Electronic contract security risk assessment system based on dynamic multi-element identity authentication
By using dynamic multi-factor authentication and layered blockchain evidence storage technology, the problems of terminal credibility and risk assessment in electronic contract systems have been solved, enabling efficient and secure contract signing and judicial evidence generation, and improving the security and availability of the system.
Patent Information
- Application Number
- CN202511457261.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-13
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2045-10-13
AI Technical Summary
Existing electronic contract systems, under the multi-terminal, 24/7, and high-concurrency online signing mode, lack a comprehensive assessment of terminal credibility, consistency of operational behavior, and risks in the operating environment, leading to frequent occurrences of forged signatures and replay attacks. Blockchain-based evidence storage suffers from write latency and resource consumption issues, and lacks end-to-end evidence chains and risk linkage capabilities, resulting in low credibility of judicial evidence.
A dynamic multi-factor authentication module is used for real-time joint authentication. Combined with a real-time security risk scoring module, a layered blockchain evidence storage module, and a security behavior audit and risk linkage module, it enables real-time monitoring and evaluation of user identity, device trustworthiness, and operational behavior. On-chain writing is optimized through slip-block detection and layered evidence storage strategies, and a behavior audit and judicial linkage mechanism is introduced.
It achieves millisecond-level accurate authentication, reduces false alarm rate, improves the security, availability and compliance of the contract system, ensures a fast closed loop of data credibility → immediate evidence availability, solves the problems of on-chain write delay and resource consumption, and enhances judicial effectiveness.
Smart Images

Figure CN120934908A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of electronic contract security and blockchain evidence storage technology, and more specifically, to an electronic contract security risk assessment system based on dynamic multi-factor authentication. Background Technology
[0002] With the widespread application of electronic contracts in government services, financial credit, and supply chain collaboration, the contract signing process is shifting from traditional offline handwriting and single-point CA authentication to a multi-terminal, 24 / 7, high-concurrency online model. Existing technologies typically use static certificates or SMS verification codes for single-identity verification, lacking a comprehensive assessment of terminal trustworthiness, consistency of operational behavior, and operational environment risks, leading to frequent instances of forged signatures and replay attacks. On the other hand, while blockchain notarization provides a theoretical guarantee for the immutability of contracts, in embedded government terminals, the limited continuous write speed of on-chip flash memory and the lack of parallel I / O optimization in the file system can cause write command queuing delays during peak periods when a large number of contract texts and summaries are simultaneously written to the consortium blockchain, triggering chain write congestion and creating the potential risk of "successful process - data not linked." In addition, existing systems mostly store all signed data in a single-chain structure, with high-frequency small packets mixed with low-frequency large packets, which not only consumes on-chain resources but also reduces retrieval efficiency. Subsequent audits of contract access behavior mostly rely on server logs, lacking end-to-end evidence chains and risk linkage capabilities. When disputes arise and judicial evidence is required, enterprises often need to manually collect scattered data, which has a long submission cycle and low credibility.
[0003] To address the above problems, this invention proposes a solution. Summary of the Invention
[0004] To overcome the aforementioned deficiencies of the prior art, embodiments of the present invention provide an electronic contract security risk assessment system based on dynamic multi-factor authentication to address the problems raised in the background art.
[0005] To achieve the above objectives, the present invention provides the following technical solution: In a preferred embodiment, it includes: a dynamic identity aggregation and authentication module, a real-time security risk scoring module, a layered blockchain evidence storage module, a security behavior audit and risk linkage module, and signal connections between the modules; The dynamic identity aggregation authentication module is mainly used to perform real-time joint authentication of user identity legitimacy, device trustworthiness, and consistency of operational behavior before electronic contract signing is initiated; The real-time security risk scoring module is mainly used to perform near real-time security assessments on requests that are about to enter the signing stage and output the risk level. The layered blockchain evidence storage module is mainly used to handle the on-chain storage of raw data and efficient data structure management throughout the entire contract signing process; The security behavior audit and risk linkage module is mainly used to monitor the access, download, and sharing of contracts throughout their entire lifecycle after signing, and to perform security analysis and risk alerts for abnormal behaviors.
[0006] In a preferred embodiment, the dynamic identity aggregation authentication module calls the CA root certificate chain to perform an initial verification of the authenticity and validity of the certificate and the legitimacy of the user's identity, and then pulls user information to generate historical real-name authentication vectors. Audio and video data are collected and encapsulated into a unified structured recognition package along with historical real-name authentication vectors. Then, the matching degree is calculated and a matching degree threshold is set. When the matching degree is insufficient and an abnormal environment is detected, secondary authentication is triggered and the lip reading verification operation is completed.
[0007] In a preferred embodiment, the dynamic identity aggregation authentication module first determines whether the current chain write path is in a potentially congested state.
[0008] In a preferred embodiment, after determining a potential congestion state, the dynamic identity aggregation and authentication module triggers a chain write health check, as follows: Obtain the page write latency time series and the write queue depth series, and synchronize and align them to form a joint timing structure; Wavelet packet decomposition is performed on the page write delay time series to extract the instantaneous phase curve, and the difference between the instantaneous phase curve and the normalized derivative curve of the write queue depth sequence is calculated point by point to determine whether phase-locked slip occurs during the page write process and the queue speed increase.
