Equipment fingerprint counterfeiting identification method and device, electronic equipment and storage medium

By collecting multi-dimensional data of the device and using large language models to identify conflict points and exception points, the problem of device fingerprint forgery identification is solved, and efficient security analysis and identity verification are achieved.

CN119988909APending Publication Date: 2025-05-13BEIJING QIYI CENTURY SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510177586.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art is difficult to accurately identify the forgery of device fingerprints, resulting in security mechanisms being bypassed and fraud or other malicious behaviors.

Method used

By collecting multi-dimensional data of the target device and inputting it into the large language model to obtain the feature value output by the large language model. These characteristic values ​​are used to characterize conflict points and/or anomalies of the device fingerprint for fake identification.

Benefits of technology

It realizes accurate forgery and identification of equipment fingerprints, improves security, and can promptly deal with new forgery methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119988909A_ABST
    Figure CN119988909A_ABST
Patent Text Reader

Abstract

The invention relates to a device fingerprint counterfeiting identification method and apparatus, an electronic device and a storage medium. The method comprises the steps of collecting multi-dimensional data of a target device; wherein the multi-dimensional data is used for describing a device fingerprint of the target device; inputting the multi-dimensional data into a large language model to obtain a characteristic value output by the large language model; wherein the feature value is used for representing a conflict point and / or an abnormal point of the device fingerprint of the target device; and performing forgery identification on the device fingerprint according to the characteristic value. The method comprises the steps of collecting multi-dimensional data of target equipment, inputting the multi-dimensional data into a large language model, obtaining characteristic values such as conflict points and abnormal points output by the large language model by utilizing the understanding ability of the large language model and a large number of existing knowledge bases, and taking the characteristic values as judgment bases of forged equipment, so that forged identification is carried out on equipment fingerprints according to the characteristic values; the effect of accurately carrying out forgery identification on the device fingerprint is achieved, and the safety is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of device fingerprint technology, and in particular to a device fingerprint forgery identification method, device, electronic device and storage medium. Background Art

[0002] Device fingerprint technology generates a unique fingerprint for each device by collecting characteristic information of device hardware and software, which is used in fields such as identity authentication, user tracking and security analysis. However, with the development of technology, attackers use technical means to forge device fingerprints, bypass security mechanisms, and conduct fraud or other malicious behaviors. Therefore, how to accurately forge and identify device fingerprints has become an urgent problem to be solved. Summary of the invention

[0003] The present application provides a device fingerprint forgery identification method, apparatus, electronic device and storage medium to solve the technical problem of how to accurately identify the forgery of device fingerprints.

[0004] In a first aspect, the present application provides a device fingerprint forgery identification method, the method comprising:

[0005] Collecting multi-dimensional data of a target device; wherein the multi-dimensional data is used to describe a device fingerprint of the target device;

[0006] Inputting the multi-dimensional data into a large language model to obtain a feature value output by the large language model; wherein the feature value is used to characterize a conflict point and / or anomaly point of a device fingerprint of the target device;

[0007] The device fingerprint is forged and identified according to the characteristic value.

[0008] Optionally, inputting the multi-dimensional data into a large language model to obtain a feature value output by the large language model includes:

[0009] Inputting the multi-dimensional data into the large language model;

[0010] Get the prompt word;

[0011] Analyzing the multi-dimensional data in the large language model based on the prompt word to obtain conflict points and / or abnormal points of the device fingerprint;

[0012] The conflict point and / or the abnormal point is used as the feature value.

[0013] Optionally, analyzing the multi-dimensional data in the large language model based on the prompt word to obtain the conflict point and / or abnormal point of the device fingerprint includes:

[0014] Obtaining the conflict judgment model and the abnormality judgment model preset in the large language model;

[0015] Analyzing the multi-dimensional data in the conflict judgment model based on a first prompt word in the prompt words to obtain a conflict point of the device fingerprint;

[0016] The multi-dimensional data is analyzed in the abnormality judgment model based on the second prompt word in the prompt words to obtain the abnormal point of the device fingerprint.

[0017] Optionally, multi-dimensional data of the target device is collected, including:

[0018] Obtaining an access request from the target device;

[0019] Based on the access request, the multi-dimensional data of the target device is collected.

