Dynamic identity authentication method and device based on Beidou space-time information, terminal equipment and storage medium
The dynamic identity authentication method using BeiDou spatiotemporal information solves the problem of low security in traditional identity authentication. By receiving authentication request data and obtaining BeiDou standard spatiotemporal data of the user's location, the method calculates the trajectory overlap and time pattern matching degree, generates a dynamic key for identity authentication, and improves the security of authentication.
Patent Information
- Application Number
- CN202511720935.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-21
- Publication Date
- 2026-02-17
AI Technical Summary
Traditional identity authentication methods rely on static information, which is easily stolen or forged, resulting in low security.
The dynamic identity authentication method based on BeiDou spatiotemporal information obtains BeiDou standard spatiotemporal data of the user's location by receiving authentication request data, calculating trajectory overlap and time pattern matching degree, and generating a dynamic key for identity authentication.
The security of identity authentication is improved by calculating the dynamic key generation based on a combination of matching degree and deviation degree, thereby enhancing the security of the authentication process.
Smart Images

Figure CN121547183A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of identity authentication, and in particular to a dynamic identity authentication method, device, terminal equipment, and storage medium based on BeiDou spatiotemporal information. Background Technology
[0002] Identity authentication is a process of verifying whether a user's claimed identity matches their actual identity through technical means. It is one of the core links in ensuring the security of information systems. Its core objective is to prevent unauthorized users from accessing system resources and to ensure the legitimacy of users' identities in scenarios such as network interaction, data access, and transaction operations.
[0003] Traditional identity authentication methods have many limitations. They rely heavily on static information (such as static biometrics), which is easily stolen or forged, leading to the leakage of user information. Therefore, existing identity authentication technologies suffer from low security. Summary of the Invention
[0004] This invention provides a dynamic identity authentication method, device, terminal equipment, and storage medium based on BeiDou spatiotemporal information, which can solve the problem of low security in existing identity authentication technologies.
[0005] The dynamic identity authentication method based on BeiDou spatiotemporal information provided by the present invention includes: receiving authentication request data sent by a user and obtaining BeiDou standard spatiotemporal data of the user's location; The authentication request data is verified, and after the verification is passed, the authentication request data is matched with the preset identity information database to calculate the identity matching degree. The system obtains the user's historical identity authentication trajectory and historical identity authentication time, calculates the trajectory overlap degree between the BeiDou standard spatiotemporal data and the historical identity authentication trajectory, calculates the time pattern matching degree between the BeiDou standard spatiotemporal data and the historical identity authentication time, and determines the comprehensive behavioral similarity based on the trajectory overlap degree and the time pattern matching degree. Obtain the current authentication scenario type, determine the weight set based on the current authentication scenario type, and perform a weighted calculation based on the identity matching degree, the comprehensive behavior similarity, and the weight set to obtain the comprehensive matching degree; After the overall behavioral similarity is greater than or equal to the preset matching threshold, the deviation is calculated based on the BeiDou standard spatiotemporal data, the historical identity authentication trajectory, and the historical identity authentication time. When the deviation is less than or equal to a preset deviation threshold, a dynamic key is generated based on the authentication request data so that the user can perform identity authentication based on the dynamic key.
[0006] Further, receiving authentication request data issued by the user includes: Receive authentication request data sent by the user through the client; the authentication request data includes: encrypted biometrics, basic identity information and device location information.
[0007] Furthermore, the client includes: The client receives basic identity information input by the user and records the device location information of the client. The client collects the user's biometrics and converts the biometrics into raw biometric binary data. The client obtains the timestamp and the base key, and concatenates the timestamp and the base key to obtain the concatenation result; The client inputs the concatenation result into a hash function to obtain a hash value; The client performs an XOR operation between the original biometric binary data and the hash value to obtain encrypted biometric data. The client sends the encrypted biometrics, the basic identity information, and the device location information.
[0008] Furthermore, the acquisition of BeiDou standard spatiotemporal data of the user's location includes: Retrieve the user's original BeiDou spatiotemporal data from the distributed spatiotemporal database; The BeiDou raw spatiotemporal data is retrieved from the distributed spatiotemporal database; wherein, the construction of the distributed spatiotemporal database is specifically as follows: by receiving real-time spatiotemporal data collected by different BeiDou terminal devices, preprocessing the real-time spatiotemporal data to obtain the BeiDou raw spatiotemporal data, and storing the BeiDou raw spatiotemporal data in the distributed spatiotemporal database; The original BeiDou spatiotemporal data is denoised using a BeiDou spatiotemporal data noise filtering algorithm to obtain denoised BeiDou spatiotemporal data. The BeiDou timestamp of the BeiDou denoised spatiotemporal data is synchronized with the preset standard time reference, and the BeiDou geographic location data in the BeiDou denoised spatiotemporal data is converted into general geographic location data under a general geographic coordinate system, thereby obtaining BeiDou standard spatiotemporal data.
[0009] Further, the step of matching the authentication request data with a preset identity information database and calculating the identity matching degree includes: The authentication request data is matched against a preset identity database to obtain a matching result; wherein, the identity database includes several user identity information; each user identity information specifically includes: basic identity data pre-entered by the user and the corresponding encrypted biometric features; Calculate the identity matching degree between the matching result and the authentication request data.
[0010] Further, the step of calculating the trajectory overlap degree between the BeiDou standard spatiotemporal data and the historical identity authentication trajectory, calculating the temporal pattern matching degree between the BeiDou standard spatiotemporal data and the historical identity authentication time, and determining the comprehensive behavioral similarity based on the trajectory overlap degree and the temporal pattern matching degree includes: Based on the historical identity authentication trajectory, determine the historical high-frequency activity area; The spatial intersection area is determined based on the location of the BeiDou standard spatiotemporal data and the location of historical high-frequency activity areas; Substitute the spatial intersection area and the total area of historical high-frequency activity areas into the overlap calculation formula to calculate the trajectory overlap. Based on the historical identity authentication time, determine the historical average authentication time for the same period as the BeiDou standard spatiotemporal data; Substitute the historical average authentication time and the authentication time of BeiDou standard spatiotemporal data into the formula for calculating the time pattern matching degree to calculate the time pattern matching degree. The trajectory overlap and the time pattern matching degree are each multiplied by a preset weight value and summed to obtain the comprehensive behavioral similarity.
