Fingerprint collision determination method, device, storage medium and electronic device

The method addresses device fingerprint collisions by analyzing current and historical device information to identify and mitigate collisions, ensuring device integrity and usability through automated risk assessment and time logic analysis.

CN115618316BActive Publication Date: 2025-07-15TONGDUN NETWORK TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211410178.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-10
Publication Date
2025-07-15
Estimated Expiration
2042-11-10

AI Technical Summary

Technical Problem

The existing technology cannot effectively solve the abnormal fingerprint acquisition characteristics of equipment caused by new models of mobile phones or new versions of systems, resulting in large-scale fingerprint collisions and affecting device availability.

Method used

By obtaining the information to be verified by multiple recovered devices within the target time period, using keyword verification and time reasoning results to determine whether the device has a fingerprint collision, including obtaining the target login ID, operation feature information and current device information, judging the operating risks of the device, and determining the fingerprint collision when the keyword verification and time reasoning results do not meet the preset conditions.

Benefits of technology

It realizes that when the device model or system is updated, it can independently detect whether the device has fingerprint collisions, improving the availability and security of the device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115618316B_ABST
    Figure CN115618316B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a method, apparatus, storage medium, and electronic device for fingerprint collision determination, and relates to the field of computer technology. The method includes: first, obtaining verification information to be verified of multiple restored devices within a target time period, determining a keyword verification result of the restored devices according to the current device information of the restored devices and the historical device information associated with the target login ID, determining a time inference result of the restored devices according to the current boot time included in the current device information and the historical boot time recorded by the target login ID, and when the keyword verification result and the time inference result do not meet the preset verification conditions, determining that a fingerprint collision occurs in the restored devices. In this way, when the device model or system is updated, self-checking can be directly performed based on the collected feature information, and it can be determined whether the restored devices meet the verification conditions according to the keyword verification result and the time inference result, so as to determine whether a fingerprint collision occurs in the restored devices.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] Device fingerprint refers to the device characteristics or unique device identifiers that can be used to uniquely identify a device. It is a relatively common technology in the Internet field and is widely used in the field of business security as a basic security service. Its principle is: by collecting a series of characteristic information of the device and sending it to the server, the server generates a unique identifier for each device through algorithm analysis and matching. There are two core indicators for the application of device fingerprints, uniqueness and stability. Uniqueness means that different devices will generate different fingerprints, and stability means that after the device undergoes some operations, such as installation, uninstallation, system upgrade, etc., the device fingerprint will not change. Due to the continuous tightening of permissions by mobile phone manufacturers and operating system providers, the collection rate of many characteristics is getting lower and lower, resulting in many collected characteristics being problematic. For example, the collection rates of core fields such as imei and idfa are getting lower and lower, and the mac addresses collected by the current new versions of Android and iOS are the same. The consequence of the repetition or absence of core characteristics is that similar devices calculate the same fingerprint after calculation, that is, collision occurs.

[0003] The existing technology has no particularly good solution for the abnormal data collection caused by the release of this new model of mobile phone or new version of the system. Facing the data anomaly situation caused by this new version, manufacturers can only rely on timely updating the SDK and applications to reduce the large-scale collision of device fingerprints, and cannot achieve self-discovery and self-repair. And the large-scale collision of fingerprints will directly affect the usability of the device.

[0004] It should be noted that the information invented in the above background art section is only used to strengthen the understanding of the background of the present disclosure, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] To overcome the problems existing in the related technology, the present disclosure provides a fingerprint collision determination method, device, storage medium and electronic device to at least solve the problem that it is difficult to self-check due to abnormal collection of characteristic information caused by device model or system update in the related technology.

[0006] According to an aspect of the present disclosure, a fingerprint collision determination method is provided, and the method includes:

[0007] Obtain the information to be verified of multiple restored devices within a target time period; the information to be verified includes a target login ID, running characteristic information, and current device information;

[0008] In the case that there is no running risk in the running characteristic information of the restored device, determine the keyword verification result of the restored device according to the current device information of the restored device and the historical device information associated with the target login ID;

[0009] Determine the time inference result of the device to be restored according to the current startup time included in the current device information of the device to be restored and the historical startup time recorded by the target login ID;

[0010] For each device to be restored, when the keyword verification result and the time inference result do not meet the preset verification conditions, it is determined that a fingerprint collision occurs on the device to be restored.

