Multi-terminal financial account security collaborative authentication method, system and medium
By constructing a terminal behavior graph and a Gaussian mixture model, the problem of identifying short-term dynamic fluctuations in terminal behavior in a multi-terminal environment was solved, and the accurate identification of cross-terminal abnormal access patterns and collaborative attack behaviors was achieved, thereby improving the reliability of secure access to financial accounts.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING YIXIANG INFORMATION TECH CO LTD
- Filing Date
- 2026-03-25
- Publication Date
- 2026-06-19
AI Technical Summary
In multi-terminal financial account access environments, existing technologies struggle to identify risks caused by drastic changes in environmental parameters or covert collaborative attacks, and lack the ability to perceive short-term dynamic fluctuations in terminal behavior, resulting in high false positive rates, delayed responses, and fragile defense systems.
By constructing a terminal behavior graph to calculate the short-term dynamic disturbance intensity index, and combining it with a Gaussian mixture model to model and analyze the historical stable behavior of multiple terminals, the system can move from single-point terminal verification to multi-dimensional collaborative risk assessment, and identify cross-terminal abnormal access patterns and collaborative attack behaviors.
It significantly improves the accuracy and reliability of secure access to financial accounts, and effectively identifies abnormal access patterns and coordinated attack behaviors across terminals.
Smart Images

Figure CN122247690A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secure access technology, specifically to a method, system, and medium for secure collaborative authentication of multi-terminal financial accounts. Background Technology
[0002] With the digitalization and mobilization of financial services, it has become commonplace for users to access financial accounts via multiple terminals such as mobile phones, tablets, and PCs. However, secure access in multi-terminal environments faces severe challenges. Existing technologies typically rely solely on the static characteristics of a single terminal (such as device fingerprints and IP addresses) for isolated verification, lacking the ability to perceive dynamic fluctuations in short-term terminal behavior. This makes it difficult to identify risks caused by drastic changes in environmental parameters or covert collaborative attacks. At the same time, traditional methods often neglect the correlation analysis of behavioral data across multiple terminals, failing to effectively construct historical stable behavior models to quantify the degree of deviation between current access and historical patterns. This results in high false positive rates, delayed responses, and fragile defense systems when facing complex scenarios such as progressive anomalies and cross-terminal collaborative fraud. Summary of the Invention
[0003] The purpose of this invention is to address the problems existing in the background technology by proposing a method, system, and medium for secure collaborative authentication of multi-terminal financial accounts.
[0004] The technical solution of this invention: a multi-terminal financial account secure collaborative authentication method, comprising: S1. Receive the user's financial account access request, extract the account identification information and login credential information for basic identity verification, generate the corresponding access session identifier, and form the initial authentication dataset. S2. Extract the access terminal environment feature vector based on the initial authentication dataset, and perform matching calculation with the historical bound terminal feature library to generate a comprehensive matching score. Construct a terminal behavior map based on the current access terminal and its most recent access records. Calculate the terminal's short-term dynamic disturbance intensity index and combine it with the neighboring nodes to adjust the current terminal's score to generate an adjusted comprehensive matching score. The terminal's credibility level is determined based on the adjusted comprehensive matching score, and whether to enter the collaborative analysis stage is determined based on the terminal's credibility level. S3. Based on the judgment results, obtain multi-terminal access behavior data of the target financial account, construct a multi-terminal behavior feature matrix, construct a historical stable behavior model based on Gaussian mixture model, generate a behavior risk score, and conduct multi-terminal collaborative risk judgment. S4. Based on the risk assessment results of multi-terminal collaboration, execute the cross-terminal collaborative verification mechanism, and generate the final security collaborative authentication assessment result through authentication decision rules.
[0005] As a further improvement to this technical solution, step S1, forming the initial authentication dataset, includes the following steps: S1.1 Receive the financial account access request initiated by the user terminal, perform integrity verification on the financial account access request, and after the integrity verification is passed, perform structured parsing of the financial account access request based on the protocol parsing operation, and extract account identification information and login credential information according to the interface field definition rules, and perform identity verification based on the account identification information and login credential information; when the identity verification is passed, generate a unique access session identifier based on the account identification information. S1.2 Collect the environmental parameters of the current access terminal that initiated the financial account access request, standardize and encode the environmental parameters to form a terminal environment feature vector, and generate an account identity feature vector based on the account identification information. Combine the access session identifier, the account identity feature vector and the account identification information to construct the initial authentication dataset.
[0006] As a further improvement to this technical solution, in step S2, the terminal's short-term dynamic disturbance intensity index is calculated and the current terminal's score is adjusted by weighting the neighboring nodes to generate an adjusted comprehensive matching score. Based on the adjusted comprehensive matching score, the terminal's credibility level is determined, and the decision to enter the collaborative analysis stage is made based on the terminal's credibility level. This includes the following steps: S2.1 Obtain the terminal environment feature vector from the initial authentication dataset; S2.2. Based on the current access account identifier information, retrieve the historical bound terminal feature set of the access account from the preset account historical terminal feature database to form a sample set to be matched. ; S2.3, Matching terminal environment feature vectors with the sample set to be matched using cosine similarity. Perform matching calculations and calculate similarity metrics; S2.4. Calculate the similarity index of all historical terminals and calculate the comprehensive matching score; S2.5. Construct a terminal behavior graph based on the current access terminal and its most recent access records. Calculate the terminal's short-term dynamic disturbance intensity index and combine it with the weighted adjustment of the current access terminal's comprehensive matching score to generate the adjusted comprehensive matching score. S2.6. Based on the adjusted comprehensive matching score, construct the terminal credibility scoring function and generate the terminal credibility score; S2.7. Based on the terminal credibility score, determine the terminal credibility level by using a preset credibility threshold, and determine whether to enter the collaborative analysis stage based on the terminal credibility level.
[0007] As a further improvement to this technical solution, in S2.5, a terminal behavior graph is constructed based on the current accessing terminal and its most recent access records. The comprehensive matching score of the current accessing terminal is adjusted by calculating the terminal's short-term dynamic disturbance intensity index and combining it with weighted neighboring nodes. This includes the following steps: S2.51, Collect the most recent data from the currently accessing terminal. This is a record of previous visits; S2.52. Construct each historical access record and the current access terminal as a graph node, construct graph edges based on the graph nodes, and construct a terminal behavior graph based on the graph nodes and graph edges. S2.53. For the current graph node, extract the terminal environment feature vector of the corresponding access terminal at the current time step, and compare it with the nearest node to that access terminal. The difference degree is calculated by using the terminal environment feature vector of each historical visit, and the short-term dynamic disturbance intensity index of the terminal is calculated by normalized Euclidean distance. S2.54. For the current graph node, the comprehensive matching score is adjusted by weighting the short-term dynamic disturbance intensity index of its neighboring nodes, and the adjusted comprehensive matching score is generated.