[0011] Further, the step of calculating the trajectory overlap degree between the BeiDou standard spatiotemporal data and the historical identity authentication trajectory, calculating the temporal pattern matching degree between the BeiDou standard spatiotemporal data and the historical identity authentication time, and determining the comprehensive behavioral similarity based on the trajectory overlap degree and the temporal pattern matching degree includes: Based on the historical identity authentication trajectory, determine the historical high-frequency activity area; The spatial intersection area is determined based on the location of the BeiDou standard spatiotemporal data and the location of historical high-frequency activity areas; Substitute the spatial intersection area and the total area of historical high-frequency activity areas into the overlap calculation formula to calculate the trajectory overlap. Based on the historical identity authentication time, determine the historical average authentication time for the same period as the BeiDou standard spatiotemporal data; Substitute the historical average authentication time and the authentication time of BeiDou standard spatiotemporal data into the formula for calculating the time pattern matching degree to calculate the time pattern matching degree. The trajectory overlap and the time pattern matching degree are each multiplied by a preset weight value and summed to obtain the comprehensive behavioral similarity.
[0012] Another embodiment of the present invention provides a dynamic identity authentication device based on BeiDou spatiotemporal information, comprising: a data acquisition module, a first calculation module, a second calculation module, a third calculation module, a fourth calculation module, and an identity authentication module; The data acquisition module is used to receive authentication request data sent by the user and to acquire BeiDou standard spatiotemporal data of the user's location. The first calculation module is used to verify the authentication request data, and after the verification is passed, to match the authentication request data with a preset identity information database and calculate the identity matching degree. The second calculation module is used to obtain the user's historical identity authentication trajectory and historical identity authentication time, calculate the trajectory overlap degree between the BeiDou standard spatiotemporal data and the historical identity authentication trajectory, calculate the time pattern matching degree between the BeiDou standard spatiotemporal data and the historical identity authentication time, and determine the comprehensive behavior similarity based on the trajectory overlap degree and the time pattern matching degree. The third calculation module is used to obtain the current authentication scenario type, determine the weight set according to the current authentication scenario type, and perform weighted calculation based on the identity matching degree, the comprehensive behavior similarity and the weight set to obtain the comprehensive matching degree. The fourth calculation module is used to calculate the deviation based on the BeiDou standard spatiotemporal data, the historical identity authentication trajectory, and the historical identity authentication time after the comprehensive behavioral similarity is greater than or equal to a preset matching threshold. The identity authentication module is used to generate a dynamic key based on the authentication request data when the deviation is less than or equal to a preset deviation threshold, so that the user can perform identity authentication based on the dynamic key.
[0013] Another embodiment of the present invention provides a terminal device, including: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the steps of the dynamic identity authentication method based on BeiDou spatiotemporal information provided by the present invention.
[0014] Another embodiment of the present invention provides a computer-readable storage medium item, including: a stored computer program, which, when the computer program is running, controls the device where the computer-readable storage medium is located to perform the steps of the dynamic identity authentication method based on BeiDou spatiotemporal information provided by the present invention.
[0015] The following benefits can be obtained by implementing the present invention: This invention discloses a dynamic identity authentication method based on BeiDou spatiotemporal information. The method involves receiving authentication request data from a user and acquiring BeiDou standard spatiotemporal data of the user's location; verifying the authentication request data; and, upon successful verification, matching the authentication request data with a preset identity information database to calculate the identity matching degree; acquiring the user's historical identity authentication trajectory and historical identity authentication time; calculating the trajectory overlap degree between the BeiDou standard spatiotemporal data and the historical identity authentication trajectory; and calculating the time pattern matching degree between the BeiDou standard spatiotemporal data and the historical identity authentication time. The trajectory overlap and the time pattern matching degree are used to determine the comprehensive behavioral similarity. The current authentication scenario type is obtained, and a weight set is determined based on this type. A weighted calculation is performed based on the identity matching degree, the comprehensive behavioral similarity, and the weight set to obtain the comprehensive matching degree. If the comprehensive behavioral similarity is greater than or equal to a preset matching degree threshold, the deviation degree is calculated based on the BeiDou standard spatiotemporal data, the historical identity authentication trajectory, and the historical identity authentication time. If the deviation degree is less than or equal to a preset deviation degree threshold, a dynamic key is generated based on the authentication request data, enabling the user to perform identity authentication based on the dynamic key. This invention calculates the comprehensive matching degree and deviation degree based on BeiDou spatiotemporal data, and uses these two indicators to determine whether to generate a dynamic key, greatly improving the security of identity authentication. Attached Figure Description
[0016] To more clearly illustrate the technical solution of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0017] Figure 1 This is a flowchart illustrating a dynamic identity authentication method based on BeiDou spatiotemporal information according to an embodiment of the present invention. Figure 2 This is a schematic diagram of the structure of a dynamic identity authentication device based on BeiDou spatiotemporal information provided in an embodiment of the present invention. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the application; the terms “comprising” and “having”, and any variations thereof, in the specification, claims, and foregoing description of the drawings are intended to cover non-exclusive inclusion.
[0020] In the description of the embodiments of this application, technical terms such as "first" and "second" are used only to distinguish different objects and should not be construed as indicating or implying relative importance or implicitly specifying the number, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, "multiple" means two or more, unless otherwise explicitly defined.
[0021] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0022] In the description of the embodiments in this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0023] In the description of the embodiments of this application, the term "multiple" refers to two or more (including two), similarly, "multiple sets" refers to two or more (including two sets), and "multiple pieces" refers to two or more (including two pieces).
[0024] In the description of the embodiments of this application, unless otherwise expressly specified and limited, technical terms such as "installation," "connection," "joining," and "fixing" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. For those skilled in the art, the specific meaning of the above terms in the embodiments of this application can be understood according to the specific circumstances.
[0025] See Figure 1To address the low security issues of existing identity authentication technologies, an embodiment of the present invention provides a dynamic identity authentication method based on BeiDou spatiotemporal information, comprising: 101. Receive authentication request data sent by the user and obtain BeiDou standard spatiotemporal data of the user's location.
[0026] In this embodiment, receiving authentication request data sent by the user includes: Receive authentication request data sent by the user through the client; the authentication request data includes: encrypted biometrics, basic identity information and device location information.
