Online environment support system for anti-cheating playing card game machine

By designing an online environment support system for anti-cheating poker game consoles, combining AI behavior analysis, real-time monitoring, encryption technology and blockchain technology, the complexity, real-time and information security of online poker games are solved, and the fairness, security and efficient operation of the game are achieved.

CN120132365APending Publication Date: 2025-06-13WINNING MACAU ASIA TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510374038.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

When the existing technology responds to the complexity, real-time requirements and information security challenges of online poker games, there are problems such as insufficient online environment support, lagging real-time cheating prevention mechanisms and weak information security mechanisms.

Method used

An online environment support system for anti-cheating playing card game consoles is designed, including an online environment support module, a cloud data synchronization module and an information security mechanism module. The system adopts AI behavior analysis algorithm unit and real-time monitoring unit, combining encryption technology and blockchain technology to achieve real-time cheating prevention, information security guarantee and cloud data synchronization.

Benefits of technology

Through AI behavior analysis and real-time monitoring, we can effectively curb cheating and ensure the fairness of the game; encryption technology and blockchain technology ensure data security; cloud data synchronously solve data island problems, and improve user experience and operational efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120132365A_ABST
    Figure CN120132365A_ABST
Patent Text Reader

Abstract

The invention provides an online environment support system for an anti-cheating playing card game machine, and the system comprises an online environment support module which is disposed on a control server, and is used for providing the support of an online game environment and a real-time anti-cheating mechanism; the cloud data synchronization module is deployed on the control server, communicates with a cloud server and realizes cloud synchronization and storage of user data through a distributed database and an incremental synchronization technology; and the information security mechanism module is deployed on a communication link between the control server and the cloud server and a communication link between the control server and the game player terminal, the scoring server and the card dealer, and the information security mechanism module adopts an encryption technology and a block chain technology to ensure the security of user data transmission and storage. The system has the functions of online environment support, real-time cheating prevention, information security guarantee, cloud data synchronization and the like, can fill the technical blank of online and offline fused game scenes, and effectively restrains cheating behaviors.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer network systems, and particularly to an online environment support system for an anti-cheating poker gaming machine. Background Art

[0002] With the rapid development of the entertainment industry, as a classic competitive event, poker games have a large user base both in offline physical games and online virtual games. The current anti-cheating poker gaming machines on the market mainly focus on the offline game environment. For classic competitive poker games, they already have basic anti-cheating monitoring, data recording and analysis functions. These systems use technical means such as physical isolation, hardware encryption, and behavior recognition to contain cheating behaviors to a certain extent and ensure the fairness of the game.

[0003] However, with the rapid popularization of online poker games, the existing technical system has shown significant deficiencies in coping with the complexity, real-time requirements of the online environment, and information security challenges:

[0004] Insufficient support for the online environment: The existing systems mainly rely on the local area network architecture and are difficult to adapt to the wide area network environment required for online games. Online games involve multi-node communication and high-concurrency data processing, which pose higher requirements for system stability, response speed, and compatibility. The traditional systems lack optimization mechanisms for problems such as network latency, packet loss, and retransmission, resulting in a degraded gaming experience and even triggering cheating loopholes.

[0005] Lagging real-time anti-cheating mechanism: The anti-cheating strategies of offline systems (such as physical card dealer verification and manual monitoring) cannot be directly migrated to the online scenario. Online games need to analyze players' behaviors in real time and detect abnormal operations (such as cheating software and coordinated cheating), but the existing technologies lack efficient AI algorithm support and are difficult to complete data collection, analysis, and intervention within milliseconds, resulting in the difficulty of containing cheating behaviors in a timely manner.

[0006] Weak information security mechanism: The online environment faces multiple risks such as data leakage, tampering, and man-in-the-middle attacks. Most of the existing systems use basic encryption technologies, but the key management and the security of transmission protocols are insufficient, and there is a lack of a hierarchical protection mechanism for players' privacy data (such as identities and transaction records). In addition, system logs are easily tampered with, making it difficult to provide non-repudiable audit evidence.

[0007] Lack of cloud data synchronization function: The offline system relies on local storage, with scattered and easily lost data, and cannot achieve real-time synchronization across platforms and devices. Online games need to integrate players' historical data, behavior pattern analysis, score ranking, etc. However, the existing technology lacks an efficient cloud synchronization solution, resulting in serious data island problems and unable to support value-added services such as personalized recommendations and risk warnings. The existing system does not integrate edge computing and cloud computing resources, with high data processing latency; cloud synchronization only supports simple backups, lacking advanced functions such as incremental updates and conflict resolution; and does not utilize blockchain technology to achieve data immutability. Summary of the Invention

[0008] To solve the above problems, the present invention proposes an online environment support system for an anti-cheating poker game machine, which has functions such as online environment support, real-time anti-cheating, information security guarantee, and cloud data synchronization, can fill the technical gap in the online-offline integrated game scenario, effectively curb cheating behavior, and thus promote the development of the poker game industry towards a more secure, fair, and intelligent direction.

