Identity authentication method and device based on fingerprint identification and identity identification, and medium

By dynamically tracking user behavior and calculating confidence levels in the carbon trading platform, the cumbersome dynamic tracking and secondary verification of user identity authentication in the carbon trading platform is solved, achieving a balance between security and convenience, reducing the risk of corporate asset loss and improving user experience.

CN121167701AActive Publication Date: 2025-12-19NATIONAL ENERGY ADMINISTRATION INFORMATION CENTER
View PDF 16 Cites 0 Cited by

Patent Information

Application Number
CN202511318456.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-16
Publication Date
2025-12-19
Estimated Expiration
2045-09-16

AI Technical Summary

Technical Problem

The existing identity authentication technology of carbon trading platforms has the problem of lacking dynamic tracking and verification of user behavior after login, which makes it possible for unauthorized accounts to execute high-risk transactions or tamper with data, and the secondary verification process is cumbersome.

Method used

By dynamically tracking user actions after login, obtaining and comparing feature vectors, calculating the user's confidence level, and triggering fingerprint verification only when the confidence level is insufficient, the system avoids frequent secondary verification.

Benefits of technology

It enables continuous verification of user identity, reduces the risk of corporate carbon asset loss, simplifies operation processes, balances security and convenience, and improves user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121167701A_ABST
    Figure CN121167701A_ABST
Patent Text Reader

Abstract

The invention provides an identity authentication method and device based on fingerprint identification and identity identification, and a medium, and relates to the technical field of identity authentication, and the method comprises the steps: obtaining the type of a current operation behavior; if the type of the current operation behavior is a preset second operation type, obtaining operation behavior data of a page of each operation within a time range from the time after the target user logs in the target platform to the current time point; obtaining a to-be-verified behavior feature vector corresponding to the page of each operation; obtaining the maximum similarity; determining a personal operation confidence degree theta corresponding to the target user; determining whether to trigger a preset fingerprint verification task according to theta; if the fingerprint verification of the target user is passed, executing the current operation behavior of the target user; otherwise, executing the preset security task; according to the method, the verification frequency of legal users can be reduced and the operation process can be simplified while the high-risk operation safety is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of identity authentication, in particular to an identity authentication method and device based on fingerprint recognition and identity identification, and a medium. BACKGROUND

[0002] In the operation of a carbon trading platform, enterprise users need to carry out key operations such as carbon quota transfer, emission data declaration, and transaction contract confirmation. Such operations are directly related to the security of enterprise carbon assets, the fairness of carbon market transactions, and the effective implementation of national carbon reduction policies. Therefore, continuous and accurate authentication of user identity is a core requirement for ensuring the safe operation of the platform.

[0003] However, the existing carbon trading platform identity authentication technology has significant defects. On the one hand, traditional authentication modes are mostly focused on the initial login stage, and identity verification is completed only through static passwords or single biometric recognition (such as initial fingerprint verification). There is a lack of dynamic tracking and verification of user subsequent operation behavior after login. If the account is illegally stolen after login, the illegal operator can still perform high-risk transactions or data tampering operations, causing loss of enterprise carbon assets and disorder of platform transaction order. On the other hand, some carbon trading platforms set up secondary verification for key operations in order to improve security, such as fingerprint verification. Although security has been improved, users need to frequently perform secondary verification, and the operation process is relatively cumbersome. Therefore, how to simplify the user's operation process while ensuring security has become a technical problem to be solved. SUMMARY

[0004] To solve the above technical problems, the technical solution adopted by the present application is as follows:

[0005] According to a first aspect of the present application, a method for identity authentication based on fingerprint recognition and identity identification is provided, which comprises the following steps:

[0006] S100, in response to the current operation behavior of a target user after logging into a target platform, the type of the current operation behavior is obtained. The target platform includes a plurality of pages. Each page corresponds to a plurality of preset standard operation behavior feature vectors and a preset basic weight. The basic weight is obtained through historical operation behavior data of a plurality of historical users on the corresponding page;

[0007] S200, if the type of the current operation behavior is a preset second operation type, the operation behavior data of the target user on each operation page within a time range from logging into the target platform to the current time point is obtained;

[0008] S300, the operation behavior data of the target user on each operation page from logging into the target platform to the current time point is subjected to feature extraction to obtain a to-be-verified behavior feature vector corresponding to each operation page;

[0009] S400, obtaining a maximum similarity between each to-be-verified behavior feature vector and each standard operation behavior feature vector of the corresponding page;

[0010] S500, determining a self-operation confidence degree θ of the target user according to the maximum similarity corresponding to each to-be-verified behavior feature vector and the basic weight of the corresponding page;

[0011] S600, if θ ≥ QR, not triggering a preset fingerprint verification task; otherwise, triggering the fingerprint verification task; wherein QR is a preset self-operation confidence degree threshold;

[0012] S700, if the fingerprint verification of the target user is passed, performing a current operation behavior of the target user; otherwise, performing a preset security task.

[0013] According to another aspect of the present application, a non-transitory computer readable storage medium is also provided, the storage medium storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by a processor to implement the above-mentioned identity authentication method based on fingerprint identification and identity identification.

[0014] According to another aspect of the present application, an electronic device is also provided, comprising a processor and the above-mentioned non-transitory computer readable storage medium.

