Multi-scene identity authentication and data sharing system based on real-name DID

By using a multi-scenario identity authentication and data sharing system based on real-name DID, and leveraging multi-source heterogeneous data fusion and collaborative attention networks, combined with the Dragonfly algorithm for global optimization, the system solves the centralization risks and data sharing security issues of traditional identity authentication systems, achieving accurate authentication and secure sharing, and adapting to the high security and efficiency requirements of multiple scenarios.

CN120979767AActive Publication Date: 2025-11-18WUHAN JIEWAI TECHNOLOGY CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202511246547.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-02
Publication Date
2025-11-18
Estimated Expiration
2045-09-02

AI Technical Summary

Technical Problem

Existing identity authentication systems suffer from centralized management risks, insufficient ability to integrate multi-source identity data, lack of intelligent model optimization, and inadequate data sharing security and compliance. In particular, they struggle to achieve accurate user identity authentication and secure data sharing in various scenarios.

Method used

It adopts a multi-scenario identity authentication and data sharing system based on real-name DID. Through the fusion of multi-source heterogeneous identity data and collaborative attention mechanism network, combined with the Dragonfly algorithm for global optimization, it realizes the joint modeling and deep fusion of multi-dimensional identity features, and is equipped with a full-process security monitoring mechanism to support data access permission management in multiple scenarios.

Benefits of technology

It achieves accurate user identity authentication and multi-scenario data sharing, improves the accuracy and robustness of identity authentication, ensures data security and compliance, adapts to the high security requirements of complex application scenarios, reduces the risk of model overfitting and resource waste, and improves data circulation efficiency and system security and controllability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979767A_ABST
    Figure CN120979767A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-scene identity authentication and data sharing system based on real-name DID, and the system comprises a multi-source identity data collection and preprocessing module which is used for collecting and preprocessing multi-source identity data of a user in different application scenes; the collaborative attention feature fusion module is used for carrying out joint modeling and feature fusion on multi-source identity features in different scenes; the collaborative attention network model optimization module is used for globally optimizing structural parameters and hyper-parameters of the collaborative attention network by adopting a centralized training and distributed execution mechanism; the identity authentication analysis module is used for receiving a user authentication request; the data access control and sharing management module is used for performing data access permission distribution and sharing management on the user data under multiple scenes; and the whole process security monitoring module is used for carrying out real-time security monitoring on the whole process of identity authentication and data sharing. According to the invention, accurate answers and solutions are provided for users.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of identity authentication security, and particularly relates to a multi-scene identity authentication and data sharing system based on a real-name DID. BACKGROUND

[0002] With the rapid development of digital economy and the wide application of Internet and Internet of Things technologies, identity authentication and data sharing have become the core basic capabilities in various digital scenarios. In many application fields such as finance, medical treatment, government affairs, education and social interaction, accurate identification of user identity and safe sharing of data are of great significance for guaranteeing business compliance, improving service efficiency and promoting the circulation of data elements. At present, traditional identity authentication methods mainly rely on single or multi-factor authentication means such as username, password, SMS verification code, and some high-security-demand scenarios introduce biometric recognition technology, supplemented by security tokens, dynamic passwords and other security enhancement measures. These traditional methods have improved the security of identity authentication to some extent, but still have many limitations in multi-scene, multi-data and dynamic environment.

[0003] Firstly, traditional identity authentication systems generally adopt a centralized management mode, and user identity data is stored in the central database of a service provider or an institution. This mode not only becomes an attack target, increasing the risk of data leakage and tampering, but also limits the user's control over identity data, making it difficult to achieve personal data self-control. At the same time, there is a lack of unified standards and mutual trust mechanisms among identity authentication systems in different application scenarios, and users often face problems such as repeated registration, repeated authentication and information silos when cross-platform, cross-service authentication and data sharing, which seriously affects user experience and data circulation efficiency.

[0004] Secondly, the current multi-source identity data fusion and modeling capability is limited. In actual applications, user identity data often comes from various sources, including biometric features, behavioral characteristics, device fingerprints and environmental information. These data have different forms and feature distributions in different scenarios, and existing technologies cannot efficiently integrate multi-source heterogeneous identity data, making it difficult to achieve comprehensive, dynamic and accurate characterization of user identity. Some research attempts to use multi-modal feature fusion and feature selection methods to improve identity recognition accuracy, but due to the single fusion mechanism or lack of scene awareness, it is generally difficult to fully explore the deep association between various data, resulting in insufficient reliability and adaptability of authentication.

[0005] Thirdly, for the structure and parameter optimization of the identity authentication model, the mainstream method relies on artificial experience or single-index-based hyperparameter adjustment, lacking intelligent and global optimization mechanism. This not only affects the generalization ability of the model in multiple scenarios, but also may lead to excessive resource consumption or suboptimal model convergence. In recent years, some research has introduced swarm intelligence optimization algorithms for automatic optimization of neural network parameters, but in complex scenarios such as identity authentication and data sharing, there is still a lack of support for multi-source features, dynamic scenarios, and model structure diversity.

[0006] In addition, the compliance and security of data sharing are increasingly prominent. Existing data sharing mechanisms are mostly based on access control lists, role permission division, and lack of intelligent authorization strategies based on identity authentication results and dynamic scenario weights, making it difficult to meet the flexible management needs of multiple users, multiple resources, and multiple strategies in complex scenarios. In the process of data sharing, real-time monitoring and traceability of data integrity, identity legality, and access behavior compliance are not fully guaranteed. Once data leakage, unauthorized access, and other security incidents occur, it is often difficult to discover and trace in a timely manner, posing a significant risk to users and data management parties.

