Device anonymous identification acquisition method, device, storage medium and computer equipment
By generating access tokens and expanding the device identification code to anonymous identification, the problem of difficulty in collecting device identification codes and no unified standards is solved, and secure device anonymous identification is achieved and user privacy is protected.
Patent Information
- Application Number
- CN202211329320.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-27
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2042-10-27
AI Technical Summary
In the prior art, it is difficult to collect equipment identification codes and there is no unified standard, which poses the risk of privacy leakage and tampering.
By generating an access token, expanding based on the mobile phone number and device identification code, obtaining the device anonymous identification, and returning it to the partner server together with the mobile phone number, instead of directly returning the device identification code.
It realizes the secure acquisition of anonymous equipment identification codes, avoids the problem of difficulty in collecting equipment identification codes and the lack of unified standards, and protects user privacy.
Smart Images

Figure CN115696314B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology for mobile devices, and in particular to a method, apparatus, storage medium, and computer equipment for obtaining an anonymous identifier for a device. Background Art
[0002] With the advancement of the mobile Internet era, many current applications still have many account security issues that trouble users. In response to this, operators have launched a unified and secure verification method - password-free authentication. It is an authentication method for operators based on mobile traffic networks. It identifies the user's mobile phone number, device identification code and other information when the user accesses the operator's network gateway, encrypts the information and transmits it to the operator's authentication system via HTTP / HTTPS. The operator's authentication system then opens its capabilities and provides it to third-party authentication.
[0003] However, traditional mobile terminal device identifiers such as the International Mobile Equipment Identity (IMEI) code have been recognized by some countries as part of user privacy and are at risk of being tampered with and misused. Therefore, many device companies have adopted extremely strict user privacy protection policies, making it difficult to collect device identifiers such as device identification codes and there is no unified standard. Summary of the Invention
[0004] The purpose of this application is to solve at least one of the above-mentioned technical defects, especially the technical defects in the prior art that device identification such as device identification codes are difficult to collect and there is no unified standard.
[0005] This application provides a method for obtaining an anonymous device identifier, the method comprising:
[0006] In response to the pre-authorization request sent by the client, determining the mobile phone number and device identification code corresponding to the client;
[0007] Generate an access token based on the mobile phone number and the device identification code, and return the access token to the client to trigger the client to send a device anonymous identification authorization request and the access token to the partner server;
[0008] receiving the access token and the device anonymous identification authorization request forwarded by the partner server, and after determining that the client information carried in the access token is correct, expanding the device identification code to obtain the device anonymous identification corresponding to the device identification code;
[0009] The anonymous device identifier and the mobile phone number are returned to the partner server, so that the partner server returns the anonymous device identifier and the mobile phone number to the client.
[0010] Optionally, the determining, in response to the pre-authorization request sent by the client, a mobile phone number and a device identification code corresponding to the client includes:
[0011] In response to a pre-authorization request sent by a client, determining header enhancement data corresponding to the client, the header enhancement data being data obtained by encrypting the mobile phone number and device identification code when the client's device is first activated;
[0012] The header enhancement data is decrypted to obtain the mobile phone number and the device identification code.
[0013] Optionally, generating an access token based on the mobile phone number and the device identification code includes:
[0014] Encoding the mobile phone number and the device identification code to obtain initial token data;
[0015] Based on a preset identification feature data set, identification feature data is randomly added to the initial token data, and the initial token data after the identification feature data is added is secondary encoded to generate an access token.
[0016] Optionally, determining whether the information carried by the access token is correct includes:
[0017] Decoding the access token to obtain client device information and token validity period;
[0018] When the client device information corresponds to the client information and the token validity period is within the validity period, it is determined that the client information carried by the access token is correct.
[0019] Optionally, the expanding the device identification code to obtain the device anonymous identifier corresponding to the device identification code includes:
[0020] Obfuscating the device identification code to obtain initial identification data corresponding to the device identification code;
[0021] Based on the identification feature of the partner server, the feature data corresponding to the partner server is added to the initial identification data, and the initial identification data after adding the feature data is asymmetrically encrypted to generate an anonymous device identification corresponding to the partner server.
[0022] Optionally, the device anonymous identifier is a hardware-type permanent device identifier.
