An artificial intelligence-based authentication decision analysis system
Patent Information
- Application Number
- CN202610918105.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-24
- Publication Date
- 2026-09-29
AI Technical Summary
现有技术缺乏这种基于指标类型的差异化评分机制
[0018]本发明的机理如下:摒弃传统机器学习对大规模标注数据的依赖,利用线性映射和分段线性评分保证计算透明性与可追溯性,并通过规则驱动的动态权重适应实时风险变化(连续失败、短时重试、高风险环境等),同时引入安全复核强制转向二次验证,在低延迟、高可控性场景下平衡了安全性与用户体验,避免了黑箱模型难以调试和解释的缺陷;
Smart Images

Figure CN122845191A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of authentication decision-making, and more particularly to an authentication decision analysis system based on artificial intelligence. Background Technology
[0002] With the increasing demand for information system security, identity authentication, as the first line of defense in access control, directly impacts the balance between system security and user experience. Current mainstream authentication decision-making technologies can be broadly categorized into two types: intelligent authentication decision-making based on machine learning models, and traditional authentication decision-making based on fixed rules or simple thresholds.
[0003] In practical applications, authentication systems typically need to consider multiple dimensions of indicators for evaluation, such as password verification results, fingerprint matching scores, abnormal behavior scores, and device reputation scores. These indicators come from different sources, have different dimensions, and vary in value range. The core issue in the authentication field is how to unify them onto a comparable scale and make reasonable authentication decisions accordingly.
[0004] Most existing authentication systems employ a binary decision-making logic: either pass or reject. When faced with authentication requests in a gray area, they lack the ability to handle intermediate states, resulting in a blanket rejection or uncritical approval, which can lead to unintended negative impacts on legitimate users or create security vulnerabilities. The lack of intermediate decision-making levels, such as two-factor authentication, prevents the implementation of refined risk classification and handling.
[0005] Existing solutions often apply a uniform normalization and scoring method to all indicators, ignoring the impact of indicator type on scoring sensitivity. Binary indicators should not have tolerance ranges (either full score or zero score), while continuous indicators require tolerance widths to avoid drastic changes in scores due to small fluctuations. Current technologies lack this type of differentiated scoring mechanism based on indicator type.
[0006] Therefore, we propose an AI-based authentication decision analysis system to address the aforementioned issues. Summary of the Invention
[0007] This invention provides an artificial intelligence-based authentication decision analysis system for obtaining authentication decisions.
[0008] The first aspect of this invention provides an AI-based authentication decision analysis system, comprising: an indicator mapping module for acquiring multiple original authentication indicators of a current authentication request, mapping each original authentication indicator to obtain a normalized indicator value; a scoring calculation module for pre-setting multiple decision levels, configuring an expected range and a tolerance width for each normalized indicator value for each decision level, calculating a score value for each normalized indicator value relative to each decision level based on the expected range and the tolerance width, and obtaining a scoring vector corresponding to each decision level; a weight adjustment module for acquiring context information of the current authentication request, running preset rules, and adjusting the baseline weights according to the context information to obtain a dynamic weight set; a weighted summation module for weighted summation of the dynamic weight set and the scoring vector corresponding to each decision level to obtain a comprehensive score value for each decision level; and a decision output module for comparing the comprehensive score value of each decision level with a corresponding preset decision threshold and outputting an authentication decision.
[0009] Optionally, in a first implementation of the first aspect of the present invention, the original authentication indicators include discrete indicators and continuous indicators; the mapping process for each of the original authentication indicators to obtain a normalized indicator value includes: mapping the discrete indicators and the continuous indicators to dimensionless continuous real numbers as normalized indicator values.
[0010] Optionally, in a second implementation of the first aspect of the present invention, the pre-setting of multiple decision levels includes setting a pass level, a secondary verification level, and a rejection level; the step of calculating a score for each normalized index value relative to each decision level based on the expected interval and the tolerance width includes: if the normalized index value is within the expected interval, the score value is a first preset value; if the normalized index value is outside the expected interval and does not exceed the tolerance width, the score value changes linearly between the first preset value and a second preset value; if the normalized index value exceeds the tolerance width, the score value is a second preset value.
[0011] Optionally, in a third implementation of the first aspect of the present invention, when the original authentication index corresponding to the normalized index value is a discrete index, the configured tolerance width is zero; when the original authentication index corresponding to the normalized index value is a continuous index, the configured tolerance width is a preset positive value.
[0012] Optionally, in a fourth implementation of the first aspect of the present invention, the context information includes at least one of consecutive failure count, time interval, external risk level, and device identifier; the step of running a preset rule to adjust the baseline weights according to the context information to obtain a dynamic weight set includes: obtaining a weight adjustment amount based on the context information hitting the corresponding preset rule; adding the weight adjustment amount to the corresponding baseline weight to obtain the original weight; extracting the maximum value between the original weight and zero as a non-negative weight; and normalizing all the non-negative weights to obtain a dynamic weight set.
[0013] Optionally, in a fifth implementation of the first aspect of the present invention, the step of weighted summing of the dynamic weight set and the scoring vector corresponding to each decision level to obtain a comprehensive score value for each decision level includes: dividing the weight values in the dynamic weight set into multiple groups according to the type of the corresponding original certification indicator; calculating the intra-group weight sum of the weight values in each group; obtaining an intra-group weighted score value based on the intra-group weight sum and the score value corresponding to the group; and summing the intra-group weighted score values of all groups to obtain a comprehensive score value corresponding to the decision level.
[0014] Optionally, in the sixth implementation of the first aspect of the present invention, the formula for calculating the comprehensive score is: ; in, The overall score representing decision level k; Represents the total number of groups; This represents the score value corresponding to the j-th group at decision level k; This represents the number of dynamic weight values within the j-th group; This represents the i-th dynamic weight value within the j-th group. Let be the sum of the weights within the j-th group.
[0015] Optionally, in a seventh implementation of the first aspect of the present invention, comparing the comprehensive score value of each decision level with the corresponding preset decision threshold and outputting an authentication decision includes: if the comprehensive score value corresponding to the pass level is greater than the first decision threshold, then outputting pass as an authentication decision; if the comprehensive score value corresponding to the pass level is not greater than the first decision threshold, and the comprehensive score value corresponding to the rejection level is greater than the second decision threshold, then outputting rejection as an authentication decision; if the comprehensive score value corresponding to the pass level is not greater than the first decision threshold, and the comprehensive score value corresponding to the rejection level is not greater than the second decision threshold, then outputting secondary verification as an authentication decision.