[0007] Decentralized identity systems have received attention in recent years, with advantages such as user self-control of identity data, cross-platform trusted mutual recognition, and privacy protection. Some projects attempt to apply DID to identity authentication and data sharing, but still face many challenges in key technical areas such as multi-source heterogeneous data fusion, model efficient optimization, and whole-process security monitoring. For example, existing DID solutions mostly focus on identity generation and storage, lacking deep modeling and intelligent authentication support for large-scale multi-source identity data, and the security and compliance management mechanism for multi-scenario data sharing is not perfect.

[0008] Therefore, how to provide a multi-scenario identity authentication and data sharing system based on real-name DID is a problem that needs to be solved by those skilled in the art. SUMMARY

[0009] One purpose of the present application is to propose a multi-scene identity authentication and data sharing system based on real-name DID. The present application realizes the joint modeling and deep fusion of multi-dimensional identity features such as biological features, behavior data, device fingerprints and environmental information in multiple scenes by constructing a multi-source heterogeneous identity data fusion and collaborative attention mechanism network. The structure parameters and hyperparameters of the collaborative attention network are globally optimized and distributed trained by combining the dragonfly algorithm, which significantly improves the identity feature expression ability and the generalization performance of the authentication model. The present application can realize accurate authentication of user identity and intelligent discrimination of data access rights in multiple scenes, and further guarantee data integrity, access compliance and identity legality through whole-process safety monitoring and traceability management. The present application integrates multiple core capabilities such as multi-source data acquisition, feature fusion, intelligent authentication, permission allocation, safety monitoring and traceability management, and constructs a real-name DID identity authentication and data sharing integrated solution for multi-scene applications.

[0010] The multi-scene identity authentication and data sharing system based on real-name DID according to the embodiment of the present application comprises:

[0011] A multi-source identity data acquisition and preprocessing module is configured to acquire multi-source identity data of a user in different application scenarios and perform preprocessing to generate initial identity data.

[0012] A collaborative attention feature fusion module is configured to perform joint modeling and feature fusion of multi-source identity features in different scenes through a multi-layer collaborative attention mechanism.

[0013] A collaborative attention network model optimization module is configured to perform global optimization of structure parameters and hyperparameters of the collaborative attention network by using a centralized training and distributed execution mechanism.

[0014] An identity authentication analysis module is configured to receive a user authentication request and perform identity authentication analysis by using the fused identity feature representation.

[0015] A data access control and sharing management module is configured to perform data access right allocation and sharing management of user data in multiple scenes according to a predetermined data access control strategy based on the identity authentication result and the user real-name DID.

[0016] A whole-process safety monitoring module is configured to perform real-time safety monitoring on the whole process of identity authentication and data sharing.

[0017] Optionally, the modules are realized by the following method:

[0018] S1, acquiring multi-source identity data of a user in different application scenarios and performing preprocessing to generate initial identity data.

[0019] S2. Input the initial identity data into the collaborative attention network model, and perform joint modeling and feature fusion of multi-source identity features under different scenarios through a multi-layer collaborative attention mechanism, and output the fused identity feature representation.

[0020] S3. Based on the fusion of identity features, the Dragonfly algorithm is used to configure exploration and development behavior units for each dragonfly. The structural parameters and hyperparameters of the collaborative attention network are globally optimized by a centralized training and distributed execution mechanism, and the optimized collaborative attention network model is output.

[0021] S4. Receive user authentication request, input initial identity data into the optimized collaborative attention network model, perform identity authentication analysis using fused identity feature representation, and output identity authentication result;

[0022] S5. Based on the identity authentication results and the user's real-name DID, and in accordance with the established data access control policy, manage the user data sharing across multiple scenarios.

[0023] S6. Perform security monitoring on the entire process of identity authentication and data sharing to ensure data integrity, identity legitimacy and access compliance, and support traceability management of identity authentication and data sharing behavior.

[0024] Optionally, the multi-source identity data includes biometric data, behavioral data, device fingerprint information, and related environmental data.

[0025] Optionally, the structural parameters and hyperparameters of the collaborative attention network include the number of network layers, the number of neurons per layer, attention mechanism parameters, and learning rate, based on identity authentication accuracy, recall, and F1 score.

[0026] Optionally, step S2 includes the following specific steps:

[0027] S21. Input the initial identity data into the collaborative attention network model, classify and organize the initial identity data according to the data source and scenario requirements, and obtain multi-source identity feature data under different scenarios.

[0028] S22. Use a scenario-specific feature extraction network to extract feature vectors from multi-source identity feature data in different scenarios to generate preliminary feature vectors for each scenario.

[0029] S23. Input the preliminary feature vectors of each scenario into the first layer collaborative attention mechanism unit, calculate the correlation weights between features of different scenarios, and output the first layer fusion feature representation.

[0030] S24, input the first layer fusion feature representation into a multi-layer cooperative attention mechanism unit, update and optimize the fusion feature representation layer by layer, dynamically allocate attention weights according to different scenes and feature categories in each layer, and output the final fusion feature representation;

[0031] S25, input the final fusion feature representation into an identity feature expression subunit, perform feature reconstruction, and generate a fusion identity feature representation.

