Data processing method, device, equipment and computer-readable storage medium
By obtaining the unified anonymous identifier of the target device and the account to be verified, combining with the blockchain network to determine the security level, and setting a human-computer verification strategy, the cumbersome problem of account verification in the existing technology is solved, and a flexible and convenient verification process is achieved.
Patent Information
- Application Number
- CN202211194697.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-03-30
- Filing Date
- 2022-09-28
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2042-09-28
AI Technical Summary
In the prior art, the verification process caused by the application or website passing Turing test during account verification is cumbersome, and it is impossible to effectively distinguish between malicious nodes and legitimate users.
By obtaining the unified anonymous identifier of the target device and the account to be verified, combining the associated records in the blockchain network, the security level of the target device is determined, and a human-machine verification strategy is set according to the security level.
A flexible and convenient account verification process is realized, reducing the risk of malicious attacks and improving verification efficiency.
Smart Images

Figure CN115622753B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a data processing method, apparatus, device, and computer-readable storage medium. Background Art
[0002] With the continuous development of computer technology, the use of applications and websites has become an indispensable part of people's lives. When using an application or visiting a website, an object usually needs to log in to an account to obtain the full functionality of the application or website. In actual applications, malicious nodes may use other people's accounts (such as mobile phone numbers) to request logins in multiple applications or websites, causing others to be harassed by verification information (such as mobile phone numbers being "bombed with text messages"). Practice has found that in order to improve the above situation, application operators or website operators usually use Turing tests to verify whether the current device is a malicious node (such as verifying whether it is batch machine behavior) before performing account verification, which makes the account verification process more cumbersome. Summary of the Invention
[0003] Embodiments of the present invention provide a data processing method, apparatus, device, and computer-readable storage medium, which can make the account verification process more flexible and convenient.
[0004] In one aspect, an embodiment of the present application provides a data processing method, comprising:
[0005] In response to an authorization operation of the target device, obtaining a unified anonymous identifier of the target device;
[0006] Obtain a pending account, which is used to request login to a website or application;
[0007] Determine the security level of the target device based on the account to be verified and the unified anonymous identifier;
[0008] Based on the security level of the target device, determine the human-machine verification strategy corresponding to the target device.
[0009] In one aspect, an embodiment of the present application provides a data processing device, comprising:
[0010] an acquiring unit, configured to acquire a unified anonymous identifier of the target device in response to an authorization operation of the target device; and to acquire an account to be verified, the account to be verified being used to request to log into a website or application;
[0011] The processing unit is used to determine the security level of the target device according to the account to be verified and the unified anonymous identifier; and to determine the human-machine verification strategy corresponding to the target device based on the security level of the target device.
[0012] In one embodiment, the processing unit is configured to determine the security level of the target device based on the account to be verified and the unified anonymous identifier, specifically to:
[0013] Determine the trustworthiness of the target device based on the account to be verified and the unified anonymous identifier;
[0014] Determine the security level of the target device based on the trustworthiness of the target device;
[0015] Among them, the credibility of the target device is obtained based on one or more of the following: the account verification result associated with the account to be verified and the unified anonymous identifier, the human-machine verification result associated with the account to be verified and the unified anonymous identifier, the network parameters associated with the account to be verified and the unified anonymous identifier, the account verification method associated with the account to be verified and the unified anonymous identifier, the scene environment parameters associated with the account to be verified and the unified anonymous identifier, and the verification initiation time of the account verification or human-machine verification associated with the account to be verified and the unified anonymous identifier.
[0016] In one embodiment, the processing unit is configured to determine the security level of the target device based on the account to be verified and the unified anonymous identifier, specifically to:
[0017] If there is an associated record of a unified anonymous identifier in the target database or blockchain network, the security level of the target device is determined based on the associated record;
[0018] If there is no associated record of the unified anonymous identifier in the target database or blockchain network, the security level of the target device is determined to be the first security level.
[0019] In one embodiment, the association record of the unified anonymous identifier includes one or more accounts associated with the unified anonymous identifier and an account verification result of each account; the processing unit is configured to determine the security level of the target device based on the association record, specifically to:
[0020] If the account to be verified matches the target account associated with the unified anonymous identifier, the security level of the target device is determined based on the account verification result of the target account;
[0021] If the account to be verified does not match one or more accounts associated with the unified anonymous identifier, determining the security level of the target device to be a second security level;
[0022] The human-machine verification strategies corresponding to the second security level and the first security level are different.
[0023] In one embodiment, the associated record of the unified anonymous identifier further includes the account verification method of each account; the processing unit is configured to determine the security level of the target device based on the account verification result of the target account, specifically to:
[0024] If the target account's account verification result is passed, the target device's security level is determined based on the target account's account verification method;
[0025] If the target account fails the account verification, the target device's security level is set to the third security level.
[0026] The first security level, the second security level, and the third security level are different from each other.
[0027] In one embodiment, the account verification method includes a text message verification method and a one-click login method; the processing unit is configured to determine the security level of the target device based on the account verification method of the target account, specifically to:
[0028] If the target account's verification method is SMS verification, the target device's security level is set to level 4.
[0029] If the target account's authentication method is one-click login, the target device's security level is set to the fifth security level;
[0030] The first security level, the second security level, the third security level, the fourth security level and the fifth security level are different from each other.
[0031] In one embodiment, the processing unit is further configured to:
[0032] Obtain the account verification method of the account to be verified, and obtain the account verification result of the account to be verified under the account verification method;
[0033] The unified anonymous identifier, the account to be verified, the account verification method of the account to be verified, and the account verification result of the account to be verified are associated and stored in a target database or blockchain network.
[0034] In one embodiment, the account verification method of the account to be verified is a text message verification method; the processing unit is used to obtain the account verification result of the account to be verified under the account verification method, specifically to:
[0035] Generate account verification information for the account to be verified and return the account verification information to the owner of the account to be verified;
[0036] Obtain account verification information provided by the target device;
[0037] If the account verification information and the account verification information match, the account to be verified is determined to have passed the account verification.
[0038] In one embodiment, the processing unit is configured to obtain a unified anonymous identifier of the target device, specifically to:
[0039] Obtaining a unified anonymous identifier address provided by the identification service, and sending an instruction message to the target device, the instruction message carrying the unified anonymous identifier address, the instruction message being used to instruct the target device to access the unified anonymous identifier address through the cellular network;
[0040] Obtaining encrypted data returned by the target device, the encrypted data being obtained after the target device accesses the unified anonymous identifier address via the cellular network;
[0041] Send encrypted data to the identity service and obtain a unified anonymous identifier returned by the identity service. The unified anonymous identifier is obtained by the identity service through a token, which is obtained by decrypting the encrypted data.
[0042] In one embodiment, if the account to be verified passes the account verification, the processing unit is further configured to:
[0043] In response to a data management operation on the account to be verified, backing up the target data indicated by the data management operation to the blockchain network;
[0044] Process the target data according to data management operations;
[0045] Among them, data management operations include data deletion operations and authorization cancellation operations.
[0046] In one embodiment, the processing unit is configured to determine the security level of the target device based on the account to be verified and the unified anonymous identifier, specifically to:
[0047] Send the account to be verified and the unified anonymous identifier to the target database or blockchain network;
[0048] Obtain security indication information returned by the target database or blockchain network, where the security indication information is determined based on the association information between the account to be verified and the unified anonymous identifier;
[0049] Based on the security instructions, determine the security level of the target device.
[0050] In one embodiment, the processing unit is configured to determine the security level of the target device based on the account to be verified and the unified anonymous identifier, specifically to:
[0051] Obtain the account verification records associated with the unified anonymous identifier and the verification records of the account to be verified;
[0052] Perform feature extraction on the account verification record associated with the unified anonymous identifier and the verification record of the account to be verified, respectively, to obtain feature information of the account verification record associated with the unified anonymous identifier and feature information of the verification record of the account to be verified;
[0053] The security level of the target device is determined based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified.
[0054] In one embodiment, the characteristic information of the verification record of the account to be verified includes at least one of the following: the number of verifications of the account to be verified in the first time period, the number of unified anonymous identifiers associated with the account to be verified in the first time period;
[0055] The characteristic information of the account verification record associated with the unified anonymous identifier includes at least one of the following: a verification success rate corresponding to the unified anonymous identifier, and the number of accounts associated with the unified anonymous identifier in the second time period.
[0056] In one embodiment, the characteristic information of the verification record of the to-be-verified account includes the number of verifications of the to-be-verified account within a first period, and the characteristic information of the verification record of the account associated with the unified anonymous identifier includes the verification success rate corresponding to the unified anonymous identifier;
[0057] The processing unit is configured to determine a security level of the target device based on characteristic information of the account verification record and characteristic information of the verification record of the account to be verified within the first time period, specifically to:
[0058] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of verifications of the account to be verified within the first time period is greater than or equal to the number threshold, the security level of the target device is determined to be the first security level;
[0059] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of verifications of the account to be verified within the first time period is less than the number threshold, the security level of the target device is determined to be the second security level;
[0060] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of verifications of the account to be verified within the first time period is greater than or equal to the number threshold, the security level of the target device is determined to be the third security level;
[0061] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of verifications of the account to be verified within the first time period is less than the number threshold, the security level of the target device is determined to be the fourth security level.
[0062] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified in a first time period, and the characteristic information of the verification record of the account associated with the unified anonymous identifier includes the number of accounts associated with the unified anonymous identifier in a second time period;
[0063] The processing unit is configured to determine a security level of the target device based on characteristic information of the account verification record and characteristic information of the verification record of the account to be verified within the first time period, specifically to:
[0064] If the number of accounts associated with the unified anonymous identifier during the second period is greater than or equal to the first number threshold, and the number of verifications of the account to be verified during the first period is greater than or equal to the number threshold, then the security level of the target device is determined to be the first security level;
[0065] If the number of accounts associated with the unified anonymous identifier during the second period is greater than or equal to the first number threshold, and the number of verifications of the account to be verified during the first period is less than the number threshold, then the security level of the target device is determined to be the second security level;
[0066] If the number of accounts associated with the unified anonymous identifier during the second period is less than the first number threshold, and the number of verifications of the account to be verified during the first period is greater than or equal to the number threshold, then the security level of the target device is determined to be the third security level;
[0067] If the number of accounts associated with the unified anonymous identifier in the second period is less than the first number threshold, and the number of verifications of the account to be verified in the first period is less than the number threshold, the security level of the target device is determined to be the fourth security level.
[0068] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified within the first time period, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the verification success rate corresponding to the unified anonymous identifier;
[0069] The processing unit is configured to determine a security level of the target device based on characteristic information of the account verification record and characteristic information of the verification record of the account to be verified within the first time period, specifically to:
[0070] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to the second number threshold, then the security level of the target device is determined to be the first security level;
[0071] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second number threshold, then the security level of the target device is determined to be the second security level;
[0072] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to the second number threshold, then the security level of the target device is determined to be the third security level;
[0073] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second number threshold, the security level of the target device is determined to be the fourth security level.
[0074] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified during a first period of time, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the number of accounts associated with the unified anonymous identifier during a second period of time;
[0075] The processing unit is configured to determine a security level of the target device based on characteristic information of the account verification record and characteristic information of the verification record of the account to be verified within the first time period, specifically to:
[0076] If the number of accounts associated with the unified anonymous identifier during the second time period is greater than or equal to the first threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is greater than or equal to the second threshold, determining the security level of the target device to be the first security level;
[0077] If the number of accounts associated with the unified anonymous identifier during the second time period is greater than or equal to the first quantity threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is less than the second quantity threshold, determining the security level of the target device to be the second security level;
[0078] If the number of accounts associated with the unified anonymous identifier during the second time period is less than the first threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is greater than or equal to the second threshold, determining the security level of the target device to be a third security level;
[0079] If the number of accounts associated with the unified anonymous identifier in the second time period is less than the first quantity threshold, and the number of unified anonymous identifiers associated with the account to be verified in the first time period is less than the second quantity threshold, the security level of the target device is determined to be the fourth security level.
[0080] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified within a first time period; if the unified anonymous identifier is not associated with the account verification record, the processing unit is configured to determine the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first time period, specifically to:
[0081] Determine the range to which the security level of the target device belongs as the target range;
[0082] If the verification record of the account to be verified in the first period is greater than or equal to the number threshold, the security level of the target device is determined to be the first security level;
[0083] If the verification record of the account to be verified in the first period is less than the number threshold, the security level of the target device is determined to be the second security level;
[0084] Among them, the first security level and the second security level belong to the target range.
[0085] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified within a first time period; if the unified anonymous identifier is not associated with an account verification record, the processing unit is configured to determine the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first time period, specifically to:
[0086] Determine the range to which the security level of the target device belongs as the target range;
[0087] If the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to a second number threshold, determining the security level of the target device to be a first security level;
[0088] If the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than a second number threshold, determining the security level of the target device to be a second security level;
[0089] Among them, the first security level and the second security level belong to the target range.
[0090] In one embodiment, the processing unit is further configured to:
[0091] If it is detected that the account to be verified has violated the rules after passing the verification, the user identification card bound to the unified anonymous identifier corresponding to the account to be verified is obtained from the provider of the unified anonymous identifier;
[0092] Punish the user identification card or the user of the user identification card according to the corresponding processing rules of the violation.
[0093] In one embodiment, if the account to be verified passes the account verification, the processing unit is further configured to:
[0094] In response to a notification management operation of the account to be verified, updating a notification recipient corresponding to the account to be verified based on the notification management operation; and
[0095] When it is detected that the account to be verified meets the notification conditions, a notification is sent to the notification recipient corresponding to the account to be verified;
[0096] The notification includes at least one of the following: account login notification, account abnormality notification, and account operation notification.
[0097] Accordingly, the present application provides a computer device, comprising:
[0098] a memory, wherein a computer program is stored in the memory;
[0099] The processor is used to load a computer program to implement the above data processing method.
[0100] Accordingly, the present application provides a computer-readable storage medium, which stores a computer program, and the computer program is suitable for being loaded by a processor and executing the above-mentioned data processing method.
[0101] Accordingly, the present application provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the above-mentioned data processing method.
[0102] In the embodiment of the present application, in response to an authorization operation on a target device, a unified anonymous identifier for the target device is obtained, the account to be verified is obtained, the security level of the target device is determined based on the account to be verified and the unified anonymous identifier, and the human-machine verification strategy corresponding to the target device is determined based on the security level of the target device. It can be seen that during the account verification process, the security level of the target device can be determined based on the account to be verified and the unified anonymous identifier, and different human-machine verification strategies can be adopted for devices with different security levels, making the account verification process more flexible and convenient. BRIEF DESCRIPTION OF THE DRAWINGS
[0103] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0104] Figure 1a A schematic diagram of the architecture of a data sharing system provided in an embodiment of the present application;
[0105] Figure 1b A schematic diagram of the structure of a blockchain provided in an embodiment of the present application;
[0106] Figure 1c A schematic diagram of a block generation process provided in an embodiment of the present application;
[0107] Figure 1d An architectural diagram of a data processing system provided in an embodiment of the present application;
[0108] Figure 1e A schematic diagram of the interaction principle of a data processing solution provided in an embodiment of the present application;
[0109] Figure 2 A flowchart of a data processing method provided in an embodiment of the present application;
[0110] Figure 3a A schematic diagram of a login page provided in an embodiment of the present application;
[0111] Figure 3b A schematic diagram of another login page provided in an embodiment of the present application;
[0112] Figure 4 A flowchart of another data processing method provided in an embodiment of the present application;
[0113] Figure 5 A flowchart of obtaining a unified anonymous identifier of a target device provided in an embodiment of the present application;
[0114] Figure 6 A flowchart for obtaining an account to be verified provided in an embodiment of the present application;
[0115] Figure 7 A schematic diagram of the architecture of a blockchain network provided in an embodiment of the present application;
[0116] Figure 8 An interactive flow chart of a data processing method provided in an embodiment of the present application;
[0117] Figure 9 An interactive flow chart of another data processing method provided in an embodiment of the present application;
[0118] Figure 10 A schematic diagram of the structure of a data processing device provided in an embodiment of the present application;
[0119] Figure 11 A schematic diagram of the structure of a computer device provided in an embodiment of the present application;
[0120] Figure 12 A schematic diagram of the structure of a data processing device provided in an embodiment of the present application;
[0121] Figure 13 A schematic diagram of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0122] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0123] The embodiments of this application involve blockchain technology. The following is a brief introduction to the relevant terms and concepts of blockchain technology:
[0124] Blockchain is a new application model for computer technologies, including distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. It is essentially a decentralized database, a series of data blocks linked using cryptographic methods. Each block contains information about a batch of network transactions, which is used to verify the validity of this information (to prevent counterfeiting) and generate the next block. Blockchain can include the underlying blockchain platform, the platform product and service layer, and the application service layer.
