Abnormal feature address association uses subject identification methods, devices, equipment and media
By identifying abnormally recurring installation and activation addresses of positioning devices, and then tracing back to related controlled carriers and users, the problem of low efficiency in risk screening in existing technologies is solved, and the automatic extended identification and accurate association of potential risk entities is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- PING AN INT FINANCIAL LEASING CO LTD
- Filing Date
- 2026-04-14
- Publication Date
- 2026-06-02
AI Technical Summary
Existing technologies cannot effectively utilize the installation and activation address information of positioning devices to identify potential risk associations, resulting in low risk screening efficiency and an inability to quickly expand the identification of other potential risk vehicles and customers in the same risk environment.
By obtaining the controlled carrier identification information from known abnormal usage events, the system extracts the set of installation and activation addresses of the positioning devices from the device database, identifies recurring addresses as abnormal feature addresses, reverse searches are conducted on other controlled carriers that have been operated on these addresses, obtains the identity information of the associated user entities, and generates a list of potential abnormal user entities.
It enables automatic correlation and identification from abnormal address characteristics to abnormal users, improving the coverage and efficiency of risk group investigation and ensuring the accurate identification of potential risk entities.
Smart Images

Figure CN122137667A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data analysis technology, and in particular to a method, apparatus, device, and medium for identifying entities associated with abnormal feature addresses. Background Technology
[0002] In financial leasing, vehicles, as leased assets, require continuous monitoring to mitigate the impact of risks such as fraudulent leasing, loss of contact, and malicious default on asset security. Currently, leasing companies primarily rely on contract information, customer information, and post-loan manual inspections to manage leased assets during risk management. When a risk event occurs, risk investigation typically focuses on known customers or vehicles, relying on manual communication, data comparison, and experience-based judgment to identify anomalies. This approach is inefficient in scenarios with a large number of vehicles and a wide distribution of customers, and it is prone to overlooking potential risk clues.
[0003] In real-world risk group cases, multiple customers or vehicles often exhibit some form of implicit connection, such as having equipment installed in the same location, activating location devices in similar environments, or displaying similar underlying behavioral characteristics. These connections are not reflected in contractual relationships or customer information but are hidden in the underlying device data generated during vehicle use. In existing technological systems, the installation and activation addresses of location devices, along with related log information, are typically only used for post-event location tracking or trajectory queries. There is a lack of means to analyze this address information as risk correlation characteristics, making it impossible to discover potential group risks from address clustering phenomena.
[0004] Therefore, existing risk screening methods struggle to quickly expand from known risky vehicles to identify other potentially risky vehicles within the same risk environment. They also fail to effectively correlate vehicle behavior characteristics with customer identity information, resulting in scattered and difficult-to-aggregate risk clues. When facing group risks, relying on manual experience for piecemeal investigations is insufficient in terms of efficiency and comprehensiveness; a technological means is lacking to automatically expand and identify potential risk subjects based on device behavior data. Summary of the Invention
[0005] The main objective of this invention is to provide a method, apparatus, device, and storage medium for identifying users associated with abnormal feature addresses. This aims to solve the technical problem that existing technologies cannot automatically expand and identify other potential risk users in the same risk environment based on the address aggregation features formed during the installation and activation of positioning devices.
[0006] To achieve the above objectives, the present invention provides a method for identifying entities associated with abnormal feature addresses, comprising: Obtain the identification information of multiple controlled carriers involved in known abnormal usage events; Based on the controlled carrier identification information, extract the set of positioning device installation addresses and the set of positioning device activation addresses associated with the controlled carrier identification information from the device database; Identify recurring installation addresses and / or recurring activation addresses from the set of installation addresses of the positioning devices and the set of activation addresses of the positioning devices; The repeated installation addresses and / or the repeated activation addresses are identified as abnormal feature addresses; Based on the abnormal feature address, search the device database for other controlled carriers besides those involved in the known abnormal usage events, and which have undergone installation or activation operations at the abnormal feature address. Obtain the user identity information associated with the other controlled carriers, and generate a list of potentially abnormal users based on the user identity information.
[0007] Furthermore, to achieve the above objectives, the present invention provides an abnormal feature address association user identification device, comprising: The exception event parsing module is used to obtain the identification information of multiple controlled carriers involved in known exception usage events; The device log parsing module is used to extract, based on the controlled carrier identification information, the set of location device installation addresses and the set of location device activation addresses associated with the controlled carrier identification information from the device database; The address frequency analysis module is used to identify recurring installation addresses and / or recurring activation addresses from the set of installation addresses of the positioning device and the set of activation addresses of the positioning device; An abnormal address marking module is used to identify the repeated installation address and / or the repeated activation address as abnormal feature addresses; The carrier reverse lookup and filtering module is used to search the device database for other controlled carriers besides those involved in the known abnormal usage events, which have been installed or activated at the abnormal feature address, based on the abnormal feature address. The entity association generation module is used to obtain the user entity identity information associated with the other controlled carriers, and generate a list of potentially abnormal users based on the user entity identity information.
[0008] Furthermore, to achieve the above objectives, the present invention also provides a computer device, the computer device including a memory, a processor, and an abnormal feature address association user identification program stored in the memory and executable on the processor, wherein when the abnormal feature address association user identification program is executed by the processor, it implements the steps of the abnormal feature address association user identification method as described above.
[0009] Furthermore, to achieve the above objectives, the present invention also provides a computer-readable storage medium storing an abnormal feature address association user identification program, wherein when the abnormal feature address association user identification program is executed by a processor, it implements the steps of the abnormal feature address association user identification method as described above.
[0010] Beneficial Effects: This invention relates to the field of data analysis technology and discloses a method, apparatus, device, and medium for identifying users associated with abnormal feature addresses. The method includes: acquiring the identification information of multiple controlled carriers involved in known abnormal usage events; combining the installation address and activation address of the positioning device recorded in the device database; identifying installation addresses or activation addresses that repeatedly appear among different controlled carriers; and marking the repeated addresses as abnormal feature addresses; further, based on the abnormal feature addresses, reversibly searching for other controlled carriers where installation or activation operations have occurred; after excluding the controlled carriers involved in known abnormal usage events, obtaining the associated user identity information; and finally generating a list of potential abnormal users, thus achieving the association identification from abnormal address features to abnormal users. This invention can be applied to business scenarios such as fintech. By establishing abnormal feature addresses through the aggregation features of the installation address and activation address of the positioning device, and then reversibly associating other controlled carriers based on the abnormal feature addresses and further associating user identity information, a complete association link from address to carrier to user is formed. This enables automatic extended identification of potential risk subjects under the same abnormal environment, improving the coverage and efficiency of risk group investigation. Attached Figure Description
[0011] The present invention will be further described below with reference to the accompanying drawings and embodiments. In the accompanying drawings: Figure 1 This is a schematic diagram of an application environment for the subject identification method used in the abnormal feature address association according to an embodiment of the present invention; Figure 2 This is a flowchart illustrating an embodiment of the abnormal feature address association subject identification method of the present invention; Figure 3 This is a schematic diagram of the functional modules of a preferred embodiment of the abnormal feature address association subject identification device of the present invention; Figure 4 This is a schematic diagram of the structure of a computer device according to an embodiment of the present invention; Figure 5 This is another structural schematic diagram of a computer device according to one embodiment of the present invention. Detailed Implementation
[0012] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.
[0013] The abnormal feature address association method provided in this embodiment of the invention can be applied to, for example, Figure 1 In this application environment, the client communicates with the server via a network. The server can obtain the identification information of multiple controlled carriers involved in known abnormal usage events from the client. Combining this with the device installation address and activation address recorded in the device database, it identifies repeated installation or activation addresses across different controlled carriers and marks these repeated addresses as abnormal feature addresses. Furthermore, based on these abnormal feature addresses, it searches for other controlled carriers where installation or activation operations have occurred. After excluding controlled carriers involved in known abnormal usage events, it obtains the associated user identity information, ultimately generating a list of potential abnormal users, thus achieving the association identification from abnormal address features to abnormal users. This invention can be applied to business scenarios such as fintech. By establishing abnormal feature addresses through the aggregation features of device installation and activation addresses, and then using these abnormal feature addresses to associate other controlled carriers and further associate user identity information, a complete association link from address to carrier to user is formed. This enables automatic extended identification of potential risk subjects under the same abnormal environment, improving the coverage and efficiency of risk group investigation. The client can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The server can be implemented using a standalone server or a server cluster consisting of multiple servers. The invention will be described in detail below through specific embodiments.
[0014] Please see Figure 2 , Figure 2 This is a flowchart illustrating an embodiment of the subject identification method for associating abnormal feature addresses provided by the present invention. It should be noted that although a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.
[0015] like Figure 2 As shown, the abnormal feature address association method for subject identification proposed in this invention includes the following steps: S10, Obtain the identification information of multiple controlled carriers involved in known abnormal usage events; In this embodiment, the acquisition of multiple controlled carrier identification information involved in known abnormal usage events is manifested as extracting a set of unique asset identifiers from risk event data that can be used for subsequent data processing. Known abnormal usage events originate from risk audit records, fraud identification results, post-loan monitoring anomaly records, or compliance investigation records, and in the financial leasing business system, they typically exist in the form of event numbers, case numbers, or risk tags. Controlled carrier identification information is used to refer to the regulated entity, and in the financial leasing scenario, it manifests as a vehicle identification code, a location device binding number, or an asset management code. This identifier is unique and traceable in the business system and is used to establish the association between assets and contract information. Multiple controlled carrier identification information means that the same abnormal event involves multiple assets, and this set provides a unified data entry point for subsequent analysis.