[0009] In a preferred embodiment, the dynamic identity aggregation authentication module determines that after the page writing process and the queuing speed increase cause phase-locked slippage, it calculates the local maximum gradient of the Hilbert yellow envelope curve of the cross-channel phase difference vector to obtain the slippage intensity value under the current scheduling cycle.
[0010] In a preferred embodiment, in the dynamic identity aggregation authentication module, the current peak value of the slip intensity is taken as the geometric center, the page write completion mark is taken as the starting point of the window, and the double reversal position of the derivative of the write queue depth is taken as the ending point of the window. A local slip window is dynamically generated, and the time domain integration or weighted integration of the slip intensity value is performed according to the size of the local slip window. Finally, the integrated slip intensity value is multiplied by the Hilbert envelope average value of the write queue depth sequence within the same local slip window to calculate the write blocking index. The temporal and spatial distribution densities of the slip intensity within the same local slip window are analyzed. Based on the results of the slip concentration period and the corresponding write queue depth slope interval, the fractional difference strategy is dynamically adjusted to obtain high-sensitivity slip speed-up data, and the cache expansion rate is determined by combining its entropy density value.
[0011] In a preferred embodiment, the dynamic identity aggregation authentication module traces back the complete historical scheduling cycle to construct an initial observation window, gradually expands to the record fragments of key performance parameters recorded during the execution of multi-round chain write tasks under continuous and stable operating conditions, and calculates the relative change rate of the write blocking index and cache expansion rate fluctuation before and after the expansion. The length of the initial observation window is recorded when no new fluctuation inflection point is introduced in two consecutive expansions and the overall relative change rate remains monotonically decreasing. Extract the moving average sequence of write blocking index and cache expansion rate in the most recent N healthy operating cycles, and establish a fusion mean baseline trajectory. Then, use the standard deviation of each mean sequence as an expansion baseline, embed the mean of the other sequence into this sequence as a modulation factor, and form a bias correction band and an outer elastic buffer. Then, based on the coupling relationship between the fused mean sequence and the standard deviation of each mean sequence, the buffer width is dynamically calculated and an adaptive threshold is set. When the continuous scheduling cycle is detected to meet the requirement that both the write blocking index and the cache expansion rate exceed the adaptive threshold, the original write path is paused and the reference-text segmentation batching process is switched to execute. After the chain write congestion is relieved, the text content writing is resumed one by one.
[0012] In a preferred embodiment, the real-time security risk scoring module extracts a multi-dimensional structured feature package, including static identity legitimacy score, dynamic behavior deviation, current environmental risk weight, and historical contract risk label, to generate a dynamic risk score. Based on the scoring results, a hierarchical processing strategy is executed, and the scoring results and corresponding feature vectors are written into the risk control cache pool and the on-chain archive structure with a unique signature identifier.
[0013] In a preferred embodiment, the layered blockchain evidence storage module divides the data to be stored into high-frequency short-cycle data and core content data according to the generation frequency and judicial value, and writes them into the local consortium chain and cross-chain notary chain nodes respectively. Consistency verification is performed in high-concurrency scenarios. At the same time, a contract-level priority field and an indexable timestamp field are set in the on-chain data structure.
[0014] In a preferred embodiment, the security behavior audit and risk linkage module automatically collects access terminal information and uploads it to the behavior analysis center when the contract is opened. If it is determined to be a high-risk access, it immediately sends a multi-channel alarm to the user and freezes the subsequent access permissions of the contract.
[0015] The technical effects and advantages of this invention's electronic contract security risk assessment system based on dynamic multi-factor authentication are as follows: This invention significantly improves the security, availability, and compliance of electronic contract systems through a four-chain closed loop of identity, risk, evidence storage, and auditing. First, it achieves millisecond-level accurate authentication based on real-time fusion of multi-source real-name and liveness behavior matrices from public security, the People's Bank of China, and telecom operators, eliminating the risks of fake credentials and device drift. Second, it employs an incrementally trained XGBoost model and introduces three auxiliary features: WAF, DNS, and CVE, enabling adaptive identification of zero-day attacks and behavioral mutations, reducing the false positive rate to one-third of traditional rule-based methods. Third, the dual-chain layered evidence storage and zero-knowledge commitment mechanism balance write throughput and judicial validity, maintaining a 99.99% complete on-chain rate even in TPS ≥ threshold scenarios. Fourth, it introduces a slip-blocking detection and reference-text segmentation batching strategy to solve the bottleneck of continuous on-chip flash memory writes, improving the single-machine concurrency of government-grade embedded terminals. Fifth, behavioral auditing and judicial linkage can generate legally valid electronic judicial reports within one minute, achieving a rapid closed loop from data credibility to immediate evidence availability. Attached Figure Description
[0016] Figure 1 This is a schematic diagram of the electronic contract security risk assessment system module based on dynamic multi-factor authentication of the present invention.
[0017] Figure 2 This is a sequence diagram of the dynamic identity aggregation authentication module in the electronic contract security risk assessment system based on dynamic multi-factor identity authentication of the present invention. Detailed Implementation
[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] Example This invention discloses an electronic contract security risk assessment system based on dynamic multi-factor authentication, such as... Figure 1 As shown, it includes: a dynamic identity aggregation and authentication module, a real-time security risk scoring module, a layered blockchain evidence storage module, a security behavior audit and risk linkage module, and signal connections between the modules.
