Mobile device fingerprint abnormal update method and system

By generating multi-factor device fingerprints on mobile devices and performing legality verification and update mechanisms in back-end services, the problem of existing mobile device fingerprints being easily tampered with and forged is solved, and the accuracy and security of identification are improved.

CN115484608BActive Publication Date: 2025-06-17PING AN TECH (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211124229.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-15
Publication Date
2025-06-17
Estimated Expiration
2042-09-15

AI Technical Summary

Technical Problem

The equipment fingerprint composition information of existing mobile devices is simple and is easily tampered with and forged by attackers, resulting in low accuracy and security of equipment fingerprint recognition.

Method used

By accepting user instructions, starting the mobile application, calling the SDK to request the back-end service interface, and generating a mobile device fingerprint. The back-end service identifies whether the deviceKey contained in the device fingerprint is legal. If it is not legal, it will enter the exception table and mark it as being updated. The user starts the application again, the backend service generates a new deviceKey and returns, and the mobile application updates and saves the new deviceKey.

Benefits of technology

By enhancing the multi-factor composition of device fingerprints and the legality verification of back-end services, the accuracy and security of device fingerprint recognition are improved to prevent tampering and forgery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115484608B_ABST
    Figure CN115484608B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for abnormal update of mobile device fingerprints, including: receiving a user instruction, starting a mobile application, calling an SDK to request a backend service interface, and generating a mobile device fingerprint; the mobile application requests the backend service and sends the device fingerprint to the backend service; if the backend service determines that the device fingerprint contains a deviceKey, the backend service identifies whether the deviceKey is legal; if the deviceKey is illegal, it enters the exception table and saves the deviceKey locally; the backend service identifies again whether the deviceKey is legal, if it is illegal, it modifies the exception table and marks the deviceKey as to be updated; receiving a user instruction, starting the mobile application again, and calling the SDK to request the backend service interface, if the backend service determines that the deviceKey is illegal, it generates a new deviceKey and returns it; the mobile application updates and saves the new deviceKey locally. It can solve the problem that the composition information of the existing mobile device fingerprint is simple and is easily tampered with and forged by attackers, resulting in low accuracy and security of device fingerprint recognition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and particularly to a method and system for abnormal update of fingerprint of a mobile device, a computer device, and a non-volatile computer-readable storage medium. Background Art

[0002] At present, with the development of communication technologies, the frequency of users using mobile devices for payment is getting higher and higher, and the data security of mobile devices is becoming more and more important. Generally, the fingerprint of a mobile device is to generate a unique identification code of the mobile device by collecting information of the mobile device. For example, the international mobile equipment identity (IMEI), media access control address (MAC), or Android identity (ID) of the mobile device can be used to generate the device fingerprint of the mobile device. However, the composition information of the existing device fingerprint of the mobile terminal is simple and is easily tampered with and forged by attackers, resulting in low accuracy and security of the existing device fingerprint recognition of the mobile terminal.

[0003] Therefore, the existing technologies still need to be improved. Summary of the Invention

[0004] In view of the deficiencies of the above-mentioned existing technologies, the purpose of the present invention is to provide a method and system for abnormal update of fingerprint of a mobile device, a computer device, and a non-volatile computer-readable storage medium that can be used in fintech or other related fields, aiming to solve the problem that the composition information of the existing device fingerprint of the mobile terminal is simple and is easily tampered with and forged by attackers, resulting in low accuracy and security of the existing device fingerprint recognition of the mobile terminal.

[0005] To achieve the above purpose, the present invention adopts the following technical solutions:

[0006] A method for abnormal update of fingerprint of a mobile device, including:

[0007] Receiving a user instruction, starting a mobile application, calling an SDK to request a back-end service interface, and generating a fingerprint of the mobile device;

[0008] The mobile application requests the back-end service and sends the device fingerprint to the back-end service;

[0009] If the back-end service determines that the device fingerprint contains a deviceKey, the back-end service identifies whether the deviceKey is legal;

[0010] If the deviceKey is illegal, enter the exception table and save the deviceKey locally;

[0011] The backend service identifies again whether the deviceKey is legal. If it is illegal, modify the exception table and mark the deviceKey as to be updated;

[0012] Receive a user instruction, restart the mobile application again, and call the SDK to request the backend service interface. If the backend service determines that the deviceKey is illegal, generate a new deviceKey and return it;

[0013] The mobile application updates and saves the new deviceKey locally.

