OneID authentication method based on artificial intelligence path matching

By constructing a user-side operation sequence chain and multiple evaluation indicators, the shortcomings of existing OneID authentication methods in comprehensive analysis are solved, achieving efficient risk identification and security improvement for the user side.

CN121283720BActive Publication Date: 2026-04-21JING AN YUNXIN
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
JING AN YUNXIN
Filing Date
2025-09-29
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing OneID authentication methods only monitor anomalies for a single operation node or a single dimension, failing to conduct comprehensive analysis based on the complete operation chain implemented by the user end. This results in insufficient authentication accuracy and security when dealing with the illegal use of legitimate credentials and complex automated attacks.

Method used

By acquiring user terminal operation data in multiple scenarios, a historical operation time sequence chain is constructed, normal operation time sequence chains are identified, abnormal operation nodes are locked, abnormal operation time sequence chains are formed, and through various evaluation indicators such as operation jump characterization value, abnormal interaction rhythm and data flow path characteristics, it is determined whether the user terminal is a suspicious user terminal and the OneID is frozen.

Benefits of technology

It effectively identifies potentially risky user clients, improves the accuracy and security of authentication, avoids misjudgments, captures automated script attacks and covert data transmission behaviors, and achieves accurate inference from abnormal behavior to malicious intent.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121283720B_ABST
    Figure CN121283720B_ABST
Patent Text Reader

Abstract

This invention relates to the field of path matching analysis, and more particularly to a OneID authentication method based on artificial intelligence path matching. This invention acquires operation data from several user terminals using the same OneID in multiple scenarios to construct several historical operation time-series chains for each user terminal. Based on the corresponding trigger frequency and the number of user terminals triggering these chains, it identifies normal operation time-series chains. Based on the user terminal's operation path trajectory, it identifies abnormal operation nodes and tracks a predetermined number of subsequent operation nodes to form abnormal operation time-series chains. These chains are then matched with the historical operation time-series chains of several user terminals to determine the corresponding matching operation time-series chains and matching user terminals. The matching degree of the operation time-series chains and the level difference of the user terminals are identified, and the operation jump characterization value of the user terminals is evaluated. The user terminals are then marked and evaluated. This invention integrates multiple evaluation indicators to effectively identify potentially risky user terminals, improving the accuracy and security of authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of path matching analysis, and in particular to a OneID authentication method based on artificial intelligence path matching. Background Technology

[0002] As digital transformation deepens, unified identity management across different application systems and service scenarios for users has become increasingly important. OneID (Unified Identity) technology emerged to address this need, aiming to provide users with a seamless login and access experience across platforms and scenarios. However, this convenience also brings new security challenges: once OneID credentials are compromised, attackers could gain access to all of a user's associated systems, posing a serious security risk.

[0003] Chinese Patent Application Publication No. CN116030059A discloses a target ID re-authentication matching method and system based on trajectory. This method classifies the starting point of the trajectory as H points and the ending point as T points. Different identities of the same target are matched based on trajectory characteristics. The H temporary storage unit stores scanned H points that do not match T points, the S temporary storage unit stores matched HT point pairs, and the T temporary storage unit stores scanned T points that do not match H points and T points from the S temporary storage unit. The trajectory of the mismatched target is then re-matched to obtain the matching result. This invention can match two segments of the same target's motion trajectory that are disconnected within a short time, achieving high matching accuracy and tracking precision, while requiring less data processing and ensuring real-time re-authentication.

[0004] However, the following problems still exist in the existing technology.

[0005] Anomaly monitoring only targets a single operation node or a single dimension, failing to conduct comprehensive analysis based on the complete operation chain implemented by the user end. This results in significant deficiencies in responding to threats such as "legitimate credentials being used illegally" and complex automated attacks, thereby reducing the accuracy and security of authentication. Summary of the Invention

[0006] To address this, the present invention provides a OneID authentication method based on artificial intelligence path matching, which overcomes the problem that existing technologies only monitor anomalies for a single operation node or a single dimension, failing to comprehensively analyze the complete operation chain implemented by the user end. This results in significant deficiencies in dealing with threats such as "legitimate credentials, illegal use" and complex automated attacks, thereby reducing the accuracy and security of authentication.

[0007] To achieve the above objectives, the present invention provides a OneID authentication method based on artificial intelligence path matching, comprising:

[0008] Obtain operation data of several user terminals based on the same OneID in multiple scenarios, and construct several historical operation time sequence chains of the user terminals;

[0009] Based on the triggering frequency of each historical operation timing chain and the number of corresponding triggering user terminals, identify the normal operation timing chain;

[0010] The operation path trajectory of the user terminal is acquired in real time, and a predetermined number of subsequent operation nodes are determined based on the locked abnormal operation nodes to form an abnormal operation sequence chain.

[0011] The abnormal operation timing chain is matched with the historical operation timing chains of several user terminals to determine the corresponding matching operation timing chain and matching user terminal. The matching degree of the operation timing chain and the level difference of the user terminal are identified, and the operation jump characterization value of the user terminal is calculated to mark the user terminal.