[0027] In this embodiment, the client includes: The client receives basic identity information input by the user and records the device location information of the client. The client collects the user's biometrics and converts the biometrics into raw biometric binary data. The client obtains the timestamp and the base key, and concatenates the timestamp and the base key to obtain the concatenation result; The client inputs the concatenation result into a hash function to obtain a hash value; The client performs an XOR operation between the original biometric binary data and the hash value to obtain encrypted biometric data. The client sends the encrypted biometrics, the basic identity information, and the device location information.
[0028] In one specific embodiment, the user submits an authentication request through a client. The authentication request includes the user's basic identity information, including username and ID card number, as well as device location information, which is provided when the device supports location functionality. The client collects users' biometric features in real time, including fingerprints and facial image features; A dynamic encryption mechanism based on biometrics is used to process biometric features. The formula for this dynamic encryption mechanism is as follows: in, For encrypted biometrics, Characteristics of primitive organisms This is the current BeiDou timestamp. The base key pre-negotiated between the client and the microservice unit. For XOR operation, Use the SHA-256 hash function; First, the client obtains the user's original biometric features through sensors. It is then converted into binary data, with the binary data length uniformly adjusted to 256 bits. If the length is insufficient, zeros are added; if it exceeds this length, it is truncated, ensuring consistency with the SHA-256 hash value. The lengths are consistent, satisfying the dimension matching requirement of the XOR operation; Obtain the current timestamp accurate to milliseconds from the BeiDou module. (Based on the time synchronization function of the BeiDou system, it has anti-tampering characteristics and a globally unified time reference, which is different from local time or ordinary GPS time that are vulnerable to network attacks.) timestamp With the base key By piecing them together in order, we obtain... ; Input the concatenated result into the SHA-256 hash function to generate a 256-bit hash value. ; Subsequently, the original biometric binary data With hash value Perform an XOR operation to obtain the encrypted biometric data. ; The encrypted request data is sent to the front-end gateway of the authentication system through an HTTPS encrypted channel. The gateway verifies the format and integrity of the request, and forwards the request to the authentication microservice unit after the verification is successful.
[0029] In this embodiment, obtaining the BeiDou standard spatiotemporal data of the user's location includes: Retrieve the user's original BeiDou spatiotemporal data from the distributed spatiotemporal database; The BeiDou raw spatiotemporal data is retrieved from the distributed spatiotemporal database; wherein, the construction of the distributed spatiotemporal database is specifically as follows: by receiving real-time spatiotemporal data collected by different BeiDou terminal devices, preprocessing the real-time spatiotemporal data to obtain the BeiDou raw spatiotemporal data, and storing the BeiDou raw spatiotemporal data in the distributed spatiotemporal database; The original BeiDou spatiotemporal data is denoised using a BeiDou spatiotemporal data noise filtering algorithm to obtain denoised BeiDou spatiotemporal data. The BeiDou timestamp of the BeiDou denoised spatiotemporal data is synchronized with the preset standard time reference, and the BeiDou geographic location data in the BeiDou denoised spatiotemporal data is converted into general geographic location data under a general geographic coordinate system, thereby obtaining BeiDou standard spatiotemporal data.
[0030] In one specific embodiment, a distributed file system (which can be HDFS distributed file system) is used as the underlying storage. The distributed spatiotemporal database includes: a data receiving layer, a hash partitioning layer, a multi-replica storage layer, and an index building layer. The data receiving layer is used to receive BeiDou spatiotemporal data from external sources; The hash partitioning layer distributes data evenly across nodes using a spatiotemporal data hash partitioning algorithm, with the target partition number being... The calculation formula is: in, The high-precision timestamps provided for the BeiDou system (accurate to the millisecond level, significantly improving the time synchronization accuracy compared to ordinary GPS) are then converted into integers. The value is a combination of BeiDou latitude and longitude coordinates (error ≤ 1 meter, significantly better than the 100-meter error of network positioning). For XOR operation, This represents the total number of partitions. It is the SHA-1 hash function.
[0031] To better illustrate the approach of distributed spatiotemporal databases, see the following case: First, the BeiDou timestamp Convert to integer format; Then, the latitude and longitude coordinates are combined into ,in, Where lat is latitude and lon is longitude; For the converted and Perform an XOR operation to obtain an intermediate value that integrates spatiotemporal features; The intermediate value is then input into the SHA-1 hash function to obtain the hash value, and then the total number of partitions is calculated. Modulo operation is used to determine the target partition number. ; Total number of partitions The settings must meet the following rules: If the number of system nodes deployed is N, then the minimum value of K is 3N, ensuring that each node is allocated at least 3 partitions to avoid uneven load; when the maximum storage capacity of a single node is C, and the expected annual data growth is D, then K must satisfy: (Reserve 3 years of data storage redundancy), and prioritize values that are powers of 2 (such as 16, 32, 64, etc.) to optimize the uniformity of partition distribution after hash modulo. The multi-replica storage layer is used to store the data of each partition in 3-replica redundant storage, and the consistency protocol ensures the consistency of data between replicas; The index building layer creates B-Tree indexes for the time dimension and R-Tree indexes for the spatial dimension. It also incorporates the Redis caching mechanism to cache frequently queried hot data in memory.
[0032] In one specific embodiment, the collection of spatiotemporal data from different BeiDou terminal devices is performed by the BeiDou data acquisition and adaptation microservice unit, which includes a multi-source access layer, a protocol conversion layer, a data verification layer, and a frequency control layer. The multi-source access layer connects to different models of Beidou RDSS / RNSS dual-mode terminals through hardware interfaces to receive raw data frames; The protocol conversion layer converts data from different protocols, such as TCP / IP, MQTT, and the BeiDou-specific transmission protocol, into the system's universal JSON format; The data verification layer filters invalid data frames through frame header and frame tail verification and CRC redundancy check, and performs deduplication based on timestamp and device ID; The frequency control layer dynamically adjusts the acquisition cycle according to the type of terminal device. The acquisition cycle for static devices is set to 1 time / minute, and the acquisition cycle for mobile devices is set to 1 time / 30 seconds. After the data collection is completed, the processed data will be transmitted to the distributed spatiotemporal database built in S1 for storage.
