User security verification method and device, program product and electronic equipment

By collecting user browser interaction behavior and biometric information and combining it with device identification to conduct real-time risk assessment on the front end, the problems of high delay and low efficiency in user front-end behavior verification in existing technologies are solved, and instant risk assessment and improved data security are achieved.

CN120806613APending Publication Date: 2025-10-17INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510863319.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-25
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

The existing technology of security verification of users' front-end behavior through big data platforms has problems of high latency and low efficiency, especially affecting the timeliness of risk response in the case of high concurrent requests, and data transmission and centralized storage bring the risk of data leakage.

Method used

Collect behavioral time series data and biometric information of users interacting with the browser, determine the verification strategy through target device identification, and combine lightweight machine learning models to conduct real-time risk assessment on the front end to avoid data transmission and centralized storage.

Benefits of technology

It enables instant completion of risk assessment at the front end, improves risk assessment efficiency and response speed, reduces latency, and improves the security and processing efficiency of user behavior data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120806613A_ABST
    Figure CN120806613A_ABST
Patent Text Reader

Abstract

The invention discloses a user safety verification method and device, a program product and electronic equipment, and relates to the field of financial science and tech, the method comprises the steps that first data, second data and third data are collected, the first data are behavior time sequence data when a target user interacts with a front-end interface of financial software through a target browser, and the second data are behavior time sequence data when the target user interacts with the front-end interface of financial software through a target browser; the second data is used for representing biological information when the target user operates the front-end interface, and the third data is used for representing parameter information of the target browser; determining a target device identifier according to the third data; and determining a target verification strategy according to the first data, the second data and the target device identifier, and performing security verification on the target user based on the target verification strategy. According to the method and the device, the technical problems of high delay and low efficiency of performing security verification on the front-end behavior of the user through a big data platform in the prior art are solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of financial technology, in particular to a user security verification method and device, a program product and an electronic device. BACKGROUND

[0002] In the field of digital financial services, with the rapid growth of online transactions, risk control has become an important link to ensure the safety of services and customer funds. The existing risk control system generally adopts a multi-level data collection and analysis mechanism, including but not limited to multi-dimensional tracking of user behavior, rule-based logical judgment, intelligent identification with machine learning, and real-time behavior analysis. The above mechanisms aim to monitor and intercept potential fraudulent behavior in real time.

[0003] However, the traditional risk control system has obvious limitations when facing a large number of concurrent requests. The existing solution relies on the traditional architecture of the backend big data platform, which often affects the timeliness of risk response due to data transmission and processing delays, especially during high-risk operations such as large amount transfers. The speed of security verification directly affects user experience and system security.

[0004] In addition, centralized storage and transmission of data also pose a risk of data leakage, increasing the difficulty of privacy protection. Moreover, deploying heavy machine learning models on the server side not only consumes a large amount of computing resources but also causes response delays, reducing overall system efficiency, thereby causing the technical problems of high delay and low efficiency in the prior art for security verification of user front-end behavior.

[0005] To address the above problems, no effective solutions have been proposed so far. SUMMARY

[0006] The present application provides a user security verification method, device, program product and electronic device to at least solve the technical problems of high delay and low efficiency in the prior art for security verification of user front-end behavior through a big data platform.

[0007] According to an aspect of the present application, a user security verification method is provided, comprising: collecting first data, second data and third data, wherein the first data is behavior time series data of a target user interacting with a front-end interface of financial software through a target browser, the second data is used to represent biological information of the target user when operating the front-end interface, and the third data is used to represent parameter information of the target browser; determining a target device identifier according to the third data, wherein the target device identifier is a unique identifier of a target device, and the target device is a device used by the target user when logging into the target browser; determining a target verification strategy according to the first data, the second data and the target device identifier, and performing security verification on the target user based on the target verification strategy, wherein the target verification strategy is used to determine a verification process for security verification of the target user.

[0008] Optionally, the user security verification method further comprises: collecting, through a preset script, a page click time, a cursor movement track and a page switching path when the target user uses the target browser, and taking the data collected by the preset script as the first data, wherein the preset script can be executed independently in the background and the main thread corresponding to the target browser; collecting, through a preset interface, pressure data and inclination angle data when the target user interacts with a touch screen corresponding to the target device, and taking the pressure data and the inclination angle data as the second data, wherein the pressure data is used to represent a pressure value of the target user pressing the touch screen, and the inclination angle data is used to represent an inclination angle formed by a finger of the target user or a stylus used by the target user on the touch screen.

[0009] Optionally, the user security verification method further comprises: determining a basic parameter according to the third data, wherein the basic parameter at least includes a resolution parameter, a time zone parameter, a language setting parameter and a target string corresponding to the target browser, and the target string is used to represent a name of the target browser and device information of a target device in which the target browser is located; performing feature extraction on the third data to obtain a first feature, a second feature and a third feature, wherein the first feature is used to represent a pixel rendering effect of the target browser, the second feature is used to represent a processing capability of the target device on audio, and the third feature is used to represent page font information corresponding to the target browser; taking the first feature, the second feature and the third feature as high-level parameters; and generating the target device identifier according to the basic parameter and the high-level parameters.

[0010] Optionally, the user security verification method further comprises: inputting the first data and the second data into a preset model, wherein the preset model is a quantification model capable of running in a front-end environment provided by the target browser; performing feature extraction on the first data and the second data by the preset model to obtain behavior time sequence features and biological time sequence features; determining a target score sequence based on the behavior time sequence features and the biological time sequence features, wherein each target score in the target score sequence is used to represent a behavior entropy value of the target user within a preset time window; and determining a target verification strategy based on the target score sequence and the target device identifier.

[0011] Optionally, the user security verification method further comprises: taking a similarity between the target device identifier and a historical device identifier as a target similarity, wherein the historical device identifier is a unique identifier of a device used by the target user to log in to the target browser in a historical time period; in a case where the target similarity is greater than or equal to a preset similarity, obtaining a preset security level corresponding to the target score, wherein the preset security level is positively correlated with the size of the target score; and taking a preset verification strategy corresponding to the preset security level as the target verification strategy.

[0012] Optionally, the user security verification method further comprises: in a case where the target similarity is less than the preset similarity, obtaining a preset security level corresponding to the target score; and taking an advanced verification strategy corresponding to the preset security level as the target verification strategy, wherein the verification difficulty of the advanced verification strategy is greater than that of the preset verification strategy.

