Request verification method and device, equipment, storage medium and computer program product

By combining multi-dimensional cross-validation and risk knowledge graphs, the problem of the single verification dimension in existing real-name authentication schemes is solved, enabling effective identification and interception of gang fraud and cross-account collaborative crimes, thereby improving the system's security and identification accuracy.

CN122002292APending Publication Date: 2026-05-08CHINA MOBILE ZHIJIE TECHNOLOGY (BEIJING) CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA MOBILE ZHIJIE TECHNOLOGY (BEIJING) CO LTD
Filing Date
2025-12-19
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing real-name authentication schemes suffer from a single verification dimension, resulting in a fragile protection system. They lack the ability to perform correlation analysis and recognize complex patterns, making it difficult to effectively identify and intercept complex attack patterns such as gang fraud and cross-account collaborative crimes.

Method used

A multidimensional cross-validation strategy combined with a risk knowledge graph is adopted. An initial risk profile is generated by acquiring users' environmental and behavioral data, multidimensional cross-validation is performed, and correlation analysis is conducted using a pre-built risk knowledge graph to determine the final validation result.

Benefits of technology

It improves the accuracy and defense capabilities for identifying complex risks, enabling the identification of hidden risks that are difficult to detect in a single verification, enhancing the ability to identify group fraud, and improving the security and defense depth of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122002292A_ABST
    Figure CN122002292A_ABST
Patent Text Reader

Abstract

The invention discloses a request verification method and device, equipment, a storage medium and a computer program product, which are used for solving the problems that the existing real-name system authentication scheme is single in verification dimension, so that a protection system is fragile, association analysis and complex mode recognition capabilities are lacked, and the verification efficiency is high. And therefore, complex attack modes such as gang fraud and cross-account collaborative crime cannot be effectively identified and intercepted. The method comprises the steps of determining an initial risk portrait corresponding to a to-be-authenticated request according to acquired environment data and behavior data of a user corresponding to the to-be-authenticated request; determining a multi-dimensional cross validation strategy according to the initial risk portrait, and performing multi-dimensional cross validation on the to-be-authenticated request according to the multi-dimensional cross validation strategy to obtain a cross validation result; based on a pre-constructed risk knowledge graph, performing association analysis on the to-be-authenticated request to obtain an association analysis result; and determining a final verification result for the to-be-authenticated request according to the cross verification result and the correlation analysis result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication technology, and in particular to a request verification method, apparatus, device, storage medium, and computer program product. Background Technology

[0002] With the rapid development of internet and mobile communication technologies, various online services, such as financial services, government services, and telecommunications services, generally require real-name authentication mechanisms to ensure the authenticity and credibility of user identities and prevent fraud and illegal activities. Common real-name authentication methods mainly include verification based on identity credentials, such as ID card numbers and mobile phone numbers; biometrics, such as facial recognition comparison; and analysis based on user behavior and device environment.

[0003] However, on the one hand, existing real-name authentication schemes often rely on only one or a few verification factors for independent judgment and processing. The verification results between the factors lack effective correlation analysis and comprehensive judgment. Once an attacker breaks through a certain verification link, such as by intercepting SMS verification codes, they can easily bypass the entire risk control system, making the overall security protection vulnerable to attacks targeting specific verification methods, which greatly affects the security of the system.

[0004] On the other hand, existing real-name authentication schemes mainly conduct risk analysis on the single user or device that initiates the request, and it is difficult to effectively identify and associate the complex relationships between different users, devices, network addresses and other entities. Therefore, the existing system is not capable of identifying and preventing organized fraud involving multiple entities cooperating with each other.

[0005] Therefore, how to implement a real-name authentication scheme that can perform multi-dimensional verification and achieve end-to-end privacy protection, so as to improve the comprehensive identification accuracy and real-time defense capability against complex risks, has become a technical problem that needs to be solved by existing technologies. Summary of the Invention

[0006] This application provides a request verification method to address the problems of existing real-name authentication schemes having a single verification dimension, resulting in a fragile protection system, and lacking the ability to perform correlation analysis and complex pattern recognition, thus failing to effectively identify and block complex attack patterns such as gang fraud and cross-account collaborative crimes.

[0007] This application also provides a request verification device to address the problem that existing real-name authentication schemes have a single verification dimension, resulting in a fragile protection system, and lack the ability to perform correlation analysis and complex pattern recognition, making it impossible to effectively identify and block complex attack patterns such as gang fraud and cross-account collaborative crimes.

[0008] This application also provides a request verification device to address the problem that existing real-name authentication schemes have a single verification dimension, resulting in a fragile protection system, and lack the ability to perform correlation analysis and complex pattern recognition, making it impossible to effectively identify and block complex attack patterns such as gang fraud and cross-account collaborative crimes.

[0009] This application also provides a computer-readable storage medium to address the problem that existing real-name authentication schemes have a single verification dimension, resulting in a fragile protection system, and lack the ability to perform correlation analysis and complex pattern recognition, making it impossible to effectively identify and intercept complex attack patterns such as gang fraud and cross-account collaborative crimes.