[0023] Optionally, after the step of returning the anonymous device identifier and the mobile phone number to the partner server, the method further includes:
[0024] A correspondence between the device anonymous identifier, the mobile phone number, and the device identification code is established and stored in the partner server, so that when the partner server receives the device anonymous identifier authorization request sent by the client again, it directly responds and returns the device anonymous identifier and the mobile phone number to the client.
[0025] The present invention also provides a device for obtaining an anonymous identification of a device, comprising:
[0026] A pre-authorization module, configured to determine the mobile phone number and device identification code corresponding to the client in response to a pre-authorization request sent by the client;
[0027] A token generation module, configured to generate an access token based on the mobile phone number and the device identification code, and return the access token to the client to trigger the client to send a device anonymous identification authorization request and the access token to the partner server;
[0028] an identification generation module, configured to receive the access token and the device anonymous identification authorization request forwarded by the partner server, expand the device identification code, and obtain the device anonymous identification corresponding to the device identification code;
[0029] The authorization module is used to return the anonymous device identifier and the mobile phone number to the partner server, so that the partner server returns the anonymous device identifier and the mobile phone number to the client.
[0030] The present invention also provides a storage medium storing computer-readable instructions. When the computer-readable instructions are executed by one or more processors, the one or more processors execute the steps of the method for obtaining an anonymous identifier of a device as described in any one of claims 1 to 7.
[0031] The present invention also provides a computer device, comprising: one or more processors, and a memory;
[0032] The memory stores computer-readable instructions, which, when executed by the one or more processors, execute the steps of the method for obtaining an anonymous identifier of a device as claimed in any one of claims 1 to 7.
[0033] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:
[0034] The present application provides a method, apparatus, storage medium and computer device for obtaining an anonymous device identifier. When receiving a pre-authorization request from a client, the method can respond to and obtain the mobile phone number and device identification code corresponding to the client, and generate an access token based on the obtained mobile phone number and device identification code, and then return the access token to the client, so that the client can send an anonymous device identifier request to the partner server with the access token; when the present application receives an anonymous device identifier request forwarded by the partner server with the access token, the device identification code can be expanded to obtain an anonymous device identifier corresponding to the device identification code, and the anonymous device identifier and mobile phone number can be returned to the partner server, so that the partner server can return the anonymous device identifier and mobile phone number to the client. In this way, the anonymous device identifier can be sent to the partner server instead of the device identification code, avoiding the difficulty in collecting device identifiers such as device identification codes and the lack of a unified standard. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0036] Figure 1 A flowchart of a method for obtaining an anonymous device identifier provided in an embodiment of the present application;
[0037] Figure 2 An interactive diagram of a method for obtaining an anonymous device identifier provided in an embodiment of the present application;
[0038] Figure 3 A schematic diagram of the structure of a device anonymous identification acquisition apparatus provided in an embodiment of the present application;
[0039] Figure 4 A schematic diagram of the internal structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0040] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0041] With the advancement of the mobile Internet era, many current applications still have many account security issues that bother users. In response to this, operators have launched a unified and secure verification method - password-free authentication. It is an authentication method for operators based on mobile traffic networks. It identifies the user's mobile phone number, device identification code and other information when the user accesses the operator's network gateway, encrypts the information and transmits it to the operator's authentication system via HTTP / HTTPS. The operator's authentication system then opens its capabilities and provides it to third-party authentication.
[0042] However, traditional mobile terminal device identifiers such as the International Mobile Equipment Identity (IMEI) code have been recognized by some countries as part of user privacy and are at risk of being tampered with and misused. Therefore, many device companies have adopted extremely strict user privacy protection policies, making it difficult to collect device identifiers such as device identification codes and there is no unified standard.
[0043] Therefore, the purpose of this application is to solve the technical problem that the collection of device identifiers such as device identification codes in the prior art is difficult and there is no unified standard, and to propose the following technical solutions:
[0044] In one embodiment, Figure 1 As shown, Figure 1 A flowchart of a method for obtaining an anonymous device identifier provided in an embodiment of the present application is provided. The present application provides a method for obtaining an anonymous device identifier, which specifically includes the following steps:
[0045] S110: In response to the pre-authorization request sent by the client, determine the mobile phone number and device identification code corresponding to the client.