[0011] Optionally, before determining the keyword verification result of the device to be restored according to the current device information of the device to be restored and the historical device information associated with the target login ID, a preset operation risk formula is set, and the method further includes:

[0012] Determine multiple risk variables included in the operation characteristic information and corresponding variable labels;

[0013] Calculate the variable labels corresponding to the multiple risk variables by using the preset operation risk formula to determine the risk score corresponding to the device to be restored;

[0014] If the risk score is less than the preset risk threshold, there is no operation risk for the device to be restored.

[0015] Optionally, determining the keyword verification result of the device to be restored according to the current device information of the device to be restored and the historical device information associated with the target login ID includes:

[0016] Obtain the historical device information of the first login using the target login ID;

[0017] Determine the corresponding first keyword field in the current device information and the corresponding second keyword field in the historical device information according to the preset device type;

[0018] Use the verification result of the first keyword field and the second keyword field as the keyword verification result of the device to be restored.

[0019] Optionally, determining the time inference result of the device to be restored according to the current startup time included in the current device information of the device to be restored and the historical startup time recorded by the target login ID includes:

[0020] Obtain the historical startup time recorded by the device of the last login using the target login ID;

[0021] Perform time inference on the current startup time included in the current device information and the historical startup time by using a preset time inference method to determine the time inference result of the device to be restored.

[0022] Optionally, when the keyword verification result and the time inference result do not meet the preset verification conditions, determining that a fingerprint collision occurs on the recovered device includes:

[0023] When the current device information is inconsistent with the historical device information, and the current boot time and the historical boot time do not conform to the preset time logic relationship, it is determined that a fingerprint collision occurs on the recovered device.

[0024] Optionally, the method further includes:

[0025] When there is a running risk for the recovered device, adding a preset risk identifier to the recovered device.

[0026] According to one aspect of the present disclosure, there is provided a fingerprint collision determination device, the device includes:

[0027] An acquisition module, configured to acquire the information to be verified of multiple recovered devices within a target time period; the information to be verified includes a target login ID, running feature information, and current device information;

[0028] A first determination module, configured to determine the keyword verification result of the recovered device according to the current device information of the recovered device and the historical device information associated with the target login ID when there is no running risk in the running feature information of the recovered device;

[0029] A second determination module, configured to determine the time inference result of the recovered device according to the current boot time included in the current device information and the historical boot time recorded by the target login ID;

[0030] A third determination module, configured to, for each recovered device, determine that a fingerprint collision occurs on the recovered device when the keyword verification result and the time inference result do not meet the preset verification conditions.

[0031] Optionally, before determining the keyword verification result of the recovered device according to the current device information of the recovered device and the historical device information associated with the target login ID, the device further includes:

[0032] A fourth determination module, configured to determine multiple risk variables included in the running feature information and corresponding variable labels;

[0033] A calculation module, configured to calculate the variable labels corresponding to the multiple risk variables by using a preset running risk formula to determine the risk score corresponding to the recovered device; if the risk score is less than the preset risk threshold, there is no running risk for the recovered device.

[0034] Optionally, the first determination module is further configured to:

[0035] Obtain the historical device information of the first login using the target login ID;

[0036] Determine the corresponding first keyword field in the current device information and the corresponding second keyword field in the historical device information according to a preset device type;

[0037] Use the verification result of the first keyword field and the second keyword field as the keyword verification result of the device to be restored.

[0038] Optionally, the second determination module is further configured to:

[0039] Obtain the historical boot time recorded by the last login device using the target login ID;

[0040] Perform time inference on the current boot time included in the current device information and the historical boot time using a preset time inference method to determine the time inference result of the device to be restored.

[0041] Optionally, the third determination module is further configured to:

[0042] When the current device information is inconsistent with the historical device information and the current boot time and the historical boot time do not conform to a preset time logic relationship, it is determined that a fingerprint collision has occurred for the device to be restored.

[0043] Optionally, the apparatus further includes:

[0044] An adding module, configured to add a preset risk identifier to the device to be restored when there is a running risk for the device to be restored.

[0045] According to one aspect of the present disclosure, there is provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the fingerprint collision determination method described in any one of the above is implemented.

[0046] According to one aspect of the present disclosure, there is provided an electronic device, including:

[0047] A processor; and

[0048] A memory for storing executable instructions of the processor;

[0049] Wherein, the processor is configured to execute the fingerprint collision determination method described in any one of the above by executing the executable instructions.

