Android Device Fingerprint, Attestation and Risk Identity

标识符回答“像不像同一安装或设备”,完整性证明回答“当前 App 与执行环境是否可信”

Android device fingerprint, integrity attestation and risk identity processing flow App-scoped identifiers, resettable advertising identifiers, Android ID, device properties, application posture and behavior feed a risk SDK. Independent integrity and key attestation signals are verified by servers, then joined with account and business context for a tiered decision. APP PROCESS / SDK ANDROID / OEM TRUST SERVICES BACKEND RISK PLATFORM deviceToken + bizId outcome feedback / device profile aging App Instance ID FID or private GUID app-scoped / reinstall-reset ANDROID_ID / SSAID signing key + user + device factory-reset / key-change semantics OAID / GAID ads-oriented / user resettable consent and purpose constrained Device Properties Build / OS / ABI / screen locale / storage / network App / Runtime Posture signature / installer / debug hook / root / emulator hints Behavior / Sensors touch rhythm / navigation motion consistency / velocity Risk SDK consent-gated collection canonicalize / sign / encrypt nonce + timestamp + bizId token is an envelope, not identity client verdicts remain bypassable Restricted Hardware IDs IMEI / serial / factory MAC not generally available to modern third-party apps Integrity Provider app recognition / device integrity / account context Play Integrity or OEM-equivalent service Android Keystore / TEE / StrongBox hardware-backed key and certificate chain verified boot / security level / patch claims server challenge prevents naive replay attestation proves properties, not a person OS Privacy Boundaries permission / package visibility / scoped storage MAC randomization / ID scoping / reset controls OEM variation and no-GMS fallback paths absence of a signal must degrade gracefully OEM / region / Android version variance Token Gateway schema / nonce / bizId anti-replay / versioning Attest Verify chain / root / revocation request binding / freshness Profile Matcher stability + confidence reset / reinstall / drift Risk Graph account / device / IP order / address / content Business Event login / payment / coupon amount / frequency account history Decision Engine rules + model + policy reason / TTL / audit tiered response ALLOW / LIMIT / STEP-UP / REVIEW / DENY LEGEND app-scoped signal OS identifier / policy integrity / trust claim server verification relationship graph Core invariant: do not bridge user resets or rebuild a permanent identity from weaker signals without a valid purpose and legal basis. Security invariant: verify integrity evidence off-device; local root, hook and emulator checks are supporting signals, not roots of trust.

ID 有不同作用域

  • 应用实例 GUID 通常重装即变,Android ID 受签名、用户和设备共同约束
  • OAID/GAID 面向广告场景,可被用户关闭或重置
  • 把这些 ID 强行拼回永久身份,会破坏平台设计的重置语义

证明不等于指纹

  • 指纹是概率匹配,完整性证明是带签名的环境声明
  • Attestation 必须在服务端验链、验撤销、验挑战绑定
  • 通过完整性校验仍不能证明操作者本人或业务行为正常

无 GMS 不是无风控

  • 国内 Android 生态常使用 OAID、OEM 能力和自有终端 SDK
  • OEM、ROM 与系统版本差异要求服务端显式处理缺失信号
  • 稳定工程依赖分级决策,而不是要求每台设备返回同一组字段