpage and the duration of the mouse cursor's stay in the information region;

[0008] Step S300: Based on the login device corresponding to each target record, the bias levels corresponding to the target records on the same login device are aggregated. Federated learning technology is used to integrate the bias levels corresponding to each device to obtain the user's bias level for each information area, and a corresponding first set is established.

[0009] Step S400: Based on the sample data currently extracted from the total behavior data to be applied to user behavior analysis, according to the total behavior data and the length of time the mouse cursor is in each information area in the sample data, and the first set, calculate the warning coefficient of the current sample data, and determine whether to issue a warning prompt for the sample data based on the warning coefficient.

[0010] Furthermore, step S100 includes:

[0011] Step S110: Obtain authentication records for identity authentication performed when logging into a target account in the past. The target account is registered by the user on a webpage during registration. The device used to register the target account is used as a trusted device for the target account. The identity authentication methods for logging into the target account include password verification and biometric verification. If a certain authentication record corresponds to password verification, the duration from the moment the password is entered to the moment the password verification is completed is used as the authentication duration for the authentication record. If a certain authentication record corresponds to biometric verification, the duration from the moment the verification interface begins to appear to the moment the biometric verification is completed is used as the authentication duration for the authentication record. Then, the authentication durations of several authentication records are averaged to obtain an average authentication duration D^.

[0012] Step S120: Extract the authentication record R that is not a history of logging into the target account on the trusted device and successfully authenticating the user; obtain the device usage period of the trusted device within the historical S days, and extract the time T of successful authentication in the authentication record R. R , set the initial target quantity to 0, if time T R If it falls within the usage period of a certain day, the target quantity value is increased by 1, and the final target quantity S is obtained. R , get the first reliability G1=S of the authentication record R R / S, 0≤S R ≤S;

[0013] If the target account is at time T R As the starting point, the subsequent period P R If no high-risk operation is performed within the authentication record R, the second reliability of the authentication record R is set to G2=1; if a high-risk operation is performed, the second reliability is set to G2=0;

[0014] Based on the authentication method of the authentication record R, the authentication duration D of the authentication record R is obtained. R , and then get the third reliability of the authentication record R , e is a natural constant, max() is for finding the maximum value, and min() is for finding the minimum value.

[0015] It should be noted that authentication records that do not show the target account logged in on a trusted device and the identity authentication is successful may not have been performed by the user who registered this account. In this case, it is necessary to make a judgment based on the login time, the behavior after login, and the authentication time during the login process. The login time is not within the daily usage time of the account user himself, the behavior of performing high-risk operations after login, and the authentication time being too fast or too slow will reduce the reliability of the authentication record as the target record. Therefore, the target record in the authentication record should be extracted based on these situations.

[0016] Furthermore, step S100 further includes: obtaining the total reliability value G of the authentication record R according to the preset weights of G1, G2 and G3. R , if the total reliability value G R If it is greater than the preset reliability threshold, the authentication record R is taken as the target record, and then all target records in which the target account is not logged in on the trusted device and the identity authentication is successful are obtained, and the authentication record in which the target account is logged in on the trusted device and the identity authentication is successful is also taken as the target record; and the moment when the identity authentication of the target record is successful is taken as the starting point, and the previous time period P is taken as the target time period, and then all target records and the target time period corresponding to each target record are obtained.

[0017] Furthermore, step S200 includes:

[0018] Step S210: extracting information areas in the webpages browsed by the user during the target period, where the information areas include text areas, control areas, and image areas, and capturing the user's behavior in each information area, where the user's behavior is the operation performed by the user on the mouse;

[0019] Get the target period P corresponding to a target record Q, extract all text areas displayed on the web page within the target period P, obtain the position of the mouse cursor at each moment within the target period P, take the period of time the mouse cursor stays in a text area FA as P1, and the duration of the stay period P1 as the stay duration D1. Extract any three adjacent moments T1, T2, and T3 within the stay period P1. If the position and shape of the mouse cursor at moments T1, T2, and T3 remain unchanged, mark moment T2, and then obtain all marked moments within the target period P. The durations of the marked moments are aggregated to obtain the marked duration D2.