[0050] In summary, the fingerprint collision determination method provided by the embodiments of the present invention can first obtain the information to be verified of multiple restored devices within a target time period. The information to be verified includes a target login ID, running feature information, and current device information. When there is no running risk in the running feature information of the restored device, the keyword verification result of the restored device is determined according to the current device information of the restored device and the historical device information associated with the target login ID. The time inference result of the restored device is determined according to the current boot time included in the current device information and the historical boot time recorded by the target login ID. For each restored device, when the keyword verification result and the time inference result do not meet the preset verification conditions, it is determined that a fingerprint collision has occurred in the restored device. In this way, when the device model or system is updated, self-checking can be directly performed based on the collected feature information, and it can be determined whether the restored device meets the verification conditions according to the keyword verification result and the time inference result, so as to determine whether a fingerprint collision has occurred in the restored device.

[0051] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0053] Figure 1 A flowchart schematically showing the steps of a fingerprint collision determination method provided by an embodiment of the present disclosure;

[0054] Figure 2 A flowchart schematically showing the steps of determining whether there is a running risk in a restored device provided by an embodiment of the present disclosure;

[0055] Figure 3 A flowchart schematically showing the steps of determining the keyword verification result of a restored device provided by an embodiment of the present disclosure;

[0056] Figure 4 A flowchart schematically showing the steps of determining the time inference result of a restored device provided by an embodiment of the present disclosure;

[0057] Figure 5 A block diagram schematically showing a fingerprint collision determination device provided by an embodiment of the present disclosure;

[0058] Figure 6Schematically illustrated is an electronic device provided by an embodiment of the present disclosure for implementing the above fingerprint collision determination method. Detailed implementation manners

[0059] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present disclosure. However, those skilled in the art will recognize that the technical solutions of the present disclosure may be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. may be used. In other cases, well-known technical solutions are not shown or described in detail to avoid obscuring the various aspects of the present disclosure.

[0060] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0061] Figure 1 is a flowchart of the steps of a fingerprint collision determination method provided by an embodiment of the present disclosure. As Figure 1 shown, the method may include:

[0062] Step S101, obtain the information to be verified of multiple restored devices within a target time period; the information to be verified includes a target login ID, running feature information, and current device information.

[0063] In the embodiments of the present disclosure, the target time period can be a time period obtained according to a preset time interval, and the verification information to be verified of multiple recovered devices within the target time period can be periodically obtained. For example, the target time period can be set to 48 hours. The verification information to be verified of the recovered device can be verification information for determining whether the device has repeated logins. The verification information to be verified can include a target login ID, running feature information, and current device information. The target login ID can be a unique identifier registered by the terminal device when it first logs in to the system, and each device corresponds to one login ID. The running feature information can be the running feature data of the terminal device after logging in to the system, and the current device information can be the attribute information of the terminal device itself. Obtaining the verification information to be verified of multiple recovered devices within the target time period can be to collect the device information, running information, and the login ID used to log in to the system of the terminal device after the terminal device logs in to the system with the user's permission. The system can be a service system, a management system, etc., and the present disclosure does not limit this.

[0064] Step S102, in the case that there is no running risk in the running feature information of the recovered device, determine the keyword verification result of the recovered device according to the current device information of the recovered device and the historical device information associated with the target login ID.

[0065] In the embodiments of the present disclosure, it can be to first determine whether there is a running risk in the operation of the recovered device on the system. In the case that there is no running risk in the running feature information of the recovered device, then determine the historical device information of the device that first logged in to the system using the target login ID, and compare the current device information of the recovered device with the historical device information to obtain the keyword verification result. The keyword verification result can be to compare whether the parameters of the current device information and the historical device information are consistent in different dimensions. Among them, the running risk can refer to whether the running environment of the recovered device is safe. If there is a running risk in the recovered device, it can indicate that there is insecure information in the running environment of the recovered device. For example, the recovered device may have been infected with a computer virus, or the running environment of the recovered device is vulnerable to network attacks, etc.

[0066] Step S103, determine the time inference result of the recovered device according to the current boot time included in the current device information and the historical boot time recorded by the target login ID.

[0067] In the embodiments of the present disclosure, the historical boot time recorded by the target login ID may be the historical boot time recorded by the device that last logged in to the system using the target login ID. According to the current boot time included in the current device information and the historical boot time recorded by the target login ID, determining the time inference result of the device to be restored may be to first determine the current boot time included in the current device information of the device to be restored and the most recent historical boot time recorded by the target login ID, and then determine the time inference result according to the order of the current boot time and the historical boot time.

