Business Data Management Method, Device, Equipment and Computer Readable Storage Medium
The integration of identity verification and data signing services addresses data access rights verification issues in business data management, enhancing security and efficiency by validating user identities and signing data transactions, thus reducing development costs and improving quality.
Patent Information
- Application Number
- CN202011235593.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-06
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2040-11-06
AI Technical Summary
In the prior art, business data management has problems with data overright and difficulty in maintaining it. Business developers need to process additional security logic, resulting in inefficient development.
User identity authentication and business data authentication are carried out through the identity authentication service platform and the signature service platform, and timely user business data authentication is realized without additional storage costs, so as to free business developers from security issues.
It improves the efficiency and quality of business service development, reduces the cost of development and architecture, and avoids users' overreach of their rights to view other user data.
Smart Images

Figure CN112149172B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security, and particularly to a method, device, equipment and computer-readable storage medium for business data management. Background Art
[0002] In terms of data security issues, more or less security problems basically exist in the business systems of each WEB service. Among them, the most likely problem is data over-authorization, that is, after user A logs in to the system through legal authentication, through certain means, user A obtains the data of user B, thus stealing the data of other users and causing the leakage of user data.
[0003] The problem of user data leakage is caused by the lack of legal verification of the ownership of user data in the design of service interfaces of the system. That is, when a user obtains data according to certain codes, the system needs to determine whether the user with the code has the permission to view. Because usually data authentication does not affect the development of business functions. For example, for a service that queries a certain business data according to a certain code, the design of the service interface usually defines a certain code as the input parameter, and the verification of whether the user has logged in is handed over to the authentication system for processing. Business developers do not need to care about this, but this has caused the generation of data over-authorization security risks. The traditional solution is that when a business developer pulls business data according to the user's credentials, the mapping relationship between the user's credentials and the user's business data is persisted to the server side. Whenever a user queries data according to a certain business code, the business developer then judges whether the code exists in the persistence according to the user's credentials and the code for querying business data to determine whether there is over-authorization. This part of the logic has nothing to do with the business logic, but business developers need to handle this part of the logic. If they are slightly careless, it will lead to the generation of over-authorization, and at the same time, it will also lead to difficult management and maintenance.
[0004] The above content is only used to assist in understanding the technical solution of the present invention, and does not represent an admission that the above content is prior art. Summary of the Invention
[0005] The main purpose of the present invention is to provide a method, device, equipment and computer-readable storage medium for business data management, aiming to solve the technical problem of difficult management and maintenance of business data in the prior art.
[0006] To achieve the above purpose, the present invention provides a method for business data management, and the method for business data management includes the following steps:
[0007] Receive a business data query request sent by a client, obtain the user identity information associated with the business data query request, and determine whether the user identity information is verified through an identity authentication service platform;
[0008] If the user identity information verification is passed, an access credential is sent to the client through the identity authentication service platform;
[0009] Receive a business data query request containing an access credential sent by the client, and forward the business data query request to the business service platform through the signature service platform;
[0010] Receive the user business data sent by the business service platform, sign the user business data through the signature service platform, and send the signed user business data to the client.
[0011] Optionally, the steps of receiving the business data query request sent by the client, obtaining the user identity information associated with the business data query request, and determining whether the user identity information is verified through the identity authentication service platform include:
[0012] Receive the business data query request sent by the client, and obtain the business query information associated with the business data query request;
[0013] Input the business query information into a preset risk classification model, and determine the risk type of the business query information through the preset risk classification model;
[0014] When the risk type is high risk, obtain the user identity information associated with the business data query request, and determine whether the user identity information is verified through the identity authentication service platform.
[0015] Optionally, before the step of inputting the business query information into a preset risk classification model and determining the risk type of the business query information through the preset risk classification model, it further includes:
[0016] Obtain a sample data set of business query events to construct an initial risk classification model based on the sample data set;
[0017] Take the output of any layer of the initial risk classification model as the target variable, take the predefined clustering dimension as the independent variable, construct a multi-branch decision tree, and divide the sample data in the sample data set to form sample data subsets;
[0018] Train the initial risk classification model based on each of the sample data subsets to obtain a customer group analysis sub-model;
[0019] Combine the stratification rules in each of the customer group analysis sub-models to determine the preset risk classification model.
[0020] Optionally, the steps of inputting the business query information into a preset risk classification model and determining the risk type of the business query information through the preset risk classification model include:
[0021] Determine the permission level corresponding to the service query information based on the user identity information, and sort the service query information according to the permission level and the temporal relationship corresponding to the service query information to obtain an input variable;
[0022] Input the input variable into the pre-trained preset risk classification model to determine the classification result corresponding to the service query information, where the classification result at least includes the risk type corresponding to the service query information.
[0023] Optionally, the step of determining the permission level corresponding to the service query information based on the user identity information and sorting the service query information according to the permission level and the temporal relationship corresponding to the service query information to obtain an input variable includes:
[0024] Determine the permission level corresponding to the service query information according to the mapping relationship between the preset user identity information set and the preset permission level set and the user identity information;
[0025] Sort the service query information according to the permission level and the temporal relationship corresponding to the service query information to obtain an input variable.
