Terminal device verification method, device, electronic device and storage medium
By obtaining the target files and device fingerprints in the terminal device memory and combining them with precise checksum features at the byte level, the problem of traditional methods that make it difficult to identify customized operating systems is solved, achieving higher security verification accuracy.
Patent Information
- Application Number
- CN202411620782.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-13
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2044-11-13
AI Technical Summary
Traditional forensic methods are unable to effectively identify and track deeply customized and optimized operating systems, leading to network security threats and damage to user rights.
By obtaining the target file and device fingerprint in the terminal device memory, combined with the precise checksum features at the byte level, the checksum features are sent to the server for security verification.
Improved sensitivity to custom operating system modifications, avoiding issues with incomplete and inaccurate logs, and achieving higher security verification accuracy.
Smart Images

Figure CN119622697B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of terminal security management technology, specifically to the field of device fingerprint and data identification, and more particularly to a terminal device verification method, device, electronic device, and storage medium. Background Art
[0002] With the rapid development of technology, customized operating systems are increasingly used in specific devices, but this also provides criminals with a means to tamper with device information and circumvent security detection. Customized operating systems may evade supervision and rounding by modifying core files, hiding key information, and changing device identifiers. Traditional forensic methods are often difficult to effectively identify and track deeply customized and optimized operating systems, which not only poses a serious threat to network security, but also greatly damages user rights. Summary of the Invention
[0003] The present disclosure provides a terminal device verification method, apparatus, electronic device, and storage medium.
[0004] According to one aspect of the present disclosure, a method for verifying a terminal device is provided, comprising:
[0005] Obtaining a target file in a memory of a terminal device, and determining a first checksum feature of the terminal device based on the target file;
[0006] Obtaining a first device fingerprint of the terminal device;
[0007] The first checksum feature and the first device fingerprint are sent to a server, where the first checksum feature and the first device fingerprint are used to perform security verification on the terminal device.
[0008] According to another aspect of the present disclosure, another terminal device verification method is provided, including:
[0009] Receiving a first checksum feature of a terminal device sent by a client, where the first checksum feature is related to a target file in a memory of the terminal device to be identified;
[0010] Receiving a first device fingerprint of the terminal device sent by the client;
[0011] Perform security verification on the operating system of the terminal device based on the first checksum feature and the first device fingerprint.
[0012] According to a third aspect of the present disclosure, there is provided a verification apparatus for a terminal device, comprising:
[0013] A first acquisition module is configured to acquire a target file in a memory of a terminal device and determine a first checksum feature of the terminal device based on the target file;
[0014] A second acquisition module is used to obtain a first device fingerprint of the terminal device;
[0015] A sending module is used to send the first checksum feature and the first device fingerprint to the server, where the first checksum feature and the first device fingerprint are used to perform security verification on the terminal device.
[0016] According to a fourth aspect of the present disclosure, another verification apparatus for a terminal device is provided, comprising:
[0017] A first receiving module is configured to receive a first checksum feature of a terminal device sent by a client, where the first checksum feature is related to a target file in a memory of the terminal device to be identified;
[0018] A second receiving module is configured to receive a first device fingerprint of the terminal device sent by the client;
[0019] A verification module is used to perform security verification on the operating system of the terminal device based on the first checksum feature and the first device fingerprint.
[0020] According to a fifth aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method described in the first aspect or the second aspect embodiment.
[0021] According to a sixth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable the computer to execute the method described in the first aspect or the second aspect embodiment.
[0022] According to a seventh aspect of the present disclosure, a computer program product is provided, comprising a computer program, which implements the steps of the method described in the first aspect or the second aspect when executed by a processor.
[0023] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The accompanying drawings are used to better understand the present invention and do not constitute a limitation of the present invention.