[0014] In a further technical solution, in the mobile device fingerprint abnormal update method, wherein, in the receiving a user instruction, starting the mobile application, calling the SDK to request the backend service interface, and generating a mobile device fingerprint, the device fingerprint includes a deviceId and multiple non-sensitive factors.

[0015] In a further technical solution, in the mobile device fingerprint abnormal update method, wherein, in the if the backend service determines that the device fingerprint contains the deviceKey, it includes:

[0016] If the backend service determines that the device fingerprint does not contain the deviceKey, use the deviceId to register and generate a deviceKey.

[0017] In a further technical solution, in the mobile device fingerprint abnormal update method, wherein, in the the backend service identifies again whether the deviceKey is legal, the backend service identifies whether the deviceKey is legal through a task or manually.

[0018] A mobile device fingerprint abnormal update system, which includes:

[0019] A first generation module, configured to receive a user instruction, start a mobile application, call the SDK to request the backend service interface, and generate a mobile device fingerprint;

[0020] A sending module, configured to request the backend service by the mobile application and send the device fingerprint to the backend service;

[0021] A first identification module, configured to if the backend service determines that the device fingerprint contains the deviceKey, the backend service identifies whether the deviceKey is legal;

[0022] The first saving module is used to enter the exception table if the deviceKey is illegal and save the deviceKey locally.

[0023] The second identification module is used for the backend service to identify again whether the deviceKey is legal. If it is illegal, the exception table is modified and the deviceKey is marked as to be updated.

[0024] The second generation module is used to accept a user instruction, restart the mobile application again, and call the SDK to request the backend service interface. If the backend service determines that the deviceKey is illegal, a new deviceKey is generated and returned.

[0025] The second saving module is used for the mobile application to update and save the new deviceKey locally.

[0026] In a further technical solution, in the mobile device fingerprint exception update system, when accepting the user instruction, starting the mobile application, calling the SDK to request the backend service interface, and generating the mobile device fingerprint, the device fingerprint includes the deviceId and multiple non-sensitive factors.

[0027] In a further technical solution, in the mobile device fingerprint exception update system, when the backend service determines whether the device fingerprint contains the deviceKey, it includes:

[0028] If the backend service determines that the device fingerprint does not contain the deviceKey, the deviceId is used for registration and generation of the deviceKey.

[0029] In a further technical solution, in the mobile device fingerprint exception update system, when the backend service identifies again whether the deviceKey is legal, the backend service identifies whether the deviceKey is legal through tasks or manually.

[0030] A computer device, where the computer device includes at least one processor; and,

[0031] A memory communicatively connected to the at least one processor; where,

[0032] A computer program is stored on the memory and can be executed by the at least one processor. When the computer program is executed by the at least one processor, it can implement:

[0033] Accept a user instruction, start the mobile application, call the SDK to request the backend service interface, and generate the mobile device fingerprint;

[0034] The mobile application requests the backend service and sends the device fingerprint to the backend service;

[0035] If the backend service determines that the device fingerprint contains a deviceKey, the backend service identifies whether the deviceKey is legal;

[0036] If the deviceKey is illegal, it enters the exception table and saves the deviceKey locally;

[0037] The backend service identifies again whether the deviceKey is legal. If it is illegal, it modifies the exception table and marks the deviceKey as to be updated;

[0038] Accepts a user instruction, starts the mobile application again, and calls the SDK to request the backend service interface. If the backend service determines that the deviceKey is illegal, it generates a new deviceKey and returns it;

[0039] The mobile application updates and saves the new deviceKey locally.

[0040] In a further technical solution, for the computer device, in the process of accepting the user instruction, starting the mobile application, calling the SDK to request the backend service interface, and generating the mobile device fingerprint, the device fingerprint includes a deviceId and multiple non-sensitive factors.

[0041] In a further technical solution, for the computer device, in the process of the backend service determining that the device fingerprint contains a deviceKey, it includes:

[0042] If the backend service determines that the device fingerprint does not contain a deviceKey, it uses the deviceId to register and generate a deviceKey.

[0043] In a further technical solution, for the computer device, in the process of the backend service identifying again whether the deviceKey is legal, the backend service identifies whether the deviceKey is legal through tasks or manually.

