A local structured evidence chain generation method for protected principal controversial behavior, electronic equipment and storage medium
By acquiring and associating runtime events locally on the terminal device, generating structured evidence objects and deriving differentiated summary payloads, the problem of unified analysis and privacy protection of disputed behaviors of protected subjects is solved, and stable support for subsequent processing is provided.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HANZHONG BIG FRUIT TECHNOLOGY CO LTD
- Filing Date
- 2026-04-22
- Publication Date
- 2026-07-10
AI Technical Summary
Existing technologies lack a unified object for behavioral analysis in scenarios involving disputed behaviors of protected entities, making it impossible to generate differentiated summaries for different subsequent processing objects. Furthermore, they are prone to the leakage of original sensitive content, making it difficult to meet the needs of subsequent confirmation, review, and collaborative processing.
Multiple runtime events are acquired locally on the terminal device. Dispute behavior analysis objects are formed through time association, source association, and stage progression relationship. Local structured evidence objects are generated by extracting behavioral scene features and subject state features. Differentiated summary payloads are derived for different subsequent processing objects to avoid outputting original sensitive content.
It achieves a unified data object representation for disputed behaviors, meets the needs of different processing objects, reduces privacy risks, and provides a reliable basis for subsequent confirmation and collaborative processing.
Smart Images

Figure CN122364332A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of terminal-side behavior analysis, object-oriented behavior evidence retention, and structured evidence chain generation, and particularly to a local structured evidence chain generation method, electronic device, and computer-readable storage medium for disputed behaviors of protected subjects.
[0002] More specifically, the present invention relates to a technical solution for: acquiring multiple runtime events related to a target disputed behavior locally on a terminal device, associating and grouping the runtime events to form a disputed behavior analysis object, and generating a local structured evidence object and a structured summary payload for different subsequent processing objects based on the disputed behavior analysis object. Background Technology
[0003] With the continuous development of smart terminals, applications, and online interactions, scenarios involving minors, the elderly, and other end-users under protected modes engaging in disputed activities on terminal devices are increasingly common. Existing technical solutions for such subjects typically revolve around identity verification, access control, risk alerts, transaction blocking, or guardianship notifications. While these solutions can provide pre-emptive intervention or in-process alerts in some scenarios, they often lack a unified data object foundation for disputed activities that have already occurred or are nearing completion and may subsequently enter into guardianship confirmation, platform review, dispute resolution, or post-event verification processes. This makes it difficult to reliably support the usage needs of different users in subsequent processing.
[0004] On the other hand, most existing electronic evidence or behavioral tracking solutions focus on log storage, screen recording screenshots, blockchain evidence storage, timestamp fixing, general behavioral evidence collection, general risk auditing, or general evidence relationship modeling. These solutions typically have the following shortcomings: 1. Failed to construct a unified object of behavioral analysis around the disputed behavioral process of the protected subject; 2. Multiple runtime event objects were not organized into data objects that can be verified later; 3. There is a lack of mechanisms to derive summaries of different granularities from the same evidence object to different subsequent processing objects; 4. By default, it relies on the output or leakage of original sensitive content, increasing the risk to privacy boundaries.
[0005] In addition, some existing solutions directly focus on evidence chain generation, evidence chain fixation, evidence chain relationship model construction, or risk assessment based on evidence relationships. However, these solutions are usually not within the scope of the scenario of disputed behavior of the protected subject, and they do not solve the problem of organizing multiple runtime events into disputed behavior analysis objects, forming local structured evidence objects, and deriving differentiated summary payloads for different subsequent processing objects locally on the terminal.
[0006] Therefore, a new technical solution is still needed that can correlate and merge multiple runtime events locally on the terminal device to form a dispute behavior analysis object, and generate a local structured evidence object and a structured summary payload for different subsequent processing objects based on the dispute behavior analysis object. This would provide a unified, stable, and object-oriented technical foundation for subsequent confirmation, review, collaboration, or dispute assistance while reducing the default outflow of original sensitive content. Summary of the Invention
[0007] (a) Technical problems to be solved The present invention aims to solve the problems in the prior art that there is a lack of a unified behavior analysis object for the disputed behavior of protected subjects, a lack of differentiated summary derivation mechanism for different subsequent processing objects, and easy reliance on the default leakage of original sensitive content.
