Authentication method and device for user identity of terminal equipment
By detecting the network environment of terminal devices and combining behavioral baselines and biometric authentication, the accuracy and privacy security issues of existing terminal identity authentication methods are resolved, achieving efficient multimodal identity authentication and privacy protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- LIAONING COMM TECH CO LTD
- Filing Date
- 2026-02-14
- Publication Date
- 2026-05-19
AI Technical Summary
Existing terminal authentication methods rely too heavily on static credentials, making it difficult to cope with dynamic changes in network security, unable to effectively distinguish between real users and attackers, and biometric authentication poses a risk of privacy leakage.
By detecting the network environment of the terminal device, a lightweight behavioral authentication model is used to perform behavioral authentication, and biometric authentication is performed when the authentication fails. Facial image data is encrypted and stored using a chaotic system to improve the accuracy and privacy security of identity authentication.
It improves the accuracy of terminal multimodal identity authentication, reduces system resource consumption, and enhances user privacy and security.
Smart Images

Figure CN122065299A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of terminal identity authentication technology, and in particular to a method and apparatus for authenticating the identity of a terminal device user. Background Technology
[0002] Currently, terminal authentication methods generally adopt the traditional model of combining username and password authentication. The core problem with this method is that it relies too much on static credentials. Even if secondary verification methods such as SMS verification codes or dynamic tokens are introduced, the essence is still to simplify the identity verification process to a single or combined verification of elements that are "known to the user" or "held by the user". Under this model, risks such as password leakage, phishing attacks, and man-in-the-middle hijacking always exist.
[0003] Furthermore, existing terminal authentication methods typically lack the ability to continuously evaluate contextual behavior. Once login authentication is successful, the session is usually valid for a long time. Even if the user logs in from an abnormal location or the operating mode changes abruptly, the system can hardly detect and respond in time. This static authentication mechanism is significantly out of sync with the dynamically changing network security landscape. A deeper problem is that traditional authentication methods are difficult to effectively deal with internal threats or spoofing after credential theft. That is, once authentication information is obtained, the system often cannot distinguish between real users and attackers. While enhancement methods such as biometric authentication can provide a certain degree of differentiation, they face problems such as privacy storage, spoofing attacks, and implementation costs, posing a risk of user privacy leakage. Summary of the Invention
[0004] In view of this, the purpose of this application is to provide a method and apparatus for authenticating the identity of a terminal device user. When the user to be authenticated starts and logs into the terminal device, the network environment in which the terminal device is located is detected. When the network environment is not a preset network environment, a behavior baseline recognition model is used to perform lightweight and imperceptible behavior authentication of the user identity based on the collected keystroke behavior data. When the user to be authenticated fails the behavior authentication, a biometric recognition model is used to perform biometric authentication based on the collected facial image data, and a chaotic system is used to encrypt and store the facial image data to determine whether the user to be authenticated is the target user. This improves the accuracy of multimodal identity authentication of the terminal and reduces the occupation of system resources, thereby improving the privacy and security of the user when using the terminal device.
[0005] This application provides a method for authenticating the identity of a terminal device user, the authentication method including: In response to a user waiting to be authenticated starting and logging into the target terminal device, the network environment of the target terminal device is detected, and it is determined whether the network environment is a preset network environment; If the network environment is not the preset network environment, then the keystroke behavior data triggered by the user to be authenticated on the target terminal device is collected, and based on the keystroke behavior data, the user to be authenticated is authenticated using a preset behavior baseline recognition model to determine whether the user to be authenticated has passed the behavior authentication. If the user to be authenticated fails the behavioral authentication, the facial image data of the user to be authenticated is obtained, and the facial image data is encrypted and stored using a preset chaotic system. Based on the facial image data, a preset biometric recognition model is used to perform biometric authentication on the user to be authenticated, so as to determine whether the user to be authenticated has passed the biometric authentication. If the user to be authenticated fails the biometric authentication, the authentication result of the user to be authenticated is determined to be that the user is not the target user, and the authentication result is uploaded to the server corresponding to the target terminal device.
[0006] Furthermore, in response to a user to be authenticated starting and logging into the target terminal device, detecting the network environment of the target terminal device and determining whether the network environment is a preset network environment includes: In response to a user waiting to be authenticated starting and logging into the target terminal device, network configuration parameters corresponding to the network environment in which the target terminal device is located are collected; Based on the network configuration parameters, the network environment is verified by using a preset network feature library to determine whether the network environment passes the IP address verification. If the network environment passes the IP address verification, then based on the network configuration parameters, a preset network feature library is used to perform DNS domain name verification on the network environment to determine whether the network environment passes the DNS domain name verification. If the network environment passes the DNS domain name verification, then the network environment is determined to be the preset network environment; If the network environment fails the IP address verification or the DNS domain name verification, then the network environment is determined to be not the preset network environment.
[0007] Furthermore, the step of collecting keystroke behavior data triggered by the user to be authenticated on the target terminal device, and based on the keystroke behavior data, performing behavioral authentication on the user to be authenticated using a preset behavioral baseline recognition model to determine whether the user to be authenticated has passed the behavioral authentication, includes: Collect keystroke behavior data of the user to be authenticated on the target terminal device at preset time intervals, and construct the behavior time series corresponding to the keystroke behavior data; The behavior time series is input into a preset behavior baseline recognition model, so that the behavior baseline recognition model can be used to classify the behavior time series based on the preset behavior baseline to obtain the behavior scalar probability value output by the behavior baseline recognition model. Determine whether the scalar probability value of the behavior is greater than a preset confidence threshold in order to perform behavioral authentication on the user to be authenticated; If the scalar probability value of the behavior is less than or equal to the confidence threshold, then it is determined that the user to be authenticated will not pass the behavior authentication. If the behavior scalar probability value is greater than the confidence threshold, the keystroke behavior data of the user to be authenticated is collected again at a preset time interval, and the behavior baseline recognition model is used to classify the keystroke behavior data and output the behavior scalar probability value corresponding to the keystroke behavior data. If the scalar probability value of the behavior is still greater than the confidence threshold, then the user to be authenticated is determined to have passed the authentication by the behavior.
[0008] Furthermore, the behavior baseline recognition model is constructed through the following steps: Acquire first time-series data corresponding to multiple first keystroke events triggered by the target user on the target terminal device, and construct a behavioral feature time baseline sequence corresponding to each first keystroke event based on the first time-series data corresponding to each first keystroke event; Acquire second time-series data corresponding to multiple second keystroke events triggered by non-target users on the target terminal device, and construct a behavioral feature time deviation sequence corresponding to each second keystroke event based on the second time-series data corresponding to each second keystroke event; Based on the behavioral feature time baseline sequence and the behavioral feature time deviation sequence, the initial behavioral baseline recognition model is trained until the initial behavioral baseline recognition model converges when distinguishing between positive and negative samples, thus obtaining the behavioral baseline recognition model.
[0009] Furthermore, the step of encrypting and storing the facial image data using a preset chaotic system includes: For each face image in the face image data, the pixel values corresponding to the RGB channels of the face image are expanded and stored to obtain a first RGB array; A pre-defined chaotic system is pre-iterated using the Runge-Kutta method to bring the chaotic system into a chaotic state, and the chaotic system is further iterated to obtain the first chaotic state value corresponding to the chaotic system. The first chaotic state value is used to scramble the first RGB array until the number of scrambling operations is equal to the number of pixels corresponding to the face image, thus obtaining the second RGB array; In response to obtaining the second RGB array, the chaotic system is iterated further to obtain the second chaotic state value corresponding to the chaotic system, and the diffusion key stream element corresponding to the second chaotic state value is determined; The second RGB array is subjected to a cross-color channel diffusion operation using the diffusion key stream element until the number of scrambling operations equals the number of pixels, resulting in a third RGB array. The encrypted image corresponding to the third RGB array is then stored in the local database set by the target terminal device.