[0013] Optionally, the user security verification method further comprises: encrypting the first data and the second data, and taking the encryption result as encrypted behavior data; and transmitting the encrypted behavior data, the target device identifier, and a verification result of the security verification to a preset database for storage.

[0014] According to another aspect of the embodiments of the present application, a user security verification apparatus is further provided, comprising: a collection unit configured to collect first data, second data, and third data, wherein the first data is behavior time sequence data of a target user interacting with a front-end interface of a financial software through a target browser, the second data is used to represent biological information of the target user when operating the front-end interface, and the third data is used to represent parameter information of the target browser; a first determination unit configured to determine a target device identifier according to the third data, wherein the target device identifier is a unique identifier of a target device, and the target device is a device used by the target user to log in to the target browser; and a second determination unit configured to determine a target verification strategy according to the first data, the second data, and the target device identifier, and perform security verification on the target user based on the target verification strategy, wherein the target verification strategy is used to determine a verification process for the security verification on the target user.

[0015] According to another aspect of the present application, a computer program product is provided, in which a computer program is stored. When the computer program is running, the computer program product is controlled to execute any one of the above-mentioned user security verification methods.

[0016] According to another aspect of the present application, an electronic device is also provided, wherein the electronic device includes one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors implement any one of the above-mentioned user security verification methods.

[0017] In the present application, first data, second data and third data are first collected, wherein the first data is the behavioral timing data of the target user interacting with the front-end interface of the financial software through the target browser, the second data is used to characterize the biometric information of the target user when operating the front-end interface, and the third data is used to characterize the parameter information of the target browser. Afterwards, the present application determines the target device identifier based on the third data, wherein the target device identifier is the unique identifier of the target device, and the target device is the device used by the target user to log in to the target browser. Then, the present application determines the target verification strategy based on the first data, the second data and the target device identifier, and performs security verification on the target user based on the target verification strategy, wherein the target verification strategy is used to determine the verification process for security verification of the target user.

[0018] From the above content, it can be seen that this application adopts a method of time-series analysis of the user's interactive behavior information with the front end (i.e., the first data) and the user's biometric characteristics (i.e., the second data), and constructs a device fingerprint (i.e., the target device identification) through the parameter information of the target browser, thereby achieving the purpose of instantly determining the target verification strategy based on the first data, the second data and the target device identification, thereby enabling real-time security verification of the user's interactive behavior in the front-end environment.

[0019] It can be seen that the technical solution of the present application does not need to wait for data processing by the back-end big data platform, and can instantly complete the risk assessment of user interaction behavior, thereby improving the work efficiency and response speed of risk assessment. At the same time, the present application can complete data analysis locally on the front end, avoiding unnecessary transmission of user behavior data, and improving the security and processing efficiency of user behavior data, thereby achieving the technical effect of reducing the delay in security verification of the user's front-end behavior and improving the efficiency of security verification of the user's front-end behavior, thereby solving the technical problems of high delay and low efficiency in the existing technology of security verification of the user's front-end behavior through the big data platform. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and together with the description serve to explain the application. In the drawings:

[0021] Figure 1 is a flow chart of an optional user security verification method according to an embodiment of the application;

[0022] Figure 2 is a schematic diagram of an optional user security verification device according to an embodiment of the application;

[0023] Figure 3 is a structural block diagram of an electronic device according to an embodiment of the application. DETAILED DESCRIPTION

[0024] In order to enable persons skilled in the art to better understand the application scheme, the technical solutions in the embodiments of the application will be described clearly and completely below with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are only a part of the embodiments of the application, but not all the embodiments of the application. Based on the embodiments in the application, all other embodiments obtained by persons skilled in the art without creative labor should fall within the scope of protection of the application.

[0025] It should be noted that the terms "first", "second", and the like in the specification and claims of the application and the above-described drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to the process, method, product or device.

[0026] It should also be noted that the relevant information (including but not limited to information for display and analyzed information) and data (including but not limited to first data, second data and third data) involved in the application are information and data authorized by the user or authorized by all parties. For example, an interface is provided between the system and the relevant user or institution. Before obtaining the relevant information, the interface needs to send a request to the user or the institution, and after receiving the consent information from the user or the institution, the relevant information is obtained.

[0027] In addition, the collection, storage, use, processing, transmission, provision, disclosure and application of the related information and related data involved in the present application comply with the relevant laws, regulations and standards of the relevant regions, and necessary security measures are taken without violating public order and good customs. In addition, the present application provides a corresponding operation portal for users to choose to authorize or refuse authorization. If the user chooses to refuse authorization, the corresponding expert decision-making process is entered.

[0028] According to an embodiment of the present application, an embodiment of a user security verification method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.

[0029] The present application provides a user security verification system (referred to as verification system) for executing the user security verification method in the present application, Figure 1 is a flowchart of an optional user security verification method according to an embodiment of the present application, as Figure 1 shown, the method comprises the following steps:

[0030] Step S101, collecting first data, second data and third data, wherein the first data is the behavior time series data of the target user interacting with the front-end interface of the financial software through the target browser, the second data is used to represent the biological information of the target user when operating the front-end interface, and the third data is used to represent the parameter information of the target browser.

[0031] Optionally, the first data, i.e. the behavior time series data, involves real-time operation details of the user in the front-end interface, such as mouse movement trajectory, touch screen sliding speed and input rhythm, etc. The verification system can collect and preliminarily process the interaction behavior information in the background of the browser through a preset script, thereby realizing the technical effect of avoiding browser interface lag and ensuring the smoothness of user experience.

[0032] Optionally, the second data, i.e. the biological characteristics / information, includes but is not limited to physiological characteristics and behavioral habits of the user when operating the front-end page, such as pen holding method, touch force and sliding speed, etc. The verification system can collect these dynamic biological characteristics through a preset interface in the user operation interface.

[0033] Optionally, the third data, i.e. the device fingerprint, is used as the unique identifier of the target device to identify the identity of the target device and prevent automated attacks.

[0034] Step S102, determining the target device identifier according to the third data, wherein the target device identifier is the unique identifier of the target device, and the target device is the device used by the target user when logging in to the target browser.

[0035] Optionally, the verification system generates a device fingerprint capable of uniquely identifying the target device by analyzing the parameter information in the third data, wherein the device fingerprint at least includes basic parameters and advanced parameters, wherein the basic parameters at least include the resolution parameter, the time zone parameter, the language setting parameter corresponding to the target browser, and the target string, and the advanced parameters are used to represent the pixel rendering effect, the audio processing capability of the target browser, and the corresponding page font information.

