User login verification method, device, equipment, storage medium and product

By conducting pre-approval of target user information and risk assessment, and dynamically adjusting the verification process, the shortcomings of existing one-click login systems in terms of security and intelligent risk protection are resolved, achieving stricter account verification and higher security.

CN122437658APending Publication Date: 2026-07-21CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD
Filing Date
2025-01-20
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing one-click login systems are inadequate in terms of security and intelligent risk protection. They cannot flexibly respond to complex attack methods, rely on static rules leading to misjudgments and insufficient security, and are difficult to cope with rapidly changing threat environments.

Method used

By verifying the information of target users in advance to obtain their risk level, different verification methods are applied based on the risk level, including multi-dimensional analysis using risk assessment models, and the verification process is dynamically adjusted to enhance the security of account verification.

Benefits of technology

Stricter account verification was implemented, enhancing login security, effectively preventing potential unauthorized access, and improving the system's adaptability and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122437658A_ABST
    Figure CN122437658A_ABST
Patent Text Reader

Abstract

The application discloses a user login verification method and device, equipment, storage medium and product, and relates to the technical field of network security, and comprises the following steps: in response to a login request of a target user, performing pre-information verification on the target user to obtain a pre-information verification result; when the pre-information verification result is verification success, performing risk assessment on the target user according to login data of the target user to obtain a risk level; performing account verification on the target user based on the risk level to obtain a verification result; and when the verification result is account verification success, feeding back login success information to the target user; the method performs pre-information verification on the target user in response to a login request of the target user, and if the pre-verification is successful, performs risk assessment on the user according to login data, determines a risk level, and performs different mode security verification based on the risk level, so that the account security is comprehensively ensured, the login security is enhanced, and potential illegal access is effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to user login authentication methods, devices, equipment, storage media, and products. Background Technology

[0002] With the development of information technology, one-click login systems are widely used in various online services due to their convenience. However, existing one-click login systems have several problems and shortcomings in terms of security and intelligent risk protection, which limits their effective application in high-security application scenarios.

[0003] While existing one-click login systems significantly simplify the user login process and improve user convenience, they suffer from numerous problems and shortcomings in terms of security and intelligent risk protection. Firstly, these systems primarily rely on static rules (such as SIM-token, mobile phone number verification, and device identification) for security checks. This fixed-rule-based security mechanism lacks flexibility, struggles to adapt to increasingly complex attack methods, and cannot detect potential risks in real time. As cyberattack techniques continue to evolve, static rules are increasingly revealing their limitations, particularly inadequate against new threats.

[0004] Furthermore, for login verification of new devices, existing systems typically rely solely on whether the device is a previously logged-in device for a simple judgment, lacking a more detailed trust assessment of the device. This approach is prone to misjudgments, impacting not only user experience but also potentially introducing additional security risks. For example, if a user's device is lost or stolen, simple device matching might allow unauthorized users to log in successfully. Finally, existing risk control systems depend on fixed, predefined risk models. This lag in response makes the system ill-equipped to handle rapidly changing threat environments, further weakening its security and reliability. Summary of the Invention

[0005] The main purpose of this application is to provide a user login verification method, device, equipment, storage medium and product, which aims to solve the technical problem that the current user login application verification is limited to static information verification, the verification method is single and cannot accurately judge the user login risk.

[0006] To achieve the above objectives, this application proposes a user login verification method, which includes:

[0007] In response to the login request of the target user, the target user is subjected to pre-verification information, and the pre-verification information result is obtained;

[0008] When the verification result of the prior information is successful, a risk assessment is performed on the target user based on the target user's login data to obtain the risk level;

[0009] Based on the risk level, the target user's account is verified to obtain the verification result;

[0010] When the verification result indicates that the account verification was successful, a login success message is sent to the target user.

[0011] In one embodiment, the prior information verification result includes successful verification;

[0012] In response to a login request from a target user, the pre-verification of the target user is performed to obtain a pre-verification result, including:

[0013] In response to a login request from a target user, obtain the target user's terminal account;

[0014] Query the registration status of the target user based on the terminal account;

[0015] When the registration status is "registered", the successful verification will be used as the result of the preliminary information verification.

[0016] If the registration status is "unregistered", check the login real-name verification requirements;

[0017] When the login real-name condition is that real-name authentication is not required, the successful verification will be used as the result of the preliminary information verification.

[0018] In one embodiment, when the pre-verification result is successful, the step of performing a risk assessment on the target user based on the target user's login data to obtain a risk level includes:

[0019] When the verification result of the prior information is successful, the login data of the target user is obtained. The login data includes user device information, geographical location, login behavior, network environment and operation behavior.

[0020] The user equipment information, geographical location, login behavior, network environment, and operation behavior are preprocessed to obtain data to be evaluated.

[0021] The risk assessment model is used to assess the risk of the target user based on the data to be assessed, and the risk level is obtained.

[0022] In one embodiment, the step of performing a risk assessment on the target user based on the data to be assessed using a risk assessment model to obtain a risk level includes:

[0023] The risk assessment model performs a basic assessment of login location, a deviation assessment, and a device credibility assessment based on the data to be assessed, resulting in a geographic location score, a deviation score, and a credibility score.

[0024] A multi-dimensional risk score is obtained based on preset dimension weights, the geographical location score, the deviation score, and the credibility score;

[0025] The risk level is obtained based on the multi-dimensional risk score and the preset risk level classification function.

[0026] In one embodiment, the step of performing a basic assessment of login location, a deviation assessment, and a device credibility assessment based on the data to be assessed using a risk assessment model to obtain a geographic location score, a deviation score, and a credibility score includes:

[0027] Based on the risk assessment model, the current login location is obtained from the data to be assessed. A basic login location assessment is performed based on the current login location and historical login locations to obtain a geolocation score.

