Electronic contract security risk assessment system based on dynamic multi-element identity authentication
By using dynamic multi-factor authentication and layered blockchain evidence storage technology, the problems of counterfeit signing and blockchain writing blockage in electronic contract systems have been solved, achieving efficient and secure contract signing and rapid generation of judicial evidence.
Patent Information
- Application Number
- CN202511457261.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-13
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2045-10-13
AI Technical Summary
Existing electronic contract systems, under the multi-terminal, 24/7, and high-concurrency online signing mode, lack a comprehensive assessment of terminal credibility, consistency of operational behavior, and risks in the operating environment, leading to frequent occurrences of forged signatures and replay attacks. Blockchain-based evidence storage suffers from write delays and resource waste, and lacks end-to-end evidence chains and risk linkage capabilities, resulting in difficulties in judicial evidence collection.
The system employs a dynamic multi-factor authentication module for real-time joint authentication, combined with a real-time security risk scoring module, a layered blockchain evidence storage module, and a security behavior audit and risk linkage module. This enables real-time monitoring and evaluation of user identity, device trustworthiness, and operational behavior. Through layered evidence storage and behavior auditing, the system's security and availability are enhanced.
It achieves millisecond-level accurate authentication, reduces false alarm rate, improves the security and availability of contract signing, ensures 99.99% data integrity on-chain rate, and generates legally valid electronic judicial reports within one minute, solving the problems of counterfeit signing and chain writing congestion.
Smart Images

Figure CN120934908B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of electronic contract security and blockchain evidence storage technology, and more specifically, to an electronic contract security risk assessment system based on dynamic multi-factor authentication. Background Technology
[0002] With the widespread application of electronic contracts in government services, financial credit, and supply chain collaboration, the contract signing process is shifting from traditional offline handwriting and single-point CA authentication to a multi-terminal, 24 / 7, high-concurrency online model. Existing technologies typically use static certificates or SMS verification codes for single-identity verification, lacking a comprehensive assessment of terminal trustworthiness, consistency of operational behavior, and operational environment risks, leading to frequent instances of forged signatures and replay attacks. On the other hand, while blockchain notarization provides a theoretical guarantee for the immutability of contracts, in embedded government terminals, the limited continuous write speed of on-chip flash memory and the lack of parallel I / O optimization in the file system can cause write command queuing delays during peak periods when a large number of contract texts and summaries are simultaneously written to the consortium blockchain, triggering chain write congestion and creating the potential risk of "successful process - data not linked." In addition, existing systems mostly store all signed data in a single-chain structure, with high-frequency small packets mixed with low-frequency large packets, which not only consumes on-chain resources but also reduces retrieval efficiency. Subsequent audits of contract access behavior mostly rely on server logs, lacking end-to-end evidence chains and risk linkage capabilities. When disputes arise and judicial evidence is required, enterprises often need to manually collect scattered data, which has a long submission cycle and low credibility.
[0003] To address the above problems, this invention proposes a solution. Summary of the Invention
[0004] To overcome the aforementioned deficiencies of the prior art, embodiments of the present invention provide an electronic contract security risk assessment system based on dynamic multi-factor authentication to address the problems raised in the background art.
[0005] To achieve the above objectives, the present invention provides the following technical solution:
[0006] In a preferred embodiment, it includes: a dynamic identity aggregation and authentication module, a real-time security risk scoring module, a layered blockchain evidence storage module, a security behavior audit and risk linkage module, and signal connections between the modules;
[0007] The dynamic identity aggregation authentication module is mainly used to perform real-time joint authentication of user identity legitimacy, device trustworthiness, and consistency of operational behavior before electronic contract signing is initiated;
[0008] The real-time security risk scoring module is mainly used to perform near real-time security assessments on requests that are about to enter the signing stage and output the risk level.
[0009] The hierarchical blockchain storage module is mainly used to undertake the original data on-chain and efficient data structure management in the whole process of contract signing.
[0010] The security behavior audit and risk linkage module is mainly used to monitor the behaviors of contract access, download, sharing and the like in the whole life cycle after contract signing, and to perform security analysis and risk warning on abnormal behaviors.
[0011] In a preferred embodiment, in the dynamic identity aggregation authentication module, the CA root certificate chain is called to perform first-round confirmation on the authenticity and validity period of the certificate and the legality of the user identity, and then the user information is pulled to generate a historical real-name authentication vector;
[0012] The audio and video data are collected, and the historical real-name authentication vector is encapsulated into a unified structured recognition package, and then the matching degree is calculated, and a matching degree threshold is set. When the matching degree is insufficient and the environment is abnormal, secondary authentication is triggered and a lip reading verification operation is completed.
[0013] In a preferred embodiment, in the dynamic identity aggregation authentication module, it is first determined whether the current chain writing path is in a potential congestion state.
[0014] In a preferred embodiment, in the dynamic identity aggregation authentication module, after determining the potential congestion state, chain writing health detection is triggered, specifically as follows:
[0015] The page writing delay time sequence and the write queue depth sequence are obtained and synchronized and aligned to form a joint time sequence structure;
[0016] The wavelet packet decomposition is performed on the page writing delay time sequence to extract an instantaneous phase curve, and the instantaneous phase curve is point-by-point subtracted from the normalized derivative curve of the write queue depth sequence to determine whether the writing page process and the queue growth rate have phase-locked slip.
