An insurance identity authentication comprehensive management data processing method and system

CN121098560BActive Publication Date: 2026-09-25BAIGE ONLINE (XIAMEN) DIGITAL TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511209465.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-27
Publication Date
2026-09-25
Estimated Expiration
2045-08-27

AI Technical Summary

Technical Problem

[0005]针对现有技术的不足,本发明提供了一种保险身份认证综合管理数据处理方法和系统,解决了现有的现有身份认证技术在安全、隐私保护及适应性方面不足的问题

Benefits of technology

[0066]1、本发明通过对用户生物特征基准数据、认知行为基准数据、实时数据及环境信息均在设备端进行加密,并以密文状态传输至服务器端的密文计算核心层。核心层在不进行数据解密的情况下执行认知冲突动力学模型和协同推理网络运算,从而在整个认证流程中有效保护了用户的敏感信息,极大地降低了数据泄露的风险。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098560B_ABST
    Figure CN121098560B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of insurance identity authentication security management, and discloses an insurance identity authentication comprehensive management data processing method and system. The method comprises the following steps: collecting reference data, and constructing a reference authentication matrix; collecting and encrypting data in real time, and transmitting the data to a server; performing ciphertext calculation to obtain an encrypted cognitive conflict index; generating an encrypted intention fingerprint, and reasoning to obtain an encrypted risk probability; decrypting the risk probability, and comparing the risk probability with a threshold value to perform authentication; and the system comprises a data collection module, a data encryption module, a data quantization module, a risk calculation module, an authentication processing module and a model optimization module. According to the application, the user biological feature reference data, the cognitive behavior reference data, real-time data and environmental information are all encrypted on the device side, and are transmitted to the ciphertext calculation core layer of the server side in the ciphertext state, so that the sensitive information of the user is effectively protected in the whole authentication process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of insurance identity authentication security management technology, specifically to an insurance identity authentication comprehensive management data processing method and system. Background Technology

[0002] Today, the digital economy is sweeping the globe, and the insurance industry is deeply integrated into it, with online and mobile services becoming mainstream. Consumers are accustomed to handling insurance business through smart devices, completing everything online in one stop, from product consultation and application to claims and policy management. This convenience undoubtedly greatly enhances the user experience and expands business boundaries, but it also brings unprecedented challenges to identity verification.

[0003] Existing identity authentication technologies are already widely used on major online platforms, including in the insurance industry. The most common are knowledge-based authentication, such as username and password, combined with SMS verification codes or security questions to confirm identity. At the same time, some systems are also beginning to introduce behavioral feature analysis, using users' typing habits, swipe patterns, and operation speed to assist in identity verification.

[0004] However, existing identity authentication technologies often require decryption on the server side before collecting users' sensitive biometric or behavioral data for comparison or analysis, increasing the risk of data leakage. Single authentication methods have limited protective capabilities, and different authentication information often lacks deep correlation and fusion analysis, making it difficult to comprehensively capture subtle abnormal behaviors. This results in many complex frauds being difficult to effectively identify, and even misjudgments. Therefore, this invention provides a comprehensive insurance identity authentication management data processing method and system to address the shortcomings of existing technologies. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention provides a comprehensive management data processing method and system for insurance identity authentication, which solves the problems of insufficient security, privacy protection, and adaptability of existing identity authentication technologies.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a comprehensive management data processing method for insurance identity authentication, comprising the following steps:

[0007] S1. Collect historical users' biometric baseline data and cognitive behavior baseline data through the device, and construct a baseline authentication matrix based on the historical users' biometric baseline data and cognitive behavior baseline data;

[0008] S2. Based on the benchmark authentication matrix, receive and encrypt the current user's biometric benchmark data and cognitive behavior benchmark data in real time according to the insurance identity authentication request initiated by the current user, generate encrypted real-time data and encrypted environment information, as well as the encrypted benchmark authentication matrix, and transmit the encrypted real-time data, the encrypted environment information and the encrypted benchmark authentication matrix to the encrypted calculation core layer of the server.

[0009] S3. The encrypted calculation core layer performs anomaly quantification calculation on the current user's behavior based on the cognitive conflict dynamics model, the encrypted real-time data, and the encrypted benchmark authentication matrix to obtain the encrypted cognitive conflict index.

[0010] S4. The encrypted calculation core layer generates an encryption intent fingerprint based on the benchmark authentication matrix, the encryption cognitive conflict index, the encryption real-time data, and the encryption environment information, and uses a collaborative reasoning network to perform fusion reasoning on the encryption intent fingerprint to obtain the comprehensive encryption risk probability.

[0011] S5. Based on the comprehensive risk probability decryption algorithm model, the encrypted comprehensive risk probability is decrypted to obtain the decrypted comprehensive risk probability. The decrypted comprehensive risk probability is compared step by step with the preset risk threshold. The current user's insurance identity authentication request is authenticated based on the comparison results, and the authentication result is returned.

[0012] Preferably, in step S1, the step of constructing a benchmark authentication matrix based on historical users' biometric benchmark data and cognitive behavior benchmark data further includes:

[0013] When a user registers for the first time or initializes their identity, the device collects the user's biometric baseline data through biometric sensors. The biometric baseline data includes fingerprints, irises, and faces. The biometric sensors include a fingerprint recognition module, an iris scanner, and a facial recognition camera.

[0014] The device records the user's cognitive behavior baseline data in a specific task through a behavior capture module. The cognitive behavior baseline data includes swiping trajectory, button habits, dwell time and eye movement pattern. The behavior capture module includes an accelerometer, a gyroscope and a touch screen sensor.

[0015] Based on the collected biometric baseline data and cognitive behavioral baseline data, and by integrating the user's biometric characteristics and behavioral patterns, a baseline authentication matrix is ​​constructed, wherein the baseline authentication matrix is ​​M. base ;

[0016] M base =Combine(Feature(D bio_base),Feature(D cog_base ));

[0017] In the formula, Combine(·) is the construction function of the benchmark authentication matrix, used to fuse the processed biometric features and cognitive behavioral features; Feature (D bio_base ) represents the raw biometric baseline data D collected. bio_base Feature vector extracted from; Feature (D cog_base (D) represents the raw cognitive-behavioral baseline data collected. cog_base The feature vectors extracted from it.

[0018] Preferably, in step S2, the step of receiving and encrypting the current user's biometric baseline data and cognitive behavior baseline data in real time based on the baseline authentication matrix and according to the insurance identity authentication request initiated by the current user further includes:

[0019] Receive the insurance identity authentication request initiated by the current user through the device, parse and collect the current user's biometric baseline data, cognitive behavior baseline data and environmental information in real time through the device's biometric sensor and behavior capture module, respectively, based on the insurance identity authentication request;

[0020] Based on a pre-distributed or generated homomorphic encryption key and the aforementioned benchmark authentication matrix, the current user's biometric benchmark data, cognitive behavior benchmark data, and environmental information are encrypted to generate and obtain the encrypted real-time data D. *eal_e,c and the encrypted environment information E enc And the cryptographic benchmark authentication matrix D base_e,c ;

[0021] The encrypted real-time data D is transmitted according to the secure transmission protocol. *eal_enc and the encrypted environment information E e,c and the cryptographic benchmark authentication matrix D base_e,c It is encapsulated into a data packet and transmitted to the encrypted computing core layer on the server side through an encrypted channel;

[0022] The encrypted real-time data includes encrypted biometric baseline data and cognitive behavior baseline data of the current user.