[0016] Optionally, in an eighth implementation of the first aspect of the present invention, a security review module is further included: comparing the comprehensive score value corresponding to the pass level with a first security review threshold, and comparing the comprehensive score value corresponding to the rejection level with a second security review threshold; if the comprehensive score value corresponding to the pass level is less than the first security review threshold, and the comprehensive score value corresponding to the rejection level is less than the second security review threshold, then the authentication decision is forcibly modified to secondary verification.
[0017] Optionally, in a ninth implementation of the first aspect of the present invention, the first security review threshold and the second security review threshold are dynamically adjusted according to the context information; when at least one of the following occurs, such as an increase in the number of consecutive failures, a shortening of the time interval, or an increase in the external risk level, the first security review threshold is increased and the second security review threshold is decreased.
[0018] The mechanism of this invention is as follows: It abandons the dependence of traditional machine learning on large-scale labeled data, uses linear mapping and piecewise linear scoring to ensure computational transparency and traceability, and adapts to real-time risk changes (continuous failures, short-term retries, high-risk environments, etc.) through rule-driven dynamic weights. At the same time, it introduces security review to force a secondary verification, balancing security and user experience in low-latency and high-controllability scenarios, and avoiding the defects of black box models that are difficult to debug and interpret. Beneficial effects: It can provide precise reasons when certification is rejected, meet the audit and explainability requirements in security compliance scenarios, and completely eliminate the cold start and drift problems of the model; By introducing secondary verification as an intermediate decision level, the authentication result is expanded from binary to three levels. This allows the system to downgrade some requests that meet the standards but pose certain risks instead of rejecting them directly, effectively reducing the probability of legitimate users being mistakenly penalized, while maintaining a firm security baseline. By using four contextual dimensions—number of consecutive failures, time interval, external risk level, and device age—the system drives real-time weight adjustments based on preset rules. After three consecutive failures, the system automatically reduces the password weight and increases the weight for abnormal behavior, enabling authentication decisions to perceive the risk context of the current request rather than treating all requests the same. For each indicator at each decision level, an expected range and a tolerance width are configured: the score is 1 within the range and linearly transitions to 0 outside the range, making the scoring function continuous and smooth; especially for binary discrete indicators, the tolerance width is set to zero to ensure that the score is either 0 or 1, avoiding unreasonable intermediate scores and achieving accurate modeling of the differences between different indicator types. When both the pass and rejection scores are below their respective security review thresholds, the decision is forced to be revised to secondary verification. These thresholds can also be dynamically adjusted according to the context. The higher the risk, the higher the pass threshold and the lower the rejection threshold, providing additional security fallback for high-risk scenarios. For indicators with different dimensions and data types, such as password verification, fingerprint matching, abnormal behavior, and device reputation, a unified normalized mapping rule and a differentiated scoring configuration method were designed to form a reusable general framework. Since it is composed entirely of expert rules, the system can be deployed without waiting for data accumulation and model training, enabling rapid cold start deployment. It is particularly suitable for new business scenarios and industry environments with strict security requirements. Attached Figure Description
[0019] Figure 1 This is a schematic diagram of an embodiment of the authentication decision analysis system based on artificial intelligence in this invention. Figure 2 This is a schematic diagram of another embodiment of the authentication decision analysis system based on artificial intelligence in this invention. Figure 3 This is a schematic diagram of one embodiment of the authentication decision analysis device based on artificial intelligence in this invention. Detailed Implementation
[0020] This invention provides an artificial intelligence-based authentication decision analysis system for obtaining authentication decisions. The terms first, second, third, fourth, etc. (if present) in the specification, claims, and accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms include or have, and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0021] For ease of understanding, the specific process of the embodiments of the present invention is described below. Please refer to [link / reference]. Figure 1 One embodiment of the authentication decision analysis system based on artificial intelligence in this invention includes: 101. The indicator mapping module is used to obtain multiple original authentication indicators for the current authentication request. Each original authentication indicator has its own dimension. Linear mapping is performed on each original authentication indicator to obtain a normalized indicator value. The numerical range of all normalized indicator values is a continuous real number between 0 and 1 and is dimensionless.
[0022] It is understood that the executing entity of this invention can be an AI-based authentication decision analysis device, a terminal, or a server; no specific limitation is made here. This embodiment of the invention will be described using a server as an example.
[0023] It should be noted that this explanation uses a smartphone application login authentication request as an example. From the current request message and the terminal operating environment, three raw authentication metrics with different dimensions are extracted: The first item is the geographic location offset distance, which represents the straight-line distance between the current network IP resolution location and the account's frequently used login location. The current raw value collected in this request is 500km.
[0024] The second item is the password input time, which represents the time interval between the user pressing the first digit of the password and triggering the login command. The current raw value collected in this request is 2400ms.
[0025] The third item is the device attitude space difference, which represents the absolute spatial difference between the current three-dimensional spatial angle of the device and the user's historical best grip angle. The current raw value collected in this request is 63°.
[0026] The system pre-defines physical lower and upper boundary values for each type of indicator. The mapping logic is as follows: subtract the corresponding lower boundary value from the current original value, and then divide the difference by the total span between the upper and lower boundary values. If the actual collected original value is less than the lower boundary value, the mapping result is truncated to 0; if it is greater than the upper boundary value, the mapping result is truncated to 1.
[0027] For geographic location offset distance, the system presets a lower limit of 0km and an upper limit of 5000km. Subtracting the lower limit of 0 from the original value of 500 and then dividing by the span of 5000 yields the normalized value of 0.1 for this indicator.
[0028] For password input time, the system presets a lower limit of 400ms and an upper limit of 4400ms. Subtracting the lower limit of 400 from the original value of 2400 gives 2000, which is then divided by the range of 4000 to obtain the normalized value of the indicator, 0.5.
[0029] For the device attitude space difference, the system presets a lower limit of 0° and an upper limit of 90°. Subtracting the lower limit of 0 from the original value of 63 gives 63, which is then divided by the span of 90 to obtain the normalized value of the index, 0.7.
[0030] After execution, the original dimensional indexes have been transformed into three standard dimensionless continuous real numbers: 0.1, 0.5, and 0.7.
[0031] 102. The scoring calculation module is used to pre-set at least three decision levels and configure an expected range and a tolerance width for each normalized index value for each decision level; based on the expected range and tolerance width, the scoring value of each normalized index value relative to each decision level is calculated in a continuous piecewise linear manner, thereby obtaining the scoring vector corresponding to each decision level.
