Fraud identification method and system based on machine-card separation and communication information

By transforming the machine card separation technology to connect to HTTPS protocol, and combining the operator's analysis technology and AI model, the shortcomings of the existing technology in fraud-related judgments are solved, and more efficient fraud identification and prevention are achieved.

CN120201434APending Publication Date: 2025-06-24CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510443051.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing organic card separation technology has serious shortcomings in judging abnormal situations involving fraud, and cannot effectively identify and prevent complex, changeable and highly concealed fraud methods.

Method used

By transforming the large network docking method of separating machines and cards into HTTPS protocol docking, and deeply integrating operators' call behavior analysis and call content analysis technology, a powerful AI call model is introduced to realize collaborative analysis and intelligent judgment of multi-dimensional data.

Benefits of technology

It significantly improves the accuracy of intelligent judgment on fraud involving calls, can fully identify potential fraud behaviors, and effectively prevent fraud incidents through timely risk assessment and early warning mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201434A_ABST
    Figure CN120201434A_ABST
Patent Text Reader

Abstract

The invention provides a fraud identification method and system based on machine-card separation and communication information, electronic equipment and a storage medium, and aims to solve the problem of insufficient fraud judgment. The method comprises the following steps: converting a machine-card separation docking mode into an HTTPS protocol; after the user inserts the card for the first time, automatically acquiring machine card information, and binding the machine card; when it is detected that the card replaces the terminal, authorization verification is carried out, and binding is carried out after verification is passed; collecting and preprocessing communication data of the card; constructing a data set containing various communication contents and behavior characteristics, and training and optimizing a deep learning model to identify abnormal modes and potential fraud behaviors in communication; and judging whether machine-card separation exists or not through machine-card verification data, and identifying possible fraud-related communication behaviors according to the machine-card separation behavior of the user in combination with the call score of the model on the real-time communication behavior and the communication content. According to the invention, the accuracy of intelligent judgment of fraud can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the fields of information security and artificial intelligence technologies, and particularly relates to a fraud recognition method based on separation of a terminal device from a SIM card (Subscriber Identity Module) and communication information, a fraud recognition system based on separation of a terminal device from a SIM card and communication information, an electronic device, and a computer-readable storage medium. Background Art

[0002] With the rapid evolution of communication technologies, the technology of separating a terminal device from a SIM card has become increasingly prominent in protecting user privacy and preventing communication fraud. Its core principle lies in the refined management of the binding relationship between a terminal device and a SIM card (Subscriber Identity Module), thereby building a solid defense line to effectively prevent illegal devices from accessing the network, significantly strengthening the user identity verification process, and creating a relatively safe and stable network environment for operators. In the existing technical system, some solutions for separating a terminal device from a SIM card mainly rely on static rules and simple pattern matching technologies to identify fraud-related communication behaviors. For the acquisition of call content, it mainly depends on conventional call recording means and basic call transcription technologies to collect data, and then analyze and judge based on this limited data.

[0003] However, such technical means have serious limitations. The technology of separating a terminal device from a SIM card exposes many key defects in the actual application process. In terms of technical implementation and interface opening, most of the widely used docking protocols for separating a terminal device from a SIM card on the market adopt a large network docking architecture combining OTA (Over-the-Air Technology) and digital short messages. Although this mode can achieve the basic function of separating a terminal device from a SIM card, due to the existence of middleware bridging, the system architecture is complicated, seriously hindering the efficient integration with existing network infrastructure, greatly limiting its flexible deployment and wide application in diverse application scenarios, and restricting the overall communication efficiency. More critically, the existing technology for separating a terminal device from a SIM card has serious deficiencies in judging fraud-related abnormal situations. It lacks the in-depth insight and intelligent analysis capabilities for the dynamic changes of complex communication behaviors, and is difficult to comprehensively and accurately identify and effectively prevent increasingly complex, changeable, and highly concealed fraud means, unable to meet the stringent requirements of modern communication security. Summary of the Invention

[0004] To address the serious deficiencies in the current SIM-card separation technology in judging fraud-related abnormal situations, the present disclosure provides a fraud recognition method based on SIM-card separation and communication information, a fraud recognition system based on SIM-card separation and communication information, an electronic device, and a computer-readable storage medium. By innovating the data docking method of SIM-card separation to the more advanced, secure, and universal HTTPS protocol (Hypertext Transfer Protocol Secure), and at the same time deeply integrating the operator's call behavior analysis and call content analysis technologies, and introducing a powerful AI call large model, the collaborative analysis and intelligent judgment of multi-dimensional data are realized. It can comprehensively improve the accuracy of intelligent judgment of fraud in calls and meet the urgent and practical needs in the current field of communication security.

[0005] In a first aspect, the present disclosure provides a fraud recognition method based on SIM-card separation and communication information, the method comprising:

[0006] Convert the data docking method of the SIM-card separation interface to the HTTPS protocol to achieve the docking of the terminal with the existing network infrastructure through the HTTPS protocol;

[0007] After the user inserts the SIM card and powers on for the first time, automatically obtain the SIM-card information of the terminal and the USIM card (Universal Subscriber Identity Module), and perform SIM-card binding;

[0008] When it is detected that the user's USIM card is replaced with a terminal, perform authorization verification, and after the verification passes, perform SIM-card binding again;

[0009] Collect the communication data of the USIM card, including SIM-card verification data, call records, text message content, and network traffic;

[0010] Preprocess the collected data;

[0011] Construct a data set containing various communication contents and behavior characteristics through the preprocessed communication data, and train and optimize a deep learning model through the data set to identify abnormal patterns and potential fraud behaviors in communication behaviors;

[0012] Judge whether there is SIM-card separation through the SIM-card verification data, and based on the user's SIM-card separation behavior, combined with the call scores of the real-time communication behavior and communication content of the deep learning model, identify possible fraud-related communication behaviors.

[0013] Further, the conversion of the data docking method of the SIM-card separation interface to the HTTPS protocol includes:

[0014] Convert the data of the card separation interface: Dynamically identify various variants of OTA and digital SMS data formats through an adaptive parsing algorithm, and convert the data into a structure that meets the requirements of the HTTPS protocol according to the characteristics of the data format;

[0015] When converting data from the card separation interface to the HTTPS protocol, dynamically allocate different levels of encryption keys according to the sensitivity of the data and the transmission stage;

[0016] Intelligently cache data that may be frequently accessed according to the historical data transmission pattern and the real-time network condition.

[0017] Furthermore, the dynamically identifying various variants of OTA and digital SMS data formats through an adaptive parsing algorithm and converting the data into a structure that meets the requirements of the HTTPS protocol according to the characteristics of the data format includes:

[0018] Data feature extraction: Extract key features from the original data, which can represent the structure and content of the data;

[0019] Pattern recognition: Use a machine learning model to identify the pattern and structure of the data;

[0020] Automatic learning and adaptation: The adaptive parsing algorithm automatically adjusts its model parameters according to new data samples to adapt to different data formats;

[0021] Conversion rule generation: Automatically generate rules for converting data into the structure required by the HTTPS protocol according to the identified data pattern.

[0022] Furthermore, the intelligently caching data that may be frequently accessed according to the historical data transmission pattern and the real-time network condition includes:

[0023] Data access pattern analysis: Identify frequently accessed data patterns by analyzing historical data access logs;

[0024] Real-time network condition monitoring: Monitor the network condition in real time, including indicators such as bandwidth, latency, and packet loss rate;

[0025] Intelligent caching strategy: Develop an intelligent caching strategy according to the identified data access pattern and the real-time network condition;

[0026] Prefetch operation: Based on a prediction model, predict upcoming data transmission requirements and perform data prefetching in advance.

[0027] Furthermore, after the user inserts the card and powers on the device for the first time, automatically obtain the device-card information of the terminal and the USIM card and perform device-card binding, including:

[0028] After the user inserts the USIM card into the device and powers it on, the device automatically reads the device-card information of the terminal and the USIM card. The device-card information includes the ICCID (Integrated Circuit Card Identifier) in the USIM card, IMEI code (International Mobile Equipment Identity), mobile phone number, and binding status information;

[0029] The obtained device-card information is packaged into blocks and distributedly stored through the blockchain network;

[0030] The data in the block is hashed using an encryption algorithm, and the block is verified by multiple nodes in the blockchain network;

[0031] After passing the verification, the block is added to the blockchain and jointly stored by multiple nodes in the network to achieve distributed storage of data.

[0032] Further, the method further includes:

[0033] During each process where the server requests to obtain the terminal IMEI, a one-time key is dynamically generated through a preset algorithm according to the current real-time status of the server and the terminal and preset key generation parameters, and the server and the terminal communicate based on the generated one-time key.

[0034] Further, the method further includes:

[0035] When the terminal returns the IMEI information, the IMEI data is compressed and encoded using compressive sensing technology and then transmitted to the server.

[0036] Further, the method further includes:

[0037] According to historical binding data and user behavior patterns, a personalized binding machine learning model is trained to enable the personalized binding machine learning model to automatically analyze and predict the binding characteristics and potential risks of different users and different devices, and generate personalized binding information accordingly;

[0038] When performing device-card binding, personalized binding information is generated in the personalized binding machine learning model according to the characteristics of the user and the device; and,

[0039] According to the binding information, additional security identifiers and verification requirements are added for high-risk users or devices.

[0040] Further, when it is detected that the user's USIM card is replaced with a terminal, authorization verification is performed, including:

[0041] After the server automatically recognizes a new IMEI code, the user is required to perform biometric verification;

[0042] Match the biometric features collected by the terminal during user verification with the information reserved by the user during the initial binding stage; and perform system verification on the new IMEI code;

[0043] If the biometric features match and the new IMEI code passes the verification, it is determined that the authorization verification is passed.

[0044] Furthermore, the method further includes:

[0045] Collect and analyze IMEI-related data in real time, and evaluate the potential risks brought by the new IMEI code through a risk assessment model, including:

[0046] Data collection: Collect the IMEI code and other relevant information through the terminal device and send them to the server;

[0047] Data processing: The server receives the data and performs preprocessing;

[0048] Model evaluation: The server uses the trained risk assessment model to evaluate the preprocessed data and identify potential risks;

[0049] Security measure triggering: According to the evaluation results, the server automatically triggers corresponding security measures.

