Multi-factor authentication-based lottery drawing platform anti-swiping method and system

By determining the user ranking factor based on the type of multi-factor authentication request in high-concurrency scenarios and assigning a lottery probability value, the problem of excessive server load caused by multi-factor authentication is solved, thereby improving user experience and platform stability.

CN121120140APending Publication Date: 2025-12-12GUANGZHOU QIDIAN CREATIVE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511229313.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In high-concurrency scenarios, multi-factor authentication operations can easily overload the server, leading to response delays, timeouts, or even temporary service unavailability, which affects user experience and the stability of the lottery platform.

Method used

By obtaining the authentication request type of the multi-factor authentication request, the user's ranking factor is determined, and lottery probability values ​​are assigned in descending order of the ranking factor. At the same time, multi-factor authentication is performed on the user to ensure that the user obtains a normal lottery probability after completing the authentication.

Benefits of technology

While ensuring user experience, it effectively combats prize-grabbing behavior, accurately distinguishes between real users and potential prize-grabbing accounts, reduces the probability of winning prizes for security-verified users, reduces concurrent traffic, and improves the stability of the prize-grabbing platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121120140A_ABST
    Figure CN121120140A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computers, and discloses a lottery drawing platform anti-swiping method and system based on multi-factor authentication, and the method comprises the steps: obtaining multi-factor authentication requests which are not completed during lottery drawing and respectively correspond to a plurality of users, and obtaining a plurality of authentication request types of each multi-factor authentication request; determining a sorting factor of the multi-factor authentication request corresponding to each user according to the authentication results of the plurality of authentication request types of the multi-factor authentication request; in the authentication process, the users are allowed to complete lottery drawing, lottery drawing probability values are given to the multiple users from low to high according to the sequence of sorting factors corresponding to the multiple users from high to low, and meanwhile multi-factor authentication is conducted on the multiple users; and after the authentication is completed, endowing a normal lottery drawing probability value to the user passing the multi-factor authentication. According to the method and the device, overhigh server load caused by multi-factor authentication in a concurrent scene can be avoided, and the use experience of a lottery drawing platform is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer technology, more specifically, to a multi-factor authentication-based anti-brushing method and system for a lottery platform. BACKGROUND

[0002] With the development of Internet technology, various lottery platforms increasingly value the authenticity of user identity and the security of prize distribution. Some existing lottery platforms have adopted a multi-factor authentication mechanism to verify the identity of users participating in the lottery, such as combining passwords, mobile phone verification codes, biometric features, and other methods to enhance authentication strength. The multi-factor authentication method can effectively prevent false accounts, robot scripts, or malicious users from repeatedly brushing prizes, and can prevent fraudulent behavior, thereby ensuring the reliability and fairness of the prize distribution process and reducing resource waste and fraud risks caused by identity fraud.

[0003] In the working process of the multi-factor authentication mechanism, due to the high concurrency of lottery activities, the authentication module for multi-factor authentication of users may face a huge request pressure. Especially during the peak lottery period, frequent multi-factor authentication operations can easily cause the server load to be too high, thereby causing response delays, timeouts, and even temporary service unavailability. This type of performance bottleneck can cause users to experience significant waiting delays or operation interruptions during the lottery process, severely affecting their participation experience and satisfaction, thereby limiting the widespread application of multi-factor authentication in high-concurrency lottery scenarios to some extent, resulting in poor control of resource waste and fraud risks for lottery platforms. SUMMARY

[0004] The purpose of the present application is to provide a multi-factor authentication-based anti-brushing method and system for a lottery platform, which solves the technical problem of multi-factor authentication operations easily causing the server load to be too high in a concurrent scenario, and achieves the technical effect of avoiding multi-factor authentication from causing the server load to be too high in a concurrent scenario.

[0005] The multi-factor authentication-based anti-brushing method for a lottery platform provided by the present application includes: obtaining a plurality of multi-factor authentication requests corresponding to a plurality of users respectively during a lottery, and obtaining a plurality of authentication request types of each multi-factor authentication request; wherein the authentication request types include device identification authentication, security question authentication, SMS verification code authentication, password authentication, fingerprint authentication, and facial recognition authentication; determining a sorting factor of the multi-factor authentication request corresponding to each user according to the authentication results of the plurality of authentication request types of the multi-factor authentication request; allowing the user to complete the lottery during the authentication process, while assigning lottery probability values to the plurality of users from low to high in order of the sorting factors corresponding to the plurality of users from high to low, and simultaneously performing multi-factor authentication on the plurality of users; and after the authentication is completed, assigning a normal lottery probability value to the user who passes the multi-factor authentication.

[0006] In one possible implementation, based on the authentication results of multiple authentication request types in a multi-factor authentication request, a ranking factor for each user's multi-factor authentication request is determined, including: obtaining the authentication contribution and authentication weight values ​​corresponding to each authentication request type in the multi-factor authentication request, where the authentication contribution represents the contribution to verifying the user's identity, and the authentication weight value represents the importance of the authentication request type in user identity authentication; and determining the sum of the products of the authentication contribution and authentication weight values ​​of all authentication request types that have passed authentication in each multi-factor authentication request as the ranking factor for each user's multi-factor authentication request.

[0007] In another possible implementation, the method further includes: obtaining the first inventory access count of each user within a preset time period before the lottery; determining the first inventory access count range corresponding to the first inventory access count, and obtaining the first multi-factor authentication request level corresponding to the first inventory access count range. Different first multi-factor authentication request levels correspond to different first multi-factor authentication requests of multiple authentication request types. Multi-factor authentication is performed on the user according to the first multi-factor authentication request. Wherein, the larger the numerical range of the first inventory access count range, the larger the first multi-factor authentication request level, and the more authentication request types corresponding to the first multi-factor authentication request level.

[0008] In another possible implementation, users are allowed to participate in a lottery during the authentication process. Simultaneously, multiple users are assigned lottery probability values ​​from low to high according to their respective sorting factors, and multi-factor authentication is performed on each user. This includes: obtaining the number of times a user accesses the second inventory during the lottery; determining the range of the second inventory access count and obtaining the second multi-factor authentication request level corresponding to that range, with different levels corresponding to different types of authentication requests; obtaining the second lottery probability value corresponding to the second multi-factor authentication request; adjusting the user's lottery probability value during the authentication process to the second lottery probability value; and performing multi-factor authentication on the user according to the second multi-factor authentication request. The larger the range of the second inventory access count, the higher the second multi-factor authentication request level; the more authentication request types corresponding to the second multi-factor authentication request level, the smaller the second lottery probability value.

[0009] In another possible implementation, the method further includes: when both the first inventory access count and the second inventory access count are greater than the preset inventory access count, authenticating the user using a multi-factor authentication request at the highest level of multi-factor authentication request; when either the first inventory access count or the second inventory access count is less than the preset inventory access count, reducing the user's first and second multi-factor authentication request levels by a preset level to obtain a third multi-factor authentication request level, and authenticating the user using multi-factor authentication requests of multiple authentication request types corresponding to the third multi-factor authentication request level; wherein, the higher the third multi-factor authentication request level, the greater the number of authentication request types corresponding to the third multi-factor authentication request level.

[0010] In another possible implementation, the method further includes: obtaining the number of authentication failures and the authentication response time for each user within a preset time period before the lottery; determining the first authentication response factor for each user based on the number of authentication failures and the authentication response time within the preset time period before the lottery using an empirical value table; wherein, the higher the number of authentication failures, the lower the first authentication response factor; and the higher the authentication response time, the lower the first authentication response factor; determining the product of the first inventory access count and the first authentication response factor as the first adjustment inventory access count; determining the range of the first adjustment inventory access count corresponding to the first adjustment inventory access count, and obtaining the first adjustment multi-factor authentication request level corresponding to the range of the first adjustment inventory access count, wherein different first adjustment multi-factor authentication request levels correspond to different first multi-factor authentication requests of multiple authentication request types, and performing multi-factor authentication on the user according to the first multi-factor authentication request; wherein, the larger the numerical range of the first adjustment inventory access count, the higher the first adjustment multi-factor authentication request level, and the more authentication request types corresponding to the first adjustment multi-factor authentication request level.

