Enterprise user registration and authentication system and method based on multi-factor verification

The enterprise user registration and authentication system with multi-factor verification combines registration information, basic identity attribute data, real-time behavior data and interface call frequency to dynamically adjust the identity authentication strategy, solving the problems of security and inefficiency in the existing system and achieving more efficient and secure user authentication.

CN120658475APending Publication Date: 2025-09-16ZHONGLIAN HENGCHUANG (SHANXI) TECHNOLOGY CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510882102.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

In existing enterprise user registration and authentication systems, single-factor verification methods cannot meet security requirements, and manual review leads to inefficiency and potential errors.

Method used

The company uses a multi-factor authentication-based enterprise user registration and authentication system, comprising a registration module, an authentication module, a judgment module, and a processing module. The system receives and examines registration information, collects basic identity attribute data, and dynamically adjusts authentication strategies based on real-time behavioral data and interface call frequency to improve security and efficiency.

Benefits of technology

It realizes comprehensive management and flexible adjustment of enterprise user registration and authentication process, improves authentication efficiency, reduces manual review costs, enhances system security, and adapts to the behavior patterns and security needs of different users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658475A_ABST
    Figure CN120658475A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of registration and authentication, and discloses an enterprise user registration and authentication system and method based on multi-factor verification, and the system comprises a registration module which is configured to judge whether a to-be-authenticated enterprise user is successfully registered or not based on an inspection result; the authentication module is configured to determine an initial identity verification strategy of the to-be-authenticated enterprise user according to the basic identity attribute data; the judgment module is configured to obtain the behavior mode deviation degree of the to-be-authenticated enterprise user based on the real-time behavior data, and judge whether to adjust the initial identity verification strategy according to the behavior mode deviation degree; the processing module is configured to determine an adjustment coefficient of the initial identity verification strategy and obtain a final identity verification strategy. According to the invention, through combination of the registration information, the basic identity attribute data, the real-time behavior data and the interface calling frequency, comprehensive management and flexible adjustment of the enterprise user registration and authentication process are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of registration and authentication, and in particular to a system and method for enterprise user registration and authentication based on multi-factor verification. Background Art

[0002] With the rapid development of information technology, enterprises have continuously increased their security requirements for user registration and authentication. Traditional single-factor authentication methods, such as relying solely on usernames and passwords, can no longer meet the current stringent security requirements. In addition,

[0003] In the enterprise user registration and authentication process, ensuring the authenticity and security of user information while simplifying the authentication steps to improve efficiency and avoid delays and errors that may be caused by manual review has become an urgent problem to be solved.

[0004] Therefore, it is necessary to design an enterprise user registration and authentication system and method based on multi-factor verification to solve the problems existing in the current technology. Summary of the Invention

[0005] In view of this, the present invention proposes an enterprise user registration and authentication system and method based on multi-factor verification, aiming to simplify the authentication steps to improve efficiency and avoid delays and errors that may be caused by manual review.

[0006] In one aspect, the present invention provides an enterprise user registration and authentication system based on multi-factor verification, comprising:

[0007] a registration module configured to receive registration information of a corporate user to be authenticated, check the registration information, and determine whether the corporate user to be authenticated has been successfully registered based on the check result;

[0008] The authentication module is configured to, upon determining that the registration of the enterprise user to be authenticated is successful, authenticate the enterprise user to be authenticated according to a multi-factor authentication rule, collect basic identity attribute data of the enterprise user to be authenticated, and determine an initial identity authentication policy for the enterprise user to be authenticated based on the basic identity attribute data; wherein the initial identity authentication policy includes initial authentication factors and initial authentication strength;

[0009] a judgment module configured to collect real-time behavior data of the enterprise user to be authenticated, obtain a behavior pattern deviation of the enterprise user to be authenticated based on the real-time behavior data, and determine whether to adjust the initial identity authentication policy according to the behavior pattern deviation;

[0010] The processing module is configured to collect the interface call frequency of the enterprise user to be authenticated when it is determined that the initial identity authentication policy needs to be adjusted, and determine the adjustment coefficient of the initial identity authentication policy based on the behavior pattern deviation and the interface call frequency, and obtain the final identity authentication policy.

[0011] Furthermore, the multi-factor authentication rule includes password authentication, biometric authentication and SMS verification code authentication.

[0012] Furthermore, the registration module checks the registration information and determines whether the enterprise user to be authenticated has successfully registered based on the check result, including:

[0013] Checking the registration information to determine whether the registration information contains the account information and enterprise qualification information of the enterprise user to be authenticated;

[0014] If the registration information includes the account information and enterprise qualification information, and both the account information and the enterprise qualification information are verified, it is determined that the registration of the enterprise user to be authenticated is successful;

[0015] If the registration information does not include the account information and / or enterprise qualification information, or any one of the account information and enterprise qualification information fails to pass the verification, it is determined that the registration of the enterprise user to be authenticated has failed.