[0050] Furthermore, based on the user's SIM-card separation behavior, combined with the call score of real-time communication behavior and communication content by a deep learning model, identify possible fraud-related communication behaviors, including:

[0051] Determine the user's SIM-card separation status;

[0052] Through the analysis of the operator's call records, analyze and compare the user's call behaviors for outgoing and incoming calls, including whether they often call different mobile phone numbers, whether they are marked as fraud calls, whether the operator's terminal is marked as an abnormal incoming call, and whether it meets the scope of the operator's fraud-related communication behavior recognition algorithm, and score the communication behavior;

[0053] Through the operator's large network recording, in the way of real-time transcribing the user's call content into text, analyze and score the fraud-related communication content through the DFA (Deterministic Finite Automaton) sensitive word algorithm analysis and AI call large model analysis;

[0054] Based on the comprehensive communication behavior score, communication content score, and SIM-card separation status, according to the preset permission coefficient determination rule, output the result of whether there is a suspected call fraud behavior or a confirmed call fraud behavior.

[0055] In a second aspect, the present disclosure provides a fraud recognition system based on SIM-card separation and communication information. The system includes:

[0056] A SIM-card separation conversion module configured to convert the data docking method of the SIM-card separation interface into the HTTPS protocol, so as to realize the docking between the terminal and the existing network infrastructure through the HTTPS protocol;

[0057] A SIM-card binding module configured to automatically obtain the SIM-card information of the terminal and the USIM card after the user inserts the card and powers on for the first time, and perform SIM-card binding;

[0058] An authorization verification module configured to perform authorization verification when it is detected that the user's USIM card is replaced with a terminal. After the verification passes, perform SIM-card binding again;

[0059] A data collection module configured to collect the communication data of the USIM card, including SIM-card verification data, call records, text message content, and network traffic;

[0060] A data processing module configured to preprocess the collected data;

[0061] A training module configured to construct a data set containing various communication contents and behavior characteristics through the preprocessed communication data, and train and optimize a deep learning model through the data set to identify abnormal patterns and potential fraud behaviors in communication behaviors;

[0062] An identification module configured to determine whether there is SIM-card separation through the SIM-card verification data, and identify possible fraud-related communication behaviors based on the user's SIM-card separation behavior and the call score of the real-time communication behavior and communication content in combination with the deep learning model.

[0063] In a third aspect, the present disclosure provides an electronic device including a memory and a processor. A computer program is stored in the memory. When the processor runs the computer program stored in the memory, the processor executes the fraud recognition method based on SIM-card separation and communication information according to any one of the first aspects.

[0064] In a fourth aspect, the present disclosure provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the fraud recognition method based on SIM-card separation and communication information according to any one of the first aspects is realized.

[0065] Beneficial effects:

[0066] The fraud recognition method, fraud recognition system, electronic device and storage medium based on SIM-card separation and communication information provided by the present disclosure upgrade the existing OTA + digital SMS docking method of SIM-card separation to docking based on the HTTPS protocol, enhancing the compatibility and scalability with existing network infrastructure. Through the seamless conversion of the HTTPS protocol, the efficiency of data processing is improved. The system can analyze communication behaviors in real time, quickly identify potential fraud behaviors, and effectively prevent fraud incidents through timely risk assessment and warning mechanisms. In addition, by combining the capabilities of large models, the system can intelligently identify and annotate call behaviors and call content, comprehensively improving the accuracy of intelligent judgment of fraud-related calls and meeting the urgent and practical needs in the current field of communication security. BRIEF DESCRIPTION OF THE DRAWINGS

[0067] Figure 1 It is a schematic flowchart of a fraud recognition method based on SIM-card separation and communication information provided in Embodiment 1 of the present disclosure;

[0068] Figure 2 It is a schematic diagram of using the scikit-learn library in Python to train a machine learning model to optimize the generation of binding information provided in an embodiment of the present disclosure;

[0069] Figure 3 It is a schematic flowchart of the specific implementation process of the communication fraud recognition process provided in an embodiment of the present disclosure;

[0070] Figure 4 It is an architecture diagram of a fraud recognition system based on SIM-card separation and communication information provided in Embodiment 2 of the present disclosure;

[0071] Figure 5 It is an architecture diagram of an electronic device provided in Embodiment 3 of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0072] To enable those skilled in the art to better understand the technical solutions of the present disclosure, the present disclosure will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments and accompanying drawings described herein are only for explaining the present invention, rather than limiting the present invention.

[0073] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence; and, without conflict, the embodiments and features in the embodiments of the present disclosure can be combined with each other arbitrarily.

[0074] Among them, the terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and are not intended to limit the present disclosure. The singular forms of "a", "the", and "said" used in the embodiments of the present disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.

[0075] In the following description, suffixes such as "module", "component", or "unit" used to represent elements are only for the convenience of explaining the present disclosure, and have no specific meaning in themselves. Therefore, "module", "component", or "unit" can be used interchangeably.

[0076] The existing technology of separating the mobile phone from the SIM card has serious deficiencies in judging fraud-related abnormal situations. It lacks sufficient intelligent analysis capabilities and accurate judgment capabilities. Relying solely on a single mechanism for judging the separation of the mobile phone from the SIM card, it is difficult to comprehensively and accurately identify and effectively prevent increasingly complex, changeable, and highly concealed fraud means, and cannot meet the stringent requirements of modern communication security. Moreover, the current docking protocol for separating the mobile phone from the SIM card, due to the existence of middleware bridging, results in a complex system architecture, seriously hindering the efficient integration with existing network infrastructure. Just like in a modern transportation network, there is a narrow and congested bottleneck section, restricting the overall traffic efficiency.

[0077] The following uses specific embodiments to elaborate in detail on the technical solutions of the present disclosure and how the technical solutions of the present disclosure solve the technical problems existing in the prior art. It can be understood that in the embodiments of the present application, the execution entity can execute some or all of the steps in the embodiments of the present application. These steps or operations are only examples, and the embodiments of the present application can also execute other operations or various deformations of the operations. In addition, the various steps can be executed in different orders presented in the embodiments of the present application, and it is possible not to execute all the operations in the embodiments of the present application. Moreover, these several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

[0078] Figure 1 The following is a schematic flowchart of a fraud recognition method based on the separation of the mobile phone from the SIM card and communication information provided for Embodiment 1 of the present disclosure, as Figure 1 shown, the method includes:

[0079] Step S101: Convert the data docking method of the interface for separating the mobile phone from the SIM card to the HTTPS protocol to achieve the docking of the terminal with the existing network infrastructure through the HTTPS protocol;

[0080] Step S102: After the user inserts the SIM card and powers on the phone for the first time, automatically obtain the information of the mobile phone and the USIM card for the binding of the mobile phone and the SIM card;

[0081] Step S103: When it is detected that the user's USIM card is replaced on a different terminal, authorization verification is performed. After successful verification, the card and device binding is re-established.

[0082] Step S104: Collect the communication data of the USIM card, including card-device verification data, call records, SMS content, and network traffic.

[0083] Step S105: Preprocess the collected data.

[0084] Step S106: Construct a dataset containing various communication contents and behavior characteristics from the preprocessed communication data, and train and optimize a deep learning model through the dataset to identify abnormal patterns and potential fraud behaviors in communication behaviors.

[0085] Step S107: Determine whether there is card-device separation based on the card-device verification data. Based on the user's card-device separation behavior and combined with the call score of the real-time communication behavior and communication content by the deep learning model, identify possible fraud-related communication behaviors.

[0086] The concept of this disclosure is to identify communication fraud by combining card-device separation based on artificial intelligence with communication behaviors and communication content. By innovating the large network docking method of card-device separation to the more advanced, secure, and general HTTPS protocol docking, while deeply integrating the operator's call behavior analysis and call content analysis technologies, and introducing a powerful AI call large model, the collaborative analysis and intelligent judgment of multi-dimensional data are realized. The aim is to comprehensively improve the accuracy of intelligent judgment of call fraud, deeply mine and analyze communication behaviors and contents, thereby significantly improving the recognition accuracy of call fraud, building a more reliable, controllable, intelligent, and closed-loop management-capable communication security protection system, effectively meeting the urgent and practical needs in the current communication security field, protecting the communication security of users, and filling the key gaps in the existing technology.

[0087] To achieve this goal, the embodiments of this disclosure transform the existing large network docking method of OTA + digital SMS into HTTPS protocol docking to improve the compatibility and scalability of the system. After the docking method is transformed into HTTPS protocol docking, the communication process between the terminal and the platform will be realized through the HTTPS protocol. During the transformation process, a new protocol conversion module is developed, which can efficiently and accurately convert the data of the card-device separation interface to ensure seamless data transmission between different protocols. By removing the middleware of OTA + digital SMS in the large network, the data of the card-device separation interface is innovatively converted into the HTTPS protocol to achieve seamless docking with the existing network infrastructure. During the data conversion process, a specific encryption key management strategy is adopted to ensure the security of data during transmission, and at the same time, the data transmission process is optimized to improve the transmission efficiency.

[0088] In the process of the operator making the SIM card, a machine-card verification data group is added to the card core server for USIM card configuration. After the configuration is completed, when the user inserts the card and powers on the device for the first time, the server (operator platform side) automatically obtains the machine-card information (such as ICCID + IMEI code + mobile phone number + binding status) for machine-card binding (automatic binding). In this process, a specific encryption module is embedded in the USIM card configuration link, and a unique encryption algorithm (such as AES-256-bit encryption algorithm) is used to encrypt and store the machine-card verification data group to ensure the security and integrity of the data. After encrypting and storing these information through the encryption algorithm, when it is detected that the user's mobile phone card changes the terminal, the terminal can read the mobile phone card, but cannot be used normally. Only after the platform administrator authorizes and passes can the re-binding be carried out. The authorization mechanism here adopts a multi-factor authentication method, including but not limited to passwords, SMS verification codes, biometric information, etc., further enhancing the security.