[0011] In another possible implementation, the method further includes: obtaining the number of authentication failures and the authentication response time when a user participates in a lottery during the authentication process; determining a second authentication response factor for each user based on the number of authentication failures and the authentication response time using an empirical value table; wherein, the higher the number of authentication failures, the lower the second authentication response factor; and the higher the authentication response time, the lower the second authentication response factor; determining the product of the second inventory access count and the second authentication response factor as the second adjustment inventory access count; determining the range of the second adjustment inventory access count corresponding to the second adjustment inventory access count, and obtaining the second adjustment inventory access count. The range of numbers corresponds to the second adjusted multi-factor authentication request level. Different second adjusted multi-factor authentication request levels correspond to different types of second multi-factor authentication requests. The second adjusted lottery probability value corresponding to the second multi-factor authentication request is obtained, and the lottery probability value of the user during the authentication process is adjusted to the second adjusted lottery probability value. At the same time, multi-factor authentication is performed on the user according to the second adjusted multi-factor authentication request. Among them, the larger the range of the second adjusted inventory access times, the higher the second adjusted multi-factor authentication request level. The more types of authentication requests corresponding to the second adjusted multi-factor authentication request level, the smaller the second adjusted lottery probability value.

[0012] In another possible implementation, the method further includes: determining the authentication weight value corresponding to each authentication request type of the multi-factor authentication request based on the empirical value table, the number of second inventory accesses, the number of authentication failures, and the authentication response time during the lottery; determining the sum of the products of the authentication contribution and authentication weight values ​​corresponding to all authentication request types of each multi-factor authentication request as the ranking factor for each user's multi-factor authentication request; allowing users to complete the lottery during the authentication process, and assigning lottery probability values ​​to multiple users from low to high according to the ranking factors corresponding to multiple users from high to low, while performing multi-factor authentication on multiple users separately; and assigning normal lottery probability values ​​to users who have passed multi-factor authentication after authentication.

[0013] In another possible implementation, the method further includes: when allowing a user to complete the lottery during the authentication process, obtaining the user's winning status during the authentication process; when the winning status is that the user has won, determining the user's authentication limit time based on the number of second inventory accesses, the number of authentication failures, and the authentication response time during the lottery, using an empirical value table; within the authentication limit time, obtaining the user's multi-factor authentication result; when the user passes multi-factor authentication within the authentication limit time, issuing the winning prize to the user; when the user fails multi-factor authentication within the authentication limit time, not issuing the winning prize to the user.

[0014] This application also provides a multi-factor authentication-based lottery platform anti-cheating system, including a unit for performing the method described in any of the preceding claims.

[0015] The beneficial effects of the embodiments in this application compared with the prior art are:

[0016] This application provides a method for preventing fraudulent activities on a lottery platform based on multi-factor authentication. The method includes: obtaining multiple incomplete multi-factor authentication requests for each user during the lottery draw, and obtaining multiple authentication request types for each multi-factor authentication request; wherein, the authentication request types include device identification authentication, security question authentication, SMS verification code authentication, password authentication, fingerprint authentication, and facial recognition authentication; determining a sorting factor for the multi-factor authentication request corresponding to each user based on the multiple authentication request types; allowing users to complete the lottery draw during the authentication process, and assigning lottery probability values ​​to multiple users from low to high according to the sorting factors corresponding to the multiple users from high to low, while performing multi-factor authentication on each user; after authentication is completed, assigning normal lottery probability values ​​to users who pass the multi-factor authentication. The method in this application embodiment can guide users to complete multi-factor authentication while allowing the lottery to ensure user experience. It can effectively resist the fraudulent behavior in the lottery platform. By dividing the ranking factors based on the authentication type security and associating them with the lottery probability, it can accurately distinguish between real users and potential fraudulent accounts, greatly reduce the lottery probability of security-authenticated users, avoid fraudulent behavior from undermining the fairness of the lottery activity, and at the same time reduce the platform's concurrent traffic and improve the stability of the lottery platform. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 A flowchart illustrating the first method for preventing fraudulent activities on a lottery platform based on multi-factor authentication, as provided in this application embodiment;

[0019] Figure 2 A schematic diagram illustrating the workflow of the first anti-fraud method for a lottery platform based on multi-factor authentication provided in this application embodiment;

[0020] Figure 3 A flowchart illustrating the second method for preventing fraudulent activities on a lottery platform based on multi-factor authentication, as provided in this application embodiment;

[0021] Figure 4 A schematic diagram illustrating the workflow of the second multi-factor authentication-based anti-fraud method for a lottery platform provided in this application embodiment;

[0022] Figure 5 A flowchart illustrating the third method for preventing fraudulent activities in a lottery platform based on multi-factor authentication, as provided in this application embodiment;

[0023] Figure 6 A schematic diagram illustrating the workflow of the third multi-factor authentication-based anti-fraud method for a lottery platform provided in this application embodiment;

[0024] Figure 7 A flowchart illustrating the fourth method for preventing fraudulent activities on a lottery platform based on multi-factor authentication provided in this application embodiment;

[0025] Figure 8 A flowchart illustrating the fifth method for preventing fraudulent activities on a lottery platform based on multi-factor authentication provided in this application embodiment;

[0026] Figure 9 A schematic diagram of the logical structure of a lottery platform anti-fraud system based on multi-factor authentication provided in this application embodiment; Detailed Implementation

[0027] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0028] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0029] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrases "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0030] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0031] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0032] During the operation of multi-factor authentication mechanisms, lottery activities are often accompanied by high-concurrency access. The authentication module that performs multi-factor authentication for users may face huge request pressure, which limits the widespread application of multi-factor authentication in high-concurrency lottery scenarios and results in poor control over resource waste and fraud risks of lottery platforms.

[0033] Based on the above reasons, this application provides a method for preventing fraudulent activities on a lottery platform based on multi-factor authentication. The method includes: obtaining multiple incomplete multi-factor authentication requests for each user during the lottery draw, and obtaining multiple authentication request types for each multi-factor authentication request; wherein, the authentication request types include device identification authentication, security question authentication, SMS verification code authentication, password authentication, fingerprint authentication, and facial recognition authentication; determining a sorting factor for the multi-factor authentication request corresponding to each user based on the multiple authentication request types; allowing users to complete the lottery draw during the authentication process, and assigning lottery probability values ​​to multiple users from low to high according to the sorting factors corresponding to the multiple users from high to low, while performing multi-factor authentication on each user; after authentication is completed, assigning normal lottery probability values ​​to users who pass the multi-factor authentication. The method in this application embodiment can guide users to complete multi-factor authentication while allowing the lottery to ensure user experience. It can effectively resist the fraudulent behavior in the lottery platform. By dividing the ranking factors based on the authentication type security and associating them with the lottery probability, it can accurately distinguish between real users and potential fraudulent accounts, greatly reduce the lottery probability of security-authenticated users, avoid fraudulent behavior from undermining the fairness of the lottery activity, and at the same time reduce the platform's concurrent traffic and improve the stability of the lottery platform.

[0034] In some scenarios, the multi-factor authentication-based anti-fraud method for lottery platforms in this application can be applied to various lottery platforms such as e-commerce platform promotions and online shopping mall promotions. It can ensure the user experience under high concurrency scenarios while ensuring that the platform is not affected by fraudulent accounts, thus protecting the legitimate rights and interests of the platform.

[0035] The following specific examples illustrate a method for preventing fraudulent activities on a lottery platform based on multi-factor authentication, as provided in this application.

