Network security identity verification method and system based on cryptographic technology
By obtaining device and network data to classify scenarios, filter and sort authentication methods, generate optimized combinations and perform secondary verification, the problem of insufficient adaptability of network security identity authentication in dynamic scenarios is solved, and the authentication success rate and user experience are improved.
Patent Information
- Application Number
- CN202511255479.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-04
- Publication Date
- 2025-09-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing network security authentication technologies lack adaptability in dynamic scenarios, making it difficult to simultaneously ensure security strength and user experience in complex environments.
By acquiring device sensor data and network status data, the scenario classification model is used to classify, filter and sort the authentication method candidate set, generate an optimized authentication method combination, and make adjustments after the initial authentication fails to perform secondary identity authentication.
It achieves dynamic adaptability of authentication strategies, improves universality and reliability in complex scenarios, and improves the final authentication success rate and user experience.
Smart Images

Figure CN120729657A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security identity authentication, and in particular to a network security identity authentication method and system based on cryptographic technology. Background Art
[0002] As a core security cornerstone of the digital age, network security authentication technology is crucial for preventing unauthorized access and thereby protecting personal privacy and data assets. With the accelerating global digitalization process, the reliability and adaptability of authentication technology have become key pillars supporting the entire network security system, profoundly impacting the security of various online services, including finance, social networking, and office work. Its core foundation encompasses traditional password verification, biometric-based recognition technologies (such as fingerprints and voiceprints), and emerging user behavior analysis. These technologies accurately identify and confirm user identities by verifying the credentials or data characteristics provided by users during access, thereby safeguarding the security boundaries of information and assets in the digital world.
[0003] In one existing technology, authentication systems typically rely on a single or fixed combination of authentication methods, such as using only a traditional password or combining a password with static biometrics (such as fingerprints). These methods can be effective in specific scenarios, but their limitations are significant in complex real-world environments. For example, the accuracy of voiceprint authentication can drop significantly in noisy environments, and on low-performance devices, complex biometric algorithms can cause system lags. Existing methods lack adaptability, making it difficult to flexibly adjust policies based on dynamic factors such as device performance, network conditions, or environmental interference. This makes it difficult to simultaneously maintain security strength and user experience in a changing environment.
[0004] In summary, the existing technology has the problem of insufficient adaptability in dynamic scenes. Summary of the Invention
[0005] The present invention provides a network security identity authentication method and system based on cryptographic technology to solve the problem of insufficient adaptability in dynamic scenarios.
[0006] In a first aspect, in order to solve the above technical problems, the present invention provides a network security identity authentication method based on cryptographic technology, comprising: Obtain device sensor data and network status data; Based on the device sensor data and the network status data, a preset scene classification model is used to perform scene classification to obtain a scene type identifier; Extracting an authentication method candidate set from the scenario type identifier, and then screening and sorting the authentication method candidate set to obtain an authentication method priority ranking; Obtaining user interaction data and biometric data corresponding to the priority ranking of the authentication methods, calculating the data missing rate and time consistency, and obtaining a data integrity score; If the data integrity score is higher than a preset integrity score threshold, optimizing the authentication method priority order to generate an optimized authentication method combination; Perform identity authentication according to the optimized authentication method combination to obtain a preliminary authentication result; If the preliminary authentication result is authentication failure, adjusting the optimized authentication method combination to obtain an updated authentication method combination; A secondary identity verification is performed based on the updated authentication method combination to obtain a final authentication result.
[0007] Preferably, the performing scene classification based on the device sensor data and the network status data using a preset scene classification model to obtain a scene type identifier includes: Removing outliers and noise from the device sensor data and the network status data to obtain a clean data set; Extracting a feature vector from the clean data set, and if the feature vector meets a preset threshold judgment condition, classifying the scene using a preset scene classification model to obtain a preliminary scene type identification; Real-time new data is acquired, and the preliminary scene type identifier is dynamically adjusted according to the real-time new data to obtain a scene type identifier.
[0008] Preferably, extracting the authentication method candidate set from the scenario type identifier, screening and sorting the authentication method candidate set, and obtaining the authentication method priority ranking includes: Extracting an authentication method candidate set and an authentication method initial weight from the scenario type identifier; Adjusting the initial weight of the authentication method according to the device performance parameters and the network status data to obtain an adjusted authentication method weight; Obtaining historical authentication data of each authentication method in the authentication method candidate set, calculating its authentication failure rate, and eliminating authentication methods with authentication failure rates higher than a preset failure rate threshold from the authentication method candidate set to obtain a preliminary priority ranking; The preliminary priority ranking is obtained and adjusted according to the real-time authentication response time and device compatibility to obtain the authentication method priority ranking.
[0009] Preferably, the acquiring of user interaction data and biometric data corresponding to the authentication method priority ranking, and calculating the data missing rate and time consistency to obtain a data integrity score includes: According to the priority sorting of the authentication methods, obtaining user interaction data, performing sequence analysis on the user interaction data, and obtaining a user behavior sequence; collecting biometric data from a high-resolution sensor, performing denoising and feature extraction on the biometric data, and obtaining a biometric template; Calculating a data missing rate based on the user behavior sequence and the biometric template; According to the data missing rate, a temporal consistency is calculated, and the data integrity score is generated based on the temporal consistency.
[0010] Preferably, if the data integrity score is higher than a preset integrity score threshold, optimizing the authentication method priority order to generate an optimized authentication method combination includes: If the data integrity score is higher than a preset integrity score threshold, extracting multi-dimensional features to obtain a first feature set; Extracting an authentication method weight from the first feature set, and generating an authentication method score based on the authentication method weight to obtain an authentication method priority; fusing the first feature set and the authentication method priority to obtain a fused feature; According to the fusion characteristics, the priority order of the authentication methods is optimized to generate an optimized authentication method combination.
