Real person verification method and system based on anti-refreshing mechanism

By using randomly generated base coordinates and a multi-step logical task verification process, combined with image rendering and user operation data analysis, the problem of insufficient security and high user experience complexity of existing verification methods is solved, achieving high security and low user burden authentication.

CN121508904APending Publication Date: 2026-02-10AI SUPER EYE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511447427.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-11
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing verification methods are not secure enough, are vulnerable to automated script attacks, and have a high user experience complexity, making them difficult to adapt to complex attack scenarios.

Method used

The verification process involves randomly generating basic coordinate tasks and multi-step logical tasks, combined with image rendering and meshing processing, to collect user operation data in real time and perform behavioral analysis. The verification results are then compared using multi-dimensional data.

Benefits of technology

It improves the security and reliability of verification, reduces the false positive rate, enhances the protection against automated attacks, and reduces the difficulty of user operation and waiting time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508904A_ABST
    Figure CN121508904A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security and identity verification, in particular to a real person verification method and system based on an anti-refreshing mechanism, and the method comprises the steps: responding to a user to execute a high-risk operation, triggering a verification process, and randomly generating a verification task; performing image rendering processing on the generated verification task to obtain a gridding image; the target user performs verification operation on the gridding image, and synchronously collects user operation data; performing behavior analysis on the collected user operation data to obtain a user verification operation report; and comparing the user verification operation report with a preset verification rule to obtain a verification result. The security and reliability of the verification method are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of network security and identity verification, and in particular to a real-person verification method and system based on an anti-fraud mechanism. Background Technology

[0002] In today's era of rapid development in internet technology, cybersecurity has become a core guarantee for the stable operation of various application systems. Human verification, as a key link in resisting automated script attacks and distinguishing between human and machine operations, directly affects the security defense of the system.

[0003] Existing verification methods have many shortcomings. Character CAPTCHAs have a high error rate due to distortion and interference lines; image CAPTCHAs require multiple clicks to pass due to low resolution or blurry annotations; image click verifications can be cracked in batches by OCR technology, and sliding puzzle verifications can be bypassed by scripts simulating uniform operation, and neither of them utilizes human logical reasoning ability, resulting in insufficient security; high-security CAPTCHAs are complex to operate and time-consuming; simple CAPTCHAs are easily breached by low-cost attacks and are difficult to adapt to complex attack scenarios. Therefore, there is an urgent need for a real-person verification method and system based on anti-fraud mechanisms. Summary of the Invention

[0004] This invention provides a real-person verification method and system based on an anti-fraud mechanism that improves the security and reliability of verification methods, and can effectively solve the problems in the background art.

[0005] To achieve the above objectives, in a first aspect, the present invention provides a real-person verification method based on an anti-fraud mechanism, comprising:

[0006] In response to a user performing a high-risk operation, a verification process is triggered, and a verification task is randomly generated.

[0007] The generated verification task is processed by image rendering to obtain a gridded image;

[0008] The target user performs a verification operation on the gridded image, and user operation data is collected synchronously.

[0009] Perform behavioral analysis on the collected user operation data to obtain user verification operation reports;

[0010] The user verification operation report is compared with the preset verification rules to obtain the verification result.

[0011] In conjunction with the first aspect, in one possible design, in response to a successful verification result, a cryptographic token is generated, allowing the user to continue to the next step.

[0012] In conjunction with the first aspect, in one possible design, in response to a failure in the verification result, if it is a low-risk scenario, a retry message is displayed and a new basic task is generated.

[0013] If it is a high-risk scenario, an upgrade verification will be triggered.

[0014] In conjunction with the first aspect, in one possible design, the high-risk operations include account login, fund transfer, modification of personal information, and linking bank cards.

[0015] In conjunction with the first aspect, in one possible design, the verification task includes one of a basic coordinate task and a multi-step logic task.

[0016] In conjunction with the first aspect, in one possible design, the gridded image comprises several grids, and each grid contains independent elements with random interference.

