Risk identification method and electronic device

By identifying risks in call forwarding or do-not-disturb modes on electronic devices, and using phone numbers and environmental information for risk identification and early warning, the problem of fraudsters using these modes to threaten user safety is solved, achieving more accurate risk assessment and user protection.

CN117544717BActive Publication Date: 2026-01-09HONOR DEVICE CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210922242.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-02
Publication Date
2026-01-09
Estimated Expiration
2042-08-02

AI Technical Summary

Technical Problem

In existing technologies, electronic devices cannot identify and issue warnings when they are induced by fraudsters to set up call forwarding or do-not-disturb mode, which threatens user information security and property security and hinders the normal operation of risk warning work.

Method used

Electronic devices acquire information by receiving user operations, identify risks in call forwarding or do-not-disturb modes, use telephone number information and environmental information to identify risks, output risk warning information, prevent risky operations, and communicate with the server to confirm the number owner information to determine security.

Benefits of technology

It improves user information security and property security, reduces the probability of risky operations, prevents electronic devices from being used to interfere with risk warning work, and optimizes user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117544717B_ABST
    Figure CN117544717B_ABST
Patent Text Reader

Abstract

The application discloses a risk identification method and an electronic device, and relates to the field of information security, and comprises the following steps: when the electronic device receives a user operation of setting a specific scene, for example, setting call forwarding, setting a do-not-disturb mode or setting a flight mode, acquiring first information, performing risk identification according to the first information, and outputting risk warning information in the case that it is determined that there is a risk operation. The first information comprises at least one of telephone number information and environment information in the specific scene. The electronic device may face or be suffering from network risk operations, property losses, information leakage and other problems when setting the specific scene. In the scheme, when the user sets the specific scene, the electronic device acquires the telephone number information and / or the environment information in the specific scene to perform risk identification to determine whether there is a risk operation in setting the specific scene, and timely performs risk warning in the case that it is determined that there is a risk operation, thereby improving the safety of the user in using the electronic device.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security, and in particular to a risk identification method and an electronic device. BACKGROUND

[0002] Communication electronic devices such as mobile phones usually provide a call forwarding function. After a user successfully sets the call forwarding function on the electronic device, the user can meet the normal listening needs of the user in some specific scenarios, for example, when the mobile phone has no network or is powered off, the user can still answer the phone through the call forwarding number.

[0003] With the development of Internet technology, the security of user terminals has gradually exposed shortcomings, and some specific users have threatened the information security of user terminals. For example, with the continuous upgrading of telecommunications network fraud methods, the functions originally provided for users on electronic devices may be used by fraudsters, making it easier for them to carry out fraud. Alternatively, specific personnel, such as fraudsters, can induce or manipulate users to set call forwarding to a specific number on the terminal, or turn on the terminal's do-not-disturb mode, so that the user terminal cannot communicate normally with the outside world. The above scenarios will cause the user terminal to temporarily lose normal contact, threatening the information security and property safety of the user terminal, and in some cases where warning personnel need to communicate with the user terminal to conduct risk warning, the above scenarios also hinder the normal progress of risk warning work.

[0004] In the process of implementing the present application, the inventors found that the electronic devices in the prior art do not identify and warn of the above risk scenarios. SUMMARY

[0005] The embodiments of the present application provide a risk identification method and an electronic device, which can identify and warn of risks in the above scenarios when the electronic device is triggered to set some functions or modes that temporarily lose normal contact, thereby improving the information security and property safety of the user terminal and optimizing the user experience. To achieve the above purpose, the embodiments of the present application adopt the following technical solutions.

[0006] In a first aspect, the embodiments provide a risk identification method applied to a terminal, which includes: an electronic device receiving a user's operation of setting a specific scenario, obtaining first information, and after obtaining the first information, the electronic device identifying risks according to the first information, and outputting risk warning information if it is determined that there is a risk.

[0007] The specific scenario can include a scenario in which the electronic device is temporarily unable to normally communicate, and the specific scenario includes, but is not limited to, call forwarding, do-not-disturb mode, or flight mode. The first information includes at least one of phone number information and environment information involved in the specific scenario. In an individual specific scenario, for example, a scenario in which call forwarding is set, the phone number information can include a local number and a call forwarding number; optionally, the phone number information can further include a terminal identifier associated with the local number and the call forwarding number. The environment information can include a phone call event, an application running event and / or a function running event, an application download event or an application installation event, an application interaction event, and the like. The phone call event refers to a behavior in which the electronic device exists a call. The application running event and / or the function running event refer to a behavior in which the electronic device exists an application running, and / or a behavior in which a specific function is run. The application download event or the application installation event refers to a behavior in which the electronic device exists an application download, or a behavior in which an application is installed. The application interaction event refers to a prompt message sent by an application and the like being received.

[0008] In this embodiment, when the electronic device detects that the specific scenario is triggered, the electronic device can obtain first information generated in the specific scenario, the first information including environment information and phone number information involved in the specific scenario, so that the electronic device can determine whether there is a risky operation in the current environment based on the first information. In a case where it is determined that there is a risky operation, the electronic device can output a risk warning in a timely manner, and stop a setting operation of the specific scenario, thereby effectively identifying a risky operation in the specific scenario, providing an effective risk prompt for a user, and to some extent, reducing a probability of the user performing the risky operation, and enhancing information security and property security of the user. Meanwhile, the risk operation is prevented from being performed, the risk operation is avoided from occurring, and to some extent, the electronic device used by the user is avoided from being used by a specific user, and a problem that the specific user uses the electronic device used by the user to hinder or interfere with a warning work performed by a staff is avoided.

[0009] With reference to the first aspect, in a possible design manner, in a case where the specific scenario is a call forwarding scenario, the phone number information at least includes a call forwarding number, and the electronic device performs risk identification based on the first information, including: if it is determined that the call forwarding number is not a safe number, it is determined that there is a risk.

[0010] With reference to the first aspect, in a possible design manner, the judgment condition for determining that the call forwarding number is a safe number includes one or more of the following: it is determined that the call forwarding number is a local SIM card number; it is determined that the call forwarding number is in a local address book; it is determined that the call forwarding number is in a preset whitelist; and it is determined that owner information of the call forwarding number is the same as owner information of the local number.

[0011] In the embodiment, if it is determined that the call transfer number satisfies at least one of the above judgment conditions, it is determined that the call transfer number is a safe number; otherwise, it is determined that the call transfer number is not a safe number.

[0012] The electronic device can send a query request to the server to obtain the owner information of the local number and the owner information of the call transfer number to determine that the owner information of the call transfer number is the same as the owner information of the local number.

[0013] In combination with the first aspect, in a possible design, determining that the owner information of the call transfer number is the same as the owner information of the local number includes: sending, to the server, a first query request carrying a first identifier and the call transfer number; the first identifier is used to indicate the local number of the terminal; the first query request is used to instruct the server to query the local owner information and the call transfer owner information based on the first identifier and the call transfer number; receiving a first query response returned by the server and carrying the local owner information and the call transfer owner information; and if it is determined that the local owner information and the call transfer owner information match successfully, it is determined that the owner information of the call transfer number is the same as the owner information of the local number.

[0014] Alternatively, the electronic device can also directly obtain the matching result of the server to determine that the owner information of the call transfer number is the same as the owner information of the local number.

[0015] In combination with the first aspect, in a possible design, determining that the owner information of the call transfer number is the same as the owner information of the local number includes: sending, to the server, a second query request carrying a first identifier and the call transfer number; the first identifier is used to indicate the local number of the terminal; the second query request is used to instruct the server to determine a matching result of the owner information of the local number and the owner information of the call transfer number; receiving a second query response returned by the server and carrying the matching result; and if it is determined that the matching result is a matching success, it is determined that the owner information of the call transfer number is the same as the owner information of the local number.

[0016] Optionally, the first identifier can be an internet protocol address (IP address) of the terminal, an international mobile subscriber identity (IMSI) of the terminal, or the like, which can be associated with the local number. It should be noted that the information field corresponding to the first identifier is not necessarily included in the above setting request, and can be an identifier of the electronic device, such as an IP address, which is directly extracted by the server when establishing a network layer connection with the electronic device. The server can determine the local number associated with the first identifier.

[0017] In this embodiment, for the scenario of call transfer, the electronic device performs risk identification from the perspective of determining whether the call transfer number is a safe number, and through one or more of the above methods, the risk identification judgment of the call transfer number from the security aspect can more accurately and effectively determine the risk of the call transfer number.

[0018] In combination with the first aspect, in a possible design manner, in a specific scenario, the scenario of call transfer, the phone number information at least includes a call transfer number, and the electronic device performs risk identification according to the first information, including: if it is determined that the call transfer number is a risk number, it is determined that there is a risk.

[0019] In combination with the first aspect, in a possible design manner, determining that the call transfer number is a risk number includes: determining that the call transfer number is in a preset blacklist; or, through a query manner to a third-party risk identification platform, determining that the call transfer number is a number that has been marked as risky.

[0020] Optionally, the number that has been marked as risky can be a number that the electronic device locally marks as risky, or a number that the electronic device obtains from the third-party risk identification platform and has been marked as risky. Optionally, the electronic device can also obtain a risk query result of querying the call transfer number from the third-party risk identification platform, and determine whether the call transfer number is a number that has been marked as risky based on the risk query result.

[0021] In this embodiment, for the scenario of call transfer, the electronic device performs risk identification from the perspective of determining whether the call transfer number is a risk number, and through one or more of the above methods, the risk identification judgment of the call transfer number from the risk aspect can more accurately and effectively determine the risk of the call transfer number.

[0022] In combination with the first aspect, in a possible design manner, in a specific scenario, the scenario of call transfer, the phone number information at least includes a call transfer number, and the electronic device performs risk identification according to the first information, including: if it is determined that the call transfer number is not a safe number, and it is determined that the call transfer number is a risk number, it is determined that there is a risk.

[0023] In this embodiment, for the scenario of call transfer, considering that some specific numbers may not be safe numbers, and may not be risk numbers, based on this situation, the electronic device can more accurately and effectively determine the risk of the call transfer number from the combination of security and risk.

[0024] With reference to the first aspect, in a possible design, the risk warning information includes content indicating that the user performs a cancel operation or a confirm operation on setting the specific scenario. Based on this, the risk identification method further includes: after the electronic device outputs the risk warning information, the electronic device acquires a setting operation triggered by the user, in a case where the setting operation is a cancel operation, outputting a prompt message indicating that the setting fails, and in a case where the setting operation is a confirm operation, outputting a prompt message indicating that the setting succeeds.

[0025] In this embodiment, the electronic device can output content for confirming setting of the specific scenario to the user at the same time as outputting the risk warning information, and perform a second confirmation on the current specific scenario setting operation, thereby allowing the user to continue or cancel setting of the specific scenario while alerting the user, improving user information security, and optimizing user experience.

[0026] With reference to the first aspect, in a possible design, in a case where the specific scenario is a call forwarding scenario, before the electronic device outputs the prompt message indicating that the setting succeeds, the electronic device further needs to send a call forwarding setting request to a server. The call forwarding setting request carries a first identifier and a call forwarding number, the first identifier is used to indicate a local number of the terminal, the call forwarding setting request is used to instruct the server to perform call forwarding from the local number to the call forwarding number according to the local number and the call forwarding number, and return a setting response to the electronic device after the setting is completed. The electronic device outputs the prompt message indicating that the setting succeeds after receiving the setting response returned by the server.

[0027] Optionally, the first identifier can be an internet protocol address (IP address) of the terminal, an international mobile subscriber identity (IMSI) of the terminal, or any identifier that can be associated with the local number. It should be noted that the information field corresponding to the first identifier is not necessarily included in the call forwarding setting request, and can be an identifier of the electronic device extracted by the server directly when a network layer connection between the electronic device and the server is established, such as an IP address. The server can determine the local number associated with the first identifier.

[0028] In this embodiment, for the scenario of setting call forwarding, the electronic device needs to communicate with the server to enable the server to perform a call forwarding setting operation according to the local number and the call forwarding number, and output the prompt message indicating that the setting succeeds after receiving the setting response returned by the server, so that the user can be explicitly informed that the call forwarding has been set successfully, thereby optimizing user experience.

[0029] With reference to the first aspect, in a possible design, the risk identification according to the first information comprises: determining, according to the environment information, whether there is a risk operation at the first moment or within a preset time length before the first moment. The first moment is the moment when the operation of setting the specific scene by the user is received.

[0030] Optionally, the preset time length before the first moment can be 5 minutes, 10 minutes, 30 minutes, etc.

[0031] In this embodiment, the electronic device determines that there is a risk if it is determined based on the environment information that there is a risk operation at the first moment or within a preset time length before the first moment. Based on different contents included in the environment information, the electronic device identifies different risk operations of the risk.

[0032] In a possible design, the environment information is a telephone call event, and the risk operation includes that a call number of the telephone call event is a risk number and / or the call number of the telephone call event is not a safe number.

[0033] Considering that the electronic device can be induced to operate by a specific user through a call, in this case, the environment information is a telephone call event, and the electronic device performs risk identification according to a call number involved in the telephone call event. For example, in combination with the first aspect, it can be determined whether the call number is a safe number and / or whether the call number is a risk number. In a case where it is determined that the call number is not a safe number and / or it is determined that the call number is a risk number, it is determined that there is a risk operation.

[0034] In this embodiment, in a case where the environment information is a telephone call event, the risk identification on the call number is the simplest and most effective risk identification method. If the electronic device determines that the call number is a risk number, or determines that the call number is not a safe number, or determines that the call number is not a safe number and is a risk number, it is directly determined that there is a risk operation in the current environment.

[0035] With reference to the first aspect, in a possible design, the environment information is an application running event and / or a function running event; and the risk operation includes that a specific application runs and / or a specific function of the specific application is run.

[0036] The specific application can be an application with a screen sharing or remote control mode, and the corresponding specific function can be a sharing or remote control mode start. Alternatively, the specific application can be a payment application, and the corresponding specific function can be a payment or transfer activity execution.

[0037] For example, if the electronic device can determine based on the environment information that there is a specific application running or that a specific function of the specific application is run, it is determined that there is a risk operation.

[0038] For example, if an electronic device determines that an application in screen-sharing mode is running, then a risky operation is identified; or, if an electronic device determines that it is currently in screen-sharing mode, then a risky operation is identified; or, if an electronic device determines that an application in screen-sharing mode is running and is currently in screen-sharing mode, then a risky operation is identified. For example, if an electronic device determines that a payment application is running, then a risky operation is identified; or, if an electronic device determines that a payment application is running and is performing a payment operation, then a risky operation is identified.

