Multi-scene identity authentication and data sharing system based on real-name DID
By using a multi-scenario identity authentication and data sharing system based on real-name DID, and leveraging multi-source heterogeneous data fusion and collaborative attention networks, combined with the Dragonfly algorithm for global optimization, the system solves the centralization risk of identity authentication systems and the security issues of data sharing. It achieves accurate authentication and secure sharing, improving the accuracy of identity authentication and the efficiency of data flow.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- WUHAN JIEWAI TECHNOLOGY CO LTD
- Filing Date
- 2025-09-02
- Publication Date
- 2026-05-19
AI Technical Summary
Existing identity authentication systems suffer from centralized management risks, insufficient identity data fusion capabilities across multiple scenarios, inadequate model optimization, and insufficient data sharing security. In particular, they lack intelligent and holistic solutions for identity authentication and data sharing under multi-source heterogeneous data.
It adopts a multi-scenario identity authentication and data sharing system based on real-name DID. Through the fusion of multi-source heterogeneous identity data and collaborative attention mechanism network, combined with the Dragonfly algorithm for global optimization, it realizes the joint modeling and deep fusion of multi-dimensional identity features. It is equipped with full-process security monitoring and traceability management, and supports the allocation and sharing of data access permissions in multiple scenarios.
It achieves accurate user identity authentication and secure data sharing across multiple scenarios, improving the accuracy and robustness of identity authentication, ensuring data integrity and compliance, reducing the risk of model overfitting and resource waste, and enhancing the system's security, controllability, and data flow efficiency.
Smart Images

Figure CN120979767B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of identity authentication security technology, and in particular to a multi-scenario identity authentication and data sharing system based on real-name DID. Background Technology
[0002] With the rapid development of the digital economy and the widespread application of internet and IoT technologies, identity authentication and data sharing have become core capabilities in various digital scenarios. In numerous application areas such as finance, healthcare, government affairs, education, and social networking, accurate user identification and secure data sharing are crucial for ensuring business compliance, improving service efficiency, and promoting the flow of data elements. Currently, traditional identity authentication methods mainly rely on single or multi-factor authentication methods such as usernames, passwords, and SMS verification codes. Some high-security scenarios have introduced biometric recognition technology, supplemented by security tokens, dynamic passwords, and other security enhancement measures. While these traditional methods have improved the security of identity authentication to some extent, they still have many limitations in multi-scenario, multi-data, and dynamic environments.
[0003] First, traditional identity authentication systems generally adopt a centralized management model, with user identity data stored centrally in the database of a single service provider or organization. This model not only makes users vulnerable to attacks, increasing the risk of data leakage and tampering, but also limits users' control over their identity data, making it difficult to achieve self-control over their personal data. Furthermore, the lack of unified standards and mutual trust mechanisms between identity authentication systems in different application scenarios leads to problems such as duplicate registration, duplicate authentication, and information silos when users need to authenticate across platforms and services and share data, severely impacting user experience and data flow efficiency.
[0004] Secondly, current capabilities for multi-source identity data fusion and modeling are limited. In practical applications, user identity data often comes from diverse sources, including biometrics, behavioral characteristics, device fingerprints, and environmental information. These data exhibit different forms and feature distributions in different scenarios, making it difficult for existing technologies to efficiently integrate multi-source heterogeneous identity data and achieve a comprehensive, dynamic, and accurate characterization of user identities. Some studies have attempted to improve identity recognition accuracy using methods such as multimodal feature fusion and feature selection, but due to the fusion mechanism being singular or lacking scenario awareness, they generally fail to fully explore the deep relationships between various types of data, resulting in insufficient reliability and adaptability of authentication.
[0005] Furthermore, regarding the optimization of the structure and parameters of identity authentication models, mainstream methods often rely on human experience or hyperparameter tuning based on single indicators, lacking intelligent and global optimization mechanisms. This not only affects the model's generalization ability across multiple scenarios but may also lead to excessive resource consumption or unsatisfactory model convergence. In recent years, some studies have introduced swarm intelligence optimization algorithms for the automatic optimization of neural network parameters; however, in complex scenarios such as identity authentication and data sharing, there is still a lack of compatibility with multi-source features, dynamic scenarios, and diverse model structures.
[0006] Furthermore, compliance and security issues in data sharing are becoming increasingly prominent. Existing data sharing mechanisms are mostly based on access control lists and role-based access control, lacking intelligent authorization strategies based on authentication results and dynamic scenario weighting. This makes it difficult to address the flexible management needs of multiple users, resources, and policies in complex scenarios. During data sharing, real-time monitoring and traceability of data integrity, identity legitimacy, and access behavior compliance are also not adequately guaranteed. Once security incidents such as data leaks or unauthorized access occur, they are often difficult to detect and trace in a timely manner, posing significant risks to users and data managers.
[0007] Decentralized identity systems have garnered industry attention in recent years due to their advantages, including user control over identity data, cross-platform trusted recognition, and privacy protection. Some projects have attempted to apply DID (Distributed Identity) to identity authentication and data sharing, but they still face numerous challenges in key technical areas such as multi-source heterogeneous data fusion, efficient model optimization, and end-to-end security monitoring. For example, most existing DID solutions focus on identity generation and storage, lacking deep modeling and intelligent authentication support for large-scale, multi-source identity data, and their security and compliance management mechanisms for multi-scenario data sharing are also inadequate.