[0033] In one specific embodiment, raw BeiDou spatiotemporal data related to the currently authenticated user is obtained from a distributed spatiotemporal database; The BeiDou spatiotemporal data noise filtering algorithm is used to remove noise from the data. The denoised data is then obtained. The calculation formula is: in, This is the raw BeiDou spatiotemporal data. This is a smoothing coefficient, and its value ranges from 0.1 to 0.5. For the Laplace operator; The specific steps are as follows: First, the raw BeiDou spatiotemporal data Grid processing is performed to discretize continuous spatiotemporal data into grid point data; Calculate the second spatial derivative at each grid point. ; For the gridded two-dimensional spatial data, the four-neighbor discrete Laplace operator is used for computation. The calculation formula is: in: Represents grid points The original spatiotemporal data values (such as latitude and longitude deviations) are located at the specified points; h is the grid side length, dynamically set according to the BeiDou positioning accuracy (for sub-meter level positioning). Meter, meter-level positioning (meters); for boundary grid points (such as x=0 or y=0), missing neighbor values are handled using mirror filling (e.g.: , ); Grid division rules: The original data is gridded before calculation. The grid range is defined with the user's current authentication location as the center. A rectangular area (covering the possible range of positioning errors); grid density: for sub-meter level positioning, it is divided into 200×200 grids. Meter-level positioning is divided into 100×100 grids. (meters); multiple sets of raw data within the same grid are used as the arithmetic mean. The input value; The smoothing coefficient is dynamically adjusted based on the signal-to-noise ratio of the data. Specifically, this involves: processing the raw BeiDou spatiotemporal data The data is divided into several consecutive segments according to the time series (e.g., each segment is a window of 10 seconds), and each segment contains the latitude and longitude and timestamp information of multiple sampling points. Define the signal in the data as the trend component, such as a user's normal movement trajectory. Extract this trend component using the moving average method or low-pass filtering, denoted as... noise components The difference between the original data and the signal components is calculated using the following formula: Signal-to-noise ratio (SNR) is the ratio of the power of the signal component to the power of the noise component, expressed in decibels (dB). The formula for calculating SNR is: in, To calculate the variance of the data, which reflects the magnitude of the power, For a logarithm to base 10, when At that time, it was determined to be a low signal-to-noise ratio, meaning the data noise was relatively strong. Use 0.4-0.5 to enhance the smoothing effect. When the signal-to-noise ratio is high, it indicates that the data quality is good. Use a value between 0.1 and 0.2 to preserve the details of the original data; raw BeiDou spatiotemporal data minus With second-order spatial derivative The product of these two numbers yields the denoised data. ; The time synchronization module synchronizes the BeiDou timestamp with UTC (Coordinated Universal Time) time (i.e., the standard time base) at the millisecond level; The coordinate transformation module is used to convert geographic location data in the BeiDou satellite coordinate system to coordinates in the WGS-84 universal geographic coordinate system; The standardized output module encapsulates the processed data according to the format of "timestamp + longitude + latitude + altitude + device status".
[0034] 102. Verify the authentication request data, and after the verification is successful, match the authentication request data with the preset identity information database and calculate the identity matching degree.
[0035] In this embodiment, the step of matching the authentication request data with a preset identity information database and calculating the identity matching degree includes: The authentication request data is matched against a preset identity database to obtain a matching result; wherein, the identity database includes several user identity information; each user identity information specifically includes: basic identity data pre-entered by the user and the corresponding encrypted biometric features; Calculate the identity matching degree between the matching result and the authentication request data.
[0036] To better illustrate the acquisition of identity matching, the following explanation is provided: First, the system receives user requests forwarded by the front-end gateway and verifies the completeness and format validity of the basic identity information submitted by the user. Extract the user's baseline information from the identity information database and compare it with the information submitted by the user in multiple dimensions, including text information (i.e., basic identity data), image information (i.e. encrypted biometrics), and historical behavior information. The matching degree calculation module uses a multi-dimensional identity matching degree calculation algorithm to quantify the matching degree. The calculation formula is: in, For the first The weights of class identity information, j=1 represent text information, j=2 represent image information, and: in, Submit information to users Information from authoritative databases similarity, This refers to the number of dimensions of identity information.
[0037] 103. Obtain the user's historical identity authentication trajectory and historical identity authentication time, calculate the trajectory overlap degree between the BeiDou standard spatiotemporal data and the historical identity authentication trajectory, calculate the time pattern matching degree between the BeiDou standard spatiotemporal data and the historical identity authentication time, and determine the comprehensive behavioral similarity based on the trajectory overlap degree and the time pattern matching degree.
[0038] In this embodiment, the calculation of trajectory overlap between the BeiDou standard spatiotemporal data and the historical identity authentication trajectory, the calculation of temporal pattern matching between the BeiDou standard spatiotemporal data and the historical identity authentication time, and the determination of comprehensive behavioral similarity based on the trajectory overlap and the temporal pattern matching, include: Based on the historical identity authentication trajectory, determine the historical high-frequency activity area; The spatial intersection area is determined based on the location of the BeiDou standard spatiotemporal data and the location of historical high-frequency activity areas; Substitute the spatial intersection area and the total area of historical high-frequency activity areas into the overlap calculation formula to calculate the trajectory overlap. Based on the historical identity authentication time, determine the historical average authentication time for the same period as the BeiDou standard spatiotemporal data; Substitute the historical average authentication time and the authentication time of BeiDou standard spatiotemporal data into the formula for calculating the time pattern matching degree to calculate the time pattern matching degree. The trajectory overlap and the time pattern matching degree are each multiplied by a preset weight value and summed to obtain the comprehensive behavioral similarity.
[0039] Behavioral data matching is calculated based on historical data matching through trajectory overlap and temporal pattern matching, where trajectory overlap is... The formula for calculating the degree of overlap is: in, The area of the circular intersection of the current authentication location and the historical high-frequency activity area. This is the sum of the areas of all historically high-frequency activity areas. Historically high-frequency activity areas are those where users have spent more than 10 hours in the past 3 months and whose frequency of occurrence is ≥5 times / week. The areas are divided into circles with a dynamic radius centered on the user's location (the radius is 1.2 times the maximum activity range within the area, and the minimum radius is 50 meters). The trajectory overlap degree is obtained through calculation. (Range from 0% to 100%) Time pattern matching degree The formula for calculating the pattern matching degree is: in, The current authentication time; For historical data, the same time period on the same weekday (e.g., Wednesday 9:00-10:00) is used. For weekends, the average of the same hour period on all weekends within the past 3 months is used. This is the arithmetic mean of the historical authentication times within this period, where 1440 is the total number of minutes in a day; The time pattern matching degree is obtained through calculation. The range is 0-1; Overall behavioral similarity The calculation formula is: The overall behavioral similarity is then calculated.
