Security authentication method and device and storage medium
By constructing a dynamic security policy model that combines user operating habits, environmental context, and authentication behavior characteristics, the authentication policy is adjusted in real time, solving the problem of insufficient adaptability of traditional authentication methods in large-scale, distributed authentication requests, and improving security and user experience.
Patent Information
- Application Number
- CN202511674592.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-14
- Publication Date
- 2026-02-10
AI Technical Summary
Traditional secure communication methods lack the ability to dynamically adapt to changes in user behavior and environment when faced with large-scale, distributed authentication requests, leading to incorrect authentication results or a degraded user experience.
By acquiring user operation habit data, environmental context data, and authentication behavior characteristics, a dynamic security policy model is constructed to adjust the authentication policy in real time. Combined with matching evaluation index and correlation coefficient, the authentication process is optimized.
It improves the security and flexibility of the authentication system, effectively responding to large-scale, distributed authentication requests and dynamic environmental changes, ensuring the security and reliability of communication.
Smart Images

Figure CN121508970A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more specifically, to a secure authentication method, device, and storage medium. Background Technology
[0002] Cloud computing, as a crucial platform supporting data processing and storage, has become an indispensable technological infrastructure for enterprises and individuals. Particularly in the field of secure communication, cloud computing provides a powerful dynamic resource pool, enabling efficient data processing and complex authentication mechanisms. Secure communication technologies primarily focus on the confidentiality and integrity of data transmission, as well as the authentication of both the sender and receiver. Traditional secure communication methods rely on static authentication methods such as passwords and digital certificates, which have been widely adopted over the past decade. However, with the increasing prevalence of cloud services and the growing number of users and devices joining cloud platforms, authentication mechanisms face more complex challenges, especially when handling large-scale, distributed authentication requests. Traditional methods lack the dynamic adaptability to changes in user behavior and the environment, often failing to adjust authentication strategies in real time, leading to incorrect authentication results or a degraded user experience. Summary of the Invention
[0003] This application provides a secure authentication method and constructs a security strategy model to improve the security and flexibility of the secure authentication system.
[0004] To achieve the above objectives, the embodiments of the present invention adopt the following technical solutions: In a first aspect, this application provides a security authentication method, which includes: obtaining a user's request for security authentication; obtaining first data, which characterizes the user's operation of performing the security authentication; obtaining second data, which characterizes the environment in which the user performs the security authentication; and determining a response strategy for the security authentication based on the first data and the second data.
[0005] The method can adjust the authentication strategy in real time in response to changes in the geographical location of the user device and changes in ambient light and sound conditions, thereby further improving the efficiency of security authentication and ensuring the security and reliability of communication.
[0006] Furthermore, the method also includes acquiring third data, the third data being used to characterize the user's behavioral features during the security authentication; determining the security authentication response strategy based on the first data and the second data includes: determining the security authentication response strategy based on the first data, the second data, and the third data.
[0007] Furthermore, the method also includes the following: the first data includes the user's operation habit data, which includes at least one of the following: password input habit data, which includes at least one of the following: the user's input speed, error rate, and frequently used character positions; and access habit data, which includes at least one of the following: the user's access frequency, duration, and applications used.
[0008] Furthermore, the method also includes the second data comprising the environmental context data of the user authentication, the environmental context data comprising at least one of the following: light intensity; sound feature parameters; geographical location change distance.
[0009] Furthermore, the method also includes the third data comprising at least one of the following: historical authentication data, which includes the time, result, and frequency of each security authentication performed by the user; and network behavior data, which includes at least one of the following: monitored data traffic, website categories accessed, and network connection duration.
[0010] Furthermore, the method further includes: acquiring fourth data, the fourth data being used to characterize the user's historical security authentication operations; obtaining a first matching evaluation index based on the first data and the fourth data, the first matching evaluation index being used to indicate the consistency between the user's security authentication operations and the historical security authentication operations; and determining the security authentication response strategy based on the first data and the second data, including: determining the security authentication response strategy based on the first matching evaluation index and the second data.
[0011] Furthermore, the method further includes: acquiring fifth data, the fifth data being used to characterize the environment in which the user performed historical security authentication; obtaining a second matching evaluation index based on the second data and the fifth data, the second matching evaluation index being used to represent the consistency between the environment in which the user performed the security authentication and the environment in which the user performed the historical security authentication; and determining the response strategy for the security authentication based on the first data and the second data, including: determining the response strategy for the security authentication based on the first data and the second matching evaluation index.
[0012] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: obtaining authentication results; performing correlation analysis between the historical authentication data and the authentication results to obtain a first correlation coefficient; performing correlation analysis between the network behavior data and the authentication results to obtain a second correlation coefficient; and determining the response strategy for security authentication based on the first data and the second data includes: determining the response strategy for security authentication based on the first data, the second data, the first correlation coefficient, and the second correlation coefficient.
[0013] In a second aspect, this application provides a communication device, characterized in that the device includes: a processor, a memory, and a communication bus; the communication bus is used to realize a communication connection between the processor and the memory; the processor is used to execute a program in the memory to implement the steps of any of the methods described.
[0014] A computer-readable storage medium, characterized in that the computer-readable storage medium stores one or more programs, which can be executed by one or more processors to implement the steps of any of the methods described.