[0125] The blockchain network can be understood as a data sharing system 100. The data sharing system 100 may refer to a system for sharing data between nodes. An exemplary structure of the data sharing system 100 can be found in Figure 1a ;like Figure 1a As shown, the data sharing system 100 refers to a system for sharing data between nodes, and the data sharing system may include multiple nodes 1001, and the multiple nodes 1001 may refer to each client in the data sharing system. Each node 1001 can receive input information during normal operation and maintain the shared data in the data sharing system based on the received input information. In order to ensure information intercommunication within the data sharing system, an information connection can exist between each node in the data sharing system, and information can be transmitted between nodes through the above-mentioned information connection. For example, when any node in the data sharing system receives input information, the other nodes in the data sharing system obtain the input information according to the consensus algorithm, and store the input information as data in the shared data, so that the data stored on all nodes in the data sharing system are consistent.
[0126] Each node in the data sharing system has a corresponding node identifier, and each node in the data sharing system can store the node identifiers of other nodes in the data sharing system so that the generated blocks can be broadcast to other nodes in the data sharing system based on the node identifiers of other nodes. Each node can maintain a node identifier list as shown in the following table, and store the node name and node identifier in the node identifier list accordingly. The node identifier can be an IP (Internet Protocol, a protocol for interconnecting networks) address or any other information that can be used to identify the node; for example, the node identifier can also be a binary serial code (such as 110001110). Table 1 only uses the IP address as an example for explanation:
[0127] Table 1
[0128] Node Name Node ID Node 1 117.114.151.174 Node 2 117.116.189.145 … … Node X (X is a positive integer) xx.xxx.xxx.xxx
[0129] Each node in the data sharing system stores the same blockchain. The blockchain consists of multiple blocks, see Figure 1b The blockchain consists of multiple blocks. The genesis block includes a block header and a block body. The block header stores the input information feature value, version number, timestamp and difficulty value, and the block body stores the input information; the next block of the genesis block uses the genesis block as the parent block, and the next block also includes a block header and a block body. The block header stores the input information feature value of the current block, the block header feature value, version number, timestamp and difficulty value of the parent block, and so on, so that the block data stored in each block in the blockchain is associated with the block data stored in the parent block, ensuring the security of the input information in the block.
[0130] When generating each block in the blockchain, see Figure 1c When the node where the blockchain is located receives the input information, it verifies the input information. After the verification is completed, the input information is stored in the memory pool and the hash tree used to record the input information is updated. After that, the update timestamp is updated to the time when the input information is received, and different random numbers are tried. The eigenvalue calculation is performed multiple times so that the calculated eigenvalue can satisfy the following formula:
[0131] SHA256(SHA256(version+prev_hash+merkle_root+ntime+nbits+x)) <TARGET
[0132] Among them, SHA256 is the eigenvalue algorithm used to calculate the eigenvalue; version (version number) is the version information of the relevant block protocol in the blockchain; prev_hash is the block header eigenvalue of the parent block of the current block; merkle_root is the eigenvalue of the input information; ntime is the update time of the update timestamp; nbits is the current difficulty, which is a fixed value within a period of time and is determined again after exceeding the fixed time period; x is a random number; TARGET is the eigenvalue threshold, which can be determined based on nbits.
[0133] In this way, when a random number that satisfies the above formula is calculated, the information can be stored accordingly, and the block header and block body can be generated to obtain the current block. Subsequently, the node where the blockchain is located will broadcast the newly generated block to other nodes in the data sharing system based on the node identifiers of other nodes in the data sharing system. The other nodes will perform consensus verification on the newly generated block and, after completing the consensus verification, add the newly generated block to their stored blockchain.
[0134] In addition, this application also relates to the International Mobile Equipment Identity (IMEI), which is a mobile phone serial number or "serial number" used to identify each individual mobile phone or other mobile communication device in a mobile phone network. The IMEI has 15 to 17 digits. The first 8 digits (TAC) are the model approval number (6 digits in the early days), which is used to distinguish the brand and model code of the terminal device; the next 2 digits (FAC) are the final assembly number (only present in early models), representing the final assembly location code; and the last 6 digits (SNR) are the serial number, representing the production sequence number. The International Mobile Equipment Identity is stored in the memory of the terminal device.
[0135] The Mobile Equipment Identifier (MEID), commonly used on Code Division Multiple Access (CDMA) devices, is an upgraded version of the ESN. It is a 14-digit hexadecimal number.
[0136] The International Mobile Subscriber Identity (IMSI) is a unique identifier used to distinguish different users on a cellular network. The terminal device stores the IMSI in a 64-bit field and sends it to the cellular network. The IMSI can be used to query information about an object in the Home Location Register (HLR) or Visitor Location Register (VLR). In some cases, a randomly generated Temporary Mobile Subscriber Identity (TMSI) is used instead of the IMSI for communications between the mobile phone and the network.
[0137] The Identifier for Advertising (IDFA) is a 32-bit hexadecimal string of numbers and letters that uniquely identifies a device. Each device has an IDFA, and different apps on the same device will generate the same IDFA.
[0138] The Uniform Anonymous Identifier (UAID) is an anonymous user identification service based on the IMEI and mobile phone number. In practice, IMEI and IDFA are difficult to obtain and pose a risk of tampering. UAID provides a more stable and unique device and object identifier for service recipients.
[0139] Based on the above introduction to the blockchain network structure and the unified anonymous identifier involved in the embodiment of this application, the following nodes introduce the data processing solution proposed by the embodiment of this application based on the above unified anonymous identifier and blockchain network structure, which can make the account verification process more flexible and convenient. Figure 1d , Figure 1d This is an architecture diagram of a data processing system provided in an embodiment of the present application. Figure 1dAs shown, the processing system may include: a target device 101, a server 102, an identifier provider 103, and a blockchain network 104. The data processing method provided in the embodiment of the present application can be executed by the server 102. The target device 101 may include, but is not limited to, smart phones (such as Android phones, iOS phones, etc.), tablet computers, portable personal computers, mobile Internet devices (MIDs), vehicle-mounted terminals, and other smart devices with display functions, which are not limited in the embodiment of the present application. The server 102 may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It may also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms, which are not limited in the embodiment of the present application. The identifier provider 103 may specifically be an operator device. Optionally, the identification provider 103 may also be a provider of other hardware identifications for uniquely indicating the target device (such as a device manufacturer). In this case, the unified anonymous identifier is replaced with the corresponding hardware identification (such as IMEI, IDFA, etc.).
[0140] It should be noted that Figure 1d The target device 101, server 102, identifier provider 103, and blockchain network 104 may be connected directly or indirectly via wired or wireless communication, which is not limited in this application. The number of target devices 101, servers 102, and identifier providers 103 is for example only and does not constitute an actual limitation of this application; for example, the data processing system may also include a target device 105, a server 106, etc.
[0141] It is understood that in the specific implementation of the present application, when it comes to obtaining the UAID of the target device, when the above embodiments of the present application are applied to specific products or technologies, it is necessary to obtain corresponding data acquisition permissions (such as the object authorizing the server 102), and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0142] Figure 1e This is a schematic diagram of the interaction principle of a data processing solution provided in an embodiment of the present application. Figure 1e As shown, the general principle of the data processing scheme is as follows:
[0143] S101. When a subject needs to log in to an application or website, a login page is displayed on the target device 101. The login page includes a description of the authorization rules (e.g., authorizing the current application or website to obtain a unified anonymous identifier for the target device). When the target device 101 detects the subject's authorization operation (e.g., the subject selects "Agree to authorize the current application or website"), the target device 101 authorizes the server 102 corresponding to the current application or website.
[0144] S102: After obtaining authorization, the server 102 sends an identification acquisition request to the identification provider 103. In the embodiment of the present application, a unified anonymous identifier is used as an example for explanation. The server 102 sends a unified anonymous identifier acquisition request to the identification provider 103 (such as an operator), and the request carries the authorization information of the target device 101.
[0145] S103 : After obtaining the identification acquisition request sent by the server 102 , the identification provider 103 verifies the authorization information carried in the identification acquisition request and returns the unified anonymous identifier of the target device 101 . The server 102 obtains the unified anonymous identifier of the target device 101 .
[0146] S104: Server 102 obtains the account to be verified provided by target device 101. The account to be verified is used to log in to the application or website corresponding to server 102. The account to be verified can specifically be the subject's mobile phone number. In one embodiment, the subject can enter the account to be verified on target device 101 and send it to server 102. In another embodiment, the account to be verified can be obtained by server 102 through a number retrieval service after obtaining authorization.
[0147] S105. Server 102 sends the account to be verified provided by target device 101 and the unified anonymous identifier of target device 101 to blockchain network 104. Optionally, blockchain network 104 can also be replaced by a target database, which can be installed in server 102 or maintained separately by a third party (such as a regulatory authority). In addition, server 102 can also provide blockchain network 104 with security level reference information such as network parameters of the target device (such as base station cell ID, geographic information, IP address, etc.), scene environment parameters (such as application identification or website identification), account verification method, human-machine verification results, etc.
[0148] S106: After receiving the unified anonymous identifier and the account to be verified from server 102, blockchain network 104 queries the blockchain network for association records associated with the unified anonymous identifier and the account to be verified, and determines the security level of target device 101 based on the association records. In one embodiment, the association records include: one or more accounts associated with the unified anonymous identifier, the account verification results for each account; and the account verification method for each account; the account verification method may include, but is not limited to, SMS verification, telephone voice verification code verification, and one-click login. Furthermore, the account verification process may also include additional Turing tests, facial recognition, and other biometric identification methods. These can be configured based on actual needs and are not limited by this application. If the target database or blockchain network does not have an associated record for the unified anonymous identifier, the target device's security level is determined to be the first security level. If the target database or blockchain network does have an associated record for the unified anonymous identifier, and the account to be verified does not match one or more accounts associated with the unified anonymous identifier, the target device's security level is determined to be the second security level. If the account to be verified matches the target account associated with the unified anonymous identifier, and the target account's account verification result is a failure, the target device's security level is determined to be the third security level. If the target account's account verification result is a success, and the target account's verification method is SMS verification or phone voice verification, the target device's security level is determined to be the fourth security level. If the target account's account verification result is a success, and the target account's verification method is one-click login, the target device's security level is determined to be the fifth security level. The first security level, the second security level, the third security level, the fourth security level, and the fifth security level are each different from one another.
[0149] S107. The server 102 obtains the security level of the target device 101 returned by the blockchain network 104, and determines the human-machine verification strategy corresponding to the target device 101 (such as the number of times the human-machine verification is performed, the method of human-machine verification, etc.) based on the security level.
[0150] Optionally, if the unified anonymous identifier of the target device cannot be obtained (for example, if the target device is not equipped with a SIM card, a UAID cannot be generated), the security level of the target device is determined to be the sixth security level; further, for target devices of the sixth security level, the human-machine verification strategy can be set to prohibit the use of SMS verification codes for verification, so as to reduce the risk of the account to be verified being maliciously attacked (such as SMS bombing). The human-machine verification strategies that can be used include but are not limited to: code scanning verification, uplink SMS (i.e., actively sending SMS carrying verification information to the server) verification.
[0151] In the embodiment of the present application, in response to an authorization operation on a target device, a unified anonymous identifier for the target device is obtained, the account to be verified is obtained, the security level of the target device is determined based on the account to be verified and the unified anonymous identifier, and the human-machine verification strategy corresponding to the target device is determined based on the security level of the target device. It can be seen that during the account verification process, the security level of the target device can be determined based on the account to be verified and the unified anonymous identifier, and different human-machine verification strategies can be adopted for devices with different security levels, making the account verification process more flexible and convenient.
[0152] Based on the above data processing scheme, the embodiment of the present application proposes a more detailed data processing method. The data processing method proposed in the embodiment of the present application will be introduced in detail below with reference to the accompanying drawings.
[0153] Figure 2 This is a flow chart of a data processing method provided in an embodiment of the present application. The data processing method can be executed by a computer device, which can be Figure 1d As shown in the server 102. Figure 2 As shown, the data processing method may include but is not limited to steps S201-S204:
[0154] S201: In response to an authorization operation of a target device, obtain a unified anonymous identifier of the target device.
[0155] The target device's authorization operation grants the computer device permission to access the target device's unified anonymous identifier. After receiving authorization from the target device, the computer device obtains the target device's unified anonymous identifier, which uniquely identifies the target device. The unified anonymous identifier is derived from the target device's IMEI and the identifier (mobile phone number) associated with the target device's Subscriber Identity Module (SIM).
[0156] Figure 3a This is a schematic diagram of a login page provided in an embodiment of the present application. Figure 3aAs shown, when an object needs to log in to an application or website, the target device displays a login page 301. The login page 301 includes an authorization entry 3015. The authorization entry 3015 is used to authorize the application or website corresponding to the login page 301. When the authorization information (related permissions and rules) carried in the authorization entry 3015 is confirmed (e.g., the object checks the authorization information carried in the authorization entry 3015), the application or website corresponding to the login page 301 is granted the corresponding permissions (e.g., the permission to obtain the target device's unified anonymous identifier). In addition, the login page 301 may also include an account input field 3011, a verification information input field 3012, a verification information acquisition entry 3013, and a login button 3014. The account input field 3011 is used to enter an account, the verification information input field 3012 is used to enter verification information, the verification information acquisition entry 3013 is used to obtain verification information (e.g., sending a verification code to the mobile phone number entered in the account input field 3011), and the login button 3014 is used to confirm the information on the login page 301 and log in.
[0157] Figure 3b This is another login page diagram provided in this embodiment of the application. Figure 3a As shown, login page 302 includes a pending account display area 3021, a login button 3022, and an authorization entry 3023. The pending account display area 3021 is used to display the account requiring one-click login. This account can be a plain text account or an account mask, which is not limited in this application. It should be noted that the account in the pending account display area 3021 can be displayed after being sent to the target device by a computer device via a number retrieval service, or can be directly entered by the subject on the target device. The specific functions of the login button 3022 and authorization entry 3023 on login page 302 are similar to those on page 301 and will not be repeated here.
[0158] S202: Obtain the account to be verified.
[0159] The account to be verified is the account used by the object to request a login URL or application. This account can specifically be a mobile phone number, email address, social application account, network platform account, etc. It should be noted that based on the account to be verified, the "previously logged-in devices" (i.e., devices that have been logged in historically) of the account can be determined. In the subsequent process of determining the security level of the target device, the computer device can judge the security level by combining the UAID and the "previously logged-in devices" associated with the account to be verified; for example, if the account associated with the UAID recorded in the blockchain network includes the account to be verified, and the login result of the account to be verified is successful, and the "previously logged-in devices" associated with the account to be verified include the target device, then the computer device will determine that the target device is trustworthy.
[0160] In one embodiment, the account to be verified is sent by the target device to the computer device. Specifically, the subject can enter the account to be verified in the account input field, and the target device, after obtaining the account to be verified entered by the subject, sends the account to be verified to the computer device.
[0161] In another embodiment, the account to be verified is obtained by the computer device through a number obtaining service after obtaining authorization.
[0162] S203: Determine the security level of the target device based on the account to be verified and the unified anonymous identifier.
[0163] The security level of the target device is used to indicate the security level of the target device. Different security levels indicate different security levels. The specific security level can be set according to actual needs, and this application does not impose any restrictions on this.
[0164] The security level of the target device can be determined instantly based on the account to be verified, the unified anonymous identifier, and the current status of the target device (such as network parameters, scene environment parameters, etc.), or it can be determined by a computer device through full calculation based on historical data associated with the account to be verified and the unified anonymous identifier. It can also be determined by a computer device through batch calculation based on a certain period of time (such as within 30 days), or when the number of historical data associated with the account to be verified and the unified anonymous identifier reaches a threshold.