[0026] Optionally, the step of receiving the service data query request containing the access credential sent by the client and forwarding the service data query request to the service platform through the signature service platform includes:
[0027] Receive the service data query request containing the access credential sent by the client, forward the service data query request to the signature service platform for the signature service platform to perform signature verification on the service query request based on the access credential, and forward the service data query request to the service platform when the service query request passes the verification;
[0028] After the step of receiving the user service data sent by the service platform, signing the user service data through the signature service platform, and sending the signed user service data to the client, further includes:
[0029] Receive the user service data sent by the service platform, and forward the user service data to the signature service platform for the signature service platform to determine the signature information based on the access credential and the request time corresponding to the service data query request when receiving the user service data, sign the user service data based on the signature information, and send the signed user service data to the client.
[0030] Optionally, after the step of receiving user service data sent by the receiving service platform, signing the user service data through the signature service platform, and sending the signed user service data to the client, the method further includes:
[0031] When receiving a service operation request sent by the client, send the service operation request including the signature information to the signature service platform to verify the signature information through the signature service platform. Wherein, when the client receives the user service data including the signature information, it parses the user service data to obtain the signature information included in the user service data header, and when detecting that the service triggers a service operation request, it associates and sends the parsed signature information with the service operation request to the server;
[0032] When the signature information verification fails, reject the service operation request;
[0033] When the signature information verification passes, send the service operation request including the signature information to the service platform for the service platform to respond to the service operation request.
[0034] In addition, to achieve the above object, the present invention further provides a service data management device, the service data management device includes:
[0035] A verification module, configured to receive a service data query request sent by the client, obtain user identity information associated with the service data query request, and determine whether the user identity information is verified through by the identity authentication service platform;
[0036] A sending module, configured to, if the user identity information is verified through, send an access credential to the client through the identity authentication service platform;
[0037] A forwarding module, configured to receive a service data query request including an access credential sent by the client, and forward the service data query request to the service platform through the signature service platform;
[0038] A signature module, configured to receive user service data sent by the service platform, sign the user service data through the signature service platform, and send the signed user service data to the client.
[0039] In addition, to achieve the above object, the present invention further provides a service data management device, the service data management device includes: a memory, a processor, and a service data management program stored on the memory and executable on the processor, and when the service data management program is executed by the processor, the steps of the service data management method as described above are implemented.
[0040] In addition, to achieve the above object, the present invention also provides a computer-readable storage medium, on which a service data management program is stored. When the service data management program is executed by a processor, the steps of the service data management method as described above are implemented.
[0041] The present invention receives a service data query request sent by a client, obtains the user identity information associated with the service data query request, and determines whether the user identity information is verified through an identity authentication service platform; if the user identity information is verified, an access credential is sent to the client through the identity authentication service platform; receives a service data query request containing the access credential sent by the client, and forwards the service data query request to the service platform through a signature service platform; receives the user service data sent by the service platform, signs the user service data through the signature service platform, and sends the signed user service data to the client. In this embodiment, by converting the traditional server to provide service data authentication services to the authentication services provided by the identity authentication service platform and the signature service platform, that is, verifying the user identity information through the identity authentication service platform, and performing service data authentication between the signature service platform and the client, it is possible to achieve without additional storage costs, provide a time-sensitive user service data authentication service, and at the same time free the service developers from the concern about the data security issues of each service interface, allowing them to only focus on the development of the service platform, rather than other issues such as security outside the service, thereby improving the development efficiency and quality and reducing the costs of service development and architecture. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 is a schematic structural diagram of a service data management device in the hardware operating environment related to the embodiment of the present invention;
[0043] Figure 2 is a schematic flowchart of the first embodiment of the service data management method of the present invention;
[0044] Figure 3 is a schematic flowchart of the second embodiment of the service data management method of the present invention.
[0045] The implementation, functional features, and advantages of the object of the present invention will be further described in conjunction with the embodiments with reference to the drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0047] As Figure 1 shown, Figure 1 is a schematic structural diagram of a terminal in the hardware operating environment related to the embodiment of the present invention.
[0048] The business data management device in the embodiment of the present invention may be a PC, or a mobile terminal device with a display function such as a smart phone, a tablet computer, an e-book reader, an MP3 (Moving Picture Experts Group Audio Layer III) player, an MP4 (Moving Picture Experts Group Audio Layer IV) player, and a portable computer.
[0049] As Figure 1 shown, the business data management device may include: a processor 1001, such as a CPU, a network interface 1004, a user interface 1003, a memory 1005, and a communication bus 1002. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display) and an input unit such as a keyboard (Keyboard). Optionally, the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory or a stable memory (non-volatile memory), such as a disk memory. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0050] Optionally, the business data management device may further include a camera, an RF (Radio Frequency) circuit, sensors, an audio circuit, a WiFi module, etc. Among them, the sensors include, for example, a light sensor, a motion sensor, and other sensors.
[0051] Those skilled in the art can understand that Figure 1 the structure of the business data management device shown in
[0052] As Figure 1 shown, the memory 1005, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a business data management program.
[0053] In Figure 1In the business data management device shown, the network interface 1004 is mainly used to connect to the back-end server and communicate data with the back-end server; the user interface 1003 is mainly used to connect to the client (user side) and communicate data with the client; and the processor 1001 can be used to call the business data management program stored in the memory 1005.