[0008] As a further improvement to this technical solution, in S2.54, for the current graph node, the comprehensive matching score is weighted and adjusted by combining the terminal short-term dynamic disturbance intensity index of its neighboring nodes to generate an adjusted comprehensive matching score, including the following steps: Based on the comprehensive matching score generated in step S2.4, the set of neighboring nodes of the access terminal in the terminal behavior graph is determined; based on the terminal's short-term dynamic disturbance intensity index, the dynamic disturbance intensity of the set of neighboring nodes in the terminal behavior graph is aggregated and calculated to obtain the average intensity of neighborhood dynamic disturbance; based on the average intensity of neighborhood dynamic disturbance with neighborhood influence weights... The overall matching score of the currently accessing terminal is weighted and adjusted to generate an adjusted overall matching score.
[0009] As a further improvement to this technical solution, in step S3, multi-terminal access behavior data of the target financial account is obtained based on the judgment result, a multi-terminal behavior feature matrix is constructed, a historical stable behavior model is constructed based on a Gaussian mixture model, a behavior risk score is generated, and multi-terminal collaborative risk judgment is performed, including the following steps: S3.1. Based on the user's financial account access request, determine the user's target financial account; S3.2 Extract all access records of the target financial account within a preset time window, form a multi-terminal access set, and uniformly vectorize and encode all access records to form a behavioral feature vector; S3.3. Sort the behavioral feature vectors in chronological order to construct a multi-terminal behavioral feature matrix. ; S3.4. Based on the preset stability determination rules, analyze the multi-terminal behavior feature matrix. Perform sliding window statistical analysis to generate a stable behavior feature submatrix. ; S3.5, Stable Behavioral Feature Submatrix For each behavioral feature vector in the dataset, a chaotic system mapping transformation is performed to generate a chaotic domain behavioral fingerprint. And construct a chaotic domain behavior feature matrix. ; S3.6, Characteristic Matrix Based on Chaotic Domain Behavior Using the input, a Gaussian mixture model is constructed, and the expectation-maximization algorithm is used to estimate the parameters of the Gaussian mixture model to generate a historical stable behavior model; S3.7 Calculate the degree of behavioral deviation of the current financial account access request based on the historical stable behavior model, and map the degree of behavioral deviation to the risk scoring range to generate a behavioral risk score.
[0010] As a further improvement to this technical solution, in S3.5, the stable behavior feature sub-matrix is... For each behavioral feature vector in the dataset, a chaotic system mapping transformation is performed to generate a chaotic domain behavioral fingerprint. And construct a chaotic domain behavior feature matrix. This includes the following steps: S3.51, for the first submatrix of stable behavior features A set of behavioral feature vectors are used to calculate the initial state through statistical mapping, and the initial state is then input into a two-dimensional Hénon chaotic system. S3.52, Starting from the initial state. In the next iteration, a sequence of chaotic trajectory points is obtained. This sequence is then unfolded and concatenated in chronological order, and the two-dimensional coordinate components of each trajectory point are sequentially unfolded into one-dimensional vectors, forming a behavioral fingerprint of the chaotic domain. ; S3.53, construction length is circular memory pool ; S3.54, Fingerprint of current chaotic domain behavior Calculate its relationship with the circular memory pool The Euclidean distances of all historical fingerprints are used to obtain the nearest neighbor distance sequence, and the behavioral fingerprints of the chaotic domain are then analyzed based on the nearest neighbor distance sequence. Perform progressive distribution offset discrimination and weight adjustment processing based on the discrimination results; S3.55. Arrange the chaotic behavior fingerprints after weight adjustment in chronological order to generate a chaotic domain behavior feature matrix. .
[0011] As a further improvement to this technical solution, in step S4, a cross-terminal collaborative verification mechanism is executed based on the multi-terminal collaborative risk assessment result, and a final secure collaborative authentication assessment result is generated through authentication decision rules, including the following steps: Based on behavioral risk scores and terminal trust levels, the multi-terminal access behavior data of the target financial account is sorted to form a multi-terminal collaborative risk assessment matrix. Set behavioral risk thresholds The risk assessment matrix for multi-terminal collaboration based on terminal credibility triggering conditions. Perform cross-terminal collaborative verification, and calculate the collaborative risk score based on the cross-terminal collaborative verification results. And based on collaborative risk scoring Determine the risk level of terminal collaboration, summarize the collaboration risk levels of all terminals, and generate the final secure collaboration authentication judgment result according to the preset authentication decision rules.
[0012] On the other hand, the present invention provides a multi-terminal financial account security collaborative authentication system, including: an initial authentication module, used to receive a user's financial account access request, extract account identification information and login credential information, to perform basic identity verification, generate a corresponding access session identifier, and form an initial authentication dataset; The terminal credibility assessment and collaborative triggering module is used to extract the environmental feature vector of the access terminal from the initial authentication dataset, match it with the historical bound terminal feature library to generate a comprehensive matching score, construct a terminal behavior graph based on the current access terminal and its most recent access records, calculate the terminal's short-term dynamic disturbance intensity index and adjust the current terminal's score by combining the neighboring nodes to generate an adjusted comprehensive matching score; determine the terminal credibility level based on the adjusted comprehensive matching score, and determine whether to enter the collaborative analysis stage based on the terminal credibility level; The multi-terminal behavior risk analysis module is used to obtain multi-terminal access behavior data of the target financial account through the judgment results, construct a multi-terminal behavior feature matrix, and construct a historical stable behavior model based on Gaussian mixture model to calculate the degree of deviation between the current access request and the historical behavior pattern, generate a behavior risk score, and form a multi-terminal collaborative risk judgment result. The cross-terminal collaborative verification and authentication decision module is used to execute the cross-terminal collaborative verification mechanism based on the multi-terminal collaborative risk assessment results, and generate the final secure collaborative authentication decision result through authentication decision rules.
[0013] On the other hand, the present invention provides a multi-terminal financial account security collaborative authentication medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the method described in any of the above-mentioned embodiments.
