Risk control method and device, electronic equipment and medium

By setting risk monitoring points and control rules between business nodes, the problems of lag and poor flexibility in existing risk management systems are solved, achieving more efficient risk control.

CN109543984BActive Publication Date: 2026-03-31SHANGHAI SHENGPAY E PAYMENT SERVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2018-11-15
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

The existing risk management systems of third-party payment institutions are outdated and lack flexibility, making it difficult to respond promptly to sudden risk points and vulnerabilities.

Method used

A large number of risk monitoring points and risk control rules are identified among various business nodes in the business scenario. The entire business process is monitored in a granular and detailed manner through the detailed monitoring points and control rules. Risk monitoring points and rules are managed using risk control path templates and databases.

Benefits of technology

It achieves greater flexibility and real-time performance, enabling timely addition or modification of risk monitoring points and rules, comprehensively covering business scenarios, and improving the efficiency and coverage of risk control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN109543984B_ABST
    Figure CN109543984B_ABST
Patent Text Reader

Abstract

The application provides a risk control method and device, electronic equipment and a computer readable medium. The risk control method comprises: determining all risk monitoring points corresponding to a target business scenario, wherein the risk monitoring points are distributed between each business node of the target business scenario; determining a risk control rule corresponding to each risk monitoring point; and performing risk control on the target business scenario according to all risk monitoring points and the corresponding risk control rules. Compared with the prior art, the risk control method provided by the application has higher flexibility, can more easily achieve comprehensive coverage of the entire business scenario, and can timely and more targeted add or modify the corresponding risk monitoring points and risk control rules when a risk loophole or a sudden risk point is found, thereby having higher real-time performance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of risk control technology, specifically to a risk control method, apparatus, electronic device, and computer-readable medium. Background Technology

[0002] With the rapid development of internet finance, third-party payment institutions have grown and expanded, leading to increasingly stringent risk management and regulatory requirements. Currently, the risk management departments within third-party payment institutions typically employ risk management systems. These systems generally consist of three operational modules: a data storage module, a transaction and user behavior anomaly identification module, and a risk control measures module. Among these, the anomaly identification module is a core component for model design, testing, and deployment, primarily utilizing a rule engine for anomaly detection.

[0003] Because the operational logic and design of the aforementioned risk management system are based on historical data and involve overall rule model design and anomaly identification for risk events, its risk control is significantly lagging, and its response to sudden risk points and potential risk vulnerabilities is often slow and inflexible. Summary of the Invention

[0004] The purpose of this application is to provide a risk control method, apparatus, electronic device, and computer-readable medium.

[0005] The first aspect of this application provides a risk control method, including:

[0006] Identify all risk monitoring points corresponding to the target business scenario, wherein the risk monitoring points are distributed among the various business nodes of the target business scenario;

[0007] Determine the risk control rules corresponding to each of the aforementioned risk monitoring points;

[0008] Risk control is performed on the target business scenario based on all the aforementioned risk monitoring points and their corresponding risk control rules.

[0009] A second aspect of this application provides a risk control device, comprising:

[0010] The monitoring point determination module is used to determine all risk monitoring points corresponding to the target business scenario, wherein the risk monitoring points are distributed among the business nodes of the target business scenario;

[0011] The monitoring rule determination module is used to determine the risk control rules corresponding to each of the aforementioned risk monitoring points;

[0012] The risk control module is used to perform risk control on the target business scenario based on all the risk monitoring points and their corresponding risk control rules.

[0013] A third aspect of this application provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method described in the first aspect of this application.

[0014] A fourth aspect of this application provides a computer-readable medium having computer-readable instructions stored thereon, the computer-readable instructions being executable by a processor to perform the method as described in the first aspect of this application.

[0015] Compared to existing technologies, the risk control method provided in the first aspect of this application, by determining a large number of risk monitoring points and risk control rules among various business nodes in a business scenario, can decompose the entire business process and use multiple detailed risk monitoring points and risk control rules to monitor the entire business process in a granular and detailed manner. On the one hand, since individual risk monitoring points and their risk control rules are relatively easy to modify or supplement, the risk control method has greater flexibility and can more easily achieve comprehensive coverage of the entire business scenario. On the other hand, when risk vulnerabilities or sudden risk points are discovered, corresponding risk monitoring points and risk control rules can be added or modified in a timely and more targeted manner, resulting in higher real-time performance.