[0165] In one embodiment, a computer device is equipped with a database, and the computer device determines the credibility of a target device based on an account to be verified and a unified anonymous identifier; and determines a security level of the target device based on the credibility of the target device; wherein the credibility of the target device is obtained based on one or more of the following: an account verification result (such as a success rate) associated with the account to be verified and the unified anonymous identifier, a ratio of security operations (such as changing a password, etc.) to non-security operations of the account to be verified after successful verification, a human-machine verification result associated with the account to be verified and the unified anonymous identifier, network parameters (such as a base station cell ID, geographic information, IP address, etc.) associated with the account to be verified and the unified anonymous identifier, an account verification method associated with the account to be verified and the unified anonymous identifier, scenario environment parameters (such as an application identifier or a website identifier, etc.) associated with the account to be verified and the unified anonymous identifier, a verification initiation time of the account verification or human-machine verification associated with the account to be verified and the unified anonymous identifier, a frequency of account verification associated with the account to be verified per unit time, a frequency of human-machine verification associated with the unified anonymous identifier per unit time, etc.
[0166] For example, if the geographic information associated with the account to be verified and the unified anonymous identifier matches the geographic information of the target device, the computer device may set the credibility of the target device to 80; if the geographic information associated with the account to be verified and the unified anonymous identifier does not match the geographic information of the target device, the computer device may set the credibility of the target device to 50. For another example, if the verification initiation time of the account verification or human-machine verification associated with the account to be verified and the unified anonymous identifier is less than a time threshold compared to the current time, the computer device may set the credibility of the target device to 30; if the verification initiation time of the account verification or human-machine verification associated with the account to be verified and the unified anonymous identifier is greater than or equal to the time threshold compared to the current time, the computer device may set the credibility of the target device to 70.
[0167] The specific implementation method of the computer device determining the security level of the target device based on the credibility of the target device is: determining the security level of the target device based on the value range of the credibility; for example, the credibility [0, 20) corresponds to the first security level, the credibility [20, 40) corresponds to the second security level, the credibility [40, 60) corresponds to the third security level, the credibility [60, 80) corresponds to the fourth security level, and the credibility [80, 100] corresponds to the fifth security level.
[0168] In another embodiment, the computer device sends the account to be verified and the unified anonymous identifier to the target database or blockchain network, and obtains the security level of the target device returned by the target database or blockchain network. It should be noted that the target database or blockchain network can directly return the security level of the target device to the computer device, or it can return the security indication information of the target device to the computer device (such as whether there is an account verification record that matches the account to be verified and the unified anonymous identifier, whether there is a human-machine verification record that matches the account to be verified and the unified anonymous identifier, etc.), and the computer device determines the security level of the target device based on the security indication information of the target device. The implementation method of the target database or blockchain network determining the security level of the target device based on the account to be verified and the unified anonymous identifier can refer to the implementation method of the computer device determining the security level of the target device based on the account to be verified and the unified anonymous identifier in the previous implementation method, and will not be repeated here.
[0169] Optionally, the computer device can calculate the credibility of the target device based on the account to be verified or based on a unified anonymous identifier, and determine the security level of the target device based on the credibility; for example, if a mobile phone number performs account verification on different devices multiple times and the account verification fails, the owner of the mobile phone number may be "bombed with text messages"; for another example, if a device participates in the account verification of multiple mobile phone numbers and the account verification fails, the device may be a malicious node (that is, the computer device determines that the device has low credibility).
[0170] S204: Determine a human-machine verification strategy corresponding to the target device based on the security level of the target device.
[0171] The human-machine verification strategy may include the method of human-machine verification, the number of human-machine verification, etc. Different security levels may correspond to the same or different human-machine verification strategies, which can be set specifically according to actual needs. This application does not impose any restrictions on this; for example, security level 1-security level 5 can correspond to human-machine verification strategy 1-human-machine verification strategy 5 respectively; for another example, among security levels 1-security level 5, security level 1 and security level 2 can correspond to human-machine verification strategy 1, security level 3 and security level 4 can correspond to human-machine verification strategy 2, and security level 5 can correspond to human-machine verification strategy 3.
[0172] Optionally, after determining the human-machine verification strategy corresponding to the target device, the computer device can also perform auxiliary verification through one or more security verification methods, including: SMS verification, biometric (fingerprint, voice, face, etc.) verification, associated account auxiliary verification (such as auxiliary verification through the "friend" account of the account to be verified, or auxiliary verification through other accounts bound to the account to be verified (such as email, social accounts, etc.)), telephone verification, password verification, etc.
[0173] In the embodiment of the present application, in response to an authorization operation on a target device, a unified anonymous identifier for the target device is obtained, the account to be verified is obtained, the security level of the target device is determined based on the account to be verified and the unified anonymous identifier, and the human-machine verification strategy corresponding to the target device is determined based on the security level of the target device. It can be seen that during the account verification process, the security level of the target device can be determined based on the account to be verified and the unified anonymous identifier, and different human-machine verification strategies can be adopted for devices with different security levels, making the account verification process more flexible and convenient.
[0174] Figure 4 This is a flow chart of another data processing method provided in an embodiment of the present application. The data processing method can be executed by a computer device, which can be Figure 1d As shown in the server 102. Figure 4 As shown, the data processing method may include but is not limited to steps S401-S406:
[0175] S401: In response to an authorization operation of a target device, obtain a unified anonymous identifier of the target device.
[0176] Figure 5 This is a flowchart of obtaining a unified anonymous identifier of a target device provided by an embodiment of the present application. Figure 5 As shown, the process of obtaining the unified anonymous identifier of the target device is as follows:
[0177] Step S501-Step S502: The target device obtains the identification address (URL address, i.e., unified anonymous identifier address) specified by the identification function from the identification service through the computer device (server); for example, the application in the target device requests the central database through the server of the application, or the mobile phone verification center provides an identification service to generate an identification address.
[0178] Step S503: The identification service generates an identification address, which may carry the Advanced Encryption Standard (AES) and signature of the identification service, and encrypts the Advanced Encryption Standard (AES) and signature of the identification service using the RSA public key of the operator gateway.
[0179] Step S504: The identification service returns the identification address to the target device; in another implementation, the identification service can return the identification address to the server, and the server sends an indication message to the target device, which carries the identification address (i.e., the unified anonymous identifier address), and the indication message is used to instruct the target device to access the identification address through the cellular network.
[0180] Step S505: the target device connects to the operator base station through the cellular data network according to the instruction of the identification address. The operator gateway identifies the service demand through the identification address and records the unified anonymous identifier of the target device.
[0181] Step S506: The operator gateway decrypts the service using its own private key to obtain the Advanced Encryption Standard (AES) and signature of the identification service, and encrypts the first token (accessCode) using AES to obtain first encrypted data.
[0182] Step S507-Step S509: The operator gateway returns the first encrypted data to the target device, and the target device returns the first encrypted data to the identification service through the server.
[0183] Step S510: The identification service decrypts the first encrypted data through AES to obtain a first token (accessCode).
[0184] Step S511: The identification service encrypts the first token (accessCode) using the RSA public key of the operator gateway to obtain the encrypted first token, and sends the encrypted first token to the operator gateway; for example, the identification service can send a unified anonymous identifier acquisition request to the operator gateway, and the unified anonymous identifier acquisition request carries the encrypted first token and the signature of the identification service.
[0185] Step S512: the operator gateway decrypts the encrypted first token (accessCode) and returns a unified anonymous identifier to the identification service according to the first token (accessCode).
[0186] Step S513: The identification service returns a unified anonymous identifier to the server, and the server can determine the subsequent business processing logic according to its own needs.
[0187] It can be understood that during the network interaction process of the above steps S501 to S513, communication security is ensured through technical means such as session key + public and private key encrypted transmission and IP locking.
[0188] S402: Obtain the account to be verified.
[0189] Figure 6 This is a flowchart of obtaining an account to be verified provided in an embodiment of the present application. Figure 6 As shown, the process of obtaining the account to be verified is as follows:
[0190] Step S601-Step S602: The target device obtains the number retrieval address (URL address) specified by the number retrieval function from the number retrieval service through the computer device (server); for example, the application in the target device requests the central database through the server of the application, or the mobile phone verification center provides the number retrieval service to generate the number retrieval address.
[0191] Step S603: The number retrieval service generates a number retrieval address, which can carry the Advanced Encryption Standard (AES) and signature of the number retrieval service, and encrypts the Advanced Encryption Standard (AES) and signature of the number retrieval service using the RSA public key of the operator gateway.
[0192] Step S604: The number retrieval service returns the number retrieval address to the target device.
[0193] Step S605: The target device connects to the operator base station through the cellular data network according to the instructions of the number acquisition address. The operator gateway identifies the service demand through the number acquisition address and records the mobile phone number used by the target device to use the cellular data network.
[0194] Step S606: The operator gateway decrypts the number retrieval service using its own private key to obtain the Advanced Encryption Standard (AES) and signature, and uses AES to encrypt the mobile phone number mask (e.g., the mask of 13812341234 is 138xxxx1234) and the second token (accessCode) to obtain the second encrypted data.
[0195] Step S607-Step S609: The operator gateway returns the second encrypted data to the target device, and the target device returns the second encrypted data to the number retrieval service through the server.
[0196] Optionally, the operator gateway may only return a determination result of whether the mobile phone number corresponding to the SIM card loaded in the target device is consistent with the mobile phone number entered by the user.
[0197] Step S610: The number retrieval service decrypts the second encrypted data through AES to obtain the mask of the mobile phone number and the second token (accessCode).
[0198] Step S611: The target device receives the mask of the mobile phone number returned by the number retrieval service and displays the mask to the object. The object confirms whether the mask is the mobile phone number that needs to be verified (i.e., the account to be verified); if the mask is not the mobile phone number that needs to be verified, the object can enter the account to be verified by himself and perform account verification; if the mask is the mobile phone number that needs to be verified, the object can authorize the server to obtain the complete mobile phone number corresponding to the mask through a confirmation operation (i.e., agree to use the complete mobile phone number corresponding to the mask for account verification).
[0199] Step S612-Step S613: After obtaining authorization from the target device, the server sends a mobile phone number acquisition request to the number acquisition service.
[0200] Step S614: The number retrieval service encrypts the second token (accessCode) using the RSA public key of the operator gateway to obtain the encrypted second token, and sends the encrypted second token to the operator gateway; for example, the number retrieval service can send a mobile phone number retrieval request to the operator gateway, and the mobile phone number retrieval request carries the encrypted second token and the signature of the number retrieval service.
[0201] Step S615: The operator gateway decrypts the encrypted second token (accessCode) and determines the complete mobile phone number according to the second token (accessCode).
[0202] Step S616: The operator gateway returns the complete mobile phone number to the number retrieval service.
[0203] Step S617: After obtaining the complete mobile phone number, the number retrieval service returns the complete mobile phone number to the server, and the server can determine the subsequent business processing logic according to its own needs.
[0204] It can be understood that during the network interaction process of the above steps S601 to S617, communication security is ensured through technical means such as session key + public and private key encrypted transmission and IP locking.
[0205] S403: Determine the security level of the target device based on the account to be verified and the unified anonymous identifier.
[0206] In one embodiment, the computer device searches a target database (such as a database onboard itself or a database maintained by a third party) or a blockchain network to see whether there is an associated record of the unified anonymous identifier. If there is an associated record of the unified anonymous identifier in the target database or blockchain network, the computer device may determine the security level of the target device based on the associated record. If there is no associated record of the unified anonymous identifier in the target database or blockchain network (i.e., there is no information related to the unified anonymous identifier), the computer device determines the security level of the target device as the first security level.
[0207] Furthermore, when there is an associated record of a unified anonymous identifier in the target database or blockchain network, the associated record of the unified anonymous identifier may include one or more accounts associated with the unified anonymous identifier, as well as the account verification result of each account. The computer device checks whether there is a target account that matches the account to be verified in the one or more accounts associated with the unified anonymous identifier. If there is a target account that matches the account to be verified in the one or more accounts associated with the unified anonymous identifier (that is, the account to be verified matches the target account associated with the unified anonymous identifier), the computer device may determine the security level of the target device based on the account verification result of the target account; if there is no target account that matches the account to be verified in the one or more accounts associated with the unified anonymous identifier (that is, the account to be verified does not match the one or more accounts associated with the unified anonymous identifier), the computer device determines the security level of the target device to be the second security level.
[0208] Furthermore, when a target account that matches the account to be verified is included in one or more accounts associated with the unified anonymous identifier, the associated record of the unified anonymous identifier may also include the account verification method of each account (such as SMS verification method, one-click login method, etc.). The specific method in which the computer device determines the security level of the target device based on the account verification result of the target account is as follows: if the account verification result of the target account is passed, the computer device may determine the security level of the target device based on the account verification method of the target account; if the account verification result of the target account is failed, the computer device determines the security level of the target device as the third security level.
[0209] Furthermore, the account verification method may include a text message verification method and a one-click login method. The specific implementation method of the computer device determining the security level of the target device based on the account verification method of the target account is: if the verification method of the target account is a text message verification method, the computer device determines the security level of the target device as the fourth security level; if the verification method of the target account is a one-click login method, the computer device determines the security level of the target device as the fifth security level.
[0210] It should be noted that the first security level, the second security level, the third security level, the fourth security level and the fifth security level are different from each other.
[0211] S404: Determine a human-machine verification strategy corresponding to the target device based on the security level of the target device.
[0212] The specific implementation of step S404 can be found in Figure 2 The implementation of step S204 is not described here in detail. Optionally, if the target device's unified anonymous identifier cannot be obtained (e.g., if the target device does not have a SIM card installed, a UAID cannot be generated), the target device's security level is determined to be the sixth security level. Furthermore, for target devices at the sixth security level, the human-machine verification strategy can be set to prohibit the use of SMS verification codes for verification, thereby reducing the risk of malicious attacks (e.g., SMS bombing) on the account to be verified. The human-machine verification strategies that can be used include, but are not limited to, code scanning verification and uplink SMS verification (i.e., actively sending SMS messages carrying verification information to the server).
[0213] In one embodiment, if the human-machine verification policy corresponding to the target device indicates: perform human-machine verification on the target device, the computer device will associate and store the unified anonymous identifier, the account to be verified and the result of the human-machine verification in the target database or blockchain network.
[0214] S405: Obtain the account verification method of the account to be verified, and obtain the account verification result of the account to be verified under the current account verification method.
[0215] The account verification result is used to indicate whether the account to be verified has passed the verification. In one embodiment, the account verification method is SMS verification, and the target device's verification request (such as the target device's Figure 3a After entering the account to be verified in the account input field 3011 shown, click on the verification information acquisition entry 3013), the computer device generates account verification information of the account to be verified (such as generating a text message verification code), and returns the account verification information to the owner of the account to be verified (such as sending a text message verification code to the mobile phone number entered by the object); the computer device obtains the account verification information provided by the target device (such as after the object receives the text message verification code through the entered mobile phone number, it enters the text message verification code in the verification information input field 3012); after obtaining the account verification information provided by the target device, the computer device compares the account verification information and the account verification information. If the account verification information and the account verification information match, the computer device determines that the account to be verified has passed the account verification; correspondingly, if the account verification information and the account verification information do not match, the computer device determines that the account to be verified has not passed the account verification.
[0216] Furthermore, in addition to recording relevant data of the target device during the account verification process (such as account verification results, account verification method, human-machine verification results, network parameters, etc.), if the account to be verified passes the account verification, the computer device will also record the operations of the verified account.
[0217] After the account verification is passed, the subject can query the data related to the account (such as the bound certificate information, etc.), and can manage the account (such as deleting the data in the account, canceling authorization, unsubscribing, suspending the receipt of verification messages, etc.), and can also manage the notification recipient corresponding to the account to be verified; for example, the subject can set the notification recipient corresponding to the account to be verified through the account management page (such as entering the mobile phone number, email address, etc. of the notification recipient). Furthermore, when the computer device detects that the account to be verified meets the notification conditions (such as the account to be verified fails to verify N times within the target time period, N is a positive integer; the unified anonymous identifier used to verify the account to be verified has no association with the account to be verified; the relevant information of the account to be verified (such as the bound identity identifier, authorization information, etc.) is modified, etc.), a notification is sent to the notification recipient corresponding to the account to be verified; the notification specifically includes at least one of the following: account login notification, account abnormality notification, account operation notification.
