Risk determination method, apparatus, electronic device, and medium

By acquiring application information and identifying risk information in a trusted execution environment, the problem of inaccurate risk information and privacy leakage in existing technologies is solved, achieving more accurate and secure risk control.

CN122133137APending Publication Date: 2026-06-02BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING XIAOMI MOBILE SOFTWARE CO LTD
Filing Date
2024-12-02
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

In existing technologies, applications can only determine risk information by combining information that can be shared by electronic devices when conducting risk prevention and control, which leads to inaccurate risk information and the risk of privacy leakage.

Method used

By acquiring application information from the application and combining it with the state information of the electronic device, risk information is identified in a trusted execution environment and sent to the application without sharing the state information in the device. Measures such as certificate signing and format checking are used to ensure information security.

Benefits of technology

It improves the accuracy and security of risk information, avoids the leakage of privacy information, and enhances the reliability and real-time nature of risk prevention and control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122133137A_ABST
    Figure CN122133137A_ABST
Patent Text Reader

Abstract

This disclosure relates to a risk determination method, apparatus, electronic device, and medium. The risk determination method includes: acquiring application information from an application; determining risk information of the electronic device based on the application information; and sending the risk information to the application. Since the application does not need to determine the risk information and there is no need to share information, more information from the electronic device can be combined when determining the risk information, thereby improving the accuracy of the risk information. Simultaneously, since only the risk information needs to be sent to the application, and there is no need to send information from the electronic device to the application to avoid privacy information leakage, the security of risk determination is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of information security technology, and in particular to a risk determination method, apparatus, electronic device, and medium. Background Technology

[0002] After a user performs a sensitive operation within an application, the application needs to implement risk control measures to prevent attacks on the electronic device. However, during the risk control process, the application can only determine risk information based on information that can be shared by the electronic device, leading to inaccurate risk information. Summary of the Invention

[0003] To overcome the problems existing in related technologies, this disclosure provides a risk determination method, apparatus, electronic device, and medium.

[0004] According to a first aspect of the present disclosure, a risk determination method is provided, the risk determination method comprising:

[0005] Get application information about the application;

[0006] Based on the application information, determine the risk information of the electronic device;

[0007] The risk information is sent to the application.

[0008] In some embodiments of this disclosure, determining the risk information of the electronic device based on the application information includes:

[0009] Based on the application information, the status information of the electronic device is collected;

[0010] The risk information is determined based on the status information.

[0011] In some embodiments of this disclosure, the application information includes an application identifier and an application scenario; the step of collecting the status information of the electronic device based on the application information includes:

[0012] Based on the application identifier, the application scenario, and the preset relationship, determine the corresponding list of status information;

[0013] Collect the status information from the status information list;

[0014] The preset relationship is used to characterize the correspondence between preset application identifiers and preset application scenarios and preset status information lists.

[0015] In some embodiments of this disclosure, the number of status information items is multiple; determining the risk information based on the status information includes:

[0016] Determine the relationship between each state information and its corresponding risk condition;

[0017] When any of the aforementioned status information satisfies the risk condition, the risk level in the risk information is increased.

[0018] In some embodiments of this disclosure, the risk information includes risk levels under multiple risk categories; before determining the relationship between each piece of status information and the corresponding risk condition, determining the risk information based on the status information further includes:

[0019] Each of the aforementioned status information is assigned to its corresponding risk category;

[0020] The step of raising the risk level in the risk information includes:

[0021] The risk level of the status information that meets the risk conditions under the risk category will be increased.

[0022] In some embodiments of this disclosure, the application information includes application scenarios; before determining the relationship between each state information and the corresponding risk condition, determining the risk information based on the state information further includes:

[0023] Based on the application scenario, determine the risk calculation method;

[0024] The step of raising the risk level in the risk information includes:

[0025] Based on the risk calculation method, the risk level is increased.

[0026] In some embodiments of this disclosure, after determining the risk information of the electronic device based on the application information, the risk determination method further includes:

[0027] Check the format of the risk information;

[0028] Sending the risk information to the application includes:

[0029] If the format of the risk information meets the format requirements, the risk information will be sent to the application.

[0030] In some embodiments of this disclosure, after determining the risk information of the electronic device based on the application information, the risk determination method further includes:

[0031] The risk information is signed with a certificate using the private key of the electronic device to obtain the risk information carrying a public key certificate;

[0032] Sending the risk information to the application includes:

[0033] The risk information carrying the public key certificate is sent to the application.

[0034] In some embodiments of this disclosure, the application information includes verification information; before the risk information is certificate-signed using the private key of the electronic device to obtain the risk information carrying a public key certificate, the risk determination method further includes:

[0035] The risk information is combined with the verification information to obtain combined information;

[0036] The step of signing the risk information with the private key of the electronic device to obtain the risk information carrying the public key certificate includes:

[0037] The combined information is signed with the private key to obtain the combined information carrying the public key certificate;

[0038] Sending the risk information carrying the public key certificate to the application includes:

[0039] The combined information carrying the public key certificate is sent to the application.

[0040] In some embodiments of this disclosure, the risk determination method further includes:

[0041] Upon receiving an update instruction, obtain the update information corresponding to the update instruction;

[0042] Based on the updated information, the preset application scenario, the preset status information list, and / or the preset risk calculation method are updated, and the preset application scenario, the preset status information list, and the preset risk calculation method are used to determine the risk information.