[0009] The present invention achieves the above object through the following technical solutions:

[0010] An online environment support system for an anti-cheating poker game machine, the game machine includes a scoring server, a control server, and a game player terminal, and the system includes:

[0011] An online environment support module, deployed on the control server, for providing support for the online game environment and a real-time anti-cheating mechanism;

[0012] A cloud data synchronization module, deployed on the control server, and communicating with the cloud server at the same time, realizing cloud synchronization and storage of user data through a distributed database and incremental synchronization technology;

[0013] An information security mechanism module, deployed on the communication links between the control server and the cloud server, as well as between the control server and the game player terminal, the scoring server, and the card dealer. This module uses encryption technology and blockchain technology to ensure the security of user data transmission and storage;

[0014] Among them, the real-time anti-cheating mechanism includes:

[0015] An AI behavior analysis algorithm unit, deployed on the computing unit of the control server, configured to perform real-time analysis on the operation behavior data of users through a machine learning model based on a preset behavior feature library to identify abnormal behavior patterns;

[0016] The real-time monitoring unit is deployed at the network layer of the control server and is configured to detect abnormal data interactions between the game player terminals and external programs or devices in real time through traffic analysis, device fingerprint technology, and process monitoring, and identify and block the access of cheating tools.

[0017] According to an online environment support system for an anti-cheating poker gaming machine provided by the present invention, the information security mechanism module includes:

[0018] The encryption technology unit is configured to encrypt user data in transmission using the SSL / TLS protocol and encrypt sensitive data in storage using the AES-256 algorithm by combining symmetric encryption and asymmetric encryption;

[0019] The blockchain recording unit is configured to generate hash values for key operation data and store them in the blockchain to ensure that the data is tamper-proof and traceable;

[0020] The cloud data synchronization unit is configured to combine the access control policy and the audit log mechanism to monitor the access behavior of cloud data in real time and verify permissions to prevent unauthorized access.

[0021] According to an online environment support system for an anti-cheating poker gaming machine provided by the present invention, the behavior feature library of the AI behavior analysis algorithm unit is constructed in the following manner:

[0022] Collect the player behavior data within a preset time period, including operation time, amount, operation frequency, and device information; preprocess the behavior data, including denoising, normalization, and feature extraction, to generate an initial feature set;

[0023] Use unsupervised learning algorithms to perform clustering analysis on the initial feature set, identify normal behavior patterns, and generate a basic feature library; combine supervised learning algorithms and use the labeled cheating behavior data to train the basic feature library to generate an advanced feature library containing abnormal behavior features.

[0024] Collect new generated player behavior data in real time and incrementally update the model parameters of the advanced feature library through online learning algorithms;

[0025] Set up a feedback verification module. When the AI behavior analysis algorithm unit marks a certain behavior as abnormal, trigger the manual review process; if the review confirms that the behavior is a cheating behavior, extract its features and add them to the advanced feature library;

[0026] Regularly perform a full-scale verification on the feature library, remove redundant features, and optimize the feature weights.

[0027] Among them, the behavior feature library includes a basic feature layer and an advanced feature layer. The basic feature layer is used to store general behavior statistics, and the advanced feature layer is used to store time series patterns and association rules.

[0028] According to an online environment support system for an anti-cheating poker game machine provided by the present invention, the AI behavior analysis algorithm unit performs real-time analysis on the operation behavior data of users through the following machine learning models to identify abnormal behavior patterns:

[0029] Adopt a hybrid model structure, including a time series feature extraction module and a non-time series feature processing module; among them, the time series feature extraction module is a long short-term memory network LSTM, configured to receive the time series data sequence of the player's operation behavior, including amount, operation time, operation type, and output a time series feature vector; the non-time series feature processing module is an extreme gradient boosting tree XGBoost, configured to receive static feature data and the time series feature vector output by the LSTM. The static feature data includes historical behavior statistics and device fingerprint information, and fuses them to generate an anomaly score.

[0030] Among them, the time series features include: the amount sequence, time interval sequence, and operation type coding sequence in the past N times; the static features include: the player's historical average amount, the standard deviation of operation frequency, and the device unique identifier.

[0031] According to an online environment support system for an anti-cheating poker game machine provided by the present invention, during model training and optimization, use historical behavior data containing normal and cheating labels to perform end-to-end training on the hybrid model. The loss function is weighted cross-entropy. Adopt an online learning mechanism, regularly update the model parameters with new data, and prevent overfitting through the early stopping strategy Early Stopping;

[0032] Dynamically adjust the anomaly score threshold, and the threshold calculation formula is:

[0033] Threshold = α · global average score + (1 - α) · standard deviation of the player's historical score

[0034] Among them, α is a weight coefficient, and the global average score is calculated based on the real-time data of all players;

[0035] When the anomaly score exceeds the dynamic threshold, it is marked as an abnormal behavior;

[0036] If M consecutive operations are marked as abnormal, the blocking mechanism of the real-time monitoring unit is triggered.

[0037] According to an online environment support system for an anti-cheating poker game machine provided by the present invention, the real-time monitoring unit detects abnormal data interaction between the game player's terminal and external programs or devices in the following ways:

[0038] Through the traffic analysis module, using deep packet inspection technology, parse the network traffic data packets of the game player's terminal, and extract the packet header information including the source IP, destination IP, and port number, as well as the payload content including the protocol type and encryption identifier;

[0039] Among them, identify abnormal traffic patterns through a rule matching algorithm, including:

[0040] The communication frequency with unknown external IPs exceeds a preset threshold;

[0041] Data transmission behavior on non-standard ports, at least including the game player's terminal using the HTTP port to send non-HTTP protocol data;

[0042] Combined with a random forest classifier, train a classification model based on historical traffic data, and predict the risk level of new traffic in real time. When the risk level exceeds the threshold, trigger an alarm.

