Identity authentication risk identification method and device for power transaction platform, medium and equipment

By employing multi-level identity authentication and risk identification models, the security issues of identity authentication on the power trading platform have been resolved, enabling accurate authentication of user identities and timely identification of abnormal operations, thus ensuring the platform's security and stability.

CN120875879APending Publication Date: 2025-10-31KUNMING POWER EXCHANGE CENT CO LTD

Patent Information

Application Number
CN202510711797.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

The existing identity authentication methods of power trading platforms are not secure enough, posing a risk of identity misuse and unauthorized login. The lack of an effective risk identification model threatens the stable operation of the platform.

Method used

A multi-level authentication method is adopted to verify the identity of users to be authenticated, and a pre-built risk identification model is used to monitor the operation behavior of authenticated users. Abnormal risks are identified by monitoring indicators and historical data, and early warning actions are triggered.

Benefits of technology

This improves the security and reliability of identity authentication on the power trading platform, enables timely detection of abnormal operations, and ensures the stable operation of the platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120875879A_ABST
    Figure CN120875879A_ABST
Patent Text Reader

Abstract

The invention discloses a power transaction platform identity authentication risk identification method and device, a medium and equipment. The method comprises the following steps: in response to an identity authentication request sent by a to-be-authenticated user, performing multi-level identity authentication on the to-be-authenticated user; acquiring monitoring data of the authenticated user in a preset monitoring period based on the monitoring index; inputting the monitoring data of the monitoring index into a risk identification model corresponding to the monitoring index, and determining a risk identification result of the authenticated user; and if the risk identification result is greater than the target threshold, triggering an early warning operation corresponding to the risk identification result. Multi-level identity authentication is carried out on the to-be-authenticated user of the power transaction platform, the identity authentication risk is controlled, meanwhile, the pre-established risk identification model is used for monitoring login, operation and other behaviors of the authenticated user of the power transaction platform, abnormity is identified, the risk is early warned, and safe and stable operation of the power transaction platform is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of electronic information security technology, and in particular to a method, apparatus, medium and equipment for identifying identity authentication risks in a power trading platform. Background Technology

[0002] With the deepening of power market reform, power trading platforms have played a crucial role in promoting the optimal allocation of power resources and improving the operational efficiency of the power system. Within these platforms, authentication of all users protects the security of data and files, reducing unauthorized access, data breaches, and cyberattacks, thereby ensuring the reliable operation of the power trading platform.

[0003] However, the existing technologies employ simple and singular authentication methods, which lack sufficient security. This leads to the possibility of identity theft, password leaks, unauthorized logins, malicious operations, and other illegal activities such as economic losses and sensitive data breaches. Furthermore, the lack of effective risk identification models during user access to the power trading platform makes it difficult to promptly detect abnormal logins and operations, threatening the stable operation of the platform. Summary of the Invention

[0004] In view of this, this application provides a method, apparatus, medium and equipment for identifying identity authentication risks in a power trading platform. This method implements multi-level identity authentication for users to be authenticated on the power trading platform, controls identity authentication risks, and simultaneously uses a pre-built risk identification model to monitor the login and operation behaviors of authenticated users on the power trading platform, identify anomalies, issue early warnings of risks, and ensure the safe and stable operation of the power trading platform.

[0005] According to one aspect of this application, a method for identifying identity authentication risks in an electricity trading platform is provided, comprising:

[0006] In response to an authentication request sent by a user to be authenticated, multi-level authentication is performed on the user to be authenticated;

[0007] The monitoring data of the certified users within a preset monitoring period is obtained based on the monitoring indicators. The monitoring data is determined based on the operational behavior information generated by the certified users during their access to the power trading platform.

[0008] The monitoring data of the monitoring indicator is input into the risk identification model corresponding to the monitoring indicator to determine the risk identification result of the certified user. The risk identification model corresponding to the monitoring indicator is determined based on the historical normal data of the monitoring indicator in the historical monitoring period.

[0009] If the risk identification result is greater than the target threshold, an early warning operation corresponding to the risk identification result is triggered.

[0010] According to another aspect of this application, a power trading platform identity authentication risk identification device is provided, comprising:

[0011] The authentication module is used to perform multi-level authentication on the user to be authenticated in response to the authentication request sent by the user to be authenticated.

[0012] An identification module is used to acquire monitoring data of authenticated users within a preset monitoring period based on monitoring indicators. The monitoring data is determined based on operational behavior information generated by the authenticated users during their access to the power trading platform.

[0013] The monitoring data of the monitoring indicator is input into the risk identification model corresponding to the monitoring indicator to determine the risk identification result of the certified user. The risk identification model corresponding to the monitoring indicator is determined based on the historical normal data of the monitoring indicator in the historical monitoring period.

[0014] The early warning module is used to trigger an early warning operation corresponding to the risk identification result if the risk identification result is greater than the target threshold.

[0015] According to another aspect of this application, a readable storage medium is provided on which a program or instructions are stored, which, when executed by a processor, implement the steps of the above-described power trading platform identity authentication risk identification method.

[0016] According to another aspect of this application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor executes the program to implement the steps of the above-described power trading platform identity authentication risk identification method.

[0017] By employing the above technical solutions, this application provides a method, apparatus, medium, and device for identifying identity authentication risks in a power trading platform. The method performs multi-level identity authentication on users awaiting authentication on the power trading platform, effectively controlling user identity authentication risks and improving the security and reliability of identity authentication on the power trading platform. Furthermore, it utilizes a pre-obtained risk identification model to monitor the operational behavior data of authenticated users during their access to the power trading platform, identifying abnormal operations, promptly detecting operational risks, and triggering risk warnings to ensure the stable operation of the power trading platform.

