Case clue acquisition method and system based on intelligent terminal forensics data
By synchronizing and denoising the evidence data collected from smart terminals, standardized feature sets and tamper-proof fingerprints are generated, solving the problem of verifying the consistency between identity and object association in smart terminal devices. This enables reliable integration of cross-terminal evidence and automated clue reasoning, improving the accuracy and efficiency of case analysis.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ANHUI GENCHUAN TECHNOLOGY CO LTD
- Filing Date
- 2025-10-16
- Publication Date
- 2026-05-19
AI Technical Summary
Existing methods and systems for obtaining case clues have problems such as unreliable verification of the consistency between identity and object association in smart terminal devices, lack of quantifiable analysis, difficulty in integrating evidence across terminals, and easy misjudgment in traditional pattern matching.
By performing time synchronization and noise reduction on multi-source evidence data, standardized feature sets and tamper-proof evidence fingerprints are generated. A dual-index storage structure is constructed to achieve cross-terminal evidence retrieval and integrity verification. Behavioral signature consistency representation is used to verify the association between identity and object. A case causal network is constructed for clue aggregation and reasoning.
It enables quantitative verification of identity and objects across terminals, reduces human judgment, improves the accuracy and efficiency of obtaining case clues, and supports automated reasoning and pattern recognition.
Smart Images

Figure CN121388252B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data analysis technology, and more specifically, to a method and system for obtaining case clues based on evidence data collected from smart terminals. Background Technology
[0002] Existing methods and systems for obtaining case leads mainly have the following problems:
[0003] With the widespread use of smart terminal devices in daily life and work, the behavioral data they generate during case investigations has become an important source of evidence. However, existing methods and systems for obtaining case clues still face several technical bottlenecks, mainly in the following aspects:
[0004] In existing technologies, behavioral data generated by smart terminal devices during case investigations is scattered, and there is a lack of systematic methods to verify the consistency of identity and object associations across different terminals. In particular, the lack of an effective consistency judgment mechanism across different time windows and different devices makes cross-device identity verification unreliable.
[0005] Existing methods typically rely on a single point in time or a single operation for behavioral judgment, making them susceptible to data collection errors, missing data, or low-frequency operations, leading to inaccurate or unreliable identity verification results. Furthermore, current technologies struggle to structure and store identity verification results and link them to tamper-proof fingerprints, hindering subsequent evidence integration and case reasoning. For behavioral data from different smart terminals, existing technologies cannot effectively quantify the consistency of behavior across terminals, resulting in significant subjective judgments and a lack of quantifiable and verifiable analytical evidence during identity verification and object binding.
[0006] Existing technologies typically analyze evidence only for a single device or event, making it difficult to achieve evidence integration and clue aggregation across terminals and events. Traditional case clue extraction relies on manual judgment or empirical rules, failing to quantify the strength of connections between nodes and struggling to dynamically update key clues when new evidence emerges, resulting in delayed clue aggregation. Traditional case pattern matching largely depends on rules or manual comparison, lacking quantitative analysis methods, making it prone to misjudgments or omissions, and unable to support automated reasoning and pattern recognition in complex cases.
[0007] In view of this, the present invention proposes a method for obtaining case clues based on evidence collection data from smart terminals to solve the above problems. Summary of the Invention
[0008] To overcome the aforementioned deficiencies of the prior art and to achieve the above objectives, the present invention provides the following technical solution: a method for obtaining case clues based on evidence collection data from intelligent terminals, comprising:
[0009] S1. Collect multi-source forensic data from smart terminal devices, perform time synchronization, noise reduction and format unification processing on the collected multi-source forensic data, extract behavioral feature vectors and map them to a unified feature space, and output a standardized feature set.
[0010] S2. Combine the standardized feature set with the corresponding time tag to generate an tamper-proof evidence fingerprint, construct a dual-index storage structure based on time and geographic dimensions, and perform cross-terminal evidence retrieval, integrity verification, and traceability.
[0011] S3. Based on the standardized feature set and tamper-proof fingerprint, the identity and object association across terminals are verified through behavioral signature consistency representation; a sub-threshold cumulative triggering mechanism is adopted to cumulatively evaluate the behavioral characteristics of the smart terminal within a preset time window and output the identity-object consistency assertion.
[0012] S4. Based on the identity and object consistency assertion, construct the case causal network; through the evidence energy transfer mechanism, strengthen and aggregate the correlation clues between case nodes, and match them with the preset case type template library to generate key case clues and case pattern reasoning conclusions.
[0013] Specifically, the multi-source forensic data includes communication data, location trajectory data, network access data, application behavior data, multimedia data, file operation data, and account payment data.