[0010] Furthermore, the step of performing biometric authentication on the user to be authenticated based on the facial image data using a preset biometric recognition model to determine whether the user to be authenticated has passed the biometric authentication includes: The face image data is scaled and pixel normalized to obtain the target face image data; The target face image data is input into a preset biometric recognition model, and the biometric recognition model is used to sequentially extract confidence features and calculate cosine similarity to the target face image data, so as to obtain the cosine similarity value corresponding to the user to be authenticated output by the biometric recognition model. Determine whether the cosine similarity value is greater than a preset similarity threshold to determine whether the user to be authenticated has passed the biometric authentication. If the cosine similarity value is greater than the preset similarity threshold, then the user to be authenticated is determined to have passed the biometric authentication. If the cosine similarity value is less than or equal to the preset similarity threshold, then it is determined that the user to be authenticated has failed the biometric authentication.
[0011] Furthermore, the authentication method also includes: If the network environment is the preset network environment, or the user to be authenticated passes the behavior authentication, or the user to be authenticated passes the biometric authentication, the identity authentication result of the user to be authenticated is determined to be the target user.
[0012] This application embodiment also provides an authentication device for the user identity of a terminal device, the authentication device comprising: The network environment identification module is used to detect the network environment of the target terminal device in response to the user to be authenticated starting and logging into the target terminal device, and to determine whether the network environment is a preset network environment. The behavior baseline recognition module is used to collect keystroke behavior data triggered by the user to be authenticated on the target terminal device if the network environment is not the preset network environment, and to perform behavior authentication on the user to be authenticated based on the keystroke behavior data using a preset behavior baseline recognition model, so as to determine whether the user to be authenticated has passed the behavior authentication. An image encryption storage module is used to acquire the facial image data of the user to be authenticated if the user to be authenticated fails the behavior authentication, and to encrypt and store the facial image data using a preset chaotic system. The biometric recognition module is used to perform biometric authentication on the user to be authenticated based on the facial image data and using a preset biometric recognition model, so as to determine whether the user to be authenticated has passed the biometric authentication. The first identity authentication module is used to determine that the identity authentication result of the user to be authenticated is not the target user if the user to be authenticated fails the biometric authentication, and upload the identity authentication result to the server corresponding to the target terminal device.
[0013] Furthermore, when the network environment identification module is used to detect the network environment of the target terminal device in response to a user seeking authentication starting and logging into the target terminal device, and to determine whether the network environment is a preset network environment, the network environment identification module is used to: In response to a user waiting to be authenticated starting and logging into the target terminal device, network configuration parameters corresponding to the network environment in which the target terminal device is located are collected; Based on the network configuration parameters, the network environment is verified by using a preset network feature library to determine whether the network environment passes the IP address verification. If the network environment passes the IP address verification, then based on the network configuration parameters, a preset network feature library is used to perform DNS domain name verification on the network environment to determine whether the network environment passes the DNS domain name verification. If the network environment passes the DNS domain name verification, then the network environment is determined to be the preset network environment; If the network environment fails the IP address verification or the DNS domain name verification, then the network environment is determined to be not the preset network environment.
[0014] Furthermore, when the behavior baseline recognition module collects keystroke behavior data triggered by the user to be authenticated on the target terminal device, and performs behavior authentication on the user to be authenticated based on the keystroke behavior data using a preset behavior baseline recognition model to determine whether the user to be authenticated has passed the behavior authentication, the behavior baseline recognition module is used to: Collect keystroke behavior data of the user to be authenticated on the target terminal device at preset time intervals, and construct the behavior time series corresponding to the keystroke behavior data; The behavior time series is input into a preset behavior baseline recognition model, so that the behavior baseline recognition model can be used to classify the behavior time series based on the preset behavior baseline to obtain the behavior scalar probability value output by the behavior baseline recognition model. Determine whether the scalar probability value of the behavior is greater than a preset confidence threshold in order to perform behavioral authentication on the user to be authenticated; If the scalar probability value of the behavior is less than or equal to the confidence threshold, then it is determined that the user to be authenticated will not pass the behavior authentication. If the behavior scalar probability value is greater than the confidence threshold, the keystroke behavior data of the user to be authenticated is collected again at a preset time interval, and the behavior baseline recognition model is used to classify the keystroke behavior data and output the behavior scalar probability value corresponding to the keystroke behavior data. If the scalar probability value of the behavior is still greater than the confidence threshold, then the user to be authenticated is determined to have passed the authentication by the behavior.
[0015] Furthermore, when the behavior baseline recognition module is used to construct the behavior baseline recognition model, the behavior baseline recognition module is used to: Acquire first time-series data corresponding to multiple first keystroke events triggered by the target user on the target terminal device, and construct a behavioral feature time baseline sequence corresponding to each first keystroke event based on the first time-series data corresponding to each first keystroke event; Acquire second time-series data corresponding to multiple second keystroke events triggered by non-target users on the target terminal device, and construct a behavioral feature time deviation sequence corresponding to each second keystroke event based on the second time-series data corresponding to each second keystroke event; Based on the behavioral feature time baseline sequence and the behavioral feature time deviation sequence, the initial behavioral baseline recognition model is trained until the initial behavioral baseline recognition model converges when distinguishing between positive and negative samples, thus obtaining the behavioral baseline recognition model.
[0016] Furthermore, when the image encryption storage module is used to encrypt and store the face image data using a preset chaotic system, the image encryption storage module is used to: For each face image in the face image data, the pixel values corresponding to the RGB channels of the face image are expanded and stored to obtain a first RGB array; A pre-defined chaotic system is pre-iterated using the Runge-Kutta method to bring the chaotic system into a chaotic state, and the chaotic system is further iterated to obtain the first chaotic state value corresponding to the chaotic system. The first chaotic state value is used to scramble the first RGB array until the number of scrambling operations is equal to the number of pixels corresponding to the face image, thus obtaining the second RGB array; In response to obtaining the second RGB array, the chaotic system is iterated further to obtain the second chaotic state value corresponding to the chaotic system, and the diffusion key stream element corresponding to the second chaotic state value is determined; The second RGB array is subjected to a cross-color channel diffusion operation using the diffusion key stream element until the number of scrambling operations equals the number of pixels, resulting in a third RGB array. The encrypted image corresponding to the third RGB array is then stored in the local database set by the target terminal device.
[0017] Furthermore, when the biometric recognition module is used to perform biometric authentication on the user to be authenticated based on the facial image data and using a preset biometric recognition model to determine whether the user to be authenticated has passed the biometric authentication, the biometric recognition module is used to: The face image data is scaled and pixel normalized to obtain the target face image data; The target face image data is input into a preset biometric recognition model, and the biometric recognition model is used to sequentially extract confidence features and calculate cosine similarity to the target face image data, so as to obtain the cosine similarity value corresponding to the user to be authenticated output by the biometric recognition model. Determine whether the cosine similarity value is greater than a preset similarity threshold to determine whether the user to be authenticated has passed the biometric authentication. If the cosine similarity value is greater than the preset similarity threshold, then the user to be authenticated is determined to have passed the biometric authentication. If the cosine similarity value is less than or equal to the preset similarity threshold, then it is determined that the user to be authenticated has failed the biometric authentication.
[0018] Furthermore, the authentication device also includes a second identity authentication module, which is used for: If the network environment is the preset network environment, or the user to be authenticated passes the behavior authentication, or the user to be authenticated passes the biometric authentication, the identity authentication result of the user to be authenticated is determined to be the target user.
[0019] This application embodiment also provides an electronic device, including: a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor communicates with the memory via the bus. When the machine-readable instructions are executed by the processor, the steps of the terminal device user authentication method described above are performed.
[0020] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps of the terminal device user authentication method described above.
