Expert signature system based on multi-factor authentication
By using a multi-factor authentication system and risk assessment model, the authentication factor collection strategy is dynamically adjusted. Combined with an immutable timestamp, the problems of low accuracy and insufficient security of identity verification in the bidding evaluation system are solved, the authenticity and traceability of signatures are realized, and the bidding evaluation efficiency is improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-11
- Publication Date
- 2026-04-14
AI Technical Summary
The existing bidding evaluation system suffers from low accuracy in identity verification of electronic signatures, insufficient security, poor compatibility and integration, and difficulty in effectively identifying identity fraud and tracing signature time.
A multi-factor authentication system is adopted, integrating a multi-dimensional cross-validation mechanism. The importance of the evaluation process is perceived through a risk assessment model, the collection strategy of authentication factors is dynamically adjusted, and an immutable timestamp is added for signature traceability.
This improved the overall efficiency of the bid evaluation process, reduced the risk of identity theft, ensured the authenticity and immutability of signatures, and provided a reliable basis for subsequent data verification.
Smart Images

Figure CN121859320A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of signature authentication technology, and in particular to an expert signature system based on multi-factor authentication. Background Technology
[0002] In current bid evaluation processes, electronic signatures are gradually replacing traditional handwritten signatures, becoming an important way for review experts to confirm bid evaluation results. In existing technologies, the electronic signature process in bid evaluation systems often employs a single authentication method, commonly including account password verification or simple facial recognition verification.
[0003] In practical applications, existing technologies have significant drawbacks and shortcomings. Firstly, the accuracy of identity verification is low; a single verification method is insufficient to effectively identify identity fraud, such as someone else using an expert's account password or a simulated facial image to pass verification, leading to doubts about the ownership of electronic signatures. Secondly, signature security is inadequate; most electronic signatures only record the signature content without simultaneously attaching an immutable timestamp, making it impossible to accurately trace the signature time. If signature data is tampered with, effective evidence collection and verification are difficult. Thirdly, system compatibility and integration are poor; the verification modules of existing signature devices mostly operate independently, resulting in delays in data interaction with the bidding evaluation system, affecting the overall efficiency of the bidding evaluation process. Summary of the Invention
[0004] The purpose of this application is to provide an expert signature system based on multi-factor authentication to solve the above-mentioned technical problems, thereby ensuring the authenticity and immutability of electronic signatures during the bid evaluation process and improving the overall efficiency of the bid evaluation work.
[0005] In some embodiments of this application, a multi-factor collection structure is integrated to construct a multi-dimensional cross-validation mechanism. By adding a risk assessment model to perceive the importance of the real-time evaluation process, the collection strategy for authentication factors is dynamically adjusted, thereby improving the overall efficiency of the evaluation work while effectively avoiding the vulnerabilities of a single verification method and significantly reducing the risk of identity theft.
[0006] In some embodiments of this application, a first storage module is added to strongly associate the collected signatures with the corresponding evaluation content. At the same time, by adding an immutable timestamp, the signature time is accurately recorded, realizing full traceability of the signature behavior and providing a reliable basis for subsequent data verification and dispute resolution.
[0007] In some embodiments of this application, an expert signature system based on multi-factor authentication is provided, including: Factor acquisition unit, used to collect authentication factor data; A security assessment unit is used to establish a risk assessment model, and the security unit is also used to set a monitoring strategy library based on the risk assessment model. The sensing unit is used to acquire risk feedback data for the current signature task; The sensing unit is also used to set the primary monitoring strategy for the current signature task based on risk feedback data and risk assessment model. The factor acquisition unit is used to collect authentication factor data for the current signature task according to the primary monitoring strategy. The factor acquisition unit is also used to generate a signature feedback package; The central control unit is used to build the certification assessment model.