[0032] It should be noted that normalized index values (position offset 0.1, password time 0.5, attitude difference 0.7) are used. The system pre-sets three independent decision levels: Level 1 (normal security), Level 2 (minor anomalies), and Level 3 (high risk). For each decision level, the system assigns specific parameters, with the expected range representing the most typical data range under that level, and the tolerance width representing the maximum allowable deviation.
[0033] The configuration is as follows, taking Level 1 (normal security) and Level 2 (minor anomaly) as examples: For Level 1: the expected range for position offset is set to 0 to 0.05, with a tolerance width of 0.1; the expected range for password latency is set to 0.2 to 0.4, with a tolerance width of 0.2; and the expected range for attitude difference is set to 0.5 to 0.6, with a tolerance width of 0.2.
[0034] For Level 2: the expected range for position offset is set to 0.05 to 0.2, with a tolerance width of 0.1; the expected range for password latency is set to 0.4 to 0.6, with a tolerance width of 0.15; and the expected range for attitude difference is set to 0.6 to 0.8, with a tolerance width of 0.15.
[0035] Scoring is performed using continuous piecewise linear logic: if the index value falls within the expected range, the score is 1; if it exceeds the expected range but the excess is less than the tolerance width, the score is 1 minus the ratio of the excess to the tolerance width; if the excess is greater than or equal to the tolerance width, the score is 0.
[0036] The scoring for Level 1 is calculated as follows: The current position offset is 0.1, exceeding the upper limit by 0.05, with an excess of 0.05. The excess divided by the tolerance width of 0.1 equals 0.5. Subtracting this ratio from 1 gives a score of 0.5.
[0037] The current password execution time is 0.5, exceeding the upper limit of 0.4 by 0.1. The excess time divided by the tolerance width of 0.2 equals 0.5. Subtracting this ratio from 1 gives a score of 0.5.
[0038] The current attitude difference is 0.7, exceeding the upper limit of 0.6 by 0.1. The excess is divided by the tolerance width of 0.2, which is 0.5. Subtracting this ratio from 1 gives a score of 0.5.
[0039] The rating vector for Level 1 is (0.5, 0.5, 0.5).
[0040] The calculations for Level 2 are as follows: the current position offset value of 0.1, the password consumption time value of 0.5, and the attitude difference value of 0.7 all fall strictly within the preset expected range for Level 2, without deviation. Therefore, each item scores a perfect score of 1. The resulting score vector for Level 2 is (1.0, 1.0, 1.0). The vector result for Level 3 is output simultaneously according to the same logic.
[0041] 103. Weight Adjustment Module: This module obtains the context information of the current authentication request. The context information includes at least one of the following: number of consecutive failures, time interval, external risk level, and device new / old identifier. It runs a set of preset context rules to obtain the weight adjustment amount for each original authentication indicator based on the context information. The weight adjustment amount is accumulated and normalized with a set of preset baseline weights to obtain a dynamic weight set.
[0042] It should be noted that the truncation mechanism is introduced to prevent excessive negative adjustments from causing the weights to become negative, thereby violating the business logic of the decision-making process.
[0043] A set of baseline weights were pre-defined for the three original authentication metrics: the baseline weight for geographical location offset distance was 0.5, the baseline weight for password input time was 0.3, and the baseline weight for device attitude space difference was 0.2. Simultaneously, the minimum positive value was preset to 0.01.
[0044] When this request was triggered, the following real-time context information was collected: the account has failed to log in twice in the past ten minutes; the threat intelligence database connected to the system assesses the network where the current IP is located as medium risk; the hardware fingerprint of the current terminal device is an old device that has been bound.
[0045] The built-in context rules derive weight adjustments based on the above information: when the network environment is of medium risk, a positive adjustment of 0.15 is obtained for the position offset indicator. When two consecutive failures occur, a positive adjustment of 0.10 is obtained for the password latency indicator. When the device is an older device, a negative adjustment of -0.05 is obtained for the attitude difference indicator.
[0046] The following accumulation and truncation criteria are applied: Position offset weight is 0.5 plus 0.15, resulting in 0.65, which is greater than zero and is retained. Password time weight is 0.3 plus 0.10, resulting in 0.40, which is greater than zero and is retained. Attitude difference weight is 0.2 minus 0.05, resulting in 0.15, which is greater than zero and is retained.
[0047] The verified weight values are normalized. The sum of the three (0.65 + 0.40 + 0.15) equals 1.20. Each value is divided by this sum to obtain the dynamic weights (rounded to two decimal places): the dynamic weight for position offset is 0.65 divided by 1.20, approximately 0.54; the dynamic weight for password time is 0.40 divided by 1.20, approximately 0.33; and the dynamic weight for attitude difference is 0.15 divided by 1.20, approximately 0.13.
[0048] The output consists of a dynamic weight set of 0.54, 0.33, and 0.13, reflecting the distribution of indicator importance in the current specific authentication scenario.
[0049] 104. The weighted summation module is used to perform a weighted summation operation on the dynamic weight set and the score vector of each decision level to obtain the comprehensive score value of each decision level.
[0050] It should be noted that the dynamic environment weights obtained in step 103 are fused with the feature matching degree vectors of each dimension obtained in step 102 to calculate the overall digital tendency of the current request under each preset decision level.
[0051] Alignment preparation of relevant values: The dynamic weight set is: position offset 0.54, password time 0.33, and attitude difference 0.13.
[0052] The rating vector for Level 1 (Regular Safety) is: (0.5, 0.5, 0.5).
[0053] The rating vector for Level 2 (minor abnormality) is (1.0, 1.0, 1.0).
[0054] Level 3 (High Risk) has an extremely low matching degree, and its output score vector is calculated as (0, 0.2, 0).
[0055] For each decision level, the system multiplies the score by its corresponding dynamic weight and then sums the results: Calculate the overall score for Level 1: the product of position offset is 0.54 multiplied by 0.5, which equals 0.27; the product of password time is 0.33 multiplied by 0.5, which equals 0.165; and the product of attitude difference is 0.13 multiplied by 0.5, which equals 0.065. Summing the three products, the overall score for Level 1 is 0.50.
[0056] Calculate the overall score for Level 2: the product of position offset is 0.54 multiplied by 1.0, which equals 0.54; the product of cipher time is 0.33 multiplied by 1.0, which equals 0.33; and the product of attitude difference is 0.13 multiplied by 1.0, which equals 0.13. Summing the three products, the overall score for Level 2 is 1.00.
[0057] Calculate the overall score for Level 3: the product of position offset is 0.54 multiplied by 0, which equals 0; the product of cipher time is 0.33 multiplied by 0.2, which equals 0.066; and the product of attitude difference is 0.13 multiplied by 0, which equals 0. Summing the three products, the overall score for Level 3 is 0.066.
