Intelligent management system and method applied to interactive authentication platform

Through multi-factor dynamic authentication and behavior pattern analysis, combined with dynamic and static behavior characteristics, a behavior pattern model is constructed to solve the security and efficiency issues of traditional authentication methods, achieve accurate verification and risk assessment of client callers, and ensure the security of interactive information.

CN120750618AActive Publication Date: 2025-10-03BEIJING JIUYI SCI & TECH CO LTD

Patent Information

Application Number
CN202511064047.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-10-03
Estimated Expiration
2045-07-31

AI Technical Summary

Technical Problem

Traditional authentication methods have low security, cannot effectively monitor the behavior of callers, have difficulty dealing with complex and varied attack methods, and cannot balance interaction security and efficiency.

Method used

It adopts multi-factor dynamic authentication module, behavior pattern analysis module and risk assessment and decision-making module, combines dynamic behavior characteristics and static behavior characteristics to build a behavior pattern model, dynamically generates authentication strategies, and performs multiple protections and risk assessments.

Benefits of technology

It achieves accurate verification of the identity of the client caller, timely detects potential malicious attacks, ensures the security of interactive information, and balances work efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750618A_ABST
    Figure CN120750618A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent management system and method applied to an interactive authentication platform, and relates to the technical field of intelligent management of interactive authentication platforms. The intelligent management system comprises a multi-factor dynamic authentication module, a behavior pattern analysis module and a risk assessment and decision module; the multi-factor dynamic authentication module is used for integrating a plurality of authentication factors and verifying the identity of a client calling party; the behavior pattern analysis module is used for collecting and analyzing historical interaction data of a client calling party and constructing a behavior pattern model; and the risk assessment and decision module is used for carrying out quantitative assessment on the risk level of each service interaction. According to the invention, a plurality of groups of authentication factor combinations are obtained based on the authentication strategy, specialized treatment and protection of various service requests are realized, the identity of a client caller is accurately verified in combination with the constructed behavior mode model, and information embezzlement or malicious operation execution can be effectively avoided through a multi-protection mechanism. And accurate protection of the system on the interaction information is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intelligent management of interactive authentication platforms, in particular to an intelligent management system and method applied to interactive authentication platforms. Background Art

[0002] In today's complex and ever-changing network environment, interactions between servers and between servers and clients are becoming increasingly frequent. Traditional authentication methods are no longer able to cope with diverse and complex attack methods.

[0003] Traditional authentication methods based on usernames and passwords have low security. After obtaining the password, attackers can easily impersonate the caller and call the service interface, thereby stealing information or performing malicious operations. At the same time, traditional authentication methods lack effective supervision and analysis of the caller's behavior, making it impossible to promptly detect potential malicious attacks on the client. In addition, the existing authentication system cannot balance the work efficiency and security of service interaction. Summary of the Invention

[0004] The purpose of the present invention is to provide an intelligent management system and method for an interactive authentication platform to solve the problems raised in the prior art.

[0005] To achieve the above object, the present invention provides the following technical solutions: an intelligent management system applied to an interactive authentication platform, the system comprising a client, a service end and an authentication server; The client interacts with the server to initiate a service request to the server, collects authentication information according to the authentication request sent by the server, and submits the collected authentication information to the server; The server exchanges information with the authentication server. The server is used to send an authentication request to the client according to the authentication policy fed back by the authentication server, and forward the service request initiated by the client and the authentication information submitted to the authentication server, and decide whether to allow the service request to continue to be executed based on the authentication result of the authentication server; The authentication server is used to generate an authentication policy based on the client information and feed it back to the server, perform authentication processing on the authentication information forwarded by the server, and feed back the authentication processing result to the server.

[0006] Furthermore, the authentication server has built-in multi-factor dynamic authentication module, behavior pattern analysis module and risk assessment and decision module; The multi-factor dynamic authentication module is used to integrate several authentication factors to verify the identity of the client caller and dynamically adjust the authentication strategy through multiple factors to ensure that the system can adapt to different application scenarios and security requirements; The behavior pattern analysis module is used to collect and analyze the historical interaction data of the client caller and build a behavior pattern model; The risk assessment and decision module is used to quantitatively assess the risk level of each service interaction and feed back the assessment result as the authentication result to the service end.