[0012] In response to the user terminal being marked, the traffic transmission characteristics of the corresponding scene port under the abnormal interaction rhythm of the user terminal are obtained, so as to analyze the operation risk characterization parameters of the user terminal and determine whether the user terminal is a suspicious user terminal.

[0013] Identify the data flow path, and based on the data reception characteristics corresponding to the end node of the data flow path and the jump probability from the abnormal operation node to the end node, evaluate the abnormal depth representation value of the user terminal to determine whether to freeze the corresponding OneID.

[0014] The traffic transmission characteristics include the amount of data transmitted through the port and the duration of data transmission, while the data reception characteristics include the increase in reception rate and the deviation in reception rate.

[0015] Furthermore, the process of identifying the normal operating sequence chain includes:

[0016] If any operation timing chain meets the normal operation conditions, then the operation timing chain is identified as the normal operation timing chain;

[0017] The normal operating conditions include a trigger frequency greater than a trigger frequency threshold and a corresponding number of triggered user terminals greater than a user terminal number threshold.

[0018] Furthermore, the process of identifying the matching degree of the operation sequence chain and the level difference of the user end includes:

[0019] The system retrieves the user's operation path and the corresponding operation nodes of several historical operation sequence chains.

[0020] The historical operation sequence chain with the most overlapping operation nodes with the operation path trajectory is taken as the matching operation sequence chain, and the corresponding number of overlaps is taken as the matching degree of the operation sequence chain.

[0021] A number of historical user terminals corresponding to the timing chain that can trigger the matching operation are identified, the lowest-level historical user terminal among the historical user terminals is identified as the matching user terminal, and the level difference is determined based on the level weight of the user terminal and the matching user terminal.

[0022] The user-side ranking weights are preset.

[0023] Further, the process of calculating the operation jump representation value of the user terminal includes:

[0024] The ratio of the matching degree threshold to the matching degree of the operation sequence chain is used as the first operation jump feature;

[0025] The ratio of the user's level difference to the level difference threshold is used as the second operation jump feature.

[0026] The sum of the first operation jump feature and the second operation jump feature is used as the operation jump characterization value.

[0027] Furthermore, the user terminal is marked, including:

[0028] If the user terminal's operation jump representation value is greater than or equal to the operation jump representation threshold, then the user terminal is marked.

[0029] Furthermore, the abnormal interaction rhythm is determined based on the time interval between user-side switching between multiple scenes using the same OneID and the uniformity of scene dwell time, wherein,

[0030] If the time interval between multiple scene switching is less than the time interval threshold, and the uniformity of scene dwell time is less than the uniformity threshold, it is identified as an abnormal interaction rhythm.

[0031] Furthermore, the process of analyzing the operational risk characterization parameters of the user terminal includes:

[0032] The ratio of the amount of data transmitted through the port to the threshold amount of data transmitted through the port is used as the first operational risk characteristic.

[0033] The ratio of the duration of transmitted data to a duration threshold is used as the second operational risk characteristic.

[0034] The sum of the first operational risk feature and the second operational risk feature is used as the operational risk characterization parameter.

[0035] Further, determining whether the user terminal is a suspicious user terminal includes:

[0036] If the operational risk characterization parameter of the user terminal is greater than or equal to the operational risk characterization parameter threshold, then the user terminal is determined to be a suspicious user terminal.

[0037] Furthermore, the process of evaluating the abnormal depth representation value of the user terminal includes:

[0038] The sum of the ratio of the increase in receiving rate to the increase threshold and the ratio of the deviation in receiving rate to the deviation threshold is used as the first anomaly depth feature.

[0039] The ratio of the jump probability threshold to the jump probability of abnormal operation nodes and terminal nodes is used as the second anomaly depth feature.

[0040] The first anomaly depth feature and the second anomaly depth feature are weighted and summed to determine the anomaly depth representation value.

[0041] Further, determining whether to freeze the corresponding OneID includes:

[0042] If the abnormal depth representation value of the user terminal is greater than or equal to the abnormal depth representation threshold, then the OneID corresponding to the user terminal will be frozen.

[0043] Compared with existing technologies, this invention acquires operation data from several user terminals based on the same OneID across multiple scenarios to construct several historical operation time-series chains for the user terminals. Based on the triggering frequency of each historical operation time-series chain and the number of corresponding triggering user terminals, it identifies normal operation time-series chains. It acquires the operation path trajectory of the user terminals in real time, locks abnormal operation nodes, and tracks a predetermined number of subsequent operation nodes to form abnormal operation time-series chains. It matches these abnormal operation time-series chains with the historical operation time-series chains of several user terminals to determine the corresponding matching operation time-series chains and matching user terminals. It identifies the matching degree of the operation time-series chains and the level difference of the user terminals, evaluates the operation jump characterization value of the user terminals, and marks the user terminals accordingly. In response to the marking of a user terminal, it performs evaluation and analysis on the user terminal. This invention integrates multiple evaluation indicators to effectively identify potentially risky user terminals, improving the accuracy and security of authentication.