[0046] In this step, when the user starts password-free authentication login, the client will send a pre-authorization request. After receiving the pre-authorization request sent by the client, you can respond to the pre-authorization request to obtain the client's corresponding mobile phone number and device identification code.
[0047] It's understood that the device identification code here refers to what's commonly known as a mobile phone serial number or serial number. It's used to identify each individual mobile phone or other device on a mobile phone network, acting as a mobile phone ID to help verify the authenticity of the phone. Each mobile phone has a unique serial number, typically consisting of 15 digits, and no two phones have the same serial number.
[0048] Furthermore, the password-free authentication login of this application is an authentication method of the operator based on the mobile traffic network. During the login process, it can accurately identify the user device terminal information and directly achieve verification. This information is accessed through the traffic gateway of the mobile device terminal and attached to the operator's authentication system in the user's request. In this way, registration and login can be achieved in seconds, thereby obtaining information and services within the application.
[0049] Therefore, before the client sends a pre-authorization request, the client SDK will determine whether the terminal device has enabled data traffic. If not, it will use the WIFI switching function to switch to using data traffic and initiate a pre-authorization request to obtain relevant information about the terminal device corresponding to the client. This method of obtaining relevant information about mobile terminal devices through the operator's traffic gateway has the advantages of high reliability and high availability.
[0050] S120: Generate an access token based on the mobile phone number and device identification code, and return the access token to the client to trigger the client to send a device anonymous identification authorization request and access token to the partner server.
[0051] In this step, after obtaining the mobile phone number and device identification code through step S110, the mobile phone number and device identification code can be further encoded to generate a corresponding access token, and the access token is returned to the client so that the client can carry the access token to initiate a device anonymous identification authorization request to the partner server.
[0052] It is understood that the access token in this application refers to the identity authentication token that the client carries with it when making a request. The client and server generally communicate via the HTTP protocol. HTTP itself is stateless, and the server does not know the origin of each request. Therefore, when the client sends a request, it must attach its identity information to each request. Therefore, when the client logs in for the first time, the server will generate an access token and return it to the client. The access token can be carried with each subsequent request to identify the client.
[0053] Specifically, since the mobile phone number and device identification code of the terminal device corresponding to the client are a series of digital strings, in order to further improve the security of the access token generated by the mobile phone number and device identification code, the data of the mobile phone number and device identification code can be disassembled to obtain a string, and then some feature identification data can be randomly added. The string with the added feature identification data is then re-encoded to obtain the access token, so that the security of the generated access token is doubly protected.
[0054] Furthermore, when the pre-authorization request sent by the client is responded to and the returned access token is received, the client can use the information on the access token to authenticate its identity and initiate a device anonymous identification authorization request to the partner server to obtain relevant information.
[0055] S130: Receive the access token and device anonymous identification authorization request forwarded by the partner server, and after confirming that the client information carried in the access token is correct, expand the device identification code to obtain the device anonymous identification corresponding to the device identification code.
[0056] In this step, the access token and device anonymous identification authorization request forwarded by the partner server are received through step S120, and the client information carried on the access token is confirmed. Then, the device identification code corresponding to the client can be expanded and encrypted to obtain the device anonymous identification corresponding to the device identification code.
[0057] Specifically, after confirming the client information through the access token and obtaining the device identification code corresponding to the client, the device identification code can be expanded. According to the identification characteristics of the partner server, the device identification code is added with the relevant data of the partner server and encrypted, and finally the device anonymous identification is obtained. The device anonymous identification obtained by this method can achieve data desensitization and information security, and has application separation between different partner servers. The device anonymous identification obtained by different partner servers is different.
[0058] S140: Return the device anonymous identifier and mobile phone number to the partner server, so that the partner server returns the device anonymous identifier and mobile phone number to the client.
[0059] In this step, the device anonymous identifier and mobile phone number obtained in step S130 are returned to the partner server, so that the partner server responds to the device anonymous identifier authorization request sent by the client and returns the device anonymous identifier and mobile phone number to the client.
[0060] It is understandable that returning the device anonymous identifier and mobile phone number to the partner server at the same time can guide the partner server to associate and append the correspondence between the mobile phone number and the device anonymous identifier, so that the client can initiate the device anonymous identifier authorization request again and activate historical assets.
