A Database Adaptive Authentication Method and System Combining Meta-Learning Model
Patent Information
- Application Number
- CN202610353884.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-23
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2046-03-23
AI Technical Summary
为了数据库的安全性,一些数据库认证方法会对认证方式本身进行优化,如改用国密算法、使用多重认证方式(如引入授权码、短信验证码和U盾硬件认证),以此提高认证强度,达到保护数据库安全的目的,但这些方法只适用于对实时性要求较低登录认证,面对客户端和数据库的会话过程,若采用多重认证方式同步认证的策略,会大幅降低访问的灵活性、增加计算机算力消耗和用户操作复杂度
1、本申请提供的一种结合元学习模型的数据库自适应认证方法及系统,通过搭建经过元学习模型框架训练过的行为风险匹配网络,对用户登录行为数据进行风险预测,进而可根据用户登录行为数据对应的风险等级,为处于登录认证阶段的客户端自适应配置多种目标认证方式及其认证次序,可在有效提高数据库安全性的同时,提高登录认证效率;
Smart Images

Figure CN121887550B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of computer data security, and more specifically, relates to a database adaptive authentication method and system that combines a meta-learning model. Background Technology
[0002] As a centralized storage platform for users' core information resources, databases rely heavily on their security authentication mechanisms to safeguard data assets. However, traditional database authentication mechanisms generally suffer from low security, poor flexibility, and high maintenance costs, making them ill-suited to increasingly complex application scenarios and evolving security threats.
[0003] Common database authentication methods primarily rely on usernames and passwords, which are vulnerable to cracking, forgery, or theft. To enhance database security, some authentication methods optimize the authentication process itself, such as using national cryptographic algorithms or employing multi-factor authentication (e.g., authorization codes, SMS verification codes, and USB token hardware authentication) to increase authentication strength and protect the database. However, these methods are only suitable for login authentication with low real-time requirements. For client-database sessions, employing a multi-factor authentication strategy for simultaneous authentication significantly reduces access flexibility, increases computing power consumption, and complicates user operations.
[0004] In addition, some technologies combine multiple authentication methods to configure the appropriate authentication strength according to different user needs. However, this mechanism relies on the administrator's preset fixed configuration and cannot automatically adjust the authentication strength according to abnormal login behavior or high-risk session behavior. This may result in a low-strength authentication method being configured for high-risk authentication behavior, which will increase the database security risk. Summary of the Invention
[0005] To address the aforementioned deficiencies in existing technologies, this application provides a database adaptive authentication method and system that combines a meta-learning model. The method aims to predict behavioral risks based on user login and data session behavior data, and dynamically and accurately configure authentication strategies with different authentication strengths generated by various authentication methods for the user based on the behavioral risk prediction results.
[0006] Firstly, this application provides a database adaptive authentication method combining a meta-learning model, including: S1. Obtain the user's login request, which includes user login behavior data; S2. Based on the behavior risk matching network trained by the meta-learning model framework, predict the login behavior risk of user login behavior data and obtain the login behavior risk level. S3. Based on the risk level of login behavior, generate a target login authentication policy to authenticate the user's login. The target login authentication policy includes multiple target authentication methods and the authentication order of each target authentication method. S4. After successful login authentication, a data session is initiated between the client and the database, and user session behavior data between the client and the database is periodically acquired at target time intervals during the session period. S5. Based on the behavior risk matching network, perform session behavior risk prediction on user session behavior data at the target time interval where the current timestamp of the data session is located, and perform or suspend session authentication on the user end based on the session behavior risk prediction results.
[0007] User login behavior data includes at least the username, user IP, login timestamp, and login device information. User session behavior data includes at least the username, user IP, operation object type, sensitivity level corresponding to the operation object type, and SQL operation type.
[0008] Furthermore, the target authentication methods include at least password authentication, digital signature authentication, and USB Key authentication.