[0044] In particular, this invention is based on screening and identifying user terminals whose behavioral patterns do not match historical behavioral patterns. It considers the anomalies presented by the operational sequence chain of these user terminals, and measures the degree of overlap between the current operational sequence and historical normal sequences by matching the operational sequence chain. This characterizes the deviation of the user terminal's behavioral pattern, captures sudden changes in user terminal behavior, and, compared to anomaly assessment of individual operational nodes, analyzes the matching degree of the entire operational sequence chain, effectively avoiding misjudgments caused by occasional user terminal errors or system fluctuations. By quantifying the difference in user terminal levels between the current user terminal level and the lowest user terminal level that would normally trigger the operational sequence, it reflects the severity of the anomaly risk and can identify the typical attack pattern of "low-level users attempting to execute high-level operations." Furthermore, as a very rigid constraint based on user attributes, when a low-level user terminal triggers a seemingly complex path, its suspicious identity can be determined based on the difference in user terminal levels that could trigger that path, thereby effectively intercepting potential risks. Therefore, this invention combines the behavioral characteristics and subject characteristics presented by the user terminal under the same OneID to calculate the user terminal's operation jump representation value. This value characterizes the degree of abnormal risk caused by deviations in user terminal behavior patterns and mismatches in user terminal operations, providing data support for subsequent user terminal labeling. This invention integrates multiple evaluation indicators to effectively identify potentially risky user terminals, improving the accuracy and security of authentication.

[0045] In particular, this invention considers the potential data transmission risks arising from multi-scenario interactions on the user end, and conducts in-depth data transmission traffic analysis on the user end. First, it analyzes the degree of anomaly in the timing patterns of user end operations to effectively detect automated script attacks. While a user end operated by a real person requires thought and operational time to switch between different scenarios, a script can complete a large number of scenario switches instantly, or exhibit abnormally consistent dwell time in each scenario. Furthermore, by analyzing the uniformity of the time intervals between scenario switches and the dwell time, abnormal interaction rhythms can be effectively identified.

[0046] Furthermore, when abnormal rhythms are triggered, the degree of abnormality in the content patterns of the corresponding network behavior is observed, extending the focus from "when the operation occurred" and "how the operation occurred" to "what was operated," identifying abnormal risk attacks. The amount of data transmitted through ports reflects the likelihood of data theft / leakage, as well as the capture of content from corresponding nodes, thus greatly improving the reliability of risk assessment. Moreover, the duration of data transmission reflects the continuity of data transmission. Even when the user's operation on an operational node has been completed or switched to another operational node, data transmission continues in the background, forming an uninterrupted data stream. This allows for the capture of hidden background activities, identifying behaviors where the front end appears normal, but malicious data transmission is occurring in the background. Therefore, this invention analyzes the operational risk characterization parameters of the user end to characterize the degree of abnormality of the user's operational behavior, thereby reflecting the suspiciousness of the user's true potential intent and providing data support for subsequent determination of whether the user end is suspicious. This invention integrates multiple evaluation indicators to effectively identify potentially risky user ends, improving the accuracy and security of authentication.

[0047] In particular, this invention achieves accurate inference from abnormal behavior to malicious intent by analyzing the final flow of data and identifying anomalies in transmission methods. The increase in the receiving rate reflects the degree of abnormality in the receiver's data retrieval speed. Under normal circumstances, the data receiving rate changes steadily or slowly. However, malicious programs attempting to steal data as quickly as possible will retrieve data at the fastest speed, causing a sharp spike in the receiving rate within a short period. The degree of this increase reflects the abnormality of the operational behavior. By comparing the receiving rate with the normal receiving rate, the determined deviation reflects the stability of the receiver's behavioral pattern and measures the degree of deviation. Normal applications driven by user interaction will have a data receiving rate that fluctuates around a relatively stable average value with a small range of fluctuation. In contrast, a malicious program driven by instability or multiple strategies may exhibit a receiving rate that fluctuates wildly, showing great instability. Furthermore, the normal operation path of the user usually follows a certain logical order. By analyzing the probability that the user can jump from an abnormal operation node to the corresponding terminal node, the attack pattern of "jumping access" can be effectively identified. Therefore, this invention assesses the anomaly depth representation value of the user terminal to characterize the maliciousness of the user terminal's actions, providing data support for subsequent determination of whether to freeze the corresponding OneID. This invention integrates multiple evaluation indicators to effectively identify potentially risky user terminals, improving the accuracy and security of authentication. Attached Figure Description

[0048] Figure 1 A schematic diagram illustrating the steps of the OneID authentication method based on artificial intelligence path matching, as an embodiment of the invention;

[0049] Figure 2 This is a logic decision diagram for marking the user terminal in an embodiment of the invention;

[0050] Figure 3 A logic diagram for determining whether a user terminal is a suspicious user terminal in an embodiment of the invention;

[0051] Figure 4 This is a logic diagram for determining whether to freeze the corresponding OneID in an embodiment of the invention. Detailed Implementation

[0052] To make the objectives and advantages of the present invention clearer, the present invention will be further described below with reference to embodiments; it should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.

[0053] Preferred embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0054] It should be noted that in the description of this invention, the terms "upper", "lower", "left", "right", "inner", "outer", etc., which indicate directions or positional relationships, are based on the directions or positional relationships shown in the accompanying drawings. This is only for the convenience of description and is not intended to indicate or imply that the device or element must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation of this invention.