[0016] Furthermore, when the authentication module determines the initial identity authentication strategy of the enterprise user to be authenticated based on the basic identity attribute data, it includes:

[0017] Parsing the basic identity attribute data to obtain the industry risk level, enterprise size, and number of historical violations of the enterprise user to be authenticated;

[0018] Determining the basic identity authentication strategy for the enterprise user to be authenticated according to the industry risk level;

[0019] Determining whether the basic identity authentication strategy needs to be optimized based on the number of historical violations; if so, determining an optimization coefficient of the basic identity authentication strategy based on the enterprise scale, and obtaining the initial identity authentication strategy;

[0020] Wherein, when determining the basic identity authentication strategy of the enterprise user to be authenticated according to the industry risk level, it includes:

[0021] The industry risk levels include low, medium and high;

[0022] When the industry risk level is low, determining the basic identity authentication strategy as the first identity authentication strategy;

[0023] When the industry risk level is medium, determining the basic identity authentication strategy as a second identity authentication strategy;

[0024] When the industry risk level is high, the basic identity authentication strategy is determined to be the third identity authentication strategy.

[0025] Furthermore, when the authentication module determines whether the basic identity authentication strategy needs to be optimized based on the number of historical violations, it includes:

[0026] Comparing the number of historical violations with a historical violation threshold, and determining whether the basic identity authentication policy needs to be optimized based on the comparison result;

[0027] When the number of historical violations is greater than or equal to the historical violation number threshold, determining that the basic identity authentication strategy needs to be optimized;

[0028] When the number of historical violations is less than the historical violation threshold, it is determined that the basic identity authentication policy does not need to be optimized.

[0029] Furthermore, when the authentication module determines the optimization coefficient of the basic identity authentication strategy according to the enterprise scale and obtains the initial identity authentication strategy, it includes:

[0030] Comparing the enterprise size with a first enterprise size and a second enterprise size, and determining an optimization coefficient of the basic identity authentication strategy according to the comparison results; wherein the first enterprise size is smaller than the second enterprise size;

[0031] When the enterprise scale is less than or equal to the first enterprise scale, determining the optimization coefficient to be the first optimization coefficient;

[0032] When the enterprise scale is larger than the first enterprise scale and smaller than the second enterprise scale, determining the optimization coefficient to be the second optimization coefficient;

[0033] When the enterprise scale is greater than or equal to the second enterprise scale, determining the optimization coefficient to be a third optimization coefficient;

[0034] The basic identity authentication strategy is optimized according to the optimization coefficient, and the initial identity authentication strategy is obtained.

[0035] Furthermore, the judgment module obtains a behavior pattern deviation of the enterprise user to be authenticated based on the real-time behavior data, and judges whether to adjust the initial identity authentication policy according to the behavior pattern deviation, including:

[0036] Analyze the real-time behavior data to obtain the real-time login time and real-time IP address;

[0037] Calculating the behavior pattern deviation based on the obtained real-time login time and real-time IP address; comparing the behavior pattern deviation with a behavior pattern deviation threshold, and determining whether to adjust the initial identity authentication policy based on the comparison result;

[0038] When the behavior pattern deviation is greater than or equal to the behavior pattern deviation threshold, determining that the initial identity authentication policy needs to be adjusted;

[0039] When the behavior pattern deviation is less than the behavior pattern deviation threshold, it is determined that there is no need to adjust the initial identity authentication policy.

[0040] Furthermore, when the processing module determines the adjustment coefficient of the initial identity authentication strategy according to the behavior pattern deviation and the interface call frequency and obtains the final identity authentication strategy, it includes:

[0041] Calculate the verification impact index based on the behavior pattern deviation and interface call frequency;

[0042] Comparing the verification impact index with historical data, and determining an adjustment coefficient for the initial identity verification policy based on the comparison result;

[0043] When there is a historical verification impact index identical to the verification impact index in the historical data, the historical adjustment coefficient corresponding to the historical verification impact index is used as the adjustment coefficient;

[0044] When there is no historical verification influence index identical to the verification influence index in the historical data, calculating the difference between the verification influence index and each historical verification influence index one by one, extracting the minimum difference, obtaining the absolute value of the minimum difference, and recording it as the minimum absolute difference; determining the adjustment coefficient of the initial identity authentication policy based on the minimum absolute difference;

[0045] The initial identity authentication strategy is adjusted according to the adjustment coefficient to obtain a final identity authentication strategy.