[0020] Optionally, performing forgery identification on the device fingerprint according to the characteristic value includes:

[0021] Determine a risk coefficient according to the weight information corresponding to the eigenvalue and the eigenvalue;

[0022] When the risk factor exceeds a preset threshold, it is determined that the device fingerprint of the target device is a forged fingerprint.

[0023] Optionally, determining a risk coefficient according to weight information corresponding to the eigenvalue and the eigenvalue includes:

[0024] adding the characteristic value to a risk scorecard;

[0025] Determining weight information corresponding to the feature value based on the risk score card;

[0026] The risk coefficient is determined according to the weight information and the characteristic value.

[0027] Optionally, the multi-dimensional data includes at least one of hardware information, operating system information and software information; wherein the hardware information is used to characterize the inherent hardware information of the target device; the operating system information is used to reflect the software operating environment of the target device; and the software information is used to reflect the running status of the software in the target device.

[0028] In a second aspect, the present application provides a device for identifying forged fingerprints of a device, the device comprising:

[0029] A collection module, used to collect multi-dimensional data of a target device; wherein the multi-dimensional data is used to describe a device fingerprint of the target device;

[0030] An analysis module, used for inputting the multi-dimensional data into a large language model to obtain a feature value output by the large language model; wherein the feature value is used to characterize a conflict point or anomaly point of a device fingerprint of the target device;

[0031] An identification module is used to perform forgery identification on the device fingerprint according to the characteristic value.

[0032] In a third aspect, the present application provides an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;

[0033] Memory, used to store computer programs;

[0034] The processor is used to implement the device fingerprint forgery identification method described in any embodiment of the first aspect when executing the program stored in the memory.

[0035] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the device fingerprint forgery identification method as described in any embodiment of the first aspect is implemented.

[0036] The above technical solution provided by the embodiment of the present application has the following advantages over the prior art: the method provided by the embodiment of the present application collects multi-dimensional data of the target device; wherein the multi-dimensional data is used to describe the device fingerprint of the target device; the multi-dimensional data is input into a large language model to obtain a characteristic value output by the large language model; wherein the characteristic value is used to characterize the conflict points and / or abnormal points of the device fingerprint of the target device; the device fingerprint is forged and identified according to the characteristic value. The method collects multi-dimensional data of the target device, inputs the multi-dimensional data into a large language model, and uses the understanding ability of the large language model and a large amount of existing knowledge base to obtain characteristic values ​​such as conflict points and abnormal points output by the large language model as a basis for judging the forged device, thereby forging and identifying the device fingerprint according to the characteristic value, achieving the effect of accurately identifying the forged device fingerprint and improving security. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0038] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0039] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplified descriptions do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.

[0040] Figure 1 A system architecture diagram of a device fingerprint forgery identification method provided in one embodiment of the present application;

[0041] Figure 2 A schematic diagram of a process flow of a device fingerprint forgery identification method provided by an embodiment of the present application;

[0042] Figure 3 A schematic diagram of a flow chart of a device fingerprint forgery identification method provided in another embodiment of the present application;

[0043] Figure 4 A schematic diagram of the structure of a device fingerprint forgery identification apparatus provided by one embodiment of the present application;

[0044] Figure 5 A schematic diagram of the structure of an electronic device provided in accordance with an embodiment of the present application. DETAILED DESCRIPTION

[0045] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0046] The disclosure below provides many different embodiments or examples to realize the different structures of the present application. In order to simplify the disclosure of the present application, the parts and settings of specific examples are described below. Of course, they are only examples, and the purpose is not to limit the present application. In addition, the present application can repeat reference numbers and / or letters in different examples. This repetition is for the purpose of simplification and clarity, and does not itself indicate the relationship between the various embodiments and / or settings discussed.

[0047] Device fingerprint technology generates a unique fingerprint for each device by collecting characteristic information of device hardware and software, which is used in fields such as identity authentication, user tracking and security analysis. However, with the development of technology, attackers use technical means to forge device fingerprints, bypass security mechanisms, and commit fraud or other malicious acts. At present, the identification process relies on rule engines and expert systems, which requires a lot of experience and knowledge accumulation of domain experts. Among them, the identification rules are numerous and complex, involving a large number of hardware and software features, which makes the rules complex and difficult to fully cover all possible forgery methods. In addition, since the maintenance and update of rules need to be done manually, the real-time performance is poor, and it is difficult to respond to new forgery methods in a timely manner, and it cannot guarantee accurate forgery identification of device fingerprints.