[0016] In the implementation process, access permission records are stored using exception event numbers as retrieval criteria. These records preserve the binding relationship between contracts and assets, as well as the corresponding user information. When parsing the access permission records, the asset identifier field is extracted, which is associated with the unique serial number of the location device in the device database. To ensure data accuracy, format validation is performed after extracting the identifier information, including encoding rule matching, character length validation, and illegal character filtering. Deduplication is also performed to prevent the same controlled carrier from being counted repeatedly. The validated and deduplicated results form a set of controlled carrier identifier information, which serves as standardized input for subsequent data processing.
[0017] At the data structure level, the controlled carrier identification information serves both as a unique asset identifier and as a cross-data source linker. In the financial leasing business environment, this identifier can be mapped to both equipment log information and contract performance information, enabling the accurate location of assets in risk events and their participation in subsequent processing.
[0018] For example, in financial leasing transactions, when the risk audit system identifies a group of lessees engaging in fraudulent activities such as rent fraud, submitting false information, or maliciously absconding, the risk event will generate a corresponding case record in the business system. By analyzing this case record, information on all customers involved in the group can be extracted, and further, vehicle asset information linked to these customers can be retrieved from the access records. Each access record contains a vehicle identification number or device binding number; by parsing these fields, the corresponding controlled vehicle identification information can be obtained.
[0019] In practice, since a single customer may be associated with multiple vehicles, and the same vehicle may have multiple records due to changes in historical contracts, it is necessary to perform format validation and deduplication on the extracted identification information to ensure that each controlled vehicle is counted only once. The processed set of controlled vehicle identification information can fully reflect the scope of all assets involved in the risk group, providing accurate data input for subsequent cluster analysis based on location device addresses.
[0020] In risk investigation work, this approach allows the risk team to no longer rely on manual verification of contracts and vehicle information item by item. Instead, the system automatically maps abnormal events to asset identifiers, significantly improving the accuracy and efficiency of risk asset identification and laying a data foundation for discovering more potential risky clients in the case.
[0021] This embodiment extracts and processes asset identifiers in abnormal events in a standardized manner to form an accurate and unique set of controlled carrier identifier information, providing a reliable data foundation for subsequent data processing, avoiding analytical biases caused by identifier confusion or duplicate statistics, and improving the consistency and accuracy of risk investigation data.
[0022] S20, based on the controlled carrier identification information, extract from the device database the set of positioning device installation addresses and the set of positioning device activation addresses associated with the controlled carrier identification information; In this embodiment, the controlled carrier identification information is used to locate the range of controlled carriers corresponding to the finance lease asset. The controlled carrier can correspond to vehicles, engineering equipment, or other regulated assets. The controlled carrier identification information can come from contract ledger fields, asset management fields, or equipment binding fields, with common formats including vehicle identification codes, asset numbers, and equipment binding numbers. The equipment database is used to store the binding information between the controlled carrier and the positioning device, as well as installation and activation-related data generated by the positioning device. The equipment database can be composed of a business database and equipment data storage, or it can use a unified table structure to carry associated data such as controlled carrier identification information, positioning device identification, installation records, and activation records. The processing objective of extracting the set of positioning device installation addresses and the set of positioning device activation addresses from the equipment database based on the controlled carrier identification information is to convert the asset-level identification information into a data set that can be used for address-level analysis. Therefore, it is necessary to complete the association and location of the controlled carrier to the positioning device in the equipment database, and aggregate and output the address information related to the installation of the positioning device and the address information related to the activation of the positioning device, respectively.
[0023] The positioning device is used to collect location-related data and generate traceable assembly and activation records on the service side. The positioning device installation address set carries the installation address information corresponding to the completion of installation. This installation address information describes the geographical location of the positioning device when it is assembled onto a controlled carrier or its associated spatial location. Sources of the installation address information may include address fields in installation work orders, address fields entered by assembly personnel, and coordinate inversion results collected during the installation process. The positioning device activation address set carries the activation address information corresponding to the completion of activation. This activation address information describes the geographical location of the positioning device when it first reaches a usable state. Sources of the activation address information may include base station positioning results upon initial network access, coordinate inversion results reported during the initial positioning, and geographic information mapping results of the initial communication access point. The installation address set and the activation address set must remain independent to avoid mixing assembly and activation locations, which could lead to semantic ambiguity in subsequent address sets.
[0024] The device database contains binding records between controlled carrier identifiers and positioning device identifiers. These binding records can be one-way or two-way, and may include fields such as binding time, binding status, and unbinding time. This supports scenarios where multiple positioning devices exist for the same controlled carrier or where the same positioning device undergoes multiple binding changes. Processing the controlled carrier identifier information requires creating a query index. This index can be an exact match key for the controlled carrier identifier information or a standardized match key processed based on a unified coding standard, avoiding retrieval biases caused by differences in coding prefixes and separators. The retrieval results from the device database need to output two sets: a set of positioning device installation addresses extracted and aggregated from installation records, and a set of positioning device activation addresses extracted and aggregated from activation records. The aggregation process needs to form a set structure with addresses as the element unit. This set structure can be a deduplicated list of addresses or a binary structure set containing addresses and corresponding positioning device identifiers. The output format should meet the address-level data input requirements for subsequent processing.
[0025] The installation address information and activation address information must be semantically comparable. Therefore, the extraction stage typically requires standardization of the address representation. This standardization process can include address field cleaning, null value removal, abnormal character filtering, administrative division completion, and merging of synonymous addresses to ensure that the elements of the address set can be stably identified. For records that only have coordinates but lack textual addresses, the address text can be obtained through coordinate inversion and stored as address information in the set. For records that only have coarse-grained location representations, standardized address representations can be obtained through administrative division mapping and stored in the set. The boundaries between the location device installation address set and the location device activation address set should not overlap to avoid the same record being included in both sets simultaneously, which could cause a shift in the meaning of the sets.
[0026] For example, in a financial leasing risk control scenario, the risk investigation team understands the scope of multiple vehicle assets involved in a particular case. The business system maintains a Vehicle Identification Number (VIN) for each vehicle as a controlled carrier identifier. The equipment database records the binding relationship between the VIN and the on-board positioning device identifier, as well as the installation and activation records of the positioning devices. Based on the VIN set, a search can retrieve the corresponding positioning device identifier set from the binding records. Then, the installation address information of the assembly location is extracted from the installation records to form the positioning device installation address set, and the location address information at the time of initial use is extracted from the activation records to form the positioning device activation address set. For some vehicles, the positioning device is installed at the outer packaging distribution point during delivery, and the installation address information is the assembly point address. For other vehicles, the positioning device is first connected to the network after the customer picks up the vehicle, and the activation address information is the customer's actual usage location or parking location. By extracting and unifying these two types of address sets, the risk investigation team can obtain the address data foundation corresponding to the assembly and activation stages of the assets in the case, providing consistent data input for subsequent address-level analysis.
[0027] This embodiment locates the bound positioning device identifier in the device database using the controlled carrier identification information, and extracts the installation address information and activation address information from the installation record and activation record respectively to form the positioning device installation address set and the positioning device activation address set. This converts the asset identification information into a structured address set input. At the same time, address unification processing and set boundary separation reduce data noise caused by address expression differences, thereby improving the comparability and usability of the address set.
[0028] S30, Identify recurring installation addresses and / or recurring activation addresses from the set of installation addresses of the positioning device and the set of activation addresses of the positioning device; In this embodiment, the location device installation address set represents the set of installation address information formed by multiple controlled carriers corresponding to the location devices during the installation process, and the location device activation address set represents the set of activation address information formed by multiple controlled carriers corresponding to the location devices during the activation process. The processing objective of identifying recurring installation addresses and recurring activation addresses is to find address records with abnormally concentrated frequency of occurrence within the two types of address sets, so as to form a stable and reusable address clustering feature input. Therefore, it is necessary to establish a countable standard expression for each address record in the address set, count the frequency of occurrence in the set dimension, and then output the recurring installation addresses and recurring activation addresses according to preset judgment conditions.
[0029] Repeated installation addresses are identified only within the set of location device installation addresses, and repeated activation addresses are identified only within the set of location device activation addresses. This avoids semantic drift caused by mixing installation and activation addresses in the statistics. The counting of address records relies on standard address representations. These standard representations map different spellings of the same geographical location to the same comparison key. Address standard representations can be formed by concatenating fields such as administrative division elements, road elements, house number elements, and park elements, or by structured identifiers such as coordinate grid codes and geofence codes, ensuring that the same address is grouped into the same counting unit during statistics. For address records with aliases, abbreviations, or missing fields, the address standard representation needs to have normalization capabilities. For example, it should unify the naming of provinces, cities, and districts, unify the format of numbers and symbols, remove irrelevant modifiers, and fill in missing administrative division levels to reduce undercounting caused by different spellings of the same address.
[0030] Frequency of occurrence indicates the number of times the address standard expression appears in the corresponding address set. Frequency statistics require building a frequency statistics table with the address standard expression as the key. Each record in the frequency statistics table must contain at least the address standard expression and its frequency of occurrence. The frequency statistics table can further include auxiliary fields such as the number of location device identifiers involved in the counting, the number of controlled carrier identifiers, and the most recent occurrence timestamp to improve the stability of duplicate identification. Preset judgment conditions are used to classify candidate addresses in the frequency statistics table as duplicate address records. These preset judgment conditions can use a preset duplication threshold as a hard condition, or they can simultaneously introduce a proportional threshold after normalizing the set size to avoid inconsistent threshold sensitivity due to changes in the address set size. The output of duplicate installation addresses and duplicate activation addresses should maintain the form of address record sets. The elements of the address record sets should maintain the same expression method as the address standard expression to ensure that subsequent processing can directly reuse the address record set without further conversion.