[0015] A computer program product comprising a computer program, characterized in that the computer program, when executed by a processor, implements any one of the methods described above. The communication method, device, computer storage medium, and computer program product provided in this invention construct a dynamic security policy adjustment model by comprehensively analyzing user operating habits, environmental context, and authentication behavior characteristics, combined with a first matching evaluation index and a second matching evaluation index. This solution not only significantly improves the security of the authentication system but also enhances its flexibility and adaptability, enabling it to more effectively cope with large-scale, distributed authentication requests and dynamic environmental changes, ensuring the security and reliability of communication. Attached Figure Description
[0016] Figure 1 This is a schematic diagram of the security authentication method applicable to this application; Figure 2 This is a flowchart illustrating a security authentication method provided in an embodiment of this application.
[0017] Figure 3 This is a schematic diagram of a security authentication method provided in an embodiment of this application. Detailed Implementation
[0018] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0019] This application provides a security authentication method, referring to... Figure 1 This method can be applied to communication systems, communication devices, or communication modules, and may include the following steps: Step 101: Obtain the user's request for security authentication; Step 102: Obtain first data, which is used to characterize the user's operation of performing the security authentication. In this embodiment of the application, obtaining the first data includes obtaining user operation habit data. First, each authentication is marked, and user operation habit data of the communication terminal during the authentication process is collected. This data is then uploaded to the cloud service platform for the authentication module to perform user behavior analysis.
[0020] Step 103: Obtain second data, which is used to characterize the environment in which the user performs the security authentication; In this embodiment of the application, obtaining the second data includes obtaining user environment context data, and this data will be uploaded to the cloud service platform for the authentication module to perform user behavior analysis.
[0021] Step 104: Determine the response strategy for the security authentication based on the first data and the second data.
[0022] The response strategy can be a security adjustment index based on a certain value range. By analyzing the first and second data and selecting an appropriate authentication strategy, the security of the authentication system is significantly improved, and its flexibility and adaptability are enhanced. This allows it to effectively cope with large-scale, distributed authentication requests and environmental changes, ensuring the security and reliability of communication.
[0023] Step 105, the method further includes obtaining third data, the third data being used to characterize the user's behavioral features during the security authentication; The step of determining the security authentication response strategy based on the first data and the second data includes: determining the security authentication response strategy based on the first data, the second data, and the third data. Specifically, after obtaining the third data, the third data is uploaded to the cloud service platform for the authentication module to perform user behavior analysis.
[0024] In this embodiment, the user operation habit data may include the user's password input habits and terminal access habits, etc.; the environmental context data may include the light intensity, sound characteristic parameters, and geographical location change distance of the terminal's environment, etc.; and the authentication behavior characteristics may include historical authentication data and network behavior data, etc. This embodiment constructs a dynamic security policy adjustment model by comprehensively analyzing the user's operation habit data, environmental context data, and authentication behavior characteristic data. This model selects an appropriate authentication strategy based on the analysis results, thereby improving the system's security and flexibility.
[0025] In this embodiment of the application, the first data includes the user's operation habit data, which includes at least one of the following: password input habit data, which includes at least one of the following: the user's input speed, error rate, and frequently used character positions; and access habit data, which includes at least one of the following: the user's access frequency, duration, and applications used.
[0026] The second data includes the environmental context data of the user authentication, which includes at least one of the following: light intensity; sound feature parameters; and distance of geographical location change.
[0027] The third data includes at least one of the following: historical authentication data, which includes the time, result, and frequency of each security authentication performed by the user; and network behavior data, which includes at least one of the following: monitored data traffic, types of websites accessed, and network connection duration.
[0028] By comprehensively analyzing the above data, a dynamic security strategy can be constructed that can effectively cope with large-scale, distributed authentication requests and dynamic environmental changes, accurately identify potential security risks, and take timely and effective security measures to ensure the security and reliability of communication.
[0029] Furthermore, embodiments of this application also include: Step 106, the method further includes: obtaining fourth data, the fourth data being used to characterize the user's historical security authentication operations; obtaining a first matching evaluation index based on the first data and the fourth data, the first matching evaluation index being used to indicate the consistency between the user's security authentication operations and the historical security authentication operations; determining the security authentication response strategy based on the first data and the second data includes: determining the security authentication response strategy based on the first matching evaluation index and the second data.
[0030] Furthermore, embodiments of this application also include: Step 107: Obtain fifth data, which is used to characterize the environment in which the user performed historical security authentication; obtain a second matching evaluation index based on the second data and the fifth data, which is used to represent the consistency between the environment in which the user performed the security authentication and the environment in which the user performed the historical security authentication; determining the response strategy for the security authentication based on the first data and the second data includes: determining the response strategy for the security authentication based on the first data and the second matching evaluation index.
[0031] Based on the first and second matching evaluation indices, relevant authentication strategies can be adjusted in real time and dynamically to improve the security and reliability of communication.
[0032] In an embodiment of this application, the first data used to characterize the user's security authentication operation includes: the first data used to characterize the user's nth security authentication operation, where n is a positive integer greater than or equal to 2; the fourth data used to characterize the user's historical security authentication operations includes: the fourth data used to characterize the user's mth to oth security authentication operations, where m and o are positive integers less than n, and o is greater than m; a first matching evaluation index is obtained based on the first data and the fourth data, and the first matching evaluation index is used to represent the consistency between the user's security authentication operations and the historical security authentication operations.