[0048] In order to solve the technical problem of how to accurately identify the forgery of device fingerprints in the prior art, the present application provides a device fingerprint forgery identification method, apparatus, electronic device and storage medium, which can use the characteristic values ​​such as conflict points and anomaly points output by a large language model as the basis for judging the forged device, thereby identifying the forgery of the device fingerprint based on the characteristic values, achieving the effect of accurately identifying the forgery of the device fingerprint and improving security.

[0049] The first embodiment of the present application provides a device fingerprint forgery identification method, which can be applied to Figure 1 The system architecture shown in the figure includes at least a target device 101 and a server 102, wherein the target device 101 and the server 102 establish a communication connection, wherein the number of target devices is not limited, and the target device can be a user's terminal device, such as a desktop computer, a tablet computer, a notebook, a mobile terminal, etc. The server 102 can be a local server, a cloud server, or a server cluster.

[0050] The method can be applied to the server 102 in the system architecture to realize counterfeit identification of the device fingerprint of the target device. Next, based on the system architecture, the device fingerprint counterfeit identification method is described in detail. Figure 2 , the device fingerprint forgery identification method includes:

[0051] Step 201, collect multi-dimensional data of the target device; wherein the multi-dimensional data is used to describe the device fingerprint of the target device.

[0052] In one embodiment, the multi-dimensional data includes at least one of hardware information, operating system information and software information; wherein the hardware information is used to characterize the inherent hardware information of the target device; the operating system information is used to reflect the software operating environment of the target device; and the software information is used to reflect the running status of the software in the target device.

[0053] In this embodiment, the hardware information may include information such as the brand, model, hardware name, CPU serial number, memory size, storage device identifier, etc. of the target device. This information is inherent to the device and is difficult to forge. The operating system information may include the operating system version, patch level, etc., which can reflect the software operating environment of the device. The software information may include a list of software installed in the target device and its version number, which can show the specific software running status on the target device. In this embodiment, the multi-dimensional data may be a data set of all the information in the above-mentioned hardware information, operating system information and software information. For example, when collecting the multi-dimensional data of the target device, the brand, model, hardware name, CPU serial number, memory size, storage device identifier, operating system version, patch level, installed software list and its version number, etc. of the target device are collected, so as to comprehensively and comprehensively obtain the device fingerprint of the target device. Of course, the collected multi-dimensional data may also be a data set of part of it, without limitation.

[0054] In one embodiment, collecting multi-dimensional data of a target device includes: obtaining an access request of the target device; and collecting multi-dimensional data of the target device based on the access request.

[0055] In this embodiment, when the target device issues an access request, multi-dimensional data of the target device can be collected based on the access request to identify the device fingerprint of the target device based on the multi-dimensional data, and determine whether the device fingerprint is a forged fingerprint. The access request can be a login request based on an account and password, a login request based on face recognition or other biometrics, or other requests to access the server, without limitation.

[0056] Step 202: input the multi-dimensional data into the large language model to obtain feature values ​​output by the large language model; wherein the feature values ​​are used to characterize the conflict points and / or abnormal points of the device fingerprint of the target device.

[0057] In one embodiment, multi-dimensional data is input into a large language model (LLM) to obtain feature values ​​output by the large language model, including: inputting the multi-dimensional data into the large language model; obtaining prompt words; analyzing the multi-dimensional data in the large language model based on the prompt words to obtain conflict points and / or abnormal points of the device fingerprint; and using the conflict points and / or abnormal points as feature values.

[0058] In this embodiment, a data set of multi-dimensional data is input into a large language model, and the large language model is allowed to judge and analyze the conflict points and abnormal points of the device fingerprint parameters through the prompt word prompt. The prompt word can be, for example, whether there is a conflict between device fingerprint parameters, or whether the device fingerprint parameter indicates that the device version is very old, etc. The conflict points or abnormal points of the device fingerprint can be obtained through the results of the large language model analysis, and these conflict points and abnormal points can be used as feature values. The large language model can be some general large models such as GPT-4 or Tongyi Qianwen, without limitation.

