Account authentication method and device, storage medium and electronic equipment
By receiving implicit behavioral data from the terminal and using the server-side authentication level judgment model, the authentication level of the user account is dynamically evaluated, solving the problem that the Super SIM card cannot identify the terminal holder, and achieving effective identification of the terminal holder and reduction of security risks.
Patent Information
- Application Number
- CN202511302353.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-12
- Publication Date
- 2025-11-21
AI Technical Summary
Existing technology cannot determine whether the terminal device installed on the Super SIM card is actually owned and operated by the user, leading to security risks such as identity theft and account fraud.
By receiving implicit behavioral data sent by the terminal, a comprehensive risk assessment is conducted using the server-side authentication level judgment model, the authentication level is dynamically output, and the corresponding authentication process is triggered. By combining user behavior data and account authentication information, a dynamic risk control mechanism based on behavior perception is constructed.
Effectively identify whether the terminal is owned and operated by the user, reduce the security risks of identity theft and account fraud, and achieve an authentication mechanism that balances high security and user experience.
Smart Images

Figure CN121000490A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, specifically to an account authentication method, apparatus, storage medium, and electronic device. Background Technology
[0002] In the current field of information security and identity authentication, many applications currently use Super SIM card-based identity recognition technology for account authentication. This technology uses the Super SIM card as the storage medium for security tokens and uses built-in encryption algorithms and security chips to authenticate user identities.
[0003] Currently, Super SIM cards are generally considered trusted identity credentials. When a user inserts and uses a Super SIM card for authentication, the system assumes the user is the legitimate holder, thus completing the account verification process. However, this authentication method only verifies the legitimacy of the Super SIM card itself and cannot determine whether the terminal device installed on the Super SIM card is actually owned and operated by the user. This could potentially lead to security risks such as identity theft and account fraud. Summary of the Invention
[0004] In view of this, this application provides an account authentication method, device, storage medium and electronic device, the main purpose of which is to improve the technical problem that the current authentication method cannot determine whether the terminal device installed on the Super SIM card is actually held and operated by the user, which may lead to security risks such as identity theft and account fraud.
[0005] Firstly, this application provides an account authentication method applied on the server side, including:
[0006] The receiver receives implicit behavior data sent by the terminal, which is generated by the terminal after compressing and converting user behavior data;
[0007] Obtain the authentication information corresponding to the user account;
[0008] Based on the implicit behavioral data and the authentication information, the authentication level of the user account is determined, and the authentication level is used to indicate the authentication method required to complete the authentication.
[0009] Based on the authentication level, the corresponding authentication process is triggered and an authentication result is generated.
[0010] Secondly, this application provides an account authentication method, characterized in that it is applied to the terminal side and includes:
[0011] In response to authentication requests initiated by third-party applications, user behavior data is obtained based on the authentication and authorization detection applet integrated in the Super SIM card;
[0012] Based on the implicit compression and transformation model of the data stored in the super SIM card, the user behavior data is converted into implicit behavior data;
[0013] The implicit behavior data is sent to the server. The server uses the implicit behavior data and the authentication information to determine the authentication level of the user account. The authentication level indicates the authentication method required to complete the authentication. Based on the authentication level, the server triggers the corresponding authentication process and generates the authentication result.
[0014] Thirdly, this application provides an account authentication device applied on the server side, including:
[0015] The receiving module is configured to receive implicit behavior data sent by the terminal, wherein the implicit behavior data is generated by the terminal after compressing and converting the collected user behavior data;
[0016] The acquisition module is configured to retrieve authentication information corresponding to the user account.
[0017] The determination module is configured to determine the authentication level of the user account based on the implicit behavior data and the authentication information, wherein the authentication level is used to indicate the authentication method required to complete the authentication.
[0018] The triggering module is configured to trigger the corresponding authentication process and generate an authentication result based on the authentication level.
[0019] Fourthly, this application provides an account authentication device, characterized in that it is applied to the terminal side and includes:
[0020] The acquisition module is configured to respond to authentication requests initiated by third-party applications and acquire user behavior data based on the authentication and authorization detection applet integrated in the Super SIM card.
[0021] The conversion module is configured to convert the user behavior data into implicit behavior data based on the implicit compression conversion model stored in the super SIM card;
[0022] The sending module is configured to send the implicit behavior data to the server. The implicit behavior data is used by the server to determine the authentication level of the user account based on the implicit behavior data and the authentication information. The authentication level is used to indicate the authentication method required to complete the authentication. According to the authentication level, the corresponding authentication process is triggered and an authentication result is generated.
[0023] Fifthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method described in the first or second aspect.
[0024] In a sixth aspect, this application provides an electronic device, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor executes the computer program to implement the method described in the first or second aspect.
[0025] In a seventh aspect, this application provides a computer program product having a computer program stored thereon, which, when executed by a processor, implements the method described in the first or second aspect.
[0026] By employing the above technical solution, this application provides an account authentication method, apparatus, storage medium, and electronic device. First, it receives implicit behavioral data sent by a terminal, which is generated after the terminal compresses and converts user behavior data. Then, it obtains the authentication information corresponding to the user account. Based on the implicit behavioral data and authentication information, it determines the authentication level of the user account, whereby the authentication level indicates the authentication method required to complete the authentication. Finally, based on the authentication level, it triggers the corresponding authentication process and generates an authentication result. Compared with existing technologies, this application combines user behavior data and account authentication information, utilizes an authentication level judgment model deployed on the server for comprehensive risk assessment, dynamically outputs the corresponding authentication level, and triggers a matching hierarchical authentication process. By constructing a dynamic risk control mechanism based on behavior perception, it effectively identifies whether the terminal is actually held and operated by the user, thereby effectively reducing security risks such as identity theft and account misuse caused by the terminal being misused by others.