[0032] Optionally, the S3 includes the following specific steps:

[0033] S31, receiving the fusion identity feature representation, initializing the dragonfly algorithm population, and assigning the initial values of the structure parameters and hyperparameters of the cooperative attention network to each dragonfly body;

[0034] S32, configuring an exploration behavior unit and a development behavior unit for each dragonfly body, and calculating the current position of each dragonfly body in the parameter space according to the fusion identity feature representation;

[0035] S33, using the exploration behavior unit and the development behavior unit to guide the position update of the dragonfly body in the parameter space, and generating updated structure parameters and hyperparameters;

[0036] S34, using a centralized training mechanism to train the cooperative attention network model corresponding to each dragonfly body, and evaluating the fitness value of each dragonfly body based on the training result;

[0037] S35, using a distributed execution mechanism, guiding the global search direction of the dragonfly body according to the fitness value, updating the structure parameters and hyperparameters of each dragonfly body in the population, and obtaining a new generation of dragonfly body distribution:

[0038]

[0039] wherein, Θ t+1 represents the structure parameters and hyperparameters of the new generation of dragonfly body, N represents the number of dragonfly bodies, M represents the number of parameter types in the cooperative attention network, w ij represents the weighting coefficient of the i-th dragonfly body on the j-th parameter, Θ i,t represents the structure parameters and hyperparameters of the i-th dragonfly body in the t-th generation, i represents the number of dragonfly bodies, j represents the type number of structure parameters and hyperparameters in the cooperative attention network, and t represents the iteration number of the current iteration;

[0040] S36, when the iteration number reaches 500, the optimal structure parameters and hyperparameters are generated, the cooperative attention network model is optimized, and the optimized cooperative attention network model is output.

[0041] Optionally, the S4 includes the following specific steps:

[0042] S41, receive a user authentication request, extract the initial identity data of the user, and format the initial identity data to generate standardized identity data;

[0043] S42, input the standardized identity data into the optimized collaborative attention network model, use the structure of the optimized collaborative attention network model to extract multi-layer features from the input data, and output the to-be-fused feature representation;

[0044] S43, joint comparison of the to-be-fused feature representation and the fused identity feature representation, calculation of the feature similarity score:

[0045]

[0046] Ψ = ∑ L =1 x k y k Θ k, k =1, 2, …, L k x k represents the kth dimension of the to-be-fused feature, y k k represents the kth dimension of the fused identity feature, Θ t+1,k k represents the kth dimension of the optimal structure parameter and the hyperparameter, and k represents the number of feature dimensions.

[0047] S44, input the feature similarity score into the identity authentication discrimination unit, perform identity discrimination according to the set authentication threshold, and generate a preliminary identity determination;

[0048] S45, perform a credibility evaluation on the preliminary identity determination, combine the confidence output of the optimized collaborative attention network model, and generate an identity authentication result.

[0049] Optionally, the S5 includes the following specific steps:

[0050] S51, receive the final identity authentication determination output and the user's real-name DID decentralized identity, and combine to generate an identity access token;

[0051] S52, according to the identity access token, retrieve the preset data access control strategy, and combine the feature similarity score to calculate the scene access weight:

[0052]

[0053] Ω = ∑ Q =1 N m =1 S m P m P, Q =1, 2, …, Q q N m represents the number of defined data access rules in the qth scene, m represents the serial number of the mth data access rule in the qth scene, Ψ represents the feature similarity score, W q,m S m represents the weight coefficient of the mth rule in the qth scene, S q,m m represents the sensitivity coefficient of the mth rule in the qth scene, P q P represents the priority coefficient of the qth scene.

[0054] S53, match the access rule set with the current identity access token, filter out the effective rules in the rule set, and generate a scene access permission set;

[0055] S54, according to the scene access permission set, identify the data resource list allowed to access in the target scene, and generate a scene data authorization instruction;

[0056] S55, the scene data authorization instruction is transmitted to the data management unit, and the data management unit performs permission verification and processing on the data requested by the user according to the instruction, to form a scene data sharing processing result;

[0057] S56, the scene data sharing processing result is returned to the user, and the data sharing management in multiple scenes is completed.

[0058] Optionally, the S6 comprises the following specific steps:

[0059] S61, collect authentication request information, data access request information and related metadata in the whole process of multi-scene identity authentication and data sharing, and form a security monitoring initial data packet;

[0060] S62, format processing is performed on the security monitoring initial data packet, and authentication judgment result, data sharing judgment result, authentication subject identifier, data resource identifier and the like are extracted, to generate a security attribute associated data set;

[0061] S63, integrity check is performed on the security attribute associated data set, an integrity check tag is generated and bound, and a security check output packet is obtained;

[0062] S64, identity legality detection is performed on the security check output packet, an identity legality judgment result is output in combination with the identity legality rule, and the security check output packet is merged to form a compliance detection input packet;

[0063] S65, data access compliance detection is performed on the compliance detection input packet, an access compliance judgment result is generated according to the data access control strategy and behavior audit rule, and a compliance detection output packet is obtained;

[0064] S66, real-time archiving and traceability indexing are performed on the compliance detection output packet, and various judgment results and check tags are stored in multiple dimensions, to realize whole-process traceability query and behavior traceability management.

[0065] The beneficial effects of the present application are:

[0066] Compared with the prior art, the present application has achieved remarkable beneficial effects. First, by introducing a decentralized identity system, the user's identity information is self-controlled and trusted across domains, breaking through the data silos and security risks of traditional centralized identity authentication, greatly improving the security and privacy protection level of user data. Through deep collection and fusion of multi-source heterogeneous identity data, the system can comprehensively utilize multi-dimensional data such as biological characteristics, behavior data, device fingerprints and environmental information to realize dynamic characterization of user identity in all directions, effectively improving the accuracy and robustness of identity authentication, and meeting the high security and high reliability requirements in complex and variable application scenarios such as finance, medical treatment and government affairs.