[0015] The present application has at least the following beneficial effects:

[0016] The identity authentication method based on fingerprint identification and identity identification of the present application, on the one hand, by dynamically tracking the behavior data of the user on each operation page and performing feature comparison for a specific operation type after the user logs in, realizes the continuous verification of the user identity, instead of relying only on the static authentication of the initial login link, can identify abnormal operations after the account is stolen in time, reduces the loss risk of enterprise carbon assets, and maintains the transaction order of the platform; on the other hand, by calculating the self-operation confidence degree and comparing it with the threshold, only when the confidence degree is insufficient, the fingerprint verification is triggered, avoiding the cumbersome process of forcibly performing secondary verification on all key operations, ensuring the safety of high-risk operations while reducing the verification frequency of the legal user and simplifying the operation process, thereby effectively balancing the safety of the carbon trading platform and the convenience of user operation, ensuring the safe operation of the platform while improving the user experience. BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0018] Figure 1 A flowchart of the identity authentication method based on fingerprint recognition and identity identification provided by the embodiment of the present application is shown. DETAILED DESCRIPTION

[0019] The technical solutions in the embodiments of the present application will be clearly and completely described with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person skilled in the art without creative work are within the protection scope of the present application.

[0020] It should be noted that, based on the present disclosure, a person skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, an apparatus and / or a method can be implemented using any number of the aspects set forth herein. In addition, this apparatus and / or method can be implemented using other structures and / or functionality in addition to or other than one or more of the aspects set forth herein.

[0021] The technical solutions in the embodiments of the present application will be clearly and completely described with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person skilled in the art without creative work are within the protection scope of the present application. Figure 1 A flowchart of the identity authentication method based on fingerprint recognition and identity identification provided by the embodiment of the present application is shown.

[0022] The identity authentication method based on fingerprint recognition and identity identification can include the following steps:

[0023] S100, in response to a current operation behavior of a target user after logging in a target platform, a type of the current operation behavior is obtained; the target platform includes a plurality of pages; each page corresponds to a plurality of preset standard operation behavior feature vectors and a preset basic weight; the basic weight is obtained through historical operation behavior data of a plurality of historical users on the corresponding page.

[0024] The application scenario of the method of the present embodiment can be a carbon trading scenario, and the target platform is a carbon trading platform. After a target user logs in the carbon trading platform, the platform background monitors the interactive behavior of the user in real time (such as clicking a button, submitting a form, entering a specific page, etc.), determines the type of the current operation behavior by analyzing the interface call, page URL or button identifier (such as a “confirm transfer” button and a “submit emission data” form) of the user operation.

[0025] In the carbon trading platform, the operation types are generally divided into two categories: the first operation type (low risk): such as querying the enterprise carbon quota balance, browsing historical transaction records, viewing policy notifications, etc.; the second operation type (high risk): such as initiating carbon quota transfer, submitting annual emission data, confirming transaction contracts, etc. (such operations directly affect carbon assets or data validity).

[0026] At the same time, the platform pre-configures standard operation behavior feature vectors (based on historical normal user behavior) and basic weights (high-risk page weights are higher, such as "quota transfer page" weight 0.5, "query page" weight 0.1) for each page (such as "quota transfer page", "emission data submission page", "transaction record query page").

[0027] Further, the standard operation behavior feature vector corresponding to each page can be obtained by the following steps:

[0028] S110, dividing a preset historical time period into a plurality of sub-historical time periods with the same length to obtain a sub-historical time period list T=(T1, T2, …, T i , …, T n ), i=1, 2, …, n; wherein T i is the i-th sub-historical time period obtained by dividing the preset historical time period, and n is the number of sub-historical time periods obtained by dividing the preset historical time period.

[0029] First, a "preset historical time period" (such as the past 1 year) is determined, and then it is evenly divided into a plurality of "sub-historical time periods" (such as divided into 12 sub-time periods by month or divided into 4 sub-time periods by quarter) with the same length, forming a sub-historical time period list T. The core purpose of division is to capture the potential changes in user operation behavior in different time periods (such as the user operation habits of the carbon trading platform may be different in the "quota reporting period" at the beginning of the month and the "transaction peak period" at the end of the month).

[0030] Example: The carbon trading platform divides "the past 1 year" (January 2023-December 2023) into 12 monthly sub-time periods, i.e. T=(T1=January, T2=February, …, T 12 =December), n=12.

[0031] Through time segmentation, the "behavior pattern out-of-date" problem caused by directly using historical data with too long span (such as user operation habits changing with platform function updates or business cycle changes) is avoided, ensuring that the subsequent feature vector can reflect the typical operation mode in recent period.

[0032] S111, for any page YM, obtain the standard user operation behavior feature vector corresponding to YM in each sub-history time period in T, to obtain the standard user operation behavior feature vector list set A=(A1, A2, …, A i , …, A n ) corresponding to T; wherein A i is the standard user operation behavior feature vector list corresponding to T i ; A i =(A i,1 , A i,2 , …, A i,j , …, A i,f(i) ), j=1, 2, …, f(i); A i,j is the jth standard user operation behavior feature vector corresponding to YM in T i , and f(i) is the number of standard user operation behavior feature vectors corresponding to YM in T i .

[0033] For any page YM (such as “Carbon Quota Transfer Confirmation Page”, “Annual Emission Data Declaration Page”) of the carbon trading platform, in each sub-time period T i , collect the operation behavior data of standard users (i.e. authenticated legal users, excluding abnormal accounts or malicious operation users) on the page, convert the features into feature vectors after extracting the features, form the vector list A i corresponding to each T i , and finally summarize the list set A.