[0010] A computer program product is designed to address the problems of existing real-name authentication schemes, which suffer from a single verification dimension, resulting in a fragile protection system, and a lack of correlation analysis and complex pattern recognition capabilities, making it impossible to effectively identify and block complex attack patterns such as gang fraud and cross-account collaborative crimes.

[0011] The embodiments of this application adopt the following technical solutions: A request verification method includes: determining an initial risk profile corresponding to the request to be authenticated based on environmental data and behavioral data of the user corresponding to the request to be authenticated; determining a multi-dimensional cross-validation strategy corresponding to the request to be authenticated based on the initial risk profile, and performing multi-dimensional cross-validation on the request to be authenticated based on the multi-dimensional cross-validation strategy to obtain a cross-validation result corresponding to the multi-dimensional cross-validation, wherein the multi-dimensional cross-validation strategy includes at least two different types of authentication factors; performing correlation analysis on the request to be authenticated based on a pre-constructed risk knowledge graph to obtain a correlation analysis result corresponding to the request to be authenticated; and determining a final verification result for the request to be authenticated based on the cross-validation result and the correlation analysis result.

[0012] A request verification device includes: an initial risk profile determination unit, configured to determine an initial risk profile corresponding to the request to be authenticated based on acquired environmental data and behavioral data of the user corresponding to the request to be authenticated; a cross-validation unit, configured to determine a multi-dimensional cross-validation strategy corresponding to the request to be authenticated based on the initial risk profile, and perform multi-dimensional cross-validation on the request to be authenticated based on the multi-dimensional cross-validation strategy to obtain a cross-validation result corresponding to the multi-dimensional cross-validation, wherein the multi-dimensional cross-validation strategy includes at least two different types of authentication factors; an association analysis unit, configured to perform association analysis on the request to be authenticated based on a pre-constructed risk knowledge graph to obtain an association analysis result corresponding to the request to be authenticated; and a comprehensive verification unit, configured to determine a final verification result for the request to be authenticated based on the cross-validation result and the association analysis result.

[0013] A data governance device, comprising: The processor; and a memory arranged to store computer-executable instructions, which, when executed, cause the processor to perform the following operations: determining an initial risk profile corresponding to the authentication request based on acquired environmental and behavioral data of the user corresponding to the authentication request; determining a multi-dimensional cross-validation strategy corresponding to the authentication request based on the initial risk profile, and performing multi-dimensional cross-validation on the authentication request based on the multi-dimensional cross-validation strategy to obtain a cross-validation result corresponding to the multi-dimensional cross-validation, wherein the multi-dimensional cross-validation strategy includes at least two different types of authentication factors; performing correlation analysis on the authentication request based on a pre-constructed risk knowledge graph to obtain a correlation analysis result corresponding to the authentication request; and determining a final verification result for the authentication request based on the cross-validation result and the correlation analysis result.

[0014] A computer-readable storage medium stores one or more programs, which, when executed by an electronic device including multiple applications, cause the electronic device to perform the following operations: determining an initial risk profile corresponding to the authentication request based on acquired environmental and behavioral data of a user corresponding to the authentication request; determining a multi-dimensional cross-validation strategy corresponding to the authentication request based on the initial risk profile, and performing multi-dimensional cross-validation on the authentication request based on the multi-dimensional cross-validation strategy to obtain a cross-validation result corresponding to the multi-dimensional cross-validation, wherein the multi-dimensional cross-validation strategy includes at least two different types of authentication factors; performing correlation analysis on the authentication request based on a pre-constructed risk knowledge graph to obtain a correlation analysis result corresponding to the authentication request; and determining a final verification result for the authentication request based on the cross-validation result and the correlation analysis result.

[0015] A computer program product includes a computer program that, when executed by a processor, implements the following: determining an initial risk profile corresponding to the authentication request based on acquired environmental and behavioral data of a user corresponding to the authentication request; determining a multi-dimensional cross-validation strategy corresponding to the authentication request based on the initial risk profile, and performing multi-dimensional cross-validation on the authentication request based on the multi-dimensional cross-validation strategy to obtain a cross-validation result corresponding to the multi-dimensional cross-validation, wherein the multi-dimensional cross-validation strategy includes at least two different types of authentication factors; performing correlation analysis on the authentication request based on a pre-constructed risk knowledge graph to obtain a correlation analysis result corresponding to the authentication request; and determining a final verification result for the authentication request based on the cross-validation result and the correlation analysis result.