[0008] In some embodiments of this application, the central control unit includes: The first user module is used to establish a user sequence A, A=(a1,a2…a…). i …a n ), where a i Let i be the i-th user; n be the number of users; The first user module is also used to establish storage sub-databases for each user; The first processing module is used to set a sequentially according to the user sequence A. i For target users; Set up a comparison sub-model for the target user based on the target user's storage sub-database; Set up the comparison sub-models for each user in sequence; The first processing module is used to construct a signature comparison model based on all comparison sub-models; The first processing module is also used to set multiple authentication factors; Each user's evaluation sub-model is set sequentially based on all authentication factors; The first processing module is also used to construct a signature evaluation model based on all evaluation sub-models; The authentication evaluation model is set based on the signature comparison model and the signature evaluation model.
[0009] In some embodiments of this application, the central control unit further includes: The second processing module is used to obtain the signature feedback packet and generate abnormal violation values of the signature feedback packet according to the authentication evaluation model. The second processing module is also used to determine whether to generate an early warning instruction for the current signature task based on the abnormal violation value; The first storage module is used to generate a storage sub-package for signature tasks.
[0010] In some embodiments of this application, the sensing unit includes: The first perception module is used to set multiple risk-related indicators; The first perception module is also used to construct a risk assessment model based on risk correlation indicators; The second sensing module is used to establish multiple expected risk value intervals; Establish a sequence B of expected risk value intervals, B = (b1, b2... b i …b m ), where b i is the i-th expected risk value interval; m is the number of expected risk value intervals; Set the monitoring sub-strategies for each expected risk value in sequence, and construct a monitoring strategy library according to all the monitoring sub-strategies.
[0011] In some embodiments of the present application, the sensing unit further includes: The third sensing module is used to obtain the risk feedback data of the current signature task; The third sensing module is further used to generate the expected risk value b' of the current signature task according to the risk assessment model and the risk feedback data; b' = β i *s i ; where, θ1 is the number of risk correlation indicators; β i is the influence factor of the i-th risk correlation indicator; s i is the reference value of the i-th risk correlation indicator generated according to the risk feedback data of the current signature task; Set the first-level monitoring strategy according to the expected risk value b'.
[0012] In some embodiments of the present application, the second processing module is further used to: Obtain the signature feedback packet of the current signature task: Generate the signature image to be compared and the authentication factor packet according to the signature feedback packet; Set the first-level comparison model of the current signature task according to the authentication evaluation model; Generate the first-level outlier c of the signature image to be compared according to the first-level comparison model; Preset the first-level outlier threshold C1; If c > C1, generate the first-level early warning instruction of the current signature task; If c < C1, generate the first-level authentication instruction of the current signature task.
[0013] In some embodiments of the present application, the first-level authentication instruction includes: Set multiple authentication nodes according to the first-level monitoring strategy; Set the first-level evaluation model of the current signature task according to the authentication evaluation model; Generate the deviation values of each authentication node according to the authentication factor packet and the first-level evaluation model; Generate the abnormal violation value f of the current signature task; f = e * d i ; e = U1 * Y(i) * (d i - d')]; Among them, e is the deviation compensation coefficient; θ2 is the number of authentication nodes; d i is the deviation value of the i-th authentication node; U1 is the preset first conversion coefficient; d' is the preset deviation value threshold; Y(i) is the selection coefficient; if (d i - d') > 0, Y(i) = 1; if (d i - d') < 0, Y(i) = 0; Preset the violation outlier threshold F1; If f > F1, generate a first-level warning instruction for the current signature task; If f < F1, generate a first-level storage instruction for the current signature task.
[0014] In some embodiments of the present application, generating the deviation values of each authentication node includes: Sequentially select target authentication nodes according to all authentication nodes; Generate an associated sub-packet of the target authentication node according to the authentication factor packet; Generate the deviation value d of the target authentication node according to the associated sub-packet; d = η i * j i ; Among them, θ3 is the number of authentication factors selected according to the first-level monitoring strategy; η i为 is the weight coefficient of the i-th selected authentication factor; j i is the difference value of the i-th authentication factor generated according to the associated sub-packet; Sequentially generate the difference values of each authentication node.