[0034] Among them, “standard user operation behavior features” need to be defined in combination with page functions, for example:

[0035] The feature dimensions of “Carbon Quota Transfer Confirmation Page” are: [page dwell time (seconds), number of clicks to check transaction amount, number of times to modify quota amount before submission, operation period (morning / afternoon)];

[0036] The feature dimensions of “Annual Emission Data Declaration Page” are: [single data input time (seconds), number of times to correct verification errors, frequency of saving drafts, page scrolling speed (pixels / second)].

[0037] Example: Taking the page YM=“Carbon Quota Transfer Confirmation Page” as an example, 200 legal user operation data is collected in T1 (January), and after extracting the features, A1=(A 1,1 , A 1,2 , …, A 1,200 ) is formed, wherein A 1,1 =[180, 3, 0, 1] (stay for 180 seconds, click to check 3 times, no quota modification, operate in the morning); 180 user data is collected in T2 (February), and A2=(A2,1 ,…,A 2,180 ), and finally we get A.

[0038] By focusing on the behavioral data of "standard users," the "legitimacy" of the original vector is ensured; classification by sub-time periods preserves the temporal attributes of the behavior, providing a foundation for subsequent capture of periodic behavioral patterns (such as operational differences between peak and off-peak seasons).

[0039] S112, use a preset clustering algorithm to cluster the standard user operation behavior feature vectors in A to obtain a cluster list B = (B1, B2, ..., B...). p B q ), p = 1, 2, ..., q; where, B p To obtain the p-th cluster through clustering, q represents the number of clusters obtained through clustering.

[0040] Use a pre-defined clustering algorithm (such as DBSCAN) to analyze the feature vectors of all sub-time periods (i.e., A1 to A2) in list set A. n Clustering is performed on all vectors in YM; vectors with similar features are grouped into the same "cluster", resulting in a list B composed of several clusters. The core of clustering is to identify the "typical operation mode" of page YM (such as different legal operation modes such as "quick confirmation" and "careful verification" on the same page).

[0041] When using DBSCAN to cluster the standard user behavior feature vectors in A, the cluster radius can be set to be smaller to improve the clustering accuracy and thus identify more types of users.

[0042] By automatically identifying various typical operation modes on the page through clustering, we can avoid the "singularity bias" caused by manually defined standards (such as using only one "normal behavior" standard, which may exclude other legitimate modes), making subsequent verification more in line with actual user habits.

[0043] S113, iterate through B, if B p The number of standard user action behavior feature vectors within NUM p ≥NUM YM Then B p Identified as the target cluster; NUM YM This is the threshold for the number of vectors within the cluster corresponding to YM.

[0044] Iterate through the cluster list B and calculate the value of each cluster B. p The number of vectors within NUM p Only NUM is retained. p ≥NUM YM Clusters with a threshold of (the number of vectors within a cluster in page YM) are designated as "target clusters". YMThe setting needs to be combined with the total data amount of the page (such as 5%-15% of the total number of vectors), and the core is to exclude "marginal clusters" with too small sample size (which may be noise or special behavior of a small number of users, and do not have universal representativeness).

[0045] Example: The total number of vectors of the "carbon quota transfer confirmation page" is 2200, NUM YM 5% of the total number (i.e. 110). After clustering: B1 contains 1000 vectors (NUM1=1000≥110)→target cluster; B2 contains 800 vectors (NUM2=800≥110)→target cluster; B3 contains 400 vectors (NUM3=400≥110)→target cluster; (if a cluster contains only 5 vectors, it is excluded).

[0046] Through the number threshold screening, it is ensured that the target cluster contains enough samples to represent the mainstream operation mode of the page, avoiding verification deviation caused by including "small behavior" or "noise data" into the standard (such as misjudging the normal behavior of most users as abnormal).

[0047] Further, in the carbon trading platform scenario, for high-risk pages (such as carbon quota transfer confirmation page), NUM YM (10%-20% of the total number) can be appropriately increased to strictly screen more universal normal operation characteristics; for low-risk pages (such as transaction record query page), NUM YM (3%-8% of the total number) can be reduced to retain more diversified normal operation modes under the premise of ensuring basic representativeness.

[0048] S114, determines the center vector corresponding to each target cluster as the standard operation behavior feature vector corresponding to YM.

[0049] For each target cluster, calculate its "center vector" (i.e. the mean or median vector of all vectors in the cluster, representing the typical characteristics of the cluster), and finally these center vectors are used as the "standard operation behavior feature vector" of the page YM.

[0050] The center vector condenses the typical characteristics of the target cluster, and serves as the "benchmark" for subsequent verification, which not only retains multiple legal operation modes of the page (avoiding a single standard), but also ensures the objectivity and calculability of verification through the quantitative vector form, laying a foundation for accurately judging whether the user behavior is normal.

[0051] In summary, S110-S114 generate the standard operation behavior feature vector through the logic of "time segmentation-feature extraction-cluster analysis-screening optimization-center vector extraction", which can dynamically reflect the mainstream legal operation mode of different pages of the carbon trading platform, adapt to the behavior changes in the time dimension, and accommodate the diversified operation habits of users, providing a core basis for the accuracy and flexibility of subsequent identity authentication.