[0007] Furthermore, the multi-factor dynamic authentication module includes an authentication policy generation unit, an authentication information analysis unit and a dynamic authentication unit; The authentication policy generation unit determines the target service interface of the server according to the application identifier of the client and the service request initiated, and dynamically generates an authentication policy according to the authority level of the determined target service interface and the type of service request initiated by the client; The authentication information analysis unit matches and analyzes the authentication information collected by the client according to the dynamically generated authentication policy with the reserved information of the client caller on the server and the historical interaction information of the client caller on the server. Based on the matching analysis result, the identity of the client caller is verified. If the identity authentication is successful, the authentication result is to execute the service request; if the identity authentication is unsuccessful, the authentication result is to reject the service request; After the client caller's identity is successfully authenticated, the dynamic authentication unit uses an asymmetric encryption algorithm, combined with the timestamp corresponding to the completion of the client caller's identity authentication, the random number and the unique identification code of the device used by the client caller, to generate a dynamic key, and transmits the generated dynamic key to the client and the server. The client uses the dynamic key to encrypt the initiated service request data, and the server uses the dynamic key to decrypt the service request data after receiving the service request.

[0008] During the key generation process, the dynamic authentication unit combines timestamps, random numbers, and the unique identification code of the device used by the client caller to ensure the uniqueness and unpredictability of the key. The key becomes invalid immediately after each service interaction and is regenerated at the next interaction, ensuring the high security of service request data.

[0009] Furthermore, the behavior pattern analysis module includes a judgment unit, a behavior feature acquisition unit and a behavior pattern model construction unit; The judgment unit performs an integrity check on the decrypted data obtained by the server, and determines whether it is necessary to re-authenticate the service request initiated by the client based on the verification result. When the integrity of the decrypted data obtained by the server is 1, the service request initiated by the client does not need to be re-authenticated. When the integrity of the decrypted data obtained by the server is not 1, the service request initiated by the client is re-authenticated according to the multi-factor authentication module. The behavior feature acquisition unit acquires the behavior features of the client caller during each service request process when the result of the judgment is that re-authentication is not required for the service request initiated by the client; The behavior pattern model building unit builds a behavior pattern model according to the acquired behavior characteristics.

[0010] Furthermore, the specific method for the behavior feature acquisition unit to acquire the behavior features of the client caller during each service request process is: Acquire the key timestamps of the client caller during the service request process. The key timestamps include the time T1 when the client initiates the service request, the start time T2 and the end time T3 when the client collects authentication information; Determine the type of service request initiated by the client at time T1, obtain the request frequency f of the client caller for the service request of the determined type, use the request frequency as the independent variable and the authentication information collection time as the dependent variable, construct a linear relationship model R between the request frequency and the collection time, input the request frequency f into the linear relationship model R, and obtain the collection time R f , the client caller's authentication information collection time deviation R f -(T3-T2) as the first static behavioral characteristic of the client caller; The target service interface called by the client at time T1 is determined. Each type of target service interface is numbered in descending order according to the number of times the client has called each type of target service interface. The numbering result is: i = 1, 2, ..., n, where n represents the total number of target service interfaces. The difference s between the numbers of the historical target service interfaces called by the client when initiating a service request of a certain type and the number of the determined target service interface is calculated. The difference g between the value 1 and 1 / |s| is used as the second static behavior feature of the client. When executing a service request of a certain type on the server side, the interaction information of the client caller is obtained, including the interaction object, interaction level and interaction type; Based on the client caller's historical interaction information, the interaction level and interaction type of each interaction object are determined, and the same interaction level or the same interaction type are assigned the same weight value. Each interaction object is numbered, and the numbering result is: j = 1, 2, ..., m, where m represents the total number of interaction objects; According to the interaction information of the client caller obtained, determine the weight value d1p corresponding to the interaction level of the interaction object p and the weight value d2p corresponding to the interaction type, where p=1, 2, ..., m; According to the historical interaction information, obtain the average weight value d1´p corresponding to the interaction level of the interaction object p and the average weight value d2´p corresponding to the interaction type; The d1p-d1´p is used as the first dynamic behavior characteristic of the client caller, and the d2p-d2´p is used as the second dynamic behavior characteristic of the client caller.