[0027] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0028] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0029] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0030] Figure 1 A flowchart illustrating an account authentication method provided in an embodiment of this application is shown;
[0031] Figure 2 A schematic diagram illustrating an example provided in an embodiment of this application is shown;
[0032] Figure 3 A schematic diagram illustrating an example provided in an embodiment of this application is shown;
[0033] Figure 4 A flowchart illustrating another account authentication method provided in an embodiment of this application is shown;
[0034] Figure 5 A schematic diagram illustrating an example provided in an embodiment of this application is shown;
[0035] Figure 6 A schematic diagram illustrating an example provided in an embodiment of this application is shown;
[0036] Figure 7 This paper shows a schematic diagram of the structure of an account authentication device provided in an embodiment of this application;
[0037] Figure 8 A schematic diagram of another account authentication device provided in an embodiment of this application is shown. Detailed Implementation
[0038] The embodiments of this application will now be described in more detail with reference to the accompanying drawings. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.
[0039] Currently, many applications use identity recognition technology based on Super SIM cards. The identity verification process uses the SIM card as the storage medium for the security token. By embedding user identity information and authentication keys inside the SIM card, hardware-level security protection is achieved. During the authentication process, the system verifies the legitimacy of the SIM card in the terminal device to determine the user's identity. When a user holds a Super SIM card with a bound identity and successfully completes the card authentication protocol, they are considered a legitimate user, thus achieving convenient and highly secure identity verification. This technology is widely used in scenarios such as mobile office, remote login, and financial payment.
[0040] To address the technical problem that current authentication methods cannot determine whether the terminal device installed on the Super SIM card is actually owned and operated by the user, potentially leading to security risks such as identity theft and account fraud, this embodiment provides an account authentication method, such as... Figure 1 As shown, applied to the server side, the method includes:
[0041] Step 101: Receive implicit behavior data sent by the terminal.
[0042] Implicit behavioral data is generated by the terminal after compressing and converting user behavior data.
[0043] For example, implicit behavioral data refers to a feature representation that cannot be restored to the original information, generated by localizing, transforming, and encrypting the user's original behavioral data (such as operation logs, terminal logs, input content, etc.) on the terminal side. It is used to protect user privacy and reduce data transmission volume, and can be generated by the terminal using the front-end data implicit compression and transformation model deployed in the super SIM card.
[0044] Optionally, the method in this embodiment may further include: training a data implicit compression and transformation model based on user behavior data samples, the data implicit compression and transformation model being used to compress and transform user behavior data; and sending the trained data implicit compression and transformation model and the corresponding digital signature to the terminal.
[0045] In some examples, a fuzzy identity behavior recognition model can be built on the server side, and implicit user behavior data can be calculated on the terminal based on this model. The fuzzy identity behavior recognition model consists of two collaborative parts: a front-end implicit data compression and transformation model Ml deployed on the terminal side, and an authentication level judgment model Ms deployed on the server side. Model Ml executes on the terminal, loaded and run by an authentication applet in the super SIM card, performing localized compression and nonlinear transformation on the collected user behavior data (including operation logs, terminal logs R2, etc.) to generate irreversible implicit data. This prevents the leakage of original sensitive information, reduces transmission overhead, and improves system efficiency. Model Ms executes on the server side, receiving the implicit data processed by Ml, combining it with user account attribute information, network behavior analysis results (such as the network request set Nr), and historical behavior characteristics to perform a comprehensive risk assessment, outputting the risk level of the current authentication request, and determining whether to trigger an enhanced authentication process. This achieves a secure authentication mechanism that combines "data privacy protection" and "dynamic identity verification."
[0046] For example, the structure of Ml can be as follows Figure 2 As shown, the model's inputs are page operation flow R1 and log R2, and its outputs are R'1 and R'2. For... Its corresponding output is: Its corresponding output is: R i ′ 2 ∈R′ 2′ The specific calculation logic of the model is as follows:
[0047]
[0048] Among them, Q 1,1 Q is the threshold for checking the effectiveness of the workflow. 2,1 To control the flow weight threshold, Q 3,1 Q is the threshold for the propagation of operational flow-related effects. 1,2Q sets the threshold for log validity checks. 2,2 Q is the log weight threshold. 3,2 Set a threshold for the propagation of log association effects. Additionally, Before being fed into the model, attribute compression processing is required. The specific compression logic is as follows: for:
[0049]
[0050] Where, n 1,i For the operation flow The attributes (see step one (1) for details) <1> )quantity, For operation flow The j-th attribute in the diagram is z1, which is the text compression coefficient of the operation pipeline, and r1 is the text transfer correlation coefficient before and after the operation pipeline.
[0051] Before being fed into the model, the text needs to be compressed. The specific compression logic is as follows:
[0052]
[0053] Where, n 2,i For logging Middle I i The number of words, For logging Middle I i The j-th word, z2 is the compression coefficient of the log text, r2 is the correlation coefficient of the text before and after the log, and c(x) represents the code after converting word x according to BERT.
