Cloud mobile phone equipment fingerprint disguising method and related equipment
By generating a virtual parameter set through Logistic chaos mapping and kernel-level injection technology, the cloud phone device fingerprint is dynamically updated, which solves the problem that the cloud phone device fingerprint is easy to be tracked and improves the anonymity and security of the device.
Patent Information
- Application Number
- CN202510997006.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-18
- Publication Date
- 2025-10-10
AI Technical Summary
The fingerprints of cloud phone devices present static characteristics and are easily tracked by attackers through multi-dimensional fingerprint association and behavior pattern analysis. Existing technologies are difficult to defend against continuous tracking attacks, and static parameter replacements are easily detected by historical data.
By obtaining hardware entropy source data, a virtual parameter set is generated using Logistic chaos mapping, and then covered to multi-level system interfaces through kernel-level injection operations. Combined with the lifecycle model, dynamic updates are performed to ensure parameter unpredictability and compliance with device parameter rules.
Effectively hide the real device fingerprint, prevent attackers from tracking through multiple channels, improve the anonymity and security of cloud phone devices, and enhance anti-fraud and privacy protection capabilities.
Smart Images

Figure CN120768541A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cloud phone security technology, and in particular to a cloud phone device fingerprint disguise method and related equipment. Background Art
[0002] Cloud phone technology generally uses fixed hardware parameter configurations, resulting in static device fingerprints. Attackers can track devices through multi-dimensional fingerprint correlation, behavioral pattern analysis, and cloud-based profile matching, posing a serious threat to user privacy and anti-fraud security. In existing technologies, static parameter replacements are easily detected by historical data anomaly detection mechanisms; timestamp-based random algorithms struggle to ensure parameter unpredictability; and the lack of a dynamic runtime maintenance mechanism causes the obfuscation effect to decay over time. These issues render existing technologies ineffective in defending against persistent tracking attacks. Therefore, a method for camouflaging cloud phone device fingerprints is urgently needed to address the aforementioned technical issues. Summary of the Invention
[0003] The Summary of the Invention introduces a series of simplified concepts that will be further described in the Detailed Description of the Invention. The Summary of the Invention of this application is not intended to limit the key features and essential technical features of the claimed technical solution, nor is it intended to determine the scope of protection of the claimed technical solution.
[0004] In a first aspect, the present application provides a method for disguising a fingerprint of a cloud phone device, comprising:
[0005] Obtaining hardware entropy source data, wherein the hardware entropy source data includes current timestamp data, hardware unique identification hash value, and environmental noise sampling value;
[0006] Performing nonlinear transformation on hardware entropy source data based on a preset chaotic mapping algorithm to generate a virtual parameter set, wherein the virtual parameter set satisfies a preset device parameter rule;
[0007] Through kernel-level injection operations, virtual parameter sets are overlaid onto multi-level system interfaces of real device fingerprints;
[0008] Monitor the usage status of virtual parameter sets based on a preset lifecycle model and determine the trigger conditions for parameter updates;
[0009] When the parameter update triggering condition is met, the nonlinear transformation is re-executed to generate an updated virtual parameter set and overlay it to the multi-level system interface.
[0010] In some implementations, obtaining hardware entropy source data includes:
[0011] Get initial timestamp data based on the system clock;
[0012] Based on the preset time zone disturbance factor, the initial timestamp data is superimposed to generate the current timestamp data;
[0013] Process the hardware unique identifier based on a preset hash algorithm to generate a hardware unique identifier hash value;
[0014] Read environmental noise sampling values based on physical sensors;
[0015] The current timestamp data, the hardware unique identification hash value and the environmental noise sampling value are determined as the hardware entropy source data.
[0016] In some implementations, performing a nonlinear transformation on hardware entropy source data based on a preset chaotic mapping algorithm to generate a virtual parameter set includes:
[0017] Based on the Lyapunov exponent stability analysis, the value range of the fractal parameters of the preset chaos mapping algorithm is determined;
[0018] Initialize the initial iteration value of the chaotic sequence based on the hardware entropy source data;
[0019] Based on the value range of fractal parameters, the initial iteration value is iteratively calculated through Logistic chaotic mapping to generate a chaotic sequence;
[0020] Based on the chaotic sequence, an intermediate parameter set that conforms to the device parameter format is generated;
[0021] Based on the preset device parameter rules, the intermediate parameter set is formatted and a virtual parameter set is generated.
[0022] In some embodiments, a kernel-level injection operation is performed to overlay a virtual parameter set onto a multi-level system interface of a real device fingerprint, including:
[0023] Determine network layer coverage parameters, driver layer coverage parameters, and application layer coverage parameters based on the virtual parameter set;
[0024] Modify the metadata broadcast strategy of the network protocol stack based on the network layer coverage parameters;
[0025] Redirect device node read operations based on driver layer overlay parameters;
[0026] Based on application layer overlay parameters, system API calls are intercepted and return values are replaced.
[0027] In some embodiments, monitoring the usage status of the virtual parameter set based on a preset lifecycle model and determining a parameter update trigger condition includes:
[0028] Generate a historical parameter state set based on the usage status of the virtual parameter set;
[0029] Based on the state transition algorithm in the preset life cycle model, the current state transition probability of the historical parameter state set is calculated;
[0030] Based on the comparison result of the current state transition probability and the preset update threshold, the parameter update trigger condition is determined.