[0023] The encrypted real-time data D *eal_enc =Enc(D *eal PK HE );

[0024] The encrypted environment information E enc =Enc(E info );

[0025] The encryption benchmark authentication matrix D base-enc =Enc(M base PK HE );

[0026] In the formula, Enc(·,·) is a homomorphic encryption function; D *eal This refers to unencrypted real-time data of the current user, including unencrypted biometric and cognitive behavioral data of the current user; E info For the current user's unencrypted environment information; M base The benchmark authentication matrix; PK HE A pre-distributed or generated homomorphic encryption key used for homomorphic encryption.

[0027] Preferably, the cognitive conflict dynamics model is as follows:

[0028] CCI enc =F enc (D *eal_enc D base_enc ,P model_enc );

[0029] In the formula, CCI enc F is the cryptographic cognitive conflict index; e,c A function that operates in the homomorphic cryptographic domain; D real_enc For the encrypted real-time data; D base_enc P is the encryption baseline authentication matrix; model_enc These are the parameters for the cognitive conflict dynamics model.

[0030] Preferably, in step S3, the step of the encrypted calculation core layer performing anomaly quantification calculation on the current user's behavior based on the cognitive conflict dynamics model, the encrypted real-time data, and the encrypted benchmark authentication matrix includes:

[0031] The core layer of ciphertext computation receives the encapsulated encrypted real-time data D. *eal_e,c and encrypted environment information E e,c and the cryptographic benchmark authentication matrix D base_e,c After receiving the data packet, the data packet is decomposed, and the encrypted real-time data D is processed using the cognitive conflict dynamics model. *eal_e,c and encryption benchmark authentication matrix D base_e,c Anomaly quantification is performed to obtain the Encryption Cognitive Conflict Index (CCI). enc The Cryptographic Cognitive Conflict Index (CCI) is mentioned above. enc The Encrypted Cognitive Conflict Index (CCI) represents the amount of anomalies between the current user's behavior and the behavior of historical users. enc The value is proportional to the number of anomalies, and the Cryptographic Cognitive Conflict Index (CCI) is... encThe larger the value, the greater the anomaly between the current user's behavior and the behavior of historical users.

[0032] Preferably, step S4 further includes:

[0033] In the ciphertext state, based on the fusion function operating in the homomorphic encryption domain, the ciphertext computation core layer is based on the baseline authentication matrix Combine() and the cryptographic cognitive conflict index CCI. enc The encrypted real-time data D *eal_enc and the encrypted environment information E e,c Generate an encrypted intent fingerprint;

[0034] The encryption intent fingerprint is subjected to fusion reasoning based on a collaborative reasoning network and a fusion reasoning model to obtain the comprehensive encryption risk probability.

[0035] in,

[0036] The encryption intent fingerprint is IF enc ,

[0037] IF enc =Merge(Enc(D base ), CCI enc D *eal_enc E enc ,P me*ge_e,c );

[0038] In the formula, Merge(·) is the fusion function operating on the homomorphic encryption domain, and Enc(D base P is an encryption form that represents the long-term, stable identity characteristics of a user. me*ge_e,c These are the encryption parameters used in the fusion function;

[0039] The fusion reasoning model is P. *isk_e,c =InferNet e,c (IF e,c ,W, et_e,c );

[0040] In the formula, P *isk_e,c For the comprehensive encryption risk probability, InferNet e,c (·,·) denotes the inference function of a cooperative inference network operating in the homomorphic cryptographic domain, W, et_e,c The cryptographic weights and structural parameters characterize the collaborative reasoning network, which are used by the collaborative reasoning network in the ciphertext state to perform fusion reasoning on the cryptographic intent fingerprint.

[0041] Preferably, step S5 further includes:

[0042] S5-1, After receiving the encrypted comprehensive risk probability in encrypted form, the authentication decision and policy layer on the server side decrypts the encrypted comprehensive risk probability using the private key held by the authentication decision and policy layer based on the comprehensive risk probability decryption algorithm model to obtain the comprehensive risk probability.

[0043] The comprehensive risk probability decryption algorithm model is as follows: P *isk =Dec(P *isk_enc SK HE In the formula, P *isk Let P be the comprehensive risk probability, and Dec(·,.) be the homomorphic decryption function in the comprehensive risk probability decryption algorithm model. Dec(·,.) is used to receive the input ciphertext and private key, and decrypt the ciphertext using the private key to output the plaintext. *isk_e,c SK represents the overall encryption risk probability. HE This is the private key used for decryption;

[0044] S5-2, compare the decrypted comprehensive risk probability with the preset risk threshold step by step, and process the current user's insurance identity authentication request based on the step-by-step comparison results, and return the authentication result;

[0045] The preset risk thresholds are pre-configured by operators according to their needs and are used to define ranges of different risk levels. These preset risk thresholds include a low-risk threshold T. low Medium risk threshold T medium and high-risk threshold T high ;

[0046] If the overall risk probability P *isk ≤Low risk threshold T low If the current user's insurance identity authentication request is deemed low-risk, the returned authentication result indicates that the user's identity is trustworthy.

[0047] If the low-risk threshold T low Overall risk probability P *isk <Medium risk threshold T> medium If the current user's insurance identity authentication request is determined to be of medium risk, the authentication result returned is that the user's identity is uncertain and requires secondary authentication, and the process returns to step S2;

[0048] If the medium risk threshold T medium Overall risk probability P *isk High-risk threshold T high If the current user's insurance identity authentication request is deemed high-risk, the authentication result returned will be a rejection of the current user's insurance identity authentication request.

[0049] If the overall risk probability P *isk High-risk threshold Thigh If the current user's insurance identity authentication request is deemed a serious risk, the authentication result will be rejected, and an alarm mechanism will be triggered to send an alert to the security management personnel.

[0050] Preferably, the method further includes the following steps:

[0051] Record the session ID, authentication time, authentication device information, returned authentication result, and encryption process data of the current user's insurance identity authentication request, and generate a security audit log. The encryption process data includes biometric baseline data, cognitive behavior baseline data, baseline authentication matrix, encryption real-time data, encryption environment information, encryption baseline authentication matrix, encryption cognitive conflict index, encryption intent fingerprint, and encryption comprehensive risk probability.

[0052] Using reinforcement learning algorithms, the authentication result is used as a feedback signal to iteratively optimize the parameters in the cognitive conflict dynamics model based on the security audit log in the encrypted state;

[0053] Simultaneously, the encryption weights and structural parameters of the collaborative reasoning network are adjusted, and the preset risk threshold is dynamically adjusted based on the optimization results of the cognitive conflict dynamics model.

[0054] The present invention also provides an insurance identity authentication integrated management data processing system, the system comprising a data acquisition module, a data encryption module, a data quantification module, a risk calculation module, and an authentication processing module;

[0055] in,

[0056] The data acquisition module is used to collect historical users' biometric baseline data and cognitive behavior baseline data through the device, and to construct a baseline authentication matrix based on the historical users' biometric baseline data and cognitive behavior baseline data.