[0020] The dynamic identity aggregation authentication module is mainly used to perform real-time joint authentication of user identity legitimacy, device trustworthiness, and consistency of operational behavior before electronic contract signing is initiated.
[0021] Specifically, such as Figure 2As shown, when a signing request arrives, the CA root certificate chain pre-installed in the terminal trusted execution environment is first invoked to reverse-parse the signing certificate attached to the request message level by level and compare the issuer fingerprint with the revocation list to conduct the first round of confirmation of the authenticity and validity of the certificate and the legitimacy of the user's identity. After verification, the dynamic identity aggregation and authentication module retrieves the registered mobile phone number, ID card number, bank card number and real-name filing record in sequence through the public security population database, the People's Bank of China credit information interface, UnionPay card organization real-name verification service and the consistency verification service of the three major operators, and concatenates them on the gateway side to generate a historical real-name authentication vector. All calls are completed within the HTTPS-TLS 1.3 channel, and the timestamp returned by the interface is used as a vector index to ensure the traceability of the data source.
[0022] Furthermore, the dynamic identity aggregation authentication module concurrently invokes the terminal-side liveness detection SDK to collect the current camera image stream, microphone audio stream, and micro-interaction trajectories output by the touch / accelerometer sensor, generating a bio-behavioral feature matrix. This matrix, after being encrypted by the terminal-side AES-GCM, is encapsulated into a unified structured recognition package along with the historical real-name authentication vector.
[0023] The structured identification packet is then delivered to the central authentication processing engine via a dedicated QUIC lightweight channel. The terminal IP, MAC, device serial number and GPS coordinates are included during the handshake when the channel is established, serving as the benchmark for subsequent environmental consistency verification.
[0024] After receiving the structured recognition packet, the central authentication processing engine performs a semantic hash mapping between the historical real-name authentication vector and the biometric-behavioral feature matrix in memory, calculates the matching degree, and sets a matching degree threshold. If the matching degree is lower than the matching degree threshold, an environment anomaly prediction is triggered. If anomalies in environmental variables such as cross-regional IP login + first-time device combination, NTP time drift, and DNS spoofing are detected simultaneously, the dynamic identity aggregation authentication module immediately starts the secondary authentication mechanism, as follows: Random lip-reading recognition commands and matching lip-reading text are issued. Then, the terminal collects video-audio streams in real time. After on-device preprocessing, only key points of lip-reading and Mel-spectral coefficients of voiceprints are retained. The processing engine calls noise filtering and alignment algorithms based on bidirectional time series modeling to perform dynamic time-normalization comparison between the current lip-sync sequence and the registered template, and outputs confidence values. Set a security warning value. If the output confidence value is greater than or equal to the security warning value, the current operator is determined to be a legitimate user. Otherwise, the signing is rejected and a risk freeze code is returned.
[0025] After successful authentication, the dynamic identity aggregation authentication module packages the current CA verification result, historical real-name authentication hash, liveness detection digest, secondary authentication confidence value, terminal device information, and high-precision GPS coordinates into a reproducible evidence item. At the same time, the evidence item triggers a lightweight write to the contract on the consortium blockchain, which writes it to the local consortium blockchain node of the contract using a SHA-3 hash index and returns the on-chain transaction ID to the calling thread, forming a traceable structured signed identity chain.
[0026] It should be noted that when the electronic contract platform is deployed in an embedded government terminal with high-concurrency batch signing tasks, and the file system on the terminal does not have a parallel IO optimization mechanism, the continuous write capability of the on-chip embedded flash memory used in such embedded government terminals is limited. When processing multiple large-capacity contract text and hash digest data packets in a short period of time, write conflicts and intra-page addressing delays are frequently triggered. At the same time, because the signing requests are batch enqueued, the cache structure of the signing content used to write to the consortium blockchain node will be continuously filled, forming a buffer blockage. Affected by the above two factors, the original on-chain writing logic loses its continuous processing capability, causing multiple signing contents to remain in the local cache area. Although the dynamic identity aggregation and authentication module does not report an error, the core data in the evidence storage path has not actually been submitted on the blockchain, which manifests as a functional void where the process appears to be completed but the actual content is not on the blockchain.
[0027] Therefore, to address the issue of discontinuous on-chain write channels, this embodiment collects the real-time duration of written data residing in the chain write buffer, i.e., the buffer dwell time, and sets a time threshold. When the buffer dwell time exceeds the time threshold and the queuing depth of flash write commands, i.e., the number of write requests to be executed, shows a continuous upward trend, it is determined that the current chain write path is in a potentially congested state, triggering the chain write health detection sub-process, as follows: First, the page write completion flag output by the terminal flash controller is selected as the sampling anchor point. This flag is reported by the flash controller in the form of a hard interrupt when a page write is successful, and is used to identify the completion of an actual page write operation. Using this anchor point as a time reference, the page write delay time series formed by the time difference from write trigger to completion within the past minimum scheduling cycle, and the write queue depth sequence representing the change of the number of queued write instructions recorded in that cycle over time are synchronously aligned and expanded to form a joint timing structure. Then, the joint timing structure is projected onto the time-frequency ring manifold structure to form the basic observation unit for glide analysis.