[0054] For example, due to the limited computing resources of terminal devices, which cannot support the local training of complex models, the training of the implicit compression transformation model Ml is completed centrally on the server side. The server trains and optimizes the model based on the user behavior dataset collected and labeled during the R&D process, including typical operation sequences, log patterns and network access characteristics, to generate model parameters with good compression efficiency and privacy protection capabilities. The trained model and its corresponding signature are then sent to the terminal through a secure channel. After verifying that the model signature is correct, the Super SIM Card Authentication Mini Program on the terminal side stores it and uses it for real-time implicit transformation of local user behavior data, ensuring lightweight and efficient edge data preprocessing while ensuring data security.
[0055] Step 102: Obtain the authentication information corresponding to the user account.
[0056] Optionally, the authentication information in this embodiment may include user account attribute information and user network analysis results. The user account attribute information may include user identity identifier, account level, registration time, bound device information, real-name authentication status, historical authentication behavior records, and security risk tags. The user network analysis results may include dynamic behavioral analysis data generated based on recent network behavior, such as access frequency characteristics, request time distribution, commonly used access paths, abnormal login detection results, traffic fluctuation trends, cross-regional access behavior, and deviation from normal behavior patterns. This data is used to support the server's comprehensive judgment of the user's current authentication risk level.
[0057] For example, the server obtains user account attribute information and user network analysis results required for authentication level judgment model inference through the BASS system; specifically, the server extracts recent network traffic data of users from the BASS system to construct a set of network requests:
[0058] N r ={N r,1 =(nt1,nd1,l1),N r,2 = (nt2,nd2,l2),...,N r,n3 =(nt n3 ,nd n3 ,l n3 )}
[0059] Among them, for nt i To record time, td i For the requested path, l i The input information is n3, which is the total number of recent network requests, and n3 = min(P nmax C2), where P lmax This parameter sets the upper limit for a single network request, where C2 represents the number of network requests generated since the last authentication and authorization request.
[0060] Step 103: Determine the authentication level of the user account based on implicit behavioral data and authentication information.
[0061] The authentication level indicates the authentication method required to complete the authentication process.
[0062] Optionally, step 103 may further include: inputting implicit behavioral data, user account attribute information, and user network analysis results into the authentication level judgment model, and outputting the authentication level corresponding to the user account.
[0063] For example, the authentication level judgment model Ms deployed on the server is used to dynamically assess user identity risk and determine authentication strength. After receiving user behavior data R'1 (implicit representation of authentication operation flow) and R'2 (implicit features of terminal logs) from the terminal side after implicit compression and transformation, the model combines the target object T of this authentication, the user's basic information U in the BASS system (such as account level, real-name status, bound device, etc.), and the recent network behavior analysis results Nr (including structured request sequences such as access time, path, and input content) as input feature vectors. The model performs comprehensive analysis through a pre-trained risk recognition algorithm and outputs the risk score or level of the current authentication request. Based on this, it determines whether it belongs to abnormal behavior or high-risk scenario and decides whether to trigger enhanced authentication processes such as secondary verification and biometric authentication, thereby realizing an adaptive identity authentication mechanism based on context awareness and behavior profiling.
[0064] In some examples, the server receives user behavior data uploaded by the terminal through a secure communication channel. After the terminal completes the inference of the implicit compression transformation model Ml for the pre-data locally, it uploads the generated implicit authentication operation behavior data R'1 and the implicit feature data R'2 of the terminal log to the server. After obtaining R'1 and R'2, the server combines the authentication request context, including the authentication target T, the user's basic information U, and the recent network behavior sequence Nr, and inputs it into the authentication level judgment model Ms deployed on the server. This model is used to perform user behavior consistency analysis and risk level determination, realizing identity authentication decision based on multi-source heterogeneous data fusion, and ensuring high-security dynamic identity recognition while protecting user privacy.
[0065] For example, such as Figure 3 As shown, the current authentication level can be obtained based on the authentication level discrimination model of the fuzzy identity behavior recognition model, and the following authentication level discrimination model Ms can be constructed: the model inputs are user operation records R'1, R'2, user network request Nr, authentication target T, and basic information U, L1 to L6 represent various authentication levels (see Table 1 for authentication levels and corresponding terminal authentication methods), ntp is the effective information strength of log information, tdp is the invalid interference coefficient of log information, and nlp is the log correlation influence coefficient.
[0066]
[0067] For example, variable-length data needs to be compressed before being fed into the model. The authentication level discrimination model table length data includes R'1, R'2, and Nr, and the corresponding compression coefficients are: P z ={P z,r1 ,P z,r2 ,P z,nrThe access control coefficients are: P d ={P d,r1 P d,r2 P d,nr The specific compression rules are as follows:
[0068]
[0069] Among them, Z k Z represents the k-th value to be compressed before compression, and Z represents the compression result.
[0070] Optionally, the above-mentioned input of implicit behavioral data, user account attribute information, and user network analysis results into the authentication level judgment model, and outputting the authentication level corresponding to the user account, may further include: compressing the variable-length data in the implicit behavioral data, user account attribute information, and user network analysis results to obtain fixed-length feature vectors; inputting the fixed-length feature vectors into a neural network model containing multiple fully connected layers for processing; calculating the classification probabilities of multiple authentication levels based on the output layer results of the neural network model; and determining the authentication level corresponding to the user account based on the classification probabilities.