[0033] In embodiments of this application, the second data used to characterize the environment in which the user performs the security authentication includes: the second data used to characterize the environment in which the user performs the security authentication for the nth time, where n is a positive integer greater than or equal to 2; the fifth data used to characterize the environment in which the user performs historical security authentication includes: the fifth data used to characterize the environment in which the user performs the security authentication for the mth to oth times, where m and o are positive integers less than n, and o is greater than m; a second matching evaluation index is obtained based on the second data and the fifth data, and the second matching evaluation index is used to represent the consistency between the environment in which the user performs the security authentication and the environment in which the user performs the historical security authentication.
[0034] In this embodiment of the application, the more inconsistent operations related to the first matching evaluation index, the higher the corresponding security risk of the communication system. The more frequently the inconsistent environment related to the second matching evaluation index occurs, the greater the difference between the current environment and the historical environment, reminding the user to make corresponding adjustments when necessary, so as to better adapt to the individual differences of the user and respond to the dynamic changes of the current communication system in a timely manner.
[0035] Furthermore, determining the security authentication response strategy based on the first data and the second data includes: determining the security authentication response strategy based on the first matching evaluation index and the second data, or determining the security authentication response strategy based on the first data and the second matching evaluation index, or determining the security authentication response strategy based on the first matching evaluation index and the second matching evaluation index.
[0036] Furthermore, in other embodiments of this application, the method further includes: analysis of authentication behavior characteristics; the analysis of authentication behavior characteristics includes: correlation analysis between historical authentication data and authentication results, and correlation analysis between network behavior data and authentication results. Through correlation analysis, potential security vulnerabilities are identified.
[0037] The security authentication method provided in this application constructs a dynamic security policy adjustment model by comprehensively analyzing user operating habits, environmental context, and authentication behavior characteristics, combined with a first matching evaluation index and a second matching evaluation index. This method not only significantly improves the security of the authentication system but also enhances its flexibility and adaptability, enabling it to more effectively cope with large-scale, distributed authentication requests and dynamic environmental changes, ensuring the security and reliability of communication.
[0038] Below, in conjunction with specific embodiments, we will discuss how... Figure 2 The method shown will be explained.
[0039] Furthermore, this application also provides an embodiment of security authentication, referring to... Figure 2 The method may include the following steps: Step 201: Mark each security authentication to form {1,2,3,...i,...n}, where i represents the i-th authentication and n represents the total number of historical authentications. After collecting user operation habit data, authentication behavior characteristics and environmental context data for each authentication process of the terminal, upload them to the cloud service platform for user behavior analysis of the authentication module.
[0040] Step 202: Acquire and analyze user operation habit data. By analyzing users' password input habits and terminal access habits, a first matching evaluation index is generated. First, data collection involves gathering information on users' password input habits and terminal access behaviors during each authentication process. For example, the speed and frequency at which users typically input passwords, and the time and number of times they access specific applications or websites. Second, quantitative indicators are generated. Password input habit indicators include input speed, error rate, and frequently used character positions; terminal location habit indicators include access frequency, duration, and the applications used. The first matching evaluation index ranges from 0 to 1, where 1 indicates complete consistency with historical behavior, and 0 indicates complete inconsistency with historical behavior.
[0041] Step 203: Acquire and analyze environmental context data. By analyzing the environmental data, a second matching evaluation index is generated. This involves: first, data acquisition, collecting information on the light intensity, sound characteristic parameters, and geographical location change distance of the communication terminal's environment; second, quantitative indicators, including light intensity, sound characteristic parameters, and geographical location change indicators. The light intensity indicator is measured in lux (Lux), reflecting the brightness change of the current detection environment. Sound characteristic parameters include volume, spectrum, user-identified background noise, and sound environment. The geographical location indicator primarily measures distance change using GPS accuracy. The second matching evaluation index is used to assess the degree of similarity between the current environment and historical environments. The index ranges from 0 to 1, where 1 indicates a completely consistent environment, and 0 indicates a completely inconsistent environment.
[0042] Step 204: Obtain the authentication behavior characteristics of the security authentication, which include historical authentication data and network behavior data. Historical authentication data includes the time, result, and frequency of each authentication session; network behavior data mainly monitors data traffic, website types visited, and network connection duration. By performing correlation analysis on the data, potential security vulnerabilities are identified. This involves: first, data collection to obtain historical authentication data and network behavior data; second, quantification indicators; historical authentication data including recorded authentication time, authentication result, and authentication frequency; and network behavior data including monitored data traffic, website types visited, and network connection duration. Finally, through analysis, a first correlation coefficient reflecting the correlation between historical authentication data and authentication results, and a second correlation coefficient reflecting the correlation between network behavior data and authentication results are obtained.
[0043] Step 205: Determine the dynamic security strategy. Based on the analysis results of the first matching evaluation index, the second matching evaluation index, and the correlation coefficient, an appropriate authentication strategy is selected and dynamically adjusted to further improve system security. If the system detects that the current correlation and matching degree are low, it will proactively take stricter security measures to ensure communication security. The Security Association (SA) index ranges from 0 to 1, where 1 indicates excellent strategy adjustment and improved system security; 0 indicates low correlation and matching degree, requiring stricter security measures.
[0044] Step 206: Construct a security policy adjustment model, which is used to select and adjust the authentication policy of the authentication module.
[0045] This application embodiment also includes further strategy adjustment, wherein the strategy adjustment amount is obtained by weighting a first matching evaluation index and a second matching evaluation index, wherein the first matching evaluation index is used to represent the consistency of the user's operation in performing the security authentication and the historical security authentication, and the second matching evaluation index is used to represent the consistency of the environment in which the user performs the security authentication and the historical security authentication.