[0025] Figure 1 This is an illustration of a terminal device verification method provided by an embodiment of the present disclosure;
[0026] Figure 2 is a schematic diagram of another terminal device verification method provided by an embodiment of the present disclosure;
[0027] Figure 3 is a schematic diagram of another terminal device verification method provided by an embodiment of the present disclosure;
[0028] Figure 4 is a schematic diagram of another terminal device verification method provided by an embodiment of the present disclosure;
[0029] Figure 5 This is a logic diagram of a terminal device verification method provided by an embodiment of the present disclosure;
[0030] Figure 6 This is a structural block diagram of a verification device for a terminal device provided by an embodiment of the present disclosure;
[0031] Figure 7 This is a structural block diagram of another terminal device verification device provided by an embodiment of the present disclosure
[0032] Figure 8 is a schematic block diagram of an electronic device for implementing an embodiment of the present disclosure. DETAILED DESCRIPTION
[0033] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0034] Mobile Internet, which combines mobile communications and the Internet, is a general term for the combination and practice of Internet technology, platforms, business models and applications with mobile communication technology. It inherits the advantages of mobile anytime, anywhere and portable and the openness, sharing and interaction of the Internet.
[0035] Endpoint Security Management is the comprehensive security management and protection of terminal devices (such as computers, printers, cameras, laptops, etc.), aiming to protect users' terminal devices and data from unauthorized access, destruction, theft, etc., and ensure the security of users' data.
[0036] Device Fingerprint refers to a technology that collects characteristic attribute information of client devices, encrypts it and uploads it to the cloud, and then generates a unique device ID for each device through background algorithm analysis to identify the device.
[0037] Data Recognition refers to the process of extracting and identifying required information from various data sources through specific technical means. There are two main types of data recognition: direct recognition and indirect recognition. It also includes optical character recognition technology, which can convert images or scanned documents into editable text or searchable text, thereby realizing automated data processing and analysis.
[0038] Figure 1 FIG. 1 is a schematic diagram of a terminal device verification method provided by an embodiment of the present disclosure; as shown in the figure, the method includes:
[0039] S101, obtaining a target file in a memory of a terminal device, and determining a first checksum feature of the terminal device according to the target file.
[0040] Optionally, the terminal device can be a computer, printer, smart phone or laptop computer and other devices. This embodiment takes the terminal device of the Android system as an example to obtain the target file in the memory of the terminal device. The target file can be an optimized executable file (Optimized Dalvik Executable, ODEX) file. The ODEX file is an executable file extracted from the application on Android. The location of the ODEX file in the memory can be determined through the relevant entry index to obtain the target file.
[0041] In some implementations, the target file may include the first checksum feature of the terminal device. The content of the target file in the memory is read and parsed to obtain the first checksum feature therein, that is, the first checksum feature of the current terminal device can be parsed from the ODEX file.
[0042] The first checksum feature is a checksum feature composed of several character strings, which can be used to calculate the checksum of the Android core library file, and can also be used to check whether the Android core library file has been tampered with; considering that when the terminal device is making customized operating system modifications, the internal core files, framework layer files and extended service files may all change, and the first checksum feature is used to perform precise byte-level verification, which has a high sensitivity to modifications to the customized operating system and can be used to accurately determine whether the operating system of the mobile device has been modified.
[0043] S102: Obtain a first device fingerprint of the terminal device.
[0044] A device fingerprint refers to a device feature or unique device identifier that can be used to uniquely identify the device, including the device's hardware identity document (ID), serial number, production ID, and other inherent and difficult-to-tamper unique identifiers.
[0045] The first device fingerprint of a terminal device can be constructed based on the system characteristic attribute value, and a terminal device with a customized operating system will allow users or developers to modify the underlying attribute values of the system. The acquisition of the first device fingerprint depends on the acquisition of the system attribute value. Therefore, any customization of the operating system may cause changes in the device fingerprint. It is difficult to accurately verify the security of the terminal device only through the first device fingerprint.
[0046] S103: Send a first checksum feature and a first device fingerprint to the server, where the first checksum feature and the first device fingerprint are used to perform security verification on the terminal device.
[0047] It can be understood that the first checksum feature and the first device fingerprint can be collected by the client, and the client can be a software application installed on the terminal device for providing local services; after the client collects the first checksum feature and the first device fingerprint of the terminal device, they are sent to the server for security verification, and the first checksum feature is added to perform security verification of the terminal device, thereby avoiding malicious users or attackers forging device fingerprints and bypassing the security verification mechanism based on device fingerprints.