[0014] Specifically, the method for outputting the standardized feature set includes:
[0015] Different types of data in multi-source forensics data are compared according to the collection timestamp, and linear interpolation is used to time-align data with missing time points or different sampling frequencies; at the same time, the local time deviation of the device is corrected based on the network time protocol time to unify the time baseline of multi-source forensics data.
[0016] The Kalman filter algorithm is used to denoise the multi-source forensic data, and the data from different sources in the multi-source forensic data are organized according to a unified data field structure. A multi-dimensional event description table is constructed with time, location, device identification, behavior type, operation object and content summary as core fields.
[0017] Statistical and pattern analysis is performed on the multidimensional event description table to extract behavioral feature vectors. Standard deviation normalization is then performed to generate behavioral feature vectors with uniform dimensions. A feature space mapping function is used to embed each behavioral feature vector into a unified feature space, and a standardized feature set that satisfies temporal and spatial consistency is output.
[0018] Specifically, the method for generating tamper-proof forensic fingerprints includes:
[0019] The standardized feature set is deterministically serialized according to a predetermined field order, including device identifier, time window, and behavioral feature vector; a secure hash value is calculated on the serialized standardized feature set to generate a single-record fingerprint;
[0020] For single-record fingerprints, construct hash trees in batches and record the root hash value. Apply for a timestamp from a trusted timestamp service for the hash tree root. Use a private key to digitally sign the hash tree root and timestamp information, and store the digital signature and the corresponding public key identifier together to generate a tamper-proof forensic fingerprint.
[0021] Specifically, the method for retrieving, verifying the integrity of, and tracing evidence across terminals includes:
[0022] The generated tamper-proof fingerprints and corresponding standardized feature sets are stored in layers according to time tags and geographic location information, and a dual-index storage structure is constructed with time dimension as the main index and geographic dimension as the secondary index.
[0023] The time index uses timestamps as keys and employs a B+ tree index structure for range retrieval. The geographic index uses latitude and longitude as keys and employs an R-tree index structure for spatial location and aggregation queries. A unique device identifier is assigned to each smart terminal, and the device identifier is used as an additional field in the index structure to realize the association mapping of the same event across different smart terminals.
[0024] When performing cross-terminal evidence retrieval, the dual indexes are jointly traversed based on the time interval, geographical range, and device identifier in the query conditions to locate the standardized feature set that meets the conditions and the corresponding tamper-proof evidence fingerprint.
[0025] In the retrieved tamper-proof forensic fingerprints, the hash tree root and the stored digital signature are verified, and the validity of the digital signature is verified using a public key. If the verification is successful, the standardized feature set is traced back according to the time index and geographical index path to achieve integrity verification and full-link traceability of cross-terminal forensic data.
[0026] Specifically, the method for verifying cross-terminal identity and object association through behavioral signature consistency representation includes:
[0027] The standardized feature sets of each smart terminal within a preset time window are aggregated and extracted to form a multi-dimensional behavior signature vector. The multi-dimensional behavior signature vector includes statistics on operation frequency, geographical location change range, application access mode, and file operation characteristics.
[0028] Based on multidimensional behavior signature vectors, a behavior consistency function is constructed to calculate the behavior consistency index of different terminals within a preset time window. When the behavior consistency index is greater than the preset behavior consistency index threshold, it is determined that the corresponding terminal has behavior consistency characteristics within the preset time window. When the determined behavior consistency characteristics match the time tag and geographic index information in the anti-tampering evidence fingerprint, the binding relationship between the smart terminal identity and the corresponding object is established.
[0029] Specifically, the method for outputting the identity object consistency assertion includes:
[0030] The arithmetic average of the behavior consistency index of each smart terminal with other smart terminals within a preset time window is obtained as the single behavior consistency signal of the smart terminal within the time window; the single behavior consistency signal is cumulatively calculated by introducing a time accumulation amount to obtain the cumulative behavior consistency amount.
[0031] A preset cumulative behavior consistency threshold is set. When the cumulative behavior consistency of a smart terminal within a preset time window is greater than or equal to the preset cumulative behavior consistency threshold, the behavior characteristics of the smart terminal are determined to meet the consistency requirements, triggering identity verification. The cumulative consistency judgment results of each smart terminal within the preset time window are recorded and organized to generate a structured identity and object consistency assertion.
[0032] Specifically, the method for constructing a case causal network includes:
[0033] The smart terminal device identifier, object identifier, time window, cumulative consistency quantity, judgment result, multi-dimensional behavioral signature vector and tamper-proof fingerprint recorded in the identity and object consistency assertion are used as nodes in the case causal network. The node types include identity nodes, object nodes and behavioral nodes.
[0034] Directed causal edges are constructed based on the temporal order between nodes and the cumulative consistency of behavior. The weights of the causal edges are calculated based on the cumulative consistency and time difference. Path search is performed on the set of directed edges in the case causal network to identify the causal chain composed of identity nodes, behavior nodes, and object nodes.