[0043] In some embodiments of this disclosure, the application runs in a rich execution environment, and the risk information is determined in a trusted execution environment.

[0044] According to a second aspect of the present disclosure, a risk determination apparatus is provided, the risk determination apparatus comprising:

[0045] An acquisition module, configured to acquire application information of the application;

[0046] A determination module, configured to determine risk information of an electronic device based on the application information;

[0047] A sending module, configured to send the risk information to the application.

[0048] According to a third aspect of the present disclosure, an electronic device is provided, the electronic device comprising:

[0049] processor;

[0050] Memory used to store the processor's executable instructions;

[0051] The processor is configured to execute the risk determination method described above.

[0052] According to a fourth aspect of the present disclosure, a non-transitory computer-readable storage medium is provided, wherein when instructions in the storage medium are executed by a processor of a terminal, the terminal is enabled to perform the risk determination method as described above.

[0053] The technical solutions provided by the embodiments of this disclosure may include the following beneficial effects:

[0054] Because different applications associate different information with different electronic devices during risk control, application information is obtained. Based on this application information, risk information of the electronic device is determined to reflect its security status. This risk information is then sent to the application, enabling it to perform risk control based on this information. Since the application does not need to determine risk information and there is no need to share information, more information from the electronic device can be combined when determining risk information, thus improving the accuracy of risk information. Simultaneously, because only risk information needs to be sent to the application, and not information from the electronic device itself, to avoid privacy leaks, the security of risk determination is improved.

[0055] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0056] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0057] Figure 1 This is a schematic diagram of a risk assessment process;

[0058] Figure 2 This is a schematic diagram illustrating a risk determination scenario according to an exemplary embodiment;

[0059] Figure 3 This is a schematic diagram illustrating a risk determination framework according to an exemplary embodiment;

[0060] Figure 4This is a flowchart illustrating a risk determination method according to an exemplary embodiment;

[0061] Figure 5-1 This is a schematic diagram illustrating a secure open service invocation process according to an exemplary embodiment;

[0062] Figure 5-2 This is a schematic diagram illustrating the passive invocation of a secure open service according to an exemplary embodiment;

[0063] Figure 5-3 This is a schematic diagram illustrating an active invocation of a secure open service according to an exemplary embodiment;

[0064] Figure 6 This is a schematic diagram illustrating a state information acquisition process according to an exemplary embodiment;

[0065] Figure 7 This is a schematic diagram illustrating a risk information determination process according to an exemplary embodiment;

[0066] Figure 8 This is a schematic diagram illustrating a combined information certificate signing process according to an exemplary embodiment;

[0067] Figure 9 This is a schematic diagram illustrating an information update process according to an exemplary embodiment;

[0068] Figure 10 This is a flowchart illustrating a risk determination method according to another exemplary embodiment;

[0069] Figure 11 This is a block diagram illustrating a risk determination apparatus according to an exemplary embodiment;

[0070] Figure 12 This is a block diagram of an electronic device according to an exemplary embodiment.

[0071] In the picture:

[0072] 100 - Acquisition module; 200 - Determination module; 300 - Transmission module; 400 - Electronic device; 402 - Processing component; 404 - Memory; 406 - Power supply component; 408 - Multimedia component; 410 - Audio component; 412 - Input / output interface; 414 - Sensor component; 416 - Communication component; 420 - Processor. Detailed Implementation

[0073] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims. It should also be understood that the term “and / or” as used in this disclosure refers to and includes any or all possible combinations of one or more of the associated listed items. Wherein, A, B, and / or C represent one or more of A, B, and C.

[0074] With the development of electronic devices, the number of applications has gradually increased to meet diverse user needs. In certain application scenarios, such as payment, fraud, and gaming, users may perform sensitive operations within these applications. To prevent attacks on electronic devices, applications need to implement risk control measures in these specific scenarios to intercept high-risk sensitive operations. During risk control, it is necessary to determine the risk information of the electronic device to assess its security status.

[0075] In related technologies, a risk determination method is provided, such as Figure 1 As shown, the risk determination method includes: upon receiving a call instruction from an application, the secure open service collects the electronic device's status information. The secure open service then sends the status information to the application. When performing risk assessment, the application determines the risk information based on the status information. In this method, the application can determine risk information based on the status information for risk prevention and control. However, because the status information needs to be sent to the application, to avoid the leakage of user privacy information, the status information is only shareable information. Due to the limited amount of status information, it cannot comprehensively reflect the security status of the electronic device, resulting in inaccurate risk information.

[0076] To address the aforementioned technical issues, this disclosure provides a risk determination method. After determining risk information, the risk information is sent to an application program, enabling the application to perform risk prevention and control based on the risk information. Since the application program does not need to determine risk information and there is no need to share information, more non-shared information can be incorporated during the risk information determination process to comprehensively reflect the security status of the electronic device, thereby improving the accuracy of the risk information.