[0061] In the above embodiment, when a pre-authorization request is received from a client, the mobile phone number and device identification code corresponding to the client can be responded to and obtained, and an access token can be generated based on the obtained mobile phone number and device identification code, and then the access token can be returned to the client, so that the client can carry the access token to send a device anonymous identification request to the partner server; when the present application receives a device anonymous identification request forwarded by the partner server carrying the access token, the device identification code can be expanded to obtain a device anonymous identification corresponding to the device identification code, and the device anonymous identification and mobile phone number can be returned to the partner server, so that the partner server can return the device anonymous identification and mobile phone number to the client, so that the device anonymous identification can be sent to the partner server instead of the device identification code, avoiding the difficulty in collecting device identifications such as device identification codes and the lack of unified standards.
[0062] In one embodiment, determining the mobile phone number and device identification code corresponding to the client in response to the pre-authorization request sent by the client in S110 may include:
[0063] S111: In response to the pre-authorization request sent by the client, determine the header enhancement data corresponding to the client.
[0064] S112: Decrypt the header enhancement data to obtain the mobile phone number and device identification code.
[0065] In this embodiment, when a pre-authorization request is received from a client, the header enhancement data corresponding to the client's mobile terminal device can be determined first, and then the header enhancement data can be decrypted to obtain the mobile phone number and device identification code corresponding to the client's mobile terminal device.
[0066] It is understandable that the header enhancement data here is the data obtained by encrypting the mobile phone number and device identification code when the client's mobile terminal device is first activated, which serves as the basis for obtaining the client device information.
[0067] Specifically, the telecommunications network inserts the header enhancement data corresponding to the client's mobile terminal device into the pre-authorization request initiated by the client. When receiving the pre-authorization request sent by the client, it can first determine the header enhancement data carried by the pre-authorization request, and decrypt the header enhancement data to obtain the mobile phone number and device identification code corresponding to the client's mobile terminal device.
[0068] In one embodiment, generating an access token based on the mobile phone number and the device identification code in S120 may include:
[0069] S121: Encode the mobile phone number and device identification code to obtain initial token data.
[0070] S122: Based on a preset identification feature data set, randomly add identification feature data to the initial token data, and perform secondary encoding on the initial token data after adding the identification feature data to generate an access token.
[0071] In this embodiment, after obtaining the mobile phone number and device identification code corresponding to the client's mobile terminal device, the mobile phone number and device identification code can be initially encoded to obtain initial token data. Then, the initial token data can be randomly added with identification feature data from a pre-set identification feature data set, and the initial token data after adding the identification feature data can be secondary encoded to generate an access token.
[0072] All identification feature data in the identification feature dataset includes operator-specific attributes. Encoding the initial token data with randomly added identification feature data ensures the security and uniqueness of the generated access token. This application encodes the data twice with a time attribute during access token generation, resulting in an access token with an expiration date.
[0073] In one embodiment, determining in S130 whether the client information carried by the access token is correct may include:
[0074] S131: Decode the access token to obtain client device information and token validity period.
[0075] S132: When the client device information corresponds to the client information, and the token validity period is within the validity period, it is determined that the client information carried by the access token is correct.
[0076] In this embodiment, after receiving the device anonymous identification authorization request forwarded by the partner server carrying the access token, the access token can be decoded, the client device information and token validity period contained in the access token can be extracted, and the extracted client device information and token validity period can be verified to determine whether the client information carried by the access token is correct; when the client device information and the client information can correspond one-to-one, and the token validity period is within the valid period, it is determined that the client information carried by the access token is correct.
[0077] For example, when verifying the client device information and token validity period obtained after decoding, you can first determine whether all the information contained in the client device information corresponds to the client information. If so, then check whether the token validity period is still within the validity period; you can first determine that the token validity period is within the validity period, and then verify the client device information; you can also verify the client device information and the token validity period information at the same time. Other methods that can implement the verification of access token information in this application can be used as preferred solutions of this application and are not limited here.
[0078] Furthermore, after the verification of the client device information and the token validity period is completed, the present application can proceed to the next step based on the verification result. If the client device information and the token validity period information are correct, the device identification code corresponding to the client can be expanded to obtain the device anonymous identification and return it to the partner server; if there are one or more errors in the client device information and the token validity period information, the error information can be directly returned to the partner server so that the partner server can re-acquire the access token and re-initiate the device anonymous identification authorization request.