[0039] Optionally, the electronic device can determine whether to execute within a preset time period before the first moment based on the start and end times of a specific application and / or its specific function. For example, if the preset time period before the first moment is 30 minutes prior to the first moment, and the electronic device determines that both the start and end times of a payment application are within 30 minutes prior to the first moment, then a risky operation is identified. Alternatively, the electronic device can directly query the processes to determine whether a specific application and / or its specific function is executing at the current moment. For example, if the electronic device directly queries the processes and determines that a payment application is currently running, then a risky operation is identified.

[0040] In this embodiment, the electronic device may be remotely controlled by a specific user or induced to make a payment. In this case, the electronic device identifies risks based on application and / or function operation events. It can determine that there is a risk in the current operation by determining that a specific application is running and / or a specific function of a specific application is being executed at the current moment, or that a specific application has been running and / or a specific function of a specific application has been executed within a preset time period before the first moment. The identification of environmental information considering the operational vulnerabilities of the electronic device is more accurate.

[0041] In conjunction with the first aspect, in one possible design approach, the environmental information is an application download event, and the risky operation includes actions involving the download of risky applications; the environmental information is an application installation event, and the risky operation includes actions involving the installation of risky applications.

[0042] The risk application can be an application of the electronic device with labeled risk determined by querying a third-party risk identification platform, or can be an application with labeled risk pre-stored in the electronic device. Considering that a specific user can induce the user to install a risk application on the electronic device to perform a risk operation, the electronic device can determine whether the risk application is downloaded to perform risk identification based on an application download event, or the electronic device can determine whether the risk application is installed to perform risk identification based on an application installation event. Alternatively, the electronic device can determine whether there is an application download or installation behavior at the first time or within a preset time period before the first time according to a download start time, a download completion time, an installation start time, and an installation completion time of the application. Alternatively, the electronic device can also query a current process to determine whether there is an application download or installation behavior at the first time. If it is determined that there is an application download behavior or an application installation behavior at the first time or within a preset time period before the first time, it is determined whether the application is a risk application based on the application with labeled risk. In a case where it is determined that the application is a risk application, it is determined that there is a risk operation.

[0043] In this embodiment, the electronic device is likely to download and install a risk application in a scenario where the electronic device is at risk. Therefore, in a case where an application download or application installation behavior occurs, it is determined whether the application is a risk application, which can quickly and effectively determine the risk of application installation in the current scenario, so that the risk identification of the current operation from this perspective is more direct and effective.

[0044] In combination with the first aspect, in a possible design manner, the environment information is an application interaction event, and the risk operation includes receiving a risk prompt message sent by a specific application.

[0045] Alternatively, the specific application herein refers to an application that can perform risk identification and generate a risk prompt. For example, the specific application can be an application with a payment function and risk identification prompt. If the application detects a risk during the execution of the payment process, the application generates a risk prompt message and transmits the risk prompt message to the risk identification module of the electronic device. For example, the electronic device can also determine whether a risk prompt message is generated within a preset time period before the first time from a historical interaction event. If it is determined that a risk prompt message is generated within a preset time period before the first time, it is determined that there is a risk operation. Alternatively, if the electronic device receives a risk prompt message generated by the specific application at the first time, it is determined that there is a risk operation.

[0046] In this embodiment, the electronic device in a scenario where the electronic device is at risk can be sensitively identified by other specific applications. Therefore, risk identification based on specific application interaction information can quickly and effectively determine whether the electronic device is at risk.

[0047] Optionally, the environmental information includes one or more of the above events, and the electronic device can combine the multiple environmental information to identify the risk operation. In this embodiment, the electronic device identifies the risk operation based on the multiple environmental information, which can be combined and identified from one or more dimensions such as application dimension, system dimension, call dimension, and interaction information dimension. Considering the complex environment in which the electronic device may be located, the risk identification of the current operation is more accurate.

[0048] In combination with the first aspect, in a possible design, the risk identification according to the first information includes:

[0049] If it is determined that there is a risk according to the telephone number information and / or it is determined that there is a risk according to the environmental information, it is determined that there is a risk. If it is determined that there is no risk according to the telephone number information and it is determined that there is no risk according to the environmental information, it is determined that there is no risk.

[0050] Optionally, the electronic device can also combine the telephone number information and the environmental information to identify the risk. In the case that it is determined that there is no risk based on the telephone number information and it is determined that there is no risk based on the environmental information, it is finally determined that there is no risk. In the case that it is determined that there is a risk based on the telephone number information and / or it is determined that there is a risk based on the environmental information, it is finally determined that there is a risk.

[0051] In this embodiment, the combination of the telephone number information and the environmental information for risk identification judgment makes the risk identification more secure and further improves the effectiveness of risk identification.

[0052] The second aspect provides an electronic device, which includes a processor and a display screen.

[0053] The processor is configured to receive a user setting operation of a specific scene, obtain first information, identify a risk according to the first information, and output risk warning information to the display screen if it is determined that there is a risk. The display screen is configured to display the risk warning information.

[0054] The specific scenario can include a scenario in which the electronic device is temporarily unable to normally communicate, and the specific scenario includes, but is not limited to, setting call forwarding, setting a do-not-disturb mode, and setting a flight mode. The first information includes, but is not limited to, number information and environment information involved in the specific scenario. The number information generally includes a call forwarding number. Optionally, the telephone number information can further include a first identifier for indicating a local number and the call forwarding number. The environment information can include a telephone call event, an application running event and / or a function running event, an application download event or an application installation event, and an application interaction event. The telephone call event refers to a behavior in which the electronic device exists a call. The application running event and / or the function running event refer to a behavior in which the electronic device exists an application running, and / or a behavior in which a specific function is run. The application download event or the application installation event refers to a behavior in which the electronic device exists an application download, or a behavior in which an application is installed. The application interaction event refers to receiving a prompt message sent by an application.

[0055] In this embodiment, when the electronic device detects that the specific scenario is triggered, the electronic device can acquire first information generated in the specific scenario, and the first information includes environment information and number information involved in the specific scenario. Therefore, the electronic device can determine whether there is a risky operation in the current environment based on the first information, and output a risk warning in a timely manner and stop a setting operation of the specific scenario in a case where it is determined that there is a risky operation. This achieves effective identification and risk warning of a risky operation in the specific scenario, provides an effective risk prompt for a user, and to some extent, reduces a probability of the user performing the risky operation and enhances information security and property security of the user. Meanwhile, the risky operation is prevented from being performed, the occurrence of the risky operation is avoided, and to some extent, the electronic device used by the user is prevented from being used by a specific user, and a problem in which the specific user uses the electronic device used by the user to hinder or interfere with a warning work performed by a staff is avoided.

[0056] With reference to the second aspect, in a possible design manner, in a case where the specific scenario is a call forwarding scenario, the telephone number information at least includes a call forwarding number, and the processor is configured to determine that there is a risk if it is determined that the call forwarding number is not a safe number.

[0057] With reference to the second aspect, in a possible design manner, the judgment condition for determining that the call forwarding number is a safe number includes one or more of the following: determining that the call forwarding number is a local SIM card number; determining that the call forwarding number is in a local address book; determining that the call forwarding number is in a preset white list; and determining that owner information of the call forwarding number is same as owner information of a local number.

[0058] The electronic device can send a query request to the server to obtain the owner information of the local number and the owner information of the call forwarding number, determine that the owner information of the call forwarding number is the same as the owner information of the local number, and based on this, the electronic device further includes a communication module.

[0059] In combination with the second aspect, in a possible design manner, the communication module is configured to send, to the server, a first query request carrying a first identifier and the call forwarding number; the first identifier is used to indicate the local number of the terminal; the first query request is used to instruct the server to query the local owner information and the call forwarding owner information based on the local number and the call forwarding number; receive the first query response returned by the server, which carries the local owner information and the call forwarding owner information; and if it is determined that the local owner information and the call forwarding owner information match successfully, it is determined that the owner information of the call forwarding number is the same as the owner information of the local number.

[0060] Alternatively, the electronic device can also directly obtain the matching result of the server to determine that the owner information of the call forwarding number is the same as the owner information of the local number.

[0061] In combination with the second aspect, in a possible design manner, the communication module is configured to send, to the server, a second query request carrying a first identifier and the call forwarding number; the second query request is used to instruct the server to determine the matching result of the owner information of the local number and the owner information of the call forwarding number; receive the second query response returned by the server, which carries the matching result; and if it is determined that the matching result is a matching success, it is determined that the owner information of the call forwarding number is the same as the owner information of the local number.

[0062] In this embodiment, for the scenario of call forwarding, the electronic device performs risk identification from the perspective of determining whether the call forwarding number is a safe number, and through one or more of the above methods, the risk identification judgment of the call forwarding number from the security aspect can more accurately and effectively judge the risk of the call forwarding number.

[0063] In combination with the second aspect, in a possible design manner, in a specific scenario, the telephone number information at least includes the call forwarding number, and the processor is configured to determine that there is a risk if it is determined that the call forwarding number is a risk number.

[0064] In combination with the second aspect, in a possible design manner, determining that the call forwarding number is a risk number includes: determining that the call forwarding number is in a preset blacklist; or determining that the call forwarding number is a number that has been labeled as a risk through a query to a third-party risk identification platform.

[0065] In the embodiment, for the scenario of call transfer, the electronic device performs risk identification from the perspective of determining whether the call transfer number is a risk number, and the risk identification of the call transfer number is determined from the risk aspect by using one or more of the above methods, so that the risk of the call transfer number can be more accurately and effectively determined.

[0066] In combination with the second aspect, in a possible design manner, in the scenario of call transfer, the phone number information at least includes a call transfer number, and the processor is configured to determine that there is a risk if it is determined that the call transfer number is not a safe number and it is determined that the call transfer number is a risk number.

[0067] In the embodiment, for the scenario of call transfer, it is considered that some specific numbers may not be safe numbers and may not be risk numbers, and based on this situation, the electronic device can more accurately and effectively determine the risk of the call transfer number by combining the safety and risk dimensions.

[0068] In combination with the second aspect, in a possible design manner, the risk warning information includes content indicating that the user performs cancelation setting of the specific scenario or performs determination setting of the specific scenario. Based on this, the processor is configured to acquire a setting operation triggered by the user, and in a case where the setting operation is cancelation setting of the specific scenario, output a prompt message of setting failure to the display screen, and in a case where the setting operation is determination setting of the specific scenario, output a prompt message of setting success to the display screen.

[0069] The display screen is configured to display the prompt message of setting failure or the prompt message of setting success.

[0070] In the embodiment, the electronic device can output the content of secondary determination setting of the specific scenario to the user while outputting the risk warning information, and perform secondary determination on the current specific scenario setting operation, thereby warning the user and allowing the user to continue or cancel the setting of the specific scenario, improving the user information security and optimizing the user experience.

[0071] In combination with the second aspect, in a possible design manner, the communication module is further configured to send a setting request of call transfer to a server, and receive a setting response returned by the server and feed back the setting response to the processor.

[0072] The processor is configured to output a prompt message of setting success to the display screen based on the feedback response.

[0073] The display screen is configured to display the prompt message of setting success.

[0074] Optionally, the first identifier and the call transfer number are carried in the setting request, the first identifier is used to indicate the local number of the terminal, the setting request is used to instruct the server to transfer the call of the local number to the call transfer number according to the local number and the call transfer number, and return a setting response to the electronic device after the setting is completed. The electronic device outputs a prompt message indicating that the setting is successful after receiving the setting response returned by the server.

[0075] In this embodiment, for the scenario of setting the call transfer, the electronic device needs to communicate with the server to enable the server to perform the setting operation of the call transfer according to the local number and the call transfer number, and output a prompt message indicating that the setting is successful after receiving the setting response returned by the server, so that the user can be explicitly aware that the call transfer has been successfully set, thereby optimizing the user experience.

[0076] With reference to the second aspect, in a possible design, the processor is configured to determine, according to the environment information, whether there is a risk operation at a first time or within a preset time length before the first time. The first time is the time when the user sets the operation of the specific scenario.

[0077] With reference to the second aspect, in a possible design, the environment information is a telephone call event, and the risk operation includes that a call number of the telephone call event is a risk number, and / or the call number of the telephone call event is not a safe number.

[0078] In this embodiment, in the case where the environment information is a telephone call event, the risk identification of the call number is the simplest and most effective risk identification method. If the electronic device determines that the call number is a risk number, or determines that the call number is not a safe number, or determines that the call number is not a safe number and is a risk number, it is directly determined that the current environment has a risk operation.

[0079] With reference to the first aspect, in a possible design, the environment information is an application running event and / or a function running event, and the risk operation includes that a specific application runs and / or a specific function of the specific application is executed.

[0080] In this embodiment, the electronic device may be remotely controlled by a specific user or induced by a specific user to perform a payment operation, in which case the electronic device performs risk identification based on the application and / or function running event, and determines that the current operation has a risk by determining that the specific application runs and / or the specific function of the specific application is executed at the current time or within a preset time length before the first time, and the identification of the environment information considering the operation vulnerability of the electronic device is more accurate.

[0081] With reference to the first aspect, in a possible design, the environment information is an application download event, and the risky operation includes an action of downloading a risky application; the environment information is an application installation event, and the risky operation includes an action of installing a risky application.

[0082] In this embodiment, the risky application is downloaded and installed in the scenario where the electronic device is at risk with a high probability, and therefore, in the case where an application download or installation action is generated, whether the application is a risky application can be determined to quickly and effectively determine the risk of application installation in the current scenario, so that the risk identification of the current operation from this perspective is more direct and effective.

[0083] With reference to the first aspect, in a possible design, when the environment information is an application interaction event, the risky operation includes receiving a risk prompt message sent by a specific application.

[0084] In this embodiment, the scenario where the electronic device is at risk can be sensitively identified by other specific applications, and therefore, risk identification based on specific application interaction information can quickly and effectively determine whether the electronic device is at risk.

[0085] Optionally, the environment information includes one or more of the above events, and the electronic device can identify the risky operation in combination with multiple environment information. In this embodiment, the electronic device identifies the risky operation based on multiple environment information, which can be identified in combination from one or more dimensions such as the application dimension, the system dimension, the call dimension, and the interaction information dimension, so that the risk identification of the current operation is more accurate considering the complex environment in which the electronic device can be located.

[0086] With reference to the second aspect, in a possible design, the processor is configured to: if it is determined that there is a risk according to the risk identification based on the telephone number information and / or the risk identification based on the environment information, it is determined that there is a risk; if it is determined that there is no risk according to the risk identification based on the telephone number information and according to the risk identification based on the environment information, it is determined that there is no risk.