[0020] Step S220: The number of interactive operations between the user and the text area of ​​the webpage during the dwell period P1 is taken as N1. The interactive operations include single-click, double-click, selection, and scrolling. Then, according to the number of text areas M in the target period P, and the dwell time, marking time, and number of interactive operations corresponding to each text area, the bias degree of the target record Q towards the text area is obtained as follows: ,in, is the marking duration corresponding to the mth text region, is the dwell time corresponding to the mth text area, e is a natural constant, is the number of interactive operations corresponding to the mth text region; and then, by analogy with the bias degree of the target record Q to the text region, the bias degree of each information region corresponding to each target record is obtained.

[0021] Furthermore, step S300 includes: establishing a local model corresponding to each device and a global model corresponding to the user, and using federated learning technology to train the global model according to the degree of bias of each information area corresponding to the target record belonging to the same device to obtain the final degree of user bias for each information area, and sorting the information areas in order from large to small according to the degree of bias, and inputting each degree of bias into the pre-established first set in sequence according to the sorting order.

[0022] Furthermore, step S400 includes: based on the sample data currently extracted from the total behavior data to be applied to user behavior analysis, extracting the time DY1 that the mouse cursor is in a certain information area Y in the total behavior data, and the time DY2 that the mouse cursor is in the information area Y in the sample data, to obtain the characteristic value Z=DY2 / DY1 of the information area Y; then obtaining the characteristic value of each information area, and inputting each characteristic value into the pre-established second set in sequence according to the serial number order corresponding to each information area in the first set; then obtaining the cosine similarity between the first set and the second set as the warning coefficient of the sample data. If the warning coefficient is less than the preset numerical threshold, a warning prompt is issued for the sample data, and relevant personnel are prompted to correct the sample data.

[0023] These sample data extracted from the total behavioral data may be simply manually extracted or simply randomly extracted through an algorithm. These sample data may not be reasonable and cannot fully represent the user's behavior, so they need to be analyzed. In this solution, it is mainly based on whether the time occupied by the text area, control area and image area in the website in the sample data screened out from the total behavioral data corresponds to the user's preference level; for example, if the user has a greater preference for the text area, then the proportion of text data in the sample data should be larger. In this solution, it is specifically determined by establishing a corresponding first set and a second set, and calculating the cosine similarity between the two sets. Since the cosine similarity is [-1,1], and the larger it is, the more similar the two are, and the more the sample data meets the expected standard, then when the warning coefficient is less than the preset numerical threshold, a warning prompt should be given for the sample data, and relevant personnel should be prompted to correct the sample data.

[0024] An AI identity authentication system based on user behavior, comprising a target period extraction module, a bias degree calculation module, a first set establishment module and a warning prompt module;

[0025] The target period extraction module is used to obtain authentication records of identity authentication when a target account is logged in historically, extract and analyze the login device, login time and authentication duration corresponding to the authentication records, and calculate the reliability of the authentication records; target records in the authentication records are extracted according to the reliability, and target periods corresponding to each target record are obtained according to the login time;

[0026] The bias degree calculation module is used to extract information areas in web pages browsed by the user in the target period, and capture user behaviors of the user in the information areas; the bias degree of each information area corresponding to each target record is obtained according to the number of interactive operations between the user and the information areas in the web pages and the residence period of the mouse cursor in the information areas;

[0027] The first set establishment module is used to collect the bias degrees corresponding to the target records in the same login device according to the login device corresponding to each target record, use federated learning technology to integrate the bias degrees corresponding to each device, obtain the bias degree of the user to each information area, and establish a corresponding first set;

[0028] The warning prompt module is used to calculate a warning coefficient of the current sample data according to the total behavior data and the sample data extracted from the total behavior data to be applied to user behavior analysis, the time length of the mouse cursor in each information area in the total behavior data and the sample data, and the first set, and determine whether to give a warning prompt to the sample data according to the warning coefficient.

[0029] Further, the target period extraction module comprises an authentication record acquisition unit, a reliability calculation unit and a target period extraction unit;

[0030] The authentication record acquisition unit is used to obtain historical authentication records of a target account, the target account is registered by the user on a web page when registering, and the identity verification mode for logging into the target account includes password verification and biometric verification;

[0031] The reliability calculation unit is used to extract and analyze the login device, login time and authentication duration corresponding to the authentication records, and calculate the first reliability, second reliability and third reliability of the authentication records;

[0032] The target period extraction unit is used to extract target records in the authentication records according to the weight values of the first reliability, second reliability and third reliability set in advance, and obtain target periods corresponding to each target record according to the identity verification success time.