[0018] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0019] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0020] Figure 1 A flowchart illustrating the risk identification method for identity authentication in a power trading platform provided in an embodiment of this application is shown.

[0021] Figure 2 A structural block diagram of the power trading platform identity authentication risk identification device provided in an embodiment of this application is shown. Detailed Implementation

[0022] The present application will be described in detail below with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in the embodiments of the present application can be combined with each other.

[0023] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application.

[0024] Those skilled in the art will understand that, unless specifically stated otherwise, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in this application means the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we say an element is “connected” or “attached” to another element, it can be directly connected or attached to the other element, or there may be intermediate elements. Furthermore, “connected” or “attached” as used herein can include wireless connections or wireless interconnections. The term “and / or” as used herein includes all or any unit and all combinations of one or more associated listed items.

[0025] Exemplary embodiments according to this application will now be described in more detail with reference to the accompanying drawings. However, these exemplary embodiments may be implemented in many different forms and should not be construed as being limited to the embodiments set forth herein. It should be understood that these embodiments are provided so that the disclosure of this application is thorough and complete, and that the concept of these exemplary embodiments is fully conveyed to those skilled in the art.

[0026] This embodiment provides a method for identifying identity authentication risks in a power trading platform, such as... Figure 1 As shown, the method includes:

[0027] Step 101: In response to the authentication request sent by the user to be authenticated, perform multi-level authentication on the user to be authenticated.

[0028] In this embodiment, the users of the power trading platform include users awaiting authentication and authenticated users. Users awaiting authentication need to send an identity authentication request to the power trading platform to obtain a valid user identity. Authenticated users can send a login request to the power trading platform to log in and perform further operations, such as trading operations and changes to identity information.

[0029] In practical applications, users of power trading platforms can be individuals or organizations, such as business entities.

[0030] Furthermore, in response to the identity authentication request sent by the user to be authenticated, the system obtains the user's multi-dimensional identity information, performs multi-level identity authentication on the user, effectively controls the risk of user identity authentication, and improves the accuracy of identity authentication.

[0031] Furthermore, as a refinement and extension of the specific implementation of the above embodiments, in order to fully illustrate the specific implementation process of this embodiment, multi-level identity authentication is performed on the user to be authenticated, including: determining the user risk level of the user to be authenticated based on the user's historical behavior information and current behavior information; obtaining the user's identity information based on the authentication mode corresponding to the user's risk level, and performing first-level identity authentication; if the first-level identity authentication is successful, determining the authentication risk level of the first-level identity authentication; if the authentication risk level is less than or equal to a preset threshold, determining the authentication result of the user to be authenticated as successful, and determining the user to be authenticated as an authenticated user; if the authentication risk level is greater than the preset threshold, performing second-level identity authentication based on the authentication risk level.

[0032] In this embodiment, the presence of any historical anomalies in the user to be authenticated can be verified through official channels. For example, if a business registration information interface is set up, the operational risks of the business entity to be authenticated can be verified through official channels to determine the user's historical behavior information. Simultaneously, the current authentication status of the user to be authenticated can be analyzed, such as the current IP address's abnormal status, and whether the user is repeatedly authenticating using different usernames with the same IP address. Therefore, the user's risk level can be assessed based on the user's historical and current behavior information.

[0033] For example, user risk levels can be categorized into high risk, medium risk, and low risk based on the actual situation. High risk means that the user to be authenticated is highly likely to engage in malicious login activities, medium risk corresponds to simple anomalies in the user to be authenticated, such as logging in from a different location, and low risk means that the user to be authenticated has no anomalies.

[0034] Furthermore, authentication modes are pre-matched to different user risk levels, avoiding a single, complex authentication process for all users. More authentication resources are allocated to high-risk users to identify potential risks and prevent incidents. While ensuring security, a convenient authentication experience is provided for low-risk users, reducing time costs and improving business processing efficiency. Then, based on the authentication mode corresponding to the user's risk level, the identity information of the user to be authenticated is obtained, and multi-factor authentication-based primary identity authentication is performed.

[0035] For example, in the identity authentication of business entities on a power trading platform, the authentication modes can include electronic business license authentication (i.e., the first authentication mode), a combination of non-electronic business license authentication and legal representative mobile phone verification code authentication (i.e., the second authentication mode), and a combination of non-electronic business license authentication and on-site authentication (i.e., the third authentication mode). High-risk business entities are automatically matched with the third authentication mode, medium-risk business entities are automatically matched with the second authentication mode, and low-risk business entities are automatically matched with the first authentication mode.

[0036] For example, if the business entity to be certified is of medium risk, it is necessary to obtain the user's multi-dimensional identity information according to the enterprise basic information maintenance process, the enterprise legal representative / operator information maintenance process, and the enterprise administrator information maintenance process in the second certification mode, so as to carry out first-level identity authentication.

[0037] Here, an application programming interface (API) is accessed through official channels to verify the business license and legal representative information of the operating entity in real time, ensuring the accuracy of identity authentication. Simultaneously, a backup API is set up; if the API accessing the official channel fails or is interrupted, data from the backup API is automatically called for comparison, ensuring the reliability of identity authentication.

[0038] Then, if Level 1 authentication is successful, the authentication risk level is assessed. This assessment can be based on factors such as the number of times the user submits identity information and the total authentication time to determine the user's completion level. This level of completion then determines the authentication risk level, allowing for the identification of potential abnormal behavior or risks and the discovery of problems in the authentication process. Authentication risk levels can also be categorized as high, medium, and low, or as Level 1, Level 2, Level 3, and Level 4, etc.

[0039] If the authentication risk level of Level 1 authentication exceeds the preset threshold, Level 2 authentication will be performed on the user to further ensure the reliability of authentication.