[0052] Further, the basic weight corresponding to each page is obtained by the following steps:

[0053] S120, the number of target clusters corresponding to each page, the number of standard user operation behavior feature vectors in the target cluster, and the total number of standard user operation behavior feature vectors are obtained, and a number group list η = (η1, η2, …, ηy) corresponding to each page is obtained. x , …, η y ), x = 1, 2, …, y; wherein η x is the number group corresponding to the xth page, y is the number of pages corresponding to the target platform; η x = (α x , λ x , γ x ); α x , λ x and γ x are the number of target clusters corresponding to the xth page, the number of standard user operation behavior feature vectors in the target cluster, and the total number of standard user operation behavior feature vectors, respectively.

[0054] α x (the number of target clusters of the xth page): that is, the "total number of target clusters meeting the NUM YM threshold" screened out in S113 (reflecting the "concentration degree" of the legal operation mode of the page - the smaller α x , the more uniform the user operation mode; the larger α x , the more dispersed the operation mode);

[0055] λ x (the total number of vectors in the target cluster of the xth page): the total number of standard user operation behavior feature vectors contained in all target clusters (reflecting the "effective behavior data amount" of the page - the larger λ x , the more comprehensive the legal behavior covered by the target cluster);

[0056] γ x (the total number of standard vectors of the xth page): all standard user operation behavior feature vectors collected by the page within a preset historical time period (including edge vectors / noise vectors that do not enter the target cluster, reflecting the original data size of the page).

[0057] Assemble the number group and list η, and combine the above three parameters into the number group η for each page (a total of y) of the carbon trading platform x = (α x , λ x , γ x ), and then summarized in the number group list η according to the page order.

[0058] This step has at least the following beneficial effects:

[0059] Data quantification of page behavior characteristics: Convert the "operation mode concentration" (α x ), "effective behavior coverage" (λ x ), and "original data size" (γx) of the page into calculable numerical values, avoid relying on artificial experience to set weights, and ensure the objectivity of weight calculation;

[0060] Correlation of historical behavior data: The parameters are directly derived from the standard behavior vector generation process in the foregoing, realizing the logical closed loop of "behavior characteristics-number indicators-weights", and making the weights truly reflect the actual operation properties of the page (such as the operation mode of high-risk pages is more concentrated, and α x is smaller);

[0061] Adapt to the risk differences in the carbon trading scene: Through the differences of α x and λ x , naturally distinguish high / medium / low-risk pages (such as the quota transfer page α x is the smallest, and λ x has the highest proportion), and lay the foundation for subsequent "risk matching weights".

[0062] S121, according to η, determine the basic weight corresponding to each page to obtain the basic weight list ω = (ω1, ω2, …, ω x , …, ω y ); wherein ω x is the basic weight of the xth page; ω x is negatively correlated with α x / λ max , and is positively correlated with λ x / (λ x + γ x ); α max is the maximum value of the number of target clusters in all pages.

[0063] Further, ω x is determined by the following steps:

[0064] S11, according to α x , λ x and γ x , determine the original weight r x = (λx / (λ x +γ x ))×1 / ((α x / α max )+1).

[0065] S12, according to r x ,Sure

[0066] By designing weights using "double correlation constraints" (negative correlation + positive correlation), pages with high risk and stable operation patterns are given a higher weight in "self-operation confidence calculation". At the same time, normalization is used to ensure that the total weight is 1, which conforms to mathematical logic and business needs.

[0067] Implementation method: It needs to be completed in 3 steps, and each step must fit "with α". x / λ max Negative correlation, with λ x / (λ x +γ x The constraint of "positive correlation":

[0068] Step 1: Determine the key benchmark value α max

[0069] α max It is the maximum number of target clusters across all pages, i.e., all α clusters in the list of number groups η. x The upper limit (α) is used to quantify the relative differences in the "degree of concentration of operating modes". Formula: α max =max(α1,α2,...,α) γ ).

[0070] Step 2: Design the "Two-Factor Original Weights"

[0071] To satisfy the relevance constraint, "negative correlation factors" and "positive correlation factors" need to be designed separately, and then the "original weight r" of the page is obtained by multiplying them. x (Unnormalized):

[0072] Positive correlation factor: directly using λ x / (λ x +γ x (Defined as "effective vector proportion") - The larger this value is, the higher the proportion of "effective behavioral data" (vectors entering the target cluster) in the page's original data, the more reliable the behavioral pattern, and the higher the weight should be.

[0073] Negative correlation factor: designed as 1 / ((α) x / α max )+1)——α x / α max The "relative dispersion" (α) that reflects page operation patternsx The larger the ratio is, the larger the ratio is, and 1 is added to avoid the denominator being 0. After taking the reciprocal of the whole, the "a x The larger the ratio is, the larger the ratio is, and 1 is added to avoid the denominator being 0. After taking the reciprocal of the whole, the "a

[0074] Original weight r x : Multiply the two factors to get the original weight (comprehensively reflect the "reliability" and "mode concentration" of the page).

[0075] Step 3: Normalization processing (ensure the weight sum is 1)

[0076] Divide the original weight r x of all pages by the sum of the original weights of all pages to get the final basic weight ω x .

[0077] The above steps have at least the following beneficial effects:

[0078] Weight and carbon trading risk match well: High-risk pages (such as quota transfer confirmation pages) have the highest weight (≈57.4%) due to "operation mode concentration (a x is small, and the negative correlation factor is large)", "effective data proportion is high (λ x / (λ x +γ x ) is large)", and the behavior similarity of this page has the greatest impact on the result when calculating the "personal operation confidence θ", which can accurately identify abnormal high-risk operations; Low-risk pages (such as query pages) have the lowest weight (≈17.8%), avoiding the interference of slight fluctuations of low-risk behaviors on the overall confidence judgment, and reducing the probability of false triggering verification.

