Positioning tamper-proofing method and device, computer equipment and storage medium

By obtaining and analyzing a variety of positioning information of a mobile terminal device, determining whether its geographical location has been tampered with, and issuing a warning when tampering occurs, the problem of low trust in the geographical location of the mobile terminal is solved, and the reliability of security and positioning data is improved.

CN120050661APending Publication Date: 2025-05-27INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410499179.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-24
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The trustworthiness of mobile terminals is challenged because some bad users gain economic benefits by tampering with the geographical location information of mobile terminals.

Method used

A positioning and tamper-proof method is provided, by obtaining satellite positioning information, base station positioning information and network positioning information of the terminal device, determining whether the geographical location has been tampered with, and issuing a positioning and tampering prompt to the terminal device when tampering occurs.

Benefits of technology

It can identify geographical location tampering, enhance the security of terminal devices, improve the accuracy of location tampering identification, and thus improve the credibility of positioning data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050661A_ABST
    Figure CN120050661A_ABST
Patent Text Reader

Abstract

The invention relates to a positioning tamper-proofing method and device, computer equipment and a storage medium, relates to the technical field of information security, and can be applied to the field of financial science and technology or other related fields. Comprising the steps of identifying whether the geographic position of the terminal equipment is tampered or not based on satellite positioning information, base station positioning information and network positioning information of the terminal equipment under the condition that the terminal equipment is detected to have a security risk, and sending a positioning tampering prompt to the terminal equipment under the condition that the geographic position of the terminal equipment is tampered, the terminal equipment can be prevented from being attacked by positioning modification, and the security of the terminal equipment is enhanced; under the condition that the terminal equipment has security risks, whether the geographic position of the terminal equipment is tampered or not is further identified, so that the accuracy of position tampering identification can be improved, and the credibility of positioning data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and particularly to a positioning anti-tampering method, device, computer device and storage medium. Background Art

[0002] Mobile terminal positioning technology generally relies on mobile communication networks and GPS (Global Positioning System) positioning technology to determine the current geographical location through mobile applications. In the financial scenario, mobile terminal positioning technology is also widely used. For example, merchant acquiring devices are set with a positioning range to prevent merchants from renting POS (Point of Sales) devices to conduct abnormal transaction behaviors; in the business marketing scenario, device positioning is used to determine whether users participate in relevant offline activities to avoid wasting marketing resources; during business risk control, geographical location information of mobile phones is used to identify risks such as remote login and abnormal transactions.

[0003] Currently, some malicious users obtain economic benefits by tampering with the geographical location information of mobile terminals, which challenges the credibility of the geographical location of mobile terminals. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide a positioning anti-tampering method, device, computer device and storage medium that can identify geographical location tampering and enhance the security of terminal devices.

[0005] In a first aspect, the present application provides a positioning anti-tampering method. The method includes:

[0006] When detecting a security risk in the terminal device, obtain the satellite positioning information, base station positioning information, and network positioning information of the terminal device;

[0007] Determine whether the geographical location of the terminal device has been tampered with based on the satellite positioning information, base station positioning information, and network positioning information;

[0008] When the geographical location of the terminal device has been tampered with, send a positioning tampering prompt to the terminal device.

[0009] In one embodiment, determining whether the geographical location of the terminal device has been tampered with based on the satellite positioning information, base station positioning information, and network positioning information includes:

[0010] Detect whether there is an actual base station that matches the base station positioning information to obtain a first detection result;

[0011] Detect whether the satellite positioning information is within the target coverage range to obtain a second detection result; the target coverage range is the coverage range of the actual base station;

[0012] Detect whether the satellite positioning information is within the area corresponding to the network positioning information to obtain a third detection result;

[0013] Detect whether the attribution of the network address corresponding to the network positioning information is consistent with the attribution of the actual base station to obtain a fourth detection result;

[0014] Detect whether the satellite positioning information, the base station positioning information, and the network positioning information are consistent to obtain a fifth detection result;

[0015] Determine whether the geographical location of the terminal device has been tampered with according to the first detection result, the second detection result, the third detection result, the fourth detection result, and the fifth detection result.

[0016] In one embodiment, the method further includes:

[0017] Determine the device type and historical geographical location of the terminal device;

[0018] Obtain the abnormal conditions corresponding to the device type;

[0019] Detect whether the position change trend of the terminal device meets the abnormal conditions according to the historical geographical location and the satellite positioning information to obtain a sixth detection result;

[0020] Determine whether the geographical location of the terminal device has been tampered with according to the first detection result, the second detection result, the third detection result, the fourth detection result, the fifth detection result, and the sixth detection result.

[0021] In one embodiment, the method includes:

[0022] Obtain the application installation list of the terminal device, and detect whether there is a malicious application located in the preset blacklist in the application installation list;

[0023] Obtain the operating system setting information of the terminal device, and detect whether there is a configuration risk in the terminal device according to the operating system setting information;

[0024] Determine that the terminal device has a security risk if there is a malicious application in the application installation list or the terminal device has a configuration risk.

[0025] In one embodiment, the method includes:

[0026] Receive blacklist configuration information; the blacklist configuration information includes at least one malicious application information;

[0027] Update the preset blacklist according to the malicious application information.

[0028] In one embodiment, the method further includes:

[0029] When it is detected that there is no security risk in the terminal device, obtain the satellite positioning information of the terminal device;

[0030] Based on the satellite positioning information, determine whether the location change trend of the terminal device is normal;

[0031] When the location change trend of the terminal device is normal, send the current geographical location to the terminal device according to the satellite positioning information.

[0032] In one embodiment, the method further includes:

[0033] When the geographical location of the terminal device has not been tampered with, send the current geographical location to the terminal device according to the satellite positioning information.

