Equipment risk confirmation method and device and storage medium

By obtaining network-based information and risk control rules of embedded SIM cards on the device, determining device risks and performing control operations, the shortcomings of eSIM devices in risk control are solved, and security and information protection are improved.

CN120282140APending Publication Date: 2025-07-08BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410024233.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-05
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

When using eSIM functionality on wearable devices or other devices, there is a lack of necessary risk control measures, especially inadequate protection in data security.

Method used

By obtaining the configuration file containing risk control rules and the network-based information of the embedded SIM card on the device, determine whether there is a risk in the device based on the risk control rules and network-based information, and perform preset risk control operations when there is a risk.

Benefits of technology

It realizes timely discovery and control of device risks, improves the security of the device, and protects user information security, avoids the risk of sending network-based information to the cloud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120282140A_ABST
    Figure CN120282140A_ABST
Patent Text Reader

Abstract

The invention relates to an equipment risk confirmation method and device and a storage medium. The method comprises the following steps: acquiring a configuration file containing risk control rules; obtaining resident network information of an embedded SIM card arranged on the equipment; determining whether the equipment has a risk according to the risk control rule and the resident network information; and if it is determined that the equipment has the risk, executing a preset risk control operation. According to the method, the risk control rule and the resident network information are acquired, whether the equipment has risks or not is determined according to the risk control rule and the resident network information, and the preset risk control operation is executed under the condition of determining that the equipment has the risks. Therefore, according to the risk control rule and the resident network information, possible risks of the equipment can be found in time, and corresponding risk control operation can be adopted in time, so that the safety of the equipment is improved. Besides, the method is directly applied to the equipment end, the risk control rule of the operator only needs to be acquired from the cloud end, the resident network information does not need to be sent to the cloud end, and the information security of the user can be effectively protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular, to a method, device, and storage medium for device risk confirmation. Background Art

[0002] With the popularization of eSIM (embedded Subscriber Identity Module), the eSIM function can be used on wearable devices or other devices. The number download is dynamically completed and issued by the device side. However, in addition to the data security guarantee provided by the chip itself, there are no necessary risk control measures in other aspects. Summary of the Invention

[0003] To overcome the problems existing in the related art, the present disclosure provides a method, device, and storage medium for device risk confirmation.

[0004] According to a first aspect of an embodiment of the present disclosure, a method for device risk confirmation is provided. The method includes:

[0005] Obtain a configuration file containing risk control rules;

[0006] Obtain the network registration information of the embedded SIM card set on the device;

[0007] Determine whether the device has risks according to the risk control rules and the network registration information;

[0008] If it is determined that the device has risks, perform a preset risk control operation.

[0009] Optionally, the obtaining the network registration information of the embedded SIM card set on the device includes:

[0010] Obtain the location information and base station information of the network registration stored in the embedded SIM card;

[0011] Obtain the device identifier corresponding to the embedded SIM card;

[0012] Determine the location information, the device identifier, and the base station information as the network registration information.

[0013] Optionally, the location information and base station information of the network registration include the location information and base station information corresponding to the embedded SIM card in at least one historical network registration process.

[0014] Optionally, the determining whether the device has risks according to the risk control rules and the network registration information includes:

[0015] According to the network registration information, determine a target abnormal event related to the risk control rules;

[0016] Determine a target risk value according to the target abnormal event and the risk control rule;

[0017] When the target risk value reaches a preset risk threshold, determine that the device has a risk.

[0018] Optionally, the target abnormal event includes at least one of camping on the network at an abnormal location, camping on the network at an abnormal base station, camping on the network during an abnormal period, and belonging to an abnormal device.

[0019] Optionally, the determining the target risk value according to the target abnormal event and the risk control rule includes:

[0020] For each target abnormal event, determine the risk value corresponding to the target abnormal event according to the risk value determination method corresponding to the target abnormal event in the risk control rule;

[0021] Determine the target risk value according to the risk values corresponding to at least one target abnormal event.

[0022] Optionally, the determining the target risk value according to the risk values corresponding to at least one target abnormal event includes:

[0023] Obtain the weight corresponding to each target abnormal event;

[0024] Determine the target risk value by weighted calculation according to the risk value corresponding to the target abnormal event and the weight corresponding to the target abnormal event.

[0025] Optionally, the performing a preset risk control operation includes at least one of the following:

[0026] Generate a risk prompt message and send it to the target platform;

[0027] Generate an alarm message and output it through the device;

[0028] Prohibit the device from camping on the network.