[0031] In some embodiments, when a parameter update trigger condition is met, re-performing the nonlinear transformation to generate an updated virtual parameter set and overlaying it to the multi-level system interface includes:
[0032] Based on the parameter update trigger condition, perform a virtual parameter update operation;
[0033] Based on the hardware entropy source data, a nonlinear transformation operation is performed through a preset chaotic mapping algorithm to generate an updated virtual parameter set;
[0034] Through kernel-level injection operations, the updated virtual parameter set is overwritten to multi-level system interfaces.
[0035] In a second aspect, the present application proposes a fingerprint disguise device for a cloud phone device, comprising:
[0036] A hardware data acquisition unit is used to acquire hardware entropy source data, wherein the hardware entropy source data includes current timestamp data, hardware unique identification hash value and environmental noise sampling value;
[0037] A virtual parameter generation unit performs nonlinear transformation on hardware entropy source data based on a preset chaotic mapping algorithm to generate a virtual parameter set, wherein the virtual parameter set satisfies a preset device parameter rule;
[0038] The system interface overlay unit is used to overlay the virtual parameter set to the multi-level system interface of the real device fingerprint through kernel-level injection operations;
[0039] A virtual parameter monitoring unit monitors the usage status of the virtual parameter set based on a preset lifecycle model and determines the parameter update triggering conditions;
[0040] The virtual parameter updating unit is used to re-execute the nonlinear transformation to generate an updated virtual parameter set and cover it to the multi-level system interface when the parameter update triggering condition is met.
[0041] In a third aspect, an electronic device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor is configured to implement the steps of the cloud phone device fingerprint disguise method of any one of the first aspects when executing the computer program stored in the memory.
[0042] In a fourth aspect, the present application proposes a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the cloud phone device fingerprint disguise method of any one of the first aspects.
[0043] In a fifth aspect, the present application proposes a computer program product, comprising a computer program, which, when executed by a processor, implements the cloud phone device fingerprint disguise method of any one of the first aspects.
[0044] In summary, this application generates a virtual parameter set through mixed modulation of Logistic chaotic mapping and hardware entropy source, and utilizes the nonlinear characteristics of chaotic mapping and the randomness of hardware entropy source to ensure that the generated virtual parameters are highly unpredictable and comply with the device parameter specifications; at the same time, it adopts kernel-level parameter injection technology to achieve multi-level parameter coverage by modifying the system call table, network protocol stack metadata, etc., which can effectively hide the real device fingerprint, prevent attackers from obtaining static features through multiple channels for tracking, improve the anonymity of cloud phone device fingerprints, and enhance security in anti-fraud, privacy protection and other scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present description. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:
[0046] Figure 1 A schematic diagram of a method for disguising fingerprints of a cloud phone device provided in an embodiment of the present application;
[0047] Figure 2 A schematic diagram of the structure of a fingerprint disguise device for a cloud phone device provided in an embodiment of the present application;
[0048] Figure 3 A schematic diagram of the structure of a disguised device for a cloud phone device fingerprint provided in an embodiment of the present application. DETAILED DESCRIPTION
[0049] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or that are inherent to these processes, methods, products or devices. The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the embodiments described are only part of the embodiments of the present application, not all of the embodiments.
[0050] See also Figure 1 , which is a flow chart of a method for disguising a fingerprint of a cloud phone device provided in an embodiment of the present application, which may specifically include:
[0051] S110, obtaining hardware entropy source data, wherein the hardware entropy source data includes current timestamp data, a hardware unique identification hash value, and an environmental noise sampling value;
[0052] For example, obtaining hardware entropy source data is the foundation for generating trusted virtual device parameters. This data, combined with multi-dimensional random information sources, provides an initial guarantee for the unpredictability of subsequent virtual parameters. This data covers information at different levels, including time, hardware characteristics, and environmental disturbances. By integrating multiple types of entropy sources, the lack of randomness associated with a single information source is avoided, laying a reliable random foundation for the generation of virtual parameter sets.
[0053] The current timestamp data, the hardware unique identifier hash value, and the ambient noise sampling value provide entropy from three dimensions: temporal dynamics, device association, and physical randomness. The timestamp changes naturally over time, the hardware unique identifier hash value is associated with the inherent characteristics of the device without directly exposing the original information, and the ambient noise sampling value is derived from the real-time fluctuations of the physical sensor. The combination of these three ensures that the hardware entropy source data is both dynamically changing and contains sufficient random perturbations to meet the diversity and randomness requirements of the initial entropy source for subsequent nonlinear transformations.
[0054] S120, performing nonlinear transformation on the hardware entropy source data based on a preset chaotic mapping algorithm to generate a virtual parameter set, wherein the virtual parameter set satisfies a preset device parameter rule;
[0055] For example, a nonlinear transformation is performed on the hardware entropy source data based on a preset chaotic mapping algorithm. By leveraging the inherent initial value sensitivity and pseudo-random properties of chaotic systems, the input entropy source data (timestamp, hardware hash value, environmental noise) is converted into a highly unpredictable chaotic sequence. This process leverages the ergodicity and mixing properties of chaotic mapping within a specific parameter range to ensure that the statistical characteristics of the output sequence approximate those of a true random signal, thereby providing mathematically untraceable protection for virtual device fingerprints.