[0017] In a preferred embodiment, in the dynamic identity aggregation authentication module, after determining that the writing page process and the queue growth rate have phase-locked slip, the local maximum gradient of the Hilbert-Huang envelope curve of the cross-channel phase difference vector is calculated to obtain the slip strength value in the current scheduling period.
[0018] In a preferred embodiment, in the dynamic identity aggregation authentication module, the time point at which the current slip strength peak value is located is taken as a geometric center, the page writing completion mark is traced back as a window starting point, and the double-reversal position of the write queue depth derivative is identified as a window endpoint, a local slip window is dynamically generated, and time domain integration or weighted integration of the slip strength value is performed according to the size of the local slip window. Finally, the integrated slip strength value is multiplied by the Hilbert envelope average value of the write queue depth sequence in the same local slip window to calculate the write blocking index.
[0019] The time distribution density and spatial distribution density of the slip strength in the same local slip window are analyzed, the high sensitivity slip acceleration data is obtained by dynamically adjusting the fractional order difference strategy according to the slip concentration period and the corresponding write queue depth slope interval result, and the cache inflation rate is determined by combining the entropy density value.
[0020] In a preferred embodiment, in the dynamic identity aggregation authentication module, the initial observation window is constructed by backtracking the history complete scheduling period, the key performance parameter record fragments in the multi-round chain write task execution process recorded under the condition of continuous stable operation are gradually expanded, and the relative change rate of the write blocking index and the cache inflation rate fluctuation degree before and after expansion is calculated. The initial observation window length is recorded when the continuous two expansions do not introduce new fluctuation inflection points and the overall relative change rate remains monotonically decreasing;
[0021] The sliding mean sequence of the write blocking index and the cache inflation rate in the last N health running periods is extracted, and a fusion mean benchmark trajectory is established. Then, the standard deviation of each mean sequence is used as an expansion benchmark, the mean of the other sequence is embedded in this sequence as a modulation factor, a deviation correction band and a peripheral elastic buffer zone are formed;
[0022] Then, based on the coupling relationship between the fusion mean sequence and the standard deviation of each mean sequence, the buffer width is dynamically calculated and the adaptive threshold is set. When it is detected that the write blocking index and the cache inflation rate exceed the adaptive threshold in the continuous scheduling period, the original write path is suspended, and the reference-text segmentation batch process is executed. After the chain write congestion is relieved, the text content writing is restored piece by piece.
[0023] In a preferred embodiment, in the real-time security risk scoring module, a multi-dimensional structured feature package including static identity legality score, dynamic behavior deviation, current environment risk weight and historical contract risk label is extracted, a dynamic risk score is generated, a hierarchical processing strategy is executed according to the score result, and the score result and the corresponding feature vector are written into the risk control cache pool and the on-chain archival structure with a unique signed identifier.
[0024] In a preferred embodiment, in the hierarchical blockchain storage module, the data to be stored is divided into high-frequency short-period data and core content data according to the generation frequency and judicial value, and is written into the local alliance chain and the cross-chain notarization chain node respectively. In high-concurrency scenarios, consistency checking is performed, and a contract-level priority field and an indexable timestamp field are set in the on-chain data structure.
[0025] In a preferred embodiment, in the security behavior audit and risk linkage module, when the contract is opened, the access terminal information is automatically collected and uploaded to the behavior analysis center. If it is determined to be a high-risk access, a multi-channel alarm is immediately sent to the user and the subsequent access permission of the contract is frozen.
[0026] The technical effects and advantages of this invention's electronic contract security risk assessment system based on dynamic multi-factor authentication are as follows:
[0027] This invention significantly improves the security, availability, and compliance of electronic contract systems through a four-chain closed loop of identity, risk, evidence storage, and auditing. First, it achieves millisecond-level accurate authentication based on real-time fusion of multi-source real-name and liveness behavior matrices from public security, the People's Bank of China, and telecom operators, eliminating the risks of fake credentials and device drift. Second, it employs an incrementally trained XGBoost model and introduces three auxiliary features: WAF, DNS, and CVE, enabling adaptive identification of zero-day attacks and behavioral mutations, reducing the false positive rate to one-third of traditional rule-based methods. Third, the dual-chain layered evidence storage and zero-knowledge commitment mechanism balance write throughput and judicial validity, maintaining a 99.99% complete on-chain rate even in TPS ≥ threshold scenarios. Fourth, it introduces a slip-blocking detection and reference-text segmentation batching strategy to solve the bottleneck of continuous on-chip flash memory writes, improving the single-machine concurrency of government-grade embedded terminals. Fifth, behavioral auditing and judicial linkage can generate legally valid electronic judicial reports within one minute, achieving a rapid closed loop from data credibility to immediate evidence availability. Attached Figure Description
[0028] Figure 1 This is a schematic diagram of the electronic contract security risk assessment system module based on dynamic multi-factor authentication of the present invention.
[0029] Figure 2 This is a sequence diagram of the dynamic identity aggregation authentication module in the electronic contract security risk assessment system based on dynamic multi-factor identity authentication of the present invention. Detailed Implementation
[0030] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0031] Example
[0032] This invention discloses an electronic contract security risk assessment system based on dynamic multi-factor authentication, such as... Figure 1 As shown, it includes: a dynamic identity aggregation and authentication module, a real-time security risk scoring module, a layered blockchain evidence storage module, a security behavior audit and risk linkage module, and signal connections between the modules.