[0009] Furthermore, based on the risk level of login behavior, a target login authentication policy is generated to authenticate users, including: Based on the login behavior risk level, multiple target authentication methods corresponding to the login behavior risk level are retrieved from the preset login behavior risk level-authentication method mapping table. Each target authentication method has a label representing the security level. The target authentication methods corresponding to the risk level of login behavior are combined into a target authentication sequence according to the security level of the target authentication methods from high to low, and the user terminal is authenticated in turn based on the target authentication sequence.
[0010] Login authentication, as a fundamental process for protecting database security, is highly vulnerable to Advanced Persistent Threats (APTs), credential theft, and social engineering attacks. Therefore, this application configures multiple target authentication methods for the current user based on the risk level of their login behavior. Specifically, when the login behavior risk level is low, a small number of authentication methods with lower security requirements are configured. These lower-security target authentication methods generally have lower complexity, thus reducing the computational power consumption of authentication devices and improving their authentication efficiency while protecting database security. Furthermore, these target authentication methods matched to the current login behavior risk level are arranged in descending order of security level to construct a target authentication sequence, which further improves authentication efficiency: login authentication is completed preferentially using the authentication algorithm corresponding to the corresponding security level.
[0011] Furthermore, the duration of the data session is a preset session duration. When the behavior risk matching network obtains the session behavior risk level, it retrieves the target session duration corresponding to the behavior risk level from the preset behavior risk level-session duration mapping table, and adjusts the duration of the session based on the target session duration.
[0012] Furthermore, based on the session behavior risk prediction results, session authentication is performed or suspended on the user end, including: Obtain the session behavior risk level corresponding to the user session behavior data. The session behavior risk level includes 0-N. When the session behavior risk level is 0, session authentication for the user is suspended within the target time interval of the current timestamp of the data session. When the session behavior risk level is any value from 1 to N, the target authentication method corresponding to the session behavior risk level is obtained from the preset session behavior risk level-authentication method mapping table, and the user terminal is authenticated based on the target authentication method. Each session behavior risk level has a corresponding target authentication method.
[0013] Furthermore, before conducting conversational behavior risk prediction, the following also includes: If, before the current timestamp, there exists historical session behavior data that is identical to the session behavior data and has already been authenticated, then session behavior risk prediction and client-side session authentication for the session behavior data will be suspended within the target time interval at the current timestamp of the data session.
[0014] Furthermore, the behavior risk matching network trained by the meta-learning model framework includes an input layer, an encoder layer, an attention layer, a loss calculation layer, and an output layer. The encoder layer consists of four encoder modules stacked in series. Each encoder module includes a convolutional layer, a batch normalization (BN) layer, a ReLU activation layer, and a max pooling layer. The attention layer is a Top-K sparse attention layer.
[0015] Secondly, this application also provides a database adaptive authentication system incorporating a meta-learning model for performing any of the methods in the first aspect, including: The login request acquisition module is used to acquire login requests from the user's client. The login risk prediction module is used to predict the login behavior risk of user login behavior data based on the behavior risk matching network trained by the meta-learning model framework, and obtain the login behavior risk level. The login authentication module is used to generate target login authentication policies based on the risk level of login behavior and to authenticate users' logins. The session behavior data acquisition module is used to start a data session between the user client and the database after successful login authentication, and periodically acquire user session behavior data between the user client and the database at target time intervals during the session period of the data session. The session risk prediction module is used to predict session behavior risks based on user session behavior data at the target time interval where the current timestamp of the data session is located, using a behavior risk matching network. The session authentication module is used to perform or suspend session authentication on the user terminal based on the results of session behavior risk prediction.
[0016] Thirdly, this application also provides an electronic device, characterized in that it comprises: At least one memory for storing computer programs; At least one processor is configured to execute a program stored in the memory, such that, when the program is executed, the processor performs the method described in the first aspect or any possible implementation thereof.