[0218] In response to a data management operation on an account to be verified, the computer device may back up the target data indicated by the data management operation to the blockchain network (i.e., perform evidence storage processing, where the stored data is only accessible to regulatory authorities); after the backup is completed, the computer device may process the target data according to the data management operation (e.g., delete the target data stored in the local database). In addition, the object may also perform one or more of the following management operations: setting an account anomaly reminder (e.g., the number of account verifications within a preset period exceeds a threshold, remote login, etc.), specifying one or more devices with login permissions for the account (e.g., the object may specify a unified anonymous identifier whitelist, i.e., only devices in the unified anonymous identifier whitelist are allowed to verify the account to be verified (e.g., mobile phone number)), similarly, specifying one or more devices that do not have login permissions for the account (e.g., the object may specify a unified anonymous identifier blacklist, i.e., devices in the unified anonymous identifier blacklist are not allowed to verify the account to be verified (e.g., mobile phone number)); making changes to account information (e.g., changing the bound mobile phone number, email address, or ID information); and querying the account's historical login records (e.g., historical login time, historical login location), etc.
[0219] Furthermore, when the computer device detects that the first device is authenticating the target account, the computer device may perform operations such as simplifying the authentication process (e.g., eliminating the need for human-machine verification); wherein the unified anonymous identifier of the first device is included in the unified anonymous identifier whitelist of the target account. Similarly, when the computer device detects that the second device is authenticating the target account, the computer device may perform operations such as intercepting or terminating the authentication, wherein the unified anonymous identifier of the second device is included in the unified anonymous identifier blacklist of the target account.
[0220] It should be noted that the blockchain network referred to in this application can be a public blockchain network, a consortium blockchain, or a private blockchain (which can be used within an enterprise to prevent internal information tampering and accidental deletion, etc.). Taking a consortium blockchain as an example, multiple application developers can participate in the consortium chain; in addition, operators or regulatory authorities can serve as administrators and be granted management rights over the consortium chain. Company A, its applications (products), and each application's use case (e.g., Game X is the use case of Social Application Y) all have unique identifiers on the consortium blockchain.
[0221] Figure 7 This is a schematic diagram of the architecture of a blockchain network provided in an embodiment of the present application. Figure 7As shown, this blockchain is a consortium blockchain. Consortium blockchains can include multiple levels of roles, each with different permissions to read data within the blockchain. Nodes not permitted by the consortium blockchain cannot access data within the blockchain or receive related services provided by the blockchain (i.e., nodes not permitted by the consortium blockchain cannot have any substantive connection with the blockchain). The blockchain network can be jointly maintained by the product databases of various companies. A company can have one or more product databases, each divided by product scenarios. Without authorization, data between different scenarios is isolated.
[0222] Smart contracts run within blockchain networks, allowing data within the network to be processed and then responded to business needs, rather than directly sharing data sources. For example, when a computer device sends a pending account and a unified anonymous identifier to the blockchain network, the blockchain network compares and determines the associated records between the pending account and the unified anonymous identifier, and transmits the judgment result (such as a security level indicator) or information related to the security level judgment (such as the verification method associated with the pending account and the unified anonymous identifier, and whether the unified anonymous identifier has a bad record) back to the computer device, rather than transmitting all the source data. Furthermore, the blockchain network records the relevant information provided by the computer device (such as the target device's network parameters). By agreeing on a richer set of data and scenarios for on-chain communication, relevant information related to account verification can be better recorded. This allows for a clearer data source on the blockchain when an entity initiates a verification request (i.e., recording the verification location and time of the pending account). Specific product-specific control interfaces can also be provided for entities, allowing them to suspend SMS verification and other forms of verification for a period of time (e.g., not receiving SMS verification messages from application A for one day).
[0223] Furthermore, blockchain networks are regulated, allowing regulators to oversee the network as super administrators. For example, regulators can perform public service functions such as providing credentials for nodes in the blockchain network, granting them access to all blockchain data (in the case of each company or application, they only have access to data related to that company or application). Blockchain networks can also incorporate other alliance roles, such as operator nodes. Operator nodes have write access to the blockchain. For example, when a mobile phone number is re-issued, the operator can write the re-issued data to the blockchain, allowing the blockchain to freeze the trusted verification data before the re-issued data is included in calculations, etc.
[0224] In practical applications, operators of applications or websites cannot obtain or provide object information from other operators without authorization, making it difficult to obtain reliable credit information of the object. Through the blockchain network, objects can be uniformly authorized to the blockchain operator, and each operator can directly query the blockchain network for object credit indication information (i.e., the blockchain network will feedback the object's specific credit status (based on the object's source data) to the querying operator), thus forming a complete user mobile phone verification process data on the blockchain.
[0225] It is understood that the aforementioned blockchain network could also be replaced with a database maintained by a third-party regulatory body. Application companies could write data to the blockchain network or database, read their own data, and obtain security level indications or other information related to security level determinations from the database or blockchain network. This implementation enables cross-company data sharing and simplifies the authorization process for entities (entities only need to authorize applications to obtain target device security level information from the blockchain network; there is no need to authorize data exchange between applications).
[0226] Optionally, the administrator of the blockchain network or the telecommunications operator may also aggregate the data in the blockchain network or the target database (such as counting the unified anonymous identifiers associated with accounts that have successfully verified accounts), and when an abnormal change in the unified anonymous identifier is detected (such as the object enters a new account to be verified in the device), notify the business party or the object to issue a security reminder, or take more security measures such as additional factor verification. In simple terms, it can be understood that when the blockchain network obtains the target database and detects an abnormal login (such as the current unified anonymous identifier and the obtained account to be verified do not match the account associated with the unified anonymous identifier in the historical records), a security reminder is issued to the business party or the object. The above process can be recorded in the blockchain network or the target database as needed. When the target database is installed in a computer device, the above method can also be executed by the computer device.
[0227] Furthermore, the blockchain network or target data can also identify malicious nodes based on historical verification data. For example, if device A, corresponding to a unified anonymous identifier A, verifies multiple accounts within a target time period and all verifications fail, device A is identified as a malicious node. Computer devices can implement specific management policies for malicious nodes (e.g., prohibiting malicious nodes from verifying any accounts for a period of time, performing multiple human-machine verifications on malicious nodes, etc.). It is understood that when the target database is hosted on a computer device, the above method can also be executed by the computer device.
[0228] S406: Associate and store the unified anonymous identifier, the account to be verified, the account verification method of the account to be verified, and the account verification result of the account to be verified in a target database or blockchain network.
[0229] The associated storage method of the unified anonymous identifier, the account to be verified, the account verification method of the account to be verified, and the account verification result of the account to be verified can be shown in Table 2:
[0230] Table 2
[0231]
[0232] As shown in Table 2, a unified anonymous identifier can be associated with one or more accounts, and each account can correspond to one or more verification methods, as well as verification results; in addition, Table 2 can also record relevant information such as geographic location and verification time. The unified anonymous identifier and the account have an indexing function. The unified anonymous identifier can be used to determine the relevant information of one or more accounts related to the unified anonymous identifier; the account can be used to determine one or more unified anonymous identifiers related to the account, as well as the relevant information of the account. It can be understood that "XXXXXX", "AA", etc. in Table 2 are only used for examples and do not constitute actual limitations of this application. In actual applications, the unified anonymous identifier can be a string based on the IMEI of the target device and the mobile phone number corresponding to the SIM card (for using the cellular network) carried in the target device; the account can be a mobile phone number, email address, etc.
[0233] The associated storage method of the unified anonymous identifier, the account to be verified, the account verification method of the account to be verified, and the account verification result of the account to be verified may also be as shown in Table 3:
[0234] Table 3
[0235]
[0236] As shown in Table 3, an account can be associated with one or more unified anonymous identifiers; each account under a unified anonymous identifier (i.e., a device) can correspond to one or more verification methods and verification results; in addition, Table 3 can also record relevant information such as geographic location and verification time. The unified anonymous identifier and account have an indexing function. The unified anonymous identifier can be used to determine the relevant information of one or more accounts related to the unified anonymous identifier (for example, for account A, it can also be associated with account A's unified anonymous identifier whitelist, blacklist, or network parameters, etc.); the account can be used to determine one or more unified anonymous identifiers related to the account, as well as the relevant information about the account. It is understandable that "XXXXXX", "AA", etc. in Table 3 are only used for examples and do not constitute actual limitations of this application. In actual applications, the unified anonymous identifier can be a string composed of the IMEI of the target device and the mobile phone number corresponding to the SIM card (for using the cellular network) carried in the target device; the account can be a mobile phone number, email address, etc.
[0237] The data processing method provided by this application is described in detail below through two complete examples. Figure 8 This is an interactive flow chart of a data processing method provided in an embodiment of the present application. Figure 8 As shown:
[0238] Step S801: The object enters the account login page, which includes a description of the authorization rules (such as authorizing the current application or website to obtain a unified anonymous identifier of the target device). When the target device detects the object's authorization operation (such as the object checks the box to agree to authorize the current application or website), the server corresponding to the current application or website is authorized.
[0239] Step S802: After obtaining the permission, the server (computer device) sends an identification acquisition request to the identification provider. The identification acquisition request may carry the authorization information of the target device.
[0240] Step S803: After receiving the identification request from the server, the identity provider returns a unified anonymous identifier to the server. The specific implementation of steps S802 and S803 can be found in Figure 5 The embodiments shown will not be described in detail here.
[0241] Optionally, if permitted by relevant laws, regulations, and standards, the server can also apply to obtain the target device's hardware identifier (such as the IMEI). In this case, the identifier provider can be the terminal device manufacturer. It should be noted that the target device's hardware identifier can be forged, while the unified anonymous identifier is derived from the IMEI and mobile phone number, and the SIM card cannot be forged; therefore, the unified anonymous identifier is more practical in actual applications.
[0242] Step S804: The server obtains the account to be verified. In one embodiment, the account to be verified may be sent to the server after the target device obtains the account to be verified filled in by the object; in another embodiment, the account to be verified may be obtained by the server from a number obtaining service. For specific implementation methods, please refer to Figure 6 The implementation method in will not be repeated here.
[0243] Step S805: The server provides the target database or blockchain network with a unified anonymous identifier and the account to be verified. Optionally, the server can also provide the blockchain network with parameters to assist in determining the security level of the target device (i.e., introducing more risk control factors); for example, network parameters (such as base station cell ID, geographic information, IP address, etc.) and scenario environment parameters (such as application identification or website identification).
[0244] Step S806: In one embodiment, the target database or blockchain network determines the security level of the target device based on the unified anonymous identifier and the account to be verified provided by the server. In another embodiment, the target database or blockchain network returns security indication information to the server based on the unified anonymous identifier and the account to be verified provided by the server (such as whether there is an account verification record that matches the account to be verified and the unified anonymous identifier, whether there is a human-machine verification record that matches the account to be verified and the unified anonymous identifier, etc.), so that the server determines the security level of the target device based on the security indication information. For a specific implementation method for determining the security level of the target device, please refer to Figure 4 The implementation of step S403 is not described here in detail.
[0245] Step S807: After obtaining the security level of the target device, the server determines the human-machine verification strategy corresponding to the target device according to the security level of the target device (such as whether to perform human-machine verification on the target device, the number of human-machine verifications, the method of performing human-machine verification, etc.). The specific human-machine verification strategy can be set and adjusted according to actual needs, and this application does not impose any restrictions on this. The human-machine verification strategy may include the method of human-machine verification, the number of human-machine verifications, etc. Different security levels may correspond to the same or different human-machine verification strategies, which can be set according to actual needs, and this application does not impose any restrictions on this. Optionally, after determining the human-machine verification strategy corresponding to the target device, the computer device can also perform auxiliary verification through one or more security verification methods. The security verification methods include: SMS verification, biometric (fingerprint, voice, face, etc.) verification, associated account auxiliary verification (such as auxiliary verification through the "friend" account of the account to be verified, or auxiliary verification through other accounts bound to the account to be verified (such as email, social accounts, etc.)), phone verification, password verification, etc.
[0246] If the human-machine verification policy corresponding to the target device is that human-machine verification needs to be performed, then continue to step S808; correspondingly, if the human-machine verification policy corresponding to the target device is that human-machine verification does not need to be performed, then continue to step S811.
[0247] Step S808: The server instructs the target device to perform human-machine verification according to the human-machine verification strategy determined in step S807.
[0248] Step S809: In one embodiment, the target device returns the human-machine verification information to the server, so that the server determines the human-machine verification result based on the human-machine verification information. In another embodiment, the target device directly returns the human-machine verification result to the server.
[0249] Step S810: The server returns the verification result of the target device to the target database or blockchain network, so that the target database or blockchain network associates and stores the unified anonymous identifier, the account to be verified, and the verification result. Furthermore, the server may also provide the target database or blockchain network with verification parameters such as the verification time, verification method, and number of verifications.
[0250] Step S811: The server obtains the account verification information provided by the target device; for example, the account verification information may be a text message verification code, which may be generated by the server after obtaining the account to be verified and sent to the account to be verified.
[0251] Step S812: The server determines the account verification result of the account to be verified based on the account verification information provided by the target device; for example, the server detects whether the SMS verification code provided by the target device matches the SMS verification code generated by the server and sent to the account to be verified; if the SMS verification code provided by the target device matches the SMS verification code generated by the server and sent to the account to be verified, the server determines that the account to be verified has passed the account verification; if the SMS verification code provided by the target device does not match the SMS verification code generated by the server and sent to the account to be verified, the server determines that the account to be verified has failed the account verification.
[0252] Step S813: The server returns the target device's account verification result to the target database or blockchain network, so that the target database or blockchain network associates and stores the unified anonymous identifier, the account to be verified, and the account verification result. Furthermore, the server may also provide the target database or blockchain network with parameters related to account verification, such as the time, method, and number of account verifications.
[0253] Figure 9This is an interactive flow chart of another data processing method provided in an embodiment of the present application. Figure 9 As shown:
[0254] S901: The applicant for verification (object) enters the account login page, which includes a description of the authorization rules (such as authorizing the current application or website to obtain a unified anonymous identifier of the target device). The applicant for verification can authorize the server corresponding to the current application or website through authorization operations (such as the object checking the box to agree to authorize the current application or website).
[0255] S902: After obtaining authorization from the applicant for verification, the target device sends authorization information to the server.
[0256] S903: After obtaining the permission, the server sends an identification acquisition request to the identification provider (such as the operator). The identification acquisition request is used to request the identification provider to generate a parameter identification address (URL address) related to the unified anonymous identifier verification for the target device to access.
[0257] S904: After receiving the identification acquisition request sent by the server, the identification provider returns the identification address for verification of the relevant unified anonymous identifier to the server.
[0258] S905: After acquiring the identification address sent by the identification provider, the server provides the identification address to the target device.
[0259] S906: After receiving the identification address provided by the server, the target device accesses the identification address through the cellular network, thereby triggering the identification provider to read the characteristic information of the device accessing the identification address (such as the IMEI, mobile phone number, etc. of the target device), and obtain the anonymous unified identifier of the target device based on the characteristic information of the target device.
[0260] S907: After obtaining the unified anonymous identifier of the target device, the identity provider returns the unified anonymous identifier to the server. Figure 5 The embodiments shown will not be described in detail here.
[0261] S908: The target device obtains the account to be verified. The account to be verified may be the account filled in by the verification applicant on the login page.
[0262] S909: In one embodiment, the server obtains the account to be verified provided by the target device. In another embodiment, the account to be verified can be obtained by the server from a number obtaining service. For a specific embodiment, please refer to Figure 6 The implementation method in will not be repeated here.
[0263] S910: The server provides the target database or blockchain network with a unified anonymous identifier and the account to be verified. Optionally, the server may also provide the blockchain network with parameters to assist in determining the security level of the target device; for example, network parameters (such as base station cell ID, geographic information, IP address, etc.) and scenario environment parameters (such as application identifier or website identifier).
[0264] S911: In one embodiment, the target database or blockchain network determines the security level of the target device based on the unified anonymous identifier and the account to be verified provided by the server. In another embodiment, the target database or blockchain network returns security indication information to the server based on the unified anonymous identifier and the account to be verified provided by the server (such as whether there is an account verification record that matches the account to be verified and the unified anonymous identifier, whether there is a human-machine verification record that matches the account to be verified and the unified anonymous identifier, etc.), so that the server determines the security level of the target device based on the security indication information. For a specific implementation method for determining the security level of the target device, please refer to Figure 4 The implementation of step S403 is not described here in detail.
[0265] S912: In one embodiment, the server receives security indication information returned by the target database or blockchain network, and determines human-machine verification reference information (e.g., a recommended human-machine verification value) based on the security indication information, or determines the security level of the target device based on the security indication information. In another embodiment, the server may directly obtain the security level of the target device returned by the target database or blockchain network.
