API Business Security Control System and Method for Open Banking

By designing an API business security control system in the API business of open banks, using technical means such as identity authentication, token application and risk assessment, the risks of data leakage and fund losses in the API business are solved, and the security control of data and funds is achieved.

CN113486348BActive Publication Date: 2025-06-13CHINA CONSTRUCTION BANK
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110740530.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-06-30
Publication Date
2025-06-13
Estimated Expiration
2041-06-30

AI Technical Summary

Technical Problem

Open banks have the risk of data breaches and capital losses in API business, mainly because the security of API usage relies on cooperation agreements and the risk of maliciously skipping business verification steps caused by system vulnerabilities.

Method used

An open banking API business security control system was designed, including a mobile SDK, cooperative agency server and open banking API gateway. Through the steps of identity authentication, token application and risk assessment, encrypted transaction packets are generated, and anti-overright verification and transaction behavior analysis is carried out to ensure data security and fund security.

Benefits of technology

It effectively avoids user data leakage and fund losses. By implementing a Session-like management mechanism, the existence of horizontal and vertical overreach is avoided, and serious vulnerabilities such as malicious skipping of business verification steps are prevented.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113486348B_ABST
    Figure CN113486348B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security and provides an API service security control system and method for open banking. The system includes: a mobile SDK for sending communication messages to the cooperative institution server; an entry address for the product to generate encrypted transaction messages and send them to the API gateway; a cooperative institution server for sending a token application request message to the API gateway after successful identity recognition and authentication of the application; an open banking API gateway for generating an access token and sending it to the open banking back-end system; returning to the mobile SDK the entry address of the product, the access token, and the key; sending a transaction message request to the open banking back-end system; an open banking back-end system for performing risk assessment and sending the assessment result to the API gateway; performing anti-overprivilege verification and transaction behavior analysis and sending the response message to the API gateway. It avoids the leakage of user data and reduces the occurrence of losses to funds.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to an open bank's API business security control system and method. Background Art

[0002] Open banking is translated from the English Open Banking. It was proposed by the United Kingdom. Its origin and promotion are the exploration of data sharing and open data in the banking industry by the United Kingdom and the European Union. It is a secure way to use open API technology to allow providers to access customer financial information. On the one hand, it allows customers to understand their accounts in more detail; on the other hand, customers can enjoy better financial services through third-party providers. As an open financial service platform, the open banking platform is user experience-oriented, ecological scenarios-based, supported by the core capabilities of financial institutions, and relying on modern technology. It is co-built and shared with customers, employees, suppliers, technology developers and other entities, so as to provide customers with first-class financial services.

[0003] The business value of open banking lies in the fact that commercial banks can conduct business cooperation with partners through APIs, breaking down previous technical barriers. Therefore, only by fulfilling the obligation of data protection can this business develop in the long run. However, when open banks conduct API business, the security of API use can only be constrained by cooperation agreements. There are serious loopholes such as malicious skipping of business verification steps caused by intentional or system loopholes of cooperative institutions, resulting in frequent incidents of user data leakage or financial losses. Summary of the invention

[0004] The embodiment of the present invention provides an open banking API business security control system to prevent user data leakage and reduce the occurrence of capital losses. The system includes:

[0005] The mobile SDK is used to receive the user identification information sent by the application and collect the application usage information; obtain the communication message based on the user identification information and the application usage information, and send the communication message to the SDK authentication service interface of the cooperative institution's server for identity authentication; enter the entry address of the product returned by the open bank API gateway, use the access token and key to generate an encrypted transaction message, and send it to the open bank API gateway;

[0006] The cooperative institution service end is used to receive the communication message sent by the mobile SDK, and perform identity authentication on the application according to the communication message; after the identity authentication is successful, convert the communication message to obtain a token application request message, and send the token application request message to the open bank API gateway;

[0007] An open banking API gateway is used to receive a token application request message sent by the server of the cooperative institution, generate an access token according to the token application request message, and send the access token to the open banking back-end system; according to the evaluation result feedback by the open banking back-end system, return to the mobile SDK: the entry address of the product, the access token, and the secret key; receive the encrypted transaction message sent by the mobile SDK, and send a transaction message request to the open banking back-end system according to the encrypted transaction message; receive the response message returned by the open banking back-end system, determine the transaction response result according to the response message, and send it to the mobile SDK.

[0008] The open banking back-end system is used to receive the access token, perform risk assessment, and send the evaluation result to the open banking API gateway; receive the transaction message request, perform anti-overprivilege verification and transaction behavior analysis according to the transaction message request to obtain a response message, and send the response message to the open banking API gateway.