[0028] It should be noted that the scheduling period represents the interval between one complete scheduling execution of resource reallocation and state refresh for the chain write task.
[0029] Subsequently, within each annular slice, wavelet packet decomposition is performed on the page write delay time series to obtain instantaneous signal features at multiple scales, and the instantaneous phase curve of the page write delay time series is extracted as a time evolution feature.
[0030] Next, the normalized derivative curve of the write queue depth sequence is calculated to quantify the queue expansion rate at each moment, and the difference is made point by point with the instantaneous phase curve to form a cross-channel phase difference vector. This vector captures the slip relationship between the phase of the page write delay and the queue growth rate.
[0031] If the cross-channel phase difference vector exhibits continuous phase shift drift within twice the Nyquist frequency band, it indicates that the page writing process and the queuing speed have experienced phase-locked slippage, meaning that the data page writing process and the write instruction enqueue rate are out of sync, causing the chain write execution rhythm to become desynchronized.
[0032] Subsequently, the cross-channel phase difference vector is input into the Hilbert-Huang Transform (HWT). First, a Hilbert transform is performed to extract the analytic signal. Then, Empirical Mode Decomposition (EMD) is used to construct a first-order Hilbert-Huang envelope, retaining only the first eigenmode, and the corresponding envelope curve is plotted. Gradient calculation is performed on this envelope curve to obtain its local maximum gradient peak. This peak is defined as the slip intensity value under the current scheduling cycle, used to characterize the degree of slippage caused by the imbalance between write latency and request backlog in the chain write path.
[0033] The first-order Hilbert yellow envelope refers to the envelope layer that retains only the first intrinsic mode after performing a Hilbert transform on the cross-channel phase difference vector and then using empirical mode decomposition.
[0034] Subsequently, taking the current peak slip intensity as the geometric center, we trace back and locate the most recent page write completion marker issued by the flash controller, and use it as the starting point of the window; we predict the derivative change trend of the write queue depth sequence, identify the next position where double derivative reversal occurs, that is, the derivative jumps twice, and use it as the end point of the window; and set a local slip window that is dynamically generated only when phase-locked slip is triggered. Subsequently, based on the sum of the time distances from the center point of the local slip window to the start and end points, the size of the local slip window is calculated and recorded. Then, considering the differences in slip energy accumulation corresponding to different local slip window sizes, a window size threshold is set. When the local slip window size is smaller than the window size threshold, the time domain integral of all slip intensity values within the local slip window is directly performed to obtain the original total slip. When the local slip window size is greater than or equal to the window size threshold, the time-weighted integral of all slip intensity values within the local slip window is performed, and higher weights are given to the time periods near the center, thereby emphasizing the main slip segment.
[0035] The integrated slip strength value is then multiplied by the envelope average value obtained by the Hilbert transform of the write queue depth sequence within the same local slip window to calculate the write blocking index Sblk, which is used to measure the blocking strength of the current write behavior. Simultaneously, the temporal and spatial distribution densities of the slip intensity within the same local slip window are analyzed to determine the main period of slip occurrence and its corresponding write queue depth interval. Specifically, in the time dimension, the local slip window is divided into M equal segments, and the slip intensity value in each segment is integrated to obtain the energy vector E_k. Then, the ratio ρ_T of E_k in the first half of the time zone to that in the second half of the time zone is calculated, and a ratio threshold θ_T is set. If ρ_T ≥ θ_T, the slip is marked as being concentrated in the first half of the window; otherwise, it is marked as being concentrated in the second half. In the spatial dimension, the write queue depth slope sequence that has been synchronously collected within the same local sliding window is used as the independent variable. The write queue depth slope sequence data at all time points are used to form a scatter group and perform adaptive two-threshold segmentation: the slope is lower than the median of the window and is regarded as a low slope region, and the slope is higher than the median and is classified as a high slope region. Then, the energy of the sliding intensity values of the two regions are accumulated to obtain the ratio ρ_S. The energy ratio threshold θ_S is set. When ρ_S≥θ_S, it means that the sliding is mainly concentrated in the low slope region, otherwise it is concentrated in the high slope region.
[0036] Based on the judgment results, a fractional-order differential regulator applies fractional-order differentials to the write queue depth sequence within the same local sliding window. Specifically, when the sliding intensity is concentrated in the first half of the local sliding window time axis and corresponds to a spatial distribution mainly concentrated in the low queue depth slope range, the fractional-order differential regulator automatically assigns higher-order differential weights to enhance the response to latent expansion regions. If the sliding intensity is concentrated in the second half of the local sliding window time axis and corresponds to a spatial distribution mainly concentrated in the high queue depth slope range, the fractional-order differential regulator automatically increases the order at the end of the window to strengthen the boundary detection capability for sudden write impacts.
[0037] Subsequently, high-sensitivity sliding growth rate data of the write queue depth sequence, which reflects the short-term dynamic change trend of the chain write channel, is obtained through differential calculation within the same local sliding window. Then, the high-sensitivity sliding growth rate data is combined with the entropy density value of the high-sensitivity sliding growth rate data, and the abnormal peaks that are not globally representative are eliminated by the short-term extreme value entropy suppression algorithm, and only the main growth trend with large entropy contribution is retained, thus forming the cache expansion rate Rc, an index that characterizes the short-term expansion rate of the cache, and is used to characterize the continuous expansion trend of the cache.