[0021] The terminal device user authentication method and apparatus provided in this application include: in response to a user to be authenticated starting and logging into a target terminal device, detecting the network environment of the target terminal device and determining whether the network environment is a preset network environment; if the network environment is not the preset network environment, collecting keystroke behavior data triggered by the user to be authenticated on the target terminal device, and performing behavioral authentication on the user to be authenticated based on the keystroke behavior data using a preset behavioral baseline recognition model to determine whether the user to be authenticated passes the behavioral authentication; if the user to be authenticated fails the behavioral authentication, acquiring the user's facial image data and encrypting and storing the facial image data using a preset chaotic system; performing biometric authentication on the user to be authenticated based on the facial image data using a preset biometric recognition model to determine whether the user to be authenticated passes the biometric authentication; if the user to be authenticated fails the biometric authentication, determining that the user's authentication result is not the target user, and uploading the authentication result to the server corresponding to the target terminal device.
[0022] Compared to the traditional authentication method that combines username and password, and introduces secondary verification methods such as SMS verification codes or dynamic tokens, as well as static authentication mechanisms, this method detects the network environment of the terminal device when the user to be authenticated starts and logs in. When the network environment is not the preset network environment, a behavioral baseline recognition model is used to perform lightweight and imperceptible behavioral authentication of the user's identity based on the collected keystroke behavior data. When the user to be authenticated fails the behavioral authentication, a biometric recognition model is used to perform biometric authentication based on the collected facial image data. A chaotic system is used to encrypt and store the facial image data to determine whether the user to be authenticated is the target user. This improves the accuracy of terminal multimodal identity authentication and reduces the consumption of system resources, thereby improving the privacy and security of users when using terminal devices.
[0023] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0024] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 This is one of the flowcharts for a terminal device user authentication method provided in an embodiment of this application; Figure 2 This is a schematic diagram of a scrambling operation provided in an embodiment of this application; Figure 3 A schematic diagram of a diffusion operation provided in an embodiment of this application; Figure 4 A second flowchart illustrating a terminal device user authentication method provided in this application embodiment; Figure 5 This is one of the structural schematic diagrams of a terminal device user identity authentication device provided in an embodiment of this application; Figure 6 This is a second schematic diagram of the structure of a terminal device user identity authentication device provided in an embodiment of this application; Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0026] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of this application. Based on the embodiments of this application, every other embodiment obtained by those skilled in the art without inventive effort falls within the scope of protection of this application.
[0027] Research has revealed that current terminal authentication methods generally employ the traditional model of combining username and password authentication. Although this model has been deployed in enterprise environments for many years and has formed certain standards, it still faces a series of deep challenges. The core problem with these methods is their over-reliance on static credentials. Even with the introduction of secondary verification methods such as SMS verification codes or dynamic tokens, the identity verification process is essentially simplified to a single or combined verification of elements "known to the user" or "held by the user." Under this model, risks such as password leakage, phishing attacks, and man-in-the-middle attacks always exist. Furthermore, the promotion of multi-factor authentication often faces the dilemma of balancing user experience and security costs.
[0028] Furthermore, existing terminal authentication methods typically lack the ability to continuously evaluate contextual behavior. Once login authentication is successful, the session is usually valid for a long time. Even if the user logs in from an unusual location or their operating mode changes abruptly, the system struggles to detect and respond promptly. This static authentication mechanism is significantly out of sync with the dynamically changing cybersecurity landscape. A deeper problem is that traditional authentication methods are ill-suited to dealing with internal threats or spoofing attempts after credential theft. Once authentication information is obtained, the system often cannot distinguish between a genuine user and an attacker. While biometric authentication and other enhancement methods can provide some differentiation, they face issues such as privacy storage, spoofing attacks, and implementation costs, posing a risk of user privacy leaks. Simultaneously, existing systems do not adequately address the security and compliance of the terminal devices themselves.
[0029] It is evident that, in existing technologies, firstly, most methods adopt a "one-time authentication, permanent validity" model, which fails to address the security issue of unauthorized personnel potentially using the terminal after the legitimate user leaves. Secondly, most methods rely on a single factor as the basis for identity authentication, resulting in insufficient system security or drawbacks such as high cost and potential leakage of user privacy. For example, systems using passwords or hardware as the basis for identity authentication cannot identify the user's biometric features in real time, leaving significant room for security improvement. Furthermore, systems based on biometrics for real-time authentication are costly, and frequent identity verification results in a poor user experience. In addition, the accuracy of single-factor authentication is lower than that of multi-factor authentication systems. Finally, biometric authentication systems only consider identity recognition while neglecting the security protection of the collected data, posing a risk of user privacy leakage.
[0030] Based on this, this application provides a method for authenticating the identity of a terminal device user. When the user to be authenticated starts and logs into the terminal device, the network environment of the terminal device is detected. When the network environment is not a preset network environment, a behavior baseline recognition model is used to perform lightweight and imperceptible behavior authentication of the user identity based on the collected keystroke behavior data. When the user to be authenticated fails the behavior authentication, a biometric recognition model is used to perform biometric authentication based on the collected face image data, and a chaotic system is used to encrypt and store the face image data to determine whether the user to be authenticated is the target user. This improves the accuracy of terminal multimodal identity authentication and reduces the occupation of system resources, thereby improving the privacy and security of users when using the terminal device.
[0031] Please see Figure 1 , Figure 1 This is one of the flowcharts for a terminal device user authentication method provided in an embodiment of this application. For example... Figure 1 As shown in the embodiments of this application, the terminal device user authentication method includes: S101. In response to the user to be authenticated starting and logging into the target terminal device, detect the network environment in which the target terminal device is located, and determine whether the network environment is a preset network environment.
[0032] It should be noted that "users awaiting authentication" refers to users who have not yet been authenticated and are attempting to access the network or system but have not yet been authorized. The "awaiting authentication" status means that the system temporarily restricts their access permissions until identity verification is completed.
[0033] Terminal devices refer to electronic devices that users directly use to access networks or run applications, such as smartphones, laptops, desktop computers, tablets, smart TVs, IoT devices (such as smart cameras and smart speakers), industrial terminals, POS machines, and self-service terminals.
[0034] Here, the terminal device is the "endpoint" of network communication, responsible for initiating or receiving data. In network security and management, information such as the identity, type, and operating system of the terminal device is often used for access control and policy formulation.
[0035] The network environment in which the target terminal device is located refers to the network infrastructure to which the terminal device is currently connected and its security, configuration and access characteristics. The same terminal device may have different access permissions and security risks in different network environments.
[0036] In this embodiment of the application, the preset network environment includes, but is not limited to, a secure intranet environment.
[0037] This step is used to determine whether the current terminal device is in a preset network environment (secure intranet environment). If the terminal device is not in a preset network environment, behavioral authentication and biometric authentication are performed on the user to be authenticated, thereby ensuring the accuracy of identity verification and preventing the problem of information leakage caused by the device being used by others if the target user does not close the terminal after leaving.
[0038] In this application embodiment, the identity of the user to be authenticated includes target users or non-target users; wherein, a target user refers to a user who has been authorized by the system or network administrator, possesses valid identity credentials, and is allowed to access specific resources or services (i.e., a legitimate user); a non-target user refers to a user or entity that has not been authorized and has attempted or has exceeded its authority to access the system, network, or data resources (i.e., an illegal user).
[0039] In one possible implementation of this application, step S101 may include: S1011. In response to the user to be authenticated starting and logging into the target terminal device, collect the network configuration parameters corresponding to the network environment in which the target terminal device is located.
[0040] In this step, when the user to be authenticated starts and logs into the target terminal device, the underlying API of the target terminal device's operating system is called to collect the network configuration parameters corresponding to the network environment in which the target terminal device is located, so as to prevent the user from tampering with them.
[0041] The network configuration parameters include, but are not limited to, internal dedicated domain name list, IP address and subnet mask, DNS server address and DNS domain suffix configuration parameters.
[0042] S1012. Based on the network configuration parameters, the network environment is checked for IP addresses using a preset network feature library to determine whether the network environment passes the IP address check.
[0043] In this embodiment of the application, the network feature database serves as the benchmark for detection. The content of the network feature database is not limited to, but includes, a set of standard private IP address ranges, custom network address ranges, a list of internal exclusive domain names, and preset DNS domain suffix parameters.