[0067] Secondly, the present application innovatively combines the collaborative attention network model and the dragonfly algorithm, which can dynamically optimize the structure parameters and hyperparameters of the collaborative attention network globally, breaking through the bottleneck of traditional artificial experience and single index optimization, and significantly improving the feature expression ability and generalization performance of the collaborative attention network. Through centralized training and distributed execution mechanism, the system can efficiently handle large-scale authentication requests of multiple scenes and multiple users, ensuring the efficiency and real-time performance of the authentication process, and significantly reducing the risk of model overfitting and resource waste.

[0068] In terms of data sharing management, based on the identity authentication result and the real-name DID, combined with intelligent data access control strategy, the system realizes fine-grained dynamic authorization and secure sharing in multiple scenarios, completely changing the limitations of traditional static permission configuration and coarse-grained management, greatly improving the data flow efficiency and compliance. The introduction of whole-process safety monitoring and traceability mechanism effectively guarantees the data integrity, identity legality and compliance of access behavior in the process of authentication and data sharing. Once abnormal behavior occurs, real-time early warning and behavior tracing can be realized, improving the overall safety and controllability of the system.

[0069] In summary, the present application not only solves the problems of fragmented identity authentication system, weak data fusion capability, insufficient model optimization and uncontrollable data sharing security in the prior art, but also provides an efficient, intelligent, safe and traceable overall solution for multi-scene real-name identity authentication and data sharing, providing solid technical support for the healthy development of digital economy and data factor market, and has broad application prospect and significant social and economic value. BRIEF DESCRIPTION OF DRAWINGS

[0070] The accompanying drawings are used to provide a further understanding of the present application, and constitute a part of the specification, together with the embodiments of the present application, to explain the present application, and do not constitute a limitation on the present application. In the drawings:

[0071] Fig. 1A method flowchart of a multi-scene identity authentication and data sharing system based on a real-name DID according to the present application is provided.

[0072] Fig. 2 A system flowchart of a multi-scene identity authentication and data sharing system based on a real-name DID according to the present application is provided.

[0073] Fig. 3 A data flowchart of a multi-scene identity authentication and data sharing system based on a real-name DID according to the present application is provided. DETAILED DESCRIPTION

[0074] The present application will now be further described in detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams and only schematically show the basic structure of the present application, and thus only show the configurations related to the present application.

[0075] REFERENCE Figs. 1-3 The multi-scene identity authentication and data sharing system based on a real-name DID comprises:

[0076] A multi-source identity data acquisition and preprocessing module is configured to acquire multi-source identity data of a user in different application scenarios and perform preprocessing to generate initial identity data.

[0077] A collaborative attention feature fusion module is configured to perform joint modeling and feature fusion of multi-source identity features in different scenarios through a multi-layer collaborative attention mechanism.

[0078] A collaborative attention network model optimization module is configured to perform global optimization of structure parameters and hyperparameters of the collaborative attention network using a centralized training and distributed execution mechanism.

[0079] An identity authentication analysis module is configured to receive a user authentication request and perform identity authentication analysis using the fused identity feature representation.

[0080] A data access control and sharing management module is configured to perform data access permission allocation and sharing management of user data in different scenarios based on the identity authentication result and the real-name DID of the user according to a predetermined data access control strategy.

[0081] A whole-process security monitoring module is configured to perform real-time security monitoring of the whole process of identity authentication and data sharing.

[0082] The present application realizes comprehensive modeling of multi-dimensional identity features of a user through multi-source identity data acquisition and multi-layer collaborative attention feature fusion. Combined with network optimization using centralized training and distributed execution, the accuracy and generalization ability of identity authentication are effectively improved. The whole-process security monitoring and intelligent permission allocation are matched to realize the security and flexibility of data sharing in different scenarios.

[0083] In this embodiment, the modules are realized by the following method:

[0084] S1, collect multi-source identity data of users in different application scenarios and preprocess to generate initial identity data;

[0085] S2, input the initial identity data into the collaborative attention network model, and perform joint modeling and feature fusion of multi-source identity features in different scenes through multi-layer collaborative attention mechanism, and output the fused identity feature representation;

[0086] S3, based on the fused identity feature representation, using dragonfly algorithm, configuring exploration and development behavior unit for each dragonfly body, using centralized training and distributed execution mechanism to globally optimize the structure parameters and hyperparameters of the collaborative attention network, and outputting the optimized collaborative attention network model;

[0087] S4, receiving a user authentication request, inputting the initial identity data into the optimized collaborative attention network model, and performing identity authentication analysis using the fused identity feature representation, and outputting the identity authentication result;

[0088] S5, based on the identity authentication result and the user real-name DID, according to the established data access control strategy, performing multi-scene data sharing management on user data;

[0089] S6, security monitoring of the whole process of identity authentication and data sharing, ensuring data integrity, identity legality and access compliance, and supporting traceability management of identity authentication and data sharing behavior.

[0090] The present application realizes efficient fusion and accurate modeling of multi-source identity features through multi-layer collaborative attention mechanism and dragonfly algorithm global optimization. Centralized training and distributed execution improve the model authentication accuracy, cooperate with real-name DID and whole process security monitoring, effectively guarantee the security, compliance and traceability of multi-scene data sharing, so that the identity authentication system has stronger intelligence and reliability.

[0091] In this embodiment, the multi-source identity data includes biological feature data, behavior data, device fingerprint information and related environment data.