[0068] Step S104. For each device to be restored, when the keyword verification result and the time inference result do not meet the preset verification conditions, it is determined that a fingerprint collision occurs for the device to be restored.

[0069] In the embodiments of the present disclosure, the preset verification conditions may be set in advance according to the actual situation. For example, the preset verification conditions may be that the keyword verification results are consistent and the time inference results conform to the time sequence. For each device to be restored, if the keyword verification result and the time inference result of the device to be restored do not meet the preset verification conditions, it may be determined that a fingerprint collision occurs for the device to be restored. If only the keyword verification result of the device to be restored does not meet the preset verification conditions, or only the time inference result does not meet the preset verification conditions, or the keyword verification result and the time inference result both meet the preset verification conditions, it may be determined that the device to be restored is normal and no fingerprint collision occurs.

[0070] In summary, the fingerprint collision determination method provided by the embodiments of the present invention can first obtain the information to be verified of multiple devices to be restored within a target time period. The information to be verified includes the target login ID, the running feature information, and the current device information. When there is no running risk in the running feature information of the device to be restored, according to the current device information of the device to be restored and the historical device information associated with the target login ID, the keyword verification result of the device to be restored is determined. According to the current boot time included in the current device information and the historical boot time recorded by the target login ID, the time inference result of the device to be restored is determined. For each device to be restored, when the keyword verification result and the time inference result do not meet the preset verification conditions, it is determined that a fingerprint collision occurs for the device to be restored. In this way, when the device model or the system is updated, self-checking can be directly performed based on the collected feature information, and whether the device to be restored meets the verification conditions can be determined according to the keyword verification result and the time inference result, so as to determine whether a fingerprint collision occurs for the device to be restored.

[0071] Optionally, in the embodiments of the present disclosure, before the operation of determining the keyword verification result of the device to be restored according to the current device information of the device to be restored and the historical device information associated with the target login ID, such as Figure 2As shown in the figure, the above fingerprint collision determination method may further include:

[0072] Step S201: Determine multiple risk variables included in the operation feature information and corresponding variable labels.

[0073] In the embodiments of the present disclosure, the risk variables and corresponding variable labels may be variables and corresponding labels preset for characterizing potential safety hazards in device operation. A mapping relationship between the risk variables and the corresponding variable labels may be set. Among them, the variables of potential safety hazards may include device information such as root permission, debugging status, group control, device modification, emulator, IP proxy, etc., and the corresponding variable labels may be preset. For example, the label corresponding to the variable root permission is x1, the label corresponding to the variable debugging status permission is x2, the label corresponding to the variable group control permission is x3, the label corresponding to the variable device modification permission is x4, the label corresponding to the variable emulator permission is x5, and the label corresponding to the variable IP proxy permission is x6. Determining multiple risk variables included in the operation feature information and corresponding variable labels may be to collect the operation feature information of the restored device from the operation log recorded on the restored device, determine the risk variables of the restored device based on the information in the operation feature information that matches the preset variable fields, and then determine the corresponding variable labels according to the information that matches the preset variable fields. Among them, the preset variable fields may be determined according to the corresponding content of the risk variables recorded in the operation log. For example, when the risk variable is root permission, the corresponding preset variable field may be is_root; when the risk variable is debugging status, the corresponding preset variable field may be is_debug; when the risk variable is group control, the corresponding preset variable field may be is_control; when the risk variable is device modification, the corresponding preset variable field may be is_hook. Specifically, the corresponding relationship table among the preset variable fields, risk variables, and variable labels may be as shown in Table 1 below. For example, when the risk variable is root permission, the corresponding variable label is x1, and the corresponding preset variable field in the operation log is is_roo, the field type is boolean, and the corresponding explanation of the field is whether it is root. It should be noted that the variable label of each risk variable may determine the corresponding value according to the risk variable characteristics recorded in the restored device. For example, when the risk variable is root permission, the corresponding variable label is x1. If the record about root permission in the restored device 1 is "is not root", then the variable label x1 = 0 may be determined; if the record is "is root", then the variable label x1 = 1 may be determined.

[0074] Table 1

[0075]

[0076] Step S202: Calculate the variable labels corresponding to the multiple risk variables using a preset operation risk formula to determine the risk score corresponding to the device to be restored.