[0043] According to an online environment support system for an anti-cheat poker gaming machine provided by the present invention, generate a static device fingerprint through the device fingerprint module, including the hardware information and the hash value of the software environment; track the dynamic device fingerprint, monitor the device behavior characteristics, generate a behavior sequence and calculate the similarity with the known normal behavior pattern. When the similarity is lower than the threshold, mark it as an abnormal device; if the device fingerprint is marked as abnormal, restrict the game permission of the device.

[0044] Through the process monitoring module, monitor the memory space of the game player's terminal process in real time, detect whether there is an injected DLL module or abnormal memory segment. If detected, terminate the game process; intercept sensitive function calls through the API Hook technology, record the call stack and match the known cheat tool feature library. If the match is successful, mark it as a cheating behavior; construct a process relationship graph, identify the processes abnormally associated with the game player's terminal, and if there is an unauthorized process, block its communication and report it.

[0045] According to an online environment support system for an anti-cheat poker gaming machine provided by the present invention, it further includes an abnormal response and blocking strategy:

[0046] Implement hierarchical blocking: The primary blocking is to restrict the network access permission of the game player's terminal, and the advanced blocking is to terminate the game process, ban the device fingerprint or IP address, and trigger an artificial review process;

[0047] Record detailed logs of the blocking operation, including the timestamp, abnormal type, associated device fingerprint, and IP address, for subsequent auditing and analysis.

[0048] According to an online environment support system for an anti-cheat poker gaming machine provided by the present invention, the online environment support module specifically realizes the support for providing an online game environment in the following ways:

[0049] The online game environment support function is split into multiple independent microservices, including a matching service, a state synchronization service, and an event processing service;

[0050] The matching service implements real-time matching based on the player's skill score and network latency using the Elo algorithm and generates a matching result log; the state synchronization service broadcasts game state data with a latency of less than 100 ms through the WebSocket or QUIC protocol; the event processing service receives player operation events, triggers subsequent game logic, and records the event processing timestamp;

[0051] Among them, a game logic processing unit is deployed at the network edge node close to the player to cache the player's state data and predict the player's operations; if the predicted operation is inconsistent with the server's confirmation result, a rollback mechanism is triggered to restore to the game state confirmed by the server; the edge node synchronizes the cached data to the core server regularly to ensure data consistency;

[0052] Moreover, the loads of each microservice are monitored in real time, and the resource allocation is dynamically adjusted based on the load metrics; when the load is high, the resource requirements of the matching service and the state synchronization service are prioritized to ensure that the matching latency is less than 500 ms and the state synchronization latency is less than 100 ms.

[0053] According to an online environment support system for an anti-cheat poker gaming machine provided by the present invention, the cloud data synchronization module specifically realizes the cloud synchronization and storage of user data through the following methods: through a distributed database and incremental synchronization technology:

[0054] Distributed database architecture: The data sharding technology is adopted to store data shards on different database nodes according to the user ID or geographical location; the Paxos or Raft protocol is used to ensure the consistency of multi-copy data, improve the fault tolerance and availability of the system; the user requests are distributed to different database nodes through a load balancer to achieve load balancing;

[0055] Incremental synchronization technology: The Change Data Capture technology is used to capture the change operations in the database, including insert, update, and delete; the captured change logs are transmitted to the cloud database node through a message queue; the change logs are applied on the cloud database node to update the data state and ensure the consistency of the cloud data and the local data;

[0056] Conflict handling and data consistency: Data conflicts are detected during the synchronization process, such as the situation of modifying the same data item simultaneously; the conflicts are resolved by adopting a merging strategy or preferentially adopting the latest data to ensure data consistency; data verification operations are performed regularly to verify the consistency of the cloud data and the local data, and data inconsistency problems are discovered and repaired in a timely manner.

[0057] As can be seen, compared with the prior art, the present invention has the following beneficial effects:

[0058] 1. Through the synergistic effect of the AI behavior analysis algorithm unit and the real-time monitoring unit, the present invention constructs a multi-level real-time anti-cheating system. Based on a preset behavior feature library, the AI behavior analysis algorithm uses a machine learning model to deeply mine the player operation data, and can accurately identify abnormal patterns (such as frequent score switching, abnormal amount sequences, etc.), effectively curbing new cheating means such as programmed cheating and collaborative cheating. The real-time monitoring unit, through traffic analysis, device fingerprint technology and process monitoring, real-time blocks the communication between the game player terminal and external cheating programs or devices, cutting off the access path of cheating tools from the network level and ensuring the fairness of the game process.

[0059] 2. The present invention combines encryption technology and blockchain technology to perform full-link encryption on the communication links between the control server and the cloud server, the game player terminal, the scoring server, and the card dealer. Encryption technology ensures that data is not stolen or tampered with during transmission, while the distributed ledger feature of blockchain technology further enhances the immutability and traceability of data, providing double security guarantees for sensitive information such as player scores and operation records, and effectively preventing data leakage and malicious tampering.