[0071] In some examples, after obtaining all the input data of the model, the data is passed through N fully connected layers (including paradox and normalization) to obtain the output, where... Let represent the o-th parameter in the j-th fully connected layer. The model output layer has 6 categories, corresponding to authentication levels L1 to L6. It is connected to the previous layer via a fully connected layer, and after normalization, softmax is used to obtain the final classification result as the authentication level lc. The model's loss function L is:
[0072] L=n(L′ t )-n(L g )
[0073] Among them, L′ t For the target certification level, L g Let n(x) be the target authentication level obtained by the model, where n(x) represents the position where authentication level x is obtained.
[0074] For example, based on the authentication level judgment model Ms outputting the authentication level lc∈{L1,L2,L3,L4,L5,L6}, the server initiates a hierarchical security verification mechanism, dynamically matching the corresponding security verification measures according to the preset authentication policy table: when lc is a low-risk level (such as L1-L2), authentication can be passed by only completing the identity token verification based on the Super SIM card; when lc is a medium-risk level (such as L3-L4), in addition to SIM card authentication, SMS verification code or static password is also required for dual verification; when lc is a high-risk level (such as L5-L6), an enhanced authentication process is triggered, requiring the user to complete biometric recognition (such as face, fingerprint), dynamic behavior verification, or multi-factor authentication; the server sends the authentication command to the terminal, and the Super SIM card, in conjunction with the STK mini-program, guides the user to complete the corresponding level of verification operation. After confirming that all authentication elements have passed, the server returns the authorization authentication result to the third-party application, realizing an adaptive authentication system that accurately matches security strength according to risk level, taking into account both security and user experience.
[0075] For example, the authentication levels and corresponding terminal authentication methods are shown in Table 1:
[0076] Table 1
[0077]
[0078]
[0079] Step 104: Based on the authentication level, trigger the corresponding authentication process and generate the authentication result.
[0080] For example, the authentication process can be triggered and authentication results generated according to the authentication levels in Table 1: For the lowest risk (L1), authentication can be passed without additional verification; a slightly higher level (L2) requires the user to complete a specific task to confirm their identity; at medium risk (L3), fingerprint recognition is required to verify the user's identity; at a further increased risk (L4), facial recognition is activated to ensure the operator's identity; in extremely high risk (L5), an inspection of the user's surrounding environment is required to prevent fraudulent activities; at the highest risk level (L6), the system will send a verification code to the user's third-party device to ensure the security of cross-device verification. This dynamic authentication mechanism based on risk levels not only ensures the security needs of different scenarios but also takes into account user experience and convenience.
[0081] Optionally, the method in this embodiment may further include: if the authentication result is successful, generating a random access token; and sending authentication response information to the terminal, wherein the authentication response information includes the authentication result and the access token.
[0082] In some examples, the authentication level output by the model can be determined based on the authentication level. The server dynamically triggers the authentication process of the corresponding security level. When the user completes the required verification steps, the authentication is deemed successful, and a unique random access token is generated. The "authentication successful" status and the token are fed back to the terminal through a secure channel. The terminal then uses the token for subsequent session authentication or operation authorization, ensuring the unforgeability and timeliness of the authentication result, and realizing a secure and reliable closed-loop authentication mechanism.
[0083] In some examples, the server can run an authentication level judgment model based on the user's historical behavior data and current access context to dynamically assess the user's identity risk and determine whether an additional enhanced authentication process needs to be triggered, thereby achieving tiered adaptive security verification. At the same time, the server remotely pushes an implicit compression conversion model for pre-processing data to the super SIM card on the terminal side through an authorization detection model distribution mechanism, ensuring that user behavior data can be privacy-preserving locally on the terminal, thereby improving data security and the overall intelligence level of system authentication.
[0084] Compared with existing technologies, the technical solution of this embodiment first receives implicit behavioral data sent by the terminal, which is generated after the terminal compresses and transforms user behavior data; then, it obtains the authentication information corresponding to the user account; based on the implicit behavioral data and authentication information, it determines the authentication level of the user account, whereby the authentication level indicates the authentication method required to complete the authentication; and then, according to the authentication level, it triggers the corresponding authentication process and generates the authentication result. By combining user behavior data and account authentication information, and using an authentication level judgment model deployed on the server to conduct a comprehensive risk assessment, it dynamically outputs the corresponding authentication level, thereby triggering a matching hierarchical authentication process. By constructing a dynamic risk control mechanism based on behavior perception, it achieves effective identification of whether the terminal is actually held and operated by the user, thereby effectively reducing security risks such as identity theft and account fraud caused by the terminal being misused by others.
[0085] Accordingly, to further illustrate the specific implementation process of account authentication, this embodiment provides the following: Figure 4 The specific method shown is applied to the terminal side, and the method includes:
[0086] Step 201: In response to the authentication request initiated by the third-party application, obtain user behavior data based on the authentication and authorization detection applet integrated in the Super SIM card.
[0087] In some examples, a third-party application, acting as the initiator of the authentication request, sends the content to be authorized to the server when user authorization is required to perform a specific operation. The server then triggers the authentication process for the corresponding user. After the Super SIM card completes identity verification and is confirmed by the server, the third-party application receives the authorization authentication result returned by the server. If the authentication is successful, the operation is automatically allowed, achieving secure, reliable, and seamless access control and business execution, ensuring the legality of user operations and the security of data assets.
[0088] For example, the authorization and authentication interface can be provided by Figure 5 As shown, the "No Authentication Required" interface on the left indicates that Zhang San's identity verification request has passed the initial review and only requires simple confirmation to authorize; while the "Enhanced Authentication" interface on the right prompts that facial recognition is required to further verify the identity and ensure the security and accuracy of the operation.
