Cloud device identification method, apparatus, device, and computer storage medium

By utilizing encrypted recognition processing of target encrypted data in cloud device identification, the problems of low accuracy in cloud device identification and data privacy leakage are solved, achieving higher identification accuracy and data transmission security.

CN118540099BActive Publication Date: 2025-12-12INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410450381.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-15
Publication Date
2025-12-12
Estimated Expiration
2044-04-15

AI Technical Summary

Technical Problem

Existing technologies have low accuracy in identifying cloud devices and pose risks of data privacy leaks and transmission security.

Method used

By receiving the target user identifier in the query request, the target encrypted data is identified and encrypted for identification. The target encrypted identification result is obtained, avoiding decryption. The cloud device is identified directly through encrypted identification, and privacy computing and encryption algorithms are used to protect data privacy.

Benefits of technology

It improves the accuracy of cloud device identification, reduces the risk of data leakage during data transmission, and ensures the security and privacy protection of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118540099B_ABST
    Figure CN118540099B_ABST
Patent Text Reader

Abstract

The application relates to a cloud device identification method, device and computer storage medium, and relates to the technical field of information security. The method comprises the following steps: in the case that a query request sent by a query device is received, determining target ciphertext data according to a target user identifier carried in the query request; and performing encryption identification processing on the target ciphertext data to obtain a target encryption identification result. Further, the target encryption identification result is sent to the query device. According to the application, the target device can be accurately identified without leaking the privacy of the ciphertext data, so that the accuracy of cloud device identification is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security, and in particular to a cloud device identification method and device, equipment and computer storage medium. BACKGROUND

[0002] A cloud device is a device running on a cloud server, based on virtualization technology and a 5G network, various mobile terminal applications can run on the cloud device, which brings convenience to users, but also raises new risk challenges, therefore, how to improve the accuracy of identifying cloud devices is crucial for cloud device service providers and device application operators.

[0003] In related technologies, the identification information of the mobile device is usually sent to the server, so that the server can identify whether the mobile device is a cloud device based on the identification information. However, this way has the problem of low identification accuracy of cloud devices. SUMMARY

[0004] Therefore, it is necessary to provide a cloud device identification method, device, equipment and computer storage medium capable of improving the accuracy of identifying cloud devices.

[0005] In a first aspect, the present application provides a cloud device identification method, which is applied to a first server, and the method comprises:

[0006] In the case that a query request sent by a query device is received, target ciphertext data is determined according to a target user identifier carried in the query request; wherein the target ciphertext data is used to indicate device running encryption information of a target device corresponding to the target user identifier;

[0007] The target ciphertext data is subjected to encryption identification processing to obtain a target encryption identification result; wherein the target encryption identification result is used to encrypt to indicate whether the target device is a cloud device;

[0008] The target encryption identification result is sent to the query device.

[0009] In one of the embodiments, the device running encryption information comprises at least one of the following information: device fingerprint encryption information, cloud device feature encryption information, network environment encryption information, operation encryption information and user behavior encryption information.

[0010] In one of the embodiments, the target ciphertext data is subjected to encryption identification processing to obtain the target encryption identification result, which comprises:

[0011] The target ciphertext data is subjected to privacy calculation processing to determine a target identification result corresponding to the target ciphertext data;

[0012] The target identification result is subjected to encryption processing to obtain the target encryption identification result.

[0013] In one of the embodiments, the target ciphertext data is processed by privacy computation to determine a target recognition result corresponding to the target ciphertext data, which includes:

[0014] The target ciphertext data and a preset cloud device ciphertext data set are processed by privacy computation to obtain the target recognition result; wherein the privacy computation processing includes at least one of the following: privacy intersection processing, privacy query processing, and joint statistical processing.

[0015] In one of the embodiments, the query request further includes a query condition type, and the target ciphertext data is determined according to the target user identifier carried in the query request, which includes:

[0016] The target ciphertext data is obtained from the preset ciphertext database according to the target user identifier and the query condition type.

[0017] In one of the embodiments, the above method further includes:

[0018] The ciphertext data corresponding to each user identifier is obtained from the second server; wherein the ciphertext data corresponding to the user identifier is used to indicate that the device corresponding to the user identifier runs encrypted information;

[0019] The ciphertext data corresponding to each user identifier is stored in the preset ciphertext database.

[0020] In a second aspect, the application provides a cloud device recognition method, which is applied to a query device, and the method includes:

[0021] According to the business requirement, a query request corresponding to the business requirement is determined;

[0022] The query request is sent to a first server; wherein the query request carries a target user identifier corresponding to a target device to be identified, and the target user identifier is used to indicate that the first server, in the case of determining target ciphertext data according to the target user identifier, processes the target ciphertext data by encrypted recognition to obtain a target encrypted recognition result, and sends the target encrypted recognition result to the query device;

[0023] The target encrypted recognition result is received, and it is determined whether the target device is a cloud device according to the target encrypted recognition result.

[0024] In one of the embodiments, it is determined whether the target device is a cloud device according to the target encrypted recognition result, which includes:

[0025] The target encrypted recognition result is processed by decryption to obtain a target decrypted recognition result; wherein the target decrypted recognition result is used to indicate in plaintext whether the target device is a cloud device.

[0026] In one embodiment, determining the query request corresponding to the business requirement based on business needs includes:

[0027] Determine the target user identifier and / or query condition type corresponding to the business requirements based on business needs;

[0028] Determine the query request corresponding to the business requirement based on the target user identifier and / or query condition type.

[0029] Thirdly, this application provides a cloud device identification method, which is applied to a second server and includes the following steps:

[0030] Obtain the device operation information corresponding to each user identifier;

[0031] The device operation information corresponding to each user identifier is encrypted to obtain ciphertext data corresponding to each user identifier; the ciphertext data corresponding to the user identifier is used to indicate the encrypted device operation information corresponding to the user identifier.

[0032] Each user identifier's corresponding encrypted data is sent to the first server; wherein, the encrypted data corresponding to each user identifier is used by the first server to determine the target encrypted data based on the target user identifier carried in the query request.

[0033] Fourthly, this application provides a cloud device identification device, which is applied to a first server, and the device includes:

[0034] The determination module is used to determine the target encrypted data based on the target user identifier carried in the query request when a query request is received from the query device; wherein, the target encrypted data is used to indicate the device operation encryption information of the target device corresponding to the target user identifier;

[0035] The encryption identification module is used to perform encryption identification processing on the target ciphertext data to obtain the target encryption identification result; wherein, the target encryption identification result is used to encrypt and indicate whether the target device is a cloud device;

[0036] The sending module is used to send the encrypted identification result of the target to the query device.

[0037] Fifthly, this application provides a cloud device identification device, which is used in query devices, and the device includes:

[0038] The first determination module is used to determine the query request corresponding to the business requirements based on the business needs.

[0039] The sending module is configured to send a query request to the first server, wherein the query request carries a target user identifier corresponding to the target device to be identified, and the target user identifier is used to instruct the first server to, in a case where the target ciphertext data is determined according to the target user identifier, perform encrypted identification processing on the target ciphertext data to obtain a target encrypted identification result, and send the target encrypted identification result to the query device.

[0040] The receiving module is configured to receive the target encrypted identification result.

[0041] The second determining module is configured to determine, according to the target encrypted identification result, whether the target device is a cloud device.

[0042] In a sixth aspect, a cloud device identification apparatus is provided, and the apparatus is applied to a second server. The apparatus includes:

[0043] The obtaining module is configured to obtain device running information corresponding to each user identifier.

[0044] The encryption module is configured to perform encrypted processing on the device running information corresponding to each user identifier to obtain ciphertext data corresponding to each user identifier, wherein the ciphertext data corresponding to the user identifier is used to indicate device running encrypted information corresponding to the user identifier.