[0038] Among them, short-term extreme values refer to instantaneous peak values that occur within the time range of a local sliding window, in the queue depth sequence or in the high-sensitivity sliding acceleration data obtained from its fractional difference, with a duration of extremely short duration but a magnitude significantly higher than that of neighboring sample points.
[0039] Next, the initial observation window is constructed by tracing back the complete historical scheduling cycle. Based on the current scheduling cycle, the key performance parameter recording segments of the multi-round chain write task execution process recorded under continuous stable operation conditions are gradually expanded. The fluctuation degree of write blocking index and cache expansion rate before and after the expansion is compared, and the relative change rate of write blocking index and cache expansion rate before and after the expansion is calculated. When no new fluctuation inflection point is introduced in two consecutive expansions and the overall relative change rate remains monotonically decreasing, the expansion is terminated immediately, and the length N of the initial observation window at this time is recorded. Next, the moving averages of the write blocking index and cache expansion rate within the most recent N healthy operating cycles are extracted and formed into a mean sequence. The mean sequence is then fused with time decay weights, so that the data closer to the current scheduling cycle has a higher weight, thus establishing a fused mean baseline trajectory. Then, the standard deviation of each mean sequence is used as an extension benchmark, and the mean of the other sequence is embedded into the current sequence as a modulation factor to form a self-pulling deviation correction band.
[0040] An elastic buffer is added around the deviation correction band, and the write scheduling thread is called to synchronously read the standard deviation σ_S of the write blocking exponential moving average sequence and the standard deviation σ_R of the cache expansion rate moving average sequence, and the numerical normalization is completed in the same thread. Then, the buffer width is calculated in real time using the geometric coupling function: W=κ·√(σ_S·σ_R)·exp(λ·|log(σ_S / σ_R)|); where κ depends on the empirical lower limit of the average page write latency of the device flash memory, and λ is the sensitivity coefficient to the inconsistency of dispersion. If the standard deviation σ_S of the writing blocking exponential moving average sequence and the standard deviation σ_R of the buffer expansion rate moving average sequence are equal, then the geometric mean-dominated W expands uniformly in the proportion of √(σ_S·σ_R). If the difference between the two widens, the exponential adjustment term exp(λ·|log(σ_S / σ_R)|) rapidly amplifies W to ensure sufficient buffer space is maintained when unilateral fluctuations intensify. When the two contract synchronously or converge again, the exponential term tends to 1, and W automatically falls back to κ·√(σ_S·σ_R), thus forming an elastic threshold band that expands and contracts synchronously with the real-time dispersion, dynamically adjusting the buffer width.
[0041] Based on the adjusted buffer width, set an adaptive write blocking threshold Sth and a cache bloat threshold Rth.
[0042] During real-time operation, if consecutive scheduling cycles within a scheduling period satisfy the conditions that the write blocking exponent Sblk ≥ write blocking threshold Sth and the cache expansion rate Rc ≥ cache expansion threshold Rth, it is determined that a high congestion state has been entered. The original synchronous text write path is immediately suspended, and the reference-text segmentation and batching process is executed instead, as follows: Calculate the text hash digest, signature fingerprint, and metadata information of each contract content to be written, and merge them into a structured reference block; then write the reference block to the consortium chain node in a priority scheduling manner to ensure that the signing behavior chain loop is completed in a timely manner; subsequently, the text content is encapsulated into multiple text block groups according to the flash page alignment rules, cached in the off-chain area, and an index mapping table between reference blocks and text blocks is established on the chain.
[0043] When the write blocking index Sblk < write blocking threshold Sth and the cache expansion rate Rc < cache expansion threshold Rth are detected for two consecutive scheduling cycles, it is considered that the chain write congestion has been relieved. The write scheduling thread triggers the resumption of the write process, sequentially executing the integrity verification of the text block group, the parallel submission operation of the text content, and the structural closure update of the mapping relationship on the chain, so as to write the text blocks one by one to the consortium chain node and update the mapping state.
[0044] The real-time security risk scoring module is mainly used to perform near real-time security assessments on requests that are about to enter the signing stage and output risk levels, providing a basis for determining subsequent evidence storage levels and signing strategies.
[0045] Specifically, after completing dynamic identity aggregation authentication, the dynamic identity aggregation authentication module outputs a multi-dimensional structured feature package containing the current user authentication overview to the real-time security risk scoring module. This multi-dimensional structured feature package has a clear source, and all data in the package is generated in real-time by the upstream authentication process and transmitted encrypted via a lightweight channel. It specifically includes the following dimensions: The static identity legitimacy score is obtained by quantitatively mapping the CA root certificate chain verification result with the consistency verification results of real-name data from the public security bureau, the People's Bank of China, UnionPay, and telecom operators. The dynamic behavior deviation is dynamically calculated from the confidence level output by liveness detection, biometric matching, and secondary authentication, and the matching error between the registered template and the target confidence level. The current environmental risk weight is formed by combining the geographical region of the login IP, NTP time offset, DNS integrity status, and current terminal usage frequency as measured by the device. Historical contract risk tags are generated based on the number of abnormal contracts involved in past signing activities of the current account or device and their judicial status such as arbitration, tampering, and access alerts. Subsequently, the four main features mentioned above are sequentially input into a lightweight classification and regression hybrid model built on XGBoost. This model is pre-trained during the development phase and continuously undergoes online incremental training after the system goes live to adapt to the latest changes in risk behavior.