[0008] Therefore, how to provide a multi-scenario identity authentication and data sharing system based on real-name DID is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0009] One objective of this invention is to propose a multi-scenario identity authentication and data sharing system based on real-name DID. This invention constructs a multi-source heterogeneous identity data fusion and collaborative attention mechanism network to achieve joint modeling and deep fusion of multi-dimensional identity features from biometrics, behavioral data, device fingerprints, and environmental information across multiple scenarios. By combining the Dragonfly algorithm with global optimization and distributed training of the structural parameters and hyperparameters of the collaborative attention network, it significantly improves the ability to express identity features and the generalization performance of the authentication model. It enables accurate user authentication and intelligent judgment of data access permissions in multiple scenarios. Furthermore, through full-process security monitoring and traceability management, it ensures data integrity, access compliance, and identity legitimacy. It integrates core capabilities such as multi-source data collection, feature fusion, intelligent authentication, permission allocation, security monitoring, and traceability management, constructing an integrated solution for real-name DID identity authentication and data sharing for multi-scenario applications.
[0010] According to an embodiment of the present invention, a multi-scenario identity authentication and data sharing system based on real-name DID includes:
[0011] The multi-source identity data acquisition and preprocessing module is used to collect multi-source identity data of users in different application scenarios and preprocess it to generate initial identity data.
[0012] The collaborative attention feature fusion module is used to jointly model and fuse multi-source identity features in different scenarios through a multi-layer collaborative attention mechanism.
[0013] The collaborative attention network model optimization module is used to globally optimize the structural parameters and hyperparameters of the collaborative attention network using a centralized training and distributed execution mechanism.
[0014] The identity authentication analysis module is used to receive user authentication requests and perform identity authentication analysis using fused identity feature representations.
[0015] The data access control and sharing management module is used to allocate and manage data access permissions for user data in multiple scenarios based on identity authentication results and user real-name DID, according to the established data access control policy.
[0016] The end-to-end security monitoring module is used to perform real-time security monitoring of the entire process of identity authentication and data sharing.
[0017] Optionally, modules can be integrated using the following methods:
[0018] S1. Collect and preprocess user multi-source identity data in different application scenarios to generate initial identity data;
[0019] S2. Input the initial identity data into the collaborative attention network model, and perform joint modeling and feature fusion of multi-source identity features under different scenarios through a multi-layer collaborative attention mechanism, and output the fused identity feature representation.
[0020] S3. Based on the fusion of identity features, the Dragonfly algorithm is used to configure exploration and development behavior units for each dragonfly. The structural parameters and hyperparameters of the collaborative attention network are globally optimized by a centralized training and distributed execution mechanism, and the optimized collaborative attention network model is output.
[0021] S4. Receive user authentication request, input initial identity data into the optimized collaborative attention network model, perform identity authentication analysis using fused identity feature representation, and output identity authentication result;
[0022] S5. Based on the identity authentication results and the user's real-name DID, and in accordance with the established data access control policy, manage the user data sharing across multiple scenarios.
[0023] S6. Perform security monitoring on the entire process of identity authentication and data sharing to ensure data integrity, identity legitimacy and access compliance, and support traceability management of identity authentication and data sharing behavior.
[0024] Optionally, the multi-source identity data includes biometric data, behavioral data, device fingerprint information, and related environmental data.
[0025] Optionally, the structural parameters and hyperparameters of the collaborative attention network include the number of network layers, the number of neurons per layer, attention mechanism parameters, and learning rate, based on identity authentication accuracy, recall, and F1 score.
[0026] Optionally, step S2 includes the following specific steps:
[0027] S21. Input the initial identity data into the collaborative attention network model, classify and organize the initial identity data according to the data source and scenario requirements, and obtain multi-source identity feature data under different scenarios.
[0028] S22. Use a scenario-specific feature extraction network to extract feature vectors from multi-source identity feature data in different scenarios to generate preliminary feature vectors for each scenario.
[0029] S23. Input the preliminary feature vectors of each scenario into the first layer collaborative attention mechanism unit, calculate the correlation weights between features of different scenarios, and output the first layer fusion feature representation.
[0030] S24. Input the first-layer fused feature representation into the multi-layer collaborative attention mechanism unit, update and optimize the fused feature representation layer by layer, dynamically allocate attention weights in each layer according to different scenarios and feature categories, and output the final fused feature representation.
[0031] S25. Input the final fused feature representation into the identity feature representation subunit, perform feature reconstruction, and generate the fused identity feature representation.
[0032] Optionally, step S3 includes the following specific steps:
[0033] S31. Receive the fused identity feature representation, adopt the Dragonfly algorithm, initialize the Dragonfly algorithm population, and assign initial values of the structural parameters and hyperparameters of the collaborative attention network to each dragonfly.
[0034] S32. Configure exploration behavior units and development behavior units for each dragonfly body, and calculate the current position of each dragonfly body in the parameter space based on the fused identity feature representation;
[0035] S33. Using exploratory and developmental behavior units, guide the dragonfly body to update its position in the parameter space, generating updated structural parameters and hyperparameters.
[0036] S34. A centralized training mechanism is adopted to train the collaborative attention network model corresponding to each dragonfly body, and the fitness value of each dragonfly body is evaluated based on the training results.