[0089] In addition to machine-card verification, the system also collects the communication behavior data of the mobile phone card in a secure way by the operator, including but not limited to call records, SMS content, network traffic and other information. The data collection process is mainly based on the operator's network interface and API (Application Programming Interface), and is realized through real-time data collection technology. The specific implementation methods are as follows: Network interface: Through the network interface provided by the operator, the communication behavior data of the mobile phone card is obtained in real time. API call: Use the API provided by the operator for real-time data collection and transmission. Encrypted transmission: In the process of data transmission, the AES-256-bit encryption algorithm is used to encrypt the data. This encryption algorithm is a variant based on AES (Advanced Encryption Standard), combining symmetric encryption and asymmetric encryption technologies to ensure the security and integrity of the data. Through the above collection methods, data can be obtained efficiently and accurately without affecting the normal communication, and the data is encrypted during transmission to prevent data leakage.

[0090] After the data is collected, the collected data needs to be preprocessed. The data preprocessing process is similar to the existing data processing process, including data cleaning, formatting and normalization, so as to facilitate subsequent analysis and processing. The data cleaning link adopts an intelligent algorithm, combining anomaly detection and clustering analysis techniques, and training models to identify anomaly points and duplicates in the data, which can automatically identify and remove abnormal data and duplicate data to improve data quality; formatting and normalization are based on a set of self-developed standard specifications to ensure that data from different sources can be analyzed under a unified framework.

[0091] The specific implementation methods are as follows:

[0092] Anomaly detection: Use statistical methods and machine learning models (such as Isolation Forest, Support Vector Machine, etc.) to detect outliers in the data.

[0093] Cluster analysis: Identify duplicates in the data through clustering algorithms (such as K-means, DBSCAN, etc.).

[0094] Model training: Train the model with a large amount of historical data to improve the accuracy and robustness of the algorithm.

[0095] Then, perform deep learning model training. Through the preprocessed communication data, construct a dataset containing various communication contents and behavior characteristics, including SIM-card and device verification data, communication recording speech-to-text data, call log outgoing and incoming call behavior data, and train and optimize the deep learning model through the dataset to identify abnormal patterns and potential fraud behaviors in communication behaviors.

[0096] Specifically, the semantic analysis of call content can be combined with natural language processing (NLP), such as fraud keywords and speech patterns. Use convolutional neural network (CNN) or recurrent neural network (RNN) to identify abnormal behavior patterns. The communication behavior analysis process can be through dynamic rule matching: detecting abnormal behaviors such as high-frequency outbound calls and concentrated calls to strange numbers; and multi-source data comparison: combining 12321 markings and the judgment results of the operator's fraud algorithms. Communication content analysis such as: DFA sensitive word matching: identifying fraud keywords such as "transfer" and "urgent operation". AI semantic analysis: parsing the induced language in the call content through large models (such as BERT), etc.

[0097] Then, judge whether there is SIM-card and device separation through the SIM-card and device verification data. According to the user's SIM-card and device separation behavior, combined with the call scores of real-time communication behaviors and communication content by the deep learning model, identify possible fraud-related communication behaviors.

[0098] Through the verification of the SIM-card and device separation status, real-time monitor the binding relationship between IMEI and SIM card to identify illegal device access; and combined with the call score annotation of real-time communication behaviors and communication content by the model, the system conducts intelligent analysis and call scoring on real-time communication behaviors through preset fraud business classification, industry scenarios, speech appropriation judgment, and call abnormal behavior judgment, combined with the deep learning model (agent annotation), and identify possible fraud-related communication behaviors. By combining the SIM-card and device separation status, call content analysis, and call behavior analysis, the system can conduct a more in-depth and comprehensive evaluation of communication behaviors.

[0099] Furthermore, the method further includes risk assessment and early warning, including:

[0100] Conduct a risk assessment of communication behaviors based on the analysis results to determine whether they are suspected of fraud. For the identified high-risk communication behaviors, the system will promptly issue a warning through instant notification channels such as enterprise WeChat / DingTalk robots / sms / robot outbound calls, etc., to remind users or automatically take blocking measures (shut down / control the call) after reporting to the operator.

[0101] Furthermore, the method further includes feedback and model optimization, including:

[0102] The system collects user feedback and actual fraud cases encountered by business administrators, and through combination with the large model, enters deep training data for further training and optimization of the deep learning model. By regularly updating the model, it can adapt to the constantly changing fraud means and communication behavior patterns. Through user feedback and new fraud cases, the model is iteratively updated to improve the generalization ability.

[0103] In the embodiments of the present disclosure, the existing OTA + digital SMS docking method of SIM-card separation is upgraded to a docking based on the HTTPS protocol, enhancing the compatibility and scalability with the existing network infrastructure. Through the seamless conversion of the HTTPS protocol, the efficiency of data processing is improved. The system can analyze communication behaviors in real time, quickly identify potential fraud behaviors, and effectively prevent the occurrence of fraud events through timely risk assessment and warning mechanisms. In addition, through the combination of SIM-card separation determination and the capabilities of the large model, the system can intelligently identify and label call behaviors and call contents, comprehensively improving the accuracy of intelligent judgment of fraud-related calls and meeting the urgent and practical needs in the current field of communication security.

[0104] Furthermore, the conversion of the data docking method of the SIM-card separation interface to the HTTPS protocol includes:

[0105] Convert the data of the SIM-card separation interface: Dynamically identify various variants of the OTA and digital SMS data formats through an adaptive parsing algorithm, and convert the data into a structure that meets the requirements of the HTTPS protocol according to the characteristics of the data format;

[0106] When the data is converted from the SIM-card separation interface to the HTTPS protocol, different levels of encryption keys are dynamically allocated according to the sensitivity of the data and the transmission stage;

[0107] Intelligently cache the data that may be frequently accessed according to the historical data transmission law and the real-time network condition.

[0108] The main key points of converting the data docking method of the SIM-card separation interface to the HTTPS protocol are:

[0109] Protocol conversion module development:

[0110] By developing a brand-new protocol conversion module, it is possible to efficiently and accurately convert the data of the SIM card separation interface. This module is the key to realizing the docking method from the OTA + digital SMS large network to the HTTPS protocol.

[0111] By analyzing the data format of the OTA + digital SMS protocol and converting it into the format required by the HTTPS protocol, seamless conversion between different protocols can be achieved. Embedding this module in the USIM card application requires the card vendor to synchronize and prefabricate the database to support this capability.

[0112] Encryption key management:

[0113] During the data conversion process, a specific encryption key management strategy is adopted to ensure the security of data during transmission. This includes using strong encryption algorithms (such as AES-256) to encrypt the data and ensuring the secure storage and transmission of the keys. By using the HTTPS protocol, the data is encrypted during transmission to prevent it from being intercepted or tampered with during transmission.

[0114] For the encryption key management strategy, a hierarchical key system is designed. The hierarchical key system is a strategy that dynamically allocates different levels of encryption keys according to the sensitivity of the data and the transmission stage. When the data is converted from the SIM card separation interface to the HTTPS protocol, different levels of encryption keys will be dynamically allocated according to the sensitivity of the data and the transmission stage. This strategy generally includes the following key steps:

[0115] ① Data classification: According to the sensitivity and importance of the data, the data is divided into different categories.

[0116] ② Key allocation: Different strengths of encryption keys are allocated to each data category. For example, for the core identification information of the SIM card (such as ICCID, IMEI, etc.), high-strength top-level keys are used for encryption, while for some relatively minor communication behavior metadata, lower-level but still sufficiently secure keys are used for encryption.

[0117] ③ Dynamic adjustment: According to the transmission stage and environment of the data, the strength and type of the encryption key are dynamically adjusted.

[0118] ④ Key management: Store, distribute, and update the encryption keys through a secure key management system.

[0119] This hierarchical method optimizes the consumption of computing resources for encryption and decryption while ensuring data security, improving the overall performance of the system. Moreover, the key update mechanism is associated with the network environment and device status. When network fluctuations or device anomalies are detected, part of the keys will be automatically updated.

[0120] Network infrastructure docking:

[0121] Convert the data of the SIM-card separation interface into the HTTPS protocol to achieve seamless docking with the existing network infrastructure. This includes conducting compatibility tests with existing network devices and systems to ensure that the new protocol can be smoothly integrated into the existing system.

[0122] Optimization of the data transmission process:

[0123] The data transmission process has been optimized, improving the transmission efficiency. This includes reducing the latency during data transmission and enhancing the stability and reliability of data transmission.

[0124] The reasons and advantages for this disclosure to change the "SIM-card separation" from the large network docking method to the HTTPS docking method are as follows:

[0125] (1) Compatibility, deployment, and maintenance aspects

[0126] The HTTPS protocol occupies a mainstream position in the field of Internet communication. With its wide support and application popularity, it has become an important part of modern network infrastructure. Changing the docking method of the SIM-card separation technology from the traditional large network docking (relying on the OTA server and digital SMS middleware) to the HTTPS protocol can significantly enhance the system's compatibility. This enhanced compatibility is reflected in multiple aspects:

[0127] Seamless integration with various network devices and systems: The universality of the HTTPS protocol enables the SIM-card separation system to easily adapt to existing network devices. Whether it is routers, switches, or servers, etc., it can interact smoothly with them without the need for cumbersome customization and adaptation work, greatly reducing the difficulty and cost of system integration.

[0128] Simplify the deployment process: Due to the existence of middleware, the traditional large network docking method has a complex deployment process and is prone to compatibility problems, requiring a large amount of debugging and configuration work by professional technical personnel. After adopting the HTTPS protocol, the deployment process is simplified. Only by setting according to the standard network configuration process can the system be quickly deployed, greatly shortening the deployment cycle and improving the deployment efficiency.

[0129] Convenient maintenance and upgrade: The HTTPS protocol is based on a mature network technology system, and its maintenance and upgrade work are relatively simple and standardized. When the network environment or system requirements change, maintenance personnel can easily perform maintenance and upgrade operations on the SIM-card separation system according to general network maintenance specifications and tools, effectively reducing the system's maintenance cost and technical threshold, and ensuring the long-term stable operation of the system.