[0087] Optionally, the electronic device can further identify the risk in combination with the telephone number information and the environment information. In the case where it is determined that there is no risk based on the telephone number information and it is determined that there is no risk based on the environment information, it is finally determined that there is no risk; in the case where it is determined that there is a risk based on the telephone number information and / or it is determined that there is a risk based on the environment information, it is finally determined that there is a risk.

[0088] In this embodiment, the risk identification in combination with the telephone number information and the environment information makes the risk identification more secure and further improves the effectiveness of the risk identification.

[0089] In a third aspect, an electronic device is provided, which includes a memory, a display screen and one or more processors; the memory, the display screen and the processors are coupled; the memory has stored computer program codes including computer instructions, which when executed by the processors, cause the electronic device to perform the method according to any one of the first aspect.

[0090] In a fourth aspect, a computer readable storage medium is provided, which has stored instructions, which when executed on an electronic device, cause the electronic device to perform the method according to any one of the first aspect.

[0091] In a fifth aspect, a computer program product is provided, which includes instructions, which when executed on an electronic device, cause the electronic device to perform the method according to any one of the first aspect.

[0092] It can be understood that the electronic device according to the second aspect, the third aspect and any possible design of the second aspect and the third aspect, the computer readable storage medium according to the fourth aspect, and the computer program product according to the fifth aspect can achieve the beneficial effects of the first aspect and any possible design of the first aspect, which will not be described here. BRIEF DESCRIPTION OF DRAWINGS

[0093] Figure 1 A scene diagram of setting call forwarding to a specific number for a specific user in a risk warning scene provided by an embodiment of the present application;

[0094] Figure 2A An interface diagram of setting call forwarding based on an electronic device interaction interface provided by an embodiment of the present application;

[0095] Figure 2B An interface diagram of setting call forwarding based on dialing mode provided by an embodiment of the present application;

[0096] Figure 3 An application environment diagram of a risk identification method provided by an embodiment of the present application;

[0097] Figure 4A A hardware structure diagram of an electronic device provided by an embodiment of the present application;

[0098] Figure 4B A system software architecture diagram of an electronic device provided by an embodiment of the present application;

[0099] Figure 5 A flowchart of a risk identification method provided by an embodiment of the present application;

[0100] Figure 6Another display interface of an electronic device provided by an embodiment of the present application is shown in the figure;

[0101] Figure 7 Another risk identification method provided by an embodiment of the present application is shown in the figure;

[0102] Figure 8 Another risk identification method provided by an embodiment of the present application is shown in the figure;

[0103] Figure 9 Another risk identification method provided by an embodiment of the present application is shown in the figure;

[0104] Figure 10 Another structure of an electronic device provided by an embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0105] Hereinafter, the terms "first" and "second" are only used for the purpose of description, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first" and "second" can explicitly or implicitly include one or more of the features. In the description of the embodiments, unless otherwise specified, the meaning of "a plurality of" is two or more.

[0106] The inventors found in the research process that in some risky scenarios, for example, in the scenario of network telecommunications fraud, a specific user may induce an ordinary user to set the mobile phone to a certain mode or set a certain function during or after communication with the ordinary user, in order to interfere with or hinder the risk warning work of the staff on the ordinary user. The specific user can be understood as a fraudster who intends to perform risk operations such as property transfer and information theft of the ordinary user. Referring to Figure 1 As shown, the electronic device 1 is an electronic device used by an ordinary user, the electronic device 2 is an electronic device used by a specific user, and the electronic device 3 is an electronic device used by a staff. Optionally, the electronic device 1, the electronic device 2, and the electronic device 3 can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc.

[0107] Taking a mobile phone as an example, the specific user induces the ordinary user to set the mobile phone to a certain mode or set a certain function, which can include inducing the ordinary user to set the electronic device 1 to call transfer to a certain number (a certain number used in the electronic device 2) so that the staff is called to the certain number when the staff makes a telephone warning to the ordinary user, and the ordinary user is impersonated by the specific user to reply to the warning; or, the specific user induces the ordinary user to set the electronic device 1 to a do-not-disturb mode, or induces the ordinary user to set the electronic device 1 to a mode of rejecting unknown numbers, so that the staff cannot effectively contact the ordinary user, and the staff's risk warning work on the ordinary user is hindered.

[0108] Among them, the call transfer function refers to transferring incoming calls to a set call transfer number in some specific scenarios such as the phone being unable to answer or unwilling to answer the phone. The call transfer function includes unconditional call transfer, busy call transfer, no-answer call transfer, and user-unavailable call transfer. Common call transfer setting methods include: the first is to set through the menu provided by the mobile phone interface, which can be referred to as Figure 2A , the user can set call transfer under different conditions based on the interactive interface 10; the second is to set call transfer through the man-machine-interface (MMI) code input by the dial pad of the phone application, which can be referred to as Figure 2B , the user can dial call transfer settings based on the dial pad interface 20 of the phone application. Exemplarily, the dialing method sets the call transfer to include the following methods:

[0109] Method one: unconditional call transfer, dial **21* called number #.

[0110] Method two: busy call transfer, dial **67* called number #.

[0111] Method three: no-answer call transfer, dial **61* called number #.

[0112] Method four: user-unavailable call transfer, dial **62* called number #.

[0113] Method five: cancel call transfer settings, dial ##002#.

[0114] Exemplarily, in the process of dialing to set the unconditional call transfer, the mobile phone triggers the display of the prompt information interface 21 on the dial pad interface 20 when detecting that the user inputs **21*137******** and ends with “#”, which can be referred to as Figure 2BAs shown, the prompt information interface can include content for prompting the user whether to unconditionally call transfer to 137********, and the prompt information interface includes function controls for determining to set the call transfer, for canceling to set the call transfer, as shown in interface 21, including two function button controls of "determine" and "cancel", to enable the user to confirm the call transfer setting operation or cancel the call transfer operation.

[0115] It can be understood that the user can also set the call transfer in other ways. Embodiments of the present application will not be described again.

[0116] It should be understood that no matter which of the above ways is used to set the call transfer, the mobile phone sends a call transfer setting request carrying the local number and the call transfer number to the operator (server) after detecting the confirmation of the call transfer setting operation, and the mobile phone completes the call transfer setting operation after receiving the response of the operator (server).

[0117] In view of the above specific user inducing ordinary users to set the mobile phone to some specific scenarios, there is no corresponding technical solution in the prior art to identify and warn the risk operation that may exist in these scenarios, which leads to the fact that specific users can use the specific scenarios to perform risk operations, which poses a certain threat to the information security and property safety of ordinary users, and interferes with or hinders the risk warning work of the staff. The present embodiment provides a risk identification method to effectively identify and warn the above risk operation, so as to avoid the interference or hindrance of the specific user to the warning work of the staff, so as to improve the information security and property safety of ordinary users. The risk identification method provided by the present embodiment is applied to the implementation environment as shown in Figure 3 Figure 3 The implementation environment includes an electronic device 100 and a server 101, and the electronic device 100 communicates with the server 101 through a network.

[0118] The electronic device 100 can be understood as a device used by an ordinary user, and in some risky scenarios, the electronic device 100 can also be understood as a device used by a victim. The electronic device 100 can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc. The electronic device 100 has functions such as communication, call transfer setting, do-not-disturb setting, and payment, and the product type of the electronic device 100 is not limited in the present embodiment. The server 101 can be a server corresponding to an operator in communication connection with the electronic device. The server 101 can be a stand-alone server, a server cluster, or a cloud server, and the product type of the server 101 is not limited in the present embodiment. It should be noted that the server 101 can provide functions such as telephone number information query and telephone number function setting for the electronic device 100.​

[0119] Illustratively, the electronic device 100 can send a call transfer setting request carrying the local number and the call transfer number to the server 101, the server 101 responds to the call transfer setting request, performs call transfer setting based on the local number and the call transfer number, and returns a setting response to the electronic device 100, and the electronic device 100, after receiving the setting response, displays prompt information such as call transfer setting success to the user based on the interactive interface.

[0120] Optionally, the electronic device 100 can also send a principal query request carrying the local number and the call transfer number to the server 101, the server 101 obtains the local principal information corresponding to the local number and the transfer principal information corresponding to the call transfer number based on its own database, and returns a query response carrying the local principal information and the transfer principal information to the electronic device 100, and the electronic device 100, after receiving the query response, displays the local principal information and the transfer principal information to the user based on the interactive interface. Wherein, the principal information refers to the personal information of the user corresponding to the telephone number, for example, the user's name, the place of residence of the telephone number, etc.

[0121] The electronic device 100 in the embodiments of the present application can be an electronic device installed with a telephone application and can be installed with other functional applications. Wherein, the other functional applications can include applications with payment functions, applications with communication functions, applications with the function of managing electronic device system, applications with the function of realizing remote control of electronic devices, etc. Illustratively, the electronic device can be a portable computer (such as a mobile phone), a tablet computer, a notebook computer, a personal computer (PC), a wearable electronic device (such as a smart watch), an augmented reality (AR) \ virtual reality (VR) device, a vehicle-mounted computer, etc., and the specific form of the electronic device is not specially limited in the following embodiments.

[0122] Please refer to Figure 4AFig. 1 shows a structural block diagram of an electronic device (e.g., the electronic device 100) according to an embodiment of the present application. The electronic device 100 can include a processor 310, an external memory interface 320, an internal memory 321, a universal serial bus (USB) interface 330, a charging management module 340, a power management module 341, a battery 342, an antenna 1, an antenna 2, a radio frequency module 350, a communication module 360, an audio module 370, a speaker 370A, a receiver 370B, a microphone 370C, a headset jack 370D, a sensor module 380, a key 390, a motor 391, an indicator 392, a camera 393, a display screen 394, and a subscriber identification module (SIM) card interface 395, etc. The sensor module 380 can include a pressure sensor 380A, a gyroscope sensor 380B, a barometric pressure sensor 380C, a magnetic sensor 380D, an acceleration sensor 380E, a distance sensor 380F, a proximity light sensor 380G, a fingerprint sensor 380H, a temperature sensor 380J, a touch sensor 380K, an ambient light sensor 380L, a bone conduction sensor 380M, etc.

[0123] The structure shown in the embodiments of the present application does not constitute a limitation on the electronic device 100. It can include more or fewer components than shown, or combine certain components, or split certain components, or different arrangement of components. The components shown can be implemented in hardware, software, or a combination of software and hardware.

[0124] The processor 310 can include one or more processing units. For example, the processor 310 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units can be independent devices or integrated into one or more processors.

[0125] The controller mentioned above can be a decision maker that commands various components of the electronic device 100 to work in coordination according to instructions. It is the nerve center and command center of the electronic device 100. The controller generates operation control signals according to instruction operation codes and timing signals to complete the control of fetching and executing instructions.

[0126] The processor 310 can also have a memory for storing instructions and data. In some embodiments, the memory in the processor 310 is a cache memory, which can hold instructions or data that the processor 310 has just used or is likely to use again. If the processor 310 needs to use the instructions or data again, it can directly call them from the memory. This avoids repeated access and reduces the waiting time of the processor 310, thereby improving the efficiency of the system.

[0127] In some embodiments, the processor 310 can include an interface. The interface can include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a SIM interface, and / or a USB interface, etc.

[0128] The USB interface 330 can be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 330 can be used to connect a charger to charge the electronic device 100, and can also be used to transmit data between the electronic device 100 and a peripheral device. It can also be used to connect earphones to play audio through the earphones. It can also be used to connect other electronic devices, such as AR devices, etc.

[0129] The interface connection relationship between the modules shown in the embodiments of the present application is only illustrative and does not constitute a limitation on the structure of the electronic device 100. The electronic device 100 can use different interface connection methods in the embodiments of the present application, or a combination of multiple interface connection methods.

[0130] The charging management module 340 is configured to receive charging input from a charger. The charger can be a wireless charger or a wired charger. In some embodiments with wired charging, the charging management module 340 can receive charging input from a wired charger through the USB interface 330. In some embodiments with wireless charging, the charging management module 340 can receive wireless charging input through a wireless charging coil of the electronic device 100. The charging management module 340 can charge the battery 342 and supply power to the electronic device 100 through the power management module 341.

[0131] The power management module 341 is configured to connect the battery 342 and the charging management module 340 to the processor 310. The power management module 341 receives input from the battery 342 and / or the charging management module 340 to supply power to the processor 310, the internal memory 321, the external memory interface 320, the display screen 394, the camera 393, and the communication module 360, etc. The power management module 341 can also be configured to monitor parameters such as battery capacity, battery cycle count, battery health status (leakage, impedance), etc. In some embodiments, the power management module 341 can also be disposed in the processor 310. In some embodiments, the power management module 341 and the charging management module 340 can also be disposed in the same device.

[0132] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the radio frequency module 350, the communication module 360, the modem, and the baseband processor, etc.

[0133] The antenna 1 and the antenna 2 are configured to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 100 can be configured to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization of the antennas. For example, a cellular network antenna can be multiplexed as a wireless local area network diversity antenna. In some embodiments, the antennas can be used in combination with a tuning switch.

[0134] The radio frequency module 350 can provide a communication processing module for wireless communication including 2G / 3G / 4G / 5G, etc. applied to the electronic device 100. The radio frequency module 350 can include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The radio frequency module 350 receives electromagnetic waves from the antenna 1, and performs filtering, amplification, etc. on the received electromagnetic waves, and transmits the electromagnetic waves to the modem for demodulation. The radio frequency module 350 can also amplify signals modulated by the modem, and convert the signals into electromagnetic waves to be radiated through the antenna 1. In some embodiments, at least part of the functional modules of the radio frequency module 350 can be disposed in the processor 310. In some embodiments, at least part of the functional modules of the radio frequency module 350 and at least part of the modules of the processor 310 can be disposed in the same device.

[0135] The modem can include a modulator and a demodulator. The modulator is configured to modulate a low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is configured to demodulate a received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. The low-frequency baseband signal processed by the baseband processor is transmitted to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 370A, the microphone 370B, etc.), or displays an image or a video through the display screen 394. In some embodiments, the modem can be a separate device. In some embodiments, the modem can be independent of the processor 310, and can be disposed in the same device as the radio frequency module 350 or other functional modules.

[0136] The communication module 360 can provide a communication processing module for wireless communication solutions applied to the electronic device 100, including wireless local area networks (WLAN) (such as a wireless fidelity (Wi-Fi) network), Bluetooth (BT), a global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), and the like. The communication module 360 can be one or more devices that integrate at least one communication processing module. The communication module 360 receives electromagnetic waves via the antenna 2, performs frequency modulation and filtering processing on the electromagnetic wave signal, and transmits the processed signal to the processor 310. The communication module 360 can also receive a signal to be transmitted from the processor 310, perform frequency modulation and amplification, and convert the signal into electromagnetic wave radiation via the antenna 2.

