Data processing method and device, electronic equipment and storage medium

By obtaining data from electronic devices locally and cloud, and performing correlation processing and merging, the problem of incomplete and coherent electronic evidence in the prior art is solved, and a more efficient digital forensic process is achieved.

CN120104667APending Publication Date: 2025-06-06SUZHOU LONGXIN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510178321.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Existing digital forensics technology is difficult to obtain complete and coherent evidence of local and cloud data for electronic devices, resulting in incomplete and coherent electronic evidence.

Method used

By obtaining inherent data from electronic sample materials locally and obtaining cloud data related to electronic sample materials from cloud services, we can process the association according to preset key matching indicators (such as time stamp information, geographical location information, keyword information), and then merge and perform visual display.

Benefits of technology

A more complete and coherent acquisition of electronic evidence is achieved, which helps to quickly locate and analyze key information and improves the efficiency and accuracy of investigations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120104667A_ABST
    Figure CN120104667A_ABST
Patent Text Reader

Abstract

The invention discloses a data processing method and device, electronic equipment and a storage medium, and relates to the technical field of digital forensics. The method comprises the following steps: locally acquiring inherent data from an electronic inspection material, and acquiring cloud data related to the electronic inspection material from a cloud service; wherein the cloud data at least comprises data of at least one application program in the electronic inspection material; performing association processing on the inherent data and the cloud data according to a preset key matching index; and carrying out merging processing on the data after association processing to obtain comprehensive evidence data, and carrying out visual display on the comprehensive evidence data. According to the scheme, the local inherent data of the electronic inspection material and the cloud data of the electronic inspection material are associated and integrated, so that more complete and coherent evidence data can be provided, key information can be quickly positioned and analyzed, the front and back effects of an event can be deeply understood through multi-dimensional analysis, and the investigation efficiency and accuracy are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital forensics, and in particular to a data processing method, device, electronic equipment and storage medium. Background Art

[0002] Digital forensics refers to the use of scientific methods to identify, collect, protect, analyze, and present electronic evidence.

[0003] At present, when conducting digital forensics, it is mainly carried out on the data stored locally on the user's electronic device. However, the electronic evidence obtained in this way is not complete and coherent. Therefore, a new method for digital forensics is urgently needed. Summary of the invention

[0004] The present invention provides a data processing method, device, electronic equipment, storage medium and computer program product.

[0005] According to one aspect of the present invention, there is provided a data processing method, comprising:

[0006] Acquire inherent data from the electronic sample locally, and acquire cloud data related to the electronic sample from the cloud service; wherein the cloud data at least includes data of at least one application in the electronic sample;

[0007] According to the preset key matching indicators, the inherent data and cloud data are associated and processed;

[0008] The data after correlation processing are merged to obtain comprehensive evidence data, and the comprehensive evidence data is visualized.

[0009] In some embodiments, obtaining cloud data related to electronic samples from a cloud service includes:

[0010] Temporarily log in to the account application in the electronic sample by connecting the spare machine to the SIM card;

[0011] Through cloud data extraction tools, cloud data of electronic samples to be extracted can be obtained from cloud services.

[0012] In some embodiments, the key matching indicator includes at least one of timestamp information, geographic location information, and keyword information;

[0013] Accordingly, the inherent data and cloud data are associated and processed according to the preset key matching indicators, including:

[0014] Extract timestamp information, geographic location information, and keyword information from native data and cloud data;

[0015] According to the timestamp information, geographic location information and keyword information included in the inherent data, and the timestamp information, geographic location information and keyword information included in the cloud data, the inherent data and the cloud data are associated with each other.

[0016] In some embodiments, extracting geographic location information from native data and cloud data includes:

[0017] Determine geographic location information based on geo-tags included in the native data and cloud data; or,

[0018] Determine geographic location information based on inherent data and cloud data including the names of points of interest, combined with map services.