[0046] Furthermore, when the processing module determines the adjustment coefficient of the initial identity authentication policy according to the minimum absolute difference, the processing module includes:

[0047] When the historical verification impact index corresponding to the minimum absolute difference is unique, the historical adjustment coefficient corresponding to the unique historical verification impact index is used as the adjustment coefficient;

[0048] When the historical verification impact index corresponding to the minimum absolute difference is not unique, the average value of the historical adjustment coefficients corresponding to all the historical verification impact indexes is calculated, and the average value of the historical adjustment coefficients is used as the adjustment coefficient.

[0049] Compared with existing technologies, the present invention offers the following advantages: The enterprise user registration and authentication system based on multi-factor authentication combines registration information, basic identity attribute data, real-time behavioral data, and interface call frequency to achieve comprehensive management and flexible adjustment of the enterprise user registration and authentication process. This system not only improves authentication efficiency and reduces the cost of manual review, but also effectively enhances system security and prevents potential security risks. Furthermore, by dynamically adjusting identity authentication policies, the system can adapt to the behavioral patterns and security needs of different enterprise users, providing more personalized and intelligent services.

[0050] In another aspect, the present invention also proposes a method for enterprise user registration and authentication based on multi-factor verification, comprising the following steps:

[0051] Receive registration information of the enterprise user to be authenticated, check the registration information, and determine whether the registration of the enterprise user to be authenticated is successful based on the check result;

[0052] When it is determined that the enterprise user to be authenticated has successfully registered, the enterprise user to be authenticated is authenticated according to a multi-factor authentication rule, and basic identity attribute data of the enterprise user to be authenticated is collected, and an initial identity authentication policy of the enterprise user to be authenticated is determined based on the basic identity attribute data; wherein the initial identity authentication policy includes initial authentication factors and initial authentication strength;

[0053] Collecting real-time behavior data of the enterprise user to be authenticated, and obtaining a behavior pattern deviation of the enterprise user to be authenticated based on the real-time behavior data, and determining whether to adjust the initial identity authentication policy according to the behavior pattern deviation;

[0054] When it is determined to adjust the initial identity authentication policy, the interface call frequency of the enterprise user to be authenticated is collected, and the adjustment coefficient of the initial identity authentication policy is determined according to the behavior pattern deviation and the interface call frequency, and the final identity authentication policy is obtained.

[0055] It is understandable that the above-mentioned enterprise user registration and authentication system and method based on multi-factor verification have the same beneficial effects and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:

[0057] Figure 1 A structural block diagram of an enterprise user registration and authentication system based on multi-factor verification provided by an embodiment of the present invention;

[0058] Figure 2 This is a flowchart of a method for enterprise user registration and authentication based on multi-factor verification provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0059] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art. It should be noted that, unless there is a conflict, the embodiments of the present disclosure and the features in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.

[0060] See Figure 1 As shown, in some embodiments of the present application, this embodiment provides an enterprise user registration and authentication system based on multi-factor verification, including:

[0061] a registration module configured to receive registration information of a corporate user to be authenticated, check the registration information, and determine whether the corporate user to be authenticated has been successfully registered based on the check result;

[0062] The authentication module is configured to, upon determining that the registration of the enterprise user to be authenticated is successful, authenticate the enterprise user to be authenticated according to a multi-factor authentication rule, collect basic identity attribute data of the enterprise user to be authenticated, and determine an initial identity authentication policy for the enterprise user to be authenticated based on the basic identity attribute data; wherein the initial identity authentication policy includes initial authentication factors and initial authentication strength;

[0063] a judgment module configured to collect real-time behavior data of the enterprise user to be authenticated, obtain a behavior pattern deviation of the enterprise user to be authenticated based on the real-time behavior data, and determine whether to adjust the initial identity authentication policy according to the behavior pattern deviation;

[0064] The processing module is configured to collect the interface call frequency of the enterprise user to be authenticated when it is determined that the initial identity authentication policy needs to be adjusted, and determine the adjustment coefficient of the initial identity authentication policy based on the behavior pattern deviation and the interface call frequency, and obtain the final identity authentication policy.

[0065] It is understood that the enterprise user registration and authentication system based on multi-factor verification provided in this embodiment achieves comprehensive management and flexible adjustment of the enterprise user registration and authentication process by combining registration information, basic identity attribute data, real-time behavioral data, and interface call frequency. This system not only improves authentication efficiency and reduces the cost of manual review, but also effectively enhances system security and prevents potential security risks. Furthermore, by dynamically adjusting identity authentication strategies, the system can adapt to the behavioral patterns and security needs of different enterprise users, providing more personalized and intelligent services.