[0016] The risk control device provided in the second aspect of this application, the electronic device provided in the third aspect, and the computer-readable medium provided in the fourth aspect are based on the same inventive concept and have the same beneficial effects as the risk control method provided in the first aspect. Attached Figure Description

[0017] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0018] Figure 1 A flowchart of a risk control method provided by some embodiments of this application is shown;

[0019] Figure 2 This application provides a schematic diagram illustrating a method for setting up risk monitoring points according to some embodiments.

[0020] Figure 3 A flowchart of a risk control method provided by some modified embodiments of this application is shown;

[0021] Figure 4 A flowchart of a risk control method provided by some other modified embodiments of this application is shown;

[0022] Figure 5 A flowchart of a risk control method provided by some further modified embodiments of this application is shown;

[0023] Figure 6 A flowchart of a risk control method provided by some further modified embodiments of this application is shown;

[0024] Figure 7 A schematic diagram of a risk control device provided by some embodiments of this application is shown;

[0025] Figure 8 A schematic diagram of an electronic device provided by some embodiments of this application is shown;

[0026] Figure 9 A schematic diagram of a computer-readable medium provided by some embodiments of this application is shown. Detailed Implementation

[0027] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0028] It should be noted that, unless otherwise stated, the technical or scientific terms used in this application shall have the ordinary meaning as understood by one of ordinary skill in the art to which this application pertains.

[0029] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0030] Furthermore, the terms "first," "second," "third," "fourth," etc., are used to distinguish different objects, not to describe a specific order. Additionally, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or apparatuses.

[0031] Please refer to Figure 1 The diagram illustrates a flowchart of a risk control method provided by some embodiments of this application, the risk control method comprising the following steps:

[0032] Step S101: Determine all risk monitoring points corresponding to the target business scenario, wherein the risk monitoring points are distributed among the business nodes of the target business scenario.

[0033] In some embodiments of this application, the business process in the target business scenario can be pre-divided into "joint-like" segments using human joints as a reference. Then, risk monitoring points are set for each of the divided "joints," and risk strategy models are designed for each of the risk monitoring points to monitor risks. This decomposes the risk control of the entire business scenario into multiple risk monitoring points for risk control at a finer granular level.

[0034] For details, please refer to Figure 2 This document illustrates a schematic diagram of a risk monitoring point setting method provided by some embodiments of this application. As shown in the figure, each business node in a business scenario can be regarded as a "joint." For each "joint," user behavior data before or after the "joint" can be analyzed to perform risk control on the "joint" before it or on subsequent "joints" after it. Therefore, corresponding risk monitoring points can be set before and / or after the "joint." Alternatively, the "joint" can also be used as a risk monitoring point. Essentially, the goal is to decompose the risk control of the entire business scenario into multiple risk monitoring points for separate risk control, thereby granularizing risk control and performing risk control at a finer level. Since each "joint" is interconnected, the risk monitoring points are also interconnected and organically combined, thus enabling detailed and comprehensive risk control of the entire business scenario from a macroscopic perspective.

[0035] The business nodes can be determined based on business logic, such as nodes between different business stages or sub-businesses, or based on user behavior corresponding to the business. This application embodiment does not impose any limitations. Generally, during business development, product engineers determine the business processes and business nodes corresponding to each business scenario. This application embodiment can directly call and read the business processes and business nodes under the target business scenario during runtime.

[0036] Taking a typical e-commerce business scenario as an example, based on user behavior, the business nodes can include: browsing, registration, login, card binding, real-name authentication, recharge, transfer, withdrawal, order placement, payment, etc. In this application embodiment, risk monitoring points can be set for each of the above business nodes to carry out risk control.

[0037] Step S102: Determine the risk control rules corresponding to each of the aforementioned risk monitoring points.

[0038] Since the risk factors at each risk monitoring point are different or not entirely the same, it is necessary to set corresponding risk control rules for each risk monitoring point. For example, for the risk monitoring point set at the "login" business node, risk control rules can be set to refuse login to blacklisted users or illegal IP addresses. For the risk monitoring point set at the "transfer" business node, risk control rules can be set such as transfer limits, transfers after successful mobile phone verification code verification, transfers after successful facial recognition verification, suspension of transfers after verification failure, and freezing of accounts after multiple verification failures. In addition, general risk control rules such as increasing or decreasing user risk levels can be set for each or multiple risk monitoring points. Such rules will not be elaborated on here. Those skilled in the art can flexibly set corresponding risk control rules for each risk monitoring point according to actual business needs and enter them into the database for easy access.