[0044] A non-volatile computer-readable storage medium, where the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by at least one processor, it can implement:

[0045] Accepts a user instruction, starts the mobile application, calls the SDK to request the backend service interface, and generates a mobile device fingerprint;

[0046] The mobile application requests the backend service and sends the device fingerprint to the backend service;

[0047] If the backend service determines that the device fingerprint contains a deviceKey, the backend service identifies whether the deviceKey is legal;

[0048] If the deviceKey is illegal, it enters the exception table and the deviceKey is saved locally;

[0049] The backend service identifies again whether the deviceKey is legal. If it is illegal, the exception table is modified and the deviceKey is marked as to be updated;

[0050] Accept the user instruction, restart the mobile application again, and call the SDK to request the backend service interface. If the backend service determines that the deviceKey is illegal, a new deviceKey is generated and returned;

[0051] The mobile application updates and saves the new deviceKey locally.

[0052] In a further technical solution, the non-volatile computer-readable storage medium, wherein, in the accepting the user instruction, starting the mobile application, calling the SDK to request the backend service interface, and generating the mobile device fingerprint, the device fingerprint includes a deviceId and multiple non-sensitive factors.

[0053] In a further technical solution, the non-volatile computer-readable storage medium, wherein, in the if the backend service determines that the device fingerprint contains a deviceKey, includes:

[0054] If the backend service determines that the device fingerprint does not contain a deviceKey, the deviceId is used to register and generate a deviceKey.

[0055] In a further technical solution, the non-volatile computer-readable storage medium, wherein, in the the backend service identifies again whether the deviceKey is legal, the backend service identifies whether the deviceKey is legal through a task or manually.

[0056] Compared with the prior art, the present invention provides a method and system for abnormal update of mobile device fingerprints. Among them, the method includes: receiving a user instruction, starting a mobile application, calling an SDK to request a back-end service interface, and generating a mobile device fingerprint; the mobile application requests the back-end service and sends the device fingerprint to the back-end service; if the back-end service determines that the device fingerprint contains a deviceKey, the back-end service identifies whether the deviceKey is legal; if the deviceKey is illegal, it enters an exception table and saves the deviceKey locally; the back-end service identifies again whether the deviceKey is legal. If it is illegal, the exception table is modified and the deviceKey is marked as to be updated; receiving a user instruction, starting the mobile application again, and calling the SDK to request the back-end service interface. If the back-end service determines that the deviceKey is illegal, a new deviceKey is generated and returned; the mobile application updates and saves the new deviceKey locally. Through the method for abnormal update of mobile device fingerprints of the present invention, the problem that the composition information of the device fingerprints of existing mobile devices is simple and easy to be tampered with and forged by attackers, resulting in low accuracy and security of device fingerprint recognition of existing mobile devices, can be solved. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0058] Figure 1 It is a schematic flow chart of the method for abnormal update of mobile device fingerprints provided by the embodiment of the present invention.

[0059] Figure 2 It is a schematic diagram of the functional modules of the system for abnormal update of mobile device fingerprints provided by the embodiment of the present invention.

[0060] Figure 3 It is a schematic diagram of the hardware structure of the computer device provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0061] In order to make the objectives, technical solutions and effects of the present invention clearer and more definite, the following further describes the present invention in detail with reference to the accompanying drawings and by way of examples. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0062] In the description of the present invention, the terms "comprising", "including", "having", "containing", etc. are all open-ended terms, meaning including but not limited to. The description with reference to terms such as "one embodiment", "one specific embodiment", "some embodiments", "for example", etc. means that the specific features, structures or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic descriptions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. The order of steps involved in each embodiment is used to schematically illustrate the implementation of the present application, and the order of steps is not limited and can be adjusted appropriately as needed.

[0063] The following will, with reference to the accompanying drawings, elaborate on various non-limiting embodiments of the present invention in detail.

[0064] Please refer to Figure 1 , a method for abnormal update of fingerprint of a mobile device provided by an embodiment of the present invention, which includes:

[0065] S100. Receive a user instruction, start a mobile application, call the SDK to request a back-end service interface, and generate a fingerprint of the mobile device;

[0066] S200. The mobile application requests the back-end service and sends the device fingerprint to the back-end service;

[0067] S300. If the back-end service determines that the device fingerprint contains a deviceKey, the back-end service identifies whether the deviceKey is legal;

[0068] S400. If the deviceKey is illegal, enter the exception table and save the deviceKey locally;

[0069] S500. The back-end service identifies again whether the deviceKey is legal. If it is illegal, modify the exception table and mark the deviceKey as to be updated;

[0070] S600. Receive a user instruction, start the mobile application again, and call the SDK to request the back-end service interface. If the back-end service determines that the deviceKey is illegal, generate a new deviceKey and return it;

[0071] S700. The mobile application updates and saves the new deviceKey locally.