[0011] Preferably, performing identity authentication according to the optimized authentication method combination to obtain a preliminary authentication result includes: Obtaining a verification model that matches the optimized authentication method combination and authentication data input by the user; Sorting the authentication method combinations in execution order according to the network status data and the scenario type identifier to obtain an authentication link order; According to the order of the authentication steps, the authentication data input by the user is verified to obtain a preliminary authentication result.
[0012] Preferably, if the preliminary authentication result is authentication failure, adjusting the optimized authentication mode combination to obtain an updated authentication mode combination includes: Obtaining feedback data indicating that the preliminary authentication result is authentication failure; Extracting log data from the feedback data and performing data analysis to obtain specific failure causes; According to the specific failure reason, combined with the historical authentication data, the parameters are adjusted to obtain dynamic adjustment parameters; An updated authentication method combination is generated from a pre-established authentication method library according to the dynamic adjustment parameters.
[0013] Preferably, performing secondary identity authentication according to the updated authentication method combination to obtain a final authentication result includes: Calculate the similarity between the user behavior sequence and the preset behavior template to obtain a behavior verification score; Calculating the characteristic distance between the biometric data and a preset biometric template to obtain a biometric matching result; The behavior verification score and the biometric matching result are weighted and fused to obtain a comprehensive authentication score. If the comprehensive authentication score is greater than the preset authentication score threshold, the authentication is passed; otherwise, the authentication fails, and a final authentication result is obtained.
[0014] In a second aspect, the present invention provides a network security identity authentication system based on cryptographic technology, comprising: Data acquisition module, used to obtain device sensor data and network status data; A scene classification module, configured to classify scenes using a preset scene classification model based on the device sensor data and the network status data to obtain a scene type identifier; a priority sorting module, configured to extract a candidate set of authentication methods from the scenario type identifier, and then screen and sort the candidate set of authentication methods to obtain a priority sorting of authentication methods; an integrity scoring module for obtaining user interaction data and biometric data corresponding to the authentication method priority ranking, calculating the data missing rate and time consistency, and obtaining a data integrity score; a combination optimization module, configured to optimize the priority ranking of the authentication methods and generate an optimized authentication method combination if the data integrity score is higher than a preset integrity score threshold; A first verification module is used to perform identity verification according to the optimized authentication method combination and obtain a preliminary authentication result; a combination adjustment module, configured to adjust the optimized authentication method combination to obtain an updated authentication method combination if the preliminary authentication result is authentication failure; The second verification module is used to perform secondary identity authentication according to the updated authentication method combination to obtain a final authentication result.
[0015] In a third aspect, the present invention also provides an electronic device comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, it implements a network security authentication system based on cryptographic technology as described above.
[0016] In a fourth aspect, the present invention also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the above-mentioned network security authentication systems based on cryptographic technology.
[0017] Compared with the prior art, the present invention has the following beneficial effects: (1) This invention dynamically classifies the user's scenario by acquiring multi-dimensional real-time data such as device sensors and network status, and intelligently filters and sorts authentication methods based on the classification results and historical data. This solution enables the authentication strategy to adapt to the current environment, network, and device status in real time, avoiding the drawbacks of traditional fixed strategies with low success rates and poor user experience in specific scenarios (such as poor network conditions or noisy environments), and significantly improving the universality and reliability of authentication methods in complex and changing scenarios.
[0018] (2) The present invention establishes a closed-loop feedback adjustment mechanism after authentication failure. After the initial authentication failure, the specific cause of the failure can be analyzed. Based on this, a more appropriate authentication method can be selected from the authentication method library to dynamically update the authentication combination, and then a secondary verification can be performed. This mechanism enables the system to learn from failures and self-optimize, avoiding users from repeatedly failing authentication due to the same problem, thereby greatly improving the final authentication success rate and enhancing the robustness and intelligence level of the system.
[0019] (3) The present invention incorporates a data integrity assessment step into the decision-making phase and introduces an intelligent scheduling mechanism for the authentication phase into the execution phase. Before generating the final authentication combination, the system will pre-verify whether the required user behavior or biometric data is sufficient and reliable, thus avoiding invalid authentication attempts due to insufficient data quality. When executing authentication, the system will optimize the execution order of the authentication phase based on factors such as network latency. This series of designs ensures the reliability of authentication decisions and the efficiency of the execution process. While ensuring security, it further optimizes resource consumption and time delay, thereby improving the smoothness of the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 This is a flowchart of a network security identity authentication method based on cryptographic technology provided by the first embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a network security identity authentication system based on cryptographic technology provided by the second embodiment of the present invention. DETAILED DESCRIPTION
[0021] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0022] Reference Figure 1 The first embodiment of the present invention provides a network security identity authentication method based on cryptographic technology, comprising the following steps: S11, obtaining device sensor data and network status data; S12, performing scene classification using a preset scene classification model based on the device sensor data and the network status data to obtain a scene type identifier; S13, extracting an authentication method candidate set from the scenario type identifier, and then screening and sorting the authentication method candidate set to obtain an authentication method priority ranking; S14, obtaining user interaction data and biometric data corresponding to the authentication method priority ranking, calculating the data missing rate and time consistency, and obtaining a data integrity score; S15, if the data integrity score is higher than a preset integrity score threshold, optimizing the authentication method priority order to generate an optimized authentication method combination; S16, performing identity authentication according to the optimized authentication method combination to obtain a preliminary authentication result; S17, if the preliminary authentication result is authentication failure, adjusting the optimized authentication method combination to obtain an updated authentication method combination; S18, performing secondary identity authentication according to the updated authentication method combination to obtain a final authentication result.