[0048] In this embodiment, the client obtains the first checksum feature and the first device fingerprint in the terminal device, and sends the first checksum feature and the first device fingerprint to the server for security verification. Combined with the byte-level precise verification of the first checksum feature, it has extremely high sensitivity to modifications to the customized operating system, avoiding the problem of incomplete and inaccurate logs caused by deep modifications to the terminal device by the customized operating system, and solving the problem of low accuracy of security verification relying solely on device fingerprints. Through the first checksum feature and the first device fingerprint, it can be easily determined whether the operating system of the terminal device has been maliciously modified, and the security verification effect is better.
[0049] Figure 2 is a schematic diagram of another terminal device verification method provided by an embodiment of the present disclosure; Figure 2 As shown, the method includes:
[0050] S201, obtaining a target file in the memory of a terminal device.
[0051] Optionally, a memory-mapped file of a terminal device can be obtained; the memory-mapped file is read to obtain entry information of a target file; the memory is read based on the entry information to obtain the target file; a memory-mapped file is a technology that allows the contents of a file to be mapped to the address space of a process, that is, the contents of a file can be directly accessed as a data block in memory, which can significantly improve the file access speed; the memory-mapped file of a terminal device is read to obtain one or more entry information in the memory-mapped file, and the required specific entry is found from the entry information of the target file. For example, if an ODEX file needs to be found, the corresponding entry can be determined based on the known file name, and the data in the memory is read based on the entry information to obtain the target file, which includes data information of data types such as strings or numbers.
[0052] S202: parse the target file content and obtain a first checksum feature based on the parsed content.
[0053] It can be understood that the target file includes the first checksum feature, so the first checksum feature is obtained by parsing the content of the target file. Compared with the detection method of the existing technology, the computational complexity is small and it is directly obtained from the memory file, so the feature is not easily tampered with.
[0054] S203: Collect system attribute information of the operating system of the terminal device, and generate a first device fingerprint based on the system attribute information.
[0055] Optionally, the device fingerprint can be generated by collecting the system attribute information of the terminal device's operating system and encrypting it and uploading it to the cloud. Through background algorithm analysis, a unique device ID is generated for each terminal device to identify the device, which serves as the first device fingerprint of the terminal device, thereby improving the credibility of security verification based on device fingerprints.
[0056] Optionally, the system attribute information of the operating system may include hardware information, operating system information, network information, etc.; hardware information such as physical characteristics of devices such as memory, storage, and central processing unit, operating system information such as operating system version, language, and time zone, network information such as Internet Protocol (IP) address and Domain Name System (DNS) settings, etc.
[0057] S204: Send a first checksum feature and a first device fingerprint to the server, where the first checksum feature and the first device fingerprint are used to perform security verification on the terminal device.
[0058] In some implementations, a second device fingerprint of the terminal device can also be obtained and sent to the server. The second device fingerprint is used to build a device fingerprint library. The second device fingerprint can be the device fingerprint corresponding to different terminal devices to ensure that the device fingerprint library includes diverse second device fingerprints, thereby performing reliable comparison of device fingerprints.
[0059] In some implementations, a second checksum feature of the terminal device can also be obtained and sent to the server. The second checksum feature is used to construct a checksum feature library. The second checksum feature can be a checksum feature corresponding to different terminal devices to ensure that the checksum feature library includes diverse second checksum features, thereby performing reliable comparison of the checksum features.
[0060] In this embodiment, by directly reading the device feature information from the memory, security is greatly improved, preventing malicious users from modifying the log files through other means, and the checksum feature does not exist in the system properties and is difficult to tamper with, thereby improving the accuracy of security verification; and the second checksum feature and the second device fingerprint of different devices can also be collected to construct a checksum feature library and a device fingerprint library for comparative verification. It is suitable for all mainstream terminal devices, has extremely high sensitivity to modifications to customized operating systems, and has better security verification effects.
[0061] Figure 3 is a schematic diagram of another terminal device verification method provided by an embodiment of the present disclosure; Figure 3 As shown, the method includes:
[0062] S301: Receive a first checksum characteristic of a terminal device sent by a client.
[0063] The first checksum feature is related to the target file in the memory of the terminal device to be identified, and can be used to check whether the system core library file has been tampered with.
[0064] S302: Receive a first device fingerprint of a terminal device sent by a client.
[0065] The first device fingerprint can be obtained based on the system attribute value, covering important information such as the brand, model, hardware identification, system version, etc. of the terminal device.
[0066] S303: Perform security verification on the operating system of the terminal device according to the first checksum feature and the first device fingerprint.