[0036] In step S103, the target verification strategy is determined according to the first data, the second data, and the target device identifier, and the target user is subjected to security verification based on the target verification strategy, wherein the target verification strategy is used to determine the verification process for security verification of the target user.

[0037] Optionally, after the verification system collects and analyzes the first data, the second data, and the third data, the verification system determines the behavior entropy value of the user's front-end interaction behavior in real time through a lightweight machine learning model based on the behavior time series data, the biological information, and the target device identifier, and automatically adjusts the level of the verification strategy in combination with the device fingerprint identification result.

[0038] Optionally, the determination of the verification strategy is based on real-time risk assessment of user behavior. For example, when the behavior mode is detected to be seriously inconsistent with historical data or the device fingerprint is abnormal, the verification system will automatically increase the verification level and adopt more stringent identity confirmation measures, such as biological recognition and enhanced verification process, to ensure the security of the operation. Conversely, when the behavior mode and the device information are normal, the system can quickly complete the verification and provide a non-intrusive operation experience.

[0039] Optionally, through the above steps, the verification system can complete risk prediction locally in the front end, avoiding the delay and data security risk caused by frequent communication with the back-end server, and balancing safety and user experience by dynamically adjusting the verification process. This method not only effectively deals with high-concurrency operation scenarios, but also flexibly adjusts security measures according to real-time changes in user behavior, thereby improving the instant response capability of risk control and the convenience of user operation.

[0040] From the above content, it can be seen that the present application adopts a time series analysis method for the interaction behavior information of the user and the front end (i.e., the first data) and the biological characteristics of the user (i.e., the second data), and constructs a device fingerprint (i.e., the target device identifier) through the parameter information of the target browser, thereby achieving the purpose of instantaneously determining the target verification strategy according to the first data, the second data, and the target device identifier, so as to be able to perform real-time security verification on the interaction behavior of the user in the front-end environment.

[0041] Therefore, the technical scheme of the present application can complete risk assessment of user interaction behavior in real time without waiting for data processing of a backend big data platform, thereby improving the working efficiency and response speed of risk assessment. Meanwhile, the present application can complete data analysis locally at the front end, avoids unnecessary transmission of user behavior data, improves the security and processing efficiency of user behavior data, thereby achieving the technical effects of reducing the delay of security verification of the front end behavior of the user and improving the efficiency of security verification of the front end behavior of the user, and further solving the technical problems of high delay and low efficiency in security verification of the front end behavior of the user by a big data platform in the prior art.

[0042] In an optional embodiment, the verification system first collects the page click time, the cursor movement trajectory and the page switching path of the target user using the target browser through a preset script, and takes the data collected by the preset script as first data, wherein the preset script can be executed independently in the background and the main thread corresponding to the target browser. Then, the verification system collects pressure data and inclination angle data when the target user interacts with the touch screen corresponding to the target device through a preset interface, and takes the pressure data and the inclination angle data as second data, wherein the pressure data represents the pressure value of the target user pressing the touch screen, and the inclination angle data represents the inclination angle formed by the finger of the target user or the stylus used by the target user on the touch screen.

[0043] Optionally, the page click time refers to the specific time point of each click operation of the user on the page, including but not limited to button click and link jump.

[0044] Optionally, the cursor movement trajectory refers to the movement path of the user's cursor (or touch point) on the screen, including the starting point, the ending point and each coordinate position in between. The cursor movement trajectory can reveal the intuitive movement trend of the target user during operation, and is of great significance for identifying automated operation (robot behavior) and real human operation.

[0045] Optionally, the page switching path is used to track the navigation order of the user among multiple pages, including the time, frequency and method of jumping from one page to another, such as directly clicking a link or using the forward / backward function of the browser. Monitoring of the page switching path helps to establish the habit pattern of user operation, and determines the behavior habit characteristics of the user based on the user's page browsing focus.

[0046] Optionally, the preset script refers to a pre-written automatic code module, which is used to capture various operation details of the user in the front-end interface in real time. In the present application, the preset script can be executed in the background independently of the main thread of the target browser, without affecting the performance of the user interface, and accurately recording the operation behavior information of the user. The design of the preset script enables the data collection work to be carried out without the user's awareness, greatly improving the user experience.

[0047] Optionally, the biological information of the user interacting with the touch screen is captured through the preset interface, providing information input of the biological feature dimension for the front-end risk control model, so as to more accurately evaluate the risk level of the user's behavior operation.

[0048] In an optional embodiment, the verification system first determines the basic parameters according to the third data, wherein the basic parameters at least include resolution parameters, time zone parameters, language setting parameters corresponding to the target browser, and a target string, the target string is used to represent the name of the target browser and the device information of the target device where the target browser is located, then the verification system extracts the first feature, the second feature and the third feature from the third data, wherein the first feature is used to represent the pixel rendering effect of the target browser, the second feature is used to represent the processing capability of the target device where the target browser is located for audio, and the third feature is used to represent the page font information corresponding to the target browser, then the verification system takes the first feature, the second feature and the third feature as high-level parameters, and finally, the verification system generates the target device identifier according to the basic parameters and the high-level parameters.

[0049] Optionally, the basic parameters at least include UserAgent (user agent, a HTTP (HyperText Transfer Protocol, HyperText Transfer Protocol) header field), screen resolution, time zone, and language corresponding to the target browser.

[0050] Optionally, the high-level parameters at least include WebGL (Web Graphics Library) rendering hash (graphics card driver difference), AudioContext (audio context) frequency response fingerprint, and installed font list corresponding to the target browser.

[0051] Optionally, the verification system generates the target device identifier based on the third data, i.e. the device fingerprint, which has the following effects:

[0052] (1) Enhancing the accuracy of device identification: By analyzing parameters including UserAgent, screen resolution, time zone, language, and more advanced parameters such as WebGL rendering hash, AudioContext frequency response fingerprint, installed font list, etc., a highly unique device fingerprint can be generated. This fingerprint not only covers basic device information but also includes subtle differences in device hardware and software environment, making device identification more accurate and effectively distinguishing different physical devices, reducing the misjudgment rate.

[0053] (2) Improving the immediacy of risk assessment: The determination of target device identification can be completed directly in the front-end interface in real time, without the need for data exchange with the back-end server, thereby shortening the risk assessment time. In high-concurrency operation scenarios, this immediacy is particularly important, ensuring that the system reacts to potential risks in the shortest time, improving the overall response speed of the risk control system.

