An identity authentication method and device based on fingerprint recognition and identity identification, and a medium
By dynamically tracking user behavior and calculating confidence levels in the carbon trading platform, the cumbersome dynamic tracking and secondary verification of user identity authentication in the carbon trading platform is solved, achieving a balance between security and convenience, reducing the risk of corporate asset loss and improving user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NATIONAL ENERGY ADMINISTRATION INFORMATION CENTER
- Filing Date
- 2025-09-16
- Publication Date
- 2026-07-21
AI Technical Summary
The existing identity authentication technology of carbon trading platforms has the problem of lacking dynamic tracking and verification of user behavior after login, which makes it possible for unauthorized accounts to execute high-risk transactions or tamper with data, and the secondary verification process is cumbersome.
By dynamically tracking user actions after login, obtaining and comparing feature vectors, calculating the user's confidence level, and triggering fingerprint verification only when the confidence level is insufficient, the system avoids frequent secondary verification.
It enables continuous verification of user identity, reduces the risk of corporate carbon asset loss, simplifies operation processes, balances security and convenience, and improves user experience.
Smart Images

Figure CN121167701B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of identity authentication technology, and in particular to an identity authentication method, device and medium based on fingerprint recognition and identity identification. Background Technology
[0002] In the operation of carbon trading platforms, corporate users need to carry out key operations such as carbon quota transfer, emission data declaration, and transaction contract confirmation. These operations are directly related to the security of corporate carbon assets, the fairness of carbon market transactions, and the effective implementation of national carbon emission reduction policies. Therefore, continuous and accurate authentication of user identities is a core requirement to ensure the safe operation of the platform.
[0003] However, existing carbon trading platform identity authentication technologies have significant shortcomings: On the one hand, traditional authentication methods are mostly concentrated in the initial login stage, verifying identity only through static passwords or single biometric identification (such as initial fingerprint verification). After login, there is a lack of dynamic tracking and verification of subsequent user operations. If an account is illegally stolen after login, unauthorized operators can still perform high-risk transactions or data tampering operations, causing corporate carbon asset losses and disrupting the platform's trading order. On the other hand, some carbon trading platforms have set up secondary verification for key operations to improve security, such as fingerprint verification. Although security has been improved, users need to perform secondary verification frequently, making the process cumbersome. Therefore, how to simplify the user's operation process while ensuring security has become an urgent technical problem to be solved. Summary of the Invention
[0004] To address the aforementioned technical problems, the technical solution adopted by this invention is as follows:
[0005] According to a first aspect of this application, an identity authentication method based on fingerprint recognition and identity identification is provided, the method comprising the following steps:
[0006] S100, responding to the current operation behavior of the target user after logging into the target platform, obtains the type of the current operation behavior; the target platform includes several pages; each page corresponds to several preset standard operation behavior feature vectors and a preset basic weight; the basic weight is obtained through the historical operation behavior data of several historical users on the corresponding page;
[0007] S200, if the type of the current operation behavior is the preset second operation type, then obtain the operation behavior data of the target user on each operation page within the time range from logging into the target platform to the current time point;
[0008] S300 extracts features from the target user's operational behavior data on each page from logging into the target platform to the current time point, in order to obtain the feature vector of the behavior to be verified corresponding to each page.
[0009] S400, obtain the maximum similarity between each feature vector of the behavior to be verified and each feature vector of the standard operation behavior of the corresponding page;
[0010] S500, based on the maximum similarity of each feature vector of the behavior to be verified and the basic weight of the corresponding page, determines the confidence level θ of the target user's own operation;
[0011] S600, if θ≥QR, then the preset fingerprint verification task is not triggered; otherwise, the fingerprint verification task is triggered; where QR is the preset confidence threshold for the user's own operation.
[0012] S700: If the target user's fingerprint verification is successful, the target user's current operation behavior is executed; otherwise, a preset security task is executed.
[0013] According to another aspect of this application, a non-transitory computer-readable storage medium is also provided, wherein at least one instruction or at least one program is stored in the storage medium, and the at least one instruction or at least one program is loaded and executed by a processor to implement the above-described identity authentication method based on fingerprint recognition and identity identification.
[0014] According to another aspect of this application, an electronic device is also provided, including a processor and the aforementioned non-transitory computer-readable storage medium.
[0015] The present invention has at least the following beneficial effects:
[0016] The fingerprint recognition and identity authentication method of this invention, on the one hand, achieves continuous verification of user identity by dynamically tracking and comparing user behavior data on various operation pages for specific operation types after login, rather than relying solely on static authentication during the initial login stage. This allows for timely identification of abnormal operations after account theft, reducing the risk of carbon asset loss for enterprises and maintaining the order of platform transactions. On the other hand, by calculating the confidence level of an individual's operation and comparing it with a threshold, fingerprint verification is triggered only when the confidence level is insufficient. This avoids the cumbersome process of forcibly performing secondary verification for all critical operations. While ensuring the security of high-risk operations, it reduces the verification frequency for legitimate users and simplifies the operation process. Thus, it achieves an effective balance between the security of the carbon trading platform and the convenience of user operation, ensuring the safe operation of the platform while improving the user experience. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 A flowchart of an identity authentication method based on fingerprint recognition and identity identification provided in an embodiment of the present invention. Detailed Implementation
[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] It should be noted that, based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Furthermore, this device and / or practice the method can be implemented using other structures and / or functionalities besides one or more of the aspects set forth herein.