[0089] For example, the terminal collects user behavior data based on the STK authentication and authorization detection mini-program integrated in the Super SIM card. Specifically, the Super SIM card has a pre-installed STK-based authentication and authorization detection mini-program that supports running at the SIM card level and triggering user interaction. With user authorization, the terminal obtains local user operation behavior data before and after authentication through this mini-program and securely stores the relevant records inside the Super SIM card. When a third-party application triggers SIM card authentication, the authentication mini-program automatically records all user operations on the authentication page.
[0090] R1={(b1,ts1,te1,lsx1,lex1,lsy1,ley1,l1), (b2,ts2,te2,lsx2,lex2,lsy2,ley2,l2),...,(b n1 ,ts n1 ,te n1 lsx n1 ,lex n1 ,lsy n1 ,ley n1 ,l n1 )}
[0091] Among them: For bi represents the operational behavior, ts i ts is the start time of the operation. i The end time of the operation, lsx i lex i lsy i ,ley i These are: the x-coordinate of the operation start position, the x-coordinate of the operation end position, the y-coordinate of the operation start position, and the y-coordinate of the operation end position. iThe input information is n1, and the total number of operations is n1.
[0092] Optionally, the user behavior data in this embodiment may include operation behavior information and operation log records.
[0093] In some examples, the terminal authentication mini-program obtains terminal operation logs through the STK authentication and authorization detection function integrated in the Super SIM card. Since accessing terminal logs involves high system privileges, user authorization and the installation of a dedicated local log reading program are required. Deployment is only implemented in high-security scenarios after a user log data openness agreement has been explicitly signed. After installation, the binding between the terminal and the Super SIM card is completed: by reading the terminal's International Mobile Equipment Identity (IMEI) and combining it with the SIM card's Integrated Circuit Card Identity (ICCID), the local log reading program calls the pre-installed third-party application authentication interface within the SIM card, reporting the IMEI and ICCID to the terminal binding service. Binding is completed after initial installation verification, and the IMEI information is securely stored in the Super SIM card. When a third-party application triggers SIM card authentication, the authentication mini-program automatically records all user operations on the authentication page, including clicks, inputs, and swipes. Simultaneously, when the user initiates a data interaction request between the terminal device and the Super SIM card, the STK authentication and authorization detection mechanism is activated.
[0094] R2={(a1,tl1,l1),(a2,tl2,l2),...,(a n2 ,tl n2 , l n2 )}
[0095] Among them: For a i For logging applications, tl i For logging time, l i The input information is n2, where n2 is the total number of recent logs, and n2 = min(P). lmax C l ), where P lmax C is the upper limit parameter for retrieving logs in a single instance. l This represents the number of logs generated since the last authentication and authorization process.
[0096] In some examples, the terminal authentication applet can obtain the authentication target initiated, and obtain the authentication target T = {A} at the time of initiation of authentication based on the parameters called by the authentication initiator when the third-party application initiates authentication. t S t, t s v v I t}, where A t Indicates the application initiating authentication, S t Indicates the authentication initiation scenario, t s For the authentication initiation time, V v For the validity period of the certification target, l t Security level is required for certification.
[0097] For example, after successfully acquiring and verifying the implicit compression and transformation model Ml, the terminal performs model inference based on locally collected user behavior data. Specifically, the terminal inputs the operation log R1 generated during the authentication process and the terminal operation log R2 obtained through authorization into model Ml, performs compression and implicit transformation operations according to the model parameters, and generates corresponding implicit output data R'1 and R'2. R'1 is the implicit representation of the authentication operation behavior, and R'2 is the implicit feature vector of the terminal log data. This output data is generated locally, and the original information cannot be restored. It is then uploaded to the server through a secure channel for the authentication level judgment model Ms to perform subsequent risk analysis and identity authentication decisions, thereby achieving privacy protection and efficient utilization of user behavior data.
[0098] Step 202: Based on the implicit compression transformation model of the data stored in the Super SIM card, convert the user behavior data into implicit behavior data.
[0099] In some examples, the terminal device and the Super SIM card work together to achieve secure authentication and privacy protection of user behavior data: the terminal is responsible for collecting user authentication requests and behavior data, and uses the Super SIM card as a secure storage medium to save some critical data; at the same time, based on the processing model built into the Super SIM card, the terminal performs local preprocessing on the collected user behavior data, and transforms it into unrecoverable implicit data through compression, conversion and other technologies before uploading it to the server, ensuring that the original data is not leaked and improving the security of data transmission; in addition, through the SIM Application Toolkit (STK) application applet pre-installed in the Super SIM card, the terminal can actively trigger authentication prompts to guide users to complete the identity verification operation, realizing an efficient, secure and user-controllable integrated authentication process.
[0100] Optionally, step 202 may specifically include: using an implicit data compression transformation model to perform attribute compression processing on the operation behavior information, and generating first implicit behavior data based on a threshold weighted compression mechanism; performing text compression processing on the log content in the operation log record to generate second implicit behavior data; and determining the first implicit behavior data and the second implicit behavior data as the implicit behavior data corresponding to the user behavior data.