[0023] In step S11, device sensor data and network status data are obtained, including: In one implementation, to acquire device sensor data, the system first continuously collects triaxial acceleration and angular velocity values at a 50Hz sampling rate using the device's built-in accelerometer and gyroscope. These raw data streams reflect the device's real-time motion. The system then uses a sliding window approach to segment the collected acceleration and angular velocity data into time series. The sliding window size is set to 2 seconds with a step size of 0.5 seconds to capture sustained motion rather than transient jitter. The mean, standard deviation, and maximum value of the data within each window are calculated to form a set of statistical features that quantitatively describe the device's motion pattern over a short period of time. The set of statistical features across all windows constitutes the time series feature set. Simultaneously, the system collects ambient sound signals at a 44.1kHz sampling rate using the device's built-in microphone. Fast Fourier Transform (FFT) is performed on the collected sound signals. The extraction rule is to extract the main frequency components and their corresponding amplitudes within the 0-500Hz frequency band, which covers common background noise such as air conditioning and conversation. This creates a noise spectrum feature set that characterizes the quietness or noisiness of the environment. Ultimately, the device sensor data is composed of the time series feature set and the noise spectrum feature set. To obtain network status data, the system performs a ping test on the preset authentication server, that is, sends an ICMP echo request message and accurately measures the round-trip time from sending the request to receiving the response message, and uses this time as the network delay value, which is the network status data. To obtain historical authentication data, the system reads all authentication records of the user in the past period of time (for example, the last 30 days) from the log database stored locally on the device or on the authentication server. These records include information such as the method used for each authentication, timestamp, geographic location, device ID, IP address, and results.
[0024] It should be noted that these three types of data together constitute the basis for subsequent scene perception and dynamic decision-making, providing comprehensive data support for the system to understand the user's physical environment, network conditions and historical behavior.
[0025] In step S12, based on the device sensor data and the network status data, a preset scene classification model is used to perform scene classification to obtain a scene type identifier, including: Removing outliers and noise from the device sensor data and the network status data to obtain a clean data set; Extracting a feature vector from the clean data set, and if the feature vector is less than a preset threshold judgment condition, classifying the scene using a preset scene classification model to obtain a preliminary scene type identification; New device sensor data and the network status data are acquired, and the preliminary scene type identifier is dynamically adjusted according to the new device sensor data and the network status data to obtain a scene type identifier.
[0026] In one implementation, the system first preprocesses the data acquired in S11 to improve data quality. For network delay values, the system uses a median filter, which effectively suppresses impulsive noise (such as instantaneous network jitter) and effectively protects edge signal information. A 10-second window is set, and outlier data points with large deviations (e.g., exceeding ±3 standard deviations of the median) are replaced with the median of all delay values within the window to eliminate the impact of instantaneous high delays caused by network jitter. For environmental noise data, a sliding average filter is used for smoothing. The core parameter is the filter window size, which is set to 5 data points. The specific implementation process is as follows: For each point in the data sequence, the arithmetic mean of the five points, including the point itself and the two points before and after it, is taken as the new filtered value for that point, reducing sudden noise interference caused by factors such as unexpected equipment vibration.
[0027] The system then combines the preprocessed data into a multidimensional feature vector. The extraction rule combines key metrics such as the acceleration mean and standard deviation from the time series feature set, the dominant frequency amplitude from the noise spectrum feature set, and network latency. Before inputting the feature vector into the model, the system can perform a pre-judgment. For example, if the network latency is greater than 500 milliseconds, it will be directly classified as an "unstable network" scenario to improve response efficiency. This 500-millisecond threshold is based on an analysis of performance test results for mainstream network applications. It is generally believed that delays exceeding this threshold significantly impact real-time interactions. In this embodiment, all feature vectors are input into a pre-set logistic regression classification model. To achieve multi-scenario classification, the pre-set logistic regression classification model is actually a model set consisting of multiple binary logistic regression classifiers, each corresponding to a pre-defined scenario (e.g., a "stationary indoors" classifier, a "walking outdoors" classifier, and so on, among others). During classification, the same feature vector obtained in the previous step is simultaneously input into all scenario classifiers. Each classifier performs a separate calculation. The process is as follows: First, each dimension of the input feature vector is multiplied by its internal unique weight coefficients learned through offline training. All products are summed to obtain a total value. This total value is then input into a Sigmoid function for mapping. Ultimately, the Sigmoid function outputs a value between 0 and 1. This value represents the probability of the specific scenario that the classifier corresponds to. In this way, the system obtains a set of probabilities corresponding to each predefined scenario. The scenario with the highest probability output by the model is determined as the preliminary scene type identification. It should be noted that for each scene classifier, a labeled dataset (feature vectors and their corresponding scene labels) is used, and its internal weight coefficients are iteratively adjusted using optimization algorithms such as gradient descent. In each iteration, the model predicts the input feature vector based on the current weights, calculates the error between the predicted result and the true label, and then adjusts the weights inversely based on this error until the model's prediction error on the validation set is minimized. Through this process, the model eventually learns and solidifies the optimal weight parameters that can distinguish this scene from other scenes, thereby ensuring its classification accuracy and generalization ability.