[0077] In the embodiments of the present disclosure, the preset operation risk formula can be a formula preset for calculating the operation risk score of the device to be restored. Therefore, the variable labels corresponding to each risk variable and the weight configured for each risk variable can be input into the preset operation risk formula for calculation, and the calculation result is used as the risk score corresponding to the device to be restored. The preset operation risk formula can be expressed as follows:

[0078]

[0079] Among them, f(x) can represent the risk score corresponding to the device to be restored, and x1, x2, x3, x4, x5, x6 can respectively represent the variable labels corresponding to the respective risk variables shown in Table 1. The values corresponding to x1, x2, x3, x4, x5, x6 can be the values determined according to the recorded content in the device to be restored.

[0080] Step S203: If the risk score is less than the preset risk threshold, there is no operation risk for the device to be restored.

[0081] In the embodiments of the present disclosure, it can be determined that there is no operation risk for the device to be restored when the risk score is less than the preset risk threshold. Among them, the preset risk threshold can be set in advance according to the actual situation. For example, it can be set to 0.5.

[0082] Exemplarily, in actual operation, determining whether there is a risk for the device to be restored can be expressed as follows:

[0083] If f(x)>α:

[0084] Return risk device

[0085] else:safe device

[0086] Optionally, in the embodiments of the present disclosure, the operation of determining the keyword verification result of the device to be restored according to the current device information of the device to be restored and the historical device information associated with the target login ID, as Figure 3 shown, may specifically include:

[0087] Step S1021: Obtain the historical device information of the first login using the target login ID.

[0088] In an embodiment of the present disclosure, it is possible to obtain the device that logs in for the first time using the target login ID, that is, the device used when registering the target login ID, and use the device information recorded by the device when logging in to the target login ID for the first time as the historical device information.

[0089] Step S1022: Determine the corresponding first key field in the current device information and the corresponding second key field in the historical device information according to the preset device type.

[0090] In an embodiment of the present disclosure, the preset device type can be a device type for keyword verification set in advance. For example, the preset device type can be the device name, the operating system version number, the processor version number, etc. Determining the corresponding first key field in the current device information and the corresponding second key field in the historical device information according to the preset device type can be taking the corresponding information including the preset device type in the current device information as the first key field and taking the corresponding information including the preset device type in the historical device information as the second key field.

[0091] Step S1023: Use the verification result of the first key field and the second key field as the keyword verification result of the device to be restored.

[0092] In an embodiment of the present disclosure, it can be comparing and verifying the first key field and the second key field, and using the obtained verification result as the keyword verification result of the device to be restored. Specifically, comparing and verifying the first key field and the second key field can be matching the first key field and the second key field to determine whether the field contents are the same. Then the verification result can be that the contents of the first key field and the second key field are the same, or the contents of the first key field and the second key field are different.

[0093] Optionally, in an embodiment of the present disclosure, the operation of determining the time inference result of the device to be restored according to the current boot time included in the current device information and the historical boot time recorded by the target login ID, as Figure 4 shown, may specifically include:

[0094] Step S1031: Obtain the historical boot time recorded by the device that logged in last using the target login ID.

[0095] In an embodiment of the present disclosure, it is possible to first determine the device that used the target login ID most recently, and then determine the historical boot time recorded by the device, that is, the boot time recorded on the device when the device logged in to the target login ID.

[0096] Step S1032: Use a preset time reasoning method to perform time reasoning on the current boot time included in the current device information and the historical boot time, and determine the time reasoning result of the device to be restored.

[0097] In the embodiments of the present disclosure, the preset time reasoning method can be a method preset for verifying time logic. Specifically, the preset time reasoning method can be: for the same device, after arranging in ascending order according to the acquisition time (currentTime), the boot time (bootTime) should not have a descending situation. Among them, the preset time reasoning method can be specifically expressed as follows:

[0098] gap(x) = T1(x) - T2(x)

[0099]

[0100] s.t.group by deviceid order by currentTime desc

[0101] Where T(x) ∈ bootTime

[0102] Judgment of collision logic:

[0103]

[0104] Among them, gap(x) can represent the time difference. For the same device, the gap value is greater than or equal to 0, and for the colliding device, the gap value is less than 0; T1(x) can represent the boot time corresponding to the device at time T1, and the corresponding acquisition time is recorded as c1. T2(x) can represent the boot time corresponding to the device at time T2, and the corresponding acquisition time is recorded as c2, where c1 < c2. Since the boot time corresponding to the same device at this moment of acquisition is T1, the boot time corresponding to the next acquisition must be greater than or equal to T1, and the time rule must be observed.