[0044] For example, the standard private IP address range set includes preset industry-standard enterprise-level private IP address ranges, such as 10.0.0.0 / 8, 172.16.0.0 / 12, and 192.168.0.0 / 16; the custom network address range indicates that if an enterprise uses a custom NAT address or public IP as its internal network address, this type of custom address range needs to be added to the feature database; the internal exclusive domain name list contains the exclusive domain names of the enterprise's internal services, and multiple core internal domain names are added to improve detection reliability; the preset DNS domain suffix parameter is the standard domain suffix issued by the enterprise through the DHCP server.
[0045] In this step, when performing IP address verification on the network environment to determine whether the network environment passes the IP address verification, firstly, the network bit of the terminal's current IP address is calculated based on the subnet mask to obtain the network address to which the terminal belongs. The calculation process uses the CIDR algorithm (the calculation formula is: "Network address = IP address AND subnet mask", where "AND" is a bitwise AND operation). Then, the calculated terminal network address is compared one by one with the standard private IP address ranges in the network feature database (e.g., 10.0.0.0 / 8, 172.16.0.0 / 12, 192.168.0.0 / 16) to determine whether the terminal network address falls within the above address ranges. Finally, if the terminal network address does not fall within the standard private IP address range, it is compared with the custom network address ranges (custom NAT address / public IP range) in the network feature database. If the terminal IP address belongs to the standard private IP address range or the custom network address range, the network environment is determined to pass the IP address verification; otherwise, the network environment is determined to fail the IP address verification.
[0046] S1013. If the network environment passes the IP address verification, then based on the network configuration parameters, the network environment is subjected to DNS domain name verification using a preset network feature library to determine whether the network environment passes the DNS domain name verification.
[0047] In this step, when performing DNS domain name verification on the network environment to determine whether the network environment passes the DNS domain name verification, firstly, internal private domain name resolution is checked. From the list of internal private domain names in the network feature database, one or two domain names are randomly selected as detection targets (to avoid misjudgment due to a single domain name failure). The target terminal device is controlled to initiate a DNS resolution request to the target domain name through the currently configured DNS server, and the resolution result is recorded. A timeout period is set for the resolution process (default 5 seconds). If there is no response within the timeout period, it is judged as a resolution failure. If the IP address corresponding to the target domain name can be successfully resolved, and the IP address belongs to a trusted address range (standard private IP or custom address range) in the network feature database, it is marked as a private domain name resolution success. If the resolution fails, or the resolved IP address is an untrusted address or a public network-irrelevant address, it is marked as a private domain name resolution failure.
[0048] Then, a DNS domain suffix verification is performed. The DNS domain suffix configuration parameters of the target terminal device are precisely compared with the preset DNS domain suffixes in the network feature database. If the terminal DNS domain suffix matches the preset domain suffix, it is marked as DNS domain suffix verification passed; otherwise, it is marked as DNS domain suffix verification failed.
[0049] Finally, the DNS domain name resolution test results are output. If both "dedicated domain name resolution passed" and "DNS domain suffix verification passed", the network environment is determined to have passed DNS domain name verification; otherwise, the network environment is determined to have failed DNS domain name verification.
[0050] S1014. If the network environment passes the DNS domain name verification, then the network environment is determined to be a preset network environment.
[0051] S1015. If the network environment fails the IP address verification or the DNS domain name verification, then it is determined that the network environment is not the preset network environment.
[0052] S102. If the network environment is not the preset network environment, then collect the keystroke behavior data triggered by the user to be authenticated on the target terminal device, and perform behavior authentication on the user to be authenticated using the preset behavior baseline recognition model based on the keystroke behavior data, so as to determine whether the user to be authenticated has passed the behavior authentication.
[0053] This step is used to continuously and unconsciously identify the user to be authenticated for the target terminal device in a non-preset network environment. A behavioral baseline recognition model is used to model and analyze the keystroke behavior of the user to be authenticated. By performing similarity analysis between the keystroke behavior of the user to be authenticated and the behavioral baseline of the target user, it is initially determined whether the user to be authenticated is the target user or not. If it is determined to be a non-target user, further biometric authentication is performed.
[0054] In this embodiment of the application, the behavioral baseline identification model may include a Long Short-Term Memory (LSTM) network model. The Long Short-Term Memory network model is a special type of recurrent neural network (RNN) used to solve the gradient vanishing or gradient explosion problems that traditional RNNs are prone to when processing long sequence data. The LSTM model can effectively capture long-term dependencies in time series.
[0055] Here, the behavioral baseline refers to the typical behavioral pattern that a user or device exhibits over a long period of time under normal conditions.
[0056] In one possible implementation of this application, the behavior baseline recognition model is constructed through the following steps: S102A: Obtain first time-series data corresponding to multiple first keystroke events triggered by the target user on the target terminal device, and construct a behavioral feature time baseline sequence corresponding to each first keystroke event based on the first time-series data corresponding to each first keystroke event.
[0057] In this step, it is necessary to collect the keystroke behavior of the target user to build the target user's behavior baseline. Specifically, based on the "SetWindowsHookEx()" function, the operating system hook is used to collect the target user's press and release events for different keys, and record the first timing data corresponding to multiple first keystroke events.
[0058] The first timing data includes, but is not limited to, key codes (e.g., a, h, r, space, enter, etc.) and the corresponding timestamps for pressing PrT and releasing RlsT.
[0059] Furthermore, for an action involving N keystrokes, the time baseline sequence of behavioral features corresponding to the first keystroke event is obtained ({x0, x1, …, x…). N-1 The behavioral feature time baseline sequence is used as the input to the behavioral baseline recognition model.
[0060] The behavioral feature time baseline sequence includes the feature vector of each first keystroke event, including but not limited to key code and key type, intra-key time (holdi = RlsTi - PrTi), forward inter-key time (interi = PrTi+1 -PrTi), specific key pairs (e.g., t->h, h->e, s->h), etc.
[0061] S102B: Obtain second time-series data corresponding to multiple second keystroke events triggered by non-target users on the target terminal device, and construct a behavioral feature time deviation sequence corresponding to each second keystroke event based on the second time-series data corresponding to each second keystroke event.
[0062] The description of S102B can be referred to the description of S102A. It only requires replacing the target user with a non-target user to achieve the same technical effect, so it will not be elaborated further.
[0063] S102C. Based on the behavioral feature time baseline sequence and the behavioral feature time deviation sequence, train the initial behavioral baseline recognition model until the initial behavioral baseline recognition model converges when distinguishing between positive and negative samples, and obtain the behavioral baseline recognition model.
[0064] In this embodiment of the application, a behavior baseline recognition model is constructed to learn the behavior baseline of the target user. First, the forget gate, input gate and output gate in the initial behavior baseline recognition model are used to dynamically filter the time series information.
[0065] The forget gate is used to control the proportion of historical information retained, and the formula is: ,in, f t Output for the forget gate; W f This is the forget gate weight matrix; b f Forget gate bias term; σ The default Sigmoid function; x t Behavioral characteristics; h t-1 This outputs the temporal features from the previous iteration.
[0066] The input gate and candidate cell state control the input of new information, respectively. The formula for the input gate is: ,in, i t For input gate output; W i The input gate weight matrix; b i For input gate bias terms; σ The default Sigmoid function; x t Behavioral characteristics; h t-1 This outputs the temporal features from the previous iteration.
[0067] The formula for candidate cell status is: ,in,C t Output of candidate cell states; W c This is the candidate cell state weight matrix; x t Behavioral characteristics; b c This refers to the candidate cell state bias term; h t-1 This outputs the temporal features from the previous iteration.
[0068] The formulas for the output gate and the hidden layer state are: ,in, o t This outputs the gate and the hidden layer state. W o The output gate and hidden layer weight matrix; b o For output gate and hidden layer bias terms; σ The default Sigmoid function; x t Behavioral characteristics; h t-1 This outputs the temporal features from the previous iteration.