[0016] The above-described technical solutions adopted in the embodiments of this application can achieve the following beneficial effects: The request verification method provided in this application allows for authentication of received requests. When authentication is required, an initial risk profile is determined based on the acquired environmental and behavioral data of the user corresponding to the request. Then, a multi-dimensional cross-validation strategy is determined based on this initial risk profile. This strategy is then applied to the request to obtain the cross-validation result. Simultaneously, a correlation analysis is performed on the request based on a pre-built risk knowledge graph, yielding the correlation analysis result. Finally, the final verification result for the request is determined based on the cross-validation and correlation analysis results. This method, by combining at least two different types of authentication factors for cross-validation, forces attackers to simultaneously bypass multiple independent verification dimensions, increasing attack difficulty and cost, and significantly improving verification accuracy and defense depth. On the other hand, by using risk knowledge graphs to perform correlation analysis on requests, hidden risks that are difficult to detect in a single verification can be identified at the entity association network level. This allows for in-depth mining of hidden relationship chains between entities such as users, devices, and network addresses. As a result, the system can not only identify the authenticity of the current request itself, but also identify potential risk aggregation patterns. This effectively improves the ability to identify group fraud and greatly enhances the accuracy of the system in identifying risks. Attached Figure Description

[0017] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 A schematic diagram of the specific structure of a request verification system provided in this application embodiment; Figure 2 This is a schematic diagram illustrating a specific process of a request verification method provided in an embodiment of this application; Figure 3 A schematic diagram of the specific structure of a request verification device provided in this application embodiment; Figure 4 This is a schematic diagram of the specific structure of a request verification device provided in an embodiment of this application. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0019] This application provides a request verification method to address the problems of existing real-name authentication schemes, which suffer from a single verification dimension, resulting in a fragile protection system and a lack of correlation analysis and complex pattern recognition capabilities, making it impossible to effectively identify and block complex attack patterns such as gang fraud and cross-account collaborative crimes.

[0020] The execution subject of the request verification method provided in this application embodiment may be, but is not limited to, at least one of a security server, an access authentication server, an identity authentication server, and a real-name authentication server; in addition, the execution subject of the method may also be the system or application (APP) itself running on these servers.

[0021] For ease of description, the following description uses the request authentication system as an example to illustrate the implementation of this method. It should be understood that using the request authentication system as the execution subject is merely an illustrative example and should not be construed as a limitation of the method.

[0022] In one implementation, the specific system architecture of the request authentication system is as follows: Figure 1 As shown, it mainly consists of several parts: risk perception and access module, multi-factor verification module, risk decision-making module, privacy computing data platform, and feedback optimization module.

[0023] The risk perception and access module is used to collect users' multimodal behavioral data and biometrics. Specifically, it can collect user touchscreen gestures (including touch speed, pressure, and trajectory), mouse movement trajectory, keyboard typing rhythm, and other operational behaviors. Furthermore, for networked devices, environmental data can be collected using a device environment probe. In this embodiment, the probe can achieve non-intrusive data collection in two ways: 1. Network traffic monitoring: This solution requires no additional software installation on the device. It analyzes the source, destination, protocol type, and data content of data packets at the network level to infer the device type, usage, and network environment status. The entire process runs automatically in the background, completely unnoticed by the user; 2. Device sensor access: This utilizes the device's built-in hardware sensors such as GPS and Wi-Fi modules to collect environmental data such as location and surrounding hotspots, also executed silently in the background. By integrating the collected device data with user real-name information and behavioral data, a preliminary assessment of potential risks can be further achieved.

[0024] The multi-factor verification module is used to call AI-enhanced verification factors and cross-verify user identity based on environmental and behavioral data collected by the risk perception and access module. The risk decision-making module is used to perform real-time correlation risk analysis using a pre-built knowledge graph, so as to achieve comprehensive risk assessment and accurately identify complex fraud patterns. A privacy-preserving computation data platform is used to achieve secure computation and joint modeling by collaborating with multiple data sources through privacy-preserving computation technology. The feedback optimization module is used to execute decisions and collect feedback results, including manual review results, user complaints and customer service tickets, and business performance data. Based on the collected feedback results, it automatically optimizes models and strategies to form a closed-loop self-evolving system.

[0025] Based on the aforementioned request verification system, a schematic diagram illustrating the specific implementation flow of the request verification method provided in this application is shown below. Figure 2 As shown, the main steps include the following: Step 11: Determine the initial risk profile corresponding to the user of the request to be authenticated based on the obtained environmental data and behavioral data of the user. In the initial stage of a user initiating a real-name authentication request, such as opening an account, logging in, or conducting business, the request verification system can seamlessly collect the user's environmental and behavioral data through the risk perception and access module. In this embodiment, the risk perception and access module integrates a smart terminal SDK, a dynamic orchestration gateway, and a data standardization module. Therefore, the request verification system can collect multi-source data without the user's awareness through a lightweight probe SDK integrated into the client app or web application.

[0026] In this embodiment of the application, environmental data may include device fingerprints, such as hardware model, operating system version, IMEI / SN number, etc.; network environment data, such as IP address, proxy detection, base station information, etc.; location data, such as GPS coordinates, etc.

[0027] Behavioral data can include: touchscreen gestures (touch speed, pressure, trajectory), mouse movement trajectory, keyboard typing rhythm, and other sequences of user actions when making a request.

[0028] It should be noted that, in this embodiment of the application, the request verification system can also collect business data when the user initiates the request. Specifically, the business data may refer to identity-related information actively uploaded by the user when initiating the real-name authentication request, such as the ID photo provided by the user or the facial image video uploaded by the user. Then, based on the scanned copy of the ID card uploaded by the user, the plaintext data related to the user's identity, such as the user's name, age, ID number, and place of residence, can be determined.