[0021] The following will refer to Figure 1 The flowchart shown illustrates an identity authentication method based on fingerprint recognition and identity identification, introducing such a method.
[0022] The fingerprint recognition and identity authentication method may include the following steps:
[0023] S100, responding to the current operation behavior of the target user after logging into the target platform, obtains the type of the current operation behavior; the target platform includes several pages; each page corresponds to several preset standard operation behavior feature vectors and a preset basic weight; the basic weight is obtained through the historical operation behavior data of several historical users on the corresponding page.
[0024] The method in this embodiment can be applied to a carbon trading scenario. The target platform is a carbon trading platform. After the target user logs into the carbon trading platform, the platform backend monitors the user's interactive behavior in real time (such as clicking a button, submitting a form, entering a specific page, etc.). By parsing the interface calls, page URLs, or button identifiers (such as the "Confirm Transfer" button or the "Submit Emissions Data" form) of the user's operation, the type of the current operation behavior is determined.
[0025] In carbon trading platforms, operations are generally divided into two categories: the first type of operation (low risk): such as checking a company's carbon allowance balance, browsing historical transaction records, and viewing policy notices; the second type of operation (high risk): such as initiating carbon allowance transfers, submitting annual emission data, and confirming transaction contracts (these operations directly affect the validity of carbon assets or data).
[0026] Meanwhile, the platform pre-configures standard operating behavior feature vectors (generated based on historical normal user behavior) and basic weights (high-risk pages have higher weights, such as "Quota Transfer Page" with a weight of 0.5 and "Query Page" with a weight of 0.1) for each page (e.g., "Quota Transfer Page" with a weight of 0.5 and "Query Page" with a weight of 0.1).
[0027] Furthermore, the standard operation behavior feature vector for each page can be obtained through the following steps:
[0028] S110, Divide the preset historical time period into several sub-historical time periods of equal duration to obtain a list of sub-historical time periods T = (T1, T2, ..., T...). i ,…,T n ), i = 1, 2, ..., n; where, T i The i-th sub-historical time period is obtained by dividing the preset historical time period, and n is the number of sub-historical time periods obtained by dividing the preset historical time period.
[0029] First, determine a "preset historical time period" (such as the past year), and then evenly divide it into several "sub-historical time periods" of equal length (such as dividing it into 12 sub-time periods by month, or 4 sub-time periods by quarter), forming a list of sub-historical time periods T. The core purpose of this division is to capture potential changes in user behavior within different time periods (for example, user behavior on a carbon trading platform may differ between the "quota application period" at the beginning of the month and the "trading peak period" at the end of the month).
[0030] Example: The carbon trading platform divides the "past year" (January 2023 - December 2023) into 12 monthly sub-periods, i.e., T = (T1 = January, T2 = February, ..., T...). 12 =December), n=12.
[0031] By segmenting time, we can avoid the problem of "outdated behavior patterns" caused by directly using historical data with too long a span (such as changes in user operating habits as platform functions are updated or business cycles change), and ensure that subsequent feature vectors can reflect recent typical operating patterns.
[0032] S111, for any page YM, obtain several standard user operation behavior feature vectors corresponding to YM in each sub-historical time period of T, so as to obtain the list set A = (A1, A2, ..., A...) of standard user operation behavior feature vectors corresponding to T. i A n ); where A i For T i The corresponding standard user operation behavior feature vector list; A i =(A i,1 A i,2 A i,j A i,f(i) ), j=1,2,…,f(i);A i,j For YM in T i The j-th standard user operation behavior feature vector corresponding to YM in T, f(i) is the feature vector of YM in T. i The number of standard user operation behavior feature vectors corresponding to the content.
[0033] For any page YM on the carbon trading platform (such as the "Carbon Allowance Transfer Confirmation Page" or the "Annual Emissions Data Declaration Page"), in each sub-time period T i Internally, it collects behavioral data of standard users (i.e., verified legitimate users, excluding abnormal accounts or malicious users) on this page, extracts features, and transforms them into feature vectors to form each T. i The corresponding vector list A i Finally, these are summarized into list set A.
[0034] Among them, "standard user operation behavior characteristics" need to be combined with the page function definition, for example:
[0035] The key features of the "Carbon Quota Transfer Confirmation Page" include: [Page dwell time (seconds), number of clicks to verify transaction amount, number of times the quota quantity was modified before submission, and operation time (morning / afternoon)].
[0036] The features of the "Annual Emissions Data Reporting Page" include: [Time taken to input a single data entry (seconds), number of times to correct validation errors, frequency of saving drafts, and page scrolling speed (pixels / second)].
[0037] Example: Taking page YM = "Carbon Quota Transfer Confirmation Page" as an example, the operation data of 200 legitimate users are collected within T1 (January). After extracting features, A1 = (A 1,1 A 1,2 ,…,A 1,200 ), where A 1,1 =[180,3,0,1] (Staying for 180 seconds, clicking to check 3 times, quota not modified, operation in the morning); 180 user data points were collected within T2 (February), forming A2 = (A2,1 ,…,A 2,180 ), and finally we get A.