[0105] Optionally, in the embodiments of the present disclosure, the operation of determining that the fingerprint collision occurs for the device to be restored when the keyword verification result and the time reasoning result do not meet the preset verification conditions can specifically include:

[0106] When the current device information is inconsistent with the historical device information, and the current boot time and the historical boot time do not conform to the preset time logical relationship, it is determined that the fingerprint collision occurs for the device to be restored.

[0107] In an embodiment of the present disclosure, when the keyword verification result is that the current device information is inconsistent with the historical device information, and the time inference result is that the current boot time does not conform to the preset time logic relationship with the historical boot time, it can be determined that fingerprint collision occurs in the restored device. If the keyword verification result of the restored device is that the current device information is inconsistent with the historical device information, and the time inference result conforms to the preset time logic relationship, or the keyword verification result of the restored device is that the current device information is consistent with the historical device information, and the time inference result does not conform to the preset time logic relationship, or the keyword verification result of the restored device is that the current device information is consistent with the historical device information, and the time inference result conforms to the preset time logic relationship, in any of the above cases, it can be determined that fingerprint collision does not occur in the restored device.

[0108] Optionally, in an embodiment of the present disclosure, the above fingerprint collision determination method may further include:

[0109] When there is an operation risk in the restored device, add a preset risk identifier to the restored device.

[0110] In an embodiment of the present disclosure, for the restored device corresponding to the operation risk, add a preset risk identifier and mark it as an untrusted device, so that security risk control can be performed in subsequent business processing. Among them, the preset risk identifier may be an identifier set in advance according to the actual situation, and the specific form of the identifier is not limited in the present disclosure.

[0111] Figure 5 Schematically shows a fingerprint collision determination device provided by an embodiment of the present disclosure, as Figure 5 shown. The device 50 may include:

[0112] An acquisition module 501, configured to acquire the information to be verified of multiple restored devices within a target time period; the information to be verified includes a target login ID, operation characteristic information, and current device information;

[0113] A first determination module 502, configured to determine the keyword verification result of the restored device according to the current device information of the restored device and the historical device information associated with the target login ID when the operation characteristic information of the restored device does not have an operation risk;

[0114] A second determination module 503, configured to determine the time inference result of the restored device according to the current boot time included in the current device information and the historical boot time recorded by the target login ID;

[0115] A third determination module 504, configured to determine that a fingerprint collision occurs for each recovered device when the keyword verification result and the time inference result do not meet the preset verification conditions.

[0116] In summary, the fingerprint collision determination device provided by the embodiment of the present invention can first obtain the information to be verified of multiple recovered devices within a target time period. The information to be verified includes a target login ID, running feature information, and current device information. When there is no running risk in the running feature information of the recovered device, according to the current device information of the recovered device and the historical device information associated with the target login ID, determine the keyword verification result of the recovered device. According to the current boot time included in the current device information and the historical boot time recorded by the target login ID, determine the time inference result of the recovered device. For each recovered device, when the keyword verification result and the time inference result do not meet the preset verification conditions, determine that a fingerprint collision occurs for the recovered device. In this way, when the device model or system is updated, it can directly perform self-checking based on the collected feature information, and determine whether the recovered device meets the verification conditions according to the keyword verification result and the time inference result, so as to determine whether a fingerprint collision occurs for the recovered device.

[0117] Optionally, before determining the keyword verification result of the recovered device according to the current device information of the recovered device and the historical device information associated with the target login ID, the device 50 further includes:

[0118] A fourth determination module, configured to determine a plurality of risk variables included in the running feature information and corresponding variable labels;

[0119] A calculation module, configured to calculate the variable labels corresponding to the plurality of risk variables by using a preset running risk formula to determine the risk score corresponding to the recovered device; if the risk score is less than the preset risk threshold, the recovered device has no running risk.

[0120] Optionally, the first determination module 502 is further configured to:

[0121] Obtain the historical device information of the first login using the target login ID;

[0122] Determine the corresponding first keyword field in the current device information and the corresponding second keyword field in the historical device information according to a preset device type;

[0123] Use the verification result of the first keyword field and the second keyword field as the keyword verification result of the recovered device.