[0035] When different causal chains converge to the same identity or object node within the same time period, a behavioral aggregation relationship is determined, and a closed loop of causal reasoning for the case is generated. When a new identity or object consistency assertion is generated, the case causal network is dynamically updated. When the new identity or object consistency assertion matches the existing causal chain, the corresponding causal edge weights are updated. When the assertion involves a new smart terminal or object, the network node set is expanded to construct the case causal network.
[0036] Specifically, the method for generating key case clues and case pattern reasoning conclusions includes:
[0037] The accumulated behavioral consistency value is used as the initial node energy and allocated to each node in the case causal network; a node energy update function is defined for iterative updates to obtain the updated node energy; when the updated node energy is greater than or equal to the preset node energy threshold, the node is marked as a key case clue node;
[0038] All key case clue nodes are counted to form a key case clue node set, which is then matched with a preset case type template library. The matching score of each template is calculated using cosine similarity. When the matching score is greater than or equal to the preset matching score threshold, the case pattern reasoning conclusion matching the corresponding template is output.
[0039] A case clue acquisition system based on evidence collection data from smart terminals includes:
[0040] The evidence collection data acquisition module collects multi-source evidence data from smart terminal devices, performs time synchronization, noise reduction and format unification processing on the collected multi-source evidence data, extracts behavioral feature vectors and maps them to a unified feature space, and outputs a standardized feature set.
[0041] The trusted data storage module combines standardized feature sets with corresponding time tags to generate tamper-proof evidence fingerprints, constructs a dual-index storage structure based on time and geographic dimensions, and performs cross-terminal evidence retrieval, integrity verification, and traceability.
[0042] The object consistency verification module verifies the cross-terminal identity and object association based on a standardized feature set and tamper-proof fingerprint, and uses behavioral signature consistency representation. It adopts a sub-threshold cumulative triggering mechanism to cumulatively evaluate the behavioral characteristics of the smart terminal within a preset time window and outputs an identity-object consistency assertion.
[0043] The spatiotemporal causal clue reasoning module constructs a case causal network based on the identity and object consistency assertion; through the evidence energy transfer mechanism, it strengthens and aggregates the correlation clues between case nodes, and matches them with a preset case type template library to generate key case clues and case pattern reasoning conclusions.
[0044] Compared with the prior art, the present invention has the following beneficial effects:
[0045] This invention achieves quantitative verification of identity and objects across terminals by aggregating standardized feature sets from various smart terminals within a preset time window, extracting multi-dimensional behavioral signature vectors, and calculating a behavioral consistency index between terminals. A subthreshold cumulative triggering mechanism is introduced to accumulate single behavioral consistency signals over time, smoothing noise and accumulating low-frequency signals, ensuring reliable identity verification even under low-frequency or weak behavioral signal conditions. The accumulated consistency judgment results are recorded and organized to generate a structured assertion set containing device identifiers, object identifiers, time windows, accumulated consistency values, multi-dimensional behavioral signature vectors, and tamper-proof forensic fingerprints, facilitating subsequent case clue reasoning, evidence management, and tracing. By setting behavioral consistency functions and accumulated consistency values, the behavioral similarity between terminals can be quantitatively evaluated, providing verifiable mathematical evidence for case clue acquisition, reducing human judgment, and improving the accuracy of case reasoning.
[0046] By constructing a causal network for cases using identity and artifact consistency assertions, smart terminals, artifacts, and behavioral nodes are integrated to achieve unified analysis of multi-source heterogeneous evidence. The node energy update function combines accumulated behavioral consistency and causal edge weights to form an iterative evidence energy transfer mechanism, enabling quantification of clue strength and weighted consideration of historical evidence. As new identity and artifact consistency assertions are generated, network node energy is dynamically updated, and key case clue nodes are identified in real time, enhancing the timeliness of case analysis. From evidence collection to causal network construction, node energy calculation, key clue identification, and case pattern matching, the entire process can be automated, improving the efficiency of case clue acquisition. Attached Figure Description
[0047] Figure 1 This is a schematic diagram of the process for obtaining case clues based on evidence collection data from smart terminals according to the present invention;
[0048] Figure 2 This is a schematic diagram of the case clue acquisition system based on evidence collection data from a smart terminal according to the present invention. Detailed Implementation
[0049] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. Example
[0050] Please see Figure 1 As shown, this embodiment provides a method for obtaining case clues based on evidence collection data from smart terminals, specifically including the following steps:
[0051] S1. Collect multi-source forensic data from smart terminal devices, perform time synchronization, noise reduction and format unification processing on the collected multi-source forensic data, extract behavioral feature vectors and map them to a unified feature space, and output a standardized feature set.