[0033] Furthermore, the bias degree calculation module includes an information region extraction unit and a bias degree calculation unit;

[0034] Information region extraction unit: used to extract information regions in the web pages browsed by users during the target period. Information regions include text regions, control regions, and image regions. User behaviors in each information region are captured. User behaviors refer to the actions performed by users on the mouse.

[0035] The bias degree calculation unit is used to obtain the bias degree of each information area corresponding to each target record according to the number of interactive operations between the user and the information area in the web page and the time period during which the mouse cursor stays in the information area.

[0036] Compared with the prior art, the beneficial effects of the present invention are as follows: the present invention provides an AI identity authentication system and method based on user behavior, including: obtaining the authentication records of historical target accounts, calculating the reliability of the authentication records, extracting target records and obtaining the target time period corresponding to each target record; extracting the information areas in the web pages browsed by users during the target time period, capturing the user behavior of the users in the information areas, and obtaining the degree of bias of each information area of ​​each target record; using federated learning technology to establish a corresponding first set based on the login device corresponding to the target record; calculating the early warning coefficient of the sample data based on the current total behavior data and sample data, and determining whether to issue an early warning prompt for the sample data. The present invention analyzes historical authentication records, comprehensively considers the degree of bias of users for each information area, determines whether the sample data fully reflects the user's behavior characteristics, and issues corresponding prompts, thereby effectively improving the reliability of identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 Schematic diagram of the process of the AI ​​identity authentication method based on user behavior of the present invention;

[0038] Figure 2 This is a structural diagram of the AI ​​identity authentication system based on user behavior of the present invention. DETAILED DESCRIPTION

[0039] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0040] Example: Figure 1 As shown, the present invention provides a technical solution for an AI identity authentication method based on user behavior, comprising the following steps:

[0041] Step S100: Obtaining historical authentication records for identity authentication when logging into a target account, extracting and analyzing the login device, login time, and authentication duration corresponding to the authentication records, and calculating the reliability of the authentication records; extracting target records from the authentication records based on the reliability, and obtaining the target time period corresponding to each target record based on the login time;

[0042] Step S110: Obtain authentication records for identity authentication when historically logging into a target account. The target account is registered by the user on a web page during registration. The device used to register the target account is used as a trusted device for the target account. Identity authentication methods for logging into the target account include password verification and biometric verification. If a certain authentication record corresponds to password verification, the duration from the moment the password is started to be entered to the moment the password verification is completed is used as the authentication duration of the certain authentication record. If a certain authentication record corresponds to biometric verification, the duration from the moment the verification interface begins to appear to the moment the biometric verification is completed is used as the authentication duration of the certain authentication record. Then, based on the authentication durations of several authentication records, the average value is calculated to obtain an average verification duration D^. Biometric verification includes facial recognition, fingerprint recognition, etc.

[0043] Step S120: Extract the authentication record R that is not a history of logging into the target account on the trusted device and successfully authenticating the user; obtain the device usage period of the trusted device within the historical S days, and extract the time T of successful authentication in the authentication record R. R , set the initial target quantity to 0, if time T R If it falls within the usage period of a certain day, the target quantity value is increased by 1, and the final target quantity S is obtained. R , get the first reliability G1=S of the authentication record R R / S, 0≤S R ≤S;

[0044] If the target account is at time T R As the starting point, the subsequent period P R If no high-risk operation is performed within the authentication record R, the second reliability of the authentication record R is set to G2=1; if a high-risk operation is performed, the second reliability is set to G2=0;

[0045] Based on the authentication method of the authentication record R, the authentication duration D of the authentication record R is obtained. R , and then get the third reliability of the authentication record R , e is a natural constant, max() is for finding the maximum value, and min() is for finding the minimum value.

[0046] It should be noted that the authentication record of not logging into the target account on a trusted device and successfully identifying the identity may not be operated by the user who registered this account. In this case, it is necessary to judge based on the login time, the behavior after login, and the authentication time during the login process. The login time is not within the daily usage time of the account user himself, the behavior of performing high-risk operations after login (in this embodiment, high-risk operations include financial transactions and information modification, etc.), and the authentication time is too fast or too slow, which will reduce the reliability of the authentication record as the target record. Therefore, the target record in the authentication record should be extracted based on these situations.