[0124] Optionally, the second determination module 503 is further configured to:

[0125] Obtain the historical boot time recorded by the last logged-in device using the target login ID;

[0126] Use a preset time reasoning method to perform time reasoning on the current boot time included in the current device information and the historical boot time, and determine the time reasoning result of the device to be restored.

[0127] Optionally, the third determination module 504 is further configured to:

[0128] When the current device information is inconsistent with the historical device information, and the current boot time and the historical boot time do not conform to the preset time logic relationship, determine that a fingerprint collision has occurred on the device to be restored.

[0129] Optionally, the apparatus 50 further includes:

[0130] An adding module, configured to add a preset risk identifier to the device to be restored when there is an operation risk for the device to be restored.

[0131] The specific details of each module in the above fingerprint collision determination device have been described in detail in the corresponding fingerprint collision determination method, and thus will not be elaborated here.

[0132] It should be noted that although several modules or units of devices for action execution are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more of the above-mentioned modules or units can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0133] In addition, although the steps of the methods in the present disclosure are described in a specific order in the drawings, this does not require or imply that these steps must be executed in that specific order, or that all the steps shown must be executed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.

[0134] In an exemplary embodiment of the present disclosure, there is also provided an electronic device capable of implementing the above method.

[0135] Those skilled in the art can understand that various aspects of the present disclosure can be implemented as a system, method, or program product. Therefore, various aspects of the present disclosure can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to herein as "circuitry", "module", or "system".

[0136] Reference is now made to Figure 6 to describe the electronic device 600 according to such an embodiment of the present disclosure. Figure 6 The electronic device 600 shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0137] As Figure 6 shown, the electronic device 600 is presented in the form of a general-purpose computing device. The components of the electronic device 600 may include, but are not limited to: at least one of the above-mentioned processing units 610, at least one of the above-mentioned storage units 620, a bus 630 connecting different system components (including the storage unit 620 and the processing unit 610), and a display unit 640.

[0138] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 610, so that the processing unit 610 executes the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification. For example, the processing unit 610 can execute steps such as Figure 1 shown in S101, obtain the information to be verified of multiple restored devices within a target time period; the information to be verified includes a target login ID, running feature information, and current device information; step S102, when there is no running risk in the running feature information of the restored device, determine the keyword verification result of the restored device according to the current device information of the restored device and the historical device information associated with the target login ID; step S103, determine the time inference result of the restored device according to the current boot time included in the current device information and the historical boot time recorded by the target login ID; step S104, for each restored device, when the keyword verification result and the time inference result do not meet the preset verification conditions, determine that the restored device has a fingerprint collision.

[0139] The storage unit 620 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 6201 and / or a cache storage unit 6202, and may further include a read-only storage unit (ROM) 6203.

[0140] The storage unit 620 may also include a program / utilities 6204 having a set (at least one) of program modules 6205. Such program modules 6205 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.

[0141] The bus 630 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus structures.

[0142] The electronic device 600 may also communicate with one or more external devices 700 (such as a keyboard, a pointing device, a Bluetooth device, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 600, and / or may communicate with any device that enables the electronic device 600 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication may be carried out through the input / output (I / O) interface 650. Also, the electronic device 600 may communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 660. As shown in the figure, the network adapter 660 communicates with other modules of the electronic device 600 through the bus 630. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0143] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or can be implemented by the way of software combined with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a portable hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0144] In an exemplary embodiment of the present disclosure, a computer-readable storage medium is further provided, on which a program product capable of implementing the above methods in this specification is stored. In some possible implementation manners, various aspects of the present disclosure may also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to cause the terminal device to execute the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification.

[0145] The program product for implementing the above method according to an embodiment of the present disclosure may be a portable compact disc read-only memory (CD-ROM) and includes program code, and may run on a terminal device, such as a personal computer. However, the program product of the present disclosure is not limited thereto. In this document, the readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in combination with an instruction execution system, apparatus, or device.

[0146] The program product may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0147] The computer-readable signal medium may include a data signal propagated in a baseband or as a part of a carrier wave, which carries the readable program code. Such a propagated data signal may take various forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The readable signal medium may also be any readable medium other than the readable storage medium, and the readable medium may send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.

[0148] The program code included on the readable medium may be transmitted by any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the above.

[0149] Program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computing device, partially on the user's device, as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).

[0150] In addition, the above-mentioned drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present disclosure, rather than for limiting purposes. It is easy to understand that the processes shown in the above-mentioned drawings do not indicate or limit the chronological order of these processes. Additionally, it is also easy to understand that these processes may be executed synchronously or asynchronously, for example, in multiple modules.