[0072] Specifically, in this embodiment, the SDK is the Software Development Kit; the deviceKey is the device key; through the mobile device fingerprint abnormal update method of this embodiment, the problem that the composition information of the device fingerprint of the existing mobile device is simple and easy to be tampered with and forged by attackers, resulting in low accuracy and security of the device fingerprint recognition of the existing mobile device can be solved.

[0073] Further, in one embodiment, in the mobile device fingerprint abnormal update method, when accepting a user instruction, starting a mobile application, calling the SDK to request a backend service interface, and generating a mobile device fingerprint, the device fingerprint includes a deviceId and multiple non-sensitive factors.

[0074] Further, in the mobile device fingerprint abnormal update method, when the backend service determines that the device fingerprint contains the deviceKey, it includes:

[0075] If the backend service determines that the device fingerprint does not contain the deviceKey, use the deviceId to register and generate a deviceKey.

[0076] Specifically, in this embodiment, the device fingerprint includes a deviceId (device ID), multiple non-sensitive factors, and a deviceKey (device key), where the multiple non-sensitive factors refer to non-sensitive information such as the type, manufacturer, CPU, and memory of the mobile device. That is, the device fingerprint in this embodiment is composed of multiple non-sensitive factors of the mobile device, the deviceId generated by the mobile device, and the deviceKey generated by the mobile device / backend service. In this way, even if the operating system and applications of the mobile device are upgraded or some factors are changed, the device fingerprint will not change, thereby avoiding the problem that the device fingerprint of the mobile device is easily tampered with and forged by attackers. At the same time, when the backend service confirms that the deviceKey is illegal, a new unique deviceKey for the mobile device is generated, and the mobile application updates and saves the new deviceKey locally, thereby ensuring the manageability and controllability of the mobile device fingerprint, and then accurately identifying the mobile device subsequently, ensuring the uniqueness of the mobile device and the security of the identification.

[0077] Further, in one embodiment, in the mobile device fingerprint abnormal update method, when the backend service re-identifies whether the deviceKey is legal, the backend service identifies whether the deviceKey is legal through a task or manually.

[0078] Specifically, in this embodiment, when the backend service manually identifies whether the deviceKey is legal, that is, the backend service manually confirms whether the multiple non-sensitive factors in the mobile device fingerprint are abnormal. For example, it is determined whether the mobile device is a newly replaced device, whether the operating system of the mobile device is upgraded, whether the application of the mobile device is upgraded, and whether the mobile device is abnormal by checking with external experts. If the judgment results are all negative, it can be determined as a conflict exception, that is, it can be confirmed that the deviceKey is illegal, and a new deviceKey is generated. The mobile application updates and saves the new deviceKey locally, thus ensuring the manageability and controllability of the mobile device fingerprint, and then accurately identifying the mobile device subsequently, ensuring the uniqueness and security of the mobile device identification.

[0079] It should be understood that although the present application provides method operation steps as described in the embodiments or flowcharts, based on routine or non-creative labor, there may be more or fewer operation steps. These operation steps are not necessarily executed in the order of the embodiments or flowcharts. The step order listed in the embodiments or flowcharts is only one way among many step execution orders and does not represent the only execution order. Moreover, at least some of the steps in the embodiments or flowcharts may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same moment but can be executed at different moments. The execution order of these sub-steps or stages is not necessarily sequential but can be executed alternately, alternately, or synchronously with at least a part of other steps or sub-steps or stages of other steps.

[0080] Based on the above embodiments, please refer to Figure 2 , the present invention also provides a mobile device fingerprint exception update system, which includes:

[0081] The first generation module 11 is used to receive a user instruction, start the mobile application, call the SDK to request the backend service interface, and generate a mobile device fingerprint;

[0082] The sending module 12 is used for the mobile application to request the backend service and send the device fingerprint to the backend service;

[0083] The first identification module 13 is used to, if the backend service determines that the device fingerprint contains a deviceKey, the backend service identifies whether the deviceKey is legal;

[0084] The first saving module 14 is used to, if the deviceKey is illegal, enter the exception table and save the deviceKey locally;

[0085] The second recognition module 15 is used to recognize again by the backend service whether the deviceKey is legal. If it is illegal, an exception table is modified, and the deviceKey is marked as to be updated.

[0086] The second generation module 16 is used to accept a user instruction, restart the mobile application again, and call the SDK to request the backend service interface. If the backend service determines that the deviceKey is illegal, a new deviceKey is generated and returned.

[0087] The second storage module 17 is used for the mobile application to update and store the new deviceKey locally.