[0054] In this embodiment, the business data management device includes: a memory 1005, a processor 1001, and a business data management program stored on the memory 1005 and executable on the processor 1001. Among them, when the processor 1001 calls the business data management program stored in the memory 1005, the following operations are performed:
[0055] Receive a business data query request sent by the client, obtain the user identity information associated with the business data query request, and determine whether the user identity information is verified through the identity authentication service platform;
[0056] If the user identity information is verified, send an access credential to the client through the identity authentication service platform;
[0057] Receive a business data query request containing an access credential sent by the client, and forward the business data query request to the business service platform through the signature service platform;
[0058] Receive the user's business data sent by the business service platform, sign the user's business data through the signature service platform, and send the signed user's business data to the client.
[0059] Further, the processor 1001 can call the business data management program stored in the memory 1005 and perform the following operations:
[0060] Receive a business data query request sent by the client, and obtain the business query information associated with the business data query request;
[0061] Input the business query information into a preset risk classification model, and determine the risk type of the business query information through the preset risk classification model;
[0062] When the risk type is high risk, obtain the user identity information associated with the business data query request, and determine whether the user identity information is verified through the identity authentication service platform.
[0063] Further, the processor 1001 can call the business data management program stored in the memory 1005 and perform the following operations:
[0064] Obtain a sample data set of business query events to construct an initial risk classification model based on the sample data set;
[0065] Use the output of any layer of the initial risk classification model as the target variable, use the predefined clustering dimension as the independent variable, construct a multi-branch decision tree, and divide the sample data in the sample dataset to form sample data subsets;
[0066] Train the initial risk classification model based on each of the sample data subsets to obtain a customer group analysis sub-model;
[0067] Combine the stratification rules in each of the customer group analysis sub-models to determine the preset risk classification model.
[0068] Further, the processor 1001 can call the service data management program stored in the memory 1005 and also perform the following operations:
[0069] Determine the permission level corresponding to the service query information based on the user identity information, and sort the service query information according to the permission level and the timing relationship corresponding to the service query information to obtain an input variable;
[0070] Input the input variable into the preset risk classification model that has been pre-trained to determine the classification result corresponding to the service query information, where the classification result at least includes the risk type corresponding to the service query information.
[0071] Further, the processor 1001 can call the service data management program stored in the memory 1005 and also perform the following operations:
[0072] Determine the permission level corresponding to the service query information according to the mapping relationship between the preset user identity information set and the preset permission level set and the user identity information;
[0073] Sort the service query information according to the permission level and the timing relationship corresponding to the service query information to obtain an input variable.
[0074] Further, the processor 1001 can call the service data management program stored in the memory 1005 and also perform the following operations:
[0075] Receive a service data query request containing an access credential sent by the client, forward the service data query request to the signature service platform for the signature service platform to perform signature verification on the service query request based on the access credential, and forward the service data query request to the service platform when the service query request passes the verification;
[0076] After the step of receiving the user service data sent by the service platform, signing the user service data through the signature service platform, and sending the signed user service data to the client, further include:
[0077] Receive the user service data sent by the service platform, and forward the user service data to the signature service platform, so that when the signature service platform receives the user service data, it determines the signature information based on the access credential and the request time corresponding to the service data query request, and signs the user service data based on the signature information, and sends the signed user service data to the client.
[0078] Further, the processor 1001 may call the service data management program stored in the memory 1005 and further perform the following operations:
[0079] When receiving a service operation request sent by the client, send the service operation request including the signature information to the signature service platform to verify the signature information through the signature service platform. Wherein, when the client receives the user service data including the signature information, it parses the user service data to obtain the signature information included in the user service data header, and when detecting that the service triggers a service operation request, it associates and sends the parsed signature information with the service operation request to the server;
[0080] When the signature information verification fails, reject the service operation request;
[0081] When the signature information verification passes, send the service operation request including the signature information to the service platform for the service platform to respond to the service operation request.
[0082] The present invention also provides a service data management method, referring to Figure 2 , Figure 2 is a schematic flowchart of the first embodiment of the service data management method of the present invention.
[0083] In this embodiment, the service data management method includes the following steps:
[0084] Step S10, receive the service data query request sent by the client, obtain the user identity information associated with the service data query request, and determine whether the user identity information is verified through the identity authentication service platform;
[0085] The service data management method proposed by the present invention is applied to a server, and the server is communicatively connected to a client, a signature service platform, an identity authentication service platform, and a service platform. Wherein, the client is a software service platform that provides preset services for users, such as an APP or a web platform, etc.
[0086] When the client receives a business data query instruction from the user or there is a business data query task, it sends a business data query request to the server. The server receives the business data query request sent by the client, obtains the user identity information associated with the business data query request, and the server sends the user identity information to the identity authentication service platform. The identity authentication service platform queries the preset user identity information set. The identity authentication service platform determines whether the preset user identity information set contains the user identity information sent by the client. If the user identity information set contains the user identity information sent by the client, the user identity information verification passes. If the user identity information set does not contain the user identity information sent by the client, the user identity information verification fails. It should be noted that the identity authentication service platform stores a pre-registered user identity information set.