[0031] When the set of installation addresses and the set of active addresses of the positioning device contain identical address standard expressions, the two types of outputs are still classified separately. Repeated installation addresses are generated only if the frequency of occurrence in the set of installation addresses meets the condition, and repeated active addresses are generated only if the frequency of occurrence in the set of active addresses meets the condition. To address the presence of noise in address records, a similarity merging strategy can be introduced for frequency statistics. Address similarity merging combines address standard expressions that are close in edit distance, within the same geofence, or within the same coordinate grid into the same counting unit, avoiding count splits caused by differences in writing styles between adjacent locations or within the same area. The triggering condition for address similarity merging can be limited by a similarity threshold or a geofence radius parameter, thereby improving the robustness of repeated identification without changing the identification target.
[0032] This embodiment establishes standard address representations and frequency statistics for the installation address set and the activation address set of the positioning device, respectively. Based on preset judgment conditions, it outputs the repeatedly occurring installation address and the repeatedly occurring activation address, so that the high-frequency clustered addresses in the two types of address sets can be stably identified. At the same time, address normalization and similarity merging reduce the interference of co-address writing and noise records on the statistical results, thereby improving the comparability and consistency of the duplicate address identification results.
[0033] S40, the repeatedly occurring installation address and / or the repeatedly occurring activation address are identified as abnormal feature addresses; In this embodiment, the recurring installation addresses and recurring activation addresses belong to the address result set that has completed cluster identification. The purpose of marking these address results as anomalous feature addresses is to add anomalous attributes that can be retrieved and referenced, transforming the address results from simple address text into anomalous feature input that can be recognized by the system. Annomalous feature addresses are used to express address entities with anomalous attributes, and their source is limited to recurring installation addresses and recurring activation addresses. The marking action includes three parts: unique representation of the address entity, assignment of anomalous attributes, and storage representation of the anomalous feature address.
[0034] The unique representation of an address entity is used to avoid multiple duplicate records for the same address in subsequent searches. This unique representation can generate an address identifier value based on the address standard representation, which serves as the unique key for the abnormal feature address. Abnormal attributes characterize the reason an address is included in the abnormal feature set. Abnormal attributes can take clustered abnormal states to indicate that the address is included in the abnormal feature address set due to its recurrence. The stored representation is used to write the abnormal feature address into a searchable data structure. The stored representation can contain an address identifier value, address standard representation, abnormal attributes, and address type flags. Address type flags distinguish between duplicate installation addresses and duplicate activation addresses corresponding to the abnormal feature address, avoiding semantic ambiguity caused by misuse. The output of abnormal feature addresses is stored in the form of a set. The elements of the set maintain a consistent field structure, ensuring that the same field has the same meaning in different elements.
[0035] This embodiment generates address identifier values for duplicate installation addresses and duplicate activation addresses and assigns them to clustered anomaly states, enabling the abnormal feature addresses to have a structured expression with unique keys and abnormal attributes. This reduces retrieval ambiguity caused by duplicate address records and improves the reusability and consistency of abnormal address results.
[0036] S50, based on the abnormal feature address, search the device database for other controlled carriers besides those involved in the known abnormal usage events, and which have undergone installation or activation operations at the abnormal feature address. In this embodiment, the abnormal feature address already possesses an address identifier value and an aggregated abnormal state. The purpose of performing a search in the device database based on this abnormal feature address is to locate controlled carriers that have previously undergone device initialization installation or first-time network activation at that address. The device database stores controlled carrier identification information, the unique serial number of the locating device, device initialization installation logs, and device first-time network activation logs. Both the installation logs and activation logs contain address standard expressions or location information that can be converted to address standard expressions. The abnormal feature address is used as a search condition and matched against the address standard expressions in the installation logs and activation logs to filter out all controlled carriers associated with actions performed at the abnormal feature address.
[0037] The restriction, excluding controlled carriers involved in known anomalous usage events, is used to avoid duplicate identification of already identified risky objects. This restriction is achieved by constructing a set of known controlled carrier identification information and performing set subtraction processing on the search results. The result of set subtraction processing retains controlled carriers whose installation or activation behavior occurred at anomalous address but did not appear in known anomalous usage events, as "other controlled carriers." The formation of other controlled carriers involves matching the anomalous address with the device behavior log and excluding them from the known set of controlled carriers, ultimately resulting in a new set of controlled carrier identification information.
[0038] For example, in a financial leasing risk assessment scenario, abnormal characteristic addresses correspond to certain vehicle dealerships or agent installation points. Using these abnormal characteristic addresses as search criteria, and matching them with standard address expressions in device initialization installation logs and initial network activation logs, a batch of vehicle identification information that has previously had location devices installed or activated at those addresses is obtained. By excluding vehicle identification information already included in risk clusters, the remaining vehicles form a new set of other controlled vehicles. Although these vehicles do not directly appear in known risk clusters, they have exhibited device activity at the same abnormal cluster address, possessing high associated risk value.
[0039] This implementation improves the accuracy of extended identification of abnormal controlled carriers by matching abnormal feature addresses with device installation and activation behavior logs and combining known controlled carrier exclusion processing, so that the identification results of new controlled carriers have clear abnormal address basis and deduplication constraints.
[0040] S60, obtain the user identity information associated with the other controlled carriers, and generate a list of potential abnormal users based on the user identity information.
[0041] In this embodiment, other controlled carriers have been identified by matching abnormal feature addresses with device behavior logs and undergoing exclusion processing. Each other controlled carrier possesses unique controlled carrier identification information. During actual use, each controlled carrier maintains a binding relationship with the user entity, which is recorded in the usage permission record database. The usage permission record database stores the correspondence between controlled carrier identification information and user entity identity information, as well as historical authorization, modification, and cancellation records. By accessing the usage permission record database using the identification information of other controlled carriers as a query index, the user entity identity information that is in a valid or historically bound state to that controlled carrier can be parsed out.
[0042] User identity information includes not only the user identifier value but also data such as authorization time, authorization type, and historical change records. This data provides a basis for identifying potentially anomalous users. User identity information parsed from different controlled carriers is uniformly aggregated, and duplicate user identity information is deduplicated to obtain a set of users that have been associated with multiple anomalous controlled carrier environments. Users in this set have a high probability of anomalous association because they are bound to multiple controlled carriers filtered by anomalous feature addresses, thus forming a list of potentially anomalous users.
[0043] For example, in a financial leasing risk assessment scenario, a batch of vehicles are identified as other controlled entities because their location devices were installed or activated at the same anomalous addresses. Inputting this vehicle identification information into a usage permission record database allows for the extraction of corresponding lessee information and authorization records. By aggregating lessees repeatedly associated with multiple vehicles, it can be discovered that some lessees are simultaneously associated with multiple vehicles that appeared at the anomalous addresses. These lessees constitute a list of potential anomalous users, providing the risk investigation team with further targets for verification.
[0044] This implementation uses the binding relationship between controlled carriers and user entities to further map the controlled carriers selected by abnormal feature addresses to specific user entities, thereby realizing the transformation from device abnormality aggregation to subject abnormality aggregation and improving the accuracy of identifying potential abnormal entities.
[0045] In one embodiment, step S10 includes: S101, Receive an anomaly investigation instruction generated for a known abnormal usage event, parse the anomaly investigation instruction, and extract a list of abnormal users involved in the known abnormal usage event from the anomaly investigation instruction; S102, using the list of abnormal users as a search index, access the usage permission record database and retrieve the target usage permission record that is bound to the list of abnormal users; S103, Traverse the target access permission records and parse out the bound controlled carrier identification information from each target access permission record; S104, perform format verification and set deduplication on the parsed controlled carrier identification information, and use the set of controlled carrier identification information after format verification and set deduplication as multiple controlled carrier identification information.
[0046] In this embodiment, an anomaly investigation instruction generated in response to a known abnormal usage event is received and parsed. The parsing process structurally decomposes fields such as event identifier, subject identifier, time range, and business domain identifier in the instruction payload, transforming the anomaly investigation instruction from a data format that cannot be directly retrieved into a parameter set that can drive queries. The anomaly investigation instruction extracts a list of abnormal users involved in the known abnormal usage event. This list of abnormal users serves as the subject-level entry point for subsequent searches. The list of abnormal users can include elements that can form matching keys in the usage permission record database, such as subject number, subject name, subject account identifier, and contract participation identifier. Multiple identifier formats are allowed for the same subject to cover differences in records from different business systems.
[0047] The database of usage permission records is accessed using the list of entities with abnormal usage as a retrieval index. Target usage permission records that are bound to the list of entities with abnormal usage are retrieved. The access action uses the entity identifier in the list of entities with abnormal usage as the query condition, and simultaneously adds constraints based on the time range or business domain identifier of known abnormal usage events to prevent irrelevant authorization records from entering the candidate set. The binding relationship of the target usage permission record is used to represent the authorized possession, leased use, or delegated use relationship between the user and the controlled carrier. The target usage permission record must contain at least the following fields: entity identifier, controlled carrier identifier, authorization status, authorization effective time, and authorization expiration time, thus supporting subsequent parsing to identify controlled carriers that are related to the event and within the valid semantic scope.
[0048] The process iterates through the target access permission records and parses the bound controlled carrier identification information from each record. The iteration process extracts the controlled carrier identification field from each record in the set, filtering the extraction results based on authorization status and effective period to remove noise caused by binding records that have been deregistered, expired, or whose time range is inconsistent with known abnormal usage events. The parsed controlled carrier identification information can originate from different identification systems; for example, vehicle carriers can correspond to contract identifiers, asset identifiers, chassis identifiers, etc., while equipment carriers can correspond to equipment numbers, terminal numbers, etc. The parsing process unifies these identifiers into a standard expression form of controlled carrier identification information, providing a consistent data foundation for subsequent set processing.