[0266] S913: The server returns human-machine verification reference information or the security level of the target device to the target device.
[0267] S914: In one embodiment, the target device obtains the human-machine verification reference information sent by the server, and the target device makes a comprehensive judgment based on the reference information, and then determines the human-machine verification strategy corresponding to the target device (such as determining the security level of the target device based on the human-machine verification reference information, and then determining the human-machine verification strategy corresponding to the target device based on the security level of the target device). In another embodiment, the target device obtains the security level of the target device sent by the server, and determines the human-machine verification strategy corresponding to the target device based on the security level of the target device (such as not calling human-machine recognition, or calling human-machine recognition, or calling more complex calculation problems or multiple puzzle check operations). The specific human-machine verification strategy can be set and adjusted according to actual needs, and this application does not impose any restrictions on this.
[0268] If the human-machine verification policy corresponding to the target device requires human-machine verification, then continue to execute step S915; correspondingly, if the human-machine verification policy corresponding to the target device does not require human-machine verification, then continue to execute step S922.
[0269] S915: The target device performs a human-machine verification on the applicant for verification.
[0270] The human-machine verification strategy may include the method of human-machine verification, the number of human-machine verifications, etc. Different security levels may correspond to the same or different human-machine verification strategies, which may be set specifically according to actual needs, and this application does not impose any restrictions on this. Optionally, after determining the human-machine verification strategy corresponding to the target device, the computer device may also perform auxiliary verification through one or more security verification methods, including: SMS verification, biometric (fingerprint, voice, face, etc.) verification, associated account auxiliary verification (such as auxiliary verification through the "friend" account of the account to be verified, or auxiliary verification through other accounts bound to the account to be verified (such as email, social accounts, etc.)), phone verification, password verification, etc.
[0271] S916: The party applying for verification enters human-machine verification information.
[0272] S917: In one embodiment, the target device may verify the human-machine verification information locally to obtain a human-machine verification result. In another embodiment, the target device may send the obtained human-machine verification information to the server.
[0273] S918: If the server receives the human-machine verification information sent by the target device, it verifies the human-machine verification information and returns the human-machine verification result to the target device.
[0274] S919: After obtaining the human-machine verification result, the target device can display the human-machine verification result and return relevant parameters of the human-machine verification (such as human-machine verification result, human-machine verification time, human-machine verification times, etc.) to the server.
[0275] S920: The server sends the human-machine verification result and human-machine verification parameters to the target database or blockchain network, so that the target database or blockchain network associates and stores the unified anonymous identifier, the account to be verified, and the human-machine verification result and human-machine verification parameters. Optionally, the target database or blockchain network may perform summary calculations based on the acquired data and historical data (e.g., calculating the human-machine verification success rate corresponding to the unified anonymous identifier).
[0276] S921: The target database or blockchain network sends first feedback information to the server, where the first feedback information is used to indicate the associated storage result of the human-machine verification result and the human-machine verification parameters.
[0277] S922: The party applying for verification may authenticate their identity through SMS verification, one-click login, or other verification methods; for example, the party applying for verification may enter account verification information on the login page.
[0278] S923: After obtaining the identity verification information, the target device sends the account verification information to the server.
[0279] S924: After receiving the account verification information from the target device, the server obtains an account verification result for the account to be verified based on the account verification information. After obtaining the account verification result for the account to be verified, the server may return the account verification result to the target device and send the target device's account verification result to the target database or blockchain network, so that the target database or blockchain network associates and stores the unified anonymous identifier, the account to be verified, and the account verification result. Furthermore, the server may provide the target database or blockchain network with account verification parameters such as the time, method, and number of account verifications.
[0280] S925: The target database or blockchain network sends second feedback information to the server, where the second feedback information is used to indicate the associated storage result of the account verification result.
[0281] Optionally, during the account verification process, the applicant may fail the account verification multiple times. In this case, steps S922-S925 can be repeated. If the number of failures exceeds the threshold, the human-machine verification (steps S915-S921) can be re-performed, or the process can be restarted from step S901. Optionally, the server can send a message reminder to the mobile phone number associated with the account being verified; or perform verification confirmation (such as confirming with the owner of the mobile phone number whether to repeat the verification); or limit the frequency and cooldown time to reduce possible risk attacks.
[0282] It should be noted that in actual applications, the server can be split into multiple independent backgrounds. For example, the server can be split into a security module background in the target device, an application background, and a background of the enterprise to which the application belongs. Each independent background can play the role of independently completing the interaction with the target database or the blockchain network, or can participate in the interaction. For ease of understanding, the embodiments of the present application merge the various backgrounds. Similarly, the target database or blockchain network can be independent of the server or can be installed in the server (in this case, the blockchain is a private chain), and this application does not limit this.
[0283] In an embodiment of the present application, in response to the authorization operation of the target device, a unified anonymous identifier of the target device is obtained, an account to be verified is obtained, the security level of the target device is determined based on the account to be verified and the unified anonymous identifier, and the human-machine verification strategy corresponding to the target device is determined based on the security level of the target device. It can be seen that in the account verification process, the security level of the target device can be determined based on the account to be verified and the unified anonymous identifier, and different human-machine verification strategies are adopted for devices with different security levels, which can make the account verification process more flexible and convenient. In addition, data sharing across companies can be achieved through the blockchain network, simplifying the authorization process of objects (the object only needs to authorize the application to obtain the security level information of the target device from the blockchain network, and there is no need to authorize data exchange between applications), thereby improving the security of the relevant data of the object and making it easier for relevant departments to supervise.
[0284] Figure 10 A flowchart of another data processing method provided in an embodiment of the present application. The data processing method can be executed by a computer device, which can be Figure 1d As shown in the server 102. Figure 10 As shown, the data processing method may include but is not limited to steps S1001-S1006:
[0285] S1001. In response to an authorization operation of a target device, obtain a unified anonymous identifier of the target device.
[0286] S1002: Obtain the account to be verified.
[0287] The specific implementation of step S1001 and step S1002 can be referred to Figure 2 The implementation of step S201 and step S202 will not be repeated here.
[0288] S1003. Obtain the account verification record associated with the unified anonymous identifier and the verification record of the account to be verified.
[0289] In one embodiment, the computer device can obtain the account verification record associated with the unified anonymous identifier and the verification record of the account to be verified from a database (such as a database of the enterprise to which the computer device belongs, a third-party database, a central database, etc.) or a blockchain network.
[0290] S1004 . Perform feature extraction on the account verification record associated with the unified anonymous identifier and the verification record of the account to be verified, respectively, to obtain feature information of the account verification record associated with the unified anonymous identifier and the verification record of the account to be verified.
[0291] The characteristic information of the verification record of the pending account includes at least one of the following: the number of verifications of the pending account within a first period, and the number of unified anonymous identifiers associated with the pending account within the first period. Specifically, the computer device can count the verification records of the pending account to obtain the number of verifications of the pending account within the first period (the device corresponding to a unified anonymous identifier may verify the pending account multiple times within the first period); or count the verification records of the pending account to obtain the number of unified anonymous identifiers associated with the pending account within the first period. The first period can be one day, one month, six months, or from the registration of the pending account to the present. The number of verifications of the pending account within the first period can be the total number of verifications of the pending account within the first period, or the number of successful verifications of the pending account within the first period. The unified anonymous identifier associated with the pending account within the first period refers to the unified anonymous identifier corresponding to the pending account when it passes verification within the first period. For example, assuming that the devices corresponding to unified anonymous identifiers 1 to 5 all verify the pending account within the first period, and the devices corresponding to unified anonymous identifiers 1 and 4 successfully verify the pending account, the unified anonymous identifiers associated with the pending account within the first period are unified anonymous identifier 1 and unified anonymous identifier 4. It is understandable that the computer device can also calculate the verification success rate, verification frequency, etc. of the unified anonymous identifier associated with the account to be verified within the first period based on the verification record of the account to be verified.
[0292] Similarly, the characteristic information of the account verification records associated with the unified anonymous identifier includes at least one of the following: the verification success rate corresponding to the unified anonymous identifier, and the number of accounts associated with the unified anonymous identifier within the second time period. Specifically, the computer device can collect statistics on the account verification records associated with the unified anonymous identifier to obtain the verification success rate corresponding to the unified anonymous identifier, or the number of accounts associated with the unified anonymous identifier within the second time period. The second time period can be one day, one month, half a year, etc.; the first time period and the second time period can be the same or different; the number of accounts associated with the unified anonymous identifier within the second time period can refer to the number of all accounts verified by the unified anonymous identifier within the second time period, or the number of accounts that the unified anonymous identifier has passed verification within the second time period. In addition, the characteristic information of the account verification records associated with the unified anonymous identifier can also include the number of times the unified anonymous identifier verifies one or more accounts within the second time period, etc.
[0293] S1005: Determine the security level of the target device based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified.
[0294] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified within a first time period, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the verification success rate corresponding to the unified anonymous identifier; the computer device determines the security level of the target device based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified. The specific implementation method is as follows: determining the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first time period, including: if the verification success rate corresponding to the unified anonymous identifier is less than or equal to a success rate threshold, and the number of verifications of the account to be verified within the first time period is greater than or equal to a number threshold, then The computer device determines the security level of the target device as the first security level; if the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of verifications of the account to be verified in the first time period is less than the number threshold, the computer device determines the security level of the target device as the second security level; if the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of verifications of the account to be verified in the first time period is greater than or equal to the number threshold, the computer device determines the security level of the target device as the third security level; if the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of verifications of the account to be verified in the first time period is less than the number threshold, the computer device determines the security level of the target device as the fourth security level.
[0295] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified in a first time period, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the number of accounts associated with the unified anonymous identifier in a second time period; the specific implementation method for the computer device to determine the security level of the target device based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified is as follows: if the number of accounts associated with the unified anonymous identifier in the second time period is greater than or equal to a first quantity threshold, and the number of verifications of the account to be verified in the first time period is greater than or equal to the number threshold, the computer device determines the security level of the target device as the first security level; if the unified anonymous identifier is greater than or equal to a first quantity threshold, the computer device determines the security level of the target device as the first security level. If the number of accounts associated with the unified anonymous identifier in the second time period is greater than or equal to the first number threshold, and the number of verifications of the account to be verified in the first time period is less than the number threshold, the computer device determines the security level of the target device as the second security level; if the number of accounts associated with the unified anonymous identifier in the second time period is less than the first number threshold, and the number of verifications of the account to be verified in the first time period is greater than or equal to the number threshold, the computer device determines the security level of the target device as the third security level; if the number of accounts associated with the unified anonymous identifier in the second time period is less than the first number threshold, and the number of verifications of the account to be verified in the first time period is less than the number threshold, the computer device determines the security level of the target device as the fourth security level.
[0296] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified within a first time period, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the verification success rate corresponding to the unified anonymous identifier; the computer device determines the security level of the target device according to the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified. The specific implementation method is as follows: if the verification success rate corresponding to the unified anonymous identifier is less than or equal to a success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to a second number threshold, then the computer device determines the security level of the target device as the first security level; if the unified anonymous identifier If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than a second quantity threshold, the computer device determines the security level of the target device as the second security level; if the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to the second quantity threshold, the computer device determines the security level of the target device as the third security level; if the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second quantity threshold, the computer device determines the security level of the target device as the fourth security level.
[0297] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified in a first time period, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the number of accounts associated with the unified anonymous identifier in a second time period; the specific implementation method of the computer device determining the security level of the target device based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified is as follows: if the number of accounts associated with the unified anonymous identifier in the second time period is greater than or equal to a first quantity threshold, and the number of unified anonymous identifiers associated with the account to be verified in the first time period is greater than or equal to a second quantity threshold, then the computer device determines the security level of the target device as the first security level; if the unified anonymous identifier is greater than or equal to a second quantity threshold in the first time period, then the computer device determines the security level of the target device as the first security level. If the number of accounts associated within the second time period is greater than or equal to the first quantity threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second quantity threshold, the computer device determines the security level of the target device as the second security level; if the number of accounts associated with the unified anonymous identifier within the second time period is less than the first quantity threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to the second quantity threshold, the computer device determines the security level of the target device as the third security level; if the number of accounts associated with the unified anonymous identifier within the second time period is less than the first quantity threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second quantity threshold, the computer device determines the security level of the target device as the fourth security level.
[0298] In one embodiment, if the unified anonymous identifier is not associated with an account verification record, and the account to be verified is not associated with a verification record, the computer device determines the security level of the target device as a preset security level; if the unified anonymous identifier is not associated with an account verification record, and the account to be verified is associated with a verification record, the computer device first determines the range to which the security level of the target device belongs as the target range, and then determines the security level of the target device based on the characteristic information of the verification record of the account to be verified. In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified within a first time period. If the verification record of the account to be verified within the first time period is greater than or equal to a number threshold, the computer device determines the security level of the target device as the first security level; if the verification record of the account to be verified within the first time period is less than the number threshold, the computer device determines the security level of the target device as the second security level; wherein the first security level and the second security level belong to the target range. In another embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified within a first time period; if the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to a second quantity threshold, the computer device determines the security level of the target device as the first security level; if the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second quantity threshold, the computer device determines the security level of the target device as the second security level; wherein the first security level and the second security level belong to the target range. Similarly, if the unified anonymous identifier is associated with an account verification record, and the account to be verified is not associated with a verification record, the computer device first determines the range to which the security level of the target device belongs as a preset range, and then determines the security level of the target device based on the characteristic information of the verification record of the unified anonymous identifier, and the security level of the target device belongs to the preset range.
[0299] In actual applications, the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified can be set to multiple based on actual needs; for example, the characteristic information of the account verification record associated with the unified anonymous identifier includes the verification success rate corresponding to the unified anonymous identifier, and the number of accounts associated with the unified anonymous identifier in the second time period; the characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified in the first time period and the number of unified anonymous identifiers associated with the account to be verified in the first time period. The computer device can determine the security level of the target device based on the weight of each characteristic information.
[0300] Optionally, if the account associated with the unified anonymous identifier engages in malicious behavior after logging in (such as sending harassing messages to other accounts or publishing false information), the security level of the target device corresponding to the unified anonymous identifier is determined to be level 5. In this case, the server determines that the target device presents a security risk and may increase the number of human-machine verifications, or impose a time limit or a limit on the number of account verifications on the target device.
[0301] It should be noted that the various security levels in this application are used to distinguish different situations. Figure 10 The first to fifth security levels in the embodiment are Figure 2 and Figure 4 The first to fifth security levels in the embodiment may be the same or different; for example, Figure 10 The human-machine verification strategy corresponding to the first security level in the embodiment is Figure 2 In the embodiment, the human-machine verification strategy corresponding to the first security level is different.
[0302] S1006. Determine a human-machine verification strategy corresponding to the target device based on the security level of the target device.
[0303] The human-machine verification strategy may include the method of human-machine verification, the number of human-machine verifications, etc. Different security levels may correspond to the same or different human-machine verification strategies, which may be set specifically according to actual needs, and this application does not impose any restrictions on this. Optionally, after determining the human-machine verification strategy corresponding to the target device, the computer device may also perform auxiliary verification through one or more security verification methods, including: SMS verification, biometric (fingerprint, voice, face, etc.) verification, associated account auxiliary verification (such as auxiliary verification through the "friend" account of the account to be verified, or auxiliary verification through other accounts bound to the account to be verified (such as email, social accounts, etc.)), phone verification, password verification, etc.
[0304] Furthermore, in a specific implementation, if it is detected that the account to be verified has violated the rules after the account has been verified, the supervisor (such as the regulatory department) can obtain the user identification card (mobile phone number) bound to the unified anonymous identifier corresponding to the account to be verified from the provider of the unified anonymous identifier, and perform penalty processing on the user identification card (mobile phone number) or the user of the user identification card in accordance with the processing rules corresponding to the violation; for example, the user identification card (mobile phone number) with the violation can be added to the blacklist and the user of the user identification card can be punished. In other words, the supervisor can profile the user of the user identification card bound to the unified anonymous identifier based on historical behavior records (i.e., account verification records associated with the unified anonymous identifier) to identify users with violations.