[0057] The data encryption module is used to receive and encrypt the current user's biometric baseline data and cognitive behavior baseline data in real time based on the baseline authentication matrix and the insurance identity authentication request initiated by the current user, generate encrypted real-time data and encrypted environment information, as well as the encrypted baseline authentication matrix, and transmit the encrypted real-time data, the encrypted environment information and the encrypted baseline authentication matrix to the encrypted calculation core layer of the server.

[0058] The data quantization module is used to perform anomaly quantification calculation on the current user's behavior through the encrypted calculation core layer and based on the cognitive conflict dynamics model, the encrypted real-time data and the encrypted benchmark authentication matrix to obtain the encrypted cognitive conflict index.

[0059] The risk calculation module is used by the core layer of the encrypted calculation to generate an encrypted intent fingerprint based on the benchmark authentication matrix, the encrypted cognitive conflict index, the encrypted real-time data, and the encrypted environment information, and to use a collaborative reasoning network to perform fusion reasoning on the encrypted intent fingerprint to obtain the comprehensive encryption risk probability.

[0060] The authentication processing module is used to decrypt the encrypted comprehensive risk probability based on the comprehensive risk probability decryption algorithm model, obtain the decrypted comprehensive risk probability, compare the decrypted comprehensive risk probability with a preset risk threshold step by step, process the current user's insurance identity authentication request based on the step-by-step comparison results, and return the authentication result.

[0061] Preferably, the user equipment terminal further includes a model optimization module, which is used for:

[0062] Record the session ID, authentication time, authentication device information, returned authentication result, and encryption process data of the current user's insurance identity authentication request, and generate a security audit log. The encryption process data includes biometric baseline data, cognitive behavior baseline data, baseline authentication matrix, encryption real-time data, encryption environment information, encryption baseline authentication matrix, encryption cognitive conflict index, encryption intent fingerprint, and encryption comprehensive risk probability.

[0063] Using reinforcement learning algorithms, the authentication result is used as a feedback signal to iteratively optimize the parameters in the cognitive conflict dynamics model based on the security audit log in the encrypted state;

[0064] Simultaneously, the encryption weights and structural parameters of the collaborative reasoning network are adjusted, and the preset risk threshold is dynamically adjusted based on the optimization results of the cognitive conflict dynamics model.

[0065] This invention provides a comprehensive data processing method and system for insurance identity authentication management. It has the following beneficial effects:

[0066] 1. This invention encrypts user biometric baseline data, cognitive behavioral baseline data, real-time data, and environmental information on the device side and transmits them in encrypted form to the encrypted computation core layer on the server side. The core layer executes cognitive conflict dynamics model and collaborative reasoning network operations without data decryption, thereby effectively protecting the user's sensitive information throughout the authentication process and greatly reducing the risk of data leakage.

[0067] 2. This invention constructs a multi-dimensional, high-precision authentication system by comprehensively utilizing biometric benchmark data, cognitive behavioral benchmark data, a cognitive conflict dynamics model, and a collaborative reasoning network. The cognitive conflict dynamics model can quantify the deviation between a user's real-time behavior and historical benchmark patterns, identifying abnormal behavior; the collaborative reasoning network performs deep fusion reasoning on encrypted intent fingerprints, comprehensively assesses overall risks, effectively resists various complex fraudulent behaviors, and improves the accuracy of authentication.

[0068] 3. This invention introduces a reinforcement learning mechanism. Based on the result of each authentication, the results of passing, secondary verification, or rejection are used as feedback signals. Under encrypted conditions, the parameters of the cognitive conflict dynamics model, the parameters of the collaborative reasoning network, and the preset risk threshold are continuously optimized. The authentication strategy and risk assessment model can be dynamically adjusted according to the actual operation and constantly changing security threats, thereby achieving continuous security management of insurance identity authentication. Attached Figure Description

[0069] Figure 1 This is a diagram illustrating the architecture of the insurance identity authentication integrated management data processing system of the present invention.

[0070] Figure 2 This is a flowchart of the data encryption process of the present invention;

[0071] Figure 3 This is a flowchart of the insurance identity authentication integrated management data processing method of the present invention.

[0072] Among them, 100 is the data acquisition module; 200 is the data encryption module; 300 is the data quantification module; 400 is the risk calculation module; 500 is the authentication processing module; and 600 is the model optimization module. Detailed Implementation

[0073] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0074] Please see the appendix Figure 1 , Figure 1This is a schematic diagram of an insurance identity authentication integrated management data processing system architecture according to an embodiment of the present invention. The present invention provides an insurance identity authentication integrated management data processing system. In one embodiment, the system collects and homomorphically encrypts data at the user device end, then the server-side ciphertext calculation core layer performs complex calculations and risk assessments in the ciphertext state, followed by intelligent authentication response from the authentication decision and strategy layer, and finally achieves continuous learning and improvement of the system through model optimization. The system includes:

[0075] The data acquisition module 100 is located on the user equipment side and collects data through biometric sensors (such as fingerprint recognition modules, iris scanners, and facial recognition cameras) and behavior capture modules (such as accelerometers, gyroscopes, and touchscreen sensors) on the device side. This module is responsible for:

[0076] Collect historical data: Collect and store the user's biometric baseline data and cognitive behavior baseline data when the user registers for the first time or initializes their identity;

[0077] Constructing a benchmark authentication matrix: Based on the collected historical benchmark data, construct a benchmark authentication matrix for subsequent comparison.

[0078] The data encryption module 200 is located on the user equipment side. When the user initiates an insurance identity authentication request, this module will receive the request in real time and perform the following processing:

[0079] Real-time data acquisition: Through the sensors and capture modules on the device, the system collects the current user's biometric baseline data, cognitive behavior baseline data, and environmental information in real time.

[0080] Homomorphic encryption: This method encrypts real-time acquired data, environmental information, and the established benchmark authentication matrix using a pre-generated homomorphic encryption key. This generates encrypted real-time data, encrypted environmental information, and an encrypted benchmark authentication matrix.

[0081] Secure transmission: All encrypted data is packaged and transmitted to the ciphertext calculation core layer on the server through an encrypted channel.

[0082] The data quantization module 300 is located in the core layer of encrypted data computation on the server side. After receiving encrypted data, it performs core computations without decryption.

[0083] Anomaly Quantization: This module performs anomaly quantification calculations on encrypted real-time data and encrypted baseline authentication matrix based on the cognitive conflict dynamics model;

[0084] Generation Index: The calculation results in a cryptographic cognitive conflict index, which characterizes the amount of anomalies between the current user's behavior and historical user behavior. The higher the index value, the greater the amount of behavioral anomalies and the higher the risk.

[0085] The risk calculation module 400 is located in the core layer of encrypted calculation on the server side, and is responsible for risk fusion and reasoning in encrypted form:

[0086] Generate Intent Fingerprint: This module generates an encrypted intent fingerprint based on the encryption benchmark authentication matrix, encryption cognitive conflict index, encryption real-time data, and encryption environment information;

[0087] Fusion reasoning: Utilizes a pre-trained collaborative reasoning network to perform fusion reasoning on encrypted intent fingerprints;

[0088] Probability of acquisition: The final output is a comprehensive encryption risk probability.

[0089] The authentication processing module 500 is located in the authentication decision and strategy layer on the server side. It performs the final authentication determination and response based on the output of the ciphertext calculation core layer.