[0034] In a second aspect, the present application also provides a positioning anti-tampering device. The device includes:

[0035] An acquisition module, configured to obtain the satellite positioning information, base station positioning information, and network positioning information of the terminal device when it is detected that there is a security risk in the terminal device;

[0036] An analysis module, configured to determine whether the geographical location of the terminal device has been tampered with according to the satellite positioning information, base station positioning information, and network positioning information;

[0037] A prompt module, configured to send a positioning tampering prompt to the terminal device when the geographical location of the terminal device has been tampered with.

[0038] In a third aspect, the present application also provides a computer device. The computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0039] When it is detected that there is a security risk in the terminal device, obtain the satellite positioning information, base station positioning information, and network positioning information of the terminal device;

[0040] According to the satellite positioning information, base station positioning information, and network positioning information, determine whether the geographical location of the terminal device has been tampered with;

[0041] When the geographical location of the terminal device has been tampered with, send a positioning tampering prompt to the terminal device.

[0042] In a fourth aspect, the present application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0043] When a security risk is detected in the terminal device, obtain the satellite positioning information, base station positioning information, and network positioning information of the terminal device;

[0044] Determine whether the geographical location of the terminal device has been tampered with according to the satellite positioning information, base station positioning information, and network positioning information;

[0045] When the geographical location of the terminal device has been tampered with, send a positioning tampering prompt to the terminal device.

[0046] In a fifth aspect, the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0047] When a security risk is detected in the terminal device, obtain the satellite positioning information, base station positioning information, and network positioning information of the terminal device;

[0048] Determine whether the geographical location of the terminal device has been tampered with according to the satellite positioning information, base station positioning information, and network positioning information;

[0049] When the geographical location of the terminal device has been tampered with, send a positioning tampering prompt to the terminal device.

[0050] In the above positioning anti-tampering method, device, computer device, and storage medium, when a security risk is detected in the terminal device, based on the satellite positioning information, base station positioning information, and network positioning information of the terminal device, it can identify whether the geographical location of the terminal device has been tampered with. When the geographical location of the terminal device has been tampered with, sending a positioning tampering prompt to the terminal device can prevent the terminal device from being attacked by positioning modification and enhance the security of the terminal device; when a security risk exists in the terminal device, further identifying whether the geographical location of the terminal device has been tampered with can improve the accuracy of location tampering identification, thereby enhancing the credibility of positioning data. Description of the Drawings

[0051] Figure 1 It is an application environment diagram of the positioning anti-tampering method in an embodiment;

[0052] Figure 2 It is a flowchart of the positioning anti-tampering method in an embodiment;

[0053] Figure 3 It is a flowchart of the positioning anti-tampering method in another embodiment;

[0054] Figure 4 It is a structural diagram of the positioning tampering identification system in an embodiment;

[0055] Figure 5The structural block diagram of the positioning anti-tampering device in an embodiment;

[0056] Figure 6 The internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0057] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0058] The positioning anti-tampering method provided by the embodiment of the present application can be applied to, for example, Figure 1 the application environment shown in the figure. Among them, the terminal device 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or placed in the cloud or other network servers. When the server 104 detects a security risk in the terminal device 102, it determines whether the geographical location of the terminal device 102 has been tampered with based on the satellite positioning information, base station positioning information, and network positioning information of the terminal device 102. When the geographical location of the terminal device 102 has been tampered with, a positioning tampering prompt is sent to the terminal device 102. Among them, the terminal device 102 can be various mobile terminals, including but not limited to various laptop computers, smart phones, tablet computers, POS devices, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart vehicle-mounted devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.

[0059] In one embodiment, as Figure 2 shown in the figure, a positioning anti-tampering method is provided. Taking the method applied to Figure 1 the server 104 in the figure as an example, the method includes the following steps:

[0060] Step 202, when detecting a security risk in the terminal device, obtain the satellite positioning information, base station positioning information, and network positioning information of the terminal device.

[0061] Among them, the server monitors multiple terminal devices within the monitoring range. The terminal device in this embodiment is any device within the monitoring range. It can be understood that the terminal device is generally a mobile terminal, and its geographical location will change, and there is a positioning requirement.

[0062] The existence of security risks in a terminal device means that there are problems or vulnerabilities in the environment where the terminal device is located that may threaten system security. In one implementation, the server determines whether there are security risks in the terminal device by detecting whether there are malicious applications among the applications installed on the terminal device. In one implementation, the server determines whether there are security risks in the terminal device by detecting the configuration information of the operating system of the terminal device.

[0063] Among them, satellite positioning information refers to the precise location data of the terminal device obtained by the terminal device through satellite positioning technology. In a specific implementation, the satellite positioning information is the positioning information obtained by the GPS positioning module of the terminal device. Base station positioning information refers to the location information of the terminal device determined based on the base station location and communication data by establishing a connection between the terminal device and a nearby base station. The base station positioning information can be the distance information between the terminal device and the connected base station. Network positioning information refers to the address information determined by the terminal device through the network IP (Internet Protocol Address). In a specific implementation, when the server detects that there are security risks in the terminal device, it notifies the terminal device to call GPS positioning, base station positioning, and network IP positioning to obtain positioning information. The terminal device feeds back the obtained satellite positioning information, base station positioning information, and network positioning information to the server for further analysis and processing.

[0064] Step 204: Determine whether the geographical location of the terminal device has been tampered with according to the satellite positioning information, base station positioning information, and network positioning information.