[0019] In some embodiments, the data after the association processing is merged to obtain comprehensive evidence data, and the comprehensive evidence data is visualized, including:

[0020] According to the timestamp information and geographic location information included in the data after association processing, each geographic location point is arranged in chronological order to obtain a geographic location sequence in chronological order, and the geographic location sequence is used as comprehensive evidence data;

[0021] Based on the sequence of geographic locations, the movement trajectory of the electronic sample owner is constructed in the map service and displayed visually.

[0022] In some embodiments, before associating the inherent data with the cloud data according to the preset key matching index, the method further includes:

[0023] The inherent data and cloud data are cleaned; wherein the cleaning process includes at least one of removing duplicate records, correcting erroneous data, and filling in missing values.

[0024] According to another aspect of the present invention, there is provided a data processing device, comprising:

[0025] A data acquisition module, used to acquire inherent data from the electronic sample locally, and to acquire cloud data related to the electronic sample from the cloud service; wherein the cloud data at least includes data of at least one application in the electronic sample;

[0026] The matching module is used to associate the inherent data with the cloud data according to the preset key matching indicators;

[0027] The merging and display module is used to merge the data after association processing to obtain comprehensive evidence data, and to visualize the comprehensive evidence data.

[0028] In some embodiments, the data acquisition module includes:

[0029] A temporary login unit is used to temporarily log in to the account application in the electronic sample by connecting the standby machine to the SIM card;

[0030] The first data extraction unit is used to obtain the cloud data of the electronic sample to be extracted from the cloud service through the cloud data extraction tool.

[0031] In some embodiments, the key matching indicator includes at least one of timestamp information, geographic location information, and keyword information;

[0032] Accordingly, the matching module includes:

[0033] A second data extraction unit, used to extract timestamp information, geographic location information and keyword information from the inherent data and the cloud data;

[0034] The association matching unit is used to associate the inherent data with the cloud data according to the timestamp information, geographic location information and keyword information included in the inherent data and the timestamp information, geographic location information and keyword information included in the cloud data.

[0035] In some embodiments, the second data extraction unit is further configured to:

[0036] Determine geographic location information based on geo-tags included in the native data and cloud data; or,

[0037] Determine geographic location information based on inherent data and cloud data including the names of points of interest, combined with map services.

[0038] In some embodiments, the merging and displaying module is specifically used to:

[0039] According to the timestamp information and geographic location information included in the data after association processing, each geographic location point is arranged in chronological order to obtain a geographic location sequence in chronological order, and the geographic location sequence is used as comprehensive evidence data;

[0040] Based on the sequence of geographic locations, the movement trajectory of the electronic sample owner is constructed in the map service and displayed visually.

[0041] In some embodiments, the data processing apparatus further comprises:

[0042] The cleaning module is used to clean the inherent data and the cloud data before associating them according to preset key matching indicators; wherein the cleaning process includes at least one of removing duplicate records, correcting erroneous data, and filling missing values.

[0043] According to another aspect of the present invention, there is provided an electronic device, the electronic device comprising:

[0044] at least one processor; and

[0045] a memory communicatively connected to at least one processor; wherein,

[0046] The memory stores a computer program that can be executed by at least one processor. The computer program is executed by at least one processor so that the at least one processor can execute the data processing method of the embodiment of the present invention.

[0047] According to another aspect of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the data processing method of an embodiment of the present invention when executed.

[0048] According to another aspect of the present invention, a computer program product is provided, comprising a computer program, and when the computer program is executed by a processor, the steps in the above method are implemented.

[0049] The technical solution of the embodiment of the present invention can provide more complete and coherent evidence data by associating and integrating the local inherent data of electronic samples and the cloud data of electronic samples, which is helpful to quickly locate and analyze key information. Multi-dimensional analysis can provide a deeper understanding of the causes and consequences of events and improve the efficiency and accuracy of investigations.