[0017] In summary, the technical solutions conceived by this invention have the following beneficial effects compared with the prior art: 1. This application provides a database adaptive authentication method and system that combines a meta-learning model. By building a behavior risk matching network trained by a meta-learning model framework, the system predicts the risk of user login behavior data. Then, based on the risk level corresponding to the user login behavior data, it can adaptively configure multiple target authentication methods and their authentication order for the client in the login authentication stage. This can effectively improve database security while improving login authentication efficiency. 2. By using a behavior risk matching network, the session behavior risk level of user session behavior data is periodically obtained at target time intervals during the session period of the data session. Then, based on the session behavior risk level, the target authentication method can be adaptively matched for the user to perform session authentication, or the user session authentication status can be directly determined to be passed in the current time interval. This can effectively ensure the security of the database during the data session and improve the efficiency of session authentication. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in this application or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1This is a schematic flowchart of a database adaptive authentication method provided in an embodiment of this application.
[0020] Figure 2 This is another schematic diagram of the database adaptive authentication method provided in the embodiments of this application.
[0021] Figure 3 This is a schematic diagram of the training process of the meta-learning model framework provided in the embodiments of this application.
[0022] Figure 4 This is a schematic diagram of the network structure of the encoder layer provided in the embodiments of this application.
[0023] Figure 5 This is a schematic diagram of the database adaptive authentication system provided in the embodiments of this application.
[0024] Figure 6 This is a schematic diagram of an electronic device structure provided in this application. Detailed Implementation
[0025] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0026] In the following description, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance. The following description provides multiple embodiments of this application, which can be substituted or combined with each other. Therefore, this application can also be considered to include all possible combinations of the same and / or different embodiments described. Thus, if one embodiment includes features A, B, and C, and another embodiment includes features B and D, then this application should also be considered to include embodiments containing one or more other possible combinations of A, B, C, and D, even if such embodiments are not explicitly described in the following text.
[0027] The following description provides examples and does not limit the scope, applicability, or examples set forth in the claims. Changes may be made to the function and arrangement of the described elements without departing from the scope of this application. Various processes or components may be appropriately omitted, substituted, or added to the examples. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Furthermore, features described with respect to some examples may be combined into other examples.
[0028] Figure 1 This is a flowchart illustrating the database adaptive authentication method combining a meta-learning model provided in an embodiment of this application, as shown below. Figure 1 As shown, the method includes at least the following steps: S1. Obtain the user's login request, which includes user login behavior data.
[0029] In the embodiments of this application, such as Figure 2 As shown, the implementing entity of this application is a server-side controller used to manage database data transmission. The sender of a user login request can be a mobile device with a frequently changing IP address connected remotely to the server, or a local computer device under fixed control. User login behavior data includes at least the username, user IP address, login timestamp, and login device information. The login timestamp is used to determine whether the client's login time segment is within a normal working period. For example, if a login request is sent during an abnormal working period, the risk level of the login behavior will increase.
[0030] S2. Based on the behavior risk matching network trained by the meta-learning model framework, the login behavior risk is predicted on the user login behavior data to obtain the login behavior risk level.
[0031] In the embodiments of this application, such as Figure 3 As shown, the behavioral risk matching network includes an input layer, an encoder layer, an attention layer, a loss calculation layer, and an output layer. The encoder layer corresponds to the CNN4 network portion in the diagram, and the attention layer employs a Top-K sparse attention layer. The loss function is calculated from the loss function of the corresponding layer. It is the cross-entropy loss between the query set labels and the prediction results. (Cross-Entropy Loss), and the triplet loss reflecting sample bias calculated from the feature vectors of positive and negative samples of the anchor. The total loss is obtained by combining the support set and the query set. Feature vectors are extracted from the support set and the query set respectively through a CNN4 network with shared weights. Cross-Entropy Loss calculates the cross-entropy loss between the query set label and the prediction result. Triplet Loss calculates the triplet loss of the anchor point, positive sample and negative sample feature vectors. The two are combined to obtain the total loss. The Top-K sparse attention layer is used to strengthen the weights of key features. , The loss function for Total Loss is as follows: , , , in, This represents the true label of the queried sample. This represents the query sample predicted by the model. Category The probability, This indicates the number of samples in the query set. The feature vector representing the anchor sample. The feature vector representing a positive sample. The feature vector representing the negative sample. The interval parameter controls the minimum difference between positive and negative samples. The anchor point is a feature vector of the query set, positive samples are feature vectors of the same type as the anchor point in the support set, and negative samples are feature vectors of different types from the anchor point in the support set. This application uses the same behavioral risk matching network structure for both login authentication and session authentication, but trains it using different types of datasets. For example, during login authentication, historical login behavior data with risk labels is used to construct the support set and query set.