[0045] The sending module is configured to send the ciphertext data corresponding to each user identifier to the first server, wherein the ciphertext data corresponding to each user identifier is used to instruct the first server to determine target ciphertext data according to a target user identifier carried in a query request.

[0046] In a seventh aspect, the present application further provides a cloud device identification device, which includes a memory and a processor. The memory stores a computer program, and the processor implements the steps of the method of the first aspect or the second aspect or the third aspect when executing the computer program.

[0047] In an eighth aspect, the present application provides a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the steps of the method of the first aspect or the second aspect or the third aspect.

[0048] In a ninth aspect, the present application further provides a computer program product, which includes a computer program. The computer program is executed by a processor to implement the steps of the method of the first aspect or the second aspect or the third aspect.

[0049] The aforementioned cloud device identification method, apparatus, device, and computer storage medium, upon receiving a query request sent by a querying device, determine the target encrypted data corresponding to the target user identifier based on the target user identifier carried in the query request; wherein, the target encrypted data is used to indicate the device operation encryption information of the target device corresponding to the target user identifier. Further, the target encrypted data undergoes encryption identification processing to obtain a target encryption identification result; wherein, the target encryption identification result is used to encrypt whether the target device is a cloud device, and the target encryption identification result is sent to the querying device. Compared to the traditional method where the server only identifies whether a device is a cloud device based on its identifier information, in this embodiment, the first server determines the target encrypted data based on the target user identifier in the query request and performs encryption identification processing on the target encrypted data to obtain the target encryption identification result. Since the target encrypted data in this embodiment includes the device operation encryption information of the target device corresponding to the target user identifier, this embodiment, by performing encryption identification processing on at least one piece of encrypted information in the target encrypted data, can more accurately identify whether the target device is a cloud device, thereby improving the accuracy of cloud device identification. Furthermore, after the first server determines the target ciphertext data, it does not need to decrypt the target ciphertext data. Instead, it directly obtains the target encrypted identification result by encrypting and identifying the target ciphertext data, thus enabling the identification of the target device without leaking the privacy of the ciphertext data. Furthermore, by sending the target encrypted identification result to the querying device, the risk of leakage during transmission can be reduced, thereby improving the security of data transmission. Attached Figure Description

[0050] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0051] Figure 1 This is a schematic diagram illustrating the implementation environment of the cloud device identification method in one embodiment of this application;

[0052] Figure 2 This is a flowchart illustrating a cloud device identification method in one embodiment of this application;

[0053] Figure 3 This is a flowchart illustrating a cloud device identification method in another embodiment of this application;

[0054] Figure 4 This is a flowchart illustrating a cloud device identification method in another embodiment of this application;

[0055] Figure 5 Flowchart of the cloud device identification method in another embodiment of the present application;

[0056] Figure 6 Flowchart of the cloud device identification method in another embodiment of the present application;

[0057] Figure 7 Flowchart of the cloud device identification method in another embodiment of the present application;

[0058] Figure 8 Flowchart of the cloud device identification method in another embodiment of the present application;

[0059] Figure 9 Flowchart of the cloud device identification method in another embodiment of the present application;

[0060] Figure 10 Flowchart of the cloud device identification method in another embodiment of the present application;

[0061] Figure 11 Overall flowchart of an exemplary cloud device identification method in one embodiment of the present application Figure 1 ;

[0062] Figure 12 Overall flowchart of another exemplary cloud device identification method in one embodiment of the present application Figure 2 ;

[0063] Figure 13 Structure diagram of the cloud device identification apparatus in one embodiment of the present application;

[0064] Figure 14 Structure diagram of the cloud device identification apparatus in another embodiment of the present application;

[0065] Figure 15 Structure diagram of the cloud device identification apparatus in another embodiment of the present application;

[0066] Figure 16 Internal structure diagram of the cloud device identification apparatus in one embodiment of the present application. DETAILED DESCRIPTION

[0067] In order to make the objects, technical solutions and advantages of the present application clearer, the present application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and should not be used to limit the present application.

[0068] The cloud device identification method, apparatus, device and computer storage medium provided in the embodiments of the present application can be applied to cloud device identification in a bank business scenario. Of course, it can also be applied to other scenarios, and the embodiments of the present application do not limit this.

[0069] Exemplarily, the cloud device in the embodiments of the present application can include, but is not limited to, any one of the following: a cloud mobile phone device, a cloud computer device.

[0070] It should be noted that the following embodiments are described for the convenience of explanation by taking the cloud device identification method of the embodiments of the present application applied to a bank business scenario as an example. It should be understood that when the cloud device identification method of the embodiments of the present application is applied to other scenarios, the implementation principles and technical effects are similar.

[0071] A cloud device is a device running on a cloud server. Based on virtualization technology and a 5G network, a user can remotely control the cloud device erected on the cloud server in real time through video streaming without purchasing device hardware. Further, various mobile terminal applications can also run on the cloud device, which brings convenience to users and also raises new risk challenges. For example, in a bank business, some personnel may attempt to use a cloud device to run a bank application, guide users to download illegal software to record face information and send it to the cloud device for logging into a bank application program to perform illegal behavior, or directly use a generative artificial intelligence to synthesize a user's portrait video to attempt to bypass the bank application face recognition system. Therefore, how to improve the accuracy of identifying a cloud device is crucial for cloud device service providers and device application operators.

[0072] Compared with the manner in which a server in the prior art only identifies whether a cloud device is based on identification information of the cloud device, in the embodiments of the present application, the first server determines target ciphertext data according to a target user identifier in a query request, and performs encryption identification processing on the target ciphertext data to obtain a target encryption identification result. Since the target ciphertext data in the embodiments of the present application includes device running encryption information of a target device corresponding to the target user identifier, in the embodiments, at least one piece of ciphertext information in the target ciphertext data is processed by the encryption identification processing manner, which can more accurately identify whether the target device is a cloud device, thereby improving the identification accuracy of the cloud device. Further, after determining the target ciphertext data, the first server does not need to perform decryption processing on the target ciphertext data, but directly obtains the target encryption identification result by performing encryption identification processing on the target ciphertext data, which realizes that the target device can be identified without leaking the privacy of the ciphertext data. Further, by sending the target encryption identification result to the query device, it can be beneficial to reduce the risk of leakage in the transmission process, thereby improving the security of data transmission.

[0073] Figure 1 This is a schematic diagram illustrating the implementation environment of the cloud device identification method in one embodiment of this application, such as... Figure 1 As shown, the implementation environment of this application embodiment may include: a query device 101, a first server 102, and a second server 103; wherein, the query device 101 can communicate with the first server 102 via a network; the first server 102 can communicate with the second server 103 via a network. The query device 101 may include, but is not limited to, various personal computers, laptops, smartphones, and tablets. The second server may include, but is not limited to, servers corresponding to cloud device service providers or servers corresponding to device application operators. The first server 102 and the second server 103 can be implemented using independent servers or a server cluster composed of multiple servers. The data storage system can store information such as query requests, target encrypted data, and target encrypted identification results. The data storage system can be integrated on the first server 102 and / or the second server 103, or it can be placed on the cloud or other network servers.

[0074] Combination Figure 1 In the implementation environment shown in this embodiment, when the first server 102 receives a query request from the query device 101, it determines the target encrypted data corresponding to the target user identifier based on the target user identifier carried in the query request. The first server 102 performs encryption recognition processing on the target encrypted data to obtain the target encryption recognition result; and sends the target encryption recognition result to the query device 101. The first server 102 can also retrieve the encrypted data corresponding to each user identifier from the second server 103.

[0075] In one embodiment, Figure 2 This is a flowchart illustrating a cloud device identification method in one embodiment of this application. In this embodiment, the method is applied to... Figure 1 Let's take the first server, 102, as an example for illustration. Figure 2 As shown, the method in this application embodiment may include the following steps.

[0076] Step S201: Upon receiving a query request from the query device, determine the target encrypted data based on the target user identifier carried in the query request.