[0028] Based on the risk assessment model, the deviation of each feature in the data to be assessed is obtained according to the preset deviation formula and preset feature weights, and a deviation score is obtained based on the deviation.

[0029] Based on the risk assessment model, device fingerprint matching, device usage habit matching, and device credibility matching are performed on the data to be assessed to obtain device matching score, device habit score, and device credibility score. A credibility score is obtained based on the device matching score, the device habit score, and the device credibility score.

[0030] In one embodiment, the step of verifying the target user's account based on the risk level to obtain a verification result includes:

[0031] When the risk level is the first risk level, successful verification will be taken as the verification result;

[0032] When the risk level is the second risk level, incremental verification is performed on the target user to obtain an incremental verification result, and the incremental verification result is used as the verification result. The incremental verification includes at least one of the following: graphic verification code verification, SMS verification, and facial recognition verification.

[0033] When the risk level is the third risk level, the verification failure is taken as the verification result. The first risk level is lower than the second risk level, and the second risk level is lower than the third risk level.

[0034] Furthermore, to achieve the above objectives, this application also proposes a user login verification device, which includes:

[0035] The pre-verification module is used to respond to the login request of the target user, perform pre-verification of the target user's information, and obtain the pre-verification result;

[0036] The risk level assessment module is used to assess the risk of the target user based on the target user's login data when the pre-verification result is successful, and to obtain the risk level.

[0037] The login verification module is used to verify the target user's account based on the risk level and obtain the verification result.

[0038] The login verification module is also used to send login success information to the target user when the verification result is successful account verification.

[0039] In addition, to achieve the above objectives, this application also proposes a user login verification device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the user login verification method as described above.

[0040] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the user login verification method described above.

[0041] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the user login verification method described above.

[0042] One or more technical solutions proposed in this application have at least the following technical effects:

[0043] By responding to the login request of the target user, the system performs pre-verification of the user's information to ensure the basic legitimacy of the user's identity. If the pre-verification is successful, a risk assessment is then conducted based on the user's login data to determine the risk level. Based on the risk level, different verification methods are used for security verification to achieve stricter account verification, thereby comprehensively ensuring account security, enhancing login security, and effectively preventing potential unauthorized access. Attached Figure Description

[0044] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0045] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0046] Figure 1 This is a flowchart illustrating the user login verification method in Embodiment 1 of this application.

[0047] Figure 2 This is a schematic diagram of the login process based on the user login verification system provided in Embodiment 1 of the user login verification method of this application;

[0048] Figure 3 This is a flowchart illustrating the second embodiment of the user login verification method in this application.

[0049] Figure 4 This is a schematic diagram of the module structure of the user login verification device in an embodiment of this application;

[0050] Figure 5 This is a schematic diagram of the device structure of the hardware operating environment involved in the user login verification method in this application embodiment.

[0051] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0052] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0053] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0054] The main solution of this application embodiment is as follows: in response to the login request of the target user, perform pre-verification of the target user and obtain the pre-verification result; when the pre-verification result is successful, perform risk assessment on the target user based on the login data of the target user and obtain the risk level; perform account verification on the target user based on the risk level and obtain the verification result; when the verification result is successful, send login success information to the target user.

[0055] With the development of information technology, one-click login systems are widely used in various online services due to their convenience. However, existing one-click login systems have several problems and shortcomings in terms of security and intelligent risk protection, which limits their effective application in high-security scenarios.

[0056] While existing one-click login systems significantly simplify the user login process and improve user convenience, they suffer from numerous problems and shortcomings in terms of security and intelligent risk protection. Firstly, these systems primarily rely on static rules (such as SIM-token, mobile phone number verification, and device identification) for security checks. This fixed-rule-based security mechanism lacks flexibility, struggles to adapt to increasingly complex attack methods, and cannot detect potential risks in real time. As cyberattack techniques continue to evolve, static rules are increasingly revealing their limitations, particularly inadequate against new threats.

[0057] Furthermore, for login verification of new devices, existing systems typically rely solely on whether the device is a previously logged-in device for a simple judgment, lacking a more detailed trust assessment of the device. This approach is prone to misjudgments, impacting not only user experience but also potentially introducing additional security risks. For example, if a user's device is lost or stolen, simple device matching might allow unauthorized users to log in successfully. Finally, existing risk control systems depend on fixed, predefined risk models. This lag in response makes the system ill-equipped to handle rapidly changing threat environments, further weakening its security and reliability.

[0058] This application provides a solution, disclosing a user login verification method, apparatus, device, storage medium, and product, relating to the field of network security technology. The method includes: responding to a login request from a target user, performing pre-verification of the target user's information to obtain a pre-verification result; if the pre-verification result is successful, performing a risk assessment on the target user based on their login data to obtain a risk level; performing account verification on the target user based on the risk level to obtain a verification result; and if the verification result is successful account verification, sending login success information back to the target user. This method, by responding to a target user's login request, performing pre-verification of the target user's information, and if the pre-verification is successful, then performing a risk assessment based on the user's login data to determine a risk level, and performing different security verification methods based on the risk level, comprehensively ensures account security, enhances login security, and effectively prevents potential unauthorized access.

[0059] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device or user login verification device capable of performing the above functions. The following description uses a user login verification device as an example to illustrate this embodiment and the subsequent embodiments.

[0060] Based on this, the embodiments of this application provide a user login verification method, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the user login verification method of this application.

[0061] In this embodiment, the user login verification method includes steps S10 to S40:

[0062] Step S10: In response to the login request of the target user, perform pre-verification of the target user and obtain the pre-verification result.

[0063] Understandably, the target user could be a user who is currently logging in.

[0064] Understandably, the results of prior information verification can include both successful and unsuccessful verification.

[0065] It should be understood that pre-verification of information can be based on static rules, which can include SIM-token verification, mobile phone number verification, and static rule matching verification.