[0052] S2. Combine the standardized feature set with the corresponding time tag to generate an tamper-proof evidence fingerprint, construct a dual-index storage structure based on time and geographic dimensions, and perform cross-terminal evidence retrieval, integrity verification, and traceability.
[0053] S3. Based on the standardized feature set and tamper-proof fingerprint, the identity and object association across terminals are verified through behavioral signature consistency representation; a sub-threshold cumulative triggering mechanism is adopted to cumulatively evaluate the behavioral characteristics of the smart terminal within a preset time window and output the identity-object consistency assertion.
[0054] S4. Based on the identity and object consistency assertion, construct the case causal network; through the evidence energy transfer mechanism, strengthen and aggregate the correlation clues between case nodes, and match them with the preset case type template library to generate key case clues and case pattern reasoning conclusions.
[0055] Multi-source forensic data includes communication data, location trajectory data, network access data, application behavior data, multimedia data, file operation data, and account payment data.
[0056] Communication data includes call logs, SMS logs, instant messaging logs, and email correspondence from smart terminal devices; location trajectory data includes GPS positioning coordinates, base station connection records, Wi-Fi access points, Bluetooth device connection logs, and application-generated geotag information; network access data includes webpage access history, network request logs, domain name resolution records, and IP address change records; application behavior data includes application launch records, operation events, and dwell time information; multimedia data includes metadata, shooting time, and device identification information for image, video, and audio files; file operation data includes file creation, modification, deletion, copying, and transmission records; and account payment data includes account login logs, electronic payment records, linked account information, and transaction time and amount.
[0057] Methods for outputting standardized feature sets include:
[0058] Different types of data in multi-source forensic data are compared according to the collection timestamp, and linear interpolation is used to time-align data with missing time points or different sampling frequencies; at the same time, the local time deviation of the device is corrected based on the Network Time Protocol (NTP) time to unify the time baseline of multi-source forensic data.
[0059] The Kalman filter algorithm is used to denoise the multi-source forensic data, and the data from different sources in the multi-source forensic data are organized according to a unified data field structure. A multi-dimensional event description table is constructed with time, location, device identification, behavior type, operation object and content summary as core fields.
[0060] Statistical and pattern analysis is performed on the multidimensional event description table to extract behavioral feature vectors, which include operation frequency, spatiotemporal distribution, interaction mode, and device habit parameters. Standard deviation normalization is then performed to generate behavioral feature vectors with uniform dimensions. A feature space mapping function is used to embed each behavioral feature vector into a unified feature space, outputting a standardized feature set that satisfies both temporal and spatial consistency.
[0061] Methods for generating tamper-proof forensic fingerprints include:
[0062] The standardized feature set is deterministically serialized according to a predetermined field order, including device identifier, time window, and behavioral feature vector; a secure hash value is calculated on the serialized standardized feature set to generate a single-record fingerprint;
[0063] For single-record fingerprints, construct hash trees in batches and record the root hash value. Apply for a timestamp from a trusted timestamp service for the hash tree root. Use a private key to digitally sign the hash tree root and timestamp information, and store the digital signature and the corresponding public key identifier together to generate a tamper-proof forensic fingerprint.
[0064] Methods for cross-terminal evidence retrieval, integrity verification, and traceability include:
[0065] The generated tamper-proof fingerprints and corresponding standardized feature sets are stored in layers according to time tags and geographic location information, and a dual-index storage structure is constructed with time dimension as the main index and geographic dimension as the secondary index.
[0066] The time index uses timestamps as keys and employs a B+ tree index structure for range retrieval. The geographic index uses latitude and longitude as keys and employs an R-tree index structure for spatial location and aggregation queries. A unique device identifier is assigned to each smart terminal, and the device identifier is used as an additional field in the index structure to realize the association mapping of the same event across different smart terminals.
[0067] When performing cross-terminal evidence retrieval, the dual indexes are jointly traversed based on the time interval, geographical range, and device identifier in the query conditions to locate the standardized feature set that meets the conditions and the corresponding tamper-proof evidence fingerprint.
[0068] In the retrieved tamper-proof forensic fingerprints, the hash tree root and the stored digital signature are verified, and the validity of the digital signature is verified using a public key. If the verification is successful, the standardized feature set is traced back according to the time index and geographical index path to achieve integrity verification and full-link traceability of cross-terminal forensic data.
[0069] Methods for verifying cross-terminal identity and object association through behavioral signature consistency representation include:
[0070] The standardized feature sets of each smart terminal within a preset time window are aggregated and extracted to form a multi-dimensional behavior signature vector. The multi-dimensional behavior signature vector includes statistics on operation frequency, geographical location change range, application access mode, and file operation characteristics.