[0087] Step S20, if the user identity information verification passes, send an access credential to the client through the identity authentication service platform;
[0088] If the user identity information verification passes, generate an access credential token based on the user identity information, and send the access credential token to the client through the identity authentication service platform. Among them, the access credential can be set according to the specific scenario. The access credential is a random and non-repeating verification code or verification combination code, which can be composed of 16-bit random string + 14-bit request time character (yyyyMMddHHmmss) + signature. The composition rule of the access credential is as follows: 1. The identity authentication service platform generates a preset string according to the user identity information through a preset algorithm, denoted as: signature. The preset string is the part or all of the user identity information carried in the signature. 2. The identity authentication service platform then splits and combines according to the following rules to form the final access credential: 4-bit random character + 5-bit request time character + the first 8 characters of the signature + 4-bit random character + 5-bit request time character + the 9th to 16th characters of the signature + 4-bit request time + 4-bit random character + the remaining characters of the signature + 4-bit random character). Among them, the request time is the time stamp corresponding to the business data query request, and the business data query request carries the time stamp.
[0089] The terminal receives the access credential sent by the user identity authentication service platform and accesses the data according to the access credential. That is, the terminal generates a business data query request containing the access credential and sends the business data query request to the server.
[0090] Step S30, receive the business data query request containing the access credential sent by the client, and forward the business data query request to the business service platform through the signature service platform;
[0091] The server receives a business data query request containing an access credential sent by the client. The server sends the business data query request to the signature service platform, and the signature service platform forwards the business data query request to the business service platform for the business service platform to query the user's business data set based on the business data query request and return it to the server.
[0092] Specifically: The signature service platform obtains the business code in the business data query request submitted by the user, as well as the signature information in the request header and the user's access credential token. The signature service platform signs the business code and then compares it with the signature information in the request header to determine whether the values are consistent. If they are consistent, it means that the information of the business code requested by the user belongs to the user and is a legal request. If they are inconsistent, it proves that the data of this request does not belong to the current requesting user and is an illegal request. At this time, the signature service will reject the user's request, thus avoiding the user from viewing other users' information beyond their authority.
[0093] Step S40: Receive the user's business data sent by the business service platform, sign the user's business data through the signature service platform, and send the signed user's business data to the client.
[0094] The server receives the user's business data sent by the business service platform, signs the user's business data through the signature service platform (the method of data signature is not specifically limited), and the server sends the signed user's business data to the client. Specifically, when the business service platform receives the business data query request sent by the signature service platform, the business service platform obtains the business data set associated with the business data query request and sends the business data set to the signature service platform; the signature service platform receives the business data set sent by the business service platform, and the signature service platform verifies the signature of the business data set; the signature service platform sends the signed business data set to the client.
[0095] In one embodiment, the client receives a set of service data containing signature information, and the client parses the set of service data to obtain the signature information included in the header of the set of service data. When the client detects that a service triggers a service operation request, the client associates the parsed signature information with the service operation request and sends it to the server. The server receives the service operation request sent by the client, and the server sends the service operation request containing the signature information to the signature service platform. When the signature service platform receives the service operation request containing the signature information, it obtains the signature information in the service operation request and verifies the signature information. The signature service platform feeds back the verification result corresponding to the verification of the signature information to the server for the server to perform corresponding operations based on the verification result corresponding to the signature information. When the signature information fails to pass the verification, the server rejects the service operation request. When the signature information passes the verification, the server sends the service operation request containing the signature information to the service platform to respond to the service operation request through the service platform.
[0096] The service data management method proposed in this embodiment obtains the user identity information associated with the service data query request by receiving the service data query request sent by the client, and determines whether the user identity information passes the verification through the identity authentication service platform. If the user identity information passes the verification, the identity authentication service platform sends an access credential to the client. The service data query request containing the access credential sent by the client is forwarded to the service platform through the signature service platform. The user service data sent by the service platform is received, and the signature service platform signs the user service data and sends the signed user service data to the client. By converting the traditional service data authentication service provided by the server into the authentication service of service data based on the identity authentication service platform and the signature service platform, that is, verifying the user identity information through the identity authentication service platform and performing service data authentication between the signature service platform and the client, this embodiment realizes no additional storage cost, provides a time-sensitive user service data authentication service, and at the same time liberates service developers from the concern about the data security issues of each service interface, allowing them to only focus on the development of service services without having to worry about issues such as security other than services, thereby improving development efficiency and quality and reducing the costs of service development and architecture.
[0097] Based on the first embodiment, a second embodiment of the service data management method of the present invention is provided. Refer to Figure 3 , in this embodiment, step S10 includes:
[0098] Step S11, receiving a service data query request sent by the client and obtaining service query information associated with the service data query request;
[0099] Step S12: Input the service query information into a preset risk classification model, and determine the risk type of the service query information through the preset risk classification model;
[0100] Step S13: When the risk type is high risk, obtain the user identity information associated with the service data query request, and determine whether the user identity information is verified through the identity authentication service platform.