[0137] In some embodiments, the antenna 1 and the radio frequency module 350 of the electronic device 100 are coupled, and the antenna 2 and the communication module 360 are coupled, so that the electronic device 100 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. The GNSS can include a satellite based augmentation systems (SBAS), global navigation satellite system (GLONASS), BeiDou navigation satellite system (BDS), Quasi-Zenith satellite system (QZSS), and / or satellite based augmentation systems (SBAS).

[0138] The electronic device 100 implements a display function through a GPU, a display screen 394, and an application processor, etc. The GPU is a microprocessor for image processing, which is connected to the display screen 394 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 310 can include one or more GPUs, which execute program instructions to generate or change display information.

[0139] The display screen 394 is configured to display images, videos, and the like. For example, the display screen 394 can display a call reminder interface and a voice call interface. In an embodiment of this application, if the electronic device 100 receives an application-in-call request initiated by a peer in a first application, the display screen 394 of the electronic device 100 can display a voice call interface including service information of the first application. The display screen 394 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diodes (QLED), or the like. In some embodiments, the electronic device 100 can include one or N display screens 394, where N is a positive integer greater than 1.

[0140] The electronic device 100 can implement a photographing function through an ISP, a camera 393, a video codec, a GPU, a display screen, and an application processor.

[0141] The ISP is configured to process data fed back by the camera 393. For example, when taking a photo, the shutter is opened, light is transmitted to the camera photosensitive element through the lens, the light signal is converted into an electrical signal, and the camera photosensitive element transmits the electrical signal to the ISP for processing to convert it into an image visible to the naked eye. The ISP can also optimize algorithms for noise, brightness, and skin color of the image. The ISP can also optimize parameters such as exposure and color temperature of the shooting scene. In some embodiments, the ISP can be disposed in the camera 393.

[0142] The camera 393 is used to capture still images or videos. An object projects an optical image through a lens to a photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the optical signal into an electrical signal, which is then passed to an ISP for conversion into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into a standard RGB, YUV, or the like format image signal. In some embodiments, the electronic device 100 can include one or N cameras 393, where N is a positive integer greater than one.

[0143] The digital signal processor is used to process digital signals, in addition to processing digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy, etc.

[0144] The video codec is used to compress or decompress digital video. The electronic device 100 can support one or more video codecs. In this way, the electronic device 100 can play or record videos in multiple encoding formats, such as moving picture experts group (MPEG) 1, MPEG 2, MPEG 3, MPEG 4, etc.

[0145] The NPU is a neural network (NN) computing processor, which learns from the structure of biological neural networks, such as the transmission mode between human brain neurons, and can quickly process input information and continuously self-learn. Through the NPU, the electronic device 100 can realize intelligent cognition applications such as image recognition, face recognition, voice recognition, and text understanding.

[0146] The external memory interface 320 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 310 through the external memory interface 320 to realize data storage functions. For example, music, video, and other files are saved in the external memory card.

[0147] The internal memory 321 can be used to store computer executable program codes including instructions. The processor 310 performs various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 321. The memory 121 can include a program storage area and a data storage area. The program storage area can store an operating system, at least one application program (such as a sound play function, an image play function, etc.) required by a function, etc. The data storage area can store data (such as audio data, a phone book, etc.) created during use of the electronic device 100, etc. In addition, the memory 121 can include a high-speed random access memory, and can further include a non-volatile memory such as at least one magnetic disk storage device, a flash memory device, another volatile solid state memory device, a universal flash storage (UFS), etc.

[0148] The electronic device 100 can implement an audio function through the audio module 370, the speaker 370A, the receiver 370B, the microphone 370C, the earphone interface 370D, and the application processor, etc. For example, music play, recording, etc.

[0149] The audio module 370 is used to convert digital audio information into an analog audio signal output, and is also used to convert an analog audio input into a digital audio signal. The audio module 370 can also be used to encode and decode an audio signal. In some embodiments, the audio module 370 can be disposed in the processor 310, or part of the functions of the audio module 370 can be disposed in the processor 310.

[0150] The speaker 370A, also called a "loudspeaker", is used to convert an audio electrical signal into a sound signal. The electronic device 100 can listen to music or listen to a hands-free call through the speaker 370A.

[0151] The receiver 370B, also called an "earpiece", is used to convert an audio electrical signal into a sound signal. When the electronic device 100 receives a call or a voice message, the user can listen to the voice by holding the receiver 370B close to the ear.

[0152] The microphone 370C, also called a "microphone", "sound transducer", is used to convert a sound signal into an audio electrical signal. When making a call or sending a voice message, the user can make a sound by holding the mouth close to the microphone 370C, and input the sound signal into the microphone 370C. The electronic device 100 can be provided with at least one microphone 370C. In some embodiments, the electronic device 100 can be provided with two microphones 370C, in addition to collecting sound signals, it can also implement a noise reduction function. In some embodiments, the electronic device 100 can also be provided with three, four or more microphones 370C, in addition to collecting sound signals, noise reduction, it can also identify the sound source, implement a directional recording function, etc.

[0153] The earphone interface 370D is used to connect a wired earphone. The earphone interface 370D can be a USB interface 330, or a 3.5 mm open mobile terminal platform (OMTP) standard interface, or a cellular telecommunications industry association of the USA (CTIA) standard interface.

[0154] The keys 390 include a power key, a volume key, and the like. The keys 390 can be mechanical keys. Alternatively, the keys 390 can be touch keys. The electronic device 100 receives a key signal input from the keys 390, and generates a key signal input related to user settings and function control of the electronic device 100.

[0155] The motor 391 can generate a vibration prompt. The motor 391 can be used for incoming call vibration prompts, or for touch vibration feedback. For example, touch operations for different applications (e.g., taking a photo, playing audio, and the like) can correspond to different vibration feedback effects. Touch operations on different regions of the display screen 394 can also correspond to different vibration feedback effects. Different application scenarios (e.g., time reminders, receiving a message, an alarm, a game, and the like) can also correspond to different vibration feedback effects. The touch vibration feedback effects can also be customizable.

[0156] The indicator 392 can be an indicator light, and can be used to indicate a charging state, a power change, or to indicate a message, a missed call, a notification, and the like.

[0157] The SIM card interface 395 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 395 to achieve contact and separation with the electronic device 100. The electronic device 100 can support one or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 395 can support a Nano SIM card, a Micro SIM card, a SIM card, and the like. The same SIM card interface 395 can simultaneously insert multiple cards. The types of the multiple cards can be the same or different. The SIM card interface 395 can be compatible with different types of SIM cards. The SIM card interface 395 can also be compatible with external storage cards. The electronic device 100 interacts with a network through a SIM card to implement functions such as a call and data communication. In some embodiments, the electronic device 100 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the electronic device 100 and cannot be separated from the electronic device 100.

[0158] The software system of electronic device 100 can adopt a layered architecture, event-driven architecture, microkernel architecture, microservice architecture, or cloud architecture. This embodiment of the invention uses the layered architecture Android system as an example to exemplify the software structure of electronic device 100.

[0159] Figure 4B This is a software structure block diagram of the electronic device 100 according to an embodiment of the present invention. The layered architecture divides the software into several layers, each with a clear role and function. Layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom: the application layer, the application framework layer, the Android runtime and system libraries, and the kernel layer.

[0160] The application layer can include a series of application packages.

[0161] like Figure 4B As shown, the application package may include applications such as camera, gallery, calendar, phone (i.e., the "phone" application in this application embodiment), map, navigation, WLAN, Bluetooth, music, video, and SMS.

[0162] The application framework layer provides application programming interfaces (APIs) and a programming framework for applications in the application layer. The application framework layer includes some predefined functions.

[0163] like Figure 4B As shown, the application framework layer may include a window manager, content provider, view system, phone manager, resource manager, notification manager, and risk identification module.

[0164] The risk identification module can interact with other modules in the application framework layer, various applications in the application layer, databases in the system library, and drivers in the kernel layer to implement the risk identification method provided in this embodiment. It should be noted that this embodiment uses the deployment of the risk identification module in the application framework layer as an example. In other embodiments, the risk identification module can be deployed in other layers or implemented by other modules. For example, the function of the risk identification module described in this application embodiment can be implemented by a "telephone" application or as a standalone application. For ease of description of the overall solution, the following embodiments use electronic device 100 as the execution subject for example.

[0165] The window manager is used to manage windows programs. The window manager can get the display screen size, determine whether there is a status bar, lock the screen, and take screenshots, etc. The content provider is used to store and obtain data, and make the data accessible to application programs. The data can include videos, images, audio, dialed and received calls, browsing history and bookmarks, phonebook, etc. The view system includes visual controls, such as controls for displaying text, controls for displaying pictures, etc. The view system can be used to build application programs. The display interface can be composed of one or more views. For example, as shown in FIG. 20, the dial pad interface 20 and the prompt information interface 21 are exemplary. In the dial pad interface 20, the view of the "dialing keypad", the view of the called number, the view of the "dial" icon, and the view of other functional controls can be displayed. Figure 2B

[0166] The phone manager is used to provide the communication function of the electronic device 100. For example, the management of the call state (including connection, hang-up, etc.). The resource manager provides various resources for application programs, such as localized strings, icons, pictures, layout files, video files, etc. The notification manager enables application programs to display notification information in the status bar, which can be used to convey notification type messages that can automatically disappear after a short stay without user interaction. For example, the notification manager is used to notify the completion of downloading, message reminders, etc. The notification manager can also be a notification that appears in the form of a chart or a scroll bar text in the top status bar of the system, such as a notification of an application program running in the background, and can also be a notification that appears in the form of a dialog window on the screen. For example, prompting text information in the status bar, issuing a prompt sound, the electronic device vibrating, the indicator light flashing, etc.

[0167] The Android runtime includes the core library and the virtual machine. The Android runtime is responsible for the scheduling and management of the Android system. The core library contains two parts: one part is the function function that the java language needs to call, and the other part is the core library of Android.

[0168] The application program layer and the application program framework layer run in the virtual machine. The virtual machine executes the java files of the application program layer and the application program framework layer into binary files. The virtual machine is used to perform the management of the object life cycle, the management of the stack, the management of the thread, the management of the security and the exception, and the garbage collection, etc.

[0169] The system library can include multiple functional modules. For example: the surface manager, the media library, the three-dimensional graphics processing library (for example: openGL ES), the 2D graphics engine (for example: SGL), etc.

[0170] ​The Surface Manager manages the display subsystem and provides fusion of 2D and 3D layers for multiple applications. The Media Library supports playback and recording of various common audio and video formats, as well as still image files. The Media Library supports multiple audio and video encoding formats, such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG. The 3D Graphics Processing Library implements 3D graphics drawing, image rendering, compositing, and layer processing. The 2D Graphics Engine is the drawing engine for 2D graphics.

[0171] The kernel layer is the layer between hardware and software. The kernel layer contains at least the display driver, camera driver, audio driver, and sensor driver.

[0172] based on Figure 3 The application environment shown and Figure 4A , Figure 4B The hardware structure and software architecture of the electronic device are shown. Taking the electronic device 100 executing an embodiment of this disclosure as an example, this embodiment of the disclosure provides a risk identification method. See [link to relevant documentation]. Figure 5 The method flow provided in this disclosure includes:

[0173] S501. When the electronic device 100 detects that a specific scene has been triggered, the first information generated by the electronic device 100 is acquired.

[0174] A specific scenario can be understood as a situation where electronic device 100 is temporarily unable to establish a communication connection. For example, a specific scenario may include electronic device 100 being in Do Not Disturb mode, electronic device 100 being set to call forwarding, electronic device 100 being set to reject unknown calls, and electronic device 100 being set to airplane mode. Electronic device 100 can detect whether a specific scenario is triggered by monitoring application processes or the user interface. For example, refer to... Figure 2A Users can set up call forwarding through the call forwarding menu interface 10, and the electronic device 100 can detect whether a call forwarding setting operation has occurred by listening to the user's operations on the interface 10. For example, users can set whether to enable Do Not Disturb mode through the menu settings interface, and the electronic device 100 can detect whether a Do Not Disturb mode activation operation has occurred by listening to the operations on the menu settings interface.

[0175] The first information can be information generated by the electronic device 100 within a preset time period before the first time, where the first time refers to a time when a specific scenario is triggered. For example, the preset time period before the first time can be 5 minutes before the first time, 10 minutes before the first time, or the like. It should be noted that the first information, the number information in the first information, and the environment information in the first information all refer to information generated within a preset time period before the first time, and the present embodiment does not limit this.

[0176] The first information includes information related to a specific environment. For example, the first information includes number information generated in a scenario of setting call forwarding. The first information can also include environment information generated in a scenario of setting call forwarding, do-not-disturb mode, or the like. The environment information can be a telephone call event, an application running event and / or a function running event, an application download event or an application installation event, an application interaction event, or the like. It should be noted that the environment information can be generated in any specific environment, such as setting call forwarding, setting do-not-disturb mode, setting flight mode, setting unknown incoming call rejection, or the like. The number information is generated in a specific environment related to number setting, such as setting call forwarding.

[0177] Optionally, the telephone call event refers to a call application of the electronic device 100 being running at the first time or having been running within a preset time period before the first time. If it is determined that the call application is running, the electronic device 100 acquires a current call number generated by the call application. If it is determined that the call application has been running within a preset time period before the first time, the electronic device 100 acquires a historical call number generated by the call application. The historical call number can be all opposite call numbers within a preset time (e.g., 10 minutes) before the first time.

[0178] Optionally, the application running event and / or the function running event refers to that the application in the electronic device 100 is running or has run, and the function corresponding to the application is running or has run. For example, the application A is running at the first time, or the application A has run within the preset time length before the first time, or the function corresponding to the application A is running at the first time, or the function corresponding to the application A has run within the preset time length before the first time. In this embodiment, the electronic device 100 can determine whether the application is running or whether the electronic device 100 is in a certain function mode by querying the current process. Optionally, the electronic device can also determine whether the application has run or the electronic device 100 has been in a certain function mode within the preset time length before the first time based on the running start time, the running end time and the like of the application or the function. For example, the last running start time of the application A is June 16, 2022, 17:38, the last running end time is June 16, 2022, 17:50, the first time is June 16, 2022, 17:52, and the preset time length before the first time is 30 minutes before the first time. Obviously, the application A has run within 30 minutes before the first time. It should be noted that if a certain application only has a last running start time and does not have a last running end time, it can also be indicated that the application is running. Optionally, the application can run in the foreground, and the application can also run in the background. Optionally, the electronic device 100 can also obtain the application running event and / or the function running event from the log corresponding to each application. Alternatively, the interaction strategy between each application and the risk identification module of the electronic device 100 can also be agreed, and the interaction strategy specifically shows that when the application starts running or ends running, and / or the function of the application is turned on or off, the operation time and the operation type corresponding to the operation are sent to the risk identification module, so that the risk identification module obtains the application running event and / or the function running event based on the information.