[0036] Figure 1 A flowchart illustrating the first method for preventing fraudulent activities on a lottery platform based on multi-factor authentication provided in this application is shown below. Figure 1 As shown, the anti-fraud method for this lottery platform based on multi-factor authentication includes S110 to S120, and S110 to S120 will be explained in detail below.

[0037] S110. Obtain the multi-factor authentication requests that were not completed during the lottery for each user, and obtain the multiple authentication request types for each multi-factor authentication request. The authentication request types include device identification authentication, security question authentication, SMS verification code authentication, password authentication, fingerprint authentication, and facial recognition authentication.

[0038] Figure 2 A schematic diagram illustrating the workflow of the first multi-factor authentication-based anti-fraud method for a lottery platform provided in this application embodiment is shown below. Figure 2 As shown, during the operation of the lottery platform, multiple incomplete multi-factor authentication requests corresponding to users during the lottery can be obtained first, and multiple authentication request types for each multi-factor authentication request can be obtained. The multi-factor authentication request can be an authentication request sent by the lottery platform to the user when the user participates in the lottery. The user's identity can be verified through the multi-factor authentication request to avoid the lottery fraud behavior of non-real users. Each multi-factor authentication request can include multiple authentication request types to improve the accuracy of user identity verification through the authentication combination of multiple authentication request types.

[0039] For example, authentication request types may include device identification authentication, security question authentication, SMS verification code authentication, password authentication, fingerprint authentication, and facial recognition authentication, which can reflect different security levels of user authentication.

[0040] For example, in a lottery platform, users may need to complete multi-factor authentication when participating in a lottery. By obtaining the authentication results of multiple authentication request types submitted by the user, the security level of the user's identity verification can be fully understood.

[0041] S120. Based on the authentication results of multiple authentication request types for the multi-factor authentication request, determine the ranking factor for each user's multi-factor authentication request. During the authentication process, allow users to participate in a lottery, and assign lottery probability values ​​to multiple users in descending order of their respective ranking factors, while simultaneously performing multi-factor authentication on each user. After authentication, assign normal lottery probability values ​​to users who pass the multi-factor authentication.

[0042] In this implementation, the ranking factor of the multi-factor authentication request for each user can be determined based on the authentication results of multiple authentication request types. The ranking factor can be calculated based on the security differences of different authentication types, and the combination of authentication types with lower security may correspond to a higher ranking factor.

[0043] like Figure 2 As shown, to address the potential disruption of the lottery service due to excessive server load, this implementation allows users to participate in the lottery during the authentication process. This prevents users' normal lottery participation from being affected by high concurrency scenarios. Furthermore, when allowing users to participate, lottery probability values ​​are assigned to multiple users in descending order of their respective ranking factors. Users with higher ranking factors are assigned lower probability values, and vice versa. This ensures that all users can participate while simultaneously adjusting the lottery probability to regulate the behavior of those who engage in excessive lottery participation.

[0044] For example, users who use device identification authentication and SMS verification code authentication can be given a higher ranking factor and a lower probability of winning prizes because these authentication methods have relatively low security. On the other hand, users who use fingerprint authentication and facial recognition authentication may be given a lower ranking factor and a higher probability of winning prizes because these authentication methods have higher security, in order to regulate prize-grabbing behavior.

[0045] While allowing users to participate in the lottery, multiple users can undergo multi-factor authentication separately. The authentication process can proceed in the order of ranking factors, with users having higher ranking factors potentially completing the authentication process first. After authentication, users who pass multi-factor authentication can be assigned a normal lottery probability value, ensuring that all authenticated users have a fair chance to participate in the lottery.

[0046] For example, when allowing users to participate in a lottery while performing multi-factor authentication on multiple users, a pop-up window can be displayed prompting users to complete multi-factor authentication after a preset number of lottery draws. The preset number of draws can be 1, 3, or 5.

[0047] The beneficial effects of the above implementation method are that it obtains multi-factor authentication requests submitted by multiple users and accurately identifies the specific authentication request type corresponding to each multi-factor authentication request. Different authentication types have different security levels. Based on preset rules linked to the security of authentication types, a corresponding ranking factor is determined for the authentication result of each user's multi-factor authentication request. While allowing users to participate in a lottery during the multi-factor authentication process, the multi-factor authentication operation is carried out on each user in descending order of their ranking factors. This ensures that users with lower security need to complete the authentication process first. Each user is assigned a corresponding lottery probability value according to their ranking factor from low to high. Users with higher ranking factors indicate lower security and require priority authentication, with a lower lottery probability. Conversely, users with lower ranking factors indicate higher security and do not need priority authentication, with a lower lottery probability. This allows the multi-factor authentication process to be rationally ordered, avoiding server congestion and minimizing impact on the user experience of users with high security.

[0048] The beneficial effects of the above implementation method are that it constructs a measurement dimension of user identity reliability through the security differences of multi-factor authentication types, directly links the security of user authentication with the priority of the authentication process and the probability of winning the lottery, and restricts potential lottery fraud behavior from the mechanism by differentiating the lottery probability of users with different reliability, while protecting the legitimate rights and interests of real users.

[0049] The beneficial effect of the above implementation method is that while allowing the lottery, guiding users to complete multi-factor authentication can effectively resist the lottery fraud behavior in the lottery platform. By dividing the ranking factors based on the security of the authentication type and associating them with the lottery probability, it can accurately distinguish between real users and potential lottery fraud accounts, greatly reduce the lottery probability of users with low security authentication, and prevent lottery fraud behavior from undermining the fairness of the lottery activity.

[0050] The beneficial effect of the above implementation method is that after the authentication is completed, users who pass the multi-factor authentication are given a normal lottery probability value, which will not affect the impact of multi-factor authentication on users and ensure the user experience of the lottery platform.

[0051] In some implementations, in S120 above, the sorting factor of the multi-factor authentication request corresponding to each user is determined based on the authentication results of multiple authentication request types of the multi-factor authentication request, including S121 to S122. S121 to S122 will be explained in detail below.

[0052] S121. Obtain the authentication contribution and authentication weight values ​​corresponding to each authentication request type of the multi-factor authentication request. The authentication contribution represents the magnitude of the contribution to verifying the user's identity, and the authentication weight value represents the magnitude of the importance of the authentication request type in user identity authentication.

[0053] In this implementation, the authentication contribution and authentication weight values ​​corresponding to each authentication request type of the multi-factor authentication request can be obtained. The authentication contribution can represent the contribution index to verifying the user's identity, and the authentication weight value can represent the importance index of the authentication request type in user identity authentication. By obtaining these two indicators, the actual role and importance of each authentication request type in the identity verification process can be quantified.

[0054] For example, in the scenario of automatic anti-fraud in a lottery platform, for multi-factor authentication requests to users, the authentication contribution and authentication weight values ​​corresponding to each authentication request type can be obtained. The authentication contribution can reflect the degree of contribution of the authentication type in verifying the user's true identity, and the authentication weight value can reflect the relative importance of the authentication type in the entire identity authentication system.

[0055] S122. Determine the sum of the products of the authentication contribution and authentication weight values ​​of all authentication request types that have passed authentication in each multi-factor authentication request, and use it as the ranking factor for the multi-factor authentication request corresponding to each user.

[0056] In this implementation, the sum of the products of the authentication contribution and the authentication weight values ​​of all authentication request types that have passed authentication in each multi-factor authentication request can be determined as the ranking factor for the multi-factor authentication requests of each user. By multiplying the authentication contribution and the authentication weight value of each authentication request type and summing them, a quantitative indicator that comprehensively reflects the security and effectiveness of the user's authentication request can be obtained.

[0057] After obtaining the sorting factors, the lottery probability values ​​are assigned to multiple users in descending order of their respective sorting factors. At the same time, multi-factor authentication is performed on multiple users. Users who fail the multi-factor authentication are given a lower winning probability, which ensures the anti-fraud effect while protecting the lottery rights of normal users.