[0077] To facilitate understanding, the risk assessment scenario of this disclosure will be described first. For example... Figure 2As shown, after a user opens an application on their electronic device and performs a sensitive operation (such as a payment), the application calls a security open service to determine risk information and receives the risk information sent by the security open service. Based on the risk information, the application performs risk control measures (e.g., prohibiting payment operations if the electronic device is at high risk). The determination of risk information may rely on the following: the state of being redirected to this application by a malicious application, the state of being redirected to this application by a malicious SMS message, the network security status of the network connection to the electronic device, recent phone call status, simulated click status, and the state of having superuser privileges acquired, etc. Figure 3 As shown, during the risk information determination process, the application calls the Secure Open Service interface. The Secure Open Service collects the electronic device's status information, determines the risk information, and performs certificate signing. The Secure Open Service then sends the certificate-signed risk information to the application through the Secure Open Service interface. The application runs in a Rich Execution Environment (REE), while the Secure Open Service runs in a Trusted Execution Environment (TEE).

[0078] This disclosure provides a risk determination method, such as... Figure 4 As shown, the method includes:

[0079] S100: Obtain application information for the application.

[0080] S200. Based on the application information, determine the risk information of the electronic device.

[0081] S300: Send risk information to the application.

[0082] In this embodiment, since different applications associate different information with electronic devices during risk prevention, application information is obtained. Based on the application information, risk information of the electronic device is determined to reflect its security status. This risk information is then sent to the application, enabling it to perform risk prevention based on this information. Because the application does not need to determine risk information and therefore does not need to share information, more information from the electronic device can be combined when determining risk information, thus improving the accuracy of the risk information. Simultaneously, since only the risk information needs to be sent to the application, and not the information from the electronic device itself, to avoid privacy leaks, the security of risk determination is improved.

[0083] In one embodiment, the application runs in a rich execution environment, while risk information is determined in a trusted execution environment.

[0084] In this embodiment, by sending the risk information determined in the trusted execution environment to the application running in the rich execution environment, the leakage of privacy information can be avoided and the risk information is not easily changed, thereby improving the security of risk determination.

[0085] For example, such as Figure 5-1 As shown, after a user performs a sensitive operation in the application, the application invokes the Security Open Service. The Security Open Service obtains application information from the application through its interface. After determining the risk information, the Security Open Service sends it to the application. This application information includes, but is not limited to, application identifier, application scenario, and verification information. The application identifier and application scenario are used to determine the list of status information and the risk calculation method. The verification information is used to prevent replay attacks. The Security Open Service can be invoked via inter-process communication or other methods; this is not limited to these methods.

[0086] When invoking secure and open services, both passive and active invocation methods can be used. For example... Figure 5-2 As shown, when an application needs to perform risk control, it sends a call instruction to the security open service to obtain risk information. The security open service determines the risk information of the electronic device and sends it to the application. This passive calling method has strong real-time performance; the risk information returned with each call reflects the current security status of the electronic device, and it needs to be sent to the application regardless of the risk information. The application needs to make a risk judgment based on the risk information each time. This calling method is mainly used in application scenarios where risk information needs to be obtained immediately. That is, obtaining the application information of the application in step S100 can be determined as follows: upon receiving the call instruction sent by the application, obtain the application information related to the call instruction in the application. Figure 5-3 As shown, regardless of whether the application needs risk control, the secure open service proactively calls the application through a registration callback to determine the risk information of the electronic device at timed intervals or in a specific application scenario. If a risk exists, the application is proactively notified, enabling it to perform risk control based on the risk information. This calling method can continuously monitor changes in the risk information of the electronic device, and the electronic device is at a higher risk when the risk information is sent. However, due to limitations of time intervals or specific scenarios, risk information cannot be determined in real time; the impact of the risk can only be reduced by increasing the monitoring frequency. This calling method is mainly used in scenarios where risk information needs to be monitored constantly. That is, obtaining the application information of the application in step S100 can also be determined in the following way: obtaining the application information of the application every preset time interval.

[0087] In one embodiment, the risk information of the electronic device in step S200, based on the application information, is determined in the following manner:

[0088] Based on application information, collect status information of electronic devices.

[0089] Based on the status information, determine the risk information.

[0090] In this embodiment, since the state information affecting the security status of electronic devices differs under different application information, the state information of the electronic devices is collected based on the application information. Because the state information reflects the security status of the electronic devices, risk information is determined based on this state information. By collecting state information related to application information to determine risk information, the security status of the electronic devices reflected by the risk information can meet the needs of the application, thereby improving the reliability of risk determination. Simultaneously, since there is no need to send state information to the application, more state information can be collected to determine risk information while avoiding the leakage of user privacy, thus improving the accuracy of risk information.

[0091] For example, the status information includes, but is not limited to, the status of super user privileges being obtained, screen casting status, screen sharing status, overseas phone call status, simulated click status, multiple account opening status, and malicious application status.

[0092] In one embodiment, the application information includes an application identifier and an application scenario. The process of collecting the electronic device's status information based on the application information in the above steps is determined as follows:

[0093] Based on the application identifier, application scenario, and preset relationships, determine the corresponding list of status information.

[0094] Collect status information from the status information list.

[0095] Among them, the preset relationship is used to characterize the correspondence between the preset application identifier and the preset application scenario and the preset state information list.

[0096] In this embodiment, since the status information affecting the security status of electronic devices varies under different application scenarios in different applications, a corresponding status information list is determined based on the application identifier, application scenario, and preset relationships. Because the status information list contains all the necessary status information, the status information in the list is collected. By determining the status information list to collect status information, omissions are avoided, thereby improving the reliability of risk determination.