[0011] By acquiring the dynamic and static behavioral characteristics of the client caller and building a behavioral pattern model based on the acquired behavioral characteristics, it is convenient to accurately verify the identity of the client caller, further improving the management effect of the system.

[0012] Furthermore, the specific method for the behavior pattern model construction unit to construct the behavior pattern model according to the acquired behavior characteristics is: H = a1 × g + a2 × ln [1 + | R f -(T3-T2)|] is used as the first behavior pattern model of the client caller, where a1 and a2 represent proportional coefficients and a1+a2=1, and H represents the first behavior characteristic value of the client caller; K = a3 × (d1p - d1´p) + a4 × (d2p - d2´p) is used as the second behavior pattern model of the client caller, where a3 and a4 represent proportional coefficients and a3 + a4 = 1, and K represents the second behavior feature value of the client caller; When K>Y or H>X, it indicates that the interaction information of the client caller is abnormal behavior information. When 0≤K≤Y and 0≤H≤X, it indicates that the interaction information of the client caller is normal behavior information.

[0013] Furthermore, the risk assessment and decision module includes a risk assessment unit and an authentication decision unit; When the risk assessment unit determines that the interaction information of the client caller is abnormal behavior information, the risk assessment unit performs a risk assessment on the interaction behavior of the client caller according to the first behavior feature value and the second behavior feature value; The authentication decision unit selects whether to add authentication factors based on the risk assessment results, and when additional authentication factors are required, sends an additional authentication request to the client through the server. The client collects additional authentication information based on the additional authentication request, and forwards the additional authentication information to the authentication server for verification through the server, until the risk assessment result is that additional authentication factors are not required, or the server rejects the service request again.

[0014] Furthermore, the specific method of the risk assessment unit to perform risk assessment on the interactive behavior of the client caller is: When K>Y and 0≤H≤X or H>X and 0≤K≤Y: Quantify the risk assessment value W of the client caller according to 1-exp (-K) or 1-exp (-H); When K>Y and H>X: Quantify the risk assessment value W of the client caller according to 1-exp(-K×H); If 0≤W≤0.3, it means the risk assessment level of the client caller is level one; If 0.3<W≤0.6, it means the risk assessment level of the client caller is level 2; If 0.6<W≤1, it means the risk assessment level of the client caller is level three; Wherein, exp() represents an exponential function with base e and e=2.73.

[0015] Furthermore, the additional authentication factors include static authentication factors and dynamic authentication factors. The static authentication factors include face recognition verification and target service interface re-verification, and the dynamic authentication factors include interactive information re-verification.

[0016] An intelligent management method applied to an interactive authentication platform, the method comprising: S10: Integrate several authentication factors to verify the identity of the client caller; S20: Collect and analyze historical interaction data of client callers to build a behavior pattern model; S30: Quantitatively assess the risk level of each service interaction and feed the assessment result back to the server as the authentication result; S40: The server chooses whether to execute the service request initiated by the client based on the feedback result.

[0017] Compared with the prior art, the present invention has the following beneficial effects: 1. The present invention dynamically generates an authentication strategy according to the permission level of the target service interface and the type of service request initiated by the client, obtains several groups of authentication factor combinations based on the authentication strategy, and implements specialized protection for various types of service requests. It constructs a behavior pattern model by combining the dynamic behavior characteristics and static behavior characteristics obtained through interactive information, and accurately verifies the identity of the client caller. Through multiple protection mechanisms, it can effectively avoid information theft or the execution of malicious operations, and realize the system's accurate protection of interactive information.

[0018] 2. The present invention effectively monitors the interactive behavior of the client caller by acquiring dynamic behavior characteristics and static behavior characteristics, which is conducive to timely discovery of potential malicious attacks suffered by the client.