[0015] In some embodiments of the present application, the first storage module is further configured to: Obtain the mapping data packet of the current signature task according to the first-level storage instruction; Generate a signature sub-image according to the signature feedback packet of the current signature task; Generate a first-level timestamp; Generate a verification hash value according to the mapping data packet; Generate a storage sub-packet of the current signature task according to the signature sub-image, the first-level timestamp and the verification hash value; Set the target storage sub-library according to the current signature task; Send the storage sub-packet to the target storage sub-library.
[0016] In some embodiments of this application, generating a first-level outlier c of the signature image to be compared based on a first-level comparison model includes: Generate a pair of first-level signature images based on the first-level comparison model; Generate matching values between the image to be compared and each first-level signature image; Establish a sequence of matching values H, H=(h1,h2…h i …h r ), where h i Let r be the matching value between the signature image to be compared and the i-th first-level signature image; r is the number of first-level signature images. Select the maximum value h from the sequence of matching values H max ; Preset matching threshold H1; If h max H1 generates a secondary authentication command, and sets a primary exception value c based on the secondary authentication command; If h max c=U2*[ h i ]; Where U2 is the preset second conversion coefficient; r is the number of first-level signature images.
[0017] Compared with existing technologies, the expert signature system based on multi-factor authentication proposed in this application has the following advantages: By integrating a multi-factor data collection structure, constructing a multi-dimensional cross-validation mechanism, and adding a risk assessment model to perceive the importance of the real-time evaluation process, the data collection strategy for authentication factors is dynamically adjusted, thereby improving the overall efficiency of the evaluation work while effectively avoiding the vulnerabilities of a single verification method and significantly reducing the risk of identity theft.
[0018] By adding a first storage module, the collected signatures and corresponding evaluation content are strongly correlated. At the same time, by adding an immutable timestamp, the signing time is accurately recorded, realizing full traceability of the signing behavior and providing a reliable basis for subsequent data verification and dispute resolution. Attached Figure Description
[0019] Figure 1 This is a schematic diagram of the structure of an expert signature system based on multi-factor authentication in a preferred embodiment of this application. Detailed Implementation
[0020] The specific embodiments of this application will be described in further detail below with reference to the accompanying drawings and examples. The following examples are used to illustrate this application, but are not intended to limit the scope of this application.
[0021] In the description of this application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.
[0022] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0023] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.
[0024] like Figure 1 As shown, a preferred embodiment of this application provides an expert signature system based on multi-factor authentication, comprising: Factor acquisition unit, used to collect authentication factor data; The security assessment unit is used to establish a risk assessment model. The security unit is also used to set up a monitoring strategy library based on the risk assessment model. The sensing unit is used to acquire risk feedback data for the current signature task; The sensing unit is also used to set the primary monitoring strategy for the current signature task based on risk feedback data and risk assessment models; The factor acquisition unit is used to collect authentication factor data for the current signature task according to the primary monitoring strategy. The factor acquisition unit is also used to generate signature feedback packets; The central control unit is used to build the certification assessment model.
[0025] Specifically, authentication factors include, but are not limited to, identity data, facial images, and dynamic biometric parameters that can be used for signature authentication, such as signing speed and signing pressure.
[0026] Specifically, the factor acquisition unit is preferably a multi-category data acquisition device used to collect various authentication factor data such as user identity data, facial images, signing speed, and signing pressure.
[0027] Specifically, the central control unit includes: The first user module is used to establish a user sequence A, A=(a1,a2…a…). i …a n ), where a i Let i be the i-th user; n be the number of users; The first user module is also used to establish storage sub-databases for each user; The first processing module is used to set a sequentially according to the user sequence A. i For target users; Set up a comparison sub-model for the target user based on the target user's storage sub-database; Set up the comparison sub-models for each user in sequence; The first processing module is used to construct a signature comparison model based on all the comparison sub-models; The first processing module is also used to set multiple authentication factors; Each user's evaluation sub-model is set sequentially based on all authentication factors; The first processing module is also used to construct a signature evaluation model based on all evaluation sub-models; The authentication evaluation model is set based on the signature comparison model and the signature evaluation model.