[0079] Avoid subjective weight deviation: The weight is designed through "data-driven + mathematical constraint" rather than artificial setting (such as directly setting 0.6 weight for high-risk pages), ensuring that the weight can objectively reflect the "behavior reliability" and "risk attribute" of the page. For example: The weight of the emission data declaration page is naturally lower than that of the quota transfer page due to the slightly dispersed operation mode (a x = 3), which is more in line with the actual business logic.

[0080] Support the balance between security and convenience: High-weight pages focus on core risk points to ensure that abnormal behaviors are accurately captured; Low-weight pages do not increase the user's operation burden, and finally achieve the authentication effect of "strictness where necessary and simplicity where possible", echoing the demand in the background technology to "solve the contradiction between security and operation complexity".

[0081] S200, if the type of the current operation behavior is a preset second operation type, the operation behavior data of the target user on each operation page within a time range from logging in to the target platform to the current time point is obtained.

[0082] Further, the operation behavior data includes: click record, browsing record, page stay time of different types of information, mouse wheel scrolling frequency, and cursor movement record.

[0083] If the current operation is determined to be the second operation type (such as the user clicking “confirm carbon quota transfer”), the platform automatically retrieves all operation behavior data of the user from the current login to the current time point, including:

[0084] Pages operated (such as first entering the “quota query page”, then entering the “counterparty selection page”, and finally entering the “transfer confirmation page”) after login.

[0085] Specific behavior data of each page: such as stay time (2 minutes), scrolling frequency (3 times / minute), and click button interval (average 1.5 seconds) on the “quota query page”; input speed (5 characters / second), time-consuming for selecting enterprises (30 seconds), etc. on the “counterparty selection page”.

[0086] It should be noted that the user behavior data collected on each page in this step is consistent with the behavior data of the standard user on the same page in S100, to ensure that the dimensions of all feature vectors corresponding to the same page are the same.

[0087] Example: after a certain enterprise user logs in, first stays on the “quota query page” for 1 minute and 30 seconds, scrolls to view the quota changes in the past 3 months, then enters the “counterparty selection page” and searches for and selects a power plant in 40 seconds, and finally clicks “confirm transfer” (second operation type). At this time, the platform will collect the behavior data of all the above pages.

[0088] Beneficial effects: only the historical behavior of high-risk operations is traced back, which ensures the comprehensiveness of verification and avoids meaningless data collection for low-risk operations, improving efficiency.

[0089] S300, feature extraction is performed on the operation behavior data of each operation page of the target user from login to the target platform to the current time point, to obtain the behavior feature vector to be verified corresponding to each operation page.

[0090] Feature extraction is performed on the behavior data of each page collected in S200, and unstructured behavior is converted into structured vectors (numerical arrays). The feature dimension is set according to the page function, for example:

[0091] “Quota query page” feature vector: [average stay time (minutes), scrolling frequency (times / minute), and number of times of clicking “refresh” button]; “counterparty selection page” feature vector: [search keyword input speed (characters / second), time-consuming for selecting enterprises (seconds), and whether the selection is modified (0 / 1)]; and finally a behavior feature vector to be verified is generated for each operated page.

[0092] Example: User's behavior data extraction in "Quota Query Page" gets vector [1.5, 2.8, 1] (stay 1.5 minutes, scroll 2.8 times / minute, click 1 refresh); in "Counterparty Selection Page" gets vector [4.2, 35, 0] (input speed 4.2 characters / sec, selection time 35 seconds, no modification of selection).

[0093] Beneficial effect: Abstract user behavior is converted into a calculable numerical vector, providing a quantitative basis for subsequent similarity comparison, ensuring the objectivity of verification.

[0094] S400, obtain the maximum similarity between each to-be-verified behavior feature vector and each standard operation behavior feature vector of the corresponding page.

[0095] For each page's to-be-verified feature vector, similarity calculation (common cosine similarity, Euclidean distance, etc.) is performed with the page's preset several standard operation behavior feature vectors (such as the typical behavior vector of historical normal users on the page), and the maximum similarity value is taken.

[0096] Example: In the carbon trading platform, the standard feature vectors of "Counterparty Selection Page" are A = [5.0, 40, 0], B = [4.5, 30, 1], and C = [3.8, 35, 0]. The user's to-be-verified vector is [4.2, 35, 0], and the cosine similarity with A, B, and C is 0.82, 0.75, and 0.93 respectively, so the maximum similarity is 0.93.

[0097] Beneficial effect: By quantifying the matching degree of the user's current behavior and historical normal behavior, the "self-operation confidence" is provided with a core basis.

[0098] S500, weighted sum of the maximum similarity corresponding to each to-be-verified behavior feature vector and the base weight of the corresponding page to obtain the self-operation confidence θ of the target user.

[0099] Step S500 includes the following steps:

[0100] S510, obtain the maximum similarity corresponding to each to-be-verified behavior feature vector to obtain the maximum similarity list τ = (τ1, τ2, …, τb), a = 1, 2, …, b; where τa is the maximum similarity corresponding to the a-th to-be-verified behavior feature vector, and b is the number of to-be-verified behavior feature vectors. a b a

[0101] ​​​S520, obtaining the basic weight of the page corresponding to each verification behavior feature vector to obtain the basic weight list σ = (σ1, σ2, …, σ a , …, σ b ) of the page of the operation; wherein σ a is the basic weight of the page corresponding to the a-th verification behavior feature vector.