[0101] For example, the authentication mini-program can obtain the terminal detection model from the server and ensure its integrity through a security mechanism: Specifically, the STK authentication and authorization detection mini-program integrated in the super SIM card periodically downloads the terminal detection model Ml for behavior analysis from the server and securely stores the model inside the SIM card; before the model is loaded, the mini-program obtains the model's digital signature information based on the trusted execution environment of the terminal device and sends the signature information back to the distribution backend for signature verification, verifying that the model has not been tampered with or replaced during transmission; only after the verification is passed is the model enabled for preprocessing and risk detection of local user behavior data, thereby ensuring the credibility of the detection model and the overall security protection capability of the system.
[0102] Step 203: Send the implicit behavior data to the server.
[0103] Implicit behavioral data is used by the server to determine the authentication level of a user account based on implicit behavioral data and authentication information. The authentication level indicates the authentication method required to complete the authentication. Based on the authentication level, the corresponding authentication process is triggered and the authentication result is generated.
[0104] In some examples, the server can also send authentication instructions to the terminal, and the Super SIM card, together with the STK mini-program, guides the user to complete the corresponding level of verification. After confirming that all authentication elements have passed, the authorization authentication result is returned to the third-party application, realizing an adaptive authentication system that is risk-based and accurately matches security strength, taking into account both security and user experience.
[0105] Optionally, the method in this embodiment may further include: receiving authentication response information sent by the server, the authentication response information including authentication result and access token; writing the access token and authentication result into the super SIM card and authorizing the third-party application.
[0106] For example, third-party authentication is used to provide dedicated identity verification functions in specific scenarios. For some high-security authentication needs that require reliance on external authoritative data sources or dedicated biometric comparison capabilities, since the relevant sensitive information (such as the image database and ID card information in the public security system) is not stored on the local server, it cannot be verified independently by the internal system. Therefore, authorization from a third-party application is required.
[0107] In some examples, after receiving a successful authentication response, the terminal parses the random access token and expiration information, and then processes it according to a predefined data structure {A}. t S t token, t s +v v , l t} It is securely stored in the Super SIM card, where A t S represents the third-party application that initiated the authentication. t Indicates the specific scenario that triggers authentication, t s v represents the time when the authentication request was initiated. v For the effective duration of the certification target, l t The security level required for this authentication is specified. At the same time, the terminal authorizes the corresponding third-party application with this token, allowing it to perform subsequent operations or service calls within the validity period. The authentication level result and validity period are recorded synchronously in the Super SIM card. The system periodically or automatically cleans up expired authentication records during each authentication to ensure the timeliness and security of the authentication status, and realize token-based dynamic authorization and localized security control.
[0108] In some examples, the overall account authentication and authorization process based on the Super SIM card can be as follows: Figure 6 As shown, firstly, the third-party application initiates an authentication request. Then, the server sends the implicit authorization compression transformation model to the terminal and stores the model in the Super SIM card. The terminal processes user behavior data and generates implicit feature representations by executing the authorization detection applet and the terminal implicit compression transformation model. The server combines user basic information, network analysis results, and trusted third-party authentication information, using an authentication discrimination model to determine the authentication level and required authentication method. Finally, the terminal executes the corresponding verification steps according to the specified authentication method. After completing identity verification, the server returns the authentication result, achieving secure and efficient dynamic identity authentication and authorization management.
[0109] Compared to existing technologies, the technical solution of this embodiment first responds to authentication requests initiated by third-party applications by acquiring user behavior data based on the authentication and authorization detection applet integrated in the Super SIM card. Then, based on the implicit data compression and transformation model stored in the Super SIM card, the user behavior data is converted into implicit behavior data. Finally, the implicit behavior data is sent to the server. The implicit behavior data is used by the server to determine the authentication level of the user account based on the implicit behavior data and authentication information. The authentication level indicates the authentication method required to complete the authentication. Based on the authentication level, the corresponding authentication process is triggered and an authentication result is generated. This embodiment introduces a user operation habit detection mechanism to construct a user-owned status detection model. The Super SIM card securely stores and manages the behavior detection model issued by the server, ensuring the model's integrity and accuracy. When SIM card authentication is triggered, the terminal calls locally stored historical user behavior data, combines it with the detection model and a preset authentication strategy model, to perform real-time analysis and matching of the current operation behavior, determine whether it matches the user's behavioral characteristics, generate a corresponding user verification strategy, and execute authentication. Only after the verification strategy passes will the identity token authentication based on the Super SIM card be completed, realizing a dual verification mechanism of "trusted behavior + trusted identity," improving authentication security and anti-impersonation capabilities.
[0110] Furthermore, as Figure 1 The specific implementation of the method shown in this embodiment provides an account authentication device applied to the server side, such as... Figure 7 As shown, the device includes: a receiving module 31, an acquisition module 32, a determining module 33, and a triggering module 34.
[0111] The receiving module 31 is configured to receive implicit behavior data sent by the terminal, wherein the implicit behavior data is generated by the terminal after compressing and converting the collected user behavior data;
[0112] Module 32 is configured to retrieve authentication information corresponding to the user account.
[0113] The determination module 33 is configured to determine the authentication level of the user account based on the implicit behavior data and the authentication information, wherein the authentication level is used to indicate the authentication method required to complete the authentication.
[0114] Trigger module 34 is configured to trigger the corresponding authentication process and generate an authentication result based on the authentication level.
[0115] In some examples of this embodiment, the authentication information includes user account attribute information and user network analysis results; accordingly, the determining module 33 is specifically configured to input the implicit behavior data, the user account attribute information and the user network analysis results into the authentication level judgment model, and output the authentication level corresponding to the user account.