[0058] After execution, the system outputs the scalar comprehensive score values (0.50, 1.00, and 0.066) corresponding to the three decision levels, providing a single quantitative comparison basis for business classification.
[0059] 105. Decision output module, which compares the comprehensive score of each decision level with its corresponding preset decision threshold and outputs the certification decision based on the comparison result; wherein, the preset decision threshold and context rules are pre-set by experts and do not rely on any historical data or machine learning model.
[0060] It should be noted that by using the rule matrix pre-extracted from the offline machine learning model, it is possible to achieve a judgment effect with artificial intelligence characteristics without consuming high online inference computing power.
[0061] Read the preset decision thresholds obtained from the offline model: Level 1 (normal safety) threshold is 0.60; Level 2 (minor anomaly) threshold is 0.75; Level 3 (high risk) threshold is 0.85.
[0062] The comprehensive score obtained in step 104 is compared in parallel with the corresponding threshold. The internal judgment logic is: when the score is greater than or equal to the corresponding threshold, it is considered to have hit the corresponding risk level. At the same time, the system has a built-in fallback rule: if all scores are lower than the preset threshold (i.e., zero hit), the current request is forcibly assumed to have unknown risks and is transferred to the high-risk handling process.
[0063] The specific numerical comparison results are shown in Table 1 below: Table 1
[0064] Based on the status determined by the table, this request triggered Level 2 (Minor Anomaly). Since there is a confirmed match, the fallback rule is not triggered. Based on the matched level, the corresponding preset security handling strategy is locked, and the following decision action is output: The current login request is determined to have minor anomaly characteristics; the normal silent login is blocked; a secondary authentication command is issued, requiring the user to enter a dynamic SMS verification code to supplement identity verification.
[0065] The entire process of transforming multi-dimensional environmental characteristics into specific business blocking actions through an artificial intelligence rule matrix is completed, achieving closed-loop single-authentication decision analysis.
[0066] Please see Figure 2Another embodiment of the authentication decision analysis system based on artificial intelligence in this invention includes: 201. The indicator mapping module is used to obtain multiple original authentication indicators for the current authentication request. Each original authentication indicator has its own dimension. Linear mapping is performed on each original authentication indicator to obtain a normalized indicator value. The numerical range of all normalized indicator values is a continuous real number between 0 and 1 and is dimensionless.
[0067] Specifically, when obtaining multiple original authentication metrics for the current authentication request, the original authentication metrics include at least the password verification result, fingerprint matching score, behavior anomaly score, and device reputation score. The password verification result is a binary discrete value of 0 or 1, the fingerprint matching score is a continuous real number between 0 and 1, the behavior anomaly score is a continuous integer between 0 and 1000, and the device reputation score is a continuous integer between 0 and 100. The password verification result is directly assigned as a normalized metric value, the fingerprint matching score is directly assigned as a normalized metric value, the difference between the behavior anomaly score divided by 1000 and the resulting quotient is used as a normalized metric value, and the device reputation score is divided by 100 and directly used as a normalized metric value. All obtained normalized metric values are within a closed interval of 0 to 1 and are continuous real numbers.
[0068] It should be noted that, taking a numerical security login authentication request initiated by a smart terminal device as an example, when the system receives this request, the authentication data collection gateway synchronously extracts four dimensions of raw authentication indicators from the operating environment and the backend security service module: The first item is the password verification result. This indicator represents the comparison status between the encrypted password entered by the user on the front end and the hash value pre-stored in the backend database. In this request, the password entered by the user was a perfect match, and the raw value extracted by the system gateway was a binary discrete data type, 1.
[0069] The second item is the fingerprint matching score. This metric characterizes the degree of topological overlap between the fingerprint texture feature points captured in real time by the terminal's biometric sensor and the registered feature points within the chip's secure area. In this request, the sensor output showed a high matching degree, and the raw value extracted by the system was a continuous real number of 0.82, which is between 0 and 1.
[0070] The third item is the behavioral anomaly score. This metric is obtained from the device's local behavior analysis engine and comprehensively evaluates the deviation of the current physical operation trajectory, such as the duration of button presses and screen swipe acceleration, from the user's historical baseline. The higher the value, the more the behavior deviates from the norm. In this request, the raw value extracted by the system was a consecutive integer of 150, ranging from 0 to 1000.
[0071] The fourth item is the device reputation score. This indicator is issued by the cloud-based risk control system based on factors such as the device's historical login records and the purity of its current operating system (whether it has been rooted). A higher value indicates a more secure operating environment for the device. In this request, the raw value extracted by the system was 95, a consecutive integer between 0 and 100.
[0072] Perform linear mapping transformation according to preset rules: For the password verification result, the system adopts a direct assignment strategy, and the original discrete value 1 is directly converted into the normalized index value 1.0.
[0073] For fingerprint matching scores, the system also adopts a direct assignment strategy, where the original real number 0.82 is directly converted into a normalized index value of 0.82.
[0074] For the abnormal behavior score, a division operation is performed, dividing the original integer 150 by the range boundary 1000 to obtain a quotient of 0.15. Next, a reverse difference operation is performed, subtracting the quotient 0.15 from the constant value 1, resulting in 0.85. 0.85 is used as the normalized index value for this indicator; this logic ensures that a larger value represents more normal behavior.
[0075] For the equipment reputation score, linear scaling is applied, dividing the original integer 95 by the range boundary 100 to directly obtain a result of 0.95. 0.95 is then used as the normalized value for this indicator.
[0076] Through the above operations, the four original indicators with physical and logical differences were successfully transformed into four standard continuous real numbers: 1.0, 0.82, 0.85, and 0.95.
[0077] 202. The scoring calculation module is used to pre-set at least three decision levels and configure an expected range and a tolerance width for each normalized index value for each decision level. Based on the expected range and tolerance width, the scoring value of each normalized index value relative to each decision level is calculated in a continuous piecewise linear manner, thereby obtaining the scoring vector corresponding to each decision level.
[0078] Specifically, when at least three decision levels are pre-defined, the process includes: pre-defining three decision levels: pass, secondary verification, and rejection; for each decision level, configuring an expected range and a tolerance width for each normalized index value, where the expected range consists of a lower bound and an upper bound, and the tolerance width represents the width of linear transition allowed outside the expected range; for each normalized index value, calculating its score relative to each decision level, specifically: if the normalized index value is within the expected range, the score is 1; if the normalized index value is outside the expected range but does not exceed the tolerance width, the score changes linearly between 0 and 1; if the normalized index value exceeds the tolerance width, the score is 0; the scores of all normalized index values under each decision level constitute the score vector for that decision level.