[0088] Specifically, in this embodiment, the SDK is the Software Development Kit; the deviceKey is the device key; through the mobile device fingerprint abnormal update system of this embodiment, the problem that the composition information of the device fingerprint of the existing mobile terminal is simple and easy to be tampered with and forged by attackers, resulting in low accuracy and security of the existing mobile device fingerprint recognition, can be solved.

[0089] Furthermore, in one embodiment, for the mobile device fingerprint abnormal update system, wherein, in the accepting the user instruction, starting the mobile application, calling the SDK to request the backend service interface, and generating the mobile device fingerprint, the device fingerprint includes the deviceId and multiple non-sensitive factors.

[0090] Furthermore, for the mobile device fingerprint abnormal update system, wherein, in the case that the backend service determines that the device fingerprint contains the deviceKey, it includes:

[0091] If the backend service determines that the device fingerprint does not contain the deviceKey, the deviceId is used for registration and the deviceKey is generated.

[0092] Specifically, in this embodiment, the device fingerprint includes a deviceId (device ID), multiple non-sensitive factors, and a deviceKey (device secret key). Among them, the multiple non-sensitive factors refer to non-sensitive information such as the type, manufacturer, CPU, and memory of the mobile device. That is, the device fingerprint in this embodiment consists of multiple non-sensitive factors of the mobile terminal, the deviceId generated by the mobile terminal, and the deviceKey generated by the mobile terminal / backend service. In this way, even if the operating system and applications of the mobile terminal are upgraded or some factors are changed, the device fingerprint will not change, thus avoiding the problem that the device fingerprint of the mobile terminal is easily tampered with and forged by attackers. At the same time, when the backend service confirms that the deviceKey is illegal, a new unique deviceKey for the mobile terminal is generated, and the mobile application updates and saves the new deviceKey locally, thereby ensuring the manageability and controllability of the device fingerprint of the mobile terminal, and then accurately identifying the mobile device subsequently, ensuring the uniqueness of the mobile device and the security of identification.

[0093] Further, in one embodiment, in the mobile device fingerprint abnormal update system, when the backend service re-identifies whether the deviceKey is legal, the backend service identifies whether the deviceKey is legal through tasks or manually.

[0094] Specifically, in this embodiment, when the backend service manually identifies whether the deviceKey is legal, that is, the backend service manually confirms whether the multiple non-sensitive factors in the device fingerprint of the mobile terminal are abnormal. For example, it is determined whether the mobile terminal is a newly replaced device, whether the operating system of the mobile terminal is upgraded, whether the application of the mobile terminal is upgraded, and whether the mobile terminal can be checked for abnormalities by external experts. If the judgment results are all negative, it can be judged as a conflict abnormality, that is, it can be confirmed that the deviceKey is illegal, and a new deviceKey is generated. The mobile application updates and saves the new deviceKey locally, thereby ensuring the manageability and controllability of the device fingerprint of the mobile terminal, and then accurately identifying the mobile device subsequently, ensuring the uniqueness of the mobile device and the security of identification.

[0095] Based on the above embodiments, please refer to Figure 3 , the present invention also provides a computer device, where the computer device 10 includes:

[0096] A memory 120 and one or more processors 110. Figure 3 Taking one processor 110 as an example for introduction, the processor 110 and the memory 120 can be connected through a communication bus or other means. Figure 3 Taking the connection through the communication bus as an example.

[0097] The processor 110 is used to complete various control logics of the computer device 10, and it can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a single-chip microcomputer, an ARM (Acorn RISCMachine), or other programmable logic devices, discrete gate or transistor logic, discrete hardware components, or any combination of these components. Moreover, the processor 110 can also be any conventional processor, microprocessor, or state machine. The processor 110 can also be implemented as a combination of computing devices, for example, a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration.

[0098] The memory 120, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules, such as the computer program corresponding to the method for abnormal fingerprint update of a mobile device in an embodiment of the present invention. The processor 110 executes various functional applications and data processing of the computer device 10 by running the non-volatile software programs, instructions, and units stored in the memory 120, that is, implements the method for abnormal fingerprint update of a mobile device in the above method embodiment.