[0029] According to the second aspect of the embodiments of the present disclosure, there is provided a device risk confirmation device, and the method includes:

[0030] A first acquisition module, configured to acquire a configuration file including a risk control rule;

[0031] A second acquisition module, configured to acquire the camping on the network information of the embedded SIM card set on the device;

[0032] A determination module, configured to determine whether the device has a risk according to the risk control rule and the camping on the network information;

[0033] An execution module, configured to perform a preset risk control operation if it is determined that the device has a risk.

[0034] According to a third aspect of the embodiments of the present disclosure, there is provided a device risk confirmation apparatus, including:

[0035] A processor;

[0036] A memory for storing executable instructions of the processor;

[0037] Wherein, the processor is configured to execute the device risk confirmation method described in the first aspect of the present disclosure.

[0038] According to a fourth aspect of the embodiments of the present disclosure, there is provided a computer-readable storage medium, on which computer program instructions are stored, and when the program instructions are executed by a processor, the steps of the device risk confirmation method provided in the first aspect of the present disclosure are implemented.

[0039] The technical solutions provided by the embodiments of the present disclosure may include the following beneficial effects:

[0040] Through the above technical solutions, by obtaining a configuration file containing risk control rules and the network registration information of the embedded SIM card on the device, and then determining whether the device has a risk according to the risk control rules and the network registration information, and performing a preset risk control operation when it is determined that the device has a risk. Thus, through the risk control rules and the network registration information, the possible risks of the device can be discovered in a timely manner, and corresponding risk control operations can be taken in a timely manner to improve the security of the device. In addition, this method is directly applied to the device side, only the risk control rules of the operator need to be obtained from the cloud, and there is no need to send the network registration information to the cloud, which can effectively protect the information security of users.

[0041] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] The drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure.

[0043] Figure 1 Is a flowchart of a device risk confirmation method shown according to an exemplary embodiment.

[0044] Figure 2 Is a block diagram of a device risk confirmation apparatus shown according to an exemplary embodiment.

[0045] Figure 3 Is a block diagram of a device risk confirmation apparatus shown according to an exemplary embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0046] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of apparatuses and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0047] It should be noted that all actions of obtaining signals, information, or data in the present disclosure are carried out on the premise of complying with the corresponding data protection regulations and policies of the country where the location is located and obtaining the authorization given by the owner of the corresponding device.

[0048] Figure 1 is a flowchart of a method for confirming device risks shown according to an exemplary embodiment. This method can be applied to an electronic device provided with an embedded SIM card (eSIM) to determine whether there are risks in the electronic device. As Figure 1 shown, the method provided by the present disclosure may include step 11 to step 14.

[0049] In step 11, obtain a configuration file containing risk control rules.

[0050] The operator can issue risk control rules in the form of a configuration file through the cloud platform. Therefore, a configuration file containing risk control rules can be obtained from the cloud platform.

[0051] Generally, over time, the risk control rules set by the operator will be adjusted or changed. Therefore, in order to ensure that the risk control rules used for device risk confirmation are the latest, in one possible implementation, the configuration file containing risk control rules can be obtained from the cloud periodically; in another possible implementation, whenever the operator updates the configuration file, an update notification can be generated through the cloud. Based on this, whenever the update notification is recognized, the step of obtaining the configuration file containing risk control rules can be triggered.

[0052] In step 12, obtain the network registration information of the embedded SIM card set on the device.

[0053] Since the device is provided with an embedded SIM card and the device may have registered on the network multiple times through the embedded SIM card, relevant network registration information can be obtained.

[0054] In one possible implementation, step 12 may include the following steps:

[0055] Obtain the network registration location information and base station information stored in the embedded SIM card;

[0056] Obtain the device identifier corresponding to the embedded SIM card;

[0057] Determine the location information, device identifier, and base station information as the network registration information.

[0058] Among them, the network registration location information and base station information may include the location information and base station information corresponding to the embedded SIM card during at least one historical network registration process. That is to say, every time a network registration is performed, there will be corresponding location information and base station information.

[0059] Configuration information (profile) can be set in the embedded SIM card. The configuration information may include, but is not limited to, ICCID (Integrated Circuit Card Identifier), Ki (Authentication Key), and OPC (Operator Policy Code). Among them, ICCID is the unique identifier of the eSIM card; Ki is the key used for authentication, which is used to verify the legality of the eSIM card and ensure communication security. It negotiates with the operator's authentication center to generate the key required for the security algorithm; OPC is the code used to generate the operator policy-related key. It is used together with Ki to generate the key for authentication and encrypted communication, and it is defined and managed by the operator. Based on the above profile information, the network registration operation of the embedded SIM card can be realized. Every time a network registration operation is completed, the network registration information corresponding to this network registration can be stored.