[0049] The parsed controlled carrier identification information undergoes format validation and set deduplication. Format validation determines whether the controlled carrier identification information meets preset format and integrity constraints, such as length constraints, character set constraints, check bit constraints, prefix field constraints, and removal of null values and placeholders, preventing erroneous identifiers from entering subsequent processing and causing retrieval deviations. Set deduplication merges duplicate controlled carrier identification information from multiple target usage permission records, eliminating interference from multiple authorization records for a single entity, historical duplication caused by authorization changes, and duplicate writes caused by cross-system synchronization, which can affect statistics and subsequent retrieval. The set of controlled carrier identification information after format validation and set deduplication is used as multiple controlled carrier identification information sets, which serve as carrier-side inputs for known abnormal usage events, laying a stable and consistent retrieval foundation for subsequent extraction of the set of location device installation addresses and the set of location device activation addresses from the device database.
[0050] This embodiment extracts the list of abnormal users by driving the abnormal user investigation command, and uses the list of abnormal users as a search index to locate the target user permission record in the user permission record database. Combined with the format verification and deduplication of the controlled carrier identification information, a stable mapping can be established between the clues on the subject side and the carrier side identification, reducing the identification noise introduced by authorization changes and differences in multi-source records, forming multiple controlled carrier identification information that can be directly used for subsequent device database retrieval, and improving the accuracy and consistency of carrier identification associated with known abnormal usage events.
[0051] In one embodiment, step S20 above includes: S201, using the controlled carrier identification information as a query index, access the device database and retrieve the unique serial number of the positioning device that is bound to the controlled carrier identification information; S202, based on the unique serial number of the positioning device, retrieve the corresponding device initialization installation log and device first network activation log from the device database; S203, extract physical installation location data from the device initialization installation log, and extract network access location data from the device's first network activation log; S204, the physical installation location data and the network access location data are processed by address standardization and coordinate transformation to generate a set of positioning device installation addresses and a set of positioning device activation addresses, respectively.
[0052] In this embodiment, the controlled carrier identification information is used as a query index to access the device database. The query index maps the controlled carrier identification information on the service side to the searchable primary key on the device side. When accessing the device database, the controlled carrier identification information is used as an equivalent matching condition or a combined matching condition to perform the search. The combined matching condition may include the type marker, the business domain marker, and the validity period marker of the controlled carrier identification information to avoid mismatches caused by the reuse of the same identifier in different business domains. The unique serial number of the positioning device that is bound to the controlled carrier identification information is retrieved. The binding status is used to limit the valid association between the controlled carrier identification information and the unique serial number of the positioning device. The binding status can be expressed by the binding effective time, binding expiration time, and binding status code, so that the unique serial number of the positioning device corresponds to a valid binding record of the controlled carrier identification information within a specified time range. The unique serial number of the positioning device serves as the unique identifier field of the positioning device, satisfying the consistency requirements of device-side log retrieval and avoiding the use of non-unique fields that could lead to multiple devices mixing the search results for the same controlled carrier identification information.
[0053] Based on the unique serial number of the positioning device, the system retrieves device initialization installation logs and device first-time network activation logs from the device database. The device initialization installation log records event data when the positioning device completes installation and initialization, and includes at least an event timestamp, the unique serial number of the positioning device, an installation method marker, a data collection source marker, and an installation location field. The device first-time network activation log records event data when the positioning device first completes network access and activation confirmation, and includes at least an event timestamp, the unique serial number of the positioning device, a network access information field, an activation status field, and an access location field. The retrieval action uses the unique serial number of the positioning device as the primary query key and limits the log category to an event type field. Further time range constraints can be added to exclude redundant logs caused by historical migration or duplicate writes. If multiple device initialization installation logs or multiple device first-time network activation logs exist for the same unique serial number, the search results can select the earliest record that meets the conditions based on the event timestamp as the device initialization installation log or device first-time network activation log to maintain consistency with the semantics of "initialization" and "first time," and to avoid subsequent address sets being contaminated by subsequent maintenance records.
[0054] Physical installation location data is extracted from the device initialization installation log. This data describes the spatial location of the positioning device during installation. Sources can include address text entered by installers, positioning coordinates collected by the installation terminal, and location codes from installation work orders. The extraction process parses the installation location field and retains information associated with timestamps and data collection source markers to support the differentiation of source reliability during subsequent standardization processing. Network access location data is extracted from the device's initial network activation log. This data describes the location formed during the initial network activation of the positioning device. Sources can include cellular network positioning information, base station information mapping results from the access network, and network egress address mapping results. The extraction process parses the access location field and retains auxiliary elements from the network access information field, such as network type markers, access identifier fragments, and positioning accuracy markers, to support the selection of accuracy in subsequent coordinate transformation processing.
[0055] Physical installation location data and network access location data undergo address standardization and coordinate transformation to generate sets of installation addresses and activation addresses for positioning devices, respectively. Address standardization unifies location descriptions from multiple sources into a single address representation system. This process includes address text cleaning, administrative division completion, alias normalization, splitting of house numbers and road information, field order regularization, and removal of null values and abnormal placeholders, resulting in comparable and aggregateable address strings or structured address fields. Coordinate transformation unifies the coordinate information in the location descriptions into a preset coordinate system and forms a computable location representation. This process includes coordinate system identification, coordinate system transformation, precision truncation or gridded representation, abnormal coordinate filtering, and range verification, ensuring that coordinates from different sources have a consistent spatial reference benchmark. The set of installation addresses for positioning devices is formed by aggregating physical installation location data after address standardization and coordinate transformation. The set of activation addresses for positioning devices is formed by aggregating network access location data after address standardization and coordinate transformation. When constructing the set, each address record retains the associated fields with the unique serial number of the positioning device, the event timestamp, and the data collection source mark, which facilitates filtering and statistics of recurring address identification in subsequent steps according to the source or time dimension.
[0056] This embodiment retrieves the binding status of controlled carrier identification information to the unique serial number of the positioning device, combines the categorized retrieval and location data extraction of the device initialization installation log and the device's first network activation log, and performs address standardization and coordinate transformation processing on the physical installation location data and network access location data. This enables the formation of a consistent and comparable set of positioning device installation addresses and a set of positioning device activation addresses, reducing the interference caused by differences in format, aliases, coordinate systems, and accuracy of multi-source location records on subsequent address duplication identification, and improving the accuracy and usability of address set construction.
[0057] In one embodiment, step S30 above includes: S301, traverse the address records in the set of installation addresses of the positioning device and the set of activation addresses of the positioning device respectively, and determine the frequency of occurrence of each address record; S302, perform clustering analysis based on the occurrence frequency to determine whether the occurrence frequency is greater than a preset repetition threshold; S303, when there is a first duplicate address record in the set of installation addresses of the positioning device with a frequency greater than the duplicate threshold, the first duplicate address record is identified as a duplicate installation address; S304, when there is a second duplicate address record in the set of active addresses of the positioning device that appears more frequently than the duplicate threshold, the second duplicate address record is identified as a duplicate active address.
[0058] In this embodiment, the address records in the set of installation addresses and the set of activation addresses of the positioning devices are traversed. This traversal is used to form measurable statistical objects within the sets. Address records, as statistical units, need to have comparable address representations. These representations can be standardized address strings, structured key-value pairs formed by combining administrative division, road, and address fields, or key-value pairs combining grid codes after coordinate transformation with standardized address strings. Frequency is determined using the address representation as the grouping key. Each address record in the set is counted and accumulated to form a mapping relationship between address representation and frequency. This mapping relationship can be stored using a key-value mapping table, a counting array, or a set structure with a counter. Auxiliary fields such as the source marker, timestamp range, and unique serial number set of the positioning device corresponding to the address record are also retained to constrain the statistical scope in subsequent clustering analysis. The installation address set and the activation address set of the positioning devices are traversed and counted separately to avoid mixing installation and activation sources in the statistics, which could cause frequency shifts. This ensures that recurring installation addresses and recurring activation addresses can form their own frequency distributions.
[0059] Cluster analysis is performed based on frequency of occurrence. This analysis determines whether there are significantly high-frequency address representations in the frequency distribution. The analysis input includes the mapping relationship between address representations and frequency of occurrence, along with a preset repetition threshold. The repetition threshold serves as a boundary to distinguish between occasional and clustered occurrences. The repetition threshold can be set as a fixed threshold, such as using an integer number of occurrences as the boundary; it can also be set as a tiered threshold, such as setting different repetition thresholds for different city levels, different channel sources, or different business cycles; or it can be set as a dynamic threshold, such as generating a repetition threshold based on set size, frequency mean, and dispersion. When generating a dynamic threshold, a lower limit constraint is set on the set size to avoid the threshold being too low due to a small sample size, leading to misjudgment of clustering. The comparison between frequency of occurrence and repetition threshold is performed at the address representation level. The comparison result generates a cluster marker. The cluster marker, address representation, and frequency of occurrence together constitute a traceable determination record, which can be used in subsequent address identification processes to maintain consistency in the determination criteria.
[0060] When a first duplicate address record with a frequency greater than the duplication threshold exists in the set of installation addresses for the positioning device, this first duplicate address record is identified as a duplicate installation address. The first duplicate address record represents a set of address records or address expression entries in the set of installation addresses that meet the judgment criteria. The identification action writes the first duplicate address record into the output structure of the duplicate installation addresses. The output structure can be a list of duplicate installation addresses or a set of duplicate installation addresses with a frequency field. The format with the frequency field is used to retain aggregation strength information in subsequent processing. If the set of installation addresses for the positioning device contains multiple address expression forms with frequencies greater than the duplication threshold, the first duplicate address record can contain multiple entries. The order of these entries can be determined based on descending frequency, timestamp span, or source marker weight. The order only affects the output presentation order and does not change the judgment result of the duplicate installation address.