[0054] (3) Strengthening user privacy protection: Device identification is generated locally, and sensitive parameter information is not uploaded to the server, avoiding potential leakage risks of user data during network transmission. At the same time, since the device fingerprint contains difficult-to-fake hardware features, it means that even if the data is intercepted, attackers will have difficulty directly locating specific users through these information, thereby enhancing the security of user privacy.

[0055] (4) Preventing automated attacks and cloning behavior: By analyzing the parameter information of the browser and its running environment, the generated device fingerprint can effectively identify the abnormal behavior of automated tools or cloned devices. Automated tools are often difficult to simulate real device parameters, while cloned devices can copy basic information but are difficult to completely copy advanced features. Therefore, as part of the verification, the device fingerprint can effectively increase the cloning difficulty of attackers and improve the security of the system.

[0056] (5) Establishing the basis for dynamic trust scoring: Device identification combined with user behavior baseline can provide the basis for creating dynamic trust scores. When the device identification is consistent with historical records, the verification system can give a higher trust score, otherwise it will reduce the score and trigger a more stringent verification process. This provides a technical basis for the implementation of adaptive verification strategies, ensuring the flexibility and effectiveness of the verification process.

[0057] In an optional embodiment, the verification system first inputs the first data and the second data into a preset model, wherein the preset model is a quantized model capable of running in a front-end environment provided by the target browser, then the verification system extracts the behavior time sequence features and the biological time sequence features from the first data and the second data through the preset model, and then determines the target score sequence based on the behavior time sequence features and the biological time sequence features, wherein each target score in the target score sequence is used to represent the behavior entropy value of the target user in a preset time window, and finally the verification system determines the target verification strategy based on the target score sequence and the target device identifier.

[0058] Optionally, the preset model, here referred to as an optimized and quantized machine learning model, is designed to run in the front-end environment of the target browser without causing significant performance burden. The quantized model reduces the model size and computational complexity by reducing numerical precision, so that the model can be quickly executed on the user device and is suitable for real-time data processing and analysis.

[0059] Optionally, the verification system inputs the first data (behavior time sequence data of the user) and the second data (biological information of the user) into the preset model. The model here is lightweight and can quickly run in the front-end environment without relying on the computing resources of the back-end server, thereby reducing the delay of data transmission and improving the immediacy of risk assessment.

[0060] Optionally, based on the extracted behavior time sequence features and biological time sequence features, the preset model calculates a series of target scores, each score corresponding to the behavior entropy value of the user in a specific time window. The behavior entropy value reflects the complexity and randomness of the user's operation and is an important indicator for measuring whether the behavior pattern deviates from the normal range. The generation of the target score sequence is essentially a real-time monitoring and quantitative evaluation of user behavior, which can instantly reflect the degree of abnormality of user operation and provide a basis for dynamically adjusting the verification strategy. By calculating the behavior entropy value in real time, the verification system can respond to changes in user behavior in real time and take appropriate security measures in a timely manner.

[0061] Optionally, in combination with the target score sequence and the target device identifier, the verification system can dynamically determine the target verification strategy based on the trust level of the user's current device and the real-time risk score of the behavior. The verification strategy automatically adjusts the strictness of the verification process according to the real-time score of the user's behavior and the trustworthiness of the device, such as direct biometric identification, enhanced verification, or manual review.

[0062] Optionally, through the execution of the above steps, the application can not only monitor user behavior in real time, but also dynamically adjust the verification strategy according to the behavior characteristics and device information, realize the intelligentization and personalization of front-end risk control verification, and provide a safer and more efficient operation environment for digital financial services. At the same time, by processing data in the front end, the transmission of sensitive data is also effectively avoided, and user privacy protection is enhanced.

[0063] In an optional embodiment, the verification system first takes the similarity between the target device identifier and the historical device identifier as the target similarity, wherein the historical device identifier is the unique identifier of the device used by the target user to log in to the target browser in the historical time period. Then, in the case that the target similarity is greater than or equal to a preset similarity, the verification system obtains a preset security level corresponding to the target score, wherein the preset security level is positively correlated with the size of the target score. Then, the verification system takes the preset verification strategy corresponding to the preset security level as the target verification strategy.

[0064] Optionally, the historical device identifier is the identifier information of the device used by the target user in the past in different login sessions, which also contains behavior and device parameter characteristics, and is used to establish the baseline of user behavior and the trusted history record of the device.

[0065] Optionally, when the target similarity reaches or exceeds the preset similarity, the verification system will further analyze the target score to determine the preset security level. The preset similarity is a judgment standard preset by the system, which indicates the degree of device consistency at which the system considers the current operation to be low risk and can enter the next scoring analysis process.

[0066] Optionally, the target score comes from real-time evaluation of user behavior, such as click interval, cursor movement speed, etc., and quantification of biological information, such as stress data, inclination angle, etc. The higher the score, the more consistent the user behavior is with its historical pattern, and the lower the risk. The lower the score, the greater the behavior deviation, and the higher the risk. The preset security level is divided according to the size of the target score, and the target score is positively correlated with the preset security level, that is, the higher the score, the higher the security level, and vice versa.

[0067] Optionally, the verification system will select a corresponding preset verification strategy as the target verification strategy according to the preset security level, wherein the preset verification strategy is a series of risk control measures preset according to the high and low of the security level, for example:

[0068] High security level (such as 80-100 points): call biometric identification for fast verification;

[0069] Medium security level (e.g. 60-79 points): Start enhanced verification, such as a distributed password input front-end interface, requiring the user to input part of the password in multiple locations;

[0070] Low security level (e.g. below 60 points): Trigger mandatory manual review, or require the user to provide additional identity proof information.

[0071] In an optional embodiment, when the target similarity is less than the preset similarity, the preset security level corresponding to the target score is obtained, and the verification system takes the advanced verification strategy corresponding to the preset security level as the target verification strategy, wherein the verification difficulty of the advanced verification strategy is greater than the verification difficulty of the preset verification strategy.

[0072] Optionally, when the target similarity is lower than the preset similarity threshold, it means that the device is replaced or the user behavior pattern changes abnormally, which may pose a potential fraud risk. Therefore, the verification system needs to increase the verification difficulty of the security verification at this time.