[0065] Among them, analyze the satellite positioning information, base station positioning information, and network positioning information. If the satellite positioning information, base station positioning information, and network positioning information conform to the real geographical area distribution and the geographical location change trend of the terminal device is normal, it is determined that the geographical location of the terminal device has not been tampered with. If the satellite positioning information, base station positioning information, and network positioning information do not conform to the real geographical area distribution, it is determined that the geographical location of the terminal device has been tampered with.

[0066] Step 206: When the geographical location of the terminal device has been tampered with, send a positioning tampering prompt to the terminal device.

[0067] Among them, if the geographical location of the terminal device has been tampered with, indicating that the geographical location is not trustworthy, call the prompt module of the terminal device to send a positioning tampering prompt, and the prompt method can be at least one of vibration prompt, sound prompt, visual prompt, etc.

[0068] In one implementation, if the geographical location change trend of the terminal device is abnormal, it is determined that the geographical location of the terminal device is abnormal, and a location abnormality prompt is sent to the terminal device. It can be understood that the positioning tampering prompt is used to prompt that the terminal device is suffering from a positioning modification attack. The abnormality prompt is used to prompt that the geographical location of the terminal device violates the regulations.

[0069] In the above positioning anti-tampering method, when a security risk of the terminal device is detected, based on the satellite positioning information, base station positioning information, and network positioning information of the terminal device, it is possible to identify whether the geographical location of the terminal device has been tampered with. When the geographical location of the terminal device has been tampered with, a positioning tampering prompt is sent to the terminal device, which can prevent the terminal device from suffering from a positioning modification attack and enhance the security of the terminal device; when there is a security risk of the terminal device, further identifying whether the geographical location of the terminal device has been tampered with can improve the accuracy of location tampering identification, and thus improve the credibility of positioning data.

[0070] In one embodiment, step 204 includes: detecting whether there is an actual base station that matches the base station positioning information to obtain a first detection result; detecting whether the satellite positioning information is within the target coverage range to obtain a second detection result; the target coverage range is the coverage range of the actual base station; detecting whether the satellite positioning information is within the area corresponding to the network positioning information to obtain a third detection result; detecting whether the attribution of the network address corresponding to the network positioning information is consistent with the attribution of the actual base station to obtain a fourth detection result; detecting whether the satellite positioning information, base station positioning information, and network positioning information are consistent to obtain a fifth detection result; and determining whether the geographical location of the terminal device has been tampered with according to the first detection result, second detection result, third detection result, fourth detection result, and fifth detection result.

[0071] Among them, the actual base station refers to a public mobile communication base station actually maintained by a communication operator. The base station positioning information includes a base station identifier. The server calls an interface provided by the communication operator and queries based on the base station identifier to determine whether the base station that generates the base station positioning information actually exists. If it actually exists, it is determined that there is an actual base station that matches the base station positioning information. The first detection result is used to represent the existence or non-existence of the actual base station.

[0072] The server calls an interface provided by the communication operator to determine the coverage range that the actual base station can cover, obtains the target coverage range, and determines whether the satellite positioning information is within the target coverage range to obtain a second detection result. The second detection result is used to represent that the satellite positioning information is within the target coverage range, or the satellite positioning information is not within the target coverage range.

[0073] Network location information is used to represent a geographical area, for example, a certain city, a certain street, etc. The server maps the geographical area corresponding to the network location information and the satellite location information onto the map by calling the map, and detects whether the satellite location information is within the area corresponding to the network location information to obtain a third detection result. The third detection result is used to represent that the satellite location information is within the area corresponding to the network location information, or the satellite location information is not within the area corresponding to the network location information.

[0074] Affiliation refers to the operator to which the IP address or the actual base station belongs. It is detected whether the operator to which the network address corresponding to the network location information belongs is consistent with the operator to which the actual base station belongs to obtain a fourth detection result. The fourth detection result is used to represent whether the affiliation of the network address is consistent with the affiliation of the actual base station.

[0075] The fifth detection result is used to represent that the satellite location information, the base station location information, and the network location information are completely consistent, or there are differences among the satellite location information, the base station location information, and the network location information. It can be understood that there are certain differences in the location results of different location methods. The complete consistency of the satellite location information, the base station location information, and the network location information is an abnormal detection result, indicating that the attacker has modified multiple geographical location acquisition methods at the same time.

[0076] Among them, if the first detection result represents that there is an actual base station matching the base station location information, the second detection result represents that the satellite location information is within the target coverage range, the third detection result represents that the satellite location information is within the area corresponding to the network location information, the fourth detection result represents that the affiliation of the network address corresponding to the network location information is consistent with the affiliation of the actual base station, and the fifth detection result represents that there are differences among the satellite location information, the base station location information, and the network location information, then it is determined that the geographical location of the terminal device has not been tampered with.

[0077] If the first detection result represents that there is no actual base station matching the base station location information, or the second detection result represents that the satellite location information is not within the target coverage range, or the third detection result represents that the satellite location information is not within the area corresponding to the network location information, or the fourth detection result represents that the affiliation of the network address corresponding to the network location information is inconsistent with the affiliation of the actual base station, or the fifth detection result represents that the satellite location information, the base station location information, and the network location information are completely consistent, then it is determined that the geographical location of the terminal device has been tampered with.

[0078] It can be understood that the accuracies of different positioning methods are different, and there are certain differences in the positioning results. Even if the attacker modifies the geographical location of the terminal device, the generated satellite positioning information, base station positioning information, and network positioning information are difficult to meet the actual geographical location distribution. Based on the multi-dimensional detection rules in this embodiment, the satellite positioning information, base station positioning information, and network positioning information are analyzed, and then it is determined whether the geographical location of the terminal device has been tampered with, which can improve the accuracy of location tampering recognition.