[0047] Formula g=e -h It is a function that g decreases as h increases, and when h is greater than or equal to 0, g takes a value between 0 and 1. Greater than or equal to 1, and the smaller the value, the greater the R The closer it is to D^, the more reliable R is in terms of authentication time. Then, subtract 1 from this value and substitute it into the formula g=e -h The calculation formula for the third reliability can be obtained.

[0048] Step S100 also includes: obtaining the total reliability value G of the authentication record R according to the preset weights of G1, G2 and G3. R , if the total reliability value G R If it is greater than the preset reliability threshold, the authentication record R is taken as the target record, and then all target records in which the target account is not logged in on the trusted device and the identity authentication is successful are obtained, and the authentication record in which the target account is logged in on the trusted device and the identity authentication is successful is also taken as the target record; and the moment when the identity authentication of the target record is successful is taken as the starting point, and the previous time period P is taken as the target time period, and then all target records and the target time period corresponding to each target record are obtained.

[0049] Here, the weights G1, G2, and G3 are set to V1, V2, and V3 respectively, and the sum of V1, V2, and V3 is 1, and the total reliability G is obtained. R , set the preset reliable threshold to 0.6, when G R >0.6, then the authentication record R will be used as the target record.

[0050] Step S200: extracting information regions in the webpages browsed by the user during the target period and capturing the user's behavior in the information regions; obtaining the degree of bias of each information region corresponding to each target record based on the number of interactions between the user and the information region in the webpage and the duration of the mouse cursor's stay in the information region;

[0051] Step S210: Extract the information area in the webpage browsed by the user in the target period, the information area including a text area, a control area and an image area, capture the user behavior of the user in each information area, the user behavior being the behavior of the user operating the mouse;

[0052] Obtain the target period P corresponding to the target record Q, extract all text areas displayed on the webpage in the target period P, obtain the position of the mouse cursor at each time in the target period P, take the stay period of the mouse cursor in a text area FA as P1, the length of the stay period P1 being the stay length D1, extract any three adjacent time points T1, T2 and T3 in the stay period P1, if the position and shape of the mouse cursor at the time points T1, T2 and T3 are all unchanged, mark the time point T2, and then obtain all marked time points in the target period P, and collect the length of the marked time points to obtain the marked length D2;

[0053] Step S220: Take the number of interactive operations between the user and the text area of the webpage in the stay period P1 as N1, the interactive operations including single click, double click, selection and scrolling, and then obtain the bias degree of the target record Q to the text area according to the number M of text areas in the target period P, and the stay length, the marked length and the number of interactive operations corresponding to each text area, that is, , wherein, is the marked length corresponding to the mth text area, is the stay length corresponding to the mth text area, e is a natural constant, is the number of interactive operations corresponding to the mth text area; and then analogously obtain the bias degree of each information area corresponding to each target record.

[0054] It should be noted that the formula g = 1-e -h is a function that increases with the increase of h, and g takes a value between 0 and 1 when h is greater than or equal to 0; since the longer the marked length of the mouse cursor in the text area, the less information the mouse cursor marks, therefore, the smaller the bias degree of the target record Q to the text area, and the smaller the number of interactive operations between the user and the text area of the webpage, the smaller the bias degree of the target record Q to the text area, so the formula for calculating the bias degree is reasonable and reliable.

[0055] Step S300: According to the login device corresponding to each target record, collect the bias degree corresponding to the target record in the same login device, use the federated learning technology to integrate the bias degree corresponding to each device, obtain the bias degree of the user to each information area, and establish a corresponding first set;

[0056] Step S300 comprises: establishing a local model corresponding to each device, and a global model corresponding to the user, training the global model using a federated learning technique according to the degree of bias of each information region corresponding to the target record belonging to the same device, obtaining the final degree of bias of the user to each information region, and sorting the information regions in descending order of the degree of bias, and inputting each degree of bias into a first set in order according to the sorting order; integrating the local model results of multiple devices, training through federated learning, avoiding direct transmission of raw data, and effectively protecting privacy.

[0057] Step S400: According to the sample data to be applied to user behavior analysis extracted from the total behavior data at present, according to the time length of the mouse cursor in each information region in the total behavior data and the sample data, and the first set, the warning coefficient of the present sample data is calculated, and whether the sample data is warned is judged according to the warning coefficient.