[0092] The present application collects multi-source identity data, including biological features, behavior data, device fingerprint and environment data, realizes multi-dimensional fusion of identity features. By introducing multi-source heterogeneous data, the comprehensiveness and robustness of identity authentication can be significantly improved, the risk of single feature being forged can be reduced, and the authentication accuracy and security of the system in complex application scenarios can be improved.

[0093] In this embodiment, the structure parameters and hyperparameters of the collaborative attention network include the number of network layers, the number of neurons in each layer, the attention mechanism parameters and the learning rate, according to the identity authentication accuracy, recall rate and F1 score.

[0094] The application dynamically optimizes the number of layers, the number of neurons, the attention parameters and the learning rate of the collaborative attention network according to the identity authentication accuracy, recall rate and F1 score. Through multi-dimensional parameter adaptive adjustment, the model expression ability and generalization ability are considered, the feature extraction and fusion effect is improved, the high accuracy and robustness of identity authentication are realized, and the flexibility and stability of the system in different application scenarios are ensured.

[0095] In this embodiment, S2 includes the following specific steps:

[0096] S21, input the initial identity data into the collaborative attention network model, classify and arrange the initial identity data according to the data source and scene requirement, and obtain multi-source identity feature data in different scenes;

[0097] S22, respectively using the scene-specific feature extraction network to extract feature vectors for the multi-source identity feature data in different scenes, and generating preliminary feature vectors in each scene;

[0098] S23, input the preliminary feature vectors in each scene into the first layer collaborative attention mechanism unit, calculate the correlation weight between different scene features, and output the first layer fusion feature representation;

[0099] S24, input the first layer fusion feature representation into the multi-layer collaborative attention mechanism unit, update and optimize the fusion feature representation layer by layer, dynamically allocate attention weights in each layer according to different scenes and feature categories, and output the final fusion feature representation;

[0100] S25, input the final fusion feature representation into the identity feature expression subunit, perform feature reconstruction, and generate a fusion identity feature representation.

[0101] The application dynamically fuses multi-source identity feature data in different scenes through a multi-layer collaborative attention mechanism, combines scene-specific feature extraction and hierarchical correlation weighting, and realizes accurate extraction and optimized expression of identity features. This method effectively improves the discrimination ability and adaptability of the fusion features, and provides higher accuracy and robustness for subsequent identity authentication.

[0102] In this embodiment, S3 includes the following specific steps:

[0103] S31, receive the fusion identity feature representation, initialize the dragonfly algorithm population using the dragonfly algorithm, and assign the initial values of the structure parameters and hyperparameters of the collaborative attention network to each dragonfly body;

[0104] S32, configure an exploration behavior unit and a development behavior unit for each dragonfly body, calculate the current position of each dragonfly body in the parameter space according to the fusion identity feature representation;

[0105] S33, using the exploration behavior unit and the development behavior unit, guiding the dragonfly body to update the position in the parameter space, generating updated structure parameters and hyperparameters;

[0106] S34, adopting a centralized training mechanism, training the collaborative attention network model corresponding to each dragonfly body, and evaluating the fitness value of each dragonfly body based on the training result;

[0107] S35, adopting a distributed execution mechanism, guiding the global search direction of the dragonfly body according to the fitness value, updating the structure parameters and hyperparameters of each dragonfly body in the population, and obtaining a new generation of dragonfly body distribution:

[0108]

[0109] wherein, Θ t+1 represents the structure parameters and hyperparameters of the new generation of dragonfly body, N represents the number of dragonfly bodies, M represents the number of types of parameters in the collaborative attention network, w ij represents the weighting coefficient of the i-th dragonfly body on the j-th parameter, Θ i,t represents the structure parameters and hyperparameters of the i-th dragonfly body in the t-th generation, i represents the number of dragonfly bodies, j represents the type number of structure parameters and hyperparameters in the collaborative attention network, and t represents the iteration number of the current iteration;

[0110] S36, when the iteration number reaches 500, the optimal structure parameters and hyperparameters are generated, and the collaborative attention network model is optimized, and the optimized collaborative attention network model is output.

[0111] The dragonfly algorithm is used to globally optimize the structure parameters and hyperparameters of the collaborative attention network, and the exploration and development behavior units and the centralized training and distributed execution mechanism are combined to realize efficient search and dynamic update of the parameter space. This method effectively improves the convergence speed and fitness of the model, and ensures that the network structure has the optimal feature expression and generalization ability in multiple scenarios.

[0112] In this embodiment, S4 includes the following specific steps:

[0113] S41, receiving a user authentication request, extracting initial identity data of the user, and formatting the initial identity data to generate standardized identity data;

[0114] S42, inputting the standardized identity data into the optimized collaborative attention network model, using the optimized collaborative attention network model structure to perform multi-layer feature extraction on the input data, and outputting a to-be-fused feature representation;

[0115] S43, jointly comparing the to-be-fused feature representation with the fused identity feature representation, and calculating a feature similarity score:

[0116]

[0117] wherein, Ψ represents a feature similarity score, L represents a feature dimension number, x k represents the kth dimension of the feature to be fused, y k represents the kth dimension of the fused identity feature, Θ t+1,k represents the kth dimension of the optimal structure parameter and hyperparameter, and k represents the number of feature dimensions.

[0118] S44, input the feature similarity score into the identity authentication discrimination unit, and perform identity discrimination according to the set authentication threshold to generate a preliminary identity determination.

[0119] S45, perform credibility evaluation on the preliminary identity determination, combine the confidence output of the optimized collaborative attention network model, and generate an identity authentication result.