[0055] Furthermore, it should be noted that, in the description of this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0056] Please see Figure 1 The diagram illustrates the steps of the OneID authentication method based on artificial intelligence path matching according to an embodiment of the present invention. The OneID authentication method based on artificial intelligence path matching according to an embodiment of the present invention includes:

[0057] Step S1: Obtain operation data of several user terminals based on the same OneID in multiple scenarios, and construct several historical operation time sequence chains of the user terminals;

[0058] Step S2: Identify normal operation timing chains based on the triggering frequency of each historical operation timing chain and the number of corresponding triggering user terminals;

[0059] Step S3: Real-time acquisition of the user terminal's operation path trajectory; determination of a predetermined number of subsequent operation nodes based on the locked abnormal operation nodes; forming an abnormal operation sequence chain.

[0060] Step S4: Match the abnormal operation timing chain with the historical operation timing chains of several user terminals to determine the corresponding matching operation timing chain and matching user terminal, identify the matching degree of the operation timing chain and the level difference of the user terminal, and calculate the operation jump characterization value of the user terminal to mark the user terminal;

[0061] Step S5: In response to the user terminal being marked, obtain the traffic transmission characteristics of the scene port corresponding to the abnormal interaction rhythm of the user terminal, so as to analyze the operation risk characterization parameters of the user terminal and determine whether the user terminal is a suspicious user terminal.

[0062] Step S6: Identify the data flow path, and based on the data receiving characteristics corresponding to the end node of the data flow path and the jump probability from the abnormal operation node to the end node, evaluate the abnormal depth representation value of the user terminal to determine whether to freeze the corresponding OneID.

[0063] The traffic transmission characteristics include the amount of data transmitted through the port and the duration of data transmission, while the data reception characteristics include the increase in reception rate and the deviation in reception rate.

[0064] Specifically, the operation data includes the triggering frequency of the operation sequence chain, the number of corresponding triggering user terminals, the time interval between user terminals switching between multiple scenes based on the same OneID, the uniformity of scene dwell time, and the jump probability from abnormal operation nodes to end nodes. In order to ensure that sufficient information before and after the user terminal performs an operation can be captured, a small segment of operation behavior trajectory is observed after the user terminal triggers an abnormal operation node. Therefore, in this implementation, the predetermined number is set to 5.

[0065] Specifically, the operation sequence chain refers to a directed and ordered sequence of operation nodes, which records a series of operations performed by a single user terminal based on the same OneID in a continuous time period in chronological order, where one operation corresponds to one operation node;

[0066] Understandably, in a digital office environment, real-time monitoring of user operations is crucial for enterprise management and security. Therefore, relevant monitoring software, such as WorkWin, can be used to monitor user operations in real time. Based on this, visualization tools, such as PlantUML, can be combined to generate operation sequence chains, clearly presenting the order and relationship of user operations, thereby obtaining relevant operation data. This will not be elaborated further.

[0067] Specifically, there are no specific limitations on the methods for collecting and acquiring traffic transmission characteristics and data reception characteristics. Enterprise-level monitoring systems, such as Zabbix, can be used for real-time collection and monitoring, which will not be elaborated further.

[0068] Specifically, a scenario refers to the functional interface, set of pages, or interaction stage that a user enters when accessing and using a related application system based on the same OneID, and that has a specific business function or purpose. Examples include product browsing scenarios and form creation scenarios.

[0069] Specifically, the process of identifying the normal operating sequence chain includes:

[0070] If any operation timing chain meets the normal operation conditions, then the operation timing chain is identified as the normal operation timing chain;

[0071] The normal operating conditions include a trigger frequency greater than a trigger frequency threshold and a corresponding number of triggered user terminals greater than a user terminal number threshold.

[0072] In this embodiment, the purpose of setting the trigger frequency threshold and the user terminal number threshold is to characterize the complete operation behavior performed by the user terminal as normal operation behavior and non-abnormal operation behavior. By obtaining historical operation data of several user terminals based on the same OneID in multiple scenarios, calling the historical trigger frequency data of several historical operation sequence chains and the corresponding historical trigger user terminal number data, the average trigger frequency and the average user terminal number are calculated and used as the benchmark value under normal circumstances. Based on the purpose of setting the above two thresholds, the trigger frequency threshold is determined as the product of the average trigger frequency and the trigger deviation coefficient, and the user terminal number threshold is determined as the product of the average user terminal number and the number deviation coefficient. The trigger deviation coefficient is selected in the interval [1.2, 1.3], preferably 1.2 in the implementation, and the number deviation coefficient is selected in the interval [1.4, 1.5], preferably 1.4 in the implementation.

[0073] It is understandable that during the implementation of office work in an enterprise, there may be situations where several user terminals perform the same task. In this case, the operation nodes on the operation sequence chain and the corresponding order of the operation nodes are the same. Therefore, in this embodiment, the triggering frequency is determined based on the number of times the operation sequence chain is operated within a predetermined time, and the number of user terminals corresponding to the triggering of the operation sequence chain is determined based on the number of user terminals that can perform operations on any operation sequence chain.

[0074] Considering that a task is phased from start to finish, and that different tasks require different operations to complete, in order to ensure the real-time effectiveness of the constructed operation sequence chain, the predetermined time is set to 5 days in this embodiment.