[0040] 104. Obtain the current authentication scenario type, determine the weight set based on the current authentication scenario type, and perform a weighted calculation based on the identity matching degree, the comprehensive behavior similarity, and the weight set to obtain the comprehensive matching degree.
[0041] The weights are dynamically adjusted based on the scene's security level. The system includes weighting coefficients for high-security, medium-security, and low-security scenarios. Specifically: in high-security scenarios (such as financial transaction systems), biometric data is weighted at 0.5, basic text information at 0.3, and historical behavior at 0.2; in medium-security scenarios (such as social media platforms), biometric data is weighted at 0.4, basic text information at 0.3, and historical behavior at 0.3; and in low-security scenarios (such as general information access), biometric data is weighted at 0.3, basic text information at 0.3, and historical behavior at 0.4. The system automatically matches the corresponding security level and weighting coefficients through its built-in scene recognition module. The similarity scores of each type of information are multiplied by their corresponding weights and then summed to obtain the overall matching score. ; The verification result decision module sets the matching threshold to 0.85. If the initial verification is successful, it will be determined that the verification is successful; otherwise, enhanced verification will be triggered, which requires the user to provide additional identity information. 105. After the comprehensive behavioral similarity is greater than or equal to the preset matching threshold, the deviation is calculated based on the Beidou standard spatiotemporal data, the historical identity authentication trajectory, and the historical identity authentication time.
[0042] In this embodiment, calculating the deviation based on the BeiDou standard spatiotemporal data, the historical identity authentication trajectory, and the historical identity authentication time includes: Based on the historical identity authentication trajectory and the historical identity authentication time, determine the historical location change rate, historical dwell time in the work area, and historical trajectory curvature; Based on the BeiDou standard spatiotemporal data, determine the current location change rate, current dwell time in the work area, and current trajectory curvature; Substitute the historical rate of change of position, historical time spent in the working area, historical trajectory curvature, current rate of change of position, current time spent in the working area, and current trajectory curvature into the deviation calculation formula to obtain the deviation.
[0043] Based on the user's BeiDou spatiotemporal data from the past three months, the average values of features such as the rate of position change, dwell time in a specific area, and trajectory curvature are calculated and used as historical baseline feature values. ; Extract the spatiotemporal trajectory feature values of the user in this authentication. ; The deviation calculation module uses deviation The formula for calculating the deviation is: Calculate the deviation of the current trajectory from the historical baseline; in, Let be the weights of each eigenvalue, and: in, The number of eigenvalues; First, determine what needs to be analyzed. The spatiotemporal trajectory features include the rate of position change, the time spent in the work area, and the trajectory curvature; Calculate the historical baseline value for each feature ; Collect user feature values during this authentication process ; Weights are assigned based on the discriminative power of features in user behavior. The formula for calculating the discrimination index is: in, For the first Discrimination of class features For the first Variance of class feature (trajectory curvature) across different users For the first Variance of class features within the same user; The feature discrimination value is calculated and divided into high discrimination, medium discrimination and low discrimination.
[0044] when When the discrimination is high (weight 0.3-0.4), When the discrimination index is moderate (weight 0.2-0.3), when The time is considered low discrimination (weight 0.1-0.2); And calculate the relative deviation for each feature. ; The total deviation is calculated by multiplying the relative deviations of each feature by their corresponding weights and then summing the results. ; 106. When the deviation is less than or equal to a preset deviation threshold, a dynamic key is generated based on the authentication request data so that the user can perform identity authentication based on the dynamic key.
[0045] In one specific embodiment, a dynamic key is generated and verified to ensure the security of the authentication process. The dynamic key is generated based on the user identity identifier, BeiDou timestamp, geographical location and basic key, and the security of the authentication process is ensured through key verification. A unique identifier for obtaining user identity. Current BeiDou timestamp User's current geographical location coordinates and user base key The obtained parameters are concatenated in order as follows: Then, input the SHA-512 hash function to generate a dynamic key: First, uniquely identify the user. Convert to string format; Get the current user's BeiDou timestamp Accurate to the second, and the user's current geographical coordinates. This refers to latitude and longitude strings; Will , , , Concatenate them sequentially into a complete string; The concatenated string is input into the SHA-512 hash function to generate a 512-bit hash value, which serves as the dynamic key. ; The dynamic key is sent to the authentication microservice unit via an end-to-end encrypted channel; The key verification module recalculates the dynamic key using the same parameters and hash function through the authentication microservice unit, and compares it with the received key. If the comparison matches, the verification is successful; otherwise, the authentication fails.
[0046] The deviation threshold is set to 0.5. When D≤0.5, the comparison is considered successful; otherwise, it is considered an abnormal trajectory and additional verification is triggered, which requires the user to explain the reason for the abnormal location.
[0047] In one specific embodiment, the present invention performs container orchestration management through a container orchestration platform (Kubernetes), including: Automated deployment of microservice unit containers based on YAML configuration files; The system monitors the CPU utilization, memory usage, and network traffic load of each container in real time. When the load exceeds the preset threshold of CPU utilization (e.g., 80%), the automatic scaling module automatically starts new container instances to scale up. When the load is lower than the preset threshold of CPU utilization (e.g., 30%), the automatic scaling module automatically reduces the number of container instances to scale down. The container's running status is monitored through a health check mechanism. Once a fault is detected, the container is immediately restarted or migrated to a healthy node, ensuring the stable operation of microservice units in high-concurrency scenarios.