[0097] For example, such as Figure 6As shown, the step above, determining the corresponding status information list based on the application identifier, application scenario, and preset relationship, can be achieved by identifying a preset application identifier that is identical to the application identifier and a preset application scenario that is identical to the application scenario within the preset relationship. The preset status information list corresponding to the identified preset application identifier and preset application scenario is then used as the status information list. For example, if the application identifier is the first preset identifier (reflecting the application as the first application) and the application scenario is a payment scenario, the status information list is determined as the first list. Status information in the first list includes, but is not limited to, the status of superuser privileges being obtained and screen mirroring status. If the application identifier is the first preset identifier and the application scenario is a fraud scenario, the status information list is determined as the second list. Status information in the second list includes, but is not limited to, screen sharing status and the presence of overseas calls. If the application identifier is the second preset identifier (reflecting the application as the second application) and the application scenario is a game scenario, the status information list is determined as the third list. Status information in the third list includes, but is not limited to, the status of simulated clicks and the status of multiple account openings. If the application identifier is the second preset identifier and the application scenario is a payment scenario, the status information list is determined as the fourth list. Status information in the fourth list includes, but is not limited to, screen sharing status and the presence of malicious applications. The application identifier can be an application ID.

[0098] In one embodiment, there are multiple status information items. The risk information is determined based on the status information in the above steps in the following manner:

[0099] Determine the relationship between each status information and the corresponding risk conditions.

[0100] If any state information meets the risk condition, the risk level in the risk information will be increased.

[0101] In this embodiment, since multiple status information items are collected, and each affects the security status of the electronic device, the relationship between each status information item and its corresponding risk condition is determined. For each status information item that meets a risk condition, the worse the security status of the electronic device, the higher the risk level in the risk information. By increasing the risk level with the number of status information items that meet the risk condition, the magnitude of the risk level can intuitively reflect the security status of the electronic device, thereby improving the reliability of risk determination. Simultaneously, because the data type of the risk level is simple, it facilitates application programs in analyzing the security status of the electronic device, thus reducing the complexity of risk prevention and control.

[0102] For example, risk conditions correspond to status information. For instance, if the status information includes "superuser privileges have been acquired," the risk condition is met when superuser privileges are acquired. If the status information includes "screen casting," the risk condition is met when screen casting is in progress. If the status information includes "screen sharing," the risk condition is met when screen sharing is in progress. If the status information includes "overseas phone number exists," the risk condition is met when an overseas phone number exists. If the status information includes "simulated click," the risk condition is met when a simulated click is in progress. If the status information includes "multiple accounts," the risk condition is met when multiple accounts are opened. If the status information includes "malicious application exists," the risk condition is met when a malicious application exists.

[0103] For example, the risk information may contain only one risk level, which is represented by a risk value. Increasing the risk level in the above steps can be achieved by incrementing the risk value by N, or by multiplying the risk value by a preset value, etc.

[0104] In one embodiment, the risk information includes risk levels under multiple risk categories. Before determining the relationship between each state information and the corresponding risk condition in the above steps, the step of determining the risk information based on the state information further includes:

[0105] Each status information is assigned to its corresponding risk category.

[0106] The risk level in the risk information mentioned above is determined as follows:

[0107] The risk level of the status information that meets the risk conditions will be increased under the risk category.

[0108] In this embodiment, since a single risk level cannot fully reflect the security status of an electronic device, risk levels are set under multiple risk categories, assigning each status information to its corresponding risk category. Whenever a status information meets a risk condition, the risk level of the corresponding risk category is increased to reflect the security status of the electronic device within that risk category. By dividing the device into multiple risk categories, the risk level under each category can comprehensively reflect the security status of the electronic device from multiple perspectives, thereby improving the reliability of risk determination.

[0109] For example, risk categories include, but are not limited to, operating system category, network connection category, and sensitive operation category. Under the operating system category, the risk level can reflect whether the operating system has been tampered with and the degree of risk associated with such tampering. Under the network connection category, the risk level can reflect whether the network connection of the electronic device is abnormal and the degree of risk associated with such an abnormal network connection. Under the sensitive operation category, the risk level can reflect whether the user is performing a sensitive operation and the degree of risk associated with that sensitive operation.

[0110] For example, the increase in risk level in the risk information mentioned above can be combined with the weighting of status information. For instance, if the status information includes whether superuser privileges have been acquired and screen sharing is in progress, the risk level will be increased by one level if superuser privileges have been acquired, and by half a level if screen sharing is in progress. In different application scenarios, the degree of risk level increase may vary when the same status information meets the risk conditions. For example, in a fraud scenario, the risk level will be increased by half a level if screen sharing is in progress. In a payment scenario, the risk level will be increased by one level if screen sharing is in progress.

[0111] In one embodiment, the application information includes the application scenario. Before determining the relationship between each state information and the corresponding risk condition in the above steps, the step of determining the risk information based on the state information further includes:

[0112] Determine the risk calculation method based on the application scenario.

[0113] The risk level in the risk information is increased in the above steps as follows:

[0114] The risk level is increased based on the risk calculation method.

[0115] In this embodiment, since the methods for combining status information to determine risk information may differ in different application scenarios, the risk calculation method is determined based on the application scenario. According to the risk calculation method, the risk level is increased to match the degree of increase in risk level with the risk calculation method. Determining risk information through the risk calculation method avoids omitting status information during risk information determination, thereby improving the reliability of risk determination.