[0056] The generated virtual parameter set must be forced to comply with the preset device parameter rules (such as IMEI encoding structure, MAC address format, etc.). The output range of the chaotic sequence is constrained by format conversion so that it can meet the syntax and semantic requirements of the operating system for hardware parameters while maintaining randomness. This not only avoids triggering system alarms due to parameter format anomalies, but also ensures that the virtual fingerprint cannot be reversely deduced through the rule engine.
[0057] S130, overlaying the virtual parameter set onto the multi-level system interface of the real device fingerprint through a kernel-level injection operation;
[0058] For example, the kernel, as the core of the operating system, can call all hardware resource access permissions and systems. When an attacker cross-verifies the device fingerprint through multi-level interfaces (network protocol stack metadata, device node files, system APIs), only by implementing unified interception and replacement at the kernel layer can the fingerprint association risk caused by inconsistent parameters at each level be completely avoided. The embodiment of the present application achieves atomic coverage of virtual parameters at the source of the data stream by modifying the system call table, redirecting the hardware abstraction layer access path, and hijacking the network protocol stack broadcast strategy, ensuring that no matter from which dimension the attacker collects device features, the same set of dynamically obfuscated virtual parameters is obtained.
[0059] The defense structure consists of synchronized coverage of multiple layers of system interfaces. The network layer modifies protocol stack metadata (such as MAC address broadcast policy) to block device association based on network packet characteristics. The driver layer redirects device node read operations (such as / sys / class / net / eth0 / address) so that physical hardware queries return virtual parameters. The application layer intercepts API calls (such as getDeviceId()) to achieve final disguise at the interface return value level. These three layers of coverage form a closed-loop defense chain, ensuring that virtual parameter sets replace real fingerprints throughout the entire chain, from data generation and transmission to access, completely eliminating static feature exposure points.
[0060] S140: Monitor the usage status of the virtual parameter set based on a preset lifecycle model and determine a parameter update trigger condition;
[0061] Exemplarily, the preset lifecycle model constructs a state transition network of virtual parameters through the Markov chain algorithm, abstracting the parameter usage status (such as call frequency and time decay characteristics) into discrete state nodes. The model calculates the transition probability between states based on the historical parameter state set (including the time series records of N consecutive parameter uses), thereby quantifying the confidence that the parameters maintain their validity under the current usage mode. It simulates the parameter update rules of real devices (such as the MAC address change cycle and the static persistence of IMEI) to ensure that the update behavior of virtual parameters conforms to the reasonable logic of physical devices, avoiding being identified by attackers due to abnormal update frequency.
[0062] Determining the triggering conditions for parameter updates relies on a dynamic assessment of state transition probabilities: The system monitors the usage status of the virtual parameter set (e.g., the number of API calls per unit time, network-layer broadcast frequency) in real time and maps it to the current state node of the Markov chain. The probability of this node transitioning to the "updated state" is calculated and compared with a preset update threshold. The triggering condition is only considered met when the probability exceeds the threshold (indicating that continued use of the current parameters will increase the risk of being linked). This mechanism implements aperiodic updates, making device fingerprints chaotic over time, completely disrupting analysis of attackers' behavioral patterns.
[0063] S150 : When the parameter update triggering condition is met, re-execute the nonlinear transformation to generate an updated virtual parameter set and cover it to the multi-level system interface.
[0064] For example, when the lifecycle model determines that the parameter update trigger conditions are met, the system immediately initiates a full update of the virtual parameter set. This process reuses the initial chaos generation mechanism and kernel injection architecture, dynamically generating a new generation of virtual parameter sets based on real-time hardware entropy source data through the same nonlinear transformation engine. Kernel-level injection operations then atomically overlay the new parameter sets onto multiple levels of system interfaces, ensuring the integrity and consistency of device fingerprints during the update process.
[0065] This dynamic update mechanism fundamentally undermines attackers' temporal correlation models: aperiodic parameter changes render device fingerprints chaotic over time, effectively defending against pattern recognition attacks based on historical data. Furthermore, the closed-loop update process enables runtime self-maintenance, overcoming the diminishing effectiveness of traditional static obfuscation schemes and ensuring that cloud phones remain anonymous.
[0066] In summary, in the embodiment of the present application, by fusing chaotic dynamic confusion and kernel-level real-time injection mechanism, the essential security of cloud mobile device fingerprint is improved: first, based on hardware entropy source data (timestamp disturbance factor, hardware hash value and physical environment noise), the virtual parameter set is generated by driving Logistic chaotic mapping. The mathematical unpredictability of the device fingerprint is ensured by the sensitivity and ergodicity of the initial value of the chaotic system, and the parameter reverse deduction based on historical data is completely prevented; secondly, the kernel-level multi-level covering technology is used to modify the network protocol stack metadata broadcast strategy, redirect the device node reading operation of the driver layer and intercept the application layer API return value, and a closed loop camouflage chain is built at the bottom of the operating system to block the attacker from realizing the device association through multi-dimensional interface cross verification; finally, the life cycle model driven by Markov chain is introduced to dynamically monitor the parameter usage state, and the virtual parameter set is updated through the aperiodic trigger mechanism, so that the device fingerprint presents chaotic characteristics in the time dimension, effectively breaking the behavior pattern analysis and LSTM time sequence modeling attack. The effective identification period of the device fingerprint is compressed to a single session level in the embodiment of the present application, while ensuring the compatibility of the operator parameter specification (such as the IMEI coding rule), reducing the system resource overhead, and providing sustainable anonymization protection capability for cloud mobile phones in anti-fraud and privacy sensitive scenarios.