[0050] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0052] Figure 1 It is a flowchart of a data processing method provided by an embodiment of the present invention;

[0053] Figure 2 is a flow chart of another data processing method provided by an embodiment of the present invention;

[0054] Figure 3 is a structural schematic diagram of a data processing device provided by an embodiment of the present invention;

[0055] Figure 4It is a structural schematic diagram of an electronic device for implementing the data processing method of an embodiment of the present invention. DETAILED DESCRIPTION

[0056] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0057] Embodiment 1

[0058] Figure 1 A flowchart of a data processing method provided in an embodiment of the present invention. This embodiment can be applicable to scenarios of digital forensics. The method can be executed by a data processing device. The data processing device can be implemented in the form of hardware and / or software. The data processing device can be configured in an electronic device.

[0059] like Figure 1 As shown, the data processing method includes:

[0060] S101. Acquire inherent data from the electronic sample locally, and acquire cloud data related to the electronic sample from the cloud service.

[0061] In the embodiment of the present invention, electronic inspection materials refer to various electronic items or storage media that can be used as sources of evidence in the process of digital evidence collection. It contains electronic data related to the case and is a key object of digital evidence collection. Common electronic inspection materials are of various types, such as electronic devices such as mobile phones and computers, or storage media such as hard disks and USB flash drives. The present invention is illustrated by taking the electronic inspection material as an example of an electronic device. In the modern digital society, electronic devices used by individuals have become an important part of people's daily lives. Electronic devices not only store a large amount of local data, but also can synchronize and save data of various applications through cloud services. Therefore, the present invention proposes to use the cloud data on the electronic device to associate and merge with the inherent data of the local electronic device to construct more complete evidence data. In the specific implementation, the inherent data can be obtained from the local storage of the electronic inspection material through standardized interfaces and protocols, and the cloud data related to the electronic inspection material can be obtained from the cloud service, so as to ensure that data from different sources can be seamlessly connected and integrated, providing a data basis for subsequent matching.

[0062] In an optional implementation, obtaining inherent data from the electronic material locally includes: using a data line to establish a communication connection between the electronic material and a local data acquisition device, so that the local data acquisition device can obtain inherent data from the electronic material locally based on a standardized interface and protocol; wherein inherent data refers to data that is fixed locally from the electronic material and can be used as electronic evidence. Exemplarily, inherent data can be picture / video data, call record data, etc. stored locally in the electronic material.

[0063] In an optional implementation, obtaining cloud data related to electronic materials from cloud services includes: temporarily logging into the account application in the electronic materials by connecting a spare machine to a SIM card; obtaining cloud data of the application to be extracted from the electronic materials from the cloud service by using a cloud data extraction tool; wherein the cloud data may include data uploaded by at least one application in the electronic materials. Exemplarily, the cloud data may be email data, social media interaction data, payment bills uploaded to the cloud service by payment applications, etc.; wherein the payment bills include information such as transaction date and merchant name.

[0064] It is understandable that the solution of the present invention is essentially to obtain data from multiple data sources in order to determine electronic evidence based on the data from multiple data sources. Compared with obtaining data from a single data source (such as local electronic evidence) to form electronic evidence, the electronic evidence constructed by the present invention will be more complete and coherent.

[0065] It should be noted that the inherent data obtained locally in the electronic samples and the cloud data collected in the cloud are information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the relevant countries and regions, take necessary confidentiality measures, and do not violate public order and good morals.

[0066] S102: Correlate the inherent data and the cloud data according to preset key matching indicators.

[0067] In the embodiment of the present invention, the key matching index includes at least one of timestamp information, geographic location information, and keyword information. On this basis, the inherent data and the cloud data are associated according to the preset key matching index, including: extracting timestamp information, geographic location information, and keyword information from the inherent data and the cloud data; according to the timestamp information, geographic location information, and keyword information included in the inherent data, and the timestamp information, geographic location information, and keyword information included in the cloud data, the inherent data and the cloud data are associated.