[0079] In one embodiment, the method further includes: determining the device type and historical geographical location of the terminal device; obtaining the abnormal conditions corresponding to the device type; detecting whether the position change trend of the terminal device meets the abnormal conditions according to the historical geographical location and the satellite positioning information, and obtaining a sixth detection result; determining whether the geographical location of the terminal device has been tampered with according to the first detection result, the second detection result, the third detection result, the fourth detection result, the fifth detection result, and the sixth detection result.

[0080] Among them, the historical geographical location refers to the trusted location related to the terminal device determined and stored by the server before the current moment. The device type refers to the type distinguished from the aspects of the device's use, function, or application scenario, etc. The sixth detection result is used to represent that the position change trend of the terminal device is normal, or the position change trend of the terminal device is abnormal.

[0081] In one implementation, multiple device types are set according to the application scenario of the device. For example, a POS device in a financial card acceptance scenario, a terminal device in a business marketing scenario, a terminal device in a business risk control scenario, and so on. In one implementation, multiple device types are set according to the use of the device. For example, portable devices such as mobile phones, card acceptance devices such as POS devices, and information output devices such as displays.

[0082] It can be understood that the positioning characteristics and usage requirements of different types of terminal devices are different. For example, the position of a portable device may change frequently, and the position of a POS device should not exceed the set range, etc. In a specific implementation, the abnormal conditions for each device type are preset, and the abnormal conditions are the conditions for judging whether the position change trend is abnormal.

[0083] In one implementation, the device type includes portable devices, card acceptance devices, and information output devices.

[0084] The abnormal conditions of the portable device are that the moving distance of the terminal device exceeds the set threshold within the first preset duration, and the terminal device remains stationary within the second preset duration, where the second preset duration is greater than the first preset duration. These abnormal conditions are used to determine whether the terminal device has moved a large range in a short period of time or has not moved for a long time. If the device type of the terminal device is a portable device, and it is detected that the moving distance of the terminal device exceeds the set threshold within the first preset period, or the terminal device remains stationary within the second preset period, then it is determined that the position change trend of the terminal device is abnormal.

[0085] The abnormal condition of the acquirer device is that the position of the terminal device exceeds the set range. If the device type of the terminal device is an acquirer device, and it is detected that the position of the terminal device exceeds the set range, then it is determined that the position change trend of the terminal device is abnormal.

[0086] The abnormal conditions of the information output device are that the moving distance of the terminal device exceeds the set threshold within the first preset duration, and the moving frequency of the terminal device exceeds the set frequency threshold. If the device type of the terminal device is an information output device, and it is detected that the moving distance of the terminal device exceeds the set threshold within the first preset period, or the moving frequency of the terminal device exceeds the set frequency threshold, then it is determined that the position change trend of the terminal device is abnormal.

[0087] In one implementation, if the first detection result indicates that there is no actual base station matching the base station positioning information, or the second detection result indicates that the satellite positioning information is not within the target coverage area, or the third detection result indicates that the satellite positioning information is not within the area corresponding to the network positioning information, or the fourth detection result indicates that the attribution of the network address corresponding to the network positioning information is inconsistent with the attribution of the actual base station, or the fifth detection result indicates that the satellite positioning information, the base station positioning information, and the network positioning information are completely the same, or the sixth detection result indicates that the position change trend of the terminal device is abnormal, then it is determined that the geographical location of the terminal device has been tampered with.

[0088] In this embodiment, based on the multi-dimensional detection rules, analyzing the satellite positioning information, the base station positioning information, and the network positioning information, and analyzing the position change trend of the terminal device based on the historical geographical location can further improve the accuracy of position tampering recognition.

[0089] In one embodiment, the method includes: obtaining the application installation list of the terminal device, and detecting whether there is a malicious application in the preset blacklist in the application installation list; obtaining the operating system setting information of the terminal device, and detecting whether there is a configuration risk in the terminal device according to the operating system setting information; and determining that the terminal device has a security risk if there is a malicious application in the application installation list or the terminal device has a configuration risk.

[0090] Among them, the preset blacklist is an application list including multiple malicious applications that is constructed in advance and updated in real time. The server checks through the preset blacklist to determine whether there are malicious applications in the application installation list of the terminal device. In one implementation, the server obtains relevant information of malicious applications in real time and updates the preset blacklist. Since currently, to tamper with the geographical location at the application layer, various applications for modifying the location need to be installed. In this embodiment, by identifying malicious applications, the server can determine the risks existing in the terminal device.

[0091] The configuration information of the operating system includes the configuration information of the virtual positioning function, the customization identifier of the operating system, the installation information of the hook framework, and the configuration information of high-risk ports. The configuration information of the virtual positioning function is used to indicate whether the virtual positioning function of the operating system is enabled. The customization identifier of the operating system is used to indicate whether the terminal device uses a customized operating system. The installation information of the hook framework is used to indicate whether the hook framework is installed on the terminal device. The configuration information of high-risk ports is used to indicate whether high-risk ports are enabled on the terminal device. The high-risk port is any port in the preset high-risk port list. By detecting whether there is a high-risk port in the preset high-risk port list among the ports enabled by the operating system, it is determined whether high-risk ports are enabled on the terminal device.

[0092] It can be understood that if the virtual positioning function of the operating system is enabled, or the terminal device uses a customized operating system, or the terminal device installs a hook framework, or the terminal device enables high-risk ports, it is determined that the terminal device has a configuration risk.

[0093] In one implementation, the recognition program for malicious applications and the recognition program for configuration risks are embedded in the application program in the form of an SDK (Software Development Kit). This application program can run on the server or on the terminal device. When running on the terminal device, if it is detected that the terminal device has a security risk, the satellite positioning information, base station positioning information, and network positioning information are sent to the server for location tampering recognition.