[0008] Specifically, the present invention seeks to solve the following technical problems: 1. How to acquire multiple runtime events related to the target disputed behavior locally on the terminal device, and elevate them from discrete events into a disputed behavior analysis object; 2. How to extract at least two types of features from the object of disputed behavior analysis to generate local structured evidence objects, rather than remaining at the level of ordinary logs, ordinary screenshots or ordinary text reminders; 3. How to generate structured summary payloads with different granularities and desensitization boundaries based on the same local structured evidence object and for different subsequent processing objects; 4. How to ensure the availability of information needed for subsequent confirmation, review, collaboration, or dispute resolution without outputting the original sensitive content by default?
[0009] (II) Technical Solution To address the aforementioned technical problems, this invention provides a method for generating a local structured chain of evidence for disputed acts of protected subjects, comprising: 1. Obtain multiple runtime events related to the target disputed behavior on the terminal device corresponding to the protected subject; 2. On the local terminal device, multiple runtime events are associated and merged based on at least one of the following: time association, source association, stage progression relationship, or subject state context, to form a disputed behavior analysis object; 3. Based on the object of disputed behavior analysis, extract at least two types of features from the behavioral scene features, subject state features, and behavioral context features to generate local structured evidence objects; 4. Based on local structured evidence objects, generate structured summary payloads for at least two types of post-processing objects, wherein the structured summary payloads corresponding to different post-processing objects differ in at least one of the following: field type, field granularity, and desensitization boundary. 5. Output local structured evidence objects and / or structured summary payloads.
[0010] Furthermore: 1. The protected subject may include minors, the elderly, end users bound to a guardianship relationship, and end users in a protected mode; 2. The objects for analyzing disputed behavior may include disputed behavior progression chain objects, disputed time window objects, and disputed behavior event sequence objects; 3. The local structured evidence object may include at least two of the following layers: a fact event layer, a summary layer, a collaborative output layer, and an index or validation field layer; 4. The index or verification field can be used to identify the correspondence between the dispute behavior analysis object and the structured summary payload, and to perform consistency verification on different structured summary payloads derived from the same dispute behavior analysis object; 5. The default output content does not include the original sensitive content.
[0011] Furthermore, in some implementations, after the terminal device completes the runtime event association merging, dispute behavior analysis object construction, local structured evidence object generation, and structured summary payload derivation locally, it can synchronize the structured summary payload, dispute behavior analysis object identifier, local structured evidence object identifier, summary version identifier, or consistency verification result to the server to support monitoring review, platform review, dispute handling, or subsequent collaboration.
[0012] In this implementation, the server does not replace the terminal device in performing runtime event association and merging, dispute behavior analysis object construction, and local structured evidence object generation. Instead, it is used to perform at least one of the following functions: summary reception, index management, collaborative forwarding, review support, object retrieval, or subsequent processing orchestration.
[0013] (III) Beneficial Effects Compared with the prior art, the present invention has at least the following beneficial effects: 1. By associating and merging multiple runtime events to form a dispute behavior analysis object, we can avoid making judgments based on a single result event and improve the ability to express the process of dispute behavior. 2. By generating local structured evidence objects based on disputed behavior analysis objects, a unified data object foundation is provided for subsequent confirmation, review, collaboration, or dispute resolution; 3. By deriving differentiated summary payloads for at least two types of subsequent processing objects based on the same local structured evidence object, the processing needs and information boundaries of different processing objects can be taken into account. 4. By excluding original sensitive content from the default output, the privacy risks caused by the default leakage of original sensitive content can be reduced; 5. Identifying object correspondences and performing consistency checks through indexes or validation fields can improve data consistency and subsequent verification availability in multi-summary derivation scenarios.
[0014] Unlike existing technologies that control transactions by blocking, intercepting, or modifying them in real time, this invention does not require intervention, interruption, or modification of third-party payment processes or application behavior. Instead, it generates local structured evidence objects and structured summary payloads on the terminal device to provide objective and verifiable data for subsequent confirmation, review, or dispute resolution. Attached Figure Description
[0015] Figure 1 This is a diagram of the overall system architecture of the present invention; Figure 2 This is a flowchart of the runtime event acquisition and association merging process of this invention; Figure 3 This is a flowchart illustrating the three types of feature extraction and local structured evidence object generation processes of this invention. Figure 4 This is a schematic diagram illustrating the hierarchical structure of local structured evidence objects in this invention. Figure 5 This is a schematic diagram illustrating the derivation of the differentiated abstract load of the present invention; Figure 6 This is a schematic diagram illustrating the index or verification field and consistency verification of the present invention; Figure 7 This is a schematic diagram of server-side collaboration after the local main chain of this invention is completed; Figure 8 This is a schematic diagram illustrating an embodiment of the highly controversial external licensing and transaction scenario of the present invention. Detailed Implementation
[0016] The present invention will be further described below with reference to specific embodiments. It should be understood that the following embodiments are for illustrative purposes only and are not intended to limit the scope of protection of the present invention.