[0046] This application embodiment also includes a quantified strategy adjustment amount, which is used to make fine adjustments to the SA to ensure the rationality of the strategy. The purpose is to improve the system's adaptability to individual differences and environmental changes, thereby ensuring user experience and system security.
[0047] In this embodiment of the application, MP is used to represent the first matching evaluation index, and the calculation formula is as follows:
[0048] Where ZB1 and ZB2 are the current values of the user's password input habit index and terminal access habit index, respectively; ZB1i and ZB2i are the ZB1 and ZB2 values at the i-th authentication; a1 and a2 are non-negative parameters used to adjust the importance of ZB1 and ZB2 in the comprehensive evaluation; and n is the total number of authentication attempts by the user.
[0049] The following is a detailed description of the allocation ratio of a1 to a2 in the examples of "having a significant impact on the evaluation" or "having a minor impact on the evaluation": Example 1 (with significant impact on the evaluation): In this scenario, password input habits and terminal access habits are highly important for security assessment. Therefore, the weights of a1 and a2 need to be relatively balanced to ensure that both are fully considered in the overall assessment. In this case, a1 ranges from 20% to 40%, and a2 ranges from 60% to 80%. Setting a1 to 30% and a2 to 70%, assuming that ZB1 and ZB2 values are within the same range, the relative weights of a1 and a2 are 3:7. This means that terminal access habits are more important than password input habits because a2 has a larger weight. Therefore, inconsistencies in terminal access habits will have a greater impact on the overall assessment index. Even if password input habits are consistent with historical data, if there are anomalies in terminal access habits, the overall assessment index will still decrease.
[0050] Example 2 (Minor impact on evaluation): In this scenario, the lower importance of one metric compared to another is due to differences in system design or security strategies, leading to less focus on one metric. In such cases, the ratio of a1 to a2 needs to be adjusted to ensure that the more critical metric receives higher weight. Specifically, a1 should range from 10% to 30%, and a2 from 70% to 90%. Setting a1 to 20% and a2 to 80% further emphasizes the relatively high importance of terminal access habits. Even if password input habits are consistent with historical data, discrepancies between terminal access habits and historical data can still lead to a decrease in the overall evaluation index. Therefore, abnormal terminal access behavior will have a greater impact on the overall evaluation index.
[0051]
[0052] As a normalization factor, MP's value range is ensured to be between 0 and 1. The MP value range is set to (0, 1). The closer the MP value is to 1, the more consistent the user's current operating habits are with historical data, indicating higher security; the closer the MP value is to 0, the more abnormal or inconsistent operations there are, indicating higher security risk. Furthermore, the effective MP value range is set to (0.1, 1), and divided into the following intervals: The first match interval is [0.8, 1); The second degree of similarity is [0.5, 0.8); The third degree of similarity is [0.3, 0.5); The fourth concordance range is [0.1, 0.3].
[0053] The first consistency interval indicates that the user's current operation is highly consistent with historical data, and the security is high. In this interval, the system only performs routine security checks and conducts a security audit once a year to ensure that operating habits remain consistent.
[0054] For the second consistency range, the user's operating habits are 90% consistent with historical data, but there is a slight deviation of less than 10%. In this range, the system should increase the monitoring frequency by 20%, conduct a detailed behavior analysis every six months, and remind users to pay attention to changes in their input habits.
[0055] For the third consistency range, there is a 10% to 30% difference between user operating habits and historical data; the system should issue a warning, prompting the user or administrator to verify, and requiring the user to re-authenticate or undergo security training, such as relearning or adjusting operating habits.
[0056] For the fourth consistency interval, where there is a difference of more than 30% between the user's actions and historical data, there is a possibility of unauthorized access or user account theft. In this interval, the system should immediately lock the account, conduct a security audit, and require the user to re-authenticate through multi-factor authentication.
[0057] When the ZB1 value decreases, indicating improved input habits, the corresponding MP value increases, suggesting improved input security for the user. When the ZB2 value decreases, meaning the terminal usage interval increases and the usage time shortens, the MP value will also increase accordingly, reflecting that the sparsity of user operations increases security.
[0058] In this embodiment, MU represents the second matching evaluation index, and the calculation formula is as follows:
[0059] Wherein, MU is used to represent the second matching evaluation index, which represents the evaluation result value of the current environmental fit; GXq i The light intensity during the i-th authentication; SYc i These are the sound feature parameters during the i-th authentication. DLj u The distance of a single position change within the u-th time period; K i c1 represents the total number of location changes during the i-th authentication; c2 represents the weight parameter of light intensity, used to control the positive influence of light intensity in the formula; c3 represents the weight parameter of sound feature parameters, used to control the positive influence of sound features; and c4 represents the weight parameter of geographical location change distance, used to control the positive influence of location change.
[0060] The weight parameters c1, c2, and c3 will be discussed in two scenarios: scenarios with a greater impact and scenarios with a smaller impact. The specific range of the weights will be given, and detailed interaction instructions will be provided. Example 1: Scenarios with significant impact on evaluation c1 weight parameter: ranges from 25% to 35%. When the light intensity has a significant impact on the matching evaluation index MU, the weight of c1 ranges from 25% to 35%. It is assumed that the light intensity GXq of the current environment is low, which means that the light is dim, resulting in a decrease in the MU value. That is, the current environment does not match the history. It is assumed that the light intensity under normal lighting conditions in an indoor environment is 500 lux. When the light intensity is lower than this value, it is considered that the light is dim.