[0061] When a second duplicate address record appears in the active address set of the positioning device with a frequency greater than the duplication threshold, the second duplicate address record is identified as a duplicate active address. This second duplicate address record represents a set of address records or address representation entries in the active address set that meet the judgment criteria. The identification process writes the second duplicate address record into the output structure of the duplicate active address. The output structure maintains the same data structure as the duplicate installation address to support unified referencing of both types of duplicate addresses in subsequent processing. The frequency statistics of the active address set of the positioning device may be affected by fluctuations in the accuracy of network access location data. Clustering analysis can introduce a gridded accuracy level into the address representation. The accuracy level is used to unify the spatial granularity after coordinate transformation, allowing active address records within the same geographical area to be aggregated statistically, reducing frequency dispersion caused by minor coordinate drift. The output structure of the duplicate active address can simultaneously retain both the accuracy level field and the frequency field to support the joint constraints of the activation address clustering degree and spatial granularity in subsequent processing.
[0062] This embodiment establishes frequency statistics for the installation address set and the activation address set of positioning devices, respectively, using address representation as the grouping key. Based on the frequency of occurrence and the repetition threshold, it performs clustering analysis and condition judgment. This enables stable identification of recurring installation addresses and recurring activation addresses under the respective statistical calibers of installation source and activation source. It reduces misjudgments and omissions caused by mixed sources, differences in address representation, or fluctuations in positioning accuracy, ensuring that subsequent address identification and association retrieval have a consistent input basis and traceable judgment criteria.
[0063] In one embodiment, step S40 above includes: S401, Construct a feature data record template that includes an address numeric field and an exception attribute field; S402, write the repeated installation address and / or the repeated activation address into the address value field of the feature data record template respectively, and set the corresponding abnormal attribute field to the aggregation abnormal state; S403, generate a blacklist of retrieval data based on the feature data record template after writing is complete and fields are set, and use the address entries in the blacklist of retrieval data as abnormal feature addresses.
[0064] In this embodiment, the processing of recurring installation addresses and recurring activation addresses as abnormal feature addresses is accomplished using structured records. Feature data record templates are used to define the format for carrying address information and abnormal status information. The address value field stores address representations that can be used for equivalence matching. Address representations can be standardized address strings, structured key values formed by concatenating administrative division and street address fields, grid codes after coordinate transformation, or composite key values composed of standardized address strings and grid codes. Composite key values are used to balance text consistency and spatial proximity. The abnormal attribute field stores abnormal status markers. Abnormal status markers use clustered abnormal states to indicate that the address meets the abnormality judgment condition due to its clustered frequency. Clustered abnormal states can be designed as enumerated values, status codes, or bit flag fields. Bit flag fields can superimpose different abnormal source markers within the same abnormal attribute field without changing the field name. The construction of feature data record templates can be represented by creating an in-memory record structure, creating a persistent table structure, and creating a serialized structure with field constraints. Field constraints include field type constraints, length constraints, character set constraints, null value constraints, and primary key constraints. The primary key constraint can be set as an address numeric field to avoid duplicate writing to the same address, which would lead to record redundancy. At the same time, the frequency field is retained to record the clustering strength without changing the definition method of abnormal feature addresses.
[0065] When repeatedly occurring installation addresses and activation addresses are written into the address value field of the feature data record template, the writing granularity is based on address entries. These address entries come from the identification result set of repeatedly occurring installation and activation addresses. The writing action and field setting action are completed within the same record context to form directly searchable abnormal address records. Separate writing is used to maintain the traceability of installation and activation source inputs. A source marker field can be added during writing to distinguish between installation and activation sources without changing the definitions of the address value field and the abnormal attribute field. When the abnormal attribute field is set to a clustered abnormal state, the setting action and the address value field writing action maintain the same correspondence, ensuring that each written address entry carries a clustered abnormal state marker, avoiding retrieval bias caused by the existence of address entries but the absence of the abnormal attribute field. After writing and field setting, the feature data record template indicates that each record in the template simultaneously satisfies two conditions: the address value field has been written and the abnormal attribute field has been set to a clustered abnormal state. These two conditions serve as input thresholds for generating the retrieval blacklist, ensuring a consistent binding relationship between address entries in the retrieval blacklist and their clustered abnormal states.
[0066] When generating a retrieval blacklist based on a feature data record template that has been written and its fields set, the retrieval blacklist serves as a searchable data structure to hold a set of abnormal candidate addresses. The generation process can involve filtering records from the feature data record template whose abnormal attribute fields equal clustered abnormal states and extracting the address value field to form a list structure. This list structure can be an array, set, inverted index key set, or hash set. Hash sets improve the efficiency of subsequent equality searches, while inverted index key sets support word segmentation or prefix matching of the address value field without altering the source of the address entries. To avoid duplicate entries caused by synonymous address expressions, a merging process can be performed on the address value field during the retrieval blacklist generation process. This merging process normalizes multiple address expressions for the same spatial location based on standardization rules. The normalized address expression is then written as an address entry into the retrieval blacklist. The normalization process does not change the name of the address value field; it only changes the form of the written value. When using address entries from the blacklist as abnormal feature addresses, the source of the abnormal feature address set is limited to the set of address entries from the blacklist. The output format of the abnormal feature address can be a list of address entries, a set of address entries, or an address entry structure with a status field. In the structure with a status field, the abnormal status is consistently associated with the address entry to ensure that the basis for abnormal judgment is traceable in subsequent processing stages.
[0067] This embodiment constructs a feature data record template containing address value fields and abnormal attribute fields. While writing recurring installation addresses and recurring activation addresses, it sets the abnormal attribute fields to clustered abnormal states. Then, based on the feature data record template after writing and setting the fields, it generates a search blacklist and uses the address entries in the search blacklist to determine abnormal feature addresses. This gives abnormal feature addresses a unified field carrying format and a consistent source of abnormal state marking, reducing the instability of abnormal address sets caused by inconsistent address expressions and missing states. At the same time, it provides a search blacklist data structure that can be directly used for subsequent retrieval matching based on abnormal feature addresses.
[0068] In one embodiment, step S50 above includes: S501, perform a conditional search on the device database based on the abnormal feature address, filter out all associated controlled carriers that have undergone installation or activation operations at the abnormal feature address, and generate a candidate carrier identifier list; S502, extract the carrier identification information of the controlled carriers involved in the known abnormal usage events, and construct a known carrier exclusion set; S503, perform set difference processing on the candidate carrier identifier list and the known carrier exclusion set to exclude carrier identifier information in the candidate carrier identifier list that belongs to the known carrier exclusion set; S504, the controlled carriers corresponding to the remaining carrier identifier information in the candidate carrier identifier list after set difference processing are used as other controlled carriers.
[0069] In this embodiment, the conditional retrieval of the device database based on abnormal feature addresses is completed using address entries as the retrieval entry point. The abnormal feature addresses are derived from address entries in the blacklist. The conditional retrieval is set around a combination of address matching conditions and operation type conditions. Address matching conditions are used to map abnormal feature addresses to installation and activation operation records in the device database. Mapping methods can include address equivalence matching, address standardization equivalence matching, coordinate transformation-based grid encoding equivalence matching, or pre-storing an address standardization result field in the device database and using that field as the matching key. Operation type conditions are used to limit the record to correspond to either an installation or activation operation. Installation operations can be determined by the operation type field, installation status field, or installation time field corresponding to the device initialization installation log. Activation operations can be determined by the activation status field, network event type field, or activation time field corresponding to the device's first network activation log. The output of conditional retrieval targets associated controlled carriers. The binding relationship between controlled carriers and positioning devices in the device database can be expressed by the binding records of controlled carrier identification information and positioning device unique serial numbers. Conditional retrieval can complete address matching, operation type filtering, and binding relationship association in the same query. Alternatively, it can first locate the set of unique serial numbers of positioning devices that meet the installation or activation operation based on abnormal feature addresses, and then reversely associate the controlled carrier identification information based on the set of unique serial numbers of positioning devices. After filtering out all associated controlled carriers that have undergone installation or activation operations at abnormal feature addresses, a candidate carrier identification list is generated. The elements of the candidate carrier identification list are expressed using carrier identification information. The values of the carrier identification information come from the controlled carrier identification information field in the device database or the primary key field that is equivalent to the controlled carrier identification information. When generating the candidate carrier identification list, set deduplication can be performed simultaneously to avoid the same controlled carrier being included repeatedly due to multiple installation or activation operations.
[0070] The process of extracting carrier identification information from controlled carriers involved in known abnormal usage events and constructing a known carrier exclusion set is completed using the input set of known abnormal usage events as the data source. The controlled carriers involved in the known abnormal usage events have already been expressed as controlled carrier identification information in the preceding processing. The extraction of carrier identification information is used to unify the comparison granularity between the candidate carrier identification list and the known carrier exclusion set. The extraction action can be manifested as extracting carrier identification information fields from the controlled carrier identification information set associated with the known abnormal usage events and forming a set structure. The set structure can adopt a hash set, a sorted set, or a bitmap mapping set. The hash set is used to support fast member determination, the sorted set is used to support range scanning and batch exclusion, and the bitmap mapping set is used to reduce storage overhead when the carrier identification information can be mapped to consecutive numbers. When constructing the known carrier exclusion set, the expression of the carrier identification information is kept consistent with the candidate carrier identification list to avoid exclusion failure due to format differences. Format consistency can be achieved through methods such as unifying capitalization, removing delimiters, fixed-length padding, and checksum processing. The processing result is still carried in the name of carrier identification information, without changing the field names.