[0014] Compared with the prior art, the above-mentioned technical solution of the present invention has the following beneficial technical effects: by constructing a terminal behavior map to calculate the short-term dynamic disturbance intensity index, and combining it with a Gaussian mixture model to model and analyze the historical stable behavior of multiple terminals, a leap from single-point terminal verification to multi-dimensional collaborative risk judgment is realized, effectively identifying abnormal access patterns and collaborative attack behaviors across terminals, thereby significantly improving the accuracy and reliability of secure access to financial accounts. Attached Figure Description
[0015] Figure 1 This is a flowchart of the overall method of the present invention. Detailed Implementation
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0017] Example 1: Please refer to Figure 1 As shown, this embodiment provides a multi-terminal financial account security collaborative authentication method, including the following steps: S1. Receive the user's financial account access request, extract the account identification information and login credential information for basic identity verification, generate the corresponding access session identifier, and form the initial authentication dataset. In this embodiment, the initial authentication dataset containing account identity features and terminal environment features is formed by the following steps: S1.1 Receive financial account access requests initiated by user terminals through the financial service access gateway (the request message must include at least: account identifier information, login credential information, and terminal basic message header information). Perform integrity verification on the financial account access request (including message structure validity verification, timestamp validity verification, and request source validity verification; if any of the above verifications fails, the authentication process is terminated directly). After the integrity verification passes, perform structured parsing of the financial account access request based on protocol parsing operations, and extract account identifier information and login credential information according to the interface field definition rules (specifically: after the integrity verification passes, the financial account access request is parsed). The request message execution protocol parsing operation deserializes the original message into a structured data object, and locates and reads the account identifier field and login credential field from the request message body according to the interface field definition rules. That is, it performs field location and semantic parsing of the request message according to the communication protocol specification and the business interface message field definition structure. The account identifier information is the unique account identifier parameter submitted by the user when initiating the access request, and the login credential information is the authentication credential parameter corresponding to the account identifier. Authentication is performed based on the account identifier information and login credential information (the extracted account identifier information and login credential information undergo format validity checks and encoding standardization processing to generate a standardized account). The system uses identifier variables and standardized login credential variables. Based on the standardized account identifier variables, it verifies the existence and legality of the account in the account database and compares the standardized login credential variables with the authentication credentials stored in the database to complete basic identity verification. When the account status is legal and the credential comparison result meets the preset consistency conditions, identity verification is considered successful. After successful identity verification, a unique access session identifier is generated based on the account identifier information (specifically: first, the parsed account identifier information (such as account ID, user number, or unified customer identifier) is standardized, including character encoding standardization, removal of redundant spaces, and format verification; then...). The system then obtains the current access context parameters, including a high-precision timestamp (milliseconds or nanoseconds), a terminal device fingerprint digest value, a network environment identifier (such as IP or ASN encoding), and a random number seed. It then constructs the original session generation string by combining the account identifier information and access context parameters in a preset concatenation order. The string is then subjected to an encrypted hash operation (e.g., using the SHA-256 algorithm) to obtain a fixed-length digest value. An optional system node identifier or sequence counter is added to the digest value to enhance uniqueness in a distributed environment. Finally, a unique access session identifier is generated and bound to the current access request, and the session creation time and source network information are recorded. S1.2 Collect environmental parameters of the current access terminal that initiated the financial account access request, including at least the terminal ID, access timestamp, operating system and browser version, IP address and network type, and geographic region code. Standardize and encode the environmental parameters to form a terminal environmental feature vector. Simultaneously, generate an account identity feature vector based on account identification information (retrieve historical data such as registration information, commonly used terminal sets, and commonly used geographic regions of the corresponding account from the account management database and account historical access record database, and perform structured encoding to generate an account identity feature vector (this account identity feature vector can be used for subsequent audit tracking or as an initial profile during the model cold start phase). In this system, the account management database stores core information such as user account registration information, account status, authentication credentials, and account identifiers, supporting account verification and basic identity management. The account history access record database records historical account access behavior, including access timestamps, terminal IDs, network environment information (such as IP / ASN), geographical location, and device fingerprints, for security auditing, behavior analysis, and risk assessment. These databases can be accessed within financial institutions through standard query interfaces. The access session identifier, account identity feature vector, and account identifier information are combined to construct an initial authentication dataset, which serves as the input basis for subsequent terminal trustworthiness assessment and multi-terminal collaborative risk analysis.
[0018] S2. Extract the access terminal environment feature vector based on the initial authentication dataset, and perform matching calculation with the historical bound terminal feature library to generate a comprehensive matching score. Construct a terminal behavior map based on the current access terminal and its most recent access records. Calculate the terminal's short-term dynamic disturbance intensity index and combine it with the neighboring nodes to adjust the current terminal's score to generate an adjusted comprehensive matching score. The terminal's credibility level is determined based on the adjusted comprehensive matching score, and whether to enter the collaborative analysis stage is determined based on the terminal's credibility level. In this embodiment, the terminal's short-term dynamic disturbance intensity index is calculated and combined with the weighted adjustment of the current terminal's score by neighboring nodes to generate an adjusted comprehensive matching score. Based on the adjusted comprehensive matching score, the terminal's credibility level is determined, and the decision on whether to enter the collaborative analysis stage is made based on the terminal's credibility level. This includes the following steps: S2.1 Obtain the terminal environment feature vector from the initial authentication dataset; S2.2. Based on the current access account identifier information, retrieve the historical bound terminal feature set of the access account from the preset account historical terminal feature database to form a sample set to be matched. Specifically, the process involves: First, using the account identifier information extracted from the current access request, a query is performed in a pre-defined historical terminal feature database to retrieve all historically bound terminal records for that account. Each record must contain at least a unique terminal identifier, a terminal environment feature vector (operating system version, browser type, network type, IP address, geographic region code, etc.), and the terminal's most recent access time. Then, the retrieved historical terminal records are formatted and standardized, including unifying feature vector dimensions, normalizing values, and cleaning up missing or abnormal data. Finally, all matching historical terminal feature vectors are sorted by time sequence or access frequency to form a sample set to be matched. This is used for subsequent matching calculations with the feature vector of the current access terminal environment; The account history terminal feature database is a structured data storage system used in the financial system to record and manage account-bound terminal information. Its typical structure includes: each record corresponds to an account and terminal binding instance, and at least includes a unique account identifier, a unique terminal identifier, a terminal environment feature vector (including operating system version, browser type, network type, IP address, geographic region code, etc.), a terminal's most recent access timestamp, a terminal registration time, and a device fingerprint code. It can also include auxiliary information such as terminal usage frequency, abnormal access markers, or risk levels. These records are stored in the form of tables or key-value indexes, supporting quick retrieval of all historically bound terminals by account identifier. The feature vectors can be uniformly formatted and normalized through standard database interfaces or APIs for use in terminal credibility assessment and multi-terminal collaborative risk analysis. S2.3, Matching terminal environment feature vectors with the sample