[0028] Finally, to ensure the continuity and accuracy of scene judgment, the system dynamically adjusts the probability values using a weighted average method. The weighting rule is: smoothed probability = (current output probability × 0.6) + (smoothed probability at the previous moment × 0.4). At the initial moment, since there is no "smoothed probability at the previous moment", the probability value calculated for the first time is directly used as the initial smoothed probability. Based on the smoothed probability value, the system selects the scene corresponding to the highest probability, thereby obtaining a scene type identifier that is more sensitive and stable to the latest environmental changes. It should be noted that the logistic regression model was obtained through offline training on a dataset containing tens of thousands of labeled scenes before the system was deployed, ensuring its classification accuracy and generalization ability.
[0029] In step S13, a candidate set of authentication methods is extracted from the scenario type identifier, and the candidate set of authentication methods is screened and sorted to obtain a priority ranking of the authentication methods, including: Extracting an authentication method candidate set and an authentication method initial weight from the scenario type identifier; Adjusting the initial weight of the authentication method according to the device performance parameters and the network status data to obtain an adjusted authentication method weight; Obtaining historical authentication data based on the adjusted authentication method weights, calculating the authentication failure rate of each authentication method based on the historical authentication data, and eliminating authentication methods with authentication failure rates higher than a preset failure rate threshold from the authentication method candidate set to obtain a preliminary priority ranking; The preliminary priority ranking is obtained and adjusted according to the real-time authentication response time and device compatibility to obtain the authentication method priority ranking.
[0030] In one implementation, the system first extracts an initial set of authentication method candidates from a preset "scenario-authentication method" mapping table based on the scenario type identifier obtained in S12. For example, if the scenario is "Indoor Stationary," the candidate set may include password, fingerprint, and behavioral authentication. Next, the system obtains real-time device performance parameters (such as CPU usage) from the device operating system API and, combined with network status data obtained in S11, dynamically adjusts the weights of each authentication method in the candidate set. For example, when the CPU usage is below 80%, the weight of fingerprint recognition is increased by 0.1. Then, based on the historical authentication data obtained in S11, the system calculates the authentication failure rate of each authentication method in the candidate set over the past 30 days. The system sets a preset failure rate threshold of 8%, determined by statistically analyzing the authentication behaviors of a large number of users and selecting a failure rate acceptable to 80% of users. Any authentication method with a failure rate above this threshold is temporarily removed from the candidate set.
[0031] Finally, for the remaining authentication methods, the system obtains their estimated real-time authentication response time and device compatibility. The real-time authentication response time is estimated by querying historical authentication data for the average response time of the device model under the network conditions. Device compatibility is determined by querying the API provided by the device's operating system to confirm whether it supports the advanced security features required by the authentication method. The system uses a comprehensive scoring formula to finally rank the authentication methods. Before substituting the formula, to resolve the dimensionality matching issue, the system first normalizes the real-time authentication response time into a dimensionless time penalty score between 0 and 1, defined as: time penalty score = min(1, real-time authentication response time / maximum acceptable response time). For example, if the maximum acceptable response time is 2000 milliseconds, a response time of 500 milliseconds corresponds to a time penalty score of 0.25. The system uses a comprehensive scoring formula to finally rank the authentication methods. To ensure that the scores are always positive and higher scores are preferred, the formula is reconstructed as follows: Comprehensive score = w1 × adjusted weight + w2 × (1-authentication failure rate) + w3 × (1-time penalty score). These coefficients are set based on the security level of the current scenario. For example, in a high-security scenario, to prioritize reliability, w1=0.5, w2=0.4, and w3=0.1 can be set. In a scenario that focuses on convenience, to prioritize response speed, w1=0.3, w2=0.2, and w3=0.5 can be set. The system sorts the comprehensive scores from high to low to obtain the final authentication method priority ranking.
[0032] It should be noted that the "scenario-authentication method" mapping table is pre-configured based on a quantitative evaluation of the security levels of different scenarios and the reliability of authentication methods, and defines a set of basic authentication methods applicable to scenarios with different security levels.
[0033] In step S14, user interaction data and biometric data corresponding to the authentication method priority ranking are obtained, and the data missing rate and time consistency are calculated to obtain a data integrity score, including: According to the priority sorting of the authentication methods, obtaining user interaction data, performing sequence analysis on the user interaction data, and obtaining a user behavior sequence; collecting biometric data from a high-resolution sensor, performing denoising and feature extraction on the biometric data, and obtaining a biometric template; Calculating a data missing rate based on the user behavior sequence and the biometric template; According to the data missing rate, a temporal consistency is calculated, and the data integrity score is generated based on the temporal consistency.
[0034] In one implementation, the system first obtains the required data for the authentication methods ranked highest in S13. For behavioral authentication, the system extracts recent user operation records from device interaction logs and analyzes them using the Apriori sequence mining algorithm to generate user behavior sequences that reflect user operating habits. The algorithm's input is time series data of user operations (e.g., [operation A, operation B, operation C]). Its core parameter is the minimum support threshold, set to 0.5, indicating that an operation sequence must appear in at least 50% of authentication sessions to be considered frequent. This threshold balances the prevalence and specificity of the pattern, ensuring that the extracted behavior sequences are representative of mainstream habits without being overly generalized. The algorithm iteratively searches for frequent itemsets and ultimately outputs the longest operation sequence that meets the support threshold, which serves as the user's behavior template. For fingerprint authentication, the system collects data from a high-resolution fingerprint sensor and performs denoising and feature extraction. The extraction rule locates and records the bifurcation points and endpoints of ridges in the fingerprint image as key features, generating a biometric template that contains these key fingerprint features.