[0071] The set difference processing, which compares the candidate carrier identifier list with the known carrier exclusion set, is performed using exclusion logic as a constraint. The set difference processing uses the candidate carrier identifier list as the filtering set and the known carrier exclusion set as the exclusion set. In implementation, it can either perform member determination on each candidate carrier identifier in the list and remove carrier identifiers that match the known carrier exclusion set, or it can perform difference filtering on the device database side through connection and exclusion condition deduction and directly output the candidate carrier identifier list after difference processing. Member determination is based on carrier identifier information equivalence matching. The input and output of equivalence matching retain the carrier identifier name. The remaining carrier identifier information in the candidate carrier identifier list after set difference processing is used to represent candidate results for carriers that meet the address and operation type conditions and are not involved in the known abnormal usage events. To ensure the determinism of set difference processing, the candidate carrier identifier list can be sorted or bucketed before set difference processing. This ensures a stable output order when the same batch of processing is repeatedly executed, with the sorting key still based on the carrier identifier information, without changing the structural definition of the candidate carrier identifier list.
[0072] The remaining controlled carriers corresponding to the carrier identifier information in the candidate carrier identifier list after set subtraction are treated as other controlled carriers, with the goal of restoring the mapping relationship. The mapping relationship from carrier identifier information to controlled carriers comes from the controlled carrier master record or binding record in the device database. The mapping method can be to use the carrier identifier information as the primary key to retrieve the controlled carrier entity record, or to use the carrier identifier information to associate with the binding record of the controlled carrier and the positioning device and retrieve the controlled carrier field set. Other controlled carriers are treated as output objects, maintaining consistency with the previous definition. The output format can be a set of controlled carrier entity records, a set of controlled carrier identifier information, or a combined record set containing the controlled carrier identifier information and the unique serial number of the associated positioning device. The combined record set is used to directly locate the unique serial number of the positioning device and the corresponding log record entry when it is necessary to trace the source of the installation or activation operation. The element range of the output set is strictly limited by the candidate carrier identifier list after set subtraction to ensure that other controlled carriers meet the abnormal characteristic address triggering conditions and satisfy the constraint of excluding controlled carriers involved in known abnormal usage events.
[0073] This embodiment performs conditional retrieval on the device database based on abnormal feature addresses to generate a candidate carrier identifier list. Then, it extracts the carrier identifier information of controlled carriers involved in known abnormal usage events to construct a known carrier exclusion set. Subsequently, it performs set difference processing between the candidate carrier identifier list and the known carrier exclusion set, and determines the controlled carriers corresponding to the remaining carrier identifier information as other controlled carriers. This enables the associated controlled carriers triggered by abnormal feature addresses to be accurately retrieved and filtered in the device database. At the same time, it excludes the controlled carriers involved in known abnormal usage events from the candidate range, improving the purity and reusability of the results outputting other controlled carriers, and reducing the subsequent processing costs caused by repeated inclusion of known objects in the set.
[0074] In one embodiment, step S60 above includes: S601, Traverse the other controlled carriers, use the identification information of the other controlled carriers to initiate a query request to the usage permission record database, and parse out the associated user identity information from the returned usage permission binding records; S602, Identify abnormal feature addresses that are installation addresses or activation addresses of other controlled carriers, and use the abnormal feature addresses as evidence for risk tracing; S603, aggregate the parsed user identity information, other corresponding controlled carriers, and the risk tracing evidence to obtain risk-related entries; S604, summarize all generated risk-related entries to obtain a list of potential abnormal users containing evidence of risk tracing.
[0075] In this embodiment, traversing other controlled carriers is used to form an executable query sequence. The traversal unit establishes a traversal cursor at the granularity of other controlled carriers. The cursor input is the set of other controlled carriers, and the cursor output is the identification information of other controlled carriers output one by one or in batches. The identification information of other controlled carriers is used as a key parameter of the query request to access the usage permission record database. The query request may include a carrier identification field, a query time field, and a permission status field. The query time field is used to limit the effective range of the permission relationship, and the permission status field is used to limit whether the returned record is in an effective or available state. The usage permission record database returns usage permission binding records to the query request. The field set of the usage permission binding record includes a controlled carrier identification information field, a user identity information field, a permission effective time field, a permission expiration time field, and a permission type field. The parsing action takes the usage permission binding record as input, and the parsing result outputs the user identity information. In the same parsing process, the controlled carrier identification information corresponding to the user identity information is retained to avoid mismatch between the subject information and the carrier information in the subsequent aggregation stage. There may be multiple records that match the same identifier information of other controlled carriers when using permission binding records. The parsing process can determine the priority based on the permission effective time field and the permission expiration time field, and output a unique user identity information by adopting a strategy of prioritizing the most recently effective record, prioritizing the non-expired record, or prioritizing the permission type field. The parsing process can also output multiple user identity information and retain a multi-subject coexistence mark in the risk association entry to express the situation where the same controlled carrier corresponds to different users at different time periods.
[0076] Anomaly address, as evidence for risk tracing, needs to establish a verifiable association with other controlled carriers. The identification process is constrained by the installation or activation address of these other controlled carriers. To establish this constraint, the correspondence between the anomaly address and the installation or activation operation can originate from the installation address field or activation address field recorded in the device database, or from address fields extracted from the device initialization installation log and the device's first network activation log. The identification process uses the identification information of other controlled carriers as an index to retrieve the installation address and activation address records associated with those carriers. Then, it performs address equivalence matching, address-standardized equivalence matching, or coordinate-transformed encoded equivalence matching with the anomaly address. A match confirms that the anomaly address belongs to the installation or activation address of another controlled carrier. Risk tracing evidence is carried by the anomaly address, along with a matching source marker to distinguish between installation address and activation address matches. A matching time field can also be included to express the installation or activation operation time, providing a traceable time anchor for the risk tracing evidence.
[0077] Data aggregation is used to organize user identity information, other controlled carriers, and risk tracing evidence into a unified data unit. The aggregation key can be a combination of user identity information and other controlled carrier identification information. The combination key is used to distinguish cases where the same user identity information is associated with multiple controlled carriers, and also to distinguish cases where the same other controlled carrier is mapped to different user identity information at different time periods. The aggregation output is a risk association entry. The field set of the risk association entry includes at least the user identity information field, the other controlled carrier identification information field, the abnormal feature address field, the hit type field, and the time field. The hit type field is used to express whether the installation address hit or the activation address hit, and the time field is used to express the installation operation time or the activation operation time. Risk-related entries can have statistical fields added to improve the list's discriminative capabilities. These statistical fields include the number of times an anomaly-featured address is hit, the number of hit addresses, the hit time span, and the permission type field. The number of times an anomaly-featured address is hit is obtained by aggregating the number of records where the same other controlled vehicle performs installation or activation operations at the same anomaly-featured address. The number of hit addresses is obtained by deduplicating the counts of other controlled vehicles associated with the same user's identity information across different anomaly-featured addresses. The hit time span is obtained by the difference between the earliest and latest hit times. The permission type field comes from the usage permission binding records and is used to express the differences in usage permission categories.
[0078] All generated risk association entries are aggregated to form a list of potential abnormal users. The aggregated input is a set of risk association entries, and the aggregated output is the list of potential abnormal users. The list of potential abnormal users can be organized using a grouped list structure based on user identity information. Each group contains a subset of risk association entries corresponding to that user identity information and a risk tracing evidence description field. The risk tracing evidence description field is generated by combining the abnormal feature address field, hit type field, and time field from the risk association entries, or it can be generated by combining the number of abnormal feature address hits, the number of hit addresses, and the hit time span. The aggregation stage can introduce deduplication and merging strategies. Deduplication is used to eliminate duplicate entries with the same user identity information and the same other controlled carrier identification information on the same abnormal feature address. Merging is used to combine multiple risk association entries with the same user identity information on the same abnormal feature address into one and accumulate the number of abnormal feature address hits. The list of potential anomaly users can include a sorting field to ensure a stable review order during output. The sorting field can prioritize the number of hit addresses, the number of hits of anomaly characteristic addresses, or the hit time span. The sorting field is derived from risk-related entries or their aggregation results, and the consistent mapping relationship between the risk tracing evidence and the corresponding risk-related entries is maintained after sorting.
[0079] For example, in financial leasing, the risk control system maintains a contract vehicle list to record key ledger data such as contract number, vehicle identification number (VIN), and customer information. The vehicle networking system maintains a GPS data list to record equipment monitoring data such as contract number, VIN, GPS device number, GPS installation address, and GPS activation address. During a post-loan monitoring session, clues such as concentrated overdue payments, suspected rental fraud, and abnormal loss of contact were discovered. Risk investigators confirmed in their investigation records that the same risk group involved multiple fraudulent customers and multiple vehicles, generating corresponding known abnormal usage events on the risk control system side. Based on these known abnormal usage events, the risk control system generates anomaly investigation instructions. These instructions carry parameters such as event identifier, subject identifier, business domain identifier, and effective time range. Parsing the instructions yields a list of abnormal users. Using this list as a search index, the system accesses the usage permission record database. It retrieves target usage permission records that are bound to the list of abnormal users from the usage permission binding records. The system then iterates through these records and parses the controlled carrier identification information, which in this scenario is expressed as fields such as contract number and VIN. The format validation and set deduplication processing of the parsed controlled carrier identification information are performed to eliminate duplicate identifiers caused by duplicate authorization records and historical change records, and obtain a set of multiple controlled carrier identification information involved in known abnormal usage events.
[0080] After receiving multiple sets of controlled carrier identification information, the vehicle-to-everything (V2X) system uses the controlled carrier identification information as a query index in the device database to retrieve the unique serial number of the positioning device that is bound to the controlled carrier identification information, thus establishing a correspondence between the contract number or vehicle identification number and the GPS device number under the same binding semantics. Based on the unique serial number of the positioning device, the system retrieves the device initialization installation log and the device first network activation log from the device database. The device initialization installation log records event data when the GPS locator completes installation initialization, and the device first network activation log records event data when the GPS locator first connects to the monitoring platform and completes activation confirmation. Physical installation location data is extracted from the device initialization installation log. This physical installation location data can come from the location field recorded in the installation work order, the location field entered by the installer, or the inverse solution result of the coordinates collected during installation. Network access location data is extracted from the device first network activation log. This network access location data can come from the inverse solution result of the coordinates reported during the first positioning, the initial network access positioning result, or the geographic mapping result of the access point. Address standardization and coordinate transformation are performed on physical installation location data and network access location data. Address standardization is used to unify the differences in the expression of provinces, cities, districts, roads, addresses, and park names. Coordinate transformation is used to unify the coordinate system and generate alignable grid codes or standardized coordinate expressions. This generates a set of positioning device installation addresses and a set of positioning device activation addresses, respectively, and makes these two sets correspond in a consistent way with the GPS installation addresses and GPS activation addresses in the GPS data list.