[0090] Decryption Probability: This module uses a comprehensive risk probability decryption algorithm model to decrypt the comprehensive risk probability of encryption using a private key, thereby obtaining the comprehensive risk probability in plaintext form;

[0091] Step-by-step comparison: The decrypted comprehensive risk probability is compared step-by-step with multiple preset risk thresholds;

[0092] Authentication processing: Based on the comparison results, the authentication request is processed and the corresponding authentication result is returned, including pass, secondary authentication required, or rejection.

[0093] Model optimization module 600 is used to achieve continuous improvement and safety management, including:

[0094] Record audit logs: Record the session ID, authentication time, device information, authentication result, and all encryption process data for each authentication request, and generate comprehensive security audit logs.

[0095] Continuous optimization: Using reinforcement learning algorithms, the authentication results are used as feedback signals to iteratively optimize the parameters in the cognitive conflict dynamics model based on the security audit logs in the encrypted state.

[0096] Dynamic parameter adjustment: Simultaneously adjust the encryption weights and structural parameters of the collaborative reasoning network, and dynamically adjust the preset risk threshold based on the optimization results of the cognitive conflict dynamics model.

[0097] During system operation, the above modules work together. The data acquisition module 100, as the front end for information collection and encryption, ensures the privacy of user data at its source; the data quantification module 300 and the risk calculation module 400 perform complex risk assessments without decrypting the data; the authentication processing module 500 makes intelligent decisions based on the encrypted calculation results, balancing security and user experience; and the model optimization module 600, through continuous learning and feedback, enables the system to self-evolve and adapt to new challenges, ensuring a high level of security, privacy protection, and adaptability to dynamic risks throughout the entire authentication process.

[0098] See attached document Figure 3 , Figure 3 This is a flowchart illustrating an insurance identity authentication integrated management data processing method according to an embodiment of the present invention. The present invention provides an insurance identity authentication integrated management data processing method, comprising the following steps:

[0099] S1. Collect historical users' biometric baseline data and cognitive behavior baseline data through the device, and construct a baseline authentication matrix based on the historical users' biometric baseline data and cognitive behavior baseline data;

[0100] S2. Based on the benchmark authentication matrix, receive and encrypt the current user's biometric benchmark data and cognitive behavior benchmark data in real time according to the insurance identity authentication request initiated by the current user, generate encrypted real-time data and encrypted environment information, as well as the encrypted benchmark authentication matrix, and transmit the encrypted real-time data, the encrypted environment information and the encrypted benchmark authentication matrix to the encrypted calculation core layer of the server.

[0101] S3. The encrypted calculation core layer performs anomaly quantification calculation on the current user's behavior based on the cognitive conflict dynamics model, the encrypted real-time data, and the encrypted benchmark authentication matrix to obtain the encrypted cognitive conflict index.

[0102] S4. The encrypted calculation core layer generates an encryption intent fingerprint based on the benchmark authentication matrix, the encryption cognitive conflict index, the encryption real-time data, and the encryption environment information, and uses a collaborative reasoning network to perform fusion reasoning on the encryption intent fingerprint to obtain the comprehensive encryption risk probability.

[0103] S5. Based on the comprehensive risk probability decryption algorithm model, the encrypted comprehensive risk probability is decrypted to obtain the decrypted comprehensive risk probability. The decrypted comprehensive risk probability is compared step by step with the preset risk threshold. The current user's insurance identity authentication request is authenticated based on the comparison results, and the authentication result is returned.

[0104] Please see the appendix Figure 2 and attached Figure 3The specific technical details of the embodiments of the present invention will be described in detail below.

[0105] In one embodiment, for S1, historical users' biometric baseline data and cognitive behavior baseline data are collected via the device, and a baseline authentication matrix is ​​constructed based on this data. This step describes the process by which the data acquisition module 100 collects user baseline data and constructs the baseline authentication matrix. This process is initiated when a user registers for the first time or their identity is initialized, establishing a unique digital identity profile for the user.

[0106] Biometric baseline data acquisition: This module collects the user's physiological characteristic data through biometric sensors (including a fingerprint recognition module, an iris scanner, and a facial recognition camera). This data is relatively stable and unique, and is an inherent attribute of the user's identity.

[0107] Fingerprint recognition module: Collects data such as fingerprint details and texture direction.

[0108] Iris scanner: Acquires information such as the unique pattern and encryption points of a user's iris.

[0109] Facial recognition camera: captures data such as the user's facial geometry, key point locations, and texture features.

[0110] Cognitive Behavioral Baseline Data Acquisition: This module synchronously records the user's cognitive behavioral data during specific tasks or free interactions through a behavior capture module (including accelerometers, gyroscopes, and touchscreen sensors). This data reflects the user's operating habits and behavioral patterns.

[0111] Accelerometers and gyroscopes work together to capture the motion and attitude changes of the device during user operation.

[0112] Touchscreen sensors: meticulously record user interaction patterns with the touchscreen, such as swipe paths, button habits, pressure applied, and button duration.

[0113] Cameras or sensors: record the user's eye movement patterns, including fixation point, saccade frequency, and dwell time.

[0114] After collection, the data acquisition module 100 integrates and standardizes these multi-source heterogeneous data, including format unification, noise removal, and timestamp alignment, to ensure data quality.

[0115] Standardized biometric and cognitive behavioral benchmark data are integrated to construct a high-dimensional benchmark authentication matrix. This matrix M base It is a multidimensional vector or tensor whose dimensions integrate various indicators of the user's biometrics and behavioral patterns, and can be represented as:

[0116] M base =Combine(Feature(D bio_base ),Feature(D cog_base ));

[0117] In the formula, M base This represents the completed benchmark authentication matrix; Combine(·) represents a function used to fuse processed biometric and cognitive behavioral features; Feature (D bio_base ) indicates that the original biometric baseline data D bio_base Feature vector extracted from; Feature (D cog_base ) indicates that the original cognitive behavioral baseline data D cog_base The feature vectors extracted from it.

[0118] In S2, based on the aforementioned benchmark authentication matrix, the system receives and encrypts the current user's biometric benchmark data and cognitive behavior benchmark data in real time according to the insurance identity authentication request initiated by the current user. This generates encrypted real-time data, encrypted environment information, and an encrypted benchmark authentication matrix. The encrypted real-time data, encrypted environment information, and encrypted benchmark authentication matrix are then transmitted to the encrypted computation core layer on the server side. This step describes the encryption process performed by the data encryption module 200 on the user device. When a user initiates an insurance identity authentication request, this module starts immediately. Its core objective is to use advanced homomorphic encryption technology to encrypt all sensitive data, ensuring the confidentiality of data during transmission and subsequent calculations.

[0119] The data encryption module 200 first receives the authentication request initiated by the user in real time. Then, it uses the biometric sensors and behavior capture module of the data acquisition module 100 to collect the current user's biometric data, cognitive behavior data, and environmental information in real time. This real-time data, including the user's fingerprints, iris scans, facial features, swipe trajectories, and key press habits, constitutes a temporary, unencrypted real-time dataset D. real Environmental information serves as E info .