[0067] In some implementations, the first checksum feature can be compared with the checksum feature set, and the first device fingerprint can be compared with the fingerprint feature set; the checksum feature set and the fingerprint feature set respectively include checksum features and device fingerprints corresponding to different terminal devices. When the first checksum feature and the first device fingerprint respectively match the consistent checksum feature and device fingerprint in the corresponding checksum feature set and fingerprint feature set, it is determined that the operating system of the terminal device is secure and the terminal device is a normal device.
[0068] It can be understood that if the first checksum feature does not have a consistent checksum feature in the checksum feature set, and / or the first device fingerprint does not have a consistent device fingerprint in the fingerprint feature set, it is determined that the operating system of the terminal device is unsafe and the terminal device is an abnormal device.
[0069] In this embodiment, the server receives the first checksum feature and the first device fingerprint sent by the client, and performs security verification of the operating system of the terminal device based on the first checksum feature and the first device fingerprint, thereby solving the problem of low accuracy of security verification based solely on the device fingerprint. Through the first checksum feature and the first device fingerprint, it can be easily determined whether the operating system of the terminal device has been maliciously modified. Combined with the byte-level precise verification of the first checksum feature, it has extremely high sensitivity to modifications to the customized operating system, and the security verification effect is better.
[0070] Figure 4 is a schematic diagram of another terminal device verification method provided by an embodiment of the present disclosure; Figure 4 As shown, the method includes:
[0071] S401: Receive a first checksum feature of a terminal device sent by a client.
[0072] In the embodiment of the present disclosure, the implementation method of step S401 can be implemented by using any of the methods in the embodiments of the present disclosure, which is not limited here and will not be described in detail.
[0073] S402: Receive a first device fingerprint of a terminal device sent by a client.
[0074] In the embodiment of the present disclosure, the implementation method of step S402 can be implemented by using any of the methods in the embodiments of the present disclosure, which is not limited here and will not be described in detail.
[0075] S403: Obtain a pre-built checksum feature library and device fingerprint library.
[0076] Optionally, the second checksum characteristics of different terminal devices sent by the client can be received, and a checksum characteristic library can be constructed based on the second checksum characteristics; the second device fingerprints of different terminal devices sent by the client can be received, and a device fingerprint library can be constructed based on the second device fingerprint; that is, the second checksum characteristics and second device fingerprints of different terminal devices sent by the client can be received, and a checksum characteristic library and a device fingerprint library can be constructed respectively according to the second checksum characteristics and the second device fingerprint, so as to facilitate the identification and verification of the first checksum characteristics and the first device fingerprint obtained in real time.
[0077] S404: Match the first checksum feature with the checksum feature library to obtain a first matching result.
[0078] In some implementations, a checksum feature library may be searched to determine whether there is a checksum feature that is consistent with the first checksum feature, thereby obtaining a first matching result. The first matching result includes whether there is a consistent checksum feature and whether there is no consistent checksum feature.
[0079] S405: Match the first device fingerprint with the device fingerprint library to obtain a second matching result.
[0080] In some implementations, a device fingerprint library may be searched for a device fingerprint that is consistent with the first device fingerprint, thereby obtaining a second matching result, which includes whether a consistent device fingerprint exists and whether a consistent device fingerprint does not exist.
[0081] S406: Perform security verification on the operating system of the terminal device to be identified based on the first matching result and the second matching result.
[0082] In some implementations, in response to the first checksum characteristic being identical to one of the second checksum characteristics and the first device fingerprint being identical to one of the second device fingerprints, it is determined that the operating system of the terminal device is secure.
[0083] In some implementations, in response to the first checksum feature being different from each second checksum feature, and / or the first device fingerprint being different from each second device fingerprint, it is determined that the operating system of the terminal device is abnormal, thereby improving the security verification effect.
[0084] Optionally, the second checksum feature and the second device fingerprint of the terminal device can also be used to identify the operating system of the terminal device; the device fingerprint can cover important information such as the brand, model, hardware identification and system version of the device. The checksum feature can be used to verify whether the system core library file has been tampered with. The second checksum feature and the second device fingerprint of the terminal device are used to identify the operating system of the terminal device and used as the identity ID of the operating system. It is suitable for multi-version terminal devices.