[0059] In one embodiment, multi-dimensional data is analyzed in a large language model based on prompt words to obtain conflict points and / or anomaly points of a device fingerprint, including: obtaining a conflict judgment model and anomaly judgment model preset in the large language model; analyzing multi-dimensional data in the conflict judgment model based on a first prompt word in the prompt words to obtain conflict points of the device fingerprint; analyzing multi-dimensional data in the anomaly judgment model based on a second prompt word in the prompt words to obtain anomaly points of the device fingerprint.

[0060] In this embodiment, the large language model includes a conflict judgment model for conflict judgment and an anomaly judgment model for anomaly judgment. The multi-dimensional data can be analyzed in the conflict judgment model based on the first prompt word to obtain the conflict point of the device fingerprint, and the multi-dimensional data can be analyzed in the anomaly judgment model based on the second prompt word to obtain the anomaly point of the device fingerprint.

[0061] For example, enter the prompt content: Are there any conflicts in the parameters of the following device fingerprints? If yes, reply 1, if not, reply 2:

[0062] "model": "MACHD-HWMAE";

[0063] "Brand": "HUAWEI";

[0064] "Hardware": "ABCxxxxxx";

[0065] LLM model output: "1";

[0066] Then it can be determined that there is a conflict in the device fingerprint.

[0067] Enter the prompt content: Is the device fingerprint parameter displayed for a mobile phone released in the past five years? If yes, reply 1, if not, reply 2:

[0068] "Platform": "IOS";

[0069] "OS version number": "8.4";

[0070] LLM model output: "2";

[0071] Then it can be judged that the fingerprint version of this device is very old, and the older version is a higher risk point in risk assessment.

[0072] At this time, the conflict between device fingerprint parameters can be used as a conflict point, and the old device fingerprint version can be used as an abnormal point. The characteristic values ​​generated for the access request of the target device can be: device conflict, old device version, etc.

[0073] It should be noted that when judging whether there is a conflict in the parameters of the device fingerprint, the judgment can be made based on the correspondence between the normal device parameters in the large language model. For example, the normal device model A corresponds to the brand A1 and the hardware is A2. If the brand corresponding to the device model A in the collected multi-dimensional data is A1, but the hardware is B2, it means that there is a conflict in the device fingerprint and there is a possibility of forgery.

[0074] Step 203: perform forgery identification on the device fingerprint according to the characteristic value.

[0075] This method collects multi-dimensional data of the target device, inputs the multi-dimensional data into a large language model, and uses the understanding ability of the large language model and a large amount of existing knowledge base to obtain characteristic values ​​such as conflict points and anomaly points output by the large language model as a basis for judging counterfeit devices, thereby performing counterfeit identification of device fingerprints based on the characteristic values, achieving accurate counterfeit identification of device fingerprints, and improving security.

[0076] In one embodiment, forgery identification is performed on a device fingerprint based on a feature value, including: determining a risk coefficient based on weight information corresponding to the feature value and the feature value; and determining that the device fingerprint of the target device is a forged fingerprint when the risk coefficient exceeds a preset threshold.

[0077] In this embodiment, in the process of forgery identification of device fingerprints based on characteristic values, the weight information of the characteristic values ​​output by the large language model can be determined first, and the risk coefficient can be determined based on the weight information and the characteristic values. Therefore, when the risk coefficient exceeds a preset threshold, the device fingerprint of the target device is determined to be a forged fingerprint. When the risk coefficient does not exceed the preset threshold, the target device can be authorized to log in to the server.

[0078] The weight information may be a preset weight for each eigenvalue, or a weight dynamically adjusted by combining various eigenvalues.

[0079] In one embodiment, determining a risk coefficient based on weight information corresponding to a feature value and the feature value includes: adding the feature value to a risk score card; determining weight information corresponding to the feature value based on the risk score card; and determining the risk coefficient based on the weight information and the feature value.

[0080] In this embodiment, when determining the weight information corresponding to the eigenvalue, the eigenvalue can be added to the risk scoring card, and the weight information of the eigenvalue can be determined based on the distribution of black and white samples in the risk scoring card, so that the assessment of the risk coefficient determined based on the weight information and the eigenvalue is more accurate.

[0081] In a specific embodiment, the device fingerprint forgery identification method is as follows: Figure 3 ,include:

[0082] Step S1, collecting a collection of device fingerprint parameters;

[0083] Step S2, input the prompt word Prompt;

[0084] Step S3, large language model (LLM) analysis;

[0085] Step S4, outputting the analysis results;

[0086] Step S5, determining conflict points and abnormal points based on content keywords;

[0087] Step S6: adding the conflict points and abnormal points as features to the risk scoring card to identify the forgery of the device fingerprint.