[0040] If the authentication risk level of Level 1 identity authentication is less than or equal to the preset threshold, then Level 1 identity authentication of the user is completed, the authentication result of the user to be authenticated is determined as successful, and the successful identity authentication result is sent to the terminal corresponding to the user to be authenticated. At the same time, the user to be authenticated is determined as an authenticated user.

[0041] Furthermore, as a refinement and extension of the specific implementation of the above embodiments, in order to fully illustrate the specific implementation process of this embodiment, secondary identity authentication based on authentication risk level includes: obtaining action instructions from a preset action library; combining the action instructions according to the authentication risk level to determine the action source sequence of the user to be authenticated; collecting image action information of the user to be authenticated based on the action source sequence of the user to be authenticated; determining the biometric features of the user to be authenticated based on the image action information of the user to be authenticated; and determining the authentication result of secondary identity authentication based on the comparison result between the biometric features of the user to be authenticated and the preset user feature library.

[0042] In this embodiment, action commands from a preset action library are obtained, and these commands are combined based on the authentication risk level to generate a user's action source sequence. Here, as the authentication risk level increases, the complexity of the action source sequence also increases, ensuring stricter identity verification in high-risk scenarios, effectively resisting security threats such as identity theft and fraud, and protecting the security of user information and transactions involved in the power trading platform. For example, high and medium levels require generating an action source sequence consisting of three action commands, while low levels require generating an action source sequence consisting of two action commands. Action commands include head shaking, looking left, looking right, blinking, opening mouth, and head shaking.

[0043] Furthermore, based on the action source series, the user to be authenticated is instructed to perform corresponding actions, thereby collecting the image action information of the user to be authenticated, extracting valid fragments from the image action information, and determining the biometric characteristics of the user to be authenticated, such as facial image information.

[0044] Then, the biometric features of the user to be authenticated are compared with a preset user feature database. The success of the first-level authentication is determined based on this comparison result. The uniqueness and stability of biometric features improve authentication accuracy and ensure the authenticity and reliability of the user's identity. For example, the biometric features of the user to be authenticated are uploaded to a public interface and compared with a reference biometric feature through official channels. If the degree of match between the user's biometric features and the reference biometric features is greater than a threshold, the second-level authentication is successful, and the successful authentication result is sent to the user's corresponding terminal. If the degree of match between the user's biometric features and the reference biometric features is less than or equal to the threshold, the second-level authentication fails, and the failure result is sent to the user's corresponding terminal.

[0045] In practical applications, if the user to be authenticated is a business entity, the image and action information of the legal representative of the business entity needs to be collected during the secondary identity authentication. This is in line with the complex scenario of the power trading platform involving various user entities, ensuring the reliability of the business entity's identity authentication, safeguarding the rights and interests of all parties involved in the transaction, and promoting the standardized and orderly operation of the power trading market.

[0046] In one embodiment, the method for identifying identity authentication risks in a power trading platform further includes: responding to an identity information change request sent by an authenticated user, determining the change risk level of the authenticated user based on the identity information change request; obtaining the authentication information of the authenticated user based on the verification mode corresponding to the change risk level; if the authentication information of the authenticated user matches the valid identity information corresponding to the authenticated user in the power trading platform, obtaining the change information of the authenticated user, and updating the valid identity information corresponding to the authenticated user in the power trading platform based on the change information.

[0047] In this embodiment, a zero-trust security architecture is adopted to authenticate and authorize all users and devices. For requests from authenticated users to change their identity information, secondary authentication is still required to ensure the safe and stable operation of the power trading platform.

[0048] Specifically, based on the information that an authenticated user wants to change, the risk level of the change is determined. Different verification modes are pre-matched to different risk levels to prevent malicious operations such as unauthorized alteration or misuse of identity information.

[0049] For example, a sudden change request from a long-inactive business entity may pose a higher risk. Furthermore, the type of information being changed matters; if it involves critical information such as company administrator information or bank account details, the risk level is higher than that of changes to general contact information. Similarly, the risk level of changes can be categorized into low, medium, and high.

[0050] Here, the verification mode can be set up with reference to the authentication mode. For example, high-risk changes require on-site verification, medium-risk changes require a combination of verification using a non-electronic business license and the mobile phone verification code of the legal representative and enterprise administrator, and low-risk changes only require the mobile phone verification code of the legal representative and enterprise administrator.

[0051] Furthermore, the system obtains the verification information required for the verification mode corresponding to the change risk level. If the verification information matches the valid identity information of the certified user in the power trading platform, the system obtains the change information of the certified user and updates the valid identity information of the certified user in the power trading platform according to the change information.

[0052] It is worth mentioning that, in addition to continuing to send identity information change requests to the power trading platform after logging in, to change their valid identity information on the power trading platform, verified users can also send identity information change requests directly to the power trading platform before logging in, thereby shortening the operation path for identity change.

[0053] Step 102: Obtain monitoring data of certified users within a preset monitoring period based on monitoring indicators.

[0054] The monitoring data is determined based on the operational behavior information generated by authenticated users during their access to the power trading platform.

[0055] In this embodiment, during the process of an authenticated user accessing the power trading platform, the authenticated user performs relevant operations. The power trading platform identifies the authenticated user's operational behavior, converts the operational behavior into operational behavior information, and stores the authenticated user's operational behavior information in the blockchain in the form of user operational behavior logs to prevent tampering. Therefore, the operational behavior information of the authenticated user can be obtained from the blockchain.

[0056] For example, taking a certified user as the operating entity, the user operation behavior log can record information such as the time, login method, login IP, login device, login result (success / failure), user operation time, operation type (registration, change, transaction, viewing, etc.), operation fields (legal representative's name, enterprise administrator's name, enterprise administrator's contact information, enterprise administrator's ID card, enterprise name, etc.), and operation result (success / failure).