[0079] Furthermore, for each decision level, when the original certification indicator corresponding to the normalized indicator value is a binary discrete type, the tolerance width of the normalized indicator value is set to zero, so that the score value of the normalized indicator value can only be 0 or 1; when the original certification indicator corresponding to the normalized indicator value is a continuous type, the tolerance width of the normalized indicator value is a preset positive value related to the indicator type.
[0080] It should be noted that the system has pre-set pass, secondary verification, and rejection levels. The system is configured with strict expected ranges and tolerance parameters for different levels.
[0081] The configuration for the pass / fail level is as follows: Password verification (binary discrete type): The expected interval is set to a closed interval [1.0, 1.0], and the tolerance width is strictly locked to 0.
[0082] Fingerprint matching (continuous type): The expected range is set to [0.85, 1.0], and the tolerance width is configured to a positive value of 0.15.
[0083] Abnormal Behavior (Continuous Type): Expected range is set to [0.90, 1.0], and tolerance width is configured to 0.10.
[0084] Equipment reputation (continuous type): Expected range is set to [0.90, 1.0], and tolerance width is configured to 0.10.
[0085] The configuration for the second verification level is as follows: Password verification: The expected range and tolerance width are the same as above, and are kept at [1.0, 1.0] and 0.
[0086] Fingerprint matching: The expected range is lowered to [0.60, 0.85], and the tolerance width is configured to 0.10.
[0087] Abnormal behavior: Reduce the expected range to [0.70, 0.90], and configure the tolerance width to 0.10.
[0088] Equipment reputation: The expected range for downward adjustment is [0.70, 0.90], and the tolerance width is configured to 0.10.
[0089] For the rejection level, the expected range is set to mainly include extremely low security thresholds (the fingerprint expected range is set to [0, 0.60], with a tolerance width of 0.10) in order to capture high-risk features.
[0090] Quantitative scoring is performed based on continuous piecewise linear rules: When calculating the pass-level rating vector: The password normalization value of 1.0 falls within the interval [1.0, 1.0] with no offset, and scores 1.
[0091] The fingerprint normalization value of 0.82 is below the lower bound of 0.85, indicating an offset of 0.03. Since 0.03 does not exceed the tolerance width of 0.15, the ratio of the offset to the width is calculated to be 0.2. Subtracting 0.2 from 1 linearly reduces the score to 0.8.
[0092] The behavior normalization value of 0.85 is below the lower bound of 0.90, with a deviation of 0.05. The tolerance width of 0.10 is not exceeded, resulting in a ratio of 0.5. Subtracting 0.5 from 1 reduces the score to 0.5.
[0093] The reputation normalized value of 0.95 falls within the range [0.90, 1.0], and the score is 1.
[0094] Therefore, the score vector for passing the level is (1, 0.8, 0.5, 1).
[0095] When calculating the secondary verification level score vector: The password normalization value is 1.0, which falls within the range, so the score is 1.
[0096] The fingerprint normalization value is 0.82, which falls perfectly within the expected range of [0.60, 0.85] for this level, with no offset, and the score is 1.
[0097] The behavior normalization value is 0.85, which falls within the expected range [0.70, 0.90] and shows no deviation, so the score is 1.
[0098] The reputation normalization value is 0.95, exceeding the upper limit of 0.90, with a deviation of 0.05. It does not exceed the tolerance width of 0.10, resulting in a ratio of 0.5. Subtracting 0.5 from 1 gives a score of 0.5.
[0099] The score vector for the secondary verification level is (1,1,1,0.5).
[0100] When calculating the rejection level score vector, the currently obtained fingerprint score of 0.82, behavior score of 0.85, and reputation score of 0.95 all far exceed the extremely low upper limit threshold of this level, and the deviation is greater than the configured tolerance width. Therefore, all individual scores are set to 0, and the rejection level score vector is (0,0,0,0).
[0101] 203. Weight Adjustment Module: This module obtains the context information of the current authentication request. The context information includes at least one of the following: number of consecutive failures, time interval, external risk level, and device new / old identifier. It runs a set of preset context rules to obtain the weight adjustment amount for each original authentication indicator based on the context information. The weight adjustment amount is accumulated and normalized with a set of preset baseline weights to obtain a dynamic weight set.
[0102] Specifically, when obtaining the context information of the current authentication request, the context information includes the number of consecutive failures, the time interval between the current attempt and the last attempt, the external risk level, and the device's new / old identifier; a set of preset context rules are run, including rule 1, rule 2, rule 3, and rule 4; rule 1 is that when the number of consecutive failures reaches or exceeds three, the baseline weight corresponding to the password verification indicator is reduced by a first fixed adjustment amount, while the baseline weight corresponding to the abnormal behavior indicator is increased by a second fixed adjustment amount, and the baseline weight corresponding to the device reputation indicator is increased by a third fixed adjustment amount; rule 2 is that when the time interval is less than two seconds, the baseline weight corresponding to the fingerprint matching indicator is reduced by a fourth fixed adjustment amount, while the baseline weight corresponding to the abnormal behavior indicator is increased by a fifth fixed adjustment amount. The first rule is to reduce the fixed adjustment amount by the sixth and seventh fixed adjustment amounts respectively when the external risk level is high, and increase the fixed adjustment amount by the eighth fixed adjustment amount for the benchmark weight corresponding to the device reputation index when the external risk level is high. The second rule is to increase the fixed adjustment amount by the ninth fixed adjustment amount for the benchmark weight corresponding to the abnormal behavior index when the device is a new device, and reduce the fixed adjustment amount by the tenth fixed adjustment amount for the benchmark weight corresponding to the device reputation index when the device is a new device. The fixed adjustment amounts generated by all the matching rules are added to the corresponding benchmark weights to obtain the original weights. For each value in the original weights, the maximum value between zero and the original weight is taken to obtain the non-negative weights. The reciprocal of the sum of all non-negative weights is used as the normalization coefficient. Each non-negative weight is multiplied by the normalization coefficient to obtain the dynamic weight set.
[0103] Furthermore, in the first rule, when the number of consecutive failures exceeds five, the first fixed adjustment amount for reducing the baseline weight corresponding to the password verification indicator is greater than the first fixed adjustment amount when the number of consecutive failures is three to five; in the second rule, when the time interval is less than one second, the fifth fixed adjustment amount for increasing the baseline weight corresponding to the abnormal behavior indicator is greater than the fifth fixed adjustment amount when the time interval is one to two seconds.