[0101] In this embodiment, a risk classification model is preset. The steps for setting the risk classification model include: obtaining a sample data set and constructing an initial risk classification model; using the output of any layer of the initial risk classification model as the target variable and the predefined clustering dimension as the independent variable to construct a multi-branch decision tree, dividing the sample data in the sample data set to form sample data subsets; training the initial risk classification model through each sample data subset respectively to obtain a customer group analysis sub-model; combining the stratification rules in each of the customer group analysis sub-models to obtain a risk classification model.
[0102] That is, the server obtains a sample data set and constructs an initial risk classification model. The server uses the output of any layer of the initial risk classification model as the target variable and the predefined clustering dimension as the independent variable to construct a multi-branch decision tree, divides the sample data in the sample data set to form sample data subsets. For example, since there are often differences in the credit performance among different customer groups, there are usually also differences in their influence under the same rule. Therefore, the server uses whether the data set hits a certain layer of rules of the initial model as the target variable and the clustering dimension (i.e., credit history, age, etc.) as the independent variable to construct a multi-branch decision tree, and divides the samples into subsets with significantly different rule influence surfaces, so as to achieve customer group division. To improve the interpretability of the clustering results, the number of customer groups is usually controlled within 2 - 4. The server divides the sample data corresponding to the branch nodes in the multi-branch decision tree into sample data subsets with different influence surfaces.
[0103] The server trains the initial risk classification model through each sample data subset respectively to obtain a customer group analysis sub-model. The server obtains the outermost layer stratification rule with the largest influence surface in each customer group analysis sub-model. The server combines each outermost layer stratification rule as the outermost layer of the model; moves each customer group analysis sub-model inward by one layer, and combines the second outermost layer stratification rules of each customer group analysis sub-model as the second outermost layer of the model. The server continues in this way until moving to the innermost layer of each customer group analysis sub-model, exhaustively listing all the stratification rule combinations formed by the moving levels to obtain multiple groups of customer group combination paths; the server selects the target customer group combination path with the highest performance from the multiple groups of customer group combination paths, and uses the target customer group combination path as the layer rule of the final model to obtain a risk classification model.
[0104] Further, before the step of inputting the service query information into a preset risk classification model to determine the risk type of the service query information through the preset risk classification model, the following steps are further included:
[0105] Obtain a sample data set of service query events to construct an initial risk classification model based on the sample data set;
[0106] Take the output of any layer of the initial risk classification model as the target variable, use the predefined clustering dimension as the independent variable, construct a multi-branch decision tree, and divide the sample data in the sample data set to form sample data subsets;
[0107] Train the initial risk classification model based on each of the sample data subsets to obtain a customer group analysis sub-model;
[0108] Combine the stratification rules in each of the customer group analysis sub-models to determine the preset risk classification model.
[0109] The server obtains a sample data set of a series of service query times, thereby constructing an initial risk classification model based on the sample data set. After that, the server takes the output of any layer of the initial risk classification model as the target variable, uses the predefined clustering dimension as the independent variable, constructs a multi-branch decision tree, divides the sample data in the sample data set to form sample data subsets. For example, since there are often differences in the credit performance among different customer groups, there are usually also differences in their impact scope under the same rule. Therefore, the server takes whether the data set hits a certain layer of rules of the initial model as the target variable, takes the clustering dimension (i.e., credit history, age, etc.) as the independent variable, constructs a multi-branch decision tree, and divides the samples into subsets with significantly different impact scopes of the rules, so as to achieve customer group division. To improve the interpretability of the clustering results, the number of customer groups is usually controlled within 2 to 4. The server divides the sample data corresponding to the branch nodes in the multi-branch decision tree into sample data subsets with different impact scopes.
[0110] The server trains the initial risk classification model through each sample data subset to obtain a customer group analysis sub-model. The server obtains the outermost layer stratification rule with the largest impact scope in each customer group analysis sub-model. The server combines each outermost layer stratification rule as the outermost layer of the model; moves each customer group analysis sub-model inward by one layer, combines the second outermost layer stratification rules of each customer group analysis sub-model as the second outermost layer of the model, and the server continues in this way until moving to the innermost layer of each customer group analysis sub-model, exhaustively listing all combinations of stratification rules formed by moving levels to obtain multiple groups of customer group combination paths; the server selects the target customer group combination path with the highest performance from the multiple groups of customer group combination paths, takes the target customer group combination path as the layer rule of the final model, and obtains a risk classification model.
[0111] Further, the step of inputting the service query information into a preset risk classification model and determining the risk type of the service query information through the preset risk classification model includes:
[0112] Determine the permission level corresponding to the service query information based on the user identity information, and sort the service query information according to the permission level and the temporal relationship corresponding to the service query information to obtain input variables;
[0113] Input the input variables into the preset risk classification model that has been pre-trained to determine the classification result corresponding to the service query information, where the classification result at least includes the risk type corresponding to the service query information.