[0099] The memory 120 can include a program storage area and a data storage area. Among them, the program storage area can store an operating device and application programs required for at least one function; the data storage area can store data created according to the use of the computer device 10, etc. In addition, the memory 120 can include high-speed random access memory, and can also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some embodiments, the memory 120 can optionally include a memory remotely set relative to the processor 110, and these remote memories can be connected to the computer device 10 through a network. Examples of the above networks include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0100] One or more units are stored in the memory 120, and when executed by one or more processors 110, can implement:

[0101] Accept a user instruction, start a mobile application, call the SDK to request a back-end service interface, and generate a fingerprint of the mobile device;

[0102] The mobile application requests the back-end service and sends the device fingerprint to the back-end service;

[0103] If the back-end service determines that the device fingerprint contains a deviceKey, the back-end service identifies whether the deviceKey is legal;

[0104] If the deviceKey is illegal, enter the exception table and save the deviceKey locally;

[0105] The backend service identifies again whether the deviceKey is legal. If it is illegal, modify the exception table and mark the deviceKey as to be updated;

[0106] Receive a user instruction, restart the mobile application again, and call the SDK to request the backend service interface. If the backend service determines that the deviceKey is illegal, generate a new deviceKey and return it;

[0107] The mobile application updates and saves the new deviceKey locally.

[0108] Specifically, in this embodiment, the SDK is the Software Development Kit; the deviceKey is the device secret key; through the computer device of this embodiment, the problem that the composition information of the device fingerprint of the existing mobile terminal is simple and easy to be tampered with and forged by attackers, resulting in low accuracy and security of the device fingerprint recognition of the existing mobile terminal can be solved.

[0109] Further, in one embodiment, for the computer device, wherein, in the receiving the user instruction, starting the mobile application, calling the SDK to request the backend service interface, and generating the mobile device fingerprint, the device fingerprint includes the deviceId and multiple non-sensitive factors.

[0110] Further, for the computer device, wherein, in the if the backend service determines that the device fingerprint contains the deviceKey, it includes:

[0111] If the backend service determines that the device fingerprint does not contain the deviceKey, use the deviceId to register and generate the deviceKey.

[0112] Specifically, in this embodiment, the device fingerprint includes the deviceId (device ID), multiple non-sensitive factors, and the deviceKey (device secret key). Among them, the multiple non-sensitive factors refer to non-sensitive information such as the type, manufacturer, CPU, and memory of the mobile device. That is, the device fingerprint in this embodiment consists of multiple non-sensitive factors of the mobile terminal, the deviceId generated by the mobile terminal, and the deviceKey generated by the mobile terminal / backend service. In this way, even if the operating system and applications of the mobile terminal are upgraded or some factors are changed, the device fingerprint will not change, thus avoiding the problem that the device fingerprint of the mobile terminal is easily tampered with or forged by attackers. At the same time, when the backend service confirms that the deviceKey is illegal, a new unique deviceKey for the mobile terminal is generated, and the mobile application updates and stores the new deviceKey locally, thereby ensuring the manageability and controllability of the device fingerprint of the mobile terminal, and then accurately identifying the mobile device subsequently, ensuring the uniqueness of the mobile device and the security of identification.

[0113] Further, in one embodiment, for the computer device, when the backend service re-identifies whether the deviceKey is legal, the backend service identifies whether the deviceKey is legal through a task or manually.

[0114] Specifically, in this embodiment, when the backend service manually identifies whether the deviceKey is legal, that is, the backend service manually confirms whether the multiple non-sensitive factors in the device fingerprint of the mobile terminal are abnormal, such as determining whether the mobile terminal is a newly replaced device, whether the operating system of the mobile terminal is upgraded, whether the application of the mobile terminal is upgraded, and whether the mobile terminal can be checked for abnormalities by external experts. If the judgment results are all negative, it can be judged as a conflict abnormality, that is, it can be confirmed that the deviceKey is illegal, and a new deviceKey is generated. The mobile application updates and stores the new deviceKey locally, thereby ensuring the manageability and controllability of the device fingerprint of the mobile terminal, and then accurately identifying the mobile device subsequently, ensuring the uniqueness of the mobile device and the security of identification.

[0115] Those skilled in the art can understand that Figure 3 the schematic diagram of the hardware structure shown in

[0116] Based on the above embodiments, the present invention further provides a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by at least one processor, the following can be implemented:

[0117] Receive a user instruction, start a mobile application, call the SDK to request a backend service interface, and generate a mobile device fingerprint;

[0118] The mobile application requests the backend service and sends the device fingerprint to the backend service;

[0119] If the backend service determines that the device fingerprint contains a deviceKey, the backend service identifies whether the deviceKey is legal;

[0120] If the deviceKey is illegal, enter the exception table and save the deviceKey locally;

[0121] The backend service identifies again whether the deviceKey is legal. If it is illegal, modify the exception table and mark the deviceKey as to be updated;

[0122] Receive a user instruction, start the mobile application again, and call the SDK to request the backend service interface. If the backend service determines that the deviceKey is illegal, generate a new deviceKey and return it;

[0123] The mobile application updates and saves the new deviceKey locally.