[0085] In some implementations, one object in the device fingerprint and checksum feature can be used as the primary key, and different terminal devices can be verified based on the primary key to obtain first device information that passes the primary key verification and second device information that fails the primary key verification; another object in the device fingerprint and checksum feature can be used as the secondary key, and the terminal device associated with the second device information can be verified based on the secondary key to obtain third device information that passes the secondary key verification and fourth device information that fails the secondary key verification; wherein the device information includes the device model and version information of the terminal device.
[0086] As an example, the device fingerprint is used as the primary key, and the checksum feature is used as the secondary key. Different terminal devices are verified based on the primary key, that is, different terminal devices are verified based on the device fingerprint, and the first device information that passes the device fingerprint verification and the second device information that fails the device fingerprint verification are determined; the terminal device associated with the second device information is verified based on the secondary key, that is, the checksum feature of the terminal device in the second device information is verified, that is, the scenario that the device fingerprint information cannot cover is identified, and the incremental value of adding the checksum feature for verification can be determined, and the third device information that passes the checksum feature verification and the fourth device information that fails the checksum feature verification can be determined. Combining the checksum feature and the device fingerprint can expand the recognition range of the terminal device operating system.
[0087] Furthermore, the number of first devices associated with the first device information and the number of second devices associated with the second device information can be obtained; the number of third devices associated with the third device information and the number of fourth devices associated with the fourth device information can be obtained; and based on the number of first devices and the number of second devices, as well as the number of third devices and the number of fourth devices, the verification coverage of device fingerprints and checksum features can be obtained.
[0088] It can be understood that, taking the primary key as the device fingerprint as an example, the first device number is the number of devices that have passed the device fingerprint verification, and the second device number is the number of devices that have not passed the device fingerprint verification. Therefore, the verification coverage of the device fingerprint can be determined based on the first device number and the second device number. For example, the sum of the first device number and the second device number is obtained, and the ratio of the first device number to the sum is used as the verification coverage of the device fingerprint; accordingly, the third device number is the number of devices that have passed the checksum feature verification, and the fourth device number is the number of devices that have not passed the checksum feature verification. Therefore, the sum of the third device number and the fourth device number can be calculated, and the ratio of the third device number to the sum is used as the verification coverage of the checksum feature, so the incremental effect of security verification can be intuitively determined.
[0089] like Figure 5As shown, it shows a logic diagram of a verification method for a terminal device, by obtaining the checksum feature and the device fingerprint, and comparing them with the cloud library, that is, the checksum feature library and the device fingerprint library in this embodiment, the terminal device is determined to be a normal device or an abnormal device through the comparison result; at the same time, the incremental value and incremental effect of verification based on the device fingerprint combined with the checksum feature can be obtained, and the verification coverage rate can also be determined by verifying the checksum feature in devices that are not covered by the device fingerprint, so as to expand the terminal device recognition range and improve the security recognition effect of the terminal device.
[0090] In this embodiment, after receiving the first checksum feature and the first device fingerprint, matching and identification are performed based on the pre-built checksum feature library and device fingerprint library to obtain a first matching result and a second matching result. Then, based on whether there are consistent checksum features and device fingerprints between the first matching result and the second matching result, it is determined whether the operating system of the current terminal device is safe. Compared with the judgment based on the device fingerprint alone, the security verification effect is better; further, the second checksum feature and the second device fingerprint can be used as the identification of the terminal device, and the verification results when the checksum feature and the device fingerprint are used as primary keys can be compared to obtain the verification coverage of the checksum feature and the device fingerprint. It can also be determined that the incremental value after adding the checksum feature is expanded to expand the recognition range of the terminal device operating system. The combined verification is based on the checksum feature and the device fingerprint with a smaller data volume, which greatly reduces the data volume, saves computing resources and ensures the accuracy of the verification.
[0091] Figure 6 is a structural block diagram of a verification device for a terminal device provided by an embodiment of the present disclosure; Figure 6 As shown, the verification device 600 of the terminal device includes:
[0092] A first acquisition module 601 is configured to acquire a target file in a memory of a terminal device and determine a first checksum feature of the terminal device based on the target file;
[0093] A second acquisition module 602 is configured to acquire a first device fingerprint of a terminal device;
[0094] The sending module 603 is used to send the first checksum feature and the first device fingerprint to the server, where the first checksum feature and the first device fingerprint are used to perform security verification on the terminal device.