[0079] In one embodiment, the device identification code is expanded in S130 to obtain the device anonymous identification corresponding to the device identification code, which may include:
[0080] S133: Obfuscate the device identification code to obtain initial identification data corresponding to the device identification code.
[0081] S134: Based on the identification feature of the partner server, the feature data corresponding to the partner server is added to the initial identification data, and the initial identification data after the feature data is added is asymmetrically encrypted to generate an anonymous device identification corresponding to the partner server.
[0082] In this embodiment, after determining the device identification code of the client, the device identification code is obfuscated to obtain the initial identification data corresponding to the device identification code. The characteristic data corresponding to the partner server is then added to the initial identification data, and the initial identification data after adding the characteristic data is asymmetrically encrypted. Finally, an anonymous device identification corresponding to the partner server is generated.
[0083] Furthermore, after the device identification code is obfuscated, the corresponding feature data of the partner server is introduced for asymmetric encryption to achieve data desensitization and information security. Including the feature data corresponding to the partner server can achieve application isolation. The same client and different partner servers will obtain different device anonymous identifiers. This application returns an anonymous device identifier extended from the device identification code instead of directly returning the device identification code, which can meet customer needs in a minimized manner and protect user privacy in a maximized manner.
[0084] In one embodiment, the anonymous device identifier in S130 is a hardware-type permanent device identifier.
[0085] In this embodiment, the device anonymous identifier is a hardware-type permanent device identifier, which will not change even if the factory settings are restored, and the device anonymous identifier code cannot be reset.
[0086] In one embodiment, after returning the anonymous device identifier and mobile phone number to the partner server in S140, the following steps may also be performed:
[0087] S141: Establish a correspondence between the device anonymous identifier, mobile phone number and device identification code and store it in the partner server, so that when the partner server receives the device anonymous identifier authorization request sent by the client again, it can directly respond and return the device anonymous identifier and mobile phone number to the client.
[0088] In this embodiment, after obtaining the device anonymous identifier, mobile phone number and device identification code, a correspondence between the device anonymous identifier, mobile phone number and device identification code can be established, and the established correspondence can be stored in the partner server. When the partner server receives the device anonymous identifier authorization request sent by the client again, it can directly respond to the device anonymous identifier authorization request and return the device anonymous identifier and mobile phone number to the client.
[0089] Furthermore, when the client requests authorization from the partner server again, the partner server can directly find the client's information in the storage and respond, and at the same time obtain the client's historical information records on the partner server and associate them to activate historical assets.
[0090] In order to better explain the device anonymous identification acquisition method of this application, the following will be Figure 2 To further illustrate, schematically, Figure 2 As shown, Figure 2 An interactive diagram of a method for obtaining an anonymous device identifier provided in an embodiment of the present application.
[0091] Figure 2 In the process, after receiving the pre-authorization request sent by the client, the telecom network head enhanced data carried in the pre-authorization request is decrypted to obtain the mobile phone number and device identification code corresponding to the client, and an access token is generated. Then, the pre-authorization request sent by the client is responded to, and the access token corresponding to the client is returned to the client, so that the client can carry the access token to initiate a device anonymous identification authorization request to the partner server, thereby triggering the partner server to issue a device anonymous identification authorization request with the access token uploaded by the client; after receiving the device anonymous identification authorization request sent by the partner server, the mobile phone number corresponding to the client obtained by pre-authorization and the device anonymous identification extended based on the device identification code are returned to the partner server, so that the partner server can respond to the client's device anonymous identification authorization request and return the mobile phone number and device anonymous identification corresponding to the client to the client.
[0092] The text processing device provided in an embodiment of the present application is described below. The device anonymous identification acquisition device described below and the device anonymous identification acquisition method described above can refer to each other.
[0093] In one embodiment, Figure 3 As shown, Figure 3 This is a schematic diagram of the structure of a device anonymous identification acquisition device provided in an embodiment of the present application; the present application also provides a device anonymous identification acquisition device, including a pre-authorization module 210, a token generation module 220, an identification generation module 230 and an authorization module 240, specifically including the following:
[0094] The pre-authorization module 210 is configured to determine the mobile phone number and device identification code corresponding to the client in response to the pre-authorization request sent by the client.