[0058] For example, in the scenario of automatic anti-fraud in a lottery platform, for each user's multi-factor authentication request, the authentication contribution value and authentication weight value corresponding to each authentication request type can be multiplied and summed to obtain the ranking factor of the user's multi-factor authentication request. This ranking factor can comprehensively reflect the completeness and reliability of the user's identity authentication.

[0059] The beneficial effect of the above implementation method is that, after obtaining the multi-factor authentication request submitted by the user, for each authentication request type contained in the request, the authentication contribution and authentication weight values ​​are obtained respectively. The authentication contribution is used to measure the quantitative indicator of the role played by the authentication type in the actual process of verifying the user's true identity, while the authentication weight value is an indicator set according to the importance of the authentication type in the entire identity authentication system. For each user's multi-factor authentication request, the authentication contribution and authentication weight values ​​corresponding to all authentication request types that passed the multi-factor authentication request are multiplied and summed to obtain the ranking factor of the user's multi-factor authentication request. By introducing two quantifiable indicators, authentication contribution and authentication weight values, the determination process of the ranking factor is more objective and accurate, which can effectively avoid the ranking bias caused by simply relying on the number of authentication types or subjective judgment, and more realistically reflect the security and effectiveness of different user authentication requests.

[0060] The beneficial effects of the above implementation method are that, when performing subsequent authentication sorting and lottery probability assignment based on the sorting factors of multi-factor authentication requests, it can prioritize the authentication processing of users with high authentication security and sufficient identity verification, and can also more reasonably assign lower lottery probability to users with low authentication validity and suspected of fraudulent activities, which greatly improves the targeting and reliability of the lottery platform's anti-fraud mechanism and further ensures the fairness of the lottery activities.

[0061] Figure 3 A flowchart illustrating the second method for preventing fraudulent activities in a lottery platform based on multi-factor authentication provided in this application is shown below. Figure 3 As shown, the above method also includes S210 to S220, which will be described in detail below.

[0062] S210. Obtain the number of times each user accesses the prize inventory within a preset time period before the lottery.

[0063] Figure 4 A schematic diagram illustrating the workflow of the second multi-factor authentication-based anti-fraud method for lottery platforms provided in this application embodiment is shown below. Figure 4 As shown, during the lottery process, the number of times each user accesses the prize inventory within a preset time period before the lottery can be obtained. The number of times the first inventory is accessed reflects the user's attention to the prize inventory and the frequency of access before the lottery, which can reflect the user's behavioral characteristics.

[0064] For example, in the minutes before a prize draw begins, the number of times users visit the prize inventory page can be counted to generate the first inventory visit count data.

[0065] S220. Determine the first inventory access count range corresponding to the first inventory access count, and obtain the first multi-factor authentication request level corresponding to the first inventory access count range. Different first multi-factor authentication request levels correspond to different first multi-factor authentication requests of multiple authentication request types. Perform multi-factor authentication on the user according to the first multi-factor authentication request. Specifically, the larger the numerical range of the first inventory access count, the higher the first multi-factor authentication request level, and the more authentication request types corresponding to the first multi-factor authentication request level.

[0066] like Figure 4 As shown, after obtaining the first inventory access count, the range of the first inventory access count corresponding to the first inventory access count can be determined based on the first inventory access count, and each range of the first inventory access count is associated with a specific first multi-factor authentication request level.

[0067] like Figure 4 As shown, after determining the first multi-factor authentication request level, the first multi-factor authentication request corresponding to the first multi-factor authentication request level can be determined according to the first multi-factor authentication request corresponding to different authentication request types for different first multi-factor authentication request levels.

[0068] In this implementation, the larger the numerical range of the first inventory access frequency range, the higher the corresponding first multi-factor authentication request level, and the more authentication request types corresponding to the first multi-factor authentication request level, so that users can be authenticated by multiple factors according to the corresponding multiple authentication request types in the future.

[0069] For example, users with a low number of visits may only need to use SMS verification codes; while users with an unusually high number of visits may need to use multiple authentication methods such as SMS verification, facial recognition, and question verification.

[0070] In this implementation, after determining the user's first multi-factor authentication request level, the user can be authenticated using the first multi-factor authentication request corresponding to that level. This process ensures that users with different risk levels receive authentication of a correspondingly strict level.

[0071] For example, for users with a large number of first-order inventory visits, who may be at risk of fraudulently obtaining prizes, they can be required to complete more types of authentication requests, thereby enhancing the reliability of identity verification.

[0072] The beneficial effect of the above implementation method is that normal users usually do not frequently access the prize inventory, while users who engage in prize-grabbing behavior often access the inventory multiple times in the short period before the draw in order to accurately grasp the timing of the draw and seize prize resources. Therefore, by dividing the authentication level by the number of times the inventory is accessed, differentiated identity verification can be achieved for users with different risk levels. The more times the inventory is accessed and the higher the risk, the more authentication types the user needs to complete, and the stricter the identity verification is, thus reducing the possibility of prize-grabbing behavior passing authentication from the source.

[0073] The beneficial effect of the above implementation method is that it provides an objective basis for the strictness of multi-factor authentication by using the specific behavioral data of user inventory access frequency. It can accurately identify high inventory access users who are suspected of fraudulently obtaining prizes. By increasing the number of authentication types for such users, the comprehensiveness of their identity verification is greatly improved, and fraudulent activities that are carried out by simplifying authentication are effectively blocked.

[0074] The beneficial effect of the above implementation method is that it requires only a small number of authentication types for normal users who access the inventory infrequently, avoiding the cumbersome operation problems caused by excessive authentication for normal users, and balancing anti-fraud security and user experience.

[0075] Figure 5 The flowchart of the third anti-fraud method for a lottery platform based on multi-factor authentication provided in this application embodiment is shown in Figure 5. In S120 above, users are allowed to complete the lottery during the authentication process. At the same time, according to the sorting factors corresponding to multiple users from high to low, lottery probability values ​​are assigned to multiple users from low to high. Multi-factor authentication is performed on multiple users separately, including S230 to S240. S230 to S240 will be described in detail below.

[0076] S230: Obtain the number of times the user accesses the second inventory during the authentication process when the user participates in the lottery.

[0077] Figure 6 A schematic diagram illustrating the workflow of the third multi-factor authentication-based anti-fraud method for lottery platforms provided in this application embodiment is shown below. Figure 6 As shown in this implementation, during the authentication process, users can complete a lottery operation. At the same time, according to the sorting factors corresponding to multiple users from high to low, lottery probability values ​​are assigned to multiple users from low to high. Multi-factor authentication is performed on multiple users. During the lottery process, the second inventory access number of users during the authentication process can be obtained, and the lottery probability can be further adjusted based on the second inventory access number.

[0078] For example, the statistical time period for the number of second inventory visits when a user participates in a lottery can be the time period from the moment the user starts participating in the lottery to the moment the user last participated in the lottery.

[0079] In this implementation, the number of times the second inventory is accessed can reflect the frequency with which users view the lottery inventory during the authentication period. Normal users usually do not frequently access the inventory during the lottery process, while users with abnormal behavior may repeatedly check the inventory status during the authentication process. By monitoring this behavioral indicator, we can better understand the user's real-time participation pattern.

[0080] S240. Determine the range of second inventory access counts corresponding to the second inventory access count, and obtain the second multi-factor authentication request level corresponding to the range of second inventory access counts. Different second multi-factor authentication request levels correspond to different types of second multi-factor authentication requests. Obtain the second lottery probability value corresponding to the second multi-factor authentication request, adjust the user's lottery probability value during the authentication process to the second lottery probability value, and simultaneously perform multi-factor authentication on the user according to the second multi-factor authentication request. Specifically, the larger the range of second inventory access counts, the higher the second multi-factor authentication request level; the more authentication request types corresponding to the second multi-factor authentication request level, the smaller the second lottery probability value.