[0124] Specifically, in this embodiment, the SDK is the Software Development Kit; the deviceKey is the device secret key; through the non-volatile computer-readable storage medium of this embodiment, the problem that the composition information of the device fingerprint of the existing mobile terminal is simple and easy to be tampered with and forged by attackers, resulting in low accuracy and security of the existing mobile terminal device fingerprint recognition, can be solved.

[0125] Further, in one embodiment, for the non-volatile computer-readable storage medium, in the step of receiving a user instruction, starting a mobile application, calling the SDK to request a backend service interface, and generating a mobile device fingerprint, the device fingerprint includes a deviceId and multiple non-sensitive factors.

[0126] Further, for the non-volatile computer-readable storage medium, in the step of if the backend service determines that the device fingerprint contains a deviceKey, it includes:

[0127] If the backend service determines that the device fingerprint does not contain a deviceKey, it uses the deviceId to register and generate a deviceKey.

[0128] Specifically, in this embodiment, the device fingerprint includes a deviceId (device ID), multiple non-sensitive factors, and a deviceKey (device secret key). Among them, the multiple non-sensitive factors refer to non-sensitive information such as the type, manufacturer, CPU, and memory of the mobile device. That is, the device fingerprint in this embodiment consists of multiple non-sensitive factors of the mobile terminal, the deviceId generated by the mobile terminal, and the deviceKey generated by the mobile terminal / backend service. In this way, even if the operating system and applications of the mobile terminal are upgraded or some factors change, the device fingerprint will not change, thereby avoiding the problem that the device fingerprint of the mobile terminal is easily tampered with and forged by attackers. At the same time, when the backend service confirms that the deviceKey is illegal, a new unique deviceKey for the mobile terminal is generated, and the mobile application updates and saves the new deviceKey locally, thereby ensuring the manageability and controllability of the device fingerprint of the mobile terminal, and then accurately identifying the mobile device subsequently, ensuring the uniqueness of the mobile device and the security of identification.

[0129] Further, in one embodiment, for the non-volatile computer-readable storage medium, when the backend service re-identifies whether the deviceKey is legal, the backend service identifies whether the deviceKey is legal through a task or manually.

[0130] Specifically, in this embodiment, when the backend service manually identifies whether the deviceKey is legal, that is, the backend service manually confirms whether the multiple non-sensitive factors in the device fingerprint of the mobile terminal are abnormal, such as determining whether the mobile terminal is a newly replaced device, whether the operating system of the mobile terminal is upgraded, whether the application of the mobile terminal is upgraded, and whether the mobile terminal can be checked for abnormalities by external experts. If the judgment results are all negative, it can be judged as a conflict abnormality, that is, it can be confirmed that the deviceKey is illegal, and a new deviceKey is generated. The mobile application updates and saves the new deviceKey locally, thereby ensuring the manageability and controllability of the device fingerprint of the mobile terminal, and then accurately identifying the mobile device subsequently, ensuring the uniqueness of the mobile device and the security of identification.

[0131] By way of example, the non-volatile storage medium can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable ROM (EEPROM), or flash memory. The volatile memory can include random access memory (RAM) as an external cache memory. By way of illustration and not limitation, RAM can be obtained in many forms such as synchronous RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), Synchl ink DRAM (SLDRAM), and direct Rambus RAM (DRRAM). The disclosed memory components or memories of the operating environment described herein are intended to include one or more of these and / or any other suitable type of memory.

[0132] Another embodiment of the present invention provides a computer program product, the computer program product includes a computer program stored on a non-volatile computer-readable storage medium, the computer program includes program instructions, when the program instructions are executed by a processor, it can implement the fingerprint abnormal update method of the mobile device in any of the above method embodiments, for example, it can implement the Figure 1 method steps S100 to step S700 described above.

[0133] The embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0134] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution in essence or the part that contributes to the related technology can be embodied in the form of a software product. The computer software product can exist in a computer-readable storage medium such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of each embodiment or some parts of the embodiments.

[0135] Among other things, conditional language such as "able to", "can", "may", or "could" generally, unless specifically stated otherwise or otherwise understood within the context in which it is used, is intended to convey that a particular embodiment can include (while other embodiments do not include) a particular feature, element, and / or operation. Thus, such conditional language generally is also intended to imply that the feature, element, and / or operation is in some way required for one or more embodiments or that one or more embodiments must include logic for deciding whether the feature, element, and / or operation is included or will be performed in any particular embodiment, given the input or prompting, if any.