[0116] In some examples of this embodiment, the determining module 33 is further configured to compress the implicit behavioral data, the user account attribute information, and the variable-length data in the user network analysis results to obtain fixed-length feature vectors; input the fixed-length feature vectors into a neural network model containing multiple fully connected layers for processing; calculate the classification probabilities of multiple authentication levels based on the output layer results of the neural network model; and determine the authentication level corresponding to the user account according to the classification probabilities.
[0117] In some examples of this embodiment, the trigger module 34 is further configured to generate a random access token if the authentication result is successful; and send authentication response information to the terminal, the authentication response information including the authentication result and the access token.
[0118] In some examples of this embodiment, the trigger module 34 is further configured to train a data implicit compression transformation model based on user behavior data samples. The data implicit compression transformation model is used to compress and transform user behavior data. The trained data implicit compression transformation model and the corresponding digital signature are then sent to the terminal.
[0119] Furthermore, as Figure 4 The specific implementation of the method shown in this embodiment provides an account authentication device applied to the terminal side, such as... Figure 8 As shown, the device includes: an acquisition module 41, a conversion module 42, and a transmission module 43.
[0120] The acquisition module 41 is configured to acquire user behavior data in response to authentication requests initiated by third-party applications, based on the authentication and authorization detection applet integrated in the Super SIM card.
[0121] The conversion module 42 is configured to convert the user behavior data into implicit behavior data based on the implicit data compression conversion model stored in the super SIM card;
[0122] The sending module 43 is configured to send the implicit behavior data to the server. The implicit behavior data is used by the server to determine the authentication level of the user account based on the implicit behavior data and the authentication information. The authentication level is used to indicate the authentication method required to complete the authentication. According to the authentication level, the corresponding authentication process is triggered and an authentication result is generated.
[0123] In some examples of this embodiment, the user behavior data includes operation behavior information and operation log records; correspondingly, the conversion module 42 is specifically configured to use the implicit data compression conversion model to perform attribute compression processing on the operation behavior information, and generate first implicit behavior data based on a threshold weighted compression mechanism; perform text compression processing on the log content in the operation log records to generate second implicit behavior data; and determine the first implicit behavior data and the second implicit behavior data as the implicit behavior data corresponding to the user behavior data.
[0124] In some examples of this embodiment, the acquisition module 41 is further configured to receive authentication response information sent by the server, the authentication response information including the authentication result and the access token; write the access token and the authentication result into the Super SIM card and authorize the third-party application.
[0125] It should be noted that for other corresponding descriptions of the various functional units involved in the account authentication device provided in this embodiment, please refer to... Figure 1 and Figure 4 The corresponding description in [the document] will not be repeated here.
[0126] Based on the above, Figure 1 and Figure 4 Accordingly, this embodiment also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described method. Figure 1 and Figure 4 The method shown.
[0127] Based on this understanding, the technical solution of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as CD-ROM, USB flash drive, mobile hard drive, etc.) and includes several instructions to cause a computer device (such as personal computer, server, or network device, etc.) to execute the methods of various implementation scenarios of this application.
[0128] Based on the above, Figure 1 and Figure 4 The method shown, and Figure 7 and Figure 8To achieve the above objectives, the present application also provides an electronic device, such as a personal computer, server, laptop computer, intelligent robot, or other intelligent terminal, as illustrated in the virtual device embodiment. This device includes a storage medium and a processor; the storage medium stores a computer program; the processor executes the computer program to implement the above-described virtual device. Figure 1 and Figure 4 The method shown.
[0129] Optionally, the aforementioned physical devices may also include a user interface, a network interface, a camera, radio frequency (RF) circuitry, sensors, audio circuitry, a Wi-Fi module, etc. The user interface may include a display screen, input units such as a keyboard, etc., and optional user interfaces may also include USB interfaces, card reader interfaces, etc. The network interface may optionally include standard wired interfaces, wireless interfaces (such as Wi-Fi interfaces), etc.
[0130] Those skilled in the art will understand that the physical device structure provided in this embodiment does not constitute a limitation on the physical device, and may include more or fewer components, or combine certain components, or have different component arrangements.
[0131] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages the hardware and software resources of the aforementioned physical device, supporting the operation of information processing programs and other software and / or programs. The network communication module is used to enable communication between the various components within the storage medium, as well as communication with other hardware and software in the information processing physical device.
[0132] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platforms, or it can be implemented by hardware. By applying the solution of this embodiment, compared with the existing technology, this embodiment collects user terminal behavior data in collaboration with the super SIM card and terminal application, and combines it with user network behavior data. It utilizes an implicit compression conversion model deployed on the terminal side and an authentication level judgment model deployed on the server side, and dynamically analyzes the current operation behavior based on artificial intelligence (AI) technology to determine whether the actual user has the operating habits and identity characteristics of the terminal owner during the authentication process. The system adaptively triggers the corresponding level of authentication method according to the risk assessment results, integrating SIM card identity tokens, behavioral feature recognition and multi-factor authentication to achieve accurate identification of user identity. While ensuring security, it simplifies the authentication process to the greatest extent and achieves efficient, intelligent and reliable account authentication and authorization. Furthermore, by adding a user identity verification mechanism to the SIM card authentication process, the system can effectively confirm whether the actual operator of the current terminal is the authorized user, ensuring that the system, services, and data are only accessed by legitimate users, and preventing the risk of impersonation due to the terminal being used by others. This mechanism clarifies the responsibility for user operations, making each operation traceable to the specific user, and enhancing the audit and accountability capabilities in the event of a security incident. At the same time, it reduces the authorization confusion caused by users sharing terminals for convenience, and improves the compliance level of business processes. Moreover, by combining behavioral feature recognition and implicit data processing, it avoids the leakage of raw behavioral data, further strengthens the protection of users' personal information, and comprehensively reduces liability disputes, compliance risks, and privacy leaks caused by identity theft.