[0028] Specifically, by analyzing historical bidding data, all bidding experts are selected, and a user column A is established based on all bidding experts, where each user represents one bidding expert.
[0029] Specifically, by establishing a storage sub-database for the target user, the mapping data packets of all the user's historical signature tasks are saved, and the complete signatures saved in each mapping data packet are extracted as first-level signature images. Based on all first-level signature images, a corresponding comparison sub-model is constructed.
[0030] Specifically, the storage sub-database also includes the target user's terminal parameters (i.e., the habitual device, including model and category (mobile phone, tablet, computer), which can be multiple, terminal IP address (i.e., habitual address), terminal location (i.e., the user's usual activity range), and other parameters.
[0031] Specifically, historical monitoring data of the target user is obtained to generate standard parameters for each authentication factor of the target user (such as corresponding facial data, identity data, signing speed and signing pressure parameters), and a corresponding comparison evaluation model is constructed based on all comparison parameters.
[0032] Specifically, the central control unit also includes: The second processing module is used to obtain the signature feedback packet and generate abnormal violation values of the signature feedback packet according to the authentication evaluation model. The second processing module is also used to determine whether to generate an early warning instruction for the current signature task based on the abnormal violation value; The first storage module is used to generate a storage sub-package for signature tasks.
[0033] It is understandable that, in the above embodiments, by integrating a multi-factor collection structure and constructing a multi-dimensional cross-validation mechanism, the vulnerabilities of a single verification method are effectively avoided, and the risk of identity theft is significantly reduced.
[0034] In a preferred embodiment of this application, the sensing unit includes: The first perception module is used to set multiple risk-related indicators; The first perception module is also used to build a risk assessment model based on risk-related indicators; The second sensing module is used to establish multiple expected risk value ranges; Establish a sequence B of expected risk value intervals, B = (b1, b2, ..., bb2). i …b m ), where b i Let be the i-th expected risk value interval; m is the number of expected risk value intervals; Set up monitoring sub-strategies for each expected risk value in sequence, and build a monitoring strategy library based on all monitoring sub-strategies.
[0035] Specifically, risk-related indicators include, but are not limited to: terminal parameter differences (whether it is a commonly used device; the greater the difference from a commonly used device, the higher the corresponding reference value), terminal IP address differences (whether it is a commonly used address; the greater the difference from a commonly used address, the higher the corresponding reference value), terminal location differences (whether it is in a historical record location; the farther away from a historical record location, the higher the corresponding reference value), and evaluation content (the importance of relevant data; the higher the importance, the higher the corresponding reference value), etc., parameters related to the signature environment. By quantifying each risk-related indicator, the reference values of each risk-related indicator are made to fall within the same range.
[0036] Specifically, by weighting the reference values of various risk-related indicators, expected risk values are generated, and by analyzing historical bidding data, multiple expected risk value ranges are constructed.
[0037] Specifically, based on the different signature environments corresponding to each expected risk value range, the corresponding monitoring sub-strategy is dynamically adjusted. Each monitoring sub-strategy includes the required collection frequency of authentication factors. The higher the expected risk value, the more types of authentication factors need to be collected, and the higher the corresponding collection frequency. Moreover, the monitoring sub-strategy corresponding to each expected risk value range is different.
[0038] Specifically, the sensing unit also includes: The third sensing module is used to obtain risk feedback data for the current signature task; The third perception module is also used to generate the expected risk value b' of the current signature task based on the risk assessment model and risk feedback data; b'=[ β i *s i ]; Where θ1 represents the number of risk-related indicators; β i s is the influencing factor of the i-th risk-related indicator; i It is the reference value of the i-th risk-related indicator generated based on the risk feedback data of the current signature task; A primary monitoring strategy is set based on the expected risk value b'.