[0081] In this implementation, the range of the second inventory access count corresponding to the second inventory access count can be determined, and the second multi-factor authentication request level corresponding to the range can be obtained. Different second multi-factor authentication request levels correspond to different types of second multi-factor authentication requests, and users can be authenticated according to the second multi-factor authentication requests in the future.

[0082] For example, a lower range of second inventory accesses can correspond to simpler authentication requirements, while a higher range of accesses can trigger a more complex authentication process. This means that the larger the range of second inventory accesses, the higher the level of the second multifactor authentication request, and the more authentication request types the second multifactor authentication request level corresponds to.

[0083] In this implementation, the second lottery probability value corresponding to the second multi-factor authentication request can be obtained, the lottery probability value of the user in the authentication process can be adjusted to the second lottery probability value, and multi-factor authentication can be performed on the user according to the second multi-factor authentication request.

[0084] When adjusting the probability of winning the lottery, the larger the range of the second inventory access frequency, the higher the level of the second multi-factor authentication request, and the lower the probability value of the second lottery, thereby regulating the behavior of winning the lottery.

[0085] For example, in the automatic anti-fraud scenario of a lottery platform, when it detects that a user frequently accesses the inventory during the authentication process, the authentication level can be automatically upgraded and the user can be required to complete more types of authentication. At the same time, the winning probability can be adjusted accordingly, which can not only ensure the lottery experience of normal users, but also effectively prevent potential fraudulent lottery behavior.

[0086] The beneficial effect of the above implementation method is that the inventory access behavior during the authentication process can reflect the user's real-time participation intention. Normal users usually do not check the inventory frequently after participating in the lottery in advance, while users with the tendency to cheat may repeatedly access the inventory during the authentication period to confirm the result. By capturing this real-time behavior and associating it with the authentication level and probability adjustment, we can not only meet the user's experience needs for participating in the lottery in advance, but also dynamically intercept potential risk behaviors.

[0087] The benefits of the above implementation method are that it allows users to complete the lottery during the authentication process, which greatly reduces the time cost for users to wait for authentication to be completed, improves the smoothness of lottery participation and user experience; by capturing the number of second inventory accesses during the authentication period, it is possible to more accurately identify the user's real-time behavioral characteristics. For potential lottery-farming users with high-frequency inventory access, by increasing the authentication level and reducing the probability value of the second lottery, the ability to prevent dynamic risks is enhanced, and it is effectively prevented that users take advantage of the time difference between "lottery first and authentication later" to farm lottery prizes.

[0088] In some implementations, the method further includes: when both the first and second inventory access counts are greater than a preset inventory access count, authenticating the user using a multi-factor authentication request at the highest level. When either the first or second inventory access count is less than the preset inventory access count, the user's first and second multi-factor authentication request levels are each reduced by a preset level to obtain a third multi-factor authentication request level, and the user is then authenticated using multi-factor authentication requests of multiple authentication request types corresponding to the third multi-factor authentication request level. The higher the third multi-factor authentication request level, the greater the number of authentication request types corresponding to that level.

[0089] In this implementation, the first inventory access count is the number of times the user accesses the inventory before the lottery, and the second inventory access count is the number of times the user accesses the inventory during the lottery phase of authentication. When both the first and second inventory access counts are greater than the preset inventory access count, it indicates that the user may have accessed the inventory a lot before and during the lottery, and the lottery behavior may be a lottery fraud program. Therefore, the user can be authenticated by using the highest level of multi-factor authentication request.

[0090] For example, the preset number of inventory accesses can be set as a reference standard based on historical lottery data. By determining whether the first number of inventory accesses and the second number of inventory accesses are both greater than the preset number of inventory accesses, high-risk users can be identified.

[0091] For example, in the automatic anti-fraud process of a lottery platform, when it is detected that a user frequently accesses the inventory before and during the lottery, the highest level of multi-factor authentication request can be triggered, requiring the user to complete multiple authentication types, thereby effectively blocking potential fraudulent activities.

[0092] In this implementation, when the number of first or second inventory accesses is less than the preset number of inventory accesses, it indicates that although the user accessed the prize inventory before and during the lottery, the number of inventory accesses before or during the lottery was small, and the possibility of the lottery behavior being a prize-grabbing behavior is low. The preset request level of the user's first and second multi-factor authentication request levels can be reduced respectively to obtain a third multi-factor authentication request level, and the user's identity can be verified by multi-factor authentication requests of multiple authentication request types corresponding to the third multi-factor authentication request level.

[0093] In this implementation, the higher the level of the third multi-factor authentication request, the greater the number of authentication request types corresponding to that level.

[0094] For example, the preset request level can be set based on the authentication strength requirement. By reducing the authentication request level, the authentication process can be simplified. The preset request level can be level 1 or level 2.

[0095] For example, in the automatic anti-fraud process of a lottery platform, when a user's number of inventory accesses is low before or during the lottery, the authentication request level can be reduced, and the number of authentication types that need to be completed can be decreased, thereby reducing the operational burden on normal users.

[0096] The beneficial effect of the above implementation method is that by combining the user's inventory access behavior in two key stages, before the lottery and during the lottery authentication, the risk level of the user's lottery fraud can be comprehensively assessed, and dynamic adaptation can be achieved to match high risk with high authentication strength and low risk with low authentication strength, avoiding risk misjudgment or over-authentication caused by single-stage behavior judgment.

[0097] The beneficial effect of the above implementation method is that by combining the judgment of the number of dual inventory accesses, high-risk prize-grabbing users can be more accurately identified. With the strict verification of the highest level of authentication, the identity verification of such users is greatly improved, effectively intercepting the bulk prize-grabbing behavior behind high-frequency inventory access, and further strengthening the anti-fraud capability of the lottery platform.

[0098] The beneficial effects of the above implementation method are that, for low-risk users with a low number of inventory accesses in a single stage, the authentication process is simplified by reducing the authentication request level, avoiding the cumbersome operation problems caused by excessive authentication for normal users, and balancing anti-fraud security with user participation experience. This dynamic authentication adjustment logic based on risk stratification optimizes the original multi-factor authentication application strategy, making the authentication level more consistent with the actual risk characteristics of users, improving the flexibility and accuracy of the anti-fraud mechanism, ensuring the fairness of the lottery activity, and maintaining the participation enthusiasm of most normal users.

[0099] Figure 7 A flowchart illustrating the fourth method for preventing fraudulent activities in a lottery platform based on multi-factor authentication provided in this application is shown below. Figure 7 As shown, the above method also includes S310 to S320, which will be described in detail below.

[0100] S310. Obtain the number of authentication failures and the authentication response time for each user within a preset time period before the lottery. Using an empirical value table, determine the first authentication response factor for each user based on the number of authentication failures and the authentication response time within the preset time period before the lottery. Specifically, the higher the number of authentication failures, the lower the first authentication response factor. Similarly, the higher the authentication response time, the lower the first authentication response factor.

[0101] In this implementation, the number of authentication failures and the authentication response time for each user within a preset time period before the lottery can be obtained. The number of authentication failures and the authentication response time can be collected in real time by the authentication log recording module built into the lottery platform, thereby enabling comprehensive monitoring of user authentication behavior. Obtaining this time-series data helps to understand the dynamic characteristics of user authentication and provides a foundation for subsequent anti-fraud control.

[0102] After obtaining the number of authentication failures and the authentication response time for each user within a preset time period before the lottery, the first authentication response factor for each user can be determined using an empirical value table based on the number of authentication failures and the authentication response time within the preset time period before the lottery.

[0103] For example, the empirical value table can be reasonably determined by statistically analyzing the relationship between the number of authentication failures, authentication response time, and the first authentication response factor before the lottery.