[0019] 3. The behavioral pattern model obtained through continuous optimization in the present invention can not only ensure that normal service requests initiated by the client can be quickly authenticated, but also reduce the interference of verification steps corresponding to additional authentication factors on the service request process, thereby achieving a balance between work efficiency and security. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 The figure is a schematic diagram showing the working principle of an intelligent management system applied to an interactive authentication platform of the present invention. DETAILED DESCRIPTION

[0021] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0022] Example: Figure 1 As shown, the present invention provides an intelligent management system and method technical solution applied to an interactive authentication platform, an intelligent management system applied to an interactive authentication platform, the system includes a client, a service end and an authentication server; The client and the server exchange information. The client is used to initiate service requests to the server, collect authentication information according to the authentication requirements sent by the server, and submit the collected authentication information to the server. The client includes but is not limited to mobile application clients, desktop application clients, IoT device clients, etc. The authentication information collection process is performed after the client caller authorizes it. The server exchanges information with the authentication server. The server sends an authentication request to the client based on the authentication policy fed back by the authentication server. The server also forwards the service request initiated by the client and the authentication information submitted to the authentication server. The server then decides whether to allow the service request to proceed based on the authentication result of the authentication server. The server includes but is not limited to web servers, mobile application backend servers, and service nodes in the microservice architecture. The authentication server is used to generate an authentication policy based on the client information and feed it back to the server, and to authenticate the authentication information forwarded by the server and feed the authentication results back to the server; The authentication server has built-in multi-factor dynamic authentication module, behavior pattern analysis module and risk assessment and decision-making module; The multi-factor dynamic authentication module is used to integrate several authentication factors to verify the identity of the client caller; The multi-factor dynamic authentication module includes an authentication strategy generation unit, an authentication information analysis unit and a dynamic authentication unit; The authentication policy generation unit determines the target service interface of the server based on the client's application identifier and the service request it initiates. It then dynamically generates an authentication policy based on the target service interface's permission level and the type of service request initiated by the client. Service request types include transfer transactions, content publishing, etc. For example, when a user completes a funds transfer operation by calling the transfer transaction interface of the bank's backend system (server) through the mobile banking client: When a user initiates a transfer transaction request on the mobile banking client, the bank's backend system sends the client's application ID to the authentication server. The application ID includes the bank's app version number and the user's device model. The authentication server generates an authentication policy based on the high-level permission level of the transfer transaction interface (target service interface). The authentication policy requires the caller of the mobile banking client to provide a username and password, fingerprint, and device location. When a user uploads multimedia content such as articles, images, and videos through a custom publishing client and calls the publishing interface of the platform content management server: When a user initiates a content request using a publishing client, the platform content management server sends the client's application ID to the authentication server. The application ID includes the client software version, the user's device model, the device operating system version, etc. The authentication server generates an authentication policy based on the medium-level permissions of the platform content publishing interface (target service interface). The authentication policy requires the caller of the publishing client to provide a username and password, a device fingerprint (the device fingerprint refers to the device hardware serial number), and the subject classification of the published content. Medium-level permissions involve the management of user-generated content. The authentication information analysis unit matches and analyzes the authentication information collected by the client according to the dynamically generated authentication policy with the client caller's reserved information on the server and the client caller's historical interaction information on the server. Based on the matching analysis results, the client caller's identity is verified. If the identity