[0179] Optionally, the application download event or the application installation event refers to that the application in the electronic device 100 is being downloaded or installed, or the application has completed the download or installation. Optionally, the electronic device 100 can determine whether the application is being downloaded or being installed by querying the current process. Alternatively, the electronic device can determine whether the application is being downloaded or being installed based on the download start time and the end time, and the installation start time and the end time of the application. Alternatively, the electronic device can determine whether the application has completed the download or installation within the preset time length before the first time based on the download start time and the end time, and the installation start time and the end time of the application.

[0180] Optionally, the application interaction event refers to an interaction generated by the risk identification module of the electronic device 100 when the application feeds back information, for example, the application with risk identification and prompting can generate risk prompt information and send it to the risk identification module of the electronic device when a risk operation is identified. The electronic device 100 can detect whether the interaction information with the application is generated in real time, so as to identify the risk operation based on the interaction information.

[0181] Optionally, in a specific scenario of setting call forwarding, the first information can include a call forwarding number, or the first signal can include a local number and a call forwarding number, or the first information can include a first identifier for indicating the local number and the call forwarding number. The first identifier can be an IP address, IMSI, or other identifier that can be associated with the local number. For example, the electronic device 100 can send a call forwarding setting request carrying the first identifier and the call forwarding number to the server, in which case the server can determine the local number of the electronic device 100 based on the first identifier, and set the call forwarding function of the local number in the electronic device 100 based on the local number and the call forwarding number. That is, the first identifier is used to enable the server to determine the number associated therewith. For example, the first information in the setting request sent by the electronic device 100 to the server only contains the call forwarding number, at which time the server can directly extract the identifier corresponding to the electronic device, such as the IP address, when establishing a network layer connection with the electronic device, thereby determining the corresponding local number. Optionally, the first information can also include other information that can provide risk identification for the electronic device 100, which is not limited in the present embodiment.

[0182] S502, the electronic device 100 determines whether there is a risk operation of the electronic device 100 according to the risk identification of the current operation based on the first information.

[0183] According to the different first information obtained, the electronic device 100 performs risk identification of the current operation based on the first information, which includes multiple aspects:

[0184] Aspect 1: In a specific scenario where the electronic device 100 detects a setting call forwarding operation, the first information obtained includes at least a call forwarding number. The electronic device 100 can determine whether the call forwarding number is a safe number, which can be understood as a number in a whitelist preset in the electronic device 100, or a number in the address book of the electronic device 100, or another local SIM card number in the electronic device 100, or a number with the same owner information as the owner information of the local number. If the electronic device 100 determines that the call forwarding number is a safe number based on the above conditions, it is determined that the current operation is not a risky operation; if it is determined that the call forwarding number is not a safe number, it is determined that the current operation is a risky operation. For example, the electronic device 100 can also determine whether the call forwarding number is a risky number, which can include a number in the blacklist of the electronic device 100, or a risky number marked by a third-party risk identification platform, etc. If the electronic device 100 determines that the call forwarding number is a risky number based on the above conditions, it is determined that the current operation is a risky operation; if it is determined that the call forwarding number is not a risky number, it is determined that the current operation is not a risky operation.

[0185] Optionally, the first information can include the call forwarding number, or the local number and the call forwarding number, or the first identifier associated with the local number and the call forwarding number. For the case where the electronic device 100 determines whether the owner information of the call forwarding number is consistent with the owner information of the local number, the electronic device 100 can send an owner information query request carrying the first information to the server, so that the server returns a query response carrying the owner information of the local number and the owner information of the call forwarding number to the electronic device 100 after obtaining the owner information of the local number and the owner information of the call forwarding number based on the first information. The electronic device 100 compares the received owner information of the local number and the owner information of the call forwarding number, and if they are consistent, it is determined that the current operation is not a risky operation; if they are not consistent, it is determined that the current operation is a risky operation. Alternatively, the electronic device 100 can also send a comparison result query request carrying the first information to the server, so that the server returns a query response carrying the comparison result to the electronic device 100 after obtaining the owner information of the local number and the owner information of the call forwarding number based on the first information and comparing them to obtain the comparison result of whether the owner information of the local number and the owner information of the call forwarding number are consistent. If the electronic device 100 determines that the received comparison result indicates that they are consistent, it is determined that the current operation is not a risky operation; if the comparison result indicates that they are not consistent, it is determined that the current operation is a risky operation. Optionally, the electronic device 100 can also make a comprehensive judgment based on the above-mentioned multiple information to determine whether the current operation is a risky operation.

[0186] Aspect two: the electronic device 100 can be in any of the specific scenarios described above, and the first information obtained by the electronic device 100 includes environmental information. The electronic device 100 determines whether the current operation is a risky operation based on the environmental information in step S501.

[0187] Optionally, in one case, the environmental information is a phone call event, and the corresponding risky operation is that the call number is a risky number and / or the call number is not a safe number. The electronic device 100 determines that the phone call event occurs, which means that the call application is running or the call application has been running within a preset time period before the first time. In this case, taking the call application as "phone" as an example, the electronic device 100 can obtain the call number of the "phone" application, for example, if the "phone" application is running, the current call number is obtained; if the "phone" application has been running within a preset time period before the first time, the historical call number is obtained, or the corresponding historical call number is obtained by obtaining the historical call record of the "phone" application to determine whether the historical call has occurred within a preset time period before the first time. The electronic device 100 identifies the risky operation based on the current call number and / or the historical call number, including determining whether the current call number is a safe number, whether it is a risky number, determining whether the historical call number is a safe number, whether it is a risky number, and the specific determination method is the same as the determination of whether the call forwarding number is a safe number or a risky number in aspect one. In the case where the electronic device 100 determines that the historical call number is a safe number, or determines that the historical call number is not a risky number, or determines that the historical call number is both a safe number and not a risky number, it is determined that there is no risky operation. In the case where the electronic device 100 determines that the historical call number is not a safe number, or determines that the historical call number is a risky number, or determines that the historical call number is neither a safe number nor a risky number, it is determined whether the current operation is a risky operation.

[0188] Optionally, the electronic device 100 can also obtain the risk identification result of the call application, for example, the call application has the function of identifying risks based on the call number. After the electronic device 100 determines that the phone call event occurs, the electronic device 100 sends a request to the call application to query whether the historical call number or the current call number is risky. The call application identifies the risks of the call number and returns the identification result to the electronic device 100, so that the electronic device 100 determines whether the call number is risky based on the identification result.

[0189] Optionally, in another case, the environmental information is an application running event and / or a function running event, and the corresponding risk operation refers to the existence of a specific application being running, or the existence of a specific application having been running within a preset time period before the first time, or the existence of a specific function of a specific application being running, or the existence of a specific function of a specific application having been running within a preset time period before the first time. Here, the specific application can be an application having a screen sharing or remote control mode, and the corresponding specific function can be the screen sharing or remote control mode being turned on. Alternatively, the specific application can also be a payment application, and the corresponding specific function can be a payment or transfer activity being performed. Alternatively, the specific function can also be a function mode of the electronic device, for example, the electronic device being in a system do-not-disturb mode, a system shared desktop mode, or a system remote control mode.

[0190] The electronic device 100 can determine whether there is a specific application and / or function running event by querying the current process. For example, the electronic device 100 determines that the electronic device is in a sharing mode by a specific application A having a sharing function by querying the current process, and then determines that the current operation has a risk operation. For another example, the electronic device 100 determines that a specific application B having a payment function is running by querying the current process, and then determines that the current operation has a risk operation. Alternatively, the electronic device 100 can also determine whether a specific application has been running within a preset time period before the first time according to a running start time and a running end time of the specific application, and if it is determined that the specific application has been running within the preset time period before the first time, it is determined that the current operation has a risk operation.

[0191] Optionally, in another case, the environmental information is an application running event and / or a function running event, and the corresponding risk operation refers to the existence of a specific application being running, or the existence of a specific application having been running within a preset time period before the first time, or the existence of a specific function of a specific application being running, or the existence of a specific function of a specific application having been running within a preset time period before the first time. Here, the specific application can be an application having a screen sharing or remote control mode, and the corresponding specific function can be the screen sharing or remote control mode being turned on. Alternatively, the specific application can also be a payment application, and the corresponding specific function can be a payment or transfer activity being performed. Alternatively, the specific function can also be a function mode of the electronic device, for example, the electronic device being in a system do-not-disturb mode, a system shared desktop mode, or a system remote control mode.

[0192] Optionally, in yet another case, the environmental information is an application interaction event, and the corresponding risk operation refers to receiving a risk prompt message sent by a specific application. Here, the specific application can be an application with risk identification and risk prompt, for example, some payment applications generally have risk identification of payment environment to ensure the safety of payment operation. If the payment application detects a risk in its payment environment, it sends a risk prompt message to the risk identification module. For another example, some communication applications (such as telephone, short message, instant messaging software, etc.) send a risk prompt message to the risk identification module when detecting that the user uses the electronic device to communicate with a risk number or account. For another example, some security management applications (such as mobile phone guardian, etc.) send a risk prompt message to the risk identification module when detecting that there is a specific risk behavior on the electronic device. If the risk identification module of the electronic device 100 receives the risk prompt information sent by these specific applications at the first time or within a preset time period before the first time, it is determined that the current operation has a risk operation.

[0193] It should be noted that the premise of the interaction between the specific application and the risk identification module of the electronic device 100 is that the interaction strategy between the risk identification module of the electronic device 100 and the specific application has been clearly defined. For example, after the specific application determines that there is a risk operation and generates a risk prompt message, it will feed back the risk prompt message to the risk identification module based on the interaction strategy, so that the risk identification module performs a risk identification operation based on the risk prompt message. The specific interaction strategy can be determined according to actual conditions, and this embodiment does not limit it.

[0194] Aspect three: The electronic device 100 performs corresponding risk identification according to the number information and the environmental information in the first information in the manner provided in aspects one and two, to determine whether there is a risk operation in the current environment. Optionally, the manner in which the electronic device 100 performs risk identification based on different contents of the first information is not limited to one. The electronic device 100 can combine different risk identification manners, perform risk identification on the current environment according to a certain execution order or execution logic, and determine that there is a risk operation in the current environment if at least one of the multiple risk identification manners indicates that there is a risk operation in the current environment. If none of the multiple risk identification manners indicates that there is a risk operation in the current environment, it is determined that there is no risk operation in the current environment. It should be noted that the execution logic of the multiple risk identification manners is not limited in this embodiment. For example, the multiple risk identification manners can be executed simultaneously; some can be executed simultaneously, some can be executed sequentially, and all can be executed sequentially. The execution order is determined according to actual conditions, and this embodiment does not limit it.

[0195] S503, in the case where it is determined that the electronic device 100 has a risk operation, outputting risk warning information.

[0196] In this embodiment, the electronic device 100 can output the risk warning information in various manners in the case that it is determined based on the first information that the current environment exists a risk operation.

[0197] Alternatively, the electronic device 100 can display the risk warning information in the current interaction interface. For example, in the specific scenario of setting the call transfer function through dialing, the electronic device detects that the setting of the call transfer function is triggered, and the electronic device 100 determines that the call transfer number is a risk number based on the local number and the call transfer number 137******** in the first information, and the owner information of the local number and the owner information of the call transfer number obtained from the server. The electronic device can display the risk warning information interface 22 based on the current interface 20. It can be referred to Figure 6 As shown, the risk warning information interface 22 includes the risk warning information that the call transfer number 137******** is a risk number. Alternatively, the risk warning information interface 22 can also include the re-determination content that please determine whether to continue to set the call transfer. In the case that the electronic device 100 detects that the user triggers the “cancel” control based on the risk warning information interface 22, the electronic device 100 cancels the operation of setting the call transfer. Alternatively, the user can also choose to continue to set the call transfer. In the case that the electronic device 100 detects that the user triggers the “confirm” control based on the risk warning information interface 22, the electronic device 100 continues to execute the operation of setting the call transfer.

[0198] For another example, in the scenario of setting the do-not-disturb mode, the electronic device 100 detects that the setting of the do-not-disturb mode is triggered, and obtains the first information. In this scenario, the electronic device 100 can determine based on the environment information in the first information that the current environment exists a risk operation, and can display the risk warning information interface in the current interface. Here, the risk warning information interface can include the content of reminding and performing secondary determination that the current operation exists a risk, please determine whether to continue. Similarly, the risk warning information interface can also include the “confirm” and “cancel” controls for triggering the user to perform the determination operation and the cancel operation. If the electronic device 100 detects that the “cancel” control is triggered, the setting of the do-not-disturb mode is cancelled. If the electronic device 100 detects that the “confirm” control is triggered, the operation of setting the do-not-disturb mode is continued. It should be noted that the user can also directly perform the secondary determination or the cancel operation through the voice input manner. The specific implementation manner of the user to perform the secondary determination and the cancel operation is not limited in this embodiment.

[0199] Optionally, the electronic device 100 can also output the risk warning information in other manners, for example, outputting a risk warning audio through an audio output device such as a speaker, earpiece, etc. in the electronic device 100. The risk warning audio can be a beep sound, an alarm sound, or an audio including voice content. For example, in the specific scenario of setting a call forwarding function, if the electronic device 100 determines that the call forwarding number is a risk number, the electronic device 100 outputs a risk warning audio, and the voice content of the audio can include “call forwarding number 137******** is a risk number, please determine whether to continue setting call forwarding”. Further, the electronic device 100 can also output a prompt interface including confirm and cancel on the current interface for the user to determine again. After the user selects confirm or cancel, the risk warning audio prompt is removed, and corresponding operations are performed based on the operation triggered by the user. In other specific scenarios, the risk warning audio is output through the audio output device, which is similar to the present embodiment and will not be described here.

[0200] Optionally, the other manners can also include that the electronic device 100 triggers an identity verification operation and outputs the risk warning information through a voice or a display interface. For example, the identity verification operation can include performing face recognition based on the current interface of the electronic device, matching the collected face features with the existing face features in the electronic device 100, and outputting the risk warning information through a voice or a display interface if the matching is passed. Further, the electronic device 100 can also output a prompt interface including confirm and cancel on the current interface for the user to determine again. After the user selects confirm or cancel, the risk warning audio prompt is removed, and corresponding operations are performed based on the operation triggered by the user. If the electronic device 100 determines that the face feature matching fails, it means that the electronic device 100 can be in a lost state. At this time, the electronic device 100 can execute a lock screen operation based on the current display interface to forcibly terminate the user's setting operation in the specific scenario.