[0066] It should be noted that the login request can be initiated when the target user clicks "One-click Login" in the APP.

[0067] In one feasible implementation, step S10 may include steps A11 to A15:

[0068] Step A11: In response to the login request of the target user, obtain the target user's terminal account.

[0069] Understandably, responding to a target user's login request can involve taking action to obtain the target user's terminal account when the login request is detected in real time.

[0070] It should be understood that the terminal account can be a user's mobile phone number or QQ number, or other accounts that represent the user's identity.

[0071] It should be noted that the target user's terminal account can be obtained through the SIM-token of the unified authentication platform. Simply put, the token associated with the user's mobile phone SIM card can be used to verify the user's identity and obtain the user's terminal account information on a specific service or platform based on this.

[0072] It should be noted that obtaining the target user's terminal account may be successful or unsuccessful. If the target user's terminal account is successfully obtained, the registration status of the target user will be queried based on the terminal account. If the target user's terminal account is not obtained, the user will be notified of the login failure, and the user will be informed that the login failure was caused by the failure to obtain the mobile phone number.

[0073] In practice, a SIM-token is a unique identifier that identifies a user's SIM card information. The system obtains the user's SIM-token and compares it with historical SIM-tokens in the database to ensure that the user's phone number matches the device's SIM card information. The verification process is as follows: the SIM-token is extracted from the user's request and compared with the SIM-token in the user center. If the SIM-token matches successfully, subsequent verification continues; if the SIM-token does not match, exception handling is triggered.

[0074] Step A12: Query the registration status of the target user based on the terminal account.

[0075] It should be understood that registration status can include both unregistered and registered.

[0076] It should be understood that the user center of applications that require users to log in stores all users' mobile phone numbers and registration information.

[0077] It should be noted that a search query can be used to find registration information that matches a user's phone number from a database containing that information. Based on this registration information, the user's registration status can be determined.

[0078] It should be noted that mobile phone number verification verifies the user by checking the registration status of the mobile phone number and the associated device information. The verification process is as follows:

[0079] Check the registration status of the user's mobile phone number from the user center. If the mobile phone number is not registered and real-name registration is not required, execute the automatic registration process; if the mobile phone number is not registered but real-name registration is required, return an exception.

[0080] In practice, the database in the user center contains mobile phone numbers and registration information corresponding to each user. Registration information may include age, address, occupation, etc., and there may also be users who only have mobile phone numbers but no registration information. The target user's mobile phone number is matched with the mobile phone numbers of each user in the database by a search query. If a matching mobile phone number is found, it is checked whether there is corresponding registration information. If there is, the user has already registered; if there is no registration information, the target user has not registered.

[0081] Step A13: When the registration status is "registered", the successful verification is taken as the result of the preliminary information verification.

[0082] It should be noted that when the registration status is "registered", it can be understood that the user has completed real-name authentication, and the user's security is relatively high. At this time, the pre-verification can be ended and the successful verification can be regarded as the pre-verification result.

[0083] Step A14: When the registration status is "unregistered", query the login real-name conditions.

[0084] Understandably, login real-name conditions include those that require real-name registration and those that do not; different apps have different login requirements, and may or may not require real-name registration.

[0085] It should be noted that if a user has not registered, it can be understood that the user has not completed real-name authentication, and further verification of prior information is required based on the login real-name conditions of the target user's current application.

[0086] Step A15: When the login real-name condition is that real-name verification is not required, the successful verification is taken as the result of the preliminary information verification.

[0087] It should be noted that when the login real-name condition is not required, then users are not required to use their real names or register. In this case, successful verification can be used as the result of the preliminary information verification.

[0088] It should be further explained that when the login real-name verification condition is required, the login failure will be reported to the target user and the reason for the login failure will be reported to the target user.

[0089] In this implementation, by using SIM-token verification, mobile phone number verification, and static rule matching, the consistency of the user's identity is quickly confirmed, ensuring that subsequent risk assessments are based on trusted basic information. This prevents attackers from easily bypassing simple identity verification methods, establishes the first line of defense for user risk analysis, effectively excludes known malicious users and abnormal devices, reduces the system burden, allows most low-risk users to pass through in the initial stage, while high-risk users will be further analyzed, thereby improving the overall efficiency and security of the system.

[0090] The above are only two feasible implementations of step S10 provided in this embodiment. This embodiment does not specifically limit the specific implementation of step S10.

[0091] Step S20: When the verification result of the prior information is successful, a risk assessment is performed on the target user based on the target user's login data to obtain the risk level.

[0092] It should be noted that the login data of the target user may include user device data, geolocation data, login behavior data, network environment data, and user operation behavior.

[0093] It should be noted that risk assessment can be conducted through a risk assessment model, and the risk level can include a first risk level, a second risk level, and a third risk level, which can be understood as a low risk level, a medium risk level, and a high risk level, respectively.

[0094] It should be noted that the risk assessment model uses user login data to conduct multi-dimensional risk analysis on target users from the perspectives of behavioral deviation and device trustworthiness, and obtains multi-dimensional risk scores. The risk level is obtained based on the risk scores and the preset risk level score range.

[0095] Step S30: Verify the target user's account based on the risk level and obtain the verification result.

[0096] Understandably, the core purpose of risk level determination is to determine the security risk level of a user's current login operation based on the results of multi-dimensional risk analysis, and then take corresponding countermeasures.

[0097] It should be noted that different risk levels require different account verification methods. Users with high risk levels will be denied login, users with medium risk levels will undergo further verification, and whether or not login is allowed will be determined based on the results of the further verification, while users with low risk levels can log in directly without further verification.

[0098] Understandably, verification results can include both verification failure and verification success.

[0099] It should be noted that account verification can be done through various methods, such as facial recognition verification, SMS verification code verification, device binding verification, and verification-free verification.