[0033] The dynamic identity aggregation authentication module is mainly used to perform real-time joint authentication of user identity legitimacy, device trustworthiness, and consistency of operational behavior before electronic contract signing is initiated.
[0034] Specifically, such as Figure 2 As shown, when a signing request arrives, the CA root certificate chain pre-installed in the terminal trusted execution environment is first invoked to reverse-parse the signing certificate attached to the request message level by level and compare the issuer fingerprint with the revocation list to conduct the first round of confirmation of the authenticity and validity of the certificate and the legitimacy of the user's identity.
[0035] After verification, the dynamic identity aggregation and authentication module retrieves the registered mobile phone number, ID card number, bank card number and real-name filing record in sequence through the public security population database, the People's Bank of China credit information interface, UnionPay card organization real-name verification service and the consistency verification service of the three major operators, and concatenates them on the gateway side to generate a historical real-name authentication vector.
[0036] All calls are completed within the HTTPS-TLS 1.3 channel, and the timestamp returned by the interface is used as a vector index to ensure the traceability of the data source.
[0037] Furthermore, the dynamic identity aggregation authentication module concurrently invokes the terminal-side liveness detection SDK to collect the current camera image stream, microphone audio stream, and micro-interaction trajectories output by the touch / accelerometer sensor, generating a bio-behavioral feature matrix. This matrix, after being encrypted by the terminal-side AES-GCM, is encapsulated into a unified structured recognition package along with the historical real-name authentication vector.
[0038] The structured identification packet is then delivered to the central authentication processing engine via a dedicated QUIC lightweight channel. The terminal IP, MAC, device serial number and GPS coordinates are included during the handshake when the channel is established, serving as the benchmark for subsequent environmental consistency verification.
[0039] After receiving the structured recognition packet, the central authentication processing engine performs a semantic hash mapping between the historical real-name authentication vector and the biometric-behavioral feature matrix in memory, calculates the matching degree, and sets a matching degree threshold. If the matching degree is lower than the matching degree threshold, an environment anomaly prediction is triggered. If anomalies in environmental variables such as cross-regional IP login + first-time device combination, NTP time drift, and DNS spoofing are detected simultaneously, the dynamic identity aggregation authentication module immediately starts the secondary authentication mechanism, as follows:
[0040] Random lip-reading recognition commands and matching lip-reading text are issued. Then, the terminal collects video-audio streams in real time. After on-device preprocessing, only key points of lip-reading and Mel-spectral coefficients of voiceprints are retained.
[0041] The processing engine calls noise filtering and alignment algorithms based on bidirectional time series modeling to perform dynamic time-normalization comparison between the current lip-sync sequence and the registered template, and outputs confidence values.
[0042] A security warning value is set. If the output confidence value is greater than or equal to the security warning value, it is determined that the current operation subject is a legal user, otherwise the signature is rejected and a risk freezing code is returned.
[0043] After authentication, the dynamic identity aggregation authentication module packs the CA verification result, historical real-name authentication hash, liveness detection digest, secondary authentication confidence value, terminal device information and high-precision GPS coordinates into a reproducible evidence item; at the same time, the evidence item triggers the alliance chain lightweight write contract, writes the contract to the local alliance chain node with SHA-3 hash index, and returns the on-chain transaction ID to the calling thread, forming a traceable structured signing identity chain.
[0044] It should be noted that when the electronic contract platform is deployed in an embedded government terminal with high-concurrency batch signing tasks, and the terminal is equipped with a file system without parallel IO optimization mechanism, since the storage chip used inside such an embedded government terminal is an on-chip embedded flash memory, its continuous writing capability is limited, and when processing multiple large-capacity contract texts and hash digest data packets in a short period of time, write conflicts and in-page addressing delays are frequently triggered; at the same time, due to the batch queuing characteristics of the signing request, the signing content cache structure used to write the alliance chain node will be continuously filled, forming a buffer blockage, which is affected by the above two factors, causing the original on-chain writing logic to lose continuous processing capability, resulting in multiple signing contents being stranded in the local cache area, and although the dynamic identity aggregation authentication module does not report an error, the core data in the evidence storage path is actually not completed on-chain submission, which is manifested as a functional hollow that the surface process is completed but the actual content is not on-chain.
[0045] Therefore, to solve the problem of discontinuity of such on-chain writing channel, the present embodiment collects the residence duration of the written data in the chain writing cache area in real time, i.e. the cache residence time, and sets a time threshold, when it is detected that the cache residence time exceeds the time threshold, and the queuing depth of the flash write instruction, i.e. the number of pending write requests, shows a sustained upward trend, it is determined that the current chain writing path is in a potential congestion state, triggering the chain writing health detection sub-process, which is as follows:
[0046] First, the page write completion flag output by the terminal flash controller is selected as the sampling anchor point, which is reported by the flash controller in the form of a hard interrupt when the page write is successful, and is used to identify the completion of an actual page write action. With this anchor point as a time reference, the page write delay time series formed by the time difference from write triggering to completion in the past one minimum scheduling period, and the write queue depth series representing the change of the number of queued write instructions over time in that period are synchronized and unfolded to form a joint time sequence structure, and then the joint time sequence structure is projected into a time-frequency ring manifold structure to form a basic observation unit for sliding analysis.
[0047] It should be noted that the scheduling period represents a complete scheduling execution interval for resource reallocation and state refresh of the chain write task.