[0017] (I) Terminology Explanation 1. Protected Subject In this invention, a "protected subject" refers to an end-user who requires enhanced evidence retention and subsequent review support for their disputed conduct. The protected subject may include minors, the elderly, end-users bound to a guardianship relationship, and end-users in a protected mode.
[0018] The protected mode can be triggered by at least one of the following: terminal system configuration, monitoring configuration, device role configuration, time-based protection configuration, or account protection configuration. In specific implementations, the protected subject can be either a pre-determined user role or a user performing the target behavior when the terminal is already in protected mode.
[0019] 2. Target dispute behavior In this invention, the "target disputed behavior" refers to an electronic interactive behavior that may subsequently enter into a process of guardianship confirmation, platform review, dispute resolution, or post-event verification during the use of a terminal device by a protected subject.
[0020] The target disputed behavior is not limited to the name of the behavior, but is judged based on whether it has the need for subsequent review or dispute assistance. In specific embodiments, the target disputed behavior may include virtual value transfer behavior, payment confirmation behavior, transaction behavior caused by inducement or misleading, and other electronic interaction behavior with the need for subsequent review.
[0021] 3. Runtime events In this invention, a "runtime event" refers to event information that is generated or obtainable in real time by the terminal system, application program, page component, input interaction module, or protection mode control module during the process of the protected subject performing operations related to the target disputed behavior on the terminal device.
[0022] The runtime events may include source entry events, page entry events, page progression events, behavior request events, interaction confirmation events, repeated attempt events, application switching events, time period status events, terminal role status events, and protected mode status events.
[0023] Real-time availability includes immediate listening and acquisition when an event occurs, as well as reading from local cache, local queue, or local event records within a preset short window after the event occurs.
[0024] 4. Phased advancement relationship In this invention, "stage progression relationship" refers to the sequential stage relationship or logical progression relationship manifested by multiple runtime events in the process of target dispute behavior.
[0025] For example, in one embodiment, a user enters the target page from the source entry point, followed by page progression events, action request events, and interaction confirmation events. This event chain can correspond to a stage progression relationship of "entry stage -> selection stage -> request stage -> confirmation stage". The stage progression relationship can be determined based on the page jump order, or based on the order of event types, the order of capability request upgrades, the order of page component changes, or the order of confirmation action triggering.
[0026] 5. Merge and associate disputed behavior analysis objects In this invention, "association merging" refers to grouping, chaining, aggregating, or objectifying multiple runtime events according to at least one of time association, source association, stage progression relationship, and subject state context, in order to form an analysis object that can characterize the disputed behavior process of the same target.
[0027] The "dispute behavior analysis object" is an intermediate technical object that objectifies the process of dispute behavior with the same objective. It is not a single event record, nor is it a raw log list sorted only by time.
[0028] In one embodiment, after the object boundaries of the same target dispute behavior process have been determined, arranging the relevant runtime events in chronological order to form a dispute behavior event sequence object also constitutes an association merging method; however, mechanically sorting the original logs without forming dispute behavior analysis objects does not belong to the association merging described in this invention.
[0029] In practice, the objects of dispute behavior analysis may include: 1. `Disputed Behavior Progression Chain Object`: Used to represent the sequence and connection between stages of multiple events in the process of behavior progression; 2. `Disputed Time Window Object`: Used to represent a set of events that fall within the same preset time window and have source or state associations; 3. `Disputed Behavior Event Sequence Object`: Used to represent a sequence of related events arranged in chronological order and filtered by event type.
[0030] In one embodiment: 1. When multiple events occur from the same source application and appear consecutively within a preset time threshold, they can be grouped into the same disputed time window object; 2. When there is a page progression or confirmation relationship between events, a dispute behavior progression chain object can be further constructed; 3. When the system retains only key node events in the same disputed behavior process, a disputed behavior event sequence object can be formed.
[0031] 6. Three types of characteristics In this invention, "behavioral scene features", "subject state features", and "behavioral context features" are three types of feature sources for the structured expression of the object of disputed behavior analysis.
[0032] in: 1. Behavioral scenario characteristics may include the type of behavior source, the stage of behavior progression, the characteristics of the request type, and the stage of behavior outcome; 2. The main status characteristics may include equipment role status, monitoring relationship status, capability control status, time period protection status, and protected mode status; 3. Behavioral context features may include event frequency, repeated triggering, multi-application jump relationships, contextual changes before and after the behavior, and the coupling relationship between protected mode and behavior progression.