[0120] Next, the data encryption module 200 uses a pre-distributed or generated homomorphic encryption key PK. HE These data are then encrypted. Homomorphic encryption is the key technology in this step, allowing operations such as addition and multiplication to be performed on the ciphertext without decryption, thus enabling complex calculations to be performed on the server side while ensuring the privacy and security of the original data. The specific encryption process is as follows:

[0121] Encrypted real-time data: For unencrypted real-time data Dreal Encryption is performed to generate encrypted real-time data D. *eal_enc :

[0122] D *eal_enc =Enc(D *eal PK HE );

[0123] Encrypted environment information: For unencrypted environment information E info Encryption is performed to generate encrypted environment information E. enc :

[0124] E enc =Enc(E info );

[0125] Encryption benchmark authentication matrix: For the constructed benchmark authentication matrix M base Encryption is performed to generate the encryption baseline authentication matrix D. base-enc :

[0126] D base-enc =Enc(M base PK HE );

[0127] In the formula, D *eal_enc This indicates encrypted real-time data, including encrypted biometric data and encrypted cognitive behavioral data; E enc Represents encrypted environmental information; D base_enc Represents the encrypted baseline authentication matrix; Enc(·,·) represents the homomorphic encryption function; D *eal This represents unencrypted real-time data, containing current biometric and cognitive behavioral data; E info Indicates unencrypted environmental information; M base Represents the unencrypted baseline authentication matrix; PK HE This represents the public key used for homomorphic encryption.

[0128] After encryption is complete, the data encryption module 200 will generate encrypted real-time data D. *eal_enc Encrypted environment information E enc and the cryptographic benchmark authentication matrix D base_enc The data packets are encapsulated into packets conforming to a specific secure transport protocol (such as TLS / SSL). These packets are then transmitted from the user device to the server's ciphertext computation core layer via a secure peer-to-peer encrypted channel, preparing for the next step of ciphertext computation.

[0129] In S3, the encrypted computation core layer performs anomaly quantification calculation on the current user's behavior based on the cognitive conflict dynamics model, the encrypted real-time data, and the encrypted benchmark authentication matrix to obtain the encrypted cognitive conflict index. This step is executed by the server-side data quantization module 300. As a core component of the encrypted computation core layer 200, the data quantization module 300 receives encrypted real-time data D transmitted from the user device. *eal_enc Encrypted environment information E enc and the cryptographic benchmark authentication matrix D base-enc All of this data is in a homomorphic encryption state, and its original plaintext content is completely invisible to the server, thus protecting user privacy to the greatest extent.

[0130] The core task of the data quantification module 300 is to perform anomaly quantification calculations on the current user's behavior without decrypting any data. It utilizes a cognitive conflict dynamics model specifically optimized for homomorphic encryption environments to perform a series of complex ciphertext operations.

[0131] The model works by performing computations within a homomorphic encryption domain to precisely compare the current behavioral patterns represented in encrypted real-time data with encrypted baseline patterns stored in an encryption baseline authentication matrix. This comparison is not a simple data matching process, but a dynamic behavioral analysis designed to assess the degree of conflict between current behavior and historical habits. For example, the model analyzes encrypted swipe trajectories, key press durations, and eye movement patterns, comparing them to encrypted baseline patterns to identify any anomalous behaviors that do not conform to the user's normal behavioral patterns.

[0132] Based on the results of these operations performed in the homomorphic encryption domain, the data quantization module 300 will quantize and generate a Cryptographic Cognitive Conflict Index (CCI). enc This index is a cryptographic numerical value that directly reflects the degree of anomaly between the current behavior and the baseline behavior. A larger index value indicates a higher degree of conflict between the current behavior pattern and the baseline pattern, and a greater likelihood of an anomaly occurring.

[0133] The cryptographic cognitive conflict index is calculated using the following formula, which operates in the homomorphic cryptography domain:

[0134] CCI enc =F enc (D *eal_enc D base_enc ,P model_enc );

[0135] In the formula, CCI enc This represents the quantified cryptographic cognitive conflict index, which exists in the form of homomorphic encryption; F encD represents a function that operates in the homomorphic cryptographic domain; *eal_enc Indicates encrypted real-time data; D base_enc Represents the cryptographic baseline authentication matrix; P model_enc The encrypted parameters represent the cognitive conflict dynamics model.

[0136] In S4, the ciphertext computation core layer generates an encryption intent fingerprint based on the baseline authentication matrix, the encryption cognitive conflict index, the encryption real-time data, and the encryption environment information. It then uses a collaborative reasoning network to perform fusion reasoning on the encryption intent fingerprint to obtain the overall encryption risk probability. This step is executed by the server-side risk calculation module 400. The data quantization module 300 successfully calculates the encryption cognitive conflict index (CCI). enc Afterwards, the risk calculation module 400 will immediately take over the work, continuing to fuse and reason about the data in encrypted form to assess deeper levels of risk.

[0137] The risk calculation module 400 integrates encrypted information from different sources, including the encryption benchmark authentication matrix D. base-enc Cognitive Conflict Index (CCI) enc Encrypted real-time data D *eal_enc and encrypted environment information E enc This module utilizes a fusion function operating in the homomorphic encryption domain to fuse these multi-dimensional encrypted data, generating a composite encrypted intent fingerprint (IF). enc .

[0138] A cryptographic intent fingerprint is a multidimensional feature vector or tensor represented in a homomorphic cryptographic domain. It is designed to comprehensively and abstractly characterize the patterns and underlying intentions of a user's current authentication behavior. It incorporates not only the user's long-term stable identity characteristics (cryptographic baseline matrix) but also the anomalies of real-time behavior (cryptographic cognitive conflict index), as well as the cryptographic details of the current environment and real-time behavior. The formula for generating a cryptographic intent fingerprint is as follows:

[0139] IF enc =Merge(Enc(D base ), CCI enc D *eal_enc E enc ,P me*ge_enc );

[0140] In the formula, IF enc Represents the generated cryptographic intent fingerprint; Merge(·) represents a fusion function operating on the homomorphic cryptographic domain; Enc(D base CCI represents an encrypted form of a user's long-term, stable identity characteristics. e,c The cryptographic cognitive conflict index reflects the anomaly of real-time behavior; D*eal_e,c Indicates encrypted real-time data; E e,c Indicates encrypted environment information; P me*ge_e,c This represents the encryption parameters used in the fusion function.

[0141] Subsequently, the collaborative inference module of the ciphertext computation core layer 200 receives this encrypted intent fingerprint IF. enc The collaborative reasoning module will use IF... enc Input into a pre-trained collaborative inference network.

[0142] Subsequently, the risk calculation module 400 uses this generated encrypted intent fingerprint IF enc The input is fed into a pre-trained collaborative inference network. This network performs deep fusion inference on the encrypted intent fingerprint in the ciphertext state. The collaborative inference network utilizes its inference function InferNet, which operates on the homomorphic encryption domain. enc (·,·), and combined with its own encryption weight and structural parameter W, et_e,c The complex patterns contained in fingerprints are analyzed and correlated to predict the final risk.