[0120] The present application realizes accurate comparison and discrimination of identity features by optimizing the collaborative attention network model to perform multi-layer feature extraction on standardized identity data, and combining the feature similarity score and the dynamic authentication threshold. With confidence evaluation, the accuracy and reliability of identity authentication are effectively improved, the misjudgment rate is significantly reduced, and the credibility and practicality of the authentication result are ensured.

[0121] In the embodiment, S5 includes the following specific steps:

[0122] S51, receive the final identity authentication determination output and the user real name DID decentralized identity, and combine to generate an identity access token;

[0123] S52, according to the identity access token, search the preset data access control strategy, and combine the feature similarity score to calculate the scene access weight:

[0124]

[0125] wherein, Ω represents a multi-scene comprehensive access weight, Q represents the number of scenes involved by the current user, N q represents the number of defined data access rules in the qth scene, m represents the serial number of the mth data access rule in the qth scene, Ψ represents the feature similarity score, W q,m represents the weight coefficient of the mth rule in the qth scene, S q,m represents the sensitivity coefficient of the mth rule in the qth scene, P q represents the priority coefficient of the qth scene.

[0126] S53, match the access rule set with the current identity access token, filter out the effective rules in the rule set, and generate a scene access permission set.

[0127] S54, according to the scene access permission set, identify the list of data resources allowed to access under the target scene, and generate scene data authorization instructions;

[0128] S55, the scene data authorization instructions are transmitted to the data management unit, and the data management unit performs permission verification and processing on the data requested by the user according to the instructions to form a scene data sharing processing result;

[0129] S56, the scene data sharing processing result is returned to the user, and the data sharing management in multiple scenes is completed.

[0130] The present application realizes flexible data access permission allocation in multiple scenes by combining identity authentication determination, DID and feature similarity. Based on the dynamic screening of the optimal access rule based on the comprehensive access weight, the scene data authorization instruction is automatically generated, which ensures the safety and compliance of data sharing and is efficient. This method improves the accuracy and automation level of permission management, and adapts to the changing actual application scene.

[0131] In the embodiment, S6 includes the following specific steps:

[0132] S61, collect authentication request information, data access request information and related metadata in the whole process of multi-scene identity authentication and data sharing, and form a security monitoring initial data packet;

[0133] S62, format processing is performed on the security monitoring initial data packet, and authentication determination results, data sharing determination results, authentication subject identification, data resource identification and the like are extracted to generate a security attribute associated data set;

[0134] S63, integrity check is performed on the security attribute associated data set, integrity check tags are generated and bound to obtain a security check output packet;

[0135] S64, identity legality detection is performed on the security check output packet, and identity legality rule is combined to output identity legality determination result, and is merged with the security check output packet to form a compliance detection input packet;

[0136] S65, data access compliance detection is performed on the compliance detection input packet, and access compliance determination result is generated according to data access control strategy and behavior audit rule to obtain compliance detection output packet;

[0137] S66, real-time archiving and traceability indexing are performed on the compliance detection output packet, and various determination results and check tags are stored in multiple dimensions to realize whole-process traceability query and behavior traceability management.

[0138] This invention implements layered security monitoring of the entire process of identity authentication and data sharing across multiple scenarios. By combining integrity verification, identity legitimacy, and access compliance detection, it achieves real-time compliance control and traceability management of the entire data access process. This effectively ensures data security, identity compliance, and behavioral traceability, significantly improving the system's security and compliance levels.

[0139] Example 1:

[0140] To verify the feasibility of this invention in practice, it was applied to the data security management system of a large fintech company. This company has over 50,000 employees and handles a large number of identity authentication and data sharing requests involving multiple departments, systems, and business scenarios daily. Previously, the company often faced challenges in identity authentication and data access control across multiple scenarios, including heterogeneous identity information, insufficient feature fusion, difficulty in globally optimizing model parameters, and rudimentary permission allocation and management. This resulted in low accuracy in identity authentication, inflexible data access control, and significant difficulties in security compliance traceability, severely impacting data security and business efficiency.

[0141] The multi-layer collaborative attention network fusion identity authentication and data sharing management method proposed in this invention, in practical deployment, first collects initial identity data from different sources in various business systems within the company, including employee biometric information, device fingerprints, behavior logs, and access history. The system automatically formats and classifies these heterogeneous identity data, and constructs a multi-source identity feature library based on business scenario requirements.

[0142] Next, for different business scenarios, feature vectors are extracted using scenario-specific feature extraction networks to obtain preliminary feature vectors for each business scenario. All preliminary feature vectors are input into a multi-layer collaborative attention mechanism network, where the system dynamically allocates weights and fully integrates feature information from different scenarios to generate a fused identity feature representation with high discriminativeness and business adaptability.

[0143] Subsequently, the Dragonfly algorithm was used to globally optimize the structural parameters and hyperparameters of the collaborative attention network. Through a centralized training and distributed execution mechanism, the Dragonfly agent continuously searches and updates the parameter space, finally obtaining the optimal model parameters after 500 iterations, thus improving the generalization and feature representation capabilities of the network structure.

[0144] When an employee initiates an identity authentication or data access request, the system first standardizes their identity data. Then, it uses an optimized collaborative attention network model to perform multi-layer feature extraction, compares the features to be fused with the stored fused identity features, and calculates a feature similarity score. The system sets a dynamic authentication threshold, combines it with model confidence, automatically makes an identity authentication decision, and provides a credibility assessment.

[0145] The identity access token is generated by the DID decentralized identity and authentication result, the system automatically retrieves the data access control policy, combines the feature similarity and scene priority and the like factors, and calculates the comprehensive access weight. Finally, the system automatically generates and issues the data authorization instruction according to the scene, accurately matches the data access permission, and effectively guarantees the security and compliance of data sharing.