[0075] Specifically, the process of identifying the matching degree of the operation sequence chain and the level difference of the user end includes:

[0076] The system retrieves the user's operation path and the corresponding operation nodes of several historical operation sequence chains.

[0077] The historical operation sequence chain with the most overlapping operation nodes with the operation path trajectory is taken as the matching operation sequence chain, and the corresponding number of overlaps is taken as the matching degree of the operation sequence chain.

[0078] A number of historical user terminals corresponding to the timing chain that can trigger the matching operation are identified, the lowest-level historical user terminal among the historical user terminals is identified as the matching user terminal, and the level difference is determined based on the level weight of the user terminal and the matching user terminal.

[0079] The user-side ranking weights are preset.

[0080] In this embodiment, the user terminal level weight is determined according to the enterprise's internal organizational structure. Since the organizational structure is a systematic arrangement of the roles, responsibilities, powers and relationships of all members of the enterprise, the weight coefficient of the user terminal corresponding to each level is increased by 0.2 from bottom to top according to the vertical hierarchy in the organizational structure. Of course, those skilled in the art can also use other methods to divide the user terminal level weight, which will not be elaborated here.

[0081] Specifically, the process of calculating the operation jump representation value of the user terminal includes:

[0082] The ratio of the matching degree threshold to the matching degree of the operation sequence chain is used as the first operation jump feature;

[0083] The ratio of the user's level difference to the level difference threshold is used as the second operation jump feature.

[0084] The sum of the first operation jump feature and the second operation jump feature is used as the operation jump characterization value.

[0085] In this embodiment, the purpose of setting the matching degree threshold and the level difference threshold is to characterize the degree to which the user's operation behavior deviates from the norm, thus increasing the possibility of abnormal risks. By acquiring historical operation data of several users based on the same OneID in multiple scenarios, the historical matching degree data of the corresponding operation sequence chain and the historical level difference data of the user are called to solve for the mean matching degree and the mean level difference, which are then used as the benchmark values ​​under normal circumstances. Based on the purpose of setting the above two thresholds, the matching degree threshold is determined as the product of the mean matching degree and the matching deviation coefficient, and the level difference threshold is determined as the product of the mean level difference and the level deviation coefficient. The matching deviation coefficient is selected in the interval [0.85, 0.95], preferably 0.85 in the implementation, and the level deviation coefficient is selected in the interval [1.2, 1.3], preferably 1.2 in the implementation.

[0086] Specifically, this invention identifies user terminals whose behavioral patterns do not match historical behavioral patterns. It considers the anomalies presented by the operational sequence chain of these user terminals, quantifies the overlap between the current operational sequence and historical normal sequences by measuring the matching of the operational sequence chain, characterizes the deviation of the user terminal's behavioral pattern, and captures sudden changes in user terminal behavior. Furthermore, compared to anomaly assessment of individual operational nodes, analyzing the matching degree of the entire operational sequence chain effectively avoids misjudgments caused by occasional user terminal errors or system fluctuations. The invention quantifies the difference between the current user terminal's level and the lowest user terminal level that would normally trigger the operational sequence by measuring the level difference between user terminals, reflecting the severity of the anomaly risk. This can identify the typical attack pattern of "low-level users attempting to execute high-level operations." Simultaneously, as a very rigid constraint based on user attributes, when a low-level user terminal triggers a seemingly complex path (high matching degree), its suspicious identity can also be determined based on the level difference between user terminals that can trigger that path, thereby effectively intercepting potential risks. Therefore, this invention combines the behavioral characteristics and subject characteristics presented by the user terminal under the same OneID to calculate the user terminal's operation jump representation value. This value characterizes the degree of abnormal risk caused by deviations in user terminal behavior patterns and mismatches in user terminal operations, providing data support for subsequent user terminal labeling. This invention integrates multiple evaluation indicators to effectively identify potentially risky user terminals, improving the accuracy and security of authentication.

[0087] Specifically, please refer to Figure 2 As shown, this is a logic decision diagram for marking the user terminal according to an embodiment of the present invention. Marking the user terminal includes:

[0088] If the user terminal's operation jump representation value is greater than or equal to the operation jump representation threshold, then the user terminal is marked.

[0089] If the user's operation jump representation value is less than the operation jump representation threshold, then there is no need to mark the user.

[0090] The operation jump threshold is predetermined. The operation jump characterization value calculated when the matching degree threshold is equal to the matching degree of the operation sequence chain and the user's level difference is equal to the level difference threshold is determined as the operation jump characterization threshold.

[0091] Specifically, the abnormal interaction rhythm is determined based on the time interval between multiple scene switching based on the same OneID on the user's end and the uniformity of scene dwell time, wherein,

[0092] If the time interval between multiple scene switching is less than the time interval threshold, and the uniformity of scene dwell time is less than the uniformity threshold, it is identified as an abnormal interaction rhythm.