[0100] Understandably, the core purpose of risk level determination is to determine the security risk level of a user's current login activity based on the results of multi-dimensional risk analysis, and then take corresponding countermeasures.

[0101] In one feasible implementation, step S30 may include steps A31 to A33:

[0102] Step A31: When the risk level is the first risk level, the verification success is taken as the verification result.

[0103] Understandably, the first risk level can be a low risk level.

[0104] It should be noted that a low-risk level means that the user's login environment, behavioral deviation, and device trustworthiness are all normal, allowing the user to be automatically granted access and the login process to proceed without obstacles.

[0105] Step A32: When the risk level is the second risk level, perform incremental verification on the target user to obtain the incremental verification result, and use the incremental verification result as the verification result. The incremental verification includes at least one of the following: image verification code verification, SMS verification, and face recognition verification.

[0106] Understandably, the second risk level can be a medium risk level.

[0107] It should be noted that the medium risk level is as follows: the current login behavior is somewhat abnormal, such as the login device having a slightly lower credibility or the behavior deviating significantly. In this case, the user's identity can be further confirmed by adding verification steps (such as image verification code, SMS verification code, etc.).

[0108] It should be noted that incremental verification can be any one or more of the following: image verification code verification, SMS verification, and facial recognition verification.

[0109] Understandably, incremental verification results can include verification failure and verification success. If incremental verification is successful, the verification result is verification success; if incremental verification fails, the verification result is verification failure.

[0110] In practice, verification measures can be dynamically adjusted by combining historical behavior patterns and current risk assessment scores. For example, dual verification of facial recognition and SMS verification codes can be enabled for users who frequently perform high-risk operations, while only a single verification measure can be enabled for users with low-frequency operations. This flexible verification process greatly improves the system's adaptability and security.

[0111] Step A33: When the risk level is the third risk level, the verification failure is taken as the verification result. The first risk level is lower than the second risk level, and the second risk level is lower than the third risk level.

[0112] Understandably, the third risk level can be a high risk level, where the first risk level is lower than the second risk level, and the second risk level is lower than the third risk level.

[0113] It should be noted that when the risk level of the target user is high, the login of the target user will be directly blocked and refused. If the system determines that the risk score reaches the high risk threshold, the login operation will be blocked immediately and the user account will be prompted that it is abnormal and further measures such as password reset will be recommended.

[0114] In this implementation, the user verification process is dynamically adjusted based on the risk assessment results of a deep learning model. Users with higher risk undergo additional identity verification, while low-risk users can log in quickly, thereby improving verification efficiency while ensuring application security.

[0115] The above are only two feasible implementation methods of step S30 provided in this embodiment. This embodiment does not specifically limit the specific implementation method of step S30.

[0116] Step S40: When the verification result is that the account verification is successful, a login success message is sent to the target user.

[0117] Understandably, when the verification result is that the account verification is successful, the target user can successfully log in to the current application APP, and the user is notified of the successful login at the same time.

[0118] It should be noted that after successful login, other business information of the target user can be queried and the login history of the target user can be recorded.

[0119] It should be noted that the user login verification method can be applied to a user login verification system, which may include a data collection module, a model training module, a risk assessment module, and a dynamic verification module.

[0120] Furthermore, the data collection module is responsible for collecting user login data, including SIM-token, device fingerprint, geolocation, timestamp, login frequency, etc. This data is used for subsequent deep learning model training and real-time risk assessment. The model training module uses historical login data to train the deep learning model, extracting user behavior patterns, device characteristics, and risk points. Through continuous learning, the system can identify abnormal login behavior. During login, the risk assessment module uses the deep learning model to assess the risk of the current login behavior and dynamically adjusts the verification strategy, such as adding multi-factor authentication for high-risk users. The dynamic verification module dynamically adjusts the user verification process based on the risk assessment results. Low-risk users can log in directly; for high-risk users, additional verification steps are added, such as SMS verification codes and facial recognition.

[0121] In practical implementation, the login process based on the user login verification system can be referenced. Figure 2 , Figure 2 It includes APP port, MCA port, unified authentication platform port, user center port and risk control system port. This implementation is combined and applied to MCA and risk control system.

[0122] This embodiment provides a user login verification method. By responding to the login request of a target user, it performs pre-verification of the target user's information to ensure the basic legitimacy of the user's identity. If the pre-verification is successful, it then performs a risk assessment based on the user's login data to determine the risk level. Based on the risk level, it performs security verification using different verification methods to achieve stricter account verification, thereby comprehensively ensuring account security, enhancing login security, and effectively preventing potential unauthorized access.

[0123] Based on the first embodiment of this application, in the second embodiment of this application, the content that is the same as or similar to that in the first embodiment described above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 3 Step S20 also includes steps S21 to S23:

[0124] Step S21: When the verification result of the prior information is successful, obtain the login data of the target user. The login data includes user device information, geographical location, login behavior, network environment and operation behavior.

[0125] It should be noted that user device data includes, but is not limited to, device model, operating system version, CPU information, memory size, screen resolution, camera model, device serial number, MAC address, and browser type. This information helps the system generate a device fingerprint to identify whether the user is using a new or untrusted device.

[0126] It should be noted that the geolocation data includes the user's precise location information and records the location coordinates at the time of login, the altitude of the login location, etc., which helps to identify whether the user logs in from a normal location or initiates a login request from an abnormal location.

[0127] It should be noted that login behavior data can include the user's login timestamp, tracking the time period, frequency, and historical time pattern of the user's login. Login at abnormal times (such as a user who usually logs in during the day but suddenly logs in at midnight) may indicate potential risks.