[0038] By focusing on the behavioral data of "standard users," the "legitimacy" of the original vector is ensured; classification by sub-time periods preserves the temporal attributes of the behavior, providing a foundation for subsequent capture of periodic behavioral patterns (such as operational differences between peak and off-peak seasons).
[0039] S112, use a preset clustering algorithm to cluster the standard user operation behavior feature vectors in A to obtain a cluster list B = (B1, B2, ..., B...). p B q ), p = 1, 2, ..., q; where, B p To obtain the p-th cluster through clustering, q represents the number of clusters obtained through clustering.
[0040] Use a pre-defined clustering algorithm (such as DBSCAN) to analyze the feature vectors of all sub-time periods (i.e., A1 to A2) in list set A. n Clustering is performed on all vectors in YM; vectors with similar features are grouped into the same "cluster", resulting in a list B composed of several clusters. The core of clustering is to identify the "typical operation mode" of page YM (such as different legal operation modes such as "quick confirmation" and "careful verification" on the same page).
[0041] When using DBSCAN to cluster the standard user behavior feature vectors in A, the cluster radius can be set to be smaller to improve the clustering accuracy and thus identify more types of users.
[0042] By automatically identifying various typical operation modes on the page through clustering, we can avoid the "singularity bias" caused by manually defined standards (such as using only one "normal behavior" standard, which may exclude other legitimate modes), making subsequent verification more in line with actual user habits.
[0043] S113, iterate through B, if B p The number of standard user action behavior feature vectors within NUM p ≥NUM YM Then B p Identified as the target cluster; NUM YM This is the threshold for the number of vectors within the cluster corresponding to YM.
[0044] Iterate through the cluster list B and calculate the value of each cluster B. p The number of vectors within NUM p Only NUM is retained. p ≥NUM YM Clusters with a threshold of (the number of vectors within a cluster in page YM) are designated as "target clusters". YMThe setting needs to be combined with the total amount of data on the page (e.g., set to 5%-15% of the total number of vectors). The core is to exclude "marginal clusters" with too small a sample size (which may be noise or the special behavior of a very small number of users and do not have general representativeness).
[0045] Example: The total vector count of the "Carbon Quota Transfer Confirmation Page" is 2200, NUM YM Let's set it to 5% of the total number (i.e., 110). After clustering: B1 contains 1000 vectors (NUM1 = 1000 ≥ 110) → target cluster; B2 contains 800 vectors (NUM2 = 800 ≥ 110) → target cluster; B3 contains 400 vectors (NUM3 = 400 ≥ 110) → target cluster; (if a cluster contains only 5 vectors, it is excluded).
[0046] By using a threshold for quantity screening, we ensure that the target cluster contains a sufficient number of samples to represent the mainstream operation mode of the page, thus avoiding verification bias caused by including "niche behaviors" or "noisy data" in the standard (such as misjudging the normal behavior of most users as abnormal).
[0047] Furthermore, in carbon trading platform scenarios, for high-risk pages (such as carbon allowance transfer confirmation pages), the NUM threshold can be appropriately increased. YM (e.g., 10%-20% of the total), to rigorously screen for more general and normal operating characteristics; for low-risk pages (e.g., transaction record query pages), the NUM can be reduced. YM (e.g., 3%-8% of the total), while ensuring basic representativeness, retaining more diverse normal operating modes.
[0048] S114, determine the center vector corresponding to each target cluster as the standard operation behavior feature vector corresponding to YM.
[0049] For each target cluster, calculate its "center vector" (i.e., the mean or median vector of all vectors within the cluster, representing the typical characteristics of the cluster), and finally use these center vectors as the "standard operation behavior feature vectors" of page YM.
[0050] The central vector encapsulates the typical characteristics of the target cluster and serves as a "benchmark" for subsequent verification. It retains multiple legitimate operation modes of the page (avoiding a single standard) and ensures the objectivity and computability of the verification through the quantified vector form, laying the foundation for accurately judging whether user behavior is normal.
[0051] In summary, S110-S114, through the logic of "time segmentation - feature extraction - cluster analysis - screening and optimization - center vector extraction", generates a standard operational behavior feature vector that can dynamically reflect the mainstream legal operation modes of different pages of the carbon trading platform. It adapts to changes in behavior over time and accommodates diverse user operating habits, providing a core basis for the accuracy and flexibility of subsequent identity authentication.
[0052] Furthermore, the basic weight corresponding to each page is obtained through the following steps:
[0053] S120, obtain the number of target clusters corresponding to each page, the number of standard user operation behavior feature vectors within the target cluster, and the total number of standard user operation behavior feature vectors, to obtain the list of quantity groups η = (η1, η2, ..., η) corresponding to each page. x ,…,η y ), x=1, 2,...,y; where, η x Let η be the number of pages corresponding to the x-th page, and y be the number of pages corresponding to the target platform. x =(α x , λ x γ x );α x , λ x and γ x These are, in order, the number of target clusters corresponding to the x-th page, the number of standard user operation behavior feature vectors within the target cluster, and the total number of standard user operation behavior feature vectors.