[0046] During model computation, three types of auxiliary input feature sources are accessed in parallel to enhance the model's ability to perceive novel attack behaviors, as detailed below: Intrusion behavior signature sequences from WAF protection systems; DNS record analysis results based on cross-regional behavior correlation, such as DNS rebinding, abnormal TTL, cross-border resolution, etc. The known CVE exposure level and patch status of the current terminal are pushed by the device firmware vulnerability scan.
[0047] Furthermore, after the main features and auxiliary features are integrated through nested nodes in the model, a unique numerical score result R is output, which is defined as a dynamic risk score. Based on the range of the score value R, a hierarchical processing logic is adopted. For example: if R∈[0,50], it is determined to be a low-risk contract request, and no additional measures are required; it can directly enter the signing process. If R∈(50,75], it is determined to be a medium-risk request, and it will automatically switch to the enhanced evidence storage chain mode, increasing the density of on-chain data fields, the frequency of signing trajectory recording, and the scope of behavioral evidence collection. If R>75, it is determined to be a high-risk request. At this time, the contract signing action is suspended, and the judicial linkage interface is triggered to enter the witness signing chain, where the judicial contract supervision completes identity re-authentication, behavior recording, and certificate mapping.
[0048] Meanwhile, the results of each risk control score, the input feature vector used, and the final classification result are all written to the local risk control cache pool and the archive structure on the contract chain, respectively, using the unique signature identifier of the current signing request as the primary key. This is for quick backtracking and link cascading, and is merged and written to the consortium chain node in a nested field manner to ensure that the scoring process has full-process review capability, input feature traceability, and classification result audit capability.
[0049] The layered blockchain evidence storage module is mainly used to handle the on-chain storage of original data throughout the contract signing process and to manage the data structure efficiently, ensuring the integrity, immutability, and auditability of the stored data.
[0050] Specifically, all data requiring evidence preservation is categorized into two types based on its generation frequency and judicial value: High-frequency, short-cycle data: including structured identity authentication results output by the dynamic identity aggregation and authentication module, current device behavior environment information, and temporary data such as lip reading / behavioral trajectory; Core content data includes key legal fields such as the main text of the contract, the digital signature generated during the signing process, the signature hash digest, the signing timestamp, and platform metadata.
[0051] Furthermore, for high-frequency, short-cycle data, it is uniformly written to the local consortium blockchain node, and a lightweight Merkle index structure is used to merge multiple high-frequency, short-cycle data into a unified time block, reducing the fragmentation problem within the chain.
[0052] For core content data, a distributed encrypted writing strategy is adopted to encapsulate this type of data and write it to the cross-chain notary chain node deployed in the cloud.
[0053] The cross-chain structure ensures the consistency of cross-regional contracts based on the joint BFT consensus protocol, and introduces the AES-CTR encrypted storage + RSA signature protection mechanism to ensure data storage security and source verifiability.
[0054] Next, the number of transaction submissions per second is monitored in real time. When the number of transaction submissions per second continues to exceed the threshold set adaptively by the platform's chain write scheduler based on the device's write capacity, it is necessary to generate hash commitment values for the core data fields, generate corresponding verification tokens for each commitment value, and write only the commitment value and verification token pair to the public chain node. The core plaintext data is temporarily cached in the off-chain secure storage area. When the original data is called later, the platform will automatically load the verification token and commitment value to perform zero-knowledge consistency verification, thereby achieving data validity verification without exposing the plaintext.
[0055] Furthermore, to enhance judicial retrieval capabilities and platform compliance, a contract-level priority field and an indexable timestamp field are introduced into the on-chain data structure. The contract-level priority field identifies the contract type and judicial weight level, and the system will prioritize the writing and reading of high-priority data blocks during scheduling. The indexable timestamp field is used to pinpoint the data writing time to the millisecond level and establishes a two-way mapping with the on-chain event table through the block timeline indexer. This enables contracts to be retrieved within seconds and their behavior trajectory to be automatically reconstructed upon judicial interface requests, allowing judicial authorities to quickly retrieve the original content and risk trajectory of contracts at any time after signing via an interface.
[0056] The security behavior audit and risk linkage module is mainly used to monitor the access, download, and sharing of contracts throughout their entire lifecycle after signing, and to perform security analysis and risk alerts for abnormal behaviors.
[0057] Specifically, after each contract is signed and submitted to the blockchain, a behavior audit listener is automatically bound to the contract. When the contract is opened, regardless of whether the visitor enters the correct security access code, a local behavior information collector is immediately started on the terminal side. The local behavior information collector then obtains the following information by calling the system interface: The device name and username of the current operating terminal; The currently assigned IP address and the latitude and longitude coordinates provided by the device location; The precise timestamp for opening the contract is provided by the system's internal unified clock.