[0094] In this embodiment, by identifying the environmental risks existing in the terminal device from the aspects of malicious applications and operating system configurations, potential risks of the terminal device can be comprehensively and accurately discovered. Combining security risk recognition and location tampering recognition can reduce the impact on the normal operation of risk-free devices and improve the recognition efficiency of location tampering.

[0095] In one embodiment, the method includes: receiving blacklist configuration information; the blacklist configuration information includes at least one malicious application information; updating the preset blacklist according to the malicious application information.

[0096] Among them, the blacklist configuration information can be input by the user or pulled by the server from a preset website regularly. The preset website is a network security blacklist website maintained by multiple users, which publishes malicious application information to remind users and network administrators of potential security risks. The malicious application information includes information such as the name and version of the application program.

[0097] For each piece of malicious application information included in the blacklist configuration information, it is detected whether there is a malicious application in the preset blacklist that matches the malicious application information. If not, the preset blacklist is updated according to the malicious application information. In this way, the real-time update of the preset blacklist is realized, providing data support for security risk identification, being able to adapt to the changing network environment, and improving the accuracy and flexibility of security risk identification.

[0098] In one embodiment, as Figure 3 shown, the method further includes:

[0099] Step 302, when it is detected that there is no security risk in the terminal device, obtain the satellite positioning information of the terminal device.

[0100] Among them, the server uses different positioning information acquisition strategies according to the different risk levels of the terminal device. When there is no security risk in the terminal device, satellite positioning information (GPS positioning information) is obtained. When there is a security risk in the terminal device, satellite positioning information, base station positioning information, and network positioning information are obtained.

[0101] Step 304, determine whether the position change trend of the terminal device is normal based on the satellite positioning information.

[0102] Among them, determine the device type and historical geographical location of the terminal device; obtain the abnormal conditions corresponding to the device type; according to the historical geographical location and satellite positioning information, detect whether the position change trend of the terminal device meets the abnormal conditions; if the position change trend of the terminal device meets the abnormal conditions, it indicates that the position change trend of the terminal device is abnormal; if the position change trend of the terminal device does not meet the abnormal conditions, it indicates that the position change trend of the terminal device is normal. The specific detection method of the position change trend can be referred to above, and this embodiment will not be elaborated here.

[0103] Step 306, when the position change trend of the terminal device is normal, send the current geographical location to the terminal device according to the satellite positioning information.

[0104] Among them, if the position change trend of the terminal device does not meet the abnormal conditions, it indicates that the position change trend is normal. At this time, the current geographical location of the terminal device is determined based on the satellite positioning information, and the current geographical location is sent to the terminal device, so that the terminal device directly uses the geographical location obtained by GPS positioning.

[0105] In one implementation, if the geographical location change trend of the terminal device is abnormal, it is determined that the geographical location of the terminal device is abnormal, and a location abnormality prompt is sent to the terminal device.

[0106] In this embodiment, when there is no security risk for the terminal device, detecting the location change trend of the terminal device can identify potential location abnormalities and improve the credibility of the geographical location of the terminal device. When the location change trend of the terminal device is normal, the current geographical location is sent to the terminal device according to the satellite positioning information, providing a credible geographical location for risk-free devices in a timely manner, providing data support for the normal operation of the terminal device, and improving the working efficiency of the terminal device.

[0107] In one embodiment, the method further includes: when the geographical location of the terminal device has not been tampered with, sending the current geographical location to the terminal device according to the satellite positioning information.

[0108] Among them, if the satellite positioning information, base station positioning information, and network positioning information conform to the real geographical area distribution, and the geographical location change trend of the terminal device is normal, it indicates that the geographical location of the terminal device has not been tampered with. At this time, the current geographical location of the terminal device is determined based on the satellite positioning information, and the current geographical location is sent to the terminal device, so that the terminal device directly uses the geographical location obtained by GPS positioning. Providing a credible geographical location for devices with untampered positioning in a timely manner, providing data support for the normal operation of the terminal device, and improving the working efficiency of the terminal device.

[0109] In one implementation, after sending the current geographical location to the terminal device according to the satellite positioning information, the method further includes: storing the current geographical location as a credible location related to the terminal device in a preset storage area. Correspondingly, determining the historical geographical location of the terminal device includes: reading the credible location related to the terminal device before the current moment from the preset storage area as the historical geographical location. In this way, data support is provided for the abnormal detection of the change trend.

[0110] In one embodiment, referring to Figure 4 , Figure 4 shows a positioning tampering identification system, which includes an environmental risk identification system, a positioning acquisition system, and a background control system. The environmental risk identification system includes a malicious application identification module and a positioning modification inspection module. The positioning acquisition system includes a GPS positioning acquisition module, a base station positioning acquisition module, and an IP positioning acquisition module. The background control system includes a policy distribution module and a geographical location risk control module. Among them:

[0111] The malicious application identification module is used to obtain the application installation list on the terminal device, upload the application installation list to the background control system, and the policy distribution module checks the application installation list according to the preset blacklist maintained, and obtains the inspection result.

[0112] The location modification inspection module conducts security inspections from aspects such as whether the virtual location function of the operating system is enabled, whether the terminal device uses a customized operating system, whether the terminal device installs a hook framework, and whether the terminal device enables high-risk ports, and uploads the inspection results to the background control system.

[0113] The GPS location acquisition module provides a method to obtain the target location through GPS, and uploads the obtained geographical location to the background control system.

[0114] The base station location acquisition module provides a method to obtain the target location through the mobile network base station. By calling the interface provided by the communication operator, it obtains the geographical location of the base station connected by the terminal device or the distance between the terminal device and the base station, and uploads it to the background control system.