[0039] Step S103: Perform risk control on the target business scenario based on all the risk monitoring points and their corresponding risk control rules.

[0040] In some implementations, this step may take risk control measures such as rejecting users, restricting permissions, suspending business, issuing warnings, freezing accounts, and raising risk levels based on the risk control rules. For details, please refer to the description of step S102 above, which will not be repeated here.

[0041] The above describes an embodiment of a risk control method provided in this application. Compared with the prior art, the risk control method provided in this application determines a large number of risk monitoring points and risk control rules among various business nodes in the business scenario. This allows the entire business process to be decomposed, and multiple detailed risk monitoring points and risk control rules are used to monitor the entire business process in a granular and detailed manner. On the one hand, since individual risk monitoring points and their risk control rules are relatively easy to modify or supplement, the risk control method has higher flexibility and can more easily achieve comprehensive coverage of the entire business scenario. On the other hand, when a risk vulnerability or sudden risk point is discovered, the corresponding risk monitoring points and risk control rules can be added or modified in a timely and more targeted manner, resulting in higher real-time performance.

[0042] Based on the above embodiments, please refer to Figure 3 In some embodiments, before step S101, the following may be included:

[0043] Step S104: Query the first risk control path template corresponding to the target business scenario in the first database, wherein the first risk control path template includes all risk monitoring points set according to the business process of the target business scenario and the risk control rules corresponding to the risk monitoring points;

[0044] Accordingly, step S101 may include:

[0045] Step S1011: Determine all risk monitoring points corresponding to the target business scenario based on the first risk control path template;

[0046] Step S102 may include:

[0047] Step S1012: Determine the risk control rules corresponding to each of the risk monitoring points based on the first risk control path template;

[0048] Step S103 may include:

[0049] Step S1031: Perform risk monitoring on the target business scenario based on all risk monitoring points in the first risk control path template and the risk control rules corresponding to the risk monitoring points.

[0050] In the above implementation, a corresponding first risk control path template can be pre-set for each business scenario, and all risk monitoring points and corresponding risk control rules for each risk monitoring point in the target business scenario can be set in the first risk control path template and stored in the first database. When this implementation is running, the first risk control path template corresponding to the target business scenario can be directly queried in the first database, and all risk monitoring points and their risk control rules corresponding to the target business scenario can be determined according to the first risk control path template. Then, risk control can be performed on the target business scenario according to all the risk monitoring points and their corresponding risk control rules.

[0051] Through the above implementation method, all risk monitoring points and their risk control rules in the target business scenario can be organically linked and integrated using the first risk control path template, and managed separately. This can improve the portability and replicability of the risk control method, and it can be directly and specifically invoked when risk control is required, thus effectively improving the overall risk control efficiency.

[0052] It should be noted that in actual implementation, the first risk control path template corresponding to the target business scenario may not be found in the first database. Therefore, please refer to [the relevant documentation / reference]. Figure 3 In some implementations, after querying the first risk control path template corresponding to the target business scenario in the first database, the method may further include:

[0053] Step S1041: If no first risk control path template corresponding to the target business scenario is found in the first database, then the first risk control path template corresponding to the target business scenario is generated according to the business process corresponding to the target business scenario, all risk monitoring points and the risk control rules corresponding to the risk monitoring points.

[0054] Through the above implementation methods, any omissions or deficiencies can be identified and addressed in a timely manner, ensuring the smooth implementation of the risk control methods.

[0055] Accordingly, based on the above implementation methods, please refer to Figure 3 The method may further include: step S1042: adding the generated first risk control path template to the first database. Through this embodiment, the newly created first risk control path template can be added to the first database in a timely manner, enriching the first database and facilitating subsequent repeated use, thereby improving overall risk control efficiency.

[0056] exist Figure 1 Based on the corresponding embodiments, please refer to other embodiments. Figures 4 to 6Step S101 may include step S1012: querying all risk monitoring points corresponding to the target business scenario in the second database.