[0067] In some examples, the hardware entropy source data is obtained, including:
[0068] Obtaining initial timestamp data based on a system clock;
[0069] Superimposing the initial timestamp data based on a preset time zone disturbance factor to generate current timestamp data;
[0070] Processing the hardware unique identifier based on a preset hash algorithm to generate a hardware unique identifier hash value;
[0071] Reading an environment noise sampling value based on a physical sensor;
[0072] Determining the current timestamp data, the hardware unique identifier hash value and the environment noise sampling value as the hardware entropy source data.
[0073] Illustratively, by calling the system clock interface provided by the operating system kernel, the original time count value recorded by the high-precision timer is obtained. The count value reflects the absolute time reference of the current system running, and its precision usually reaches the nanosecond level, providing a basic data source for time dimension dynamics.
[0074] The initial timestamp data is superimposed based on a preset time zone perturbation factor, aiming to enhance the randomness and unpredictability of the timestamp data. The preset time zone perturbation factor is a pre-set adjustment parameter based on the time offset characteristics and random perturbation rules of different time zones (for example, the random difference between UTC+8 and UTC-5). Its function is to break the monotonically increasing pattern of the initial timestamp. By superimposing this factor on the initial timestamp data, the generated current timestamp data retains the dynamic characteristics of time changes, while being difficult for attackers to predict due to the randomness of the perturbation factor. This effectively avoids the problem of insufficient entropy caused by a single time source and increases the complexity of the entropy source in the time dimension.
[0075] The hardware unique identifier is processed based on a preset hash algorithm to generate a hardware unique identifier hash value. The core is to achieve desensitization and entropy value conversion of hardware features. The preset hash algorithm (such as HMAC-SHA256) is one-way and collision-resistant, and can convert the original hardware unique identifier (such as CPU serial number, baseband chip ID, etc.) into a fixed-length hash value (such as 128 bits). This process not only retains the association between the hardware identifier and the device, ensuring that the generated virtual parameters can indirectly reflect the basic characteristics of the device to comply with the specifications, but also avoids the direct exposure of the original hardware identifier, preventing attackers from tracking the device through the original identifier. At the same time, the hash operation itself can also increase the randomness of the entropy source.
[0076] Reading environmental noise samples using physical sensors is a key step in introducing physical-level randomness. Physical sensors (such as CPU temperature sensors and memory controllers) can capture physical quantities with inherent randomness, including real-time CPU temperature fluctuations and instantaneous changes in memory usage. These environmental noise samples are affected by a variety of uncontrollable factors, such as the hardware's operating status and external environmental interference. Their variations are difficult to accurately model or predict, providing high physical-level randomness to the entropy source data. By incorporating these physical entropy sources into the hardware entropy source data, the unpredictability of the overall entropy source can be improved, providing a more reliable random foundation for the subsequent generation of virtual parameters.
[0077] Determining the current timestamp data, the hardware unique identifier hash value, and the ambient noise sampling value as hardware entropy source data enables the synergistic improvement of multi-dimensional entropy sources. Timestamp data provides temporal dynamics, the hardware unique identifier hash value provides a basis for device association, and the ambient noise sampling value provides physical randomness. These three contribute entropy values from different dimensions, together forming a set of entropy sources that are dynamic, correlated, and unpredictable. This multi-source fusion of entropy source data not only meets the chaotic mapping's high randomness requirements for initial entropy, ensuring the generated virtual parameters are highly unpredictable, but also ensures that the virtual parameters comply with device operating specifications, providing a solid foundation for the subsequent generation of virtual parameter sets and effectively improving the security and reliability of fingerprint camouflage for cloud phone devices.
[0078] In some instances, a nonlinear transformation is performed on the hardware entropy source data based on a preset chaotic mapping algorithm to generate a virtual parameter set, including:
[0079] Based on the Lyapunov exponent stability analysis, the value range of the fractal parameters of the preset chaos mapping algorithm is determined;
[0080] Initialize the initial iteration value of the chaotic sequence based on the hardware entropy source data;
[0081] Based on the value range of fractal parameters, the initial iteration value is iteratively calculated through Logistic chaotic mapping to generate a chaotic sequence;
[0082] Based on the chaotic sequence, an intermediate parameter set that conforms to the device parameter format is generated;
[0083] Based on the preset device parameter rules, the intermediate parameter set is formatted and a virtual parameter set is generated.
[0084] Exemplarily, the dynamic behavior characteristics of the Logistic chaotic mapping system are quantitatively evaluated through Lyapunov exponent stability analysis. The Lyapunov exponent characterizes the system's sensitive dependence on initial conditions, and when the exponent value is positive, it indicates that the system is in a chaotic state. In an embodiment of the present application, based on the bifurcation characteristic analysis in chaos theory, the critical range of fractal parameters that make the Lyapunov exponent continuously positive is determined. Specifically, it is verified through numerical simulation that when the fractal parameter is greater than 3.57, the system enters a strongly chaotic state and has ergodicity; at the same time, in order to avoid the system converging to a stable period, the upper limit of the fractal parameter is set to 4.0. It is thus determined that the value range of the fractal parameter is a continuous interval greater than 3.57 and not exceeding 4.0. The confirmation of this range provides a mathematical guarantee for the unpredictability of subsequent chaotic sequences.