verification is successful, the authentication result is to execute the service request. If the identity verification is unsuccessful, the authentication result is to deny the service request. The historical interaction information includes the client caller's frequently used transaction area range and the hardware serial number of the device previously used by the client caller. For example, when a user completes a funds transfer operation by calling the transfer transaction interface of the bank's backend system (server) through the mobile banking client: The user enters their username and password as prompted on the mobile banking client and performs fingerprint recognition. The client also collects the device's geographic location information (such as coordinate data based on GPS or base station positioning). The client encrypts this authentication information and sends it to the bank's back-end system, which forwards it to the multi-factor dynamic authentication module on the authentication server. The authentication information analysis unit first verifies the correctness of the username and password. If correct, it then calls the biometric recognition service to verify whether the fingerprint information matches the fingerprint information the user has registered with the bank. It also checks whether the device's geographic location information is within the user's frequently used transaction area (based on historical transaction records). If the username and password are correct, the fingerprint matches, and the geographic location is correct, the user's identity verification is successful. Otherwise, the user's identity verification fails. When a user uploads multimedia content such as articles, images, and videos through a custom publishing client and calls the publishing interface of the platform content management server: The user enters their username and password in the publishing client, and allows the publishing client to collect device fingerprint information and select the topic category of the published content. The publishing client packages and encrypts this authentication information and sends it to the platform content management server. The server forwards it to the authentication server. The multi-factor dynamic authentication module verifies whether the username and password are correct. If correct, it then compares the device fingerprint information to see if it matches the fingerprint record of the device previously used by the user (to prevent the device from being stolen and publishing illegal content). At the same time, it checks whether the topic category of the published content falls within the range allowed by the platform. If the username and password are correct, the device fingerprint matches, and the content topic is within the range allowed by the platform, the user's identity verification is successful. Otherwise, the user's identity verification fails. After the client caller's identity is successfully authenticated, the dynamic authentication unit uses an asymmetric encryption algorithm to combine the timestamp corresponding to the completion of the client caller's identity authentication, a random number, and the unique identification code of the device used by the client caller to generate a dynamic key. The method for generating the dynamic key belongs to the existing technology, and the generated dynamic key is transmitted to the client and the server. The client uses the dynamic key to encrypt the service request data initiated. After receiving the service request, the server uses the dynamic key to decrypt the service request data. The behavior pattern analysis module is used to collect and analyze the historical interaction data of the client caller and build a behavior pattern model; The behavior pattern analysis module includes a judgment unit, a behavior feature acquisition unit, and a behavior pattern model construction unit; The judgment unit performs an integrity check on the decrypted data obtained by the server, and determines whether it is necessary to re-authenticate the service request initiated by the client based on the verification result. When the integrity of the decrypted data obtained by the server is 1, the service request initiated by the client does not need to be re-authenticated. When the integrity of the decrypted data obtained by the server is not 1, the service request initiated by the client is re-authenticated based on the multi-factor authentication module. The method of performing integrity check on decrypted data belongs to the existing technology; When the behavior feature acquisition unit determines that re-authentication is not required for the service request initiated by the client, it acquires the behavior features of the client caller during each service request process. The specific method is as follows: Acquire the key timestamps of the client caller during the service request process. The key timestamps include the time T1 when the client initiates the service request, the start time T2 and the end time T3 when the client collects authentication information; Determine the type of service request initiated by the client at time T1, obtain the request frequency f of the client caller for the service request of the determined type, use the request frequency as the independent variable and the authentication information collection time as the dependent variable, construct a linear relationship model R between the request frequency and