[0039] Specifically, the risk feedback data includes the real-time terminal parameters, real-time terminal IP address, real-time terminal location, and the context of the corresponding evaluation content for the current signature task. By analyzing the risk feedback data, real-time reference values for various risk-related indicators are generated.
[0040] Specifically, the higher the expected risk value, the higher the likelihood of forged signatures in the current signing environment.
[0041] Specifically, the impact factors of each risk-related indicator are set according to their degree of correlation with forged signatures. The greater the degree of correlation, the larger the value of the corresponding impact factor.
[0042] Specifically, the monitoring sub-strategy corresponding to the expected risk value range in which the expected risk value b' is located is set as the first-level monitoring strategy.
[0043] It is understandable that, in the above embodiments, by adding a risk assessment model to perceive the importance of the real-time bidding process, the collection strategy for certification factors is dynamically adjusted to improve the overall efficiency of the bidding process.
[0044] In a preferred embodiment of this application, the second processing module is further configured to: Retrieve the signature feedback packet for the current signing task: Generate a signature image to be compared and an authentication factor package based on the signature feedback package; Set the first-level comparison model for the current signature task according to the authentication evaluation model; Generate the first-level outlier c of the signature image to be compared according to the first-level comparison model; Preset the first-level outlier threshold C1; If c > C1, generate a first-level warning instruction for the current signature task; If c < C1, generate a first-level authentication instruction for the current signature task.
[0045] Specifically, generating the first-level outlier c of the signature image to be compared according to the first-level comparison model includes: Generate multiple first-level signature images according to the first-level comparison model; Generate the fitting values between the image to be compared and each first-level signature image; Establish a fitting value sequence H, H=(h1, h2…h i …h r ), where h i is the fitting value between the signature image to be compared and the i-th first-level signature image; r is the number of first-level signature images; Select the maximum value h max in the fitting value sequence H; Preset the fitting value threshold H1; If h max > H1, generate a second-level authentication instruction, and set the first-level outlier c according to the second-level authentication instruction; If h max < H1, generate the first-level outlier c according to all the fitting values; c = U2 * h i ; Among them, U2 is the preset second conversion coefficient; r is the number of first-level signature images.
[0046] Specifically, the first-level outlier threshold can be set according to historical parameters. When the real-time first-level outlier is greater than the preset first outlier threshold, it indicates that the signature collected in the current signature task is a forged signature, and a first-level warning instruction needs to be generated in time for processing to reduce the risk of identity theft.
[0047] Specifically, set the comparison sub-model corresponding to the user of the current signature task as the first-level comparison model.
[0048] Specifically, make the first-level outlier fall within the preset value range through the preset second conversion coefficient, and h i The larger the value of ], the smaller the corresponding first-level outlier, and the mapping relationship between the two can be set according to historical parameters.
[0049] Specifically, handwriting analysis is performed on the signature image to be compared and each first-level signature image to generate corresponding matching values. The larger the matching value, the more similar the signature in the signature image to be compared and the current first-level signature image.
[0050] Specifically, the matching value threshold can be set according to historical handwriting analysis data. When the matching value of two signatures is greater than the preset matching value threshold, it can be presumed that the two signatures are replicas of the same signature, that is, exactly the same. At this time, it is necessary to determine whether the hash value of the mapped data packet corresponding to the signature image to be compared is the same as the verification hash value of this first-level signature image according to the secondary authentication instruction. If not, it means that the signature in the signature image to be compared is a forged signature, and at this time, the corresponding first-level outlier value is set to the preset first-level outlier value threshold. If they are the same, it means that repeated verification is being performed, and this signature task is directly excluded.