[0130] (2) Data security and transmission performance aspects

[0131] The HTTPS protocol incorporates efficient encryption algorithms, such as the SSL (Secure Sockets Layer) / TLS (Transport Layer Security) protocols, which play a crucial role in ensuring the security of data transmission:

[0132] High-strength data encryption: During the data transmission process of the SIM card detachment, the HTTPS protocol can perform end-to-end encryption of data to ensure that the data is not stolen, tampered with, or forged during transmission. Whether it is the key identification information of the SIM card (such as ICCID, IMEI, etc.) or sensitive data during the communication process, it can be strictly protected, effectively preventing various network attacks and data leakage risks, and providing a solid guarantee for user privacy and communication security.

[0133] Optimized data transmission mechanism: The HTTPS protocol not only focuses on data security but also optimizes the data transmission performance. It adopts advanced transmission protocols and data compression technologies, which can reduce the data transmission delay and bandwidth occupancy while ensuring data integrity and security. For example, in real-time communication scenarios, the SIM card detachment system needs to transmit data frequently for real-time fraud identification and risk assessment. The efficient transmission mechanism of the HTTPS protocol can ensure the rapid transmission and timely processing of data, enabling real-time research and judgment analysis, providing technical support for timely detection and prevention of fraud behaviors, and significantly improving the system's response speed and processing capacity.

[0134] (3) Industrial promotion and innovation development

[0135] The SIM card detachment technology using the HTTPS docking method has a profound impact and positive promotion on the entire communication industry chain:

[0136] Promote innovation in the smart card SIM chip manufacturing industry: The application of the HTTPS protocol poses new technical requirements and development directions for smart card SIM chip manufacturing. Chip manufacturers will need to develop new SIM chips that support the HTTPS protocol, which will prompt them to innovate and upgrade in aspects such as chip design, encryption algorithm integration, and communication performance optimization. For example, developing chips with higher encryption performance and lower power consumption to meet the data security and transmission efficiency requirements under the HTTPS protocol, thus driving the smart card SIM chip manufacturing industry towards a higher technical level.

[0137] Drive the development of related industries such as the conditional access (CA) system: The introduction of the HTTPS protocol will change the architecture and working mode of the conditional access system. The conditional access system needs to be closely integrated and interact with the card-machine separation system to effectively manage communication content and permissions. In the HTTPS docking mode, the conditional access system will be able to better integrate with the modern network environment and achieve more efficient and secure content distribution and permission control.

[0138] Furthermore, the various variants of the OTA and digital SMS data formats are dynamically identified through an adaptive parsing algorithm, and the data is converted into a structure that meets the requirements of the HTTPS protocol according to the characteristics of the data format, including:

[0139] Data feature extraction: Extract key features from the original data, which can represent the structure and content of the data;

[0140] Pattern recognition: Use machine learning models to identify the patterns and structures of the data;

[0141] Automatic learning and adaptation: The adaptive parsing algorithm automatically adjusts its model parameters according to new data samples to adapt to different data formats;

[0142] Conversion rule generation: According to the identified data patterns, automatically generate rules for converting the data into a structure required by the HTTPS protocol.

[0143] Converting the data to meet the requirements of the HTTPS protocol requires combining multiple technologies (such as machine learning, pattern recognition, etc.) to achieve the function of dynamically identifying and converting data formats. During the transformation process of the card-machine separation technology from the OTA + digital SMS large network docking mode to the HTTPS protocol docking, there are multiple key points.

[0144] First of all, in the research and development of the protocol conversion module, an adaptive parsing algorithm is adopted internally. The adaptive parsing algorithm is an algorithm based on machine learning, which can automatically identify and convert data by learning the characteristics of different data formats. This algorithm includes the following key steps: ① Data feature extraction: Extract key features from the original data, which can represent the structure and content of the data. ② Pattern recognition: Use machine learning models (such as neural networks, decision trees, etc.) to identify the patterns and structures of the data. ③ Automatic learning and adaptation: The algorithm can automatically adjust its model parameters according to new data samples to adapt to different data formats. ④ Conversion rule generation: According to the identified data patterns, automatically generate rules for converting the data into a structure required by the HTTPS protocol.

[0145] The adaptive parsing algorithm automatically extracts data features (such as protocol headers, field delimiters, instruction types, etc.) through a machine learning model, eliminating the need for manual definition of parsing rules. It can be compatible with protocol variants of different operators or devices (such as binary SMS, custom OTA instructions) and can dynamically adapt to multi-source data formats. Through pattern recognition and conversion rule generation, the algorithm can convert traditional protocol data (such as control instructions in SMS) into the standard structure of the HTTPS protocol (such as RESTful API requests) in real time, meeting the requirements of low-latency communication and real-time conversion capabilities.

[0146] The HTTPS protocol has built-in SSL / TLS encryption, which naturally solves the data leakage risk of traditional protocols (such as plaintext SMS) and meets the high security requirements of the SIM-card detachment scenario.

[0147] During the model training process, for the problem that the structure of the original protocol (such as OTA instructions) is highly non-standard (such as nested fields, dynamic lengths), feature extraction may miss key information, leading to conversion errors. Multi-modal feature extraction can be introduced, combined with syntactic analysis (such as regular expressions) and semantic understanding (such as natural language processing), to enhance the parsing ability for complex protocols. And add manual rules as a fallback: for high-frequency or critical instructions, preset some parsing rules as an alternative when the model fails. Also, by building a multi-source protocol sample library: jointly establish a protocol dataset with operators and device manufacturers to cover mainstream and edge scenarios. Adopt few-shot learning: through meta-learning or transfer learning techniques, improve the model's adaptability to rare protocol formats.

[0148] Since the HTTPS protocol needs to strictly follow specifications such as status codes and request methods, a semantic mapping template can be used to define the mapping relationship between common instructions and HTTPS operations (such as OTA update instruction → PUT request) to restrict the scope of rule generation. And through a two-way feedback mechanism: monitor conversion failure cases through the platform and reverse-optimize the model training data.

[0149] Regarding the problem that the adaptive algorithm may be misled by malicious data (such as forged protocol packets), through adversarial training: inject noise or attack samples into the training data to improve the model's anti-interference ability; and set request legality verification: add secondary protection mechanisms such as signature verification and parameter legality check on the HTTPS interface side to prevent security vulnerabilities.

[0150] Through the above adaptive parsing algorithm, various variants of OTA and digital SMS data formats can be dynamically recognized, and the data can be accurately converted into a structure that meets the requirements of the HTTPS protocol according to their characteristics. Different from the traditional fixed-format conversion method, it does not require a large amount of manual adjustment and adaptation for specific data sources, greatly improving the versatility and flexibility of the conversion. For example, in the face of subtle data format differences that may exist among different operators or device manufacturers, the adaptive parsing algorithm can automatically learn and adapt to ensure the accuracy and stability of data conversion.

[0151] Furthermore, according to the historical data transmission law and the real-time network condition, intelligent caching is performed on the data that may be frequently accessed, including:

[0152] Data access pattern analysis: By analyzing historical data access logs, identify frequently accessed data patterns;

[0153] Real-time network condition monitoring: Monitor the network condition in real time, including bandwidth, latency, and packet loss rate metrics;

[0154] Intelligent caching strategy: Based on the identified data access patterns and real-time network conditions, formulate an intelligent caching strategy;

[0155] Prefetch operation: Based on a prediction model, predict upcoming data transmission requirements and perform data prefetching in advance.

[0156] After the data at the SIM-card detachment interface is converted into the HTTPS protocol, the system will perform intelligent caching on the data that may be frequently accessed according to the historical data transmission law and the real-time network condition. For example, for certain key communication behavior pattern data that is often used for fraud identification and analysis, it will be cached locally for a certain period of time. When it is needed again, it can be quickly obtained directly from the cache, reducing the repeated transmission and waiting time of the data. At the same time, for upcoming data transmission requirements, the system can perform prefetch operations based on the prediction model.

[0157] The technologies for intelligent caching and prefetching of data include:

[0158] ① Data access pattern analysis:

[0159] By collecting and analyzing historical data access logs, identify frequently accessed data patterns, such as using clustering algorithms to identify the similarity of access patterns. This can be achieved through data mining and machine learning technologies, using data mining technologies (such as clustering, association rule mining, etc.) to identify access patterns and rules, so as to obtain access rules:

[0160] ② Real-time network condition monitoring:

[0161] Monitor the network status in real time, including indicators such as bandwidth, latency, and packet loss rate. This can be achieved through network monitoring tools and APIs, such as using network management software or the network monitoring functions provided by the operating system.

[0162] ③ Intelligent caching strategy:

[0163] Based on the identified data access patterns and real-time network status, formulate an intelligent caching strategy. For example, for frequently accessed data, it can be cached locally for a certain period of time; for poor network conditions, the caching time can be increased to reduce network requests.

[0164] ④ Prefetch operation:

[0165] Based on the prediction model, predict the upcoming data transmission requirements and perform data prefetching in advance.

[0166] Source of the prediction model: The prediction model can be built based on historical data and access patterns. By collecting and analyzing historical data access logs, machine learning algorithms (such as time series analysis, neural networks, etc.) are used to train the model. The prediction model can predict future data access requirements based on historical data and access patterns. By performing data prefetching and intelligent caching in advance, the repeated transmission and waiting time of data can be reduced, and the efficiency and response speed of data transmission can be improved.

[0167] By preparing the relevant data in advance, the data transmission can be made smoother and more efficient, greatly improving the data processing efficiency and response speed of the entire system, and having significant advantages compared with the traditional linear transmission method. When the machine-card separation technology is docked using the HTTPS protocol, breakthrough progress has been made in aspects such as data conversion, security guarantee, and transmission efficiency.

[0168] Furthermore, after the user inserts the card and powers on the device for the first time, the machine-card information of the terminal and the USIM card is automatically obtained for machine-card binding, including:

[0169] After the user inserts the USIM card into the device and powers it on, the machine-card information of the terminal and the USIM card is automatically read. The machine-card information includes the ICCID, IMEI code, mobile phone number, and binding status information in the USIM card;

[0170] The obtained machine-card information is packaged into a block and distributedly stored through the blockchain network;

[0171] Use an encryption algorithm to perform hash processing on the data in the block, and verify the block through multiple nodes in the blockchain network;

[0172] After verification, add the block to the blockchain and store it jointly by multiple nodes in the network to achieve distributed storage of data;

[0173] The machine-card information stored in the blockchain serves as the basic data for subsequent machine-card separation identification, and is used to verify the legality and consistency of the machine and card.