[0088] In this embodiment, the collection of device fingerprint parameters, i.e., the collection of multi-dimensional data sets, may include:

[0089] Hardware information, such as brand, model, hardware name, CPU serial number, memory size, storage device identifier, etc., is inherent in the device and is difficult to forge.

[0090] Operating system information, such as the operating system version and patch level, reflects the software operating environment of the device.

[0091] Software information, such as a list of installed software and its version numbers, shows the specific software running on the device.

[0092] Input the multi-dimensional data set into the LLM model, and use the prompt words to let the large model judge and analyze the conflict points and abnormal points of the device fingerprint parameters. Select different LLM models for testing and choose the model that meets the expected effect.

[0093] For example: Enter the prompt content: Are there any conflicts in the parameters of the following device fingerprints? If yes, reply 1; if no, reply 2:

[0094] "model": "MACHD-HWMAE";

[0095] "Brand": "HUAWEI";

[0096] "Hardware": "ABCxxxxxx";

[0097] LLM model output: "1";

[0098] Then it can be determined that there is a conflict in the device fingerprint.

[0099] Enter the prompt content: Is the device fingerprint parameter displayed for a mobile phone released in the past five years? If yes, reply 1, if not, reply 2:

[0100] "Platform": "IOS";

[0101] "OS version number": "8.4";

[0102] LLM model output: "2";

[0103] Then it can be judged that the fingerprint version of this device is very old, and the older version is a higher risk point in risk assessment.

[0104] According to the output of the LLM model, a corresponding feature value is generated for each request, such as device conflict: yes; old device version: yes. Features such as device conflict and old device version can be used as feature values ​​and added to the risk score card. According to the distribution of black and white samples, the corresponding weights are determined, and finally the total value of the risk score card is given to judge the risk level of the request, and then identify whether the device fingerprint is forged. According to the latest knowledge base of LLM, new forgery methods can be responded to in a timely manner. In addition, the LLM model can replace expert experience and automatically identify whether a large number of device fingerprints are forged, thereby improving security and identification response speed.

[0105] Based on the same technical concept, the second embodiment of the present application provides a device for identifying forged fingerprints of a device, such as Figure 4 , the device comprises:

[0106] The acquisition module 401 is used to acquire multi-dimensional data of the target device; wherein the multi-dimensional data is used to describe the device fingerprint of the target device;

[0107] An analysis module 402 is used to input the multi-dimensional data into a large language model to obtain a feature value output by the large language model; wherein the feature value is used to characterize a conflict point or anomaly point of a device fingerprint of the target device;

[0108] The identification module 403 is used to perform forgery identification on the device fingerprint according to the characteristic value.

[0109] The device collects multi-dimensional data of the target device, inputs the multi-dimensional data into a large language model, and uses the understanding ability of the large language model and a large amount of existing knowledge base to obtain characteristic values ​​such as conflict points and anomaly points output by the large language model as a basis for judging whether the device is counterfeit. The device then performs counterfeit identification of the device fingerprint based on the characteristic values, thereby achieving accurate counterfeit identification of the device fingerprint and improving security.

[0110] like Figure 5 As shown, an embodiment of the present application provides an electronic device, including a processor 111, a communication interface 112, a memory 113 and a communication bus 114, wherein the processor 111, the communication interface 112, and the memory 113 communicate with each other through the communication bus 114.

[0111] Memory 113, used for storing computer programs;

[0112] In one embodiment of the present application, the processor 111 is used to execute the program stored in the memory 113 to implement the device fingerprint forgery identification method provided by any of the above method embodiments, including:

[0113] Collecting multi-dimensional data of a target device; wherein the multi-dimensional data is used to describe a device fingerprint of the target device;

[0114] Inputting the multi-dimensional data into a large language model to obtain a feature value output by the large language model; wherein the feature value is used to characterize a conflict point and / or anomaly point of a device fingerprint of the target device;

[0115] The device fingerprint is forged and identified according to the characteristic value.

[0116] The communication bus mentioned in the above terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0117] The communication interface is used for communication between the above terminal and other devices.

[0118] The memory may include a random access memory (RAM) or a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.