[0116] For example, determining the risk calculation method based on the application scenario in the above steps can be to determine a preset application scenario that is the same as the application scenario, and use the preset risk calculation method corresponding to the determined preset application scenario as the risk calculation method.

[0117] For example, the risk calculation method can include corresponding risk conditions and weights for different state information. The risk calculation method determines the degree to which the risk level increases when different state information meets the corresponding risk conditions.

[0118] In one embodiment, after determining the risk information of the electronic device based on the application information in step S200, the risk determination method further includes:

[0119] Check the format of the risk information.

[0120] The process of sending the risk information to the application in step S300 is determined as follows:

[0121] If the risk information meets the format requirements, the risk information will be sent to the application.

[0122] In this embodiment, since the identified risk information may contain information about electronic devices, the format of the risk information needs to be checked to prevent the leakage of user information. If the risk information meets the format requirements and does not contain information about electronic devices, the risk information is sent to the application. By sending the risk information to the application only after it meets the format requirements, user information is avoided from being sent to the application and thus leaking user privacy, thereby improving the security of risk identification.

[0123] For example, when the risk information includes a risk level, the data type of the risk level can be defined as an unsigned integer, an integer, a floating-point number, etc. The format requirements are related to the data type of the risk level. That is, if the data type of the risk level is an unsigned integer, and the data type of the risk information being checked is also an unsigned integer, then the format of the risk information meets the format requirements. If the data type of the risk information being checked is a floating-point number, then the format of the risk information does not meet the format requirements.

[0124] For example, such as Figure 7As shown, when determining risk information based on status information, the application scenario and collected status information can be input into the corresponding model calculation software development kit (SDK) via the input application programming interface (API). The model calculation SDK uses its included risk calculation method to determine the risk level based on the status information and outputs the risk level through the output application programming interface. Before sending the risk level to the application, the format of the risk level is checked to ensure it meets the requirements. If the format of the risk level meets the requirements, it is sent to the application. For example, the model calculation SDK can use the following risk calculation method to determine the risk level: the application is the first application, the application scenario is a payment scenario, and the status information includes the superuser permission acquisition status and the screen projection status. The initial value of the risk level is set to 0. The superuser permission acquisition status is determined. If superuser permission is acquired, the risk level is incremented by 1. The screen projection status is determined. If screen projection is in progress, the risk level is incremented by 1. By embedding the model computation software development kit (MDK) into a secure open service within a trusted execution environment (TEA), the TEA collects state information and then invokes the corresponding MMD to calculate risk information. After identifying the risk information, a format check is performed to ensure that the application's MMD does not retrieve unauthorized state information or allow user information to leave the TEA, thus protecting user privacy.

[0125] For example, since the risk information is determined in the trusted execution environment, even if the rich execution environment is compromised by an attacker and can arbitrarily call the interface of the trusted execution environment, as long as the logic of the trusted execution environment's state information collection and risk calculation method is not tampered with, the attacker can only obtain a risk information containing the minimum amount of information and will not carry user information, unique identifiers, or other information involving user privacy.

[0126] For example, after checking the format of the risk information in the above steps, the risk determination method further includes:

[0127] If the risk information does not meet the format requirements, the risk information will be deleted.

[0128] It is understandable that, in addition to determining risk information based on status information, risk information can also be determined based on processor information, memory information, cumulative runtime information, operating system information, etc., without limitation here.

[0129] In one embodiment, after determining the risk information of the electronic device based on the application information in step S200, the risk determination method further includes:

[0130] The risk information is signed with a certificate using the private key of the electronic device to obtain the risk information carrying the public key certificate.

[0131] The process of sending the risk information to the application in step S300 is determined as follows:

[0132] Send risk information carrying the public key certificate to the application.

[0133] In this embodiment, to prevent the risk information from being tampered with, the risk information is certificate-signed using the private key of the electronic device to obtain risk information carrying a public key certificate. This risk information carrying the public key certificate is then sent to the application, allowing the application to verify the risk information based on the public key certificate. By certificate-signing the risk information, tampering with the risk information and its impact on risk control is prevented, thereby improving the reliability of risk identification.

[0134] For example, the step of signing the risk information with the private key of the electronic device to obtain the risk information carrying the public key certificate can be achieved by using an asymmetric digital signature algorithm to sign the risk information with the private key to obtain the risk information carrying the public key certificate.

[0135] In one embodiment, the application information includes verification information. Before the risk information is signed with the private key of the electronic device in the above steps to obtain the risk information carrying the public key certificate, the risk determination method further includes:

[0136] The risk information and the verification information are combined to obtain the combined information.

[0137] The risk information obtained by signing the risk information with the private key of the electronic device in the above steps, and then determining the risk information carrying the public key certificate, is as follows:

[0138] The combined information is signed with a certificate using the private key to obtain the combined information carrying the public key certificate.

[0139] The risk information carrying the public key certificate, as described in the above steps, is determined by sending it to the application in the following way:

[0140] Send the combined information, including the public key certificate, to the application.

[0141] In this embodiment, since risk information may be attacked and replaced during transmission, its alteration could affect risk control. Verification information is obtained when acquiring application information. The risk information and verification information are combined to obtain combined information. The combined information is then certificate-signed using a private key, resulting in combined information carrying a public key certificate. The public key certificate prevents tampering with the combined information. This combined information carrying the public key certificate is sent to the application, allowing the application to verify the combined information based on the public key certificate and, in conjunction with the verification information, check whether the risk information has been replaced. By certificate-signing the combined information containing verification information, multiple measures can prevent risk information from being tampered with, thereby improving the reliability of risk identification.