[0037] S35. Employing a distributed execution mechanism, the global search direction of dragonfly bodies is guided by fitness values, and the structural parameters and hyperparameters of each dragonfly body in the population are updated to obtain the distribution of the new generation of dragonfly bodies:
[0038]
[0039] Where, Θ t+1 The structural parameters and hyperparameters of the new generation of dragonfly bodies are represented, N represents the number of dragonfly bodies, M represents the number of parameter types in the collaborative attention network, and w ij Θ represents the weighting coefficient of the i-th dragonfly body on the j-th type of parameter. i,t Let i represent the structural parameters and hyperparameters of the i-th dragonfly body in the t-th generation, i represent the dragonfly body number, j represent the type number of the structural parameters and hyperparameters in the collaborative attention network, and t represent the generation number of the current iteration.
[0040] S36. When the number of iterations reaches 500, generate the optimal structural parameters and hyperparameters, optimize the collaborative attention network model, and output the optimized collaborative attention network model.
[0041] Optionally, step S4 includes the following specific steps:
[0042] S41. Receive user authentication request, extract the user's initial identity data, and format the initial identity data to generate standardized identity data;
[0043] S42. Input standardized identity data into the optimized collaborative attention network model, use the optimized collaborative attention network model structure to perform multi-layer feature extraction on the input data, and output the feature representation to be fused.
[0044] S43. Jointly compare the feature representation to be fused with the fused identity feature representation, and calculate the feature similarity score:
[0045]
[0046] Where Ψ represents the feature similarity score, L represents the number of feature dimensions, and x k Let y represent the k-th dimension feature to be fused. k Θ represents the k-th dimension fused identity feature. t+1,k Let represent the optimal structural parameters and hyperparameters in the k-th dimension, where k represents the number of the feature dimension;
[0047] S44. Input the feature similarity score into the identity authentication discrimination unit, perform identity discrimination according to the set authentication threshold, and generate a preliminary identity determination;
[0048] S45. Conduct a credibility assessment on the preliminary identity determination, and generate the identity authentication result by combining the confidence output of the optimized collaborative attention network model.
[0049] Optionally, step S5 includes the following specific steps:
[0050] S51. Receive the final identity authentication judgment output and the user's real-name DID decentralized identity identifier, and combine them to generate an identity access token;
[0051] S52. Based on the identity access token, retrieve the preset data access control policy, and calculate the scene access weight by combining the feature similarity score:
[0052]
[0053] Where Ω represents the comprehensive access weight across multiple scenarios, Q represents the number of scenarios involved for the current user, and N q Let represent the number of defined data access rules in the q-th scenario, m represent the sequence number of the m-th data access rule in the q-th scenario, Ψ represent the feature similarity score, and W represent the number of defined data access rules in the q-th scenario. q,m S represents the weight coefficient of the m-th rule in the q-th scenario. q,m P represents the sensitivity coefficient of the m-th rule in the q-th scenario. q This represents the priority coefficient of the q-th scenario;
[0054] S53. Match the access rule set with the current identity access token, filter out the valid rules in the rule set, and generate the scene access permission set;
[0055] S54. Based on the scene access permission set, identify the list of data resources that are allowed to be accessed in the target scene, and generate scene data authorization instructions;
[0056] S55. The scene data authorization instruction is transmitted to the data management unit, which performs permission verification and processing on the data requested by the user according to the instruction, and forms the scene data sharing processing result.
[0057] S56. Return the scene data sharing processing results to the user to complete the data sharing management in multiple scenarios.
[0058] Optionally, step S6 includes the following specific steps:
[0059] S61. Collect authentication request information, data access request information, and related metadata throughout the entire process of identity authentication and data sharing in multiple scenarios to form an initial data packet for security monitoring;
[0060] S62. Format the initial data packet for security monitoring, extract authentication judgment results, data sharing judgment results, authentication subject identifier, data resource identifier, etc., and generate a security attribute association dataset.
[0061] S63. Perform integrity verification on the security attribute associated dataset, generate integrity verification labels and bind them to obtain the security verification output package;
[0062] S64. Perform identity legitimacy checks on the security verification output packet, combine the identity legitimacy rules to output the identity legitimacy judgment result, and merge it with the security verification output packet to form a compliance check input packet;
[0063] S65. Perform data access compliance checks on the compliance check input package, generate access compliance judgment results based on data access control policies and behavior audit rules, and obtain a compliance check output package;
[0064] S66. Perform real-time archiving and traceability indexing of compliance testing output packages, store various judgment results and verification labels in multiple dimensions, and realize full-process traceability query and behavior traceability management.
[0065] The beneficial effects of this invention are:
[0066] Compared to existing technologies, this invention achieves significant advantages. Firstly, by introducing a decentralized identity system, user identity information achieves autonomous control and reliable cross-domain circulation, overcoming the data silos and security vulnerabilities of traditional centralized identity authentication, and greatly improving the security and privacy protection of user data. Secondly, through the deep collection and fusion of multi-source heterogeneous identity data, the system can comprehensively utilize multi-dimensional data such as biometrics, behavioral data, device fingerprints, and environmental information to achieve a comprehensive and dynamic characterization of user identity, effectively improving the accuracy and robustness of identity authentication and adapting to the high security and reliability requirements of complex and ever-changing application scenarios such as finance, healthcare, and government affairs.