[0069] The classification head takes the hidden state of the initial behavior baseline recognition model at the final time as the feature summary of the entire sequence, inputs it into the fully connected layer and the Sigmoid activation function, and outputs a scalar P between 0 and 1, that is, the probability that the sequence belongs to the target user.
[0070] Furthermore, the constructed initial behavior baseline recognition model is trained. The sample sequence labels of the collected target users are "y=1", and the sample sequence labels of the non-target user dataset are "y=0". The binary cross-entropy loss (Loss= - [y·log(p) + (1-y)·log(1-p)]) is used as the loss function. The loss function is minimized through the backpropagation algorithm, so that the model parameters learn to maximize the distinction between positive and negative samples. That is, until the initial behavior baseline recognition model converges in distinguishing between positive and negative samples, the behavior baseline recognition model is obtained.
[0071] In one possible implementation of this application, step S102 may include: S1021. Collect keystroke behavior data triggered by the user to be authenticated on the target terminal device at preset time intervals, and construct the behavior time series corresponding to the keystroke behavior data.
[0072] S1022. Input the behavior time series into a preset behavior baseline recognition model, so as to use the behavior baseline recognition model to classify the behavior time series based on the preset behavior baseline, and obtain the behavior scalar probability value output by the behavior baseline recognition model.
[0073] Here, the behavior scalar probability value is a quantification of the confidence that the currently observed keystroke behavior belongs to the "normal baseline" by the behavior baseline identification model. It is a scalar value between 0 and 1. For example, when the behavior scalar probability value is high (e.g., 0.95), it means that the current keystroke behavior is highly consistent with the historical baseline and is very likely normal. When the behavior scalar probability value is low (e.g., 0.1), it means that the current keystroke behavior deviates significantly from the baseline and may be abnormal or risky.
[0074] S1023. Determine whether the probability value of the behavior scalar is greater than a preset confidence threshold, so as to perform behavior authentication on the user to be authenticated.
[0075] In this embodiment, the preset confidence threshold is a manually set critical value used to determine whether the model output is sufficiently reliable. This threshold is typically a real number between 0 and 1 (e.g., 0.9), used to convert the probability or confidence score of the model output into a binary decision.
[0076] S1024. If the scalar probability value of the behavior is less than or equal to the confidence threshold, then it is determined that the user to be authenticated does not pass the behavior authentication.
[0077] S1025. If the behavior scalar probability value is greater than the confidence threshold, the keystroke behavior data of the user to be authenticated is collected again at a preset time interval, and the behavior baseline recognition model is used to classify the keystroke behavior data and output the behavior scalar probability value corresponding to the keystroke behavior data.
[0078] The description of S1025 can refer to the descriptions of S1021 to S1023, and can achieve the same technical effect, so it will not be elaborated further.
[0079] S1026. If the scalar probability value of the behavior is still greater than the confidence threshold, then it is determined that the user to be authenticated has passed the behavior authentication.
[0080] S103. If the user to be authenticated fails the behavior authentication, the facial image data of the user to be authenticated is obtained, and the facial image data is encrypted and stored using a preset chaotic system.
[0081] It should be noted that storing the acquired facial image data of the user to be authenticated after encryption not only avoids the security risk of the system leaking the user's personal privacy information on the terminal device, but also prevents the facial recognition information from being tampered with by the user, effectively improving the integrity and security of identity authentication.
[0082] Here, when the user to be authenticated starts and logs into the target terminal device for the first time, the camera of the target terminal device is called to collect facial images of the user to be authenticated from different angles, so as to obtain candidate facial image data of the user to be authenticated.
[0083] Furthermore, in this step, when the user to be authenticated fails the behavioral authentication, face image data consisting of a preset number of face images is obtained from the candidate face image data of the user to be authenticated, and the face image data is encrypted and stored using a preset chaotic system.
[0084] Among them, the chaotic system may include a three-dimensional autonomous chaotic system. The three-dimensional autonomous chaotic system does not contain a time variable, the phase volume shrinks with time, and the trajectory forms a complex, non-periodic structure in the phase space that is sensitive to the initial value.
[0085] In one possible implementation of this application, in specific implementation, the step of encrypting and storing the face image data using a preset chaotic system in step S103 may include: S1031. For each face image in the face image data, expand and store the pixel values corresponding to the RGB channels of the face image to obtain a first RGB array.
[0086] In this step, the pixel values of the RGB channels in the face image are expanded from bottom to top and from left to right, and stored in the first RGB array.
[0087] The first RGB array includes a first red array, a first green array, and a first blue array. For example, the first red array is “R_FI={rp0, rp1, ...,rpH×W-1}”; the first green array is “G_FI={gp0, gp1, ...,gpH×W-1}”; and the first blue array is “B_FI={bp0, bp1, ..., bpH×W-1}”. H and W are the width and height values of the face image (FI), respectively.
[0088] S1032. Use the preset Runge-Kutta method to pre-iterate the preset chaotic system to make the chaotic system in a chaotic state, and continue to iterate the chaotic system to obtain the first chaotic state value corresponding to the chaotic system.
[0089] In this embodiment of the application, the key “{chen_x, chen_y, chen_z}” is used as the preset initial chaotic value of the chaotic system, and the chaotic system is pre-iterated N times using the fourth-order Runge-Kutta method to fully iterate the chaotic system and prevent security problems from occurring.
[0090] Here, the chaos formula for a chaotic system is shown below.
[0091] .
[0092] in,( , , ) are the state variables of the chaotic system; a, b, and c are the control parameters (e.g., a=35, b=3, c=28); , , () represents the derivative of the state variable with respect to time t.
[0093] In this embodiment of the application, the first chaotic state value corresponding to the chaotic system is obtained by the following formula.
[0094] .
[0095] in,{ , , } represents the first chaotic state value corresponding to the chaotic system; H and W are the width and height values of the face image, respectively; , , ) is the state variable value of the chaotic system at step n.
[0096] S1033. Use the first chaotic state value to scramble the first RGB array until the number of scrambling operations is equal to the number of pixels corresponding to the face image, and obtain the second RGB array.
[0097] For example, please refer to Figure 2 , Figure 2 This is a schematic diagram illustrating a scrambling operation provided in an embodiment of this application. Figure 2 As shown, the chaotic system only needs to be iterated once to fully perturb the pixel values of the three color channels (R, G, B) in the face image within the channel and between different channels, which has high scrambling efficiency.
[0098] Among them, such as Figure 2As shown, pixel values rpi, gpi, and bpi are swapped with pixel values rpper_r, gpper_g, and bpper_b, respectively; mod3 operations are performed on per_r, per_g, and per_b to obtain per_r`, per_g`, and per_b`; cyclic shifts are performed on pixel values {rpi, gpper_r, bpper_r}, {rpper_g, gpi, bpper_g}, and {rpper_b, gpper_b, bpi}, respectively, using perr`, per_g`, and per_b`, and the scrambled pixel values are written into the first red array R_FI, the first green array G_FI, and the first blue array B_FI, respectively.
[0099] S1034. In response to obtaining the second RGB array, the chaotic system is iterated further to obtain the second chaotic state value corresponding to the chaotic system, and the diffusion key stream element corresponding to the second chaotic state value is determined.
[0100] In this embodiment of the application, the diffusion key stream element corresponding to the second chaotic state value is obtained by the following formula.
[0101] .
[0102] in,( , , ) represents a diffused keystream element; , , ) is the second chaotic state value.
[0103] S1035. Using the diffusion key stream element, perform a cross-color channel diffusion operation on the second RGB array until the number of scrambling operations equals the number of pixels to obtain a third RGB array, and store the ciphertext image corresponding to the third RGB array in the local database set by the target terminal device.