[0058] Step S400 comprises: according to the sample data to be applied to user behavior analysis extracted from the total behavior data at present, extracting the time length DY1 of the mouse cursor in the total behavior data in a certain information region Y, and the time length DY2 of the mouse cursor in the sample data in the information region Y, obtaining the characteristic value Z=DY2 / DY1 of the information region Y; further obtaining the characteristic value of each information region, and inputting each characteristic value into a second set in order according to the serial number of each information region in the first set; further calculating the cosine similarity between the first set and the second set as the warning coefficient of the sample data, if the warning coefficient is less than the preset numerical threshold, the sample data is warned, and the relevant personnel is prompted to correct the sample data.

[0059] The application also provides an AI identity authentication system based on user behavior, as shown in the accompanying drawings, comprising: Figure 2

[0060] The target period extraction module is used for obtaining authentication records of identity authentication when logging in to the target account, extracting and analyzing the login device, login time and authentication time length corresponding to the authentication records, calculating the reliability of the authentication records, extracting the target records in the authentication records according to the reliability, and obtaining the target period corresponding to each target record according to the login time.

[0061] The bias degree calculation module is used for extracting information regions in the webpage browsed by the user in the target period, capturing the user behavior of the user in the information region; obtaining the degree of bias of each information region corresponding to each target record according to the number of interactive operations between the user and the information region in the webpage and the stay period of the mouse cursor in the information region.

[0062] ​The first set establishing module is configured to collect the bias degree corresponding to the target record in the same login device according to the login device corresponding to each target record, use a federated learning technology, and comprehensively use the bias degree corresponding to each device to obtain the bias degree of the user to each information region and establish a corresponding first set;

[0063] The early warning prompt module is configured to calculate an early warning coefficient of the current sample data according to the time length of the mouse cursor in each information region in the total behavior data and the sample data and the first set according to the sample data to be applied to the user behavior analysis extracted from the total behavior data, and determine whether to perform early warning prompt on the sample data according to the early warning coefficient.

[0064] The target period extraction module includes an authentication record acquisition unit, a reliability calculation unit, and a target period extraction unit.

[0065] The authentication record acquisition unit is configured to acquire the authentication record of the target account history, the target account is registered by the user on the webpage when registering, and the identity verification mode for logging in the target account includes password verification and biometric verification.

[0066] The reliability calculation unit is configured to extract and analyze the login device, login time, and authentication time length corresponding to the authentication record, and calculate the first reliability, the second reliability, and the third reliability of the authentication record.

[0067] The target period extraction unit is configured to extract the target record in the authentication record according to the weight of the first reliability, the second reliability, and the third reliability set in advance, and obtain the target period corresponding to each target record according to the identity verification success time.

[0068] The bias degree calculation module includes an information region extraction unit and a bias degree calculation unit.

[0069] The information region extraction unit is configured to extract the information region in the webpage browsed by the user in the target period, the information region includes a text region, a control region, and an image region, and capture the user behavior of the user in each information region, the user behavior being the operation of the mouse performed by the user.

[0070] The bias degree calculation unit is configured to obtain the bias degree of each information region corresponding to each target record according to the number of interactive operations between the user and the information region in the webpage and the stay period of the mouse cursor in the information region.

[0071] It will be apparent to those skilled in the art that the application is not limited to the details of the above-exemplified embodiments and that the present application can be implemented in other particular forms without departing from the spirit or essential characteristics of the present application. The embodiments should therefore be considered in all respects as illustrative and not restrictive, the scope of the application being indicated by the appended claims rather than by the above description, and all changes which come within the meaning and range of equivalency of the claims are therefore intended to be embraced therein. No reference signs in the claims should be considered as limiting the scope of the claims with respect to the figures of the patent document.