[0128] It should be noted that network environment data may include the user's IP address, detecting the geographical region and network type from which it originates (home network, office network, VPN, etc.). Abnormal IP addresses or instances of bypassing geographical restrictions via VPN will be flagged as potential risks. The network provider is determined using SIM-token or network operator data to ensure the user's network environment is normal. If the user's preferred network operator suddenly changes, the system will trigger a risk assessment.

[0129] It should be noted that user behavior includes actions taken while using the application, such as the speed of character input, the path and speed of swipe gestures, etc., to extract unique user habits. If these behaviors change, it may be because the device has been stolen or used by someone else.

[0130] Step S22: Preprocess the user equipment information, geographical location, login behavior, network environment, and operation behavior to obtain data to be evaluated.

[0131] It should be noted that the core of deep learning models lies in the continuous learning and analysis of user behavior data, and data collection is the foundation of the entire system. After data collection is completed, the raw data undergoes preprocessing before being fed into the model for training and analysis. To ensure the effectiveness and accuracy of the model, the system of this invention collects data from multiple dimensions to support more comprehensive risk assessment and device verification.

[0132] It should be noted that preprocessing can be combined with specific enhancement techniques (such as noise cancellation and data smoothing) to process the user equipment information, geographical location, login behavior, network environment, and operation behavior, which can effectively improve data quality and enhance the model's accuracy in risk identification.

[0133] It is understood that the data to be evaluated can be multi-dimensional feature data after preprocessing the user device information, the geographical location, the login behavior, the network environment, and the operation behavior.

[0134] It should be noted that after obtaining the data to be evaluated, the risk assessment model can be trained based on the data to be evaluated and the risk level to obtain the training parameters of the risk assessment model; the risk assessment model can be optimized based on the training parameters to obtain the optimized risk assessment model; and the risk assessment model can be updated based on the optimized risk assessment model.

[0135] Step S23: Perform a risk assessment on the target user based on the data to be assessed using a risk assessment model to obtain a risk level.

[0136] It should be noted that before using the risk assessment model, it is advisable to first build, train, and optimize the model. This involves collecting historical login data and risk indicators for each user, and preprocessing the collected historical login data using the same method as the target user's login data. After data collection and preprocessing are complete, the system will generate training and testing sets. The model will then be trained using the user's historical login data to simulate normal user behavior patterns and, combined with labeled risk behavior data, construct multi-dimensional risk judgment criteria.

[0137] It should be further explained that, in order to improve user security, the risk assessment model of this invention is based on deep learning algorithms, especially Transformer, to process users' time-series behavioral data, and is trained on a large-scale dataset to enable it to accurately judge users' normal and abnormal behaviors.

[0138] Furthermore, a Transformer-based deep neural network is used. This model excels at handling long sequence inputs and can extract complex temporal dependencies. The model includes multiple self-attention layers and feedforward neural networks to capture long-term trends and short-term changes in user behavior.

[0139] Furthermore, a cross-entropy loss function based on a classification problem is used. The model will classify each login (normal login or abnormal login) and optimize the model parameters by minimizing the loss function for classification errors.

[0140] Furthermore, the Adam optimizer is used to optimize the model parameters, which can efficiently update gradients in multi-dimensional data, accelerate the convergence speed of the model, and improve the accuracy of prediction.

[0141] In practice, model training employs batch processing, typically using millions of historical login records. During training, the model learns normal user behavior patterns, including device usage frequency, login location, and operating habits. When user behavior deviates from these normal patterns, the model automatically increases the risk score for that login. The trained model is then evaluated using a test set, with key metrics including accuracy, recall, and F1 score, used to measure the model's ability to detect abnormal login behavior. By continuously adjusting the model's structure and hyperparameters, its ability to accurately identify login risks is ensured, reducing false positives and false negatives.

[0142] In one feasible implementation, step S23 may include steps A231 to A233:

[0143] Step A231: Based on the data to be evaluated, the risk assessment model performs a basic assessment of the login location, a deviation assessment, and a device credibility assessment to obtain a geographic location score, a deviation score, and a credibility score.

[0144] It should be noted that the current login location is obtained based on the data to be evaluated using the risk assessment model. A basic login location assessment is then performed based on the current login location and historical login locations to obtain a geolocation score.

[0145] It should be understood that basic rule matching algorithms are used to perform preliminary verification of user login behavior, such as blacklist verification and IP geolocation verification.

[0146] It should be noted that the basic login location assessment can check whether the user's IP address, device ID, and phone number are on a blacklist. If they are on the blacklist, login is blocked directly. The login location is determined by analyzing the country / region to which the user's IP address belongs. The following formula can be used as a reference for details:

[0147]

[0148] Wherein, N can be a predefined value, which can be set according to requirements, and can be 4, 5, 6, 7, etc. This embodiment does not limit this.

[0149] It is understandable that the location is obtained from the previous N login locations. If the current login location is the same as the previous N login locations, the location score is zero; if the current login location is different from any of the previous N login locations, the location score is 1.

[0150] It should be noted that, based on the risk assessment model, the deviation of each feature in the data to be assessed is obtained according to the preset deviation formula and preset feature weights, and the deviation score is obtained based on the deviation.

[0151] It should be noted that behavioral deviation analysis is used to determine the difference between a user's current login behavior and their historical behavior; the greater the deviation, the higher the risk. Behavioral deviation is comprehensively evaluated by comparing the user's login time, geographical location, device information, and operating habits. Its main purpose is to detect potential abnormal behavior in a timely manner by comparing the user's current login behavior with historical behavioral patterns. This analysis can identify operations that significantly differ from normal user behavior, thereby assessing login risk. For example, a large behavioral deviation may indicate account theft or user device spoofing. By comparing multi-dimensional behavioral characteristics such as user login time, operating habits, and geographical location, this analysis greatly improves the system's real-time perception capabilities, enabling it to take timely preventative measures when minor anomalies in user behavior occur, effectively preventing spoofing or hijacking attacks.