[0104] For example, please refer to Figure 3 , Figure 3 This is a schematic diagram of a diffusion operation provided in an embodiment of this application. For i=0, there is no en_bp. -1 In this case, set "en_bp-1=bp" H×W-1 "and then execute such Figure 3 The diffusion operation sequence is shown.
[0105] Here, the diffusion operation across color channels is performed using the following formula.
[0106] .
[0107] in, , , These represent the third RGB array; , , These represent the second RGB array respectively; , , ) represents a diffuse key stream element; Represents the initial diffusion element (i.e., bp). H×W-1 ).
[0108] S104. Based on the facial image data, perform biometric authentication on the user to be authenticated using a preset biometric recognition model to determine whether the user to be authenticated has passed the biometric authentication.
[0109] It should be noted that continuous identification of the behavioral baseline of the user to be authenticated can achieve the purpose of identity verification without being noticed. However, since the behavior of the user to be authenticated may fluctuate in the short term or drift gradually due to environment, emotion, task type or fatigue state, the behavioral baseline identification model may make misjudgments or decrease confidence in certain situations. Therefore, in this embodiment of the application, biometric identification is further performed on the user to be authenticated who does not conform to the behavioral baseline in order to fully ensure the accuracy of identity authentication.
[0110] Here, the biometric recognition model may include a residual network with 50 layers (ResNet-50).
[0111] In this embodiment, the biometric recognition model is constructed through the following steps: First, training face images that meet the input size and format requirements of the initial biometric recognition model are acquired; then, the training face images are standardized to construct a face dataset; then, the initial biometric recognition model is pre-trained using the face dataset; then, the pre-trained initial biometric recognition model is fine-tuned with a low learning rate and a small number of training epochs using the acquired face images, and 512-dimensional feature vectors from multiple face images are extracted and effective vectors with satisfactory confidence are selected; then, feature vector fusion based on a weighted average strategy is performed; finally, the fused feature vectors are L2 normalized and used as a face template file for the target user for the initial biometric recognition model to learn, thus obtaining the biometric recognition model.
[0112] Here, feature vector fusion based on a weighted average strategy is performed using the following formula.
[0113] .
[0114] in, The facial template feature vector of the target user. For the first The confidence weights of the feature vectors of each acquired face image; This represents the 512-dimensional feature vectors corresponding to multiple face images.
[0115] In one possible implementation of this application, step S104 may include: S1041. The face image data is subjected to size scaling and pixel normalization processing to obtain the target face image data.
[0116] In this step, each face image in the face image data is converted into a grayscale image, and a Gaussian filter is used to filter noise in the grayscale image for subsequent biometric recognition processing.
[0117] Furthermore, the MTCNN deep learning model is used to segment the face region of the noise-filtered face image, thereby eliminating the interference of background information; then, the obtained image is scaled to the set input size of the biometric recognition model (e.g., 224×224 pixels); finally, the scaled face image is normalized to obtain the target face image data.
[0118] In this embodiment of the application, the scaled face image is normalized using the following formula.
[0119] .
[0120] in, This represents the normalized pixel value of each pixel in the scaled face image; This represents the pixel value corresponding to each pixel in the scaled face image; This represents the maximum pixel value in the scaled face image; This represents the minimum pixel value in the scaled face image.
[0121] S1042. Input the target face image data into a preset biometric recognition model, and use the biometric recognition model to sequentially perform confidence feature extraction and cosine similarity calculation on the target face image data to obtain the cosine similarity value corresponding to the user to be authenticated output by the biometric recognition model.
[0122] In this embodiment of the application, the cosine similarity value corresponding to the user to be authenticated is calculated using the following formula.
[0123] .
[0124] in, This represents the cosine similarity value; This represents the feature vector corresponding to the target user pre-determined by the biometric recognition model. This represents the feature vector corresponding to the target face image data. Represents the multi-dimensional feature elements corresponding to the target face image data; This represents feature elements across multiple dimensions corresponding to the target user.
[0125] S1043. Determine whether the cosine similarity value is greater than a preset similarity threshold, so as to determine whether the user to be authenticated has passed the biometric authentication.
[0126] In the embodiments of this application, the preset similarity threshold can be set to 95%, but is not limited to 95%, and can also be other values, which will not be limited here.
[0127] S1044. If the cosine similarity value is greater than the preset similarity threshold, then it is determined that the user to be authenticated has passed the biometric authentication.
[0128] S1045. If the cosine similarity value is less than or equal to the preset similarity threshold, then it is determined that the user to be authenticated does not pass the biometric authentication.
[0129] S105. If the user to be authenticated fails the biometric authentication, the authentication result of the user to be authenticated is determined to be a non-target user, and the authentication result is uploaded to the server corresponding to the target terminal device.
[0130] In this step, when the network environment of the target terminal device is not the preset network environment, and the user to be authenticated fails both behavioral authentication and biometric authentication, the identity authentication result of the user to be authenticated is determined to be a non-target user (i.e., an illegal user), and the identity authentication result is uploaded to the server corresponding to the target terminal device.
[0131] Optional, please refer to Figure 4 , Figure 4 This is a second flowchart illustrating a method for authenticating the identity of a terminal device user, as provided in an embodiment of this application. Figure 4 As shown in the embodiment of this application, the terminal device user identity authentication method includes step S106 in addition to steps S101 to S105. Specifically, step S106 is used to explain the conditions for determining that the identity authentication result of the user to be authenticated is the target user.
[0132] S106. If the network environment is the preset network environment, or the user to be authenticated passes the behavior authentication, or the user to be authenticated passes the biometric authentication, the identity authentication result of the user to be authenticated is determined to be the target user.
[0133] When the network environment of the target terminal device is the preset network environment, or when the user to be authenticated passes behavioral authentication, or when the user to be authenticated passes biometric authentication, that is, when at least one of the above conditions is met, the identity authentication result of the user to be authenticated is determined to be the target user, and the identity authentication result is uploaded to the server corresponding to the target terminal device.
[0134] Here, if the target terminal device is in a preset network environment, only one initial identity authentication is performed on the user to be authenticated. Subsequently, the identity of the user to be authenticated will not be continuously verified by means of behavioral baseline recognition and biometric recognition, so as to reduce the system's consumption of terminal device resources.
[0135] Thus, the method described in this application does not enable resource-intensive face recognition authentication in a secure intranet environment, but only triggers face recognition authentication through lightweight behavioral baseline recognition in high-risk extranet environments. Furthermore, by using multi-factor fusion verification, the network environment, behavioral baseline, and biometrics are fused to achieve multimodal identity authentication, which not only effectively enhances the accuracy of identity authentication but also greatly reduces system resource consumption.
[0136] Furthermore, the method described in this application, after enabling facial recognition authentication, compares and stores the obtained facial images only within the local terminal and uploads the comparison results to the server, rather than uploading the facial images collected by the system to the server. This effectively ensures that personal privacy information is not leaked and achieves the purpose of identity authentication. Simultaneously, encrypting the locally stored facial images not only fully guarantees information security but also effectively prevents users from altering the images, further enhancing the integrity and credibility of the data.
[0137] Here, in the method described in the embodiments of this application, the acquisition of face images is rapidly and seamlessly encrypted based on a chaotic system. This reduces the resource consumption of the terminal during the encryption process, avoids the latency that may be caused by the encryption process, improves the overall efficiency of multimodal identity authentication, ensures the security of users' personal information on the terminal device, and has high encryption efficiency, thus achieving seamless encryption.
[0138] The terminal device user authentication method provided in this application detects the network environment of the terminal device when the user to be authenticated starts and logs in. When the network environment is not a preset network environment, a behavior baseline recognition model is used to perform lightweight and imperceptible behavior authentication of the user's identity based on the collected keystroke behavior data. When the user to be authenticated fails the behavior authentication, a biometric recognition model is used to perform biometric authentication based on the collected face image data, and a chaotic system is used to encrypt and store the face image data to determine whether the user to be authenticated is the target user. This improves the accuracy of terminal multimodal identity authentication and reduces the occupation of system resources, thereby improving the privacy and security of users when using terminal devices.