[0174] In the process of the user's first boot-up for machine-card binding, the embodiment of the present disclosure introduces an identity verification mechanism based on blockchain technology. When the user first inserts the USIM card and powers on the device, the system will not only automatically obtain the machine-card information (ICCID + IMEI code + mobile phone number + binding status), but also distribute and encrypt and verify this information through the blockchain network. The immutable feature of the blockchain ensures the authenticity and integrity of the machine-card information, providing highly reliable basic data for subsequent machine-card separation identification. Compared with the traditional simple information recording method, it greatly enhances the security and credibility of machine-card binding, effectively prevents security risks such as information tampering and forgery, and lays a solid innovative foundation for the entire machine-card separation identification process.

[0175] Process steps:

[0176] A1-1 The user inserts the card and powers on for the first time:

[0177] The user inserts the USIM card into the device and powers on.

[0178] A1-2 Automatically obtain machine-card information:

[0179] The system automatically reads information such as the ICCID (Integrated Circuit Card Identification Code), IMEI code (International Mobile Equipment Identity), mobile phone number, and binding status in the USIM card.

[0180] A1-3 Information is uploaded to the chain:

[0181] The obtained machine-card information is packaged into a block and distributed and stored through the blockchain network. Each block contains the hash value of the previous block, forming an ever-extending chain.

[0182] A1-4 Encryption verification:

[0183] Use an encryption algorithm (such as SHA-256) to perform a hash process on the data in the block to ensure the integrity and immutability of the data.

[0184] Verify the block through multiple nodes in the blockchain network to ensure the authenticity of the data.

[0185] A1-5 Distributed storage:

[0186] After the verification is passed, add the block to the blockchain and jointly store it by multiple nodes in the network to achieve distributed storage of the data.

[0187] A1-6 Subsequent machine-card separation identification:

[0188] The card information stored in the blockchain serves as the basic data for subsequent card separation identification, and is used to verify the legality and consistency of the card.

[0189] [Data example]

[0190] Suppose when the user first turns on the machine, the system obtains the following card information:

[0191] ICCID: 89014104000000000000

[0192] IMEI code: 357474060129927

[0193] Mobile phone number: 1380013XXXX

[0194] Binding status: Unbound

[0195] These information will be packaged into a block and stored and encrypted and verified through the blockchain network. The hash value of the block may be as follows:

[0196] Block hash:

[0197] 0000000000000000000d8b7b6b1b2a3b4a5b6c7b8c9b0c1d2e3f4a5b6c7.

[0198] Furthermore, the method further includes:

[0199] In the process of the server requesting to obtain the terminal IMEI each time, a one-time key is dynamically generated through a preset algorithm according to the current real-time status of the server and the terminal and the preset key generation parameters, and the server and the terminal communicate according to the generated one-time key.

[0200] In the process of requesting to obtain the terminal IMEI, the embodiments of the present disclosure adopt an intelligent dynamic key negotiation mechanism. Instead of using a fixed key for communication between the server and the terminal, a one-time key is dynamically generated through a complex algorithm according to the real-time status and environmental factors of both parties at each request.

[0201] Diffie-Hellman algorithm selection:

[0202] Existing security protocols can be used, the Diffie-Hellman key exchange algorithm, combined with the Elliptic Curve Diffie-Hellman (ECDH) algorithm to generate a one-time key. These algorithms can ensure that even in an insecure communication channel, both parties can safely generate a shared key without being stolen by a third party.

[0203] Dynamic generation process: At each request, the server and the terminal generate parameters based on the current real-time status (such as timestamp, device status, network environment, etc.) and a preset secret key, and dynamically generate a one-time key through an algorithm.

[0204] For example, using the ECDH algorithm, the server and the terminal each generate a pair of public and private keys. After exchanging the public keys, both parties can calculate the same shared key, and this key is only valid for the current session.

[0205] Key validity period: The validity period of the key can be set to be very short, such as a few minutes or a few seconds, to ensure that even if the key is stolen, the attacker cannot use the key after the validity period.

[0206] This kind of key is only valid during the current request process, greatly improving the security of communication and effectively resisting malicious attacks and data theft by hackers. At the same time, this mechanism can also automatically adjust the parameters of key negotiation according to the network conditions to ensure that the terminal IMEI information can be obtained efficiently and securely in various complex network environments. This is a major innovation in the traditional static key acquisition method, significantly enhancing the security and adaptability of the SIM card detachment recognition process.

[0207] [Data example]

[0208] The process of dynamic key negotiation between the server and the terminal is as follows:

[0209] Parameter setting:

[0210] The server and the terminal preset elliptic curve parameters (such as P-256) and an initial vector.

[0211] Real-time status acquisition:

[0212] The server obtains the current timestamp: 2024-06-13T14:30:00Z.

[0213] The terminal obtains the current device status: battery power 80%, signal strength -70dBm.

[0214] Key generation:

[0215] The server generates a pair of public and private keys (public key A, private key A);

[0216] The terminal generates a pair of public and private keys (public key B, private key B).

[0217] Both parties exchange public keys and calculate the shared key: K = ECDH(private key A, public key B) = ECDH(private key B, public key A).

[0218] Key validity period:

[0219] Set the key validity period to 5 minutes.

[0220] Data encryption and decryption:

[0221] Use the shared key K to perform AES encryption on the IMEI information: Ciphertext = AES(K, IMEI).

[0222] After the terminal receives the encrypted data, use the shared key K to perform AES decryption: IMEI = AES^-1(K, Ciphertext).

[0223] Furthermore, the method further includes:

[0224] When the terminal returns the IMEI information, use compressive sensing technology to compress and encode the IMEI data and then transmit it to the server.

[0225] In the process of the terminal returning the IMEI information to the server, the embodiments of the present disclosure design an optimized data transmission scheme based on compressive sensing technology. When the terminal returns the IMEI information, instead of simply sending the original data to the server, it uses compressive sensing technology to compress and encode the IMEI data.

[0226] Compressive sensing technology is a technology used for data compression and encoding in signal processing. It is based on the fact that many signals are sparse in a certain transform domain, that is, they have only a few non-zero elements in that domain. By utilizing this characteristic, compressive sensing can significantly reduce the amount of data transmission and improve the transmission efficiency without losing key information.

[0227] Process steps

[0228] A3-1 Data acquisition:

[0229] The terminal acquires the IMEI information, which is usually a 15-digit hexadecimal digital sequence.

[0230] A3-2 Sparse representation:

[0231] Convert the IMEI information into a sparse representation. For example, through methods such as discrete cosine transform (DCT) or discrete wavelet transform (DWT), map the IMEI information to a sparse domain.

[0232] A3-3 Random projection:

[0233] Perform random projection on the sparse representation to generate a set of measurement values much smaller than the original data volume. These measurement values contain the key information of the original IMEI information.

[0234] A3-4 Data transmission:

[0235] Send these measurement values to the server instead of sending the complete IMEI information. This greatly reduces the amount of data transmitted.

[0236] A3-5 Data Recovery:

[0237] The server uses a dedicated decoding algorithm, such as an algorithm based on optimization (e.g., L1 minimization) or an iterative algorithm, to recover the original IMEI information from the measurement values.

[0238] This technology can significantly reduce the amount of data transmitted and improve the transmission efficiency without losing key information. Especially in the case of limited network bandwidth, the advantages are more obvious. At the same time, the server is equipped with a dedicated decoding algorithm that can quickly and accurately recover the original IMEI information.

[0239] [Data Example]

[0240] Suppose the IMEI information collected by the terminal is: 353566071234567.

[0241] Sparse Representation:

[0242] Through DCT transformation, the IMEI information may be converted into a sparse vector, for example: [0,0,150,0,0,0,0,30,0,0,0,0,0].

[0243] Random Projection:

[0244] Perform random projection on the sparse vector to generate 4 measurement values, for example: [100,200,50,10].

[0245] Data Transmission:

[0246] The terminal sends these 4 measurement values to the server.

[0247] Data Recovery:

[0248] The server uses a decoding algorithm to recover the original IMEI information from these 4 measurement values. The decoding process may involve solving an optimization problem, such as minimizing the difference between the original IMEI information and the recovered information.

[0249] The combination of high efficiency and accuracy in data transmission is achieved through compression and encoding, providing strong support for the efficient operation of the entire system during the data interaction process of SIM card detachment.

[0250] Furthermore, the method further includes:

[0251] Train a personalized binding machine learning model based on historical binding data and user behavior patterns, enabling the personalized binding machine learning model to automatically analyze and predict the binding characteristics and potential risks of different users and different devices, and generate personalized binding information accordingly;

[0252] When performing SIM-card binding, generate personalized binding information in the personalized binding machine learning model according to the characteristics of the user and the device; and,

[0253] According to the binding information, add additional security identifiers and verification requirements for high-risk users or devices.

[0254] In the step of first binding the IMEI with the terminal and generating binding information, the present disclosure introduces a machine learning model to optimize the generation and management of binding information. The system will train a dedicated machine learning model based on historical binding data and user behavior patterns. This model can automatically analyze and predict the binding characteristics and potential risks of different users and different devices, and generate more accurate and personalized binding information accordingly.

[0255] The following are the steps for obtaining and typing the model:

[0256] A4-1 Model Selection:

[0257] Multiple machine learning models can be selected, such as decision trees, random forests, support vector machines (SVMs), neural networks, etc. Which model to choose specifically depends on the characteristics of the data and the expected model performance.

[0258] A4-2 Model Training:

[0259] Use historical binding data and user behavior patterns to train the model. This data may include the user's binding history, device type, binding frequency, geographical location, timestamp, etc.

[0260] A4-3 Feature Engineering:

[0261] Extract features from the original data that are helpful for model prediction. For example, the number of devices bound by the user, the number of binding failures, the brand and model of the device, etc.

[0262] A4-4 Model Training Process:

[0263] Divide the data into a training set and a test set, use the training set to train the model, and then use the test set to evaluate the performance of the model.

[0264] A4-5 Model Optimization:

[0265] Adjust the model parameters according to the test results and optimize the model to improve the prediction accuracy and generalization ability.

[0266] Steps to Train the Model

[0267] A4-6 Data Preprocessing:

[0268] Clean the data, handle missing values and outliers, and encode categorical variables.