[0115] The IP location acquisition module provides a method to obtain the location through the network IP, and uploads the obtained geographical location to the background control system.

[0116] The policy distribution module is responsible for performing security risk identification and judgment on the environmental risk information uploaded by the environmental risk identification system. According to the situation of the security risk, it determines which location acquisition modules in the location acquisition system need to be called for the current geographical location judgment. For risk-free terminal devices, the GPS location acquisition module can be directly called. For terminal devices detected with risks, all the GPS location acquisition module, base station location acquisition module, and IP location acquisition module are called to perform location acquisition and upload the results. The policy distribution module is also responsible for updating the malicious APP blacklist.

[0117] The geographical location risk control module judges the geographical locations uploaded by the GPS location acquisition module, base station location acquisition module, and IP location acquisition module in the case of security risks on the terminal device to determine whether the geographical location is tampered with. Specifically, it analyzes whether the GPS location information, base station location information, and IP location information conform to the real geographical area distribution, and analyzes whether the geographical location change trend of the terminal device is normal. Abnormal geographical location change trends include, for example, large-scale geographical location changes in a short time, no geographical location changes for a long time, etc. When the geographical location risk control module identifies that the geographical location of the terminal device is tampered with, it issues a location tampering prompt to the terminal device.

[0118] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown according to the indications of the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limitation, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of the steps or stages in other steps or other steps.

[0119] Based on the same inventive concept, an embodiment of the present application further provides a positioning anti-tampering device for implementing the positioning anti-tampering method involved above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the positioning anti-tampering device provided below can refer to the limitations on the positioning anti-tampering method in the above text, and will not be repeated here.

[0120] In one embodiment, as Figure 5 shown, a positioning anti-tampering device is provided, including:

[0121] An acquisition module 502, configured to acquire the satellite positioning information, base station positioning information, and network positioning information of the terminal device when it is detected that the terminal device has a security risk.

[0122] An analysis module 504, configured to determine whether the geographical location of the terminal device has been tampered with according to the satellite positioning information, base station positioning information, and network positioning information.

[0123] A prompt module 506, configured to send a positioning tampering prompt to the terminal device when the geographical location of the terminal device has been tampered with.

[0124] In the above positioning anti-tampering device, when it is detected that the terminal device has a security risk, based on the satellite positioning information, base station positioning information, and network positioning information of the terminal device, it can identify whether the geographical location of the terminal device has been tampered with. When the geographical location of the terminal device has been tampered with, a positioning tampering prompt is sent to the terminal device, which can prevent the terminal device from being attacked by positioning modification and enhance the security of the terminal device; when the terminal device has a security risk, further identifying whether the geographical location of the terminal device has been tampered with can improve the accuracy of location tampering identification, and thus improve the credibility of positioning data.

[0125] In one embodiment, the analysis module 504 is further configured to detect whether there is an actual base station that matches the base station positioning information to obtain a first detection result; detect whether the satellite positioning information is within the target coverage area to obtain a second detection result; the target coverage area is the coverage area of the actual base station; detect whether the satellite positioning information is within the area corresponding to the network positioning information to obtain a third detection result; detect whether the attribution of the network address corresponding to the network positioning information is consistent with the attribution of the actual base station to obtain a fourth detection result; detect whether the satellite positioning information, the base station positioning information, and the network positioning information are consistent to obtain a fifth detection result; and determine whether the geographical location of the terminal device has been tampered with according to the first detection result, the second detection result, the third detection result, the fourth detection result, and the fifth detection result.

[0126] In one embodiment, the analysis module 504 is further configured to determine the device type and historical geographical location of the terminal device; obtain the abnormal conditions corresponding to the device type; detect whether the position change trend of the terminal device satisfies the abnormal conditions according to the historical geographical location and the satellite positioning information to obtain a sixth detection result; and determine whether the geographical location of the terminal device has been tampered with according to the first detection result, the second detection result, the third detection result, the fourth detection result, the fifth detection result, and the sixth detection result.

[0127] In one embodiment, the positioning anti-tampering device further includes a risk identification module;

[0128] The risk identification module is configured to obtain the application installation list of the terminal device and detect whether there is a malicious application in the preset blacklist in the application installation list; obtain the operating system setting information of the terminal device and detect whether there is a configuration risk for the terminal device according to the operating system setting information; and determine that the terminal device has a security risk if there is a malicious application in the application installation list or the terminal device has a configuration risk.

[0129] In one embodiment, the risk identification module is further configured to receive blacklist configuration information; the blacklist configuration information includes at least one malicious application information; and update the preset blacklist according to the malicious application information.

[0130] In one embodiment, the positioning anti-tampering device further includes a distribution module;

[0131] The acquisition module 502 is further configured to obtain the satellite positioning information of the terminal device when it is detected that the terminal device has no security risk.

[0132] The analysis module 504 is further configured to determine whether the position change trend of the terminal device is normal based on the satellite positioning information.

[0133] A sending module, configured to send the current geographical location to the terminal device according to the satellite positioning information when the location change trend of the terminal device is normal.

[0134] In one embodiment, the positioning anti-tampering device further includes a sending module;

[0135] The sending module is configured to send the current geographical location to the terminal device according to the satellite positioning information when the geographical location of the terminal device has not been tampered with.

[0136] Each module in the above positioning anti-tampering device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above respective modules.

[0137] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 6 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. The computer program, when executed by the processor, implements a positioning anti-tampering method.