[0048] Subsequently, within each annular slice, wavelet packet decomposition is performed on the page write delay time series to obtain instantaneous signal features at multiple scales, and the instantaneous phase curve of the page write delay time series is extracted as the time evolution feature.
[0049] Next, the normalized derivative curve of the write queue depth sequence is calculated to quantify the queue expansion rate at each time, and the instantaneous phase curve is point-by-point differentiated to form a cross-channel phase difference vector, which captures the slip relationship between the phase of the page write delay and the queue expansion rate.
[0050] If the cross-channel phase difference vector has a persistent phase shift drift within the double Nyquist band, it indicates that the write page process and the queue expansion rate are in phase-locked slip, i.e., the data page write process and the write instruction queue rate are out of synchronization, causing the chain write execution rhythm to be out of synchronization.
[0051] Subsequently, the cross-channel phase difference vector is input into a Hilbert-Huang transformer, which first performs Hilbert transform to extract the analytic signal, and then uses empirical mode decomposition (EMD) to retain only the first intrinsic mode to construct a first-order Hilbert-Huang envelope, and draw the corresponding envelope curve. Gradient calculation is performed on the envelope curve to obtain its local maximum gradient peak value, which is defined as the slip intensity value at the current scheduling period, used to represent the slip degree caused by the imbalance between write delay and request accumulation in the chain write path.
[0052] Where the first-order Hilbert-Huang envelope refers to Hilbert transform of the cross-channel phase difference vector, and then retaining only the envelope layer of the first intrinsic mode by empirical mode decomposition.
[0053] Subsequently, the time point where the current slip intensity peak value is located is taken as the geometric center, and the latest page write completion flag issued by the flash controller is located by backtracking, which is taken as the window starting point; the derivative trend of the write queue depth sequence is predicted, and the position where the next double derivative inversion occurs, i.e., the derivative positive and negative jumps twice, is identified as the window endpoint, to set the local slip window generated dynamically only when the phase-locked slip is triggered;
[0054] Then, the size of the local slip window is calculated and recorded based on the sum of the time distances from the center point of the local slip window to the start point and the end point. Then, considering the difference in slip energy accumulation corresponding to different local slip window sizes, a window size threshold is set. When the size of the local slip window is less than the window size threshold, the time domain cumulative integral is directly performed on all slip intensity values in the local slip window to obtain the original slip total amount. When the size of the local slip window is greater than or equal to the window size threshold, the time weighted integral is performed on all slip intensity values in the local slip window, and higher weight is given to the center adjacent time period, so as to emphasize the main slip section.
[0055] Then, the integral slip intensity value is multiplied by the envelope average value of the write queue depth sequence in the same local slip window obtained by Hilbert transform to calculate the write blocking index Sblk, which is used to measure the blocking strength of the current write behavior.
[0056] At the same time, the time distribution density and the space distribution density of the slip intensity in the same local slip window are analyzed to determine the main concentration period of the slip and the corresponding write queue depth interval. Specifically, in the time dimension, the local slip window length is equally divided into M sections, and the integral of the slip intensity value in each section is performed to obtain the energy vector E_k. Then, the ratio ρ_T of E_k in the first half time zone and the second half time zone is calculated, and a proportion threshold θ_T is set. If ρ_T≥θ_T, it is marked that the slip is mainly concentrated in the first half of the window, otherwise it is marked as the second half.
[0057] In the spatial dimension, the write queue depth slope sequence synchronously collected in the same local slip window is taken as the independent variable, and adaptive two-threshold segmentation is performed on the scatter group composed of the write queue depth slope sequence data at all time points: the slope lower than the median is regarded as the low slope area, and the slope higher than the median is regarded as the high slope area. Then, the energy of the slip intensity values in the two areas is accumulated respectively to obtain the ratio ρ_S. When ρ_S≥θ_S, it is indicated that the slip is mainly concentrated in the low slope area, otherwise it is concentrated in the high slope area.
[0058] Based on the judgment result, a fractional order difference regulator is used to apply fractional order difference to the write queue depth sequence in the same local slip window. When the slip intensity is concentrated in the first half of the local slip window time axis and mainly concentrated in the low queue depth slope interval in the spatial distribution, the fractional order difference regulator automatically assigns a high order difference weight in front to enhance the response to the latent expansion area. If the slip intensity is concentrated in the second half of the local slip window time axis and mainly concentrated in the high queue depth slope interval in the spatial distribution, the fractional order difference regulator automatically increases the order of the weight at the tail of the window to enhance the boundary detection ability of the sudden write impact.
[0059] Afterwards, the high-sensitivity sliding acceleration data of the write queue depth sequence reflecting the short-term dynamic change trend of the chain write channel in the same local sliding window is obtained by difference, and then the high-sensitivity sliding acceleration data is combined with the entropy density value of the high-sensitivity sliding acceleration data, and the short-term extreme entropy suppression algorithm is used to eliminate abnormal peaks without global representation, and only the main acceleration trend with large entropy contribution is retained, thereby forming the cache inflation rate Rc representing the short-term inflation rate of the cache area, which is used to represent the continuous inflation trend of the cache area.
[0060] Wherein, the short-term extreme value represents a transient peak with extremely short duration but significantly higher amplitude than adjacent sample points in the write queue depth sequence or the high-sensitivity sliding acceleration data obtained by fractional order difference of the local sliding window.