[0269] A4-7 Feature Selection:

[0270] Use methods such as correlation analysis and feature importance assessment to select the features that are most helpful for model prediction.

[0271] A4-8 Model Training:

[0272] Use the selected features and training dataset to train the model. For example, if the random forest model is selected, it can be implemented using the scikit-learn library in Python: as Figure 2 shown.

[0273] Model Evaluation:

[0274] Use the test set to evaluate the performance of the model. Common evaluation metrics include accuracy, precision, recall, and F1 score.

[0275] Model Tuning:

[0276] Adjust the model parameters, such as the number of trees and maximum depth, according to the evaluation results to improve the model performance.

[0277] A4-9 Binding Information Generation:

[0278] Dynamic Optimization:

[0279] The model can dynamically adjust the generation of binding information based on the characteristics of the user and the device, thereby improving the security of the binding and the user experience.

[0280] Personalized Management:

[0281] The model can generate personalized binding information for different users and devices to meet the needs of different users.

[0282] Risk Prediction:

[0283] The model can predict potential risks and generate corresponding security measures accordingly, such as adding additional security identifiers and verification requirements.

[0284] Data examples are shown in Table 1 below.

[0285] Table 1: Historical Binding Data Verification:

[0286]

[0287] By training the model, a model capable of predicting whether a user is a high-risk user can be obtained. For example, the model may find that users with more than 0 binding failures are more likely to be high-risk users. Therefore, for these users, the model will recommend adding additional security verification steps during the binding process. In this way, the machine learning model can optimize the generation and management of binding information, improving the security and user experience of the SIM-card binding.

[0288] For high-risk users or devices, the model will automatically add additional security identifiers and verification requirements to further enhance the security of the binding; for normal users and devices, the binding process will be simplified to improve the user experience. This intelligent binding information management method based on machine learning breaks through the constraints of traditional fixed rules and realizes the dynamic optimization and precise management of the SIM-card binding.

[0289] Furthermore, when it is detected that the user's USIM card changes the terminal, authorization verification is performed, including:

[0290] After the server automatically identifies the new IMEI code, the user is required to perform biometric verification;

[0291] The biometric features collected by the terminal during user verification are matched with the information reserved by the user during the first binding stage; and the new IMEI code is verified by the system;

[0292] If the biometric features match and the new IMEI code passes the verification, it is determined that the authorization verification is passed.

[0293] When the user turns on the new terminal, a dual-verification mechanism combining biometric recognition and SIM-card binding is adopted. In addition to the system automatically identifying the new IMEI code, the user is also required to perform biometric verification (such as fingerprint recognition, face recognition, etc.). Only when the biometric features match the information reserved by the user during the first binding stage and the new IMEI code passes the system verification can subsequent operations be allowed.

[0294] Increased software, hardware, and design steps:

[0295] A5-1 Hardware enhancements:

[0296] Biometric sensors: Such as fingerprint recognition modules, face recognition cameras, etc., for collecting the user's biometric information.

[0297] Security chips: Used to store the encrypted data of the user's biometric information and IMEI code to ensure the security of the data.

[0298] A5-2 Software enhancements:

[0299] Biometric Algorithm Library: including fingerprint recognition algorithm, face recognition algorithm, etc., used to process and analyze the collected biometric information.

[0300] Dual Verification Software Module: used to integrate IMEI code verification and biometric verification to ensure that device access is allowed only when both pass.

[0301] Design Steps:

[0302] Step 1: Automatic IMEI Code Recognition:

[0303] The system automatically recognizes the new IMEI code when the device is powered on and compares it with the bound information in the database.

[0304] Step 2: Biometric Verification Request:

[0305] If the IMEI code verification passes, the system requests the user to perform biometric verification (such as fingerprint or face recognition).

[0306] Step 3: Biometric Collection and Verification:

[0307] Collect the user's biometric information and compare it with the biometric information stored in the security chip.

[0308] Step 4: Dual Verification Decision:

[0309] If both the IMEI code and biometric verification pass, allow the user to perform subsequent operations; if either verification fails, deny access and prompt the user.

[0310] A5-4 How to Implement Dual Verification:

[0311] - IMEI Code Verification:

[0312] When the device is powered on, the system automatically obtains the IMEI code by reading the SIM card or device information.

[0313] Compare the obtained IMEI code with the bound information in the server database to verify whether the device is authorized.

[0314] - Biometric Verification:

[0315] The user registers biometric information on the device (such as entering fingerprint or face information during the first binding).

[0316] When changing the terminal, the system collects the user's biometric information through the biometric sensor.

[0317] Use the biometric algorithm library to process the collected information and compare it with the information stored in the security chip.

[0318] - Integrated Dual Verification:

[0319] Develop a software module to integrate IMEI code verification and biometric verification functions.

[0320] Design a user interface to guide users through the dual-verification process.

[0321] Implement a decision logic to ensure that users are allowed to access the device only when both IMEI code and biometric verification are passed.

[0322] [Data example]

[0323] Suppose the user enters fingerprint information during the first binding and binds the IMEI code 123456789012345.

[0324] When replacing the terminal:

[0325] The user inserts the SIM card into the new device and turns it on.

[0326] The system automatically recognizes the new IMEI code 987654321098765 and compares it with the binding information in the database.

[0327] Biometric verification:

[0328] The system prompts the user to perform fingerprint verification.

[0329] The user places a finger on the fingerprint recognition module, and the system collects fingerprint information.

[0330] Use the fingerprint recognition algorithm to process the collected fingerprint information and compare it with the fingerprint information stored in the security chip.

[0331] Verification passed:

[0332] If both the IMEI code and fingerprint verification are passed, the system allows the user to access the device.

[0333] If any verification fails, the system rejects access and prompts the user.

[0334] Furthermore, the method further includes:

[0335] Collect and analyze IMEI-related data in real time, and evaluate the potential risks brought by the new IMEI code through a risk assessment model, including:

[0336] Data collection: Collect the IMEI code and other relevant information through the terminal device and send it to the server;

[0337] Data processing: The server receives the data and performs preprocessing;

[0338] Model evaluation: The server uses the trained risk assessment model to evaluate the preprocessed data and identify potential risks;

[0339] Security measure triggering: Based on the evaluation results, the server automatically triggers corresponding security measures.

[0340] After identifying a new IMEI code, this disclosure uses a risk assessment model based on big data analysis to evaluate the potential risks brought by the new IMEI code. The system will collect and analyze a large amount of IMEI-related data in real time, including the usage records of this IMEI globally, whether it has ever been marked as an abnormal IMEI, the device models and user group characteristics related to this IMEI, etc. Through in-depth mining and analysis of this big data, the risk assessment model can quickly and accurately evaluate the potential risks brought by the new IMEI code and automatically trigger corresponding security measures according to the risk level. For example, for a high-risk IMEI code, the system will immediately restrict the usage functions of the SIM card and send detailed risk warning information to the user and the administrator; for a low-risk IMEI code, further observation and verification will be carried out. This real-time risk assessment mechanism based on big data enables the SIM-card separation technology to more intelligently and accurately respond to various complex security threats, providing a more comprehensive and effective technical means for ensuring communication security.

[0341] Source of the model and platform evaluation capabilities:

[0342] A6-1 Model source:

[0343] The risk assessment model can be developed based on existing machine learning frameworks (such as TensorFlow, PyTorch) and algorithms (such as random forest, gradient boosting tree, neural network, etc.).

[0344] The model is trained with historical data, including the usage records of IMEI codes, abnormal markings, device models, user group characteristics, etc.

[0345] A6-2 Evaluation capabilities:

[0346] The model can evaluate the potential risks of IMEI codes because it identifies the risks that a new IMEI code may bring by learning the patterns and associations in historical data.

[0347] The evaluation capabilities of the model come from the complexity of its algorithm and the diversity of the training data, enabling it to extract useful information from a large amount of data.

[0348] A6-3 Evaluation location of the model:

[0349] The model is usually evaluated on the server side or in the cloud platform because the platform has the ability to process and analyze a large amount of data.

[0350] The terminal device is usually responsible for data collection and preliminary processing, and then sends the data to the server side for in-depth analysis and evaluation.

[0351] A6-4 implementation path:

[0352] Data collection: The terminal device collects the IMEI code and other relevant information and sends it to the server.

[0353] Data processing: The server side receives the data and performs necessary preprocessing, such as data cleaning, feature extraction, etc.

[0354] Model evaluation: The server side uses the trained model to evaluate the processed data and identify potential risks.

[0355] Security measure triggering: According to the evaluation results, the server side automatically triggers corresponding security measures, such as restricting functions, sending warning messages, etc.

[0356] [Data example]

[0357] The system identifies a new IMEI code 123456789012345. The following is an example of the evaluation process:

[0358] - Data collection: The terminal device collects the new IMEI code 123456789012345 and records information such as the device model and user behavior.

[0359] - Data sending: The terminal sends the collected data to the server.

[0360] - Data processing: The server receives the data and performs data cleaning and feature extraction, such as extracting the usage record of the IMEI code, device model, user behavior characteristics, etc.

[0361] - Model evaluation: The server uses the trained model to evaluate the extracted features. The model may identify that this IMEI code has been marked as abnormal in historical data or is associated with a high-risk device model.

[0362] - Security measure triggering: According to the evaluation results, the server determines that this IMEI code belongs to the high-risk category and automatically triggers security measures, such as restricting the usage function of the SIM card and sending risk warning messages to the user and administrator.

[0363] Furthermore, based on the user's behavior of separating the device from the SIM card and combining the call score of real-time communication behavior and communication content by using a deep learning model, potential fraud-related communication behaviors are identified, including:

[0364] Determine the user's device-SIM card separation status;

[0365] Through the analysis of the operator's call records, the call behaviors of outgoing and incoming users are analyzed and compared, including whether they often call different mobile phone numbers, whether they are marked as fraud calls, whether the operator's terminal is marked as an abnormal incoming call, and whether they meet the scope of the operator's fraud-related communication behavior recognition algorithm. The communication behavior is scored.

[0366] Through the operator's network-wide recording, the user's call content is transcribed into text in real time. Through DFA sensitive word algorithm analysis and AI call large model analysis, the fraud-related communication content is defined and scored.