[0048] The authentication strategy is dynamically adjusted based on the score, and the authentication result is output. By dynamically adjusting the authentication strategy and calculating the risk score based on the risk parameters in the identity verification process, the authentication strategy is adjusted based on the score, and the authentication result is finally output and relevant information is recorded. The dynamic adjustment of authentication policies is executed by the dynamic authentication policy microservice unit, which includes: risk parameter receiving module, risk level assessment module, verification policy generation module, and policy execution module; The risk parameter receiving module collects spatiotemporal trajectory deviation in real time. Biometric matching bias and equipment safety status score Among them, biometric matching bias The value ranges from 0 to 1, where 0 indicates a complete match between the current biometric feature and the baseline feature, and 1 indicates a complete mismatch. The acquisition process relies on the collaborative execution of the client, the identity verification microservice unit, and the authoritative identity information database. The specific process is as follows: First, biometric data collection and format conversion are performed: The client collects user biometric data (fingerprint and facial image features) in real time through built-in sensors (fingerprint sensor, camera), and converts the collected raw biometric data into binary feature data that is universal to the system; Baseline Feature Extraction and Feature Vectorization: The identity verification microservice unit extracts the user's pre-stored baseline biometric data from an authoritative identity information database. It then performs feature vectorization processing on both the currently collected biometric features and the baseline biometric features. Specifically, the fingerprint feature is mapped to a 128-dimensional / 256-dimensional numerical vector (denoted as ) by extracting core points and minutiae features (coordinates, orientation angle, curvature). The current feature vector), facial features are mapped to a numerical vector of the same dimension by extracting key region information (relative positions and textures of the corners of the eyes, nose, and mouth). (reference feature vector); Similarity calculation: First, the difference distance between the two types of feature vectors is calculated using the Euclidean distance formula: in, For the feature vector dimension, For the current feature vector, the th One element, For the baseline eigenvector, the first One element; The maximum reasonable threshold for this type of biological characteristic ( Based on sample testing, a threshold exceeding this value is considered a complete mismatch. The distance is then mapped to a similarity value within the range of 0-1 using a linear normalization formula. :like ,but ;like (Theoretically, this only holds true when the features are completely identical), then ;like ,but ; Finally, the biometric matching bias was calculated. According to the formula To arrive at the final value; Equipment safety status rating The value ranges from 0 to 1, where 1 indicates an extremely high equipment safety risk and 0 indicates that the equipment is completely safe. Its value is obtained through multi-dimensional detection and weighted calculation performed by the equipment safety detection module. The specific process is as follows: First, determine the testing dimensions and standards, clarifying the four core testing dimensions and judgment criteria, including equipment system status, software environment, equipment usage history, and network environment security: Device system status: Detects whether the terminal has been rooted (Android) or jailbroken (iOS); Software environment: Detect whether the device has malicious software (viruses, Trojans) installed, and whether there are any unpatched high-risk vulnerabilities; Device usage history: Based on the "Device ID-BeiDou spatiotemporal data" association record in the distributed spatiotemporal database, it is determined whether it is a frequently used device by the user in the past 3 months. The determination criteria are: the number of authentication requests initiated in the past 3 months is ≥10 and the cumulative usage time is ≥30 hours. Network environment security: Detect whether the currently connected network is encrypted Wi-Fi / official cellular network, and whether there are any signs of abnormal data eavesdropping / tampering; Then, dimensional quantification and weight allocation were performed: each dimension was converted into a quantified score according to the rule of "0 points for safety, 1 point for risk", and recorded as follows: , , , ; assign fixed weights to each dimension based on its degree of impact on equipment safety. (Equipment system status) (Software environment) (Equipment usage history) (Network environment security), and the total weight is 1 (0.3+0.3+0.2+0.2=1). Execution and Score Acquisition: The device security detection module performs four-dimensional detections on each terminal device initiating an authentication request and obtains the corresponding quantitative score for each dimension. , , , ; Calculate the final Value: via formula Calculate the weighted sum to obtain the equipment safety status score. ; The risk level assessment module uses a certification risk scoring algorithm. Calculate certification risk score ,in, , , These are the weighting coefficients, and ; The risk scoring process is as follows: First, the weights of various identity information types are dynamically adjusted based on the security level of the scenario: in high-security scenarios (such as financial transactions), , , In medium-security scenarios (such as social media platforms), , , In low-security scenarios (such as general information access), , , The system automatically associates the corresponding weight coefficients through the scene recognition module. Get S4 calculation Values and biometric comparisons Values and equipment safety testing results value; Then, each value is multiplied by its corresponding weight and summed to obtain the certification risk score. ; The verification strategy generation module is based on Risk level classification: Low risk is Medium risk High risk Each risk level is assigned a corresponding strategy: low risk level uses a basic verification process, including only identity information and spatiotemporal data comparison; medium risk level initiates enhanced verification, which adds a second biometric verification; and high risk level triggers strict verification, including the addition of dynamic passwords and manual review. In one specific embodiment, the corresponding verification interface is invoked to execute the strategy; If the authentication is successful, the system will return a success message to the user and generate an authentication token containing the user's identifier, authentication time, and validity period. If authentication fails, the reason for the failure will be returned. Reasons for authentication failure include identity information mismatch and abnormal spatiotemporal trajectory. Simultaneously, user identity information, authentication request time, verification results at each stage, and risk score data are recorded in the authentication log database for auditing, security analysis, and system optimization, ultimately completing the entire authentication process.
[0049] In one specific embodiment, multi-dimensional identity verification also includes a predictive verification mechanism based on user behavior patterns. This predictive verification mechanism works in conjunction with spatiotemporal trajectory verification to form a two-layer spatiotemporal verification. The specific collaborative relationship includes: spatiotemporal trajectory verification as the first layer of verification, which constructs a historical baseline based on the average of the user's spatiotemporal data over the past three months, calculates the deviation of the current trajectory from the baseline, and identifies sudden anomalies; the predictive verification mechanism as the second layer of verification, which constructs a pattern baseline based on the user's behavioral patterns over the past three months, predicts reasonable behavior in the current scenario, and identifies temporal anomalies. Predictive verification and spatiotemporal trajectory verification are executed in parallel, and the verification result must simultaneously satisfy both spatiotemporal trajectory verification and predictive verification. Specifically, the deviation in spatiotemporal trajectory verification... In predictive verification, the actual location is within the predicted activity area, and the deviation of the movement speed and dwell time from the predicted pattern is ≤20%. If any condition is not met, enhanced verification is triggered, including uploading environmental photos and answering dynamic security questions. It includes a user behavior learning model, which analyzes the user's BeiDou spatiotemporal data over the past three months to extract features such as daily travel time, distribution of frequently visited locations, and frequency of trajectory changes, and constructs a baseline of user behavior patterns. When a user initiates an authentication request, the user behavior learning model predicts the user's reasonable activity area and behavioral characteristics at that time point based on the current time and historical behavior patterns. The current spatiotemporal information of the authentication is compared with the prediction results. If the actual location is outside the predicted activity area or the deviation of the movement speed or dwell time from the prediction pattern in the behavioral characteristics exceeds the preset threshold, the location deviation threshold is configured according to the application scenario, and the movement speed deviation threshold is set to 20% of the historical maximum record, then the enhanced verification process is triggered. The enhanced verification process includes requiring users to upload photos of their current environment in real time and answer preset dynamic security questions. These dynamic security questions are related to key locations in the user's historical trajectory. Only after both verifications are passed can the user's identity be deemed verified.