[0033] The phrase "at least two types of features" refers to selecting any two or three types of features from the above three types of feature sources to extract corresponding feature information in order to generate a local structured evidence object.
[0034] The coupling relationship between protected mode and behavior advancement can be expressed as follows: when the terminal is in different protected modes, the event retention rules, summary rules, or summary granularity rules in the behavior advancement chain change.
[0035] 7. Local structured evidence objects In this invention, a "local structured evidence object" refers to a data object generated locally on a terminal device that is used to express the target disputed behavior process and its subsequent processing support information.
[0036] The object is not a simple text notification or a stack of screenshots, but a data object with field organization relationships, parsable relationships, or hierarchical organization relationships. In specific implementations, the local structured evidence object may include at least two of the following layers: 1. `Fact Event Layer`: Used to record at least one of the following: event type, event time, source application, source page, key interactive actions, and subject state snapshot; 2. `Summary Layer`: Used to record at least one of the following: behavior type summary, scenario source summary, dispute auxiliary identifier, and result stage summary; 3. Collaborative Output Layer: Used to record at least one of the following for different subsequent processing objects: summary version, output object identifier, anonymization level, or summary template identifier; 4. `Index or Validation Field Layer`: Used to record at least one of the following: dispute behavior analysis object identifier, summary version identifier, output object identifier, derivation relationship identifier, or consistency validation field.
[0037] This invention does not limit the above layers to be implemented using a specific data format. The layers can be implemented through field groups, object attributes, key-value sets, structured records, or multi-table related records.
[0038] 8. Index or validation fields and consistency checks like Figure 6As shown, in some implementations, the index or verification field may be located in the derivation relationship link between the disputed behavior analysis object, the local structured evidence object, and the structured summary payload, and is used to identify the object correspondence and perform consistency verification.
[0039] In this invention, the `index or verification field` is used to identify the derivation and correspondence between the dispute behavior analysis object and the structured summary payload, and can be used to perform consistency verification on different structured summary payloads derived from the same dispute behavior analysis object.
[0040] In one embodiment, the index or validation field may include at least one of the following: 1. Identification of objects involved in disputed behavior analysis; 2. Local structured evidence object identification; 3. Summary version identifier; 4. Output object identifier; 5. Derivation relationship identifier; 6. Consistency check result field.
[0041] Among them, "consistency verification" refers to verifying whether different structured summary payloads derived from the same disputed behavior analysis object originate from the same local structured evidence object, whether they correspond to the same disputed behavior analysis object, and whether their summary version, output object, and desensitization level conform to the preset mapping relationship.
[0042] In one embodiment, consistency verification can be completed through at least one of the following methods: object identifier comparison, derivation relationship identifier comparison, digest version identifier comparison, or preset rule matching.
[0043] In a minimal field-level embodiment, the local structured evidence object and its summary derivation relationship may include at least some of the following fields: 1. `analysis_object_id` is used to identify the object of the dispute behavior analysis; 2. `evidence_object_id`, used to identify local structured evidence objects; 3. `summary_version` is used to identify the summary version; 4. `output_target_type` is used to identify the type of object to be processed later; 5. `derivation_relation_id`, used to identify the derivation relationship of the abstract; 6. `consistency_check_result` is used to record the consistency check results.
[0044] In this embodiment, the system can determine whether different structured summary payloads originate from the same disputed behavior analysis object and the same local structured evidence object by comparing the correspondence between `analysis_object_id`, `evidence_object_id`, `summary_version`, and `output_target_type`.
[0045] 9. Subsequent processing objects and differentiated summary payloads In this invention, a "subsequent processing object" refers to a processing object that receives the structured digest payload and performs subsequent confirmation, review, or dispute resolution actions. In specific implementations, the subsequent processing object may include at least two of the following: a monitoring review object, a platform review object, and a dispute resolution object.
[0046] A differentiated summary payload refers to a structured summary output derived from the same local structured evidence object but for different subsequent processing objects. Differentiation is reflected in at least one of the following: 1. Different types of fields; 2. Different field granularity; 3. The desensitization boundaries are different; 4. The output object identifier or summary version identifier is different.
[0047] In one embodiment: 1. Summary payloads for monitored review subjects can retain relatively complete behavioral stage information; 2. The summary payload for platform review targets can retain key fields used for platform review and de-identify sensitive personal content; 3. The summary payload for dispute resolution objects can retain only the fields required for dispute location, object index fields, and consistency verification fields.