[0054] α x (Number of target clusters on the x-th page): i.e., the number of clusters that meet the NUM criteria selected in S113. YM The total number of target clusters at the threshold (reflecting the "concentration" of legitimate page operation patterns - α) x The smaller the value, the more uniform the user operation pattern; α x The larger the value, the more dispersed the operating mode.
[0055] λ x (Total number of vectors within the target cluster of the x-th page): The sum of standard user action behavior feature vectors contained in all target clusters (reflecting the "effective behavior data volume" of the page) – λ x The larger the value, the more comprehensive the legal behaviors covered by the target cluster.
[0056] γ x (Total number of standard vectors for the xth page): All standard user operation behavior feature vectors collected for this page within a preset historical time period (including edge vectors / noise vectors that do not enter the target cluster, reflecting the original data scale of the page).
[0057] For each page (y in total) of the carbon trading platform, combine the above three parameters into a quantity group η. x =(α x ,λ x ,γ x Then, summarize them into a list of quantity groups η in page order.
[0058] This step has at least the following beneficial effects:
[0059] Quantifying page behavior characteristics using data: This involves quantifying the "centralization of page operation patterns" (α). x ), "effective behavior coverage" (λ) x The "original data size" (γx) is transformed into a computable value, avoiding reliance on human experience to set weights and ensuring the objectivity of weight calculation;
[0060] Linking historical behavior data: The parameters are directly derived from the standard behavior vector generation process described above, achieving a logical closed loop of "behavioral features - quantitative indicators - weights," allowing the weights to truly reflect the actual operational attributes of the page (e.g., high-risk pages have more concentrated operation patterns, α). x Smaller);
[0061] Adapting to the different risks of carbon trading scenarios: through alpha x , λ x The differences naturally distinguish high / medium / low risk pages (such as the quota transfer page α). x Minimum, λ x (with the highest proportion), laying the foundation for subsequent "risk matching weight".
[0062] S121, Based on η, determine the basic weight corresponding to each page to obtain the basic weight list ω=(ω1, ω2, ..., ω x ,…,ω y ); where ω x ω is the base weight of the x-th page; x With α x / λ max It is negatively correlated with λ. x / (λ x +γ x ) are positively correlated; α max This represents the maximum number of target clusters across all pages.
[0063] Furthermore, ω x Determined through the following steps:
[0064] S11, according to α x , λ x and γ x Determine the original weight r of page x. x =(λx / (λ x +γ x ))×1 / ((α x / α max )+1).
[0065] S12, according to r x ,Sure
[0066] By designing weights using "double correlation constraints" (negative correlation + positive correlation), pages with high risk and stable operation patterns are given a higher weight in the "self-operation confidence calculation". At the same time, normalization is used to ensure that the total weight is 1, which conforms to mathematical logic and business needs.
[0067] Implementation method: It needs to be completed in 3 steps, and each step must fit "with α". x / λ max Negative correlation, with λ x / (λ x +γ x The constraint of "positive correlation":
[0068] Step 1: Determine the key benchmark value α max
[0069] α max It is the maximum number of target clusters across all pages, i.e., all α clusters in the list of number groups η. x The upper limit (α) is used to quantify the relative differences in the "degree of concentration of operating modes". Formula: α max =max(α1,α2,...,α) γ ).
[0070] Step 2: Design the "Two-Factor Original Weights"
[0071] To satisfy the relevance constraint, "negative correlation factors" and "positive correlation factors" need to be designed separately, and then the "original weight r" of the page is obtained by multiplying them. x (Unnormalized):
[0072] Positive correlation factor: directly using λ x / (λ x +γ x (Defined as "effective vector proportion") - The larger this value is, the higher the proportion of "effective behavioral data" (vectors entering the target cluster) in the page's original data, the more reliable the behavioral pattern, and the higher the weight should be.
[0073] Negative correlation factor: designed as 1 / ((α) x / α max )+1)——α x / α max The "relative dispersion" (α) that reflects page operation patternsx The larger the value, the larger the ratio. Adding 1 is to avoid the denominator being 0. Taking the reciprocal of the whole result in "α". x The constraint is that "the larger the value, the smaller the negative correlation factor".
[0074] Original weight r x Multiply the two factors to obtain the original weight (which comprehensively reflects the "reliability" and "pattern concentration" of the page).
[0075] Step 3: Normalization (ensure the sum of weights is 1)
[0076] All pages' original weights r x Divide by the sum of the original weights of all pages to obtain the final base weight ω. x .
[0077] The above steps have at least the following beneficial effects:
[0078] Weighting is strongly correlated with carbon trading risk: High-risk pages (such as the quota transfer confirmation page) are due to "concentrated operation mode (α)". x Small, large negative correlation factor); high proportion of effective data (λ) x / (λ x +γ x The page with the highest weight (≈57.4%) has the greatest impact on the result when calculating the "confidence level θ" of the user's actions. It can accurately identify abnormal high-risk actions. The low-risk page (such as the query page) has the lowest weight (≈17.8%). This avoids the slight fluctuations of low-risk actions from interfering with the overall confidence level judgment and reduces the probability of falsely triggering verification.