[0093] In this embodiment, the purpose of setting the time interval threshold and the uniformity threshold is to characterize the situation where the current operation behavior performed by the user terminal is highly abnormal and deviates significantly from the time pattern operated by a real person. By acquiring historical operation data of several user terminals based on the same OneID in multiple scenarios, calling historical time interval data and historical uniformity data of scene dwell time of several user terminals based on the same OneID in multiple scenarios, the mean of time interval and the mean of uniformity are calculated. Based on the purpose of setting the above two thresholds, the time interval threshold is determined as the product of the mean of time interval and the first deviation coefficient, and the uniformity threshold is determined as the product of the mean of uniformity and the second deviation coefficient. The first deviation coefficient is selected in the interval [0.95, 0.98], preferably 0.95 in the implementation, and the second deviation coefficient is selected in the interval [0.9, 0.95], preferably 0.9 in the implementation.

[0094] Specifically, the standard deviation of the dwell time in each scenario is calculated as the uniformity of the dwell time in the scenario. The smaller the standard deviation, the more uniform the dwell time of the user terminal in each scenario, which in turn reflects the higher probability that the operation performed by the current user terminal is an attack type such as automated script attack.

[0095] Specifically, the process of analyzing the operational risk characterization parameters of the user terminal includes:

[0096] The ratio of the amount of data transmitted through the port to the threshold amount of data transmitted through the port is used as the first operational risk characteristic.

[0097] The ratio of the duration of transmitted data to a duration threshold is used as the second operational risk characteristic.

[0098] The sum of the first operational risk feature and the second operational risk feature is used as the operational risk characterization parameter.

[0099] In this embodiment, the purpose of setting the port transmission data volume threshold and the duration threshold is to characterize situations where the user terminal's operational behavior is highly abnormal and the user terminal's true potential intent is highly suspicious. By acquiring historical operation data of several user terminals based on the same OneID in multiple scenarios, calling the historical data flow paths of several suspicious user terminals, identifying the historical data of port transmission data volume and the historical data of transmission duration of the terminal nodes of the data flow path, and solving for the average port transmission data volume and the average duration, based on the purpose of setting the above two thresholds, the port transmission data volume threshold is determined as the average port transmission data volume and the transmission deviation coefficient, and the duration threshold is determined as the product of the average duration and the duration deviation coefficient. The transmission deviation coefficient is selected within the interval [1.2, 1.25], preferably 1.2 in the implementation, and the duration deviation coefficient is selected within the interval [1.1, 1.2], preferably 1.1 in the implementation.

[0100] Specifically, this invention considers the potential data transmission risks arising from multi-scenario interactions on the user end and conducts in-depth data transmission traffic analysis on the user end. First, it analyzes the degree of anomaly in the timing patterns of user end operations to effectively detect automated script attacks. While a user end operated by a real person requires thought and operational time to switch between different scenarios, a script can complete a large number of scenario switches instantly or exhibit abnormally consistent dwell time in each scenario. Furthermore, by analyzing the uniformity of the time intervals between scenario switches and the dwell time, abnormal interaction rhythms can be effectively identified.

[0101] Furthermore, when abnormal rhythms are triggered, the degree of abnormality in the content patterns of the corresponding network behavior is observed. This extends the analysis from "when the operation occurred" and "how the operation occurred" to "what was operated," identifying anomalous risk attacks. The volume of data transmitted through ports reflects the likelihood of data theft / leakage, such as large-scale data transmission within a short period and the scraping of content from corresponding nodes, such as rapid and large-scale downloading of corresponding page data or resources. For example, if a user client rapidly switches between scenarios, generating continuous data transmission traffic far exceeding normal user client activity in each scenario, it indicates the possibility of data crawling or theft, greatly enhancing the reliability of risk assessment. Moreover, the duration of data transmission reflects the continuity of data transmission. Even after the user client has completed its operation on a specific node or switched to another node, data transmission continues in the background, forming an uninterrupted data stream. This allows for the capture of hidden background activities, identifying behaviors where the front end appears normal, but malicious data transmission is occurring in the background. Therefore, this invention analyzes operational risk characterization parameters on the user terminal to characterize the degree of abnormality of the user terminal's operational behavior, thereby reflecting the suspiciousness of the user terminal's true potential intent and providing data support for subsequent determination of whether the user terminal is suspicious. This invention integrates multiple evaluation indicators to effectively identify potentially risky user terminals, improving the accuracy and security of authentication.

[0102] Specifically, please refer to Figure 3 As shown, this is a logic diagram for determining whether a user terminal is a suspicious user terminal according to an embodiment of the present invention. Determining whether the user terminal is a suspicious user terminal includes:

[0103] If the operational risk characterization parameter of the user terminal is greater than or equal to the operational risk characterization parameter threshold, then the user terminal is determined to be a suspicious user terminal.

[0104] If the operational risk characterization parameter of the user terminal is less than the operational risk characterization parameter threshold, then the user terminal is determined not to be a suspicious user terminal.

[0105] The operational risk characterization parameter threshold is predetermined. The operational risk characterization parameter is determined by calculating the amount of data transmitted at the port and the duration of data transmission, which are equal to the port data transmission threshold and the duration of data transmission, which are equal to the duration threshold.

[0106] Specifically, the process of evaluating the abnormal depth representation value of the user terminal includes:

[0107] The sum of the ratio of the increase in receiving rate to the increase threshold and the ratio of the deviation in receiving rate to the deviation threshold is used as the first anomaly depth feature.