[0057] In this embodiment, all risk monitoring points and risk control rules corresponding to the target business scenario can be pre-entered into the second database, or all risk monitoring points and risk control path templates containing risk control rules corresponding to the target business scenario can be pre-entered into the second database and queried in real time when needed. Compared with the aforementioned method of using the first risk control path template for templated management, this method is more flexible in implementation.

[0058] Accordingly, step S102 may specifically include the following two implementation methods:

[0059] Method 1, please refer to Figure 4 If the second database includes risk monitoring points and risk control rules, then step S102 may include:

[0060] Step S1022: Query the risk control rules corresponding to each of the risk monitoring points in the second database.

[0061] Method 2, please refer to Figure 5 If the second database includes risk monitoring points and a second risk control path template containing risk control rules, then step S102 may include:

[0062] Step S1024: Query the second database for all second risk control path templates corresponding to all the risk monitoring points;

[0063] Step S1025: Query the third risk control path template corresponding to the target business scenario from all the second risk control path templates, wherein the third risk control path template includes risk control rules corresponding to all the risk monitoring points set according to the business process of the target business scenario;

[0064] Step S1026: Determine the risk control rules corresponding to each of the risk monitoring points according to the third risk control path template.

[0065] Through this implementation method, the risk control rules can be managed using the (second) risk control path template, resulting in better management efficiency.

[0066] Considering that the third risk control path template may not be included in all the second risk control path templates, please refer to... Figure 5In some implementations, based on the foregoing implementations, after querying the third risk control path template corresponding to the target business scenario from all the second risk control path templates, the process may further include:

[0067] Step S1027: If no third risk control path template corresponding to the target business scenario is found from all the second risk control path templates, then generate the third risk control path template corresponding to the target business scenario based on the business process corresponding to the target business scenario, all the risk monitoring points and the risk control rules corresponding to all the risk monitoring points.

[0068] Through the above implementation methods, any omissions or deficiencies can be identified and addressed in a timely manner, ensuring the smooth implementation of the risk control methods.

[0069] Accordingly, please refer to Figure 5 In some embodiments, after the steps of the above embodiments, the following may also be included:

[0070] Step S1028: Add the generated third risk control path template to the second database.

[0071] This implementation method allows newly created third risk control path templates to be added to the second database in a timely manner, enriching the second database and facilitating subsequent repeated calls, thereby improving the overall efficiency of risk control.

[0072] Based on the above implementation method, please refer to Figure 4 and Figure 5 After querying the second database for all risk monitoring points corresponding to the target business scenario, the process may further include:

[0073] Step S1051: If no risk monitoring points corresponding to the target business scenario are found in the second database, then the business nodes adjacent to the missing risk monitoring points are determined according to the business process of the target business scenario.

[0074] Step S1052: Add the missing risk monitoring points between the adjacent business nodes to the second database.

[0075] This implementation method allows for timely identification and correction of deficiencies, addition of missing risk monitoring points, and ensures the smooth implementation of the risk control method.

[0076] Furthermore, in the aforementioned Figure 5 Based on the corresponding implementation method, considering that if the second database lacks all risk monitoring points corresponding to the target business scenario, it is highly likely that it will also not contain a third risk control path template corresponding to the target business scenario, therefore, in the above... Figure 5 For some modified implementation methods corresponding to the corresponding implementation method, please refer to Figure 6 If the control rules are recorded using a risk control path template, then after step S1052 adds the missing risk monitoring points between the adjacent business nodes to the second database, it may further include:

[0077] Step S1053: Generate a fourth risk control path template corresponding to the target business scenario based on the business process corresponding to the target business scenario, all risk monitoring points and risk control rules corresponding to all risk monitoring points, wherein the fourth risk control path template includes risk control rules corresponding to all the risk monitoring points set according to the business process of the target business scenario.

[0078] Accordingly, step S102 includes:

[0079] Step S1023: Determine the risk control rules corresponding to each of the risk monitoring points according to the fourth risk control path template.

[0080] This implementation method eliminates the need to search for the second and third risk control path templates in the second database after adding missing risk monitoring points. Instead, it allows for the direct and timely supplementation of the corresponding fourth risk control path template, ensuring that risk control can be successfully completed based on the fourth risk control path template, resulting in higher overall risk control efficiency.

[0081] Accordingly, in some embodiments, after the above steps, the method may further include adding the generated fourth risk control path template to the second database. This embodiment allows for the timely addition of the newly created fourth risk control path template to the second database, enriching the database and facilitating subsequent repeated use, thereby improving overall risk control efficiency.