[0077] In this context, "query device" can refer to the party that needs to query whether a target device is a cloud device based on business needs. For example, query device can include, but is not limited to, the device where the cloud device service provider is located or the device where the device application operator is located. The cloud device service provider refers to the organization that provides cloud device-related services and resources. The device application operator refers to the organization that is responsible for the operation and management of device applications.

[0078] The query request can indicate a request sent by the query device to the first server for obtaining target device information or performing a specific operation. For example, the query request can include, but is not limited to, a target user identifier and a query condition type.

[0079] The target user identifier is an identifier uniquely identifying a specific user, used to determine a target object that needs to be operated or information that needs to be obtained.

[0080] The target ciphertext data can be used to indicate device running encryption information of a target device corresponding to the target user identifier. The device running encryption information can include, but is not limited to, at least one of the following information: device fingerprint encryption information, cloud device feature encryption information, network environment encryption information, operation encryption information, and user behavior encryption information.

[0081] For example, the user identifier and the ciphertext data can be one-to-one corresponding through a preset mapping table. For example, the user identifier A can find at least one of the device fingerprint encryption information, the cloud device feature encryption information, the network environment encryption information, the operation encryption information, and the user behavior encryption information corresponding to the user identifier A through the preset mapping table.

[0082] For example, the device fingerprint encryption information can indicate information obtained by encrypting device fingerprint information. The device fingerprint information can include, but is not limited to, a central processing unit (CPU) instruction set, a Bluetooth media access control (MAC) address, an international mobile equipment identity, an international mobile subscriber identity, chip manufacturer information, a device brand, hardware information, a manufacturer, screen resolution information, a system version, system total memory, a secure digital (SD) card total capacity, and a time zone.

[0083] For example, the cloud device feature encryption information can indicate information obtained by encrypting cloud device feature information. The cloud device feature information can include, but is not limited to, a cloud device model, a version number, a screen resolution, and an operating system version.

[0084] For example, the network environment encryption information can indicate information obtained by encrypting network environment information. The network environment information can include, but is not limited to, a network type, an Internet Protocol (IP) location, base station information, and a nearby Wireless Fidelity (WIFI) list.

[0085] Exemplarily, the operation encryption information can indicate information obtained by encrypting operation information, where the operation information can include cloud device operation information, device application operation information. Optionally, the cloud device operation information can include, but is not limited to, a user identifier (ID) of the cloud device, a cloud device ID, and an online state of the cloud device. Optionally, the device application operation information can include, but is not limited to, a user ID of the device application and an online state of the device application.

[0086] Exemplarily, the user behavior encryption information can indicate information obtained by encrypting user behavior information, where the user behavior information can include, but is not limited to, user online duration, user login frequency, user transaction type, user location information, and user abnormal behavior.

[0087] In this step, the first server can determine the target ciphertext data according to the target user identifier in the query request when receiving the query request sent by the query device. In this way, the privacy of the user is protected, and only a legal query request carrying a correct target user identifier can obtain the corresponding ciphertext data, thereby improving the security of querying user data.

[0088] In step S202, the target ciphertext data is subjected to encryption identification processing to obtain a target encryption identification result.

[0089] The encryption identification processing is used to indicate that the target ciphertext data is calculated according to a preset calculation method or algorithm to obtain the target encryption identification result; and the target encryption identification result is used to encrypt to indicate whether the target device is a cloud device.

[0090] In the following, the related content of obtaining the target encryption identification result will be exemplarily introduced and described.

[0091] In one possible implementation manner, the first server can perform privacy calculation on the target ciphertext data to obtain a privacy calculation result, and encrypt the privacy calculation result to obtain the target encryption identification result.

[0092] In this implementation manner, the first server obtains the privacy calculation result by performing privacy calculation on the target ciphertext data. Since the target ciphertext data is obtained by the second server performing encryption processing on the device operation information of each user and sending to the first server, the target ciphertext data not only includes cloud device identifier information, but also includes other operation information of the cloud device, thereby improving the identification accuracy of the cloud device. Further, the first server does not need to perform decryption processing on the target ciphertext data, but can directly perform encryption identification processing to obtain the target encryption identification result, so that the target device can be identified without leaking the privacy of the ciphertext data, thereby improving the security of data transmission.

[0093] In another possible implementation manner, the first server can input the target ciphertext data into the first neural network model trained in advance, and through the neural network model, the first server can obtain the target encrypted recognition result.

[0094] In this implementation manner, the first server inputs the target ciphertext data into the first neural network model trained in advance, and through multiple iterations of training, the first server constantly optimizes the neural network model, so as to quickly and accurately obtain the target encrypted recognition result.

[0095] In step S203, the target encrypted recognition result is sent to the query device.

[0096] In this step, the first server can send the target encrypted recognition result to the query device in a wired or wireless manner, so that the query device can perform subsequent operations according to the target encrypted recognition result.

[0097] Correspondingly, the query device receives the target encrypted recognition result sent by the first server, and decrypts the target encrypted recognition result to obtain a target decrypted recognition result.

[0098] In the cloud device recognition method, the first server determines target ciphertext data corresponding to a target user identifier according to the target user identifier carried in the query request when the first server receives the query request sent by the query device, and the target ciphertext data is used to indicate device running encryption information of a target device corresponding to the target user identifier. Further, the first server performs encrypted recognition processing on the target ciphertext data to obtain a target encrypted recognition result, and the target encrypted recognition result is used to indicate whether the target device is a cloud device. The first server sends the target encrypted recognition result to the query device. Compared with the manner in which the server in the prior art only identifies whether a cloud device is based on the identifier information of the cloud device, in the embodiment of the present application, the first server determines the target ciphertext data according to the target user identifier in the query request, and performs encrypted recognition processing on the target ciphertext data to obtain the target encrypted recognition result. Since the target ciphertext data in the embodiment of the present application includes the device running encryption information of the target device corresponding to the target user identifier, the embodiment can more accurately identify whether the target device is a cloud device by performing encrypted recognition processing on at least one item of ciphertext information in the target ciphertext data, thereby improving the recognition accuracy of the cloud device. Further, after determining the target ciphertext data, the first server does not need to perform decryption processing on the target ciphertext data, but directly obtains the target encrypted recognition result by performing encrypted recognition processing on the target ciphertext data, so that the target device can be identified without leaking the privacy of the ciphertext data. Further, by sending the target encrypted recognition result to the query device, the risk of leakage in the transmission process can be reduced, thereby improving the security of data transmission.

[0099] In one embodiment, on the basis of the above-mentioned embodiments, Figure 3 For another flowchart of the cloud device identification method in another embodiment of the application, the related content of the step S202 "performing encryption identification processing on the target ciphertext data to obtain a target encryption identification result" involved in the above-mentioned embodiments is exemplarily introduced and described. The method of the embodiment of the application can include the following steps.

[0100] Step S2021, performing privacy calculation processing on the target ciphertext data to determine a target identification result corresponding to the target ciphertext data.

[0101] Among them, the privacy calculation processing is used to indicate that the target ciphertext data is subjected to specific calculation processing to ensure that the user's privacy information is not disclosed in the calculation identification process. The target identification result is used to indicate the identification result obtained after the privacy calculation processing.

[0102] In the following, the related content of "performing privacy calculation processing on the target ciphertext data" will be exemplarily introduced and described.

[0103] The first server can perform privacy calculation processing on the target ciphertext data and the preset cloud device ciphertext data set to obtain the target identification result.

[0104] Among them, the preset cloud device ciphertext data set is used to indicate a set of standard cloud device ciphertext data stored in the first server in advance; the privacy calculation processing includes at least one of the following: privacy intersection processing, anonymous query processing, joint statistical processing.

[0105] Optionally, the privacy intersection processing refers to an intersection operation performed in an encrypted state. Participants can perform intersection calculation on encrypted data without disclosing the original data, which is beneficial to protect the data privacy of each participant, and at the same time, the result of the intersection can be obtained.