[0035] The system then evaluates the acquired data to generate a data integrity score. This process involves two steps: First, the system calculates the missing data rate. For example, if a biometric template should contain 50 feature points but only 45 are extracted, the missing data rate is 10%. Second, the system calculates the temporal consistency of the behavioral data. This calculation method involves analyzing the timestamps in historical authentication data to establish a user's usual authentication time window (for example, 8:00 AM to 9:00 AM). When a new authentication occurs, the system determines whether the current timestamp falls within this window and assigns a consistency score between 0 and 1 based on the probability or confidence level of the timestamp. Finally, the system combines these two metrics using a weighted formula to generate a comprehensive data integrity score. For example, data integrity score = (1 - missing data rate) × 0.5 + (temporal consistency) × 0.5. For example, if 90% of a user's logins occur between 8:00 AM and 9:00 AM, the temporal consistency is 90%. When calculating temporal consistency, the reliability of the missing data rate calculated in the previous step is adjusted. For example, a high missing data rate may reduce the weight of the temporal consistency calculation. It should be noted that data integrity assessment is a key step in ensuring the reliability of subsequent certification decisions, avoiding possible failed certification processes when data quality is insufficient, thereby improving user experience.
[0036] In step S15, if the data integrity score is higher than the preset integrity score threshold, the authentication method priority ranking is optimized to generate an optimized authentication method combination, including: If the data integrity score is higher than a preset integrity score threshold, extracting multi-dimensional features to obtain a first feature set; Extracting an authentication method weight from the first feature set, and generating an authentication method score based on the authentication method weight to obtain an authentication method priority; fusing the first feature set and the authentication method priority to obtain a fused feature; According to the fusion characteristics, the priority order of the authentication methods is optimized to generate an optimized authentication method combination.
[0037] First, the system compares the data integrity score obtained in S14 with a preset integrity score threshold. This threshold can be set to 0.85, determined by statistically analyzing the data quality of historical successful authentication cases and selecting the minimum score that covers 85% of successful cases. Only when the score is higher than this threshold does the system consider the current data quality sufficient to support reliable authentication and proceed to the subsequent steps. If the judgment is passed, the system will immediately extract a multi-dimensional first feature set from the user interaction data and biometric data. This set may include indicators such as the frequency of user operations, average time interval, and texture clarity of biometric features (such as fingerprints).
[0038] Then, the system performs scoring and feature fusion based on the first feature set. The system extracts key features that affect the reliability of different authentication methods from the first feature set as their authentication method weights. For example, a high-definition fingerprint feature will give fingerprint authentication a higher weight. Next, the system uses a preset logistic regression model to generate an authentication method score for each candidate authentication method. The scoring process is as follows: the model first multiplies the feature values in the first feature set with their corresponding weight coefficients and sums them, and then maps the sum value to the interval of 0 to 1 through a Sigmoid function. The output value is the score of the authentication method. Subsequently, the system performs feature fusion. The specific integration process is: the authentication method score just generated is appended to the end of the first feature set as a new dimension, thereby forming a more comprehensive fusion feature vector.
[0039] Finally, the system uses the fusion features to perform a final optimization on the authentication method priority ranking obtained in S13 through a preset decision table, and generates an optimized authentication method combination. The rule structure of the decision table includes two parts: "condition" and "action", and is sorted by priority, with the fusion feature vector as input and the optimal authentication combination as output. For example, a rule of the decision table can be defined as: if the fusion feature score of fingerprint authentication is greater than 0.9 and the fusion feature score of behavioral authentication is greater than 0.7, the output combination is "fingerprint authentication + behavioral authentication"; if only the score of fingerprint authentication is greater than 0.9, the output combination is "fingerprint authentication". If the conditions of all high-priority rules are not met, a default rule will be matched: the output combination is "password authentication" to ensure that when the data quality or score is not ideal, it will fall back to the most basic and reliable authentication method.
[0040] In step S16, identity verification is performed according to the optimized authentication method combination to obtain a preliminary authentication result, including: Obtaining a verification model that matches the optimized authentication method combination and authentication data input by the user; Sorting the authentication method combinations in execution order according to the network status data and the scenario type identifier to obtain an authentication link order; According to the order of the authentication steps, the authentication data input by the user is verified to obtain a preliminary authentication result.
[0041] In one implementation, the system first loads a verification model matching each authentication method in the optimized authentication method combination generated in S15. The verification model is a pre-trained or established algorithmic entity used to compare user input data with pre-stored templates. It should be noted that the pre-stored templates here are generated through a separate registration or entry process when the user first uses the authentication function. For example, when a user registers their fingerprint, the system will guide them to collect fingerprints multiple times. These high-quality collections are then refined and integrated into a standard feature template, which is stored in a secure database and serves as the benchmark for all subsequent identity verifications. For example, if the optimized authentication method combination includes "fingerprint authentication," the loaded matching verification model is a classifier based on a support vector machine (SVM). Its core parameters are the kernel function type (e.g., radial basis function (RBF)) and the penalty coefficient C (e.g., set to 1.0). This model is trained to distinguish between the user's pre-stored fingerprint feature templates and real-time fingerprint features. The system then intelligently schedules the execution order of each authentication step in the combination based on the network status data obtained in S11 and the scenario type identifier determined in S12. For example, if network status data indicates high latency, local authentication methods requiring minimal network interaction (such as fingerprint authentication) will be prioritized over those requiring a network connection (such as dynamic passwords). Finally, the system prompts the user to enter authentication data in the prioritized order and compares the user's input with the loaded verification model to generate a preliminary authentication result.
[0042] It should be noted that the mechanism of intelligently scheduling execution order is designed to dynamically optimize resource consumption and time delays during the authentication process, especially in cases of unstable network or limited device performance, which can significantly improve the smoothness of the authentication process.