the collection time, input the request frequency f into the linear relationship model R, and obtain the collection time R f , the client caller's authentication information collection time deviation R f -(T3-T2) is the first static behavior feature of the client caller, and the authentication information collection time = T3-T2; The target service interface called by the client at time T1 is determined. Each type of target service interface is numbered in descending order according to the number of times the client has called each type of target service interface. The numbering result is: i = 1, 2, ..., n, where n represents the total number of target service interfaces. The difference s between the numbers of the historical target service interfaces called by the client when initiating a service request of a certain type and the number of the determined target service interface is calculated. The difference g between the value 1 and 1 / |s| is used as the second static behavior feature of the client. When executing a service request of a certain type on the server side, the interaction information of the client caller is obtained, including the interaction object, interaction level and interaction type; Based on the client caller's historical interaction information, the interaction level and interaction type of each interaction object are determined, and the same interaction level or the same interaction type are assigned the same weight value. Each interaction object is numbered, and the numbering result is: j = 1, 2, ..., m, where m represents the total number of interaction objects; According to the interaction information of the client caller obtained, determine the weight value d1p corresponding to the interaction level of the interaction object p and the weight value d2p corresponding to the interaction type, where p=1, 2, ..., m; According to the historical interaction information, obtain the average weight value d1´p corresponding to the interaction level of the interaction object p and the average weight value d2´p corresponding to the interaction type; Take d1p-d1´p as the first dynamic behavior characteristic of the client caller, and take d2p-d2´p as the second dynamic behavior characteristic of the client caller; The behavior pattern model building unit builds a behavior pattern model based on the acquired behavior features. The specific method is as follows: H = a1 × g + a2 × ln [1 + | R f -(T3-T2)|] is used as the first behavior pattern model of the client caller, where a1 and a2 represent proportional coefficients and a1+a2=1, H represents the first behavior characteristic value of the client caller, and ‌ln[]‌ represents a logarithmic function with the natural constant e as the base and e=2.73; K = a3 × (d1p - d1´p) + a4 × (d2p - d2´p) is used as the second behavior pattern model of the client caller, where a3 and a4 represent proportional coefficients and a3 + a4 = 1, and K represents the second behavior feature value of the client caller; When K>Y or H>X, it indicates that the interaction information of the client caller is abnormal behavior information. When 0≤K≤Y and 0≤H≤X, it indicates that the interaction information of the client caller is normal behavior information. X and Y are both manually set thresholds. The risk assessment and decision module is used to quantitatively assess the risk level of each service interaction and feed the assessment results back to the server as authentication results; The risk assessment and decision module includes a risk assessment unit and an authentication decision unit; When the risk assessment unit determines that the interaction information of the client caller is abnormal behavior information, it performs a risk assessment on the interaction behavior of the client caller based on the first behavior feature value and the second behavior feature value. The specific method is as follows: When K>Y and 0≤H≤X or H>X and 0≤K≤Y: Quantify the risk assessment value W of the client caller according to 1-exp (-K) or 1-exp (-H); When K>Y and H>X: Quantify the risk assessment value W of the client caller according to 1-exp(-K×H); If 0≤W≤0.3, it means the risk assessment level of the client caller is level one; If 0.3<W≤0.6, it means the risk assessment level of the client caller is level 2; If 0.6<W≤1, it means the risk assessment level of the client caller is level three; Wherein, exp() represents an exponential function with e as the base and e=2.73. The larger the risk assessment value, the higher the corresponding risk assessment level. The authentication decision unit chooses whether to add additional authentication factors based on the risk assessment results. If additional authentication factors are required, the server sends an additional authentication request to the client through the server. The client collects additional authentication information based on the additional authentication request and forwards the additional authentication information to the authentication server through the server for verification until the risk assessment result shows that additional authentication factors are not required, or the server rejects the service request again. Additional authentication factors include static authentication factors and dynamic authentication factors. Static authentication factors include face recognition verification and target service interface re-verification, and dynamic authentication factors include interactive information re-verification.