[0017] In conjunction with the first aspect, in one possible design, the random disturbance of the elements includes rotation processing, transparency gradients, and local noise.

[0018] In conjunction with the first aspect, in one possible design, the user operation data includes click coordinate data, time data, trajectory data, and device data.

[0019] In conjunction with the first aspect, in one possible design, the user verification operation report includes operation result compliance, behavioral characteristic score, and risk suspicion mark.

[0020] Secondly, the present invention also provides a real-person verification system based on an anti-fraud mechanism, comprising:

[0021] The verification trigger module responds to high-risk user actions by triggering the verification process and randomly generating verification tasks.

[0022] The image rendering module performs image rendering processing on the generated verification task to obtain a gridded image.

[0023] The data acquisition module collects user operation data synchronously when the target user performs a verification operation on the gridded image.

[0024] The behavior analysis module performs behavior analysis on the collected user operation data and obtains user verification operation reports.

[0025] The verification rule comparison module compares the user's verification operation report with the preset verification rules to obtain the verification result.

[0026] The technical solution of this invention can achieve the following technical effects:

[0027] By randomly generating verification tasks that include basic coordinate tasks and multi-step logical tasks, this method avoids the vulnerability of traditional CAPTCHAs such as character and image CAPTCHAs. The diversity and uncertainty of the verification tasks make it difficult for automated attack tools to bypass the verification process. Image rendering and meshing enhance the complexity of the verification tasks, solving traditional problems such as low resolution, blurriness, and interference lines. This ensures clear images that are difficult for image recognition software to crack in batches. By designing multi-step logical tasks, users are encouraged to perform logical reasoning and decision-making, which not only improves the security of the verification but also avoids the reliance on image recognition or simple click tasks found in traditional CAPTCHAs. The method can collect user operation data in real time and perform behavioral analysis, helping to identify the differences between normal users and automated scripts and improving the accuracy of the results. The method improves accuracy and reduces false positive rates; combined with anti-fraud mechanisms, it better handles complex attack scenarios; by continuously monitoring and analyzing user behavior, it can promptly identify and intercept potential automated attacks, enhancing its protective capabilities; high-security CAPTCHAs are typically complex and time-consuming to operate, while this method, through reasonable design of verification tasks, ensures sufficient security while avoiding a significant decline in user experience; users do not need to wait for long periods or perform complex tasks during verification; the method not only optimizes for simple attack methods but also considers countermeasures against various attack techniques, further improving security; the real-person verification method based on anti-fraud mechanisms enhances the security and reliability of the verification method by increasing task complexity, data analysis, and logical reasoning elements, while also reducing the operational difficulty for users. Attached Figure Description

[0028] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0029] Figure 1 This is a flowchart of the present invention;

[0030] Figure 2 This is a structural diagram of a real-person verification system based on an anti-fraud mechanism; Detailed Implementation

[0031] This application will now be described with reference to the accompanying drawings.

[0032] like Figure 1 As shown, the present invention provides a real-person verification method based on an anti-fraud mechanism, which specifically includes the following steps:

[0033] S1. In response to a user performing a high-risk operation, a verification process is triggered, and a verification task is randomly generated; the verification task includes one of a basic coordinate task and a multi-step logic task.

[0034] S2. Perform image rendering processing on the generated verification task to obtain a gridded image;

[0035] S3. The target user performs a verification operation on the gridded image, and user operation data is collected synchronously.

[0036] S4. Perform behavioral analysis on the collected user operation data to obtain a user verification operation report;

[0037] S5. The user verification operation report is compared with the preset verification rules to obtain the verification result.