[0060] Among them, the network registration information may include the above location information, base station information, and device identifier, or may also include the above configuration information profile.

[0061] The network registration location information can be understood as information related to the location, and it may not be limited to the geographical location. Optionally, the network registration location information may include, but is not limited to, the country code, mobile network code, call tracking area code, and cell identification code. In essence, the above-mentioned several items represent location information in different dimensions, so in this disclosure, they can all be used as location information.

[0062] Optionally, the country code can use MCC (Mobile Country Code), the mobile network code can use MNC (Mobile Network Code), the call tracking area code can use LAC (Location Area Code), TAC (Tracking Area Code), or SID (System Identification), and the cell identification code can use CID (Cell Identity), ECI (E-UTRAN Cell Identifier), RCI (Radio Cell Identifier), or NID (Network ID).

[0063] The information of the base station in the network is the information of the base station connected during a network registration process.

[0064] The device identifier can be used to uniquely identify the embedded SIM card. For example, the ICCID mentioned above can be used as the device identifier. Another example is that the embedded SIM card can use an eUICC (embedded Universal Integrated Circuit Card) chip, which is hardware with an EAL4+ security level (EAL, Evaluation Assurance Level). The hardware information cannot be tampered with, providing higher security. Based on this, the unique identifier EID (eUICC Identifier) of the eUICC chip can also be used as the device identifier.

[0065] It should be noted that there is no strict execution order for steps 11 and 12 in the present disclosure. They can be executed simultaneously or sequentially, and the present disclosure does not limit this.

[0066] In step 13, based on the risk control rules and the network registration information, it is determined whether the device has risks.

[0067] In a possible implementation, step 13 may include the following steps:

[0068] Based on the network registration information, determine the target abnormal event related to the risk control rules;

[0069] Based on the target abnormal event and the risk control rules, determine the target risk value;

[0070] In the case where the target risk value reaches the preset risk threshold, it is determined that the device has risks.

[0071] Among them, the target abnormal event may include but is not limited to at least one of staying connected to the network at an abnormal location, staying connected to the network at an abnormal base station, staying connected to the network during an abnormal period, and belonging to an abnormal device.

[0072] Optionally, the risk control rules may include information such as a location blacklist, a base station blacklist, a device blacklist, and abnormal periods. In this way, based on the risk control rules and the relevant content included in the network connection information, the target abnormal event can be determined.

[0073] Exemplarily, if a base station included in the base station information in the network connection information exists in the base station blacklist of the risk control rules, it can be regarded as a target abnormal event occurring once. For another example, if multiple location codes included in the location information in the network connection information appear in the location blacklist, it can be regarded as multiple target abnormal events occurring.

[0074] Optionally, the target abnormal event may correspond to the number of occurrences and the occurrence time. In this way, the number of target abnormal events occurring within a specified period can be determined.

[0075] Based on the above method, all the target abnormal events involved in the network connection information can be determined.

[0076] In a possible implementation manner, determining a target risk value according to the target abnormal event and the risk control rules includes:

[0077] For each target abnormal event, determine the risk value corresponding to the target abnormal event according to the risk value determination method corresponding to the target abnormal event in the risk control rules;

[0078] Determine the target risk value according to the risk values corresponding to at least one target abnormal event.

[0079] The risk control rules may include risk value determination methods corresponding to different abnormal events. Based on the risk value determination method, combined with the target abnormal event or the number of occurrences of the abnormal event, the risk value corresponding to the target abnormal event can be determined.

[0080] The risk value determination method can be adaptively set according to actual requirements. Exemplarily, the risk value determination method can be provided as a formula, such as a calculation formula constructed according to the number of occurrences of the abnormal event. For another example, the risk value determination method can be determined as a corresponding relationship, such as the corresponding relationship between the number of occurrences of a certain abnormal event and the risk value.

[0081] Based on this, the risk value corresponding to each target abnormal event can be determined. In this way, the target risk value used to finally determine whether the device is at risk can be determined according to the risk values corresponding to at least one target abnormal event.

[0082] In a possible implementation, the maximum value among the risk values corresponding to at least one target abnormal event may be determined as the target risk value.