[0032] like Figure 3 As shown, meta-learning frameworks mainly include three types of methods: metric-based, model-based, and optimization-based. This application adopts a metric-based matching network. The metric-based meta-learning framework maps input data to a metric space by training an embedding function and constructs transferable similarity calculation criteria. Its technical characteristics are manifested in a non-parametric two-layer architecture: the outer training layer learns a general feature extractor through multi-task joint optimization, utilizing the data distribution of different tasks to optimize the embedding space; the inner inference layer directly applies the pre-trained metric function for similarity comparison, and the network parameters remain frozen when a new task appears. This mechanism can avoid the optimization limitations caused by gradient iteration in parameterized methods (such as learning rate sensitivity, optimizer dependency, and multi-step update requirements) while maintaining similar model performance. The matching network differs from other networks in that it can build different encoders for the support set and the query set, and its classifier output is obtained by weighted summation of the predicted values between the support set samples and the query set samples. The matching network obtains weighted labels by introducing an attention mechanism to the support set, which simplifies the entire analysis process to the calculation of attention. If the attention score of a certain category is high, then the probability that the query set sample belongs to that category will be relatively high.
[0033] In addition, such as Figure 4As shown, the encoder layer in this application uses a self-built CNN4 network to extract feature information from user login behavior data and user session behavior data, and encodes it into a one-dimensional feature vector. For example, a 64×64 two-dimensional feature vector is converted into a 64×4×4 three-dimensional feature vector. Finally, the 64×4×4 three-dimensional feature vector is reshaped to output a one-dimensional feature vector of length 1024. The CNN4 network consists of multiple encoder modules stacked in series. Each encoder module is a two-dimensional feature network with a different convolution size. Each two-dimensional feature network includes a convolutional layer (Conv2D), a batch normalization (BN) layer, a ReLU activation layer, and a max-pooling layer. Therefore, compared with feature extraction networks such as MobileNetV2, GhostNet, and ResNet18, the CNN4 network has a smaller network structure and lower computational cost. In this application, the CNN4 feature extraction network is used to implement lightweight feature extraction for behavior risk matching networks. It reduces the computational cost and parameter count by simplifying the model and reducing the number of model layers. Furthermore, since convolution or pooling is essentially filtering, filtering inevitably causes information loss. Layer-by-layer filtering will cause information loss at each layer. However, if the number of layers is too small, there will be too many useless features, resulting in low feature extraction accuracy. Therefore, considering both efficiency and accuracy, this application sets the number of encoder modules to 4, but the setting method is not limited to this.
[0034] S3. Based on the risk level of login behavior, generate a target login authentication policy to authenticate the user's login. The target login authentication policy includes multiple target authentication methods and the authentication order of each target authentication method.
[0035] In one possible implementation, a target login authentication policy is generated based on the risk level of login behavior to authenticate the user's login, including: Based on the login behavior risk level, multiple target authentication methods corresponding to the login behavior risk level are retrieved from the preset login behavior risk level-authentication method mapping table. Each target authentication method has a label representing the security level. The target authentication methods corresponding to the risk level of login behavior are combined into a target authentication sequence according to the security level of the target authentication methods from high to low, and the user terminal is authenticated in turn based on the target authentication sequence.