[0106] Optionally, the anonymous query processing refers to a query operation realized through encryption technology. The user can send an encrypted query request, and the data holder can perform encryption processing on his own data and perform a query operation in an encrypted state, and finally return an encrypted query result, which can protect the data privacy and at the same time meet the user's query demand.

[0107] Optionally, the joint statistical processing is a statistical analysis operation performed by multiple data holders. Each party can perform joint statistical analysis on encrypted data without disclosing the original data to obtain a summarized statistical result, which is beneficial to protect the data privacy and at the same time realize cross-data-source statistical analysis.

[0108] In this implementation, the first server matches the target ciphertext data and the preset cloud device ciphertext data set by performing privacy calculation processing on the target ciphertext data and the preset cloud device ciphertext data set, so that the target recognition result can be obtained, and the privacy information of the user can be fully protected during data calculation and processing, and the data can be prevented from being maliciously attacked or stolen during transmission and processing.

[0109] In step S2022, the target recognition result is encrypted to obtain a target encrypted recognition result.

[0110] The encryption processing refers to encrypting the data by using a preset encryption algorithm, which can effectively prevent unauthorized access to sensitive information and ensure the security of the data during transmission and storage. The preset encryption algorithm can include, but is not limited to, symmetric encryption algorithm, asymmetric encryption algorithm, and homomorphic encryption algorithm.

[0111] In this step, the first server can encrypt the target recognition result to obtain a target encrypted recognition result. By encrypting the target recognition result, the confidentiality of the data can be effectively protected, and the security of the data during transmission and storage can be improved.

[0112] In the embodiment of the application, the first server matches the target ciphertext data and the preset cloud device ciphertext data set by performing privacy calculation processing on the target ciphertext data and the preset cloud device ciphertext data set, so that the target recognition result can be obtained without disclosing the target ciphertext data, and the data can be prevented from being maliciously attacked or stolen during transmission and processing. Further, the first server can encrypt the target recognition result to obtain a target encrypted recognition result. By encrypting the target recognition result, the confidentiality of the data can be effectively protected.

[0113] In one embodiment, on the basis of the above-mentioned embodiment, the related content of step S201 involved in the above-mentioned embodiment, i.e., "determining the target ciphertext data corresponding to the target user identifier according to the target user identifier carried in the query request", is exemplarily introduced and explained. The query request also includes a query condition type, and the method of the embodiment of the application can include the following steps.

[0114] The first server obtains the target ciphertext data from the preset ciphertext database according to the target user identifier and the query condition type.

[0115] The query condition type refers to the type or category of the query condition that can be specified according to different query requirements and purposes. The query condition can include, but is not limited to, at least one of device fingerprint information, cloud device feature information, network environment information, operation information, and user behavior information. The preset ciphertext database refers to a data set stored in the database after the device operation information is encrypted in advance.

[0116] In this step, the first server can obtain the target ciphertext data from the preset ciphertext database according to the target user identifier and the query condition type. As can be seen, the first server can quickly and accurately retrieve the ciphertext data that meets the condition from the preset ciphertext database according to the target user identifier and the query condition type, thereby improving the query efficiency and accuracy. Further, based on the query according to the target user identifier, the target ciphertext data is determined according to the query condition type, which can also realize the customized return of data, so that the first server can return the corresponding ciphertext data according to different query condition types, thereby improving the flexibility and personalization of the service.

[0117] In one embodiment, based on the above-mentioned embodiments, Figure 4 For the flowchart of the cloud device identification method in another embodiment of the present application, the related content of the "preset ciphertext database" in step S2011 in the above-mentioned embodiments is exemplarily introduced and described. The method of the present embodiment can include the following steps.

[0118] Step S401: Obtain the ciphertext data corresponding to each user identifier from the second server.

[0119] The ciphertext data corresponding to the user identifier is used to indicate the device operation encryption information corresponding to the user identifier.

[0120] In this step, the first server obtains the ciphertext data corresponding to each user identifier from the second server, which is conducive to accurately identifying and obtaining the data to be processed, and provides the necessary information basis for the subsequent steps.

[0121] Correspondingly, the second server encrypts the device operation information corresponding to each user identifier, and sends the ciphertext data corresponding to each user identifier to the first server.

[0122] Step S402: Store the ciphertext data corresponding to each user identifier in the preset ciphertext database.

[0123] In this step, the first server can store the ciphertext data obtained from the second server into a preset ciphertext database, which can effectively protect data security and privacy, and storing into the database can also facilitate subsequent data management and retrieval, improve the efficiency and accuracy of data processing, so that the first server can obtain target ciphertext data from the preset ciphertext database according to the target user identifier and the query condition type.

[0124] In the embodiments of this application, the first server obtains the ciphertext data corresponding to each user identifier from the second server, which is conducive to accurately identifying and obtaining the data to be processed, and provides the necessary information basis for the subsequent steps. Further, the first server stores the ciphertext data into a preset ciphertext database, which can facilitate subsequent data management and retrieval, improve the efficiency and accuracy of data processing.

[0125] In one embodiment, Figure 5 For the flowchart of the cloud device identification method in another embodiment of the application, the method in the embodiments of the application is applied to the query device 101 in Figure 1 For example, as shown in Figure 5 The method of the embodiments of the application can include the following steps.

[0126] Step S501, according to the business requirement, determining the query request corresponding to the business requirement.

[0127] The business requirement refers to the business requirement generated by different query devices according to different businesses, for example, the business requirement can include but is not limited to querying whether the running environment is a cloud device before starting the device application, and querying whether the device is a cloud device before logging in the device.

[0128] In this step, the query device can determine the query request corresponding to the business requirement according to the business requirement. By determining the query request according to the business requirement, it is conducive to improving the accuracy and effectiveness of the query, so as to better meet the specific business requirement.

[0129] Step S502, sending the query request to the first server.

[0130] The query request carries the target user identifier corresponding to the target device to be identified; the target user identifier is used to instruct the first server to perform encrypted identification processing on the target ciphertext data to obtain a target encrypted identification result under the condition that the target ciphertext data is determined according to the target user identifier, and send the target encrypted identification result to the query device.

[0131] In this step, the query device can send a query request carrying the target user identifier and / or the query condition type to the first server, so that the first server performs the encrypted identification processing on the target encrypted identification data to obtain the target encrypted identification result in a case where the target encrypted identification data is determined according to the query request.

[0132] It should be noted that the specific implementation of each step in the embodiments of the present application can refer to the related content in the above embodiments, which will not be repeated here.

[0133] In step S503, the target encrypted identification result is received, and it is determined whether the target device is a cloud device according to the target encrypted identification result.

[0134] In the following, the related content of determining whether the target device is a cloud device according to the target encrypted identification result is exemplarily introduced and described.

[0135] The query device decrypts the target encrypted identification result to obtain a target decrypted identification result.

[0136] The target decrypted identification result is used to indicate in plaintext whether the target device is a cloud device.

[0137] The decryption processing refers to decrypting the target encrypted identification result through a preset decryption algorithm, so that the query device can obtain the target decrypted identification result, and ensure the security of data in the transmission and storage process.

[0138] In this step, the query device can receive the target encrypted identification result and decrypt the target encrypted identification result, so that the target decrypted identification result can be obtained. It can be seen that the query device can obtain the original target identification information by decrypting the target encrypted identification result, so that the query device can accurately understand whether the target device is a cloud device.

[0139] In the embodiments of the present application, the query device can determine the query request according to the business requirement, which is beneficial to improve the accuracy and effectiveness of the query, so as to better meet the specific business requirement. Further, the query device can send the query request carrying the target user identifier and / or the query condition type to the first server, so that the first server performs the encrypted identification processing on the target encrypted identification data to obtain the target encrypted identification result in a case where the target encrypted identification data is determined according to the query request. The query device can obtain the original target identification information by decrypting the target encrypted identification result, so that the query device can accurately understand whether the target device is a cloud device.