set to be matched using cosine similarity. Perform matching calculations to determine the similarity index; specifically: first, compare the feature vector of the currently accessing terminal environment with the sample set to be matched. Each historical terminal feature vector is dimensionally aligned and normalized to ensure all feature components are on the same scale and within the same value range. Then, for each historical terminal feature vector, the cosine similarity with the environment feature vector is calculated to obtain the similarity index between the current terminal and each historical terminal. In the formula, This is the normalized and processed terminal environment feature vector. This is the historical terminal feature vector after normalization and processing. For historical terminal index; S2.4. Calculate the similarity index of all historical terminals and the comprehensive matching score. (In the formula, This represents the total number of historical terminals. For the first The weight of each historical terminal record indicates the terminal's contribution to the overall matching score. S2.5. Construct a terminal behavior graph based on the current access terminal and its most recent access records. Calculate the terminal's short-term dynamic disturbance intensity index and combine it with the weighted adjustment of the current access terminal's comprehensive matching score to generate the adjusted comprehensive matching score. In this embodiment, by constructing a terminal behavior graph and calculating the short-term dynamic disturbance intensity index of the terminal, the aim is to address the risk of misjudgment of credibility caused by drastic fluctuations in environmental parameters (such as IP address and geographical location) of a single terminal within a short time window. It also overcomes the shortcomings of traditional methods that rely solely on isolated terminal information and cannot perceive the potential risks transmitted from abnormal behavior of associated terminals (such as different access record nodes of the same device). This invention upgrades from "static point matching" to "dynamic graph association analysis." Existing technologies typically only perform a one-time similarity match between the current terminal and historically bound terminals, ignoring the fluctuation patterns of the terminal itself in recent behavior sequences and the influence of behavioral transmission between terminals. This step (step S2.5), by introducing a graph structure, not only quantifies the dynamic disturbance intensity of environmental parameters of a single terminal within a short time but also propagates this disturbance information through neighboring nodes in a weighted manner. This allows the comprehensive matching score to reflect the composite abnormal information from the terminal itself and its associated neighboring nodes, thereby significantly enhancing the ability and robustness to identify covert, progressive, or collaborative terminal attack behaviors. The process involves constructing a terminal behavior graph based on the current accessing terminal and its most recent access records. This is achieved by calculating the terminal's short-term dynamic disturbance intensity index and adjusting the overall matching score of the current accessing terminal using a weighted average of neighboring nodes. The steps include: S2.51, Collect the most recent data from the currently accessing terminal. Each access record contains at least the following: terminal ID, access timestamp, network environment information (IP / ASN), geographic location information, and device fingerprint code. S2.52. Construct each historical access record and the current access terminal into a graph node. The features of the graph nodes are the corresponding terminal environment feature vectors, based on the graph nodes. Constructing graph edges (If the time interval between visits to two graph nodes) Less than the preset threshold ( Nodes in the graph The corresponding access timestamp, Nodes in the graph (corresponding access timestamp), then establish graph edges. And construct a terminal behavior graph based on graph nodes and graph edges. This is used to capture short-term behavioral correlations of the terminal. S2.53. For the current graph node, extract the terminal environment feature vector of the corresponding access terminal at the current time step, and compare it with the nearest node to that access terminal. The difference degree is calculated by analyzing the terminal environment feature vectors from each historical visit, and the short-term dynamic disturbance intensity index of the terminal is calculated by normalized Euclidean distance. (In the formula, This represents the number of historical access records for the currently accessing terminal. The current access terminal after normalization The environmental feature vector of each historical visit. For a minimal constant (e.g.) ), used to prevent division by zero errors; the terminal's short-term dynamic disturbance intensity index Reflecting the degree of change in terminal behavior characteristics in the short term, high Indicating abnormal behavior or increased risk, the terminal's short-term dynamic disturbance intensity index is used to characterize the fluctuation range of environmental parameters of the currently accessing terminal within a short time window. It is only used as an adjustment factor in the terminal credibility scoring function and does not participate in account-level risk distribution modeling. S2.54. For the current graph node, the comprehensive matching score is adjusted by weighting the terminal short-term dynamic disturbance intensity index of its neighboring nodes, and the adjusted comprehensive matching score is generated. Furthermore, for the current graph node, the comprehensive matching score is weighted and adjusted by combining the terminal short-term dynamic disturbance intensity index of its neighboring nodes, generating an adjusted comprehensive matching score, including the following steps: Based on the comprehensive matching score generated in step S2.4, determine the set of neighboring nodes of the access terminal in the terminal behavior graph (based on the graph nodes corresponding to the current access terminal). Centered on the graph edges Connect, select and In the graph, nodes reachable by no more than c edges are designated as neighborhood nodes; then, the feature vectors of these neighborhood nodes are associated with the current graph nodes to form a neighborhood node set. Based on the terminal short-term dynamic disturbance intensity index For the set of neighboring nodes in the terminal behavior graph The dynamic disturbance intensity is aggregated and calculated to obtain the average intensity of the neighborhood dynamic disturbance. (Average intensity of neighborhood dynamic disturbance) This is used to characterize the overall fluctuation level of the local geographic environment in which the current terminal is located. In the formula... For a single node in the neighborhood node set, it represents a historical access record or node that is associated with the current access terminal in the short-term behavior graph. Neighboring nodes The corresponding short-term dynamic disturbance intensity index (first extract the neighboring nodes) The environmental feature vector corresponding to the terminal at the current access time step is then compared with the terminal's most recent... The environmental feature vectors of the corresponding nodes in each historical visit are used to calculate the dissimilarity (using normalized Euclidean distance), and the average of all dissimilarity values is calculated to quantify the neighborhood node. The fluctuation range of environmental parameters within a short time window is used to obtain the neighboring nodes. (corresponding short-term dynamic disturbance intensity index); based on the average intensity of neighborhood dynamic disturbances) Neighborhood influence weight The overall matching score of the currently accessing terminal is weighted and adjusted: Generate the adjusted overall matching score The adjusted score takes into account both the matching degree of a single terminal and the short-term abnormal behavior information of neighboring nodes, and is used for subsequent terminal credibility level determination and collaborative analysis triggering. S2.6. Based on the adjusted comprehensive matching score, construct the terminal credibility scoring function and generate the terminal credibility score. (In the formula, The mapping slope coefficient, The credibility center threshold, (where the natural constant is used) S2.7, Based on terminal trustworthiness score The trust level of a terminal is determined by a preset trust threshold. (if ,but ;if ,but ;if ,but In the formula, The upper limit threshold of credibility (in this embodiment, (0.8) The confidence threshold (in this embodiment, (0.3), and based on the terminal's trust level, determine whether to enter the collaborative analysis stage, that is, determine whether to enter step S3 (the process of determining whether to enter the collaborative analysis stage is divided into three rules: Rule 1: if or This directly triggers the multi-terminal collaborative analysis phase; Rule 2: Even When the terminal short-term dynamic disturbance intensity index Greater than the preset disturbance threshold (In this embodiment, When the value is 0.5, an abnormal dynamic fluctuation risk is determined, and the multi-terminal collaborative analysis phase is forcibly triggered; Rule 3: When ,in, The width of the credibility boundary buffer (ranging from 0.02 to 0.05, determined by expert experience) indicates that the terminal is within the credibility critical range. To avoid misjudgment due to scoring errors, a multi-terminal collaborative analysis phase is triggered. Furthermore, if the terminal's credibility level... If the terminal is deemed "highly trustworthy" and does not meet the triggering conditions of Rules 2 and 3, then the current access terminal is determined to have sufficiently high trustworthiness, and multi-terminal collaborative analysis is unnecessary. At this point, the final security collaborative authentication result is directly generated, which includes at least the following information: access session identifier, current terminal trustworthiness level, and authentication result of "passed". Simultaneously, this access record (including terminal environment characteristics, timestamp, session identifier, etc.) is written to the account's historical access record database for subsequent behavior analysis and model updates; the authentication process ends here.