[0095] The token generation module 220 is used to generate an access token based on the mobile phone number and the device identification code, and return the access token to the client to trigger the client to send a device anonymous identification authorization request and the access token to the partner server.
[0096] The identification generation module 230 is configured to receive the access token and device anonymous identification authorization request forwarded by the partner server, expand the device identification code, and obtain the device anonymous identification corresponding to the device identification code.
[0097] The authorization module 240 is used to return the device anonymous identifier and mobile phone number to the partner server, so that the partner server can return the device anonymous identifier and mobile phone number to the client.
[0098] In the above embodiment, when a pre-authorization request is received from a client, the mobile phone number and device identification code corresponding to the client can be responded to and obtained, and an access token can be generated based on the obtained mobile phone number and device identification code, and then the access token can be returned to the client, so that the client can carry the access token to send a device anonymous identification request to the partner server; when the present application receives a device anonymous identification request forwarded by the partner server carrying the access token, the device identification code can be expanded to obtain a device anonymous identification corresponding to the device identification code, and the device anonymous identification and mobile phone number can be returned to the partner server, so that the partner server can return the device anonymous identification and mobile phone number to the client, so that the device anonymous identification can be sent to the partner server instead of the device identification code, avoiding the difficulty in collecting device identifications such as device identification codes and the lack of unified standards.
[0099] In one embodiment, the pre-authorization module 210 may include:
[0100] The data acquisition module is used to determine the header enhancement data corresponding to the client in response to the pre-authorization request sent by the client.
[0101] The data decryption module is used to decrypt the header enhancement data to obtain the mobile phone number and device identification code.
[0102] In one embodiment, the token generation module 220 may include:
[0103] The initial encoding module is used to encode the mobile phone number and device identification code to obtain the initial token data.
[0104] The secondary encoding module is used to randomly add identification feature data to the initial token data based on a preset identification feature data set, and perform secondary encoding on the initial token data after adding the identification feature data to generate an access token.
[0105] In one embodiment, the identification generation module 230 may include:
[0106] The token decoding module is used to decode the access token to obtain the client device information and the token validity period.
[0107] The data verification module is used to verify whether the client device information and token validity period are correct.
[0108] In one embodiment, the identification generation module 230 may further include:
[0109] The data obfuscation module is used to perform obfuscation processing on the device identification code to obtain the initial identification data corresponding to the device identification code.
[0110] The data encryption module is used to add the characteristic data corresponding to the partner server to the initial identification data based on the identification characteristics of the partner server, and asymmetrically encrypt the initial identification data after adding the characteristic data to generate an anonymous device identification corresponding to the partner server.
[0111] In one embodiment, the authorization module 240 may further include:
[0112] The relationship establishment module is used to establish the corresponding relationship between the device anonymous identifier, mobile phone number and device identification code.
[0113] The relationship storage module is used to store the corresponding relationship between the device anonymous identifier, mobile phone number and device identification code to the partner server.
[0114] In one embodiment, the present application also provides a storage medium storing computer-readable instructions. When the computer-readable instructions are executed by one or more processors, the one or more processors execute the steps of the device anonymous identification acquisition method as described in any of the above embodiments.
[0115] In one embodiment, the present application also provides a computer device having computer-readable instructions stored therein. When the computer-readable instructions are executed by one or more processors, the one or more processors execute the steps of the device anonymous identification acquisition method as described in any of the above embodiments.
[0116] Schematically, as Figure 4 As shown, Figure 4 This is a schematic diagram of the internal structure of a computer device provided in an embodiment of the present application. The computer device 300 can be provided as a server. Figure 4 Computer device 300 includes a processing component 302, which further includes one or more processors, and a memory resource represented by memory 301 for storing instructions executable by processing component 302, such as an application. The application stored in memory 301 may include one or more modules, each corresponding to a set of instructions. In addition, processing component 302 is configured to execute the instructions to perform the method for obtaining an anonymous device identifier according to any of the above-mentioned embodiments.
[0117] The computer device 300 may further include a power supply component 303 configured to perform power management of the computer device 300, a wired or wireless network interface 304 configured to connect the computer device 300 to a network, and an input / output (I / O) interface 305. The computer device 300 may operate based on an operating system stored in the memory 301, such as Windows Server™, Mac OS X™, Unix™, Linux™, Free BSD™, or the like.