[0082] It should be noted that the third risk control path template and the fourth risk control path template mentioned in the aforementioned multiple embodiments are all members of the second risk control path template. They are named "third" and "fourth" only because they correspond to the target business scenario, in order to distinguish them and more clearly describe the different implementation methods. They do not imply any limiting meaning.

[0083] Based on any of the foregoing embodiments, in some implementations, step S103 may include:

[0084] Based on the risk control rules of the current risk monitoring point, a risk assessment is performed on the user behavior of the business node preceding the current risk monitoring point, and risk control is performed on the business node following the current risk monitoring point based on the risk assessment results.

[0085] Specifically, the risk control rules may include risk identification rules for prior business nodes and risk control rules for subsequent business nodes;

[0086] The step of conducting a risk assessment of user behavior at the preceding business node of the current risk monitoring point based on the risk control rules of the current risk monitoring point, and then conducting risk control on the following business node based on the risk assessment results, includes:

[0087] Obtain the user behavior data of the previous business node of the current risk monitoring point;

[0088] Based on the user behavior data, the risk assessment is performed on the user behavior of the previous business node of the current risk monitoring point using the risk identification rules, and the risk assessment result is obtained.

[0089] Based on the risk assessment results, the risk control rules are used to control the risk of the next business node after the current risk monitoring point.

[0090] Through the above implementation methods, business nodes before and after the risk monitoring point can be effectively linked. For example, if a user enters the wrong password multiple times when logging in, even after successfully logging in, the risk assessment of the user's repeated password errors can be performed. This can yield a risk assessment result indicating that the user's credibility is low and the risk is high. Based on this risk assessment result, stricter risk control measures can be taken in subsequent business nodes to control the risk, thereby reducing potential business risks and improving security as a whole.

[0091] Based on the above implementation methods, in some implementation methods, the risk control rules include multiple risk control sub-rules corresponding to different risk levels;

[0092] The step of applying the risk control rules to perform risk control on the next business node after the current risk monitoring point based on the risk assessment results may include:

[0093] Determine the risk level corresponding to the risk assessment results;

[0094] Select the risk control sub-rule corresponding to the determined risk level to perform risk control on the next business node after the current risk monitoring point.

[0095] This implementation method allows for setting corresponding risk levels based on different risk assessment results, and setting corresponding risk control sub-rules for different risk levels, thereby enabling risk control at different levels.

[0096] It is readily understood that the risk control method provided in this application embodiment can be applied to risk monitoring of various businesses such as non-bank payment accounts (e.g., e-wallets), internet acquiring products, bank card acquiring products, and prepaid card issuance and acceptance products. By breaking down the business process into its components and setting risk monitoring points, full-chain risk prevention and control can be achieved, significantly improving the coverage of risk identification and control.

[0097] In the above embodiments, a risk control method is provided. Correspondingly, this application also provides a risk control device. The risk control device provided in this application can implement the above-described risk control method. This risk control device can be implemented through software, hardware, or a combination of both. For example, the risk control device may include integrated or separate functional modules or units to perform the corresponding steps in the above methods. Please refer to... Figure 7 This is a schematic diagram of a risk control device provided in some embodiments of this application. Since the device embodiments are basically similar to the method embodiments, the description is relatively simple; relevant details can be found in the description of the method embodiments. The device embodiments described below are merely illustrative.

[0098] like Figure 7 As shown in the embodiment of this application, a risk control device 10 includes:

[0099] The monitoring point determination module 101 is used to determine all risk monitoring points corresponding to the target business scenario, wherein the risk monitoring points are distributed among the business nodes of the target business scenario;

[0100] The monitoring rule determination module 102 is used to determine the risk control rule corresponding to each of the risk monitoring points;

[0101] The risk control module 103 is used to perform risk control on the target business scenario based on all the risk monitoring points and their corresponding risk control rules.

[0102] In some modified embodiments of this application, the device 10 further includes:

[0103] The risk control path query module is used to query the database for a first risk control path template corresponding to the target business scenario. The first risk control path template includes all risk monitoring points set according to the business process of the target business scenario and the risk control rules corresponding to the risk monitoring points.

[0104] The risk control module 103 includes:

[0105] The risk control unit is used to monitor the target business scenario based on all risk monitoring points in the first risk control path template and the risk control rules corresponding to the risk monitoring points.