[0367] Based on the comprehensive communication behavior score, communication content score, and SIM-card separation status, according to the preset permission coefficient determination rule, the result of whether there is a suspected call fraud behavior or a confirmed call fraud behavior is output.

[0368] The process of identifying fraud-related communication behaviors is as Figure 3 shown. By changing the docking method of the SIM-card separation technology from OTA + digital SMS network docking to HTTPS protocol docking, the SIM-card separation verification data during the user's first binding and device replacement control process is obtained to determine whether the user has SIM-card separation.

[0369] Through the model for communication behavior analysis and control, as well as communication content identification and control, such as steps B1 - B4: Through the analysis of the operator's call records, the call behaviors of outgoing and incoming users are analyzed and compared, such as whether they often call different mobile phone numbers (making high-frequency outgoing calls to different numbers every day, which is inconsistent with the normal user behavior); whether they are marked as fraud calls by 12321, whether the operator's terminal is marked as an abnormal incoming call (obtaining the marking type for multi-dimensional matching); whether they meet the scope of the operator's fraud-related communication behavior recognition algorithm; this shows the complete process of intelligent communication behavior analysis.

[0370] Steps C1 - C3: Through the operator's network-wide recording, the user's call content is transcribed into text in real time. Through DFA sensitive word algorithm analysis and AI call large model analysis, the fraud-related call content is defined and scored, such as whether there is a mention of transfer operation, whether there is a sense of time urgency, whether it hits the preset fraud scenarios and fraud-related type classifications, and a comprehensive judgment is made based on the output of fraud-related evidence; this shows the complete process of intelligent communication content analysis.

[0371] Finally, based on the comprehensive analysis of the above three methods, a permission coefficient determination rule that can be adjusted and triggered is formed. According to the combination of automatically triggered means and weight judgment, two judgment results of suspected call fraud behavior and confirmed call fraud behavior are output. According to the preset rules, real-time warnings for users and business managers are automatically completed, such as real-time warning business managers (such as SMS notifications); after confirming fraud, the number is immediately shut down or the communication is blocked. A closed-loop control measure is formed.

[0372] Through the combined analysis of the separation of the mobile device and the SIM card, call behavior, and call content, the call fraud analysis in the embodiments of the present disclosure can achieve the following:

[0373] Improve the recognition accuracy and adaptive learning ability: Through the AI intelligent analysis of communication behavior data by deep learning algorithms, the accuracy of identifying fraud-related communication behaviors has been significantly improved through multiple means of judgment, effectively reducing misjudgments and missed judgments. It can reduce manual intervention and improve operational efficiency: Provide automated intelligent judgment, reduce the need for manual review, reduce operational costs, and at the same time improve the processing speed and the overall efficiency of the system. Real-time monitoring and early warning throughout the user's call process: By real-time monitoring the separation status of the mobile terminal and the SIM card, it can effectively identify and prevent fraud behaviors using the separated terminal and card, providing additional protection for the user's fund security and privacy protection. Through call behavior, call content data collection and AI real-time analysis, combining the three analysis methods can more effectively identify and prevent these new types of fraud means, and can send timely warnings through text messages, intelligent outbound calls, enterprise WeChat robots / DingTalk. It truly realizes the full-process control of criminals from the first insertion of the card, the generated call behavior, and the generated call content. Cope with new types of fraud means and enhance the technical confrontation ability: Effectively combat GoIP fraud. The GoIP device supports converting traditional telephone signals into network signals, realizing the separation of the device and the SIM card and hiding the true location of the crime. Combining the technology of separating the mobile device and the SIM card with call behavior and call content analysis can more effectively identify and combat GoIP fraud.

[0374] The embodiments of the present disclosure significantly improve the accuracy of identifying fraud-related communication behaviors through the intelligent analysis of communication behavior and communication content data by combining the separation of the mobile device and the SIM card with deep learning algorithms. By upgrading the existing OTA + digital SMS docking method for separating the mobile device and the SIM card to a docking based on the HTTPS protocol, the compatibility and scalability with the existing network infrastructure are enhanced. Through the seamless conversion of the HTTPS protocol, the efficiency of data processing is improved. The system can analyze communication behaviors in real time, quickly identify potential fraud behaviors, and effectively prevent the occurrence of fraud events through a timely risk assessment and early warning mechanism. In addition, the system combines the capabilities of large models to intelligently identify and annotate call behaviors and call content. And through the combination of three means, comprehensively judge the possibility of call fraud. And it provides adaptive learning and model optimization based on user feedback and new fraud cases to adapt to the evolving fraud means. While protecting user privacy, it reduces manual intervention, lowers operational costs, and improves the user experience.

[0375] Embodiment 2 of the present disclosure also provides a fraud recognition system based on the separation of the mobile device and the SIM card and communication information, as Figure 4 shown, the system includes:

[0376] The SIM-card separation conversion module 11 is configured to convert the data docking method of the SIM-card separation interface into the HTTPS protocol, so as to achieve the docking between the terminal and the existing network infrastructure through the HTTPS protocol;

[0377] The SIM-card binding module 12 is configured to automatically obtain the SIM-card information of the terminal and the USIM card after the user inserts the card and powers on for the first time, and perform SIM-card binding;

[0378] The authorization verification module 13 is configured to perform authorization verification when it detects that the user's USIM card is replaced with a terminal. After the verification passes, perform SIM-card binding again;

[0379] The data collection module 14 is configured to collect the communication data of the USIM card, including SIM-card verification data, call records, text message content, and network traffic;

[0380] The data processing module 15 is configured to preprocess the collected data;

[0381] The training module 16 is configured to construct a data set containing various communication contents and behavior characteristics through the preprocessed communication data, and train and optimize the deep learning model through the data set to identify abnormal patterns and potential fraud behaviors in communication behaviors;

[0382] The identification module 17 is configured to determine whether there is SIM-card separation through the SIM-card verification data, and identify possible fraud-related communication behaviors based on the user's SIM-card separation behavior and the call score of the real-time communication behavior and communication content in combination with the deep learning model.

[0383] Further, the SIM-card separation conversion module 11 is specifically configured as follows:

[0384] Convert the data of the SIM-card separation interface: Dynamically identify various variants of the OTA and digital text message data formats through an adaptive parsing algorithm, and convert the data into a structure that meets the requirements of the HTTPS protocol according to the characteristics of the data format;

[0385] When converting the data from the SIM-card separation interface to the HTTPS protocol, dynamically allocate different levels of encryption keys according to the sensitivity of the data and the transmission stage;

[0386] Intelligently cache the data that may be frequently accessed according to the historical data transmission law and the real-time network condition.

[0387] Further, the dynamically identifying various variants of the OTA and digital text message data formats through an adaptive parsing algorithm, and converting the data into a structure that meets the requirements of the HTTPS protocol includes:

[0388] Data feature extraction: Extract key features from the original data, which can represent the structure and content of the data;

[0389] Pattern recognition: Use machine learning models to identify the patterns and structures of the data;

[0390] Automatic learning and adaptation: Adaptive parsing algorithms automatically adjust their model parameters according to new data samples to adapt to different data formats;

[0391] Conversion rule generation: Automatically generate rules to convert data into the structure required by the HTTPS protocol according to the recognized data patterns.

[0392] Furthermore, intelligent caching is performed on data that may be frequently accessed according to the historical data transmission law and the real-time network condition, including:

[0393] Data access pattern analysis: Identify frequently accessed data patterns by analyzing historical data access logs;

[0394] Real-time network condition monitoring: Real-time monitor the network condition, including bandwidth, latency, and packet loss rate metrics;

[0395] Intelligent caching strategy: Develop an intelligent caching strategy according to the identified data access patterns and real-time network conditions;

[0396] Prefetch operation: Based on a prediction model, predict upcoming data transmission requirements and perform data prefetching in advance.

[0397] Furthermore, the machine-card binding module 12 is specifically set as:

[0398] After the user inserts the USIM card into the device and powers it on, the machine-card information of the terminal and the USIM card is automatically read, and the machine-card information includes the ICCID, IMEI code, mobile phone number, and binding status information in the USIM card;

[0399] Pack the obtained machine-card information into blocks and perform distributed storage through the blockchain network;

[0400] Use an encryption algorithm to perform hash processing on the data in the block, and verify the block through multiple nodes in the blockchain network;

[0401] After verification, add the block to the blockchain, and jointly store it by multiple nodes in the network to achieve distributed storage of data;

[0402] The machine-card information stored in the blockchain is used as the basic data for subsequent machine-card separation identification to verify the legality and consistency of the machine and the card.

[0403] Furthermore, the machine-card binding module 12 is also set as:

[0404] In the process of the server requesting to obtain the IMEI of the terminal each time, a one-time key is dynamically generated through a preset algorithm according to the current real-time status of the server and the terminal and the preset key generation parameters, and the server and the terminal communicate according to the generated one-time key.

[0405] Further, the card-terminal binding module 12 is also set to:

[0406] When the terminal returns the IMEI information, the IMEI data is compressed and encoded by using the compressive sensing technology and then transmitted to the server.

[0407] Further, the card-terminal binding module 12 is also set to:

[0408] According to the historical binding data and the user behavior patterns, a personalized binding machine learning model is trained, so that the personalized binding machine learning model can automatically analyze and predict the binding characteristics and potential risks of different users and different devices, and generate personalized binding information accordingly;

[0409] When performing card-terminal binding, personalized binding information is generated according to the characteristics of the user and the device in the personalized binding machine learning model; and,

[0410] According to the binding information, additional security identifiers and verification requirements are added for high-risk users or devices.

[0411] Further, the authorization verification module 13 is specifically set to:

[0412] After the server automatically recognizes a new IMEI code, it requests the user to perform biometric verification;

[0413] The biometric features collected by the terminal during user verification are matched with the information reserved by the user during the first binding stage; and the new IMEI code is verified by the system;

[0414] If the biometric features match and the new IMEI code passes the verification, it is determined that the authorization verification is passed.