[0067] Secondly, this invention innovatively combines a collaborative attention network model with the Dragonfly algorithm, enabling global dynamic optimization of the structural parameters and hyperparameters of the collaborative attention network. This overcomes the bottlenecks of traditional manual experience and single-index tuning, significantly improving the feature representation ability and generalization performance of the collaborative attention network. Through a centralized training and distributed execution mechanism, the system can efficiently handle large-scale authentication requests from multiple scenarios and users, ensuring the efficiency and real-time nature of the authentication process and significantly reducing the risk of model overfitting and resource waste.
[0068] In terms of data sharing management, this invention, based on identity authentication results and real-name DID, combined with intelligent data access control strategies, achieves fine-grained dynamic authorization of user data and secure sharing in multiple scenarios. This completely changes the limitations of traditional static permission configuration and coarse-grained management, greatly improving data flow efficiency and compliance. The introduction of end-to-end security monitoring and traceability mechanisms effectively ensures data integrity, identity legitimacy, and compliance of access behavior during authentication and data sharing. Real-time alerts and behavior tracing are possible in case of abnormal behavior, enhancing the overall security and controllability of the system.
[0069] In summary, this invention not only solves the prominent problems of fragmented identity authentication systems, weak data fusion capabilities, insufficient model optimization, and uncontrollable data sharing security in existing technologies, but also provides an efficient, intelligent, secure, and traceable overall solution for real-name identity authentication and data sharing in multiple scenarios. It provides solid technical support for the healthy development of the digital economy and the data element market, and has broad application prospects and significant socio-economic value. Attached Figure Description
[0070] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:
[0071] Figure 1This is a flowchart of the method for a multi-scenario identity authentication and data sharing system based on real-name DID proposed in this invention;
[0072] Figure 2 This is a system flowchart of the multi-scenario identity authentication and data sharing system based on real-name DID proposed in this invention;
[0073] Figure 3 This is a data flow diagram of the multi-scenario identity authentication and data sharing system based on real-name DID proposed in this invention. Detailed Implementation
[0074] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.
[0075] refer to Figure 1-3 A multi-scenario identity authentication and data sharing system based on real-name DID, including:
[0076] The multi-source identity data acquisition and preprocessing module is used to collect multi-source identity data of users in different application scenarios and preprocess it to generate initial identity data.
[0077] The collaborative attention feature fusion module is used to jointly model and fuse multi-source identity features in different scenarios through a multi-layer collaborative attention mechanism.
[0078] The collaborative attention network model optimization module is used to globally optimize the structural parameters and hyperparameters of the collaborative attention network using a centralized training and distributed execution mechanism.
[0079] The identity authentication analysis module is used to receive user authentication requests and perform identity authentication analysis using fused identity feature representations.
[0080] The data access control and sharing management module is used to allocate and manage data access permissions for user data in multiple scenarios based on identity authentication results and user real-name DID, according to the established data access control policy.
[0081] The end-to-end security monitoring module is used to perform real-time security monitoring of the entire process of identity authentication and data sharing.
[0082] This invention achieves comprehensive modeling of users' multi-dimensional identity features through multi-source identity data collection and multi-layer collaborative attention feature fusion. Combined with network optimization involving centralized training and distributed execution, it effectively improves the accuracy and generalization ability of identity authentication. Furthermore, it includes end-to-end security monitoring and intelligent permission allocation, ensuring the security and flexibility of data sharing across multiple scenarios.
[0083] In this embodiment, the modules are interconnected using the following method:
[0084] S1. Collect and preprocess user multi-source identity data in different application scenarios to generate initial identity data;
[0085] S2. Input the initial identity data into the collaborative attention network model, and perform joint modeling and feature fusion of multi-source identity features under different scenarios through a multi-layer collaborative attention mechanism, and output the fused identity feature representation.
[0086] S3. Based on the fusion of identity features, the Dragonfly algorithm is used to configure exploration and development behavior units for each dragonfly. The structural parameters and hyperparameters of the collaborative attention network are globally optimized by a centralized training and distributed execution mechanism, and the optimized collaborative attention network model is output.
[0087] S4. Receive user authentication request, input initial identity data into the optimized collaborative attention network model, perform identity authentication analysis using fused identity feature representation, and output identity authentication result;
[0088] S5. Based on the identity authentication results and the user's real-name DID, and in accordance with the established data access control policy, manage the user data sharing across multiple scenarios.
[0089] S6. Perform security monitoring on the entire process of identity authentication and data sharing to ensure data integrity, identity legitimacy and access compliance, and support traceability management of identity authentication and data sharing behavior.
[0090] This invention achieves efficient fusion and accurate modeling of multi-source identity features through a multi-layer collaborative attention mechanism and global optimization using the Dragonfly Algorithm. Centralized training and distributed execution improve the model's authentication accuracy. Combined with real-name DID and full-process security monitoring, it effectively ensures the security, compliance, and traceability of data sharing across multiple scenarios, making the identity authentication system more intelligent and reliable.
[0091] In this embodiment, multi-source identity data includes biometric data, behavioral data, device fingerprint information, and related environmental data.
[0092] This invention collects multi-source identity data, including biometrics, behavioral data, device fingerprints, and environmental data, achieving multi-dimensional fusion of identity features. By introducing multi-source heterogeneous data, it can significantly improve the comprehensiveness and robustness of identity authentication, reduce the risk of forgery of single features, and improve the authentication accuracy and security of the system in complex application scenarios.