[0140] In one embodiment, on the basis of the above embodiments, Figure 6For another embodiment of the cloud device identification method flowchart of the present application, the present embodiment makes an exemplary introduction to the related content of the step S501 in the above embodiment, which is "determining the query request corresponding to the business requirement according to the business requirement". The method of the present embodiment can include the following steps.

[0141] In step S5011, the target user identifier and / or the query condition type corresponding to the business requirement are determined according to the business requirement.

[0142] Exemplarily, the business requirement of the query device is to query whether the device used by the target user A is a cloud device before starting the device application, and the corresponding target user identifier can be the user identifier of the target user A, and the query condition type can be to determine whether it is a cloud device according to the cloud device ID and the device fingerprint.

[0143] In this step, the query device can determine the target user identifier and the query condition type corresponding to the business requirement according to the business requirement. It can be seen that the query device can achieve accurate query of specific users or specific query information by determining the target user identifier and the query condition type, thereby more effectively meeting the business requirement.

[0144] It should be noted that the specific implementation of each step in the present embodiment can refer to the related content in the above embodiment, which will not be repeated here.

[0145] In step S5012, the query request corresponding to the business requirement is determined according to the target user identifier and / or the query condition type.

[0146] Exemplarily, the business requirement of the query device is to query whether the device used by the target user A is a cloud device before starting the device application, and the corresponding target user identifier can be the user identifier of the target user A, and the query condition type can be to determine whether it is a cloud device according to the cloud device ID and the device fingerprint. The query request can carry the target user identifier of the target user A, the cloud device ID and the device fingerprint. For another example, the business requirement of the query device is to query whether the device used by the target user B is a cloud device before starting the device application, and the corresponding target user identifier can be the user identifier of the target user B, and the query condition type can be to determine whether it is a cloud device according to the user ID of the device application. The query request can carry the target user identifier of the target user B and the user ID of the device application.

[0147] Exemplarily, if the querying device is a device application operator, the querying device wants to query whether the device used by the target user A is a cloud device before starting the device application, the querying request can include the user identifier of the target user A, the cloud device ID, the device fingerprint, the network environment, etc. The querying device can query the cloud device ID, the device fingerprint, the network environment, etc. according to the user identifier of the target user A, query whether the user is a cloud device user according to the cloud device ID (for example, a mobile phone number), if the result is no, query whether the user is a cloud device according to the device fingerprint of the user, if the result is no, query whether the user is a cloud device according to the network environment. If the result is no, it is determined that the device used by the user is a real machine device.

[0148] In this step, the querying device can determine the query request corresponding to the service requirement according to the target user identifier and / or the query condition type. It can be seen that the querying device can ensure that the query request is consistent with the service requirement by generating the query request according to the target user identifier and the query condition type, thereby improving the accuracy of the query result, avoiding unnecessary query range, and improving the query efficiency and response speed.

[0149] In the embodiment of the application, the querying device can achieve accurate query of specific users or specific query information by determining the target user identifier and the query condition type, thereby more effectively meeting the service requirement. Further, the querying device can ensure that the query request is consistent with the service requirement by generating the query request according to the target user identifier and the query condition type, thereby improving the accuracy of the query result, avoiding unnecessary query range, and improving the query efficiency and response speed.

[0150] It should be noted that the specific implementation mode of each step in the embodiment of the application can refer to the related content in the above embodiments, which will not be described here.

[0151] In one embodiment, on the basis of the above embodiment, Figure 7 For the flowchart of the cloud device identification method in another embodiment of the application, the method in the embodiment of the application is applied to the second server 103 in the above embodiment as an example. As shown in Figure 1 the method of the embodiment of the application can include the following steps. Figure 7

[0152] Step S701, obtaining device running information corresponding to each user identifier respectively.

[0153] The device running information can include but is not limited to device fingerprint information, cloud device feature information, network environment information, operation information, and user behavior information.

[0154] ​In this step, the second server can obtain the device running information corresponding to each user identifier. By obtaining the device running information, the second server can better understand the device characteristics, network environment and behavior information of the user, so as to improve the accuracy of the device running encryption information obtained by the first server subsequently.

[0155] It should be noted that the second server can obtain the device running information corresponding to each user identifier from the preset database according to a preset time, or can generate the device running information in real time when the device user uses the target device, which is not limited herein.

[0156] In step S702, the device running information corresponding to each user identifier is encrypted to obtain the ciphertext data corresponding to each user identifier.

[0157] The ciphertext data corresponding to the user identifier is used to indicate the device running encryption information corresponding to the user identifier.

[0158] Optionally, the device running information can be preprocessed before being encrypted, wherein the preprocessing can include but is not limited to abnormal data cleaning, default data completion, generating device fingerprint ID and cloud device characteristic ID using a hash algorithm, etc., which is not limited herein.

[0159] The device fingerprint ID generated using the hash algorithm is used to indicate that the second server combines the information in the device fingerprint information according to the agreed rules, and obtains a device fingerprint ID value through the hash algorithm; and the cloud device characteristic ID generated using the hash algorithm is used to indicate that the second server combines the information in the cloud device characteristic information according to the agreed rules, and obtains a cloud device characteristic ID value through the hash algorithm.

[0160] In this step, the second server can preprocess and encrypt the device running information corresponding to each user identifier, thereby obtaining the ciphertext data corresponding to each user identifier, which is beneficial to ensuring the security of the device running information in the transmission process.

[0161] It should be noted that a data processing module can be deployed in the second server, and the specific implementation form of the module can be a software development kit (Software Development Kit, SDK), a client or a web service, which is responsible for data preprocessing, data encryption and decryption, etc. Of course, data preprocessing and data encryption can also be performed by other means, which is not limited herein.

[0162] In step S703, the ciphertext data corresponding to each user identifier is sent to the first server.

[0163] The ciphertext data corresponding to each user identifier is used for the first server to determine target ciphertext data according to a target user identifier carried in the query request.

[0164] In this step, the second server can send the ciphertext data corresponding to each user identifier to the first server, so that the first server can determine target ciphertext data according to a target user identifier carried in the query request. In the data transmission process, ciphertext transmission is used, and therefore the security of the device running information in the transmission process is improved.

[0165] It should be noted that the specific implementation of each step in the embodiments of the present application can refer to the related content in the above embodiments, which will not be described here.

[0166] In the embodiments of the present application, the second server can better understand the device characteristics, network environment and behavior information of the user by obtaining the device running information, so as to improve the accuracy of the first server in obtaining the device running encrypted information. Further, the second server can encrypt the device running information corresponding to each user identifier, which is helpful to ensure the security of the device running information in the transmission process. The second server can send the ciphertext data corresponding to each user identifier to the first server, which is helpful to improve the security of the device running information in the transmission process.

[0167] Optionally, the second server can include but is not limited to a server where a cloud device service provider is located, a server where a device application operator is located. The cloud device identification method can also support white list / black list and other cooperation modes.

[0168] For example, the server where the cloud device service provider is located and the server where the device application operator is located share the user identifier lists of both parties to the first server in the form of ciphertext. By performing privacy intersection on the user identifiers, the intersection of the users of both parties can be obtained. In this way, both parties can quickly query the use of other device products of their own users, for example, whether a user of a certain device application is a cloud device user, whether a certain cloud device user has used a certain device application or other brand cloud device.

[0169] Further, the lists shared by both parties can also be blacklists or whitelists. For example, device application B finds that user C uses the application for abnormal or illegal transactions, and can share the user identifier and other information to the first server in the form of ciphertext. Other cloud device service providers and device application operators accessing the first server can take corresponding measures on the user C.

[0170] In summary, in the embodiments of the present application, through the cooperation between the cloud device service provider and the device application operator, the cloud device identification is realized without leaking the user privacy and business secrets, effectively improving the identification efficiency and accuracy of the cloud device, and effectively blocking the behavior of criminals using cloud devices to implement new-style electric fraud.