[0060] 3. The cloud data synchronization module, through a distributed database architecture, dispersedly stores user data on multiple nodes, significantly improving data read and write performance and fault tolerance. The distributed database supports horizontal expansion and can flexibly handle the massive data storage requirements in the high-concurrency scenario of online games, avoiding data loss or service interruption caused by a single point of failure. The module adopts incremental synchronization technology, only transmitting the changed part of the data instead of the full amount of data, greatly reducing network bandwidth occupancy and synchronization latency. This technology is especially suitable for online game scenarios with high real-time requirements, ensuring the fast and accurate synchronization of player scores, historical records and other data between the cloud and the local server, and providing real-time data support for functions such as cross-platform games and leaderboard updates.

[0061] 4. The system adopts a modular architecture design. The online environment support module, the cloud data synchronization module, and the information security mechanism module can all be independently deployed and upgraded, reducing the system coupling degree and facilitating flexible function expansion according to business requirements. For example, new AI algorithm models or security protocols can be quickly integrated without large-scale adjustment of the overall architecture.

[0062] 5. Through cloud data synchronization and standardized communication protocols, the system supports multi-terminal (PC, mobile, smart device) access, allowing players to seamlessly switch devices and continue the game. Meanwhile, the distributed database and incremental synchronization technology ensure cross-platform data consistency, avoiding issues such as lost points or unsynchronized progress due to device switching, and significantly enhancing the user experience.

[0063] 6. The real-time monitoring unit discovers and blocks cheating behaviors in real time through automated traffic analysis and process monitoring, reducing the reliance on manual review and lowering operating costs. At the same time, the system log and blockchain evidence storage function provide non-repudiable audit evidence for the operator, facilitating the quick tracing of cheating incidents and the taking of measures. The massive user behavior data stored in the cloud data synchronization module can provide a basis for in-depth analysis for the operator. By mining data such as player habits and game duration, the operator can formulate more precise marketing strategies, risk warning mechanisms, and personalized services, improving user retention rates and profitability.

[0064] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. Description of the Drawings

[0065] Figure 1 It is a schematic diagram of an embodiment of an online environment support system for an anti-cheating poker gaming machine of the present invention. Specific Embodiments

[0066] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without making creative efforts based on the embodiments in the present invention fall within the protection scope of the present invention.

[0067] The mention of "embodiments" in this document means that the specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The phrase does not necessarily refer to the same embodiment at every position in the specification, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0068] Refer to Figure 1 , this embodiment provides an online environment support system for an anti-cheating poker gaming machine. The anti-cheating poker gaming machine (patent name: Anti-cheating Poker Gaming Machine, application number: 200510033440.8) includes a scoring server, a control server, and a game player terminal. The system includes:

[0069] The online environment support module is deployed on the control server and is used to provide support for the online game environment and a real-time anti-cheat mechanism.

[0070] The cloud data synchronization module is deployed on the control server and communicates with the cloud server at the same time. Through a distributed database and incremental synchronization technology, it realizes the cloud synchronization and storage of user data, ensuring data consistency and real-time between multiple devices. Among them, user data includes account information, game records, asset status, and behavior logs.

[0071] The information security mechanism module is deployed on the communication links between the control server and the cloud server, as well as between the control server and the game player terminals, score servers, and card dealers. This module uses encryption technology and blockchain technology to ensure the security of user data transmission and storage.

[0072] Among them, the real-time anti-cheat mechanism includes:

[0073] The AI behavior analysis algorithm unit is deployed on the computing unit of the control server and is configured to, based on a preset behavior feature library, perform real-time analysis on the operation behavior data of users through a machine learning model to identify abnormal behavior patterns. Such patterns include, but are not limited to: a significant deviation of the amount from the player's historical behavior statistical data, a frequency exceeding the preset threshold, and an unreasonable match between the time and the game process.

[0074] The real-time monitoring unit is deployed on the network layer of the control server and is configured to, through traffic analysis, device fingerprint technology, and process monitoring, detect abnormal data interactions between the game player terminals and external programs or devices in real time, identify and block the access of cheating tools. Cheating tools include cheating software, multi-account collaboration tools, and automated scripts.

[0075] In this embodiment, the information security mechanism module includes:

[0076] The encryption technology unit is configured to use a combination of symmetric encryption and asymmetric encryption to encrypt user data in transmission using the SSL / TLS protocol. Among them, asymmetric encryption is used for key exchange, and symmetric encryption is used for data encryption. Sensitive data in storage is encrypted using the AES-256 algorithm, and the key is stored in a hardware security module or a key management system.

[0077] The blockchain recording unit is configured to generate hash values for key operation data (including records, settlement results, and abnormal behavior marks) and store them in the blockchain. The hash values are generated through the SHA-256 algorithm. The block data includes a timestamp, an operation type, and a user identifier, ensuring that the data is tamper-proof and traceable. Among them, the blockchain adopts a consortium chain architecture, and the nodes are deployed on the control server, the cloud server, and a third-party auditing agency.

[0078] The cloud data synchronization unit is configured to combine an access control policy with an audit log mechanism to monitor access behaviors of cloud data in real time and verify permissions. The access control policy is based on the RBAC model.

[0079] Furthermore, the encryption technology unit is further configured as follows: the SSL / TLS protocol version is TLS1.3, supporting forward secrecy; the symmetric encryption adopts the AES-GCM mode to ensure data confidentiality and integrity.

[0080] Furthermore, the blockchain recording unit is further configured as follows: the consensus mechanism adopts PBFT or PoA to ensure efficient consensus and immutability of block data; the data integrity is verified through the Merkle tree structure to support fast traceability of historical operation records.