[0085] The hardware entropy source data (including the current timestamp data, the hardware unique identifier hash value, and the ambient noise sampling value) is normalized and fused to generate the initial iteration value of the chaotic map. Specifically, a modulo-1 operation is performed on the timestamp data, mapping it to the interval [0, 1]. The 128-bit hardware hash value is converted to a floating point number and the decimal portion is taken. The ambient noise sampling value is linearly scaled to the range [-0.001, 0.001] as a micro-perturbation. The above three data components are weighted and summed according to a preset weight coefficient, and the result is used as the initial iteration value of the chaotic sequence. This process ensures that the initial value combines temporal dynamics, device correlation, and physical randomness, laying the foundation for the initial value sensitivity of the chaotic system.
[0086] In the range of fractal parameter values, a specific value (for example, 3.9) is selected, and an improved Logistic chaotic mapping is used for iterative calculation, that is, the product of the previous step iteration value and the product of the fractal parameter and 1 minus the previous step iteration value is superimposed with the environmental noise adjustment mechanism of the sine wave modulation term, and then the modulo operation is performed on 1; the environmental noise sampling value is introduced as an external disturbance term to avoid the chaotic sequence from falling into a short cycle; a preset number (such as 1000 times) of preheating iterations are performed to eliminate transient effects, and subsequent continuous output of stable chaotic sequences is performed. The finally generated chaotic sequence has a random-like distribution characteristic and long-term unpredictability.
[0087] The chaotic sequence is converted into device parameter prototype data, and the chaotic sequence sub-section is intercepted according to the target parameter length (such as 15 bits for IMEI); the chaotic value in the interval [0, 1] is mapped to the target numerical range (such as the 0-255 integer space of the MAC address); and the data section is combined according to the parameter type (such as the Android ID is converted into a 16-byte hexadecimal string). This process outputs an intermediate parameter set containing virtual IMEI, virtual MAC address and other elements, and the numerical characteristics meet the data format of the device parameters but do not yet meet the semantic rules.
[0088] The semantic layer constraint is applied to the intermediate parameter set, the virtual IMEI is verified to meet the manufacturer code allocation rules and check bit algorithm of 3GPP TS 23.003, the multicast identification bit (the least significant bit of the first bit) of the virtual MAC address is ensured to be 0, and the OUI registration prefix is matched, and the parameters conflicting with the operating system reserved value (such as all-zero address) are replaced. After forced correction by the rule engine, a virtual parameter set that meets the syntax structure and semantic specification is generated, which has both mathematical randomness and system compatibility.
[0089] In summary, the embodiments of the present application strictly constrain the dynamic behavior of the chaotic system by Lyapunov exponent, ensure that the fractal parameter is in the strong chaotic state interval, use multi-source entropy fusion initialization to improve the randomness of the initial value, improve the Logistic mapping combined with environmental noise disturbance to enhance the anti-analysis ability of the sequence, and use segmented mapping and rule checking to double protect the format compliance of the virtual parameters. Finally, the mathematical level realizes the irreversible confusion of the device fingerprint, effectively solves the defect that the traditional random algorithm is easy to be inversely deduced, and meets the syntax and semantic requirements of the operating system for the hardware parameters, providing a high-trust virtual parameter source for kernel-level dynamic camouflage.
[0090] In some examples, by kernel-level injection operation, the virtual parameter set is covered to the multi-level system interface of the real device fingerprint, including:
[0091] Based on the virtual parameter set, network layer coverage parameters, driver layer coverage parameters and application layer coverage parameters are determined;
[0092] Modify the metadata broadcast strategy of the network protocol stack based on the network layer coverage parameters;
[0093] Redirect device node read operations based on driver layer overlay parameters;
[0094] Based on application layer overlay parameters, system API calls are intercepted and return values are replaced.
[0095] For example, based on the structured characteristics of the virtual parameter set, network layer coverage parameters (such as virtual MAC addresses), driver layer coverage parameters (such as virtual baseband chip version numbers), and application layer coverage parameters (such as virtual Android IDs) are determined. This step uses the parameter classification engine to parse the semantic labels of the virtual parameter set and map different parameter types to corresponding system layers, ensuring that the coverage parameters at each layer strictly match the target interface, providing accurate input for subsequent targeted injection.
[0096] At the network layer, the virtual MAC address is written to the network stack's sk_buff structure by modifying the Linux kernel's netlink socket metadata broadcast policy. This involves rewriting the source address field in the data link layer frame header and disabling the Address Resolution Protocol (ARP) query function for the real hardware, ensuring that all outbound network packets carry the virtual MAC address. This action blocks MAC address-based device association attacks at the source of network communication, preventing attackers from obtaining real device fingerprints through traffic sniffing.
[0097] At the driver level, device node read operations are redirected to a virtual parameter set. Specifically, this involves hijacking the read() system call for device files such as / sys / class / net / eth0 / address, dynamically replacing the file operation function table (file_operations) via the kernel module. When a user-mode process reads the device node, it forces the driver layer to return overwritten parameters (such as a virtual SIM card serial number). This mechanism implements transparent interception at the hardware abstraction layer, ensuring that the data returned by the driver interface is consistent with the parameters broadcast by the network layer, eliminating cross-layer fingerprint verification vulnerabilities.