[0073] Optionally, once it is determined that the preset security level corresponding to the target score is lower than the normal range, the verification system will enable the advanced verification strategy as the target verification strategy. The advanced verification strategy has a higher verification difficulty and a more stringent verification process than the conventional preset verification strategy, in order to cope with possible security threats.

[0074] For example, the preset verification strategy includes simple biometric identification (such as fingerprint scanning) or conventional password verification, while the advanced verification strategy includes:

[0075] Composite biometric verification: requires the user to provide multiple biometric information simultaneously or sequentially, such as fingerprint and facial recognition;

[0076] Behavioral verification code: requires the user to perform a specific behavior, such as drawing a gesture at a specific rhythm or inputting a dynamic verification code, to verify the naturalness of the operation;

[0077] Forced secondary verification: in addition to the conventional verification, a secondary confirmation through phone, SMS or email is required.

[0078] Manual review: submit the operation to the security team for manual review to ensure the legality of the operation.

[0079] Optionally, by switching to the advanced verification strategy, the verification system can take more stringent verification measures when there is an anomaly in the device or behavior pattern, effectively preventing risks and protecting user account security. The dynamic adjustment of this strategy can ensure that the system provides corresponding security protection under different risk levels, while minimizing the disturbance to normal users.

[0080] In an optional embodiment, the verification system first encrypts the first data and the second data, and transmits the encrypted results as encrypted behavior data to a preset database for storage.

[0081] Optionally, the verification system can encrypt the first data and the second data through a preset interface, which provides native encryption and decryption functions of a browser, can generate a device unique key pair, and realizes homomorphic encryption and decryption of data. Even if the data is intercepted during transmission, it cannot be decrypted and understood, thereby protecting the privacy and data security of the user.

[0082] Optionally, after the encryption operation is completed, the first data and the second data are converted into encrypted behavior data, i.e., user operation behavior information after encryption processing. These encrypted behavior data contain key features of user behavior, but are stored and transmitted in an encrypted form, thereby increasing the security of the data.

[0083] Optionally, the verification system stores the encrypted behavior data, the target device identifier, and the verification result of the security verification, so that the data can be stored for a long time and can be further analyzed by the backend platform. Through encrypted transmission and storage, sensitive information can be protected from unauthorized access or leakage. The information stored in the database can be used for subsequent analysis and learning, helping the preset model to optimize, thereby improving the accuracy and efficiency of risk identification of user behavior at future moments.

[0084] From the above, it can be seen that the present application adopts a time sequence analysis method for the interactive behavior information of the user and the front end (i.e., the first data) and the user biometric features (i.e., the second data), and constructs a device fingerprint (i.e., the target device identifier) through the parameter information of the target browser, thereby achieving the purpose of determining a target verification strategy in real time according to the first data, the second data, and the target device identifier, so as to be able to perform real-time security verification on the interactive behavior of the user in the front-end environment.

[0085] Therefore, the technical scheme of the present application can complete risk assessment of user interactive behavior in real time without waiting for data processing of a backend big data platform, thereby improving the work efficiency and response speed of risk assessment. At the same time, the present application can complete data analysis locally in the front end, avoids unnecessary transmission of user behavior data, improves the security and processing efficiency of user behavior data, thereby achieving the technical effects of reducing the delay of security verification of the front-end behavior of the user and improving the efficiency of security verification of the front-end behavior of the user, and further solving the technical problems of high delay and low efficiency of security verification of the front-end behavior of the user through a big data platform in the prior art.

[0086] In an alternative embodiment, the architecture of the user security verification system includes a behavior collection layer, a lightweight model layer, a hierarchical verification layer, and an encrypted communication layer, which are described as follows:

[0087] (1) Behavior collection layer:

[0088] The preset script continuously captures user operation timing data (i.e., first data) in real time, including click intervals, page switching paths, and mouse trajectory records, etc. The preset script can run a lightweight behavior analysis algorithm, thereby avoiding front-end page lag, ensuring the smoothness of user browsing, and improving user experience.

[0089] Through the preset interface, biological characteristics such as pressure and inclination angle (i.e., second data) are uniformly collected across devices to obtain millimeter-level touch trajectory features, thereby identifying abnormal sliding patterns corresponding to user behavior.

[0090] A unique device fingerprint (i.e., target device identifier) is generated based on browser parameter characteristics. The parameters in the device fingerprint include basic parameters and advanced parameters. The basic parameters include UserAgent, screen resolution, time zone, and language. The advanced parameters include WebGL rendering hash, AudioContext frequency response fingerprint, and installed font list.

[0091] (2) Lightweight model layer:

[0092] The preset model is deployed and run locally on the front end. Based on the collected user operation timing data and biological characteristics, the preset model calculates user behavior entropy values in real time (60 inferences per second). At the same time, the device fingerprint calculation is dynamically executed, and a timestamp key is added each time the device fingerprint is generated to prevent long-term tracking. The device fingerprint is stored in association with the user behavior baseline, which is a series of user behavior entropy values arranged in time sequence. The similarity between the current device fingerprint and the registered device fingerprints in the historical time period is compared in real time, and a dynamic trust score is generated based on the similarity result and the user behavior baseline.

[0093] (3) Hierarchical verification layer:

[0094] When a device fingerprint mutation is detected but the user behavior pattern is similar, an anti-cloning mechanism is triggered to automatically upgrade the security verification level. The verification strategy is automatically switched based on the score, as illustrated by the following examples:

[0095] High security level (e.g., 80-100 points): invoke biometric recognition for fast verification;

[0096] Medium security level (e.g., 60-79 points): start enhanced verification, such as a decentralized password input front-end interface, requiring the user to input part of the password at multiple locations;

[0097] Low security level (e.g. below 60 points): triggers mandatory manual review or requires users to provide additional identity verification information.

[0098] (4) Encrypted communication layer:

[0099] A preset interface is used to implement homomorphic encryption of user behavior data and generate a device-unique key pair (hardware-level secure storage) to achieve end-to-end encryption at the transport layer.

[0100] Establish a two-way authentication channel with the back-end risk control platform to transmit encrypted data, transmit the encrypted device fingerprint to the risk control platform as the basis for traceability, automatically switch to the backup node when the encrypted communication fails, and cache the risk control strategy when offline.

[0101] When a user switches transfer accounts rapidly and continuously and the user's touch trajectory shows programmed characteristics, the front-end automatically triggers an invisible verification pop-up window (for example, requiring gestures to be drawn at a specific rhythm), and at the same time encrypts and uploads the abnormal behavior clip to the risk control platform.