[0036] In this application embodiment, the target authentication methods include at least password authentication, digital signature authentication, and USB Key authentication, but other authentication methods such as SMS authentication and facial video authentication can also be added according to actual needs. Password authentication uses the SM3 algorithm for optimization. The SM3 algorithm is used to generate the hash value during the signature verification process. This authentication method provides higher security; the uniqueness of the private key ensures that the signature cannot be forged, resisting identity impersonation. It is suitable for authenticating abnormal login behaviors, such as access from unused user IP addresses or access within time periods that do not conform to historical behavior. USB Key authentication is a hardware-based authentication technology. By combining a physical device (USB Key) with encryption technology, it ensures the authenticity of the user's identity and data security. The USB Key has a built-in security chip that stores the user's private key, digital certificate, or encryption key. All sensitive operations (such as signing and decryption) are completed inside the chip, ensuring that the private key is never leaked. It is suitable for authenticating administrator users logging into database systems and high-risk data operation behaviors.
[0037] Furthermore, the login behavior risk level ranges from 1 to N, with higher levels indicating higher login risk and a greater number of corresponding target authentication methods. Higher-security target authentication methods should be prioritized for login authentication. Since higher-security target authentication methods generally involve more complex algorithms, when the login behavior risk level is low and multiple target authentication methods exist, lower-security target authentication methods can be prioritized for login authentication. Similarly, when the login behavior risk level is high and multiple target authentication methods exist, higher-security target authentication methods should be prioritized for login authentication. Through this login authentication strategy, database security can be protected while reducing the computational power consumption of authentication devices and improving their authentication efficiency.
[0038] S4. After successful login authentication, a data session is initiated between the client and the database, and user session behavior data between the client and the database is periodically acquired at target time intervals during the session period.
[0039] In this embodiment of the application, the purpose of session authentication is to securely monitor user login authentication behavior and database object access behavior after establishing a session through login authentication. User session behavior data includes at least the username, user IP, operation object type, sensitivity level corresponding to the operation object type, and SQL operation type. SQL operation type is divided into sensitive and normal. For example, sensitive operations include user querying tables with sensitive data tags, deleting sensitive data, modifying keys, modifying security policies, etc.
[0040] The duration of a data session is a preset session duration. After the behavior risk matching network obtains the session behavior risk level, it retrieves the target session duration corresponding to the behavior risk level from the preset behavior risk level-session duration mapping table, and adjusts the session duration based on the target session duration. The data session duration consists of a large number of target time intervals, each of which is longer than the authentication duration of each target authentication method once. This ensures that the user has sufficient data session time, while also enabling periodic authentication of the user during the data session.
[0041] Furthermore, before performing session behavior risk prediction, the following steps are taken: If, before the current timestamp, there exists historical session behavior data that is identical to the session behavior data and has already passed session authentication within the session time period of the data session, then within the target time interval of the current timestamp of the data session, session behavior risk prediction for the session behavior data and session authentication on the user's end are paused. It is assumed that session authentication within the current target time interval has already passed, which avoids duplicate authentication operations and reduces computing power consumption. For example, if a user has a history of periodically deleting data from a table within a session time period, or if the user's IP address and access time match historical behavior, and there has been frequent recent access to the sensitive data, then this behavior can be considered safe, and no further authentication is required.
[0042] S5. Based on the behavior risk matching network, perform session behavior risk prediction on user session behavior data at the target time interval where the current timestamp of the data session is located, and perform or suspend session authentication on the user end based on the session behavior risk prediction results.
[0043] In one possible implementation, based on the session behavior risk prediction results, session authentication is performed or suspended on the user terminal, including: Obtain the session behavior risk level corresponding to the user session behavior data. The session behavior risk level includes 0-N. When the session behavior risk level is 0, session authentication for the user is suspended within the target time interval of the current timestamp of the data session. When the session behavior risk level is any value from 1 to N, the target authentication method corresponding to the session behavior risk level is obtained from the preset session behavior risk level-authentication method mapping table, and the user terminal is authenticated based on the target authentication method. Each session behavior risk level has a corresponding target authentication method.