[0057] Furthermore, based on preset risk rules, the operational behavior information of certified users is divided into multiple types, and corresponding monitoring indicators are set. The operational behavior information of certified users is used as the monitoring data of their respective monitoring indicators, thereby enabling targeted monitoring of the operational behavior of certified users according to the monitoring indicators, improving monitoring efficiency, and quickly identifying anomalies in massive user behavior data.

[0058] For specific examples, risk rules can be pre-set based on abnormal situations in actual application scenarios. For instance, for business entities, preset risk rules could be set to include frequent changes in enterprise administrators, logins outside of working hours, logins from different locations, frequent logins via different devices, frequent logins, short-term frequent use of pre-login change operations, and changes in enterprise administrators during non-working hours. Based on these preset risk rules, monitoring indicators can be set as login time, login IP, login frequency, login device, frequency of enterprise administrator changes, and frequency of pre-login change operations.

[0059] This allows for the acquisition of monitoring data for various monitoring indicators of certified users within a preset monitoring period from the blockchain, providing a data foundation for subsequent risk identification.

[0060] Here, the preset monitoring period can be set to different durations to achieve real-time and scheduled monitoring of authenticated users.

[0061] Step 103: Input the monitoring data of the monitoring indicators into the risk identification model corresponding to the monitoring indicators to determine the risk identification results of the certified users.

[0062] The risk identification model corresponding to the monitoring indicator is determined based on the historical normal data of the monitoring indicator within the historical monitoring period.

[0063] In this embodiment, the risk identification model corresponding to the monitoring indicator is determined in advance based on the historical normal data of the monitoring indicator in the historical monitoring period. The monitoring data of the monitoring indicator in the preset monitoring period is monitored by the risk identification model corresponding to the monitoring indicator, thereby improving the efficiency and accuracy of risk identification.

[0064] It should be noted that the duration of the historical monitoring period and the preset monitoring period must be the same to ensure the comparability and reliability of risk identification.

[0065] In one embodiment, the power trading platform identity authentication risk identification method further includes: preprocessing historical normal data of monitoring indicators; initializing the model parameters of a Gaussian mixture model, wherein the model parameters of the Gaussian mixture model include the mean vector, covariance matrix, and mixing weights of the Gaussian distribution in the Gaussian mixture model; calculating the posterior probability that the preprocessed historical normal data belongs to the Gaussian distribution; updating the model parameters of the Gaussian mixture model according to the posterior probability until the model parameters of the Gaussian mixture model reach a preset convergence condition; and determining the Gaussian mixture model whose model parameters reach the preset convergence condition as the risk identification model corresponding to the monitoring indicator.

[0066] In this embodiment, a Gaussian mixture model (GMM) is used as the risk identification model. By characterizing the probability distribution of normal behavioral data, data that deviates from the distribution is regarded as abnormal, thereby effectively detecting anomalies.

[0067] Here, the Gaussian mixture model is a probabilistic model used to represent a dataset consisting of multiple Gaussian distributions (normal distributions). The Gaussian mixture model assumes that each data point in the dataset is generated by one of several potential Gaussian distributions.

[0068] Specifically, the historical normal data of the monitoring indicators are preprocessed, such as feature extraction and feature standardization, to ensure that historical normal data of different dimensions are comparable.

[0069] Next, initialize the model parameters of the Gaussian mixture model, that is, set the mean vector, covariance matrix and mixture weights of each Gaussian distribution in the Gaussian mixture model.

[0070] Then, the hind lag probability, i.e., responsibility, is calculated for each preprocessed historical normal data point belonging to each Gaussian distribution.

[0071] For example,

[0072] in, Let be the probability that the i-th historical normal data is generated by the r-th Gaussian distribution in the t-th iteration. Let r be the mixed weights of the Gaussian distribution at the t-th iteration. x i This represents the i-th historical normal data after preprocessing. Let be the mean vector of the r-th Gaussian distribution at the t-th iteration. Let be the covariance matrix of the r-th Gaussian distribution during the t-th iteration.

[0073] Then, the calculated posterior probabilities are used to update the model parameters of the Gaussian mixture model, which are obtained by maximizing the log-likelihood estimate.

[0074] For example, updating the mixed weights is represented as:

[0075]

[0076] in, is the mixed weight of the r-th Gaussian distribution in the (t+1)-th iteration. This represents the total responsibility of all historical normal data for the r-th Gaussian distribution, where N is the number of historical normal data.

[0077] The updated mean vector is represented as:

[0078]

[0079] in, Let be the mean vector of the r-th Gaussian distribution at the (t+1)-th iteration.

[0080] The updated covariance matrix is ​​represented as:

[0081]

[0082] in, Let be the covariance matrix of the r-th Gaussian distribution in the (t+1)-th iteration.

[0083] Furthermore, it is checked whether the changes in model parameters or log-likelihood have reached a preset convergence condition (e.g., less than a certain threshold). If the convergence condition is met, the iteration stops; otherwise, the hind lag probability of each preprocessed historical normal data point belonging to each Gaussian distribution is recalculated based on the current model parameters. Finally, the Gaussian mixture model whose model parameters have reached the preset convergence condition is determined as the risk identification model corresponding to the monitoring indicator.

[0084] For example, the risk identification model p(x) corresponding to the monitoring indicator is expressed as:

[0085]

[0086] Where, π r Let r be the mixture weights of the r-th Gaussian distribution in p(x). μ r Let ∑ be the mean vector of the r-th Gaussian distribution in p(x). r Let be the covariance matrix of the r-th Gaussian distribution in p(x).

[0087] It is understandable that the higher p(x) is, the more the data x conforms to the normal pattern, and conversely, the lower p(x) is, the greater the possibility that the data x is abnormal.