[0061] Then, the initial observation window is constructed by looking back at the history of the complete scheduling period, and the current scheduling period is taken as the benchmark to gradually expand the key performance parameter record fragments recorded during the execution of multiple rounds of chain write tasks under continuous and stable running conditions. The write blocking index and cache inflation rate fluctuation degree before and after expansion are compared, and the relative change rate of the write blocking index and cache inflation rate fluctuation degree before and after expansion is calculated. When the continuous two expansions do not introduce new fluctuation inflection points and the overall relative change rate remains monotonically decreasing, the expansion is immediately terminated, and the initial observation window length N at this time is recorded.
[0062] Afterwards, the sliding mean values of the write blocking index and cache inflation rate in the last N healthy running periods are extracted and composed into mean value sequences, and fusion is performed with time decay weight, so that the data closer to the current scheduling period has higher weight, and a fusion mean reference track is established. Then, the standard deviation of each mean value sequence is taken as the expansion reference, and the mean value of the other sequence is embedded into the current sequence as a modulation factor to form a self-pulling deviation correction band.
[0063] An elastic buffer zone is added to the periphery of the deviation correction band, and the standard deviation σ_S of the sliding mean value sequence of the write blocking index and the standard deviation σ_R of the sliding mean value sequence of the cache inflation rate are synchronously read by the write scheduling thread, and the numerical normalization is completed in the same thread. Then, the buffer width is calculated in real time by the geometric coupling function: W=κ·√(σ_S·σ_R)·exp(λ·|log(σ_S / σ_R)|); where κ depends on the empirical lower limit of the average delay of the device flash write page, and λ is the sensitivity coefficient to the inconsistency of dispersion;
[0064] If the standard deviation of the write blocking index sliding mean sequence σ_S and the standard deviation of the cache expansion rate sliding mean sequence σ_R, then the geometric mean dominates W by √(σ_S·σ_R) proportional uniform expansion; if the difference is enlarged, then the exponential adjustment term exp(λ·|log(σ_S / σ_R)|) quickly amplifies W, ensuring that there is still enough buffer space when the unilateral fluctuation intensifies; when the two are synchronized to shrink or re-approach, the exponential term tends to 1, and W automatically falls back to κ·√(σ_S·σ_R), thereby forming an elastic threshold band that synchronously stretches and contracts with real-time dispersion, dynamically adjusting the buffer width.
[0065] Based on the adjusted buffer width, set the adaptive write blocking threshold Sth and the cache expansion threshold Rth.
[0066] In the real-time running phase, if it is detected that the write blocking index Sblk≥ write blocking threshold Sth and the cache expansion rate Rc≥ cache expansion threshold Rth in the continuous scheduling period within the scheduling period, it is determined that the high congestion state is entered, the original text synchronization writing path is immediately suspended, and the reference-text segmentation batch process is executed instead, as follows:
[0067] Calculate the text hash digest, signature fingerprint, and metadata information of each contract content to be written, merge them to form a structured reference block, and write the reference block to the alliance chain node in a priority scheduling manner to ensure that the signature behavior chain closed loop is completed in time; then, the text content is packaged into multiple text block groups according to the flash page alignment rule and cached in the off-chain area, and an index mapping table between the reference block and the text block is established on the chain.
[0068] When the write blocking index Sblk< write blocking threshold Sth and the cache expansion rate Rc< cache expansion threshold Rth are continuously monitored for two periods, it is considered that the chain writing congestion has been alleviated, and the write scheduling thread triggers the recovery of the writing process, sequentially performs the integrity verification of the text block group, the parallel submission operation of the text content, and the structure closure update of the mapping relationship on the chain, and realizes the writing of the text block into the alliance chain node and the update of the mapping state.
[0069] The real-time security risk scoring module is mainly used for real-time security evaluation of the request about to enter the signing link and outputs the risk level, which provides the basis for the subsequent evidence level and signing strategy.
[0070] Specifically, after completing the dynamic identity aggregation authentication, the dynamic identity aggregation authentication module outputs a multi-dimensional structured feature package containing the current user authentication panorama to the real-time security risk scoring module. The multi-dimensional structured feature package has clear sources, and all data in the multi-dimensional structured feature package is generated in real time by the upstream authentication process and transmitted through a lightweight channel encryption, which includes the following dimensions:
[0071] The static identity legality score obtained by quantitatively mapping the verification result of the CA root certificate chain and the consistency verification result of the four-party real-name data of public security, the People's Bank of China, China UnionPay and operators;
[0072] The dynamic behavior deviation degree dynamically calculated from the confidence output by the living body detection, biological feature matching and secondary authentication, and the matching error of the registered template;
[0073] The current environment risk weight formed by the geographical area of the login IP measured by the device end, the NTP time offset, the DNS integrity state and the current terminal usage frequency;
[0074] The historical contract risk label generated based on the number of abnormal contracts involved in the past signing behavior of the current account or device identifier and the judicial status such as arbitration, tampering and access alarm;
[0075] Then, the above four types of main features are sequentially input into the lightweight classification regression mixed model based on XGBoost, wherein the model is pre-trained during the development stage and continuously performs online incremental training after the system goes online to adapt to the latest risk behavior changes.
[0076] During the model calculation process, three types of auxiliary input feature sources are accessed in parallel to enhance the model's perception of new attack behaviors, as follows:
[0077] Intrusion behavior signature sequence from WAF protection system;
[0078] DNS record analysis results based on off-site behavior correlation, such as DNS rebinding, abnormal TTL, cross-border resolution, etc.