[0114] Before inputting the service query information into the preset risk classification model for prediction, first perform data preprocessing on the service query information. Specifically, obtain the user identity information, and determine the permission level corresponding to the service query information based on the user identity information through the mapping relationship between the preset user identity information set and the preset permission level set; and extract the time information corresponding to each piece of information in the service query information, sort the time information according to the preset temporal relationship and permission level, so as to sort each piece of query information in the service query information, and finally obtain input variables. Preferably, use the permission level corresponding to each piece of information in the service query information as the first label, and use the temporal relationship as the second label, and perform two-dimensional sorting on each piece of information in the service query information based on the two dimensions of the first label and the second label. After the sorting is completed, input variables are obtained. For example, use the permission level corresponding to each piece of information in the service query information as the abscissa, and use the temporal relationship corresponding to the service query information as the ordinate to sort the service query information.
[0115] After obtaining the service query information with sorting completed, that is, after performing data processing on the service query information, input the input variables into the preset risk classification model that has been pre-trained to determine the classification result corresponding to the service query information. The classification result at least includes the risk type corresponding to the service query information. Further, the classification result may also include the risk probability corresponding to the risk type.
[0116] Further, the step of determining the permission level corresponding to the service query information based on the user identity information and sorting the service query information according to the permission level and the temporal relationship corresponding to the service query information to obtain input variables includes:
[0117] Determine the permission level corresponding to the service query information according to the mapping relationship between the preset user identity information set and the preset permission level set and the user identity information;
[0118] Sort the service query information according to the time sequence relationship corresponding to the permission level and the service query information to obtain an input variable.
[0119] In this embodiment, user identity information is obtained, and according to the mapping relationship between the preset user identity information set and the preset permission level set, the permission level corresponding to the service query information is determined through the user identity information; and the time information corresponding to each piece of information in the service query information is extracted, and the time information is sorted according to the preset time sequence relationship and the permission level, so as to sort each piece of query information in the service query information, and finally an input variable is obtained.
[0120] Further, the step of receiving a service data query request including an access credential sent by a client and forwarding the service data query request to a service platform through a signature service platform includes:
[0121] Receive a service data query request including an access credential sent by a client, forward the service data query request to a signature service platform for the signature service platform to perform signature verification on the service query request based on the access credential, and forward the service data query request to a service platform when the service query request passes the verification;
[0122] After the step of receiving user service data sent by the service platform, signing the user service data through the signature service platform, and sending the signed user service data to the client, it further includes:
[0123] Receive user service data sent by the service platform, and forward the user service data to a signature service platform for the signature service platform to determine signature information based on the access credential and the request time corresponding to the service data query request when receiving the user service data, sign the user service data based on the signature information, and send the signed user service data to the client.
[0124] In this embodiment, when the server receives a service data query request containing an access credential sent by the client, it sends the service data query request to the signature service platform. When the signature service platform receives the service data query request sent by the server, it parses the service data query request to obtain the access credential, and then performs signature verification on the service query request based on the access credential. When the service query request passes the verification, the signature service platform forwards the service data query request to the service platform. When the service platform receives the service data query request, it queries the user's service data set and returns the user's service data set to the server. Specifically: The signature service platform obtains the service code in the service data query request submitted by the user, as well as the signature information and access credential token in the request header. The signature service platform signs the service code and then compares it with the signature information in the request header to determine whether the values are the same. If they are the same, it means that the information of the service code requested by the user belongs to the user and is a legal request. If they are not the same, it proves that the data of this request does not belong to the current requesting user and is an illegal request. At this time, the signature service will reject the user's request. Thus, it avoids the situation where a user views the information of other users beyond their authority.
[0125] When the server receives the user service data sent by the service platform, it signs the user service data through the signature service platform (the method of data signature is not specifically limited), and the server sends the signed user service data to the client. Specifically, when the service platform receives the service data query request sent by the signature service platform, the service platform obtains the service data set associated with the service data query request and sends the service data set to the signature service platform. When the signature service platform receives the service data set sent by the service platform, it determines the signature information based on the access credential and the request time corresponding to the service data query request, and signs the user service data based on the signature information. The signature service platform sends the signed service data set to the client.
[0126] Further, after the step of receiving the user service data sent by the service platform, signing the user service data through the signature service platform, and sending the signed user service data to the client, the following steps are further included:
[0127] When receiving a service operation request sent by the client, the service operation request containing the signature information is sent to the signature service platform to verify the signature information through the signature service platform. Among them, when the client receives the user service data containing the signature information, it parses the user service data to obtain the signature information contained in the user service data header, and when detecting that the service triggers a service operation request, it associates and sends the parsed signature information with the service operation request to the server;
[0128] When the signature information verification fails, reject the business operation request;
[0129] When the signature information verification passes, send the business operation request containing the signature information to the business service platform for the business service platform to respond to the business operation request.
[0130] In this embodiment, the client receives a business data set containing signature information, and the client parses the business data set to obtain the signature information included in the header of the business data set; when the client detects that the service triggers a business operation request, the client sends the parsed signature information and the business operation request to the server in association; the server receives the business operation request sent by the client, and the server sends the business operation request containing the signature information to the signature service platform; when the signature service platform receives the business operation request containing the signature information, it obtains the signature information in the business operation request and verifies the signature information; the signature service platform feeds back the verification result corresponding to the verification of the signature information to the server for the server to perform corresponding operations based on the verification result corresponding to the signature information. When the signature information verification fails, the server rejects the business operation request; when the signature information verification passes, the server sends the business operation request containing the signature information to the service platform to respond to the business operation request through the service platform.