[0088] Furthermore, as a refinement and extension of the specific implementation of the above embodiments, in order to fully illustrate the specific implementation process of this embodiment, the monitoring data of the monitoring indicators are input into the risk identification model corresponding to the monitoring indicators to determine the risk identification result of the certified users, including: inputting the historical normal data of the monitoring indicators into the risk identification model corresponding to the monitoring indicators to determine the probability density of the historical normal data; calculating the negative log-likelihood value of the probability density of the historical normal data to determine the first abnormal index of the historical normal data; sorting the first abnormal index of the historical normal data to obtain the first index order; obtaining the first quantile, and determining the first target position based on the number of the first quantile and the first abnormal index; determining the first abnormal index located in the first target position in the first index order as the first abnormal threshold of the monitoring indicators; inputting the monitoring data of the monitoring indicators into the risk identification model corresponding to the monitoring indicators to determine the monitoring probability density of the monitoring data; calculating the negative log-likelihood value of the monitoring probability density to determine the second abnormal index of the monitoring data; and determining the risk identification result of the certified users based on the comparison result of the second abnormal index and the first abnormal threshold.

[0089] In this embodiment, the Gaussian mixture model trained in the above embodiment, i.e. the risk identification model corresponding to the monitoring indicator, is used to calculate the negative log-likelihood value of the probability density of each historical normal data. The negative log-likelihood value is used as the first anomaly index of the historical normal data. The larger the value, the higher the probability of anomaly.

[0090] For example, Score 1i =-logp(x i Among them, Score 1i It is the first anomaly index of the i-th historical normal data.

[0091] Furthermore, the first anomaly index of the historical normal data is sorted from smallest to largest to obtain the first index order. Next, the quantile method is used to obtain the first quantile. Based on the first quantile and the number of first anomaly indices, the first target position is determined, and the first anomaly index in the first index order located at the first target position is determined as the first anomaly threshold of the monitoring indicator. For example, if the 95th quantile is selected, the first anomaly threshold of the monitoring indicator is the Score1 value at the 95th position after sorting, which is the first anomaly index value (i.e., the Score1 of 95% of the normal samples is less than this value). The remaining 5% of the historical normal data has a Score1 value greater than the threshold, but these are themselves normal data. At this point, this 5% is considered "normal fluctuations within the tolerable range".

[0092] Here, the first anomaly threshold of the monitoring indicator is a "tolerance limit" used to quantify the "acceptable degree of deviation from normal behavior". Data exceeding the first anomaly threshold is defined as "abnormal", even if they may be extreme cases of normal data.

[0093] Then, the monitoring data of the monitoring indicators are input into the risk identification model corresponding to the monitoring indicators to determine the monitoring probability density of the monitoring data. The negative log-likelihood value of the monitoring probability density is then calculated to determine the second anomaly index of the monitoring data. Here, the second anomaly index is calculated similarly to the first anomaly index and will not be elaborated further.

[0094] Furthermore, the second abnormality index of the monitoring data of the monitoring indicator is compared with the first abnormality threshold of the monitoring indicator. If the second abnormality index is greater than the first abnormality threshold, it is determined that the certified user has a risky abnormal operation in the monitoring indicator; otherwise, it is considered normal, thus obtaining the risk identification result of the certified user.

[0095] Furthermore, as a refinement and extension of the specific implementation of the above embodiments, in order to fully illustrate the specific implementation process of this embodiment, the monitoring data of the monitoring indicators are input into the risk identification model corresponding to the monitoring indicators, and the risk identification result of the certified users is determined, including: calculating the first distance between historical normal data of the monitoring indicators and the second distance between the monitoring data of the monitoring indicators and historical normal data based on a preset distance measurement method; sorting the first distance of the historical normal data and the second distance of the monitoring data to obtain a first distance order and a second distance order; determining the third abnormal index of the historical normal data based on the first distance in the first distance order that is located before the preset order; sorting the third abnormal index of the historical normal data to obtain a second index order; obtaining the second quantile, and determining the second target order based on the number of the second quantile and the third abnormal index; determining the third abnormal index in the second index order that is located in the second target order as the second abnormal threshold of the monitoring indicators; determining the fourth abnormal index of the monitoring data based on the second distance in the second distance order that is located before the preset order; and determining the risk identification result of the certified users based on the fourth abnormal index and the second abnormal threshold.

[0096] In this embodiment, a distance-based method is used, employing the k-nearest neighbor (KNN) algorithm to monitor the monitoring data of the monitoring indicators and effectively identify abnormal user operations.

[0097] Here, KNN is a "lazy learning" method that does not require explicit model training, but instead performs real-time distance calculations directly based on stored data.

[0098] Specifically, the historical normal data of the monitoring indicators within the historical monitoring period is stored in the risk identification model corresponding to the monitoring indicators as a reference dataset to determine the k-value (nearest neighbor number) and the distance measurement method (such as Euclidean distance or Manhattan distance). The data is standardized (e.g., Z-score) to avoid the influence of differences in units on distance calculation.

[0099] Furthermore, based on a preset distance metric, the first distance between historical normal data in the reference dataset is calculated. For any historical normal data, the k historical normal data with the smallest distance to it are found and taken as its first nearest neighbors. The average distance from the historical normal data to its k first nearest neighbors is calculated and used as the third anomaly index of the historical normal data (i.e., the first distances of the historical normal data are sorted to obtain a first distance order, and the third anomaly index of the historical normal data is determined based on the first distance that is located before the preset position in the first distance order).

[0100] For example, the third anomaly index Score of the i-th historical normal data. 3i Represented as: Where d(x) i ,x o ) represents the distance between the i-th historical normal data and its o-th first nearest neighbor data.