[0023] An intelligent management method applied to an interactive authentication platform, the method comprising: S10: Integrate several authentication factors to verify the identity of the client caller; S20: Collect and analyze historical interaction data of client callers to build a behavior pattern model; S30: Quantitatively assess the risk level of each service interaction and feed the assessment result back to the server as the authentication result; S40: The server chooses whether to execute the service request initiated by the client based on the feedback result.

[0024] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims, not the foregoing description, and all variations within the meaning and range of equivalents of the claims are intended to be included therein. Any reference sign in a claim should not be construed as limiting the claim to which it relates.

Claims

1. An intelligent management system applied to an interactive authentication platform, characterized by: The system includes a client, a service end and an authentication server; The client interacts with the server to initiate a service request to the server, collects authentication information according to the authentication request sent by the server, and submits the collected authentication information to the server; The server exchanges information with the authentication server. The server is used to send an authentication request to the client according to the authentication policy fed back by the authentication server, and forward the service request initiated by the client and the authentication information submitted to the authentication server, and decide whether to allow the service request to continue to be executed based on the authentication result of the authentication server; The authentication server is used to generate an authentication policy based on the client information and feed it back to the server, perform authentication processing on the authentication information forwarded by the server, and feed back the authentication processing result to the server.

2. The intelligent management system for an interactive authentication platform according to claim 1, characterized in that: The authentication server has built-in multi-factor dynamic authentication module, behavior pattern analysis module and risk assessment and decision-making module; The multi-factor dynamic authentication module is used to integrate several authentication factors to verify the identity of the client caller; The behavior pattern analysis module is used to collect and analyze the historical interaction data of the client caller and build a behavior pattern model; The risk assessment and decision module is used to quantitatively assess the risk level of each service interaction and feed back the assessment result as the authentication result to the service end.

3. The intelligent management system for an interactive authentication platform according to claim 2, characterized in that: The multi-factor dynamic authentication module includes an authentication strategy generation unit, an authentication information analysis unit and a dynamic authentication unit; The authentication policy generation unit determines the target service interface of the server according to the application identifier of the client and the service request initiated, and dynamically generates an authentication policy according to the authority level of the determined target service interface and the type of service request initiated by the client; The authentication information analysis unit matches and analyzes the authentication information collected by the client according to the dynamically generated authentication policy with the reserved information of the client caller on the server and the historical interaction information of the client caller on the server. Based on the matching analysis result, the identity of the client caller is verified. If the identity authentication is successful, the authentication result is to execute the service request; if the identity authentication is unsuccessful, the authentication result is to reject the service request; After the client caller's identity is successfully authenticated, the dynamic authentication unit uses an asymmetric encryption algorithm, combined with the timestamp corresponding to the completion of the client caller's identity authentication, the random number and the unique identification code of the device used by the client caller, to generate a dynamic key, and transmits the generated dynamic key to the client and the server. The client uses the dynamic key to encrypt the initiated service request data, and the server uses the dynamic key to decrypt the service request data after receiving the service request.

4. The intelligent management system for an interactive authentication platform according to claim 3, characterized in that: The behavior pattern analysis module includes a judgment unit, a behavior feature acquisition unit and a behavior pattern model construction unit; The judgment unit performs an integrity check on the decrypted data obtained by the server, and determines whether it is necessary to re-authenticate the service request initiated by the client based on the verification result. When the integrity of the decrypted data obtained by the server is 1, the service request initiated by the client does not need to be re-authenticated. When the integrity of the decrypted data obtained by the server is not 1, the service request initiated by the client is re-authenticated according to the multi-factor authentication module. The behavior feature acquisition unit acquires the behavior features of the client caller during each service request process when the result of the judgment is that re-authentication is not required for the service request initiated by the client; The behavior pattern model building unit builds a behavior pattern model according to the acquired behavior characteristics.

5. The intelligent management system for an interactive authentication platform according to claim 4, characterized in that: The specific method for the behavior feature acquisition unit to acquire the behavior features of the client caller during each service request process is: Acquire the key timestamps of the client caller during the service request process. The key timestamps include the time T1 when the client initiates the service request, the start time T2 and the end time T3 when the client collects authentication information; Determine the type of service request initiated by the client at time T1, obtain the request frequency f of the client caller for the service request of the determined type, use the request frequency as the independent variable and the authentication information collection time as the dependent variable, construct a linear relationship model R between the request frequency and the collection time, input the request frequency f into the linear relationship model R, and obtain the collection time R f , the client caller's authentication information collection time deviation R f -(T3-T2) as the first static behavioral characteristic of the client caller; The target service interface called by the client at time T1 is determined. Each type of target service interface is numbered in descending order according to the number of times the client has called each type of target service interface. The numbering result is: i = 1, 2, ..., n, where n represents the total number of target service interfaces. The difference s between the numbers of the historical target service interfaces called by the client when initiating a service request of a certain type and the number of the determined target service interface is calculated. The difference g between the value 1 and 1 / |s| is used as the second static behavior feature of the client. When executing a service request of a certain type on the server side, the interaction information of the client caller is obtained, including the interaction object, interaction level and interaction type; Based on the historical interaction information of the client caller, the interaction level and interaction type of each interaction object are determined, and the same interaction level or the same interaction type are assigned the same weight value. Each interaction object is numbered, and the numbering result is: j = 1, 2, ..., m; m represents the total number of interaction objects; According to the interaction information of the client caller obtained, determine the weight value d1p corresponding to the interaction level of the interaction object p and the weight value d2p corresponding to the interaction type, where p=1, 2, ..., m; According to the historical interaction information, obtain the average weight value d1´p corresponding to the interaction level of the interaction object p and the average weight value d2´p corresponding to the interaction type; The d1p-d1´p is used as the first dynamic behavior characteristic of the client caller, and the d2p-d2´p is used as the second dynamic behavior characteristic of the client caller.