[0068] In an embodiment of the present invention, the inherent data and cloud data usually include clear time information and text descriptions, so timestamp information and keyword information can be directly extracted from the inherent data and cloud data. However, the inherent data and cloud data may not include direct geographic location information, so extracting geographic location information from the inherent data and cloud data includes: determining geographic location information based on the inherent data and cloud data including geographic tags. Exemplarily, taking the inherent data and cloud data as a video or picture taken of electronic materials as an example, the geographic tags embedded during shooting (which can be an Exif data) can be extracted from the inherent data and cloud data through a special data reading tool, and the geographic tags can be converted into specific geographic location information (such as longitude and latitude information) through a map service. Alternatively, the geographic location information can be determined based on the names of points of interest (such as the names of merchants included in payment records, etc.) included in the inherent data and cloud data, combined with a map service; for example, a search is performed in the map service based on the merchant name, and the corresponding geographic location information is determined based on the search results.

[0069] When performing data matching, it can be based on timestamp information alone, geographic location information alone, or keywords alone, or it can be based on these three key matching indicators at the same time, and no specific limitation is made here. Exemplarily, when performing data association matching based on timestamp information, each data record included in the inherent data is sorted in chronological order, and each data record included in the cloud data is sorted in chronological order; each data record in the inherent data is traversed in turn, and each time a data record is traversed, the timestamp information of the data record is compared with the timestamp information of each data record included in the cloud data; if the time of the data record (such as a consumption record) is the same as the time of one or more data records (such as social media interaction records) in the cloud data or the time difference meets the preset conditions, a matching relationship in the time dimension is constructed. When matching based on geographic location information, if the geographic location information included in a consumption record in the inherent data is the same as the geographic location information included in a video / picture in the cloud data, a matching relationship in the spatial dimension is established. When performing association matching based on keyword information (such as a specific file name, application name, transaction description, etc.), the title of a document in the inherent data can be used as a keyword to search for records containing the same keyword in the cloud data, such as related operation records of the same document stored in the cloud, and then a keyword-based matching relationship can be constructed.

[0070] It can be understood that through association processing, not only the matching relationship between inherent data and cloud data can be determined, but also the timestamp information and geographic location information of each data record in the inherent data, as well as the timestamp information and geographic location information of each data record in the cloud data can be determined.

[0071] It should be noted that the above-mentioned association processing of the inherent data and the cloud data according to the preset key matching indicators is only an optional implementation scheme. In addition, machine learning algorithms can also be used for data association processing. For example, through the machine learning algorithm, historical matching data is learned, the association pattern between information of different dimensions is analyzed, and then the matching relationship between the newly collected inherent data and the cloud data is predicted.

[0072] S103: Merge the associated data to obtain comprehensive evidence data, and visualize the comprehensive evidence data.

[0073] In an embodiment of the present invention, the data after the association processing can be merged in a serial manner. Specifically, each geographical location point can be arranged in chronological order according to the timestamp information and geographical location information included in the data after the association processing to obtain a geographical location sequence in chronological order, and the geographical location sequence can be used as comprehensive evidence data; according to the geographical location sequence, the movement trajectory of the owner of the electronic evidence can be constructed in the map service. For example, for two geographical location points that are adjacent in the time dimension, the movement trajectory between the two geographical location points can be planned according to the connecting road between the two geographical location points and the time difference between the two geographical location points, and a visual display can be performed. In addition, some important geographical location points can also be marked.

[0074] In the embodiment of the present invention, the inherent data on the electronic device and the cloud data respectively record the user's activities in different scenarios. The cloud data may contain information that is not saved on the device, such as emails, social media activities, etc. Therefore, by associating and matching the inherent data and the cloud data and integrating the data, a complete and coherent electronic evidence can be obtained. In addition, by associating and matching the data in three dimensions, namely, timestamp, geographic location and keywords, the time and spatial distribution relationship of different data records can be clarified, thus realizing the visual display of electronic evidence.

[0075] The data processing method in the embodiment of the present invention can be implemented based on a distributed computing framework to ensure the high efficiency of data processing. Moreover, the distributed computing framework has good scalability and can dynamically adjust resource allocation according to the growth of data volume.