[0143] The collaborative inference network outputs an encrypted form of the overall risk probability P. *isk_e,c The P *isk_enc This is a ciphertext value representing the overall risk level of the current authentication session; its plaintext content remains encrypted. This reasoning process can be expressed as:

[0144] P *isk_enc =InferNet enc (IF e,c W net_enc );

[0145] In the formula, P *isk_e,c InferNet represents the combined risk probability of the encrypted form output by the collaborative inference network; e,c (·,·) denotes the inference function of a collaborative inference network operating in the homomorphic cryptographic domain; IF e,c W represents the encrypted intent fingerprint input to the collaborative inference network. et_enc This represents the cryptographic weights and structural parameters of the collaborative reasoning network, which are used by the network for reasoning in the ciphertext state.

[0146] In S5, the authentication processing module decrypts the encrypted comprehensive risk probability to obtain the decrypted comprehensive risk probability, and performs authentication processing on the authentication request based on the comparison result, finally returning the authentication result. This step is executed by the server-side authentication processing module 500. This module is located in the authentication decision and policy layer 300 and is the decision endpoint of the entire authentication process. It receives the encrypted comprehensive risk probability P output from the ciphertext calculation core layer 200.*isk_enc This probability remains encrypted throughout the entire transmission and computation process to ensure its confidentiality.

[0147] The authentication processing module 500 first needs to decrypt the comprehensive risk probability to obtain the plaintext form of P. *isk The decryption process can employ one of the following two security methods, the specific choice depending on the system's security policy and deployment environment:

[0148] Private key decryption: This is the most direct decryption method. The authentication processing module 500 holds and compares the homomorphic encryption public key. HE Paired private key SK HE By using this private key, the module can directly assess the received overall encryption risk probability P. *isk_e,c Decryption is performed. The decryption process can be represented as:

[0149] P *isk =Dec(P *isk_e,c SK HE );

[0150] In the formula, P *isk The decrypted plaintext has a combined risk probability; Dec(·,·) represents a homomorphic decryption function that takes the ciphertext and private key as input and outputs the plaintext; P *isk_e,c SK represents the overall risk probability of the encrypted form output from the collaborative inference network; HE This represents the private key used for decryption, compared to the homomorphic encryption public key (PK). HE Correspondingly.

[0151] Secure Multi-Party Computation (MPC) Decryption: To further enhance security, the system may not hold the complete private key alone. In this case, the private key is divided into multiple secret shares, each held by a pre-defined group of participants. The authentication processing module 500 will collaborate with other participants to jointly decrypt the P key by executing the MPC protocol without revealing their respective secret shares. *isk_e,c The decryption process ultimately led to the collaborative calculation of the overall risk probability P of the plaintext. *isk This method can effectively prevent the risks associated with single-point private key leakage.

[0152] Once the overall risk probability P of the plaintext is obtained *isk The authentication processing module 500 will then enter the decision-making stage, comparing the probability with multiple preset risk thresholds step by step. These risk thresholds (such as T...) low T medium T high These are pre-configured ranges used to define different risk levels.

[0153] Based on the comparison results, the authentication processing module 500 will perform different authentication processes and responses:

[0154] Direct authentication: If the overall risk probability P after decryption risk Below the preset low-risk threshold T low Once the system determines that the user's identity is trustworthy, the authentication policy module will directly return a "authentication passed" response, allowing the user to access the corresponding insurance business resources.

[0155] Customized secondary verification: If P risk Between the low risk threshold T low With medium risk threshold T medium A value between these two indicates a medium level of risk or uncertainty. The system will then trigger customized secondary verification, such as requiring the user to enter a dynamic verification code, performing a liveness detection, or answering security questions, to further confirm the user's identity.

[0156] Authentication denied: If P risk The risk level is higher than the preset high-risk threshold T. high (or higher than T) medium This indicates the presence of high-risk or suspicious activity. The system will directly reject the authentication request and simultaneously trigger an alarm mechanism, sending an alert to security management personnel.

[0157] To further clarify the collaborative working process of the technical solution described in this invention, a specific working scenario example will be used for illustration below.

[0158] When a user first registers for the online services of the insurance company described in this invention and completes identity verification, or triggers an identity verification request during subsequent logins and high-risk operations, the system will work collaboratively according to the following process:

[0159] 1. Data collection and local encryption on user devices;

[0160] S1. Data acquisition module 100 constructs a benchmark authentication matrix:

[0161] When a user registers for insurance services for the first time, the data collection module 100 will be activated, guiding the user to enter identity authentication information. This module collects the user's fingerprint, iris, and facial feature baseline data through biometric sensors (such as fingerprint recognition modules and facial recognition cameras) on its smart device.

[0162] At the same time, the behavior capture module (such as accelerometer, gyroscope, touch screen sensor) will synchronously record the cognitive behavior baseline data of the user when performing registration operations (such as swiping the screen, entering information, clicking buttons), including swiping trajectory, key press duration, operation speed, contact pressure, and eye movement pattern.

[0163] The data acquisition module 100's internal data stream processing module integrates and standardizes this multi-source heterogeneous data, removes noise, and performs precise timestamp alignment. Ultimately, these standardized biometric and cognitive behavioral benchmark data are fused to construct a high-dimensional benchmark authentication matrix. This matrix serves as a unique digital identity profile for each user, providing a benchmark reference for subsequent authentication.

[0164] S2, Data Encryption Module 200 Real-time Authentication Data Acquisition and Encryption:

[0165] When a user logs into the insurance application or performs sensitive operations (such as large policy changes) later, the system will trigger identity authentication again. The data encryption module 200 will then be activated, collecting the user's current biometric data, cognitive behavior data, and relevant environmental information (such as device location, network environment, time, device type, etc.) in real time.

[0166] The data encryption module 200 uses a pre-distributed or generated homomorphic encryption key to locally encrypt the real-time collected data, generating encrypted real-time data, encrypted environment information, and encrypting the baseline authentication matrix to generate an encrypted baseline authentication matrix.

[0167] Finally, the data encryption module 200 encapsulates all encrypted data into data packets conforming to a specific secure transmission protocol and transmits them to the ciphertext calculation core layer 200 on the server side via a secure peer-to-peer encrypted channel. Throughout the entire transmission process, all data remains encrypted, maximizing the protection of the privacy of the user's original sensitive information.

[0168] 2. Ciphertext computation and fusion reasoning in the core layer of ciphertext computation;

[0169] S3: Data Quantization Module 300 Quantization Encryption Cognitive Conflict Index:

[0170] The server-side data quantization module 300 receives encrypted data transmitted from the user device. Without performing any data decryption, this module utilizes a cognitive conflict dynamics model based on homomorphic encryption optimization to evaluate the degree of deviation between the encrypted real-time data and the encryption benchmark pattern stored in the encryption benchmark authentication matrix by performing comparison operations in the homomorphic encryption domain.

[0171] Based on the results of these encrypted operations, the data quantization module 300 generates an encrypted cognitive conflict index. This index exists in encrypted form, and its value directly reflects the degree of deviation between the user's current behavior and normal, habitual behavior patterns. The larger the index value, the higher the degree of conflict between the current behavior pattern and the baseline pattern, and the greater the possibility of anomalies occurring.

[0172] S4: Risk calculation module 400 generates encrypted intent fingerprints and collaborative reasoning:

[0173] The risk calculation module 400 continues to process the encrypted data in the encrypted state, integrating the encryption baseline authentication matrix, encryption cognitive conflict index, real-time encryption data, and encryption environment information to generate a composite encryption intent fingerprint. This fingerprint integrates the immediacy characteristics of user behavior, the degree of deviation from historical patterns, the user's inherent baseline identity information, and external environmental factors related to the authentication session.