[0108] The ratio of the jump probability threshold to the jump probability of abnormal operation nodes and terminal nodes is used as the second anomaly depth feature.

[0109] The first anomaly depth feature and the second anomaly depth feature are weighted and summed to determine the anomaly depth representation value.

[0110] Specifically, data reception characteristics, as an indicator of the degree of abnormality in user-side operations, can suggest that the data transmission method is too "aggressive," but cannot directly prove that the user's target is malicious. However, the redirection probability provides evidence of the user's true intent, directly pointing to the user's attack target. A low-probability redirection suggests that the attacker may have bypassed regular security checkpoints to attempt to obtain more valuable sensitive data. Therefore, the second anomaly depth feature, calculated based on the redirection probability of abnormal operation nodes and terminal nodes, is given a higher weight coefficient, set to 0.6, while the first anomaly depth feature, calculated based on data reception characteristics—namely, the increase in reception rate and the deviation in reception rate—is given a weight coefficient of 0.4.

[0111] In this embodiment, the purpose of setting the increase threshold, deviation threshold, and jump probability threshold is to characterize the high degree of malice of the operation behavior performed by the user terminal. By acquiring historical operation data of several user terminals based on the same OneID in multiple scenarios, and calling historical data of the increase in receiving rate, historical data of the deviation in receiving rate, and historical data of the jump probability of the corresponding locked abnormal operation nodes and end nodes of the data flow path corresponding to the user terminal, based on the purpose of setting the above three thresholds, the increase threshold is determined as the product of the average increase value and the first offset coefficient, the deviation threshold is determined as the product of the average deviation value and the second offset coefficient, and the jump probability threshold is determined as the product of the average jump probability and the third offset coefficient. The first offset coefficient is selected in the interval [1.2, 1.25], preferably 1.2 in the implementation; the second offset coefficient is selected in the interval [1.15, 1.2], preferably 1.15 in the implementation; and the third offset coefficient is selected in the interval [0.9, 0.95], preferably 0.9 in the implementation.

[0112] Specifically, based on the data reception rate of the end node at each time, a standard deviation of the reception rate is determined as the deviation of the reception rate to reflect the degree of fluctuation of the reception rate. The larger the standard deviation, the more unstable the reception rate and the more severe the fluctuation.

[0113] Specifically, by acquiring several historical operation time sequence chain data corresponding to the user terminal, the proportion of the number of times that an abnormal operation node can directly jump to the corresponding end node is determined to be the jump probability.

[0114] Specifically, this invention achieves accurate inference from abnormal behavior to malicious intent by analyzing the final flow of data and identifying anomalies in transmission methods. The increase in the receiving rate reflects the degree of abnormality in the receiver's data retrieval speed. Under normal circumstances, the data receiving rate changes steadily or slowly. However, malicious programs attempting to steal data as quickly as possible will retrieve data at the fastest speed, causing the receiving rate to spike dramatically in a short period. The degree of abnormality in the operational behavior is reflected by the magnitude of the increase in the receiving rate; the larger the increase, the more abnormal the behavior, and the more likely it is malicious behavior driven by automated scripts. By comparing the receiving rate with the normal receiving rate, the determined deviation reflects the stability of the receiver's behavioral pattern and measures the degree of deviation. Normal applications driven by user interaction will fluctuate around a relatively stable average data receiving rate with a small range of fluctuation. In contrast, a malicious program driven by unstable or multiple strategies may exhibit a highly unstable receiving rate, fluctuating wildly. Furthermore, normal user operation paths typically follow a certain logical order. Therefore, by assessing the probability that a user can jump from an abnormal operation node to the corresponding endpoint, "jump-access" attack patterns can be effectively identified. A lower jump probability indicates a rarer and more suspicious operation path. Thus, this invention evaluates the anomaly depth representation value of the user terminal to characterize the maliciousness of the user's actions, providing data support for subsequent determination of whether to freeze the corresponding OneID. This invention integrates multiple evaluation indicators to effectively identify potentially risky user terminals, improving the accuracy and security of authentication.

[0115] Specifically, please refer to Figure 4 As shown, this is a logic diagram for determining whether to freeze the corresponding OneID according to an embodiment of the present invention. Determining whether to freeze the corresponding OneID includes:

[0116] If the abnormal depth representation value of the user terminal is greater than or equal to the abnormal depth representation threshold, then the OneID corresponding to the user terminal will be frozen.

[0117] If the abnormal depth representation value of the user terminal is less than the abnormal depth representation threshold, there is no need to freeze the OneID corresponding to the user terminal.

[0118] The abnormal depth characterization threshold is predetermined. It is determined by calculating the abnormal depth characterization value when the increase in the receiving rate is equal to the increase threshold, the deviation in the receiving rate is equal to the deviation threshold, and the jump probability threshold is equal to the jump probability of the abnormal operation node and the end node.

[0119] If the OneID authentication method based on artificial intelligence path matching of the present invention is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to cause a computer device to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media that can store program code, such as USB flash drives, mobile hard drives, read-only memory, random access memory, magnetic disks, or optical disks.

[0120] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.