[0019] S3. Based on the judgment results, obtain multi-terminal access behavior data of the target financial account, construct a multi-terminal behavior feature matrix, construct a historical stable behavior model based on Gaussian mixture model, generate a behavior risk score, and conduct multi-terminal collaborative risk judgment. In this embodiment, multi-terminal access behavior data of the target financial account is obtained based on the judgment result, a multi-terminal behavior feature matrix is constructed, a historical stable behavior model is constructed based on a Gaussian mixture model, a behavior risk score is generated, and multi-terminal collaborative risk judgment is performed, including the following steps: S3.1. Based on the user's financial account access request, determine the user's target financial account (locate the user's target financial account in the account management database based on the account identification information). S3.2, Extract funds from the target financial account within the preset time window. (In the formula, For time, This consists of all access records within a time window (each access record must include at least the terminal ID, access timestamp, IP address, and ASN information), forming a multi-terminal access set. (In the formula, Indicates the first Each access record is then uniformly vectorized and encoded to form a behavioral feature vector. (Specifically: set the preset time window) For each access record of the target financial account, key fields are uniformly extracted, including terminal ID, access timestamp, operating system and browser version, IP address and ASN, geolocation information, device fingerprint code, etc., and each type of field is standardized or normalized. For example, numerical features are standardized using Min-Max, and categorical features are converted into numerical vectors through one-hot encoding or embedding encoding. Subsequently, the encoded vectors of each field are concatenated in a fixed order to form the behavioral feature vector of a single access record. ); S3.3, Transfer the behavioral feature vector Sorting by time, constructing a multi-terminal behavior feature matrix. (In the formula, For the number of visits, The feature dimension of the behavior feature vector. (representing the real number field). S3.4. Based on the preset stability determination rules, analyze the multi-terminal behavior feature matrix. Sliding window statistical analysis is performed to filter continuous access subsequences whose statistical features satisfy stability constraints, remove data in statistical drift intervals, and generate a stable behavior feature submatrix. (In the formula, The number of visits to consecutive access subsequences to satisfy stability constraints); and the behavior feature matrix of multiple terminals according to preset stability determination rules. Performing sliding window statistical analysis to screen consecutive access subsequences whose statistical features satisfy stability constraints specifically involves: in the behavioral feature matrix... The above is arranged in chronological order by step size. The system slides a preset time window, extracting a subset of behavioral feature vectors within each window. Then, it calculates statistical features (such as mean, variance, skewness, or maximum / minimum range) for each feature dimension within the window, comparing these features with preset stability thresholds. If all statistical features within the window meet stability constraints (i.e., the fluctuation range of all feature dimensions within the window does not exceed their respective thresholds), the window is determined to be a stable subsequence. For windows that do not meet stability constraints or exhibit a significant drift trend, the corresponding access records are removed. Finally, all stable continuous subsequences are merged in chronological order to form a stable behavioral feature submatrix. ; S3.5, Stable Behavioral Feature Submatrix For each behavioral feature vector in the dataset, a chaotic system mapping transformation is performed to generate a chaotic domain behavioral fingerprint. And construct a chaotic domain behavior feature matrix. (In the formula, (Dimension of the behavioral fingerprint in the chaotic domain). In this embodiment, a chaotic system mapping transformation is applied to the stable behavior feature submatrix to generate a chaotic domain behavior fingerprint. This addresses the specific problem that high-dimensional, nonlinear, and time-dependent financial behavior data is difficult to effectively represent and extract deep stable patterns using traditional statistical models. This method aims to solve the problems that original behavior features (such as terminal ID, IP address, access timestamp, etc.) are often linearly inseparable in Euclidean space, suffer from significant noise interference, and are difficult to capture small but crucial anomalous disturbances. By introducing the initial sensitivity and pseudo-random characteristics of a chaotic system (such as a two-dimensional Hénon mapping), the original behavior vector is mapped to a high-dimensional chaotic domain. This preserves the dynamic correlation information of the original behavior while achieving nonlinear dimensionality expansion and enhanced sensitivity of the feature space, thereby improving the modeling ability and anomaly detection accuracy of subsequent Gaussian mixture models for complex stable behavior patterns. Existing technologies typically perform clustering or probability distribution modeling directly based on the original or standardized behavior vectors (such as directly using GMM), which is easily affected by data noise, linear correlation of features, and small fluctuations, making it difficult to distinguish between normal behavior fluctuations and potential risk disturbances. This invention, through chaotic system mapping, leverages the extreme sensitivity of chaotic systems to initial conditions to significantly amplify minute differences in behavioral characteristics along chaotic trajectories, thereby effectively enhancing the distinguishability of anomalous behaviors. Simultaneously, the ergodicity and pseudo-randomness of chaotic systems map the original behavioral data to a more expressive high-dimensional space, enabling subsequent GMM models to more precisely fit the stable manifold of behavioral distributions, significantly improving the sensitivity to the identification of concealed and progressive anomalous behaviors and the robustness of the model. Among them, the stable behavior feature submatrix For each behavioral feature vector in the dataset, a chaotic system mapping transformation is performed to generate a chaotic domain behavioral fingerprint. And construct a chaotic domain behavior feature matrix. This includes the following steps: S3.51, for the first submatrix of stable behavior features Given a set of behavioral feature vectors, the initial state is obtained through statistical mapping (specifically, for a stable behavioral feature submatrix). The first in For each behavioral feature vector, its features in each dimension are first normalized, mapping the original features to... Intervals are defined to eliminate dimensional differences; then, the statistical mapping of this behavior's eigenvectors is calculated, including the mean. and standard deviation The above statistics are then transformed into the allowable initial state interval of the chaotic system through a linear mapping function: , ,in, For scaling parameters, For the offset parameter; finally, the first... The initial state of the chaotic system corresponding to each behavioral feature vector The initial state is then input into a two-dimensional Hénon chaotic system (which consists of two state variables, representing the system's horizontal state). and vertical state This forms a two-dimensional state space. The system's iteration is controlled by two coupled equations. In each iteration, the horizontal state is influenced by the nonlinearity of its own squared term and the linear superposition of the vertical state. The vertical state is determined by a linear mapping of the horizontal state. The system controls the chaos intensity and mapping ratio through the initial state and iteration parameters, generating new two-dimensional state points in each iteration, forming a deterministic, aperiodic chaotic trajectory that is highly sensitive to initial conditions. This architecture can map input features to a two-dimensional chaotic domain, generating continuous chaotic