[0029] After collecting user environmental, behavioral, and business data through the risk perception and access module, the request verification system first cleans, transforms, and encrypts the collected raw data, then converts it into a standard data stream in a unified format. For example, it handles missing and outlier values ​​by assigning them unified default values ​​and converting all types of data into numerical values. It should be noted that this application embodiment does not limit the specific methods of data cleaning, transformation, and encryption.

[0030] Based on the device fingerprints in the collected environmental data, a unique and anonymous device ID is generated using the SHA-256 hash algorithm. By calling a predefined real-time rule base and a lightweight AI model, such as a logistic regression model, the generated device ID is matched with a historical black market device database to query device reputation, detect inconsistencies in environmental data, and detect abnormal behavior by comparing the collected behavioral data with normal user behavior data. Finally, by comprehensively analyzing the above analysis results, an initial risk profile corresponding to the authentication request is obtained.

[0031] In one implementation, the real-time rule base and lightweight AI model can be constructed through the following sub-steps, including: Sub-step 1101, Feature construction: Statistical features are constructed based on historical data, and multiple fields are combined to generate cross features. For cardinality and categorical variables, embedding technology is used to map them into a low-dimensional dense vector feature.

[0032] Sub-step 1102, rule base execution: Define the rule base, match the feature vector of the current request with the preset rule set, and output a boolean value for each rule.

[0033] Sub-step 1103: Train a logistic regression model for lightweight real-time inference, running in parallel with the rule base, to capture complex, non-linear risk patterns. Input the generated feature vector into the trained model, and the logistic regression model outputs a probability score in the range of 0 to 1, representing the probability that the request is malicious. Sub-step 1104: Add a penalty term triggered by the rule to the output probability score to obtain a preliminary risk score, and generate a risk label based on the triggered rule and the high-scoring features output by the model.

[0034] In this embodiment of the application, the preliminary risk score can be calculated and determined according to the following formula [1]: [1] in, The probability score of malicious requests output by a trained logistic regression model; R i I(R) represents the i-th predefined risk control rule; i ) indicates the rule trigger indicator function, when rule R i The value is 1 if the condition is met, and 0 otherwise; w i ≥0 is used to represent rule R i The penalty weight reflects the severity of the risk and can be configured according to business needs.

[0035] Step 12: Based on the initial risk profile obtained by executing Step 11, determine the multi-dimensional cross-validation strategy corresponding to the request to be authenticated. In this embodiment of the application, the request verification system can determine the multi-dimensional cross-validation strategy corresponding to the request to be authenticated according to the following method: determining the risk level corresponding to the request to be authenticated based on the initial risk profile; determining the combination of verification factors corresponding to the risk level from the preset strategy matrix based on the risk level, thereby obtaining the multi-dimensional cross-validation strategy corresponding to the request to be authenticated.

[0036] Specifically, the request verification system can determine the risk level of the request to be authenticated based on the preliminary risk score in the preliminary risk profile. Then, based on the risk level, it can dynamically select a set of verification factors that need to be provided by the user from the preset verification factor library. In this embodiment, based on the preliminary risk score, the user corresponding to the request to be authenticated can be divided into three risk levels: low risk, medium risk, and high risk.

[0037] Among them, low-risk users are S final <T score Furthermore, no high-risk rules were triggered, and the medium-risk user is T.low ≤S final <T high Furthermore, there are minor abnormalities but they do not reach the high-risk level. The high-risk user is S. final ≥T score Or it may trigger critical high-risk rules. In this embodiment of the application, T score T low T high T represents the preset risk score threshold, where T low <T high <T score .

[0038] In this embodiment of the application, the request verification system can determine the multi-dimensional cross-validation strategy corresponding to the risk level of the request to be authenticated by querying the strategy matrix shown in Table 1 below.

[0039] Table 1 Risk Level-Strategy Matrix

[0040] Step 13: Based on the multidimensional cross-validation strategy obtained by executing Step 12, perform multidimensional cross-validation on the authentication request to obtain the cross-validation result corresponding to the multidimensional cross-validation. Based on the multidimensional cross-validation strategy determined by executing step 12, the request validation system calls services in the pluggable validation factor library to perform at least two different types of validation factor verification.

[0041] In this embodiment of the application, the verification factors stored in the pluggable verification factor library include, but are not limited to, the following: 1) Verification Factor 1: Verification of document authenticity; Specifically, the document verification scheme provided in this application embodiment may include: using Optical Character Recognition (OCR) technology and information extraction technology, and utilizing a deep learning OCR model to extract text information from user-uploaded document photos with high precision under complex backgrounds, poor lighting, and tilted angles; employing physical anti-counterfeiting feature detection technology to automatically detect physical anti-counterfeiting features on the document, such as security lines, microtext, ultraviolet fluorescence, and rainbow printing, to determine its authenticity; and using convolutional neural networks to analyze abnormalities such as texture consistency, edge artifacts, moiré patterns, and Photoshop traces in the document image; finally, it can also ensure that the document uploaded by the user is a directly photographed physical document, rather than a document image, by detecting EXIF ​​information, imaging consistency, and reflected light spots in the image.