[0079] To avoid subjective weighting bias: Weights should be designed using a "data-driven + mathematical constraint" approach, rather than manually set (e.g., directly assigning a weight of 0.6 to high-risk pages). This ensures that the weights objectively reflect the "behavioral reliability" and "risk attributes" of the page. For example, the emissions data declaration page has a slightly dispersed operation mode (α...). x =3), so the weight is naturally lower than that of the quota transfer page, which is more in line with the actual business logic.
[0080] Supporting a balance between security and convenience: High-weight pages focus on core risk points to ensure that abnormal behavior is accurately captured; low-weight pages do not increase the user's operational burden, ultimately achieving the authentication effect of "strict where necessary and simple where necessary", echoing the background technology's need to "resolve the contradiction between security and cumbersome operation".
[0081] S200, if the current operation type is the preset second operation type, then obtain the target user's operation behavior data on each operation page within the time range from logging into the target platform to the current time.
[0082] Furthermore, the operation behavior data includes: click records, browsing records, page dwell time for different types of information, mouse wheel scrolling frequency, and cursor movement records.
[0083] If the current operation is determined to be the second type of operation (such as the user clicking "Confirm Carbon Quota Transfer"), the platform will automatically retrieve all operation data of the user from this login to the current time, including:
[0084] Pages that have been accessed (e.g., after logging in, first you go to the "Quota Inquiry Page", then to the "Counterpartner Selection Page", and finally to the "Transfer Confirmation Page").
[0085] Specific behavioral data for each page: such as dwell time on the "Quota Inquiry Page" (2 minutes), scrolling frequency (3 times / minute), and button click interval (average 1.5 seconds); and input speed (5 characters / second) and time spent selecting a company on the "Counterpartner Selection Page" (30 seconds).
[0086] It should be noted that the user behavior data collected on each page in this step is consistent with the behavior data of the standard user on the same page in S100, so as to ensure that the dimensions of all feature vectors corresponding to the same page are the same in the end.
[0087] Example: After logging in, a corporate user spends 1 minute and 30 seconds on the "Quota Inquiry Page" to scroll through the quota changes over the past 3 months. Then, they go to the "Counterpartner Selection Page" and spend 40 seconds searching for and selecting a power plant. Finally, they click "Confirm Transfer" (second operation type). At this point, the platform will collect behavioral data from all the pages mentioned above.
[0088] Beneficial effects: By tracing historical behavior only for high-risk operations, the verification is comprehensive while avoiding meaningless data collection for low-risk operations, thus improving efficiency.
[0089] S300 extracts features from the target user's operational behavior data on each page from logging into the target platform to the current time point, in order to obtain the feature vector of the behavior to be verified corresponding to each page.
[0090] Feature extraction is performed on the page behavior data collected in S200, transforming unstructured behavior into structured vectors (numerical arrays). Feature dimensions are set according to page function, for example:
[0091] Feature vector for "Quota Inquiry Page": [Average dwell time (minutes), scrolling frequency (times / minute), number of times the "Refresh" button is clicked]; Feature vector for "Counterpartner Selection Page": [Search keyword input speed (characters / second), time spent selecting a company (seconds), whether the selection has been modified (0 / 1)]; Finally, a behavioral feature vector to be verified is generated for each page that has been operated on.
[0092] Example: After extracting the user's behavior data on the "Quota Inquiry Page", the vector [1.5, 2.8, 1] is obtained (staying for 1.5 minutes, scrolling 2.8 times / minute, and refreshing once). On the "Counterpartner Selection Page", the vector [4.2, 35, 0] is obtained (input speed of 4.2 characters / second, selection time of 35 seconds, and selection not modified).
[0093] Beneficial effects: It transforms abstract user behavior into computable numerical vectors, providing a quantitative basis for subsequent similarity comparisons and ensuring the objectivity of the verification.
[0094] S400: Obtain the maximum similarity between each feature vector of the behavior to be verified and each feature vector of the standard operation behavior on the corresponding page.
[0095] For each page's feature vector to be verified, a similarity calculation is performed between it and several preset standard operational behavior feature vectors for that page (such as typical behavior vectors of historical normal users on that page). Common methods include cosine similarity and Euclidean distance. The largest similarity value is then taken.
[0096] Example: In a carbon trading platform, the standard feature vectors for the "Counterpartner Selection Page" are three: A = [5.0, 40, 0], B = [4.5, 30, 1], and C = [3.8, 35, 0]. The user's vector to be verified is [4.2, 35, 0]. The cosine similarities with A, B, and C are 0.82, 0.75, and 0.93, respectively. Therefore, the maximum similarity is 0.93.
[0097] Beneficial effect: By measuring the degree of matching between a user's current behavior and historical normal behavior, similarity measures provide a core basis for "confidence of the user's own actions".
[0098] S500 calculates the weighted sum of the maximum similarity of each feature vector of the behavior to be verified and the basic weight of the corresponding page to obtain the confidence score θ of the target user's own operation.
[0099] Step S500 includes the following steps:
[0100] S510, obtain the maximum similarity corresponding to each feature vector of the behavior to be verified, so as to obtain the maximum similarity list τ = (τ1, τ2, ..., τ3). a , ..., τ b ), a=1, 2,...,b; where, τ a Let be the maximum similarity corresponding to the a-th behavioral feature vector to be verified, and b be the number of behavioral feature vectors to be verified.