[0152] It should be noted that the deviation of each feature in the data to be evaluated can be calculated using a multi-dimensional vector distance algorithm based on Euclidean distance. Each user login behavior feature is abstracted into a multi-dimensional vector, where each dimension of the vector represents a behavior feature. The specific calculation of the behavior deviation can refer to the following preset deviation formula:

[0153]

[0154] Wherein, D(X) C X h ) indicates the current login behavior X C With historical behavior X h Deviation; X c,i and X h,i ω represents the i-th feature (such as geographical location, login time, etc.) of the current login behavior and historical behavior, respectively. i This represents the preset feature weight for the i-th feature. Different features have different weights (e.g., the weight of geographical location may be higher than that of login time).

[0155] It should be noted that the preset weights of each feature can be set according to requirements. This embodiment does not limit this. In this embodiment, the preset weights of geographical location are 0.4, login time is 0.2, device information is 0.3, and operating habits are 0.1.

[0156] It should be noted that the deviation score obtained based on the deviation can be interpreted as follows: a higher deviation score indicates a greater difference between the current login behavior and historical behavior, and thus a higher risk. Specifically, a deviation threshold can be set, such that if D(X) = ...C X h If D(X) > the threshold, then the current login is considered to have abnormal behavior; if D(X) > the threshold, then the current login is considered to have abnormal behavior. C X h If the value is less than or equal to the threshold, then the current login is considered to have no abnormal behavior.

[0157] It should be noted that, based on the risk assessment model, device fingerprint matching, device usage habit matching, and device credibility matching are performed on the data to be assessed to obtain device matching score, device habit score, and device credibility score. The credibility score is obtained based on the device matching score, the device habit score, and the device credibility score.

[0158] It should be noted that the device trustworthiness scoring determines the trustworthiness of a device by analyzing its fingerprint (such as device model, operating system, and serial number) and user habits. The device trustworthiness scoring uses a weighted scoring model that integrates multiple device characteristics. Its main purpose is to determine device trustworthiness by analyzing the matching degree between the device's hardware characteristics and historical device data. This scoring system not only analyzes device fingerprints (such as operating system version and MAC address) but also considers user habits (such as touch frequency and swipe gestures), ensuring that even if the device hardware information remains unchanged, abnormal user behavior can trigger an alert. This scoring system effectively prevents attacks that copy device information or tamper with device fingerprints, thereby significantly improving the system's security detection capabilities for new device logins.

[0159] Device fingerprint matching can be performed by matching device fingerprint information (such as device serial number, operating system version, MAC address, etc.) with historical login records to calculate a device matching score. The specific formula is as follows:

[0160]

[0161] Among them, S device X represents the device matching score. c,i and X h,i Let m represent the i-th feature of the current device and the historical device, respectively. i I represents the weight of the i-th feature, and I(·) is an indicator function, which is 1 if the device features match and 0 if they do not match.

[0162] In addition to hardware characteristics, it is also necessary to analyze users' device usage habits, such as touch pressure, screen brightness, and network connectivity. Based on these usage habits, a device habit score is obtained. The formula for calculating the device habit score can be found in the following formula:

[0163]

[0164] Among them, Dhabits The device habit score is represented by Hc,i and Hh,i, which represent the current and historical operating habit characteristics, respectively.

[0165] It should be noted that the device trustworthiness score can be a weighted result of device fingerprint matching and operating habit matching. The specific calculation can be referenced from the following formula:

[0166] S total =α·S device +β·(1-D habits )

[0167] Where α and β represent the weights of device fingerprint and operating habits, respectively, and can be preset. This embodiment uses α = 0.6 and β = 0.4 as an example. total This indicates the overall trustworthiness score of the device; the higher the score, the more trustworthy the device.

[0168] Step A232: Obtain a multi-dimensional risk score based on preset dimension weights, the geographical location score, the deviation score, and the credibility score.

[0169] It should be noted that the preset dimension weights can be based on actual business needs. Different scenarios can optimize the accuracy of the risk assessment model by adjusting the weights. Weight adjustment employs an automated adaptive learning algorithm, dynamically adjusting the weights of different dimensions based on real-time login data. By analyzing changes in user behavior patterns, the weights of behavioral deviation, device trustworthiness, and basic verification results can be automatically adjusted, enabling the risk assessment model to optimize in real time and adapt to the ever-changing security environment.

[0170] It should be noted that this embodiment uses the basic verification weight ω b : 0.2; Behavioral deviation weight ω p : 0.4; Equipment reliability weight ω d Let's take 0.4 as an example for explanation.

[0171] It should be noted that multi-dimensional risk analysis integrates and analyzes information such as behavioral deviation, device trustworthiness score, and basic verification results to generate a comprehensive risk score. Its main purpose is to provide a comprehensive risk assessment by integrating information from multiple aspects, including user behavior, device trustworthiness, and basic verification results. It can not only identify abnormal behavior in a single dimension but also improve detection accuracy through multi-dimensional cross-analysis, especially in complex login scenarios, avoiding incorrect judgments caused by single points of failure.

[0172] In practical implementation, the calculation of multi-dimensional risk scores can refer to the following formula:

[0173] S risk =ω b ·Sbase +ω p ·S behavior +ω d ·S device

[0174] Among them, S risk S represents a multi-dimensional risk score. base S represents the geographical location score. behavior S represents the deviation score. device This indicates the credibility score.

[0175] Among them, S base The geolocation score represents the basic verification result. If the verification passes, the score is 0; if the verification fails, the score is set to 0.8-1. The score can be set according to the actual situation.

[0176] Step A233: Obtain the risk level based on the multi-dimensional risk score and the preset risk level classification function.

[0177] It should be noted that the preset risk level classification function can refer to the following expression:

[0178]

[0179] Understandably, the risk level can be obtained by comparing the multi-dimensional risk score with the two thresholds of 0.3 and 0.7. The two thresholds of 0.3 and 0.7 can be set according to the actual situation.