[0042] 2) Verification Factor Two: Biometric Verification; Specifically, in this embodiment, the request verification system can employ deep liveness detection technology to distinguish between real people, photos, screens, 3D head models, or masks by analyzing the texture of facial skin, subtle color changes caused by capillary blood flow, and 3D depth information. At the same time, it can also integrate a dedicated Deepfake detection model to identify video attacks generated by AI face-swapping technology. Finally, after confirming that it is a real person, it performs a high-precision comparison with the ID photo in the public security database.

[0043] 3) Verification Factor Three: Possession Factor Verification; Specifically, in this embodiment, the request verification system can cooperate with the operator through contactless verification technology, and under authorization, directly verify in the background whether the local mobile phone number is consistent with the registered mobile phone number through data tag or gateway authentication, eliminating the step of manually entering the verification code; and assess the risk of the mobile phone card itself based on SIM card risk detection.

[0044] In one implementation, the request verification system may specifically perform cross-validation based on the verification factors stored in the verification factor library, in the following dimensions: 1. Cross-validation of credential logical consistency: Based on the collected multi-dimensional identity credential information of the user corresponding to the authentication request, cross-validate the logical consistency between the multi-dimensional identity credential information. Specifically, the verification system can extract the location corresponding to the first 6 digits of the user's ID number and the first 7 digits of their mobile phone number, and input them together with the user's authorized current GPS location (after correction) into the geospatial analysis model. The system converts location data in different formats into unified geographic coordinates, calculates spatial distance, and determines whether the spatiotemporal logic is consistent based on preset thresholds.

[0045] II. Biometric Consistency Cross-validation: Based on the collected multi-dimensional biometric information of the user corresponding to the authentication request, cross-validate the consistency between the multi-dimensional biometric information. Specifically, in this embodiment, the verification system can utilize AI-enhanced liveness detection and document authentication. It employs a deep neural network model to analyze skin texture, 3D information, and microvascular blood flow to defend against attacks from photos, screen captures, and 3D masks; and integrates a Deepfake detection model to analyze the consistency of video biometric signals. Simultaneously, it uses a computer vision model to analyze physical features of document images, such as microtext, rainbow printing, and laser anti-counterfeiting features, for authenticity verification. Finally, it performs a high-precision comparison between the captured live face and the document photo in the public security database.

[0046] III. Cross-validation of behavioral characteristics consistency: Based on the collected multi-dimensional behavioral characteristics of the user corresponding to the authentication request, cross-validate the consistency between the multi-dimensional behavioral characteristics.

[0047] Specifically, in this application embodiment, the request verification system can compare the user's current form filling speed, number of field modifications, cursor movement trajectory and other micro-behavioral sequences with the user's declared identity historical behavior profile (or similar normal user profile) in real time to detect whether there are abnormal patterns such as scripting or automation.

[0048] Step 14: Based on the pre-built risk knowledge graph, perform correlation analysis on the authentication request to obtain the correlation analysis results corresponding to the authentication request; In this embodiment of the application, step 14 may be implemented in the following ways: obtaining at least one target entity corresponding to the request to be authenticated, wherein the target entity includes at least one of user identifier, device identifier, network address, and mobile phone number; determining the entity relationship network corresponding to the target entity based on the risk knowledge graph, using each target entity as a query node; and completing the association analysis of the request to be authenticated by judging whether the request to be authenticated has a preset high-risk association based on the entity relationship network.

[0049] Specifically, in this embodiment of the application, the request verification system can construct a knowledge graph analysis module through the risk decision module. This knowledge graph analysis module maintains a dynamically growing risk knowledge graph, whose nodes include entities such as users, device IDs, IP addresses, and mobile phone numbers, and whose edges represent co-occurrence relationships between entities, such as "using," "login," and "attribution."

[0050] In one implementation, the risk decision module can extract key entities as target nodes from the current authentication requests and verification results, such as the current user identifier, device ID, login IP, and operating mobile phone number; and use the target node as the center to query its one-hop or multi-hop related entities and relationships in the graph to form a local entity relationship network; finally, based on graph algorithms (e.g., path query), it can identify whether there are preset high-risk association patterns.

[0051] In one implementation, the identified high-risk associations may include, but are not limited to, the following categories: 1. Device clustering risk: The number of different user identifiers associated with the current device ID exceeds the preset threshold.

[0052] 2. Clustering Risk: The number of high-risk requests associated with the current IP address within a preset time window T exceeds the threshold.

[0053] 3. Gang Pattern: Through subgraph matching, network structures similar to historical fraud cases are identified, consisting of multiple devices, IPs, and mobile phone numbers.

[0054] Finally, the verification system can add associated risk labels to the requests to be authenticated based on the analysis results. For example, it can add a label indicating suspected group fraud.

[0055] Step 15: Based on the cross-validation results and correlation analysis results obtained by performing the above steps, determine the final verification result for the request to be authenticated.

[0056] It should be noted that, in order to further ensure the accuracy of the identity verification results, in this embodiment of the application, the request verification system can call a third-party data source to obtain authoritative user identity information, and perform identity verification on the user corresponding to the authentication request based on the obtained authoritative identity information.