[0171] In one embodiment, based on the above-mentioned embodiments, Figure 8 For the flowchart of the cloud device identification method in another embodiment of the present application, for the first server 102, as shown in the figure, the method comprises the following steps. Figure 8 As shown in the figure, the method comprises the following steps.

[0172] Step S801, the first server obtains the ciphertext data corresponding to each user identifier from the second server.

[0173] Among them, the ciphertext data corresponding to the user identifier is used to indicate the device running encryption information corresponding to the user identifier.

[0174] Correspondingly, the second server obtains the device running information corresponding to each user identifier, and encrypts the device running information corresponding to each user identifier, and sends the ciphertext data corresponding to each user identifier to the first server.

[0175] Step S802, the first server stores the ciphertext data corresponding to each user identifier to the preset ciphertext database.

[0176] Step S803, the first server receives the query request sent by the query device, and obtains the target ciphertext data from the preset ciphertext database according to the target user identifier and the query condition type.

[0177] Among them, the query request includes query condition type and target user identifier; the target ciphertext data is used to indicate the device running encryption information of the target device corresponding to the target user identifier; the device running encryption information includes at least one of the following information: device fingerprint encryption information, cloud device feature encryption information, network environment encryption information, operation encryption information, user behavior encryption information.

[0178] Correspondingly, the query device determines the query request corresponding to the business requirement according to the business requirement, and sends the query request to the first server.

[0179] Step S804, the first server performs privacy calculation processing on the target ciphertext data and the preset cloud device ciphertext data set, and obtains the target identification result.

[0180] Among them, the privacy calculation processing includes at least one of the following: privacy intersection processing, privacy query processing, joint statistical processing. The target encryption identification result is used to encrypt the indication of whether the target device is a cloud device.

[0181] Step S805, the first server encrypts the target recognition result to obtain a target encrypted recognition result.

[0182] Step S806, the first server sends the target encrypted recognition result to the query device.

[0183] Correspondingly, the query device receives the target encrypted recognition result and determines whether the target device is a cloud device according to the target encrypted recognition result.

[0184] It should be noted that the specific implementation of each step in the embodiments of the present application can refer to the related content in the above embodiments, which will not be repeated here.

[0185] In one embodiment, based on the above embodiments, Figure 9 For the flowchart of the cloud device identification method in another embodiment of the present application, for the query device 101, as shown in the figure, the method comprises the following steps. Figure 9

[0186] Step S901, the query device determines the target user identifier corresponding to the business requirement and / or the query condition type according to the business requirement.

[0187] Step S902, the query device determines the query request corresponding to the business requirement according to the target user identifier and / or the query condition type.

[0188] Step S903, the query device sends the query request to the first server.

[0189] Among them, the target user identifier corresponding to the target device to be identified is carried in the query request, and the target user identifier is used to instruct the first server to perform encrypted identification processing on the target ciphertext data to obtain a target encrypted recognition result in the case of determining the target ciphertext data according to the target user identifier, and send the target encrypted recognition result to the query device;

[0190] Correspondingly, the first server determines the target ciphertext data according to the target user identifier carried in the query request in the case of receiving the query request sent by the query device, and performs encrypted identification processing on the target ciphertext data to obtain a target encrypted recognition result. The first server sends the target encrypted recognition result to the query device.

[0191] Step S904, the query device receives the target encrypted recognition result and performs decryption processing on the target encrypted recognition result to obtain a target decrypted recognition result.

[0192] Among them, the target decrypted recognition result is used to indicate in plaintext whether the target device is a cloud device.

[0193] ​It should be noted that the specific implementation of each step in the embodiments of the present application can refer to the related content in the above embodiments, which will not be repeated here.

[0194] In one embodiment, on the basis of the above embodiments, Figure 10 For the flowchart of the cloud device identification method in another embodiment of the present application, for the second server 103, as shown in Figure 10 The method comprises the following steps.

[0195] Step S1001, the second server acquires device running information corresponding to each user identifier.

[0196] Step S1002, the second server encrypts the device running information corresponding to each user identifier to obtain ciphertext data corresponding to each user identifier.

[0197] Among them, the ciphertext data corresponding to the user identifier is used to indicate the device running encryption information corresponding to the user identifier;

[0198] Step S1003, the second server sends the ciphertext data corresponding to each user identifier to the first server.

[0199] Among them, the ciphertext data corresponding to each user identifier is used by the first server to determine target ciphertext data according to the target user identifier carried in the query request.

[0200] Correspondingly, the first server acquires the ciphertext data corresponding to each user identifier from the second server, and stores the ciphertext data corresponding to each user identifier into a preset ciphertext database.

[0201] It should be noted that the specific implementation of each step in the embodiments of the present application can refer to the related content in the above embodiments, which will not be repeated here.

[0202] In one embodiment, on the basis of the above embodiments, the present embodiment provides a whole flowchart of a cloud device identification method. Figure 11 For the whole flowchart of an exemplary cloud device identification method in one embodiment of the present application, Figure 1 , Figure 12 For the whole flowchart of another exemplary cloud device identification method in one embodiment of the present application, Figure 2 As shown in Figure 11 and Figure 12 The method comprises the following steps.

[0203] Step S1201, the second server acquires device running information corresponding to each user identifier.

[0204] The second server can include, but is not limited to, a server where a cloud device service provider is located, and a server where a device application operator is located.

[0205] In step S1202, the second server encrypts the device running information corresponding to each user identifier respectively to obtain ciphertext data corresponding to each user identifier respectively.

[0206] In step S1203, the second server sends the ciphertext data corresponding to each user identifier respectively to the first server.

[0207] In step S1204, the first server obtains the ciphertext data corresponding to each user identifier respectively from the second server.

[0208] In step S1205, the first server stores the ciphertext data corresponding to each user identifier respectively in a preset ciphertext database.

[0209] In step S1206, the query device determines a target user identifier and / or a query condition type corresponding to a business requirement according to the business requirement.

[0210] In step S1207, the query device determines a query request corresponding to the business requirement according to the target user identifier and / or the query condition type.

[0211] In step S1208, the query device sends the query request to the first server.

[0212] In step S1209, the first server obtains target ciphertext data from the preset ciphertext database according to the target user identifier and the query condition type, in a case where the query request sent by the query device is received.

[0213] In step S1210, the first server performs privacy calculation processing on the target ciphertext data and a preset cloud device ciphertext data set to obtain a target identification result.

[0214] In step S1211, the first server encrypts the target identification result to obtain a target encrypted identification result.

[0215] In step S1212, the first server sends the target encrypted identification result to the query device.

[0216] In step S1213, the query device receives the target encrypted identification result, and decrypts the target encrypted identification result to obtain a target decrypted identification result.

[0217] It should be noted that the specific implementation of each step in the embodiments of the present application can refer to the related content in the above embodiments, which will not be described here.

[0218] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps.

[0219] Based on the same inventive concept, this application also provides a cloud device identification apparatus for implementing the cloud device identification method described above. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, the specific limitations in one or more cloud device identification apparatus embodiments provided below can be found in the limitations of the cloud device identification method described above, and will not be repeated here.

[0220] In one embodiment, Figure 13 This is a schematic diagram of the structure of a cloud device identification device in one embodiment of this application. Figure 13 As shown, the cloud device identification device of this application embodiment can be applied to a first server. The cloud device identification device may include: a determining module 1301, an encrypted identification module 1302, and a sending module 1303. Wherein,

[0221] The determining module 1301 is used to determine the target encrypted data based on the target user identifier carried in the query request when a query request is received from the query device; wherein the target encrypted data is used to indicate the device operation encryption information of the target device corresponding to the target user identifier.

[0222] The encryption identification module 1302 is used to perform encryption identification processing on the target ciphertext data to obtain the target encryption identification result; wherein, the target encryption identification result is used to encrypt and indicate whether the target device is a cloud device;

[0223] The sending module 1303 is used to send the target encrypted identification result to the query device.