[0180] Understandably, the first risk level - low risk: if the final score is low (e.g., less than 0.3), it means that the user's login behavior and device performance are normal, and the user can continue to log in.

[0181] Second risk level - medium risk: If the score is in the middle range (e.g., 0.3 to 0.7), the system can further prompt the user to perform additional verification (e.g., SMS verification, email verification, etc.).

[0182] Third risk level - high risk: If the risk score is high (e.g., greater than 0.7), the system will consider the current login behavior abnormal, directly reject the login request, and may trigger account protection measures.

[0183] In this embodiment, the security and accuracy of the system are enhanced by comprehensively analyzing multi-dimensional data such as user behavior, device information, and network environment. By combining device fingerprints and usage habits, intelligent trustworthiness assessment of new devices is achieved, which can more intelligently determine the legitimacy of login behavior and reduce the false judgment rate.

[0184] The above are only two feasible implementation methods of step S23 provided in this embodiment. This embodiment does not specifically limit the specific implementation method of step S23.

[0185] This embodiment provides a user login verification method. By collecting various data, including user device information, geographical location, login behavior patterns, network environment parameters, and operation behavior records, the accuracy of risk assessment is improved based on multi-dimensional data. A pre-trained risk assessment model is used to perform in-depth analysis on the preprocessed dataset to be assessed, accurately assessing the user's risk level and determining whether further verification is needed for subsequent user logins. This enhances the security of user authentication, accurately identifies and efficiently responds to potential threats, significantly improves the overall security and reliability of the system, optimizes the user experience, and ensures that high-risk situations are handled promptly and effectively.

[0186] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the user login verification method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.

[0187] This application also provides a user login verification device, please refer to... Figure 4 The user login verification device includes:

[0188] The pre-verification module 10 is used to respond to the login request of the target user, perform pre-verification of the target user, and obtain the pre-verification result.

[0189] Risk level assessment module 20 is used to assess the risk of the target user based on the target user's login data when the pre-verification result is successful, and obtain the risk level.

[0190] The login verification module 30 is used to verify the account of the target user based on the risk level and obtain the verification result.

[0191] The login verification module 30 is also used to send login success information to the target user when the verification result is successful account verification.

[0192] The user login verification device provided in this application, employing the user login verification method described in the above embodiments, can solve the technical problem that current user login verification methods are limited to static information verification, have a single verification method, and cannot accurately determine user login risks. Compared with the prior art, the beneficial effects of the user login verification device provided in this application are the same as those of the user login verification method provided in the above embodiments, and other technical features in the user login verification device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0193] In one embodiment, the pre-verification module 10 is further configured to obtain the target user's terminal account in response to the target user's login request;

[0194] Query the registration status of the target user based on the terminal account;

[0195] When the registration status is "registered", the successful verification will be used as the result of the preliminary information verification.

[0196] If the registration status is "unregistered", check the login real-name verification requirements;

[0197] When the login real-name condition is that real-name authentication is not required, the successful verification will be used as the result of the preliminary information verification.

[0198] In one embodiment, the risk level assessment module 20 is further configured to obtain the login data of the target user when the pre-verification result is successful. The login data includes user device information, geographical location, login behavior, network environment, and operation behavior.

[0199] The user equipment information, geographical location, login behavior, network environment, and operation behavior are preprocessed to obtain data to be evaluated.

[0200] The risk assessment model is used to assess the risk of the target user based on the data to be assessed, and the risk level is obtained.

[0201] In one embodiment, the risk level assessment module 20 is further configured to perform a basic assessment of login location, a deviation assessment, and a device credibility assessment based on the data to be assessed using a risk assessment model, thereby obtaining a geographic location score, a deviation score, and a credibility score.

[0202] A multi-dimensional risk score is obtained based on preset dimension weights, the geographical location score, the deviation score, and the credibility score;

[0203] The risk level is obtained based on the multi-dimensional risk score and the preset risk level classification function.

[0204] In one embodiment, the risk level assessment module 20 is further configured to obtain the current login location based on the data to be assessed according to the risk assessment model, and to perform a basic assessment of the login location based on the current login location and historical login locations to obtain a geographical location score;

[0205] Based on the risk assessment model, the deviation of each feature in the data to be assessed is obtained according to the preset deviation formula and preset feature weights, and a deviation score is obtained based on the deviation.

[0206] Based on the risk assessment model, device fingerprint matching, device usage habit matching, and device credibility matching are performed on the data to be assessed to obtain device matching score, device habit score, and device credibility score. A credibility score is obtained based on the device matching score, the device habit score, and the device credibility score.

[0207] In one embodiment, the login verification module 30 is further configured to take successful verification as the verification result when the risk level is the first risk level;

[0208] When the risk level is the second risk level, incremental verification is performed on the target user to obtain an incremental verification result, and the incremental verification result is used as the verification result. The incremental verification includes at least one of the following: graphic verification code verification, SMS verification, and facial recognition verification.

[0209] When the risk level is the third risk level, the verification failure is taken as the verification result. The first risk level is lower than the second risk level, and the second risk level is lower than the third risk level.

[0210] This application provides a user login verification device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the user login verification method in Embodiment 1 above.

[0211] The following is for reference. Figure 5 The diagram illustrates a structural schematic suitable for implementing a user login verification device according to embodiments of this application. The user login verification device in embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The user login verification device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0212] like Figure 5As shown, the user login authentication device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the user login authentication device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. The communication device 1009 allows the user login authentication device to communicate wirelessly or wiredly with other devices to exchange data. Although user login authentication devices with various systems are shown in the figure, it should be understood that implementing or having all of the systems shown is not required. More or fewer systems may be implemented alternatively.