[0146] In addition, the system performs security audit on the whole process of identity authentication and data sharing, collects metadata such as authentication request and data access request in real time, and performs integrity and compliance verification. All the determination results and verification tags are stored and traced in multiple dimensions, which provides strong technical support for subsequent security monitoring and compliance accountability.

[0147] Table 1 Comparison table of optimization effect of multi-scene identity authentication and data sharing system based on real-name DID

[0148]

[0149] Table 1 shows that after the deployment of the present application in the financial technology company, after actual operation for three consecutive months, the system processes 136,428 times of identity authentication requests, 198,324 times of data access requests, and involves 10 core business fields such as human resources, financial approval, customer information management, and R&D document sharing. By comparing with the original traditional identity authentication and permission management system of the company, the identity authentication accuracy is improved from 96.2% of the original system to 99.78%, and the false recognition rate is reduced from 1.7% to 0.12%. The average identity authentication response delay is reduced from 1.86 seconds to 0.93 seconds, greatly improving the user experience. The fine degree of data access permission allocation is improved, the number of covered scenes is expanded from 6 of the original system to 10, and the flexibility of permission configuration is improved by about 68%. The access compliance determination accuracy is improved to 99.92%, effectively preventing unauthorized access and illegal sharing events. No data leakage event caused by incorrect permission configuration has occurred in the past three months. The real-time security audit and traceability index function realizes minute-level behavior traceability, and the security compliance response speed is improved by 3 times, supporting rapid positioning and accountability of security events. The system automatically adjusts the authentication threshold and access strategy, taking into account security and convenience, and the employee feedback satisfaction questionnaire score is improved from 3.8 of the original system to 4.7.

[0150] The above is only a preferred specific embodiment of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can make equivalent replacement or change according to the technical solution and inventive concept of the present application within the technical range disclosed by the present application, which should be covered within the protection scope of the present application.

Claims

1. A multi-scene identity authentication and data sharing system based on a real-name DID, characterized in that, include: The multi-source identity data acquisition and preprocessing module is used to collect multi-source identity data of users in different application scenarios and preprocess it to generate initial identity data. The collaborative attention feature fusion module is used to jointly model and fuse multi-source identity features in different scenarios through a multi-layer collaborative attention mechanism. The collaborative attention network model optimization module is used to globally optimize the structural parameters and hyperparameters of the collaborative attention network using a centralized training and distributed execution mechanism. The identity authentication analysis module is used to receive user authentication requests and perform identity authentication analysis using fused identity feature representations. The data access control and sharing management module is used to allocate and manage data access permissions for user data in multiple scenarios based on identity authentication results and user real-name DID, according to the established data access control policy. The end-to-end security monitoring module is used to perform real-time security monitoring of the entire process of identity authentication and data sharing.

2. The multi-scene identity authentication and data sharing system based on a real-name DID according to claim 1, characterized in that, The modules are connected in the following way: S1. Collect and preprocess user multi-source identity data in different application scenarios to generate initial identity data; S2. Input the initial identity data into the collaborative attention network model, and perform joint modeling and feature fusion of multi-source identity features under different scenarios through a multi-layer collaborative attention mechanism, and output the fused identity feature representation. S3. Based on the fusion of identity features, the Dragonfly algorithm is used to configure exploration and development behavior units for each dragonfly. The structural parameters and hyperparameters of the collaborative attention network are globally optimized by a centralized training and distributed execution mechanism, and the optimized collaborative attention network model is output. S4. Receive user authentication request, input initial identity data into the optimized collaborative attention network model, perform identity authentication analysis using fused identity feature representation, and output identity authentication result; S5. Based on the identity authentication results and the user's real-name DID, and in accordance with the established data access control policy, manage the user data sharing across multiple scenarios. S6. Perform security monitoring on the entire process of identity authentication and data sharing to ensure data integrity, identity legitimacy and access compliance, and support traceability management of identity authentication and data sharing behavior.

3. The multi-scene identity authentication and data sharing system based on a real-name DID according to claim 2, characterized in that, The multi-source identity data includes biometric data, behavioral data, device fingerprint information, and related environmental data.

4. The multi-scene identity authentication and data sharing system based on a real-name DID according to claim 2, characterized in that, The structural parameters and hyperparameters of the collaborative attention network include the number of network layers, the number of neurons per layer, attention mechanism parameters, and learning rate, based on identity authentication accuracy, recall, and F1 score.

5. The multi-scene identity authentication and data sharing system based on a real-name DID according to claim 2, characterized in that, S2 includes the following specific steps: S21. Input the initial identity data into the collaborative attention network model, classify and organize the initial identity data according to the data source and scenario requirements, and obtain multi-source identity feature data under different scenarios. S22. Use a scenario-specific feature extraction network to extract feature vectors from multi-source identity feature data in different scenarios to generate preliminary feature vectors for each scenario. S23. Input the preliminary feature vectors of each scenario into the first layer collaborative attention mechanism unit, calculate the correlation weights between features of different scenarios, and output the first layer fusion feature representation. S24, input the first layer fusion feature representation into the multi-layer collaborative attention mechanism unit, update and optimize the fusion feature representation layer by layer, dynamically allocate attention weights in each layer according to different scenes and feature categories, and output the final fusion feature representation; S25, input the final fusion feature representation into the identity feature expression subunit, perform feature reconstruction, and generate a fusion identity feature representation.