[0038] In this embodiment, by randomly generating verification tasks including basic coordinate tasks and multi-step logical tasks, the shortcomings of traditional CAPTCHAs such as character CAPTCHAs and image CAPTCHAs, which are easily cracked, are avoided. The diversity and uncertainty of the verification tasks make it difficult for automated attack tools to bypass the verification process. The image rendering and meshing methods enhance the complexity of the verification tasks, solving traditional problems such as low resolution, blurriness, and interference lines. This ensures that the image is clear and difficult for image recognition software to crack in batches. By designing multi-step logical tasks, users can be prompted to perform logical reasoning and decision-making, which not only improves the security of verification but also avoids the reliance on image recognition or simple click tasks in traditional CAPTCHAs. The method can collect user operation data in real time and perform behavioral analysis, which helps to identify the differences between normal users and automated scripts. This method improves recognition accuracy and reduces false positive rates. Combined with anti-fraud mechanisms, it better handles complex attack scenarios. Through continuous monitoring and analysis of user behavior, it can promptly identify and intercept potential automated attacks, enhancing its protective capabilities. High-security CAPTCHAs are typically complex and time-consuming to operate; this method, through reasonable verification task design, ensures sufficient security while avoiding a significant decline in user experience. Users do not need to wait for long periods or perform complex tasks during verification. The method not only optimizes for simple attack methods but also considers countermeasures against various attack techniques, further improving security. The human verification method based on anti-fraud mechanisms enhances the security and reliability of the verification method by increasing task complexity, data analysis, and logical reasoning elements, while also reducing the difficulty of operation for users.

[0039] In some embodiments of the present invention, for step S1, in response to the user performing a high-risk operation, a verification process is triggered and a verification task is randomly generated.

[0040] High-risk operations refer to operations involving sensitive information or critical functions, including account login, fund transfer, modification of personal information, and linking bank cards; these operations need to be protected against unauthorized access by bots or automated scripts; when a user is identified as performing a high-risk operation, a verification process is automatically triggered;

[0041] The task generation engine randomly generates one of two types of verification tasks, including basic coordinate tasks and multi-step logic tasks;

[0042] Basic coordinate tasks are gridded positioning tasks based on the X and Y axes, such as "click the animal icon in the 3rd row and 2nd column" or "select the vehicle icon in the X=4, Y=5 area", which require users to complete the operation through spatial positioning;

[0043] Multi-step logical tasks are related operation tasks that combine logical reasoning, such as "first sort all icons in ascending order by the X-axis, then select the icon with the largest Y-axis value" or "after filtering out plant icons with X-axis values ​​greater than 3, click on the target with the smallest Y-axis value among them", which require users to complete multi-step logical related operations.

[0044] Each generated verification task is unique. The grid size, element type, and coordinate rules in the task are all randomly varied and do not rely on a fixed template, preventing attackers from cracking the verification logic through reverse engineering. At the same time, the task difficulty is fine-tuned according to the real-time risk level to ensure the effectiveness of the defense against automated scripts.

[0045] In this embodiment, verification is triggered for high-risk operations involving sensitive information or key functions, such as account login and fund transfer, to avoid interfering with normal low-risk operations. This ensures core security while reducing unnecessary operational burden on users. A task generation engine randomly generates basic coordinate tasks and multi-step logic tasks, fully utilizing human-specific spatial positioning and logical reasoning abilities. Compared to traditional single mechanical operation verification, this significantly increases the simulation threshold for robots or automated scripts. Each generated verification task is unique, with grid size, element type, and coordinate rules all changing randomly and not relying on a fixed template. This effectively prevents attackers from cracking the verification logic through reverse engineering. At the same time, the task difficulty can be fine-tuned according to the real-time risk level, flexibly responding to different attack intensities and continuously ensuring the effectiveness of the defense.

[0046] In some embodiments of the present invention, for step S2, the generated verification task is subjected to image rendering processing to obtain a gridded image; the gridded image includes a plurality of grids, and each grid includes independent elements, the elements being accompanied by random interference;

[0047] The purpose of generating a gridded image through image rendering is to increase the difficulty of the CAPTCHA task, prevent automated scripts from cracking it, and at the same time ensure that human users can complete the task through logical reasoning and judgment.