[0058] The above information is then structured into a data packet locally and encapsulated and transmitted using the DNSoverHTTPS protocol. It is then transmitted to the behavior analysis center deployed in the cloud through a secure communication tunnel registered in the operating system's UNC path, avoiding tampering by local DNS caching or man-in-the-middle attacks, while ensuring that the behavior data can be received uniformly across the network.
[0059] The Behavioral Analysis Center is deployed independently of the electronic contract platform and possesses the following four core analytical capabilities: Whitelist verification capability: The received device information is compared item by item with the terminal identifiers recorded when the contract was signed. If the currently accessing device is not in the legal whitelist during the signing period, it is marked as high risk. Behavioral trajectory tracing capability: Based on contract access behavior and system timestamp sequence, automatically construct behavioral path map to identify whether the access conforms to normal geographical movement trajectory; Repeated access detection capability: Analyze the frequent access behavior of the same user to the contract. If multiple repeated opening behaviors occur in a short period of time and the device changes abnormally, a medium risk indicator will be triggered. Device anomaly push capability: In conjunction with the device fingerprint recognition system, when the access source is found to have characteristics such as emulator, jailbroken system, proxy server, etc., the system will automatically classify it as a high-risk behavior tag.
[0060] When the behavior analysis center determines, based on a comprehensive assessment of various dimensions, that the current behavior constitutes a high-risk access behavior, it immediately sends an SMS notification to the registered mobile phone of the user to whom the contract belongs; initiates a voice dialing alert to the associated user; and pops up a security alert window on the current access device, indicating that the user's current operation has been frozen.
[0061] At the same time, by calling the contract status interface in the blockchain, access to the current contract document is frozen immediately. All subsequent access attempts will be forcibly redirected to the contract security verification entry point, and access can only be unlocked after identity authentication and behavior confirmation are performed again.
[0062] In addition, the security behavior audit and risk linkage module provides a contract access log back function. Specifically, users can initiate an access log query request on the front-end interface by using the unique identifier of the contract. The system will retrieve the access history corresponding to the contract in the contract index structure and display the timestamp corresponding to each opening behavior in a time series format; access device and system identity; geographical location and access IP; and whether access alarms were triggered. Furthermore, after the electronic contract is signed, the contract's associated status, output by the real-time security risk scoring module, will be continuously linked to the real-time risk scoring indicators.
[0063] The certificate preparation process is triggered if any of the following conditions are detected: The risk score R exceeds the arbitration warning threshold; Users actively initiate the contract appeal process and explicitly request judicial verification. If multiple high-risk visits are detected, the platform will automatically enter the "arbitration" status. Subsequently, the system accesses the corresponding original evidence storage structure based on the unique identifier of the current contract, and extracts the necessary evidentiary data field by field to ensure that all materials originate from the authentic chain-written records of the signing process. This original evidence storage structure specifically contains the following entries: Signing log entries include: contract signing timestamp, signing process chain, signature status at each step, and signing IP and terminal ID recorded by the platform; Identity authentication records include CA certificate verification, consistency verification results of the four elements of public security, confidence level of biometric matching, secondary authentication process and lip reading results; Risk scoring labels and behavioral sequences: Risk score R generated by the XGBoost model, distribution map of scoring reasons, and access trajectory determination results output by the behavior analysis center; Abnormal Behavior Chain: Includes logs of all high-risk access time periods, access device fingerprints, IP geographical migration paths, and system alarm trigger results.
[0064] After extraction, the above items are structured and merged by the judicial evidence collection and packaging engine to form a unified and standardized electronic judicial report. This electronic judicial report is then pushed synchronously to the connected judicial service platform or online arbitration platform via the platform's own API interface.
[0065] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.
[0066] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, in the form of a computer program product.
[0067] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and inventive constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0068] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.
[0069] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0070] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An electronic contract security risk assessment system based on dynamic multi-factor authentication, characterized in that: include: The module includes a dynamic identity aggregation and authentication module, a real-time security risk scoring module, a layered blockchain evidence storage module, a security behavior audit and risk linkage module, and signal connections between the modules. The dynamic identity aggregation authentication module is mainly used to perform real-time joint authentication of user identity legitimacy, device trustworthiness, and consistency of operational behavior before electronic contract signing is initiated; The real-time security risk scoring module is mainly used to perform near real-time security assessments on requests that are about to enter the signing stage and output the risk level. The layered blockchain evidence storage module is mainly used to handle the on-chain storage of raw data and efficient data structure management throughout the entire contract signing process; The security behavior audit and risk linkage module is mainly used to monitor the access, download, and sharing of contracts throughout their entire lifecycle after signing, and to perform security analysis and risk alerts for abnormal behaviors.
2. The electronic contract security risk assessment system based on dynamic multi-factor authentication as described in claim 1, characterized in that: In the dynamic identity aggregation and authentication module, the CA root certificate chain is called to perform the first round of confirmation on the authenticity and validity of the certificate and the legitimacy of the user's identity, and then the user information is pulled to generate historical real-name authentication vectors. Audio and video data are collected and encapsulated into a unified structured recognition package along with historical real-name authentication vectors. Then, the matching degree is calculated and a matching degree threshold is set. When the matching degree is insufficient and an abnormal environment is detected, secondary authentication is triggered and the lip reading verification operation is completed.