[0043] In step S17, if the preliminary authentication result is authentication failure, the optimized authentication method combination is adjusted to obtain an updated authentication method combination, including: Obtaining feedback data indicating that the preliminary authentication result is authentication failure; Extracting log data from the feedback data and performing data analysis to obtain specific failure causes; According to the specific failure reason, combined with the historical authentication data, the parameters are adjusted to obtain dynamic adjustment parameters; An updated authentication method combination is generated from a pre-established authentication method library according to the dynamic adjustment parameters.
[0044] In one implementation, the system first analyzes the log data recorded when authentication failed, including timestamps and user behavior, to determine the specific cause of the failure. This analysis is implemented using a simple rules engine. For example, a rule might be set as follows: If the log shows that the authentication response time exceeds 5 seconds and the network latency exceeds 200 milliseconds, the failure cause is determined to be "network timeout." The 5-second threshold is based on the maximum tolerable latency determined by user experience research, and the 200-millisecond threshold is based on industry standards for high-latency network conditions. Another rule might be set as follows: If the log shows three consecutive incorrect password entries within 30 seconds, the failure cause is determined to be "incorrect password." The system then adjusts parameters based on the determined failure cause and historical authentication data obtained in S11 to obtain dynamically adjusted parameters. For example, if the failure cause is "network timeout" and historical data shows that the user has a high fingerprint authentication success rate in this network environment, the dynamic parameter adjustment will appropriately relax the fingerprint authentication error tolerance threshold. For example, the required similarity score of the fingerprint comparison model might be reduced by 5% from 0.95 to 0.90 to increase the pass rate in situations where network data transmission may be incomplete. Finally, based on the dynamically adjusted parameters, the system selects a new authentication method from the authentication method library that is unrelated to the failure cause, or adjusts the parameters of the original authentication method (for example, extending the sliding verification timeout from 5 seconds to 8 seconds), thereby generating an updated authentication method combination. The "relevance determination rule" here is implemented based on metadata in the authentication method library. For example, if the failure cause is "network timeout," the system will query the library for authentication methods with a "low" "network sensitivity" field (such as local fingerprint) as unrelated options.
[0045] It should be noted that this step relies on an authentication method library established during system initialization. This library is a structured database configured by the system administrator based on available technical modules. Its data structure contains the following fields: [Authentication method name, Security level, Network sensitivity, Resource consumption]. The configuration rules are as follows: For example, "Security level" is assigned based on the authentication method's attack resistance, such as "High" for dynamic passwords, "Medium" for local fingerprints, and "Low" for simple passwords; "Network sensitivity" is assigned based on whether the verification process requires an internet connection, such as "High" for dynamic passwords and "Low" for local fingerprints; and "Resource consumption" is assigned based on the computing resources consumed during operation.
[0046] In step S18, secondary identity verification is performed according to the updated authentication method combination to obtain a final authentication result, including: Calculate the similarity between the user behavior sequence and the preset behavior template to obtain a behavior verification score; Calculating the characteristic distance between the biometric data and a preset biometric template to obtain a biometric matching result; The behavior verification score and the biometric matching result are weighted and fused to obtain a comprehensive authentication score. If the comprehensive authentication score is greater than the preset authentication score threshold, the authentication is passed; otherwise, the authentication fails, and a final authentication result is obtained.
[0047] In one implementation, the system initiates a secondary verification process defined by the updated authentication method combination. For example, this combination might be "behavioral authentication + fingerprint authentication." The system first uses the K-means clustering algorithm to compare the user's real-time behavior sequence with pre-stored user behavior templates to calculate a behavior verification score. The pre-stored user behavior templates here are not single, fixed data points, but rather the centers of multiple clusters formed by iteratively calculating the user's historical behavior data using the K-means clustering algorithm. Each center is a feature vector representing a typical user operation pattern (features include sliding speed, duration, and pressure). The algorithm inputs a set of feature vectors extracted from the user's historical behavior data (features include sliding speed, duration, and pressure). The core parameter K is set to 3, indicating that the system assumes that the user has three typical operation patterns. The algorithm's implementation process involves: first, randomly initializing three cluster centers. Then, assigning each historical behavior data point to the nearest cluster center. Finally, recalculating each cluster center as the new cluster center, and repeating steps 2 and 3 until the cluster center remains unchanged. The algorithm iteratively divides a user's historical behavioral data into three clusters, with the center of each cluster representing a behavioral template. When new behavioral data is input, the system calculates its distance from the centers of the three templates and uses an inverse function, for example, similarity = 1 / (1 + minimum distance). The similarity corresponding to the minimum distance is used as the behavioral verification score. Simultaneously, the system collects the user's fingerprint data and calculates the Euclidean distance between the feature points of the newly collected fingerprint and those of the pre-stored template to obtain a biometric match result. The preset Euclidean distance threshold is 0.05, which was set by matching 1,000 paired fingerprint samples and selecting the maximum distance that achieved a 99.5% accuracy rate. If the calculated distance is less than this threshold, the match is considered successful. Finally, the system performs a weighted fusion of the behavioral verification score and the biometric match result. It should be noted that for ease of calculation, the biometric match result is quantized: a successful match is assigned a value of 100; a failed match is assigned a value of 0. The calculation formula is: Comprehensive score = (Behavioral Verification Score × 0.4) + (Biometric Match Result × 0.6). The final authentication pass threshold is set at 80 points. This threshold is a balance between security and convenience, determined through Receiver Operating Characteristic (ROC) curve analysis, and is a compromise value that keeps the False Acceptance Rate (FAR) within a preset security level (e.g., 1 in a million). If the comprehensive score is greater than 80, the final authentication result is passed; otherwise, it is failed.