[0048] Select appropriate image content based on the generated task; to increase complexity, the image content needs to be deformed, including rotation, cropping, scaling, and color changes, to increase the difficulty of automated cracking;

[0049] Random perturbation elements are added to the generated images to interfere with the image recognition capabilities of the automated scripts. These random perturbation elements include rotation processing, transparency gradients, and local noise. By randomizing these perturbations, it is ensured that the generated images are unique for each verification, thereby enhancing the system's anti-fraud capabilities.

[0050] The rendered image is divided into several grids, each containing an independent element; the size, number, and shape of the grids vary depending on the task requirements.

[0051] Each element within a grid may be a graphic or symbol, or a piece of visual information related to other grid elements; these elements are mixed with random distracting elements, making it difficult for automated scripts to obtain the correct answer through simple image analysis.

[0052] In this embodiment, by adding random interference elements to the gridded image, the automated scripts are made more difficult to crack using image recognition technology; this increases the difficulty of cracking the CAPTCHA and effectively improves the system's anti-scraping capabilities; the image content is deformed, increasing the image's complexity and making it difficult for automated tools to solve the task through simple pattern recognition, thus improving the system's resistance to attacks; although the complexity of the CAPTCHA is increased, through reasonable design and image processing, it is ensured that human users can complete the verification task through logical reasoning and judgment, thereby not affecting the experience of normal users; through randomization processing during image rendering, each generated CAPTCHA image is unique, further improving the anti-scraping capabilities and avoiding the reuse or recognition of automated scripts; the grid division, element selection, and interference methods can all be adjusted according to specific task requirements, enhancing the system's flexibility and adaptability, and enabling it to cope with different types of automated attacks.

[0053] In some embodiments of the present invention, for step S3, the target user performs a verification operation on the gridded image, and user operation data is collected simultaneously; the user operation data includes click coordinate data, time data, trajectory data and device data;

[0054] The target user performs operations on the gridded image generated by the image rendering module according to the verification task prompts, including clicking on specific grids, dragging elements to sort, and continuously selecting targets. The interface guides the user to complete the operation through clear coordinate labels, reducing the understanding cost.

[0055] During user operations, user operation data is collected in real time. This user operation data includes:

[0056] Click coordinate data: Records the precise coordinates of each user click in the gridded image, used for subsequent verification of coordinate matching.

[0057] Time data: including operation response time and total operation time, used to distinguish between high-speed batch operations by machines and normal human reaction speed;

[0058] Trajectory data: Captures the movement path of the mouse or touch, including features such as trajectory curvature, acceleration, and pause points, and identifies common linear motion or uniform sliding patterns in scripts;

[0059] Device data: By combining device sensor information and device fingerprints, multimodal behavioral profiles are constructed to enhance the accuracy of identity differentiation.

[0060] In this embodiment, by recording click coordinates, time data, trajectory data, and device data, user operations can be accurately analyzed, ensuring the efficiency and accuracy of the verification process. Real-time collection of device and trajectory data effectively distinguishes between human users and machine scripts, improving authentication security and preventing interference from automated attacks and script operations. The interface guides users through clear coordinate markers, allowing them to intuitively understand the operation process and reducing cognitive burden and the likelihood of errors. Combining click coordinates, time, trajectory, and other data, the system can perform more detailed analysis, construct user behavior profiles, identify normal user operations, and distinguish them from automated operations, thereby enhancing the system's intelligent recognition capabilities. This step, while ensuring verification accuracy, improves system security, intelligence, and user experience through multi-dimensional data collection and analysis.

[0061] In some embodiments of the present invention, for step S4, behavioral analysis is performed on the collected user operation data to obtain a user verification operation report.

[0062] The coordinate data, time data, trajectory data, and device data in the user operation data are analyzed one by one.

[0063] Click coordinate data refers to the specific location where a user clicks in a gridded image. By analyzing the coordinate data, it can be determined whether the user follows a specific verification pattern. Normal user click behavior is usually orderly and may have some deviation. Robots or automated scripts, on the other hand, usually make precise or completely random clicks on the coordinates. Analyzing the accuracy, order, and relative positional relationships of these coordinates helps to determine whether the user's behavior is reasonable.