[0104] It should be noted that the pre-set benchmark weights for the indicators are: password verification 0.3, fingerprint matching 0.3, abnormal behavior 0.2, and device reputation 0.2. The preset minimum positive number is 0.001.
[0105] During the current request flow, the system collected real-time context data: the account failed to log in 4 times consecutively; the time interval between the current and last attempts was 0.8 seconds; the risk level issued by the external security intelligence database was medium risk; the current device was identified as an old device.
[0106] The engine iterates through preset rules to perform matching operations: Matching rule 1: Four consecutive failures, meeting the condition of three or more failures but not exceeding five. Triggering standard adjustment thresholds: Password verification indicator decreases by 0.15, abnormal behavior indicator increases by 0.10, and device reputation indicator increases by 0.05.
[0107] Matching rule 2: Time interval 0.8s, meeting the stringent condition of less than two seconds and further matching less than one second. Trigger upgrade adjustment threshold: Fingerprint matching indicator decreases by 0.10, and a larger fifth fixed adjustment is enabled for abnormal behavior indicators, i.e., an increase of 0.20.
[0108] Matching the third and fourth rules: The current network is in a medium-risk area and the device is an old device. Neither of them has triggered the rule's threshold, so no adjustment will be made.
[0109] The obtained adjustment amount is accumulated into the benchmark weight: Password verification: Subtract 0.15 from the baseline of 0.3 to obtain the original weight of 0.15.
[0110] Fingerprint matching: Subtract 0.10 from the baseline of 0.3 to obtain the original weight of 0.20.
[0111] Abnormal behavior: The baseline of 0.2 is added to the first rule of 0.10 and the second rule of 0.20 to obtain the original weight of 0.50.
[0112] Equipment reputation: The baseline of 0.2 plus the first rule of 0.05 results in an original weight of 0.25.
[0113] The original weights are all zeroed out one by one. Since all values are greater than zero, the original values are retained as non-negative weights.
[0114] The normalization process begins: The system calculates the sum of non-negative weights (0.15 + 0.20 + 0.50 + 0.25 = 1.10). The system compares 1.10 with the preset minimum positive number 0.001 and takes the maximum value, resulting in 1.10. This completely avoids the risk of mathematical collapse due to a zero denominator.
[0115] The calculations are performed using the reciprocal of 1.10 as the coefficient: the dynamic weight of the password is 0.15 divided by 1.10, resulting in 0.14; the dynamic weight of the fingerprint is 0.20 divided by 1.10, resulting in 0.18; the dynamic weight of the behavior is 0.50 divided by 1.10, resulting in 0.45; and the dynamic weight of the reputation is 0.25 divided by 1.10, resulting in 0.23.
[0116] The resulting dynamic weight set (0.14, 0.18, 0.45, 0.23) maps the defense strategy of increasing behavioral weights in anti-brute-force attack scenarios.
[0117] 204. The weighted summation module is used to perform a weighted summation operation on the dynamic weight set and the score vector of each decision level to obtain the comprehensive score value of each decision level.
[0118] Specifically, the weighted summation operation of the dynamic weight set and the score vector of each decision level includes: obtaining the dynamic weight set and the score vector of each decision level; the dynamic weight set contains dynamic weight values corresponding one-to-one with each original certification indicator, and the score vector contains the score value of each normalized indicator value relative to the decision level; for each decision level, multiplying each score value in the score vector of that decision level by the dynamic weight value of the original certification indicator corresponding to that score value to obtain a set of weighted score values; summing all the weighted score values in the set of weighted score values to obtain the comprehensive score value of that decision level; performing the same operation on all decision levels to obtain a comprehensive score value corresponding to each decision level.
[0119] Furthermore, before calculating the weighted score for each decision level, each dynamic weight value in the dynamic weight set is grouped according to the corresponding original authentication indicator type. The groups include password verification group, fingerprint matching group, behavior anomaly group, and device reputation group. For the dynamic weight values within each group, the weight sum within the group is first calculated to obtain the weight sum within the group, and then the weight sum within the group is multiplied by the score value corresponding to the group to obtain the weighted score value within the group. The weighted scores within all groups are summed to obtain the comprehensive score value for that decision level.
[0120] It should be noted that the dynamic weight values are organized into four independent groups according to the indicator type. Since each category in the embodiment contains only a single indicator, the sum of the weights within each group is the dynamic weight itself: the sum of the weights within the password verification group is 0.14, the sum of the weights within the fingerprint matching group is 0.18, the sum of the weights within the abnormal behavior group is 0.45, and the sum of the weights within the device reputation group is 0.23.
[0121] Simultaneously, the rating vector matrices for each level obtained in step 202 are invoked to prepare for the execution of the following core aggregation calculation framework, employing a dimensionless calculation framework to ensure the uniformity of dimensions: Comprehensive score for each decision level The calculation method is as follows:
[0122] In this operational mechanism, This represents the total number of groups (4 in this example). This represents the pure number score of the j-th group at a specific decision level; This represents the number of indicator elements within the group; Represents specific dynamic characteristic coefficients.
[0123] Based on this framework, the system outputs the calculation results item by item: Calculate the overall score for the passing grade: Password verification group: The weight is 0.14 multiplied by the group score of 1.0, and the weighted value within the group is 0.14.
[0124] Fingerprint matching group: The weight sum of 0.18 is multiplied by the group score of 0.8, and the weighted value within the group is 0.144.
[0125] Abnormal Behavior Group: The weighted sum of 0.45 is multiplied by the group score of 0.5, and the output weighted value within the group is 0.225.
[0126] Equipment reputation group: The weight is 0.23 multiplied by the group score of 1.0, and the output group weighted value is 0.23.
[0127] The weighted values were summed to obtain a total score of 0.739, which is the exact score for passing the test.
[0128] Calculate the comprehensive score for the secondary verification level: Password verification group: Weight sum 0.14 multiplied by score 1.0, output 0.14.
[0129] Fingerprint matching group: weight sum 0.18 multiplied by score 1.0, output 0.18.
[0130] Abnormal behavior group: weighted sum of 0.45 multiplied by score of 1.0, output 0.45.
[0131] Equipment reputation group: weight sum 0.23 multiplied by score 0.5, output 0.115.
[0132] The weighted values were summed (0.14 + 0.18 + 0.45 + 0.115) to obtain a comprehensive score of 0.885 for the secondary verification level.