[0106] In some modified embodiments of this application, the device 10 further includes:

[0107] The risk control path generation module is used to generate a first risk control path template corresponding to the target business scenario based on the business process corresponding to the target business scenario, all risk monitoring points, and the risk control rules corresponding to the risk monitoring points if no first risk control path template corresponding to the target business scenario is found in the first database.

[0108] In some modified embodiments of this application, the device 10 further includes:

[0109] The risk control path adding module is used to add the generated first risk control path template to the database.

[0110] In some modified embodiments of this application, the monitoring point determination module 101 includes:

[0111] The monitoring point query unit is used to query all risk monitoring points corresponding to the target business scenario in the second database.

[0112] In some modified embodiments of this application, the monitoring point determination module 101 further includes:

[0113] The monitoring point determination unit is used to determine the business node adjacent to the missing risk monitoring point based on the business process of the target business scenario if no risk monitoring point corresponding to the target business scenario is found in the second database.

[0114] Indeed, the monitoring point addition unit is used to add missing risk monitoring points between the adjacent business nodes in the second database.

[0115] In some modified embodiments of this application, the risk control module 103 includes:

[0116] The risk control unit is used to assess the risk of user behavior of the business node preceding the current risk monitoring point according to the risk control rules of the current risk monitoring point, and to control the risk of the business node following the current risk monitoring point based on the risk assessment results.

[0117] In some modified embodiments of this application, the risk control rules include risk identification rules for prior business nodes and risk control rules for subsequent business nodes;

[0118] The risk control unit includes:

[0119] The user behavior data acquisition subunit is used to acquire user behavior data of the previous business node of the current risk monitoring point.

[0120] The risk assessment subunit is used to assess the user behavior of the previous business node of the current risk monitoring point based on the user behavior data and the risk identification rules, and obtain the risk assessment result.

[0121] The risk control subunit is used to perform risk control on the next business node after the current risk monitoring point based on the risk assessment results and the risk control rules.

[0122] In some modified embodiments of this application, the risk control rules include multiple risk control sub-rules corresponding to different risk levels;

[0123] The risk control subunit includes:

[0124] The risk level determination subunit is used to determine the risk level corresponding to the risk assessment result.

[0125] The risk control subunit is used to select the risk control sub-rule corresponding to the determined risk level to perform risk control on the next business node after the current risk monitoring point.

[0126] The risk control device 10 provided in this application embodiment is based on the same inventive concept as the risk control method provided in the foregoing embodiments of this application and has the same beneficial effects.

[0127] In the above embodiments, a risk control method and apparatus are provided. Correspondingly, this application also provides an electronic device, which can be any computing device with data and graphics processing capabilities, such as a mobile phone, laptop computer, tablet computer, desktop computer, etc. Please refer to... Figure 8 , Figure 8 This is a schematic diagram of an electronic device provided for some embodiments of this application. For example... Figure 8 As shown, the electronic device 20 includes: a processor 200, a memory 201, a bus 202, and a communication interface 203. The processor 200, the communication interface 203, and the memory 201 are connected via the bus 202. The memory 201 stores a computer program that can run on the processor 200. When the processor 200 runs the computer program, it executes the risk control method provided in this application.

[0128] The memory 201 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 203 (which can be wired or wireless), such as the Internet, wide area network, local area network, or metropolitan area network.

[0129] Bus 202 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory 201 is used to store programs. After receiving an execution instruction, the processor 200 executes the program. The risk control method disclosed in any of the foregoing embodiments of this application can be applied to the processor 200, or implemented by the processor 200.

[0130] The processor 200 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the processor 200 or by instructions in software form. The processor 200 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules may reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 201. The processor 200 reads the information in memory 201 and, in conjunction with its hardware, completes the steps of the above method.

[0131] The electronic devices and risk control methods provided in this application are based on the same inventive concept and have the same beneficial effects.

[0132] This application also provides a computer-readable medium corresponding to the above-described risk control method. Please refer to... Figure 9 The computer-readable storage medium shown is an optical disc 30, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it executes the risk control method provided in any of the foregoing embodiments.

[0133] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical and magnetic storage media, which will not be elaborated here.

[0134] The computer-readable storage medium provided in this application embodiment and the risk control method provided in this application embodiment are based on the same inventive concept and have the same beneficial effects.