[0102] S530, determining SUM according to τ and σ, wherein SUM is a preset summation function.

[0103] In this embodiment, there are multiple pages in the target platform, and the target user does not operate all the pages after this login, and it is possible to operate part of the pages. Based on the basic weight of each page, the maximum weight of each page operated by the target user is re-determined through σ a / SUM(σ).

[0104] The basic weight reflects the risk difference of different pages (the weight of high-risk pages is higher), so that the confidence θ is more in line with the actual risk assessment, and the excessive interference of low-risk page behaviors on the result is avoided.

[0105] The above steps have at least the following beneficial effects:

[0106] Highlight the core influence of high-risk operations: in the molecular calculation, the similarity (τ1=0.92) of the high-weight page (such as the transfer page σ1=0.574) contributes about 0.528 of the weighted value, accounting for more than 60% of the total sum of molecules, ensuring that θ can reflect the legality of high-risk operations. If the similarity of the high-risk page is low (such as τ1=0.6), θ will decrease significantly, and the anomaly will be identified in time.

[0107] θ range is intuitive and controllable: by dividing by SUM(σ), θ is constrained between 0 and 1, which is more intuitive when compared with the preset threshold QR (such as 0.8) (such as θ = 0.878 ≥ 0.8, no fingerprint verification is triggered; θ = 0.75 < 0.8, verification is triggered), avoiding θ exceeding the reasonable range due to the fluctuation of the weight sum;

[0108] Balance safety and user experience: if the user's high-risk page operation is normal (τ1 is high), even if there is a slight fluctuation in the low-risk page (such as τ3=0.78), θ can still maintain a high value (such as 0.878), without triggering fingerprint verification, reducing the operation burden of legitimate users; if the high-risk page operation is abnormal (τ1 is low), θ will quickly decrease, timely blocking the risk, meeting the needs of the carbon trading platform "safety first, and convenience".

[0109] In summary, S510-S530 converts the user's multi-page operation behavior into a single and intuitive "self-operation confidence θ" through the logic of "structured similarity sorting → binding corresponding weight → weighted normalization calculation", focusing on high-risk operations on the carbon trading platform, and ensuring controllable results through normalization, providing a scientific and accurate quantitative basis for the subsequent decision of "whether to trigger fingerprint verification".

[0110] S600, if θ≥QR, the preset fingerprint verification task is not triggered; otherwise, the fingerprint verification task is triggered; wherein QR is a preset self-operation confidence threshold.

[0111] In this embodiment, QR can be determined by the following method:

[0112] 1. Collect historical operation data for the past 6-12 months (covering the peak / trough of carbon trading)

[0113] Positive samples: "self-normal operation" confirmed by fingerprint verification (θ is calculated from the similarity and weight at that time);

[0114] Negative samples: "non-self abnormal operation" (such as account theft, simulation operation, which needs to be marked with the actual operator's identity) that has been intercepted.

[0115] For example: the carbon trading platform collects 10,000 positive samples (self-operation) and 500 negative samples (non-self-operation).

[0116] 2. θ distribution statistics and ROC curve analysis

[0117] Statistically analyze the θ values of positive and negative samples: positive samples θ usually concentrate in 0.75-0.95 (behavior conforms to the standard mode);

[0118] Negative samples θ usually concentrate in 0.4-0.7 (behavior deviates from the standard mode); draw the ROC curve (receiver operating characteristic curve): take "θ as the threshold", the horizontal axis as the "false positive rate (misjudgment rate: self-operation is judged as abnormal)", and the vertical axis as the "true positive rate (probability of correctly identifying self-operation)", the point in the curve closest to the upper left corner corresponds to the optimal QR (at this time, the false negative rate and the false positive rate are both the lowest).

[0119] 3. Threshold fine-tuning and landing

[0120] If the carbon trading platform requires higher security (such as quota transfer and other core operations), the optimal threshold can be increased by 0.05-0.1 (e.g. optimal value 0.8 → QR=0.85) to further reduce the false negative rate; if the requirement for convenience is higher (such as non-core emission data draft saving), the optimal threshold can be decreased by 0.03-0.05 (e.g. optimal value 0.8 → QR=0.77).

[0121] Through this step, only when the behavior credibility is insufficient, the secondary verification is triggered, the problem of cumbersome process caused by "forcing verification for all key operations" is solved, and the security and user experience are balanced.

[0122] S700, if the fingerprint verification of the target user passes, the current operation behavior of the target user is executed; otherwise, a preset security task is executed.

[0123] If the fingerprint verification passes (matches the user fingerprint template pre-stored by the platform), it is determined that the user is legal, and the current operation (such as completing the carbon quota transfer and generating a transaction voucher) is executed; if the fingerprint verification fails (multiple matching failures or verification within a specified time), a preset security task is executed, such as suspending the current operation, locking the account for 1 hour, and sending an abnormal operation alert (including operation time, IP address, etc.) to the enterprise administrator.

[0124] Through fingerprint verification as the final security barrier, the authenticity of high-risk operations is ensured, and illegal operations are timely blocked through security tasks to protect the safety of enterprise carbon assets.

[0125] In summary, through the logic of "dynamic behavior tracking-quantitative confidence evaluation-condition triggered verification", the method not only solves the problem that traditional static authentication cannot cope with account theft, but also avoids the cumbersome of frequent secondary verification, and balances the security and convenience in the carbon trading platform.