[0081] Furthermore, the cloud data synchronization unit is further configured as follows: the access control policy combines user identity, device fingerprint, and operation context for dynamic risk scoring; high-risk access requests trigger a secondary authentication mechanism, such as SMS verification codes or biometrics.

[0082] Furthermore, the audit log mechanism is further configured as follows: the log content includes operation time, user ID, IP address, operation type, and result; it supports a real-time alert function, automatically triggering a security response when detecting abnormal access behaviors.

[0083] In this embodiment, the behavior feature library of the AI behavior analysis algorithm unit is constructed in the following manner:

[0084] Collect player behavior data within a preset time period, including operation time, amount, operation frequency, and device information; preprocess the behavior data, including denoising, normalization, and feature extraction, to generate an initial feature set;

[0085] Use an unsupervised learning algorithm (such as DBSCAN clustering) to perform clustering analysis on the initial feature set, identify normal behavior patterns, and generate a basic feature library; combine a supervised learning algorithm (such as an XGBoost classifier) and use the labeled cheating behavior data to train the basic feature library to generate an advanced feature library containing abnormal behavior features.

[0086] Collect newly generated player behavior data in real time and incrementally update the model parameters of the advanced feature library through an online learning algorithm (such as stochastic gradient descent);

[0087] Set up a feedback verification module. When the AI behavior analysis algorithm unit marks a certain behavior as abnormal, trigger an artificial review process; if the review confirms that the behavior is a cheating behavior, extract its features and add them to the advanced feature library;

[0088] Perform a full verification of the feature library at regular intervals (e.g., every 24 hours), remove redundant features, and optimize feature weights.

[0089] Among them, the behavior feature library includes a basic feature layer and an advanced feature layer. The basic feature layer is used to store general behavior statistics (such as average amount, standard deviation of operation intervals), and the advanced feature layer is used to store time series patterns (such as operation sequence Markov chains) and association rules (such as the mapping relationship between device fingerprints and abnormal behaviors).

[0090] In this embodiment, the AI behavior analysis algorithm unit performs real-time analysis on the user's operation behavior data through the following machine learning models to identify abnormal behavior patterns:

[0091] Adopt a hybrid model structure, including a time series feature extraction module and a non-time series feature processing module; among them, the time series feature extraction module is a long short-term memory network LSTM, configured to receive the time series data sequence of the player's operation behavior, including amount, operation time, operation type, and output a time series feature vector; the non-time series feature processing module is an extreme gradient boosting tree XGBoost, configured to receive static feature data and the time series feature vector output by the LSTM. The static feature data includes historical behavior statistics and device fingerprint information, and fuses them to generate an anomaly score.

[0092] Among them, the time series features include: the amount sequence, time interval sequence, and operation type encoding sequence of the past N times; the static features include: the player's historical average amount, standard deviation of operation frequency, and device unique identifier (such as the hash value of the hardware ID).

[0093] During model training and optimization, use historical behavior data (including normal and cheating labels) containing normal and cheating labels to perform end-to-end training on the hybrid model. The loss function is weighted cross-entropy (assigning higher weights to cheating samples), adopt an online learning mechanism, regularly (e.g., every hour) update the model parameters with new data, and prevent overfitting through the early stopping strategy EarlyStopping.

[0094] Dynamically adjust the anomaly score threshold, and the threshold calculation formula is:

[0095] Threshold = α · Global average score + (1 - α) · Standard deviation of the player's historical score

[0096] Among them, α is the weight coefficient, and the global average score is calculated based on the real-time data of all players;

[0097] When the anomaly score exceeds the dynamic threshold, it is marked as an abnormal behavior;

[0098] If M consecutive operations (e.g., 3 times) are marked as abnormal, trigger the blocking mechanism of the real-time monitoring unit.

[0099] In this embodiment, the real-time monitoring unit detects abnormal data interaction between the game player terminal and external programs or devices in the following ways:

[0100] Through the traffic analysis module, using deep packet inspection technology, parse the network traffic data packets of the game player terminal, and extract the packet header information including source IP, destination IP, and port number, as well as the payload content including protocol type and encryption identifier;

[0101] Among them, identify abnormal traffic patterns through rule matching algorithms, including:

[0102] The communication frequency with unknown external IPs exceeds a preset threshold (such as 10 times per second);

[0103] Data transmission behaviors on non-standard ports, at least including the game player terminal using the HTTP port to send non-HTTP protocol data;

[0104] Combined with a random forest classifier, train a classification model based on historical traffic data, and predict the risk level of new traffic in real time. When the risk level exceeds a threshold (such as 0.8), trigger an alarm.

[0105] Generate a static device fingerprint through the device fingerprint module, including the hash values of hardware information (such as CPU serial number, hard disk ID, MAC address) and software environment (such as operating system version, browser UA); track the dynamic device fingerprint, monitor the device behavior characteristics, such as mouse movement trajectory, key press frequency, sensor data, generate a behavior sequence and calculate the similarity with known normal behavior patterns. When the similarity is lower than a threshold (such as 0.6), mark it as an abnormal device; if the device fingerprint is marked as abnormal, restrict the game permissions of the device, such as prohibiting login and restricting operations.