[0101] S520, obtain the basic weights of the page corresponding to each verification behavior feature vector, so as to obtain the list of basic weights of the operated page σ = (σ1, σ2, ..., σ...). a , …, σ b ); where σ a represents the base weight of the page corresponding to the a-th behavioral feature vector to be verified.
[0102] S530, determined based on τ and σ. SUM is the default summation function.
[0103] In this embodiment, the target platform has multiple pages. After logging in, the target user may not operate on all pages, but only on some. Based on the basic weight of each page, through σ... a / SUM(σ) redetermines the final weight of each page for the target user's actions.
[0104] By using basic weights to reflect the risk differences between different pages (high-risk pages have higher weights), the confidence level θ is made more consistent with actual risk assessment, avoiding excessive interference from the behavior of low-risk pages on the results.
[0105] The above steps have at least the following beneficial effects:
[0106] Highlighting the core impact of high-risk operations: In the numerator calculation, the similarity (τ1 = 0.92) of high-weight pages (such as transfer pages σ1 = 0.574) contributes approximately 0.528 to the weighted value, accounting for more than 60% of the total numerator. This ensures that θ can effectively reflect the legitimacy of high-risk operations. If the similarity of high-risk pages is low (such as τ1 = 0.6), θ will decrease significantly, allowing for timely identification of anomalies.
[0107] The range of θ is intuitive and controllable: By dividing by SUM(σ), θ is constrained between 0 and 1, which makes it more intuitive to compare with the preset threshold QR (e.g., 0.8) (e.g., θ = 0.878 ≥ 0.8, no fingerprint verification is triggered; θ = 0.75 < 0.8, verification is triggered), avoiding θ from exceeding the reasonable range due to fluctuations in the total weight.
[0108] Balancing security and user experience: If a user operates normally on a high-risk page (τ1 is high), even if there are slight fluctuations on a low-risk page (e.g., τ3 = 0.78), θ can still maintain a high value (e.g., 0.878), without triggering fingerprint verification, thus reducing the operational burden on legitimate users; if a user operates abnormally on a high-risk page (τ1 is low), θ will drop rapidly, blocking the risk in time, which meets the carbon trading platform's requirement of "security first, convenience second".
[0109] In summary, S510-S530 transforms a user's multi-page operation behavior into a single, intuitive "confidence level θ of personal operation" through the logic of "structured similarity sorting → binding corresponding weights → weighted normalization calculation". It focuses on high-risk operations on the carbon trading platform and ensures the controllability of the results through normalization, providing a scientific and accurate quantitative basis for subsequent decisions on "whether to trigger fingerprint verification".
[0110] S600, if θ≥QR, then the preset fingerprint verification task is not triggered; otherwise, the fingerprint verification task is triggered; where QR is the preset confidence threshold for the user's own operation.
[0111] In this embodiment, QR can be determined in the following way:
[0112] 1. Collect historical operational data from the past 6-12 months (covering peak and off-peak carbon trading seasons).
[0113] Positive samples: "Normal operation by the individual" confirmed by fingerprint verification (θ is calculated based on the similarity and weight at that time);
[0114] Negative samples: "Abnormal operations not performed by the user" that have been blocked (such as account theft or simulated operations, the identity of the actual operator must be indicated).
[0115] For example, the carbon trading platform collected 10,000 positive samples (operated by the user) and 500 negative samples (operated by someone other than the user).
[0116] 2. Statistical analysis of θ distribution and ROC curve analysis
[0117] The distribution of θ values for positive and negative samples was analyzed separately: the θ values for positive samples are usually concentrated between 0.75 and 0.95 (behavior conforms to the standard pattern);
[0118] Negative samples typically have a value θ between 0.4 and 0.7 (behavior deviates from the standard pattern); plot the ROC curve (Respondent Operating Characteristic curve): with θ as the threshold, the horizontal axis represents the false positive rate (misjudgment rate: the user's operation is judged as abnormal) and the vertical axis represents the true positive rate (the probability of correctly identifying the user's operation); the θ value corresponding to the point closest to the top left corner of the curve is the optimal QR (at which point the false negative rate and misjudgment rate are both the lowest).
[0119] 3. Threshold fine-tuning and implementation
[0120] If the carbon trading platform has higher security requirements (such as core operations like quota transfer), it can raise the threshold by 0.05-0.1 (e.g., optimal value 0.8 → QR = 0.85) to further reduce the false negative rate; if it has higher convenience requirements (e.g., saving drafts of non-core emission data), it can lower the threshold by 0.03-0.05 (e.g., optimal value 0.8 → QR = 0.77).
[0121] This step triggers secondary verification only when the credibility of the behavior is insufficient, solving the problem of cumbersome processes caused by "mandatory verification of all critical operations" and balancing security and user experience.
[0122] S700: If the target user's fingerprint verification is successful, the target user's current operation behavior is executed; otherwise, a preset security task is executed.