[0133] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0134] The above description is merely a specific embodiment of this application, enabling those skilled in the art to understand or implement this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.
Claims
1. An account authentication method, characterized in that, Applied to the server side, including: The receiver receives implicit behavior data sent by the terminal, which is generated by the terminal after compressing and converting user behavior data; Obtain the authentication information corresponding to the user account; Based on the implicit behavioral data and the authentication information, the authentication level of the user account is determined, and the authentication level is used to indicate the authentication method required to complete the authentication. Based on the authentication level, the corresponding authentication process is triggered and an authentication result is generated.
2. The method according to claim 1, characterized in that, The authentication information includes user account attribute information and user network analysis results; Determining the authentication level of the user account based on the implicit behavioral data and the authentication information includes: The implicit behavioral data, the user account attribute information, and the user network analysis results are input into the authentication level judgment model, and the authentication level corresponding to the user account is output.
3. The method according to claim 2, characterized in that, The step of inputting the implicit behavioral data, the user account attribute information, and the user network analysis results into the authentication level judgment model and outputting the authentication level corresponding to the user account includes: The implicit behavioral data, the user account attribute information, and the variable-length data in the user network analysis results are compressed to obtain fixed-length feature vectors. The fixed-length feature vector is input into a neural network model containing multiple fully connected layers for processing. Based on the output layer results of the neural network model, the classification probabilities of multiple authentication levels are calculated. The authentication level corresponding to the user account is determined based on the classification probability.
4. The method according to claim 1, characterized in that, After triggering the corresponding authentication process and generating the authentication result based on the authentication level, the method further includes: If the authentication result is successful, a random access token is generated; The authentication response information is sent to the terminal, and the authentication response information includes the authentication result and the access token.
5. The method according to claim 1, characterized in that, The method further includes: Based on user behavior data samples, an implicit data compression and transformation model is trained, which is used to compress and transform user behavior data. The trained implicit compression transformation model of the data and the corresponding digital signature are sent to the terminal.
6. An account authentication method, characterized in that, Applied to the terminal side, including: In response to authentication requests initiated by third-party applications, user behavior data is obtained based on the authentication and authorization detection applet integrated in the Super SIM card; Based on the implicit compression and transformation model of the data stored in the super SIM card, the user behavior data is converted into implicit behavior data; The implicit behavior data is sent to the server. The server uses the implicit behavior data and the authentication information to determine the authentication level of the user account. The authentication level indicates the authentication method required to complete the authentication. Based on the authentication level, the server triggers the corresponding authentication process and generates the authentication result.
7. The method according to claim 6, characterized in that, The user behavior data includes operation behavior information and operation log records; The implicit compression and transformation model based on the data stored in the super SIM card converts the user behavior data into implicit behavior data, including: Using the aforementioned implicit data compression transformation model, the operation behavior information is subjected to attribute compression processing, and based on a threshold-weighted compression mechanism, first implicit behavior data is generated. The log content in the operation log is compressed to generate second implicit behavior data; The first implicit behavior data and the second implicit behavior data are determined as the implicit behavior data corresponding to the user behavior data.
8. The method according to claim 6, characterized in that, After sending the implicit behavior data to the server, the method further includes: Receive authentication response information sent by the server, the authentication response information including the authentication result and the access token; The access token and authentication result are written into the Super SIM card, and the third-party application is authorized.
9. An account authentication device, characterized in that, Applied to the server side, including: The receiving module is configured to receive implicit behavior data sent by the terminal, wherein the implicit behavior data is generated by the terminal after compressing and converting the collected user behavior data; The acquisition module is configured to retrieve authentication information corresponding to the user account. The determination module is configured to determine the authentication level of the user account based on the implicit behavior data and the authentication information, wherein the authentication level is used to indicate the authentication method required to complete the authentication. The triggering module is configured to trigger the corresponding authentication process and generate an authentication result based on the authentication level.
10. An account authentication device, characterized in that, Applied to the terminal side, including: The acquisition module is configured to respond to authentication requests initiated by third-party applications and acquire user behavior data based on the authentication and authorization detection applet integrated in the Super SIM card. The conversion module is configured to convert the user behavior data into implicit behavior data based on the implicit compression conversion model of the data stored in the super SIM card; The sending module is configured to send the implicit behavior data to the server. The implicit behavior data is used by the server to determine the authentication level of the user account based on the implicit behavior data and the authentication information. The authentication level is used to indicate the authentication method required to complete the authentication. According to the authentication level, the corresponding authentication process is triggered and an authentication result is generated.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 8.
12. An electronic device comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 8.
13. A computer program product having a computer program stored thereon, characterized in that, When the computer program product is executed by a processor, it implements the method of any one of claims 1 to 8.
Citation Information
Patent Citations
Resource operation safety authentication method and system under cloud calculation environment
CN104301328A
Identity authentication system, method and device and account authentication method
CN108076018A
Login authentication method and device, equipment and storage medium
CN117527381A
Hierarchical authentication system and method
CN118802166A