[0136] What has been described herein in the specification and the drawings includes examples of a method, system, computer device, and non - volatile computer - readable storage medium that can provide a fingerprint anomaly update method for a mobile device. Of course, it is not possible to describe every conceivable combination of elements and / or methods for the purpose of describing the various features of the present disclosure, but it can be recognized that many additional combinations and permutations of the disclosed features are possible. Thus, it is apparent that various modifications can be made to the present disclosure without departing from the scope or spirit of the present disclosure, but all such various modifications should fall within the scope of the protection of the appended claims of the present invention. In addition, or in the alternative, other embodiments of the present disclosure may be apparent from consideration of the specification and the drawings and from practice of the present disclosure as presented herein. It is intended that the examples presented in the specification and the drawings be considered illustrative in all respects and not restrictive. Although specific terms are employed herein, they are used in a general and descriptive sense and not for purposes of limitation.

Claims

1. A method for abnormal fingerprint update of a mobile device, characterized in that, Including: Receive a user instruction, start the mobile application, call the SDK to request the backend service interface, and generate a mobile device fingerprint; The mobile application requests the backend service and sends the device fingerprint to the backend service; If the backend service determines that the device fingerprint contains a deviceKey, the backend service identifies whether the deviceKey is legal; If the deviceKey is illegal, enter the exception table and save the deviceKey locally; The backend service identifies again whether the deviceKey is legal. If it is illegal, modify the exception table and mark the deviceKey as pending update; Receive a user instruction, start the mobile application again, and call the SDK to request the backend service interface. If the backend service determines that the deviceKey is illegal, generate a new deviceKey and return it; The mobile application updates and saves the new deviceKey locally; In the step of receiving a user instruction, starting the mobile application, calling the SDK to request the backend service interface, and generating a mobile device fingerprint, the device fingerprint includes a deviceId and multiple non-sensitive factors; In the step of if the backend service determines that the device fingerprint contains a deviceKey, it includes: If the backend service determines that the device fingerprint does not contain a deviceKey, use the deviceId to register and generate a deviceKey; In the step of the backend service identifying again whether the deviceKey is legal, the backend service identifies whether the deviceKey is legal through tasks or manually.

2. A system for abnormal fingerprint update of a mobile device, characterized in that, Including: A first generation module, configured to receive a user instruction, start the mobile application, call the SDK to request the backend service interface, and generate a mobile device fingerprint; A sending module, configured to request the backend service by the mobile application and send the device fingerprint to the backend service; A first identification module, configured to if the backend service determines that the device fingerprint contains a deviceKey, the backend service identifies whether the deviceKey is legal; A first saving module, configured to if the deviceKey is illegal, enter the exception table and save the deviceKey locally; A second identification module, configured to identify again by the backend service whether the deviceKey is legal. If it is illegal, modify the exception table and mark the deviceKey as pending update; A second generation module, configured to receive a user instruction, start the mobile application again, and call the SDK to request the backend service interface. If the backend service determines that the deviceKey is illegal, generate a new deviceKey and return it; A second saving module, configured to update and save the new deviceKey locally by the mobile application; In the step of receiving a user instruction, starting the mobile application, calling the SDK to request the backend service interface, and generating a mobile device fingerprint, the device fingerprint includes a deviceId and multiple non-sensitive factors; If the backend service determines that the device fingerprint contains the deviceKey, it includes: If the backend service determines that the device fingerprint does not contain the deviceKey, then register and generate the deviceKey using the deviceId; When the backend service identifies again whether the deviceKey is legal, the backend service identifies whether the deviceKey is legal through tasks or manually.

3. A computer device, characterized in that, The computer device includes at least one processor; and, A memory communicatively connected to the at least one processor; wherein, A computer program executable by the at least one processor is stored on the memory, and when the computer program is executed by the at least one processor, the abnormal update method of the mobile device fingerprint as described in claim 1 can be implemented.

4. A non - volatile computer - readable storage medium, characterized in that, The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by at least one processor, the abnormal update method of the mobile device fingerprint as described in claim 1 can be implemented.

Citation Information

Patent Citations

  • System and method for multi-system authentication and synchronization in mobile equipment

    CN107172008A

  • Internet surfing equipment marking method and device, storage medium and computer equipment

    CN109995751A