[0142] For example, the step of combining risk information and verification information to obtain combined information can be achieved by combining risk information and verification information in parallel across different dimensions. For instance, if risk information and verification information are represented by a single value, the combined information can be represented by two values. The verification information can be a challenge value.

[0143] For example, such as Figure 8 As shown, assuming the risk information format meets the requirements, the risk information and verification information are combined in a trusted execution environment to obtain combined information. The combined information is then signed with a certificate using the electronic device's private key, resulting in combined information carrying a public key certificate. This combined information carrying the public key certificate is sent to the application through a secure open service interface. Upon receiving the combined information carrying the public key certificate, the application verifies the signature using the electronic device's root public key. If the signature is valid, it checks whether the verification information in the combined information matches the obtained verification information. If both verification information matches, risk control measures are implemented based on the risk information in the combined information.

[0144] In one embodiment, the risk determination method further includes:

[0145] Upon receiving an update command, retrieve the update information corresponding to the update command.

[0146] Based on the updated information, update the preset application scenarios, preset status information list, and / or preset risk calculation method. The preset application scenarios, preset status information list, and preset risk calculation method are used to determine risk information.

[0147] In this embodiment, upon receiving an update instruction, relevant information needs to be updated to ensure that the determination of risk information meets the application's requirements. Updated information corresponding to the update instruction is obtained. Based on the updated information, the preset application scenario, preset status information list, and / or preset risk calculation method are updated to update the method for determining risk information. By obtaining updated information to update the preset application scenario, preset status information list, and / or preset risk calculation method, inaccurate risk information can be avoided from affecting risk prevention and control, thereby improving the reliability of risk determination.

[0148] For example, such as Figure 9 As shown, over-the-air (OTA) updates (i.e., software updates) can be implemented to update preset application scenarios, preset status information lists, and / or preset risk calculation methods. Since the preset application scenarios, preset status information lists, and preset risk calculation methods are determined by the application, timely updates are required when the application scenario or application requirements change. Update information must be authenticated by the electronic device to ensure that the update information originates from the application that needs to determine risk information and not a malicious application. Specifically, the model calculation software development kit related to the preset risk calculation method directly updates the program. Because the preset application scenarios and preset status information lists are stored in the secure storage of the trusted execution environment, the corresponding information in the update information needs to be written to the secure storage. Since the preset application scenarios and preset status information lists are stored in secure storage, the application can call the interface provided by the update module to rewrite the update information related to the preset application scenarios and preset status information lists into the secure storage. During the status information collection process, the preset application scenarios and preset status information lists can be directly read from the secure storage. This ensures that the timing of updates to the preset application scenarios, preset status information lists, and model calculation software development kits is controlled by the application, preventing any mismatch between the three and guaranteeing update compatibility.

[0149] This disclosure provides a risk determination method, such as... Figure 10 As shown, the method includes:

[0150] S400: Upon receiving a call instruction from an application running in a rich execution environment, obtain the application identifier, application scenario, and challenge value related to the call instruction from the application.

[0151] S410. In a trusted execution environment, determine the corresponding list of status information and risk calculation method based on the application identifier, application scenario and preset relationship.

[0152] S420, Collect status information from the status information list.

[0153] S430. If any state information meets the risk conditions, the risk level is increased by risk calculation.

[0154] S440, Check the format of the risk level.

[0155] S450. If the risk level format meets the format requirements, combine the risk level and the challenge value to obtain the combined value.

[0156] S460. Sign the combined value with the private key of the electronic device to obtain the combined value carrying the public key certificate.

[0157] S470: Send the combined value carrying the public key certificate to the application.

[0158] S480. Upon receiving an update command, obtain the update information corresponding to the update command.

[0159] S490. Based on the updated information, update the preset application scenarios, preset status information list, and preset risk calculation method.

[0160] In this embodiment, upon receiving a call instruction from an application running in a rich execution environment, the application needs to determine the security status of the electronic device for risk control, obtaining the application identifier, application scenario, and challenge value related to the call instruction from the application. In the trusted execution environment, based on the application identifier, application scenario, and preset relationships, a corresponding list of status information and a risk calculation method are determined, and the status information in the status information list is collected. For each status information that meets a risk condition, the security status of the electronic device deteriorates, and the risk level is increased using the risk calculation method. The format of the risk level is checked to determine if it carries information from the electronic device. If the risk level format meets the requirements, the risk level is combined with the challenge value to obtain a combined value. The combined value is then signed with the electronic device's private key to obtain a combined value carrying a public key certificate, thus protecting the risk level. The combined value carrying the public key certificate is sent to the application, allowing the application to combine the signature and challenge value to determine the validity of the risk level for risk control. Upon receiving an update instruction, the relevant information used to determine the risk level needs to be updated, and the update information corresponding to the update instruction is obtained. Based on the updated information, the preset application scenarios, preset status information lists, and preset risk calculation methods have been updated to ensure that the risk levels meet the application's risk control requirements. Since the application no longer needs to determine the risk level, more status information from the electronic device can be combined to determine the risk level, thereby improving the accuracy of the risk level. Simultaneously, because only the risk level needs to be sent to the application, without sending the electronic device's status information to the application to avoid privacy leaks, the security of risk determination is improved.