[0009] In a specific embodiment, the server of the cooperative institution is specifically used for:

[0010] Receive the communication message sent by the mobile SDK, verify whether the application is counterfeit according to the communication message, and if the verification result is not counterfeit, it is determined that the identity recognition authentication is successful.

[0011] After the identity recognition authentication is successful, determine the user identity information according to the communication message.

[0012] Convert the user identity information into the identity information of the open banking system, use the identity information of the open banking system to replace the user identity information in the communication message to obtain a token application request message, and send the token application request message to the open banking API gateway.

[0013] In a specific embodiment, the mobile SDK is specifically used for:

[0014] When the mobile SDK is initialized, receive the user identification information sent by the application, and collect the application usage information; obtain a communication message according to the user identification information and the application usage information, and send the communication message to the SDK authentication service interface of the server of the cooperative institution for identity recognition authentication.

[0015] When the mobile SDK is in page mode for transactions, open the web view control and jump to the entry address of the product; assemble the access token into the transaction message, and encrypt the transaction message with the secret key to generate an encrypted transaction message, and send it to the open banking API gateway.

[0016] In a specific embodiment, when the mobile SDK is initialized, the open banking API gateway is specifically used for:

[0017] Receiving a token application request message sent by the server of the cooperating institution, and performing permission verification according to the token application request message;

[0018] After the permission verification passes, generating an access token and sending the access token to the product service backend component of the open banking backend system;

[0019] Receiving the user factor information and the main transaction account information returned by the product service backend component, and caching them in Redis with the access token as the key and the user factor information and the main transaction account information as the values;

[0020] According to the information cached in Redis, initiating a risk assessment request to the risk control platform of the open banking backend system, and receiving the evaluation result feedback by the risk control platform;

[0021] Determining whether to approve the access of the mobile SDK according to the evaluation result feedback by the risk control platform;

[0022] When approving the access of the mobile SDK, returning to the mobile SDK: the entry address of the product, the access token, and the secret key.

[0023] Correspondingly, in a specific embodiment, the open banking backend system includes:

[0024] A product service backend component, which is used to receive the access token sent by the open banking API gateway, identify the access token, and obtain the user factor information and the main transaction account information of the user; returning the user factor information and the main transaction account information of the user to the open banking API gateway;

[0025] A risk control platform, which is used to receive the risk assessment request initiated by the open banking API gateway, determine the application usage information and the user factor information according to the risk assessment request; using the application usage information and the user factor information to perform risk assessment, determine the evaluation result, and feedback the evaluation result to the open banking API gateway.

[0026] In a specific embodiment, when the mobile SDK is in page mode for transactions, the open banking API gateway is specifically used for:

[0027] Receiving an encrypted transaction message sent by the mobile SDK and decrypting the encrypted transaction message;

[0028] Performing token verification on the decrypted transaction message, and after the verification passes, sending a transaction message request to the product service backend component of the open banking backend system;

[0029] Receive the response message returned by the open banking back-end system, determine the transaction response result according to the response message, and send the transaction response result to the mobile SDK.

[0030] Correspondingly, in a specific embodiment, the open banking back-end system includes:

[0031] A product service back-end component, which is used to receive the transaction message request sent by the open banking API gateway, record the processing status of the business process in the cache according to the transaction message request; obtain the user identity information from the user element information cached in Redis, and compare the obtained user identity information with the transaction identity information in the transaction message request for anti-over-authorization comparison; after the comparison passes, process the corresponding transaction; push the relevant information of the transaction to the risk control platform; receive the transaction behavior analysis result feedback by the risk control platform, generate a response message, and return it to the open banking API gateway;

[0032] A risk control platform, which is used to receive the relevant information of the transaction pushed by the product service back-end component, perform transaction behavior analysis according to the relevant information of the transaction, determine the transaction behavior analysis result, and feedback it to the product service back-end component.

[0033] An embodiment of the present invention also provides an API service security control method for an open bank to avoid user data leakage and reduce the occurrence of loss of funds. The method includes:

[0034] The mobile SDK receives the user identification information sent by the application program and collects the application program usage information; according to the user identification information and the application program usage information, obtains a communication message, and sends the communication message to the SDK authentication service interface of the cooperative institution server for identity authentication;

[0035] The cooperative institution server receives the communication message sent by the mobile SDK, and performs identity authentication on the application program according to the communication message; after the identity authentication is successful, converts the communication message to obtain a token application request message, and sends the token application request message to the open banking API gateway;

[0036] The open banking API gateway receives the token application request message sent by the cooperative institution server, generates an access token according to the token application request message, and sends the access token to the open banking back-end system;