[0081] After the sets of installation addresses and activation addresses of positioning devices are formed, the vehicle-to-everything (V2X) system traverses the address records in both sets, groups them according to address standards, and determines the frequency of occurrence of each address record. The frequency of occurrence indicates the degree of clustering of the same installation address or activation address across multiple controlled carriers. Clustering analysis is performed based on the frequency of occurrence, comparing it with a preset repetition threshold. The repetition threshold distinguishes between occasional and clustered occurrences. If a first repetitive address record exists in the installation address set with a frequency greater than the repetition threshold, it is identified as a recurring installation address. Similarly, if a second repetitive address record exists in the activation address set with a frequency greater than the repetition threshold, it is identified as a recurring activation address. In this scenario, recurring installation addresses may correspond to a location where multiple vehicles are centrally equipped with GPS trackers at a repair shop or vehicle dealership, while recurring activation addresses may correspond to a parking lot, park, or a location where GPS trackers are centrally activated. In a risk control context, the clustering significance of these two types of addresses corresponds to risk signals related to concentrated operation points and concentrated activation points in a group case.
[0082] To facilitate subsequent retrieval and referencing, the vehicle-to-everything (V2X) system identifies recurring installation addresses and recurring activation addresses as anomalous feature addresses. This is achieved by using feature data record templates to carry anomalous address entries. These templates include address value fields and anomalous attribute fields. The address value field contains the standard expression for the recurring installation address or recurring activation address, while the anomalous attribute field is set to an aggregated anomalous state, ensuring each address entry carries a clear anomalous attribute. Based on the completed feature data record templates with defined fields, a retrieval blacklist is generated. This blacklist contains a set of address entries for matching, and these entries are used as anomalous feature addresses, thus forming a set of anomalous addresses that can be directly used for device database retrieval.
[0083] The vehicle-to-everything (V2X) system performs conditional searches on the device database based on abnormal feature addresses. These searches include both address matching and operation type conditions. Address matching conditions are used to match address fields or convertible fields in the device initialization installation log and the device's first network activation log. Operation type conditions are used to limit the records to corresponding installation or activation operations. All associated controlled vehicles that have undergone installation or activation operations at the abnormal feature addresses are filtered out, and a candidate vehicle identifier list is generated accordingly. To avoid duplicate inclusion of vehicles already identified in known abnormal usage events, the V2X system extracts the vehicle identifier information of the controlled vehicles involved in known abnormal usage events to construct a known vehicle exclusion set. The candidate vehicle identifier list and the known vehicle exclusion set are then compared using a set difference process. Vehicle identifier information belonging to the known vehicle exclusion set is excluded from the candidate vehicle identifier list. The remaining controlled vehicles corresponding to the vehicle identifier information in the candidate vehicle identifier list after the set difference process are designated as other controlled vehicles. This output corresponds to more potential risk contract numbers and vehicle identification numbers in the original business context, covering associated vehicles in the same case that have not yet been discovered during the investigation phase.
[0084] After obtaining information about other controlled carriers, the risk control system or vehicle network system proceeds to the entity backtracking and list aggregation stage. It iterates through these other controlled carriers, using their identification information to initiate query requests to the usage permission record database. From the returned usage permission binding records, it parses the associated user entity identity information, establishing a traceable correspondence between vehicle assets and entity dimensions such as lessees, users, and authorized users. To enhance the verifiability of the investigation, it identifies abnormal characteristic addresses that serve as installation or activation addresses for other controlled carriers, using these abnormal characteristic addresses as risk tracing evidence. This evidence may include fields such as the abnormal characteristic address text, hit type, and time range. The parsed user entity identity information, corresponding other controlled carriers, and risk tracing evidence are aggregated to obtain risk association entries. Each risk association entry is represented by a structured record expressing the association between the entity, vehicle, and abnormal address. By summarizing all generated risk-related entries, a list of potential abnormal users containing evidence of risk tracing is obtained. The list of potential abnormal users can be grouped and displayed according to the user's identity information, showing the associated contract number or vehicle identification number set and the set of abnormal characteristic addresses. This facilitates risk control personnel in financial scenarios to perform further verification, link black and gray lists, adjust credit strategies, trigger margin and recovery strategies, and prepare asset disposal plans. It also provides risk investigators with a structured list of investigation targets for telephone verification, offline verification, and evidence preservation.
[0085] This embodiment traverses other controlled carriers and initiates a query request to the usage permission record database using the identification information of other controlled carriers. It parses the associated user identity information from the usage permission binding records, and then matches the abnormal feature addresses with the installation address or activation address dimensions of other controlled carriers as risk tracing evidence. Subsequently, it performs data aggregation on the user identity information, other controlled carriers, and risk tracing evidence to obtain risk-related entries and summarizes them to form a potential abnormal user list containing risk tracing evidence descriptions. This allows the abnormal aggregation information at the controlled carrier level to be mapped to the user identity information dimension and output as structured entries. At the same time, it retains evidence elements such as abnormal feature addresses, hit types, and times in the list, improving the verifiability and traceability of the potential abnormal user list and reducing the investigation bias caused by the lack of association between user identity information and other controlled carriers.
[0086] In one embodiment, an abnormal feature address association user identification device is provided, which corresponds one-to-one with the abnormal feature address association user identification method in the above embodiments. (Refer to...) Figure 3 , Figure 3 This is a schematic diagram of the functional modules of a preferred embodiment of the abnormal feature address association device of the present invention. The modules include: abnormal event parsing module 10, device log parsing module 20, address frequency analysis module 30, abnormal address marking module 40, carrier reverse lookup filtering module 50, and subject association generation module 60. Detailed descriptions of each functional module are as follows: The abnormal event parsing module 10 is used to obtain the identification information of multiple controlled carriers involved in known abnormal usage events; The device log parsing module 20 is used to extract, based on the controlled carrier identification information, a set of location device installation addresses and a set of location device activation addresses associated with the controlled carrier identification information from the device database; The address frequency analysis module 30 is used to identify recurring installation addresses and / or recurring activation addresses from the set of installation addresses of the positioning device and the set of activation addresses of the positioning device; The abnormal address marking module 40 is used to identify the repeated installation address and / or the repeated activation address as abnormal feature addresses; The carrier reverse lookup and filtering module 50 is used to search the device database for other controlled carriers besides those involved in the known abnormal usage events, which have been installed or activated at the abnormal feature address, based on the abnormal feature address. The subject association generation module 60 is used to obtain the user subject identity information associated with the other controlled carriers, and generate a list of potential abnormal users based on the user subject identity information.
[0087] In one embodiment, the exception event parsing module 10 is specifically used for: Receive an anomaly investigation instruction generated for a known abnormal usage event, parse the anomaly investigation instruction, and extract a list of abnormal users involved in the known abnormal usage event from the anomaly investigation instruction; Using the list of abnormal users as a search index, access the usage permission record database and retrieve the target usage permission record that is bound to the list of abnormal users. Traverse the target access permission records and parse out the bound controlled carrier identification information from each target access permission record; The parsed controlled carrier identification information is subjected to format verification and set deduplication, and the set of controlled carrier identification information after format verification and set deduplication is used as multiple controlled carrier identification information.
[0088] In one embodiment, the device log parsing module 20 is specifically used for: Using the controlled carrier identification information as a query index, the device database is accessed to retrieve the unique serial number of the positioning device that is bound to the controlled carrier identification information; Based on the unique serial number of the positioning device, retrieve the corresponding device initialization installation log and device first network activation log from the device database; Extract physical installation location data from the device initialization installation log, and extract network access location data from the device's first network activation log; The physical installation location data and the network access location data are processed by address standardization and coordinate transformation to generate a set of installation addresses for positioning devices and a set of activation addresses for positioning devices, respectively.
[0089] In one embodiment, the address frequency analysis module 30 is specifically used for: The address records in the set of installation addresses of the positioning device and the set of activation addresses of the positioning device are traversed respectively to determine the frequency of occurrence of each address record; Clustering analysis is performed based on the occurrence frequency to determine whether the occurrence frequency is greater than a preset repetition threshold; When there is a first duplicate address record in the set of installation addresses of the positioning device that appears more frequently than the duplicate threshold, the first duplicate address record is identified as a duplicate installation address. When there is a second duplicate address record in the set of active addresses of the positioning device that appears more frequently than the duplicate threshold, the second duplicate address record is identified as a duplicate active address.
[0090] In one embodiment, the abnormal address marking module 40 is specifically used for: Construct a feature data record template that includes address numeric fields and exception attribute fields; Write the repeated installation address and / or the repeated activation address into the address value field of the feature data record template, and set the corresponding abnormal attribute field to the clustered abnormal state. A blacklist is generated based on the feature data record template after writing is complete and the fields are set, and the address entries in the blacklist are used as abnormal feature addresses.
[0091] In one embodiment, the carrier reverse lookup and filtering module 50 is specifically used for: Based on the abnormal feature address, a conditional search is performed on the device database to filter out all associated controlled carriers that have undergone installation or activation operations at the abnormal feature address, and a candidate carrier identifier list is generated. Extract the carrier identification information of the controlled carriers involved in the known abnormal usage events, and construct a known carrier exclusion set; The candidate carrier identifier list is compared with the known carrier exclusion set by performing set difference processing to exclude carrier identifier information in the candidate carrier identifier list that belongs to the known carrier exclusion set; The controlled carriers corresponding to the remaining carrier identifier information in the candidate carrier identifier list after set difference processing are used as other controlled carriers.