[0151] Other embodiments of the present disclosure will be readily envisioned by those of ordinary skill in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the art not invented by the present disclosure. The specification and examples are to be considered exemplary only, and the true scope and spirit of the present disclosure are pointed out by the claims.

Claims

1. A fingerprint collision determination method, characterized in that, The method includes: Obtaining verification information to be verified for multiple restored devices within a target time period; the verification information to be verified includes a target login ID, operating characteristic information, and current device information; When there is no operating risk in the operating characteristic information of the restored device, determining a keyword verification result of the restored device according to the current device information of the restored device and the historical device information associated with the target login ID; Determining a time inference result of the restored device according to the order of the current boot time included in the current device information and the historical boot time recorded by the target login ID; For each restored device, when the keyword verification result and the time inference result do not meet the preset verification conditions, determining that a fingerprint collision occurs for the restored device.

2. The method according to claim 1, characterized in that, Before determining the keyword verification result of the restored device according to the current device information of the restored device and the historical device information associated with the target login ID, a preset operating risk formula, the method further includes: Determining a plurality of risk variables and corresponding variable labels included in the operating characteristic information; Calculating the variable labels corresponding to the plurality of risk variables by using the preset operating risk formula to determine a risk score corresponding to the restored device; If the risk score is less than a preset risk threshold, there is no operating risk for the restored device.

3. The method according to claim 1, wherein The determining the keyword verification result of the restored device according to the current device information of the restored device and the historical device information associated with the target login ID includes: Obtaining the historical device information for the first login using the target login ID; Determining a corresponding first keyword field in the current device information and a corresponding second keyword field in the historical device information according to a preset device type; Using the verification result of the first keyword field and the second keyword field as the keyword verification result of the restored device.

4. The method according to claim 1, wherein The determining the time inference result of the restored device according to the order of the current boot time included in the current device information and the historical boot time recorded by the target login ID includes: Obtaining the historical boot time recorded by the device for the last login using the target login ID; Performing time inference on the current boot time included in the current device information and the historical boot time by using a preset time inference method to determine the time inference result of the restored device.

5. The method according to claim 1, characterized in that, The determining that a fingerprint collision occurs for the restored device when the keyword verification result and the time inference result do not meet the preset verification conditions includes: When the current device information is inconsistent with the historical device information and the current boot time and the historical boot time do not meet a preset time logic relationship, determining that a fingerprint collision occurs for the restored device.

6. The method according to claim 1, wherein The method further includes: When there is an operating risk for the restored device, adding a preset risk identifier to the restored device.

7. A fingerprint collision determination device, characterized in that The device includes: An acquisition module, configured to acquire the information to be verified of multiple restored devices within a target time period; the information to be verified includes a target login ID, operating characteristic information, and current device information; A first determination module, configured to determine the keyword verification result of the restored device according to the current device information of the restored device and the historical device information associated with the target login ID when there is no operating risk in the operating characteristic information of the restored device; A second determination module, configured to determine the time inference result of the restored device according to the sequence of the current boot time included in the current device information and the historical boot time recorded by the target login ID; A third determination module, configured to determine that a fingerprint collision occurs for each restored device when the keyword verification result and the time inference result do not meet the preset verification conditions; 8. The device according to claim 7, characterized in that Before determining the keyword verification result of the restored device according to the current device information of the restored device and the historical device information associated with the target login ID, the apparatus further includes: A fourth determination module, configured to determine multiple risk variables included in the operating characteristic information and corresponding variable labels; A calculation module, configured to calculate the variable labels corresponding to the multiple risk variables by using a preset operating risk formula to determine the risk score corresponding to the restored device; if the risk score is less than a preset risk threshold, there is no operating risk for the restored device.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, The computer program, when executed by a processor, implements the fingerprint collision determination method according to any one of claims 1-6.

10. An electronic device, characterized in that, Including: A processor; And A memory, configured to store executable instructions of the processor; Wherein, the processor is configured to execute the fingerprint collision determination method according to any one of claims 1-6 by executing the executable instructions.

Citation Information

Patent Citations

  • Equipment verification method and device, equipment and storage medium

    CN110837635A

  • Malicious behavior detection method based on non-intrusive power terminal time sequence monitoring

    CN111932051A

  • Risk state determination method and device and electronic equipment

    CN115270137A