[0093] In this embodiment, the structural parameters and hyperparameters of the collaborative attention network include the number of network layers, the number of neurons per layer, attention mechanism parameters, and learning rate, based on identity authentication accuracy, recall, and F1 score.
[0094] This invention dynamically optimizes the number of layers, neurons, attention parameters, and learning rate of the collaborative attention network based on the accuracy, recall, and F1 score of identity authentication. Through adaptive adjustment of multi-dimensional parameters, it balances the model's expressive power and generalization ability, improves feature extraction and fusion effects, achieves high accuracy and robustness in identity authentication, and ensures the system's flexibility and stability in different application scenarios.
[0095] In this embodiment, S2 includes the following specific steps:
[0096] S21. Input the initial identity data into the collaborative attention network model, classify and organize the initial identity data according to the data source and scenario requirements, and obtain multi-source identity feature data under different scenarios.
[0097] S22. Use a scenario-specific feature extraction network to extract feature vectors from multi-source identity feature data in different scenarios to generate preliminary feature vectors for each scenario.
[0098] S23. Input the preliminary feature vectors of each scenario into the first layer collaborative attention mechanism unit, calculate the correlation weights between features of different scenarios, and output the first layer fusion feature representation.
[0099] S24. Input the first-layer fused feature representation into the multi-layer collaborative attention mechanism unit, update and optimize the fused feature representation layer by layer, dynamically allocate attention weights in each layer according to different scenarios and feature categories, and output the final fused feature representation.
[0100] S25. Input the final fused feature representation into the identity feature representation subunit, perform feature reconstruction, and generate the fused identity feature representation.
[0101] This invention dynamically fuses multi-source identity feature data from different scenarios through a multi-layer collaborative attention mechanism. By combining scenario-specific feature extraction and hierarchical correlation weighting, it achieves accurate extraction and optimized representation of identity features. This method effectively improves the discriminative power and adaptability of the fused features, providing higher accuracy and robustness for subsequent identity authentication.
[0102] In this embodiment, S3 includes the following specific steps:
[0103] S31. Receive the fused identity feature representation, adopt the Dragonfly algorithm, initialize the Dragonfly algorithm population, and assign initial values of the structural parameters and hyperparameters of the collaborative attention network to each dragonfly.
[0104] S32. Configure exploration behavior units and development behavior units for each dragonfly body, and calculate the current position of each dragonfly body in the parameter space based on the fused identity feature representation;
[0105] S33. Using exploratory and developmental behavior units, guide the dragonfly body to update its position in the parameter space, generating updated structural parameters and hyperparameters.
[0106] S34. A centralized training mechanism is adopted to train the collaborative attention network model corresponding to each dragonfly body, and the fitness value of each dragonfly body is evaluated based on the training results.
[0107] S35. Employing a distributed execution mechanism, the global search direction of dragonfly bodies is guided by fitness values, and the structural parameters and hyperparameters of each dragonfly body in the population are updated to obtain the distribution of the new generation of dragonfly bodies:
[0108]
[0109] Where, Θ t+1 The structural parameters and hyperparameters of the new generation of dragonfly bodies are represented, N represents the number of dragonfly bodies, M represents the number of parameter types in the collaborative attention network, and w ij Θ represents the weighting coefficient of the i-th dragonfly body on the j-th type of parameter. i,t Let i represent the structural parameters and hyperparameters of the i-th dragonfly body in the t-th generation, i represent the dragonfly body number, j represent the type number of the structural parameters and hyperparameters in the collaborative attention network, and t represent the generation number of the current iteration.
[0110] S36. When the number of iterations reaches 500, generate the optimal structural parameters and hyperparameters, optimize the collaborative attention network model, and output the optimized collaborative attention network model.
[0111] This invention employs the Dragonfly Algorithm to globally optimize the structural parameters and hyperparameters of the collaborative attention network. Combined with exploration and development behavior units and a centralized training and distributed execution mechanism, it achieves efficient search and dynamic updating of the parameter space. This method effectively improves the model's convergence speed and fitness, ensuring that the network structure possesses optimal feature representation and generalization capabilities across multiple scenarios.
[0112] In this embodiment, S4 includes the following specific steps:
[0113] S41. Receive user authentication request, extract the user's initial identity data, and format the initial identity data to generate standardized identity data;
[0114] S42. Input standardized identity data into the optimized collaborative attention network model, use the optimized collaborative attention network model structure to perform multi-layer feature extraction on the input data, and output the feature representation to be fused.
[0115] S43. Jointly compare the feature representation to be fused with the fused identity feature representation, and calculate the feature similarity score:
[0116]
[0117] Where Ψ represents the feature similarity score, L represents the number of feature dimensions, and x k Let y represent the k-th dimension feature to be fused. k Θ represents the k-th dimension fused identity feature. t+1,k Let represent the optimal structural parameters and hyperparameters in the k-th dimension, where k represents the number of the feature dimension;
[0118] S44. Input the feature similarity score into the identity authentication discrimination unit, perform identity discrimination according to the set authentication threshold, and generate a preliminary identity determination;
[0119] S45. Conduct a credibility assessment on the preliminary identity determination, and generate the identity authentication result by combining the confidence output of the optimized collaborative attention network model.
