Web Device Fingerprint and Risk Identity Architecture

网页只提供可观测信号;稳定设备关系、风险标签与业务决策主要在服务端形成

Web device fingerprint and risk identity processing flow Browser, network, first-party state and behavioral signals are collected into an event-bound token, normalized on the server, matched with historical profiles, joined to a risk graph and used for tiered business decisions. BROWSER / FIRST-PARTY ORIGIN EDGE / TRANSPORT RISK CONTROL PLATFORM event-bound envelope outcome feedback / profile aging Passive Request UA / UA-CH / Accept language / fetch metadata Runtime Surface screen / timezone / locale CPU hints / APIs / media Render / Timing Canvas / WebGL / fonts Audio / DOMRect / latency Behavior Stream pointer / touch / scroll typing / navigation rhythm First-party State account / cookie / storage session / challenge history Collection SDK capability probes + event sampler consistency checks / coarse buckets nonce / timestamp / business event returns token, not a trusted verdict Transport Observation IP / ASN / region / proxy hints TLS / HTTP behavior / velocity Event Gateway schema / size / replay validation bind token to session + bizId join edge-side observations client claims remain untrusted Rate / Reputation IP history / subnet / egress reuse burst, concurrency, challenge debt Normalization bucket / canonicalize missingness is a feature Feature Store versioned vectors TTL / consent / lineage Fuzzy Matcher similarity + confidence split / merge / drift Risk Graph account / device / network address / order / content Decision Engine rules + model + policy reason codes / audit trail Business Context login / payment / coupon amount / asset / sensitivity ALLOW / LIMIT / CHALLENGE / REVIEW / DENY LEGEND client observation network / context server processing relationship / behavior risk decision Core invariant: a browser fingerprint is probabilistic evidence. It is neither a secret nor an authenticator by itself. Privacy boundary: origin scope, purpose limitation, TTL and reset semantics must be enforced outside the fingerprint algorithm.

指纹不是一段 Hash

  • 真实系统保留特征向量、缺失模式和版本信息
  • Hash 适合索引,不适合处理浏览器升级后的漂移
  • 匹配结果应带置信度,而不是伪装成绝对设备 ID

服务端才形成风险身份

  • 浏览器信号必须与账号、网络、业务事件一起解释
  • 图关系能识别设备农场,也可能把家庭共享设备误合并
  • 结果反馈用于校准模型,同时需要防止标签污染

决策必须分级

  • 低风险放行,中风险限额或追加验证,高风险人工复核
  • 仅凭 Canvas、IP 或一次异常行为直接封禁都很脆弱
  • 每次决策应保留原因码、模型版本与申诉入口