[0037] The open banking back-end system receives the access token, performs a risk assessment, and sends the assessment result to the open banking API gateway;

[0038] The Open Banking API Gateway returns to the Mobile SDK the entry address, access token, and key of the product based on the evaluation results feedback by the Open Banking back-end system;

[0039] The Mobile SDK enters the entry address of the product returned by the Open Banking API Gateway, generates an encrypted transaction message using the access token and key, and sends it to the Open Banking API Gateway;

[0040] The Open Banking API Gateway receives the encrypted transaction message sent by the Mobile SDK and sends a transaction message request to the Open Banking back-end system according to the encrypted transaction message;

[0041] The Open Banking back-end system receives the transaction message request, performs anti-over-authorization verification and transaction behavior analysis according to the transaction message request, obtains a response message, and sends the response message to the Open Banking API Gateway;

[0042] The Open Banking API Gateway receives the response message returned by the Open Banking back-end system, determines the transaction response result according to the response message, and sends it to the Mobile SDK.

[0043] In a specific embodiment, the cooperative institution server receives the communication message sent by the Mobile SDK, and performs identity recognition and authentication on the application according to the communication message; after the identity recognition and authentication is successful, the communication message is converted to obtain a token application request message, and the token application request message is sent to the Open Banking API Gateway, including:

[0044] The cooperative institution server receives the communication message sent by the Mobile SDK, and verifies whether the application is counterfeit according to the communication message. If the verification result is not counterfeit, it is determined that the identity recognition and authentication is successful;

[0045] After the identity recognition and authentication is successful, the user identity information is determined according to the communication message;

[0046] The user identity information is converted into the identity information of the Open Banking system, and the identity information of the Open Banking system is used to replace the user identity information in the communication message to obtain a token application request message, and the token application request message is sent to the Open Banking API Gateway.

[0047] In a specific embodiment, the Mobile SDK receives the user identification information sent by the application, and collects the application usage information; according to the user identification information and the application usage information, a communication message is obtained, and the communication message is sent to the SDK authentication service interface of the cooperative institution server for identity recognition and authentication, including:

[0048] When the mobile SDK is initialized, the mobile SDK receives the user identification information sent by the application and collects the application usage information;

[0049] According to the user identification information and the application usage information, a communication message is obtained, and the communication message is sent to the SDK authentication service interface of the cooperative institution server for identity recognition authentication.

[0050] In a specific embodiment, the open banking API gateway receives the token application request message sent by the cooperative institution server, generates an access token according to the token application request message, and sends the access token to the open banking back-end system, including:

[0051] When the mobile SDK is initialized, the open banking API gateway receives the token application request message sent by the cooperative institution server and performs permission verification according to the token application request message;

[0052] After the permission verification passes, an access token is generated, and the access token is sent to the product service back-end component of the open banking back-end system;

[0053] Receive the user factor information and the main transaction account information returned by the product service back-end component, and cache them in Redis with the access token as the key and the user factor information and the main transaction account information as the value;

[0054] According to the information cached in Redis, initiate a risk assessment request to the risk control platform of the open banking back-end system.

[0055] In a specific embodiment, the open banking back-end system receives the access token, performs a risk assessment, and sends the assessment result to the open banking API gateway, including:

[0056] The product service back-end component receives the access token sent by the open banking API gateway, identifies the access token, and obtains the user factor information and the main transaction account information of the user; returns the user factor information and the main transaction account information of the user to the open banking API gateway;

[0057] The risk control platform receives the risk assessment request initiated by the open banking API gateway, determines the application usage information and the user factor information according to the risk assessment request; uses the application usage information and the user factor information to perform a risk assessment, determines the assessment result, and feeds back the assessment result to the open banking API gateway.

[0058] In a specific embodiment, the open banking API gateway returns to the mobile SDK the entry address, access token, and key of the product according to the assessment result fed back by the open banking back-end system, including:

[0059] When the mobile SDK is initialized, the open banking API gateway receives the evaluation results feedback by the risk control platform;

[0060] According to the evaluation results feedback by the risk control platform, determine whether to approve the access of the mobile SDK;

[0061] When approving the access of the mobile SDK, return to the mobile SDK: the entry address of the product, the access token and the secret key.

[0062] In a specific embodiment, the mobile SDK enters the entry address of the product returned by the open banking API gateway, and uses the access token and the secret key to generate an encrypted transaction message and send it to the open banking API gateway, including:

[0063] When the mobile SDK conducts page-mode transactions, the mobile SDK opens a web view control and jumps to the entry address of the product;

[0064] Assemble the access token into the transaction message, and use the secret key to encrypt the transaction message to generate an encrypted transaction message, and send it to the open banking API gateway.