[0044] In this embodiment, the risk level of a session behavior ranges from 0 to N, where risk level 0 represents that the user's session behavior is normal or consistent with the authenticated session behavior in the previous target time interval, and therefore can be considered as authenticated and the session authentication for the user is paused. Furthermore, only one target authentication method is used for session authentication within each target time interval. This is to improve the user experience and reduce operational complexity while ensuring the security of the data session process. Therefore, this application selects a preset session behavior risk level-authentication method mapping table to adaptively adjust the target authentication method selected for the current session authentication based on the session behavior risk level of the current session behavior.
[0045] like Figure 5 As shown in the embodiments of this application, the database adaptive authentication system combining a meta-learning model includes: The login request acquisition module is used to acquire login requests from the user's client. The login risk prediction module is used to predict the login behavior risk of user login behavior data based on the behavior risk matching network trained by the meta-learning model framework, and obtain the login behavior risk level. The login authentication module is used to generate target login authentication policies based on the risk level of login behavior and to authenticate users' logins. The session behavior data acquisition module is used to start a data session between the user client and the database after successful login authentication, and periodically acquire user session behavior data between the user client and the database at target time intervals during the session period of the data session. The session risk prediction module is used to predict session behavior risks based on user session behavior data at the target time interval where the current timestamp of the data session is located, using a behavior risk matching network. The session authentication module is used to perform or suspend session authentication on the user terminal based on the results of session behavior risk prediction.
[0046] like Figure 6 As shown, Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. The electronic device may include: a processor 601, a communications interface 602, a memory 603, and a communication bus 604. The processor 601, communications interface 602, and memory 603 communicate with each other via the communication bus 604. The processor 601 can call software instructions in the memory 603 to execute the methods described in the above embodiments.
[0047] Furthermore, the logical instructions in the aforementioned memory 603 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application.
[0048] Based on the methods in the above embodiments, this application provides a computer-readable storage medium storing a computer program that, when run on a processor, causes the processor to execute the methods in the above embodiments.
[0049] Based on the methods in the above embodiments, this application provides a computer program product that, when run on a processor, causes the processor to execute the methods in the above embodiments.
[0050] It is understood that the processor in the embodiments of this application can be a CPU (Central Processing Unit), or other general-purpose processors, DSPs (Digital Signal Processors), ASICs (Application Specific Integrated Circuits), FPGAs (Field Programmable Gate Arrays), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor can be a microprocessor or any conventional processor.
[0051] The method steps in this application embodiment can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory (RAM), flash memory, ROM (Read-only Memory), PROM (Programmable ROM), EPROM (Erasable PROM), EEPROM (Electrically Erasable EPROM), registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can reside in an ASIC.
[0052] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in or transmitted through a computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line DSL) or wireless (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., SSD (Solid State Disk)).
[0053] It is understood that the various numerical designations used in the embodiments of this application are merely for the convenience of description and are not intended to limit the scope of the embodiments of this application.