[0101] Then, the third anomaly index of all historical normal data is sorted to obtain the second index order. Next, the quantile method is used to obtain the second quantile, and the second target position is determined based on the second quantile and the number of third anomaly indices. The third anomaly index in the second index order that is located in the second target position is determined as the second anomaly threshold of the monitoring indicator.

[0102] Furthermore, for the monitoring data of the monitoring indicators, the second distance between the monitoring data and historical normal data is calculated, and the k historical normal data with the smallest distance to the monitoring data are found as its second nearest neighbor data. The average distance from the monitoring data to its k second nearest neighbors is calculated and used as the fourth anomaly index of the monitoring data (that is, the second distances of the monitoring data are sorted to obtain the second distance order, and the fourth anomaly index of the monitoring data is determined according to the second distance that is located before the preset position in the second distance order).

[0103] It should be noted that normal samples are usually clustered in dense areas and are relatively close to their neighbors; abnormal samples are sparsely distributed and are relatively far apart.

[0104] Next, the fourth anomaly index of the monitoring data is compared with the second anomaly threshold of the monitoring indicator. If the fourth anomaly index is greater than the second anomaly threshold, it is determined that the certified user has a risky abnormal operation in this monitoring indicator; otherwise, it is considered normal, thus obtaining the risk identification result of the certified user.

[0105] Here, the value of k is set according to the specific application scenario, for example, it can be set to 15.

[0106] It is worth mentioning that, in this embodiment, the first and second anomaly thresholds of the monitoring indicators can be updated periodically to adapt to changes in data distribution in actual application scenarios, such as changes in user behavior patterns, and the quantiles can be adjusted according to business needs (e.g., higher quantiles can be selected for high-risk scenarios).

[0107] Step 104: If the risk identification result is greater than the target threshold, trigger the warning operation corresponding to the risk identification result.

[0108] In this embodiment, risk identification results include abnormal and normal. Here, abnormal risk identification results are assessed for abnormal risk levels, and different warning actions corresponding to different abnormal risk levels are pre-set so that different abnormal risk levels can trigger different downstream business alerts or business controls. For example, the abnormal risk level can also be set to three levels: low risk, medium risk, and high risk. If the low risk is not greater than the target threshold, it can be logged. If the medium risk is greater than the target threshold, secondary authentication is triggered for medium risk and manual review is triggered for high risk. At the same time, the warning information for medium and high risks should also be promptly notified to relevant personnel through SMS, system pop-ups, etc. Thus, after abnormal operation is detected, the warning operation is triggered in a timely manner to ensure the stable operation of the power trading platform.

[0109] It should be noted that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0110] Furthermore, such as Figure 2 As shown, as a specific implementation of the above-mentioned power trading platform identity authentication risk identification method, this application embodiment provides a power trading platform identity authentication risk identification device 200, which includes: an authentication module 201, an identification module 202, and an early warning module 203.

[0111] The authentication module 201 is used to respond to the identity authentication request sent by the user to be authenticated and perform multi-level identity authentication on the user to be authenticated.

[0112] The identification module 202 is used to obtain monitoring data of authenticated users within a preset monitoring period based on monitoring indicators. The monitoring data is determined based on the operational behavior information generated by the authenticated users during their access to the power trading platform; and...

[0113] The monitoring data of the monitoring indicators are input into the risk identification model corresponding to the monitoring indicators to determine the risk identification results of the certified users. The risk identification model corresponding to the monitoring indicators is determined based on the historical normal data of the monitoring indicators in the historical monitoring period.

[0114] The early warning module 203 is used to trigger an early warning operation corresponding to the risk identification result if the risk identification result is greater than the target threshold.

[0115] In one embodiment, the authentication module 201 is specifically used to determine the user risk level of the user to be authenticated based on the user's historical behavior information and current behavior information; obtain the user's identity information based on the authentication mode corresponding to the user risk level, and perform first-level identity authentication; if the first-level identity authentication is successful, determine the authentication risk level of the first-level identity authentication; if the authentication risk level is less than or equal to a preset threshold, determine the authentication result of the user to be authenticated as successful, and determine the user to be authenticated as an authenticated user; if the authentication risk level is greater than the preset threshold, perform second-level identity authentication based on the authentication risk level.

[0116] In one embodiment, the authentication module 201 is specifically used to obtain action instructions from a preset action library; combine the action instructions according to the authentication risk level to determine the action source sequence of the user to be authenticated; collect image action information of the user to be authenticated based on the action source sequence of the user to be authenticated; determine the biometric features of the user to be authenticated based on the image action information of the user to be authenticated; and determine the authentication result of the secondary identity authentication based on the comparison result between the biometric features of the user to be authenticated and the preset user feature library.

[0117] In one embodiment, the power trading platform identity authentication risk identification device 200 further includes:

[0118] The change module is used to respond to identity information change requests sent by authenticated users, determine the change risk level of authenticated users based on the identity information change request, obtain the verification information of authenticated users based on the verification mode corresponding to the change risk level, and if the verification information of authenticated users matches the valid identity information of authenticated users in the power trading platform, obtain the change information of authenticated users, and update the valid identity information of authenticated users in the power trading platform according to the change information.

[0119] The training module is used to preprocess historical normal data of monitoring indicators; initialize the model parameters of the Gaussian mixture model, which includes the mean vector, covariance matrix, and mixture weights of the Gaussian distribution in the Gaussian mixture model; calculate the posterior probability that the preprocessed historical normal data belongs to the Gaussian distribution; update the model parameters of the Gaussian mixture model according to the posterior probability until the model parameters of the Gaussian mixture model reach the preset convergence condition; and determine the Gaussian mixture model whose model parameters reach the preset convergence condition as the risk identification model corresponding to the monitoring indicator.