[0106] Through the process monitoring module, real-time monitor the memory space of the game player terminal processes, detect whether there are injected DLL modules or abnormal memory segments. If detected, terminate the game process; intercept sensitive function calls through API Hook technology, such as network communication APIs and file operation APIs, record the call stack and match the known cheat tool feature library. If the match is successful, mark it as a cheating behavior; construct a process relationship graph to identify processes abnormally associated with the game player terminal (such as parent-child processes, network communication associations). If there are unauthorized processes, block their communication and report it.

[0107] In this embodiment, there is also an abnormal response and blocking strategy:

[0108] Implement hierarchical blocking: The primary blocking is to restrict the network access permissions of the game player terminal (such as blocking communication with abnormal IPs), and the advanced blocking is to terminate the game process, ban the device fingerprint or IP address, and trigger an artificial review process;

[0109] Block the operation record to detailed logs, including timestamps, exception types, associated device fingerprints, and IP addresses, for subsequent auditing and analysis.

[0110] In this embodiment, the online environment support module specifically provides support for the online game environment in the following ways:

[0111] Split the online game environment support function into multiple independent microservices, including a matching service, a status synchronization service, and an event handling service;

[0112] The matching service, based on the player's skill score and network latency, uses the Elo algorithm to achieve real-time matching and generate matching result logs; the status synchronization service broadcasts game status data, including player positions and hand information, with a latency of less than 100 ms through the WebSocket or QUIC protocol; the event handling service receives player operation events, such as discarding cards, triggers subsequent game logic (such as settlement and animation playback), and records the event handling timestamp.

[0113] Among them, deploy a game logic processing unit at the network edge node close to the player, cache the player's status data, and predict the player's operations; if the predicted operations are inconsistent with the server's confirmation results, trigger a rollback mechanism to restore to the game state confirmed by the server; the edge node regularly synchronizes the cached data to the core server to ensure data consistency.

[0114] Adopt a multi-channel communication strategy. The main channel (TCP) transmits reliable data (such as settlement results), and the secondary channel (UDP) transmits real-time data (such as player operations); implement the function of reconnecting after disconnection. After the player disconnects, the edge node saves the state snapshot of the player. When reconnecting, quickly restore the game progress through the snapshot, and the restoration time does not exceed 3 seconds.

[0115] Moreover, monitor the load of each microservice in real time, and dynamically adjust resource allocation based on load metrics (such as CPU usage rate and request queue length); when the load is high, prioritize ensuring the resource requirements of the matching service and the status synchronization service to ensure that the matching latency is less than 500 ms and the status synchronization latency is less than 100 ms.

[0116] In this embodiment, the cloud data synchronization module specifically realizes the cloud synchronization and storage of user data through a distributed database and incremental synchronization technology in the following ways:

[0117] Distributed database architecture: Adopt data sharding technology to store data shards on different database nodes according to user IDs or geographical locations; use the Paxos or Raft protocol to ensure the consistency of multi-copy data, improve the fault tolerance and availability of the system; distribute user requests to different database nodes through a load balancer to achieve load balancing;

[0118] Incremental Synchronization Technology: Utilize Change Data Capture technology to capture change operations in the database, including insertions, updates, and deletions; transmit the captured change logs to the cloud database node through a message queue (such as Kafka); apply the change logs on the cloud database node to update the data status and ensure the consistency between cloud data and local data;

[0119] Conflict Handling and Data Consistency: Detect data conflicts during the synchronization process, such as the situation of modifying the same data item simultaneously; adopt a merge strategy or give priority to the latest data to resolve conflicts and ensure data consistency; regularly perform data verification operations to verify the consistency between cloud data and local data, and promptly discover and fix data inconsistency problems.

[0120] Performance Optimization and Fault Tolerance Mechanism: Utilize multi-threading or distributed computing technology to process synchronization tasks in parallel to improve synchronization efficiency; compress the transmitted change logs to reduce network bandwidth consumption; implement fault tolerance mechanisms such as automatic retry and failover to ensure the reliability and stability of the synchronization process.

[0121] Specifically, the online environment support module is mainly deployed on the control server. As the core coordination module of the entire system, it is responsible for coordinating the communication and data interaction between the cloud synchronization module, AI behavior analysis module, real-time monitoring module and the scoring server, card dealer, and game player terminals, ensuring data synchronization and smooth processes between modules, and improving the overall operation efficiency and stability of the system.

[0122] The cloud synchronization module is deployed on the control server and communicates with the cloud server. It regularly encrypts and uploads data such as player scores and operation records to the cloud server to achieve remote backup and storage of data. At the start of the game, it pulls the latest player score status from the cloud server to ensure data timeliness and consistency. It supports the resume function of interrupted transfer to ensure data is not lost during network fluctuations or connection interruptions.

[0123] The AI behavior analysis module is deployed on the computing unit of the control server to monitor and analyze players' operation behaviors in real time, collect operation data of players during the game, such as amount, frequency, score selection, etc. Based on machine learning algorithms (such as random forest, LSTM, etc.), train an abnormal behavior detection model to perform real-time analysis on the collected data. Identify abnormal patterns or behaviors (such as frequently switching scores, abnormal amount sequences, etc.), and trigger alarms or take corresponding measures. The model training data should include samples of normal and abnormal behaviors to improve the accuracy and generalization ability of the model. Regularly update and optimize the model to adapt to new cheating methods and game environments. Design reasonable feature extraction and selection methods to improve the computing efficiency and accuracy of the model.