Claims

1. The AI ​​identity authentication method based on user behavior is characterized by: The following steps are involved: Step S100: Obtaining historical authentication records of identity authentication when logging into the target account, extracting and analyzing the login device, login time, and authentication duration corresponding to the authentication records, and calculating the reliability of the authentication records; Extract target records from the authentication records based on the reliability, and obtain the target time period corresponding to each target record based on the login time; Step S200: extracting information areas in the web pages browsed by the user during the target period, and capturing the user behavior in the information areas; According to the number of interactive operations between the user and the information area in the webpage, and the time period during which the mouse cursor stays in the information area, the bias degree of each information area corresponding to each target record is obtained; Step S300: Based on the login device corresponding to each target record, the bias levels corresponding to the target records on the same login device are aggregated. Federated learning technology is used to integrate the bias levels corresponding to each device to obtain the user's bias level for each information area, and a corresponding first set is established. Step S400: Based on the sample data currently extracted from the total behavior data to be applied to user behavior analysis, based on the length of time the mouse cursor is in each information area in the total behavior data and the sample data, and the first set, calculate the warning coefficient of the current sample data, and determine whether to issue a warning prompt for the sample data based on the warning coefficient.

2. The AI ​​identity authentication method based on user behavior according to claim 1, characterized in that: Step S100 includes: Step S110: Obtaining historical authentication records of identity authentication when logging into a target account. The target account is registered by the user on a webpage during registration, and the device used to register the target account is used as a trusted device for the target account. The identity authentication methods for logging into the target account include password verification and biometric verification. If a certain authentication record corresponds to password verification, the duration from the moment the password is entered to the moment the password verification is completed is used as the authentication duration of the certain authentication record. If a certain authentication record corresponds to biometric verification, the duration from the moment the verification interface begins to appear to the moment the biometric verification is completed is used as the authentication duration of the certain authentication record. Then, based on the authentication durations of several authentication records, the average authentication duration D^ is calculated. Step S120: Extract the authentication record R that is not a history of logging into the target account on the trusted device and successfully authenticating the user; obtain the device usage period of the trusted device within the historical S days, and extract the time T of successful authentication in the authentication record R. R , set the initial target quantity to 0, if time T R If it falls within the usage period of a certain day, the target quantity value is increased by 1, and the final target quantity S is obtained. R , get the first reliability G1=S of the authentication record R R / S, 0≤S R ≤S; If the target account is at time T R As the starting point, the subsequent period P R If no high-risk operation is performed within the authentication record R, the second reliability of the authentication record R is set to G2=1; if a high-risk operation is performed, the second reliability is set to G2=0; Based on the authentication method of the authentication record R, the authentication duration D of the authentication record R is obtained. R , and then get the third reliability of the authentication record R , e is a natural constant, max() is for finding the maximum value, and min() is for finding the minimum value.

3. The AI ​​identity authentication method based on user behavior according to claim 2, characterized in that: Step S100 also includes: obtaining the total reliability value G of the authentication record R according to the preset weights of G1, G2 and G3. R , if the total reliability value G R If it is greater than the preset reliability threshold, the authentication record R is taken as the target record, and then all target records in which the target account is not logged in on the trusted device and the identity authentication is successful are obtained, and the authentication record in which the target account is logged in on the trusted device and the identity authentication is successful is also taken as the target record; and the moment when the identity authentication of the target record is successful is taken as the starting point, and the previous time period P is taken as the target time period, and then all target records and the target time period corresponding to each target record are obtained.

4. The AI ​​identity authentication method based on user behavior according to claim 1, characterized in that: Step S200 includes: Step S210: extracting information areas in the webpages browsed by the user during the target period, the information areas including text areas, control areas, and image areas, and capturing the user's behavior in each information area, the user behavior being the user's mouse operation; Get the target period P corresponding to a target record Q, extract all text areas displayed on the web page within the target period P, obtain the position of the mouse cursor at each moment within the target period P, take the period of time the mouse cursor stays in a text area FA as P1, and the duration of the stay period P1 as the stay duration D1. Extract any three adjacent moments T1, T2, and T3 within the stay period P1. If the position and shape of the mouse cursor at moments T1, T2, and T3 remain unchanged, mark moment T2, and then obtain all marked moments within the target period P. The durations of the marked moments are aggregated to obtain the marked duration D2. Step S220: The number of interactive operations between the user and the text area of ​​the webpage during the dwell period P1 is taken as N1. The interactive operations include single-click, double-click, selection, and scrolling. Then, according to the number of text areas M in the target period P, and the dwell time, marking time, and number of interactive operations corresponding to each text area, the bias degree of the target record Q towards the text area is obtained as follows: ,in, is the marking duration corresponding to the mth text region, is the dwell time corresponding to the mth text area, e is a natural constant, is the number of interactive operations corresponding to the mth text region; and then, by analogy with the bias degree of the target record Q to the text region, the bias degree of each information region corresponding to each target record is obtained.