[0048] In a simplified embodiment, the structured summary payload for dispute resolution objects may only include the object identifier for dispute behavior analysis, the local structured evidence object identifier, and the consistency verification result, without including specific behavior detail fields. The identifier can be used for subsequent object retrieval, server-side index collaboration, or authorized further retrieval, thereby supporting subsequent dispute resolution with minimal information exposure.
[0049] 10. Default output content In this invention, the "default output content" refers to the standard content that the system outputs to subsequent processing objects when it has not received additional manual authorization, has not entered a special dispute handling process, and has not triggered higher permission configuration.
[0050] The default output content does not include the original sensitive content. The default output content may include at least one of the following: metadata, digest field, index field, abstract hash field, and consistency check field.
[0051] The abstract hash field can be used to summarize local structured evidence objects, summary content, or object derivation relationships without directly exposing the original sensitive content. The original sensitive content may include at least one of the following: original audio / video content, complete page text, complete input content, and complete original interactive payload.
[0052] (II) Overall Process Implementation Method like Figures 1 to 7 As shown, the overall implementation process of this invention may include runtime event acquisition, association and merging to form dispute behavior analysis objects, three types of feature extraction, local structured evidence object generation, differential summary payload derivation, index or verification field consistency verification, and server-side collaboration after the local main chain is completed.
[0053] In one embodiment, the method of the present invention may be performed according to the following steps.
[0054] Step S1: Runtime Event Acquisition like Figure 2 As shown, the terminal device first acquires multiple runtime events during the operation related to the target disputed behavior.
[0055] During the process of the protected subject performing operations related to the disputed target behavior, the terminal device acquires multiple runtime events. These runtime events may be generated by the terminal system event listening module, application event callback module, page status monitoring module, input interaction module, or protection mode control module.
[0056] In one embodiment, the terminal device can record the event immediately when it occurs; in another embodiment, the terminal device can also read the relevant event from the local cache or the local event queue within a preset short window.
[0057] Step S2: Local associations are merged to form objects for disputed behavior analysis. like Figure 2 As shown, multiple runtime events obtained can be associated and merged locally on the terminal device according to time association, source association, stage progression relationship or subject state context to form a dispute behavior analysis object.
[0058] The terminal device correlates and merges multiple runtime events locally. The correlation and merging can be based on at least one of the following: 1. Time correlation; 2. Source association; 3. The relationship of phased advancement; 4. Subject state context.
[0059] In one embodiment, when multiple events occur from the same source application or source page and the occurrence time falls within a preset time threshold, the system merges the multiple runtime events into the same disputed time window object.
[0060] In another embodiment, when there is a sequential relationship between multiple events, namely page entry, page advancement, behavior request, and interaction confirmation, the system constructs a disputed behavior advancement chain object based on this sequential relationship.
[0061] In another embodiment, when the system retains only the key node events in the disputed behavior process, the system forms a disputed behavior event sequence object.
[0062] Step S3: Generate local structured evidence objects like Figure 3 and Figure 4 As shown, the system can extract three types of features based on the object of disputed behavior analysis and organize and generate local structured evidence objects with a hierarchical structure.
[0063] Based on the disputed behavior analysis object, the system extracts at least two types of features from the behavior scene features, subject state features, and behavior context features, and generates local structured evidence objects accordingly.
[0064] In one embodiment, the system extracts fields from behavioral scene features and subject state features; in another embodiment, the system extracts fields simultaneously from behavioral scene features, subject state features, and behavioral context features.
[0065] The generated local structured evidence object may include at least two of the following layers: a fact event layer, a summary layer, a collaborative output layer, and an index or validation field layer.
[0066] Step S4: Differentiated Summary Loading Derivation like Figure 5 As shown, the system can derive structured summary payloads with different field granularities and desensitization boundaries for different subsequent processing objects based on the same local structured evidence object.
[0067] Based on the same local structured evidence object, the system selects the corresponding summary template, field retention rules, and desensitization rules according to the type of object to be processed later, in order to generate a structured summary payload.
[0068] In one embodiment, the summary payload for the monitoring review object retains relatively complete behavioral stage information; the summary payload for the platform review object retains the key fields required for platform review and desensitizes sensitive personal content; the summary payload for the dispute resolution object retains the fields required for dispute location, object index field, and consistency verification field.
[0069] Step S5: Output and Subsequent Collaboration like Figure 6 and Figure 7 As shown, during the output phase, the system can perform consistency checks on different structured digest payloads using indexes or verification fields, or it can synchronize relevant digests or identifiers to the server after the local main chain is completed to support subsequent collaboration.