[0133] Calculating the overall rejection score: Because all elements in the called rejection score vector are 0, the weighted values within all groups are 0 after multiplication, resulting in an overall rejection score of 0 after summation. After execution, the complex multidimensional data is reduced to three scalar values reflecting environmental bias (0.739, 0.885, 0), achieving the data preparation goal for quantitative evaluation.
[0134] 205. Decision output module, which compares the comprehensive score of each decision level with its corresponding preset decision threshold and outputs the certification decision based on the comparison result; wherein, the preset decision threshold and context rules are pre-set by experts and do not rely on any historical data or machine learning model.
[0135] Specifically, when comparing the comprehensive score of each decision level with its corresponding preset decision threshold, the process includes: setting a first decision threshold for the pass level, a second decision threshold for the rejection level, and a third decision threshold for the secondary verification level; obtaining the comprehensive score of the pass level, the comprehensive score of the secondary verification level, and the comprehensive score of the rejection level; comparing the comprehensive score of the pass level with the first decision threshold; if the comprehensive score of the pass level is greater than the first decision threshold, then output "pass" as the authentication decision; if the comprehensive score of the pass level is not greater than the first decision threshold, then compare the comprehensive score of the rejection level with the second decision threshold; if the comprehensive score of the rejection level is greater than the second decision threshold, then output "reject" as the authentication decision; if the comprehensive score of the rejection level is also not greater than the second decision threshold, then output "secondary verification" as the authentication decision.
[0136] It should be noted that by obtaining the leading-edge threshold parameters issued by the offline model, the system executes a rigorous logical judgment flow in a predetermined order, stripping away the burden of online inference to ensure high-concurrency processing performance.
[0137] Read the pre-loaded decision thresholds. In response to the current overall system security baseline, the model has pre-deployed relevant parameters: the first decision threshold (used for passing the level definition) is set to 0.80; the second decision threshold (used for rejecting the level definition) is set to 0.60; and the third decision threshold (auxiliary definition parameter) is set to 0.70.
[0138] Extract the three core data points from step 204: Pass rating: 0.739; Secondary verification rating: 0.885; Rejection rating: 0.
[0139] The execution status and inference path of the sequential comparison and decision distribution module are shown in Table 2 below: Table 2
[0140] Following the above logic chain: Since 0.739 did not break through the direct release water level of 0.80, and 0 failed to touch the direct interception warning line of 0.60, the system terminates the comparison according to the fallback routing rule, outputs the authentication decision of secondary verification, and commands the business gateway to send an SMS or slider verification pop-up.
[0141] 206. Security Review Module: This module obtains the pass / rejection comprehensive score and the rejection comprehensive score, compares the pass / rejection comprehensive score with a first security review threshold, and compares the rejection comprehensive score with a second security review threshold. If the pass / rejection comprehensive score is less than the first security review threshold and the rejection comprehensive score is less than the second security review threshold, the authentication decision is forcibly modified to two-factor authentication. If the pass / rejection comprehensive score is not less than the first security review threshold or the rejection comprehensive score is not less than the second security review threshold, the authentication decision remains unchanged.
[0142] Furthermore, the first security review threshold and the second security review threshold are dynamically obtained based on the context information of the current authentication request; the context information includes the number of consecutive failures, the time interval, and the external risk level; when the number of consecutive failures increases, the first security review threshold increases and the second security review threshold decreases; when the time interval shortens, the first security review threshold increases and the second security review threshold decreases; when the external risk level increases, the first security review threshold increases and the second security review threshold decreases.
[0143] It should be noted that the monitoring focuses on extreme context environments, and through the two-way squeezing effect of the threshold driven by environmental degradation, it intercepts high-risk traffic that may be misjudged under the normal static threshold.
[0144] Using the complete data, extract the current status output from step 205: the authentication decision is secondary verification, the pass rating is 0.739, and the rejection rating is 0.
[0145] Extract the contextual factors recorded in step 203: 4 consecutive login failures, with an attempt time interval of 0.8s, and the external risk level is medium risk.
[0146] Load the underlying base parameters for review and correction: the first security review threshold baseline is 0.75, and the second security review threshold baseline is 0.20.
[0147] Dynamic pressure triggered by the engine injecting a real-time context: Driven by four consecutive failures, the system applies an increment of 0.03 to the first review threshold and a decrement of 0.02 to the second review threshold.
[0148] Driven by an extremely short time interval (0.8s), the system applies an increment of 0.02 to the first review threshold and a decrement of 0.02 to the second review threshold.
[0149] Driven by the medium-risk network, the system applies an increment of 0.02 to the first review threshold and a decrement of 0.01 to the second review threshold.
[0150] Through the superposition effect of environmental factors, the system calculates the specific intervention boundary markers under the current extremely harsh environment: The dynamic first security review threshold is raised to: 0.75 + 0.03 + 0.02 + 0.02 = 0.82.
[0151] The dynamic second security review threshold is reduced to: 0.20-0.02-0.02-0.01=0.15.
[0152] The entry condition interpretation intervention flow is shown in Table 3 below: Table 3
[0153] The logic engine determines that although the current system has increased its intervention sensitivity due to environmental degradation (lowering the second review threshold to 0.15), the extremely malicious characteristics of this session are not obvious (the rejection score is only 0). Therefore, it is not necessary to use the forced interception right. The system security review result remains unchanged from the conclusion output in step 205. The robust output of the second verification completes the technical loop of this authentication analysis.
[0154] Figure 3 This is a schematic diagram of an AI-based authentication decision analysis device according to an embodiment of the present invention. The device 300 can vary significantly due to differences in configuration or performance. The device 300 includes a transmitter 301, a receiver 302, and a processor 303. The processor 303 can also be a controller. Figure 3 The controller / processor is 303. Optionally, the device 300 may also include a modem processor 305, which may include an encoder 306, a modulator 307, a decoder 308, and a demodulator 309.
[0155] In one example, transmitter 301 modulates (e.g., analog-to-analog conversion, filtering, amplification, and up-conversion, etc.) the output sample to obtain an uplink signal, which is transmitted via an antenna to an access network device. On the downlink, the antenna receives the downlink signal transmitted by the access network device. Receiver 302 modulates (e.g., filtering, amplification, down-conversion, and digitization, etc.) the signal received from the antenna and provides an input sample. In modem processor 305, encoder 306 receives service data and signaling messages to be transmitted on the uplink and processes (e.g., formatting, encoding, and interleaving) the service data and signaling messages. Modulator 307 further processes (e.g., symbol mapping and modulation) the encoded service data and signaling messages and provides an output sample. Demodulator 309 processes (e.g., demodulates) the input sample and provides a symbol estimate. Decoder 308 processes (e.g., deinterleaving and decoding) the symbol estimate and provides decoded data and signaling messages to device 300. Encoder 306, modulator 307, demodulator 309, and decoder 308 can be implemented by a combined modem processor 305. These units perform processing according to the radio access technology adopted by the radio access network (e.g., LTE and other evolved systems access technologies). It should be noted that when device 300 does not include modem processor 305, the above-mentioned functions of modem processor 305 can also be performed by processor 303.