[0161] In one exemplary embodiment, a risk determination apparatus is provided for implementing the method described above. (Reference) Figure 11 As shown, the risk determination device may include an acquisition module 100, a determination module 200, and a transmission module 300. During the implementation of the above method,

[0162] The acquisition module 100 is configured to acquire application information of the application.

[0163] The determination module 200 is configured to determine risk information of electronic devices based on application information.

[0164] The sending module 300 is configured to send risk information to the application.

[0165] In one exemplary embodiment, a risk determination apparatus is provided, wherein a determination module 200 is configured to:

[0166] Based on application information, collect status information of electronic devices.

[0167] Based on the status information, determine the risk information.

[0168] In one exemplary embodiment, a risk determination apparatus is provided, wherein a determination module 200 is configured to:

[0169] Based on the application identifier, application scenario, and preset relationships, determine the corresponding list of status information.

[0170] Collect status information from the status information list.

[0171] Among them, the preset relationship is used to characterize the correspondence between the preset application identifier and the preset application scenario and the preset state information list.

[0172] In one exemplary embodiment, a risk determination apparatus is provided, wherein a determination module 200 is configured to:

[0173] Determine the relationship between each status information and the corresponding risk conditions.

[0174] If any state information meets the risk condition, the risk level in the risk information will be increased.

[0175] In one exemplary embodiment, a risk determination apparatus is provided, wherein a determination module 200 is configured to:

[0176] Each status information is assigned to its corresponding risk category.

[0177] If any state information meets the risk conditions, the risk level of the state information in the corresponding risk category will be increased.

[0178] In one exemplary embodiment, a risk determination apparatus is provided, wherein a determination module 200 is configured to:

[0179] Determine the risk calculation method based on the application scenario.

[0180] The risk level is increased based on the risk calculation method.

[0181] In one exemplary embodiment, a risk determination apparatus is provided, the apparatus further comprising:

[0182] The inspection module is configured to inspect the format of risk information.

[0183] In one exemplary embodiment, a risk determination apparatus is provided, wherein a sending module 300 is configured to:

[0184] If the risk information meets the format requirements, the risk information will be sent to the application.

[0185] In one exemplary embodiment, a risk determination apparatus is provided, the apparatus further comprising:

[0186] The signature module is configured to use the private key of the electronic device to sign the risk information with a certificate, thereby obtaining the risk information carrying the public key certificate.

[0187] In one exemplary embodiment, a risk determination apparatus is provided, wherein a sending module 300 is configured to:

[0188] Send risk information carrying the public key certificate to the application.

[0189] In one exemplary embodiment, a risk determination apparatus is provided, wherein a signature module is configured to:

[0190] The risk information and the verification information are combined to obtain the combined information.

[0191] The combined information is signed with a certificate using the private key to obtain the combined information carrying the public key certificate.

[0192] In one exemplary embodiment, a risk determination apparatus is provided, wherein a sending module 300 is configured to:

[0193] Send the combined information, including the public key certificate, to the application.

[0194] In one exemplary embodiment, a risk determination apparatus is provided, the apparatus further comprising:

[0195] The update module is configured to retrieve the update information corresponding to the update command when an update command is received.

[0196] Based on the updated information, update the preset application scenarios, preset status information list, and / or preset risk calculation method. The application scenarios, status information list, and preset risk calculation method are used to determine risk information.

[0197] In one exemplary embodiment, an electronic device is provided, such as a mobile phone, a laptop computer, a tablet computer, and a wearable device.

[0198] refer to Figure 12 As shown, the electronic device 400 may include one or more of the following components: processing component 402, memory 404, power supply component 406, multimedia component 408, audio component 410, input / output (I / O) interface 412, sensor component 414, and communication component 416.

[0199] Processing component 402 typically controls the overall operation of electronic device 400, such as operations associated with display, telephone calls, data communication, camera operation, and recording. Processing component 402 may include one or more processors 420 to execute instructions to perform all or part of the steps of the methods described above. Furthermore, processing component 402 may include one or more modules to facilitate interaction between processing component 402 and other components. For example, processing component 402 may include a multimedia module to facilitate interaction between multimedia component 408 and processing component 402.

[0200] Memory 404 is configured to store various types of data to support the operation of electronic device 400. Examples of this data include instructions for any application or method operating on electronic device 400, contact data, phonebook data, messages, pictures, videos, etc. Memory 404 can be implemented by any type of volatile or non-volatile storage terminal or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0201] Power supply component 406 provides power to various components of electronic device 400. Power supply component 406 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to electronic device 400.

[0202] Multimedia component 408 includes a screen that provides an output interface between electronic device 400 and user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of touch or swipe actions but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 408 includes a front-facing camera module and / or a rear-facing camera module. When electronic device 400 is in an operating mode, such as shooting mode or video mode, the front-facing camera module and / or rear-facing camera module may receive external multimedia data. Each front-facing camera module and rear-facing camera module may be a fixed optical lens system or have focal length and optical zoom capabilities.

[0203] Audio component 410 is configured to output and / or input audio signals. For example, audio component 410 includes a microphone (MIC) configured to receive external audio signals when electronic device 400 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 404 or transmitted via communication component 416. In some embodiments, audio component 410 also includes a speaker for outputting audio signals.