[0064] Time data refers to the specific timestamps when a user clicks on each grid element; by analyzing the response time of user operations, it can be determined whether the user is behaving abnormally; real user operations usually have a certain time interval, while automated scripts often exhibit a more regular operation pattern with almost no delay when executed; by statistically analyzing the distribution of time intervals, it is possible to effectively distinguish between normal users and scripts.

[0065] Trajectory data includes the mouse or touchscreen trajectory of a user during verification operations, recording the user's operation path as a series of continuous coordinate points. For real users, their operation trajectory is smooth and natural, and will show a certain non-linear and tortuous path. In contrast, robots or automated scripts often exhibit straight and regular click trajectories. By analyzing trajectory data, the system can identify the continuity and naturalness of the trajectory. If the trajectory shows an overly regular or mechanical pattern, it may be the behavior of an automated script.

[0066] Device data refers to the device information used by a user when performing a verification task, including device model, operating system, browser type, IP address, etc. It can help analyze the authenticity of the user and the uniqueness of the device. Multiple operations on the same device without obvious changes may be the behavior of a bot or script. Device data can reveal whether there is a shared device or proxy IP. Conversely, if the device information is abnormal, it may indicate that the attacker used a simulated device for disguise.

[0067] Based on the above analysis, a user verification operation report is obtained, which includes:

[0068] Operation result compliance: including coordinate matching degree and logical step completion degree;

[0069] Behavioral characteristic scoring: Quantitative scoring is conducted through dimensions such as trajectory naturalness, time reasonableness, and device interaction consistency;

[0070] Risk warning: If abnormal features such as ultra-high speed operation or overly regular trajectory are observed, they should be clearly marked in the report.

[0071] In this embodiment, by analyzing four types of data—coordinates, time, trajectory, and device—multi-dimensionally, the natural characteristics of human operation and the typical features of automated scripts are fully captured, enabling accurate differentiation between human and machine operations. This solves the problem of high false positive rates caused by traditional verification relying on only a single data dimension. By analyzing the accuracy, order, and relative positional relationships of coordinates, it is possible to identify whether the verification pattern is followed. By statistically analyzing the distribution of time intervals, regular operations of scripts can be effectively filtered out. By judging the continuity and naturalness of the trajectory, mechanized operation patterns can be identified. Through device data correlation analysis, risks such as shared devices, proxy IPs, or spoofed devices can be discovered. The risk and suspicion markers formed by multi-dimensional analysis significantly improve the defense capability against automated attacks.

[0072] In some embodiments of the present invention, for step S5, the user verification operation report is compared with the preset verification rules to obtain the verification result;

[0073] If the verification result is successful, an encrypted token is generated, and the user is allowed to continue to the next step;

[0074] If the verification result fails, a retry message will be displayed for low-risk scenarios, and a new basic task will be generated; if the result is high-risk scenarios, an upgrade verification will be triggered.

[0075] The preset verification rules include:

[0076] Basic coordinate task rules: For basic coordinate tasks, preset rules define the correct coordinate range; in a verification task of clicking a specific image area, the system will preset the coordinate boundary of that area in the gridded image; if the user's click coordinates fall within this preset range, then the operation conforms to the rules; if the click coordinates are outside the range, then it is judged as non-compliant; at the same time, the rules will also consider the accuracy tolerance of the click to accommodate the slight deviations that may exist in different user operations.

[0077] Multi-step logical task rules: For multi-step logical tasks, the correct order of each operation, the content of each operation, and the logical relationship between each step are specified in detail. In a multi-step logical task that requires the user to click different image elements in a specific order, the rules clearly specify which element should be clicked in the first step, which element should be clicked in the second step, and if the user operates in the wrong order or omits a step, it is judged as not conforming to the rules.