[0224] In one embodiment, the device operation encryption information includes at least one of the following: device fingerprint encryption information, cloud device feature encryption information, network environment encryption information, operation encryption information, and user behavior encryption information.

[0225] In one embodiment, the encryption identification module 1302 may include: a privacy computing unit and an encryption unit, wherein:

[0226] The privacy computing unit is used to perform privacy computing processing on the target ciphertext data to determine the target recognition result corresponding to the target ciphertext data.

[0227] The encryption unit is used to encrypt the target recognition result to obtain the encrypted target recognition result.

[0228] In one embodiment, the privacy computing unit is specifically used for:

[0229] The target encrypted data and the preset cloud device encrypted dataset are subjected to privacy computation processing to obtain the target recognition result; wherein, the privacy computation processing includes at least one of the following: privacy intersection processing, hidden query processing, and joint statistical processing.

[0230] In one embodiment, the query request further includes a query condition type, and the aforementioned determining module 1301 is specifically used for:

[0231] Based on the target user identifier and query condition type, retrieve the target encrypted data from the preset encrypted database.

[0232] In one embodiment, the cloud device identification device may further include: an acquisition module and a storage module, wherein,

[0233] The acquisition module is used to acquire the ciphertext data corresponding to each user identifier from the second server; wherein, the ciphertext data corresponding to the user identifier is used to instruct the device corresponding to the user identifier to run encrypted information;

[0234] The storage module is used to store the ciphertext data corresponding to each user identifier into a preset ciphertext database.

[0235] The cloud device identification device provided in this application embodiment can execute the technical solution of the first server in the above cloud device identification method embodiment. Its implementation principle and technical effect are similar, and will not be repeated here.

[0236] In one embodiment, Figure 14 This is a schematic diagram of the cloud device identification device in another embodiment of this application. Figure 14 As shown, the cloud device identification device of this application embodiment can be applied to a query device. The cloud device identification device may include: a first determining module 1401, a sending module 1402, a receiving module 1403, and a second determining module 1404. Wherein,

[0237] The first determining module 1401 is used to determine the query request corresponding to the business requirement based on the business requirements.

[0238] The sending module 1402 is used to send a query request to the first server; wherein the query request carries a target user identifier corresponding to the target device to be identified, and the target user identifier is used to instruct the first server to perform encryption identification processing on the target encrypted data based on the target user identifier to obtain the target encrypted identification result, and send the target encrypted identification result to the query device.

[0239] Receiver module 1403 is used to receive the target encryption identification result;

[0240] The second determining module 1404 is used to determine whether the target device is a cloud device based on the target encryption identification result.

[0241] In one embodiment, the second determining module 1404 is specifically used for:

[0242] The target encryption identification result is decrypted to obtain the target decryption identification result; the target decryption identification result is used to indicate in plaintext whether the target device is a cloud device.

[0243] In one embodiment, the first determining module 1401 is specifically used for:

[0244] Determine the target user identifier and / or query condition type corresponding to the business requirements based on business needs;

[0245] Determine the query request corresponding to the business requirement based on the target user identifier and / or query condition type.

[0246] The cloud device identification device provided in this application embodiment can execute the technical solution for querying devices in the above cloud device identification method embodiment. Its implementation principle and technical effect are similar, and will not be repeated here.

[0247] In one embodiment, Figure 15 This is a schematic diagram of the cloud device identification device in another embodiment of this application. Figure 15 As shown, the cloud device identification device of this application embodiment can be applied to a second server. The cloud device identification device may include: an acquisition module 1501, an encryption module 1502, and a sending module 1503. Wherein,

[0248] The acquisition module 1501 is used to acquire the device operation information corresponding to each user identifier;

[0249] The encryption module 1502 is used to encrypt the device operation information corresponding to each user identifier to obtain ciphertext data corresponding to each user identifier; wherein, the ciphertext data corresponding to the user identifier is used to indicate the encrypted device operation information corresponding to the user identifier.

[0250] The sending module 1503 is configured to send the ciphertext data corresponding to each user identifier to the first server, wherein the ciphertext data corresponding to each user identifier is used to instruct the first server to determine target ciphertext data according to a target user identifier carried in the query request.

[0251] The cloud device identification apparatus provided by the embodiments of the present application can execute the technical solutions about the second server in the cloud device identification method embodiments, and the implementation principles and technical effects are similar, and thus are not described herein.

[0252] The modules in the cloud device identification apparatus can be all or partially implemented by software, hardware, or a combination thereof. The modules can be embedded in or independent of a processor in the cloud device identification apparatus in a hardware form, or stored in a memory in the cloud device identification apparatus in a software form, so as to be called and executed by the processor to execute the operations corresponding to the modules.

[0253] In an exemplary embodiment, Figure 16 FIG. 1 is a schematic structural diagram of a cloud device identification apparatus according to an embodiment of the present application. As shown in FIG. 1, the cloud device identification apparatus can include but is not limited to a first server, a second server, and a query device. The cloud device identification apparatus includes a processor, a memory, an input / output interface, and a communication interface. The processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the cloud device identification apparatus is configured to provide computing and control capabilities. The memory of the cloud device identification apparatus includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The input / output interface of the cloud device identification apparatus is configured to exchange information between the processor and external devices. The database of the cloud device identification apparatus is configured to store information such as a query request, target ciphertext data, and a target encryption identification result. The input / output interface of the cloud device identification apparatus is configured to exchange information between the processor and external devices. The communication interface of the cloud device identification apparatus is configured to communicate with external devices through a network connection. The computer program is executed by the processor to implement the cloud device identification method provided by the embodiments of the present application.

[0254] Those skilled in the art can understand that Figure 16 The structure shown in FIG. 1 is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the cloud device identification apparatus to which the scheme of the present application is applied. Specifically, the cloud device identification apparatus can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0255] In an embodiment, a cloud device identification device is provided, comprising a memory and a processor, the memory storing a computer program, and the processor implementing the technical solutions of the first server, the second server or the query device in the cloud device identification method embodiments of the present application when executing the computer program, which have similar implementation principles and technical effects, and will not be described here.

[0256] In an embodiment, a computer readable storage medium is provided, storing a computer program, and the computer program is executed by a processor to implement the technical solutions of the first server, the second server or the query device in the cloud device identification method embodiments of the present application, which have similar implementation principles and technical effects, and will not be described here.

[0257] In an embodiment, a computer program product is provided, comprising a computer program, and the computer program is executed by a processor to implement the technical solutions of the first server, the second server or the query device in the cloud device identification method embodiments of the present application, which have similar implementation principles and technical effects, and will not be described here.

[0258] It should be noted that the file information and user data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant regulations.

[0259] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by a computer program instructing relevant hardware. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of each method can be included. Any reference to memory, database or other medium used in each embodiment provided by the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in each embodiment provided by the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in each embodiment provided by the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.

[0260] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of each technical feature in the above embodiments are not described, however, as long as the combination of the technical features does not exist, it should be considered as the scope of the present application.

[0261] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A cloud device identification method, characterized by, The method is applied to a first server, and the method comprises: In a case where a query request sent by a query device is received, target ciphertext data is determined according to a target user identifier carried in the query request; wherein the target ciphertext data is used to indicate device running encryption information of a target device corresponding to the target user identifier; The target ciphertext data is subjected to encryption identification processing to obtain a target encryption identification result; wherein the target encryption identification result is used to encrypt an indication of whether the target device is a cloud device; The target encryption identification result is sent to the query device; The target ciphertext data is subjected to encryption identification processing to obtain a target encryption identification result, comprising: the target ciphertext data is subjected to privacy calculation processing to determine a target identification result corresponding to the target ciphertext data; the target identification result is subjected to encryption processing to obtain the target encryption identification result; The target ciphertext data is subjected to privacy calculation processing to determine a target identification result corresponding to the target ciphertext data, comprising: the target ciphertext data and a preset cloud device ciphertext data set are subjected to privacy calculation processing to obtain the target identification result; wherein the privacy calculation processing comprises at least one of the following: privacy intersection processing, privacy query processing, and joint statistical processing.