[0213] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0214] The user login verification device provided in this application, employing the user login verification method described in the above embodiments, can solve the technical problem that current user login verification methods are limited to static information verification, have a single verification method, and cannot accurately determine user login risks. Compared with the prior art, the beneficial effects of the user login verification device provided in this application are the same as those of the user login verification method provided in the above embodiments, and other technical features of this user login verification device are the same as those disclosed in the previous embodiment method, and will not be repeated here.

[0215] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0216] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0217] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the user login verification method in the above embodiments.

[0218] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0219] The aforementioned computer-readable storage medium may be included in the user login authentication device; or it may exist independently and not assembled into the user login authentication device.

[0220] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by the user login verification device, the user login verification device performs the following actions in response to a login request from a target user: performs pre-verification of the target user's information and obtains a pre-verification result; if the pre-verification result is successful, performs a risk assessment on the target user based on the target user's login data and obtains a risk level; performs account verification on the target user based on the risk level and obtains a verification result; and if the verification result is successful account verification, sends login success information back to the target user.

[0221] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0222] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0223] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0224] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described user login verification method. This solves the technical problem that current user login applications only verify static information, resulting in a single verification method and an inability to accurately assess user login risks. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the user login verification method provided in the above embodiments, and will not be repeated here.

[0225] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the user login verification method described above.

[0226] The computer program product provided in this application can solve the technical problem that current user login application verification is limited to static information verification, has a single verification method, and cannot accurately determine user login risks. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the user login verification method provided in the above embodiments, and will not be repeated here.

[0227] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.

Claims

1. A user login verification method, characterized in that, The user login verification method includes: In response to the login request of the target user, the target user is subjected to pre-verification information, and the pre-verification information result is obtained; When the verification result of the prior information is successful, a risk assessment is performed on the target user based on the target user's login data to obtain the risk level; Based on the risk level, the target user's account is verified to obtain the verification result; When the verification result indicates that the account verification was successful, a login success message is sent to the target user.

2. The method as described in claim 1, characterized in that, The verification result of the prior information includes successful verification; In response to a login request from a target user, the pre-verification of the target user is performed to obtain a pre-verification result, including: In response to a login request from a target user, obtain the target user's terminal account; Query the registration status of the target user based on the terminal account; When the registration status is "registered", the successful verification will be used as the result of the preliminary information verification. If the registration status is "unregistered", check the login real-name verification requirements; When the login real-name condition is that real-name authentication is not required, the successful verification will be used as the result of the preliminary information verification.

3. The method as described in claim 1, characterized in that, When the pre-verification result is successful, a risk assessment is performed on the target user based on the target user's login data to obtain a risk level, including: When the verification result of the prior information is successful, the login data of the target user is obtained. The login data includes user device information, geographical location, login behavior, network environment and operation behavior. The user equipment information, geographical location, login behavior, network environment, and operation behavior are preprocessed to obtain data to be evaluated. The risk assessment model is used to assess the risk of the target user based on the data to be assessed, and the risk level is obtained.

4. The method as described in claim 3, characterized in that, The step of conducting a risk assessment of the target user based on the data to be assessed using a risk assessment model to obtain a risk level includes: The risk assessment model performs a basic assessment of login location, a deviation assessment, and a device credibility assessment based on the data to be assessed, resulting in a geographic location score, a deviation score, and a credibility score. A multi-dimensional risk score is obtained based on preset dimension weights, the geographical location score, the deviation score, and the credibility score; The risk level is obtained based on the multi-dimensional risk score and the preset risk level classification function.

5. The method as described in claim 4, characterized in that, The risk assessment model performs a basic assessment of login location, a deviation assessment, and a device credibility assessment based on the data to be assessed, resulting in a geographic location score, a deviation score, and a credibility score, including: Based on the risk assessment model, the current login location is obtained from the data to be assessed. A basic login location assessment is performed based on the current login location and historical login locations to obtain a geolocation score. Based on the risk assessment model, the deviation of each feature in the data to be assessed is obtained according to the preset deviation formula and preset feature weights, and a deviation score is obtained based on the deviation. Based on the risk assessment model, device fingerprint matching, device usage habit matching, and device credibility matching are performed on the data to be assessed to obtain device matching score, device habit score, and device credibility score. A credibility score is obtained based on the device matching score, the device habit score, and the device credibility score.

6. The method as described in claim 1, characterized in that, The process of verifying the target user's account based on the risk level and obtaining the verification result includes: When the risk level is the first risk level, successful verification will be taken as the verification result; When the risk level is the second risk level, incremental verification is performed on the target user to obtain an incremental verification result, and the incremental verification result is used as the verification result. The incremental verification includes at least one of the following: graphic verification code verification, SMS verification, and facial recognition verification. When the risk level is the third risk level, the verification failure is taken as the verification result. The first risk level is lower than the second risk level, and the second risk level is lower than the third risk level.

7. A user login verification device, characterized in that, The user login verification device includes: The pre-verification module is used to respond to the login request of the target user, perform pre-verification of the target user's information, and obtain the pre-verification result; The risk level assessment module is used to assess the risk of the target user based on the target user's login data when the pre-verification result is successful, and to obtain the risk level. The login verification module is used to verify the target user's account based on the risk level and obtain the verification result. The login verification module is also used to send login success information to the target user when the verification result is successful account verification.

8. A user login verification device, characterized in that, The user login verification device includes: a memory, a processor, and a user login verification program stored in the memory and executable on the processor, the user login verification program being configured to implement the user login verification method as described in any one of claims 1 to 6.

9. A storage medium, characterized in that, The storage medium stores a user login verification program, which, when executed by a processor, implements the user login verification method as described in any one of claims 1 to 6.

10. A computer program product, characterized in that, The computer program product includes a user login verification program, which, when executed by a processor, implements the steps of the user login verification method as described in any one of claims 1 to 6.