[0120] In one embodiment, the identification module 203 is specifically used to input historical normal data of the monitoring indicator into the risk identification model corresponding to the monitoring indicator to determine the probability density of the historical normal data; calculate the negative log-likelihood value of the probability density of the historical normal data to determine the first abnormal index of the historical normal data; sort the first abnormal index of the historical normal data to obtain a first index order; obtain a first quantile and determine a first target position based on the number of the first quantile and the first abnormal index; determine the first abnormal index in the first index order that is located in the first target position as the first abnormal threshold of the monitoring indicator; input the monitoring data of the monitoring indicator into the risk identification model corresponding to the monitoring indicator to determine the monitoring probability density of the monitoring data; calculate the negative log-likelihood value of the monitoring probability density to determine the second abnormal index of the monitoring data; and determine the risk identification result of the authenticated user based on the comparison result of the second abnormal index and the first abnormal threshold.

[0121] In one embodiment, the identification module 203 is specifically configured to: calculate a first distance between historical normal data of the monitoring indicator and a second distance between the monitoring data of the monitoring indicator and historical normal data based on a preset distance measurement method; sort the first distance of the historical normal data and the second distance of the monitoring data to obtain a first distance order and a second distance order; determine a third abnormality index of the historical normal data based on the first distance that is located before the preset position in the first distance order; sort the third abnormality index of the historical normal data to obtain a second index order; obtain a second quantile and determine a second target position based on the number of the second quantile and the third abnormality index; determine the third abnormality index located in the second target position in the second index order as the second abnormality threshold of the monitoring indicator; determine a fourth abnormality index of the monitoring data based on the second distance that is located before the preset position in the second distance order; and determine the risk identification result of the authenticated user based on the fourth abnormality index and the second abnormality threshold.

[0122] Specific limitations regarding the identity authentication risk identification device for power trading platforms can be found in the limitations of the identity authentication risk identification method for power trading platforms mentioned above, and will not be repeated here. Each module in the aforementioned identity authentication risk identification device for power trading platforms can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0123] Based on the above, Figure 1 Accordingly, embodiments of this application also provide a readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described method. Figure 1 The method for identifying identity authentication risks in power trading platforms is shown.

[0124] Based on this understanding, the technical solution of this application can be embodied in the form of a software product. This software product can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or portable hard drive), and includes several instructions to cause a computer device (such as a personal computer, server, or network device) to execute the methods described in the various implementation scenarios of this application.

[0125] Based on the above, Figure 1 The method shown, and Figure 2 To achieve the above objectives, the present application also provides a computer device, specifically a personal computer, server, network device, etc., as shown in the virtual device embodiment. This computer device includes a storage medium and a processor; the storage medium stores a computer program; the processor executes the computer program to achieve the above-described objectives. Figure 1 The method for identifying identity authentication risks in power trading platforms is shown.

[0126] Optionally, the computer device may also include a user interface, a network interface, a camera, radio frequency (RF) circuitry, sensors, audio circuitry, a Wi-Fi module, etc. The user interface may include a display screen, input units such as a keyboard, etc., and optional user interfaces may also include USB interfaces, card reader interfaces, etc. The network interface may optionally include standard wired interfaces, wireless interfaces (such as Bluetooth interfaces, Wi-Fi interfaces), etc.

[0127] Those skilled in the art will understand that the computer device structure provided in this embodiment does not constitute a limitation on the computer device, and may include more or fewer components, or combine certain components, or have different component arrangements.

[0128] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages and stores the hardware and software resources of a computer device, supporting the operation of information processing programs and other software and / or programs. The network communication module is used to enable communication between the various components within the storage medium, as well as communication with other hardware and software within the physical device.

[0129] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platform, or the embodiments of this application can be implemented by hardware.

[0130] Those skilled in the art will understand that the accompanying drawings are merely schematic diagrams of a preferred embodiment, and the modules or processes shown in the drawings are not necessarily essential for implementing this application. Those skilled in the art will understand that the modules in the apparatus of the embodiment can be distributed within the apparatus of the embodiment as described, or can be modified to be located in one or more apparatuses different from this embodiment. The modules of the above-described embodiment can be combined into one module, or further divided into multiple sub-modules.

[0131] The serial numbers in this application are for descriptive purposes only and do not represent the superiority or inferiority of any particular implementation scenario. The above disclosures are merely a few specific implementation scenarios of this application; however, this application is not limited thereto, and any variations conceived by those skilled in the art should fall within the protection scope of this application.

Claims

1. A method for identifying identity authentication risks in an electricity trading platform, characterized in that, The method includes: In response to an authentication request sent by a user to be authenticated, multi-level authentication is performed on the user to be authenticated; The monitoring data of the certified users within a preset monitoring period is obtained based on the monitoring indicators. The monitoring data is determined based on the operational behavior information generated by the certified users during their access to the power trading platform. The monitoring data of the monitoring indicator is input into the risk identification model corresponding to the monitoring indicator to determine the risk identification result of the certified user. The risk identification model corresponding to the monitoring indicator is determined based on the historical normal data of the monitoring indicator in the historical monitoring period. If the risk identification result is greater than the target threshold, an early warning operation corresponding to the risk identification result is triggered.

2. The method for identifying identity authentication risks in a power trading platform according to claim 1, characterized in that, The multi-level identity authentication of the user to be authenticated includes: The user risk level of the user to be authenticated is determined based on the user's historical behavior information and current behavior information; Based on the authentication mode corresponding to the user risk level of the user to be authenticated, the identity information of the user to be authenticated is obtained, and first-level identity authentication is performed; If the Level 1 identity authentication is successful, determine the authentication risk level of the Level 1 identity authentication; If the authentication risk level is less than or equal to a preset threshold, the authentication result of the user to be authenticated is determined to be successful, and the user to be authenticated is determined to be the authenticated user. If the authentication risk level is greater than the preset threshold, secondary identity authentication is performed based on the authentication risk level.