trajectories (used to characterize dynamically changing features or behavioral fingerprints). S3.52, Starting from the initial state. The iteration (the iteration process is carried out in a two-dimensional Hénon chaotic system, and the iteration formula is:) In the formula, For the first The first-dimensional state variable in the next iteration. For the first The first-dimensional state variable in the next iteration. For the first The second-dimensional state variable at the next iteration Here are the one-dimensional nonlinear control parameters for the Hénon chaotic system. (where the linear coupling parameters are for the Hénon chaotic system), the sequence of chaotic trajectory points is obtained. The chaotic trajectory point sequence is unfolded and spliced in chronological order, and the two-dimensional coordinate components of each trajectory point in the chaotic trajectory point sequence are unfolded into one-dimensional vectors in turn, forming a chaotic domain behavioral fingerprint. ; S3.53, construction length is (For example ) circular memory pool Store recent chaotic domain behavior fingerprints and their corresponding original features, where, In order to be with the first Auxiliary features or time index identifiers associated with historical fingerprints, For the internal sample index of the memory pool; S3.54, Fingerprint of current chaotic domain behavior Calculate its relationship with the circular memory pool Euclidean distance of all historical fingerprints (In the formula, For the first (from the historical chaotic domain behavioral fingerprint), the nearest neighbor distance sequence is obtained. And based on the nearest neighbor distance sequence Fingerprint of behavior in chaotic domains Perform progressive distribution offset discrimination and weight adjustment processing based on the discrimination results; The process of performing asymptotic distribution offset discrimination and weight adjustment based on the discrimination results is as follows: When the chaotic domain behavior fingerprint... With circular memory pool Nearest neighbor distance sequence of historical fingerprints Trend coefficient Greater than the preset threshold (In this embodiment, When the value is 0.1 (obtained by analyzing the rate of change of nearest neighbor distance under normal behavior), the current sample is determined to be a sample with asymptotically shifted distribution (where, It is a sliding window. (This is an index variable used to iterate through samples in the sliding window); weighting coefficients are assigned to this asymptotically offset sample. ;in, The attenuation coefficient, tuned using the validation set, is used to adjust its contribution to the training of the stable behavior model; when the weight coefficient... Below the minimum threshold (In this embodiment, When the value is 0.05, the asymptotically shifted sample is temporarily stored in an isolation buffer and is not included in the current step of parameter estimation of the Gaussian mixture model using the Expectation-Maximization (EM) algorithm. Once subsequent continuous observations confirm that its trend has recovered to a stable level, it can be reintegrated into the historical sample set for updating the stable behavior model, depending on the actual situation. The trigger condition for detecting "trend recovery" can be determined by analyzing the nearest neighbor distance sequence. Continuous monitoring is implemented to achieve the following: when a sample in the isolation buffer is observed for M consecutive times, the trend coefficient of its distance sequence is recorded. The price has steadily fallen and remained below the preset threshold. And sample weight coefficients Restore to minimum threshold When the above is reached, it can be determined that the behavior pattern of the terminal has returned from the offset state to the historical stable envelope surface, thereby triggering the recovery mechanism to re-include it in the model training set; S3.55. Arrange the chaotic behavior fingerprints after weight adjustment in chronological order to generate a chaotic domain behavior feature matrix. ; S3.6, Characteristic Matrix Based on Chaotic Domain Behavior Using the input, construct a Gaussian mixture model: (In the formula, Input chaotic domain behavior fingerprint The probability density reflects the rationality of this behavior under a historical stable behavior model. This represents the number of components in the Gaussian mixture model. For the first The mixing weights of Gaussian components, For the first The mean vector of Gaussian components, For the first The covariance matrix of Gaussian components is used to describe the linear correlation and distribution shape among the feature dimensions. For the first The probability density function of each Gaussian distribution is used, and the parameter estimation of the Gaussian mixture model is performed using the expectation-maximization (EM) algorithm to generate a historical stable behavior model (specifically, the chaotic domain behavior fingerprint matrix is used). As input data, initialize the parameters of the Gaussian mixture model, including the mean vector of each component. Covariance matrix and mixed weights Then, the Expectation-Maximization (EM) algorithm is executed iteratively: in the E-step, the posterior probability (responsibility) of each sample belonging to each Gaussian component is calculated based on the current model parameters, reflecting the degree to which the sample belongs to each component; in the M-step, the mean vector of each component is re-estimated using these posterior probabilities. Covariance matrix and mixed weights To maximize the likelihood function of the sample under the model; repeat the E-step and M-step until the model parameters converge (the change is below the preset threshold b) or the maximum number of iterations is reached; finally, the converged Gaussian mixture model parameters are used as the historical stable behavior model (the historical stable behavior model is...). Among them, the historical stable behavior model uses the chaotic domain behavior fingerprint matrix. As input, the distribution characteristics of multi-terminal access behavior are modeled using a Gaussian Mixture Model (GMM), where the model includes... There are 1 Gaussian components, each composed of a mean vector. Covariance matrix and mixed weights The description reflects the central tendency and fluctuation characteristics of behavioral features under different patterns; the model parameters are iteratively estimated using the Expectation-Maximization (EM) algorithm, so that each visit behavior sample obtains an attribution probability under the model, which is used to quantify the degree of deviation of the behavior from the historical stable pattern, thereby forming a complete historical stable behavior probability distribution architecture, providing a statistical basis and interpretable probability output for behavioral risk scoring. S3.7 Calculate the degree of behavioral deviation of the current financial account access request based on the historical stable behavior model. (The chaotic domain behavior fingerprint of the current access request) Input historical stable behavior model Then, for each Gaussian component... ,calculate probability density value under this component and combined with mixed weights Calculate the overall probability density This reflects the rationality of current behavior within a historically stable pattern; then, the overall probability density is... Transformed into behavioral deviation indicators The degree of behavioral deviation is then mapped to a risk score range to generate a behavioral risk score. (In the formula, This is a risk sensitivity adjustment coefficient (a positive number, empirically ranging from 1 to 10), which controls the sensitivity of the degree of deviation to the final risk score. To deviate from the threshold, in Within the specified range, the normal / abnormal boundary points of historical data are set; and the behavioral risk score and terminal trust score corresponding to the current access request are associated with the current access record (including access session identifier, terminal ID, timestamp, environmental characteristics, etc.) and stored in the account historical access record database. During storage, it is ensured that each historical record includes the behavioral risk score and terminal trust score calculated at that time, so that it can be directly extracted and used in subsequent multi-terminal collaborative risk analysis.