6. The intelligent management system for an interactive authentication platform according to claim 5, characterized in that: The specific method for the behavior pattern model construction unit to construct the behavior pattern model according to the acquired behavior characteristics is: H = a1 × g + a2 × ln [1 + | R f -(T3-T2)|] is used as the first behavior pattern model of the client caller, where a1 and a2 represent proportional coefficients and a1+a2=1, and H represents the first behavior characteristic value of the client caller; K = a3 × (d1p - d1´p) + a4 × (d2p - d2´p) is used as the second behavior pattern model of the client caller, where a3 and a4 represent proportional coefficients and a3 + a4 = 1, and K represents the second behavior feature value of the client caller; When K>Y or H>X, it indicates that the interaction information of the client caller is abnormal behavior information. When 0≤K≤Y and 0≤H≤X, it indicates that the interaction information of the client caller is normal behavior information.

7. The intelligent management system for an interactive authentication platform according to claim 6, characterized in that: The risk assessment and decision-making module includes a risk assessment unit and an authentication decision-making unit; When the risk assessment unit determines that the interaction information of the client caller is abnormal behavior information, the risk assessment unit performs a risk assessment on the interaction behavior of the client caller according to the first behavior feature value and the second behavior feature value; The authentication decision unit selects whether to add authentication factors based on the risk assessment results, and when additional authentication factors are required, sends an additional authentication request to the client through the server. The client collects additional authentication information based on the additional authentication request, and forwards the additional authentication information to the authentication server for verification through the server, until the risk assessment result is that additional authentication factors are not required, or the server rejects the service request again.

8. The intelligent management system for an interactive authentication platform according to claim 7, characterized in that: The specific method of the risk assessment unit performing risk assessment on the interactive behavior of the client caller is: When K>Y and 0≤H≤X or H>X and 0≤K≤Y: Quantify the risk assessment value W of the client caller according to 1-exp (-K) or 1-exp (-H); When K>Y and H>X: Quantify the risk assessment value W of the client caller according to 1-exp(-K×H); If 0≤W≤0.3, it means the risk assessment level of the client caller is level one; If 0.3<W≤0.6, it means the risk assessment level of the client caller is level 2; If 0.6<W≤1, it means the risk assessment level of the client caller is level three; Wherein, exp() represents an exponential function with base e and e=2.

73.

9. The intelligent management system for an interactive authentication platform according to claim 8, characterized in that: The additional authentication factors include static authentication factors and dynamic authentication factors. The static authentication factors include face recognition verification and target service interface re-verification, and the dynamic authentication factors are interactive information re-verification.

10. An intelligent management method for an interactive authentication platform, applied to the intelligent management system for an interactive authentication platform according to any one of claims 1 to 9, characterized in that: The method comprises: S10: Integrate several authentication factors to verify the identity of the client caller; S20: Collect and analyze historical interaction data of client callers to build a behavior pattern model; S30: Quantitatively assess the risk level of each service interaction and feed the assessment result back to the server as the authentication result; S40: The server chooses whether to execute the service request initiated by the client based on the feedback result.

Citation Information

Patent Citations

  • Zero-trust access control method and device and electronic equipment

    CN113783844A

  • Zero-trust API gateway dynamic trust evaluation and access control method and system based on machine learning

    CN114465807A

  • Access control strategy self-adaption method and system based on attribute trust

    CN117371007A

  • Unified authority platform system based on multi-factor authentication, authentication method, equipment and medium

    CN118916895A

  • Data request access control method

    CN119135440A

Cited By

  • Gateway management system and method of intelligent cloud platform, electronic equipment and storage medium

    CN122053414A