[0120] This invention optimizes a collaborative attention network model to extract multi-layer features from standardized identity data, and combines feature similarity scores with dynamic authentication thresholds to achieve accurate comparison and discrimination of identity features. Combined with confidence assessment, it effectively improves the accuracy and reliability of identity authentication, significantly reduces the false positive rate, and ensures the credibility and practicality of the authentication results.
[0121] In this embodiment, S5 includes the following specific steps:
[0122] S51. Receive the final identity authentication judgment output and the user's real-name DID decentralized identity identifier, and combine them to generate an identity access token;
[0123] S52. Based on the identity access token, retrieve the preset data access control policy, and calculate the scene access weight by combining the feature similarity score:
[0124]
[0125] Where Ω represents the comprehensive access weight across multiple scenarios, Q represents the number of scenarios involved for the current user, and N q Let represent the number of defined data access rules in the q-th scenario, m represent the sequence number of the m-th data access rule in the q-th scenario, Ψ represent the feature similarity score, and W represent the number of defined data access rules in the q-th scenario. q,m S represents the weight coefficient of the m-th rule in the q-th scenario. q,m P represents the sensitivity coefficient of the m-th rule in the q-th scenario. q This represents the priority coefficient of the q-th scenario;
[0126] S53. Match the access rule set with the current identity access token, filter out the valid rules in the rule set, and generate the scene access permission set;
[0127] S54. Based on the scene access permission set, identify the list of data resources that are allowed to be accessed in the target scene, and generate scene data authorization instructions;
[0128] S55. The scene data authorization instruction is transmitted to the data management unit, which performs permission verification and processing on the data requested by the user according to the instruction, and forms the scene data sharing processing result.
[0129] S56. Return the scene data sharing processing results to the user to complete the data sharing management in multiple scenarios.
[0130] This invention achieves flexible data access permission allocation across multiple scenarios by combining identity authentication, DID (Data Identity Registry), and feature similarity. Based on comprehensive access weights, it dynamically filters optimal access rules and automatically generates scenario-based data authorization instructions, ensuring secure, compliant, and efficient data sharing. This method improves the accuracy and automation of access control, adapting to diverse real-world application scenarios.
[0131] In this embodiment, S6 includes the following specific steps:
[0132] S61. Collect authentication request information, data access request information, and related metadata throughout the entire process of identity authentication and data sharing in multiple scenarios to form an initial data packet for security monitoring;
[0133] S62. Format the initial data packet for security monitoring, extract authentication judgment results, data sharing judgment results, authentication subject identifier, data resource identifier, etc., and generate a security attribute association dataset.
[0134] S63. Perform integrity verification on the security attribute associated dataset, generate integrity verification labels and bind them to obtain the security verification output package;
[0135] S64. Perform identity legitimacy checks on the security verification output packet, combine the identity legitimacy rules to output the identity legitimacy judgment result, and merge it with the security verification output packet to form a compliance check input packet;
[0136] S65. Perform data access compliance checks on the compliance check input package, generate access compliance judgment results based on data access control policies and behavior audit rules, and obtain a compliance check output package;
[0137] S66. Perform real-time archiving and traceability indexing of compliance testing output packages, store various judgment results and verification labels in multiple dimensions, and realize full-process traceability query and behavior traceability management.
[0138] This invention implements layered security monitoring of the entire process of identity authentication and data sharing across multiple scenarios. By combining integrity verification, identity legitimacy, and access compliance detection, it achieves real-time compliance control and traceability management of the entire data access process. This effectively ensures data security, identity compliance, and behavioral traceability, significantly improving the system's security and compliance levels.
[0139] Example 1:
[0140] To verify the feasibility of this invention in practice, it was applied to the data security management system of a large fintech company. This company has over 50,000 employees and handles a large number of identity authentication and data sharing requests involving multiple departments, systems, and business scenarios daily. Previously, the company often faced challenges in identity authentication and data access control across multiple scenarios, including heterogeneous identity information, insufficient feature fusion, difficulty in globally optimizing model parameters, and rudimentary permission allocation and management. This resulted in low accuracy in identity authentication, inflexible data access control, and significant difficulties in security compliance traceability, severely impacting data security and business efficiency.
[0141] The multi-layer collaborative attention network fusion identity authentication and data sharing management method proposed in this invention, in practical deployment, first collects initial identity data from different sources in various business systems within the company, including employee biometric information, device fingerprints, behavior logs, and access history. The system automatically formats and classifies these heterogeneous identity data, and constructs a multi-source identity feature library based on business scenario requirements.
[0142] Next, for different business scenarios, feature vectors are extracted using scenario-specific feature extraction networks to obtain preliminary feature vectors for each business scenario. All preliminary feature vectors are input into a multi-layer collaborative attention mechanism network, where the system dynamically allocates weights and fully integrates feature information from different scenarios to generate a fused identity feature representation with high discriminativeness and business adaptability.
[0143] Subsequently, the Dragonfly algorithm was used to globally optimize the structural parameters and hyperparameters of the collaborative attention network. Through a centralized training and distributed execution mechanism, the Dragonfly agent continuously searches and updates the parameter space, finally obtaining the optimal model parameters after 500 iterations, thus improving the generalization and feature representation capabilities of the network structure.
[0144] When an employee initiates an identity authentication or data access request, the system first standardizes their identity data. Then, it uses an optimized collaborative attention network model to perform multi-layer feature extraction, compares the features to be fused with the stored fused identity features, and calculates a feature similarity score. The system sets a dynamic authentication threshold, combines it with model confidence, automatically makes an identity authentication decision, and provides a credibility assessment.