[0078] Comprehensive rules for operation data: In addition to the rules for the task itself, the preset rules also take into account the time data, trajectory data, and device data in the user's operation data. For time data, the rules will set a reasonable time range for completing the verification operation; if the user's operation is too fast or too slow, it may be judged as abnormal behavior. For trajectory data, the rules will analyze whether the user's click or swipe trajectory conforms to the characteristics of normal human operation, such as whether there are sudden jumps or irregular trajectories. For device data, the rules will check the device type, operating system version, IP address, and other information to determine whether there are abnormal devices or access from high-risk areas.

[0079] The system compares each piece of data recorded in the user's verification operation report with the preset verification rules one by one. For coordinate data, it calculates the distance between the user's click coordinates and the preset coordinate range to determine whether it is within the tolerance range. For time data, it calculates the difference between the actual time the user completed the operation and the preset reasonable time range to determine whether it exceeds the range. Through comprehensive comparison, it determines whether the user's operation conforms to the preset rules.

[0080] When all data in the user's verification operation report meets the preset verification rules, the system determines that the verification result is passed; this indicates that the user's operation behavior is consistent with the characteristics of a normal human user, and there is a high probability that it is a real user performing the operation, rather than an automated script or a malicious attacker.

[0081] If any data in the user's verification operation report does not meet the preset verification rules, the system determines that the verification result is failed; this means that the user's operation may be abnormal, which may be the attack behavior of the automated script, or the user's operation error.

[0082] When the verification result is successful, an encrypted token is generated. The encrypted token is a unique and secure identifier, containing the user's relevant information and a timestamp indicating that the verification was successful. The encrypted token serves as the user's credential for passing the real-person verification and is used for identity verification and authorization in the user's subsequent operations. After the encrypted token is generated, the user can continue to perform the high-risk operations that originally triggered the verification process.

[0083] When the verification fails, in low-risk scenarios, if the verification fails, the user is prompted to retry; if the system assumes that the user's operation was due to an accidental error, the user is given another chance to try; the system will prompt "Verification failed, please try again" and guide the user to perform the verification operation again; at the same time, a new basic task is generated for the user to re-verify; the new basic task will be different from the previous task to prevent attackers from cracking the verification by repeatedly trying the same task.

[0084] In high-risk scenarios, if the verification result fails, the system will trigger an upgrade verification; the upgrade verification adopts a more complex and stricter verification method to further improve security.

[0085] In this embodiment, by comparing coordinates, time, trajectory, and device data, the system can accurately determine whether a user's operation conforms to predetermined rules, reducing the risk of automated scripts or malicious attacks. Based on the verification results, the system can intelligently determine the risk level of the operation. In low-risk scenarios, the system only prompts the user to retry and generates a new task, while in high-risk scenarios, it triggers a more stringent upgrade verification to further protect the security of the user and the system. By setting accuracy tolerance and a reasonable time range, the system takes into account the differences in user operations and can effectively handle anomalies caused by user misoperation or environmental factors, improving the user experience. For different risk levels in different scenarios, the system will dynamically adjust the verification method, simply prompting a retry in low-risk situations and ensuring higher security through upgrade verification in high-risk situations. After successful verification, the system will generate an encrypted token as a security credential, which not only effectively proves the legitimacy of the user's identity but also ensures the security of the system in subsequent operations, preventing unauthorized access. Through multi-dimensional comprehensive analysis of tasks, the system can effectively identify automated attacks and malicious behaviors, enhancing the system's protection capabilities.

[0086] like Figure 2 As shown, the present invention also provides a real-person verification system based on an anti-fraud mechanism, which specifically includes the following modules;

[0087] The verification trigger module responds to high-risk user actions by triggering the verification process and randomly generating verification tasks.

[0088] The image rendering module performs image rendering processing on the generated verification task to obtain a gridded image.

[0089] The data acquisition module collects user operation data synchronously when the target user performs a verification operation on the gridded image.

[0090] The behavior analysis module performs behavior analysis on the collected user operation data and obtains user verification operation reports.

[0091] The verification rule comparison module compares the user's verification operation report with the preset verification rules to obtain the verification result.