[0104] In this implementation, after determining the first authentication response factor, the first authentication response factor quantifies the degree of abnormality of the user's authentication behavior. Generally, the more times the authentication operation fails and the longer the authentication response time, the higher the probability that the authentication operation is a real person's operation. When the number of authentication failures is higher, the first authentication response factor can be lower. When the authentication response time is longer, the first authentication response factor can be lower. These relationships reflect the authenticity characteristics of the user's operation.

[0105] S320. Determine the product of the first inventory access count and the first authentication response factor as the first inventory adjustment access count. Determine the range of the first inventory adjustment access count corresponding to the first inventory adjustment access count, and obtain the first multi-factor authentication request level corresponding to the range of the first inventory adjustment access count. Different first multi-factor authentication request levels correspond to different first multi-factor authentication requests of multiple authentication request types. Perform multi-factor authentication on the user according to the first multi-factor authentication request. Specifically, the larger the numerical range of the first inventory adjustment access count, the higher the first multi-factor authentication request level, and the more authentication request types corresponding to the first multi-factor authentication request level.

[0106] In this implementation, the product of the first inventory access count and the first authentication response factor can be determined as the first adjusted inventory access count. The first adjusted inventory access count combines the inventory access frequency and authentication behavior characteristics, which can more comprehensively evaluate user behavior.

[0107] In this implementation, the range of the first adjustment inventory access count corresponding to the first adjustment inventory access count can be determined, and the first adjustment multi-factor authentication request level corresponding to the range of the first adjustment inventory access count can be obtained. Different first adjustment multi-factor authentication request levels correspond to different first multi-factor authentication requests of multiple authentication request types, and multi-factor authentication is performed on the user according to the first multi-factor authentication request.

[0108] Specifically, the larger the range of the first adjustment of the number of inventory visits, the higher the level of the first adjustment of the multi-factor authentication request, and the more authentication request types corresponding to the first adjustment of the multi-factor authentication request level. This hierarchical mechanism can dynamically adjust the authentication strength according to the risk level of user behavior.

[0109] For example, in the automatic anti-fraud process of a lottery platform, when a user's authentication failure count is high or the authentication response time is long, the first authentication response factor can be reduced, thereby reducing the number of first adjustment inventory accesses and ultimately reducing the types of authentication requests required, thus optimizing the authentication experience for real users.

[0110] The beneficial effects of the above implementation method are that by incorporating the number of authentication failures and response time before the lottery into the evaluation, the higher the number of authentication failures and response time, the closer the user's operation behavior is to real operation. It can dynamically identify low-frequency but abnormally accurate multi-factor authentication or high-frequency and abnormally accurate multi-factor authentication lottery fraud behavior. It retains the restriction on script-based lottery fraud and program-controlled lottery fraud with high-frequency inventory access, and can avoid misjudgment caused by a single dimension. The platform can significantly improve the identification accuracy of potential lottery fraudsters, optimize the authentication experience of real users, reduce the consumption of lottery resources, and make the overall anti-fraud effect more robust and accurate.

[0111] The beneficial effect of the above implementation method is that the higher the number of authentication failures and response time before the lottery, the closer the user's operation behavior is to real human operation. By reducing the authentication types of users who are closer to real human operation, the user experience of lottery operation behavior of real human operation is improved.

[0112] Figure 8 A flowchart illustrating the fifth method for preventing fraudulent activities in a lottery platform based on multi-factor authentication provided in this application is shown below. Figure 8 As shown, the above method also includes S330 to S340, which will be described in detail below.

[0113] S330. Obtain the number of authentication failures and the authentication response time when a user participates in the lottery during the authentication process. Using an empirical value table, determine the second authentication response factor for each user based on the number of authentication failures and the authentication response time during the lottery. Specifically, the higher the number of authentication failures, the lower the second authentication response factor. Similarly, the higher the authentication response time, the lower the second authentication response factor.

[0114] During the lottery process, the number of authentication failures and the authentication response time of users can also be obtained. The number of authentication failures reflects the cumulative number of authentication attempts that failed during the lottery process, and the authentication response time can represent the length of time required for users to complete authentication. These data can be recorded and collected in real time through the lottery platform's backend system, thereby enabling comprehensive monitoring of user behavior.

[0115] By using the empirical value table, the number of authentication failures and the authentication response time can be obtained. Based on these two parameters, the second authentication response factor for each user can be determined. The higher the number of authentication failures, the lower the second authentication response factor; the higher the authentication response time, the lower the second authentication response factor. This relationship setting takes into account the degree of influence of the number of authentication failures and the authentication response time on the authenticity of user behavior.

[0116] For example, the empirical value table can be reasonably determined by statistically analyzing the relationship between the number of authentication failures during the lottery, the authentication response time, and the second authentication response factor.

[0117] S340. Determine the product of the second inventory access count and the second authentication response factor as the second adjusted inventory access count. Determine the range of the second adjusted inventory access count corresponding to the second adjusted inventory access count, and obtain the second adjusted multi-factor authentication request level corresponding to the range of the second adjusted inventory access count. Different second adjusted multi-factor authentication request levels correspond to different types of second multi-factor authentication requests. Obtain the second adjusted lottery probability value corresponding to the second multi-factor authentication request, adjust the user's lottery probability value during the authentication process to the second adjusted lottery probability value, and simultaneously perform multi-factor authentication on the user according to the second adjusted multi-factor authentication request. Wherein, the larger the range of the second adjusted inventory access count, the higher the second adjusted multi-factor authentication request level; the more authentication request types corresponding to the second adjusted multi-factor authentication request level, the smaller the second adjusted lottery probability value.

[0118] After determining the second authentication response factor, the product of the second inventory access count and the second authentication response factor can be calculated. This product is used as the second adjusted inventory access count, thereby integrating the user's inventory access behavior characteristics and authentication response characteristics to form a more comprehensive user behavior evaluation index.

[0119] After obtaining the second adjustment inventory access count, the range of the second adjustment inventory access count corresponding to the second adjustment inventory access count can be determined, and the second adjustment multi-factor authentication request level corresponding to the range can be obtained. Different second adjustment multi-factor authentication request levels correspond to different types of second multi-factor authentication requests, and users can be subsequently authenticated according to the second adjustment multi-factor authentication request.

[0120] In this implementation, the larger the numerical range of the second adjustment of the inventory access frequency range, the higher the level of the second adjustment multi-factor authentication request, and the more corresponding authentication request types there are, so that multiple authentication request types can perform different levels of authentication according to the user type.

[0121] For example, the second adjustment to the multi-factor authentication request level can include multiple levels, each corresponding to a different combination of authentication types, such as a combination of multiple authentication methods such as SMS verification, facial recognition, and fingerprint verification.

[0122] In this implementation, after obtaining the second adjusted lottery probability value corresponding to the second multi-factor authentication request, the lottery probability value of the user in the authentication process can be adjusted to this second adjusted lottery probability value. At the same time, the larger the range of the second adjusted inventory access times, the higher the level of the second adjusted multi-factor authentication request, and the smaller the second adjusted lottery probability value.

[0123] For example, when a user's number of second adjustment inventory accesses is high, the corresponding second adjustment multi-factor authentication request level is higher, requiring the user to complete more types of authentication. However, at the same time, the user's lottery probability value is reduced accordingly. This ensures both security and the user experience when drawing prizes with real people.

[0124] The beneficial effects of the above implementation method are that by incorporating the number of authentication failures and response time during the lottery process into the evaluation, the higher the number of authentication failures and response time, the closer the user's operation behavior is to real human operation. It can dynamically identify low-frequency but abnormally accurate multi-factor authentication or high-frequency and abnormally accurate multi-factor authentication fraudulent behavior. It retains the restrictions on script-based and program-controlled fraudulent behavior that accesses high-frequency inventory, avoids misjudgments caused by a single dimension, significantly improves the platform's identification accuracy of potential fraudsters, optimizes the authentication experience of real users, reduces lottery resource consumption, and makes the overall anti-fraud effect more robust and accurate.