[0057] In this embodiment, the request verification system can send the hash values ​​Hash(N) and Hash(ID) generated from the user's name and ID number to the privacy computing data platform. The privacy computing node in the privacy computing data platform acts as a coordinator and distributes the encryption computing task to the business party and the authoritative data source (such as the public security database) based on the secure multi-party computation (MPC) protocol. The authoritative data source performs the comparison calculation in its local encrypted database and returns the encryption result. After decryption, the privacy computing node returns the plaintext verification result, such as "match" or "inconsistent", to the decision engine.

[0058] The verification system can then determine the final verification result for the request to be authenticated by calling a weighted fusion model based on the identity verification result, cross-validation result, and correlation analysis result obtained through the above steps.

[0059] In this embodiment of the application, the weighted fusion model can dynamically adjust the weights w of each factor. i (t), for example, when threat intelligence indicates an increase in "device cloning" attacks, the weight w of the device factor. device Automatic boosting. In this embodiment of the application, the weight can be dynamically adjusted according to the following formula [2]: [2] Where 'a' is the smoothing coefficient, with a default value of 0.7, and 'V(t)' is the threat index for the current period.

[0060] Ultimately, the request verification system can make a final verification decision based on the comprehensive cross-validation results (confidence of each factor), knowledge graph association analysis results, external verification results, and real-time rules: pass, reject, require manual review, or enhance verification.

[0061] Finally, after the decision is executed, the request verification system can collect the handling results (such as pass / reject) and subsequent user behavior data, which will be automatically fed into the feedback optimization module through event-driven or timed batch processing. These data are automatically labeled, such as "confirmed as fraud" or "confirmed as normal", and used as training samples.

[0062] Under the federated learning framework, each participant uses new local samples to incrementally train the model, and only uploads the model parameters to the central server for aggregation, thereby optimizing the global risk identification model and realizing the closed-loop self-evolution of the system.

[0063] The request verification method provided in this application allows for authentication of received requests. When authentication is required, an initial risk profile is determined based on the acquired environmental and behavioral data of the user corresponding to the request. Then, a multi-dimensional cross-validation strategy is determined based on this initial risk profile. This strategy is then applied to the request to obtain the cross-validation result. Simultaneously, a correlation analysis is performed on the request based on a pre-built risk knowledge graph, yielding the correlation analysis result. Finally, the final verification result for the request is determined based on the cross-validation and correlation analysis results. This method, by combining at least two different types of authentication factors for cross-validation, forces attackers to simultaneously bypass multiple independent verification dimensions, increasing attack difficulty and cost, and significantly improving verification accuracy and defense depth. On the other hand, by using risk knowledge graphs to perform correlation analysis on requests, hidden risks that are difficult to detect in a single verification can be identified at the entity association network level. This allows for in-depth mining of hidden relationship chains between entities such as users, devices, and network addresses. As a result, the system can not only identify the authenticity of the current request itself, but also identify potential risk aggregation patterns. This effectively improves the ability to identify group fraud and greatly enhances the accuracy of the system in identifying risks.

[0064] In one embodiment, this application also provides a request verification device to address the problems of existing real-name authentication schemes having a single verification dimension, resulting in a weak protection system, and lacking the ability to perform correlation analysis and complex pattern recognition, thus failing to effectively identify and intercept complex attack patterns such as group fraud and cross-account collaborative crimes. A schematic diagram of the specific structure of the request verification device is shown below. Figure 3 As shown, it includes: an initial risk profile determination unit 31, a cross-validation unit 32, a correlation analysis unit 33, and a comprehensive validation unit 34.

[0065] The initial risk profile determination unit 31 is used to determine the initial risk profile corresponding to the authentication request based on the environmental data and behavioral data of the user corresponding to the authentication request. Cross-validation unit 32 is used to determine the multi-dimensional cross-validation strategy corresponding to the request to be authenticated based on the initial risk profile, and to perform multi-dimensional cross-validation on the request to be authenticated based on the multi-dimensional cross-validation strategy to obtain the cross-validation result corresponding to the multi-dimensional cross-validation, wherein the multi-dimensional cross-validation strategy includes at least two different types of authentication factors. The association analysis unit 33 is used to perform association analysis on the request to be authenticated based on a pre-built risk knowledge graph, and obtain the association analysis result corresponding to the request to be authenticated. The comprehensive verification unit 34 is used to determine the final verification result for the request to be authenticated based on the cross-validation results and the correlation analysis results.

[0066] In one implementation, the cross-validation unit 32 is specifically used to: cross-validate the logical consistency between the multi-dimensional identity credential information based on the collected multi-dimensional identity credential information of the user corresponding to the authentication request; and / or cross-validate the consistency between the multi-dimensional biometric information based on the collected multi-dimensional biometric information of the user corresponding to the authentication request; and / or cross-validate the consistency between the multi-dimensional behavioral features based on the collected multi-dimensional behavioral features of the user corresponding to the authentication request.