[0305] It is understandable that an account may be associated with multiple unified anonymous identifiers. The above-mentioned unified anonymous identifier corresponding to the account to be verified refers to the unified anonymous identifier of the target device when the account to be verified commits a violation; for example, account A is associated with unified anonymous identifiers 1-unified anonymous identifier 3, and unified anonymous identifiers 1-unified anonymous identifiers 3 correspond to devices 1-device 3 respectively. If device 1 (corresponding to unified anonymous identifier 1) commits a violation after logging into account A, the regulator (with relevant regulatory authority) can obtain the user identification card bound to the unified anonymous identifier 1 from the provider of the unified anonymous identifier, and punish the user identification card bound to the unified anonymous identifier 1, or punish the user of the user identification card bound to the unified anonymous identifier 1.
[0306] Optionally, if it is detected that the account to be verified has violated the rules after the account has been verified, the regulator may also punish the owner of the account to be verified (such as the registrant of the account to be verified, or the user currently bound to the account to be verified).
[0307] For example, when a malicious user needs to register a large number of mobile phone numbers for an app to obtain "benefits" in bulk, they may obtain the numbers through informal channels. Using the UAID, computers can clearly identify this temporary cross-device login, prompting information service providers to implement restrictions on such temporary cross-device logins to obtain "benefits." For users who "rent their accounts," computers can clearly identify this temporary cross-device login through the UAID. For example, if an adult account is frequently used on different UAID devices, and these UAID devices have previously been marked as minors, regulators can regulate the rented accounts and the devices using them.
[0308] Table 4 is a relationship table provided in an embodiment of the present application:
[0309] Table 4
[0310] Subject 1 Subject 2 Subject 3 Subject 4 Device 1 Device 2 Device 3 Device 4 Mobile phone number 1 Mobile phone number 2 Mobile number 3 Mobile number 4 UAID1 UAID2 UAID3 UAID4
[0311] As shown in Table 4, assuming that subjects 1 and 3 are family members and subject 4 is a malicious user, and subject 2 frequently verifies mobile numbers 1 and 3 through device 2, the computer device can determine, based on the UAID verification records, that UAID 2 is trustworthy for mobile numbers 1 through 3. However, when subject 4 verifies mobile number 1 or 3 through device 4, because UAID 4's verification records do not include verification records for mobile number 1 or 3, or do not include verification records showing that mobile number 1 or 3 successfully passed account verification, the computer device determines that UAID 4 is untrustworthy for mobile numbers 1 and 3 and requires further security verification.
[0312] Figure 11 This is a schematic diagram of the interaction principle of a data processing solution provided in an embodiment of the present application. Figure 11 As shown, the general principle of the data processing scheme is as follows:
[0313] S1101: On the one hand, after the front end of the target device obtains the object authorization (such as the user checks the consent authorization, allowing the front end to initiate an identity identifier (such as UAID) query and central database / blockchain verification to the identity provider (such as the operator), it initiates an identity identifier query to the identity provider to obtain the identity identifier of the target device. On the other hand, the front end of the target device obtains the account to be verified input by the object. After obtaining the identity identifier and the account to be verified, the front end transmits the identity identifier and the account to be verified of the target device to the background. The identity identifier includes at least one of the following: a unified anonymous identifier (UAID), an international mobile equipment identity (IMEI), an international mobile subscriber identity (IMSI), and an advertising identifier (IDFA).
[0314] The front end can be the front end of an application on the target device or the front end of a web page accessed on the target device, and this application does not limit this. Optionally, the front end can also transmit acquired network parameters (such as IP address) and geographic location, which can be used to assist in determining the security level of the target device, to the back end.
[0315] S1102: The backend can be installed in the server. After obtaining the identity identifier of the target device and the account to be verified transmitted by the frontend, the backend will transmit the requirements (such as the need to determine the security level of the target device, or determine the human-machine verification strategy corresponding to the target device, etc.) and parameters (including the identity identifier of the target device and the account to be verified) to the security policy module. The security policy module can be built-in to the backend, or independent (such as provided by a third party), or shared (such as multiple applications or websites of a company share a security policy module).
[0316] In one embodiment, the target device is equipped with a Subscriber Identity Module (SIM) card. The backend can also obtain the mask of the SIM card (eg, 131XXXX1234) from the operator and package the mask into a parameter to pass to the security policy module.
[0317] S1103: The security policy module can be installed in the server together with the backend, or can be installed independently in another server, or can be installed in the target device, and this application does not impose any restrictions on this. After the security policy module obtains the requirements and parameters sent by the backend, the central database (such as a local historical record database) or the blockchain shared by the three parties initiates the retrieval of relevant data records, such as retrieving all historical records related to the identity identifier of the target device, or retrieving all historical records related to the identity identifier within a preset time period.
[0318] The central database / blockchain network can use the identity identifier of the target device as an index condition to index in the central database / blockchain network and return relevant records to the security policy module.
[0319] In one embodiment, the central database / blockchain network can record in the following format: [time, TEL-A, TEL7M, identity identifier, TELU, target device parameters, network parameters, app / website, app / website scenario, object id, object key information (such as ID card, registered mobile phone number, etc.), verification success / failure result, verification method, TEL]. Among them, TEL-A refers to the account to be verified (such as the mobile phone number entered by the object in the front end for login); TEL7M refers to the mask of the user identification card loaded in the target device obtained from the operator (such as 131XXXX1234); TELU refers to the user identification card (mobile phone number) used to generate the UAID when the identity identifier is UAID. It should be noted that in the above records, the identity identifier and the account to be verified (i.e., TEL-A) are required items, and the remaining items are optional. In actual applications, they can be dynamically adjusted or expanded based on demand, and this application does not impose any restrictions on this.
[0320] S1104: After obtaining the records related to the target device's identity identifier and the records related to the account to be verified returned by the central database, the security policy module determines the security level of the target device based on the records related to the target device's identity identifier and the records related to the account to be verified; for specific implementation methods, please refer to Figure 10The implementation method of step S1005 is not described here in detail. Among them, the records related to the identity identifier of the target device include at least one of the following items: the account verification result associated with the identity identifier of the target device, the account identifier associated with the identity identifier of the target device, and the account identifier associated with the identity identifier of the target device can be used to count the number of accounts associated with the identity identifier of the target device (such as the total number of accounts associated with the identity identifier of the target device, the number of accounts associated with the identity identifier of the target device that have passed verification, etc.); the records related to the account to be verified include at least the identity identifier of the device used to verify the account, and the verification records of the account to be verified in the first time period can be counted based on the records related to the account to be verified. It should be noted that the verification records of the account to be verified in the first time period can specifically refer to the total number of times the account to be verified is verified in the first time period, or it can refer to the number of times the account to be verified is successfully verified in the first time period. It can be set according to actual needs, and this application does not impose any restrictions on this.
[0321] S1105: The security policy module determines the corresponding human-machine verification strategy based on the obtained security level and sends a human-machine verification strategy recommendation to the backend. Human-machine verification strategies include but are not limited to: face verification, password verification, fingerprint verification, friend-assisted verification, firewall verification, and SMS verification.
[0322] S1106: The backend determines the security verification method according to the human-machine verification policy suggestion sent by the security policy module, and instructs the frontend to perform security verification according to the determined security verification method.
[0323] S1107: The front end performs a security check according to the determined security check method. After the security check passes, the front end obtains the identity authentication information of the account to be verified and transmits the identity authentication information back to the back end.
[0324] S1108: The backend verifies the identity authentication information and stores the verification results, security verification results and related information (such as verification method, verification time, etc.) in the central database or blockchain network. It is understandable that Figure 11 The backend and security policy module in the system can together form a server, or the backend, security policy module and central database can together form a service.
[0325] It is understandable that the embodiments in the various drawings of the present application can be combined with each other in actual application; for example, the embodiment in which the supervisor obtains the user identification card bound to the unified anonymous identifier and punishes the user identification card in step S1006 can also be applied to Figure 2 and Figure 4For example, in step S405, the object manages the corresponding notification recipient of the account after the account verification is passed, and the embodiment can also be applied to 2 and Figure 10 In another embodiment; for example, in step S403, when there is an associated record of a unified anonymous identifier in the target database or blockchain network, the computer device may continue to execute Figure 10 These combinations all fall within the scope of protection of this application.
[0326] In this embodiment of the present application, the security level of the target device is determined based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified. Then, flexible security verification is performed on the object based on the security level of the target device, making the account verification process more flexible and convenient (i.e., the verification strategy is determined by the security level, simplifying the verification process for normal users and reducing the risk of users being attacked by malicious means). In addition, the UAID can be used to mark and identify the user identification number (mobile phone number) of the offending user, providing convenience for supervision.
[0327] The above describes in detail the method of the embodiment of the present application. In order to facilitate better implementation of the above scheme of the embodiment of the present application, the device of the embodiment of the present application is provided below accordingly.
[0328] See Figure 12 , Figure 12 This is a structural diagram of a data processing device provided in an embodiment of the present application. The device can be mounted on a computer device, which can be specifically Figure 1d Server 102 is shown. Figure 12 The data processing device shown can be used to perform the above Figure 2 , Figure 4 and Figure 10 Some or all of the functions described in the method embodiments. Figure 12 , the detailed description of each unit is as follows:
[0329] An acquiring unit 1201 is configured to acquire a unified anonymous identifier of a target device in response to an authorization operation of the target device;
[0330] and used to obtain a pending account, which is used to request login to a website or application;
[0331] The processing unit 1202 is configured to determine a security level of the target device based on the account to be verified and the unified anonymous identifier;
[0332] It is also used to determine the human-machine verification strategy corresponding to the target device based on the security level of the target device.
[0333] In one embodiment, the processing unit 1202 is configured to determine the security level of the target device based on the account to be verified and the unified anonymous identifier, specifically to:
[0334] Determine the trustworthiness of the target device based on the account to be verified and the unified anonymous identifier;
[0335] Determine the security level of the target device based on the trustworthiness of the target device;
[0336] Among them, the credibility of the target device is obtained based on one or more of the following: the account verification result associated with the account to be verified and the unified anonymous identifier, the human-machine verification result associated with the account to be verified and the unified anonymous identifier, the network parameters associated with the account to be verified and the unified anonymous identifier, the account verification method associated with the account to be verified and the unified anonymous identifier, the scene environment parameters associated with the account to be verified and the unified anonymous identifier, and the verification initiation time of the account verification or human-machine verification associated with the account to be verified and the unified anonymous identifier.
[0337] In one embodiment, the processing unit 1202 is configured to determine the security level of the target device based on the account to be verified and the unified anonymous identifier, specifically to:
[0338] If there is an associated record of a unified anonymous identifier in the target database or blockchain network, the security level of the target device is determined based on the associated record;
[0339] If there is no associated record of the unified anonymous identifier in the target database or blockchain network, the security level of the target device is determined to be the first security level.
[0340] In one embodiment, the association record of the unified anonymous identifier includes one or more accounts associated with the unified anonymous identifier and the account verification result of each account; the processing unit 1202 is configured to determine the security level of the target device based on the association record, specifically to:
[0341] If the account to be verified matches the target account associated with the unified anonymous identifier, the security level of the target device is determined based on the account verification result of the target account;
[0342] If the account to be verified does not match one or more accounts associated with the unified anonymous identifier, determining the security level of the target device to be a second security level;
[0343] The human-machine verification strategies corresponding to the second security level and the first security level are different.
[0344] In one embodiment, the associated record of the unified anonymous identifier further includes the account verification method of each account; the processing unit 1202 is configured to determine the security level of the target device based on the account verification result of the target account, specifically to:
[0345] If the target account's account verification result is passed, the target device's security level is determined based on the target account's account verification method;
[0346] If the target account fails the account verification, the target device's security level is set to the third security level.
[0347] The first security level, the second security level, and the third security level are different from each other.
[0348] In one embodiment, the account verification method includes a text message verification method and a one-click login method; the processing unit 1202 is configured to determine the security level of the target device based on the account verification method of the target account, specifically to:
[0349] If the target account's verification method is SMS verification, the target device's security level is set to level 4.
[0350] If the target account's authentication method is one-click login, the target device's security level is set to the fifth security level;
[0351] The first security level, the second security level, the third security level, the fourth security level and the fifth security level are different from each other.
[0352] In one embodiment, the processing unit 1202 is further configured to:
[0353] Obtain the account verification method of the account to be verified, and obtain the account verification result of the account to be verified under the account verification method;
[0354] The unified anonymous identifier, the account to be verified, the account verification method of the account to be verified, and the account verification result of the account to be verified are associated and stored in a target database or blockchain network.
[0355] In one embodiment, the account verification method of the account to be verified is a text message verification method; the processing unit 1202 is used to obtain the account verification result of the account to be verified in the account verification method, specifically for:
[0356] Generate account verification information for the account to be verified and return the account verification information to the owner of the account to be verified;
[0357] Obtain account verification information provided by the target device;
[0358] If the account verification information and the account verification information match, the account to be verified is determined to have passed the account verification.
[0359] In one embodiment, the processing unit 1202 is configured to obtain a unified anonymous identifier of the target device, specifically to:
[0360] Obtaining a unified anonymous identifier address provided by the identification service, and sending an instruction message to the target device, the instruction message carrying the unified anonymous identifier address, the instruction message being used to instruct the target device to access the unified anonymous identifier address through the cellular network;
[0361] Obtaining encrypted data returned by the target device, the encrypted data being obtained after the target device accesses the unified anonymous identifier address via the cellular network;
[0362] Send encrypted data to the identity service and obtain a unified anonymous identifier returned by the identity service. The unified anonymous identifier is obtained by the identity service through a token, which is obtained by decrypting the encrypted data.
[0363] In one embodiment, if the account to be verified passes the account verification, the processing unit 1202 is further configured to:
[0364] In response to a data management operation on the account to be verified, backing up the target data indicated by the data management operation to the blockchain network;
[0365] Process the target data according to data management operations;
[0366] Among them, data management operations include data deletion operations and authorization cancellation operations.
[0367] In one embodiment, the processing unit 1202 is configured to determine the security level of the target device based on the account to be verified and the unified anonymous identifier, specifically to:
[0368] Send the account to be verified and the unified anonymous identifier to the target database or blockchain network;
[0369] Obtain security indication information returned by the target database or blockchain network, where the security indication information is determined based on the association information between the account to be verified and the unified anonymous identifier;
[0370] Based on the security instructions, determine the security level of the target device.
[0371] In one embodiment, the processing unit 1202 is configured to determine the security level of the target device based on the account to be verified and the unified anonymous identifier, specifically to:
[0372] Obtain the account verification records associated with the unified anonymous identifier and the verification records of the account to be verified;
[0373] Perform feature extraction on the account verification record associated with the unified anonymous identifier and the verification record of the account to be verified, respectively, to obtain feature information of the account verification record associated with the unified anonymous identifier and feature information of the verification record of the account to be verified;
[0374] The security level of the target device is determined based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified.
[0375] In one embodiment, the characteristic information of the verification record of the account to be verified includes at least one of the following: the number of verifications of the account to be verified in the first time period, the number of unified anonymous identifiers associated with the account to be verified in the first time period;
[0376] The characteristic information of the account verification record associated with the unified anonymous identifier includes at least one of the following: a verification success rate corresponding to the unified anonymous identifier, and the number of accounts associated with the unified anonymous identifier in the second time period.
[0377] In one embodiment, the characteristic information of the verification record of the to-be-verified account includes the number of verifications of the to-be-verified account within a first period, and the characteristic information of the verification record of the account associated with the unified anonymous identifier includes the verification success rate corresponding to the unified anonymous identifier;
[0378] The processing unit 1202 is configured to determine the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first period, specifically to:
[0379] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of verifications of the account to be verified within the first time period is greater than or equal to the number threshold, the security level of the target device is determined to be the first security level;
[0380] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of verifications of the account to be verified within the first time period is less than the number threshold, the security level of the target device is determined to be the second security level;
[0381] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of verifications of the account to be verified within the first time period is greater than or equal to the number threshold, the security level of the target device is determined to be the third security level;
[0382] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of verifications of the account to be verified within the first time period is less than the number threshold, the security level of the target device is determined to be the fourth security level.