[0123] If fingerprint verification passes (matching the user's fingerprint template stored on the platform), the user is deemed a legitimate user and the current operation is executed (such as completing carbon quota transfer and generating a transaction certificate). If fingerprint verification fails (multiple matching failures or failure to verify within the specified time), a preset security task is executed, such as suspending the current operation, locking the account for 1 hour, or sending an abnormal operation alert to the enterprise administrator (including operation time, IP address, and other information).
[0124] Fingerprint verification serves as the ultimate security barrier, ensuring the authenticity of high-risk operations. At the same time, security tasks promptly block illegal operations, protecting the company's carbon asset security.
[0125] In summary, this method, through the logic of "dynamic behavior tracking - quantitative confidence assessment - condition-triggered verification," not only solves the problem of traditional static authentication being unable to address account theft, but also avoids the tediousness of frequent secondary verification, achieving a balance between security and convenience in carbon trading platforms.
[0126] In this embodiment, on the one hand, by dynamically tracking and comparing user behavior data across various operation pages for specific operation types after login, continuous verification of user identity is achieved, rather than relying solely on static authentication during the initial login phase. This allows for timely identification of abnormal operations after account theft, reducing the risk of corporate carbon asset loss and maintaining platform trading order. On the other hand, by calculating the user's operation confidence level and comparing it with a threshold, fingerprint verification is triggered only when the confidence level is insufficient. This avoids the cumbersome process of forcibly performing secondary verification for all critical operations. While ensuring the security of high-risk operations, it reduces the verification frequency for legitimate users and simplifies the operation process. Thus, an effective balance is achieved between the security of the carbon trading platform and the convenience of user operation, ensuring the platform's safe operation while improving the user experience.
[0127] Furthermore, although the steps of the method in this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in that specific order, or that all the steps shown must be performed to achieve the desired result. Additional or alternative steps may be omitted, multiple steps may be combined into one step, and / or a step may be broken down into multiple steps.
[0128] Embodiments of the present invention also provide a non-transitory computer-readable storage medium that can be disposed in an electronic device to store at least one instruction or at least one program related to implementing a method in the method embodiments, wherein the at least one instruction or the at least one program is loaded and executed by the processor to implement the method provided in the above embodiments.
[0129] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0130] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting programs for use by or in conjunction with an instruction execution system, apparatus, or device.
[0131] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0132] Program code for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0133] Embodiments of the present invention also provide an electronic device, including a processor and the aforementioned non-transitory computer-readable storage medium.
[0134] The electronic device is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments in this application.
[0135] Electronic devices are manifested in the form of general-purpose computing devices. Components of an electronic device may include, but are not limited to: at least one processor, at least one memory, and a bus connecting different system components (including memory and processor).
[0136] The memory stores program code that can be executed by the processor, causing the processor to perform the steps in the various embodiments described in this specification.
[0137] The memory may include readable media in the form of volatile memory, such as random access memory (RAM) and / or cache memory, and may further include read-only memory (ROM).
[0138] The memory may also include programs / utilities having a set (at least one) of program modules, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.
[0139] A bus can represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus that uses any of the various bus structures.
[0140] Electronic devices can also communicate with one or more external devices (e.g., keyboards, pointing devices, Bluetooth devices, etc.), one or more devices that enable user interaction with the electronic device, and / or any device that enables the electronic device to communicate with one or more other computing devices (e.g., routers, modems, etc.). This communication can be achieved through input / output (I / O) interfaces. Furthermore, electronic devices can communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via network adapters. The network adapter communicates with other modules of the electronic device via a bus. It should be understood that other hardware and / or software modules can be used in conjunction with the electronic device, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0141] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or network device, etc.) to execute the methods according to the embodiments of this disclosure.
[0142] Embodiments of the present invention also provide a computer program product including program code, which, when the program product is run on an electronic device, causes the electronic device to perform the steps of the methods described above in various exemplary embodiments of the present invention.
[0143] While specific embodiments of the invention have been described in detail by way of examples, those skilled in the art should understand that the examples are for illustrative purposes only and are not intended to limit the scope of the invention. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the invention.