[0066] Specifically, the multi-factor verification rules include password verification, biometric verification and SMS verification code verification.

[0067] It is understandable that biometric verification uses biometric technologies such as fingerprint recognition, facial recognition or iris scanning to improve the accuracy and security of verification.

[0068] Specifically, the registration module checks the registration information and determines whether the enterprise user to be authenticated has successfully registered based on the check result, including:

[0069] Checking the registration information to determine whether the registration information contains the account information and enterprise qualification information of the enterprise user to be authenticated;

[0070] If the registration information includes the account information and enterprise qualification information, and both the account information and the enterprise qualification information are verified, it is determined that the registration of the enterprise user to be authenticated is successful;

[0071] If the registration information does not include the account information and / or enterprise qualification information, or any one of the account information and enterprise qualification information fails to pass the verification, it is determined that the registration of the enterprise user to be authenticated has failed.

[0072] Understandably, during the registration process, the system performs a uniqueness check on account information (such as username, email address, and mobile phone number) to ensure that each corporate user has a unique account. Simultaneously, corporate qualification information (such as business license and tax registration certificate) is verified by comparing it with the corporate credit information disclosure system or data interfaces of relevant government agencies to confirm the legitimacy and authenticity of the corporate user. This dual verification mechanism effectively prevents fraudulent registrations and malicious attacks, ensuring the security and reliability of the system.

[0073] Specifically, when the authentication module determines the initial identity authentication strategy of the enterprise user to be authenticated according to the basic identity attribute data, it includes:

[0074] Parsing the basic identity attribute data to obtain the industry risk level, enterprise size, and number of historical violations of the enterprise user to be authenticated;

[0075] Determining the basic identity authentication strategy for the enterprise user to be authenticated according to the industry risk level;

[0076] Determining whether the basic identity authentication strategy needs to be optimized based on the number of historical violations; if so, determining an optimization coefficient of the basic identity authentication strategy based on the enterprise scale, and obtaining the initial identity authentication strategy;

[0077] Wherein, when determining the basic identity authentication strategy of the enterprise user to be authenticated according to the industry risk level, it includes:

[0078] The industry risk levels include low, medium and high;

[0079] When the industry risk level is low, determining the basic identity authentication strategy as the first identity authentication strategy;

[0080] When the industry risk level is medium, determining the basic identity authentication strategy as a second identity authentication strategy;

[0081] When the industry risk level is high, the basic identity authentication strategy is determined to be the third identity authentication strategy.

[0082] In this embodiment, the first identity authentication strategy has a basic authentication strength of 0% to 30%, with password verification as the initial authentication factor. The second identity authentication strategy has a basic authentication strength of 31% to 70%, with password verification and biometric verification as the initial authentication factor, or a combination of password verification and biometric verification. The third identity authentication strategy has a basic authentication strength of 71% to 100%, with a combination of password verification, biometric verification, and SMS verification as the initial authentication factor. This approach allows the system to implement different levels of identity authentication for enterprise users of varying risk levels, ensuring both security and efficiency. When the basic authentication strength is 30.4%, rounded to 30%, the first identity authentication strategy (password verification) is adopted. When the basic authentication strength falls between the two strategies, such as 70.6%, rounded to 71%, the higher-strength authentication strategy (the third authentication strategy) is adopted, ensuring complete security.

[0083] In this embodiment, the verification strength is a quantitative value. When this value falls within a certain value range, the corresponding verification factor is selected for verification.

[0084] Understandably, different industries face varying degrees of security risks due to their business characteristics and operating models. Therefore, determining basic authentication strategies based on industry risk levels allows for differentiated management of enterprise users at varying risk levels.

[0085] Specifically, when the authentication module determines whether the basic identity authentication strategy needs to be optimized based on the number of historical violations, it includes:

[0086] Comparing the number of historical violations with a historical violation threshold, and determining whether the basic identity authentication policy needs to be optimized based on the comparison result;

[0087] When the number of historical violations is greater than or equal to the historical violation number threshold, determining that the basic identity authentication strategy needs to be optimized;

[0088] When the number of historical violations is less than the historical violation threshold, it is determined that the basic identity authentication policy does not need to be optimized.

[0089] Understandably, for enterprise users with a high number of historical violations, the system adopts a stricter authentication policy to improve system security and risk control capabilities. By analyzing the number of historical violations, the system can identify potential high-risk users and take appropriate measures to strengthen authentication, thereby avoiding potential security risks.