[0054] Those skilled in the art will readily understand that the above are merely preferred embodiments of this application and are not intended to limit this application. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A database adaptive authentication method combining a meta-learning model, characterized in that, include: S1. Obtain the user's login request, wherein the login request includes user login behavior data; S2. Based on the behavior risk matching network trained by the meta-learning model framework, predict the login behavior risk of the user login behavior data to obtain the login behavior risk level. S3. Based on the risk level of the login behavior, generate a target login authentication strategy to authenticate the user terminal. The target login authentication strategy includes multiple target authentication methods and the authentication order of each target authentication method. S4. After the login authentication is successful, a data session is started between the user terminal and the database, and user session behavior data between the user terminal and the database is periodically acquired at target time intervals during the session period of the data session. S5. Based on the behavior risk matching network, perform session behavior risk prediction on the user session behavior data of the target time interval where the current timestamp of the data session is located, and perform or suspend session authentication on the user terminal based on the session behavior risk prediction result. The step of generating a target login authentication policy based on the login behavior risk level and performing login authentication on the user terminal includes: Based on the login behavior risk level, multiple target authentication methods corresponding to the login behavior risk level are retrieved from the preset login behavior risk level-authentication method mapping table, and each target authentication method is labeled with a security level. The target authentication methods corresponding to the risk level of the login behavior are combined into a target authentication sequence in descending order of the security level of the target authentication method, and the user terminal is authenticated sequentially based on the target authentication sequence. The step of performing or suspending session authentication on the user terminal based on the session behavior risk prediction result includes: Obtain the session behavior risk level corresponding to the user session behavior data, where the session behavior risk level includes 0-N; When the session behavior risk level of the session behavior is 0, the session authentication of the user terminal is suspended within the target time interval where the current timestamp of the data session is located. When the session behavior risk level is any value from 1 to N, the target authentication method corresponding to the session behavior risk level is obtained from the preset session behavior risk level-authentication method mapping table, and the user terminal is authenticated based on the target authentication method. Each session behavior risk level corresponds to one target authentication method.
2. The database adaptive authentication method according to claim 1, characterized in that, The user login behavior data includes at least the username, user IP, login timestamp, and login device information. The user session behavior data includes at least the username, user IP, operation object type, the sensitivity level corresponding to the operation object type, and the SQL operation type.
3. The database adaptive authentication method according to claim 1, characterized in that, The types of target authentication methods include at least password authentication, digital signature authentication, and USB Key authentication.
4. The database adaptive authentication method according to claim 1, characterized in that, The duration of the data session is a preset session duration. When the behavior risk matching network obtains the session behavior risk level, it obtains the target session duration corresponding to the behavior risk level from the preset behavior risk level-session duration mapping table, and adjusts the duration of the session based on the target session duration.
5. The database adaptive authentication method according to claim 4, characterized in that, Before performing the session behavior risk prediction, the following is also included: If, before the current timestamp, there exists historical session behavior data that is identical to the session behavior data and has already been authenticated during the session time period of the data session, then during the target time interval at the current timestamp of the data session, session behavior risk prediction for the session behavior data and session authentication for the user terminal will be suspended.
6. The database adaptive authentication method according to claim 1, characterized in that, The behavior risk matching network trained by the meta-learning model framework includes an input layer, an encoder layer, an attention layer, a loss calculation layer, and an output layer. The encoder layer consists of four encoder modules stacked in series. Each encoder module includes a convolutional layer, a batch normalization (BN) layer, a ReLU activation layer, and a max pooling layer. The attention layer is a Top-K sparse attention layer.
7. A database adaptive authentication system incorporating a meta-learning model, used to perform the method as described in any one of claims 1-6, characterized in that, include: The login request acquisition module is used to acquire login requests from the user's client. The login risk prediction module is used to predict the login behavior risk of the user login behavior data based on the behavior risk matching network trained by the meta-learning model framework, and obtain the login behavior risk level. The login authentication module is used to generate a target login authentication policy based on the risk level of the login behavior and to perform login authentication on the user terminal. The session behavior data acquisition module is used to initiate a data session between the user terminal and the database after the login authentication is successful, and to periodically acquire user session behavior data between the user terminal and the database at target time intervals during the session period of the data session. The session risk prediction module is used to predict session behavior risks based on the behavior risk matching network for the user session behavior data at the target time interval where the current timestamp of the data session is located. The session authentication module is used to perform or suspend session authentication on the user terminal based on the session behavior risk prediction results.
8. An electronic device, characterized in that, include: At least one memory for storing computer programs; At least one processor is configured to execute a program stored in the memory, wherein when the program stored in the memory is executed, the processor is configured to perform the method as described in any one of claims 1-6.
Citation Information
Patent Citations
Account authentication method and system based on risk rule model
CN118916860A
Login risk processing method, device and equipment based on user behavior analysis
CN121644132A