[0048] It should be noted that the weight coefficients of weighted fusion (0.4 and 0.6) can be dynamically adjusted according to different security levels. For example, in high-risk scenarios, the weight of the biometric matching result can be increased to 0.7 to enhance the reliability of authentication.
[0049] In summary, the present invention realizes intelligent and flexible identity authentication in complex and changing environments by dynamically sensing the user's situation, adaptively deciding and optimizing the combination of authentication methods, and establishing a closed-loop feedback adjustment mechanism after authentication failure, thereby significantly improving the success rate of the authentication process and effectively balancing security and user experience.
[0050] Reference Figure 2 The second embodiment of the present invention provides a network security identity authentication system based on cryptographic technology, including: Data acquisition module, used to obtain device sensor data and network status data; A scene classification module, configured to classify scenes using a preset scene classification model based on the device sensor data and the network status data to obtain a scene type identifier; a priority sorting module, configured to extract a candidate set of authentication methods from the scenario type identifier, and then screen and sort the candidate set of authentication methods to obtain a priority sorting of authentication methods; an integrity scoring module for obtaining user interaction data and biometric data corresponding to the authentication method priority ranking, calculating the data missing rate and time consistency, and obtaining a data integrity score; a combination optimization module, configured to optimize the priority ranking of the authentication methods and generate an optimized authentication method combination if the data integrity score is higher than a preset integrity score threshold; A first verification module is used to perform identity verification according to the optimized authentication method combination and obtain a preliminary authentication result; a combination adjustment module, configured to adjust the optimized authentication method combination to obtain an updated authentication method combination if the preliminary authentication result is authentication failure; The second verification module is used to perform secondary identity authentication according to the updated authentication method combination to obtain a final authentication result.
[0051] It should be noted that the network security identity authentication device based on cryptographic technology provided in an embodiment of the present invention is used to execute all the process steps of the network security identity authentication method based on cryptographic technology in the above embodiment. The working principles and beneficial effects of the two correspond one to one, so they will not be repeated here.
[0052] An embodiment of the present invention further provides an electronic device. The electronic device includes: a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a network security authentication program based on cryptographic technology. When the processor executes the computer program, the steps in the above-mentioned embodiments of the network security authentication method based on cryptographic technology are implemented, such as Figure 1 Alternatively, when the processor executes the computer program, the functions of the modules / units in the above-mentioned device embodiments are realized, such as the data acquisition module.
[0053] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to implement the present invention. The one or more modules / units may be a series of computer program instruction segments capable of implementing specific functions, and the instruction segments are used to describe the execution process of the computer program in the electronic device.
[0054] The electronic device may be a computing device such as a desktop computer, notebook, PDA, or smart tablet. The electronic device may include, but is not limited to, a processor and memory. Those skilled in the art will appreciate that the aforementioned components are merely examples of electronic devices and do not constitute a limitation of the electronic device. The electronic device may include more or fewer components than those described above, or a combination of certain components, or different components. For example, the electronic device may also include input / output devices, network access devices, buses, and the like.
[0055] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the electronic device, connecting various parts of the entire electronic device using various interfaces and lines.
[0056] The memory can be used to store the computer programs and / or modules. The processor implements the various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory and accessing the data stored in the memory. The memory may primarily include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as a sound playback function or an image playback function); the data storage area may store data generated based on the use of the mobile phone (such as audio data, a phone book, etc.). Furthermore, the memory may include high-speed random access memory and non-volatile memory, such as a hard disk, internal memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.
[0057] If the module / unit integrated into the electronic device is implemented as a software functional unit and sold or used as a standalone product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention can implement all or part of the process steps in the above-mentioned method embodiments by using a computer program to instruct the relevant hardware. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signals, telecommunication signals, and software distribution media. It should be noted that the content of the computer-readable medium can be appropriately increased or decreased based on the requirements of legislation and patent practice within a jurisdiction. For example, in some jurisdictions, based on legislation and patent practice, computer-readable media does not include electric carrier signals and telecommunication signals.
[0058] It should be noted that the device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. In addition, in the drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that there is a communication connection between them, which may be specifically implemented as one or more communication buses or signal lines. A person of ordinary skill in the art can understand and implement the present invention without inventive effort.
[0059] The specific embodiments described above further illustrate the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.
Claims
1. A network security identity authentication method based on cryptographic technology, characterized in that: include: Obtain device sensor data and network status data; Based on the device sensor data and the network status data, a preset scene classification model is used to perform scene classification to obtain a scene type identifier; Extracting an authentication method candidate set from the scenario type identifier, and then screening and sorting the authentication method candidate set to obtain an authentication method priority ranking; Obtaining user interaction data and biometric data corresponding to the priority ranking of the authentication methods, calculating the data missing rate and time consistency, and obtaining a data integrity score; If the data integrity score is higher than a preset integrity score threshold, optimizing the authentication method priority order to generate an optimized authentication method combination; Perform identity authentication according to the optimized authentication method combination to obtain a preliminary authentication result; If the preliminary authentication result is authentication failure, adjusting the optimized authentication method combination to obtain an updated authentication method combination; A secondary identity verification is performed based on the updated authentication method combination to obtain a final authentication result.
2. A network security identity authentication method based on cryptographic technology according to claim 1, characterized in that: The performing scene classification based on the device sensor data and the network status data using a preset scene classification model to obtain a scene type identifier includes: Removing outliers and noise from the device sensor data and the network status data to obtain a clean data set; Extracting a feature vector from the clean data set, and if the feature vector is less than a preset threshold judgment condition, classifying the scene using a preset scene classification model to obtain a preliminary scene type identification; New device sensor data and the network status data are acquired, and the preliminary scene type identifier is dynamically adjusted according to the new device sensor data and the network status data to obtain a scene type identifier.