[0095] In some implementations, the first acquisition module 601 includes:
[0096] Get the memory mapping file of the terminal device;
[0097] Read the memory-mapped file to obtain the entry information of the target file;
[0098] Read the memory based on the entry information to obtain the target file.
[0099] In some implementations, the first acquisition module 601 includes:
[0100] The target file is parsed for content, and a first checksum feature is obtained based on the parsed content.
[0101] In some implementations, the second obtaining module 602 includes:
[0102] Collect system attribute information of the operating system of the terminal device, and generate a first device fingerprint based on the system attribute information.
[0103] In some implementations, the apparatus 600 further includes:
[0104] The second device fingerprint of the terminal device is obtained and sent to the server, where the second device fingerprint is used to construct a device fingerprint library.
[0105] In some implementations, the apparatus 600 further includes:
[0106] A second checksum feature of the terminal device is obtained and sent to the server. The second checksum feature is used to construct a checksum feature library.
[0107] In this embodiment, the client obtains the first checksum feature and the first device fingerprint in the terminal device, and sends the first checksum feature and the first device fingerprint to the server for security verification. Combined with the byte-level precise verification of the first checksum feature, it has extremely high sensitivity to modifications to the customized operating system, avoiding the problem of incomplete and inaccurate logs caused by deep modifications to the terminal device by the customized operating system, and solving the problem of low accuracy of security verification relying solely on device fingerprints. Through the first checksum feature and the first device fingerprint, it can be easily determined whether the operating system of the terminal device has been maliciously modified, and the security verification effect is better.
[0108] Figure 7 is a structural block diagram of another verification device for a terminal device provided by an embodiment of the present disclosure; Figure 7 As shown, the verification device 700 of the terminal device includes:
[0109] A first receiving module 701 is configured to receive a first checksum characteristic of a terminal device sent by a client, where the first checksum characteristic is related to a target file in a memory of the terminal device to be identified;
[0110] The second receiving module 702 is configured to receive a first device fingerprint of a terminal device sent by a client;
[0111] The verification module 703 is used to perform security verification on the operating system of the terminal device according to the first checksum feature and the first device fingerprint.
[0112] In some implementations, the verification module 703 further includes:
[0113] receiving second checksum features of different terminal devices sent by the client, and building a checksum feature library based on the second checksum features;
[0114] Receive second device fingerprints of different terminal devices sent by the client, and build a device fingerprint library based on the second device fingerprints.
[0115] In some implementations, the verification module 703 includes:
[0116] Get pre-built checksum signature libraries and device fingerprint libraries;
[0117] Matching the first checksum feature with the checksum feature library to obtain a first matching result;
[0118] Matching the first device fingerprint with the device fingerprint library to obtain a second matching result;
[0119] The operating system of the terminal device to be identified is securely identified according to the first matching result and the second matching result.
[0120] In some implementations, the verification module 703 includes:
[0121] In response to the first checksum feature being identical to one of the second checksum features, and the first device fingerprint being identical to one of the second device fingerprints, determining that the operating system of the terminal device is secure;
[0122] In response to the first checksum feature being different from each of the second checksum features, and / or the first device fingerprint being different from each of the second device fingerprints, it is determined that the operating system of the terminal device is abnormal.
[0123] In some implementations, the apparatus 700 further includes:
[0124] The operating system of the terminal device is identified using the second checksum feature and the second device fingerprint of the terminal device.
[0125] In some implementations, the apparatus 700 further includes:
[0126] Using the device fingerprint and one of the verification and features as the primary key, different terminal devices are verified based on the primary key to obtain the first device information that passes the primary key verification and the second device information that fails the primary key verification, wherein the device information includes the device model and version information of the terminal device.
[0127] In some implementations, the device fingerprint and another object in the verification and feature are used as secondary keys, and the terminal device associated with the second device information is verified based on the secondary key to obtain third device information that passes the secondary key verification and fourth device information that fails the secondary key verification.
[0128] In some implementations, the apparatus 700 further includes:
[0129] Obtaining the number of first devices associated with the first device information and the number of second devices associated with the second device information;
[0130] Obtaining the number of third devices associated with the third device information and the number of fourth devices associated with the fourth device information;
[0131] According to the first number of devices and the second number of devices, as well as the third number of devices and the fourth number of devices, verification coverage of device fingerprints and checksum features is obtained.