[0065] In a specific embodiment, the open banking API gateway receives the encrypted transaction message sent by the mobile SDK, and according to the encrypted transaction message, sends a transaction message request to the open banking back-end system, including:

[0066] When the mobile SDK conducts page-mode transactions, receive the encrypted transaction message sent by the mobile SDK and decrypt the encrypted transaction message;

[0067] Conduct token verification on the decrypted transaction message. After the verification passes, send a transaction message request to the product service back-end component of the open banking back-end system.

[0068] In a specific embodiment, the open banking back-end system receives the transaction message request, and according to the transaction message request, conducts anti-over-authorization verification and transaction behavior analysis to obtain a response message, and sends the response message to the open banking API gateway, including:

[0069] The product service back-end component receives the transaction message request sent by the open banking API gateway, and according to the transaction message request, records the processing status of the business process in the cache; obtains the user identity information from the user element information cached in Redis, and compares the obtained user identity information with the transaction identity information in the transaction message request for anti-over-authorization comparison; after the comparison passes, process the corresponding transaction; push the relevant information of the transaction to the risk control platform;

[0070] The risk control platform receives the relevant information of the transaction pushed by the product service backend component, conducts transaction behavior analysis based on the relevant information of the transaction, determines the transaction behavior analysis result, and feeds it back to the product service backend component;

[0071] The product service backend component receives the transaction behavior analysis result fed back by the risk control platform, generates a response message, and returns it to the open banking API gateway.

[0072] An embodiment of the present invention also provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the above-mentioned API service security control method of the open banking is implemented.

[0073] An embodiment of the present invention also provides a computer-readable storage medium, which stores a computer program for executing the above-mentioned API service security control method of the open banking.

[0074] In the embodiments of the present invention, by setting up a mobile SDK, the user identification information sent by the application is received, and the application usage information is collected; according to the user identification information and the application usage information, a communication message is obtained, and the communication message is sent to the SDK authentication service interface of the cooperative institution server for identity identification and authentication; enter the entry address of the product returned by the open banking API gateway, and use the access token and key to generate an encrypted transaction message and send it to the open banking API gateway; set up the cooperative institution server to receive the communication message sent by the mobile SDK, and according to the communication message, perform identity identification and authentication on the application; after the identity identification and authentication is successful, convert the communication message to obtain a token application request message, and send the token application request message to the open banking API gateway; set up the open banking API gateway to receive the token application request message sent by the cooperative institution server, and according to the token application request message, generate an access token and send the access token to the open banking back-end system; according to the evaluation result feedback by the open banking back-end system, return to the mobile SDK: the entry address of the product, the access token and the key; receive the encrypted transaction message sent by the mobile SDK, and according to the encrypted transaction message, send a transaction message request to the open banking back-end system; receive the response message returned by the open banking back-end system, and according to the response message, determine the transaction response result and send it to the mobile SDK; set up the open banking back-end system to receive the access token, perform risk assessment, and send the evaluation result to the open banking API gateway; receive the transaction message request, and according to the transaction message request, perform anti-over-authorization verification and transaction behavior analysis to obtain a response message, and send the response message to the open banking API gateway. By using the access token for business process association, a Session (time domain)-like management mechanism is realized, avoiding the existence of horizontal and vertical over-authorization, and avoiding the occurrence of serious vulnerabilities such as maliciously skipping business verification steps, thereby avoiding user data leakage and reducing the occurrence of losses of funds. BRIEF DESCRIPTION OF THE DRAWINGS

[0075] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts.

[0076] Figure 1 It is a schematic structural diagram of the API service security control system of the open banking in the embodiments of the present invention.

[0077] Figure 2 It is a schematic diagram of the initialization control process of the mobile SDK in the specific examples of the present invention.

[0078] Figure 3Schematic diagram of the normal transaction control process for the mobile SDK page mode in a specific example of the present invention.

[0079] Figure 4 Schematic diagram of the risk control mechanism in a specific example of the present invention.

[0080] Figure 5 Schematic diagram of the API service security control method for the open bank in an embodiment of the present invention.

[0081] Figure 6 Schematic diagram of the implementation process of step 502 in a specific embodiment of the present invention.

[0082] Figure 7 Schematic diagram of the implementation process of step 503 in a specific embodiment of the present invention.

[0083] Figure 8 Schematic diagram of the implementation process of step 504 in a specific embodiment of the present invention.