[0138] Those skilled in the art can understand that Figure 6 the structure shown in

[0139] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented: when a security risk of a terminal device is detected, obtain the satellite positioning information, base station positioning information, and network positioning information of the terminal device; determine whether the geographical location of the terminal device is tampered with according to the satellite positioning information, base station positioning information, and network positioning information; when the geographical location of the terminal device is tampered with, send a positioning tampering prompt to the terminal device.

[0140] In one embodiment, when the processor executes the computer program, the following steps are further implemented: detect whether there is an actual base station that matches the base station positioning information to obtain a first detection result; detect whether the satellite positioning information is within a target coverage range to obtain a second detection result; the target coverage range is the coverage range of the actual base station; detect whether the satellite positioning information is within the area corresponding to the network positioning information to obtain a third detection result; detect whether the attribution of the network address corresponding to the network positioning information is consistent with the attribution of the actual base station to obtain a fourth detection result; detect whether the satellite positioning information, base station positioning information, and network positioning information are consistent to obtain a fifth detection result; determine whether the geographical location of the terminal device is tampered with according to the first detection result, second detection result, third detection result, fourth detection result, and fifth detection result.

[0141] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine the device type and historical geographical location of the terminal device; obtain the abnormal conditions corresponding to the device type; detect whether the position change trend of the terminal device meets the abnormal conditions according to the historical geographical location and satellite positioning information to obtain a sixth detection result; determine whether the geographical location of the terminal device is tampered with according to the first detection result, second detection result, third detection result, fourth detection result, fifth detection result, and sixth detection result.

[0142] In one embodiment, when the processor executes the computer program, the following steps are further implemented: obtain the application installation list of the terminal device, and detect whether there is a malicious application located in a preset blacklist in the application installation list; obtain the operating system setting information of the terminal device, and detect whether there is a configuration risk in the terminal device according to the operating system setting information; when there is a malicious application in the application installation list or the terminal device has a configuration risk, determine that the terminal device has a security risk.

[0143] In one embodiment, when the processor executes the computer program, the following steps are further implemented: receive blacklist configuration information; the blacklist configuration information includes at least one malicious application information; update the preset blacklist according to the malicious application information.

[0144] In one embodiment, when the processor executes a computer program, the following steps are further implemented: when it is detected that there is no security risk in the terminal device, obtain the satellite positioning information of the terminal device; determine whether the position change trend of the terminal device is normal based on the satellite positioning information; when the position change trend of the terminal device is normal, send the current geographical location to the terminal device according to the satellite positioning information.

[0145] In one embodiment, when the processor executes a computer program, the following steps are further implemented: when the geographical location of the terminal device has not been tampered with, send the current geographical location to the terminal device according to the satellite positioning information.

[0146] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: when it is detected that there is a security risk in the terminal device, obtain the satellite positioning information, base station positioning information, and network positioning information of the terminal device; determine whether the geographical location of the terminal device has been tampered with according to the satellite positioning information, base station positioning information, and network positioning information; when the geographical location of the terminal device has been tampered with, issue a positioning tampering prompt to the terminal device.

[0147] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: detect whether there is an actual base station that matches the base station positioning information to obtain a first detection result; detect whether the satellite positioning information is within the target coverage range to obtain a second detection result; the target coverage range is the coverage range of the actual base station; detect whether the satellite positioning information is within the area corresponding to the network positioning information to obtain a third detection result; detect whether the attribution of the network address corresponding to the network positioning information is consistent with the attribution of the actual base station to obtain a fourth detection result; detect whether the satellite positioning information, base station positioning information, and network positioning information are consistent to obtain a fifth detection result; determine whether the geographical location of the terminal device has been tampered with according to the first detection result, second detection result, third detection result, fourth detection result, and fifth detection result.

[0148] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine the device type and historical geographical location of the terminal device; obtain the abnormal conditions corresponding to the device type; detect whether the position change trend of the terminal device meets the abnormal conditions according to the historical geographical location and the satellite positioning information to obtain a sixth detection result; determine whether the geographical location of the terminal device has been tampered with according to the first detection result, second detection result, third detection result, fourth detection result, fifth detection result, and sixth detection result.

[0149] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: obtaining an application installation list of the terminal device, and detecting whether there is a malicious application located in a preset blacklist in the application installation list; obtaining the operating system setting information of the terminal device, and detecting whether there is a configuration risk in the terminal device according to the operating system setting information; in the case that there is a malicious application in the application installation list or the terminal device has a configuration risk, determining that the terminal device has a security risk.

[0150] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: receiving blacklist configuration information; the blacklist configuration information includes at least one malicious application information; updating the preset blacklist according to the malicious application information.

[0151] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: in the case that it is detected that the terminal device has no security risk, obtaining the satellite positioning information of the terminal device; determining whether the position change trend of the terminal device is normal based on the satellite positioning information; in the case that the position change trend of the terminal device is normal, sending the current geographical location to the terminal device according to the satellite positioning information.

[0152] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: in the case that the geographical location of the terminal device has not been tampered with, sending the current geographical location to the terminal device according to the satellite positioning information.

[0153] In one embodiment, a computer program product is provided, including a computer program, which when executed by a processor, implements the following steps: in the case that it is detected that the terminal device has a security risk, obtaining the satellite positioning information, base station positioning information, and network positioning information of the terminal device; determining whether the geographical location of the terminal device has been tampered with according to the satellite positioning information, base station positioning information, and network positioning information; in the case that the geographical location of the terminal device has been tampered with, sending a positioning tampering prompt to the terminal device.