[0083] In another possible implementation, the average value of the risk values corresponding to at least one target abnormal event may be determined as the target risk value.

[0084] In another possible implementation, the median value of the risk values corresponding to at least one target abnormal event may be determined as the target risk value.

[0085] In another possible implementation, determining the target risk value according to the risk values corresponding to at least one target abnormal event may include the following steps:

[0086] Obtain the weight corresponding to each target abnormal event;

[0087] Based on the risk value corresponding to the target abnormal event and the weight corresponding to the target abnormal event, determine the target risk value by weighting.

[0088] That is to say, weights corresponding to each type of abnormal event may be set in the risk control rule. In this way, the weight corresponding to the target abnormal event in the risk control rule can be obtained. After determining the risk value corresponding to the target abnormal event, weighted summation calculation may also be performed according to the risk value corresponding to each target abnormal event and its respective corresponding weight. After obtaining the result of the weighted summation, the result of the weighted summation is determined as the finally obtained target risk value.

[0089] Furthermore, according to the determined target risk value, the following method may be used to determine whether the device is at risk:

[0090] When the target risk value reaches the preset risk threshold, it is determined that the device is at risk;

[0091] When the target risk value does not reach the preset risk threshold, it is determined that the device is not at risk.

[0092] Among them, the preset risk threshold may be set according to actual needs, and the present disclosure does not make excessive limitations.

[0093] Optionally, according to the risk control rule and the in-network information, the following method may also be used to determine whether the device is at risk:

[0094] In the risk control rules, the priority of risk identification can be set. For example, if the risk control rules include rules regarding location, rules regarding base stations, rules regarding devices, and rules regarding time periods, and the priorities gradually decrease, then the risk value can be determined starting from the highest priority, that is, determining the risk value of the target abnormal event related to location. If this risk value reaches the specified threshold, there is no need to continue determining the risk values of other target abnormal events, and it can be directly determined that the device is at risk. If this risk value does not reach the specified threshold, continue to determine the risk value of the next priority, that is, the risk value of the target abnormal event related to the base station, until it is determined that the device is at risk, or it is determined that the device is not at risk after judging the lowest priority.

[0095] Among them, the specified threshold can be set according to actual needs, and the present disclosure does not limit this too much.

[0096] In step 14, if it is determined that the device is at risk, perform a preset risk control operation.

[0097] Optionally, the preset risk control operation may include but is not limited to at least one of the following:

[0098] Generate a risk prompt message and send it to the target platform;

[0099] Generate an alarm message and output it through the device;

[0100] Prohibit the device from registering on the network.

[0101] Among them, the target platform can be a cloud platform managed by the operator. Generating a risk prompt message and sending it to the target platform is equivalent to reporting the risk-related information to the target platform so that the target platform can make further judgments and / or take measures based on the risk prompt message.

[0102] Generating an alarm message and outputting it through the device is used to prompt the user at the device end, facilitating the user to take corresponding countermeasures.

[0103] Prohibiting the device from registering on the network can be achieved by disconnecting the network connection of the device. For example, if the device is registering on the network, prohibiting the device from registering on the network can be achieved by stopping the network registration activation process of the device. Another example is that if the device has successfully registered on the network, prohibiting the device from registering on the network can be achieved by deleting the local profile.

[0104] Exemplarily, the method provided by the present disclosure can be applied to the LPA (Local Profile Assistant, a tool for managing local user profiles) application of an electronic device. The LPA can forward information between the SM-DP+ (Secure Element Data Preparation and Secure Transfer Platform) and the eUICC to assist the user in activating the eSIM.

[0105] Through the above technical solution, by obtaining the configuration file containing the risk control rules and the network registration information of the embedded SIM card on the device, and then determining whether the device has risks according to the risk control rules and the network registration information. When it is determined that the device has risks, a preset risk control operation is executed. Thus, through the risk control rules and the network registration information, the possible risks of the device can be discovered in a timely manner, and corresponding risk control operations can be taken in a timely manner to improve the security of the device. In addition, this method is directly applied to the device side, only the risk control rules of the operator need to be obtained from the cloud, and there is no need to send the network registration information to the cloud, which can effectively protect the information security of the user.

[0106] Figure 2 is a block diagram of a device risk confirmation device shown according to an exemplary embodiment. Refer to Figure 2 and the device 20 includes:

[0107] A first acquisition module 21, configured to acquire a configuration file containing risk control rules;

[0108] A second acquisition module 22, configured to acquire the network registration information of the embedded SIM card set on the device;

[0109] A determination module 23, configured to determine whether the device has risks according to the risk control rules and the network registration information;

[0110] An execution module 24, configured to execute a preset risk control operation if it is determined that the device has risks.