[0071] Based on multidimensional behavior signature vectors, a behavior consistency function is constructed to calculate the behavior consistency index of different terminals within a preset time window. When the behavior consistency index is greater than the preset behavior consistency index threshold, it is determined that the corresponding terminal has behavior consistency characteristics within the preset time window. When the determined behavior consistency characteristics match the time tag and geographic index information in the anti-tampering evidence fingerprint, the binding relationship between the smart terminal identity and the corresponding object is established.
[0072] The behavioral consistency function is: ;in, Indicates smart terminal and Within the preset time window Internal behavioral consistency index; This represents the smoothing coefficient, used to control similarity sensitivity; Indicates smart terminal and The square of the Euclidean distance between the multidimensional behavioral signature vectors; Indicates the first Smart terminals within a preset time window The multidimensional behavioral signature vector within; Indicates the first Smart terminals within a preset time window The multidimensional behavioral signature vector within; and This represents the index of the smart terminal.
[0073] Methods for outputting identity-object consistency assertions include:
[0074] The arithmetic average of the behavior consistency index of each smart terminal with other smart terminals within a preset time window is obtained as the single behavior consistency signal of the smart terminal within the time window; the single behavior consistency signal is cumulatively calculated by introducing a time accumulation amount to obtain the cumulative behavior consistency amount.
[0075] The cumulative behavioral consistency measure is: ;in, Indicates smart terminal At the current time point The cumulative behavioral consistency quantity; This represents the cumulative decay coefficient, which controls the weight of historical cumulative behavior consistency in the current cumulative behavior consistency. Indicates smart terminal At the previous point in time The cumulative behavioral consistency quantity; Index representing a point in time;
[0076] A preset cumulative behavior consistency threshold is set. When the cumulative behavior consistency of a smart terminal within a preset time window is greater than or equal to the preset cumulative behavior consistency threshold, the behavior characteristics of the smart terminal are determined to meet the consistency requirements, triggering identity verification. The cumulative consistency judgment results of each smart terminal within the preset time window are recorded and organized to generate a structured identity and object consistency assertion.
[0077] The identity-object consistency assertion includes the smart terminal device identifier, object identifier, time window, cumulative consistency quantity, judgment result, multi-dimensional behavioral signature vector, and tamper-proof forensic fingerprint. It should be noted that "object" here refers to an external physical object that can be perceived, operated, controlled, or interacted with by the smart terminal device (such as a door lock, vehicle, camera, USB flash drive, etc.); "identity" corresponds to a person or account.
[0078] Methods for constructing causal networks in cases include:
[0079] The smart terminal device identifier, object identifier, time window, cumulative consistency quantity, judgment result, multi-dimensional behavioral signature vector and tamper-proof fingerprint recorded in the identity and object consistency assertion are used as nodes in the case causal network. The node types include identity nodes, object nodes and behavioral nodes.
[0080] Directed causal edges are constructed based on the temporal order between nodes and the cumulative consistency of behavior. The weights of the causal edges are calculated based on the cumulative consistency and time difference. Path search is performed on the set of directed edges in the case causal network to identify the causal chain composed of identity nodes, behavior nodes, and object nodes.
[0081] When different causal chains converge to the same identity or object node within the same time period, a behavioral aggregation relationship is determined, and a closed loop of causal reasoning for the case is generated. When a new identity or object consistency assertion is generated, the case causal network is dynamically updated. When the new identity or object consistency assertion matches the existing causal chain, the corresponding causal edge weights are updated. When the assertion involves a new smart terminal or object, the network node set is expanded to construct the case causal network.
[0082] Methods for generating key case clues and case pattern reasoning conclusions include:
[0083] The accumulated behavioral consistency value is used as the initial node energy and allocated to each node in the case causal network; a node energy update function is defined for iterative updates to obtain the updated node energy; when the updated node energy is greater than or equal to the preset node energy threshold, the node is marked as a key case clue node;
[0084] The node energy update function is: ;in, Indicates the first Each node at a given time point Node energy; Indicates the first Each node at a given time point Node energy; This represents the energy decay coefficient, which controls the weight of the influence of historical node capabilities on the current node's energy. Represents a node To node Causal edge weights; Indicates the first Each node at a given time point Node energy; and Indicates the sequence number of the node in the causal network of the case;
[0085] All key case clue nodes are counted to form a key case clue node set, which is then matched with a preset case type template library. The matching score of each template is calculated using cosine similarity. When the matching score is greater than or equal to the preset matching score threshold, the case pattern reasoning conclusion matching the corresponding template is output.
[0086] The preset behavioral consistency index threshold is set by staff based on historical data analysis results. This historical analysis process includes the system collecting multiple behavioral consistency indices and calculating their average value as a reference to obtain the preset behavioral consistency index threshold. Similarly, the preset cumulative behavioral consistency threshold, preset node energy threshold, and preset matching score threshold are also set and adjusted by staff according to the specific application scenario requirements.