[0050] In one specific embodiment, generating and verifying dynamic keys further includes a scenario-risk-based adaptive key management enhancement module. This module works in conjunction with the basic key generation logic, dynamically adjusting the key complexity, update frequency, and validity period parameters in the basic key generation logic by acquiring scenario risk level parameters in real time, thereby enhancing the scenario adaptability of key management. Based on user identity, BeiDou timestamp, geographic location and basic key parameters, the system incorporates the user's current scenario characteristics, including terminal device type (e.g., mobile phone, vehicle terminal or IoT device), network environment (e.g., cellular network, Wi-Fi or satellite direct connection) and time period risk level (e.g., 22:00 to 6:00 the next day is a high-risk period). The key complexity is dynamically adjusted based on scenario characteristics, including: generating a 64-bit mixed key containing uppercase and lowercase letters, numbers, and special symbols for high-risk scenarios (such as authenticating via cellular network using an unfamiliar device at night); generating a 48-bit combined key of letters and numbers for medium-risk scenarios (such as authenticating via Wi-Fi using a familiar device during the day); and generating a 32-bit numeric key for low-risk scenarios (such as authenticating using a bound device at a familiar location on a weekday). The validity period of the dynamic key changes dynamically with the risk level of the scenario. The key validity period is dynamically adjusted according to the risk level of the scenario. Specifically, the key validity period is 5 minutes for high-risk scenarios, 15 minutes for medium-risk scenarios, and 30 minutes for low-risk scenarios. The key expires immediately after being used once. During key verification, if the first verification fails, the system automatically analyzes the reason for the failure, including timestamp deviation, location mismatch, and abnormal scene characteristics, and generates differentiated secondary verification instructions based on the reason (for example, if the timestamp is deviated, it requires synchronization with BeiDou time; if the location is mismatched, it requires supplementary location information). After the secondary verification is successful, a dynamic key is regenerated for verification.
[0051] like Figure 2 As shown, based on the above method embodiments, corresponding apparatus embodiments are provided; An embodiment of the present invention provides a dynamic identity authentication device based on BeiDou spatiotemporal information, comprising: a data acquisition module 201, a first calculation module 202, a second calculation module 203, a third calculation module 204, a fourth calculation module 205, and an identity authentication module 206; The data acquisition module is used to receive authentication request data sent by the user and to acquire BeiDou standard spatiotemporal data of the user's location. The first calculation module is used to verify the authentication request data, and after the verification is passed, to match the authentication request data with a preset identity information database and calculate the identity matching degree. The second calculation module is used to obtain the user's historical identity authentication trajectory and historical identity authentication time, calculate the trajectory overlap degree between the BeiDou standard spatiotemporal data and the historical identity authentication trajectory, calculate the time pattern matching degree between the BeiDou standard spatiotemporal data and the historical identity authentication time, and determine the comprehensive behavior similarity based on the trajectory overlap degree and the time pattern matching degree. The third calculation module is used to obtain the current authentication scenario type, determine the weight set according to the current authentication scenario type, and perform weighted calculation based on the identity matching degree, the comprehensive behavior similarity and the weight set to obtain the comprehensive matching degree. The fourth calculation module is used to calculate the deviation based on the BeiDou standard spatiotemporal data, the historical identity authentication trajectory, and the historical identity authentication time after the comprehensive behavioral similarity is greater than or equal to a preset matching threshold. The identity authentication module is used to generate a dynamic key based on the authentication request data when the deviation is less than or equal to a preset deviation threshold, so that the user can perform identity authentication based on the dynamic key.
[0052] It is understood that the above-described device embodiments correspond to the method embodiments of the present invention, and can implement the dynamic identity authentication method based on BeiDou spatiotemporal information provided by any of the above-described method embodiments of the present invention.
[0053] It should be noted that the device embodiments described above are merely illustrative, and some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can specifically be implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0054] Based on the above embodiments of the dynamic identity authentication method based on BeiDou spatiotemporal information, another embodiment of the present invention provides a terminal device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the dynamic identity authentication method based on BeiDou spatiotemporal information of any embodiment of the present invention.
[0055] For example, in this embodiment, the computer program can be divided into one or more modules, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the terminal device.
[0056] The terminal device may be a desktop computer, laptop, handheld computer, or cloud server, etc. The terminal device may include, but is not limited to, a processor and a memory.
[0057] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the terminal device, connecting all parts of the terminal device via various interfaces and lines.
[0058] Based on the above-described method embodiments, another embodiment of the present invention provides a computer-readable storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute the dynamic identity authentication method based on BeiDou spatiotemporal information as described in any of the above-described method embodiments of the present invention.
[0059] The modules / units integrated in the device / terminal equipment, if implemented as software functional units and sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.