[0132] In this embodiment, the server receives the first checksum feature and the first device fingerprint sent by the client, and performs security verification of the operating system of the terminal device based on the first checksum feature and the first device fingerprint, thereby solving the problem of low accuracy of security verification based solely on the device fingerprint. Through the first checksum feature and the first device fingerprint, it can be easily determined whether the operating system of the terminal device has been maliciously modified. Combined with the byte-level precise verification of the first checksum feature, it has extremely high sensitivity to modifications to the customized operating system, and the security verification effect is better.
[0133] In the technical solutions disclosed herein, the acquisition, storage, and application of user personal information involved comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0134] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0135] Figure 8 Schematic block diagram of an electronic device used to implement an embodiment of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0136] like Figure 8As shown, the device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. Various programs and data required for the operation of the device 800 can also be stored in the RAM 803. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0137] Various components in device 800 are connected to I / O interface 805, including an input unit 806, such as a keyboard, mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a magnetic disk, optical disk, etc.; and a communication unit 809, such as a network card, modem, wireless communication transceiver, etc. The communication unit 809 allows device 800 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0138] The computing unit 801 can be a variety of general-purpose and / or specialized processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 801 performs the various methods and processes described above, such as the verification method of the terminal device. For example, in some embodiments, the verification method of the terminal device can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed on the device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the computing unit 801, one or more steps of the verification method of the terminal device described above can be performed. Alternatively, in other embodiments, the computing unit 801 can be configured to perform the verification method of the terminal device by any other appropriate means (e.g., by means of firmware).
[0139] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0140] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0141] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0142] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0143] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0144] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship arises through computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.
[0145] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not limited herein.
[0146] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.
Claims
1. A method for verifying a terminal device, wherein: The method comprises: Receiving a first checksum feature of a terminal device to be identified sent by a client, where the first checksum feature is related to a target file in a memory of the terminal device; Receiving a first device fingerprint of the terminal device sent by the client; Performing security verification on the operating system of the terminal device based on the first checksum feature and the first device fingerprint; The method further comprises: Obtaining the number of first devices associated with the first device information and the number of second devices associated with the second device information; Obtaining the number of third devices associated with the third device information and the number of fourth devices associated with the fourth device information; Obtaining a sum of the first number of devices and the second number of devices, and using a ratio of the first number of devices to the sum as a verification coverage rate of the device fingerprint; Calculating a sum of the third number of devices and the fourth number of devices, and using a ratio of the third number of devices to the sum as a verification coverage of the checksum feature; The first device information includes device information of terminal devices that have passed primary key verification; the second device information includes device information of terminal devices that have not passed primary key verification; the third device information includes device information of terminal devices that have passed secondary key verification; and the fourth device information includes device information of terminal devices that have not passed secondary key verification. One of the device fingerprint and the checksum feature is used as the primary key, and the other object is used as the secondary key.
2. The method according to claim 1, wherein Before performing security verification on the operating system of the terminal device according to the first checksum feature and the first device fingerprint, the method further includes: receiving second checksum features of different terminal devices sent by the client, and building a checksum feature library based on the second checksum features; Receive second device fingerprints of different terminal devices sent by the client, and build a device fingerprint library based on the second device fingerprints.
3. The method according to claim 1 or 2, wherein: The performing security verification on the operating system of the terminal device according to the first checksum feature and the first device fingerprint includes: Get pre-built checksum signature libraries and device fingerprint libraries; Matching the first checksum feature with the checksum feature library to obtain a first matching result; Matching the first device fingerprint with the device fingerprint library to obtain a second matching result; Perform security verification on the operating system of the terminal device according to the first matching result and the second matching result.
4. The method according to claim 3, wherein: The performing security verification on the operating system of the terminal device according to the first matching result and the second matching result includes: In response to the first checksum feature being identical to one of the second checksum features, and the first device fingerprint being identical to one of the second device fingerprints, determining that the operating system of the terminal device is secure; In response to the first checksum feature being different from each of the second checksum features, and / or the first device fingerprint being different from each of the second device fingerprints, it is determined that the operating system of the terminal device is abnormal.