[0067] In one implementation, the association analysis unit 33 is specifically used for: obtaining at least one target entity corresponding to the request to be authenticated, wherein the target entity includes at least one of user identifier, device identifier, network address, and mobile phone number; determining the entity relationship network corresponding to the target entity based on the risk knowledge graph, using each target entity as a query node; and completing the association analysis of the request to be authenticated by judging whether the request to be authenticated has a preset high-risk association based on the entity relationship network.

[0068] In one implementation, high-risk association specifically includes: the number of user identifiers associated with the device identifier corresponding to the authentication request is higher than a preset user number threshold; and / or the number of high-risk requests issued by the network address corresponding to the authentication request within a preset time period is higher than a preset request number threshold.

[0069] In one implementation, the comprehensive verification unit 34 is specifically used to: based on a privacy computing node, use a secure multi-party computation protocol to call a third-party data source to authenticate the user corresponding to the request to be authenticated, and obtain an authentication result; and determine the final verification result for the request to be authenticated based on the authentication result, the cross-validation result, and the correlation analysis result.

[0070] In one implementation, the initial risk profile determination unit 31 is specifically used to: determine the risk level corresponding to the request to be authenticated based on the initial risk profile; and determine the combination of verification factors corresponding to the risk level from a preset strategy matrix based on the risk level to obtain the multidimensional cross-validation strategy corresponding to the request to be authenticated.

[0071] Using the request verification apparatus provided in this application embodiment, when identity authentication of a received request is required, an initial risk profile corresponding to the request to be authenticated can be determined based on the environmental and behavioral data of the user corresponding to the request to be authenticated. Then, based on the initial risk profile, a multi-dimensional cross-validation strategy corresponding to the request to be authenticated can be determined, and multi-dimensional cross-validation can be performed on the request to be authenticated according to the determined multi-dimensional cross-validation strategy to obtain the cross-validation result. Simultaneously, based on a pre-constructed risk knowledge graph, correlation analysis is performed on the request to be authenticated to obtain the correlation analysis result corresponding to the request to be authenticated. Finally, based on the cross-validation result and the correlation analysis result, the final verification result for the request to be authenticated is determined. Using the request verification method provided in this application embodiment, on the one hand, cross-validation is performed by combining at least two different types of authentication factors. In this cross-validation mode, attackers must simultaneously break through multiple independent verification dimensions, increasing the difficulty and cost of attacks and greatly improving verification accuracy and defense depth. On the other hand, by using risk knowledge graphs to perform correlation analysis on requests, hidden risks that are difficult to detect in a single verification can be identified at the entity association network level. This allows for in-depth mining of hidden relationship chains between entities such as users, devices, and network addresses. As a result, the system can not only identify the authenticity of the current request itself, but also identify potential risk aggregation patterns. This effectively improves the ability to identify group fraud and greatly enhances the accuracy of the system in identifying risks.

[0072] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Please refer to it. Figure 4At the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and memory. The memory may include main memory, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk drive. Of course, the electronic device may also include other hardware required for other business operations.

[0073] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 4 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0074] Memory is used to store programs. Specifically, programs may include program code, which includes computer operation instructions. Memory may include main memory and non-volatile memory, and provides instructions and data to the processor.

[0075] The processor reads the corresponding computer program from non-volatile memory into main memory and then executes it, forming a request verification mechanism at the logical level. The processor executes the program stored in memory and specifically performs the following operations: Based on the obtained environmental and behavioral data of the user corresponding to the authentication request, an initial risk profile is determined for the authentication request. Based on the initial risk profile, a multi-dimensional cross-validation strategy is determined for the authentication request, and multi-dimensional cross-validation is performed on the authentication request according to the multi-dimensional cross-validation strategy to obtain the cross-validation result. The multi-dimensional cross-validation strategy includes at least two different types of authentication factors. Based on a pre-constructed risk knowledge graph, a correlation analysis is performed on the authentication request to obtain the correlation analysis result. Based on the cross-validation result and the correlation analysis result, the final verification result for the authentication request is determined.

[0076] The above is as stated in this application. Figure 4The method for requesting verification of an electronic device disclosed in the illustrated embodiments can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0077] Of course, in addition to software implementation, the electronic device of this application does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. In other words, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0078] This application also proposes a computer-readable storage medium that stores one or more programs, the programs including instructions that, when executed by a portable electronic device including multiple applications, enable the portable electronic device to perform... Figure 1 The request verification method of the illustrated embodiment is specifically used to perform the following operations: Based on the obtained environmental and behavioral data of the user corresponding to the authentication request, an initial risk profile is determined for the authentication request. Based on the initial risk profile, a multi-dimensional cross-validation strategy is determined for the authentication request, and multi-dimensional cross-validation is performed on the authentication request according to the multi-dimensional cross-validation strategy to obtain the cross-validation result. The multi-dimensional cross-validation strategy includes at least two different types of authentication factors. Based on a pre-constructed risk knowledge graph, a correlation analysis is performed on the authentication request to obtain the correlation analysis result. Based on the cross-validation result and the correlation analysis result, the final verification result for the authentication request is determined.