[0111] Optionally, the second acquisition module 22 includes:

[0112] A first acquisition sub-module, configured to acquire the network registration location information and base station information stored in the embedded SIM card;

[0113] A second acquisition sub-module, configured to acquire the device identifier corresponding to the embedded SIM card;

[0114] A first determination sub-module, configured to determine the network registration information from the location information, the device identifier and the base station information.

[0115] Optionally, the location information and base station information of the network residence include the location information and base station information corresponding to the embedded SIM card during at least one historical network residence process.

[0116] Optionally, the determining module 23 includes:

[0117] A second determining sub-module, configured to determine a target abnormal event related to the risk control rule according to the network residence information;

[0118] A third determining sub-module, configured to determine a target risk value according to the target abnormal event and the risk control rule;

[0119] A fourth determining sub-module, configured to determine that the device has a risk when the target risk value reaches a preset risk threshold.

[0120] Optionally, the target abnormal event includes at least one of network residence at an abnormal location, network residence at an abnormal base station, network residence during an abnormal period, and belonging to an abnormal device.

[0121] Optionally, the third determining sub-module includes:

[0122] A fifth determining sub-module, configured to determine the risk value corresponding to each target abnormal event according to the risk value determination method corresponding to the target abnormal event in the risk control rule;

[0123] A sixth determining sub-module, configured to determine the target risk value according to the risk values corresponding to at least one target abnormal event.

[0124] Optionally, the sixth determining sub-module includes:

[0125] A third obtaining sub-module, configured to obtain the weight corresponding to each target abnormal event;

[0126] A seventh determining sub-module, configured to determine the target risk value by weighted calculation according to the risk value corresponding to the target abnormal event and the weight corresponding to the target abnormal event.

[0127] Optionally, the execution module 24 includes at least one of the following:

[0128] A first execution sub-module, configured to generate a risk prompt message and send it to the target platform;

[0129] A second execution sub-module, configured to generate an alarm message and output it through the device;

[0130] A third execution sub-module, configured to prohibit the device from residing in the network.

[0131] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.

[0132] The present disclosure also provides a device risk confirmation device, including:

[0133] A processor;

[0134] A memory for storing instructions executable by the processor;

[0135] Wherein, the processor is configured to execute the device risk confirmation method provided by the present disclosure.

[0136] The present disclosure also provides a computer-readable storage medium, on which computer program instructions are stored, and when the program instructions are executed by a processor, the steps of the device risk confirmation method provided by the present disclosure are implemented.

[0137] Figure 3 FIG. 800 is a block diagram of a device risk confirmation device 800 shown according to an exemplary embodiment. For example, the device 800 may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0138] Referring to Figure 3 , the device 800 may include one or more of the following components: a processing component 802, a memory 804, a power supply component 806, a multimedia component 808, an audio component 810, an input / output interface 812, a sensor component 814, and a communication component 816.

[0139] The processing component 802 generally controls the overall operation of the device 800, such as operations associated with display, telephone calls, data communication, camera operations, and recording operations. The processing component 802 may include one or more processors 820 to execute instructions to complete all or part of the steps of the above device risk confirmation method. In addition, the processing component 802 may include one or more modules to facilitate the interaction between the processing component 802 and other components. For example, the processing component 802 may include a multimedia module to facilitate the interaction between the multimedia component 808 and the processing component 802.

[0140] The memory 804 is configured to store various types of data to support the operation of the device 800. Examples of such data include instructions for any application or method operating on the device 800, contact data, phone book data, messages, pictures, videos, and the like. The memory 804 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk.

[0141] The power supply component 806 provides power to the various components of the device 800. The power supply component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the device 800.

[0142] The multimedia component 808 includes a screen that provides an output interface between the device 800 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can not only sense the boundaries of the touch or swipe actions but also detect the duration and pressure associated with the touch or swipe operation. In some embodiments, the multimedia component 808 includes a front camera and / or a rear camera. When the device 800 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each of the front camera and the rear camera can be a fixed optical lens system or have focal length and optical zoom capabilities.

[0143] The audio component 810 is configured to output and / or input audio signals. For example, the audio component 810 includes a microphone (MIC) that is configured to receive external audio signals when the device 800 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 804 or transmitted via the communication component 816. In some embodiments, the audio component 810 further includes a speaker for outputting audio signals.