[0087] This embodiment aggregates standardized feature sets from various smart terminals within a preset time window, extracts multi-dimensional behavioral signature vectors, and calculates a behavioral consistency index between terminals to achieve quantitative verification of identity and objects across terminals. A subthreshold cumulative triggering mechanism is introduced to accumulate single behavioral consistency signals over time, smoothing noise and accumulating low-frequency signals, ensuring reliable identity verification even under low-frequency or weak behavioral signal conditions. The accumulated consistency judgment results are recorded and organized to generate a structured assertion set containing device identifiers, object identifiers, time windows, accumulated consistency quantities, multi-dimensional behavioral signature vectors, and tamper-proof forensic fingerprints, facilitating subsequent case clue reasoning, evidence management, and tracing. By setting behavioral consistency functions and accumulated consistency quantities, the behavioral similarity between terminals can be quantitatively evaluated, providing verifiable mathematical evidence for case clue acquisition, reducing human judgment, and improving the accuracy of case reasoning.
[0088] By constructing a causal network for cases using identity and artifact consistency assertions, smart terminals, artifacts, and behavioral nodes are integrated to achieve unified analysis of multi-source heterogeneous evidence. The node energy update function combines accumulated behavioral consistency and causal edge weights to form an iterative evidence energy transfer mechanism, enabling quantification of clue strength and weighted consideration of historical evidence. As new identity and artifact consistency assertions are generated, network node energy is dynamically updated, and key case clue nodes are identified in real time, enhancing the timeliness of case analysis. From evidence collection to causal network construction, node energy calculation, key clue identification, and case pattern matching, the entire process can be automated, improving the efficiency of case clue acquisition. Example
[0089] Please see Figure 2 As shown, parts not described in detail in this embodiment are described in Embodiment 1. A case clue acquisition system based on evidence collection data from smart terminals is provided, including:
[0090] The evidence collection data acquisition module collects multi-source evidence data from smart terminal devices, performs time synchronization, noise reduction and format unification processing on the collected multi-source evidence data, extracts behavioral feature vectors and maps them to a unified feature space, and outputs a standardized feature set.
[0091] The trusted data storage module combines standardized feature sets with corresponding time tags to generate tamper-proof evidence fingerprints, constructs a dual-index storage structure based on time and geographic dimensions, and performs cross-terminal evidence retrieval, integrity verification, and traceability.
[0092] The object consistency verification module verifies the cross-terminal identity and object association based on a standardized feature set and tamper-proof fingerprint, and uses behavioral signature consistency representation. It adopts a sub-threshold cumulative triggering mechanism to cumulatively evaluate the behavioral characteristics of the smart terminal within a preset time window and outputs an identity-object consistency assertion.
[0093] The spatiotemporal causal clue reasoning module constructs a case causal network based on the identity and object consistency assertion; through the evidence energy transfer mechanism, it strengthens and aggregates the correlation clues between case nodes, and matches them with a preset case type template library to generate key case clues and case pattern reasoning conclusions.
[0094] Since the electronic device described in this embodiment is the electronic device used to implement the case clue acquisition method and system based on smart terminal evidence collection data in the embodiments of this application, those skilled in the art can understand the specific implementation method and various variations of the electronic device in this embodiment based on the case clue acquisition method and system based on smart terminal evidence collection data described in the embodiments of this application. Therefore, how the electronic device implements the method in the embodiments of this application will not be described in detail here. As long as those skilled in the art implement the electronic device used in the case clue acquisition method and system based on smart terminal evidence collection data in the embodiments of this application, it falls within the scope of protection of this application. The above formulas are all dimensionless numerical calculations. The formulas are obtained by software simulation based on a large amount of collected data to get the most recent real situation. The preset parameters and threshold selections in the formulas are set by those skilled in the art according to the actual situation.
[0095] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should also be considered within the scope of protection of the present invention.