[0092] In this embodiment, by randomly generating verification tasks including basic coordinate tasks and multi-step logical tasks, the shortcomings of traditional CAPTCHAs such as character CAPTCHAs and image CAPTCHAs, which are easily cracked, are avoided. The diversity and uncertainty of the verification tasks make it difficult for automated attack tools to bypass the verification process. The image rendering and meshing methods enhance the complexity of the verification tasks, solving traditional problems such as low resolution, blurriness, and interference lines. This ensures that the image is clear and difficult for image recognition software to crack in batches. By designing multi-step logical tasks, users are prompted to perform logical reasoning and decision-making, which not only improves the security of verification but also avoids the reliance on image recognition or simple click tasks found in traditional CAPTCHAs. The system can collect user operation data in real time and perform behavioral analysis, which helps to identify the differences between normal users and automated scripts. The system improves recognition accuracy and reduces false positive rates; combined with anti-fraud mechanisms, it better handles complex attack scenarios; through continuous monitoring and analysis of user behavior, it can promptly identify and intercept potential automated attacks, enhancing its protection capabilities; high-security CAPTCHAs are typically complex and time-consuming to operate, but this system, through reasonable design of verification tasks, ensures sufficient security while avoiding a significant decline in user experience; users do not need to wait for long periods or perform complex tasks during verification; the system is optimized not only for simple attack methods but also considers countermeasures against various attack methods, further improving security; the real-person verification system based on anti-fraud mechanisms enhances the security and reliability of the verification system by increasing task complexity, data analysis, and logical reasoning elements, while also reducing the operational difficulty for users.

[0093] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.

Claims

1. A real-person verification method based on an anti-fraud mechanism, characterized in that, include: In response to a user performing a high-risk operation, a verification process is triggered, and a verification task is randomly generated. The generated verification task is processed by image rendering to obtain a gridded image; The target user performs a verification operation on the gridded image, and user operation data is collected synchronously. Perform behavioral analysis on the collected user operation data to obtain user verification operation reports; The user verification operation report is compared with the preset verification rules to obtain the verification result.

2. The real-person verification method based on an anti-fraud mechanism according to claim 1, characterized in that, If the verification result is successful, an encrypted token is generated, and the user is allowed to continue to the next step.

3. The real-person verification method based on an anti-fraud mechanism according to claim 1, characterized in that, If the verification result fails, and it is a low-risk scenario, a message asking for a retry will be displayed, and a new basic task will be generated. If it is a high-risk scenario, an upgrade verification will be triggered.

4. The real-person verification method based on an anti-fraud mechanism according to claim 1, characterized in that, The high-risk operations include account login, fund transfer, modification of personal information, and linking bank cards.

5. The real-person verification method based on an anti-fraud mechanism according to claim 1, characterized in that, The verification task includes one of the following: a basic coordinate task and a multi-step logic task.

6. The real-person verification method based on an anti-fraud mechanism according to claim 1, characterized in that, The gridded image comprises several grids, and each grid contains independent elements with random interference.

7. The real-person verification method based on an anti-fraud mechanism according to claim 6, characterized in that, The random disturbances to the elements include rotation processing, transparency gradients, and local noise.

8. The real-person verification method based on an anti-fraud mechanism according to claim 1, characterized in that, The user operation data includes click coordinate data, time data, trajectory data, and device data.

9. The real-person verification method based on an anti-fraud mechanism according to claim 1, characterized in that, The user verification operation report includes the compliance of the operation results, behavioral characteristic scores, and risk and suspicion markers.

10. A real-person verification system based on an anti-fraud mechanism, characterized in that, include: The verification trigger module responds to high-risk user actions by triggering the verification process and randomly generating verification tasks. The image rendering module performs image rendering processing on the generated verification task to obtain a gridded image. The data acquisition module collects user operation data synchronously when the target user performs a verification operation on the gridded image. The behavior analysis module performs behavior analysis on the collected user operation data and obtains user verification operation reports. The verification rule comparison module compares the user's verification operation report with the preset verification rules to obtain the verification result.