[0154] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: detecting whether there is an actual base station that matches the base station positioning information to obtain a first detection result; detecting whether the satellite positioning information is within a target coverage area to obtain a second detection result; the target coverage area is the coverage area of the actual base station; detecting whether the satellite positioning information is within the area corresponding to the network positioning information to obtain a third detection result; detecting whether the attribution of the network address corresponding to the network positioning information is consistent with the attribution of the actual base station to obtain a fourth detection result; detecting whether the satellite positioning information, the base station positioning information, and the network positioning information are consistent to obtain a fifth detection result; and determining whether the geographical location of the terminal device has been tampered with according to the first detection result, the second detection result, the third detection result, the fourth detection result, and the fifth detection result.

[0155] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determining the device type and historical geographical location of the terminal device; obtaining an abnormal condition corresponding to the device type; detecting whether the position change trend of the terminal device satisfies the abnormal condition according to the historical geographical location and the satellite positioning information to obtain a sixth detection result; and determining whether the geographical location of the terminal device has been tampered with according to the first detection result, the second detection result, the third detection result, the fourth detection result, the fifth detection result, and the sixth detection result.

[0156] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: obtaining the application installation list of the terminal device and detecting whether there is a malicious application located in a preset blacklist; obtaining the operating system setting information of the terminal device and detecting whether there is a configuration risk for the terminal device according to the operating system setting information; and determining that the terminal device has a security risk when there is a malicious application in the application installation list or the terminal device has a configuration risk.

[0157] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: receiving blacklist configuration information; the blacklist configuration information includes at least one malicious application information; and updating the preset blacklist according to the malicious application information.

[0158] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: when it is detected that the terminal device has no security risk, obtaining the satellite positioning information of the terminal device; determining whether the position change trend of the terminal device is normal based on the satellite positioning information; and when the position change trend of the terminal device is normal, sending the current geographical location to the terminal device according to the satellite positioning information.

[0159] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: when the geographical location of the terminal device has not been tampered with, send the current geographical location to the terminal device according to the satellite positioning information.

[0160] It should be noted that the information collected in this application is information and data authorized by the user or fully authorized by all parties. Moreover, for the processing of relevant data such as collection, storage, use, processing, transmission, provision, disclosure, and application, all comply with relevant regulations and standards, necessary confidentiality measures are taken, it does not violate public order and good customs, and a corresponding operation entry is provided for the user to choose to authorize or reject.

[0161] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random-access memories (ReRAM), magnetoresistive random-access memories (MRAM), ferroelectric random-access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., and are not limited thereto. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logics, data processing logics based on quantum computing, etc., and are not limited thereto.

[0162] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0163] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A positioning anti-tampering method, characterized in that: The method comprises: When a terminal device is detected to have a security risk, obtaining satellite positioning information, base station positioning information, and network positioning information of the terminal device; Determining whether the geographical location of the terminal device has been tampered with according to the satellite positioning information, the base station positioning information and the network positioning information; In the event that the geographical location of the terminal device is tampered with, a location tampering prompt is sent to the terminal device.

2. The method according to claim 1, characterized in that The determining, according to the satellite positioning information, the base station positioning information and the network positioning information, whether the geographical location of the terminal device has been tampered with includes: Detecting whether there is an actual base station matching the base station location information to obtain a first detection result; Detecting whether the satellite positioning information is within a target coverage range to obtain a second detection result; the target coverage range is the coverage range of the actual base station; detecting whether the satellite positioning information is within an area corresponding to the network positioning information to obtain a third detection result; Detecting whether the ownership of the network address corresponding to the network positioning information is consistent with the ownership of the actual base station, and obtaining a fourth detection result; detecting whether the satellite positioning information, the base station positioning information, and the network positioning information are consistent, and obtaining a fifth detection result; Determine whether the geographic location of the terminal device has been tampered with based on the first detection result, the second detection result, the third detection result, the fourth detection result, and the fifth detection result.

3. The method according to claim 2, characterized in that The method further comprises: Determining a device type and a historical geographic location of the terminal device; Obtaining an abnormal condition corresponding to the device type; Detecting, according to the historical geographical location and the satellite positioning information, whether the location change trend of the terminal device meets the abnormal condition, to obtain a sixth detection result; Determine whether the geographic location of the terminal device has been tampered with based on the first detection result, the second detection result, the third detection result, the fourth detection result, the fifth detection result, and the sixth detection result.

4. The method according to claim 1, characterized in that: The method comprises: Obtaining an application installation list of the terminal device, and detecting whether there is a malicious application in a preset blacklist in the application installation list; Acquire operating system setting information of the terminal device, and detect whether the terminal device has a configuration risk according to the operating system setting information; When there are malicious applications in the application installation list or there are configuration risks in the terminal device, it is determined that there are security risks in the terminal device.

5. The method according to claim 4, characterized in that The method comprises: Receive blacklist configuration information; the blacklist configuration information includes at least one malicious application information; The preset blacklist is updated according to the malicious application information.

6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: When it is detected that there is no security risk to the terminal device, obtaining satellite positioning information of the terminal device; Determining whether the location change trend of the terminal device is normal based on the satellite positioning information; When the position change trend of the terminal device is normal, the current geographical location is sent to the terminal device according to the satellite positioning information.

7. The method according to any one of claims 1 to 5, characterized in that The method further comprises: In the case where the geographical location of the terminal device has not been tampered with, the current geographical location is sent to the terminal device according to the satellite positioning information.

8. A positioning anti-tampering device, characterized in that: The device comprises: An acquisition module, used to acquire satellite positioning information, base station positioning information and network positioning information of the terminal device when a security risk is detected in the terminal device; An analysis module, used to determine whether the geographical location of the terminal device has been tampered with according to the satellite positioning information, the base station positioning information and the network positioning information; The prompt module is used to send a location tampering prompt to the terminal device when the geographical location of the terminal device is tampered with.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.