[0061] Setting the weight of c1 at a lower end, such as 25%, means that even if light intensity has a significant impact on MU, its contribution to the overall MU will be relatively low.
[0062] Suppose that in a specific scenario, the light intensity decreases by 30%, and the weight of c1 is 25%, then even if the light intensity changes significantly, its impact on MU is only 25% * 30% = 7.5%. c2 weight parameter: ranges from 40% to 50%. When the sound feature parameters have a significant impact on the matching evaluation index MU, the weight of c2 ranges from 40% to 50%. If the stability of the sound feature parameters in the environment increases, it means that SYc increases, and then the MU value will rise, because the stability of the sound features shows the consistency of the environment. Suppose that in a specific scenario, a change in the sound feature parameters causes MU to increase by 20%, and the weight of c2 is 40%, then the impact of the change in sound feature parameters on MU is 40% * 20% = 8%; c3 weight parameter: ranges from 15% to 25%. When the distance of geographical location change has a significant impact on the matching evaluation index MU, the weight of c3 ranges from 15% to 25%. When the distance of geographical location change increases, DLj increases, indicating that the location change is large, which leads to a decrease in the MU value, because movement increases the inconsistency of the environment. If we set the weight of c3 to a relatively high endpoint, such as 25%, then even if the distance of the geographical location change increases, its impact on MU will be relatively large. Assuming that the distance of the geographical location change increases by 30%, and the weight of c3 is 25%, then the impact of the geographical location change on MU will be 25% * 30% = 7.5%.
[0063] Example 2: Scenarios with minimal impact on evaluation c1 weight parameter: ranging from 10% to 20%. When the light intensity has little impact on the matching evaluation index MU, the weight of c1 is in the range of 10% to 20%; assuming that the light intensity of the current environment changes little, the impact on MU is relatively small.
[0064] Setting the weight of c1 at a higher end, such as 20%, means that even a small change in light intensity will have a relatively large impact on MU. Suppose in a specific scene, the light intensity changes only slightly, by a margin of 5%, and the weight of c1 is 20%. Then, the impact of the light intensity change on MU would be 20% * 5% = 1%.
[0065] The c2 weight parameter ranges from 30% to 40%. When the influence of sound feature parameters on the matching evaluation index (MU) is small, the weight of c2 ranges from 30% to 40%. If the stability of sound feature parameters in the environment changes little, the impact on MU is also relatively small. Suppose that in a specific scenario, the change in sound feature parameters only causes MU to increase by 10%, and the weight of c2 is 30%, then the impact of the change in sound feature parameters on MU is 30% * 10% = 3%.
[0066] c3 weight parameter: ranges from 35% to 45%. When the change in geographical location distance has a small impact on the matching evaluation index MU, the weight of c3 ranges from 35% to 45%. When the change in geographical location distance is small, the impact on MU is also relatively small.
[0067] Assuming the change in geographical location is only slight, with a change margin of 8%, and c3 has a weight of 35%, then the impact of geographical location change on MU is 35% * 8% = 2.8%. When the GXq value decreases, it indicates dim lighting, and a decrease in the MU value indicates a mismatch between the current environment and the historical environment. When SYc increases, the MU increases because the stability of sound features indicates environmental consistency. When DLj increases, it indicates a significant change in location, and a decrease in MU is due to increased environmental inconsistency caused by movement. Through normalization, the MU value is set to the range (0,1). The closer the MU value is to 1, the higher the match between the current and historical environments; the closer the MU value is to 0, the more significant the difference between the current and historical environments, and the lower the match.
[0068] If the light intensity It is very large, making If the value of this part approaches 0, and the value of other parts cannot offset the effect of this part, then the entire numerator will approach 0. Sound feature parameters or distance of position change When it is very small, part of the molecule is:
[0069] If the numerator approaches 0, and the value of the denominator c2+c3 is large enough to offset the effect of this part, then the entire numerator will also approach 0.
[0070] The value range of MU (0,1) is subdivided into 5 intervals, and specific performance indicators and action plans are defined for each interval: Interval 1 is (0, 0.2], the current environment is extremely mismatched with the historical environment; the light intensity is low at this time: light intensity Below the average by 80%; unstable sound characteristics, with sound frequency F, amplitude A, or duration D varying by more than 50%, and SYc value below 30%; geographical location changes by distance. Greater than 100 meters.
[0071] The action plan prompts users to check if their devices have been moved or if the usage environment has changed drastically, and recommends re-authentication.
[0072] Interval 2 is (0.2, 0.4]. The current environment does not match the historical environment, and the light intensity is low. Below the average by 60%; sound characteristics are relatively unstable, with significant variations in sound frequency (F), amplitude (A), or duration (D), and SYc values between 30% and 50%; geographical location varies significantly, with changes in distance... Greater than 50 meters but less than 100 meters.
[0073] The action plan aims to alert users to changes in the environment and suggests verifying the authenticity of the current environment.
[0074] Interval 3 is (0.4, 0.6], the current environment partially matches the historical environment; the light intensity is moderate. 40% below average; sound characteristics are moderately stable, with limited variation in sound frequency F, amplitude A, or duration D; SYc value is between 50% and 70%; geographical location variation is moderate, with changes in distance... Between 20 and 50 meters.