6. The multi-scene identity authentication and data sharing system based on a real-name DID according to claim 2, characterized in that, The S3 includes the following specific steps: S31, receive the fusion identity feature representation, initialize the dragonfly algorithm population using the dragonfly algorithm, and assign initial values of structure parameters and hyperparameters of the collaborative attention network to each dragonfly body; S32, configure an exploration behavior unit and a development behavior unit for each dragonfly body, and calculate the current position of each dragonfly body in the parameter space according to the fusion identity feature representation; S33, use the exploration behavior unit and the development behavior unit to guide the position update of the dragonfly body in the parameter space, and generate updated structure parameters and hyperparameters; S34, use a centralized training mechanism to train the collaborative attention network model corresponding to each dragonfly body, and evaluate the fitness value of each dragonfly body based on the training result; S35, use a distributed execution mechanism to guide the global search direction of the dragonfly body according to the fitness value, update the structure parameters and hyperparameters of each dragonfly body in the population, and obtain a new generation of dragonfly body distribution: wherein, Θ t+1 denotes the structure parameters and hyperparameters of the new generation of dragonfly, N denotes the number of dragonflies, M denotes the number of types of parameters in the collaborative attention network, w ij denotes the weighting coefficient of the i-th dragonfly on the j-th type of parameter, Θ i,t denotes the structure parameters and hyperparameters of the i-th dragonfly in the t-th generation, i denotes the number of dragonflies, j denotes the number of types of structure parameters and hyperparameters in the collaborative attention network, and t denotes the iteration number of the current generation. S36, when the number of iterations reaches 500, the optimal structure parameters and hyperparameters are generated, and the collaborative attention network model is optimized, and the optimized collaborative attention network model is output.

7. The multi-scene identity authentication and data sharing system based on a real-name DID according to claim 2, characterized in that, The S4 includes the following specific steps: S41, receive a user authentication request, extract initial identity data of the user, and perform format processing on the initial identity data to generate standardized identity data; S42, input the standardized identity data into the optimized collaborative attention network model, use the optimized collaborative attention network model structure to perform multi-layer feature extraction on the input data, and output the to-be-fused feature representation; S43, jointly compare the to-be-fused feature representation and the fusion identity feature representation, and calculate the feature similarity score: wherein, Ψ represents the feature similarity score, L represents the feature dimension number, x k represents the kth dimension of the feature to be fused, y k represents the kth dimension of the fused identity feature, Θ t+1,k represents the kth dimension of the optimal structure parameter and hyperparameter, and k represents the number of feature dimensions. S44, input the feature similarity score into the identity authentication discrimination unit, perform identity discrimination according to the set authentication threshold, and generate a preliminary identity determination; S45, perform credibility evaluation on the preliminary identity determination, combine the confidence output of the optimized collaborative attention network model, and generate an identity authentication result.

8. The multi-scene identity authentication and data sharing system based on a real-name DID according to claim 2, characterized in that, The S5 includes the following specific steps: S51, receive the final identity authentication determination output and the user's real-name DID decentralized identity, and combine to generate an identity access token; S52, according to the identity access token, retrieve the preset data access control strategy, and combine the feature similarity score to calculate the scene access weight: wherein, Ω represents a multi-scenario comprehensive access weight, Q represents a number of scenarios involved by a current user, N q represents a number of defined data access rules under the qth scenario, m represents a serial number of the mth data access rule under the qth scenario, Ψ represents a feature similarity score, W q,m represents a weight coefficient of the mth rule under the qth scenario, S q,m represents a sensitivity coefficient of the mth rule under the qth scenario, P q represents a priority coefficient of the qth scenario. S53, match the access rule set with the current identity access token, filter out the effective rules in the rule set, and generate a scene access permission set; S54, according to the scene access permission set, identify the list of data resources allowed to access in the target scene, and generate a scene data authorization instruction; S55, transmit the scene data authorization instruction to the data management unit, and perform permission check and processing on the data requested by the user according to the instruction by the data management unit to form a scene data sharing processing result; S56, return the scene data sharing processing result to the user, and complete the data sharing management in multiple scenes.

9. The multi-scene identity authentication and data sharing system based on a real-name DID according to claim 2, characterized in that, The S6 includes the following specific steps: S61, collect authentication request information, data access request information and related metadata in the whole process of multi-scene identity authentication and data sharing, and form a security monitoring initial data packet; S62, format the security monitoring initial data packet, extract authentication decision results, data sharing decision results, authentication subject identifiers, data resource identifiers, etc., and generate a security attribute association data set; S63, integrity check the security attribute association data set, generate an integrity check tag and bind it to obtain a security check output packet; S64, perform identity legality detection on the security check output packet, output an identity legality decision result combined with the identity legality rules, and merge it with the security check output packet to form a compliance detection input packet; S65, perform data access compliance detection on the compliance detection input packet, generate an access compliance decision result according to the data access control strategy and behavior audit rules, and obtain a compliance detection output packet; S66, perform real-time archiving and traceability indexing on the compliance detection output packet, and store the various decision results and check tags in multiple dimensions to realize whole-process traceability query and behavior traceability management.

Citation Information

Patent Citations

  • Overdue risk prediction method for optimizing multi-core support vector machine based on dragonfly algorithm

    CN113239638A

  • Intelligent access control management method and system based on multi-mode identification and Internet of Things technology

    CN118968665A

  • Shared storage method and device for multi-source data

    CN120180468A

  • Domain name information processing and displaying method based on multi-modal data fusion

    CN120342997A

  • Identity authentication method, server, and storage medium

    US20170351852A1