[0125] The beneficial effect of the above implementation method is that the higher the number of authentication failures and response time during the lottery process, the closer the user's operation behavior is to real human operation. By reducing the authentication types of users who are closer to real human operation, the user experience of lottery operation behavior of real human operation is improved.

[0126] The beneficial effect of the above implementation method is that it can dynamically adjust the probability value of users in the lottery, and improve the probability of winning the lottery corresponding to the real user lottery behavior obtained by taking the number of authentication failures and response time into the evaluation judgment, thereby improving the probability of winning the lottery in the authentication of real people.

[0127] In some implementations, the above method also includes S510 to S520, which are described in detail below.

[0128] S510. Using the experience value table, determine the authentication weight value corresponding to each authentication request type of the multi-factor authentication request based on the number of second inventory accesses, the number of authentication failures, and the authentication response time during the lottery.

[0129] In this implementation, the authentication weight value corresponding to each authentication request type of the multi-factor authentication request can be determined by using an empirical value table based on the number of second inventory accesses, the number of authentication failures, and the authentication response time during the lottery.

[0130] For example, the experience value table can be pre-set based on historical lottery activity data. The experience value table stores the weight values ​​of different authentication request types corresponding to different ranges of second inventory access times, authentication failure times, and authentication response time.

[0131] For example, an empirical value table can be used to dynamically adjust the weight values ​​of different authentication request types, such as SMS verification, facial recognition, and device fingerprint, based on the number of times the second inventory is accessed during the lottery, the number of authentication failures, and the authentication response time, so that certain authentication types have higher weights in high-risk scenarios.

[0132] For example, using an empirical value table, when the number of second inventory accesses, the number of authentication failures, or the authentication response time increases, the probability that a user may be engaging in prize-grabbing behavior is higher. The authentication weight value corresponding to each authentication request type of the multi-factor authentication request can be increased to improve the ranking factor of the multi-factor authentication request for each user.

[0133] S520. Determine the sum of the products of the authentication contribution and authentication weight values ​​corresponding to all authentication request types for each multi-factor authentication request, and use this as the ranking factor for each user's multi-factor authentication request. During the authentication process, allow users to participate in a lottery, and assign lottery probability values ​​to multiple users in descending order of their respective ranking factors, while simultaneously performing multi-factor authentication on each user. After authentication, assign normal lottery probability values ​​to users who pass multi-factor authentication.

[0134] In this implementation, the sum of the products of the authentication contribution and authentication weight values ​​of all authentication request types passed by each multi-factor authentication request user can be determined as the ranking factor for each user's multi-factor authentication request. By multiplying and summing the authentication contribution and authentication weight values ​​of all authentication request types passed by the user, the user's authentication risk and authentication strength can be comprehensively evaluated, and a quantitative ranking factor can be generated for subsequent processing.

[0135] In this implementation, users are allowed to participate in a lottery during the authentication process. Multiple users are assigned lottery probability values ​​from low to high according to their respective ranking factors, and multi-factor authentication is performed on each user. Users with higher ranking factors face higher risks or abnormal behavior, so they can be assigned lower lottery probability values ​​and are prioritized for multi-factor authentication to identify and handle potential risk users as early as possible. Normal users with lower ranking factors receive higher lottery probability values ​​and are processed later in the authentication queue.

[0136] After authentication is completed, users who pass multi-factor authentication are assigned a normal lottery probability value. Authentication demonstrates the legitimacy of their identity and behavior, so normal lottery probability values ​​can be restored or assigned to them to ensure that these users can participate in the lottery fairly. Users who fail authentication can be restricted or excluded from the lottery, further ensuring the platform's security.

[0137] The beneficial effects of the above implementation method are that by correlating the number of second inventory accesses, the number of authentication failures, the authentication response time, and the weight of each authentication type, and combining this with the authentication contribution to calculate the ranking factor, it can more accurately reflect each user's risk characteristics and true authentication capabilities in different authentication dimensions. This makes the determination of the ranking factor more closely aligned with the user's actual situation, thereby making the allocation of authentication order and lottery probability more precise. High-risk users will be given a lower lottery probability due to their high ranking factor and will be given priority in authentication, effectively improving the targeting and accuracy of the anti-fraud mechanism, while protecting the legitimate rights and interests of normal users, and further maintaining the fairness of the lottery activity and the security of the platform.

[0138] In some implementations, the above method also includes S610 to S620, which will be described in detail below.

[0139] S610. When allowing a user to complete a lottery during the authentication process, obtain the user's winning status during the authentication process.

[0140] When allowing users to participate in a lottery during the authentication process, the system can obtain the user's winning status during the authentication process. The winning status can reflect the user's winning situation in the lottery activity. By monitoring the winning status, user groups that need further verification can be identified.

[0141] S620. When a user's winning status is "Winner," the authentication time limit for the user is determined using an empirical value table based on the number of second inventory accesses, authentication failures, and authentication response time at the time of the draw. Within the authentication time limit, the user's multi-factor authentication result is obtained. If the user passes multi-factor authentication within the authentication time limit, the winning prize is awarded to the user. If the user fails multi-factor authentication within the authentication time limit, the winning prize is not awarded to the user.

[0142] In this implementation, when a user wins a prize, the authentication time limit can be determined using an empirical value table based on the number of second inventory accesses, authentication failures, and authentication response times during the lottery. Within this time limit, the user's multi-factor authentication result can be obtained. Multi-factor authentication can include a combination of various authentication methods such as SMS verification codes, facial recognition, and fingerprint verification, improving the reliability of verification through a multi-layered authentication mechanism.

[0143] For example, the experience value table can be a query table manually determined based on historical data. The experience value table stores the authentication limit duration values ​​corresponding to different combinations of second inventory access times, authentication failure times, and authentication response times.

[0144] For example, the higher the number of accesses to the second inventory, the more authentication failures, or the longer the authentication response time, the higher the probability that the user is engaging in prize-grabbing behavior. In this case, the shorter the authentication restriction time for the user, the more restrictive the prize-grabbing behavior will be. Conversely, the lower the number of accesses to the second inventory, the more authentication failures, or the longer the authentication response time, the lower the probability that the user is engaging in prize-grabbing behavior. In this case, the longer the authentication restriction time for the user, the more secure the rights of the user in the normal prize draw.

[0145] In this implementation, when a user passes multi-factor authentication within the authentication time limit, a prize can be awarded to the user. The prize awarding process can be completed after authentication is successful by calling the prize awarding interface.

[0146] In this implementation, if a user fails to pass multi-factor authentication within the authentication time limit, the prize will not be issued to the user. After the authentication timeout, the prize issuance channel can be automatically closed to ensure that users who fail to pass authentication cannot receive prizes.

[0147] For example, in a lottery event on an e-commerce platform, when a user is detected as a winner, an appropriate authentication time limit can be calculated based on the user's historical access behavior data and an empirical value table. Within this time limit, the user needs to complete both SMS verification and facial recognition authentication. Only after passing the authentication can the user receive prizes such as coupons.

[0148] The beneficial effect of the above implementation method is that, for users who have won prizes but may be abnormal, there is a lack of effective subsequent verification constraints. After a user wins a prize, by introducing an authentication time limit and binding the prize distribution to the authentication results within that time limit, a closed-loop control mechanism of winning, time-limited authentication, and prize distribution is formed. This ensures that even if an abnormal user wins a prize by chance, they must pass multi-factor authentication within a limited time to receive the prize. This effectively intercepts users who rely on automated tools to cheat for prizes and cannot complete the real authentication within the time limit, further compressing the space for cheating for prizes, strengthening the integrity and effectiveness of the anti-cheating mechanism, and at the same time protecting the rights of real users to obtain prizes after completing authentication within a reasonable time. This more effectively maintains the fairness of the lottery activity and the operational order of the platform.