[0139] Please see Figure 5 , Figure 6 , Figure 5 This is one of the structural schematic diagrams of a terminal device user identity authentication device provided in an embodiment of this application. Figure 6 This is a second schematic diagram of a terminal device user identity authentication device provided in an embodiment of this application. Figure 5 As shown, the authentication device 500 includes: The network environment identification module 510 is used to detect the network environment of the target terminal device in response to the user to be authenticated starting and logging into the target terminal device, and to determine whether the network environment is a preset network environment. The behavior baseline recognition module 520 is used to collect keystroke behavior data triggered by the user to be authenticated on the target terminal device if the network environment is not the preset network environment, and to perform behavior authentication on the user to be authenticated based on the keystroke behavior data using a preset behavior baseline recognition model, so as to determine whether the user to be authenticated has passed the behavior authentication. The image encryption storage module 530 is used to obtain the face image data of the user to be authenticated if the user to be authenticated fails the behavior authentication, and to encrypt and store the face image data using a preset chaotic system. The biometric identification module 540 is used to perform biometric authentication on the user to be authenticated based on the face image data and using a preset biometric identification model, so as to determine whether the user to be authenticated has passed the biometric authentication. The first identity authentication module 550 is used to determine that the identity authentication result of the user to be authenticated is not the target user if the user to be authenticated fails the biometric authentication, and upload the identity authentication result to the server corresponding to the target terminal device.
[0140] Furthermore, when the network environment identification module 510 is used to detect the network environment of the target terminal device in response to the user to be authenticated starting and logging into the target terminal device, and to determine whether the network environment is a preset network environment, the network environment identification module 510 is used to: In response to a user waiting to be authenticated starting and logging into the target terminal device, network configuration parameters corresponding to the network environment in which the target terminal device is located are collected; Based on the network configuration parameters, the network environment is verified by using a preset network feature library to determine whether the network environment passes the IP address verification. If the network environment passes the IP address verification, then based on the network configuration parameters, a preset network feature library is used to perform DNS domain name verification on the network environment to determine whether the network environment passes the DNS domain name verification. If the network environment passes the DNS domain name verification, then the network environment is determined to be the preset network environment; If the network environment fails the IP address verification or the DNS domain name verification, then the network environment is determined to be not the preset network environment.
[0141] Furthermore, when the behavior baseline recognition module 520 collects keystroke behavior data triggered by the user to be authenticated on the target terminal device, and performs behavior authentication on the user to be authenticated based on the keystroke behavior data using a preset behavior baseline recognition model to determine whether the user to be authenticated has passed the behavior authentication, the behavior baseline recognition module 520 is used to: Collect keystroke behavior data of the user to be authenticated on the target terminal device at preset time intervals, and construct the behavior time series corresponding to the keystroke behavior data; The behavior time series is input into a preset behavior baseline recognition model, so that the behavior baseline recognition model can be used to classify the behavior time series based on the preset behavior baseline to obtain the behavior scalar probability value output by the behavior baseline recognition model. Determine whether the scalar probability value of the behavior is greater than a preset confidence threshold in order to perform behavioral authentication on the user to be authenticated; If the scalar probability value of the behavior is less than or equal to the confidence threshold, then it is determined that the user to be authenticated will not pass the behavior authentication. If the behavior scalar probability value is greater than the confidence threshold, the keystroke behavior data of the user to be authenticated is collected again at a preset time interval, and the behavior baseline recognition model is used to classify the keystroke behavior data and output the behavior scalar probability value corresponding to the keystroke behavior data. If the scalar probability value of the behavior is still greater than the confidence threshold, then the user to be authenticated is determined to have passed the authentication by the behavior.
[0142] Furthermore, when constructing the behavior baseline recognition model, the behavior baseline recognition module 520 is used to: Acquire first time-series data corresponding to multiple first keystroke events triggered by the target user on the target terminal device, and construct a behavioral feature time baseline sequence corresponding to each first keystroke event based on the first time-series data corresponding to each first keystroke event; Acquire second time-series data corresponding to multiple second keystroke events triggered by non-target users on the target terminal device, and construct a behavioral feature time deviation sequence corresponding to each second keystroke event based on the second time-series data corresponding to each second keystroke event; Based on the behavioral feature time baseline sequence and the behavioral feature time deviation sequence, the initial behavioral baseline recognition model is trained until the initial behavioral baseline recognition model converges when distinguishing between positive and negative samples, thus obtaining the behavioral baseline recognition model.
[0143] Furthermore, when the image encryption storage module 530 is used to encrypt and store the face image data using a preset chaotic system, the image encryption storage module 530 is used to: For each face image in the face image data, the pixel values corresponding to the RGB channels of the face image are expanded and stored to obtain a first RGB array; A pre-defined chaotic system is pre-iterated using the Runge-Kutta method to bring the chaotic system into a chaotic state, and the chaotic system is further iterated to obtain the first chaotic state value corresponding to the chaotic system. The first chaotic state value is used to scramble the first RGB array until the number of scrambling operations is equal to the number of pixels corresponding to the face image, thus obtaining the second RGB array; In response to obtaining the second RGB array, the chaotic system is iterated further to obtain the second chaotic state value corresponding to the chaotic system, and the diffusion key stream element corresponding to the second chaotic state value is determined; The second RGB array is subjected to a cross-color channel diffusion operation using the diffusion key stream element until the number of scrambling operations equals the number of pixels, resulting in a third RGB array. The encrypted image corresponding to the third RGB array is then stored in the local database set by the target terminal device.
[0144] Furthermore, when the biometric recognition module 540 is used to perform biometric authentication on the user to be authenticated based on the facial image data and using a preset biometric recognition model to determine whether the user to be authenticated has passed the biometric authentication, the biometric recognition module 540 is used to: The face image data is scaled and pixel normalized to obtain the target face image data; The target face image data is input into a preset biometric recognition model, and the biometric recognition model is used to sequentially extract confidence features and calculate cosine similarity to the target face image data, so as to obtain the cosine similarity value corresponding to the user to be authenticated output by the biometric recognition model. Determine whether the cosine similarity value is greater than a preset similarity threshold to determine whether the user to be authenticated has passed the biometric authentication. If the cosine similarity value is greater than the preset similarity threshold, then the user to be authenticated is determined to have passed the biometric authentication. If the cosine similarity value is less than or equal to the preset similarity threshold, then it is determined that the user to be authenticated has failed the biometric authentication.
[0145] Furthermore, such as Figure 6 As shown, the authentication device 500 further includes a second identity authentication module 560, which is used for: If the network environment is the preset network environment, or the user to be authenticated passes the behavior authentication, or the user to be authenticated passes the biometric authentication, the identity authentication result of the user to be authenticated is determined to be the target user.
[0146] The terminal device user authentication device provided in this application detects the network environment of the terminal device when the user to be authenticated starts and logs in. When the network environment is not a preset network environment, a behavior baseline recognition model is used to perform lightweight and imperceptible behavior authentication of the user's identity based on the collected keystroke behavior data. When the user to be authenticated fails the behavior authentication, a biometric recognition model is used to perform biometric authentication based on the collected face image data, and a chaotic system is used to encrypt and store the face image data to determine whether the user to be authenticated is the target user. This improves the accuracy of terminal multimodal identity authentication and reduces the occupation of system resources, thereby improving the privacy and security of users when using terminal devices.
[0147] Please see Figure 7 , Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 7As shown, the electronic device 700 includes a processor 710, a memory 720, and a bus 730.
[0148] The memory 720 stores machine-readable instructions executable by the processor 710. When the electronic device 700 is running, the processor 710 communicates with the memory 720 via the bus 730. When the machine-readable instructions are executed by the processor 710, they can perform the operations described above. Figure 1 as well as Figure 4 The steps of the terminal device user identity authentication method in the method embodiment shown are described in detail in the method embodiment, and will not be repeated here.