3. The electronic contract security risk assessment system based on dynamic multi-factor authentication as described in claim 2, characterized in that: In the dynamic identity aggregation and authentication module, the first step is to determine whether the current chain write path is in a potentially congested state.
4. The electronic contract security risk assessment system based on dynamic multi-factor authentication as described in claim 3, characterized in that... In the dynamic identity aggregation and authentication module, after determining a potential congestion state, a chain write health check is triggered, as detailed below: Obtain the page write latency time series and the write queue depth series, and synchronize and align them to form a joint timing structure; Wavelet packet decomposition is performed on the page write delay time series to extract the instantaneous phase curve, and the difference between the instantaneous phase curve and the normalized derivative curve of the write queue depth sequence is calculated point by point to determine whether phase-locked slip occurs during the page write process and the queue speed increase.
5. The electronic contract security risk assessment system based on dynamic multi-factor authentication as described in claim 4, characterized in that: In the dynamic identity aggregation authentication module, after the page writing process and the queuing speed increase cause phase-locked slippage, the local maximum gradient of the Hilbert yellow envelope curve of the cross-channel phase difference vector is calculated to obtain the slippage intensity value under the current scheduling cycle.
6. The electronic contract security risk assessment system based on dynamic multi-factor authentication as described in claim 5, characterized in that: In the dynamic identity aggregation authentication module, the current peak value of the slip intensity is taken as the geometric center, the page write completion mark is taken as the starting point of the window, and the double reversal position of the derivative of the write queue depth is taken as the ending point of the window. Local slip windows are dynamically generated, and the time domain integration or weighted integration of the slip intensity value is performed according to the size of the local slip window. Finally, the integrated slip intensity value is multiplied by the Hilbert envelope average value of the write queue depth sequence within the same local slip window to calculate the write blocking index. The temporal and spatial distribution densities of the slip intensity within the same local slip window are analyzed. Based on the results of the slip concentration period and the corresponding write queue depth slope interval, the fractional difference strategy is dynamically adjusted to obtain high-sensitivity slip speed-up data, and the cache expansion rate is determined by combining its entropy density value.
7. The electronic contract security risk assessment system based on dynamic multi-factor authentication as described in claim 6, characterized in that: In the dynamic identity aggregation authentication module, the initial observation window is constructed by tracing back the complete historical scheduling cycle. It is then gradually expanded to the record fragments of key performance parameters recorded during the execution of multi-round chain write tasks under continuous and stable operating conditions. The relative change rate of the write blocking index and cache expansion rate fluctuation before and after the expansion is calculated. The length of the initial observation window is recorded when no new fluctuation inflection point is introduced in two consecutive expansions and the overall relative change rate remains monotonically decreasing. Extract the moving average sequence of write blocking index and cache expansion rate in the most recent N healthy operating cycles, and establish a fusion mean baseline trajectory. Then, use the standard deviation of each mean sequence as an expansion baseline, embed the mean of the other sequence into this sequence as a modulation factor, and form a bias correction band and an outer elastic buffer. Then, based on the coupling relationship between the fused mean sequence and the standard deviation of each mean sequence, the buffer width is dynamically calculated and an adaptive threshold is set. When the continuous scheduling cycle is detected to meet the requirement that both the write blocking index and the cache expansion rate exceed the adaptive threshold, the original write path is paused and the reference-text segmentation batching process is switched to execute. After the chain write congestion is relieved, the text content writing is resumed one by one.
8. The electronic contract security risk assessment system based on dynamic multi-factor authentication according to claim 7, characterized in that; In the real-time security risk scoring module, a multi-dimensional structured feature package is extracted, including static identity legitimacy score, dynamic behavior deviation, current environment risk weight and historical contract risk label, to generate a dynamic risk score. Based on the scoring results, a hierarchical processing strategy is executed, and the scoring results and corresponding feature vectors are written into the risk control cache pool and on-chain archive structure with a unique signature identifier.
9. The electronic contract security risk assessment system based on dynamic multi-factor authentication as described in claim 8, characterized in that: In the layered blockchain evidence storage module, the data to be stored is divided into high-frequency short-cycle data and core content data according to the generation frequency and judicial value, and written into the local consortium chain and cross-chain notary chain nodes respectively. Consistency verification is performed in high-concurrency scenarios. At the same time, contract-level priority fields and indexable timestamp fields are set in the on-chain data structure.
10. The electronic contract security risk assessment system based on dynamic multi-factor authentication as described in claim 9, characterized in that: In the security behavior audit and risk linkage module, access terminal information is automatically collected and uploaded to the behavior analysis center when the contract is opened. If it is determined to be a high-risk access, a multi-channel alarm will be immediately issued to the user and subsequent access to the contract will be frozen.
Citation Information
Patent Citations
Systems and methods for predicting an expected blockage of a signal path of an ultrasound signal
CN103959214A
Identity authentication method and device, and mobile terminal
CN109117688A
Contract trust digital signature method and device based on block chain
CN115760124A
Real name authentication method and device, equipment and storage medium
CN117615375A
Judicial system confidential data security circulation method based on block chain technology
CN120567451A