Claims
1. A method for obtaining case clues based on evidence collection data from smart terminals, characterized in that, include: S1. Collect multi-source forensic data from smart terminal devices, perform time synchronization, noise reduction and format unification processing on the collected multi-source forensic data, extract behavioral feature vectors and map them to a unified feature space, and output a standardized feature set. S2. Combine the standardized feature set with the corresponding time tag to generate an tamper-proof evidence fingerprint, construct a dual-index storage structure based on time and geographic dimensions, and perform cross-terminal evidence retrieval, integrity verification, and traceability. S3. Based on the standardized feature set and tamper-proof fingerprint, the identity and object association across terminals are verified through behavioral signature consistency representation; a sub-threshold cumulative triggering mechanism is adopted to cumulatively evaluate the behavioral characteristics of the smart terminal within a preset time window and output the identity-object consistency assertion. The method for verifying cross-terminal identity and object association through behavioral signature consistency representation includes: The standardized feature sets of each smart terminal within a preset time window are aggregated and extracted to form a multi-dimensional behavior signature vector. The multi-dimensional behavior signature vector includes statistics on operation frequency, geographical location change range, application access mode, and file operation characteristics. Based on multidimensional behavioral signature vectors, a behavioral consistency function is constructed to calculate the behavioral consistency index of different terminals within a preset time window. When the behavioral consistency index is greater than the preset behavioral consistency index threshold, it is determined that the corresponding terminal has behavioral consistency characteristics within the preset time window. When the determined behavioral consistency characteristics match the time tag and geographic index information in the anti-tampering evidence fingerprint, the binding relationship between the smart terminal identity and the corresponding object is established. The method for outputting the identity object consistency assertion includes: The arithmetic average of the behavior consistency index of each smart terminal with other smart terminals within a preset time window is obtained as the single behavior consistency signal of the smart terminal within the time window; the single behavior consistency signal is cumulatively calculated by introducing a time accumulation amount to obtain the cumulative behavior consistency amount. A preset cumulative behavior consistency threshold is set. When the cumulative behavior consistency of a smart terminal within a preset time window is greater than or equal to the preset cumulative behavior consistency threshold, the behavior characteristics of the smart terminal are determined to meet the consistency requirements, triggering identity verification. The cumulative consistency judgment results of each smart terminal within the preset time window are recorded and organized to generate a structured identity and object consistency assertion. S4. Based on the identity and object consistency assertion, construct the case causal network; through the evidence energy transfer mechanism, strengthen and aggregate the correlation clues between case nodes, and match them with the preset case type template library to generate key case clues and case pattern reasoning conclusions. The evidence energy transfer mechanism involves allocating the accumulated behavioral consistency value as the initial node energy to each node in the case causal network; defining a node energy update function for iterative updates to obtain the updated node energy; and marking the node as a key case clue node when the updated node energy is greater than or equal to a preset node energy threshold.
2. The method for obtaining case clues based on evidence collection data from intelligent terminals according to claim 1, characterized in that, The multi-source forensic data includes communication data, location trajectory data, network access data, application behavior data, multimedia data, file operation data, and account payment data.
3. The method for obtaining case clues based on evidence collection data from intelligent terminals according to claim 2, characterized in that, The method for outputting the standardized feature set includes: Different types of data in multi-source forensics data are compared according to the collection timestamp, and linear interpolation is used to time-align data with missing time points or different sampling frequencies; at the same time, the local time deviation of the device is corrected based on the network time protocol time to unify the time baseline of multi-source forensics data. The Kalman filter algorithm is used to denoise the multi-source forensic data, and the data from different sources in the multi-source forensic data are organized according to a unified data field structure. A multi-dimensional event description table is constructed with time, location, device identification, behavior type, operation object and content summary as core fields. Statistical and pattern analysis is performed on the multidimensional event description table to extract behavioral feature vectors. Standard deviation normalization is then performed to generate behavioral feature vectors with uniform dimensions. A feature space mapping function is used to embed each behavioral feature vector into a unified feature space, and a standardized feature set that satisfies temporal and spatial consistency is output.
4. The method for obtaining case clues based on evidence collection data from intelligent terminals according to claim 3, characterized in that, The method for generating tamper-proof forensic fingerprints includes: The standardized feature set is deterministically serialized according to a predetermined field order, including device identifier, time window, and behavioral feature vector; a secure hash value is calculated on the serialized standardized feature set to generate a single-record fingerprint; For single-record fingerprints, construct hash trees in batches and record the root hash value. Apply for a timestamp from a trusted timestamp service for the hash tree root. Use a private key to digitally sign the hash tree root and timestamp information, and store the digital signature and the corresponding public key identifier together to generate a tamper-proof forensic fingerprint.
5. The method for obtaining case clues based on evidence collection data from intelligent terminals according to claim 4, characterized in that, The methods for retrieving, verifying the integrity of, and tracing evidence across terminals include: The generated tamper-proof fingerprints and corresponding standardized feature sets are stored in layers according to time tags and geographic location information, and a dual-index storage structure is constructed with time dimension as the main index and geographic dimension as the secondary index. The time index uses timestamps as keys and employs a B+ tree index structure for range retrieval. The geographic index uses latitude and longitude as keys and employs an R-tree index structure for spatial location and aggregation queries. A unique device identifier is assigned to each smart terminal, and the device identifier is used as an additional field in the index structure to realize the association mapping of the same event across different smart terminals. When performing cross-terminal evidence retrieval, the dual indexes are jointly traversed based on the time interval, geographical range, and device identifier in the query conditions to locate the standardized feature set that meets the conditions and the corresponding tamper-proof evidence fingerprint. In the retrieved tamper-proof forensic fingerprints, the hash tree root and the stored digital signature are verified, and the validity of the digital signature is verified using a public key. If the verification is successful, the standardized feature set is traced back according to the time index and geographical index path to achieve integrity verification and full-link traceability of cross-terminal forensic data.