[0201] Optionally, during the above-mentioned user determination process, if the electronic device 100 detects that the user triggers a cancel operation, the electronic device 100 can further output information that the setting of the specific scenario fails on the current interface. For example, in the specific scenario of setting a call forwarding function, if the electronic device 100 detects that the user triggers a cancel operation, it can output information that the setting of the call forwarding function fails on the current interface. In the specific scenario of setting a do-not-disturb mode, if the electronic device 100 detects that the user triggers a cancel operation, it can output information that the setting of the do-not-disturb mode fails on the current interface. The present embodiment does not limit this.

[0202] In combination with the above-mentioned embodiments, optionally, after the electronic device 100 outputs the risk warning information, the electronic device 100 can further execute the following steps:

[0203] S504, when the electronic device 100 detects the cancel operation, output a prompt message indicating that the setting fails.

[0204] Alternatively, the user can perform the cancel operation by triggering the cancel control in the interactive interface, the user can also perform the cancel operation by inputting "cancel" through voice, or the user can also perform the cancel operation by double-clicking or other specified operations on the specified keys such as the "home" key, the volume key, etc., which are not limited in the embodiment. When the electronic device 100 detects the cancel operation, the electronic device 100 performs the operation of terminating the current setting operation of the specific scenario at the same time of outputting the prompt message indicating that the setting fails, or after outputting the prompt message indicating that the setting fails, or before outputting the prompt message indicating that the setting fails. For example, if the current operation is setting call forwarding, the electronic device 100 terminates the operation of sending the call forwarding request to the server 101; for another example, if the current operation is setting the do-not-disturb mode, the electronic device 100 terminates the operation of setting the system to the do-not-disturb mode, i.e., the electronic device 100 prohibits the do-not-disturb mode from being turned on.

[0205] S505, when the electronic device 100 detects the determination operation, output a prompt message indicating that the setting succeeds.

[0206] Correspondingly, the user can perform the secondary determination operation by triggering the determination control in the interactive interface, the user can also perform the secondary determination operation by inputting "determination" or "confirmation" or "continue" or the like through voice, or the user can also perform the secondary determination operation by double-clicking or other specified operations on the specified keys such as the "home" key, the volume key, etc., which are not limited in the embodiment. When the electronic device 100 detects the determination operation, the electronic device 100 continues to perform the setting operation of the current specific scenario before outputting the prompt message indicating that the setting succeeds. For example, if the current operation is setting call forwarding, the electronic device 100 continues to perform the operation of sending the call forwarding request to the server 101 to complete the call forwarding operation; for another example, if the current operation is setting the do-not-disturb mode, the electronic device 100 performs the operation of turning on the do-not-disturb mode.

[0207] Alternatively, after the specific scenario is successfully set, the electronic device can also continue to perform risk identification. In an optional embodiment, after the specific scenario is successfully set or within a preset time period after the successful setting, if the electronic device determines that there is a risk operation based on the risk identification method, output a prompt message for reminding the user to cancel the corresponding specific scenario setting.

[0208] Optionally, the electronic device can output a reminder information at the current interface, such as, within 10 minutes after the user sets the call transfer function, the electronic device detects the existence of a risky operation, and then outputs the reminder information, which is "the current scene exists a risky operation, please cancel the setting of the call transfer function". Optionally, the electronic device can also output the reminder information by playing a voice, for example, playing the voice reminder information "the current scene exists a risky operation, please cancel the setting of the call transfer function".

[0209] This is considering that in actual situation, some risky operations may also occur after setting a specific scene, based on this situation, after the specific scene is successfully set, the electronic device still detects whether there is a risky operation, which can further improve the device security of the electronic device and avoid being exploited by fraudsters. It can be understood that the risk identification method of the electronic device after the specific scene is successfully set can refer to the above embodiments, which will not be repeated here.

[0210] In the risk identification method provided in the above embodiments, when the electronic device 100 detects that a certain specific scene is triggered, the electronic device 100 can obtain first information generated in the specific scene, and the first information includes environment information or number information corresponding to the specific scene, so that the electronic device 100 can determine whether there is a risky operation in the current environment based on the first information, and output a risk warning information in a timely manner in the case of determining that there is a risky operation, and stop the setting operation of the specific scene, which realizes the effective identification and risk warning of the risky operation in the specific scene, provides an effective risk prompt for the user, and reduces the probability of the user executing the risky operation to a certain extent, and enhances the information security and property safety of the user. At the same time, the progress of the risky operation is prevented, the occurrence of the risky operation is avoided, and the situation that the electronic device used by the user is exploited by a specific user is also avoided to a certain extent, and the problem that the specific user exploits the electronic device used by the user to hinder or interfere with the warning work of the staff is avoided.

[0211] In some embodiments, in combination with Figure 5 The scheme provided in the embodiments provides an implementation of the risk identification method in the case where the first information includes number information:

[0212] In this embodiment, the electronic device 100 can perform risk identification on the target number in the number information according to a preset identification method, and the preset identification method can include identification and judgment of two dimensions, i.e., whether the target number is a safe number or whether the target number is a risky number. Here, the safe number refers to a number that does not have a harassment label or a risk label in the conventional sense, or a self-defined white list number, or a number with the same owner as the user number, etc.; the risky number refers to a number labeled as risky by the user or the risk identification platform, or a number in the preset blacklist, etc.

[0213] Exemplarily, in the specific scenario of setting the call transfer, the target number is a call transfer number.

[0214] The following is described from the dimensions of whether the electronic device 100 judges the target number to be a safe number and whether the target number is a risky number, respectively.

[0215] Dimension one: in one feasible solution of the embodiment, the electronic device 100 judges whether the target number is a safe number, including the following methods:

[0216] Method one: the electronic device 100 judges whether the target number is a local SIM card number.

[0217] Exemplarily, the electronic device 100 can directly judge whether the target number is a local number, the electronic device 100 can obtain the local SIM card number information, if the target number is consistent with any one of the local SIM card number information, it is considered that the target number is a safe number; if the target number is not consistent with all the numbers in the local SIM card number information, it is considered that the target number is not a safe number.

[0218] Method two: the electronic device 100 judges whether the target number is in the local address book.

[0219] In the embodiment, the electronic device 100 can obtain the local address book information from the local register, or the electronic device 100 can interact with the "phone" application to obtain the local address book information. Optionally, the local address book information includes at least one known number annotated with a name.

[0220] Exemplarily, after the electronic device 100 obtains the target number, the electronic device 100 can match the target number with all the known numbers in the local address book, if the matching is successful, that is, there is a known number consistent with the target number in the local address book, it is considered that the target number is a safe number; if the matching fails, that is, there is no known number consistent with the target number in the local address book, the target number is not a safe number.

[0221] Method three: the electronic device 100 judges whether the target number is in the white list.

[0222] Among them, the white list can be understood as a list of numbers with high security pre-stored in the electronic device 100, after the electronic device 100 obtains the target number, the electronic device 100 matches the target number with the numbers in the white list, if the matching is successful, that is, there is a number consistent with the target number in the white list, it is considered that the target number is a safe number; if the matching fails, that is, there is no number consistent with the target number in the white list, it is considered that the target number is not a safe number.

[0223] Alternatively, the white list can also be a number list obtained by the electronic device 100 from a third-party platform. After obtaining the target number, the electronic device 100 obtains the white list from the third-party platform, and after obtaining the white list, matches the target number with the numbers in the white list. If the matching is successful, that is, there is a number consistent with the target number in the white list, it is considered that the target number is a safe number. If the matching fails, that is, there is no number consistent with the target number in the white list, it is considered that the target number is not a safe number.

[0224] Method four: The electronic device 100 judges whether the owner information of the target number is the same as the owner information of the local number.

[0225] Exemplarily, the electronic device 100 can send a query request carrying the target number to the server 102 to receive the response carrying the owner information of the target number returned by the server 102, and determine whether the owner information of the target number and the owner information of the local number are consistent based on the received owner information of the target number and the owner information of the local number. For example, the owner information includes the name of the number user with unique identity, user identity card information and other information. If at least one item of information with unique identity in the owner information is consistent, it is considered that the owner information of the target number is the same as the owner information of the local number, and the target number is a safe number. If any one of the owner information is inconsistent, it is considered that the owner information of the target number is not the same as the owner information of the local number, and the target number is not a safe number. It should be noted that the owner information of the local number can be stored locally by the electronic device, or can be obtained by querying the server. The latter mode can directly carry the local number or a first identifier indicating the local number in the query request, or the server can obtain the first identifier when establishing a network layer connection with the electronic device. The present application does not limit this.

[0226] Alternatively, the electronic device 100 can also send a query request carrying a first identifier indicating the local number and the target number to the server 102, request the server 102 to determine the local number based on the first identifier, and match the owner information based on the local number and the target number. To receive the response carrying the owner information matching result returned by the server 102. If the received owner information matching result is matching success, it is considered that the owner information of the target number is the same as the owner information of the local number, and the target number is a safe number. If the received owner information matching result is matching failure, it is considered that the owner information of the target number is not the same as the owner information of the local number, and the target number is not a safe number.

[0227] It can be understood that the electronic device 100 executes the above four methods from the dimension of judging whether the target number is a safe number, and the electronic device 100 can execute the four methods in combination, and the execution order and execution logic of the methods are not limited and can be determined according to actual conditions. In the embodiment, a method for determining whether the target number is a safe number by combining the four methods is given, as shown in Figure 7 The method comprises the following steps:

[0228] S701, the electronic device 100 acquires a target number.

[0229] S702, the electronic device 100 judges whether the target number is a local SIM card number; if yes, S706 is executed; if not, S703 is executed.

[0230] Exemplarily, the above method one is used to judge whether the target number is a local SIM card number.

[0231] S703, the electronic device 100 judges whether the target number is in a local address book; if yes, S706 is executed; if not, S704 is executed.

[0232] Exemplarily, the above method two is used to judge whether the target number is in the local address book.

[0233] S704, the electronic device 100 judges whether the target number is in a white list; if yes, S706 is executed; if not, S705 is executed.

[0234] Exemplarily, the above method three is used to judge whether the target number is in the white list.

[0235] S705, the electronic device 100 judges whether the owner information of the target number is the same as the owner information of the local number; if yes, S706 is executed; if not, S707 is executed.

[0236] Exemplarily, the above method four is used to judge whether the owner information of the target number is the same as the owner information of the local number.

[0237] S706, it is determined that the target number is a safe number.

[0238] S707, it is determined that the target number is not a safe number.

[0239] In the embodiment, the electronic device 100 first determines whether the target number is the local SIM card number. If the target number is not the local SIM card number, the electronic device 100 does not determine whether the target number is a safe number. In consideration of the case that the electronic device 100 is lost and the SIM card slot is inserted with an unknown number, if the target number is the local SIM card number, the target number can also not be a safe number, or the electronic device can not have multiple SIM cards, or the SIM card corresponding to the call forwarding number set by the user can be inserted into other devices, and the like. Therefore, the electronic device 100 can further determine the target number according to the local address book and the white list. If the target number is not in the local address book, the electronic device can continue to determine whether the target number is in the white list. If the target number is not in the white list, the electronic device performs the determination of the owner information of the target number. If the owner information is determined to be the same, the target number is determined to be a safe number. Otherwise, the target number is not a safe number. If the target number is in the local address book or the target number is in the white list, the target number is determined to be a safe number.

[0240] Through the determination of the execution sequence and the execution logic, the effectiveness and the accuracy of the identification of the safe number based on the target number can be further improved.

[0241] It should be noted that, Figure 7 The execution sequence and the execution logic of the different determination methods in the embodiments are examples, and the execution sequence and the execution logic of each method are not limited in the actual identification process.

[0242] Dimension two: In one feasible solution of the embodiment, the electronic device 100 determines whether the target number is a risk number, including the following methods.

[0243] Method five: The electronic device 100 determines whether the target number is in the black list.

[0244] The black list can be understood as a list of harassment numbers with risk or harassment in the electronic device 100. After the electronic device 100 obtains the target number, the electronic device 100 matches the target number with the harassment numbers in the black list. If the matching is successful, that is, there is a harassment number consistent with the target number in the black list, the target number is determined to be a risk number. If the matching fails, that is, there is no harassment number consistent with the target number in the black list, the target number is determined to be not a risk number.

[0245] Alternatively, the blacklist can also be a risk number list obtained by the electronic device 100 from a third-party platform. After obtaining the target number, the electronic device 100 obtains the blacklist from the third-party platform, and after obtaining the blacklist, matches the target number with the risk numbers in the blacklist. If the matching is successful, that is, there is a risk number consistent with the target number in the blacklist, it is considered that the target number is a risk number. If the matching fails, that is, there is no risk number consistent with the target number in the blacklist, it is considered that the target number is not a risk number.

[0246] Method six: The electronic device 100 judges whether the target number is marked as a risk.

[0247] Exemplarily, the electronic device 100 can send a query request information carrying the target number to the server 102 or a third-party risk identification platform, to receive the response information returned by the server 102 or the third-party risk identification platform, which carries whether the target number is marked as a risk. Based on the received response information, it is determined whether the target number is a number marked as a risk. If so, it is considered that the target number is a risk number. If it is determined that the target number is not marked as a risk, it is considered that the target number is not a risk number.

[0248] It can be understood that the electronic device 100 executes the above-mentioned method five and / or method six from the dimension of judging whether the target number is a risk number. The electronic device 100 can execute method five or method six, or can execute method five and method six in combination. The execution order and execution logic of these methods are not limited, and can be determined according to actual conditions.

[0249] In combination with the method for determining whether the target number is a risk number given in the above-mentioned embodiments, reference is made to FIG. 8, which shows an implementation method for determining whether the target number is a risk number in combination with multiple methods, including: Figure 8

[0250] S801, the electronic device 100 obtains a target number.

[0251] S802, the electronic device 100 judges whether the target number is in a blacklist. If so, S805 is executed. If not, S803 is executed.

[0252] Exemplarily, the above-mentioned method five is used to judge whether the target number is in the blacklist.

[0253] S803, the electronic device 100 judges whether the target number is marked as a risk. If so, S805 is executed. If not, S804 is executed.

[0254] Exemplarily, the above-mentioned method six is used to judge whether the target number is marked as a risk.

[0255] S804, it is determined that the target number is not a risk number.​

[0256] S805, determine that the target number is a risk number.