[0076] Embodiment 2

[0077] Figure 2 A flowchart of a data processing method provided by an embodiment of the present invention. Figure 2 , the method comprises the following steps:

[0078] S201. Acquire inherent data from the electronic sample locally, and acquire cloud data related to the electronic sample from the cloud service; wherein the cloud data at least includes data of at least one application in the electronic sample.

[0079] S202: Clean the inherent data and cloud data.

[0080] In the embodiment of the present invention, the cleaning process includes at least one of removing duplicate records, correcting erroneous data, and filling missing values. Among them, removing duplicate records means deleting duplicate data records in the inherent data and cloud data; correcting erroneous data may mean modifying data with errors in data format to a unified format; filling missing values ​​means supplementing data with missing data types or values.

[0081] In the embodiment of the present invention, the cleaned inherent data and cloud data can be unified in data structure through data formatting technology to facilitate subsequent processing.

[0082] S203: According to preset key matching indicators, the cleaned inherent data and cloud data are associated with each other.

[0083] In an embodiment of the present invention, the key matching index includes at least one of timestamp information, geographic location information, and keyword information; the inherent data and cloud data are associated according to the preset key matching index, including: extracting timestamp information, geographic location information, and keyword information from the inherent data and cloud data; and associating the inherent data and cloud data according to the timestamp information, geographic location information, and keyword information included in the inherent data and the timestamp information, geographic location information, and keyword information included in the cloud data. Extracting geographic location information from the inherent data and cloud data includes: determining geographic location information according to geographic tags included in the inherent data and cloud data; or determining geographic location information according to the names of points of interest included in the inherent data and cloud data in combination with map services.

[0084] S204: Merge the associated data to obtain comprehensive evidence data, and visualize the comprehensive evidence data.

[0085] Optionally, based on the timestamp information and geographic location information included in the associated data, each geographic location point is arranged in chronological order to obtain a chronological geographic location sequence, and the geographic location sequence is used as comprehensive evidence data; based on the geographic location sequence, the movement trajectory of the owner of the electronic sample is constructed in the map service and displayed visually.

[0086] The present invention can ensure the accuracy of subsequent data association matching by cleaning inherent data and cloud data.

[0087] Embodiment 3

[0088] Figure 3 The structure diagram of a data processing device provided by an embodiment of the present invention is shown in FIG. This embodiment is applicable to the scenario of digital forensics. The device can execute any data processing method of the present invention. Figure 3 As shown, the data processing device includes:

[0089] The data acquisition module 301 is used to acquire inherent data from the electronic sample locally, and to acquire cloud data related to the electronic sample from the cloud service; wherein the cloud data at least includes data of at least one application in the electronic sample;

[0090] A matching module 302 is used to associate the inherent data with the cloud data according to preset key matching indicators;

[0091] The merging and displaying module 303 is used to merge the data after the association processing to obtain comprehensive evidence data, and to visually display the comprehensive evidence data.

[0092] In some embodiments, the data acquisition module 301 includes:

[0093] A temporary login unit is used to temporarily log in to the account application in the electronic sample by connecting the standby machine to the SIM card;

[0094] The first data extraction unit is used to obtain the cloud data of the electronic sample to be extracted from the cloud service through the cloud data extraction tool.

[0095] In some embodiments, the key matching indicator includes at least one of timestamp information, geographic location information, and keyword information;

[0096] Accordingly, the matching module 302 includes:

[0097] A second data extraction unit, used to extract timestamp information, geographic location information and keyword information from the inherent data and the cloud data;

[0098] The association matching unit is used to associate the inherent data with the cloud data according to the timestamp information, geographic location information and keyword information included in the inherent data and the timestamp information, geographic location information and keyword information included in the cloud data.

[0099] In some embodiments, the second data extraction unit is further configured to:

[0100] Determine geographic location information based on geo-tags included in the native data and cloud data; or,

[0101] Determine geographic location information based on inherent data and cloud data including the names of points of interest, combined with map services.