[0102] Optionally, the technical solution of the above embodiment brings the following technical effects:

[0103] (1) Zero-delay risk control: It effectively combines the real-time computing capabilities of the front-end to avoid the time difference required by traditional solutions to transmit data back to the server.

[0104] (2) Privacy protection: There is no need to transmit user behavior data to the backend or other platforms for analysis. This application only analyzes user behavior data in a lightweight model running in the front-end environment and does not write it to local storage, thereby improving the security of user behavior information.

[0105] (3) Adaptive experience: Automatically strengthen verification in high-risk scenarios without disturbing users' regular operations.

[0106] (4) Anti-cracking design: Combine device fingerprints to prevent automated attacks.

[0107] According to another aspect of the embodiment of the present application, a user security verification device is also provided. Figure 2 is a schematic diagram of an optional user security verification device according to an embodiment of the present application, such as Figure 2 As shown, a user security verification device includes: a collection unit 201, a first determination unit 202 and a second determination unit 203.

[0108] Optionally, the collection unit is configured to collect first data, second data, and third data, wherein the first data is behavior time series data of the target user interacting with the front-end interface of the financial software through the target browser, the second data is used to represent biological information of the target user when operating the front-end interface, and the third data is used to represent parameter information of the target browser; the first determination unit is configured to determine a target device identifier according to the third data, wherein the target device identifier is a unique identifier of a target device, and the target device is a device used by the target user when logging in to the target browser; the second determination unit is configured to determine a target verification strategy according to the first data, the second data, and the target device identifier, and perform security verification on the target user based on the target verification strategy, wherein the target verification strategy is used to determine a verification process for security verification of the target user.

[0109] In an optional embodiment, the collection unit includes a first collection subunit and a second collection subunit.

[0110] Optionally, the first collection subunit is configured to collect a page click time, a cursor movement track, and a page switching path of the target user using the target browser through a preset script, and collect data collected by the preset script as the first data, wherein the preset script can be executed independently in the background and a main thread corresponding to the target browser; and the second collection subunit is configured to collect pressure data and inclination angle data of the target user interacting with a touch screen of the target device through a preset interface, and collect the pressure data and the inclination angle data as the second data, wherein the pressure data is used to represent a pressure value of the target user pressing the touch screen, and the inclination angle data is used to represent an inclination angle formed by a finger of the target user or a stylus used by the target user on the touch screen.

[0111] In an optional embodiment, the first determination unit includes a first determination subunit, a first extraction subunit, a second determination subunit, and a generation subunit.

[0112] Optionally, the first determining subunit is configured to determine a basic parameter according to the third data, wherein the basic parameter comprises at least a resolution parameter corresponding to the target browser, a time zone parameter, a language setting parameter, and a target string, and the target string is used to represent a name of the target browser and device information of a target device in which the target browser is located; the first extracting subunit is configured to perform feature extraction on the third data to obtain a first feature, a second feature, and a third feature, wherein the first feature is used to represent a pixel rendering effect of the target browser, the second feature is used to represent a processing capability of the target device in which the target browser is located for audio, and the third feature is used to represent page font information corresponding to the target browser; the second determining subunit is configured to take the first feature, the second feature, and the third feature as high-level parameters; and the generating subunit is configured to generate the target device identifier according to the basic parameter and the high-level parameters.

[0113] In an optional embodiment, the second determining unit comprises an input subunit, a second extracting subunit, a third determining subunit, and a fourth determining subunit.

[0114] Optionally, the input subunit is configured to input the first data and the second data to a preset model, wherein the preset model is a quantification model capable of running in a front-end environment provided by the target browser; the second extracting subunit is configured to perform feature extraction on the first data and the second data by using the preset model to obtain a behavior time sequence feature and a biological time sequence feature; the third determining subunit is configured to determine a target score sequence based on the behavior time sequence feature and the biological time sequence feature, wherein each target score in the target score sequence is used to represent a behavior entropy value of the target user within a preset time window; and the fourth determining subunit is configured to determine the target verification strategy based on the target score sequence and the target device identifier.

[0115] In an optional embodiment, the fourth determining subunit comprises a first determining module, a first obtaining module, and a second determining module.

[0116] Optionally, the first determining module is configured to take a similarity between the target device identifier and a historical device identifier as a target similarity, wherein the historical device identifier is a unique identifier of a device used by the target user to log in to the target browser within a historical time period; the first obtaining module is configured to obtain a preset security level corresponding to the target score in a case where the target similarity is greater than or equal to a preset similarity; and the second determining module is configured to take a preset verification strategy corresponding to the preset security level as the target verification strategy.

[0117] In an optional embodiment, the fourth determining subunit further comprises a second obtaining module and a third determining module.

[0118] Optionally, the second obtaining module is configured to obtain a preset security level corresponding to the target score in a case where the target similarity is less than a preset similarity; and the third determining module is configured to determine a high-level verification strategy corresponding to the preset security level as the target verification strategy, wherein a verification difficulty of the high-level verification strategy is greater than a verification difficulty of the preset verification strategy.

[0119] In an optional embodiment, the user security verification apparatus further comprises an encryption unit and a transmission unit.

[0120] Optionally, the encryption unit is configured to encrypt the first data and the second data, and the encryption result is taken as the encryption behavior data; and the transmission unit is configured to transmit the encryption behavior data, the target device identifier, and the verification result of the security verification to a preset database for storage.

[0121] As can be seen from the above, the present application adopts a manner of time sequence analysis on the interactive behavior information (i.e., the first data) of the user and the front end and the biological features (i.e., the second data) of the user, and constructs a device fingerprint (i.e., the target device identifier) through the parameter information of the target browser, so as to achieve the purpose of determining the target verification strategy in real time according to the first data, the second data, and the target device identifier, thereby being capable of performing real-time security verification on the interactive behavior of the user in the front-end environment.

[0122] Therefore, the technical solution of the present application can complete the risk assessment on the interactive behavior of the user in real time without waiting for the data processing of the back-end big data platform, thereby improving the work efficiency and response speed of the risk assessment. Meanwhile, the present application can complete the data analysis locally in the front end, avoids unnecessary transmission of the user behavior data, improves the security and processing efficiency of the user behavior data, thereby achieving the technical effects of reducing the delay of the security verification on the front-end behavior of the user and improving the efficiency of the security verification on the front-end behavior of the user, and further solving the technical problems of high delay and low efficiency in the prior art of performing security verification on the front-end behavior of the user through the big data platform.