[0415] Further, the authorization verification module 13 is also set to:

[0416] Collect and analyze IMEI-related data in real time, and evaluate the potential risks brought by the new IMEI code through a risk assessment model, including:

[0417] Data collection: Collect the IMEI code and other relevant information through the terminal device and send them to the server;

[0418] Data processing: The server receives the data and performs preprocessing;

[0419] Model evaluation: The server uses the trained risk assessment model to evaluate the preprocessed data and identify potential risks;

[0420] Security measure triggering: Based on the evaluation results, the server automatically triggers corresponding security measures.

[0421] Furthermore, the recognition module 17 is specifically set as follows:

[0422] Determine the SIM-card separation status of the user;

[0423] Through the analysis of the operator's call records, analyze and compare the calling behaviors of incoming and outgoing users, including whether they often call different mobile phone numbers, whether they are marked as fraud calls, whether the operator's terminal is marked as an abnormal incoming call, whether it falls within the scope of the operator's fraud-related communication behavior recognition algorithm, and score the communication behaviors;

[0424] Through the operator's network-wide recording, in the way of real-time transcribing the user's call content into text, analyze and score the fraud-related communication content through the DFA sensitive word algorithm analysis and the AI call large model analysis;

[0425] Based on the comprehensive communication behavior score, communication content score, and SIM-card separation status, according to the preset permission coefficient determination rule, output the result of whether there is a suspected call fraud behavior or a confirmed call fraud behavior.

[0426] The fraud recognition system based on SIM-card separation and communication information in the embodiments of the present disclosure is used to implement the fraud recognition method based on SIM-card separation and communication information in the first method embodiment, so the description is relatively simple. For specific details, please refer to the relevant descriptions in the previous method embodiments and will not be elaborated here.

[0427] In addition, as Figure 5 shown, the third embodiment of the present disclosure also provides an electronic device, including a memory 100 and a processor 200. A computer program is stored in the memory 100. When the processor 200 runs the computer program stored in the memory 100, the processor 200 executes the above various possible methods.

[0428] Among them, the memory 100 is connected to the processor 200. The memory 100 can be a flash memory or a read-only memory or other memories, and the processor 200 can be a central processing unit or a single-chip microcomputer.

[0429] In addition, the embodiments of the present disclosure also provide a computer-readable storage medium, on which a computer program is stored, and the computer program is executed by the processor to perform the above various possible methods.

[0430] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, computer program modules, or other data. The computer-readable storage medium includes, but is not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), digital versatile disc (DVD, Digital Video Disc) or other optical disc storage, magnetic cassette, tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer.

[0431] It should be understood that the above embodiments are merely exemplary embodiments adopted to illustrate the principles of the present disclosure, but the present disclosure is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present disclosure, and these modifications and improvements are also regarded as the protection scope of the present disclosure.

Claims

1. A fraud identification method based on machine-card separation and communication information, characterized in that: The method comprises: Convert the data connection mode of the machine-card separation interface to the Hypertext Transfer Protocol (HTTPS) protocol, so as to realize the connection between the terminal and the existing network infrastructure through the HTTPS protocol; After the user inserts the card and turns on the device for the first time, the terminal and the USIM card information are automatically obtained to perform the device-card binding. When it is detected that the user's USIM card has been replaced, authorization verification is performed. After the verification is passed, the machine-card binding is performed again; Collect USIM card communication data, including card verification data, call records, SMS content, and network traffic; Preprocess the collected data; Build a dataset containing various communication content and behavior characteristics through preprocessed communication data, and train and optimize deep learning models through the dataset to identify abnormal patterns and potential fraudulent behaviors in communication behaviors; The machine-card verification data is used to determine whether there is machine-card separation. Based on the user's machine-card separation behavior, the deep learning model is combined with call scoring of real-time communication behavior and communication content to identify possible fraudulent communication behavior.

2. The method according to claim 1, characterized in that The converting of the data connection mode of the machine-card separation interface into the HTTPS protocol includes: Convert the data of the device-card separation interface: Dynamically identify various variations of the over-the-air download technology OTA and digital SMS data formats through an adaptive parsing algorithm, and convert the data into a structure that meets the requirements of the HTTPS protocol based on the characteristics of the data format; When data is converted from the machine-card separation interface to the HTTPS protocol, different levels of encryption keys are dynamically allocated according to the sensitivity of the data and the transmission stage; Based on historical data transmission rules and real-time network conditions, data that may be frequently accessed is intelligently cached.

3. The method according to claim 2, characterized in that The adaptive parsing algorithm dynamically identifies various variants of OTA and digital SMS data formats, and converts the data into a structure that complies with the requirements of the HTTPS protocol according to the characteristics of the data format, including: Data feature extraction: extract key features from raw data, which can represent the structure and content of the data; Pattern recognition: using machine learning models to identify patterns and structures in data; Automatic learning and adaptation: Adaptive parsing algorithms automatically adjust their model parameters based on new data samples to adapt to different data formats; Conversion rule generation: Based on the identified data patterns, automatically generate rules to convert data into the structure required by the HTTPS protocol.

4. The method according to claim 2 or 3, characterized in that: The intelligent caching of data that may be frequently accessed based on historical data transmission rules and real-time network conditions includes: Data access pattern analysis: Identify frequently accessed data patterns by analyzing historical data access logs; Real-time network status monitoring: Real-time monitoring of network status, including bandwidth, delay, and packet loss rate indicators; Intelligent caching strategy: formulate intelligent caching strategy based on identified data access patterns and real-time network conditions; Prefetch operation: Based on the prediction model, the upcoming data transmission demand is predicted and data is prefetched in advance.

5. The method according to claim 1, characterized in that After the user inserts the card and turns on the device for the first time, the terminal and the USIM card information are automatically obtained to perform the terminal-card binding, including: After the user inserts the USIM card into the device and turns it on, the terminal and the USIM card's machine and card information are automatically read. The machine and card information includes the integrated circuit card identification code ICCID, the international mobile equipment identity code IMEI code, the mobile phone number, and the binding status information in the USIM card; The acquired machine card information is packaged into blocks and distributedly stored through the blockchain network; Use encryption algorithms to hash the data in the block and verify the block through multiple nodes in the blockchain network; After verification, the block is added to the blockchain and stored by multiple nodes in the network to achieve distributed storage of data.

6. The method according to claim 5, characterized in that The method further comprises: Each time the server requests to obtain the terminal IMEI, a one-time key is dynamically generated through a preset algorithm according to the current real-time status of the server and the terminal and preset key generation parameters, and the server and the terminal communicate based on the generated one-time key.

7. The method according to claim 5 or 6, characterized in that: The method further comprises: When the terminal returns the IMEI information, the IMEI data is compressed and encoded using compressed sensing technology before being transmitted to the server.

8. The method according to claim 1, characterized in that The method further comprises: Based on historical binding data and user behavior patterns, a personalized binding machine learning model is trained to enable the personalized binding machine learning model to automatically analyze and predict the binding characteristics and potential risks of different users and devices, and generate personalized binding information accordingly; When binding a device to a card, generating personalized binding information based on the characteristics of the user and the device in a personalized binding machine learning model; and, Based on the binding information, add additional security identification and verification requirements for high-risk users or devices.

9. The method according to claim 1, characterized in that: When it is detected that the user's USIM card has been replaced by a terminal, authorization verification is performed, including: After the server automatically recognizes the new IMEI code, it requires the user to perform biometric verification; Match the biometrics collected by the terminal during user authentication with the information reserved by the user during the first binding phase; and perform system verification on the new IMEI code; If the biometrics match and the new IMEI code is verified, the authorization verification is judged to be successful.

10. The method according to claim 1 or 9, characterized in that: The method further comprises: Collect and analyze IMEI-related data in real time, and use risk assessment models to assess the potential risks posed by new IMEI codes, including: Data collection: collect IMEI code and other related information through terminal devices and send them to the server; Data processing: The server receives data and performs preprocessing; Model evaluation: The server uses the trained risk assessment model to evaluate the preprocessed data and identify potential risks; Security measures triggering: Based on the evaluation results, the server automatically triggers the corresponding security measures.

11. The method according to claim 1, characterized in that: The method of identifying possible fraudulent communication behaviors based on the user's card-device separation behavior and the call scoring of the real-time communication behavior and communication content by the deep learning model includes: Determine the user's machine-card separation status; Through the operator's call record analysis, the calling behavior of users who make outgoing and incoming calls is analyzed and compared, including whether different mobile phone numbers are frequently dialed, whether they are marked as fraudulent calls, whether the operator's terminal is marked as an abnormal call, and whether it meets the judgment range of the operator's fraudulent communication behavior identification algorithm, and the communication behavior is scored; By recording the operator's large network and transcribing the user's call content into text in real time, the fraudulent communication content is defined and scored through the determination of the DFA sensitive word algorithm and the AI ​​call large model analysis; Based on the comprehensive communication behavior score, communication content score and phone-card separation status, according to the preset authority coefficient judgment rule, the output is whether there is suspected call fraud or the result of confirmed call fraud.

12. A fraud identification system based on machine-card separation and communication information, characterized in that: The system comprises: A machine-card separation conversion module, which is configured to convert the data connection mode of the machine-card separation interface into the HTTPS protocol, so as to realize the connection between the terminal and the existing network infrastructure through the HTTPS protocol; The machine-card binding module is configured to automatically obtain the machine-card information of the terminal and the USIM card and perform machine-card binding after the user inserts the card and turns on the machine for the first time; The authorization verification module is configured to perform authorization verification when it detects that the user's USIM card has been replaced with a terminal. After the verification is passed, the machine-card binding is performed again; A data collection module is configured to collect communication data of the USIM card, including machine card verification data, call records, text message content, and network traffic; A data processing module, which is configured to pre-process the collected data; A training module configured to construct a data set containing a variety of communication content and behavior characteristics through the preprocessed communication data, and train and optimize a deep learning model through the data set to identify abnormal patterns and potential fraudulent behaviors in communication behaviors; The identification module is configured to determine whether there is a machine-card separation through the machine-card verification data, and identify possible fraudulent communication behaviors based on the user's machine-card separation behavior and call scoring of real-time communication behaviors and communication content combined with a deep learning model.

13. An electronic device, characterized in that: It includes a memory and a processor, wherein the memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the fraud identification method based on machine-card separation and communication information as described in any one of claims 1-11.

14. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the fraud identification method based on machine-card separation and communication information as described in any one of claims 1-11 is implemented.