[0098] At the application level, system API calls are intercepted and their return values replaced. By modifying the entry addresses of functions such as getDeviceId() in the kernel system call table (sys_call_table), they are directed to custom processing routines. When an application calls the device information query API, the routine directly returns application-layer overlay parameters (such as a virtual IMEI) and skips the underlying hardware access process. This operation completes the final disguise at the application interface layer, forming a closed loop with full link coverage from network transmission, driver access, and application calls.
[0099] In summary, the kernel-level injection mechanism covers a multi-level atomic overlay to construct a defense depth for device fingerprint camouflage. The network layer modifies the protocol stack metadata to block device association based on network traffic; the driver layer redirects device node access to eliminate hardware query exposure points; and the application layer hijacks API return values to defend against user-space fingerprint collection tools. The three-layer cooperation ensures the consistency of the virtual parameter set output at each level of the operating system interface, solving the multi-dimensional fingerprint association risk caused by incomplete replacement in traditional solutions. At the same time, the kernel-level implementation ensures the real-time and atomicity of parameter replacement, avoiding state inconsistency problems during the update process, and providing continuous and reliable device anonymization capabilities for cloud phones.
[0100] In some examples, the usage state of the virtual parameter set is monitored based on a preset life cycle model to determine a parameter update trigger condition, including:
[0101] Based on the usage state of the virtual parameter set, a historical parameter state set is generated;
[0102] Based on a state transition algorithm in the preset life cycle model, a current state transition probability of the historical parameter state set is calculated;
[0103] Based on the comparison result of the current state transition probability and the preset update threshold, the parameter update trigger condition is determined.
[0104] For example, based on the real-time call records of the virtual parameter set at each level of the operating system, the usage state data is dynamically collected, including the MAC address broadcast frequency of the network protocol stack, the timestamp sequence of the device node file read operation, and the return value request number of the system API call. Through the kernel monitoring module, the above multi-dimensional state indicators are aggregated at a preset sampling period (such as 10 times per second) to generate a structured log containing time dimension, operation type dimension and call frequency dimension; further, the state sequence within a continuous time window (such as the last 100 sampling points) is extracted to construct a historical parameter state set. This set is stored in a ring buffer to ensure that the sliding window record of the latest state is always retained, providing a time-effective data basis for state transition probability calculation.
[0105] Based on the Markov chain state transition algorithm embedded in the preset lifecycle model, the historical parameter state set is mapped into a discrete state space. Specifically, it includes: defining state nodes (such as "low-frequency use", "medium-frequency use", and "high-frequency use"), each node corresponds to the interval of the number of calls of the virtual parameter set per unit time; quantifying the transfer relationship between nodes through the preset state transfer matrix (pre-trained and generated according to the real device parameter update rules). When calculating the current state transition probability, first identify the node position of the last state in the historical state set; then, based on the preset probability value of the node pointing to the "state to be updated" in the transfer matrix, combined with the weighted correction factor of the real-time call frequency (such as the deviation coefficient between the current call frequency and the historical mean), generate the final state transition probability value. This process realizes the transformation of parameter usage patterns into mathematical probabilities, making the update decision data-interpretable.
[0106] The calculated state transition probability value is compared in real time with the preset update threshold, which is dynamically calibrated through adversarial testing (for example, set to 0.85) to represent the critical confidence level that the continued use of the current parameters will lead to device-associated risks. If the state transition probability value is greater than or equal to the preset update threshold, it is determined that the parameter update trigger condition is met, and the system immediately starts the virtual parameter set update process; otherwise, the current parameter set is maintained. The judgment result is synchronously fed back to the Markov chain model to optimize the weight distribution of the state transition matrix (such as increasing the transition probability of high-frequency usage states) to form a closed-loop learning mechanism. This design ensures that the update action is only triggered when the parameter usage pattern shows an identified risk, avoiding resource waste caused by invalid updates.
[0107] In summary, the embodiments of the present application implement dynamic intelligent maintenance of device fingerprints through a lifecycle model, a sliding window mechanism for historical parameter state sets to ensure the timeliness and continuity of state assessments; Markov chain-driven state transition probability calculations to quantify parameter usage patterns into interpretable risk indicators; a dynamic comparison mechanism with preset update thresholds to ensure that update actions accurately match actual security requirements. The embodiments of the present application destroy the attacker's timing association model through non-periodic updates, effectively defending against the behavioral pattern analysis of LSTM networks; an on-demand triggering mechanism reduces system overhead; and closed-loop learning optimization enables update strategies to continuously adapt to new attack patterns, extending the anonymity lifecycle of cloud phones.
[0108] In some examples, when a parameter update trigger condition is met, the nonlinear transformation is re-executed to generate an updated virtual parameter set and overlayed to a multi-level system interface, including:
[0109] Based on the parameter update trigger condition, perform a virtual parameter update operation;
[0110] Based on the hardware entropy source data, a nonlinear transformation operation is performed through a preset chaotic mapping algorithm to generate an updated virtual parameter set;
[0111] Through kernel-level injection operations, the updated virtual parameter set is overwritten to multi-level system interfaces.
[0112] For example, when the lifecycle model determines that the parameter update trigger conditions are met, the system immediately initiates a virtual parameter update operation through the kernel semaphore mechanism. This operation is executed by an independent kernel thread. First, all system calls involving device fingerprint reading (including network protocol stack metadata queries, device node file access, and API calls) are suspended to ensure that there is no state conflict between the new and old parameter sets during the update process; then the current parameter cache of the multi-level system interface is cleared to establish a temporary isolation environment for atomic overwriting. This synchronization control mechanism ensures the priority and exclusivity of the update operation at the operating system scheduling level to avoid parameter inconsistency due to concurrent access.