[0131] The business data management method proposed in this embodiment obtains the business query information associated with the business data query request by receiving the business data query request sent by the client; inputs the business query information into a preset risk classification model, and determines the risk type of the business query information through the preset risk classification model; when the risk type is high risk, obtains the user identity information associated with the business data query request, and determines whether the user identity information is verified through the identity authentication service platform. In this embodiment, the risk type of the business query information is determined through the preset risk classification model of the identity authentication service platform, so that the risk type of the business query information can be judged, the business query information of the high-risk type can be determined, and the identity verification of the high-risk business query information can be performed, thus liberating the business service developers from the identity verification problem of the data, enabling them to only focus on the development of the business service without having to worry about the identity verification problem, thereby improving the development efficiency and quality and reducing the cost of service development and architecture.
[0132] In addition, an embodiment of the present invention also proposes a business data management device, where the business data management device includes:
[0133] A verification module, configured to receive a business data query request sent by a client, obtain user identity information associated with the business data query request, and determine whether the user identity information is verified through an identity authentication service platform;
[0134] A sending module, configured to send an access credential to a client through an identity authentication service platform if the user identity information is verified;
[0135] A forwarding module, configured to receive a service data query request containing an access credential sent by the client, and forward the service data query request to a service platform through a signature service platform;
[0136] A signature module, configured to receive user service data sent by the service platform, sign the user service data through the signature service platform, and send the signed user service data to the client.
[0137] Further, the verification module is further configured to:
[0138] Receive a service data query request sent by the client, and obtain service query information associated with the service data query request;
[0139] Input the service query information into a preset risk classification model, and determine the risk type of the service query information through the preset risk classification model;
[0140] When the risk type is high risk, obtain user identity information associated with the service data query request, and determine whether the user identity information is verified through the identity authentication service platform.
[0141] Further, the verification module is further configured to:
[0142] Obtain a sample data set of service query events, and construct an initial risk classification model based on the sample data set;
[0143] Use the output of any layer of the initial risk classification model as a target variable, use a predefined clustering dimension as an independent variable, construct a multi-branch decision tree, and divide the sample data in the sample data set to form sample data subsets;
[0144] Train the initial risk classification model based on each of the sample data subsets to obtain a customer group analysis sub-model;
[0145] Combine the stratification rules in each of the customer group analysis sub-models to determine the preset risk classification model.
[0146] Further, the verification module is further configured to:
[0147] Determine the permission level corresponding to the service query information based on the user identity information, and sort the service query information according to the permission level and the time sequence relationship corresponding to the service query information to obtain an input variable;
[0148] Input the input variable into the pre-trained preset risk classification model to determine the classification result corresponding to the service query information, where the classification result at least includes the risk type corresponding to the service query information.
[0149] Further, the verification module is further configured to:
[0150] Determine the permission level corresponding to the service query information according to the mapping relationship between the preset user identity information set and the preset permission level set and the user identity information;
[0151] Sort the service query information according to the permission level and the time sequence relationship corresponding to the service query information to obtain the input variable.
[0152] Further, the forwarding module is further configured to:
[0153] Receive a service data query request containing an access credential sent by the client, forward the service data query request to the signature service platform for the signature service platform to perform signature verification on the service query request based on the access credential, and forward the service data query request to the service platform when the service query request passes the verification;
[0154] Further, the signature module is further configured to:
[0155] Receive the user service data sent by the service platform, and forward the user service data to the signature service platform for the signature service platform to determine the signature information based on the access credential and the request time corresponding to the service data query request when receiving the user service data, sign the user service data based on the signature information, and send the signed user service data to the client.
[0156] Further, the forwarding module is further configured to:
[0157] When receiving a service operation request sent by the client, send the service operation request containing the signature information to the signature service platform to verify the signature information through the signature service platform. Among them, when the client receives the user service data containing the signature information, it parses the user service data to obtain the signature information included in the user service data header, and when detecting that the service triggers a service operation request, it associates and sends the parsed signature information with the service operation request to the server;
[0158] When the signature information verification fails, reject the service operation request;
[0159] When the signature information is verified to be passed, the service operation request including the signature information is sent to the service platform for the service platform to respond to the service operation request.
[0160] In addition, an embodiment of the present invention further provides a computer-readable storage medium, on which a service data management program is stored. When the service data management program is executed by a processor, the steps of the service data management method described in any one of the above are implemented.
[0161] The specific embodiments of the computer-readable storage medium of the present invention are basically the same as the embodiments of the above service data management method, and will not be described in detail herein.
[0162] It should be noted that in this article, the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, so that a process, method, article or system including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or system. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or system including that element.
[0163] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages and disadvantages of the embodiments.