[0090] Specifically, when the authentication module determines the optimization coefficient of the basic identity authentication strategy according to the enterprise scale and obtains the initial identity authentication strategy, it includes:

[0091] Comparing the enterprise size with a first enterprise size and a second enterprise size, and determining an optimization coefficient of the basic identity authentication strategy according to the comparison results; wherein the first enterprise size is smaller than the second enterprise size;

[0092] When the enterprise scale is less than or equal to the first enterprise scale, determining the optimization coefficient to be the first optimization coefficient;

[0093] When the enterprise scale is larger than the first enterprise scale and smaller than the second enterprise scale, determining the optimization coefficient to be the second optimization coefficient;

[0094] When the enterprise scale is greater than or equal to the second enterprise scale, determining the optimization coefficient to be a third optimization coefficient;

[0095] The basic identity authentication strategy is optimized according to the optimization coefficient, and the initial identity authentication strategy is obtained.

[0096] It's understandable that optimizing the basic authentication strategy actually involves adjusting the basic verification strength. Assuming the initial authentication strategy for a corporate user to be authenticated is a basic verification strength of 29%, and the corresponding basic verification method is password verification, with an optimization factor of 1.5, the optimized basic verification strength is 43.5%, bringing it within the range of the secondary authentication strategy and requiring the addition of biometric verification as an initial verification factor. This allows the system to flexibly adjust verification strength based on the scale of the enterprise, ensuring a balance between security and verification efficiency.

[0097] Understandably, differences in enterprise size often translate into varying levels of business complexity and security risk. For smaller enterprises, due to their relatively simple operations and potentially lower security risks, a more relaxed authentication policy may be sufficient. In this case, the optimization factor (the first optimization factor) may favor lower authentication strength to simplify the verification process and improve user experience. Larger enterprises, on the other hand, have complex operations, involving higher-value data and assets, and correspondingly higher potential security risks. Therefore, the system requires a more stringent authentication policy to ensure security. In this case, the optimization factor (the second or third optimization factor) may favor higher authentication strength and additional verification elements, such as introducing more biometric verification or increasing the frequency of SMS verification codes. In this way, the system can flexibly adjust the stringency of authentication policies based on enterprise size, ensuring both convenience for small enterprises and security for larger ones.

[0098] Specifically, the judgment module obtains the behavior pattern deviation of the enterprise user to be authenticated based on the real-time behavior data, and judges whether to adjust the initial identity authentication policy according to the behavior pattern deviation, including:

[0099] Analyze the real-time behavior data to obtain the real-time login time and real-time IP address;

[0100] Calculating the behavior pattern deviation based on the obtained real-time login time and real-time IP address; comparing the behavior pattern deviation with a behavior pattern deviation threshold, and determining whether to adjust the initial identity authentication policy based on the comparison result;

[0101] When the behavior pattern deviation is greater than or equal to the behavior pattern deviation threshold, determining that the initial identity authentication policy needs to be adjusted;

[0102] When the behavior pattern deviation is less than the behavior pattern deviation threshold, it is determined that there is no need to adjust the initial identity authentication policy.

[0103] In this embodiment, when calculating the behavior pattern deviation, it is obtained by weighted calculation of the normalized time deviation and IP address deviation.

[0104] The time deviation is obtained by the following formula:

[0105]

[0106] Where DT represents the time deviation; Tr represents the current login time; Th represents the historical average login time; and σT represents the standard deviation of the historical login time.

[0107] The IP address deviation is obtained by the following formula:

[0108]

[0109] Among them, DIP represents the deviation of the IP address; LOCc represents the geographical location of the current login IP (expressed in longitude and latitude); LOCct represents the center point of the geographical location of the historical login IP (average longitude and latitude); dmax represents the maximum tolerance distance of geographical offset; d(LOCc,LOCct) represents the geographical distance function (such as the distance calculated by the Haversine formula, in kilometers).

[0110] It is understood that the behavioral pattern deviation reflects the degree of difference between the real-time behavior of the enterprise user to be authenticated and his or her historical behavior pattern. When the real-time behavior of the enterprise user to be authenticated deviates significantly from his or her historical behavior pattern, it may indicate an abnormal login or potential security risk. Therefore, the system promptly identifies and responds to these potential risks by calculating the behavioral pattern deviation and comparing it with the preset behavioral pattern deviation threshold. When the behavioral pattern deviation reaches or exceeds the threshold, the system determines that the initial identity authentication policy needs to be adjusted. Such adjustments may include adding verification factors, increasing verification strength, or taking other security measures to address potential security risks.