[0079] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0080] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0081] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0082] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0083] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0084] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0085] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0086] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0087] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0088] The above description is merely an embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of this application should be included within the scope of the claims of this application.

Claims

1. A request verification method, characterized in that, include: Based on the environmental and behavioral data of the user corresponding to the authentication request, an initial risk profile corresponding to the authentication request is determined. Based on the initial risk profile, a multidimensional cross-validation strategy corresponding to the request to be authenticated is determined, and multidimensional cross-validation is performed on the request to be authenticated according to the multidimensional cross-validation strategy to obtain the cross-validation result corresponding to the multidimensional cross-validation. The multidimensional cross-validation strategy includes at least two different types of authentication factors. Based on a pre-built risk knowledge graph, the association analysis is performed on the request to be authenticated to obtain the association analysis results corresponding to the request to be authenticated. Based on the cross-validation results and the correlation analysis results, the final verification result for the request to be authenticated is determined.

2. The method according to claim 1, characterized in that, The step of performing multi-dimensional cross-validation on the request to be authenticated according to the multi-dimensional cross-validation strategy specifically includes: Based on the collected multi-dimensional identity credential information of the user corresponding to the authentication request, cross-validate the logical consistency between the multi-dimensional identity credential information; and / or Based on the collected multi-dimensional biometric information of the user corresponding to the authentication request, the consistency between the multi-dimensional biometric information is cross-validated; and / or Based on the collected multidimensional behavioral characteristics of the user corresponding to the authentication request, the consistency between the multidimensional behavioral characteristics is cross-validated.

3. The method according to claim 1, characterized in that, The association analysis of the authentication request based on the pre-built risk knowledge graph specifically includes: Obtain at least one target entity corresponding to the authentication request, wherein the target entity includes at least one of user identifier, device identifier, network address, and mobile phone number; Based on the risk knowledge graph, the entity relationship network corresponding to each target entity is determined by using each target entity as a query node. Based on the entity relationship network, the association analysis of the request to be authenticated is completed by determining whether there is a preset high-risk association.

4. The method according to claim 3, characterized in that, The high-risk associations specifically include: The number of user identifiers associated with the device identifier corresponding to the authentication request is higher than a preset user number threshold; and / or The number of high-risk requests issued by the network address corresponding to the request to be authenticated within a preset time period exceeds a preset request number threshold.

5. The method according to claim 1, characterized in that, The step of determining the final verification result for the request to be authenticated based on the cross-validation results and the correlation analysis results specifically includes: Based on privacy-preserving computing nodes, a secure multi-party computation protocol is used to authenticate the user corresponding to the authentication request by calling a third-party data source, and the authentication result is obtained. Based on the authentication result, the cross-validation result, and the correlation analysis result, the final verification result for the request to be authenticated is determined.

6. The method according to claim 1, characterized in that, The step of determining the multi-dimensional cross-validation strategy corresponding to the request to be authenticated based on the initial risk profile includes: Based on the initial risk profile, the risk level corresponding to the request to be authenticated is determined; Based on the risk level, a combination of verification factors corresponding to the risk level is determined from a preset strategy matrix to obtain the multidimensional cross-validation strategy corresponding to the request to be authenticated.

7. A request verification device, characterized in that, include: The initial risk profile determination unit is used to determine the initial risk profile corresponding to the authentication request based on the environmental data and behavioral data of the user corresponding to the authentication request. The cross-validation unit is used to determine the multi-dimensional cross-validation strategy corresponding to the request to be authenticated based on the initial risk profile, and to perform multi-dimensional cross-validation on the request to be authenticated based on the multi-dimensional cross-validation strategy to obtain the cross-validation result corresponding to the multi-dimensional cross-validation, wherein the multi-dimensional cross-validation strategy includes at least two different types of authentication factors. The association analysis unit is used to perform association analysis on the request to be authenticated based on a pre-built risk knowledge graph, and obtain the association analysis results corresponding to the request to be authenticated. The comprehensive verification unit is used to determine the final verification result for the request to be authenticated based on the cross-validation results and the correlation analysis results.

8. A request verification device, comprising: processor; as well as A memory configured to store computer-executable instructions, which, when executed, cause the processor to perform the following operations: Based on the environmental and behavioral data of the user corresponding to the authentication request, an initial risk profile corresponding to the authentication request is determined. Based on the initial risk profile, a multidimensional cross-validation strategy corresponding to the request to be authenticated is determined, and multidimensional cross-validation is performed on the request to be authenticated according to the multidimensional cross-validation strategy to obtain the cross-validation result corresponding to the multidimensional cross-validation. The multidimensional cross-validation strategy includes at least two different types of authentication factors. Based on a pre-built risk knowledge graph, the association analysis is performed on the request to be authenticated to obtain the association analysis results corresponding to the request to be authenticated. Based on the cross-validation results and the correlation analysis results, the final verification result for the request to be authenticated is determined.

9. A computer-readable storage medium storing one or more programs that, when executed by an electronic device including a plurality of applications, cause the electronic device to perform the request verification method as described in any one of claims 1-6.

10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the request verification method as described in any one of claims 1-6.