[0174] Subsequently, the risk calculation module 400 inputs the encrypted intent fingerprint into a pre-trained collaborative inference network. This network is a model specifically designed for deep learning inference in the homomorphic encryption domain. Through deep fusion inference of the encrypted intent fingerprint, the risk calculation module 400 ultimately outputs a comprehensive risk probability for the encrypted form.

[0175] 3. Decryption and intelligent decision-making at the authentication and strategy layers;

[0176] S5, Decoding the Overall Risk Probability:

[0177] The authentication processing module 500 receives the encryption comprehensive risk probability P output by the ciphertext calculation core layer 200. risk_enc It employs a comprehensive risk probability decryption algorithm model, obtaining the comprehensive risk probability P in plaintext form through private key decryption or secure multi-party computation (MPC) decryption. risk .

[0178] Once P is obtained risk The authentication processing module 500 compares this probability with multiple risk thresholds T preset by the system. low T medium T high A step-by-step comparison is performed. Based on the comparison results, the authentication processing module 500 will take different authentication responses:

[0179] Direct authentication: If P risk ≤T low The system determines that the user's identity is trustworthy and directly returns "Authentication successful".

[0180] Customized secondary verification: If T low <P risk ≤T medium This indicates a medium risk, and the system will trigger customized secondary verification, such as requiring the user to enter a dynamic verification code or performing a liveness detection.

[0181] Authentication denied: If P risk >T high or P risk >T medium This indicates a high risk, and the system will directly reject the authentication request and trigger an alarm mechanism.

[0182] The model optimization module 600 accurately records detailed information and the final authentication result for each authentication request, building a comprehensive security audit log. These logs serve as the foundational data for subsequent system performance analysis, security incident tracing, and model optimization.

[0183] The model optimization module 600 utilizes reinforcement learning algorithms, using the final result of each authentication as a feedback signal. In encrypted form, this module continuously iteratively optimizes key parameters within the system, including the parameters of the cognitive conflict dynamics model, the encryption weights and structural parameters of the collaborative inference network, and preset risk thresholds. This continuous self-learning and adjustment enables the system to improve based on actual performance, constantly adapting to evolving security threats and user behavior patterns, thereby enhancing the accuracy and security of authentication.

[0184] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for comprehensive management data processing of insurance identity authentication, characterized in that, Includes the following steps: S1. Collect historical users' biometric baseline data and cognitive behavior baseline data through the device, and construct a baseline authentication matrix based on the historical users' biometric baseline data and cognitive behavior baseline data; S2. Based on the benchmark authentication matrix, receive and encrypt the current user's biometric benchmark data and cognitive behavior benchmark data in real time according to the insurance identity authentication request initiated by the current user to generate encrypted real-time data, encrypt the unencrypted environmental information to generate encrypted environmental information, encrypt the benchmark authentication matrix to generate an encrypted benchmark authentication matrix, and transmit the encrypted real-time data, the encrypted environmental information and the encrypted benchmark authentication matrix to the encrypted calculation core layer of the server. S3. The encrypted calculation core layer performs anomaly quantification calculation on the current user's behavior based on the cognitive conflict dynamics model, the encrypted real-time data, and the encrypted benchmark authentication matrix to obtain the encrypted cognitive conflict index. S4. The core layer of the encrypted calculation generates an encryption intent fingerprint based on the encryption benchmark authentication matrix, the encryption cognitive conflict index, the encryption real-time data, and the encryption environment information, and uses a collaborative reasoning network to perform fusion reasoning on the encryption intent fingerprint to obtain the comprehensive encryption risk probability. S5. Based on the comprehensive risk probability decryption algorithm model, the encrypted comprehensive risk probability is decrypted to obtain the decrypted comprehensive risk probability. The decrypted comprehensive risk probability is compared step by step with the preset risk threshold. The current user's insurance identity authentication request is authenticated based on the step-by-step comparison results, and the authentication result is returned. The cognitive conflict dynamics model is as follows: ; In the formula, The cryptographic cognitive conflict index; A function that operates in the homomorphic encryption domain; For the encrypted real-time data; The encryption benchmark authentication matrix; These are parameters for the cognitive conflict dynamics model; Step S4 further includes: In the encrypted state, based on the fusion function operating in the homomorphic encryption domain, the core layer of ciphertext computation is based on the encryption benchmark authentication matrix and the encryption cognitive conflict index. The encrypted real-time data and the encrypted environment information Generate an encrypted intent fingerprint; The encryption intent fingerprint is subjected to fusion reasoning based on a collaborative reasoning network and a fusion reasoning model to obtain the comprehensive encryption risk probability. in, The encrypted intent fingerprint is , ; In the formula, A fusion function operating on the homomorphic encryption domain. An encryption form that represents a user's long-term, stable identity characteristics. These are the encryption parameters used in the fusion function; The fusion reasoning model is ; In the formula, The overall encryption risk probability is... Characterizes the inference function of a collaborative inference network operating in the homomorphic cryptographic domain. The cryptographic weights and structural parameters characterize the collaborative reasoning network, which are used by the collaborative reasoning network in the ciphertext state to perform fusion reasoning on the cryptographic intent fingerprint.

2. The insurance identity authentication integrated management data processing method according to claim 1, characterized in that, In step S1, the step of constructing a benchmark authentication matrix based on historical users' biometric benchmark data and cognitive behavior benchmark data further includes: When a user registers for the first time or initializes their identity, the device collects the user's biometric baseline data through biometric sensors. The biometric baseline data includes fingerprints, irises, and faces. The biometric sensors include a fingerprint recognition module, an iris scanner, and a facial recognition camera. The device records the user's cognitive behavior baseline data in a specific task through a behavior capture module. The cognitive behavior baseline data includes swiping trajectory, button habits, dwell time and eye movement pattern. The behavior capture module includes an accelerometer, a gyroscope and a touch screen sensor. Based on the collected biometric baseline data and cognitive behavioral baseline data, and by integrating the user's biometric characteristics and behavioral patterns, a baseline authentication matrix is ​​constructed, wherein the baseline authentication matrix is: ; ; In the formula, This is the construction function for the benchmark authentication matrix, used to fuse the processed biometric features and cognitive behavioral features; For the raw biometric baseline data collected Feature vectors extracted from; From the collected raw cognitive behavioral benchmark data The feature vectors extracted from them.