[0102] In some embodiments, the merging and displaying module 303 is specifically used to:

[0103] According to the timestamp information and geographic location information included in the data after association processing, each geographic location point is arranged in chronological order to obtain a geographic location sequence in chronological order, and the geographic location sequence is used as comprehensive evidence data;

[0104] Based on the sequence of geographic locations, the movement trajectory of the electronic sample owner is constructed in the map service and displayed visually.

[0105] In some embodiments, the data processing apparatus further comprises:

[0106] The cleaning module is used to clean the inherent data and the cloud data before associating them according to preset key matching indicators; wherein the cleaning process includes at least one of removing duplicate records, correcting erroneous data, and filling missing values.

[0107] The data processing device provided in the embodiment of the present invention can execute the data processing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0108] According to an embodiment of the present invention, the present invention also provides an electronic device, a readable storage medium and a computer program product.

[0109] Embodiment 4

[0110] Figure 4 The components, their connections and relationships, and their functions shown herein are merely examples and are not intended to limit implementation of the invention described and / or claimed herein.

[0111] like Figure 4As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0112] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0113] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as executing a data processing method.

[0114] In some embodiments, the data processing method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the data processing method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to perform the data processing method in any other appropriate manner (e.g., by means of firmware).

[0115] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0116] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0117] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0118] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0119] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0120] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.

[0121] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.

[0122] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A data processing method, characterized in that: include: Acquire inherent data from the electronic sample locally, and acquire cloud data related to the electronic sample from a cloud service; wherein the cloud data at least includes data of at least one application in the electronic sample; According to preset key matching indicators, the inherent data and the cloud data are associated with each other; The associated data are merged to obtain comprehensive evidence data, and the comprehensive evidence data is visualized.

2. The method according to claim 1, characterized in that: The obtaining of cloud data related to the electronic sample from the cloud service includes: Temporarily log in to the account application in the electronic sample by connecting the spare machine to the SIM card; Through the cloud data extraction tool, the cloud data of the electronic sample to be extracted is obtained from the cloud service.

3. The method according to claim 1, characterized in that The key matching indicator includes at least one of timestamp information, geographic location information, and keyword information; Accordingly, the inherent data and the cloud data are associated with each other according to the preset key matching index, including: Extracting timestamp information, geographic location information, and keyword information from the inherent data and the cloud data; According to the timestamp information, geographic location information and keyword information included in the inherent data, and the timestamp information, geographic location information and keyword information included in the cloud data, the inherent data and the cloud data are associated with each other.

4. The method according to claim 3, characterized in that Extracting geographic location information from the inherent data and the cloud data includes: Determine the geographic location information according to the inherent data and the geographic tags included in the cloud data; or, The geographic location information is determined based on the inherent data and the names of points of interest included in the cloud data in combination with a map service.

5. The method according to claim 3, characterized in that: The data after the association processing is merged to obtain comprehensive evidence data, and the comprehensive evidence data is visualized, including: Arrange each geographical location point in chronological order according to the timestamp information and geographical location information included in the associated data to obtain a geographical location sequence in chronological order, and use the geographical location sequence as the comprehensive evidence data; According to the sequence of geographic locations, the movement trajectory of the owner of the electronic sample is constructed in the map service and displayed visually.

6. The method according to claim 1, characterized in that Before associating the inherent data with the cloud data according to the preset key matching index, the method further includes: The inherent data and the cloud data are cleansed; wherein the cleaning process includes at least one of removing duplicate records, correcting erroneous data, and filling missing values.

7. A data processing device, characterized in that: include: A data acquisition module, used to acquire inherent data from the electronic sample locally, and to acquire cloud data related to the electronic sample from a cloud service; wherein the cloud data at least includes data of at least one application in the electronic sample; A matching module, used for associating the inherent data with the cloud data according to preset key matching indicators; The merging and displaying module is used to merge the data after the association processing to obtain comprehensive evidence data, and to visually display the comprehensive evidence data.

8. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the method according to any one of claims 1 to 6 when executed.

10. A computer program product, comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 6.