[0135] It should be noted that the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0136] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0137] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.

[0138] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0139] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0140] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0141] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application, and they should all be covered within the scope of the claims and specification of this application.

Claims

1. A risk control method, characterized by, The method comprises the following steps: setting a first risk control path template corresponding to each target business scenario in advance, setting all risk monitoring points in the target business scenario and risk control rules corresponding to each risk monitoring point in the first risk control path template, and storing the first risk control path template in a first database; querying the first risk control path template corresponding to the target business scenario in the first database, wherein the first risk control path template comprises all risk monitoring points set according to the business process of the target business scenario and risk control rules corresponding to the risk monitoring points; determining all risk monitoring points corresponding to the target business scenario, wherein the risk monitoring points are distributed between each business node of the target business scenario; determining the risk control rules corresponding to each risk monitoring point; controlling the risk of the target business scenario according to all risk monitoring points and the risk control rules corresponding to the risk monitoring points; wherein the user behavior data of the previous business node of the current risk monitoring point is obtained; risk assessment of the user behavior of the previous business node of the current risk monitoring point is performed according to the user behavior data and the risk identification rules to obtain a risk assessment result; risk control of the next business node of the current risk monitoring point is performed according to the risk assessment result and the risk control rules. The risk control includes rejection, permission limitation, suspension of business, early warning, freezing and risk level increase of the user.

2. The method of claim 1, wherein, The risk control of the target business scenario according to the risk monitoring points and the risk control rules corresponding to the risk monitoring points comprises: risk monitoring of the target business scenario according to all risk monitoring points in the first risk control path template and the risk control rules corresponding to the risk monitoring points.

3. The method of claim 2, wherein, After querying the first risk control path template corresponding to the target business scenario in the first database, the method further comprises the following steps: if the first risk control path template corresponding to the target business scenario is not queried in the first database, generating the first risk control path template corresponding to the target business scenario according to the business process of the target business scenario, all risk monitoring points and the risk control rules corresponding to the risk monitoring points.

4. The method of claim 3, wherein, After generating the first risk control path template corresponding to the target business scenario, the method further comprises the following steps: adding the generated first risk control path template to the first database.

5. The method of claim 1, wherein, The determination of all risk monitoring points corresponding to the target business scenario further comprises the following steps: querying all risk monitoring points corresponding to the target business scenario in a second database, wherein the second database is a database in which all risk monitoring points and risk control rules corresponding to the target business scenario are recorded in advance.

6. The method of claim 5, wherein, After querying all risk monitoring points corresponding to the target business scenario in the second database, the method further comprises the following steps: if all risk monitoring points corresponding to the target business scenario are not queried in the second database, determining the business node adjacent to the missing risk monitoring point according to the business process of the target business scenario. adding a missing risk monitoring point between the adjacent business nodes in the second database.

7. The method of claim 1, wherein, the risk control on the target business scenario according to all the risk monitoring points and corresponding risk control rules comprises: risk assessment on user behavior of a previous business node of a current risk monitoring point according to a risk control rule of the current risk monitoring point, and risk control on a next business node of the current risk monitoring point according to a risk assessment result.

8. The method of claim 7, wherein, the risk control rule comprises a risk identification rule for a previous business node and a risk control rule for a next business node; the risk control on the target business scenario according to all the risk monitoring points and corresponding risk control rules comprises: obtaining user behavior data of a previous business node of a current risk monitoring point; risk assessment on user behavior of the previous business node of the current risk monitoring point according to the risk identification rule based on the user behavior data, to obtain a risk assessment result; risk control on a next business node of the current risk monitoring point according to the risk control rule based on the risk assessment result.

9. The method of claim 8, wherein, the risk control rule comprises a plurality of risk control sub-rules corresponding to different risk levels; the risk control on the target business scenario according to all the risk monitoring points and corresponding risk control rules comprises: determining a risk level corresponding to the risk assessment result; selecting a risk control sub-rule corresponding to the determined risk level to perform risk control on the next business node of the current risk monitoring point.

10. An electronic device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method of any one of claims 1-9.

11. A computer readable medium having stored thereon computer readable instructions executable by a processor to implement the method of any one of claims 1-9.

Citation Information

Patent Citations

  • Realization method and device for general data quality control adapter

    CN102571403A

  • Risk control feature generating method, risk monitoring method and devices

    CN107424069A