5. The AI ​​identity authentication method based on user behavior according to claim 1, characterized in that: Step S300 includes: establishing a local model corresponding to each device and a global model corresponding to the user, training the global model using federated learning technology based on the degree of bias of each information area corresponding to the target record belonging to the same device, obtaining the final degree of bias of the user for each information area, and sorting the information areas in descending order of bias, and inputting the degree of bias into the pre-established first set in sequence according to the sorting order.

6. The AI ​​identity authentication method based on user behavior according to claim 1, characterized in that: Step S400 includes: based on the sample data currently extracted from the total behavior data to be applied to user behavior analysis, extracting the time DY1 that the mouse cursor is in a certain information area Y in the total behavior data, and the time DY2 that the mouse cursor is in the information area Y in the sample data, and obtaining the characteristic value Z=DY2 / DY1 of the information area Y; then obtaining the characteristic value of each information area, and inputting each characteristic value into a pre-established second set in sequence according to the serial number order corresponding to each information area in the first set; then obtaining the cosine similarity between the first set and the second set as the warning coefficient of the sample data. If the warning coefficient is less than the preset numerical threshold, a warning prompt is issued for the sample data, and relevant personnel are prompted to correct the sample data.

7. An AI identity authentication system based on user behavior, configured to execute the AI ​​identity authentication method based on user behavior according to any one of claims 1 to 6, characterized in that: The system includes a target period extraction module, a deviation degree calculation module, a first set establishment module and an early warning prompt module; Target Time Period Extraction Module: This module is used to obtain the authentication records of the target account during historical login, extract and analyze the login device, login time, and authentication duration corresponding to the authentication records, and calculate the reliability of the authentication records; based on the reliability, it extracts the target records in the authentication records and obtains the target time period corresponding to each target record based on the login time; Bias degree calculation module: used to extract the information area in the web pages browsed by users during the target period and capture the user behavior in the information area; According to the number of interactive operations between the user and the information area in the webpage, and the time period during which the mouse cursor stays in the information area, the bias degree of each information area corresponding to each target record is obtained; A first set establishment module is used to collect the bias levels corresponding to target records in the same login device based on the login device corresponding to each target record, use federated learning technology to integrate the bias levels corresponding to each device, obtain the user's bias level for each information area, and establish the corresponding first set; Early warning prompt module: used to calculate the early warning coefficient of the current sample data based on the sample data to be applied to user behavior analysis currently extracted from the total behavior data, the length of time the mouse cursor is in each information area in the total behavior data and sample data, and the first set, and determine whether to issue an early warning prompt for the sample data based on the early warning coefficient.

8. The user behavior-based AI identity authentication system according to claim 7, characterized in that: The target period extraction module includes an authentication record acquisition unit, a reliability calculation unit and a target period extraction unit; Authentication record acquisition unit: used to obtain the historical authentication records of the target account. The target account is registered by the user on the web page during registration. The authentication methods for logging into the target account include password verification and biometric verification; Reliability calculation unit: used to extract and analyze the login device, login time and authentication duration corresponding to the authentication record, and calculate the first reliability, second reliability and third reliability of the authentication record; A target period extraction unit is configured to extract a target record from the authentication record according to preset weights of the first reliability, the second reliability, and the third reliability; And according to the successful identity authentication time, the target time period corresponding to each target record is obtained.

9. The user behavior-based AI identity authentication system according to claim 7, characterized in that: The deviation degree calculation module includes an information region extraction unit and a deviation degree calculation unit; An information region extraction unit is configured to extract information regions in the web pages browsed by the user during the target period. The information regions include text regions, control regions, and image regions, and to capture the user's behavior in each information region. The user behavior is the user's behavior of operating the mouse. The bias degree calculation unit is used to obtain the bias degree of each information area corresponding to each target record according to the number of interactive operations between the user and the information area in the web page and the time period during which the mouse cursor stays in the information area.

Citation Information

Patent Citations

  • Access control and security protection method and system based on zero-trust network

    CN118200042A

  • Identity authentication method and system based on block chain

    CN120342624A