[0079] The current terminal known CVE exposure degree and patch state pushed by the device firmware vulnerability scanning.
[0080] Further, after the main features and auxiliary features are integrated through model nested nodes, the output is a unique numerical score result R, defined as a dynamic risk score. According to the interval of the score value R, a hierarchical processing logic is adopted, for example: if R∈[0,50], it is determined as a low-risk contract request, no additional measures are needed, and it can directly enter the signing process; if R∈(50,75], it is determined as a medium-risk request, which will automatically switch to the enhanced evidence chain mode, increasing the density of on-chain data fields, the frequency of signing track records and the scope of behavior evidence; if R>75, it is determined as a high-risk request, at which time the contract signing action is suspended, and the judicial linkage interface is triggered to cut into the witnessed signing link to complete identity re-authentication, behavior recording and evidence mapping under the supervision of the judicial contract.
[0081] Meanwhile, the result of each risk control score, the input feature vector used, and the final classification result are written into the local risk control cache pool and the archiving structure on the contract chain with the unique signing identifier of the current signing request as the primary key, for quick review and link concatenation, and are written into the alliance chain node in a nested field manner, ensuring that the scoring process has full-process review capability, input feature traceability, and classification result audit capability.
[0082] The hierarchical blockchain storage module is mainly used to undertake the original data on-chain and efficient data structure management in the entire contract signing process, ensuring the integrity, non-tamperability, and auditability of the stored data.
[0083] Specifically, all data to be stored are classified into two categories according to their generation frequency and judicial value:
[0084] High-frequency short-period data: including structured identity authentication results output by the dynamic identity aggregation authentication module, current device behavior environment information, and temporary data such as lip reading / behavior trajectory;
[0085] Core content data: including contract text content, digital signature generated during the signing process, signature hash digest, signing timestamp, and platform metadata.
[0086] Further, for high-frequency short-period data, unified writing is performed into the local alliance chain node, and a lightweight Merkle index structure is used to merge multiple high-frequency short-period data into a unified time slice block, reducing the fragmentation problem in the chain.
[0087] For core content data, a distributed encryption writing strategy is adopted, and the data is encapsulated and written into a cross-chain notarization chain node deployed in the cloud.
[0088] Among them, the cross-chain structure is based on a joint BFT consensus protocol to ensure the consistency of cross-regional contracts, and introduces an AES-CTR encryption storage + RSA signature protection mechanism to ensure data storage security and source verifiability.
[0089] Then, the number of transactions submitted per second is monitored in real time. When the number of transactions submitted per second continuously exceeds the threshold value set by the platform chain writing scheduler according to the device writing capability, a hash commitment value is generated for the core data field, a corresponding verification token is generated for each commitment value, and only the commitment value and the verification token are written into the public chain node. The core plaintext data is temporarily cached in the off-chain secure storage area; when the original data is called later, the platform will automatically load the verification token and the commitment value to perform zero-knowledge consistency verification, thereby completing the data validity verification without exposing the plaintext.
[0090] In addition, to improve the judicial access ability and platform compliance, a contract-level priority field and an indexable timestamp field are introduced in the on-chain data structure. The contract-level priority field is used to identify the contract type and judicial weight level, and the system will prioritize processing data block writing and reading with high priority. The indexable timestamp field is used to accurately record the data writing time to the millisecond level, and through the block timeline indexer and the on-chain event table, a bidirectional mapping is established to enable the contract to be retrieved and the behavior track to be automatically restored within seconds upon request from the judicial interface, so that the contract can be quickly accessed by the judicial authority to retrieve the original content and risk track at any time after signing.
[0091] The security behavior audit and risk linkage module is mainly used to monitor the behaviors of accessing, downloading, and sharing the contract during the whole life cycle after signing, and to perform security analysis and risk warning on abnormal behaviors.
[0092] Specifically, after each contract is signed and submitted to the blockchain, a behavior audit listener is automatically bound to the contract. When the contract is opened, whether the visitor inputs the correct security access code or not, the local behavior information collector is immediately started on the terminal side, and then the local behavior information collector obtains the following information by calling the system interface:
[0093] The device name and username of the current operating terminal;
[0094] The IP address allocated by the current public network and the latitude and longitude coordinates provided by the device positioning;
[0095] The precise timestamp of opening the contract, provided by the system's internal unified clock.
[0096] Then the above information is formed into a structured data packet locally, and is transmitted by encapsulating and transmitting it using the DNSoverHTTPS protocol, through the secure communication tunnel registered in the operating system UNC path, to the behavior analysis center deployed in the cloud, avoiding tampering by local DNS caching or man-in-the-middle attacks, while ensuring that behavior data can be received uniformly across networks.
[0097] Among them, the behavior analysis center is independent of the electronic contract platform and has the following four core analysis capabilities:
[0098] White list verification capability: compare the received device information with the terminal identifiers recorded during contract signing, and if the current access device is not in the legal white list during the signing period, it is marked as high risk;
[0099] Behavior track tracing capability: based on the contract access behavior and system timestamp sequence, automatically build a behavior path graph to identify whether the access conforms to the normal geographic movement track;
[0100] Repeated access detection capability: statistics the frequent access behavior of the same user to the contract, if multiple repeated opening behaviors occur in a short time and the device changes abnormally, the moderate risk identification is triggered;
[0101] Device abnormality pushing capability: linkage device fingerprint identification system, when it is found that the access source has characteristics such as simulator, jailbroken system, proxy server, etc., the system automatically belongs to high-risk behavior label.