[0126] In this embodiment, on the one hand, by dynamically tracking the behavior data of the user on each operation page for specific operation types after the user logs in and performing feature comparison, the continuous verification of the user's identity is realized, instead of relying only on static authentication in the initial login link, which can timely identify abnormal operations after the account is stolen, reduce the risk of loss of enterprise carbon assets, and maintain the trading order of the platform; on the other hand, by calculating the self-operation confidence and comparing it with the threshold, fingerprint verification is triggered only when the confidence is insufficient, avoiding the cumbersome process of forcing secondary verification for all key operations, ensuring the security of high-risk operations while reducing the verification frequency of legal users and simplifying the operation process, thereby effectively balancing the security and user operation convenience of the carbon trading platform, ensuring the safe operation of the platform while improving the user experience.

[0127] In addition, although the steps of the method in the present disclosure are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired results. In addition or alternatively, some steps can be omitted, multiple steps can be combined into one step, and / or one step can be divided into multiple steps, etc.

[0128] The embodiment of the present application further provides a non-transitory computer readable storage medium, which can be arranged in an electronic device to store at least one instruction or at least one program for implementing a method related to the method in the method embodiment, and the at least one instruction or the at least one program is loaded and executed by the processor to implement the method provided by the above embodiment.

[0129] The program product can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium may, for example, be but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination thereof. More specific examples (non-exhaustive list) of readable storage media include an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0130] The computer readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which readable program code is borne. Such propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination thereof. The readable signal medium can also be any readable medium other than the readable storage medium, which can send, propagate or transmit the program for use by or in connection with an instruction execution system, device or apparatus.

[0131] The program code contained on the readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0132] The program code for performing the operations of the present application can be written in any combination of one or more programming languages, including an object-oriented programming language such as Java, C++, etc., and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, connected to the Internet through an Internet service provider).

[0133] Embodiments of the present application also provide an electronic device including a processor and the aforementioned non-transitory computer-readable storage medium.

[0134] Electronic device is merely an example, and should not bring any limitation to the function and use range of embodiments of the present application.

[0135] The electronic device is in the form of a general computing device. Components of the electronic device can include, but are not limited to, the aforementioned at least one processor, the aforementioned at least one memory, a bus connecting different system components including the memory and the processor.

[0136] The memory stores program codes, which can be executed by the processor, so that the processor performs steps in various embodiments described in the specification.

[0137] The memory can include a readable medium in the form of a volatile memory, such as a random access memory (RAM) and / or a cache memory, and can further include a read-only memory (ROM).

[0138] The memory can also include programs / utilities with a set of (at least one) program modules, such as an operating system, one or more application programs, other program modules, and program data, each of which or some combination of which can include implementation of a network environment.

[0139] The bus can be one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor or a local bus using any of a variety of bus structures.

[0140] The electronic device can also communicate with one or more external devices (such as a keyboard, a pointing device, a Bluetooth device, etc.) and can also communicate with one or more devices that enable a user to interact with the electronic device (and / or one or more input / output (I / O) devices 620), and / or with any devices (such as a router, a modem, etc.) that enable the electronic device to communicate with one or more other computing devices. Such communication can occur via an I / O interface. Also, the electronic device can communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or the public network, such as the Internet) via a network adapter. The network adapter communicates with the other modules of the electronic device via the bus. It should be appreciated that other hardware and / or software modules can be used in conjunction with the electronic device, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0141] Those skilled in the art can clearly understand the example embodiments described herein through the above description of the example embodiments, and the example embodiments described herein can be implemented by software or by software in combination with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash disk, a mobile hard disk, or the like) or on a network, and includes a number of instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to perform the methods according to the embodiments of the present disclosure.

[0142] Embodiments of the present disclosure also provide a computer program product comprising program code for causing an electronic device to perform the steps of the methods according to the various example embodiments of the present disclosure described above in the specification when the program product is run on the electronic device.

[0143] Although some specific embodiments of the present disclosure have been described in detail by way of examples, those skilled in the art should understand that the above examples are only for illustration, and are not intended to limit the scope of the present disclosure. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the present disclosure.

Claims

1. A method for identity authentication based on fingerprint recognition and identity identification, characterized in that, The method comprises the following steps: S100, in response to a current operation behavior of a target user after logging in a target platform, obtaining a type of the current operation behavior; the target platform comprises a plurality of pages; each page corresponds to a plurality of preset standard operation behavior feature vectors and a preset basic weight; the basic weight is obtained through historical operation behavior data of a plurality of historical users on the corresponding page; S200, if the type of the current operation behavior is a preset second operation type, obtaining operation behavior data of the target user on each operation page within a time range from logging in the target platform to a current time point; S300, performing feature extraction on the operation behavior data of the target user on each operation page from logging in the target platform to the current time point to obtain a to-be-verified behavior feature vector corresponding to each operation page; S400, obtaining a maximum similarity between each to-be-verified behavior feature vector and each standard operation behavior feature vector of the corresponding page; S500, determining a self-operation confidence degree θ of the target user according to the maximum similarity corresponding to each to-be-verified behavior feature vector and the basic weight of the corresponding page; S600, if θ ≥ QR, a preset fingerprint verification task is not triggered; otherwise, the fingerprint verification task is triggered; wherein QR is a preset self-operation confidence threshold; S700, if the fingerprint verification of the target user is passed, the current operation behavior of the target user is executed; otherwise, a preset security task is executed.