[0051] In the preferred embodiment of this application, the first-level authentication instruction includes: Setting multiple authentication nodes according to the first-level monitoring strategy; Setting the first-level evaluation model of the current signature task according to the authentication evaluation model; Generating the deviation value of each authentication node according to the authentication factor package and the first-level evaluation model; Generating the abnormal violation value f of the current signature task; f = e * d i ; e = U1 * Y(i) * (d i - d'); Among them, e is the deviation compensation coefficient; θ2 is the number of authentication nodes; d i is the deviation value of the i-th authentication node; U1 is the preset first conversion coefficient; d' is the preset deviation value threshold; Y(i) is the selection coefficient; if (d i - d') > 0, Y(i) = 1; if (d i - d') < 0, Y(i) = 0; Presetting the violation outlier value threshold F1; If f > F1, generating the first-level warning instruction of the current signature task; If f < F1, generating the first-level storage instruction of the current signature task.
[0052] Specifically, multiple authentication nodes are set according to the data collection frequency and the overall collection volume in the first-level monitoring strategy (that is, one authentication node corresponds to one data collection node).
[0053] Specifically, the deviation compensation coefficient e is made to be within the preset value range through the preset first conversion coefficient, and Y(i) * (di The larger the value of -d')], the larger the corresponding deviation compensation coefficient e value will be. The mapping relationship between the two can be set according to historical parameters.
[0054] Specifically, the deviation threshold can be set based on historical parameters. If the deviation value of the current authentication node is greater than the preset deviation threshold, it indicates that the current authentication node has a potential risk of identity theft.
[0055] Specifically, the threshold for abnormal violation values can be set based on historical parameters. If the abnormal violation value exceeds the preset threshold, it indicates that the current signature task is at risk of forgery and must be handled according to the Level 1 warning instruction to reduce the risk of identity theft and ensure the authenticity and immutability of the electronic signature.
[0056] Specifically, the deviation values for each authentication node are generated, including: Select the target authentication node sequentially from all authentication nodes; Generate associated sub-packages for the target authentication node based on the authentication factor package; The deviation value d of the target authentication node is generated based on the associated sub-packages; d=[ η i *j i ]; Where θ3 is the number of certification factors selected according to the primary monitoring strategy; η i为 The weight coefficient of the selected i-th authentication factor; j i It is the difference value of the i-th authentication factor generated based on the associated sub-package; The difference values for each authentication node are generated sequentially.
[0057] Specifically, the evaluation sub-model corresponding to the user of the current signature task is set as the first-level evaluation model. Specifically, by filtering the certification factor package, data collection nodes corresponding to the target certification node are selected to obtain data for each certification factor, and this data is compared with the parameters of each certification factor in the primary evaluation model. A difference degree is generated for each certification factor, and a corresponding difference value is set based on the difference degree; the greater the difference degree, the larger the corresponding difference value.
[0058] Specifically, corresponding influence factors are set according to the degree of correlation between each authentication factor and the risk of identity theft. The greater the degree of correlation, the larger the value of the corresponding influence factor. The mapping relationship between the two can be set according to historical parameters.
[0059] In a preferred embodiment of this application, the first storage module is further configured to: Retrieve the mapping data packet for the current signature task according to the first-level storage instructions; Generate a signature sub-image based on the signature feedback packet of the current signature task; Generate a first-level timestamp; Generate a verification hash value based on the mapped data packet; Generate a storage sub-packet for the current signing task based on the signature sub-image, first-level timestamp, and verification hash value; Set the target storage sub-repository based on the current signature task; Send the storage sub-packet to the target storage sub-database.
[0060] Specifically, the mapping data packet contains the evaluation content data corresponding to the current signature task.
[0061] Specifically, the first-level timestamp is the time node when the second processing module obtains the signature feedback packet.
[0062] It can be understood that, in the above embodiments, by strongly associating the collected signatures with the corresponding evaluation content, and by adding an immutable timestamp to accurately record the signature time, the entire process of signature behavior can be traced, providing a reliable basis for subsequent data verification and dispute resolution.