[0113] Based on real-time hardware entropy source data (including the latest timestamp with superimposed time zone perturbation factors, a hashed hardware unique identifier, and ambient noise values obtained by physical sensors), a nonlinear transformation is performed using a preset Logistic Chaotic Mapping algorithm. The specific process includes: initializing the chaotic sequence iteration value with the real-time entropy source using the same fractal parameter value range (μ∈(3.57,4]) as the initial parameter generation; performing a warm-up iteration to eliminate transient effects, and then outputting a new generation of chaotic sequences; converting the sequence into an intermediate parameter set according to the device parameter format rules; and finally generating an updated virtual parameter set through operator compatibility verification (such as the encoding rules for IMEI in 3GPP TS23.003). This process ensures that the new parameter set inherits the unpredictability of the initial generation while also having the random refresh provided by the time-sensitive entropy source.
[0114] Through kernel-level injection, the updated virtual parameter set is synchronously written to the three-layer system interface. At the network layer, the source address field of the sk_buff structure is modified and the ARP cache table is updated, ensuring that subsequent outbound packets carry the new virtual MAC address. At the driver layer, the device node file operation function table is rewritten so that read operations on nodes such as / sys / class / net / eth0 / address return the new virtual parameters. At the application layer, the API handling routines in the system call table are replaced to ensure that functions such as getDeviceId() return the updated return values. After the three-layer injection is completed, the synchronization semaphore is released and the suspended system call is resumed. Atomic operations ensure that all interfaces at all levels switch to the new parameter set at the same time, eliminating the time window for inconsistent parameter states across layers.
[0115] In summary, the embodiments of the present application achieve continuous anonymization of device fingerprints through a closed-loop update mechanism, and synchronous control ensures that the update process is stateless and conflict-free, preventing attackers from using time differences to implement fingerprint association; real-time entropy source drive ensures that the new parameter set has mathematical unpredictability and timeliness, and effectively defends against reverse deduction based on historical data; multi-level atomic coverage completely eliminates the risk of fingerprint fragmentation caused by step-by-step replacement in traditional solutions.
[0116] See also Figure 2 , which is a schematic diagram of the structure of a fingerprint disguise device for a cloud phone device provided in an embodiment of the present application, including:
[0117] The hardware data acquisition unit 21 is used to acquire hardware entropy source data, wherein the hardware entropy source data includes current timestamp data, hardware unique identification hash value and environmental noise sampling value;
[0118] The virtual parameter generating unit 22 performs nonlinear transformation on the hardware entropy source data based on a preset chaotic mapping algorithm to generate a virtual parameter set, wherein the virtual parameter set satisfies a preset device parameter rule;
[0119] The system interface overlay unit 23 is used to overlay the virtual parameter set to the multi-level system interface of the real device fingerprint through a kernel-level injection operation;
[0120] A virtual parameter monitoring unit 24 monitors the usage status of the virtual parameter set based on a preset lifecycle model and determines a parameter update trigger condition;
[0121] The virtual parameter updating unit 25 is configured to re-execute the nonlinear transformation to generate an updated virtual parameter set and cover it to the multi-level system interface when the parameter update triggering condition is met.
[0122] See also Figure 3 An embodiment of the present application also provides an electronic device 300, including a memory 310, a processor 320, and a computer program 311 stored in the memory 310 and executable on the processor. When the processor 320 executes the computer program 311, steps of a method for disguising a fingerprint of a cloud phone device are implemented.
[0123] Since the electronic device introduced in this embodiment is a device used to implement a disguised device for a cloud phone device fingerprint in the embodiment of this application, based on the method introduced in the embodiment of this application, technical personnel in this field can understand the specific implementation of the electronic device of this embodiment and its various variations. Therefore, how the electronic device implements the method in the embodiment of this application will not be introduced in detail here. As long as the equipment used by technical personnel in this field to implement the method in the embodiment of this application falls within the scope of protection of this application.
[0124] During the specific implementation process, when the computer program 311 is executed by the processor, any implementation method of the embodiments corresponding to the first aspect can be implemented.
[0125] It should be noted that, in the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0126] Those skilled in the art will appreciate that embodiments of the present application may provide methods, systems, or computer program products. Thus, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product embodied on one or more computer-readable storage media containing computer-readable program code.
[0127] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded computer or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0128] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0129] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0130] The present application also provides a computer program product, which includes computer software instructions. When the computer software instructions are executed on a processing device, the processing device executes Figure 1 The process of a method for disguising a fingerprint of a cloud phone device in the corresponding embodiment.
[0131] A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can store or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium can be a magnetic medium, an optical medium or a semiconductor medium, etc.
[0132] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0133] In the several embodiments provided in this application, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative, and for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not implemented. In addition, the coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.
[0134] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0135] In addition, the functional units in the various embodiments of the present application may be integrated into a processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The above-mentioned integrated units may be implemented in the form of hardware and / or software functional units.
[0136] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory, a magnetic disk, or an optical disk.
[0137] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
[0138] Although the preferred embodiments of this specification have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of this specification.