[0156] The processor 303 controls and manages the operation of the device 300, and is used to execute the processing procedures performed by the device 300 in the above embodiments of this disclosure. For example, the processor 303 is also used to execute various steps of the transmitting or receiving device in the above method embodiments, and / or other steps of the technical solutions described in the embodiments of this disclosure.
[0157] Furthermore, the device 300 may also include a memory 304 for storing program code and data for the device 300.
[0158] Understandable, Figure 3 Only a simplified design of device 300 is shown. In practical applications, device 300 can include any number of transmitters, receivers, processors, modem processors, memory, etc., and all devices that can implement the embodiments of this disclosure are within the protection scope of the embodiments of this disclosure.
[0159] The present invention also provides an AI-based authentication decision analysis device, which includes a memory and a processor. The memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, the processor performs the steps of the AI-based authentication decision analysis system in the above embodiments.
[0160] The present invention also provides a computer-readable storage medium, which can be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium, wherein the computer-readable storage medium stores instructions that, when executed on a computer, cause the computer to perform the steps of the artificial intelligence-based authentication decision analysis system.
[0161] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0162] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0163] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. An authentication decision analysis system based on artificial intelligence, characterized in that, include: The indicator mapping module is used to obtain multiple original authentication indicators of the current authentication request, and to perform mapping processing on each of the original authentication indicators to obtain a normalized indicator value. The scoring calculation module is used to pre-set multiple decision levels and configure the expected range and tolerance width for each decision level for each normalized index value; Based on the expected range and the tolerance width, calculate the score value of each normalized index value relative to each decision level to obtain the score vector corresponding to each decision level; The weight adjustment module is used to obtain the context information of the current authentication request, run preset rules, adjust the base weight according to the context information, and obtain a dynamic weight set. The weighted summation module is used to perform a weighted summation of the dynamic weight set and the scoring vector corresponding to each decision level to obtain a comprehensive score value for each decision level. The decision output module is used to compare the comprehensive score value of each decision level with the corresponding preset decision threshold and output the authentication decision.
2. The authentication decision analysis system based on artificial intelligence according to claim 1, characterized in that, The original certification indicators include discrete indicators and continuous indicators; The step of mapping each of the original authentication indicators to obtain a normalized indicator value includes: mapping the discrete indicator and the continuous indicator to dimensionless continuous real numbers, which are used as normalized indicator values.
3. The authentication decision analysis system based on artificial intelligence according to claim 1, characterized in that, The pre-defined multiple decision levels include setting a pass level, a secondary verification level, and a rejection level; The step of calculating the score value of each normalized index value relative to each decision level based on the expected interval and the tolerance width includes: If the normalized index value is within the expected range, then the score value is taken as the first preset value; If the normalized index value is outside the expected range but does not exceed the tolerance width, the score value changes linearly between the first preset value and the second preset value. If the normalized index value exceeds the tolerance range, the score value is taken as the second preset value.
4. The authentication decision analysis system based on artificial intelligence according to claim 3, characterized in that, When the original certification index corresponding to the normalized index value is a discrete index, the configured tolerance width is zero; When the original certification indicator corresponding to the normalized indicator value is a continuous indicator, the configured tolerance width is a preset positive value.
5. The authentication decision analysis system based on artificial intelligence according to claim 1, characterized in that, The context information includes at least one of the following: number of consecutive failures, time interval, external risk level, and device identifier; The preset running rules adjust the baseline weights based on the context information to obtain a dynamic weight set, including: Based on the context information, the corresponding preset rule is matched to obtain the weight adjustment amount; The original weight is obtained by adding the weight adjustment amount to the corresponding benchmark weight; Extract the maximum value between the original weights and zero as the non-negative weights; All the non-negative weights are normalized to obtain a dynamic weight set.
6. The authentication decision analysis system based on artificial intelligence according to claim 1, characterized in that, The step of weighted summing of the dynamic weight set and the scoring vector corresponding to each decision level to obtain a comprehensive score value for each decision level includes: The weight values in the dynamic weight set are divided into multiple groups according to the type of the corresponding original certification indicator; Calculate the sum of the in-group weights for the weight values within each group; The weighted score within the group is obtained based on the weights within the group and the score value corresponding to that group. The weighted scores within each group are summed to obtain the overall score corresponding to the decision level.
7. The authentication decision analysis system based on artificial intelligence according to claim 6, characterized in that, The formula for calculating the comprehensive score is as follows: ; in, The overall score representing decision level k; Represents the total number of groups; This represents the score value corresponding to the j-th group at decision level k; This represents the number of dynamic weight values within the j-th group; This represents the i-th dynamic weight value within the j-th group. Let be the sum of the weights within the j-th group.
8. The authentication decision analysis system based on artificial intelligence according to claim 3, characterized in that, The step of comparing the comprehensive score value of each decision level with the corresponding preset decision threshold and outputting an authentication decision includes: If the comprehensive score value corresponding to the pass level is greater than the first decision threshold, then pass is output as the authentication decision; If the comprehensive score value corresponding to the pass level is not greater than the first decision threshold, and the comprehensive score value corresponding to the rejection level is greater than the second decision threshold, then a rejection is output as the authentication decision. If the comprehensive score value corresponding to the pass level is not greater than the first decision threshold, and the comprehensive score value corresponding to the rejection level is not greater than the second decision threshold, then secondary verification is output as the authentication decision.
9. The authentication decision analysis system based on artificial intelligence according to claim 8, characterized in that, It also includes a security review module: The comprehensive score corresponding to the pass level is compared with the first security review threshold, and the comprehensive score corresponding to the rejection level is compared with the second security review threshold; If the comprehensive score value corresponding to the pass level is less than the first security review threshold, and the comprehensive score value corresponding to the rejection level is less than the second security review threshold, then the authentication decision will be forcibly modified to secondary verification.
10. The authentication decision analysis system based on artificial intelligence according to claim 9, characterized in that, The first security review threshold and the second security review threshold are dynamically adjusted based on the context information; When at least one of the following occurs: an increase in the number of consecutive failures, a shortening of the time interval, or an increase in the level of external risk, the first security review threshold increases and the second security review threshold decreases.