3. A network security identity authentication method based on cryptographic technology according to claim 1, characterized in that: The step of extracting a candidate set of authentication methods from the scenario type identifier, screening and sorting the candidate set of authentication methods, and obtaining a priority sorting of the authentication methods includes: Extracting an authentication method candidate set and an authentication method initial weight from the scenario type identifier; Adjusting the initial weight of the authentication method according to the device performance parameters and the network status data to obtain an adjusted authentication method weight; Obtaining historical authentication data of each authentication method in the authentication method candidate set, calculating its authentication failure rate, and eliminating authentication methods with authentication failure rates higher than a preset failure rate threshold from the authentication method candidate set to obtain a preliminary priority ranking; The preliminary priority ranking is obtained and adjusted according to the real-time authentication response time and device compatibility to obtain the authentication method priority ranking.
4. A network security identity authentication method based on cryptographic technology according to claim 1, characterized in that: The acquiring of user interaction data and biometric data corresponding to the authentication method priority ranking, and calculating the data missing rate and time consistency to obtain a data integrity score includes: According to the priority sorting of the authentication methods, obtaining user interaction data, performing sequence analysis on the user interaction data, and obtaining a user behavior sequence; collecting biometric data from a high-resolution sensor, performing denoising and feature extraction on the biometric data, and obtaining a biometric template; Calculating a data missing rate based on the user behavior sequence and the biometric template; According to the data missing rate, a temporal consistency is calculated, and the data integrity score is generated based on the temporal consistency.
5. The network security identity authentication method based on cryptographic technology according to claim 1, characterized in that: If the data integrity score is higher than a preset integrity score threshold, the authentication method priority ranking is optimized to generate an optimized authentication method combination, including: If the data integrity score is higher than a preset integrity score threshold, extracting multi-dimensional features to obtain a first feature set; Extracting an authentication method weight from the first feature set, and generating an authentication method score based on the authentication method weight to obtain an authentication method priority; fusing the first feature set and the authentication method priority to obtain a fused feature; According to the fusion characteristics, the priority order of the authentication methods is optimized to generate an optimized authentication method combination.
6. A network security identity authentication method based on cryptographic technology according to claim 1, characterized in that: The step of performing identity authentication according to the optimized authentication method combination to obtain a preliminary authentication result includes: Obtaining a verification model that matches the optimized authentication method combination and authentication data input by the user; Sorting the authentication method combinations in execution order according to the network status data and the scenario type identifier to obtain an authentication link order; According to the order of the authentication steps, the authentication data input by the user is verified to obtain a preliminary authentication result.
7. A network security identity authentication method based on cryptographic technology according to claim 3, characterized in that: If the preliminary authentication result is authentication failure, adjusting the optimized authentication mode combination to obtain an updated authentication mode combination includes: Obtaining feedback data indicating that the preliminary authentication result is authentication failure; Extracting log data from the feedback data and performing data analysis to obtain specific failure causes; According to the specific failure reason, combined with the historical authentication data, the parameters are adjusted to obtain dynamic adjustment parameters; An updated authentication method combination is generated from a pre-established authentication method library according to the dynamic adjustment parameters.
8. A network security identity authentication method based on cryptographic technology according to claim 4, characterized in that: The performing of secondary identity authentication according to the updated authentication method combination to obtain a final authentication result includes: Calculate the similarity between the user behavior sequence and the preset behavior template to obtain a behavior verification score; Calculating the characteristic distance between the biometric data and a preset biometric template to obtain a biometric matching result; The behavior verification score and the biometric matching result are weighted and fused to obtain a comprehensive authentication score. If the comprehensive authentication score is greater than the preset authentication score threshold, the authentication is passed; otherwise, the authentication fails, and a final authentication result is obtained.
9. A network security identity authentication system based on cryptographic technology, characterized in that: include: Data acquisition module, used to obtain device sensor data and network status data; A scene classification module, configured to classify scenes using a preset scene classification model based on the device sensor data and the network status data to obtain a scene type identifier; a priority sorting module, configured to extract a candidate set of authentication methods from the scenario type identifier, and then screen and sort the candidate set of authentication methods to obtain a priority sorting of authentication methods; an integrity scoring module for obtaining user interaction data and biometric data corresponding to the authentication method priority ranking, calculating the data missing rate and time consistency, and obtaining a data integrity score; a combination optimization module, configured to optimize the priority ranking of the authentication methods and generate an optimized authentication method combination if the data integrity score is higher than a preset integrity score threshold; A first verification module is used to perform identity verification according to the optimized authentication method combination and obtain a preliminary authentication result; a combination adjustment module, configured to adjust the optimized authentication method combination to obtain an updated authentication method combination if the preliminary authentication result is authentication failure; The second verification module is used to perform secondary identity authentication according to the updated authentication method combination to obtain a final authentication result.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute a network security identity authentication method based on cryptographic technology as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Identity verification method and equipment
CN107172084A
Multi-factor dynamic identity verification and access control system
CN119272259A
Data security protection verification method and system for environment field monitoring equipment
CN119323035A
Industrial Internet of Things security authentication method and system based on zero-knowledge proof
CN119743270A
Identity non-inductive verification method and device in weak network environment, medium and equipment
CN120087964A
Cited By
Multi-cluster message bus intelligent management method and system based on unified control plane
CN121397094A