[0111] Specifically, when the processing module determines the adjustment coefficient of the initial identity authentication strategy according to the behavior pattern deviation and the interface call frequency and obtains the final identity authentication strategy, it includes:

[0112] Calculate the verification impact index based on the behavior pattern deviation and interface call frequency;

[0113] Comparing the verification impact index with historical data, and determining an adjustment coefficient for the initial identity verification policy based on the comparison result;

[0114] When there is a historical verification impact index identical to the verification impact index in the historical data, the historical adjustment coefficient corresponding to the historical verification impact index is used as the adjustment coefficient;

[0115] When there is no historical verification influence index identical to the verification influence index in the historical data, calculating the difference between the verification influence index and each historical verification influence index one by one, extracting the minimum difference, obtaining the absolute value of the minimum difference, and recording it as the minimum absolute difference; determining the adjustment coefficient of the initial identity authentication policy based on the minimum absolute difference;

[0116] The initial identity authentication strategy is adjusted according to the adjustment coefficient to obtain a final identity authentication strategy.

[0117] In this embodiment, the verification impact index is obtained by the following formula:

[0118]

[0119] Among them, VII represents the verification impact index; D represents the behavior pattern deviation; F represents the interface call frequency; Dmax represents the set maximum deviation; Fmax represents the set maximum interface call frequency; ω1 and ω2 represent weight coefficients, satisfying ω1+ω2=1.

[0120] As you can understand, the Verification Impact Index comprehensively considers both behavioral pattern deviation and interface call frequency, providing the system with a more comprehensive and accurate assessment basis. Interface call frequency reveals a user's utilization of system resources. High behavioral pattern deviation and abnormal interface call frequency may indicate that the user is engaging in high-risk operations or potentially malicious behavior. Therefore, the system considers this combination of behavioral pattern and interface call activity as a high security risk and quantifies this risk by calculating the Verification Impact Index. The process of determining the adjustment coefficient demonstrates the system's ability to flexibly adjust authentication policies. By comparing the current Verification Impact Index with historical data, the system identifies scenarios where the historical data matches the current Verification Impact Index and selects the corresponding historical adjustment coefficient as a reference. If there's no exact match in the historical data, the system calculates the minimum absolute difference to approximate the most similar historical authentication scenario and determines the adjustment coefficient accordingly. This approach ensures that the system can dynamically adjust the stringency of authentication policies based on the current security risk situation, enabling personalized security management and risk control.

[0121] Specifically, when the processing module determines the adjustment coefficient of the initial identity authentication policy according to the minimum absolute difference, it includes:

[0122] When the historical verification impact index corresponding to the minimum absolute difference is unique, the historical adjustment coefficient corresponding to the unique historical verification impact index is used as the adjustment coefficient;

[0123] When the historical verification impact index corresponding to the minimum absolute difference is not unique, the average value of the historical adjustment coefficients corresponding to all the historical verification impact indexes is calculated, and the average value of the historical adjustment coefficients is used as the adjustment coefficient.

[0124] It is understandable that in the process of determining the adjustment coefficient, the system fully considers the diversity and complexity of historical data. When the historical verification impact index corresponding to the minimum absolute difference is unique, the system directly adopts the historical adjustment coefficient corresponding to the historical verification impact index. This method is simple and direct, and can ensure that the adjustment coefficient is highly matched with the current security risk situation. When the historical verification impact index corresponding to the minimum absolute difference is not unique, the system determines the adjustment coefficient by calculating the average of all relevant historical adjustment coefficients. This method can comprehensively consider the impact of multiple similar historical verification scenarios, making the adjustment coefficient more robust and reliable. Through this flexible adjustment mechanism, the system can dynamically optimize the authentication strategy according to the real-time security risk situation, which not only ensures security but also improves the user experience.

[0125] It can be understood that, similar to the optimization of the basic authentication strategy, the adjustment of the initial authentication strategy is actually the adjustment of the initial verification strength.

[0126] See Figure 2 As shown, in some embodiments of the present application, this embodiment provides an enterprise user registration and authentication method based on multi-factor verification, including the following steps:

[0127] S100: receiving registration information of a corporate user to be authenticated, checking the registration information, and determining whether the corporate user to be authenticated has been successfully registered based on the check result;

[0128] S200: When it is determined that the enterprise user to be authenticated has successfully registered, the enterprise user to be authenticated is authenticated according to a multi-factor authentication rule, basic identity attribute data of the enterprise user to be authenticated is collected, and an initial identity authentication policy of the enterprise user to be authenticated is determined based on the basic identity attribute data; wherein the initial identity authentication policy includes initial authentication factors and initial authentication strength;

[0129] S300: collecting real-time behavior data of the enterprise user to be authenticated, and obtaining a behavior pattern deviation of the enterprise user to be authenticated based on the real-time behavior data, and determining whether to adjust the initial identity authentication policy according to the behavior pattern deviation;

[0130] S400: When it is determined to adjust the initial identity authentication policy, the interface call frequency of the enterprise user to be authenticated is collected, and the adjustment coefficient of the initial identity authentication policy is determined according to the behavior pattern deviation and the interface call frequency, and a final identity authentication policy is obtained.