[0118] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0119] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0120] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The various embodiments can be combined as needed, and the same or similar parts can be referenced to each other.
[0121] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for obtaining an anonymous device identifier, characterized in that: Applied to the operator service end, the method includes: In response to the pre-authorization request sent by the client, determining the mobile phone number and device identification code corresponding to the client; Generate an access token based on the mobile phone number and the device identification code, and return the access token to the client to trigger the client to send a device anonymous identification authorization request and the access token to the partner server; receiving the access token and the device anonymous identification authorization request forwarded by the partner server, and after determining that the client information carried in the access token is correct, expanding the device identification code to obtain the device anonymous identification corresponding to the device identification code; The anonymous device identifier and the mobile phone number are returned to the partner server, so that the partner server returns the anonymous device identifier and the mobile phone number to the client.
2. The method for obtaining an anonymous device identifier according to claim 1, wherein: The step of determining the mobile phone number and device identification code corresponding to the client in response to the pre-authorization request sent by the client includes: In response to a pre-authorization request sent by a client, determining header enhancement data corresponding to the client, the header enhancement data being data obtained by encrypting the mobile phone number and device identification code when the client's device is first activated; The header enhancement data is decrypted to obtain the mobile phone number and the device identification code.
3. The method for obtaining an anonymous device identifier according to claim 1, wherein: Generating an access token based on the mobile phone number and the device identification code includes: Encoding the mobile phone number and the device identification code to obtain initial token data; Based on a preset identification feature data set, identification feature data is randomly added to the initial token data, and the initial token data after the identification feature data is added is secondary encoded to generate an access token.
4. The method for obtaining an anonymous device identifier according to claim 1, wherein: Determining whether the client information carried in the access token is correct includes: Decoding the access token to obtain client device information and token validity period; When the client device information corresponds to the client information and the token validity period is within the validity period, it is determined that the client information carried by the access token is correct.
5. The method for obtaining an anonymous device identifier according to claim 1, wherein: The step of expanding the device identification code to obtain the device anonymous identification corresponding to the device identification code includes: Obfuscating the device identification code to obtain initial identification data corresponding to the device identification code; Based on the identification feature of the partner server, the feature data corresponding to the partner server is added to the initial identification data, and the initial identification data after adding the feature data is asymmetrically encrypted to generate an anonymous device identification corresponding to the partner server.
6. The method for obtaining an anonymous device identifier according to claim 1, wherein: The anonymous device identifier is a hardware-type permanent device identifier.
7. The method for obtaining an anonymous device identifier according to claim 1, wherein: After the step of returning the anonymous device identifier and the mobile phone number to the partner server, the method further includes: A correspondence between the device anonymous identifier, the mobile phone number, and the device identification code is established and stored in the partner server, so that when the partner server receives the device anonymous identifier authorization request sent by the client again, it directly responds and returns the device anonymous identifier and the mobile phone number to the client.
8. A device anonymous identification acquisition device, characterized in that: Applied to the operator service end, the device includes: A pre-authorization module, configured to determine the mobile phone number and device identification code corresponding to the client in response to a pre-authorization request sent by the client; A token generation module, configured to generate an access token based on the mobile phone number and the device identification code, and return the access token to the client to trigger the client to send a device anonymous identification authorization request and the access token to the partner server; an identification generation module, configured to receive the access token and the device anonymous identification authorization request forwarded by the partner server, expand the device identification code, and obtain the device anonymous identification corresponding to the device identification code; The authorization module is used to return the anonymous device identifier and the mobile phone number to the partner server, so that the partner server returns the anonymous device identifier and the mobile phone number to the client.
9. A storage medium, characterized in that: The storage medium stores computer-readable instructions, which, when executed by one or more processors, enable the one or more processors to perform the steps of the method for obtaining an anonymous identifier of a device as described in any one of claims 1 to 7.
10. A computer device, characterized in that: include: one or more processors, and memory; The memory stores computer-readable instructions, which, when executed by the one or more processors, execute the steps of the method for obtaining an anonymous identifier of a device as claimed in any one of claims 1 to 7.
Citation Information
Patent Citations
Terminal equipment, method for generating identification token of terminal equipment and interaction method of client
CN111953477A
Mobile terminal device anonymous identification information authentication method and system for protecting device identification information
CN112926046A