2. The method of claim 1, wherein, The standard operation behavior feature vector corresponding to each page is obtained through the following steps: S110, divide the preset historical time period into a plurality of sub historical time periods with the same length to obtain a sub historical time period list T=(T1, T2, …, Tn), i=1, 2, …, n; wherein T is the i-th sub historical time period obtained by dividing the preset historical time period, and n is the number of sub historical time periods obtained by dividing the preset historical time period. i , …, T n ), i=1, 2, …, n; wherein T i is the i-th sub historical time period obtained by dividing the preset historical time period, and n is the number of sub historical time periods obtained by dividing the preset historical time period. S111, for any page YM, obtain a plurality of standard user operation behavior feature vectors corresponding to YM in each sub-history time period of T to obtain a standard user operation behavior feature vector list set A=(A1, A2,..., Af(i)) corresponding to T; wherein A is a standard user operation behavior feature vector list corresponding to T; A=(A1, A2,..., Af(i)), j=1, 2,..., f(i); A is the jth standard user operation behavior feature vector corresponding to YM in T; f(i) is the number of standard user operation behavior feature vectors corresponding to YM in T. i n i i i i,1 i,2 i,j i,f(i) i,j i i ​​​​​​​​​​​​ S112, use a preset clustering algorithm to cluster the standard user operation behavior feature vectors in A to obtain a cluster list B = (B1, B2, ..., B...). p B q ), p = 1, 2, ..., q; where, B p To obtain the p-th cluster through clustering, q is the number of clusters obtained through clustering; S113, iterate through B, if B p The number of standard user action behavior feature vectors within NUM p ≥NUM YM Then B p Identified as the target cluster; NUM YM This is the threshold for the number of intra-cluster vectors corresponding to YM; S114, the center vector corresponding to each target cluster is determined as the standard operation behavior feature vector corresponding to YM. 3.The method of claim 2, wherein, The basic weight corresponding to each page is obtained through the following steps: S120, obtain the number of target clusters corresponding to each page, the number of standard user operation behavior feature vectors in the target cluster, and the total number of standard user operation behavior feature vectors, to obtain the number group list corresponding to each page η=(η1, η2, …, ηy), x=1, 2, …, y; wherein ηx is the number group corresponding to the xth page, y is the number of pages corresponding to the target platform; ηx=(αx, λx, γx); αx, λx and γx are the number of target clusters corresponding to the xth page, the number of standard user operation behavior feature vectors in the target cluster, and the total number of standard user operation behavior feature vectors, respectively. x , …, η y ), x=1, 2, …, y; wherein η x is the number group corresponding to the xth page, y is the number of pages corresponding to the target platform; η x =(α x , λ x , γ x ); α x , λ x and γ x are the number of target clusters corresponding to the xth page, the number of standard user operation behavior feature vectors in the target cluster, and the total number of standard user operation behavior feature vectors, respectively. S121, determining the base weight corresponding to each page according to η to obtain a base weight list ω=(ω1, ω2, …, ω x ); y ); wherein ω x is the base weight of the xth page; ω x is negatively correlated with α x / α max , and is positively correlated with λ x / (λ x +γ x ); α max is the maximum value of the number of target clusters in all pages.

4. The method of claim 3, wherein, ω x was determined by the following steps: S11, according to α x , λ x and γ x Determine the original weight r of page x. x =(λ x / (λ x +γ x ))×1 / ((α x / α max )+1); S12, according to r x , determine 5. The method of claim 1, wherein, Step S500 comprises the following steps: S510, obtaining the maximum similarity corresponding to each to-be-verified behavior feature vector to obtain a maximum similarity list τ=(τ1, τ2, …, τ a ), a=1, 2, …, b; wherein τ b is the maximum similarity corresponding to the a-th to-be-verified behavior feature vector, and b is the number of to-be-verified behavior feature vectors; a ​ S520, obtaining the basic weight of the page corresponding to each verification behavior feature vector to obtain the basic weight list σ = (σ1, σ2, …, σ a ) of the page of operation; wherein σ b is the basic weight of the page corresponding to the a-th to-be-verified behavior feature vector. a ​ S530, determining, according to τ and σ, SUM is a preset summation function.

6. The method of claim 1, wherein, The operation behavior data comprises click records, browsing records, page stay time of different types of information, mouse wheel scrolling frequency and cursor movement records.

7. The method of claim 1, wherein, After step S100 and before step S200, the method further comprises the following steps: S130, if the type of the current operation behavior is a preset first operation type, a direct response is performed; wherein the security level of the first operation type is lower than that of the second operation type. 8.The method of claim 2, wherein, The preset clustering algorithm is a DBSCAN clustering algorithm. 9.A non-transitory computer-readable storage medium having stored therein at least one instruction or at least one piece of program, characterized in that, The at least one instruction or the at least one program is loaded and executed by the processor to implement the identity authentication method based on fingerprint identification and identity identification according to any one of claims 1-8.

10. An electronic device, comprising: The non-transitory computer readable storage medium comprises a processor and the non-transitory computer readable storage medium of claim 9.

Citation Information

Patent Citations

  • Risk identification method and apparatus for user operation behavior

    CN108229963A

  • Sustainable identity authentication method in allusion to smartphone sensitive APP

    CN108920921A

  • Identity authentication method and device, electronic equipment and computer readable storage medium

    CN110851808A

  • Platform authentication login method based on block chain and related device

    CN111786991A

  • Network identity recognition method and device based on website behavior event response

    CN115426129A