[0131] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or a combination of software and hardware embodiments. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0132] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0133] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0134] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0135] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. An enterprise user registration and authentication system based on multi-factor verification, characterized in that: include: a registration module configured to receive registration information of a corporate user to be authenticated, check the registration information, and determine whether the corporate user to be authenticated has been successfully registered based on the check result; The authentication module is configured to, upon determining that the registration of the enterprise user to be authenticated is successful, authenticate the enterprise user to be authenticated according to a multi-factor authentication rule, collect basic identity attribute data of the enterprise user to be authenticated, and determine an initial identity authentication policy for the enterprise user to be authenticated based on the basic identity attribute data; wherein the initial identity authentication policy includes initial authentication factors and initial authentication strength; a judgment module configured to collect real-time behavior data of the enterprise user to be authenticated, obtain a behavior pattern deviation of the enterprise user to be authenticated based on the real-time behavior data, and determine whether to adjust the initial identity authentication policy according to the behavior pattern deviation; The processing module is configured to collect the interface call frequency of the enterprise user to be authenticated when it is determined that the initial identity authentication policy needs to be adjusted, and determine the adjustment coefficient of the initial identity authentication policy based on the behavior pattern deviation and the interface call frequency, and obtain the final identity authentication policy.

2. The enterprise user registration and authentication system based on multi-factor verification according to claim 1, characterized in that: The multi-factor authentication rules include password authentication, biometric authentication and SMS verification code authentication.

3. The enterprise user registration and authentication system based on multi-factor verification according to claim 2, characterized in that: The registration module checks the registration information and determines whether the enterprise user to be authenticated has successfully registered based on the check result, including: Checking the registration information to determine whether the registration information contains the account information and enterprise qualification information of the enterprise user to be authenticated; If the registration information includes the account information and enterprise qualification information, and both the account information and the enterprise qualification information are verified, it is determined that the registration of the enterprise user to be authenticated is successful; If the registration information does not include the account information and / or enterprise qualification information, or any one of the account information and enterprise qualification information fails to pass the verification, it is determined that the registration of the enterprise user to be authenticated has failed.

4. The enterprise user registration and authentication system based on multi-factor verification according to claim 3 is characterized in that: When the authentication module determines the initial identity authentication strategy of the enterprise user to be authenticated according to the basic identity attribute data, it includes: Parsing the basic identity attribute data to obtain the industry risk level, enterprise size, and number of historical violations of the enterprise user to be authenticated; Determining the basic identity authentication strategy for the enterprise user to be authenticated according to the industry risk level; Determining whether the basic identity authentication strategy needs to be optimized based on the number of historical violations; if so, determining an optimization coefficient of the basic identity authentication strategy based on the enterprise scale, and obtaining the initial identity authentication strategy; Wherein, when determining the basic identity authentication strategy of the enterprise user to be authenticated according to the industry risk level, it includes: The industry risk levels include low, medium and high; When the industry risk level is low, determining the basic identity authentication strategy as the first identity authentication strategy; When the industry risk level is medium, determining the basic identity authentication strategy as a second identity authentication strategy; When the industry risk level is high, the basic identity authentication strategy is determined to be the third identity authentication strategy.

5. The enterprise user registration and authentication system based on multi-factor verification according to claim 4 is characterized in that: When the authentication module determines whether the basic identity authentication strategy needs to be optimized based on the number of historical violations, the method includes: Comparing the number of historical violations with a historical violation threshold, and determining whether the basic identity authentication policy needs to be optimized based on the comparison result; When the number of historical violations is greater than or equal to the historical violation number threshold, determining that the basic identity authentication strategy needs to be optimized; When the number of historical violations is less than the historical violation threshold, it is determined that the basic identity authentication policy does not need to be optimized.