[0070] The system outputs local structured evidence objects and / or structured summary payloads.
[0071] In one embodiment, after the terminal device completes the runtime event association merging, dispute behavior analysis object construction, local structured evidence object generation, and structured summary payload derivation locally, it can synchronize at least one of the structured summary payload, dispute behavior analysis object identifier, local structured evidence object identifier, summary version identifier, output object identifier, or consistency verification result to the server to support monitoring review, platform review, dispute handling, or subsequent collaboration.
[0072] In this implementation, the server does not replace the terminal device in completing runtime event association and merging, dispute behavior analysis object construction, and local structured evidence object generation. Instead, it performs at least one of the following functions: summary reception, index management, collaborative forwarding, review support, object retrieval, or subsequent processing orchestration.
[0073] In some embodiments, steps S1 to S5 described above can be performed by an electronic device. The electronic device may include a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement at least some or all of steps S1 to S5 described above.
[0074] In some embodiments, the present invention may also be implemented by a computer-readable storage medium storing a computer program, which, when executed by a processor, is used to implement at least some or all of the steps S1 to S5 described above.
[0075] (III) Example 1: Game recharge scenario like Figures 2 to 5 As shown, in the game recharge scenario, the system can form a disputed behavior progression chain object around the event progression process of the recharge behavior, and further generate local structured evidence objects and differentiated summary payloads.
[0076] In one embodiment, the protected subject is a minor, and the target disputed behavior is game recharge behavior.
[0077] The terminal device first obtains the source entry event, page entry event, page advancement event, behavior request event, and interaction confirmation event, and forms the corresponding disputed behavior advancement chain object locally.
[0078] Subsequently, the system extracts: - Type of behavior source; - Behavior progression phase; - Guardianship status; - Protected mode status; - The relationship between the behavior and the context before and after; And based on this, a local structured evidence object is generated.
[0079] Then, the system derives two types of summaries based on this object: 1. Summary payload for the monitored review subject; 2. Summary payload for platform-reviewed objects.
[0080] The two types of summaries differ in at least one of the following: field granularity and desensitization boundary.
[0081] (iv) Example 2: Live Streaming Tipping Scenario like Figures 2 to 5 As shown, in the live streaming tipping scenario, the system can form a disputed time window object around high-frequency triggering, short-term advancement and protected mode state changes, and generate a local structured evidence object and a differentiated summary payload based on the object.
[0082] In one embodiment, the protected subject is a minor or an elderly person, and the target disputed behavior is live-streaming tipping.
[0083] The system acquires repeated attempt events, time period status events, protected mode status events, and page progression events, and constructs a disputed time window object based on time association and state context.
[0084] In this embodiment, the behavioral context features are specifically manifested as follows: - Event frequency; - Repeated triggering situations; - The coupling relationship between protected mode and behavior advancement.
[0085] Based on the above features, the system generates local structured evidence objects and further derives different summary payloads for guardianship review objects and dispute resolution objects to reflect different de-identification boundaries.
[0086] (V) Example 3: Induced Trading Scenario like Figure 2 , Figure 5 and Figure 6As shown, in the scenario of induced transactions, the system can form a sequence of disputed behavioral events around multi-application jumps and changes in behavioral context, and output a more contracted structured summary payload.
[0087] In one embodiment, the target disputed behavior is a transaction that is induced or misled.
[0088] The system obtains the multi-application jump relationship, the context change relationship before and after the behavior, the behavior request event and the interaction confirmation event, and forms a disputed behavior event sequence object locally.
[0089] Subsequently, the system generates a local structured evidence object based on the event sequence object and outputs a more contracted summary payload to the dispute resolution object, which retains the dispute location field, object index field, and consistency check field.
[0090] (vi) Example 4: High-Controversy External Licensing and Transaction Scenarios like Figure 8 As shown, in highly controversial external authorization and transaction scenarios, the system can form a disputed behavior advancement chain object around the external authorization, confirmation and transaction advancement process, and generate local structured evidence objects and structured summary payloads for subsequent review or dispute handling.
[0091] In one embodiment, the target controversial behavior can be a highly controversial external authorization and transaction behavior, such as QR code payment, misuse of payment code, being induced to click to confirm, online loan application or credit authorization.
[0092] In this embodiment, the system acquires source entry events, page progression events, behavior request events, and interaction confirmation events, and forms a corresponding disputed behavior progression chain object based on the page progression order, event triggering order, and subject state context.
