Android Device Registration Lifecycle

设备注册不是账号注册:它把一次安装的本地种子换成服务端句柄,再由事件、账号和风险反馈持续修正

Android device registration from local installation seed to server risk identity The client collects consented installation and device context, sends a protected registration envelope, receives server handles and configuration, then binds events and accounts while lifecycle controls rotate or revoke the identity. APP AND SDK RUNTIME REGISTRATION EDGE IDENTITY AND LIFECYCLE BUSINESS AND RISK rotation, revocation, reinstall and profile split/merge return a new or refreshed handle Consent and SDK Startprivacy gate / app id / channel / versioninitialization must not outrun consent Local Seed and Contextprivate GUID + scoped IDs + app identitydevice/system/network only when justified Persisted Server Handlesdevice_id / install_id / FID / configcached locally; not a physical identity Registration Envelopeschema + timestamp + app/device contextTLS plus product-specific integrity layer Verify and Normalizeapp identity / freshness / consistencymissing and unsupported remain explicit Event and Config Channelactivation / analytics / remote configregistration handle joins later events Candidate Profile Resolvernew install OR reconnect known profilescope and collision policy are product-specific Issue Handles and Configserver ID + install ID + policy snapshotobserved Douyin sample returns DID and IID Lifecycle Controllerrefresh / rotate / revoke / delete / splitreset semantics are part of the contract Activation and Event Historyfirst install / update / reinstall / sessionsdevice handle gains temporal meaning here Account and User Bindinguser_unique_id / login / logout / account graphdevice registration never authenticates a person Risk Graph and Decisionaccounts / content / payment / network / outcomeregistration is an input, not authorization Four registration semantics that look similar on the wire but carry different trust and reset properties: SERVER DID + INSTALL HANDLEByteDance-style analytics / activation continuity INSTALLATION ID + AUTH TOKENFirebase FID scoped to one app installation SHORT-LIVED RISK TOKENAlibaba-style observation envelope for a biz event PER-ACTION ATTESTATIONPlay Integrity binds verdict to requestHash or nonce documented or locally observed flow lifecycle and risk feedback Evidence boundary: official DataFinder and Firebase behavior is not proof that every consumer app uses the same fields, scope or matching policy.

先分清三个身份

  • 本地种子描述一次安装的初始状态
  • 服务端句柄用于连接配置与事件历史
  • 账号身份只在登录后与设备关系绑定

抖音样本的关键闭环

  • 注册信封先建立 DID/IID,再回填 SDK 上下文
  • 后续事件与 API 携带句柄形成连续历史
  • 字段和保护方案必须带版本与证据等级

注册成功不是设备可信

  • 服务端发号证明结构可接受,不证明环境真实
  • 重装、清数据、轮换和撤销必须有明确语义
  • 高价值动作仍需 Attestation、账号和业务图谱