[0063] Based on the first concept of this application, a multi-dimensional cross-validation mechanism is constructed by integrating a multi-factor collection structure. By adding a risk assessment model to perceive the importance of the real-time evaluation process, the collection strategy for authentication factors is dynamically adjusted, thereby improving the overall efficiency of the evaluation work while effectively avoiding the vulnerabilities of a single verification method and significantly reducing the risk of identity theft.
[0064] According to the second concept of this application, by adding a first storage module, the collected signatures and corresponding evaluation content are strongly correlated. At the same time, by adding an immutable timestamp, the signature time is accurately recorded, realizing full traceability of the signature behavior and providing a reliable basis for subsequent data verification and dispute resolution.
[0065] The above are merely preferred embodiments of this application. It should be noted that, for those skilled in the art, several improvements and substitutions can be made without departing from the technical principles of this application, and these improvements and substitutions should also be considered within the scope of protection of this application.
Claims
1. An expert signature system based on multi-factor authentication, characterized in that, Comprising: A factor acquisition unit for acquiring authentication factor data; A security assessment unit for establishing a risk assessment model, and the security unit is also used for setting a monitoring strategy library according to the risk assessment model; A perception unit for obtaining risk feedback data of the current signature task; The perception unit is also used for setting a first-level monitoring strategy for the current signature task according to the risk feedback data and the risk assessment model; The factor acquisition unit for acquiring authentication factor data of the current signature task according to the first-level monitoring strategy; The factor acquisition unit is also used for generating a signature feedback package; A central control unit for constructing an authentication assessment model.
2. The expert signature system based on multi-factor authentication as described in claim 1, characterized in that, The central control unit includes: The first user module is used to establish a user sequence A, A=(a1,a2…a…). i …a n ), where a i Let i be the i-th user; n be the number of users; The first user module is also used for establishing a storage sub-library for each user; The first processing module is used to set a sequentially according to the user sequence A. i For target users; Setting a comparison sub-model for the target user according to the storage sub-library of the target user; Sequentially setting comparison sub-models for each user; The first processing module is used for constructing a signature comparison model according to all the comparison sub-models; The first processing module is also used for setting multiple authentication factors; Sequentially setting evaluation sub-models for each user according to all the authentication factors; The first processing module is also used for constructing a signature evaluation model according to all the evaluation sub-models; Setting an authentication assessment model according to the signature comparison model and the signature evaluation model.
3. The expert signature system based on multi-factor authentication as described in claim 2, characterized in that, The central control unit also includes: A second processing module for obtaining the signature feedback package and generating an abnormal violation value of the signature feedback package according to the authentication assessment model; The second processing module is also used for judging whether to generate a warning instruction for the current signature task according to the abnormal violation value; A first storage module for generating a storage sub-package of the signature task.
4. The expert signature system based on multi-factor authentication as described in claim 3, characterized in that, The perception unit includes: A first perception module for setting multiple risk correlation indicators; The first perception module is also used for constructing a risk assessment model according to the risk correlation indicators; A second perception module for establishing multiple expected risk value intervals; Establish a sequence B of expected risk value intervals, B = (b1, b2, ..., bb2). i …b m ), where b i Let be the i-th expected risk value interval; m is the number of expected risk value intervals; Sequentially setting monitoring sub-strategies for each expected risk value, and constructing a monitoring strategy library according to all the monitoring sub-strategies.
5. The expert signature system based on multi-factor authentication as described in claim 4, characterized in that, The perception unit also includes: A third perception module for obtaining risk feedback data of the current signature task; The third perception module is also used for generating an expected risk value b' of the current signature task according to the risk assessment model and the risk feedback data; b'=[ b i *s i ]; Where θ1 represents the number of risk-related indicators; β i s is the influencing factor of the i-th risk-related indicator; i It is the reference value of the i-th risk-related indicator generated based on the risk feedback data of the current signature task; Setting a first-level monitoring strategy according to the expected risk value b'.