[0164] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium as described above (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0165] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. A business data management method, characterized in that, The business data management method includes the following steps: Receiving a business data query request sent by a client, obtaining user identity information associated with the business data query request, and determining whether the user identity information is verified through an identity authentication service platform, including: Receiving a business data query request sent by a client, and obtaining business query information associated with the business data query request; Inputting the business query information into a preset risk classification model, and determining the risk type of the business query information through the preset risk classification model. Among them, the setting steps of the preset risk classification model include: obtaining a sample data set of business query events, and constructing an initial risk classification model based on the sample data set; using the output of any layer of the initial risk classification model as the target variable, and using predefined clustering dimensions as independent variables to construct a multi-branch decision tree to divide the sample data in the sample data set to form sample data subsets; training the initial risk classification model through each of the sample data subsets to obtain a customer group analysis sub-model; combining the stratification rules in each of the customer group analysis sub-models to obtain a risk classification model; When the risk type is high risk, obtaining user identity information associated with the business data query request, and determining whether the user identity information is verified through an identity authentication service platform; If the user identity information is verified, sending an access credential to the client through the identity authentication service platform; Receiving a business data query request containing an access credential sent by the client, and forwarding the business data query request to the business service platform through the signature service platform; Receiving the user's business data sent by the business service platform, signing the user's business data through the signature service platform, and sending the signed user's business data to the client.
2. The service data management method according to claim 1, wherein The steps of inputting the business query information into a preset risk classification model and determining the risk type of the business query information through the preset risk classification model include: Determining the permission level corresponding to the business query information based on the user identity information, and sorting the business query information according to the permission level and the time sequence relationship corresponding to the business query information to obtain an input variable; Inputting the input variable into the preset risk classification model that has been pre-trained to determine the classification result corresponding to the business query information, and the classification result at least includes the risk type corresponding to the business query information.
3. The service data management method according to claim 2, characterized in that, The steps of determining the permission level corresponding to the business query information based on the user identity information and sorting the business query information according to the permission level and the time sequence relationship corresponding to the business query information to obtain an input variable include: Determining the permission level corresponding to the business query information according to the mapping relationship between the preset user identity information set and the preset permission level set and the user identity information; Sorting the business query information according to the permission level and the time sequence relationship corresponding to the business query information to obtain an input variable.
4. The service data management method according to any one of claims 1 to 3, characterized in that, The steps of receiving a business data query request containing an access credential sent by the client and forwarding the business data query request to the business service platform through the signature service platform include: Receive a business data query request containing an access credential sent by a client, forward the business data query request to a signature service platform for the signature service platform to perform signature verification on the business data query request based on the access credential, and forward the business data query request to a business service platform when the business data query request passes the verification; After the step of receiving user business data sent by the business service platform, signing the user business data through the signature service platform, and sending the signed user business data to the client, the method further includes: Receive user business data sent by the business service platform, and forward the user business data to the signature service platform for the signature service platform to determine signature information based on the access credential and the request time corresponding to the business data query request when receiving the user business data, sign the user business data based on the signature information, and send the signed user business data to the client.
5. The service data management method according to claim 4, characterized in that After the step of receiving user business data sent by the business service platform, signing the user business data through the signature service platform, and sending the signed user business data to the client, the method further includes: When receiving a business operation request sent by the client, send the business operation request containing the signature information to the signature service platform to verify the signature information through the signature service platform. Wherein, when the client receives the user business data containing the signature information, the client parses the user business data to obtain the signature information included in the user business data header, and when detecting that the service triggers a business operation request, associates and sends the parsed signature information with the business operation request to the server; When the signature information fails to pass the verification, reject the business operation request; When the signature information passes the verification, send the business operation request containing the signature information to the business service platform for the business service platform to respond to the business operation request.
6. A business data management device, characterized in that, The business data management device includes: A verification module, configured to receive a business data query request sent by a client, obtain user identity information associated with the business data query request, and determine whether the user identity information passes verification through an identity authentication service platform, including: Receive a business data query request sent by the client, and obtain business query information associated with the business data query request; Input the business query information into a preset risk classification model, and determine the risk type of the business query information through the preset risk classification model. The setting steps of the preset risk classification model include: obtaining a sample data set of business query events to construct an initial risk classification model based on the sample data set; using any layer output of the initial risk classification model as a target variable and a predefined clustering dimension as an independent variable to construct a multi-branch decision tree to divide the sample data in the sample data set to form sample data subsets; training the initial risk classification model through each of the sample data subsets to obtain a customer group analysis sub-model; combining the stratification rules in each of the customer group analysis sub-models to obtain a risk classification model; When the risk type is high risk, obtain the user identity information associated with the business data query request, and determine whether the user identity information is verified through the identity authentication service platform; A sending module, configured to send an access credential to the client through the identity authentication service platform if the user identity information is verified; A forwarding module, configured to receive the business data query request containing the access credential sent by the client, and forward the business data query request to the business service platform through the signature service platform; A signature module, configured to receive the user business data sent by the business service platform, sign the user business data through the signature service platform, and send the signed user business data to the client.
7. A business data management device, characterized in that, The business data management device includes: a memory, a processor, and a business data management program stored on the memory and executable on the processor. When the business data management program is executed by the processor, the steps of the business data management method according to any one of claims 1 to 5 are implemented.
8. A computer-readable storage medium, characterized in that, A business data management program is stored on the computer-readable storage medium. When the business data management program is executed by the processor, the steps of the business data management method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Mobile transaction business realization method, device and system
CN101702803A
Authentication method, system and device based on user authorization information and storage medium
CN109194673A
Public accumulation fund service handling method, system and device and readable storage medium
CN111612443A