[0257] In this embodiment, the electronic device 100 first determines whether the target number is in the blacklist. If the target number is in the blacklist, it means that the target number is a risk number. If the target number is not in the blacklist, in order to further determine the security of the target number, the electronic device 100 can determine whether the target number is marked as a risk. If the target number is marked as a risk, it is determined that the target number is a risk number. If the target number is not marked as a risk, it means that the target number is not a risk number.

[0258] Through the above execution sequence and execution logic determination, the effectiveness and accuracy of risk number identification based on the target number can be further improved.

[0259] It should be noted that, Figure 8 The execution sequence and execution logic of different determination methods involved in the embodiments are examples, and the execution sequence and execution logic of each method in the actual identification process are not limited.

[0260] In one feasible solution of this embodiment, the electronic device 100 can determine the security of the target number in combination with the above two dimensions of determining whether the target number is a safe number and determining whether the target number is a risk number.

[0261] For example, the electronic device 100 can determine whether the target number is a safe number based on one or more of the above methods 1 to 4, for example, the electronic device 100 can determine whether the target number is a safe number based on the above method 1. Figure 7 If the target number is a safe number, it is determined that there is no risk operation in the current environment. If the target number is not a safe number, the electronic device 100 determines whether the target number is a risk number based on one or more of the above methods 5 and 6. If the target number is not a risk number, it is determined that there is no risk operation in the current environment. If the target number is a risk number, it is determined that there is a risk operation in the current environment.

[0262] For example, the electronic device 100 can determine whether the target number is a risk number based on one or more of the above methods 5 and 6, for example, the electronic device 100 can determine whether the target number is a risk number based on the above method 5. Figure 8In the embodiments provided, the target number is determined to be a risk number, and if the target number is a risk number, it is determined that the current environment has a risk operation, and if the target number is not a risk number, the electronic device 100 can determine whether the target number is a safe number based on one or more of the above methods one to four, and if the target number is a safe number, it is determined that the current environment does not have a risk operation, and if the target number is not a safe number, it is determined that the current environment has a risk operation.

[0263] Alternatively, the electronic device 100 can determine whether the target number is a safe number based on one or more of the above methods one to four, for example, the electronic device 100 can determine whether the target number is a safe number based on Figure 7 In the embodiments provided, the target number is determined to be a risk number, and if the target number is a risk number, it is determined that the current environment has a risk operation, and if the target number is not a risk number, the electronic device 100 can determine whether the target number is a safe number based on one or more of the above methods one to four, and if the target number is a safe number, it is determined that the current environment does not have a risk operation, and if the target number is not a safe number, it is determined that the current environment has a risk operation. Figure 8 In the embodiments provided, the target number is determined to be a risk number, and if the target number is a risk number, it is determined that the current environment has a risk operation, and if the target number is not a risk number, the electronic device 100 can determine whether the target number is a safe number based on one or more of the above methods one to four, and if the target number is a safe number, it is determined that the current environment does not have a risk operation, and if the target number is not a safe number, it is determined that the current environment has a risk operation.

[0264] In the risk identification method provided in this embodiment, the technical solution of determining whether the current environment has a risk operation based on the target number in the first information can be applied to a specific scenario in which the electronic device 100 is set to call forwarding or other specific scenarios involving number information. In this embodiment, in the specific scenario involving number information, the target number is directly obtainable information, and the acquisition method is relatively convenient. The electronic device 100 can effectively and quickly determine whether the operation in the current environment has a risk based on the obtained target number, thereby providing a risk reminder in the case where it is determined that the current environment has a risk operation, enhancing the information security of the user, and optimizing the user experience.

[0265] In other embodiments, in combination with Figure 5 The embodiments provided provide another implementation manner of the risk identification method. In a scenario where the first information includes environment information, the risk identification method includes:

[0266] The electronic device 100 acquires environment information, and determines whether there is a risk operation within a preset time period before a first time according to the environment information; wherein the first time is the time when the user sets the operation of the specific scenario.

[0267] Alternatively, the time period before the first time can be 5 minutes, 10 minutes, 30 minutes, etc. before the time of the operation of the specific scenario.

[0268] Optionally, the environment information can include different events generated on the electronic device at the time of the current operation or within a preset time before the current operation. For example, the environment information can be a telephone call event, an application and / or function running event, an application downloading or installing event, a terminal and application interaction event, etc. The electronic device 100 determines whether there is a risk operation at the first time or within a preset time before the first time based on the environment information, and the following embodiments specifically describe how to identify and determine the risk operation.

[0269] Based on different environment information, the determination of whether the electronic device 100 has a risk operation includes the following methods:

[0270] Method seven: if the environment information is an application running event and / or a function running event, the electronic device 100 determines whether the current environment has a risk operation according to whether a specific application and / or a specific function corresponding thereto is running.

[0271] The specific application can be an application with a screen sharing or remote control mode, and the corresponding specific function can be the screen sharing or remote control mode being turned on. For example, the specific application can also be a payment application, and the corresponding specific function can be a payment or transfer activity being performed. Optionally, a specific application list can be pre-set in the electronic device 100. The electronic device 100 can determine whether a specific application is running based on the specific application list by querying the current process, and accordingly, the electronic device 100 can also determine whether the electronic device 100 is in a specific function mode of the specific application by querying the current process. Optionally, the electronic device 100 can also determine whether the specific application is running or whether the specific application has run within a preset time before the first time based on the running start time and / or the running end time of the specific application. It should be noted that the running end time of the application is recorded when the application ends running, and if there is no running end time, it means that the application should be running.

[0272] For example, if the electronic device 100 determines that the specific application A is running by querying the current process, it is determined that the current operation is a risky operation. Alternatively, if the electronic device 100 determines that the electronic device 100 is in a specific function mode of the specific application A by querying the current process, it is determined that the current operation is a risky operation. Alternatively, if the electronic device 100 determines that the specific application A has no last running end time, and then determines that the specific application A is running, it is determined that the current environment is a risky operation. Alternatively, if the electronic device 100 determines that the last start running time of the specific application A is 17:38 on June 16, 2022, the last running start time is 17:50 on June 16, 2022, and the electronic device 100 detects that the first time is 17:52 on June 16, 2022, and the preset time period before the first time is 30 minutes, it is obvious that the specific application A has run within 30 minutes before the first time. In this case, it is determined that the current operation is a risky operation. If the electronic device determines that the last start running time of the specific application A is 10:38 on June 16, 2022, the last running start time is 11:50 on June 16, 2022, and it is obvious that the specific application A has not run within 30 minutes before the first time. It is determined that the current operation is not a risky operation.

[0273] It should be understood that the above embodiments are exemplified by 1 specific application. If there are multiple specific applications, the judgment is based on the logical or principle, that is, if it is determined that at least one specific application is running or has run within the first time or the preset time period before the first time, it is determined that the current operation is a risky operation. If it is determined that none of the specific applications is running and none of the specific applications has run within the first time or the preset time period before the first time, it is determined that the current operation is not a risky operation.

[0274] Optionally, the specific function can also include a system function mode of the electronic device 100, such as a working mode, a do-not-disturb mode, a remote control mode, a desktop sharing mode, a flight mode, a mute mode, a conference mode, and the like of the electronic device 100. Here, the specific function refers to a mode that can have information leakage, no-call risk, and has remote control and communication functions. For example, if the electronic device 100 queries the current process and determines that the remote control mode has been started within a preset time period before the first time, it is determined that the current operation has a risk operation. Alternatively, the electronic device 100 can also determine whether there is a risk operation based on the execution time of the specific function. For example, if the start time of the remote control mode is June 16, 2022, 17:38, and there is no end time, it means that the remote control mode is still in progress, and this case can also be determined as a risk operation. If the start time of the remote control mode is June 13, 2022, 10:38, the end time is June 13, 2022, 11:50, and the first time is June 16, 2022, 17:40, and the risk operation is detected within 30 minutes before the first time. Obviously, although the remote control mode has been started, the start time is not within 30 minutes before the specific scenario is triggered, and in this case, it is determined that the current operation does not have a risk operation.

[0275] In this embodiment, especially for specific applications with payment functions, these applications with payment functions are generally deployed with a payment software development kit (Software Development Kit, SDK). Optionally, the electronic device 100 can also determine whether the payment SDK of each application is called according to the running log of each application. If the payment SDK is called within the first time or a preset time period before the first time, it is determined that the current operation has a risk operation. Here, the risk identification module of the electronic device 100 can obtain the running log of each application from the register of each application. The running log mainly records the running data of each application itself, for example, what information the application obtains at what time, what information the application generates at what time, and the like.

[0276] Method eight: If the environmental information is an application download event or an application installation event, the electronic device 100 determines whether there is a risk operation according to whether a risk application is downloaded or whether a risk application is installed.

[0277] The risk application can be an application with a risk label, a list of applications with a risk label can be pre-set in the electronic device 100, the electronic device 100 can also obtain the list of applications with a risk label from a third-party risk identification platform in real time, or the electronic device 100 can also obtain the risk query result of the application from the third-party risk identification platform in real time, and determine whether the queried application is a risk application according to the risk query result. The electronic device 100 can determine whether an application is being downloaded or installed by querying the current process or by interacting with a specific application (such as an installer application, an application market, or other applications with application distribution functions), and if there is an application being downloaded or installed, it is determined whether the application is a risk application, and if it is determined to be a risk application, it is determined that the current operation is a risky operation. Alternatively, the electronic device 100 can also determine whether there is a download or installation behavior within a preset time period before the first time by querying the process log and the like, and if there is a download or installation behavior, it is determined whether the application is a risk application, and if it is determined that the application is a risk application, it is determined that the current operation is a risky operation. Alternatively, the electronic device 100 can also determine whether there is a download or installation behavior of an application within a preset time period before the first time according to the download start time, the download completion time, the installation start time, and the installation completion time of each application. For example, the first time is June 16, 2022, 17:50, the preset time period before the first time is 30 minutes before the first time, the download start time of the application C is June 16, 2022, 17:38, and the electronic device 100 determines that the application C has a download behavior within 30 minutes before the first time. The risk application identification of the application C is performed, if the application C is in the list of applications with a risk label set in the electronic device 100, or the application C is in the list of applications with a risk label obtained from the third-party risk identification platform, or the electronic device 100 obtains the risk query result of the application C from the third-party risk identification platform, and the result shows that the application C is a risk application, in these cases, it is determined that the current operation is a risky operation.

[0278] It should be understood that the above embodiments are exemplified by the existence of a download behavior of one risk application, if it is determined that there are multiple application download or installation behaviors within the first time or the preset time period before the first time, the risk application identification of the multiple applications is performed based on the logical or principle, if there is at least one application that is a risk application, it is determined that the current operation is a risky operation; if all downloaded or installed applications are not risk applications, it is determined that the current environment does not have a risky operation.

[0279] Method nine: if the environment information is a telephone call event, the electronic device 100 determines whether there is a risky operation according to the call number of the telephone call event.

[0280] In this embodiment, if the electronic device 100 determines that the call application is running, the current call number is obtained, the current call number is identified based on the above-mentioned method two, method three, method five and method six, if it is determined that the current call number is a safe number, and / or, it is determined that the current call number is not a risk number, it is determined that the current operation does not exist risk operation; if it is determined that the current call number is not a safe number, and / or, it is determined that the current call number is a risk number, it is determined that the current operation exists risk operation. If the electronic device 100 determines that the call application has run within the preset time period before the first time, the historical call numbers within the preset time period before the first time are obtained, and the historical call numbers are identified one by one based on the above-mentioned method two, method three, method five and method six, if it is determined that all historical call numbers are safe numbers, and / or, it is determined that all historical call numbers are not risk numbers, it is determined that the current operation does not exist risk operation; if it is determined that at least one historical call number is not a safe number, and / or, it is determined that at least one historical call number is a risk number, it is determined that the current operation exists risk operation.

[0281] Method ten: the environmental information is an application interaction event, and the electronic device 100 determines whether the current operation exists risk operation based on specific application interaction information.

[0282] In this embodiment, the specific application can be an application with risk identification and risk prompt, and after the specific application determines that there is a risk operation and generates risk prompt information based on user operation, the specific application feeds back the risk prompt information to the risk identification module based on the interaction strategy. For example, if the risk identification module of the electronic device 100 determines the first time, or receives the risk prompt information sent by the specific application within the preset time period before the first time, it is determined that the current operation exists risk operation; if the risk identification module of the electronic device 100 does not receive the risk prompt information at the first time and within the preset time period before the first time, it is determined that there is no risk operation in the current operation.

[0283] In combination with the above-mentioned method seven to method ten based on environmental information to determine whether the current operation is a risk operation, as shown in Figure 9 An implementation method for determining whether there is a risk operation by combining multiple ways is given, including:

[0284] S901, the electronic device 100 obtains environmental information.

[0285] S902, the electronic device 100 determines that a specific application is running or has run within a period of time before a specific scene is triggered; if yes, execute S909; if no, execute S903.

[0286] Exemplarily, the method seven above can be used to determine that the specific application is running or has been running for a period of time before the specific scenario is detected to be triggered.

[0287] S903, the electronic device 100 determines whether the call application is running or has been running for a period of time before the specific scenario is detected to be triggered, if yes, S904 is executed; if no, S905 is executed.

[0288] S904, the electronic device 100 determines whether the current call number or the historical call number is a safe number based on the call information generated by the call application; if yes, S905 is executed; if no, S909 is executed.

[0289] Exemplarily, the method nine above can be used to determine whether the current call number or the historical call number is a safe number.

[0290] S905, the electronic device 100 determines whether the risk application is being downloaded or installed, or has been downloaded or installed for a period of time before the specific scenario is detected to be triggered; if yes, S909 is executed; if no, S906 is executed.

[0291] Exemplarily, the method eight above can be used to determine whether the risk application is being downloaded or installed, or has been downloaded or installed for a period of time before the specific scenario is detected to be triggered.

[0292] S906, the electronic device 100 determines whether the risk mode is turned on at the current time or a period of time before the specific scenario is detected to be triggered; if yes, S909 is executed; if no, S907 is executed.

[0293] Exemplarily, the method seven above can be used to determine whether the risk mode is turned on at the current time or a period of time before the specific scenario is detected to be triggered.

[0294] S907, the electronic device 100 determines whether the risk reminder information of the specific application is received at the current time or a period of time before the specific scenario is detected to be triggered; if yes, S909 is executed; if no, S908 is executed.

[0295] Exemplarily, the method ten above can be used to determine whether the risk reminder information is received at the current time or a period of time before the specific scenario is detected to be triggered.

[0296] S908, it is determined that there is no risk operation in the current environment.

[0297] S909, it is determined that there is a risk operation in the current environment.