6. The expert signature system based on multi-factor authentication as described in claim 5, characterized in that, The second processing module is also used for: Obtaining the signature feedback package of the current signature task: Generating a signature image to be compared and an authentication factor package according to the signature feedback package; Setting a first-level comparison model for the current signature task according to the authentication assessment model; Generating a first-level abnormal value c of the signature image to be compared according to the first-level comparison model; Presetting a first-level abnormal value threshold C1; If c > C1, generating a first-level warning instruction for the current signature task; If c < C1, generating a first-level authentication instruction for the current signature task.
7. The expert signature system based on multi-factor authentication as described in claim 6, characterized in that, The first-level authentication instruction includes: Setting multiple authentication nodes according to the first-level monitoring strategy; Setting a first-level evaluation model for the current signature task according to the authentication assessment model; Generating a deviation value for each authentication node according to the authentication factor package and the first-level evaluation model; Generating an abnormal violation value f of the current signature task; f=e*[ d i ]; e=U1*[ Y(i)*(d i -d')]; Where e is the deviation compensation coefficient; θ2 is the number of certified nodes; d i Let be the deviation value of the i-th authentication node; U1 is the preset first conversion coefficient; d' is the preset deviation threshold; Y(i) is the selection coefficient; if (d i -d')>0, Y(i)=1; if (d i -d')<0,Y(i)=0; Presetting a violation abnormal value threshold F1; If f > F1, generating a first-level warning instruction for the current signature task; If f < F1, generate a first-level storage instruction for the current signature task.
8. The expert signature system based on multi-factor authentication as described in claim 7, characterized in that, Generate deviation values for each authentication node, including: Sequentially select target authentication nodes based on all authentication nodes; Generate an associated sub-package for the target authentication node according to the authentication factor package; Generate a deviation value d for the target authentication node according to the associated sub-package; d=[ or i *j i ]; Where θ3 is the number of certification factors selected according to the primary monitoring strategy; η i j is the weight coefficient of the selected i-th authentication factor; i It is the difference value of the i-th authentication factor generated based on the associated sub-package; Sequentially generate difference values for each authentication node.
9. The expert signature system based on multi-factor authentication as described in claim 8, characterized in that, The first storage module is further configured to: Obtain a mapped data packet for the current signature task according to the first-level storage instruction; Generate a signature sub-image according to the signature feedback packet of the current signature task; Generate a first-level timestamp; Generate a verification hash value according to the mapped data packet; Generate a storage sub-package for the current signature task according to the signature sub-image, the first-level timestamp, and the verification hash value; Set a target storage sub-library according to the current signature task; Send the storage sub-package to the target storage sub-library.
10. The expert signature system based on multi-factor authentication as described in claim 9, characterized in that, Generate a first-level outlier c for the signature image to be compared according to the first-level comparison model, including: Generate multiple first-level signature images according to the first-level comparison model; Generate a fit value between the signature image to be compared and each first-level signature image; Establish a sequence of matching values H, H=(h1,h2…h i …h r ), where h i Let r be the matching value between the signature image to be compared and the i-th first-level signature image; r is the number of first-level signature images. Select the maximum value h from the sequence of matching values H max ; Preset a fit value threshold H1; If h max H1 generates a secondary authentication command, and sets a primary exception value c based on the secondary authentication command; If h max <H1, generate the first-level outlier c according to all the matching values; c=U2*[ h i ]; Where U2 is a preset second conversion coefficient; r is the number of first-level signature images.
Citation Information
Patent Citations
Electronic signature verification method and device, computer device and storage medium
CN109446905A
Multi-factor identity authentication method and device, equipment and storage medium
CN115859259A
Online bid evaluation smart cloud signature system and method based on multi-dimensional identity authentication
CN120893983A