[0204] I / O interface 412 provides an interface between processing component 402 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, power buttons, and lock buttons.

[0205] Sensor assembly 414 includes one or more sensors for providing state assessments of various aspects of electronic device 400. For example, sensor assembly 414 may detect the on / off state of electronic device 400, the relative positioning of components such as the display and keypad of electronic device 400, changes in position of electronic device 400 or a component of electronic device 400, the presence or absence of user contact with electronic device 400, orientation or acceleration / deceleration of electronic device 400, and temperature changes of electronic device 400. Sensor assembly 414 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 414 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 414 may also include an accelerometer, gyroscope, magnetometer, pressure sensor, or temperature sensor.

[0206] Communication component 416 is configured to facilitate wired or wireless communication between electronic device 400 and other terminals. Electronic device 400 can access wireless networks based on communication standards, such as WiFi, 2G, 3G, 4G, 5G, or combinations thereof. In one exemplary embodiment, communication component 416 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 416 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0207] In an exemplary embodiment, the electronic device 400 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing terminals (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods shown in the above embodiments or combinations thereof.

[0208] In one exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 404 including instructions, which can be executed by a processor 420 of an electronic device 400 to perform the methods shown in the embodiments or combinations thereof. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage terminal, etc. When the instructions in the storage medium are executed by the processor of the terminal, the terminal is able to perform the methods shown in the embodiments or combinations thereof.

[0209] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the claims.

[0210] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this disclosure. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0211] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this disclosure, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0212] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0213] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A risk determination method, characterized in that, The risk determination method includes: Get application information about the application; Based on the application information, determine the risk information of the electronic device; The risk information is sent to the application.

2. The risk determination method according to claim 1, characterized in that, The step of determining the risk information of the electronic device based on the application information includes: Based on the application information, the status information of the electronic device is collected; The risk information is determined based on the status information.

3. The risk determination method according to claim 2, characterized in that, The application information includes an application identifier and an application scenario; the step of collecting the status information of the electronic device based on the application information includes: Based on the application identifier, the application scenario, and the preset relationship, determine the corresponding list of status information; Collect the status information from the status information list; The preset relationship is used to characterize the correspondence between preset application identifiers and preset application scenarios and preset status information lists.

4. The risk determination method according to claim 2, characterized in that, The number of status information items is multiple; determining the risk information based on the status information includes: Determine the relationship between each state information and its corresponding risk condition; When any of the aforementioned status information satisfies the risk condition, the risk level in the risk information is increased.

5. The risk determination method according to claim 4, characterized in that, The risk information includes the risk level under multiple risk categories; Before determining the relationship between each state information and the corresponding risk condition, the step of determining the risk information based on the state information further includes: Each of the aforementioned status information is assigned to its corresponding risk category; The step of raising the risk level in the risk information includes: The risk level of the status information that meets the risk conditions under the risk category will be increased.

6. The risk determination method according to claim 4, characterized in that, The application information includes application scenarios; before determining the relationship between each state information and the corresponding risk condition, determining the risk information based on the state information further includes: Based on the application scenario, determine the risk calculation method; The step of raising the risk level in the risk information includes: Based on the risk calculation method, the risk level is increased.

7. The risk determination method according to claim 1, characterized in that, After determining the risk information of the electronic device based on the application information, the risk determination method further includes: Check the format of the risk information; Sending the risk information to the application includes: If the format of the risk information meets the format requirements, the risk information will be sent to the application.

8. The risk determination method according to claim 1, characterized in that, After determining the risk information of the electronic device based on the application information, the risk determination method further includes: The risk information is signed with a certificate using the private key of the electronic device to obtain the risk information carrying a public key certificate; Sending the risk information to the application includes: The risk information carrying the public key certificate is sent to the application.

9. The risk determination method according to claim 8, characterized in that, The application information includes verification information; before the risk information is signed with the private key of the electronic device to obtain the risk information carrying the public key certificate, the risk determination method further includes: The risk information is combined with the verification information to obtain combined information; The step of signing the risk information with the private key of the electronic device to obtain the risk information carrying the public key certificate includes: The combined information is signed with the private key to obtain the combined information carrying the public key certificate; Sending the risk information carrying the public key certificate to the application includes: The combined information carrying the public key certificate is sent to the application.

10. The risk determination method according to claim 1, characterized in that, The risk determination method also includes: Upon receiving an update instruction, obtain the update information corresponding to the update instruction; Based on the updated information, the preset application scenario, the preset status information list, and / or the preset risk calculation method are updated, and the preset application scenario, the preset status information list, and the preset risk calculation method are used to determine the risk information.

11. The risk determination method according to any one of claims 1 to 10, characterized in that, The application runs in a rich execution environment, and the risk information is determined in a trusted execution environment.

12. A risk determination device, characterized in that, The risk determination device includes: An acquisition module, configured to acquire application information of an application; A determination module, configured to determine risk information of an electronic device based on the application information; A sending module, configured to send the risk information to the application.

13. An electronic device, characterized in that, The electronic device includes: processor; Memory used to store the processor's executable instructions; The processor is configured to perform the risk determination method as described in any one of claims 1 to 11.

14. A non-transitory computer-readable storage medium, characterized in that, When the instructions in the storage medium are executed by the processor of the terminal, the terminal is able to perform the risk determination method as described in any one of claims 1 to 11.