5. The method according to claim 3, wherein The method further comprises: The operating system of the terminal device is identified using the second checksum feature of the terminal device and the second device fingerprint.
6. The method according to claim 5, wherein: Before identifying the operating system of the terminal device using the second checksum feature and the second device fingerprint of the terminal device, the method further includes: Different terminal devices are verified based on the primary key to obtain first device information that passes the primary key verification and second device information that fails the primary key verification, wherein the device information includes device model and version information of the terminal device.
7. The method according to claim 6, wherein: The terminal device associated with the second device information is verified based on the secondary key, and the third device information that passes the secondary key verification and the fourth device information that fails the secondary key verification are obtained.
8. The method according to claim 1, wherein The first checksum feature is obtained based on content parsing of the target file, which is obtained by reading memory through entry information, and the entry information is obtained by reading a memory-mapped file of the terminal device.
9. The method according to claim 1, wherein: The first device fingerprint is generated based on system attribute information of the operating system of the terminal device.
10. A verification device for a terminal device, comprising: A first receiving module is configured to receive a first checksum feature of a terminal device to be identified sent by a client, where the first checksum feature is related to a target file in a memory of the terminal device; A second receiving module is configured to receive a first device fingerprint of the terminal device sent by the client; a verification module, configured to perform security verification on the operating system of the terminal device based on the first checksum feature and the first device fingerprint; The verification module is further configured to: Obtaining the number of first devices associated with the first device information and the number of second devices associated with the second device information; Obtaining the number of third devices associated with the third device information and the number of fourth devices associated with the fourth device information; Obtaining a sum of the first number of devices and the second number of devices, and using a ratio of the first number of devices to the sum as a verification coverage rate of the device fingerprint; Calculating a sum of the third number of devices and the fourth number of devices, and using a ratio of the third number of devices to the sum as a verification coverage of the checksum feature; The first device information includes device information of terminal devices that pass primary key verification; the second device information includes device information of terminal devices that fail primary key verification; the third device information includes device information of terminal devices that pass secondary key verification; and the fourth device information includes device information of terminal devices that fail secondary key verification. One of the device fingerprint and the checksum feature is used as the primary key, and the other object is used as the secondary key.
11. The device according to claim 10, wherein The verification module further includes: receiving second checksum features of different terminal devices sent by the client, and building a checksum feature library based on the second checksum features; Receive second device fingerprints of different terminal devices sent by the client, and build a device fingerprint library based on the second device fingerprints.
12. The device according to claim 10 or 11, wherein The verification module includes: Get pre-built checksum signature libraries and device fingerprint libraries; Matching the first checksum feature with the checksum feature library to obtain a first matching result; Matching the first device fingerprint with the device fingerprint library to obtain a second matching result; The operating system of the terminal device is securely identified according to the first matching result and the second matching result.
13. The device according to claim 12, wherein The verification module includes: In response to the first checksum feature being identical to one of the second checksum features, and the first device fingerprint being identical to one of the second device fingerprints, determining that the operating system of the terminal device is secure; In response to the first checksum feature being different from each of the second checksum features, and / or the first device fingerprint being different from each of the second device fingerprints, it is determined that the operating system of the terminal device is abnormal.
14. The device according to claim 12, wherein The device further comprises: The operating system of the terminal device is identified using the second checksum feature of the terminal device and the second device fingerprint.
15. The device according to claim 14, wherein The device further comprises: Different terminal devices are verified based on the primary key to obtain first device information that passes the primary key verification and second device information that fails the primary key verification, wherein the device information includes device model and version information of the terminal device.
16. The device according to claim 15, wherein The device fingerprint and another object in the verification and feature are used as a secondary key, and the terminal device associated with the second device information is verified based on the secondary key to obtain the third device information that passes the secondary key verification and the fourth device information that fails the secondary key verification.
17. The device according to claim 10, wherein The first checksum feature is obtained based on content parsing of the target file, which is obtained by reading memory through entry information, and the entry information is obtained by reading a memory-mapped file of the terminal device.
18. The device according to claim 10, wherein The first device fingerprint is generated based on system attribute information of the operating system of the terminal device.
19. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 9.
20. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 9.
21. A computer program product comprising a computer program, which, when executed by a processor, implements the steps of the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Equipment verification method and device
CN105763521A
Equipment fingerprint-based authority authentication method, device and system
CN107426235A