[0102] When the behavior analysis center comprehensively judges that the current behavior conforms to the high-risk access behavior in all dimensions, it immediately sends a short message to the contract belonging to the user's registered mobile phone, initiates voice dialing alarm to the associated user, and pops up a security alarm window on the current access device, prompting the user that the current operation has been frozen.
[0103] At the same time, by calling the contract state interface in the block chain, the access permission of the current contract document is frozen immediately, and all subsequent access attempts will be forced to be redirected to the contract security check entry, and the access can be unlocked after re-identifying and confirming the behavior.
[0104] In addition, the security behavior audit and risk linkage module provides a contract access log backtracking function. Specifically, the user can initiate an access log query request in the front-end interface according to the unique identifier of the contract, the system will retrieve the access history record corresponding to the contract in the contract index structure, and display the time stamp corresponding to each opening behavior, access device and system identity, geographic location and access IP, and whether the access alarm is triggered in time sequence;
[0105] Further, after the electronic contract is signed, the contract associated state output by the real-time security risk scoring module and the real-time risk score index are continuously linked.
[0106] When any of the following conditions is detected, the certificate preparation process is triggered:
[0107] The risk score R exceeds the arbitration warning threshold;
[0108] The user actively operates into the contract complaint process and explicitly initiates a judicial verification request;
[0109] It is determined that there are multiple high-risk accesses, and the platform automatically enters the "arbitration in progress" state;
[0110] Subsequently, according to the unique identifier of the current contract, the original evidence structure body corresponding thereto is entered, and the judicial evidence data required is extracted field by field to ensure that all materials come from the real chain record in the signing process. The original evidence structure body specifically includes the following entries:
[0111] Signing log entry: contains contract signing timestamp, signing process chain, signature state of each step, and platform recorded signing IP and terminal ID;
[0112] Identity authentication record: including CA certificate verification, consistency verification result of four elements of public security, biometric feature matching confidence, secondary authentication process and lip reading result;
[0113] Risk score label and behavior sequence: risk score R generated by XGBoost model, score reason distribution diagram, access track judgment result output by behavior analysis center;
[0114] Behavior anomaly chain: contains all high-risk access time periods, access device fingerprints, IP geographic drift paths and system alarm triggering results, etc.
[0115] The above items are structured and merged by the judicial evidence packaging engine after extraction to form a unified and standardized electronic judicial report. The electronic judicial report is synchronized and pushed to the connected judicial service platform or online arbitration platform through the platform's own API interface.
[0116] The above formulas are dimensionless values calculated. The formulas are obtained by software simulation of a large number of data to obtain a formula of the most recent real situation. The preset parameters in the formula are set by a person skilled in the art according to the actual situation.
[0117] The above embodiments can be realized wholly or partially by software, hardware, firmware or any other combination. When realized by software, the above embodiments can be realized wholly or partially in the form of a computer program product.
[0118] Those skilled in the art can realize that the modules and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application of the technical solution and the constraints of the application. A person skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0119] In addition, the functional modules in each embodiment of the present application can be integrated in one processing module, or each module can exist physically alone, or two or more modules can be integrated in one module.
[0120] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0121] Finally: the above only for the preferred embodiments of the present application, and not for limiting the present application, any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application, should be included in the scope of protection of the present application.
Claims
1. An electronic contract security risk assessment system based on dynamic multi-factor identity authentication, characterized in that, Comprise: Dynamic identity aggregation authentication module, real-time security risk scoring module, hierarchical blockchain storage module, security behavior audit and risk linkage module, signal connection between modules; The dynamic identity aggregation authentication module is used for real-time joint authentication of user identity legality, device trustworthiness and operation behavior consistency before the initiation of electronic contract signing; The real-time security risk scoring module is used for real-time security evaluation of the request about to enter the signing link and output of risk level; The hierarchical blockchain storage module is used for original data on-chain and efficient data structure management in the whole process of contract signing; The security behavior audit and risk linkage module is used for monitoring the contract access, download and sharing behavior in the whole life cycle after the contract signing, and performing security analysis and risk warning on abnormal behavior; In the dynamic identity aggregation authentication module, after determining the potential congestion state, trigger the blockchain write health detection, as follows: perform wavelet packet decomposition on the page write delay time sequence formed by the time difference from write triggering to completion to extract the instantaneous phase curve, and calculate the local maximum gradient of the Hilbert Huang envelope curve of the cross-channel phase difference vector by point-by-point difference between the normalized derivative curve of the write queue depth sequence and the instantaneous phase curve, to obtain the slip intensity value in the current scheduling period; take the time point where the current slip intensity peak value is located as the geometric center, dynamically generate a local slip window, and perform integration according to the size of the local slip window, and finally multiply the integrated slip intensity value by the Hilbert envelope average value of the write queue depth sequence in the same local slip window to calculate the write blocking index; analyze the time distribution density and spatial distribution density of the slip intensity in the same local slip window, dynamically adjust the fractional difference strategy to obtain high-sensitivity sliding speed-up data, and determine the cache expansion rate combined with its entropy density value; extract the sliding mean sequence of the write blocking index and the cache expansion rate in the last N healthy operation periods, and establish a fusion mean reference track, and then dynamically calculate the buffer width based on the coupling relationship between the fusion mean sequence and the standard deviation of each mean sequence and set an adaptive threshold, when the detection of consecutive scheduling periods meets the condition that both the write blocking index and the cache expansion rate exceed the adaptive threshold, suspend the original write path and switch to the reference-text segmentation and batch process, and then restore the text content writing one by one after the chain write congestion is relieved.