Claims
1. An identity authentication method based on fingerprint recognition and identity identification, characterized in that, The method includes the following steps: S100, in response to the current operation behavior of the target user after logging into the target platform, obtain the type of the current operation behavior; the target platform includes several pages; each page corresponds to several preset standard operation behavior feature vectors and a preset basic weight; the basic weight is obtained through the historical operation behavior data of several historical users on the corresponding page; the standard behavior feature vector is obtained by clustering the historical user operation behavior data to obtain the center vector representing the mainstream operation mode; the basic weight is positively correlated with the effective data ratio of the standard operation behavior feature vector of the page, and negatively correlated with the dispersion of the standard operation behavior feature vector of the page; S130, if the type of the current operation is a preset first operation type, then respond directly; wherein, the security level of the first operation type is lower than the security level of the second operation type; S200, if the type of the current operation behavior is a preset second operation type, then obtain the operation behavior data of the target user on each operation page within the time range from logging into the target platform to the current time point; S300, extract features from the target user's operation behavior data on each operation page from logging into the target platform to the current time point, so as to obtain the behavior feature vector to be verified corresponding to each operation page; S400, obtain the maximum similarity between each feature vector of the behavior to be verified and each feature vector of the standard operation behavior of the corresponding page; S500, based on the maximum similarity corresponding to each feature vector of the behavior to be verified and the basic weight of the corresponding page, determine the confidence level θ of the target user's own operation; Step S500 includes the following steps: S510, obtain the maximum similarity corresponding to each feature vector of the behavior to be verified, so as to obtain the maximum similarity list τ = (τ1, τ2, ..., τ... a , ..., τ b ), a=1, 2,...,b; where, τ a Let b be the maximum similarity corresponding to the a-th behavioral feature vector to be verified, and b be the number of behavioral feature vectors to be verified. S520, obtain the basic weights of the page corresponding to each verification behavior feature vector, so as to obtain the list of basic weights of the operated page σ = (σ1, σ2, ..., σ...). a , …, σ b ); where σ a The base weights of the page corresponding to the a-th feature vector of the behavior to be verified; S530, determined based on τ and σ. SUM is the default summation function. S600, if θ≥QR, then the preset fingerprint verification task is not triggered; otherwise, the fingerprint verification task is triggered; where QR is the preset confidence threshold for the user's own operation. S700: If the fingerprint verification of the target user is successful, then the current operation behavior of the target user is executed; otherwise, a preset security task is executed.
2. The identity authentication method based on fingerprint recognition and identity identification according to claim 1, characterized in that, The standard operation behavior feature vector for each page is obtained through the following steps: S110, Divide the preset historical time period into several sub-historical time periods of equal duration to obtain a list of sub-historical time periods T = (T1, T2, ..., T...). i ,…,T n ), i = 1, 2, ..., n; where T i Let n be the i-th sub-historical time period obtained by dividing the preset historical time period, and n be the number of sub-historical time periods obtained by dividing the preset historical time period. S111, for any page YM, obtain several standard user operation behavior feature vectors corresponding to YM in each sub-historical time period of T, so as to obtain a list set A = (A1, A2, ..., A...) of standard user operation behavior feature vectors corresponding to T. i A n ); where A i For T i The corresponding standard user operation behavior feature vector list; A i = (A i,1 A i,2 A i,j A i,f(i) ), j=1,2,…,f(i);A i,j For YM in T i The j-th standard user operation behavior feature vector corresponding to YM in T, f(i) is the feature vector of YM in T. i The number of standard user operation behavior feature vectors corresponding to the content; S112, use a preset clustering algorithm to cluster the standard user operation behavior feature vectors in A to obtain a cluster list B = (B1, B2, ..., B...). p B q ), p=1,2,…,q; where, B p To obtain the p-th cluster through clustering, q is the number of clusters obtained through clustering; S113, iterate through B, if B p The number of standard user action behavior feature vectors within NUM p ≥NUM YM Then B p Identified as the target cluster; NUM YM This is the threshold for the number of intra-cluster vectors corresponding to YM; S114, determine the center vector corresponding to each target cluster as the standard operation behavior feature vector corresponding to YM.
3. The identity authentication method based on fingerprint recognition and identity identification according to claim 2, characterized in that, The basic weight corresponding to each page is obtained through the following steps: S120, obtain the number of target clusters corresponding to each page, the number of standard user operation behavior feature vectors within the target cluster, and the total number of standard user operation behavior feature vectors, to obtain the list of quantity groups η = (η1, η2, ..., η) corresponding to each page. x ,…,η y ),x=1,2,…,y; where, η x Let η be the number of pages corresponding to the x-th page, and y be the number of pages corresponding to the target platform. x =(α x , λ x γ x ); α x , λ x and γ x The numbers are, in order, the number of target clusters corresponding to the x-th page, the number of standard user operation behavior feature vectors within the target cluster, and the total number of standard user operation behavior feature vectors; S121, Based on η, determine the basic weight corresponding to each page to obtain the basic weight list ω = (ω1, ω2, ..., ω...). x ,…,ω y ); where ω x ω is the base weight of the x-th page; x With α x / α max It is negatively correlated with λ. x / (λ x +γ x ) are positively correlated; α max This represents the maximum number of target clusters across all pages.
4. The identity authentication method based on fingerprint recognition and identity identification according to claim 3, characterized in that, ω x Determined through the following steps: S11, according to α x , λ x and γ x Determine the original weight r of page x. x =(λ x / (λ x +γ x ))×1 / ((α) x / α max )+1); S12, according to r x ,Sure .
5. The identity authentication method based on fingerprint recognition and identity identification according to claim 1, characterized in that, The operational behavior data includes: click records, browsing records, page dwell time for different types of information, mouse wheel scrolling frequency, and cursor movement records.
6. The identity authentication method based on fingerprint recognition and identity identification according to claim 2, characterized in that, The preset clustering algorithm is the DBSCAN clustering algorithm.
7. A non-transitory computer-readable storage medium, wherein the storage medium stores at least one instruction or at least one program segment, characterized in that, The at least one instruction or the at least one program segment is loaded and executed by the processor to implement the identity authentication method based on fingerprint recognition and identity identification as described in any one of claims 1-6.
8. An electronic device, characterized in that, Includes a processor and the non-transitory computer-readable storage medium as described in claim 7.