Claims

1. A OneID authentication method based on artificial intelligence path matching, characterized in that, include: Obtain operation data of several user terminals based on the same OneID in multiple scenarios, and construct several historical operation time sequence chains of the user terminals; Based on the triggering frequency of each historical operation timing chain and the number of corresponding triggering user terminals, identify the normal operation timing chain; The operation path trajectory of the user terminal is acquired in real time, and a predetermined number of subsequent operation nodes are determined based on the locked abnormal operation nodes to form an abnormal operation sequence chain. The abnormal operation timing chain is matched with the historical operation timing chains of several user terminals to determine the corresponding matching operation timing chain and matching user terminal. The matching degree of the operation timing chain and the level difference of the user terminal are identified, and the operation jump characterization value of the user terminal is calculated to mark the user terminal. In response to the user terminal being marked, the traffic transmission characteristics of the corresponding scene port under the abnormal interaction rhythm of the user terminal are obtained, so as to analyze the operation risk characterization parameters of the user terminal and determine whether the user terminal is a suspicious user terminal. Identify the data flow path, and based on the data reception characteristics corresponding to the end node of the data flow path and the jump probability from the abnormal operation node to the end node, evaluate the abnormal depth representation value of the user terminal to determine whether to freeze the corresponding OneID. The traffic transmission characteristics include the amount of data transmitted at the port and the duration of data transmission; the data reception characteristics include the increase in reception rate and the deviation in reception rate. The abnormal interaction rhythm is determined based on the time interval between multiple scene switching based on the same OneID on the user's end and the uniformity of scene dwell time, wherein, If the time interval between multiple scene switching is less than the time interval threshold, and the uniformity of scene dwell time is less than the uniformity threshold, it is identified as an abnormal interaction rhythm.

2. The OneID authentication method based on artificial intelligence path matching according to claim 1, characterized in that, The process of identifying the normal operating sequence chain includes: If any operation timing chain meets the normal operation conditions, then the operation timing chain is identified as the normal operation timing chain; The normal operating conditions include a trigger frequency greater than a trigger frequency threshold and a corresponding number of triggered user terminals greater than a user terminal number threshold.

3. The OneID authentication method based on artificial intelligence path matching according to claim 1, characterized in that, The process of identifying the matching degree of the operation sequence chain and the level difference of the user end includes: The system retrieves the user's operation path and the corresponding operation nodes of several historical operation sequence chains. The historical operation sequence chain with the most overlapping operation nodes with the operation path trajectory is taken as the matching operation sequence chain, and the corresponding number of overlaps is taken as the matching degree of the operation sequence chain. A number of historical user terminals corresponding to the timing chain that can trigger the matching operation are identified, the lowest-level historical user terminal among the historical user terminals is identified as the matching user terminal, and the level difference is determined based on the level weight of the user terminal and the matching user terminal. The user-side ranking weights are preset.

4. The OneID authentication method based on artificial intelligence path matching according to claim 1, characterized in that, The process of calculating the operation jump representation value of the user terminal includes: The ratio of the matching degree threshold to the matching degree of the operation sequence chain is used as the first operation jump feature; The ratio of the user's level difference to the level difference threshold is used as the second operation jump feature. The sum of the first operation jump feature and the second operation jump feature is used as the operation jump characterization value.

5. The OneID authentication method based on artificial intelligence path matching according to claim 4, characterized in that, Marking the user terminal includes: If the user terminal's operation jump representation value is greater than or equal to the operation jump representation threshold, then the user terminal is marked.

6. The OneID authentication method based on artificial intelligence path matching according to claim 1, characterized in that, The process of analyzing the operational risk characterization parameters of the user terminal includes: The ratio of the amount of data transmitted through the port to the threshold amount of data transmitted through the port is used as the first operational risk characteristic. The ratio of the duration of transmitted data to a duration threshold is used as the second operational risk characteristic. The sum of the first operational risk feature and the second operational risk feature is used as the operational risk characterization parameter.

7. The OneID authentication method based on artificial intelligence path matching according to claim 6, characterized in that, Determining whether the client is a suspicious client includes: If the operational risk characterization parameter of the user terminal is greater than or equal to the operational risk characterization parameter threshold, then the user terminal is determined to be a suspicious user terminal.

8. The OneID authentication method based on artificial intelligence path matching according to claim 1, characterized in that, The process of evaluating the anomaly depth representation value of the user terminal includes: The sum of the ratio of the increase in receiving rate to the increase threshold and the ratio of the deviation in receiving rate to the deviation threshold is used as the first anomaly depth feature. The ratio of the jump probability threshold to the jump probability of abnormal operation nodes and terminal nodes is used as the second anomaly depth feature. The first anomaly depth feature and the second anomaly depth feature are weighted and summed to determine the anomaly depth representation value.

9. The OneID authentication method based on artificial intelligence path matching according to claim 8, characterized in that, Determining whether to freeze the corresponding OneID includes: If the abnormal depth representation value of the user terminal is greater than or equal to the abnormal depth representation threshold, then the OneID corresponding to the user terminal will be frozen.

Citation Information

Patent Citations

  • Target ID re-authentication matching method and system based on trajectory

    CN116030059A

  • User identification method, device and apparatus based on data burying point, and storage medium

    CN111191201A

  • Financial risk early warning method and system based on big data technology

    CN119624661A