[0383] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified in a first time period, and the characteristic information of the verification record of the account associated with the unified anonymous identifier includes the number of accounts associated with the unified anonymous identifier in a second time period;
[0384] The processing unit 1202 is configured to determine the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first time period, specifically to:
[0385] If the number of accounts associated with the unified anonymous identifier during the second period is greater than or equal to the first number threshold, and the number of verifications of the account to be verified during the first period is greater than or equal to the number threshold, then the security level of the target device is determined to be the first security level;
[0386] If the number of accounts associated with the unified anonymous identifier during the second period is greater than or equal to the first number threshold, and the number of verifications of the account to be verified during the first period is less than the number threshold, then the security level of the target device is determined to be the second security level;
[0387] If the number of accounts associated with the unified anonymous identifier during the second period is less than the first number threshold, and the number of verifications of the account to be verified during the first period is greater than or equal to the number threshold, then the security level of the target device is determined to be the third security level;
[0388] If the number of accounts associated with the unified anonymous identifier in the second period is less than the first number threshold, and the number of verifications of the account to be verified in the first period is less than the number threshold, the security level of the target device is determined to be the fourth security level.
[0389] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified within the first time period, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the verification success rate corresponding to the unified anonymous identifier;
[0390] The processing unit 1202 is configured to determine the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first time period, specifically to:
[0391] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to the second number threshold, then the security level of the target device is determined to be the first security level;
[0392] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second number threshold, then the security level of the target device is determined to be the second security level;
[0393] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to the second number threshold, then the security level of the target device is determined to be the third security level;
[0394] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second number threshold, the security level of the target device is determined to be the fourth security level.
[0395] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified during a first period of time, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the number of accounts associated with the unified anonymous identifier during a second period of time;
[0396] The processing unit 1202 is configured to determine the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first period, specifically to:
[0397] If the number of accounts associated with the unified anonymous identifier during the second time period is greater than or equal to the first threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is greater than or equal to the second threshold, determining the security level of the target device to be the first security level;
[0398] If the number of accounts associated with the unified anonymous identifier during the second time period is greater than or equal to the first quantity threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is less than the second quantity threshold, determining the security level of the target device to be the second security level;
[0399] If the number of accounts associated with the unified anonymous identifier during the second time period is less than the first threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is greater than or equal to the second threshold, determining the security level of the target device to be a third security level;
[0400] If the number of accounts associated with the unified anonymous identifier in the second time period is less than the first quantity threshold, and the number of unified anonymous identifiers associated with the account to be verified in the first time period is less than the second quantity threshold, the security level of the target device is determined to be the fourth security level.
[0401] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified within a first time period. If the unified anonymous identifier is not associated with the account verification record, the processing unit 1202 is configured to determine the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first time period, specifically to:
[0402] Determine the range to which the security level of the target device belongs as the target range;
[0403] If the verification record of the account to be verified in the first period is greater than or equal to the number threshold, the security level of the target device is determined to be the first security level;
[0404] If the verification record of the account to be verified in the first period is less than the number threshold, the security level of the target device is determined to be the second security level;
[0405] Among them, the first security level and the second security level belong to the target range.
[0406] In one embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified within the first time period; if the unified anonymous identifier is not associated with an account verification record, the processing unit 1202 is configured to determine the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first time period, specifically to:
[0407] Determine the range to which the security level of the target device belongs as the target range;
[0408] If the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to a second number threshold, determining the security level of the target device to be a first security level;
[0409] If the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than a second number threshold, determining the security level of the target device to be a second security level;
[0410] Among them, the first security level and the second security level belong to the target range.
[0411] In one embodiment, the processing unit 1202 is further configured to:
[0412] If it is detected that the account to be verified has violated the rules after passing the verification, the user identification card bound to the unified anonymous identifier corresponding to the account to be verified is obtained from the provider of the unified anonymous identifier;
[0413] Punish the user identification card or the user of the user identification card according to the corresponding processing rules of the violation.
[0414] In one embodiment, if the account to be verified passes the account verification, the processing unit 1202 is further configured to:
[0415] In response to a notification management operation of the account to be verified, updating a notification recipient corresponding to the account to be verified based on the notification management operation; and
[0416] When it is detected that the account to be verified meets the notification conditions, a notification is sent to the notification recipient corresponding to the account to be verified;
[0417] The notification includes at least one of the following: account login notification, account abnormality notification, and account operation notification.
[0418] According to one embodiment of the present application, Figure 2 , Figure 4 and Figure 10 Some of the steps involved in the data processing method shown can be represented by Figure 12 The data processing apparatus shown in FIG. Figure 2 Steps S201 and S202 shown in FIG can be replaced by Figure 12 The acquisition unit 1201 shown in FIG. 1 is executed, and steps S203 and S204 can be performed by Figure 12 The processing unit 1202 shown executes; Figure 4 Steps S401, S402 and S405 shown in FIG can be replaced by Figure 12 The acquisition unit 1201 shown in FIG. 1 is executed, and steps S403, S404 and S406 can be performed by Figure 12 The processing unit 1202 shown executes; Figure 10 Steps S1001 to S1003 shown in FIG. Figure 12 The acquisition unit 1201 shown in FIG. 1 is executed, and steps S1004 to S1006 can be performed by Figure 12 Processing unit 1202 is shown executing. Figure 12 The various units in the data processing apparatus shown can be separately or all merged into one or several other units to constitute, or a certain unit (or units) therein can also be split into multiple smaller units in function to constitute, which can achieve the same operation without affecting the realization of the technical effects of the embodiments of the present application. The above-mentioned units are divided based on logical functions. In practical applications, the function of a unit can also be realized by multiple units, or the function of multiple units can be realized by one unit. In other embodiments of the present application, the data processing apparatus may also include other units. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented by the collaboration of multiple units.
[0419] According to another embodiment of the present application, the program can be executed by running on a general computing device such as a computer including a central processing unit (CPU), a random access memory (RAM), a read-only memory (ROM) and other processing elements and storage elements. Figure 2 , Figure 4 and Figure 10 A computer program (including program code) for each step involved in the corresponding method shown in Figure 12 The data processing device shown in and the data processing method of the embodiment of the present application are implemented. The computer program can be recorded on a computer-readable recording medium, for example, and loaded into the above-mentioned computing device through the computer-readable recording medium and run therein.
[0420] Based on the same inventive concept, the principles and beneficial effects of solving problems by the data processing device provided in the embodiment of the present application are similar to the principles and beneficial effects of solving problems by the data processing method in the method embodiment of the present application. Please refer to the principles and beneficial effects of the implementation of the method. For the sake of concise description, they will not be repeated here.
[0421] See also Figure 13 , Figure 13 A schematic diagram of the structure of a computer device provided in an embodiment of the present application is shown in FIG. Figure 13As shown, the computer device includes at least a processor 1301, a communication interface 1302, and a memory 1303. The processor 1301, the communication interface 1302, and the memory 1303 can be connected via a bus or other means. The processor 1301 (or central processing unit (CPU)) is the computing core and control core of the computer device. It can parse various instructions within the computer device and process various data of the computer device. For example, the CPU can be used to parse the power on and off instructions sent by the user to the computer device and control the computer device to perform power on and off operations. For another example, the CPU can transmit various interactive data between the internal structures of the computer device, etc. The communication interface 1302 can optionally include a standard wired interface or a wireless interface (such as WI-FI, mobile communication interface, etc.), which can be used to send and receive data under the control of the processor 1301. The communication interface 1302 can also be used for the transmission and interaction of data within the computer device. The memory 1303 (Memory) is a memory device in the computer device, used to store programs and data. It is understood that the memory 1303 herein may include both the built-in memory of the computer device and, of course, the extended memory supported by the computer device. The memory 1303 provides storage space that stores the operating system of the computer device, which may include but is not limited to: Android system, iOS system, Windows Phone system, etc., and this application does not limit this.
[0422] The embodiment of the present application also provides a computer-readable storage medium (Memory), which is a memory device in the terminal for storing programs and data. It is understandable that the computer-readable storage medium here can include both the built-in storage medium in the terminal and, of course, the extended storage medium supported by the terminal. The computer-readable storage medium provides a storage space that stores the processing system of the terminal. In addition, one or more instructions suitable for being loaded and executed by the processor 1301 are also stored in the storage space. These instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory, or a non-volatile memory (non-volatile memory), such as at least one disk storage; optionally, it can also be at least one computer-readable storage medium located away from the aforementioned processor.
[0423] In one embodiment, the computer device may be Figure 1d The server 102 shown in FIG. 10 is a processor 1301 that executes the following operations by running the executable program code in the memory 1303:
[0424] In response to an authorization operation of the target device, obtaining a unified anonymous identifier of the target device;
[0425] Obtain a pending account, which is used to request login to a website or application;
[0426] Determine the security level of the target device based on the account to be verified and the unified anonymous identifier;
[0427] Based on the security level of the target device, determine the human-machine verification strategy corresponding to the target device.
[0428] As an optional embodiment, the processor 1301 determines the security level of the target device according to the account to be verified and the unified anonymous identifier.
[0429] Determine the trustworthiness of the target device based on the account to be verified and the unified anonymous identifier;
[0430] Determine the security level of the target device based on the trustworthiness of the target device;
[0431] Among them, the credibility of the target device is obtained based on one or more of the following: the account verification result associated with the account to be verified and the unified anonymous identifier, the human-machine verification result associated with the account to be verified and the unified anonymous identifier, the network parameters associated with the account to be verified and the unified anonymous identifier, the account verification method associated with the account to be verified and the unified anonymous identifier, the scene environment parameters associated with the account to be verified and the unified anonymous identifier, and the verification initiation time of the account verification or human-machine verification associated with the account to be verified and the unified anonymous identifier.
[0432] As an optional embodiment, the processor 1301 determines the security level of the target device according to the account to be verified and the unified anonymous identifier.
[0433] If there is an associated record of a unified anonymous identifier in the target database or blockchain network, the security level of the target device is determined based on the associated record;
[0434] If there is no associated record of the unified anonymous identifier in the target database or blockchain network, the security level of the target device is determined to be the first security level.
[0435] As an optional embodiment, the association record of the unified anonymous identifier includes one or more accounts associated with the unified anonymous identifier and the account verification result of each account; a specific embodiment of the processor 1301 determining the security level of the target device based on the association record is as follows:
[0436] If the account to be verified matches the target account associated with the unified anonymous identifier, the security level of the target device is determined based on the account verification result of the target account;
[0437] If the account to be verified does not match one or more accounts associated with the unified anonymous identifier, determining the security level of the target device to be a second security level;
[0438] The human-machine verification strategies corresponding to the second security level and the first security level are different.
[0439] As an optional embodiment, the association record of the unified anonymous identifier also includes the account verification method of each account; the specific embodiment of the processor 1301 determining the security level of the target device based on the account verification result of the target account is:
[0440] If the target account's account verification result is passed, the target device's security level is determined based on the target account's account verification method;
[0441] If the target account fails the account verification, the target device's security level is set to the third security level.
[0442] The first security level, the second security level, and the third security level are different from each other.
[0443] As an optional embodiment, the account verification method includes a text message verification method and a one-key login method; a specific embodiment in which the processor 1301 determines the security level of the target device according to the account verification method of the target account is as follows:
[0444] If the target account's verification method is SMS verification, the target device's security level is set to level 4.
[0445] If the target account's authentication method is one-click login, the target device's security level is set to the fifth security level;
[0446] The first security level, the second security level, the third security level, the fourth security level and the fifth security level are different from each other.
[0447] As an optional embodiment, the processor 1301 further performs the following operations by running the executable program code in the memory 1303:
[0448] Obtain the account verification method of the account to be verified, and obtain the account verification result of the account to be verified under the account verification method;
[0449] The unified anonymous identifier, the account to be verified, the account verification method of the account to be verified, and the account verification result of the account to be verified are associated and stored in a target database or blockchain network.
[0450] As an optional embodiment, the account verification method of the account to be verified is a text message verification method; a specific embodiment of the processor 1301 obtaining the account verification result of the account to be verified in the account verification method is:
[0451] Generate account verification information for the account to be verified and return the account verification information to the owner of the account to be verified;
[0452] Obtain account verification information provided by the target device;
[0453] If the account verification information and the account verification information match, the account to be verified is determined to have passed the account verification.
[0454] As an optional embodiment, the specific embodiment of the processor 1301 obtaining the unified anonymous identifier of the target device is:
[0455] Obtaining a unified anonymous identifier address provided by the identification service, and sending an instruction message to the target device, the instruction message carrying the unified anonymous identifier address, the instruction message being used to instruct the target device to access the unified anonymous identifier address through the cellular network;
[0456] Obtaining encrypted data returned by the target device, the encrypted data being obtained after the target device accesses the unified anonymous identifier address via the cellular network;
[0457] Send encrypted data to the identity service and obtain a unified anonymous identifier returned by the identity service. The unified anonymous identifier is obtained by the identity service through a token, which is obtained by decrypting the encrypted data.
[0458] As an optional embodiment, if the account to be verified passes the account verification, the processor 1301 further performs the following operations by running the executable program code in the memory 1303:
[0459] In response to a data management operation on the account to be verified, backing up the target data indicated by the data management operation to the blockchain network;
[0460] Process the target data according to data management operations;
[0461] Among them, data management operations include data deletion operations and authorization cancellation operations.
[0462] As an optional embodiment, the processor 1301 determines the security level of the target device according to the account to be verified and the unified anonymous identifier.
[0463] Send the account to be verified and the unified anonymous identifier to the target database or blockchain network;
[0464] Obtain security indication information returned by the target database or blockchain network, where the security indication information is determined based on the association information between the account to be verified and the unified anonymous identifier;
[0465] Based on the security instructions, determine the security level of the target device.
[0466] As an optional embodiment, the processor 1301 determines the security level of the target device according to the account to be verified and the unified anonymous identifier.
[0467] Obtain the account verification records associated with the unified anonymous identifier and the verification records of the account to be verified;
[0468] Perform feature extraction on the account verification record associated with the unified anonymous identifier and the verification record of the account to be verified, respectively, to obtain feature information of the account verification record associated with the unified anonymous identifier and feature information of the verification record of the account to be verified;
[0469] The security level of the target device is determined based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified.
[0470] As an optional embodiment, the characteristic information of the verification record of the account to be verified includes at least one of the following: the number of verifications of the account to be verified in the first time period, the number of unified anonymous identifiers associated with the account to be verified in the first time period;
[0471] The characteristic information of the account verification record associated with the unified anonymous identifier includes at least one of the following: a verification success rate corresponding to the unified anonymous identifier, and the number of accounts associated with the unified anonymous identifier in the second time period.
[0472] As an optional embodiment, the characteristic information of the verification record of the to-be-verified account includes the number of verifications of the to-be-verified account within the first time period, and the characteristic information of the verification record of the account associated with the unified anonymous identifier includes the verification success rate corresponding to the unified anonymous identifier;
[0473] A specific embodiment in which the processor 1301 determines the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first period is as follows:
[0474] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of verifications of the account to be verified within the first time period is greater than or equal to the number threshold, the security level of the target device is determined to be the first security level;
[0475] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of verifications of the account to be verified within the first time period is less than the number threshold, the security level of the target device is determined to be the second security level;
[0476] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of verifications of the account to be verified within the first time period is greater than or equal to the number threshold, the security level of the target device is determined to be the third security level;
[0477] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of verifications of the account to be verified within the first time period is less than the number threshold, the security level of the target device is determined to be the fourth security level.
[0478] As an optional embodiment, the characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified within a first time period, and the characteristic information of the verification record of the account associated with the unified anonymous identifier includes the number of accounts associated with the unified anonymous identifier within a second time period;
[0479] A specific embodiment in which the processor 1301 determines the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first period is as follows:
[0480] If the number of accounts associated with the unified anonymous identifier during the second period is greater than or equal to the first number threshold, and the number of verifications of the account to be verified during the first period is greater than or equal to the number threshold, then the security level of the target device is determined to be the first security level;
[0481] If the number of accounts associated with the unified anonymous identifier during the second period is greater than or equal to the first number threshold, and the number of verifications of the account to be verified during the first period is less than the number threshold, then the security level of the target device is determined to be the second security level;
[0482] If the number of accounts associated with the unified anonymous identifier during the second period is less than the first number threshold, and the number of verifications of the account to be verified during the first period is greater than or equal to the number threshold, then the security level of the target device is determined to be the third security level;
[0483] If the number of accounts associated with the unified anonymous identifier in the second period is less than the first number threshold, and the number of verifications of the account to be verified in the first period is less than the number threshold, the security level of the target device is determined to be the fourth security level.