[0124] The real-time monitoring module is deployed at the network layer of the control server to monitor the communication between the game client and external programs, detect abnormal communication between the game client and external programs (such as cheating software), such as data transmission, function calls, etc. Once abnormal communication is detected, the connection is immediately blocked, and the relevant devices or accounts are banned. The deep packet inspection technology (DPI) is used to analyze the communication content in real time to ensure the accurate identification of abnormal behaviors. Efficient abnormal detection algorithms and strategies are designed to ensure the rapid response and blocking of abnormal behaviors, and work in coordination with the cloud synchronization module and the AI behavior analysis module to achieve multi-dimensional anti-cheating protection.

[0125] In practical applications, ensure that the control server, score server, game player terminal, and card dealer are correctly connected to the local area network; check whether the identification device in the card dealer is working properly and can verify the authenticity of the playing cards. Install the online environment support module, cloud synchronization module, AI behavior analysis module, real-time monitoring module, and information security mechanism module on the control server; configure the connection parameters and communication protocols of each module to ensure that they can communicate and interact with data normally, and conduct functional tests on each module to ensure that they can work properly and meet the requirements. Conduct system joint debugging to test the collaborative working ability between modules, conduct comprehensive functional tests and stress tests to ensure that the system can still run stably under high load, optimize and adjust the system according to the test results to improve the performance and stability of the system; put the system into operation, open the game service to players, monitor the running status and performance indicators of the system in real time, handle abnormal situations in a timely manner, regularly collect player feedback and opinions, and continuously optimize and improve the system.

[0126] In summary, the online environment support system of the present invention significantly improves the fairness, security, and operation efficiency of the anti-cheating poker gaming machine through the deep integration of the real-time anti-cheating mechanism, cloud data synchronization, and information security technology. Its technical advantages are not only reflected in the effective containment of new cheating means, but also provide an expandable and reusable solution for the industry through data-driven and modular design, with significant social and commercial value.

[0127] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0128] The above embodiments are only the preferred embodiments of the present invention and cannot be used to limit the scope of protection of the present invention. Any non-substantive changes and substitutions made by those skilled in the art based on the present invention belong to the scope required to be protected by the present invention.

Claims

1. An online environment support system for an anti-cheating poker game machine, the game machine comprising a scoring server, a control server and a game player terminal, characterized in that: The system includes: The online environment support module is deployed on the control server to provide support for the online game environment and real-time anti-cheating mechanism; The cloud data synchronization module is deployed on the control server and communicates with the cloud server at the same time, realizing cloud synchronization and storage of user data through distributed database and incremental synchronization technology; The information security mechanism module is deployed in the communication link between the control server and the cloud server, as well as the communication link between the control server and the game player terminal, the scoring server, and the card dealer. This module uses encryption technology and blockchain technology to ensure the security of user data transmission and storage; Among them, the real-time anti-cheating mechanism includes: The AI ​​behavior analysis algorithm unit is deployed on the computing unit of the control server and is configured to analyze the user's operation behavior data in real time based on a preset behavior feature library through a machine learning model to identify abnormal behavior patterns; The real-time monitoring unit is deployed at the network layer of the control server and is configured to detect abnormal data interactions between game player terminals and external programs or devices in real time through traffic analysis, device fingerprint technology and process monitoring, and identify and block access to cheating tools.

2. The system according to claim 1, characterized in that The information security mechanism module includes: The encryption technology unit is configured to use a combination of symmetric and asymmetric encryption to encrypt user data in transit using the SSL / TLS protocol and to encrypt sensitive data in storage using the AES-256 algorithm; A blockchain recording unit, configured to generate a hash value of key operation data and store it in the blockchain to ensure that the data cannot be tampered with and is traceable; The cloud data synchronization unit is configured to combine access control policies with audit log mechanisms to conduct real-time monitoring and permission verification of cloud data access behaviors to prevent unauthorized access.

3. The system according to claim 1, characterized in that The behavior feature library of the AI ​​behavior analysis algorithm unit is constructed in the following way: Collecting player behavior data within a preset time period, including operation time, amount, operation frequency and device information; preprocessing the behavior data, including denoising, normalization and feature extraction, to generate an initial feature set; An unsupervised learning algorithm is used to perform cluster analysis on the initial feature set, identify normal behavior patterns, and generate a basic feature library. Combined with a supervised learning algorithm, the basic feature library is trained using labeled cheating behavior data to generate an advanced feature library containing abnormal behavior features. Collect newly generated player behavior data in real time and incrementally update the model parameters of the advanced feature library through online learning algorithms; Set up a feedback verification module. When the AI ​​behavior analysis algorithm unit marks a behavior as abnormal, it triggers the manual review process. If the review confirms that the behavior is cheating, its features are extracted and added to the advanced feature library. Regularly perform full verification of the feature library, remove redundant features and optimize feature weights. The behavior feature library includes a basic feature layer and an advanced feature layer. The basic feature layer is used to store general behavior statistics, and the advanced feature layer is used to store time series patterns and association rules.