[0075] The action plan recommends that users ensure environmental consistency and make environmental adjustments when necessary.
[0076] Interval 4 is (0.6, 0.8]. The current environment matches the historical environment well, and the light intensity is good. The sound characteristics are relatively stable, with little variation in sound frequency (F), amplitude (A), or duration (D), and the SYc value is between 70% and 90%. Geographical location variation is also minimal, with minimal distance change. Less than 20 meters.
[0077] The action plan assumes a basically stable environment, advising users to maintain their current environment or make slight adjustments.
[0078] Interval 5 is (0.8, 1). The current environment matches the historical environment very well, and the light intensity is stable. Approaching the average value ±10%; sound characteristics are highly stable, with minimal changes in sound frequency F, amplitude A, or duration D, and a SYc value greater than 90%; geographical location remains almost unchanged, with minimal changes in distance. Less than 10 meters.
[0079] The action plan is highly compatible with the environment and requires no adjustments.
[0080] In this embodiment of the application, the security policy adjustment model is used to select and adjust the authentication policy of the authentication module, specifically including the following:
[0081] SA is the result index of security policy adjustment, and its value range is (0,1]. It is the index enhancement factor for adjusting C1 and C2; MP is the first matching evaluation index, reflecting the consistency between the user's current operating habits and historical data; MU is the second matching evaluation index, evaluating the degree of fit between the current environment and the historical environment; C1 is the first correlation coefficient, and C2 is the second correlation coefficient.
[0082] f1, f2, and f3 are non-negative weighting factors for the corresponding parameters, ensuring the balance of the overall formula; they are used to adjust the influence of MP, MU, and the exponential term in the overall evaluation.
[0083] f1, f2, and f3 were determined by the expert group based on experimental data and will not be elaborated further.
[0084] The allocation ratio of f1 in the system ranges from 20% to 40%.
[0085] When the f1 ratio is relatively high, meaning it is in a high proportion range, the system pays more attention to the consistency between the user's current operating habits and historical data, and has a greater impact on the first matching evaluation index. Assuming the f1 ratio is 35%, this means that the system is more inclined to adjust the authentication strategy based on the user's historical data, rather than relying too much on the matching degree of the current environment.
[0086] When the proportion of f1 is relatively small, that is, in a low proportion range, the system considers historical data and the current environment in a more balanced way, and has a smaller impact on the first matching evaluation index. Assuming that the proportion of f1 is 25%, this means that the system will consider the user's current operating habits and historical data in a more balanced way, rather than relying too much on historical data.
[0087] The allocation ratio of f2 in the system ranges from 30% to 50%. When the proportion of f2 is large, that is, in a high proportion range, the system pays more attention to the fit between the current environment and the historical environment, and has a greater impact on the second matching evaluation index. Assuming that the proportion of f2 is 45%, this means that the system attaches more importance to the fit between the current environment and the historical environment, and does not rely as much on the user's historical data.
[0088] When the proportion of f2 is relatively small, that is, in a lower proportion range, the system considers the historical environment and the current environment in a more balanced way, and has a smaller impact on the second matching evaluation index. For example, assuming that the proportion of f2 is 35%, this means that the system will consider the fit between the current environment and the historical environment in a more balanced way, and will not rely too much on the current environment.
[0089] The allocation ratio of f3 in the system ranges from 20% to 30%. The impact of f3 is relatively small compared to f1 and f2, but it is still an important part of the overall formula; it is used to adjust the influence of the index term in the overall evaluation to ensure the balance of the overall security strategy.
[0090] for The exponential enhancement factor, Controlling the influence of the first correlation coefficient C1, when Value When the value is greater than a certain threshold, the influence of C1 will be greater, and vice versa. In this embodiment of the system, The range is from 0.1 to 0.3. If If C1's value is 0.2, then C1's influence is relatively large. If C1's value is 0.5, then the final security policy adjustment will be affected by... Influence.
[0091] for Exponential enhancement factor: Controlling the influence of the second correlation coefficient C2, when The larger the value of C2, the greater its influence, and vice versa. In this embodiment of the system, The range is from 0.05 to 0.15.
[0092] if If C2's value is 0.1, then C2's influence is relatively large. If C2's value is 0.8, then the final security policy adjustment will be affected by... Influence.
[0093] When SA approaches 1, the system's security policy adjustment is more effective, and the adjustment strategy of the authentication system improves the system's security. When SA approaches 0, it indicates that the current relevance and matching degree are lower, and the system needs to take more stringent security measures or re-evaluate the existing security policy.
[0094] In this embodiment of the application, the fine-tuning index is defined as FTI, and the calculation formula is as follows:
[0095] in, These are the weighting factors for the corresponding parameters, and
[0096] in These are positive constants, used to ensure the following size relationships:
[0097] and The results were determined by an expert panel based on experimental data, and will not be elaborated further.
[0098] The purpose of using a logarithmic function to process MP is to smooth out large-scale changes, so that the impact of MP changes on FTI decreases gradually and the numerical changes are relatively smooth.
[0099] The exponential function is used to process MU to amplify the impact of MU changes on FTI, ensuring that MU changes significantly affect FTI. The range of FTI is set to (0,1), and the comparison threshold for SA is determined through historical data analysis and practical application experience. ,and .
[0100] In this embodiment, the fine-tuning strategy includes: when At that time, the following fine-tuning formula is provided for SA:
[0101] in, , .
[0102] when At that time, the following fine-tuning formula is provided for SA:
[0103] in, , .