[0145] By combining decentralized identity identifiers (DIDs) with authentication results to generate identity access tokens, the system automatically retrieves data access control policies and calculates a comprehensive access weight based on factors such as feature similarity and scenario priority. Finally, the system automatically generates and issues data authorization instructions according to the scenario, accurately matching data access permissions and effectively ensuring the security and compliance of data sharing.
[0146] Furthermore, the system conducts security audits on the entire process of identity authentication and data sharing, collecting metadata such as authentication requests and data access requests in real time for integrity and compliance verification. All judgment results and verification tags are stored in multiple dimensions and indexed for traceability, providing strong technical support for subsequent security monitoring and compliance accountability.
[0147] Table 1 Comparison of Optimization Effects of Multi-Scenario Identity Authentication and Data Sharing Systems Based on Real-Name DID
[0148]
[0149] Table 1 shows that after three consecutive months of operation at the fintech company, the system processed 136,428 identity authentication requests and 198,324 data access requests, covering 10 core business areas including human resources, financial approval, customer data management, and R&D document sharing. Compared with the company's existing traditional identity authentication and access control system, the accuracy rate of identity authentication increased from 96.2% to 99.78%, and the false recognition rate decreased from 1.7% to 0.12%. The average identity authentication response latency decreased from 1.86 seconds to 0.93 seconds, significantly improving the user experience. The granularity of data access permission allocation improved, expanding the number of covered scenarios from 6 to 10, increasing the flexibility of permission configuration by approximately 68%. The accuracy rate of access compliance judgment increased to 99.92%, effectively preventing unauthorized access and unauthorized sharing incidents. No data leakage incidents due to incorrect permission configuration occurred within three months. Real-time security auditing and source tracing capabilities enable minute-level behavior tracing, improving security compliance response speed by 3 times and supporting rapid location and accountability for security incidents. The system automatically adjusts authentication thresholds and access policies, balancing security and convenience, and employee satisfaction survey scores have increased from 3.8 to 4.7.
[0150] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A multi-scenario identity authentication and data sharing system based on real-name DID, characterized in that, include: The multi-source identity data acquisition and preprocessing module is used to collect multi-source identity data of users in different application scenarios and preprocess it to generate initial identity data. The collaborative attention feature fusion module is used to jointly model and fuse multi-source identity features in different scenarios through a multi-layer collaborative attention mechanism. The collaborative attention network model optimization module is used to globally optimize the structural parameters and hyperparameters of the collaborative attention network using a centralized training and distributed execution mechanism. The identity authentication analysis module is used to receive user authentication requests and perform identity authentication analysis using fused identity features; The data access control and sharing management module is used to allocate and manage data access permissions for user data in multiple scenarios based on identity authentication results and user real-name DID, according to the established data access control policy. The end-to-end security monitoring module is used for real-time security monitoring of the entire process of identity authentication and data sharing; The modules are connected in the following way: S1. Collect and preprocess user multi-source identity data in different application scenarios to generate initial identity data; S2. Input the initial identity data into the collaborative attention network model, and perform joint modeling and feature fusion of multi-source identity features under different scenarios through a multi-layer collaborative attention mechanism, and output the fused identity feature representation. S3. Based on the fusion of identity features, the Dragonfly algorithm is used to configure exploration and development behavior units for each dragonfly. The structural parameters and hyperparameters of the collaborative attention network are globally optimized by a centralized training and distributed execution mechanism, and the optimized collaborative attention network model is output. S4. Receive user authentication request, input initial identity data into the optimized collaborative attention network model, perform identity authentication analysis using fused identity feature representation, and output identity authentication result; S5. Generate an identity access token by combining the user's real-name DID with the identity authentication result. Based on the identity access token, retrieve the preset data access control policy to perform data sharing management of user data in multiple scenarios. The system automatically generates and issues data authorization instructions according to the scenario to accurately match data access permissions. S6. Perform security monitoring on the entire process of identity authentication and data sharing to ensure data integrity, identity legitimacy and access compliance, and support traceability management of identity authentication and data sharing behavior; The multi-source identity data includes biometric data, behavioral data, device fingerprint information, and related environmental data.
2. The multi-scenario identity authentication and data sharing system based on real-name DID as described in claim 1, characterized in that, The structural parameters and hyperparameters of the collaborative attention network include the number of network layers, the number of neurons per layer, attention mechanism parameters, and learning rate, based on identity authentication accuracy, recall, and F1 score.
3. The multi-scenario identity authentication and data sharing system based on real-name DID as described in claim 1, characterized in that, S2 includes the following specific steps: S21. Input the initial identity data into the collaborative attention network model, classify and organize the initial identity data according to the data source and scenario requirements, and obtain multi-source identity feature data under different scenarios. S22. Use a scene feature extraction network to extract feature vectors from multi-source identity feature data in different scenarios to generate preliminary feature vectors for each scenario. S23. Input the preliminary feature vectors of each scenario into the first layer collaborative attention mechanism unit, calculate the correlation weights between features of different scenarios, and output the first layer fusion feature representation. S24. Input the first-layer fused feature representation into the multi-layer collaborative attention mechanism unit, update and optimize the fused feature representation layer by layer, dynamically allocate attention weights in each layer according to different scenarios and feature categories, and output the final fused feature representation. S25. Input the final fused feature representation into the identity feature representation subunit, perform feature reconstruction, and generate the fused identity feature representation.