4. The system according to claim 3, characterized in that The AI ​​behavior analysis algorithm unit uses the following machine learning model to analyze the user's operation behavior data in real time and identify abnormal behavior patterns: A hybrid model structure is adopted, including a time series feature extraction module and a non-time series feature processing module; wherein the time series feature extraction module is a long short-term memory network LSTM, configured to receive a time series data sequence of the player's operation behavior, including the amount, operation time, and operation type, and output a time series feature vector; the non-time series feature processing module is an extreme gradient boosting tree XGBoost, configured to receive static feature data and the time series feature vector output by LSTM, the static feature data includes historical behavior statistics, device fingerprint information, and fuses them to generate anomaly scores. Among them, the time series features include: the amount sequence of the past N times, the time interval sequence, and the operation type coding sequence; the static features include: the player's historical average amount, the standard deviation of the operation frequency, and the device unique identifier.

5. The system according to claim 4, characterized in that: During model training and optimization, the hybrid model is trained end-to-end using historical behavior data containing normal and cheating labels. The loss function is weighted cross entropy. An online learning mechanism is used to regularly update model parameters with new data, and an early stopping strategy is used to prevent overfitting. Dynamically adjust the anomaly scoring threshold. The threshold calculation formula is: Threshold = α·global average rating + (1-α)·standard deviation of player historical ratings Among them, α is the weight coefficient, and the global average score is calculated based on the real-time data of all players; When the anomaly score exceeds the dynamic threshold, it is marked as abnormal behavior; If M consecutive operations are marked as abnormal, the blocking mechanism of the real-time monitoring unit is triggered.

6. The system according to claim 1, characterized in that The real-time monitoring unit detects abnormal data interaction between the game player terminal and the external program or device in real time in the following manner: The traffic analysis module uses deep packet inspection technology to parse the network traffic data packets of the game player's terminal, extracting the data packet header information including the source IP, destination IP, port number, and the payload content including the protocol type and encryption identifier; Among them, the rule matching algorithm is used to identify abnormal traffic patterns, including: The frequency of communication with unknown external IP exceeds the preset threshold; Data transmission via non-standard ports, including at least the game player terminal sending non-HTTP protocol data using HTTP ports; Combined with the random forest classifier, the classification model is trained based on historical traffic data to predict the risk level of new traffic in real time, and an alarm is triggered when the risk level exceeds the threshold.

7. The system according to claim 6, characterized in that: Generate static device fingerprints through the device fingerprint module, including hash values ​​of hardware information and software environment; track dynamic device fingerprints, monitor device behavior characteristics, generate behavior sequences and calculate the similarity with known normal behavior patterns. When the similarity is lower than the threshold, it is marked as an abnormal device; if the device fingerprint is marked as abnormal, the game permissions of the device are restricted. The process monitoring module monitors the memory space of the game player's terminal process in real time to detect whether there is an injected DLL module or abnormal memory segment. If detected, the game process is terminated; Intercept sensitive function calls through API Hook technology, record the call stack and match it with the signature library of known cheating tools. If the match is successful, it will be marked as cheating behavior; Build a process relationship graph to identify processes that are abnormally associated with game player terminals. If there are unauthorized processes, block their communication and report them.

8. The system according to claim 7, characterized in that It also includes an abnormal response and blocking strategy: Implement graded blocking: primary blocking is to restrict the network access rights of game players’ terminals, and advanced blocking is to terminate the game process, block device fingerprints or IP addresses, and trigger a manual review process; Blocking operations record detailed logs, including timestamp, anomaly type, associated device fingerprint and IP address, for subsequent auditing and analysis.

9. The system according to any one of claims 1 to 8, characterized in that: The online environment support module specifically implements the support of the online game environment in the following ways: Split the online game environment support functions into multiple independent microservices, including matching services, state synchronization services, and event processing services; The matching service uses the Elo algorithm to achieve real-time matching based on player skill scores and network latency, and generates a matching result log; the state synchronization service broadcasts game state data with a delay of less than 100ms through the WebSocket or QUIC protocol; the event processing service receives player operation events, triggers subsequent game logic, and records event processing timestamps; Among them, the game logic processing unit is deployed at the network edge node close to the player to cache the player status data and predict the player operation; if the predicted operation is inconsistent with the server confirmation result, the rollback mechanism is triggered to restore the game status confirmed by the server; the edge node regularly synchronizes the cache data to the core server to ensure data consistency; In addition, the load of each microservice is monitored in real time, and resource allocation is dynamically adjusted based on load indicators. When the load is high, the resource requirements of the matching service and the state synchronization service are prioritized to ensure that the matching delay is less than 500ms and the state synchronization delay is less than 100ms.

10. The system according to claim 1, characterized in that The cloud data synchronization module specifically implements cloud synchronization and storage of user data through distributed database and incremental synchronization technology in the following ways: Distributed database architecture: Use data sharding technology to store data shards on different database nodes based on user ID or geographic location; use Paxos or Raft protocols to ensure the consistency of multiple copies of data and improve the fault tolerance and availability of the system; distribute user requests to different database nodes through a load balancer to achieve load balancing; Incremental synchronization technology: Use Change Data Capture technology to capture change operations in the database, including insert, update, and delete; transmit the captured change log to the cloud database node through the message queue; apply the change log on the cloud database node to update the data status and ensure the consistency of cloud data and local data; Conflict handling and data consistency: Detect data conflicts during the synchronization process, such as when the same data item is modified at the same time; use a merge strategy or prioritize the latest data to resolve conflicts and ensure data consistency; perform data verification operations regularly to verify the consistency of cloud data and local data, and promptly discover and fix data inconsistencies.

Citation Information

Patent Citations

  • Cheat-proof playing cards game machine

    CN1830511A