[0104] in, This is the value of SA after fine-tuning the strategy. , For the corresponding adjustment coefficient, Used to ensure , Used to ensure The value range (0,1] of the security policy adjustment model SA is divided into the following specific intervals, and the description of each interval is quantified in detail: For the first safety adjustment range [0.9,1], it indicates that the system's safety policy adjustment is very close to the optimal state. At this time, the system automatically adjusts to the most stringent safety measures based on the comprehensive correlation and matching degree, providing 95% operational safety. It is recommended to maintain the existing policy and strengthen data monitoring in this range.
[0105] The security measures include multi-factor authentication, multi-layer data encryption, IP whitelisting, and location detection; furthermore, multi-factor authentication increases security by 5%; the data encryption layer is increased to 256 bits; the data backup policy is updated hourly; and the monitoring measures include enhanced monitoring of abnormal behavior, with a focus on data access and authentication behavior.
[0106] For the second security adjustment range (0.7, 0.9), SA indicates that the security strategy is suitable for the current situation and the security performance index reaches 85%. It is recommended to continue using the current strategy, but new situations should be evaluated regularly.
[0107] Furthermore, we monitor new users and devices in real time to increase security by 5%; we keep two-factor authentication mechanism enabled; we back up all sensitive data daily; and we conduct weekly assessments of user identities and access policies, adjusting the matching assessment index and correlation coefficient.
[0108] For the third security adjustment range [0.5, 0.7], SA indicates that the security strategy meets more than 90% of the requirements in this range, but the security performance index is 70%. It is recommended to optimize and adjust 30% of the key parameters to improve the security level.
[0109] Furthermore, implement multi-factor authentication and access control to optimize security by 10%; increase data encryption and backup frequency to increase security by 10%; and add conditional data for triggering alerts based on abnormal behavior to increase security by 10%. And 24 / 7 real-time monitoring of relevant data access; for the fourth security adjustment interval [0.3, 0.5), SA indicates that there is a significant security risk, with a security performance index of 50%. At this time, a major adjustment to the security strategy is needed to enhance the current security measures by 35% and closely monitor system behavior.
[0110] Furthermore, implementing multi-factor authentication and restricting device access permissions improves security by 15%; increasing the encryption layer of data transmission by 10% improves security; and regularly training users to avoid phishing attacks and malware improves security by another 10%.
[0111] For the fifth security adjustment range (0, 0.3), an SA value in this range indicates that the current correlation and matching degree are very low, the security performance index is only 30%, and emergency measures need to be taken immediately to reassess and redesign the security strategy.
[0112] In this embodiment, a global multi-layer encryption mechanism is enabled, and a high-level access restriction is introduced to improve security by 20%; an independent backup system is configured to reduce the risk of data loss; and an automatic isolation function for abnormal behavior is established to improve security by 10%. The emergency measure is that the system needs to ensure overall data and communication security by reassessing security policies and developing stringent access and backup plans.
[0113] In this embodiment of the application, increasing the first matching evaluation index MP means that the user's current operating habits are more consistent with historical data, which will directly increase the value of SA and enhance security.
[0114] Increasing the second matching evaluation index MU reflects a high degree of fit between the current environment and historical environments, and will also increase the SA value; increasing C1 or C2 in passing... and The adjustment will enhance the contribution of the exponential term, thereby increasing the value of SA, which means that even minor adjustments to the security strategy will have a significant impact.
[0115] In this embodiment, detailed metrics and index calculations enable precise analysis of user behavior and environmental context, thereby dynamically adjusting security strategies to ensure a balance between efficiency and security.
[0116] Four groups of test subjects were set up to simulate different safety adjustment demand intervals: the first safety adjustment interval, the second safety adjustment interval, the third safety adjustment interval, and the fourth safety adjustment interval. The SA value was simulated and calculated for each interval by changing the weighting factors f1, f2, f3 and the adjustment factor. and To observe the changes in SA values and the corresponding effects of strategy adjustments, in each experiment, initial MP and MU were first set based on historical data and user behavior, along with correlation coefficients C1 and C2. Next, adjustments were made... and This simulates the impact of environmental changes on the SA value, and then adjusts the authentication strategy based on the SA value. Each security adjustment range also includes: increasing or decreasing the values of f1, f2, and f3 to simulate the sensitivity of the authentication strategy to changes in real-world scenarios. Furthermore, it involves changing... and The value of the enhancement factor is analyzed to assess its impact on the SA, thereby finely adjusting the weight of each parameter to achieve the desired safety performance.
[0117] The table below shows the specific data from the experiment. Table 1 displays the parameter settings and SA value measurement results for the four groups of test subjects within different safety adjustment ranges. Table 1
[0118] The table data analysis is as follows: For the first safety adjustment interval [0.9, 1], in the experimental data SA = 0.937, the corresponding weighting factors f1 = 0.25, f2 = 0.35, f3 = 0.4, and the adjustment factor... =0.25, =0.25.
[0119] When the SA value in this interval approaches 1, it indicates that the adjustment of the security strategy is very close to the optimal state, achieved by using a high-weighted f3 and a larger... and The enhancement factor strengthens the model's sensitivity to the fit of current operating habits and the environment. This adjustment strategy optimizes the application of advanced security measures such as multi-factor authentication and data encryption layers, providing more than 95% operational security and demonstrating the model's excellent adaptability and foresight in high-risk environments.