4. The multi-scenario identity authentication and data sharing system based on real-name DID as described in claim 1, characterized in that, S3 includes the following specific steps: S31. Receive the fused identity feature representation, adopt the Dragonfly algorithm, initialize the Dragonfly algorithm population, and assign initial values of the structural parameters and hyperparameters of the collaborative attention network to each dragonfly. S32. Configure exploration behavior units and development behavior units for each dragonfly body, and calculate the current position of each dragonfly body in the parameter space based on the fused identity feature representation; S33. Using exploratory and developmental behavior units, guide the dragonfly body to update its position in the parameter space, generating updated structural parameters and hyperparameters. S34. A centralized training mechanism is adopted to train the collaborative attention network model corresponding to each dragonfly body, and the fitness value of each dragonfly body is evaluated based on the training results. S35. Employing a distributed execution mechanism, the global search direction of dragonfly bodies is guided by fitness values, and the structural parameters and hyperparameters of each dragonfly body in the population are updated to obtain the distribution of the new generation of dragonfly bodies: ; in, The structural parameters and hyperparameters of the new generation of dragonfly bodies are represented by N, where N represents the number of dragonfly bodies and M represents the number of parameter types in the collaborative attention network. This represents the weighting coefficient of the i-th dragonfly body on the j-th type of parameter. Let i represent the structural parameters and hyperparameters of the i-th dragonfly body in the t-th generation, i represent the dragonfly body number, j represent the type number of the structural parameters and hyperparameters in the collaborative attention network, and t represent the generation number of the current iteration. S36. When the number of iterations reaches 500, generate the optimal structural parameters and hyperparameters, optimize the collaborative attention network model, and output the optimized collaborative attention network model.
5. The multi-scenario identity authentication and data sharing system based on real-name DID according to claim 1, characterized in that, S4 includes the following specific steps: S41. Receive user authentication request, extract the user's initial identity data, and format the initial identity data to generate standardized identity data; S42. Input standardized identity data into the optimized collaborative attention network model, use the optimized collaborative attention network model structure to perform multi-layer feature extraction on the input data, and output the feature representation to be fused. S43. Jointly compare the feature representation to be fused with the fused identity feature representation, and calculate the feature similarity score: ; in, Represents the feature similarity score. Number of feature dimensions This represents the k-th dimension feature to be fused. This represents the k-th dimension of the fused identity feature. Let represent the optimal structural parameters and hyperparameters in the k-th dimension, where k represents the number of the feature dimension; S44. Input the feature similarity score into the identity authentication discrimination unit, perform identity discrimination according to the set authentication threshold, and generate a preliminary identity determination; S45. Conduct a credibility assessment on the preliminary identity determination, and generate the identity authentication result by combining the confidence output of the optimized collaborative attention network model.
6. The multi-scenario identity authentication and data sharing system based on real-name DID according to claim 1, characterized in that, S5 includes the following specific steps: S51. Receive the final identity authentication judgment output and the user's real-name DID decentralized identity identifier, and combine them to generate an identity access token; S52. Based on the identity access token, retrieve the preset data access control policy, and calculate the scene access weight by combining the feature similarity score: ; in, This indicates the overall access weight across multiple scenarios. This indicates the number of scenarios currently involved for the user. This represents the number of data access rules defined in the q-th scenario, where m represents the sequence number of the m-th data access rule in the q-th scenario. Represents the feature similarity score. This represents the weight coefficient of the m-th rule in the q-th scenario. Let represent the sensitivity coefficient of the m-th rule in the q-th scenario. This represents the priority coefficient of the q-th scenario; S53. Match the access rule set with the current identity access token, filter out the valid rules in the rule set, and generate the scene access permission set; S54. Based on the scene access permission set, identify the list of data resources that are allowed to be accessed in the target scene, and generate scene data authorization instructions; S55. The scene data authorization instruction is transmitted to the data management unit, which performs permission verification and processing on the data requested by the user according to the instruction, and forms the scene data sharing processing result. S56. Return the scene data sharing processing results to the user to complete the data sharing management in multiple scenarios.
7. The multi-scenario identity authentication and data sharing system based on real-name DID according to claim 1, characterized in that, S6 includes the following specific steps: S61. Collect authentication request information, data access request information, and related metadata throughout the entire process of identity authentication and data sharing in multiple scenarios to form an initial data packet for security monitoring; S62. Format the initial data packet for security monitoring, extract the authentication judgment result, data sharing judgment result, authentication subject identifier, and data resource identifier, and generate a security attribute association dataset. S63. Perform integrity verification on the security attribute associated dataset, generate integrity verification labels and bind them to obtain the security verification output package; S64. Perform identity legitimacy checks on the security verification output packet, combine the identity legitimacy rules to output the identity legitimacy judgment result, and merge it with the security verification output packet to form a compliance detection input packet; S65. Perform data access compliance checks on the compliance check input package, generate access compliance judgment results based on data access control policies and behavior audit rules, and obtain a compliance check output package; S66. Perform real-time archiving and traceability indexing of compliance testing output packages, store various judgment results and verification labels in multiple dimensions, and realize full-process traceability query and behavior traceability management.