[0149] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, can perform the above-described actions. Figure 1 as well as Figure 4 The steps of the terminal device user identity authentication method in the method embodiment shown are described in detail in the method embodiment, and will not be repeated here.
[0150] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0151] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the shown or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.
[0152] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0153] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0154] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0155] Finally, it should be noted that the above-described embodiments are merely specific implementations of this application, used to illustrate the technical solutions of this application, and not to limit them. The scope of protection of this application is not limited thereto. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some of the technical features, within the scope of the technology disclosed in this application. Such modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for authenticating the identity of a user on a terminal device, characterized in that, The authentication method includes: In response to a user waiting to be authenticated starting and logging into the target terminal device, the network environment of the target terminal device is detected, and it is determined whether the network environment is a preset network environment; If the network environment is not the preset network environment, then the keystroke behavior data triggered by the user to be authenticated on the target terminal device is collected, and based on the keystroke behavior data, the user to be authenticated is authenticated using a preset behavior baseline recognition model to determine whether the user to be authenticated has passed the behavior authentication. If the user to be authenticated fails the behavioral authentication, the facial image data of the user to be authenticated is obtained, and the facial image data is encrypted and stored using a preset chaotic system. Based on the facial image data, a preset biometric recognition model is used to perform biometric authentication on the user to be authenticated, so as to determine whether the user to be authenticated has passed the biometric authentication. If the user to be authenticated fails the biometric authentication, the authentication result of the user to be authenticated is determined to be that the user is not the target user, and the authentication result is uploaded to the server corresponding to the target terminal device.
2. The method according to claim 1, characterized in that, The step of responding to a user seeking authentication starting and logging into the target terminal device, detecting the network environment of the target terminal device, and determining whether the network environment is a preset network environment includes: In response to a user waiting to be authenticated starting and logging into the target terminal device, network configuration parameters corresponding to the network environment in which the target terminal device is located are collected; Based on the network configuration parameters, the network environment is verified by using a preset network feature library to determine whether the network environment passes the IP address verification. If the network environment passes the IP address verification, then based on the network configuration parameters, a preset network feature library is used to perform DNS domain name verification on the network environment to determine whether the network environment passes the DNS domain name verification. If the network environment passes the DNS domain name verification, then the network environment is determined to be the preset network environment; If the network environment fails the IP address verification or the DNS domain name verification, then the network environment is determined to be not the preset network environment.
3. The method according to claim 1, characterized in that, The process of collecting keystroke behavior data triggered by the user to be authenticated on the target terminal device, and performing behavior authentication on the user to be authenticated based on the keystroke behavior data using a preset behavior baseline recognition model to determine whether the user to be authenticated has passed the behavior authentication, includes: Collect keystroke behavior data of the user to be authenticated on the target terminal device at preset time intervals, and construct the behavior time series corresponding to the keystroke behavior data; The behavior time series is input into a preset behavior baseline recognition model, so that the behavior baseline recognition model can be used to classify the behavior time series based on the preset behavior baseline to obtain the behavior scalar probability value output by the behavior baseline recognition model. Determine whether the scalar probability value of the behavior is greater than a preset confidence threshold in order to perform behavioral authentication on the user to be authenticated; If the scalar probability value of the behavior is less than or equal to the confidence threshold, then it is determined that the user to be authenticated will not pass the behavior authentication. If the behavior scalar probability value is greater than the confidence threshold, the keystroke behavior data of the user to be authenticated is collected again at a preset time interval, and the behavior baseline recognition model is used to classify the keystroke behavior data and output the behavior scalar probability value corresponding to the keystroke behavior data. If the scalar probability value of the behavior is still greater than the confidence threshold, then the user to be authenticated is determined to have passed the authentication by the behavior.
4. The method according to claim 1, characterized in that, The behavior baseline identification model is constructed using the following steps: Acquire first time-series data corresponding to multiple first keystroke events triggered by the target user on the target terminal device, and construct a behavioral feature time baseline sequence corresponding to each first keystroke event based on the first time-series data corresponding to each first keystroke event; Acquire second time-series data corresponding to multiple second keystroke events triggered by non-target users on the target terminal device, and construct a behavioral feature time deviation sequence corresponding to each second keystroke event based on the second time-series data corresponding to each second keystroke event; Based on the behavioral feature time baseline sequence and the behavioral feature time deviation sequence, the initial behavioral baseline recognition model is trained until the initial behavioral baseline recognition model converges when distinguishing between positive and negative samples, thus obtaining the behavioral baseline recognition model.
5. The method according to claim 1, characterized in that, The method of encrypting and storing the facial image data using a preset chaotic system includes: For each face image in the face image data, the pixel values corresponding to the RGB channels of the face image are expanded and stored to obtain a first RGB array; A pre-defined chaotic system is pre-iterated using the Runge-Kutta method to bring the chaotic system into a chaotic state, and the chaotic system is further iterated to obtain the first chaotic state value corresponding to the chaotic system. The first chaotic state value is used to scramble the first RGB array until the number of scrambling operations is equal to the number of pixels corresponding to the face image, thus obtaining the second RGB array; In response to obtaining the second RGB array, the chaotic system is iterated further to obtain the second chaotic state value corresponding to the chaotic system, and the diffusion key stream element corresponding to the second chaotic state value is determined; The second RGB array is subjected to a cross-color channel diffusion operation using the diffusion key stream element until the number of scrambling operations equals the number of pixels, resulting in a third RGB array. The encrypted image corresponding to the third RGB array is then stored in the local database set by the target terminal device.
6. The method according to claim 1, characterized in that, The step of performing biometric authentication on the user to be authenticated based on the facial image data using a preset biometric recognition model, to determine whether the user to be authenticated has passed the biometric authentication, includes: The face image data is scaled and pixel normalized to obtain the target face image data; The target face image data is input into a preset biometric recognition model, and the biometric recognition model is used to sequentially extract confidence features and calculate cosine similarity to the target face image data, so as to obtain the cosine similarity value corresponding to the user to be authenticated output by the biometric recognition model. Determine whether the cosine similarity value is greater than a preset similarity threshold to determine whether the user to be authenticated has passed the biometric authentication. If the cosine similarity value is greater than the preset similarity threshold, then the user to be authenticated is determined to have passed the biometric authentication. If the cosine similarity value is less than or equal to the preset similarity threshold, then it is determined that the user to be authenticated has failed the biometric authentication.
7. The method according to claim 1, characterized in that, The authentication method further includes: If the network environment is the preset network environment, or the user to be authenticated passes the behavior authentication, or the user to be authenticated passes the biometric authentication, the identity authentication result of the user to be authenticated is determined to be the target user.
8. An authentication device for user identity of a terminal device, characterized in that, The authentication device includes: The network environment identification module is used to detect the network environment of the target terminal device in response to the user to be authenticated starting and logging into the target terminal device, and to determine whether the network environment is a preset network environment. The behavior baseline recognition module is used to collect keystroke behavior data triggered by the user to be authenticated on the target terminal device if the network environment is not the preset network environment, and to perform behavior authentication on the user to be authenticated based on the keystroke behavior data using a preset behavior baseline recognition model, so as to determine whether the user to be authenticated has passed the behavior authentication. An image encryption storage module is used to acquire the facial image data of the user to be authenticated if the user to be authenticated fails the behavior authentication, and to encrypt and store the facial image data using a preset chaotic system. The biometric recognition module is used to perform biometric authentication on the user to be authenticated based on the facial image data and using a preset biometric recognition model, so as to determine whether the user to be authenticated has passed the biometric authentication. The first identity authentication module is used to determine that the identity authentication result of the user to be authenticated is not the target user if the user to be authenticated fails the biometric authentication, and upload the identity authentication result to the server corresponding to the target terminal device.
9. An electronic device, characterized in that, include: The device includes a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor communicates with the memory via the bus. The machine-readable instructions are executed by the processor to perform the steps of the terminal device user authentication method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, performs the steps of the terminal device user authentication method as described in any one of claims 1 to 7.