[0144] The input / output interface 812 provides an interface between the processing component 802 and a peripheral interface module, which can be a keyboard, a click wheel, buttons, etc. These buttons can include, but are not limited to: a home button, a volume button, a power-on button, and a lock button.

[0145] The sensor assembly 814 includes one or more sensors for providing an assessment of the status of the device 800 in various aspects. For example, the sensor assembly 814 can detect the on / off state of the device 800, the relative positioning of components, such as the display and keypad of the device 800, the sensor assembly 814 can also detect a change in the position of the device 800 or a component of the device 800, the presence or absence of user contact with the device 800, the orientation or acceleration / deceleration of the device 800, and the temperature change of the device 800. The sensor assembly 814 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor assembly 814 can also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor assembly 814 can further include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0146] The communication component 816 is configured to facilitate communication between the device 800 and other devices in a wired or wireless manner. The device 800 can access a wireless network based on communication standards, such as WiFi, 2G, or 3G, or a combination thereof. In an exemplary embodiment, the communication component 816 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 816 further includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0147] In an exemplary embodiment, the device 800 can be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components for performing the above-described device risk confirmation method.

[0148] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as the memory 804 including instructions, and the above instructions can be executed by the processor 820 of the device 800 to complete the above-described device risk confirmation method. For example, the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0149] In another exemplary embodiment, there is also provided a computer program product, which includes a computer program executable by a programmable device, and the computer program has a code portion for performing the above-described device risk confirmation method when executed by the programmable device.

[0150] After considering the specification and practicing the present disclosure, those skilled in the art will readily conceive of other embodiments of the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include well-known knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the following claims.

[0151] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. A method for confirming device risks, characterized in that, The method includes: Obtaining a configuration file containing risk control rules; Obtaining the network registration information of the embedded SIM card set on the device; Determining whether there is a risk for the device according to the risk control rules and the network registration information; If it is determined that the device has a risk, performing a preset risk control operation.

2. The method according to claim 1, wherein The obtaining of the network registration information of the embedded SIM card set on the device includes: Obtaining the stored network registration location information and base station information in the embedded SIM card; Obtaining the device identifier corresponding to the embedded SIM card; Determining the location information, the device identifier, and the base station information as the network registration information.

3. The method according to claim 2, wherein The network registration location information and base station information include the location information and base station information corresponding to the embedded SIM card during at least one historical network registration process.

4. The method according to claim 1, wherein The determining whether there is a risk for the device according to the risk control rules and the network registration information includes: Determining a target abnormal event related to the risk control rules according to the network registration information; Determining a target risk value according to the target abnormal event and the risk control rules; When the target risk value reaches a preset risk threshold, determining that the device has a risk.

5. The method according to claim 4, wherein The target abnormal event includes at least one of registering network at an abnormal location, registering network at an abnormal base station, registering network during an abnormal time period, and belonging to an abnormal device.

6. The method according to claim 4, wherein The determining of the target risk value according to the target abnormal event and the risk control rules includes: For each target abnormal event, determining the risk value corresponding to the target abnormal event according to the risk value determination method corresponding to the target abnormal event in the risk control rules; Determining the target risk value according to the risk values corresponding to at least one target abnormal event.

7. The method according to claim 6, wherein The determining of the target risk value according to the risk values corresponding to at least one target abnormal event includes: Obtaining the weight corresponding to each target abnormal event; Weightedly determining the target risk value according to the risk value corresponding to the target abnormal event and the weight corresponding to the target abnormal event.

8. The method according to claim 1, characterized in that The performing of the preset risk control operation includes at least one of the following: Generating a risk prompt message and sending it to a target platform; Generating an alarm message and outputting it through the device; Forbidding the device to register network.

9. An apparatus for confirming device risks, characterized in that, The device includes: A first obtaining module configured to obtain a configuration file containing risk control rules; A second obtaining module configured to obtain the network registration information of the embedded SIM card set on the device; A determining module configured to determine whether there is a risk for the device according to the risk control rules and the network registration information; An execution module configured to perform a preset risk control operation if it is determined that the device has a risk.

10. An apparatus for confirming equipment risks, characterized in that, Includes: A processor; A memory for storing instructions executable by the processor; Wherein, the processor is configured to execute the device risk confirmation method according to any one of claims 1-8.

11. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the program instructions are executed by the processor, the steps of the method according to any one of claims 1-8 are implemented.