[0123] According to another aspect of the embodiments of the present application, a computer program product is also provided, which comprises a stored computer program, wherein the computer program product controls the computer program to execute the user security verification method of any one of the above when the computer program runs.

[0124] According to another aspect of the embodiments of the present application, an electronic device is also provided, which comprises a processor and a memory for storing executable instructions of the processor, wherein the processor is configured to execute the user security verification method of any one of the above via execution of the executable instructions.

[0125] Optionally, Figure 3 is a structural block diagram of an electronic device according to an embodiment of the present application. As shown in FIG. 1, the electronic device comprises a processor 1001, a memory 1002, a communication interface 1003, and a display 1004.Figure 3 As shown, the electronic device can include one or more (only one is shown in the figure) processors 302, memory 304, storage controller, and peripheral interface, wherein the peripheral interface is connected with a radio frequency module, an audio module, and a display. Figure 3

[0126] The processor can call information and application programs stored in the memory through the transmission device to perform the following steps: collecting first data, second data, and third data, wherein the first data is time series data of the target user's interaction with the front-end interface of the financial software through the target browser, the second data is used to represent the biological information of the target user when operating the front-end interface, and the third data is used to represent the parameter information of the target browser; determining the target device identifier according to the third data, wherein the target device identifier is the unique identifier of the target device, and the target device is the device used by the target user when logging in to the target browser; determining the target verification strategy according to the first data, the second data, and the target device identifier, and performing security verification on the target user based on the target verification strategy, wherein the target verification strategy is used to determine the verification process of the security verification on the target user.

[0127] The processor can call information and application programs stored in the memory through the transmission device to perform the following steps: collecting the page click time, the cursor movement track, and the page switching path of the target user using the target browser through a preset script, and taking the data collected by the preset script as the first data, wherein the preset script can be executed independently in the background and the main thread corresponding to the target browser; collecting pressure data and inclination angle data when the target user interacts with the touch screen corresponding to the target device through a preset interface, and taking the pressure data and the inclination angle data as the second data, wherein the pressure data is used to represent the pressure value of the target user pressing the touch screen, and the inclination angle data is used to represent the inclination angle formed by the target user's finger or the target user's touch pen on the touch screen.

[0128] ​The processor can call information and application programs stored in the memory through the transmission device to perform the following steps: determining a basic parameter according to the third data, wherein the basic parameter at least includes a resolution parameter corresponding to the target browser, a time zone parameter, a language setting parameter and a target string, and the target string is used to represent the name of the target browser and the device information of the target device where the target browser is located; performing feature extraction on the third data to obtain a first feature, a second feature and a third feature, wherein the first feature is used to represent the pixel rendering effect of the target browser, the second feature is used to represent the processing capability of the target device where the target browser is located for audio, and the third feature is used to represent the page font information corresponding to the target browser; taking the first feature, the second feature and the third feature as advanced parameters; and generating the target device identifier according to the basic parameter and the advanced parameters.

[0129] The processor can call information and application programs stored in the memory through the transmission device to perform the following steps: inputting the first data and the second data into a preset model, wherein the preset model is a quantization model capable of running in a front-end environment provided by the target browser; performing feature extraction on the first data and the second data through the preset model to obtain a behavior time sequence feature and a biological time sequence feature; determining a target score sequence based on the behavior time sequence feature and the biological time sequence feature, wherein each target score in the target score sequence is used to represent the behavior entropy value of the target user within a preset time window; and determining the target verification strategy based on the target score sequence and the target device identifier.

[0130] The processor can call information and application programs stored in the memory through the transmission device to perform the following steps: taking the similarity between the target device identifier and a historical device identifier as a target similarity, wherein the historical device identifier is a unique identifier of a device used by the target user to log in to the target browser within a historical time period; in a case where the target similarity is greater than or equal to a preset similarity, obtaining a preset security level corresponding to the target score, wherein the high and low of the preset security level and the size of the target score are in a positive correlation relationship; and taking a preset verification strategy corresponding to the preset security level as the target verification strategy.

[0131] The processor can call information and application programs stored in the memory through the transmission device to perform the following steps: in a case where the target similarity is less than the preset similarity, obtaining a preset security level corresponding to the target score; and taking an advanced verification strategy corresponding to the preset security level as the target verification strategy, wherein the verification difficulty of the advanced verification strategy is greater than the verification difficulty of the preset verification strategy.

[0132] The processor can call information and application programs stored in the memory through the transmission device to perform the following steps: encrypting the first data and the second data, and taking the encryption result as encryption behavior data; transmitting the encryption behavior data, the target device identifier, and a verification result of the security verification to a preset database for storage.

[0133] By adopting the embodiments of the present application, a technical scheme of a user security verification method is provided. The present application adopts a time sequence analysis manner for interactive behavior information (i.e., first data) of a user and a front end and a user biological feature (i.e., second data), and constructs a device fingerprint (i.e., a target device identifier) through parameter information of a target browser, so as to achieve the purpose of instantaneously determining a target verification strategy according to the first data, the second data, and the target device identifier, thereby being capable of performing real-time security verification on interactive behavior of the user in a front end environment.

[0134] It can be seen that the technical scheme of the present application can instantaneously complete risk assessment on interactive behavior of a user without waiting for data processing of a back end big data platform, thereby improving work efficiency and response speed of risk assessment. Meanwhile, the present application can complete data analysis locally in a front end, avoids unnecessary transmission of user behavior data, improves security and processing efficiency of user behavior data, thereby achieving the technical effects of reducing delay of security verification on front end behavior of a user and improving efficiency of security verification on front end behavior of a user, and further solving the technical problems of high delay and low efficiency of security verification on front end behavior of a user through a big data platform in the prior art.

[0135] Those skilled in the art can understand that the above-mentioned embodiments can be implemented by one or more of the above-mentioned methods. Figure 3 The structure shown is only schematic, and the electronic device can also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a palm computer, a Mobile Internet Device (MID), a PAD, or the like. Figure 3 It does not limit the structure of the above-mentioned electronic device. For example, the electronic device can further include more or fewer components (such as a network interface, a display device, etc.) than those shown in the figure, or have a different configuration from that shown in the figure. Figure 3 For example, the electronic device can further include more or fewer components (such as a network interface, a display device, etc.) than those shown in the figure, or have a different configuration from that shown in the figure. Figure 3 For example, the electronic device can further include more or fewer components (such as a network interface, a display device, etc.) than those shown in the figure, or have a different configuration from that shown in the figure.