[0060] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A dynamic identity authentication method based on Beidou space-time information, characterized in that, The application relates to a method for identity authentication based on Beidou standard space-time data. The method comprises the following steps: receiving authentication request data sent by a user and obtaining Beidou standard space-time data of a position where the user is located; checking the authentication request data, and after the checking is passed, performing identity matching on the authentication request data and a preset identity information database, and calculating an identity matching degree; obtaining a historical identity authentication track and a historical identity authentication time of the user, calculating a track coincidence degree of the Beidou standard space-time data and the historical identity authentication track, calculating a time rule matching degree of the Beidou standard space-time data and the historical identity authentication time, and determining a comprehensive behavior similarity according to the track coincidence degree and the time rule matching degree; obtaining a current authentication scene type, determining a weight set according to the current authentication scene type, performing weighted calculation according to the identity matching degree, the comprehensive behavior similarity and the weight set, and obtaining a comprehensive matching degree; when the comprehensive behavior similarity is greater than or equal to a preset matching degree threshold, calculating a deviation degree according to the Beidou standard space-time data, the historical identity authentication track and the historical identity authentication time; 2.The dynamic identity authentication method based on Beidou space-time information of claim 1, wherein, when the deviation degree is less than or equal to a preset deviation degree threshold, generating a dynamic key based on the authentication request data, so that the user performs identity authentication based on the dynamic key. The receiving of the authentication request data sent by the user comprises the following steps: 3.The dynamic identity authentication method based on Beidou space-time information of claim 2, wherein, receiving authentication request data sent by the user through a client; wherein the authentication request data comprises encrypted biological characteristics, basic identity information and device position information. The client comprises the following steps: the client receives basic identity information input by the user and records device position information where the client is located; the client collects biological characteristics of the user, and converts the biological characteristics into original biological characteristic binary data; the client obtains a timestamp and a basic key, and splices the timestamp and the basic key to obtain a splicing result; the client inputs the splicing result into a hash function to obtain a hash value; the client performs exclusive or operation on the original biological characteristic binary data and the hash value to obtain encrypted biological characteristics; 4. The dynamic identity authentication method based on Beidou space-time information according to claim 3, characterized in that, the client sends the encrypted biological characteristics, the basic identity information and the device position information. The obtaining of the Beidou standard space-time data of the position where the user is located comprises the following steps: obtaining Beidou original space-time data of the position where the user is located from a distributed space-time database; obtaining the Beidou original space-time data from the distributed space-time database; wherein the distributed space-time database is constructed by receiving real-time space-time data collected by different Beidou terminal devices, pre-processing the real-time space-time data to obtain Beidou original space-time data, and storing the Beidou original space-time data in the distributed space-time database; performing noise filtering on the Beidou original space-time data by using a Beidou space-time data noise filtering algorithm to obtain Beidou denoised space-time data; synchronizing a Beidou timestamp of the Beidou denoised space-time data with a preset standard time reference, converting Beidou geographic position data in the Beidou denoised space-time data into general geographic position data in a general geographic coordinate system, and then obtaining Beidou standard space-time data.
5. The dynamic identity authentication method based on Beidou space-time information according to claim 4, characterized in that, The identity matching of the authentication request data with the preset identity information database and the identity matching degree calculation comprise: Matching the authentication request data in the preset identity database to obtain a matching result; wherein the identity database comprises a plurality of user identity information; each user identity information specifically comprises basic identity data and corresponding encrypted biological characteristics input by the user in advance; Calculating the identity matching degree between the matching result and the authentication request data.
6. The dynamic identity authentication method based on Beidou space-time information according to claim 5, characterized in that, The calculation of the trajectory coincidence degree of the Beidou standard space-time data and the historical identity authentication trajectory, the calculation of the time rule matching degree of the Beidou standard space-time data and the historical identity authentication time, and the determination of the comprehensive behavior similarity according to the trajectory coincidence degree and the time rule matching degree comprise: Determining a historical high-frequency activity area according to the historical identity authentication trajectory; Determining a spatial intersection area according to the position of the Beidou standard space-time data and the position of the historical high-frequency activity area; Calculating the trajectory coincidence degree by substituting the spatial intersection area and the total area of the historical high-frequency activity area into a coincidence degree calculation formula; Determining a historical average authentication time of the same period as the Beidou standard space-time data according to the historical identity authentication time; Calculating the time rule matching degree by substituting the historical average authentication time and the authentication time of the Beidou standard space-time data into a rule matching degree calculation formula; Obtaining the comprehensive behavior similarity by multiplying the trajectory coincidence degree and the time rule matching degree by a preset weight value and summing them up.
7. The dynamic identity authentication method based on Beidou space-time information according to claim 6, characterized in that, The calculation of the deviation degree according to the Beidou standard space-time data, the historical identity authentication trajectory, and the historical identity authentication time comprises: Determining a historical position change rate, a historical working area stay time, and a historical trajectory curvature according to the historical identity authentication trajectory and the historical identity authentication time; Determining a current position change rate, a current working area stay time, and a current trajectory curvature according to the Beidou standard space-time data; Obtaining the deviation degree by substituting the historical position change rate, the historical working area stay time, the historical trajectory curvature, the current position change rate, the current working area stay time, and the current trajectory curvature into a deviation degree calculation formula.
8. A dynamic identity authentication device based on Beidou space-time information, characterized in that, It comprises: A data acquisition module, a first calculation module, a second calculation module, a third calculation module, a fourth calculation module, and an identity authentication module; The data acquisition module is configured to receive authentication request data sent by a user and acquire Beidou standard space-time data of a position where the user is located; The first calculation module is configured to verify the authentication request data, and after verification, match the authentication request data with a preset identity information database and calculate an identity matching degree; The second calculation module is configured to acquire a historical identity authentication trajectory and a historical identity authentication time of the user, calculate a trajectory coincidence degree of the Beidou standard space-time data and the historical identity authentication trajectory, calculate a time rule matching degree of the Beidou standard space-time data and the historical identity authentication time, and determine a comprehensive behavior similarity according to the trajectory coincidence degree and the time rule matching degree; The third calculation module is used to obtain the current authentication scenario type, determine the weight set according to the current authentication scenario type, and perform weighted calculation based on the identity matching degree, the comprehensive behavior similarity and the weight set to obtain the comprehensive matching degree. The fourth calculation module is used to calculate the deviation based on the BeiDou standard spatiotemporal data, the historical identity authentication trajectory, and the historical identity authentication time after the comprehensive behavioral similarity is greater than or equal to a preset matching threshold. The identity authentication module is used to generate a dynamic key based on the authentication request data when the deviation is less than or equal to a preset deviation threshold, so that the user can perform identity authentication based on the dynamic key.
9. A terminal device, comprising: The method includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the dynamic identity authentication method based on BeiDou spatiotemporal information as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, include: A stored computer program, wherein, when the computer program is executed, it controls the device containing the computer-readable storage medium to perform the dynamic identity authentication method based on BeiDou spatiotemporal information as described in any one of claims 1-7.