2. The dynamic multi-factor identity authentication based e-contract security risk assessment system of claim 1, wherein: In the dynamic identity aggregation authentication module, the CA root certificate chain is called to perform first-round confirmation on the certificate authenticity and validity period and user identity legality, and then the user information is pulled to generate a historical real-name authentication vector; Audio and video data are collected, and the historical real-name authentication vector is encapsulated into a unified structured recognition package, then the matching degree is calculated, and a matching degree threshold is set, when the matching degree is insufficient and environmental anomalies are detected, secondary authentication is triggered and lip reading verification operation is completed.
3. The dynamic multi-factor identity authentication based e-contract security risk assessment system of claim 2, wherein: In the dynamic identity aggregation authentication module, first determine whether the current blockchain write path is in a potential congestion state.
4. The dynamic multi-factor identity authentication based e-contract security risk assessment system of claim 3, wherein In the dynamic identity aggregation authentication module, after determining the potential congestion state, trigger the chain write health detection, as follows: Obtain the page write delay time sequence and the write queue depth sequence, and synchronize and align them to form a joint time sequence structure; Perform wavelet packet decomposition on the page write delay time sequence to extract the instantaneous phase curve, and calculate the difference between the instantaneous phase curve and the normalized derivative curve of the write queue depth sequence point by point to determine whether the write page process and the queue speed-up occur phase-locked slip.
5. The dynamic multi-factor identity authentication based e-contract security risk assessment system of claim 4, wherein: In the dynamic identity aggregation authentication module, after determining that the write page process and the queue speed-up occur phase-locked slip, the local maximum gradient of the Hilbert Huang envelope curve of the cross-channel phase difference vector is calculated to obtain the slip intensity value in the current scheduling period.
6. The dynamic multi-factor identity authentication based e-contract security risk assessment system of claim 5, wherein: In the dynamic identity aggregation authentication module, the time point at which the current slip intensity peak value is located is taken as the geometric center, the page write completion marker is traced back as the window starting point, and the double-reversal position of the write queue depth derivative is identified as the window endpoint, and a local slip window is dynamically generated. According to the size of the local slip window, the time domain integration or weighted integration mode of the slip intensity value is performed, and finally the integrated slip intensity value is multiplied by the Hilbert envelope average value of the write queue depth sequence in the same local slip window to calculate the write blocking index. The time distribution density and spatial distribution density of the slip intensity in the same local slip window are analyzed, the high-sensitivity slip speed-up data is obtained by dynamically adjusting the fractional order difference strategy according to the slip concentration period and the corresponding write queue depth slope interval result, and the cache inflation rate is determined by combining the entropy density value.
7. The dynamic multi-factor identity authentication based e-contract security risk assessment system of claim 6, wherein: In the dynamic identity aggregation authentication module, the initial observation window is constructed by tracing back the history complete scheduling period, the key performance parameter record fragments in the multi-round chain write task execution process recorded under the condition of continuous and stable operation are gradually expanded, and the relative change rate of the write blocking index and the cache inflation rate fluctuation degree before and after expansion is calculated. When the initial observation window length is recorded when the continuous two expansions do not introduce new fluctuation inflection points and the overall relative change rate remains monotonically decreasing; The sliding mean sequence of the write blocking index and the cache inflation rate in the last N healthy operation periods is extracted, and a fusion mean benchmark trajectory is established. Then, the standard deviation of each mean sequence is taken as the expansion benchmark, the mean value of the other sequence is embedded into the current sequence as the modulation factor, the deviation correction band and the peripheral elastic buffer zone are formed.
8. The dynamic multi-factor identity authentication based e-contract security risk assessment system of claim 7, wherein; In the real-time security risk scoring module, a multi-dimensional structured feature package including static identity legality score, dynamic behavior deviation, current environment risk weight, and historical contract risk label is extracted to generate a dynamic risk score. According to the scoring result, a hierarchical processing strategy is executed, and the scoring result and the corresponding feature vector are written into the risk control cache pool and the on-chain archival structure with a unique signed identifier.
9. The dynamic multi-factor identity authentication based e-contract security risk assessment system of claim 8, wherein: In the hierarchical blockchain storage module, the data to be stored is divided into high-frequency short-period data and core content data according to the generation frequency and judicial value, and is written into the local alliance chain and the cross-chain notarization chain node respectively. In high-concurrency scenarios, consistency checking is performed, and contract-level priority fields and indexable timestamp fields are set in the on-chain data structure.
10. The dynamic multi-factor identity authentication based e-contract security risk assessment system of claim 9, wherein: In the security behavior audit and risk linkage module, when the contract is opened, the access terminal information is automatically collected and uploaded to the behavior analysis center. If it is determined that the access is high-risk, the user is immediately alerted through multiple channels and the subsequent access permission of the contract is frozen.
Citation Information
Patent Citations
Systems and methods for predicting an expected blockage of a signal path of an ultrasound signal
CN103959214A
Identity authentication method and device, and mobile terminal
CN109117688A