[0136] Those skilled in the art can understand that all or part of the steps in the above-mentioned embodiments can be completed by a program instructing a terminal device related hardware, and the program can be stored in a computer readable storage medium, which can include a flash disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk or an optical disk, etc.

[0137] The above-mentioned sequence numbers of the embodiments of the present application are only for description, and do not represent the advantages or disadvantages of the embodiments.

[0138] In the above-mentioned embodiments of the present application, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0139] In the several embodiments of the present application, it should be understood that the disclosed technology can be implemented in other ways. Of course, the above-described device embodiments are only illustrative, and the division of units is only a logical function division. There can be another division manner in actual implementation, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, units or modules, and can be electrical or other forms.

[0140] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., they can be located in one place or distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.

[0141] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The above integrated unit can be realized in the form of hardware or in the form of software functional unit.

[0142] The integrated unit, if realized in the form of software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part of the prior art that makes a contribution or the whole or part of the technical solutions can be embodied in the form of software product, which is stored in a storage medium and includes a plurality of instructions for making a computer device (which can be a personal computer, a server or a network device, etc.) execute all or part of the steps of the method described in each embodiment of the present application. The above-mentioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic or optical disk and various program code storage media.

[0143] The above merely describes the preferred embodiments of the present application, and it should be pointed out that, for those skilled in the art, some improvements and refinements can be made without departing from the principles of the present application, and these improvements and refinements should also be considered as the protection scope of the present application.

Claims

1. A user security verification method, characterized in that: include: Collecting first data, second data, and third data, wherein the first data is time-series data of a target user's behavior interacting with a front-end interface of financial software through a target browser, the second data is used to represent biometric information of the target user when operating the front-end interface, and the third data is used to represent parameter information of the target browser; Determining a target device identifier based on the third data, wherein the target device identifier is a unique identifier of a target device, and the target device is a device used by the target user to log in to the target browser; A target verification strategy is determined according to the first data, the second data and the target device identifier, and security verification is performed on the target user based on the target verification strategy, wherein the target verification strategy is used to determine a verification process for security verification of the target user.

2. The user security verification method according to claim 1, characterized in that: Collecting first data and second data includes: collecting, by means of a preset script, page click moments, cursor movement trajectories, and page switching paths of the target user when using the target browser, and using the data collected by the preset script as the first data, wherein the preset script can be executed independently in the background from a main thread corresponding to the target browser; The pressure data and tilt angle data when the target user interacts with the touch screen corresponding to the target device are collected through a preset interface, and the pressure data and the tilt angle data are used as the second data, wherein the pressure data is used to characterize the pressure value of the target user pressing the touch screen, and the tilt angle data is used to characterize the tilt angle formed by the target user's finger or the stylus used by the target user on the touch screen.

3. The user security verification method according to claim 1, characterized in that: Determining the target device identifier according to the third data includes: Determining basic parameters based on the third data, wherein the basic parameters include at least a resolution parameter, a time zone parameter, a language setting parameter, and a target string corresponding to the target browser, wherein the target string is used to represent the name of the target browser and device information of a target device where the target browser is located; performing feature extraction on the third data to obtain a first feature, a second feature, and a third feature, wherein the first feature is used to characterize a pixel rendering effect of the target browser, the second feature is used to characterize an audio processing capability of a target device where the target browser is located, and the third feature is used to characterize page font information corresponding to the target browser; using the first feature, the second feature, and the third feature as high-level parameters; The target device identifier is generated according to the basic parameters and the advanced parameters.

4. The user security verification method according to claim 1, characterized in that: Determining a target verification strategy based on the first data, the second data, and the target device identifier includes: Inputting the first data and the second data into a preset model, wherein the preset model is a quantitative model that can be run in the front-end environment provided by the target browser; Extracting features from the first data and the second data using the preset model to obtain behavioral temporal features and biological temporal features; Determining a target score sequence based on the behavioral time series features and the biological time series features, wherein each target score in the target score sequence is used to represent a behavioral entropy value of the target user within a preset time window; The target verification strategy is determined based on the target scoring sequence and the target device identification.

5. The user security verification method according to claim 4, characterized in that: Determining the target verification strategy based on the target scoring sequence and the target device identifier includes: The similarity between the target device identifier and the historical device identifier is used as the target similarity, wherein the historical device identifier is a unique identifier of a device used by the target user to log in to the target browser within a historical time period; When the target similarity is greater than or equal to a preset similarity, obtaining a preset security level corresponding to the target score, wherein the preset security level is positively correlated with the target score; The preset verification strategy corresponding to the preset security level is used as the target verification strategy.

6. The user security verification method according to claim 5, characterized in that: After taking the similarity between the target device identifier and the historical device identifier as the target similarity, the user security verification method further includes: When the target similarity is less than the preset similarity, obtaining a preset security level corresponding to the target score; An advanced verification strategy corresponding to the preset security level is used as the target verification strategy, wherein the verification difficulty of the advanced verification strategy is greater than the verification difficulty of the preset verification strategy.

7. The user security verification method according to claim 1, characterized in that: After performing security verification on the target user based on the target verification policy, the user security verification method further includes: encrypting the first data and the second data, and using the encryption result as encrypted behavior data; The encrypted behavior data, the target device identification, and the verification result of the security verification are transmitted to a preset database for storage.

8. A user security verification device, characterized in that: include: a collection unit configured to collect first data, second data, and third data, wherein the first data is time-series data of a target user's behavior of interacting with a front-end interface of financial software via a target browser, the second data is used to represent biometric information of the target user when operating the front-end interface, and the third data is used to represent parameter information of the target browser; a first determining unit, configured to determine a target device identifier based on the third data, wherein the target device identifier is a unique identifier of a target device, and the target device is a device used by the target user to log in to the target browser; The second determination unit is used to determine a target verification strategy based on the first data, the second data and the target device identifier, and perform security verification on the target user based on the target verification strategy, wherein the target verification strategy is used to determine the verification process for performing security verification on the target user.

9. A computer program product, characterized in that The computer program product includes a computer program, wherein when the computer program is running, the computer program product is controlled to execute the user security verification method according to any one of claims 1 to 7.

10. An electronic device, characterized in that: It includes one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the user security verification method described in any one of claims 1 to 7.