[0093] Furthermore, in this embodiment: 1. Source entry events can correspond to external link redirects, message entry redirects, or external application switching; 2. Page progression events can correspond to the transition between the authorization page entry, confirmation page display, or payment page stages; 3. Behavioral request events can correspond to payment requests, authorization requests, loan application requests, or credit line application requests; 4. Interactive confirmation events can correspond to user actions such as confirmation, authorization, submission, or clicking continue.
[0094] The system constructs disputed behavior analysis objects based on both subject state characteristics and behavioral context characteristics, and generates local structured evidence objects. Subsequently, the system generates structured summary payloads with different granularities and anonymization boundaries for guardianship review objects, platform review objects, and dispute resolution objects, respectively.
[0095] In this embodiment, the default output does not include the original sensitive content, but retains the object identifier, digest version identifier, and consistency check fields.
[0096] (vii) Extended Example 5: Further Expansion of Loan Application or Authorization Scenarios In some extended embodiments, the target disputed behavior may also include loan applications, credit confirmations, automatic renewal authorizations, payment instrument binding, or other electronic interactive behaviors that require post-event review.
[0097] This example is used to illustrate: This invention is not limited to the recharge or tipping behavior in the current main implementation scenario. As long as the behavior meets the conditions of "execution by a protected subject, subsequent confirmation or dispute assistance processing needs, and the formation of an analysis object through multiple runtime events", the method of this invention can be applied.
[0098] In this extended embodiment, the system still uses the main chain of runtime event acquisition, association merging, dispute behavior analysis object construction, local structured evidence object generation, and differential summary derivation, without changing the boundary of choosing whether to synchronize the summary payload and index fields to the server after the local main chain is completed.
[0099] (viii) Extended Example 6: AI Agent Behavior Review Scenario In some extended embodiments, the disputed behavior of the protected subject can also be reflected in the scenario of AI agent behavior review.
[0100] In this embodiment, the protected subject can be a natural person user authorized by an AI agent to perform external actions, an account user bound to a guardianship relationship, or an account user in a protected mode. The AI agent is the execution carrier rather than the protected subject itself.
[0101] In this embodiment, the following events are treated as runtime events: 1. User authorization event; 2. Session command events; 3. Tool invocation event; 4. External execution events; 5. Result write-back event.
[0102] Based on time association, call order relationship and permission status context, the system associates and merges the aforementioned events to form a proxy behavior advancement chain object or a proxy behavior event sequence object.
[0103] Subsequently, based on the agent behavior analysis object, the system extracts at least two types of features from the behavior scenario features, subject status features, and behavior context features to generate a local structured evidence object, and outputs structured summary payloads with different field granularities to user review objects, platform audit objects, or dispute resolution objects.
[0104] In this embodiment, the user review object, platform audit object, or dispute resolution object can be respectively used as the specific implementation form of the guardian review object, platform review object, or dispute resolution object in the main case under the AI agent behavior scenario.
[0105] In this embodiment, the default output does not include the complete conversation text, complete prompts, or complete tool parameters.
[0106] (ix) Extended Implementation Example 7: Embodied Action Responsibility Chain Scenario In some extended embodiments, the disputed behavior of the protected subject can also be embodied action responsibility chain scenario.
[0107] In this embodiment, the protected subject can be a person being cared for, a device user bound to a guardianship relationship, or a terminal or device user in a protected mode. The embodied device is the action execution carrier rather than the protected subject itself.
[0108] In this embodiment, the following events are treated as runtime events: 1. Perceiving events; 2. Decision-making events; 3. Control command events; 4. Action execution events; 5. Result feedback event.
[0109] The system associates and merges the aforementioned events based on time correlation, action progression relationship, device state context, and protected mode state to form action progression chain objects, action time window objects, or action event sequence objects.
[0110] Based on the action analysis object, the system generates a local structured evidence object and outputs structured summary payloads of different granularities to family review objects, operation platform objects, or dispute resolution objects.
[0111] In this embodiment, the family member review object, the operating platform object, or the dispute resolution object can be respectively used as the specific implementation form of the guardianship review object, the platform review object, or the dispute resolution object in the main case in the embodied action responsibility chain scenario.
[0112] In this embodiment, the default output does not include the complete raw sensor stream, the complete continuous video stream, or other raw sensitive motion data.
[0113] (x) Rules for implementation 1. Time window merging rules In one embodiment, when multiple runtime events occur from the same source application or the same source page, and the event occurrence time falls within a preset time threshold, the system merges the multiple runtime events into the same disputed time window object.
[0114] 2. Advance Chain Construction Rules In one embodiment, when there is a sequential relationship between events, namely page entry, page advancement, behavior request, and interaction confirmation, the system constructs a disputed behavior advancement chain object based on this sequential relationship.