[0092] In one embodiment, the subject association generation module 60 is specifically used for: Traverse the other controlled carriers, use the identification information of the other controlled carriers to initiate a query request to the usage permission record database, and parse out the associated user identity information from the returned usage permission binding records; Identify abnormal feature addresses that serve as installation or activation addresses for other controlled carriers, and use these abnormal feature addresses as evidence for risk tracing. The parsed user identity information, other corresponding controlled carriers, and the risk tracing evidence are aggregated to obtain risk-related entries; By summarizing all generated risk-related entries, a list of potential anomalous users containing evidence of risk tracing is obtained.
[0093] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 4As shown. The computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides determination and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external clients via a network connection. When the computer program is executed by the processor, it implements a function or step on the server side using an abnormal feature address association method for subject identification.
[0094] In one embodiment, a computer device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 5 As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides determination and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When executed by the processor, the computer program implements a client-side function or procedure using an abnormal feature address association subject identification method.
[0095] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps: Obtain the identification information of multiple controlled carriers involved in known abnormal usage events; Based on the controlled carrier identification information, extract the set of positioning device installation addresses and the set of positioning device activation addresses associated with the controlled carrier identification information from the device database; Identify recurring installation addresses and / or recurring activation addresses from the set of installation addresses of the positioning devices and the set of activation addresses of the positioning devices; The repeated installation addresses and / or the repeated activation addresses are identified as abnormal feature addresses; Based on the abnormal feature address, search the device database for other controlled carriers besides those involved in the known abnormal usage events, and which have undergone installation or activation operations at the abnormal feature address. Obtain the user identity information associated with the other controlled carriers, and generate a list of potentially abnormal users based on the user identity information.
[0096] In one embodiment, a computer-readable storage medium is provided, which may be non-volatile or volatile, and a computer program is stored thereon, which, when executed by a processor, performs the following steps: Obtain the identification information of multiple controlled carriers involved in known abnormal usage events; Based on the controlled carrier identification information, extract the set of positioning device installation addresses and the set of positioning device activation addresses associated with the controlled carrier identification information from the device database; Identify recurring installation addresses and / or recurring activation addresses from the set of installation addresses of the positioning devices and the set of activation addresses of the positioning devices; The repeated installation addresses and / or the repeated activation addresses are identified as abnormal feature addresses; Based on the abnormal feature address, search the device database for other controlled carriers besides those involved in the known abnormal usage events, and which have undergone installation or activation operations at the abnormal feature address. Obtain the user identity information associated with the other controlled carriers, and generate a list of potentially abnormal users based on the user identity information.
[0097] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.
[0098] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0099] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0100] It should be noted that any software tools or components not belonging to this company appearing in the embodiments of this application are merely illustrative examples and do not represent actual use. All user personal information involved in the embodiments of this application has been authorized (with knowledge and consent) by the relevant parties or has been fully authorized by all parties, and the executing entity may obtain it through various legal and compliant means. The collection, storage, use, processing, transmission, provision, and disclosure of the information, data, and signals involved all comply with relevant laws and regulations and do not violate public order and good morals.
[0101] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A method for identifying entities using abnormal feature address association, characterized in that, Includes the following steps: Obtain the identification information of multiple controlled carriers involved in known abnormal usage events; Based on the controlled carrier identification information, extract the set of positioning device installation addresses and the set of positioning device activation addresses associated with the controlled carrier identification information from the device database; Identify recurring installation addresses and / or recurring activation addresses from the set of installation addresses of the positioning devices and the set of activation addresses of the positioning devices; The repeated installation addresses and / or the repeated activation addresses are identified as abnormal feature addresses; Based on the abnormal feature address, search the device database for other controlled carriers besides those involved in the known abnormal usage events, and which have undergone installation or activation operations at the abnormal feature address. Obtain the user identity information associated with the other controlled carriers, and generate a list of potentially abnormal users based on the user identity information.
2. The abnormal feature address association subject identification method as described in claim 1, characterized in that, Obtain the identification information of multiple controlled carriers involved in known abnormal usage events, including: Receive an anomaly investigation instruction generated for a known abnormal usage event, parse the anomaly investigation instruction, and extract a list of abnormal users involved in the known abnormal usage event from the anomaly investigation instruction; Using the list of abnormal users as a search index, access the usage permission record database and retrieve the target usage permission record that is bound to the list of abnormal users. Traverse the target access permission records and parse out the bound controlled carrier identification information from each target access permission record; The parsed controlled carrier identification information is subjected to format verification and set deduplication, and the set of controlled carrier identification information after format verification and set deduplication is used as multiple controlled carrier identification information.
3. The abnormal feature address association subject identification method as described in claim 1, characterized in that, Based on the controlled carrier identification information, the set of location device installation addresses and the set of location device activation addresses associated with the controlled carrier identification information are extracted from the device database, including: Using the controlled carrier identification information as a query index, the device database is accessed to retrieve the unique serial number of the positioning device that is bound to the controlled carrier identification information; Based on the unique serial number of the positioning device, retrieve the corresponding device initialization installation log and device first network activation log from the device database; Extract physical installation location data from the device initialization installation log, and extract network access location data from the device's first network activation log; The physical installation location data and the network access location data are processed by address standardization and coordinate transformation to generate a set of installation addresses for positioning devices and a set of activation addresses for positioning devices, respectively.
4. The abnormal feature address association subject identification method as described in claim 1, characterized in that, Identifying recurring installation addresses and / or recurring activation addresses from the set of installation addresses and the set of activation addresses of the positioning devices includes: The address records in the set of installation addresses of the positioning device and the set of activation addresses of the positioning device are traversed respectively to determine the frequency of occurrence of each address record; Clustering analysis is performed based on the occurrence frequency to determine whether the occurrence frequency is greater than a preset repetition threshold; When there is a first duplicate address record in the set of installation addresses of the positioning device that appears more frequently than the duplicate threshold, the first duplicate address record is identified as a duplicate installation address. When there is a second duplicate address record in the set of active addresses of the positioning device that appears more frequently than the duplicate threshold, the second duplicate address record is identified as a duplicate active address.
5. The abnormal feature address association subject identification method as described in claim 1, characterized in that, Identify the recurring installation address and / or the recurring activation address as abnormal characteristic addresses, including: Construct a feature data record template that includes address numeric fields and exception attribute fields; Write the repeated installation address and / or the repeated activation address into the address value field of the feature data record template, and set the corresponding abnormal attribute field to the clustered abnormal state. A blacklist is generated based on the feature data record template after writing is complete and the fields are set, and the address entries in the blacklist are used as abnormal feature addresses.
6. The abnormal feature address association subject identification method as described in claim 1, characterized in that, Based on the abnormal feature address, search the device database for other controlled carriers besides those involved in the known abnormal usage events, which have undergone installation or activation operations at the abnormal feature address, including: Based on the abnormal feature address, a conditional search is performed on the device database to filter out all associated controlled carriers that have undergone installation or activation operations at the abnormal feature address, and a candidate carrier identifier list is generated. Extract the carrier identification information of the controlled carriers involved in the known abnormal usage events, and construct a known carrier exclusion set; The candidate carrier identifier list is compared with the known carrier exclusion set by performing set difference processing to exclude carrier identifier information in the candidate carrier identifier list that belongs to the known carrier exclusion set; The controlled carriers corresponding to the remaining carrier identifier information in the candidate carrier identifier list after set difference processing are used as other controlled carriers.
7. The abnormal feature address association subject identification method as described in claim 1, characterized in that, Obtain the user entity identity information associated with the other controlled carriers, and generate a list of potentially abnormal users based on the user entity identity information, including: Traverse the other controlled carriers, use the identification information of the other controlled carriers to initiate a query request to the usage permission record database, and parse out the associated user identity information from the returned usage permission binding records; Identify abnormal feature addresses that serve as installation or activation addresses for other controlled carriers, and use these abnormal feature addresses as evidence for risk tracing. The parsed user identity information, other corresponding controlled carriers, and the risk tracing evidence are aggregated to obtain risk-related entries; By summarizing all generated risk-related entries, a list of potential anomalous users containing evidence of risk tracing is obtained.
8. A subject identification device for associating abnormal feature addresses, characterized in that, The abnormal feature address association using the subject identification device includes: The exception event parsing module is used to obtain the identification information of multiple controlled carriers involved in known exception usage events; The device log parsing module is used to extract, based on the controlled carrier identification information, the set of location device installation addresses and the set of location device activation addresses associated with the controlled carrier identification information from the device database; The address frequency analysis module is used to identify recurring installation addresses and / or recurring activation addresses from the set of installation addresses of the positioning device and the set of activation addresses of the positioning device; An abnormal address marking module is used to identify the repeated installation address and / or the repeated activation address as abnormal feature addresses; The carrier reverse lookup and filtering module is used to search the device database for other controlled carriers besides those involved in the known abnormal usage events, which have been installed or activated at the abnormal feature address, based on the abnormal feature address. The entity association generation module is used to obtain the user entity identity information associated with the other controlled carriers, and generate a list of potentially abnormal users based on the user entity identity information.
9. A computer device, characterized in that, The computer device includes a memory, a processor, and an abnormal feature address association user identification program stored in the memory and executable on the processor. When the abnormal feature address association user identification program is executed by the processor, it implements the steps of the abnormal feature address association user identification method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The storage medium stores an abnormal feature address association user identification program, which, when executed by a processor, implements the steps of the abnormal feature address association user identification method as described in any one of claims 1-7.