[0484] As an optional embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified within the first time period, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the verification success rate corresponding to the unified anonymous identifier;
[0485] A specific embodiment in which the processor 1301 determines the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first period is as follows:
[0486] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to the second number threshold, then the security level of the target device is determined to be the first security level;
[0487] If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second number threshold, then the security level of the target device is determined to be the second security level;
[0488] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to the second number threshold, then the security level of the target device is determined to be the third security level;
[0489] If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second number threshold, the security level of the target device is determined to be the fourth security level.
[0490] As an optional embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified within a first time period, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the number of accounts associated with the unified anonymous identifier within a second time period;
[0491] A specific embodiment in which the processor 1301 determines the security level of the target device based on the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first period is as follows:
[0492] If the number of accounts associated with the unified anonymous identifier during the second time period is greater than or equal to the first threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is greater than or equal to the second threshold, determining the security level of the target device to be the first security level;
[0493] If the number of accounts associated with the unified anonymous identifier during the second time period is greater than or equal to the first quantity threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is less than the second quantity threshold, determining the security level of the target device to be the second security level;
[0494] If the number of accounts associated with the unified anonymous identifier during the second time period is less than the first threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is greater than or equal to the second threshold, determining the security level of the target device to be a third security level;
[0495] If the number of accounts associated with the unified anonymous identifier in the second time period is less than the first quantity threshold, and the number of unified anonymous identifiers associated with the account to be verified in the first time period is less than the second quantity threshold, the security level of the target device is determined to be the fourth security level.
[0496] As an optional embodiment, the characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified within the first time period. If the unified anonymous identifier is not associated with an account verification record, the processor 1301 determines the security level of the target device based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified. A specific embodiment is as follows:
[0497] Determine the range to which the security level of the target device belongs as the target range;
[0498] If the verification record of the account to be verified in the first period is greater than or equal to the number threshold, the security level of the target device is determined to be the first security level;
[0499] If the verification record of the account to be verified in the first period is less than the number threshold, the security level of the target device is determined to be the second security level;
[0500] Among them, the first security level and the second security level belong to the target range.
[0501] As an optional embodiment, the characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified within the first time period; if the unified anonymous identifier is not associated with an account verification record, the processor 1301 determines the security level of the target device based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified. Specific embodiments include:
[0502] Determine the range to which the security level of the target device belongs as the target range;
[0503] If the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to a second number threshold, determining the security level of the target device to be a first security level;
[0504] If the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than a second number threshold, determining the security level of the target device to be a second security level;
[0505] Among them, the first security level and the second security level belong to the target range.
[0506] As an optional embodiment, the processor 1301 further performs the following operations by running the executable program code in the memory 1303:
[0507] If it is detected that the account to be verified has violated the rules after passing the verification, the user identification card bound to the unified anonymous identifier corresponding to the account to be verified is obtained from the provider of the unified anonymous identifier;
[0508] Punish the user identification card or the user of the user identification card according to the corresponding processing rules of the violation.
[0509] As an optional embodiment, if the account to be verified passes the account verification, the processor 1301 further performs the following operations by running the executable program code in the memory 1303:
[0510] In response to a notification management operation of the account to be verified, updating a notification recipient corresponding to the account to be verified based on the notification management operation; and
[0511] When it is detected that the account to be verified meets the notification conditions, a notification is sent to the notification recipient corresponding to the account to be verified;
[0512] The notification includes at least one of the following: account login notification, account abnormality notification, and account operation notification.
[0513] Based on the same inventive concept, the principles and beneficial effects of solving problems with the computer device provided in the embodiment of the present application are similar to the principles and beneficial effects of solving problems with the data processing method in the method embodiment of the present application. Please refer to the principles and beneficial effects of the implementation of the method. For the sake of concise description, they will not be repeated here.
[0514] An embodiment of the present application also provides a computer-readable storage medium, in which one or more instructions are stored, and the one or more instructions are suitable for being loaded by a processor and executing the data processing method of the above method embodiment.
[0515] An embodiment of the present application also provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute the data processing method of the above method embodiment.
[0516] The present application also provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the above-described data processing method.
[0517] The steps in the method of the embodiment of the present application can be adjusted in order, combined and deleted according to actual needs.
[0518] The modules in the device of the embodiment of the present application can be merged, divided and deleted according to actual needs.
[0519] A person skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, which can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0520] The above disclosure is only a preferred embodiment of the present application, and certainly cannot be used to limit the scope of rights of the present application. Ordinary technicians in this field can understand that all or part of the processes of the above embodiment and equivalent changes made in accordance with the claims of this application are still within the scope covered by the application.
Claims
1. A data processing method, characterized in that: The method comprises: In response to an authorization operation of the target device, obtaining a unified anonymous identifier of the target device; Obtaining an account to be verified, where the account to be verified is used to request to log in to a website or application; determining a security level of the target device according to the account to be verified and the unified anonymous identifier; Based on the security level of the target device, a human-machine verification strategy corresponding to the target device is determined, and different security levels correspond to different human-machine verification strategies.
2. The method according to claim 1, wherein The determining the security level of the target device according to the account to be verified and the unified anonymous identifier includes: Determining the credibility of the target device based on the account to be verified and the unified anonymous identifier; Determining a security level of the target device based on the credibility of the target device; The credibility of the target device is obtained based on one or more of the following: the account verification result associated with the account to be verified and the unified anonymous identifier, the human-machine verification result associated with the account to be verified and the unified anonymous identifier, the network parameters associated with the account to be verified and the unified anonymous identifier, the account verification method associated with the account to be verified and the unified anonymous identifier, the scene environment parameters associated with the account to be verified and the unified anonymous identifier, and the verification initiation time of the account verification or human-machine verification associated with the account to be verified and the unified anonymous identifier.
3. The method according to claim 1, wherein The determining the security level of the target device according to the account to be verified and the unified anonymous identifier includes: If there is an associated record of the unified anonymous identifier in the target database or blockchain network, determining the security level of the target device based on the associated record; If there is no associated record of the unified anonymous identifier in the target database or blockchain network, the security level of the target device is determined to be the first security level.
4. The method according to claim 3, wherein The associated record of the unified anonymous identifier includes one or more accounts associated with the unified anonymous identifier and an account verification result of each account; Determining the security level of the target device according to the association record includes: If the account to be verified matches the target account associated with the unified anonymous identifier, determining the security level of the target device according to the account verification result of the target account; If the account to be verified does not match one or more accounts associated with the unified anonymous identifier, determining the security level of the target device to be a second security level; The human-machine verification strategies corresponding to the second security level and the first security level are different.
5. The method according to claim 4, wherein The associated record of the unified anonymous identifier also includes an account verification method for each account; and determining the security level of the target device based on the account verification result of the target account includes: If the target account's account verification result is passed, determining the target device's security level based on the target account's account verification method; If the account verification result of the target account is failed, determining the security level of the target device to be the third security level; The first security level, the second security level and the third security level are different from each other.
6. The method according to claim 5, wherein The account verification method includes a text message verification method and a one-click login method; and determining the security level of the target device according to the account verification method of the target account includes: If the verification method of the target account is SMS verification, the security level of the target device is determined to be the fourth security level; If the verification method of the target account is a one-key login method, the security level of the target device is determined to be the fifth security level; The first security level, the second security level, the third security level, the fourth security level and the fifth security level are different from each other.
7. The method according to claim 1, wherein The method further comprises: Obtaining an account verification method for the account to be verified, and obtaining an account verification result for the account to be verified under the account verification method; The unified anonymous identifier, the account to be verified, the account verification method of the account to be verified, and the account verification result of the account to be verified are associated and stored in a target database or blockchain network.
8. The method according to claim 7, wherein The account verification method of the account to be verified is a text message verification method; and obtaining the account verification result of the account to be verified under the account verification method includes: Generate account verification information for the account to be verified, and return the account verification information to the owner of the account to be verified; Obtaining account verification information provided by the target device; If the account verification information matches the account check information, it is determined that the account to be verified has passed the account verification.
9. The method according to claim 1, wherein The obtaining of the unified anonymous identifier of the target device includes: Obtaining a unified anonymous identifier address provided by an identification service, and sending instruction information to the target device, wherein the instruction information carries the unified anonymous identifier address, and the instruction information is used to instruct the target device to access the unified anonymous identifier address through a cellular network; Obtaining encrypted data returned by the target device, where the encrypted data is obtained after the target device accesses the unified anonymous identifier address through a cellular network; The encrypted data is sent to the identification service, and a unified anonymous identifier is obtained from the identification service through a token obtained by decrypting the encrypted data.
10. The method according to claim 1, wherein If the account to be verified passes the account verification, the method further includes: In response to the data management operation of the account to be verified, backing up the target data indicated by the data management operation to the blockchain network; processing the target data according to the data management operation; The data management operation includes a data deletion operation and a revocation of authorization operation.
11. The method according to claim 1, wherein The determining the security level of the target device according to the account to be verified and the unified anonymous identifier includes: Sending the account to be verified and the unified anonymous identifier to a target database or blockchain network; Obtaining security indication information returned by the target database or the blockchain network, where the security indication information is determined based on association information between the account to be verified and the unified anonymous identifier; Determine the security level of the target device according to the security indication information.
12. The method according to claim 1, wherein The determining the security level of the target device according to the account to be verified and the unified anonymous identifier includes: Obtaining the account verification record associated with the unified anonymous identifier and the verification record of the account to be verified; Performing feature extraction on the account verification record associated with the unified anonymous identifier and the verification record of the account to be verified, respectively, to obtain feature information of the account verification record associated with the unified anonymous identifier and feature information of the verification record of the account to be verified; The security level of the target device is determined according to the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified.
13. The method according to claim 12, wherein: The characteristic information of the verification record of the account to be verified includes at least one of the following: the number of verifications of the account to be verified in the first time period, and the number of unified anonymous identifiers associated with the account to be verified in the first time period; The characteristic information of the account verification record associated with the unified anonymous identifier includes at least one of the following: a verification success rate corresponding to the unified anonymous identifier, and the number of accounts associated with the unified anonymous identifier in the second time period.
14. The method according to claim 12, wherein: The characteristic information of the verification record of the to-be-verified account includes the number of verifications of the to-be-verified account within the first period, and the characteristic information of the verification record of the account associated with the unified anonymous identifier includes the verification success rate corresponding to the unified anonymous identifier; Determining the security level of the target device according to the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first time period includes: If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of verifications of the account to be verified within the first time period is greater than or equal to the number threshold, then the security level of the target device is determined to be the first security level; If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of verifications of the account to be verified within the first time period is less than the number threshold, then determining the security level of the target device to be a second security level; If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of verifications of the account to be verified within the first time period is greater than or equal to the number threshold, then the security level of the target device is determined to be the third security level; If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of verifications of the account to be verified within the first time period is less than the number threshold, the security level of the target device is determined to be the fourth security level.
15. The method according to claim 12, wherein The characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified in the first time period, and the characteristic information of the verification record of the account associated with the unified anonymous identifier includes the number of accounts associated with the unified anonymous identifier in the second time period; Determining the security level of the target device according to the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first time period includes: If the number of accounts associated with the unified anonymous identifier during the second period is greater than or equal to a first number threshold, and the number of verifications of the account to be verified during the first period is greater than or equal to a number threshold, then determining the security level of the target device to be a first security level; If the number of accounts associated with the unified anonymous identifier during the second time period is greater than or equal to a first number threshold, and the number of verifications of the account to be verified during the first time period is less than a number threshold, determining the security level of the target device to be a second security level; If the number of accounts associated with the unified anonymous identifier during the second period is less than a first number threshold, and the number of verifications of the account to be verified during the first period is greater than or equal to a number threshold, then determining the security level of the target device to be a third security level; If the number of accounts associated with the unified anonymous identifier in the second time period is less than the first number threshold, and the number of verifications of the account to be verified in the first time period is less than the number threshold, the security level of the target device is determined to be the fourth security level.
16. The method according to claim 12, wherein The characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified within the first time period, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the verification success rate corresponding to the unified anonymous identifier; Determining the security level of the target device according to the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first time period includes: If the verification success rate corresponding to the unified anonymous identifier is less than or equal to a success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to a second number threshold, determining the security level of the target device to be a first security level; If the verification success rate corresponding to the unified anonymous identifier is less than or equal to the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than a second number threshold, determining the security level of the target device to be a second security level; If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to a second number threshold, then determining the security level of the target device to be a third security level; If the verification success rate corresponding to the unified anonymous identifier is greater than the success rate threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second number threshold, the security level of the target device is determined to be the fourth security level.
17. The method according to claim 12, wherein The characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified in a first time period, and the characteristic information of the account verification record associated with the unified anonymous identifier includes the number of accounts associated with the unified anonymous identifier in a second time period; Determining the security level of the target device according to the characteristic information of the account verification record and the characteristic information of the verification record of the account to be verified within the first time period includes: If the number of accounts associated with the unified anonymous identifier during the second time period is greater than or equal to a first threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is greater than or equal to a second threshold, determining the security level of the target device to be a first security level; If the number of accounts associated with the unified anonymous identifier during the second time period is greater than or equal to a first threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is less than a second threshold, determining the security level of the target device to be a second security level; If the number of accounts associated with the unified anonymous identifier during the second time period is less than a first threshold, and the number of unified anonymous identifiers associated with the account to be verified during the first time period is greater than or equal to a second threshold, determining the security level of the target device to be a third security level; If the number of accounts associated with the unified anonymous identifier within the second time period is less than the first quantity threshold, and the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than the second quantity threshold, the security level of the target device is determined to be the fourth security level.
18. The method according to claim 12, wherein The characteristic information of the verification record of the account to be verified includes the number of verifications of the account to be verified within a first time period; if the unified anonymous identifier is not associated with an account verification record, determining the security level of the target device based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified includes: Determine the range to which the security level of the target device belongs as a target range; If the verification record of the account to be verified within the first time period is greater than or equal to the number threshold, the security level of the target device is determined to be the first security level; If the verification record of the account to be verified in the first time period is less than the number threshold, the security level of the target device is determined to be the second security level; The first security level and the second security level belong to the target range.
19. The method according to claim 12, wherein The characteristic information of the verification record of the account to be verified includes the number of unified anonymous identifiers associated with the account to be verified within a first time period; if the unified anonymous identifier is not associated with an account verification record, determining the security level of the target device based on the characteristic information of the account verification record associated with the unified anonymous identifier and the characteristic information of the verification record of the account to be verified includes: Determine the range to which the security level of the target device belongs as a target range; If the number of unified anonymous identifiers associated with the account to be verified within the first time period is greater than or equal to a second number threshold, determining the security level of the target device to be a first security level; If the number of unified anonymous identifiers associated with the account to be verified within the first time period is less than a second number threshold, determining the security level of the target device to be a second security level; The first security level and the second security level belong to the target range.
20. The method according to any one of claims 1 to 19, wherein The method further comprises: If it is detected that the account to be verified has violated the rules after passing the verification, obtaining a user identification card bound to the unified anonymous identifier corresponding to the account to be verified from the provider of the unified anonymous identifier; According to the processing rules corresponding to the illegal behavior, a penalty process is performed on the user identification card or the user of the user identification card.
21. The method according to any one of claims 1 to 19, wherein: If the account to be verified passes the account verification, the method further includes: In response to a notification management operation of the account to be verified, updating a notification recipient corresponding to the account to be verified based on the notification management operation; and When it is detected that the account to be verified meets the notification condition, a notification is sent to the notification recipient corresponding to the account to be verified; The notification includes at least one of the following: account login notification, account abnormality notification, and account operation notification.
22. A data processing device, characterized in that: The data processing device includes: an acquiring unit, configured to acquire a unified anonymous identifier of the target device in response to an authorization operation of the target device; and to acquire an account to be verified, the account to be verified being used to request to log in to a website or application; A processing unit is used to determine the security level of the target device based on the account to be verified and the unified anonymous identifier; and to determine the human-machine verification strategy corresponding to the target device based on the security level of the target device, where different security levels correspond to different human-machine verification strategies.
23. A computer device, characterized in that: include: memory and processor; a memory storing a computer program; A processor, configured to load the computer program to implement the data processing method according to any one of claims 1 to 21.
24. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and the computer program is suitable for being loaded by a processor and executing the data processing method according to any one of claims 1 to 21.
25. A computer program product, characterized in that The computer program product comprises a computer program, which is suitable for being loaded by a processor and executing the data processing method according to any one of claims 1 to 21.
Citation Information
Patent Citations
Internet of things mobile finance payment system based on cloud platform
CN106372874A
A one-click login procedure
CN113826095A