[0020] S4. Based on the risk assessment results of multi-terminal collaboration, execute the cross-terminal collaborative verification mechanism, and generate the final security collaborative authentication assessment result through authentication decision rules; In this embodiment, a cross-terminal collaborative verification mechanism is executed based on the multi-terminal collaborative risk assessment result, and a final secure collaborative authentication assessment result is generated through authentication decision rules, including the following steps: Multi-terminal access behavior data of the target financial account is collected. Based on behavioral risk scoring, terminal credibility scoring, and terminal credibility level, the multi-terminal access behavior data of the target financial account is sorted by terminal ID and access timestamp (the multi-terminal access behavior data of the target financial account includes the core field information corresponding to each access initiated by the account from all terminals within a preset time window, including at least the terminal unique identifier, access timestamp, operating system and browser version, IP address, and ASN information; these data are uniformly vectorized and encoded to construct a multi-terminal behavioral feature matrix), forming a multi-terminal collaborative risk judgment matrix. (In the formula, (For feature dimensions); set behavioral risk thresholds. (In this embodiment, The risk assessment matrix for multi-terminal collaboration is based on the conditions for triggering terminal credibility (0.7). Perform cross-terminal collaborative verification (extract behavioral risk scores from each access record in the multi-terminal collaborative risk assessment matrix). Terminal credibility score ( For access record index), if it exists or ( This is the terminal trust threshold. (0.3), or the trust level of the terminal. If so, the terminal is marked as a suspicious terminal node; subsequently, in the access sequence sorted by time, those within the preset time window are counted. ( The number of suspicious terminals and their alternating access patterns within a time step are considered. If multiple different terminals alternately access the same account within this window and their risk status shows a clustering trend (e.g., risk score continuously increases or credibility continuously decreases), then cross-terminal collaborative risk behavior is determined to exist, triggering collaborative verification. Based on the cross-terminal collaborative verification results, a collaborative risk score is calculated. (Risk scoring) Terminal credibility score A unified scale mapping is performed to the same numerical range (e.g., normalization to [0,1]), and the normalized risk score is weighted and fused with the terminal credibility score to generate a collaborative risk score. ), and based on collaborative risk scoring Determine the risk level of terminal collaboration (if) If so, the risk level of terminal collaboration is high; if Then the risk level of terminal collaboration is medium risk; if If the terminal collaboration risk level is low, then the risk level is low. The upper limit threshold for risk is 0.8. The risk threshold is set at 0.3. The collaborative risk levels of all terminals are summarized, and the final security collaborative authentication judgment result is generated according to the preset authentication decision rules (the preset authentication decision rules are: if the collaborative risk level of all terminals is low risk, the final authentication judgment result is: pass; if there is a medium-risk terminal, additional verification (such as SMS verification code, dynamic password, multi-factor authentication) is triggered according to the preset security policy, and the judgment result is "additional verification pass / fail"; if there is a high-risk terminal, the access request is directly judged as "rejected" and the abnormal event is recorded). The final security collaborative authentication judgment result includes at least the access session identifier, the collaborative risk level of each terminal, and the authentication judgment result.
[0021] Example 2: This example provides a multi-terminal financial account security collaborative authentication system, including: The initial authentication module is used to receive users' financial account access requests, extract account identification information and login credential information, perform basic identity verification, generate corresponding access session identifiers, and form an initial authentication dataset. The terminal credibility assessment and collaborative triggering module is used to extract the environmental feature vector of the access terminal from the initial authentication dataset, match it with the historical bound terminal feature library to generate a comprehensive matching score, construct a terminal behavior graph based on the current access terminal and its most recent access records, calculate the terminal's short-term dynamic disturbance intensity index and adjust the current terminal's score by combining the neighboring nodes to generate an adjusted comprehensive matching score; determine the terminal credibility level based on the adjusted comprehensive matching score, and determine whether to enter the collaborative analysis stage based on the terminal credibility level; The multi-terminal behavior risk analysis module is used to obtain multi-terminal access behavior data of the target financial account through the judgment results, construct a multi-terminal behavior feature matrix, and construct a historical stable behavior model based on Gaussian mixture model to calculate the degree of deviation between the current access request and the historical behavior pattern, generate a behavior risk score, and form a multi-terminal collaborative risk judgment result. The cross-terminal collaborative verification and authentication decision module is used to execute the cross-terminal collaborative verification mechanism based on the multi-terminal collaborative risk assessment results, and generate the final secure collaborative authentication decision result through authentication decision rules.
[0022] This embodiment also provides a multi-terminal financial account security collaborative authentication medium, on which a computer program is stored, characterized in that: when the computer program is executed by a processor, it implements the steps of the method described in any of the above-mentioned embodiments.
[0023] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited thereto. Various changes can be made within the scope of knowledge possessed by those skilled in the art without departing from the spirit of the present invention.
Claims
1. A method for multi-terminal financial account security co- authentication, characterized in that, include: S1. Receive the user's financial account access request, extract the account identification information and login credential information for basic identity verification, generate the corresponding access session identifier, and form the initial authentication dataset. S2. Extract the access terminal environment feature vector based on the initial authentication dataset, and perform matching calculation with the historical bound terminal feature library to generate a comprehensive matching score. Construct a terminal behavior map based on the current access terminal and its most recent access records. Calculate the terminal's short-term dynamic disturbance intensity index and combine it with the neighboring nodes to adjust the current terminal's score to generate an adjusted comprehensive matching score. The terminal's credibility level is determined based on the adjusted comprehensive matching score, and whether to enter the collaborative analysis stage is determined based on the terminal's credibility level. S3. Based on the judgment results, obtain multi-terminal access behavior data of the target financial account, construct a multi-terminal behavior feature matrix, construct a historical stable behavior model based on Gaussian mixture model, generate a behavior risk score, and conduct multi-terminal collaborative risk judgment. S4. Based on the risk assessment results of multi-terminal collaboration, execute the cross-terminal collaborative verification mechanism, and generate the final security collaborative authentication assessment result through authentication decision rules.
2. The multi-terminal financial account security co- authentication method of claim 1, wherein, In step S1, the initial authentication dataset is formed, including the following steps: S1.1 Receive the financial account access request initiated by the user terminal, perform integrity verification on the financial account access request, and after the integrity verification is passed, perform structured parsing of the financial account access request based on the protocol parsing operation, and extract account identification information and login credential information according to the interface field definition rules, and perform identity verification based on the account identification information and login credential information; when the identity verification is passed, generate a unique access session identifier based on the account identification information. S1.2 Collect the environmental parameters of the current access terminal that initiated the financial account access request, standardize and encode the environmental parameters to form a terminal environment feature vector, and generate an account identity feature vector based on the account identification information. Combine the access session identifier, the account identity feature vector and the account identification information to construct the initial authentication dataset.
3. The multi-terminal financial account security co- authentication method of claim 1, wherein, In step S2, the terminal's short-term dynamic disturbance intensity index is calculated and the current terminal's score is adjusted by weighting the neighboring nodes to generate an adjusted comprehensive matching score. Based on the adjusted comprehensive matching score, the terminal's credibility level is determined, and the decision on whether to enter the collaborative analysis stage is made based on the terminal's credibility level. This includes the following steps: S2.1 Obtain the terminal environment feature vector from the initial authentication dataset; S2.
2. Based on the current access account identifier information, retrieve the historical bound terminal feature set of the access account from the preset account historical terminal feature database to form a sample set to be matched. ; S2.3, Matching terminal environment feature vectors with the sample set to be matched using cosine similarity. Perform matching calculations and calculate similarity metrics; S2.
4. Calculate the similarity index of all historical terminals and calculate the comprehensive matching score; S2.
5. Construct a terminal behavior graph based on the current access terminal and its most recent access records. Calculate the terminal's short-term dynamic disturbance intensity index and combine it with the weighted adjustment of the current access terminal's comprehensive matching score to generate the adjusted comprehensive matching score. S2.
6. Based on the adjusted comprehensive matching score, construct the terminal credibility scoring function and generate the terminal credibility score; S2.
7. Based on the terminal credibility score, determine the terminal credibility level by using a preset credibility threshold, and determine whether to enter the collaborative analysis stage based on the terminal credibility level.
4. The multi-terminal financial account security collaborative authentication method according to claim 3, characterized in that, In step S2.5, a terminal behavior graph is constructed based on the current accessing terminal and its most recent access records. The comprehensive matching score of the current accessing terminal is adjusted by calculating the terminal's short-term dynamic disturbance intensity index and combining it with weighted neighboring nodes. This includes the following steps: S2.51, Collect the most recent data from the currently accessing terminal. This is a record of previous visits; S2.