[0149] This application also provides a multi-factor authentication-based lottery platform anti-cheating system, including a unit for performing the method described in any of the preceding claims.

[0150] Figure 9 A schematic diagram of the logical structure of a lottery platform anti-fraud system based on multi-factor authentication provided in this application embodiment is shown below. Figure 9As shown, the system 1 of this embodiment includes a processing unit 11, a storage unit 12, and a transceiver unit 13. The processing unit 11 is used to process data, the storage unit 12 is used to store data, and the transceiver unit 13 is used to send and receive data. The processing unit 11, the storage unit 12, and the transceiver unit 13 cooperate with each other to implement the above-described method. The beneficial effects of the embodiments of this application have been described in the above-described method and will not be repeated here.

[0151] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.

[0152] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0153] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a photographing device / terminal device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunication signals.

[0154] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0155] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0156] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0157] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0158] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A method for preventing fraudulent activities on a lottery platform based on multi-factor authentication, characterized in that, The method includes: Retrieve multiple incomplete multi-factor authentication requests from users during the lottery draw, and obtain multiple authentication request types for each multi-factor authentication request; among which, the authentication request types include device identification authentication, security question authentication, SMS verification code authentication, password authentication, fingerprint authentication, and facial recognition authentication; Based on the authentication results of multiple authentication request types for multi-factor authentication requests, determine the ranking factor for each user's multi-factor authentication request; during the authentication process, allow users to complete a lottery, and assign lottery probability values ​​to multiple users from low to high according to the ranking factors corresponding to the multiple users from high to low, while performing multi-factor authentication on multiple users separately; after authentication is completed, assign normal lottery probability values ​​to users who pass multi-factor authentication.

2. The method as described in claim 1, characterized in that, Based on the authentication results of multiple authentication request types in the multi-factor authentication request, determine the ranking factor for each user's corresponding multi-factor authentication request, including: Obtain the authentication contribution and authentication weight values ​​for each authentication request type in a multi-factor authentication request. The authentication contribution represents the contribution to verifying the user's identity, and the authentication weight value represents the importance of the authentication request type in user identity authentication. The sum of the products of the authentication contribution and authentication weight values ​​of all authentication request types that have passed authentication in each multi-factor authentication request is determined as the ranking factor for the multi-factor authentication requests corresponding to each user.

3. The method as described in claim 2, characterized in that, The method further includes: Get the first number of times each user accesses the prize inventory within a preset time period before the lottery; Determine the range of first inventory access counts corresponding to the first inventory access count, and obtain the first multi-factor authentication request level corresponding to the range of first inventory access counts. Different first multi-factor authentication request levels correspond to different first multi-factor authentication requests of multiple authentication request types. Perform multi-factor authentication on the user according to the first multi-factor authentication request. Among them, the larger the numerical range of the first inventory access count, the higher the first multi-factor authentication request level, and the more authentication request types corresponding to the first multi-factor authentication request level.

4. The method as described in claim 3, characterized in that, During the authentication process, users are allowed to participate in a lottery. Based on a ranking factor from highest to lowest, multiple users are assigned lottery probability values ​​from lowest to highest. Furthermore, multi-factor authentication is performed on each user, including: Get the number of times a user accesses the second inventory during the user's lottery draw during the authentication process; Determine the range of second inventory access counts corresponding to the second inventory access count, and obtain the second multi-factor authentication request level corresponding to the range of second inventory access counts. Different second multi-factor authentication request levels correspond to different types of second multi-factor authentication requests. Obtain the second lottery probability value corresponding to the second multi-factor authentication request, adjust the user's lottery probability value during the authentication process to the second lottery probability value, and perform multi-factor authentication on the user according to the second multi-factor authentication request. Among these, the larger the range of second inventory access counts, the higher the second multi-factor authentication request level, the more types of authentication requests corresponding to the second multi-factor authentication request level, and the smaller the second lottery probability value.

5. The method as described in claim 4, characterized in that, The method further includes: When both the first and second inventory access counts exceed the preset inventory access count, the user is authenticated using a multi-factor authentication request at the highest level. When either the first or second inventory access count is less than the preset inventory access count, the user's first and second multi-factor authentication request levels are reduced by the preset request level to obtain a third multi-factor authentication request level. The user is then authenticated using multi-factor authentication requests of multiple authentication request types corresponding to the third multi-factor authentication request level. The higher the third multi-factor authentication request level, the greater the number of authentication request types corresponding to that level.

6. The method as described in claim 5, characterized in that, The method further includes: Obtain the number of authentication failures and the authentication response time for each user within a preset time period before the lottery; determine the first authentication response factor for each user based on the number of authentication failures and the authentication response time within the preset time period before the lottery using an experience value table; where the higher the number of authentication failures, the lower the first authentication response factor; and the higher the authentication response time, the lower the first authentication response factor. The product of the first inventory access count and the first authentication response factor is determined as the first inventory adjustment access count. The range of the first inventory adjustment access count is determined, and the first multi-factor authentication request level corresponding to the range of the first inventory adjustment access count is obtained. Different first multi-factor authentication request levels correspond to different first multi-factor authentication requests of multiple authentication request types. Multi-factor authentication is performed on the user according to the first multi-factor authentication request. The larger the range of the first inventory adjustment access count, the larger the first multi-factor authentication request level, and the more authentication request types corresponding to the first multi-factor authentication request level.

7. The method as described in claim 6, characterized in that, The method further includes: The system obtains the number of authentication failures and the authentication response time when a user participates in a lottery during the authentication process. Based on the experience value table, the system determines the second authentication response factor for each user according to the number of authentication failures and the authentication response time during the lottery. Specifically, the higher the number of authentication failures, the lower the second authentication response factor; and the higher the authentication response time, the lower the second authentication response factor. The product of the second inventory access count and the second authentication response factor is determined as the second adjusted inventory access count. The range of the second adjusted inventory access count is determined, and the second adjusted multi-factor authentication request level corresponding to this range is obtained. Different second adjusted multi-factor authentication request levels correspond to different types of second multi-factor authentication requests. The second adjusted lottery probability value corresponding to the second multi-factor authentication request is obtained, and the user's lottery probability value during the authentication process is adjusted to the second adjusted lottery probability value. Simultaneously, multi-factor authentication is performed on the user according to the second adjusted multi-factor authentication request. Specifically, the larger the range of the second adjusted inventory access count, the higher the second adjusted multi-factor authentication request level; the more authentication request types corresponding to the second adjusted multi-factor authentication request level, the smaller the second adjusted lottery probability value.

8. The method as described in claim 7, characterized in that, The method further includes: Using an empirical value table, the authentication weight value corresponding to each authentication request type of the multi-factor authentication request is determined based on the number of second inventory accesses, the number of authentication failures, and the authentication response time during the lottery. The sum of the products of the authentication contribution and authentication weight values ​​corresponding to all authentication request types for each multi-factor authentication request is determined and used as the ranking factor for each user's multi-factor authentication request. During the authentication process, users are allowed to participate in a lottery, and lottery probability values ​​are assigned to multiple users from low to high according to the ranking factors corresponding to them, while multi-factor authentication is performed on multiple users separately. After authentication is completed, users who pass multi-factor authentication are assigned normal lottery probability values.

9. The method as described in claim 8, characterized in that, The method further includes: When allowing users to participate in the lottery during the authentication process, obtain the user's winning status during the authentication process; When a user wins a prize, the authentication time limit is determined based on the number of second inventory accesses, authentication failures, and authentication response time during the draw, using an empirical value table. Within the authentication time limit, the user's multi-factor authentication result is obtained. If the user passes multi-factor authentication within the authentication time limit, the prize is awarded to the user. If the user fails multi-factor authentication within the authentication time limit, the prize is not awarded to the user.

10. A lottery platform anti-fraud system based on multi-factor authentication, characterized in that, Includes a unit for performing the method according to any one of claims 1 to 9.