3. The method for identifying identity authentication risks in a power trading platform according to claim 2, characterized in that, The secondary identity authentication based on the authentication risk level includes: Retrieve action instructions from the preset action library; The action instructions are combined according to the authentication risk level to determine the action source sequence of the user to be authenticated; Based on the action source series of the user to be authenticated, the image action information of the user to be authenticated is collected; Based on the image and action information of the user to be authenticated, the biometric characteristics of the user to be authenticated are determined; The authentication result of the secondary identity authentication is determined based on the comparison between the biometric features of the user to be authenticated and the preset user feature database.

4. The method for identifying identity authentication risks in a power trading platform according to claim 1, characterized in that, The method further includes: In response to the identity information change request sent by the authenticated user, the risk level of the change of the authenticated user is determined according to the identity information change request; Based on the verification mode corresponding to the change risk level, obtain the verification information of the authenticated user; If the verification information of the certified user matches the valid identity information corresponding to the certified user in the power trading platform, obtain the change information of the certified user, and update the valid identity information corresponding to the certified user in the power trading platform according to the change information.

5. The method for identifying identity authentication risks in a power trading platform according to claim 1, characterized in that, The method further includes: The historical normal data of the monitoring indicators are preprocessed; Initialize the model parameters of the Gaussian mixture model, wherein the model parameters of the Gaussian mixture model include the mean vector, covariance matrix and mixture weights of the Gaussian distribution in the Gaussian mixture model; Calculate the posterior probability that the preprocessed historical normal data belongs to the Gaussian distribution; The model parameters of the Gaussian mixture model are updated according to the posterior probability until the model parameters of the Gaussian mixture model reach the preset convergence condition. The Gaussian mixture model whose model parameters meet the preset convergence condition is determined as the risk identification model corresponding to the monitoring indicator.

6. The method for identifying identity authentication risks in a power trading platform according to claim 5, characterized in that, The step of inputting the monitoring data of the monitoring indicators into the risk identification model corresponding to the monitoring indicators to determine the risk identification result of the certified user includes: Input the historical normal data of the monitoring indicator into the risk identification model corresponding to the monitoring indicator to determine the probability density of the historical normal data; Calculate the negative log-likelihood value of the probability density of the historical normal data, and determine the first anomaly index of the historical normal data; The first abnormal index of the historical normal data is sorted to obtain the first index order; Obtain the first quantile, and determine the first target position based on the number of the first quantile and the first abnormal index; The first abnormal index that is located in the first target position in the first index sequence is determined as the first abnormal threshold of the monitoring indicator. The monitoring data of the monitoring indicators are input into the risk identification model corresponding to the monitoring indicators to determine the monitoring probability density of the monitoring data; Calculate the negative log-likelihood value of the monitoring probability density to determine the second anomaly index of the monitoring data; Based on the comparison between the second anomaly index and the first anomaly threshold, the risk identification result of the certified user is determined.

7. The method for identifying identity authentication risks in a power trading platform according to claim 1, characterized in that, The step of inputting the monitoring data of the monitoring indicators into the risk identification model corresponding to the monitoring indicators to determine the risk identification result of the certified user includes: Based on a preset distance measurement method, the first distance between the historical normal data of the monitoring indicator and the second distance between the monitoring data of the monitoring indicator and the historical normal data are calculated respectively. The first distance of the historical normal data and the second distance of the monitoring data are sorted respectively to obtain the first distance order and the second distance order; The third abnormality index of the historical normal data is determined based on the first distance that is located before the preset position in the first distance order; The third anomaly index of the historical normal data is sorted to obtain the second index order; Obtain the second quantile, and determine the second target position based on the number of the second quantile and the third abnormal index; The third abnormal index located in the second target position in the second index sequence is determined as the second abnormal threshold of the monitoring indicator; The fourth anomaly index of the monitoring data is determined based on the second distance that precedes the preset position in the second distance sequence; The risk identification result of the certified user is determined based on the fourth anomaly index and the second anomaly threshold.

8. A power trading platform identity authentication risk identification device, characterized in that, The device includes: The authentication module is used to perform multi-level authentication on the user to be authenticated in response to the authentication request sent by the user to be authenticated. An identification module is used to acquire monitoring data of authenticated users within a preset monitoring period based on monitoring indicators. The monitoring data is determined based on operational behavior information generated by the authenticated users during their access to the power trading platform. The monitoring data of the monitoring indicator is input into the risk identification model corresponding to the monitoring indicator to determine the risk identification result of the certified user. The risk identification model corresponding to the monitoring indicator is determined based on the historical normal data of the monitoring indicator in the historical monitoring period. The early warning module is used to trigger an early warning operation corresponding to the risk identification result if the risk identification result is greater than the target threshold.

9. A readable storage medium having a program or instructions stored thereon, characterized in that, When the program or instructions are executed by the processor, they implement the steps of the power trading platform identity authentication risk identification method as described in any one of claims 1 to 7.

10. A computer device, comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, When the processor executes the program, it implements the power trading platform identity authentication risk identification method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Identity authentication method and system

    CN109756458A

  • Personalized edge-cloud collaborative high-rise risk monitoring method

    CN118155112A

  • Risk behavior identification method and device

    CN118628254A

  • E-commerce platform high-risk user identification method based on time series data analysis

    CN119130539A

  • Abnormal data identification and cleaning method and system

    CN119272016A

Cited By

  • Authentication method and system for automobile collision digital human body model

    CN121302564A

  • A method and system for authenticating a digital human body model of a car crash

    CN121302564B

  • Intelligent identification and analysis method and system for data release risk

    CN121881161A

  • Database adaptive authentication method and system combined with meta-learning model

    CN121887550A