6. The method for obtaining case clues based on evidence collection data from intelligent terminals according to claim 5, characterized in that, The method for constructing a causal network of cases includes: The smart terminal device identifier, object identifier, time window, cumulative behavioral consistency quantity, judgment result, multi-dimensional behavioral signature vector and tamper-proof fingerprint recorded in the identity and object consistency assertion are used as nodes in the case causal network. The node types include identity nodes, object nodes and behavioral nodes. Directed causal edges are constructed based on the temporal order between nodes and the cumulative consistency of behavior. The weights of the causal edges are calculated based on the cumulative consistency of behavior and the time difference. Path search is performed on the set of directed edges in the case causal network to identify the causal chain composed of identity nodes, behavior nodes and object nodes. When different causal chains converge to the same identity or object node within the same time period, a behavioral aggregation relationship is determined, and a closed loop of causal reasoning for the case is generated. When a new identity or object consistency assertion is generated, the case causal network is dynamically updated. When the new identity or object consistency assertion matches the existing causal chain, the corresponding causal edge weights are updated. When the assertion involves a new smart terminal or object, the network node set is expanded to construct the case causal network.
7. The method for obtaining case clues based on evidence collection data from intelligent terminals according to claim 6, characterized in that, The methods for generating key case clues and case pattern reasoning conclusions include: All key case clue nodes are counted to form a key case clue node set, which is then matched with a preset case type template library. The matching score of each template is calculated using cosine similarity. When the matching score is greater than or equal to the preset matching score threshold, the case pattern reasoning conclusion matching the corresponding template is output.
8. A case clue acquisition system based on evidence collection data from intelligent terminals, used to implement the case clue acquisition method based on evidence collection data from intelligent terminals as described in any one of claims 1 to 7, characterized in that, include: The evidence collection data acquisition module collects multi-source evidence data from smart terminal devices, performs time synchronization, noise reduction and format unification processing on the collected multi-source evidence data, extracts behavioral feature vectors and maps them to a unified feature space, and outputs a standardized feature set. The trusted data storage module combines standardized feature sets with corresponding time tags to generate tamper-proof evidence fingerprints, constructs a dual-index storage structure based on time and geographic dimensions, and performs cross-terminal evidence retrieval, integrity verification, and traceability. The object consistency verification module verifies the cross-terminal identity and object association based on a standardized feature set and tamper-proof fingerprint, and uses behavioral signature consistency representation. It adopts a sub-threshold cumulative triggering mechanism to cumulatively evaluate the behavioral characteristics of the smart terminal within a preset time window and outputs an identity-object consistency assertion. The method for verifying cross-terminal identity and object association through behavioral signature consistency representation includes: The standardized feature sets of each smart terminal within a preset time window are aggregated and extracted to form a multi-dimensional behavior signature vector. The multi-dimensional behavior signature vector includes statistics on operation frequency, geographical location change range, application access mode, and file operation characteristics. Based on multidimensional behavioral signature vectors, a behavioral consistency function is constructed to calculate the behavioral consistency index of different terminals within a preset time window. When the behavioral consistency index is greater than the preset behavioral consistency index threshold, it is determined that the corresponding terminal has behavioral consistency characteristics within the preset time window. When the determined behavioral consistency characteristics match the time tag and geographic index information in the anti-tampering evidence fingerprint, the binding relationship between the smart terminal identity and the corresponding object is established. The method for outputting the identity object consistency assertion includes: The arithmetic average of the behavior consistency index of each smart terminal with other smart terminals within a preset time window is obtained as the single behavior consistency signal of the smart terminal within the time window; the single behavior consistency signal is cumulatively calculated by introducing a time accumulation amount to obtain the cumulative behavior consistency amount. A preset cumulative behavior consistency threshold is set. When the cumulative behavior consistency of a smart terminal within a preset time window is greater than or equal to the preset cumulative behavior consistency threshold, the behavior characteristics of the smart terminal are determined to meet the consistency requirements, triggering identity verification. The cumulative consistency judgment results of each smart terminal within the preset time window are recorded and organized to generate a structured identity and object consistency assertion. The spatiotemporal causal clue reasoning module constructs a case causal network based on the identity and object consistency assertion; through the evidence energy transfer mechanism, it strengthens and aggregates the correlation clues between case nodes, and matches them with a preset case type template library to generate key case clues and case pattern reasoning conclusions. The evidence energy transfer mechanism involves allocating the accumulated behavioral consistency value as the initial node energy to each node in the case causal network; defining a node energy update function for iterative updates to obtain the updated node energy; and marking the node as a key case clue node when the updated node energy is greater than or equal to a preset node energy threshold.