3. The insurance identity authentication integrated management data processing method according to claim 1, characterized in that, In step S2, the step of receiving and encrypting the current user's biometric baseline data and cognitive behavior baseline data in real time based on the baseline authentication matrix and according to the insurance identity authentication request initiated by the current user further includes: Receive the insurance identity authentication request initiated by the current user through the device, parse and collect the current user's biometric baseline data, cognitive behavior baseline data and environmental information in real time through the device's biometric sensor and behavior capture module, respectively, based on the insurance identity authentication request; Based on a pre-distributed or generated homomorphic encryption key and the aforementioned benchmark authentication matrix, the current user's biometric benchmark data, cognitive behavior benchmark data, and environmental information are encrypted to generate and obtain the encrypted real-time data. and the encrypted environment information Simultaneously, the baseline authentication matrix is ​​encrypted to generate an encrypted baseline authentication matrix. ; The encrypted real-time data is transmitted according to the secure transmission protocol. and the encrypted environment information and the cryptographic benchmark authentication matrix It is encapsulated into a data packet and transmitted to the encrypted computing core layer on the server side through an encrypted channel; The encrypted real-time data includes encrypted biometric baseline data and cognitive behavior baseline data of the current user. The encrypted real-time data ; The encrypted environment information ; The encryption benchmark authentication matrix ; In the formula, It is a homomorphic encryption function; This refers to unencrypted real-time data of the current user, including unencrypted biometric and cognitive behavioral data of the current user. This is the unencrypted environment information of the current user; The benchmark authentication matrix; A pre-distributed or generated homomorphic encryption key used for homomorphic encryption.

4. The insurance identity authentication integrated management data processing method according to claim 1, characterized in that, In step S3, the step of the encrypted computation core layer performing anomaly quantification calculation on the current user's behavior based on the cognitive conflict dynamics model, the encrypted real-time data, and the encrypted benchmark authentication matrix includes: The core layer for ciphertext computation receives encapsulated encrypted real-time data. and encrypted environment information and the cryptographic benchmark authentication matrix After receiving the data packet, the data packet is decomposed, and the encrypted real-time data is processed using the cognitive conflict dynamics model. and encryption benchmark authentication matrix Anomaly quantification calculations are performed to obtain the encrypted cognitive conflict index. The encrypted cognitive conflict index, wherein The encrypted cognitive conflict index represents the amount of anomalies between the current user's behavior and the behavior of historical users. The value is proportional to the number of anomalies, and the cryptographic cognitive conflict index is... The larger the value, the greater the anomaly between the current user's behavior and the behavior of historical users.

5. The insurance identity authentication integrated management data processing method according to claim 1, characterized in that, Step S5 further includes: S5-1, After receiving the encrypted comprehensive risk probability in encrypted form, the authentication decision and policy layer on the server side decrypts the encrypted comprehensive risk probability using the private key held by the authentication decision and policy layer based on the comprehensive risk probability decryption algorithm model to obtain the comprehensive risk probability. The comprehensive risk probability decryption algorithm model is as follows: In the formula, The comprehensive risk probability, This is a homomorphic decryption function in the comprehensive risk probability decryption algorithm model. It is used to receive the input ciphertext and private key, and decrypt the ciphertext using the private key to output the plaintext. The overall probability of encryption risk; This is the private key used for decryption; S5-2, compare the decrypted comprehensive risk probability with the preset risk threshold step by step, and process the current user's insurance identity authentication request based on the step-by-step comparison results, and return the authentication result; The preset risk thresholds are pre-configured by operators according to their needs and are used to define ranges of different risk levels. These preset risk thresholds include low-risk thresholds. Medium risk threshold and high risk threshold ; If we consider the overall risk probability Low risk threshold If the current user's insurance identity authentication request is deemed low-risk, the returned authentication result indicates that the user's identity is trustworthy. If low risk threshold Overall risk probability Medium risk threshold If the current user's insurance identity authentication request is determined to be of medium risk, the authentication result returned is that the user's identity is uncertain and requires secondary authentication, and the process returns to step S2; If the medium risk threshold Overall risk probability High risk threshold If the current user's insurance identity authentication request is deemed high-risk, the authentication result returned will be a rejection of the current user's insurance identity authentication request. If we consider the overall risk probability High risk threshold If the current user's insurance identity authentication request is deemed a serious risk, the authentication result will be rejected, and an alarm mechanism will be triggered to send an alert to the security management personnel.

6. The insurance identity authentication integrated management data processing method according to claim 1, characterized in that, The method further includes the following steps: Record the session ID, authentication time, authentication device information, returned authentication result, and encryption process data of the current user's insurance identity authentication request, and generate a security audit log. The encryption process data includes biometric baseline data, cognitive behavior baseline data, baseline authentication matrix, encryption real-time data, encryption environment information, encryption baseline authentication matrix, encryption cognitive conflict index, encryption intent fingerprint, and encryption comprehensive risk probability. Using reinforcement learning algorithms, the authentication result is used as a feedback signal to iteratively optimize the parameters in the cognitive conflict dynamics model based on the security audit log in the encrypted state; Simultaneously, the encryption weights and structural parameters of the collaborative reasoning network are adjusted, and the preset risk threshold is dynamically adjusted based on the optimization results of the cognitive conflict dynamics model.

7. A system for implementing the insurance identity authentication integrated management data processing method according to claim 1, characterized in that, The system includes a data acquisition module, a data encryption module, a data quantification module, a risk calculation module, and an authentication processing module; in, The data acquisition module is used to collect historical users' biometric baseline data and cognitive behavior baseline data through the device, and to construct a baseline authentication matrix based on the historical users' biometric baseline data and cognitive behavior baseline data. The data encryption module is used to receive and encrypt the current user's biometric baseline data and cognitive behavior baseline data in real time based on the baseline authentication matrix and the insurance identity authentication request initiated by the current user, generating encrypted real-time data; encrypting the unencrypted environmental information to generate encrypted environmental information; encrypting the baseline authentication matrix to generate an encrypted baseline authentication matrix; and transmitting the encrypted real-time data, the encrypted environmental information, and the encrypted baseline authentication matrix to the encrypted computing core layer on the server side. The data quantization module is used to perform anomaly quantification calculation processing on the current user's behavior through the encrypted computing core layer and based on the cognitive conflict dynamics model, the encrypted real-time data, and the encrypted baseline authentication matrix to obtain an encrypted cognitive conflict index. The risk calculation module is used by the core layer of the encrypted calculation to generate an encrypted intent fingerprint based on the benchmark authentication matrix, the encrypted cognitive conflict index, the encrypted real-time data, and the encrypted environment information, and to use a collaborative reasoning network to perform fusion reasoning on the encrypted intent fingerprint to obtain the comprehensive encryption risk probability. The authentication processing module is used to decrypt the encrypted comprehensive risk probability based on the comprehensive risk probability decryption algorithm model, obtain the decrypted comprehensive risk probability, compare the decrypted comprehensive risk probability with a preset risk threshold step by step, process the current user's insurance identity authentication request based on the step-by-step comparison results, and return the authentication result.

8. The system according to claim 7, characterized in that, The system also includes a model optimization module, which is used for: Record the session ID, authentication time, authentication device information, returned authentication result, and encryption process data of the current user's insurance identity authentication request, and generate a security audit log. The encryption process data includes biometric baseline data, cognitive behavior baseline data, baseline authentication matrix, encryption real-time data, encryption environment information, encryption baseline authentication matrix, encryption cognitive conflict index, encryption intent fingerprint, and encryption comprehensive risk probability. Using reinforcement learning algorithms, the authentication result is used as a feedback signal to iteratively optimize the parameters in the cognitive conflict dynamics model based on the security audit log in the encrypted state; Simultaneously, the encryption weights and structural parameters of the collaborative reasoning network are adjusted, and the preset risk threshold is dynamically adjusted based on the optimization results of the cognitive conflict dynamics model.

Citation Information

Patent Citations

  • Distributed intelligent authentication method based on dynamic multi-modal fusion

    CN120546922A