[0119] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0120] An embodiment of the present application further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the device fingerprint forgery identification method provided by any of the aforementioned method embodiments is implemented.

[0121] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0122] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a general hardware platform, and of course, by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the relevant technology can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0123] It should be understood that the terms used herein are only for the purpose of describing specific example embodiments and are not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms "one", "an" and "said" as used herein may also be meant to include plural forms. The terms "include", "comprise", "contain", and "have" are inclusive, and therefore specify the existence of stated features, steps, operations, elements and / or parts, but do not exclude the existence or addition of one or more other features, steps, operations, elements, parts, and / or combinations thereof. The method steps, processes, and operations described herein are not interpreted as necessarily requiring them to be performed in the specific order described or illustrated, unless the execution order is clearly indicated. It should also be understood that additional or alternative steps may be used.

[0124] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. In the description, the suffixes such as "module", "component" or "unit" used to represent the elements are only used to facilitate the description of the present application and have no specific meaning in themselves. Therefore, "module", "component" or "unit" can be used in a mixed manner.

[0125] The above description is only a specific implementation of the present application, so that those skilled in the art can understand or implement the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest range consistent with the principles and novel features applied for herein.

Claims

1. A device fingerprint forgery identification method, characterized in that: The method comprises: Collecting multi-dimensional data of a target device; wherein the multi-dimensional data is used to describe a device fingerprint of the target device; Inputting the multi-dimensional data into a large language model to obtain a feature value output by the large language model; wherein the feature value is used to characterize a conflict point and / or anomaly point of a device fingerprint of the target device; The device fingerprint is forged and identified according to the characteristic value.

2. The method according to claim 1, characterized in that Inputting the multi-dimensional data into a large language model to obtain a feature value output by the large language model includes: Inputting the multi-dimensional data into the large language model; Get the prompt word; Analyzing the multi-dimensional data in the large language model based on the prompt word to obtain conflict points and / or abnormal points of the device fingerprint; The conflict point and / or the abnormal point is used as the feature value.

3. The method according to claim 2, characterized in that Analyzing the multi-dimensional data in the large language model based on the prompt word to obtain conflict points and / or abnormal points of the device fingerprint includes: Obtaining the conflict judgment model and the abnormality judgment model preset in the large language model; Analyzing the multi-dimensional data in the conflict judgment model based on a first prompt word in the prompt words to obtain a conflict point of the device fingerprint; The multi-dimensional data is analyzed in the abnormality judgment model based on the second prompt word in the prompt words to obtain the abnormal point of the device fingerprint.

4. The method according to claim 1, characterized in that Collect multi-dimensional data of the target device, including: Obtaining an access request from the target device; Based on the access request, the multi-dimensional data of the target device is collected.

5. The method according to claim 1, characterized in that Performing forgery identification on the device fingerprint according to the characteristic value includes: Determine a risk coefficient according to the weight information corresponding to the eigenvalue and the eigenvalue; When the risk factor exceeds a preset threshold, it is determined that the device fingerprint of the target device is a forged fingerprint.

6. The method according to claim 5, characterized in that Determining a risk coefficient according to weight information corresponding to the eigenvalue and the eigenvalue includes: adding the characteristic value to a risk scorecard; Determining weight information corresponding to the feature value based on the risk score card; The risk coefficient is determined according to the weight information and the characteristic value.

7. The method according to claim 1, characterized in that The multi-dimensional data includes at least one of hardware information, operating system information and software information; wherein the hardware information is used to characterize the inherent hardware information of the target device; the operating system information is used to reflect the software operating environment of the target device; and the software information is used to reflect the running status of the software in the target device.

8. A device for identifying forged fingerprints of a device, characterized in that: The device comprises: A collection module, used to collect multi-dimensional data of a target device; wherein the multi-dimensional data is used to describe a device fingerprint of the target device; An analysis module, used for inputting the multi-dimensional data into a large language model to obtain a feature value output by the large language model; wherein the feature value is used to characterize a conflict point or anomaly point of a device fingerprint of the target device; An identification module is used to perform forgery identification on the device fingerprint according to the characteristic value.

9. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; The processor is used to implement the device fingerprint forgery identification method described in any one of claims 1 to 7 when executing the program stored in the memory.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the device fingerprint forgery identification method according to any one of claims 1 to 7 is implemented.