52. Construct each historical access record and the current access terminal as a graph node, construct graph edges based on the graph nodes, and construct a terminal behavior graph based on the graph nodes and graph edges. S2.
53. For the current graph node, extract the terminal environment feature vector of the corresponding access terminal at the current time step, and compare it with the nearest node to that access terminal. The difference degree is calculated by using the terminal environment feature vector of each historical visit, and the short-term dynamic disturbance intensity index of the terminal is calculated by normalized Euclidean distance. S2.
54. For the current graph node, the comprehensive matching score is adjusted by weighting the short-term dynamic disturbance intensity index of its neighboring nodes, and the adjusted comprehensive matching score is generated.
5. The multi-terminal financial account security collaborative authentication method according to claim 4, characterized in that, In step S2.54, for the current graph node, the comprehensive matching score is weighted and adjusted by combining the terminal short-term dynamic disturbance intensity index of its neighboring nodes to generate the adjusted comprehensive matching score, including the following steps: Based on the comprehensive matching score generated in step S2.4, the set of neighboring nodes of the access terminal in the terminal behavior graph is determined; based on the terminal's short-term dynamic disturbance intensity index, the dynamic disturbance intensity of the set of neighboring nodes in the terminal behavior graph is aggregated and calculated to obtain the average intensity of neighborhood dynamic disturbance; based on the average intensity of neighborhood dynamic disturbance with neighborhood influence weights... The overall matching score of the currently accessing terminal is weighted and adjusted to generate an adjusted overall matching score.
6. The multi-terminal financial account security collaborative authentication method according to claim 1, characterized in that, In step S3, based on the judgment result, multi-terminal access behavior data of the target financial account is obtained, a multi-terminal behavior feature matrix is constructed, and a historical stable behavior model is constructed based on a Gaussian mixture model to generate a behavior risk score. Multi-terminal collaborative risk assessment is then performed, including the following steps: S3.
1. Based on the user's financial account access request, determine the user's target financial account; S3.2 Extract all access records of the target financial account within a preset time window, form a multi-terminal access set, and uniformly vectorize and encode all access records to form a behavioral feature vector; S3.
3. Sort the behavioral feature vectors in chronological order to construct a multi-terminal behavioral feature matrix. ; S3.
4. Based on the preset stability determination rules, analyze the multi-terminal behavior feature matrix. Perform sliding window statistical analysis to generate a stable behavior feature submatrix. ; S3.5, Stable Behavioral Feature Submatrix For each behavioral feature vector in the dataset, a chaotic system mapping transformation is performed to generate a chaotic domain behavioral fingerprint. And construct a chaotic domain behavior feature matrix. ; S3.6, Characteristic Matrix Based on Chaotic Domain Behavior Using the input, a Gaussian mixture model is constructed, and the expectation-maximization algorithm is used to estimate the parameters of the Gaussian mixture model to generate a historical stable behavior model; S3.7 Calculate the degree of behavioral deviation of the current financial account access request based on the historical stable behavior model, and map the degree of behavioral deviation to the risk scoring range to generate a behavioral risk score.
7. The multi-terminal financial account security collaborative authentication method according to claim 6, characterized in that, In S3.5, the stable behavior feature sub-matrix For each behavioral feature vector in the dataset, a chaotic system mapping transformation is performed to generate a chaotic domain behavioral fingerprint. And construct a chaotic domain behavior feature matrix. This includes the following steps: S3.51, for the first submatrix of stable behavior features A set of behavioral feature vectors are used to calculate the initial state through statistical mapping, and the initial state is then input into a two-dimensional Hénon chaotic system. S3.52, Starting from the initial state. In the next iteration, a sequence of chaotic trajectory points is obtained. This sequence is then unfolded and concatenated in chronological order, and the two-dimensional coordinate components of each trajectory point are sequentially unfolded into one-dimensional vectors, forming a behavioral fingerprint of the chaotic domain. ; S3.53, construction length is circular memory pool ; S3.54, Fingerprint of current chaotic domain behavior Calculate its relationship with the circular memory pool The Euclidean distances of all historical fingerprints are used to obtain the nearest neighbor distance sequence, and the behavioral fingerprints of the chaotic domain are then analyzed based on the nearest neighbor distance sequence. Perform progressive distribution offset discrimination and weight adjustment processing based on the discrimination results; S3.
55. Arrange the chaotic behavior fingerprints after weight adjustment in chronological order to generate a chaotic domain behavior feature matrix. .
8. The multi-terminal financial account security collaborative authentication method according to claim 1, characterized in that, In step S4, a cross-terminal collaborative verification mechanism is executed based on the multi-terminal collaborative risk assessment result, and a final secure collaborative authentication assessment result is generated through authentication decision rules, including the following steps: Based on behavioral risk scores and terminal trust levels, the multi-terminal access behavior data of the target financial account is sorted to form a multi-terminal collaborative risk assessment matrix. Set behavioral risk thresholds The risk assessment matrix for multi-terminal collaboration based on terminal credibility triggering conditions. Perform cross-terminal collaborative verification, and calculate the collaborative risk score based on the cross-terminal collaborative verification results. And based on collaborative risk scoring Determine the risk level of terminal collaboration, summarize the collaboration risk levels of all terminals, and generate the final secure collaboration authentication judgment result according to the preset authentication decision rules.
9. A multi-terminal financial account security collaborative authentication system, characterized in that, include: The initial authentication module is used to receive users' financial account access requests, extract account identification information and login credential information, perform basic identity verification, generate corresponding access session identifiers, and form an initial authentication dataset. The terminal credibility assessment and collaborative triggering module is used to extract the access terminal environment feature vector through the initial authentication dataset, and perform matching calculation with the historical bound terminal feature library to generate a comprehensive matching score. Based on the current access terminal and its most recent access records, a terminal behavior map is constructed. The module calculates the terminal's short-term dynamic disturbance intensity index and combines it with the neighboring nodes to adjust the current terminal's score to generate an adjusted comprehensive matching score. The terminal's credibility level is determined based on the adjusted comprehensive matching score, and whether to enter the collaborative analysis stage is determined based on the terminal's credibility level. The multi-terminal behavior risk analysis module is used to obtain multi-terminal access behavior data of the target financial account through the judgment results, construct a multi-terminal behavior feature matrix, and construct a historical stable behavior model based on Gaussian mixture model to calculate the degree of deviation between the current access request and the historical behavior pattern, generate a behavior risk score, and form a multi-terminal collaborative risk judgment result. The cross-terminal collaborative verification and authentication decision module is used to execute the cross-terminal collaborative verification mechanism based on the multi-terminal collaborative risk assessment results, and generate the final secure collaborative authentication decision result through authentication decision rules.
10. A multi-terminal financial account security collaborative authentication medium, on which a computer program is stored, characterized in that: When the computer program is executed by the processor, it implements the steps of the multi-terminal financial account security collaborative authentication method according to any one of claims 1 to 8.