6. The enterprise user registration and authentication system based on multi-factor verification according to claim 5, characterized in that: When the authentication module determines the optimization coefficient of the basic identity authentication strategy according to the enterprise scale and obtains the initial identity authentication strategy, it includes: Comparing the enterprise size with a first enterprise size and a second enterprise size, and determining an optimization coefficient of the basic identity authentication strategy according to the comparison results; wherein the first enterprise size is smaller than the second enterprise size; When the enterprise scale is less than or equal to the first enterprise scale, determining the optimization coefficient to be the first optimization coefficient; When the enterprise scale is larger than the first enterprise scale and smaller than the second enterprise scale, determining the optimization coefficient to be the second optimization coefficient; When the enterprise scale is greater than or equal to the second enterprise scale, determining the optimization coefficient to be a third optimization coefficient; The basic identity authentication strategy is optimized according to the optimization coefficient, and the initial identity authentication strategy is obtained.

7. The enterprise user registration and authentication system based on multi-factor verification according to claim 6, characterized in that: The judgment module obtains the behavior pattern deviation of the enterprise user to be authenticated based on the real-time behavior data, and judges whether to adjust the initial identity authentication policy according to the behavior pattern deviation, including: Analyze the real-time behavior data to obtain the real-time login time and real-time IP address; Calculating the behavior pattern deviation based on the obtained real-time login time and real-time IP address; comparing the behavior pattern deviation with a behavior pattern deviation threshold, and determining whether to adjust the initial identity authentication policy based on the comparison result; When the behavior pattern deviation is greater than or equal to the behavior pattern deviation threshold, determining that the initial identity authentication policy needs to be adjusted; When the behavior pattern deviation is less than the behavior pattern deviation threshold, it is determined that there is no need to adjust the initial identity authentication policy.

8. The enterprise user registration and authentication system based on multi-factor verification according to claim 7, characterized in that: When the processing module determines the adjustment coefficient of the initial identity authentication strategy according to the behavior pattern deviation and the interface call frequency and obtains the final identity authentication strategy, it includes: Calculate the verification impact index based on the behavior pattern deviation and interface call frequency; Comparing the verification impact index with historical data, and determining an adjustment coefficient for the initial identity verification policy based on the comparison result; When there is a historical verification impact index identical to the verification impact index in the historical data, the historical adjustment coefficient corresponding to the historical verification impact index is used as the adjustment coefficient; When there is no historical verification influence index identical to the verification influence index in the historical data, calculating the difference between the verification influence index and each historical verification influence index one by one, extracting the minimum difference, obtaining the absolute value of the minimum difference, and recording it as the minimum absolute difference; determining the adjustment coefficient of the initial identity authentication policy based on the minimum absolute difference; The initial identity authentication strategy is adjusted according to the adjustment coefficient to obtain a final identity authentication strategy.

9. The enterprise user registration and authentication system based on multi-factor verification according to claim 8, characterized in that: When the processing module determines the adjustment coefficient of the initial identity authentication policy according to the minimum absolute difference, it includes: When the historical verification impact index corresponding to the minimum absolute difference is unique, the historical adjustment coefficient corresponding to the unique historical verification impact index is used as the adjustment coefficient; When the historical verification impact index corresponding to the minimum absolute difference is not unique, the average value of the historical adjustment coefficients corresponding to all the historical verification impact indexes is calculated, and the average value of the historical adjustment coefficients is used as the adjustment coefficient.

10. A method for enterprise user registration and authentication based on multi-factor authentication, applied to the enterprise user registration and authentication system based on multi-factor authentication according to any one of claims 1 to 9, characterized in that: include: Receive registration information of the enterprise user to be authenticated, check the registration information, and determine whether the registration of the enterprise user to be authenticated is successful based on the check result; When it is determined that the enterprise user to be authenticated has successfully registered, the enterprise user to be authenticated is authenticated according to a multi-factor authentication rule, and basic identity attribute data of the enterprise user to be authenticated is collected, and an initial identity authentication policy of the enterprise user to be authenticated is determined based on the basic identity attribute data; wherein the initial identity authentication policy includes initial authentication factors and initial authentication strength; Collecting real-time behavior data of the enterprise user to be authenticated, and obtaining a behavior pattern deviation of the enterprise user to be authenticated based on the real-time behavior data, and determining whether to adjust the initial identity authentication policy according to the behavior pattern deviation; When it is determined to adjust the initial identity authentication policy, the interface call frequency of the enterprise user to be authenticated is collected, and the adjustment coefficient of the initial identity authentication policy is determined according to the behavior pattern deviation and the interface call frequency, and the final identity authentication policy is obtained.

Citation Information

Patent Citations

  • Multi-factor identity authentication method and device, equipment and storage medium

    CN115859259A

  • Safety management method for laboratory data cloud storage platform

    CN117118692A

  • Financial service approval method and system based on multiple data sources

    CN119067607A

  • Dynamic access control method and device based on security gateway and trust evaluation and related products

    CN119449465A

  • Self-adaptive secure authentication system

    US20180351925A1