[0115] 3. Abstract Derivation Rules In one embodiment, the system generates a structured summary payload by selecting the corresponding summary template, field retention rules, and desensitization rules based on the same local structured evidence object and the type of object to be processed.
[0116] 4. Consistency Verification Rules In one embodiment, the system performs consistency verification on different structured summary payloads derived from the same dispute behavior analysis object by using at least two of the following: dispute behavior analysis object identifier, local structured evidence object identifier, summary version identifier, and output object identifier.
[0117] 5. Server-side collaboration rules after the local main chain is completed In one embodiment, after the terminal device completes the runtime event association merging, dispute behavior analysis object construction, local structured evidence object generation, and structured summary payload derivation locally, it can synchronize at least one of the structured summary payload, dispute behavior analysis object identifier, local structured evidence object identifier, summary version identifier, output object identifier, or consistency verification result to the server to support monitoring review, platform review, dispute handling, or subsequent collaboration.
[0118] In this embodiment, the server does not replace the terminal device in completing the local association and merging of the main chain, but is used to perform at least one of the following functions: summary reception, index management, collaborative forwarding, review support, object retrieval, or subsequent processing orchestration.
[0119] in conclusion This invention provides a structured evidence chain generation scheme for the disputed behavior of protected subjects, which is different from general evidence preservation, general evidence collection and general relationship model construction, by acquiring multiple runtime events locally on the terminal device, associating and merging them into disputed behavior analysis objects, generating local structured evidence objects based on at least two types of features, and outputting differentiated summary payloads for different subsequent processing objects.
[0120] This invention is particularly applicable to disputed behavior scenarios that require subsequent monitoring confirmation, platform review, dispute resolution, or post-event verification processes, and can reduce the outflow of original sensitive content by default.
Claims
1. A method for generating a local structured chain of evidence for disputed acts of protected subjects, characterized in that, include: Acquire multiple runtime events related to the target disputed behavior on the terminal device corresponding to the protected subject; On the local terminal device, based on at least one of the following: time association, source association, stage progression relationship, or subject state context among the multiple runtime events, the multiple runtime events are associated and merged to form a disputed behavior analysis object; Based on the disputed behavior analysis object, at least two types of features are extracted from the behavior scene features, subject state features, and behavior context features to generate a local structured evidence object. Based on the local structured evidence object, a structured summary payload is generated for at least two types of subsequent processing objects, wherein the structured summary payloads corresponding to different subsequent processing objects are different in at least one of the following: field type, field granularity, and desensitization boundary. Output the local structured evidence object and / or the structured summary payload.
2. The method according to claim 1, characterized in that, The protected subject includes at least one of the following: Minors; elderly people; End users who are bound to a guardianship relationship; End users in protected mode.
3. The method according to claim 1, characterized in that, The runtime events include at least one of the following: Source entry event; Page entry event; Page advance events; Action request event; Interactive confirmation event; Repeated attempt event; Application switching events; Time-based status events; Terminal role status events; Protected mode state events.
4. The method according to claim 1, characterized in that, The objects of the disputed behavior analysis include at least one of the following: Objects involved in the disputed behavior progression chain; Disputed time window object; Controversial behavior event sequence object.
5. The method according to claim 1, characterized in that: The behavioral scenario features include at least one of the following: behavioral source type, behavioral progression stage, request type features, and behavioral result stage; The main status characteristics include at least one of the following: device role status, monitoring relationship status, capability control status, time period protection status, and protected mode status; The behavioral context features include at least one of the following: event frequency, repeated triggering, multi-application jump relationship, context change relationship before and after behavior, and coupling relationship between protected mode and behavior advancement.
6. The method according to claim 1, characterized in that, The local structured evidence object includes at least two of the following layers: a fact event layer, a summary layer, a collaborative output layer, and an index or verification field layer; the index or verification field is used to identify the correspondence between the dispute behavior analysis object and the structured summary payload, and to perform consistency verification on different structured summary payloads derived from the same dispute behavior analysis object.
7. The method according to claim 1, characterized in that, The at least two types of follow-up processing objects include at least two of the following: guardianship review objects, platform review objects, and dispute resolution objects.
8. The method according to claim 1, characterized in that, The default output content of the local structured evidence object and / or the structured summary payload does not include the original sensitive content; the default output content includes at least one of metadata, summary field, index field, abstract hash field, or verification field.
9. An electronic device, characterized in that, include: Memory; processor; The memory stores a computer program, and when the processor executes the computer program, it implements the method as described in any one of claims 1 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 8.