2. The method of claim 1, wherein, The device running encryption information comprises at least one of the following information: device fingerprint encryption information, cloud device feature encryption information, network environment encryption information, operation encryption information, and user behavior encryption information.

3. The method according to any one of claims 1-2, characterized in that, The query request further comprises a query condition type, and the target ciphertext data is determined according to the target user identifier carried in the query request, comprising: The target ciphertext data is obtained from a preset ciphertext database according to the target user identifier and the query condition type.

4. The method of claim 3, wherein, The method further comprises: Ciphertext data corresponding to each user identifier is obtained from a second server; wherein the ciphertext data corresponding to the user identifier is used to indicate device running encryption information corresponding to the user identifier; The ciphertext data corresponding to each user identifier is stored in the preset ciphertext database.

5. A cloud device identification method, characterized by, The method is applied to a query device, and the method comprises: According to a business requirement, a query request corresponding to the business requirement is determined; The query request is sent to a first server; wherein the query request carries a target user identifier corresponding to the target device to be identified, the target user identifier being used to instruct the first server, when determining the target encrypted data based on the target user identifier, to perform encrypted identification processing on the target encrypted data to obtain a target encrypted identification result, and to send the target encrypted identification result to the query device; wherein the first server performs encrypted identification processing on the target encrypted data to obtain a target encrypted identification result, including: performing privacy calculation processing on the target encrypted data to determine the target identification result corresponding to the target encrypted data, and then encrypting the target identification result to obtain the target encrypted identification result; wherein the first server performs privacy calculation processing on the target encrypted data to determine the target identification result corresponding to the target encrypted data, including: performing privacy calculation processing on the target encrypted data and a preset cloud device encrypted dataset to obtain the target identification result, wherein the privacy calculation processing includes at least one of the following: privacy intersection processing, hidden query processing, and joint statistical processing; Receive the target encryption identification result, and determine whether the target device is a cloud device based on the target encryption identification result.

6. The method of claim 5, wherein, The step of determining whether the target device is a cloud device based on the target encryption identification result includes: The target encryption identification result is decrypted to obtain the target decryption identification result; wherein, the target decryption identification result is used to indicate in plaintext whether the target device is a cloud device.

7. The method according to claim 5 or 6, characterized in that, The step of determining the query request corresponding to the business requirement based on the business requirements includes: Determine the target user identifier and / or query condition type corresponding to the business requirements based on the business requirements; Based on the target user identifier and / or query condition type, determine the query request corresponding to the business requirement.

8. A cloud device identification method, characterized by, The method is applied to a second server, and the method includes: Obtain the device operation information corresponding to each user identifier; The device operation information corresponding to each user identifier is encrypted to obtain ciphertext data corresponding to each user identifier; wherein, the ciphertext data corresponding to the user identifier is used to indicate the encrypted device operation information corresponding to the user identifier; The encrypted data corresponding to each of the user identifiers is sent to the first server; wherein, the encrypted data corresponding to each of the user identifiers is used by the first server to determine target encrypted data based on the target user identifier carried in the query request, and to perform encrypted recognition processing on the target encrypted data to obtain a target encrypted recognition result; wherein, the first server performs encrypted recognition processing on the target encrypted data to obtain a target encrypted recognition result, including: performing privacy calculation processing on the target encrypted data to determine the target recognition result corresponding to the target encrypted data, and then encrypting the target recognition result to obtain the target encrypted recognition result; wherein, the first server performs privacy calculation processing on the target encrypted data to determine the target recognition result corresponding to the target encrypted data, including: performing privacy calculation processing on the target encrypted data and a preset cloud device encrypted dataset to obtain the target recognition result, wherein the privacy calculation processing includes at least one of the following: privacy intersection processing, hidden query processing, and joint statistical processing.

9. A cloud device identification apparatus, characterized by, The device is applied to a first server, and the device includes: The determination module is used to determine target encrypted data based on the target user identifier carried in the query request when a query request is received from the query device; wherein the target encrypted data is used to indicate the device operation encryption information of the target device corresponding to the target user identifier; An encryption identification module is used to perform encryption identification processing on the target encrypted data to obtain a target encryption identification result; wherein, the target encryption identification result is used to encrypt and indicate whether the target device is a cloud device; The sending module is used to send the encrypted identification result of the target to the query device; The encrypted identification module includes: a privacy calculation unit, used to perform privacy calculation processing on the target ciphertext data to determine the target identification result corresponding to the target ciphertext data; and an encryption unit, used to encrypt the target identification result to obtain the target encrypted identification result. The privacy computing unit is specifically used to: perform privacy computing processing on the target encrypted data and the preset cloud device encrypted dataset to obtain the target identification result; wherein, the privacy computing processing includes at least one of the following: privacy intersection processing, hidden query processing, and joint statistical processing.

10. A cloud device identification apparatus, comprising: The device is used in a query device, and the device includes: The first determining module is used to determine the query request corresponding to the business requirement based on the business requirements. A sending module is configured to send the query request to a first server; wherein the query request carries a target user identifier corresponding to the target device to be identified, and the target identifier instructs the first server, when determining the target encrypted data based on the target user identifier, to perform encrypted identification processing on the target encrypted data to obtain a target encrypted identification result, and to send the target encrypted identification result to the query device; wherein the first server performs encrypted identification processing on the target encrypted data to obtain a target encrypted identification result, including: performing privacy calculation processing on the target encrypted data to determine the target identification result corresponding to the target encrypted data, and then encrypting the target identification result to obtain the target encrypted identification result; wherein the first server performs privacy calculation processing on the target encrypted data to determine the target identification result corresponding to the target encrypted data, including: performing privacy calculation processing on the target encrypted data and a preset cloud device encrypted dataset to obtain the target identification result, wherein the privacy calculation processing includes at least one of the following: privacy intersection processing, hidden query processing, and joint statistical processing; The receiving module is used to receive the target encrypted identification result; The second determining module is used to determine whether the target device is a cloud device based on the target encryption identification result.

11. A cloud device identification apparatus, comprising: The device is used in a second server, and the device includes: The acquisition module is used to acquire the device operation information corresponding to each user identifier. An encryption module is used to encrypt the device operation information corresponding to each of the user identifiers to obtain ciphertext data corresponding to each of the user identifiers; wherein, the ciphertext data corresponding to the user identifier is used to indicate the encrypted device operation information corresponding to the user identifier. A sending module is used to send the encrypted data corresponding to each of the user identifiers to a first server; wherein the encrypted data corresponding to each of the user identifiers is used to instruct the first server to determine the target encrypted data according to the target user identifier carried in the query request, and to perform encryption recognition processing on the target encrypted data to obtain the target encrypted recognition result; wherein the first server performs encryption recognition processing on the target encrypted data to obtain the target encrypted recognition result, including: performing privacy calculation processing on the target encrypted data to determine the target recognition result corresponding to the target encrypted data, and then encrypting the target recognition result to obtain the target encrypted recognition result; wherein the first server performs privacy calculation processing on the target encrypted data to determine the target recognition result corresponding to the target encrypted data, including: performing privacy calculation processing on the target encrypted data and a preset cloud device encrypted dataset to obtain the target recognition result, wherein the privacy calculation processing includes at least one of the following: privacy intersection processing, hidden query processing, and joint statistical processing.

12. A cloud device identification device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 8.

13. A computer readable storage medium having stored thereon a computer program, characterized in that When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 8.

14. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Privacy protection equipment identification model design and use method based on homomorphic encryption

    CN111984960A

  • Information processing method and device, equipment and medium

    CN115442117A