[0139] Obviously, those skilled in the art may make various changes to this specification without departing from the spirit and scope of this specification. Thus, if such changes to this specification fall within the scope of the claims and their equivalents, this specification is intended to include such changes.
Claims
1. A method for disguising fingerprints of cloud phone devices, characterized in that: include: Acquire hardware entropy source data, wherein the hardware entropy source data includes current timestamp data, hardware unique identification hash value and environmental noise sampling value; Performing a nonlinear transformation on the hardware entropy source data based on a preset chaotic mapping algorithm to generate a virtual parameter set, wherein the virtual parameter set satisfies a preset device parameter rule; Overlaying the virtual parameter set onto the multi-level system interface of the real device fingerprint through kernel-level injection operations; Monitor the usage status of the virtual parameter set based on a preset lifecycle model and determine a parameter update trigger condition; When the parameter update triggering condition is met, the nonlinear transformation is re-executed to generate an updated virtual parameter set and overlay it to the multi-level system interface.
2. The method according to claim 1, wherein obtaining hardware entropy source data comprises: Get initial timestamp data based on the system clock; Based on a preset time zone disturbance factor, the initial timestamp data is superimposed to generate current timestamp data; Process the hardware unique identifier based on a preset hash algorithm to generate a hardware unique identifier hash value; Read environmental noise sampling values based on physical sensors; The current timestamp data, the hardware unique identification hash value, and the environmental noise sampling value are determined as the hardware entropy source data.
3. The method according to claim 1, wherein the step of performing a nonlinear transformation on the hardware entropy source data based on a preset chaotic mapping algorithm to generate a virtual parameter set comprises: Determining the value range of the fractal parameter of the preset chaotic mapping algorithm based on Lyapunov exponent stability analysis; Initializing an initial iteration value of a chaotic sequence based on the hardware entropy source data; Based on the value range of the fractal parameter, the initial iteration value is iteratively calculated by Logistic chaotic mapping to generate a chaotic sequence; Based on the chaotic sequence, generating an intermediate parameter set that conforms to a device parameter format; Based on preset device parameter rules, the intermediate parameter set is format converted to generate the virtual parameter set.
4. The method according to claim 1, wherein The kernel-level injection operation is used to overlay the virtual parameter set onto the multi-level system interface of the real device fingerprint, including: Determining network layer coverage parameters, driver layer coverage parameters, and application layer coverage parameters based on the virtual parameter set; Modifying a metadata broadcast strategy of a network protocol stack based on the network layer overlay parameters; Redirecting a device node read operation based on the driver layer overlay parameter; Based on the application layer overlay parameters, system API calls are intercepted and return values are replaced.
5. The method according to claim 1, characterized in that The monitoring of the usage status of the virtual parameter set based on the preset lifecycle model and determining the parameter update triggering condition includes: generating a historical parameter state set based on the usage state of the virtual parameter set; Calculating the current state transition probability of the historical parameter state set based on the state transition algorithm in the preset life cycle model; A parameter update triggering condition is determined based on a comparison result of the current state transition probability and a preset update threshold.
6. The method according to claim 1, characterized in that When the parameter update trigger condition is met, re-executing the nonlinear transformation to generate an updated virtual parameter set and overwriting it to the multi-level system interface includes: Based on the parameter update trigger condition, executing a virtual parameter update operation; Based on the hardware entropy source data, a nonlinear transformation operation is performed through the preset chaotic mapping algorithm to generate an updated virtual parameter set; Through the kernel-level injection operation, the updated virtual parameter set is overwritten to the multi-level system interface.
7. A fingerprint disguise device for cloud mobile phone devices, characterized in that: include: A hardware data acquisition unit, configured to acquire hardware entropy source data, wherein the hardware entropy source data includes current timestamp data, a hardware unique identification hash value, and an environmental noise sampling value; a virtual parameter generating unit, performing a nonlinear transformation on the hardware entropy source data based on a preset chaotic mapping algorithm to generate a virtual parameter set, wherein the virtual parameter set satisfies a preset device parameter rule; a system interface overlay unit, configured to overlay the virtual parameter set onto the multi-level system interface of the real device fingerprint through a kernel-level injection operation; A virtual parameter monitoring unit, which monitors the usage status of the virtual parameter set based on a preset lifecycle model and determines a parameter update trigger condition; The virtual parameter updating unit is configured to re-execute the nonlinear transformation to generate an updated virtual parameter set and overwrite the updated virtual parameter set to the multi-level system interface when the parameter update triggering condition is met.
8. An electronic device comprising: A memory, a processor, and a computer program stored in the memory and runnable on the processor, characterized in that the processor is used to implement the steps of the cloud phone device fingerprint disguise method as described in any one of claims 1 to 6 when executing the computer program stored in the memory.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for disguising a fingerprint of a cloud phone device according to any one of claims 1 to 6 is implemented.
10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method for disguising a fingerprint of a cloud phone device according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Cloud mobile phone identification method and device, equipment and storage medium
CN119420776A
Network security defense method and system based on intrusion modeling trapping
CN119996093A
Company information encryption method combined with chaotic public key encryption algorithm
CN120034313A
Edge node heterogeneous network heterogeneous platform access management method and system
CN120090889A
Cloud mobile phone end-to-end performance tracking method and related equipment
CN120151231A
Cited By
Intelligent terminal multi-mode equipment fingerprint detection method and system
CN121211369A
Intelligent terminal multi-modal device fingerprint detection method and system
CN121211369B