[0120] For the second safety adjustment interval (0.7, 0.9), the experimental data showed SA = 0.875, and weighting factors f1 = 0.3, f2 = 0.4, and f3 = 0.3.
[0121] An SA value within this range indicates that the security is well adapted to the current situation. The model maintains a high level of security through balanced weight allocation and appropriate adjustment factors without frequent changes, demonstrating the model's intelligent decision-making ability to maintain a high level of security while reducing over-adjustment.
[0122] For the third safety adjustment interval [0.5, 0.7], SA = 0.625 in the experimental data, and weighting factors f1 = 0.35, f2 = 0.3, f3 = 0.35.
[0123] The SA value in this range indicates that the security strategy basically meets the requirements but needs to be optimized. By increasing the weights of f1 and f3, the model enhances its sensitivity to changes in operating habits and environment, allowing for rapid adjustments when new or added security threats are discovered. This demonstrates the model's dynamic adjustment capability and adaptability to medium-risk environments.
[0124] For the fourth safety adjustment interval [0.3, 0.5), SA = 0.425 in the experimental data, and weighting factors f1 = 0.4, f2 = 0.3, f3 = 0.3.
[0125] An SA value below 0.5 indicates a significant security risk. The model responds to inconsistencies between user behavior and historical data by increasing f1, strengthening multi-factor authentication and data encryption. This demonstrates the model's rapid response and high adjustability in the face of declining security performance, effectively addressing the challenge of low security ratings.
[0126] Optionally, embodiments of this application also provide a communication device, including: a processor, a memory, and a communication bus; the communication bus is used to realize a communication connection between the processor and the memory; the processor is used to execute a program in the memory to implement the steps of the method described in any of the above figures.
[0127] This application also provides a computer-readable storage medium storing one or more programs that can be executed by one or more processors to implement the steps of the method described in any of the above figures.
[0128] This application also provides a computer program product, which includes a computer program, characterized in that the computer program, when executed by a processor, implements the method described in any of the above figures.
[0129] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0130] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0131] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the system and equipment described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0132] In the several embodiments provided in this application, it should be understood that the disclosed methods and devices can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation. Furthermore, the couplings or direct couplings or communication connections shown or discussed may be indirect couplings or communication connections through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0133] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0134] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0135] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
Claims
1. A security authentication method, characterized in that, include: Obtain the user's request for security authentication; Obtain first data, which is used to characterize the user's operation of performing the security authentication; Obtain second data, which is used to characterize the environment in which the user performs the security authentication; The response strategy for the security authentication is determined based on the first data and the second data.
2. The method according to claim 1, characterized in that, The method further includes: acquiring third data, the third data being used to characterize the user's behavioral features during the security authentication; Determining the security authentication response strategy based on the first data and the second data includes: determining the security authentication response strategy based on the first data, the second data, and the third data.
3. The method according to claim 1 or 2, characterized in that, The first data includes the user's operating habit data, which includes at least one of the following: Password input habit data, which includes at least one of the following: the user's input speed, error rate, and frequently used character positions; Access habit data, which includes at least one of the following: the frequency of the user's accesses, the duration of accesses, and the applications used.
4. The method according to claim 1 or 2, characterized in that, The second data includes the user authentication environment context data, which includes at least one of the following: Light intensity; Sound characteristic parameters; Distance due to changes in geographical location.
5. The method according to claim 2, characterized in that, The third data includes at least one of the following: Historical authentication data, which includes the time, result, and frequency of each security authentication performed by the user; Network behavior data, which includes at least one of the following: monitored data traffic, types of websites visited, and network connection duration.
6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: Obtain fourth data, which is used to characterize the user's historical security authentication operations; obtain a first matching evaluation index based on the first data and the fourth data, which is used to indicate the consistency between the user's security authentication operations and the historical security authentication operations; The step of determining the response strategy for security authentication based on the first data and the second data includes: determining the response strategy for security authentication based on the first matching evaluation index and the second data.
7. The method according to any one of claims 1 to 5, characterized in that, The method further includes: Obtain fifth data, which is used to characterize the environment in which the user performed historical security authentication; obtain a second matching evaluation index based on the second data and the fifth data, which is used to indicate the consistency between the environment in which the user performed the security authentication and the environment in which the user performed the historical security authentication; Determining the response strategy for security authentication based on the first data and the second data includes: determining the response strategy for security authentication based on the first data and the second matching evaluation index.
8. The method according to claim 5, characterized in that, The method further includes: Obtain the authentication result; perform correlation analysis between the historical authentication data and the authentication result to obtain a first correlation coefficient; perform correlation analysis between the network behavior data and the authentication result to obtain a second correlation coefficient; Determining the security authentication response strategy based on the first data and the second data includes: determining the security authentication response strategy based on the first data, the second data, the first correlation coefficient, and the second correlation coefficient.
9. A communication device, characterized in that, The device includes: a processor, a memory, and a communication bus; The communication bus is used to realize the communication connection between the processor and the memory; The processor is used to execute the program in the memory to implement the steps of the method according to any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores one or more programs that can be executed by one or more processors to implement the steps of the method as described in any one of claims 1 to 8.
11. A computer program product, said computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Security authentication method, equipment, device and storage medium
CN110232270A
Computer remote login identification equipment based on artificial intelligence
CN120180409A
Login authentication method and device and computer readable storage medium
CN120658520A
Multi-factor dynamic authentication method and device, electronic equipment and storage medium
CN120934856A