[0298] The technical solution of the risk identification method given in this embodiment, which is based on the environment information in the first information to identify and determine whether there is a risk operation in the current environment, can be applied to any specific scenario, such as the specific scenario in which the electronic device 100 is set to call forwarding, or the specific scenario in which the electronic device 100 is set to do not disturb mode, or the specific scenario in which the electronic device 100 is set to flight mode, or the specific scenario in which the electronic device 100 is set to reject unknown incoming call mode, or other scenarios that can cause the electronic device 100 to temporarily lose communication capability. In this embodiment, the electronic device 100 determines whether the specific application is opened or running based on the environment information at the current time or a previous period of time when the specific scenario is triggered, determines whether the electronic device has a call with a risk number based on the call information in the case where the call application is opened or running, determines whether a risk application is downloaded or installed, determines whether a risk mode is started by the system, and determines whether a risk prompt information is generated, and so on, to identify and determine the risk in multiple aspects and dimensions to determine whether there is a risk operation in the current environment, thereby further improving the effectiveness and accuracy of risk identification based on environment information.

[0299] It should be noted that, Figure 8 The execution order and execution logic of the different determination methods involved in the embodiments given are examples, and the execution order and execution logic of each method are not limited in the actual identification and determination process.

[0300] It can be understood that aspects one give methods one to six for identifying the risk of a number based on the number information in the first information; and aspects two give methods seven to ten for identifying the risk based on the environment information in the first information.

[0301] In some other embodiments, the risk operation identification of the current environment can also be performed by the identification method of aspect three, which is actually a combination of aspects one and two. For example, if the electronic device 100 can determine the risk of the number information based on the combination of methods one to six in aspect one, and determine that the target number in the number information is a risk number, and the electronic device 100 can identify the risk of the environment information based on the combination of methods seven to ten in aspect two, and determine that the current environment has a risk operation, then it is finally determined that the current environment has a risk operation. For another example, if the electronic device 100 can determine the risk of the number information based on the combination of methods one to six in aspect one, and determine that the target number in the number information is a risk number, or the electronic device 100 can identify the risk of the environment information based on the combination of methods seven to ten in aspect two, and determine that the current environment has a risk operation, then it is finally determined that the current environment has a risk operation.

[0302] Optionally, in the identification method of aspect one and aspect two, the electronic device 100 performs the identification method of method one to method six in aspect one, and the order of performing the identification method of method seven to method ten in aspect two is not limited. It can be understood that the identification method of aspect one and aspect two can also be executed in parallel, and the present embodiment does not limit this.

[0303] In the present embodiment, the electronic device 100 performs risk identification of the target number involved in the current operation based on the number information in the first information, and performs risk identification of the environment where the current operation is located based on various information in the environment information, thereby improving the utilization rate of various information in the first information, and further improving the effectiveness and accuracy of risk identification of the current operation of the electronic device based on different information, thereby improving the success rate of risk interception and optimizing the user experience.

[0304] Figure 10 A possible structural schematic diagram of the electronic device involved in the above embodiments is shown. The electronic device 1000 includes a processor 1001, a display screen 1002, and a communication module 1003.

[0305] The processor 1001 is configured to control and manage the actions of the electronic device 1000. The display screen 1002 is configured to display the images generated by the processor 1001. The communication module 1003 is configured to support the communication between the electronic device 1000 and other network entities (such as a server).

[0306] The processor 1001 is configured to receive the operation set by the user in a specific scenario, obtain the first information, perform risk identification according to the first information, and output risk warning information to the display screen if it is determined that there is a risk. The display screen 1002 is configured to display the risk warning information.

[0307] In an optional embodiment, in the scenario where the specific scenario is call transfer, the phone number information at least includes a call transfer number. The processor 1001 is configured to determine that there is a risk if it is determined that the call transfer number is not a safe number.

[0308] In an optional embodiment, determining that the call transfer number is a safe number includes: determining that the call transfer number is a local SIM card number; or determining that the call transfer number is in a local address book; or determining that the call transfer number is in a preset whitelist; or determining that the owner information of the call transfer number is the same as the owner information of the local number.

[0309] In an optional embodiment, the communication module 1003 is configured to send, to a server, a first query request carrying a local number or a first identifier of the local number and a call forwarding number, the first query request being configured to instruct the server to query local owner information and call forwarding owner information based on the local number and the call forwarding number, receive a first query response returned by the server and carrying the local owner information and the call forwarding owner information, and determine that the owner information of the call forwarding number is the same as the owner information of the local number if it is determined that the local owner information and the call forwarding owner information match successfully.

[0310] In an optional embodiment, the communication module 1003 is configured to send, to a server, a second query request carrying a local number or a first identifier of the local number and a call forwarding number, the second query request being configured to instruct the server to determine a matching result of the owner information of the local number and the owner information of the call forwarding number, receive a second query response returned by the server and carrying the matching result, and determine that the owner information of the call forwarding number is the same as the owner information of the local number if it is determined that the matching result is a matching success.

[0311] In an optional embodiment, in a scenario where the specific scenario is a call forwarding scenario, the phone number information at least includes a call forwarding number, and the processor 1001 is configured to determine that there is a risk if it is determined that the call forwarding number is a risk number.

[0312] In an optional embodiment, determining that the call forwarding number is a risk number includes: determining that the call forwarding number is in a preset blacklist; or determining that the call forwarding number is a number that has been labeled as a risk.

[0313] In an optional embodiment, in a scenario where the specific scenario is a call forwarding scenario, the phone number information at least includes a call forwarding number, and the processor 1001 is configured to determine that there is a risk if it is determined that the call forwarding number is not a safe number and it is determined that the call forwarding number is a risk number.

[0314] In an optional embodiment, the risk warning information includes content instructing the user to perform a cancel setting specific scenario or perform a determination setting specific scenario. Based on this, the processor 1001 is configured to acquire a setting operation triggered by the user, output, to the display screen, a prompt message indicating a setting failure in a case where the setting operation is a cancel setting specific scenario, and output, to the display screen 1002, a prompt message indicating a setting success in a case where the setting operation is a determination setting specific scenario.

[0315] The display screen 1002 is configured to display the prompt message indicating the setting failure or the prompt message indicating the setting success.

[0316] In an optional embodiment, the communication module 1003 is further configured to send a setting request of call transfer to the server, and receive a setting response returned by the server and feed back the setting response to the processor.

[0317] The processor 1001 is configured to output a prompt message of setting success to the display screen based on the feedback response.

[0318] The display screen 1002 is configured to display the prompt message of setting success.

[0319] In an optional embodiment, the processor 1001 is configured to determine whether there is a risk operation at a first time or within a preset time period before the first time according to the environmental information, wherein the first time is a time when the user sets the operation of the specific scenario.

[0320] In an optional embodiment, the environmental information is a telephone call event, and the risk operation includes that a call number of the telephone call event is a risk number and / or the call number of the telephone call event is not a safe number.

[0321] In an optional embodiment, the environmental information is an application running event and / or a function running event, and the risk operation includes that a specific application is running and / or a specific function of the specific application is running.

[0322] In an optional embodiment, the environmental information is an application downloading event, and the risk operation includes that there is a behavior of downloading a risk application; the environmental information is an application installing event, and the risk operation includes that there is a behavior of installing a risk application.

[0323] In an optional embodiment, the environmental information is an application interaction event, and the risk operation includes that a risk prompt message sent by a specific application is received.

[0324] In an optional embodiment, the processor 1001 is configured to determine that there is a risk if it is determined that there is a risk according to the telephone number information and / or it is determined that there is a risk according to the environmental information; otherwise, it is determined that there is no risk.

[0325] The processor 1001 can be a central processing unit (CPU), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, transistor logic device, hardware component, or any combination thereof. The processor can include an application processor and a baseband processor. The processor can implement or execute various example logical blocks, modules, and circuits described in connection with the disclosure. The processor can also be a combination of computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like. The communication module 1003 can be a transceiver, a transceiver circuit, or the like. The storage module can be a memory.

[0326] For example, the processor 1001 can be a processor 3210 as shown in Figure 4A The communication module 1003 includes a radio frequency module (such as a radio frequency module 350 as shown in Figure 4A The communication module can also include a Wi-Fi module and a Bluetooth module, a radio frequency module 350, and the like. The storage module can be a memory (such as an internal memory 221 as shown in Figure 4A The display screen 1002 can be a display screen 394 as shown in Figure 4A The display screen 394 can be a touch screen, which can integrate a display panel and a touch panel. The terminal provided by the embodiments of the present application can be an electronic device 100 as shown in Figure 4A The above processor and display and the like can be connected together, for example, through a bus.

[0327] The embodiments of the present application also provide a computer readable storage medium, which includes computer instructions, when the computer instructions run on the above electronic device, make the electronic device execute various functions or steps executed by the electronic device 100 in the above method embodiments.

[0328] The embodiments of the present application also provide a computer program product, when the computer program product runs on a computer, makes the computer execute various functions or steps executed by the electronic device 100 in the above method embodiments. For example, the computer can be the above electronic device 100.

[0329] Through the description of the above embodiments, those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional modules is exemplified, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0330] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative, for example, the division of the modules or units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0331] The units described as separate components can or can not be physically separated, and the components displayed as units can be one physical unit or multiple physical units, that is, they can be located in one place or distributed to multiple different places. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0332] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0333] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application essentially or say the parts that make contributions to the prior art or all or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions to make a device (which can be a single-chip microcomputer, a chip, etc.) or a processor execute all or part of the steps of the method described in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various storage medium that can store program codes.

[0334] The above merely provides the specific implementation of the present application, but the protection scope of the present application is not limited to this. Any change or replacement within the technical scope disclosed by the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A risk identification method, characterized by, The method applied to a terminal comprises: receiving an operation of setting a specific scenario by a user, obtaining first information; the specific scenario comprises call forwarding, do-not-disturb mode or flight mode; the first information comprises environmental information involved in the specific scenario; the environmental information comprises one or more of a telephone call event, an application running event, a function running event, an application downloading event, an application installing event or an application interaction event; the first information is information generated at a first time or within a preset time period before the first time, the first time being a time when the operation of setting the specific scenario by the user is received; the risk operation corresponding to the application running event comprises running of a specific application, the specific application comprising an application having a screen sharing capability and / or a remote control capability; the risk operation corresponding to the function running event comprises running of a specific function, the specific function comprising screen sharing and / or remote control; performing risk identification according to the first information; if it is determined that there is a risk, outputting risk warning information and aborting the operation of setting the specific scenario; the risk warning information is used to prompt that the operation of setting the specific scenario has a risk.

2. The method of claim 1, wherein, The risk identification according to the first information comprises: determining whether there is a risk operation at the first time or within the preset time period before the first time according to the environmental information; the first time being a time when the operation of setting the specific scenario by the user is received.

3. The method of claim 2, wherein, The environmental information is a telephone call event, The risk operation comprises: a call number of the telephone call event is a risk number, and / or the call number of the telephone call event is not a safe number.

4. The method of claim 2, wherein, The environmental information is an application downloading event, and the risk operation comprises a behavior of downloading a risk application; or the environmental information is an application installing event, and the risk operation comprises a behavior of installing a risk application.

5. The method of claim 2, wherein, The environmental information is an application interaction event, and the risk operation comprises receiving a risk prompt message sent by a specific application.

6. The method of claim 1, wherein, The specific scenario is call forwarding, the first information further comprises telephone number information, the telephone number information comprises a call forwarding number, and the risk identification according to the first information comprises: if it is determined that the call forwarding number is not a safe number, and / or if it is determined that the call forwarding number is a risk number, it is determined that there is a risk.

7. The method of claim 6, wherein, The judgment condition for determining that the call forwarding number is a safe number comprises one or more of the following: it is determined that the call forwarding number is a number of a local SIM card; it is determined that the call forwarding number is in a local address book; it is determined that the call forwarding number is in a preset whitelist; it is determined that owner information of the call forwarding number is same as owner information of a local number.

8. The method of claim 7, wherein, The determination that the owner information of the call forwarding number is same as the owner information of the local number comprises: sending, to a server, a first query request carrying a first identifier and the call forwarding number; the first identifier is used to indicate a local number of the terminal; the first query request is used to instruct the server to query local owner information and call forwarding owner information based on the first identifier and the call forwarding number; receiving a first query response returned by the server, the first query response carrying the local owner information and the call forwarding owner information; if it is determined that the local owner information matches the call forwarding owner information, determining that the call forwarding number has the same owner information as the local number.

9. The method of claim 7, wherein, The determination that the call forwarding number has the same owner information as the local number includes: sending a second query request carrying a first identifier and the call forwarding number to a server, the first identifier being used to indicate the local number of the terminal, and the second query request being used to instruct the server to determine a matching result of the local number and the call forwarding number; receiving a second query response returned by the server, the second query response carrying the matching result; if it is determined that the matching result is a match, determining that the call forwarding number has the same owner information as the local number.

10. The method of claim 6, wherein, The determination that the call forwarding number is a risk number includes: determining that the call forwarding number is in a preset blacklist; or determining that the call forwarding number is a number that has been marked as risky by querying a three-party risk identification platform.

11. The method of claim 6, wherein, The method further includes: if it is determined that there is no risk, sending a setting request for setting call forwarding to a server; receiving a setting response returned by the server, and outputting a prompt message indicating that the setting is successful; The setting request carries a first identifier and a call forwarding number, the first identifier being used to indicate the local number of the terminal, and the setting request being used to instruct the server to forward the local number to the call forwarding number according to the local number and the call forwarding number.

12. The method according to any one of claims 1-11, characterized in that, The first information includes telephone number information and the environment information, and the risk identification according to the first information includes: if it is determined that there is a risk according to the risk identification of the telephone number information, and / or it is determined that there is a risk according to the risk identification of the environment information, then it is determined that there is a risk.

13. The method according to any one of claims 1-11, characterized in that, The first information includes telephone number information and the environment information, and the risk identification according to the first information includes: if it is determined that there is no risk according to the risk identification of the telephone number information, and / or it is determined that there is no risk according to the risk identification of the environment information, then it is determined that there is no risk.

14. An electronic device, comprising: The electronic device includes a memory, a display screen and one or more processors; the memory, the display screen and the processor are coupled; the memory stores computer program code, the computer program code includes computer instructions, when the computer instructions are executed by the processor, the electronic device executes the method of any one of claims 1-13.

15. A computer-readable storage medium, characterized in that, The computer program product includes computer instructions, when the computer instructions are executed on the electronic device, the electronic device executes the method of any one of claims 1-13.

Citation Information

Patent Citations

  • Call forwarding setting prompting method and network side equipment

    CN104935762A

  • Call forwarding setting prompting method and terminal

    CN105101132A

  • Method and device for preventing phone scam, and mobile terminal

    CN106657690A