[0084] Figure 9 Schematic diagram of the implementation process of step 505 in a specific embodiment of the present invention.

[0085] Figure 10 Schematic diagram of the implementation process of step 506 in a specific embodiment of the present invention.

[0086] Figure 11 Schematic diagram of the implementation process of step 507 in a specific embodiment of the present invention.

[0087] Figure 12 Schematic diagram of the implementation process of step 508 in a specific embodiment of the present invention.

[0088] Figure 13 Schematic diagram of the electronic device for API service security control for the open bank in an embodiment of the present invention. Detailed implementation manners

[0089] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0090] To facilitate the understanding of the API service security control system and method for the open bank provided in the embodiments of the present invention, the professional terms involved in the embodiments of the present invention are explained as follows:

[0091] Open Banking: Translated from the English Open Banking, it was proposed by the United Kingdom. Its origin and promotion are the exploration of data sharing and open data in the banking industry by the United Kingdom and the European Union. It is a secure way to use open API technology to allow providers to access customer financial information. On the one hand, it allows customers to understand their accounts in more detail; on the other hand, customers can enjoy better financial services through third-party providers. As an open financial service platform, the open banking platform is user experience-oriented, ecological scenarios-based, supported by the core capabilities of financial institutions, and relying on modern technology. It is co-built and shared with customers, employees, suppliers, technology developers and other entities, so as to provide customers with first-class financial services.

[0092] API: application programming interface, an application programming interface is a set of predefined functions that developers can use to easily access related services without having to worry about the design and implementation of the services.

[0093] SDK: software development kit. An application software development kit is a collection of development tools used to build applications based on specific software packages, framework hardware platforms, operating systems, etc.

[0094] Interface mode: Users design and develop functional interfaces according to business processes and implementation requirements to meet the design style and specific product and service needs of partner organizations' network applications.

[0095] Page mode: Users do not need to develop functional interfaces. Commercial banks develop and design functional interfaces for customers to use. Customer transaction processes are completed on the bank side. This mode embeds the Construction Bank application software development toolkit on the application side to achieve rapid access.

[0096] Application party: The institution that calls the commercial bank's application programming interface.

[0097] C3 data: The "Personal Financial Information Protection Technical Specification" (JRT 0171-2020) stipulates that personal financial information is divided into three levels of sensitivity from high to low: C3, C2, and Cl, based on the impact and harm caused by unauthorized viewing or unauthorized changes to the information. C3 category information is mainly user identification information. Once this type of information is viewed or changed without authorization, it will cause serious damage to the information security and property security of the subject of personal financial information.

[0098] Open banking application programming interface (API) service: It is a financial service model that relies on API technology to achieve internal and external interconnection. Commercial banks provide application programming interfaces for interconnection to their partners, outputting their own financial service capabilities and information technology capabilities, which provides a useful supplement to increasing the stickiness of the financial ecosystem. The value creation of open banking is reflected in: only by building the security capabilities of open banking that can replace the dedicated line mode can truly rich financial products be output; while all financial services are within reach, the access cost is fully saved. Only in this way can customer resources be better precipitated and data support be provided for digital transformation. The financial industry is an industry with strong supervision, an industry involving a large amount of sensitive business data, an industry highly dependent on informatization, and an industry with extremely severe information security risks.

[0099] An embodiment of the present invention provides an API service security control system for open banking, which is used to avoid the leakage of user data and reduce the occurrence of losses of funds. The system is as Figure 1 shown and includes:

[0100] The mobile SDK 101 is used to receive the user identification information sent by the application, collect the application usage information; obtain a communication message according to the user identification information and the application usage information, and send the communication message to the SDK authentication service interface of the cooperative institution server 102 for identity identification and authentication; enter the entry address of the product returned by the open banking API gateway 103, generate an encrypted transaction message using the access token and the key, and send it to the open banking API gateway 103;

[0101] The cooperative institution server 102 is used to receive the communication message sent by the mobile SDK 101, and perform identity identification and authentication on the application according to the communication message; after the identity identification and authentication is successful, convert the communication message to obtain a token application request message, and send the token application request message to the open banking API gateway 103;

[0102] The open banking API gateway 103 is used to receive the token application request message sent by the cooperative institution server 102, generate an access token according to the token application request message, and send the access token to the open banking back-end system 104; according to the evaluation result feedback by the open banking back-end system 104, return to the mobile SDK 101: the entry address of the product, the access token and the key; receive the encrypted transaction message sent by the mobile SDK 101, and send a transaction message request to the open banking back-end system 104 according to the encrypted transaction message; receive the response message returned by the open banking back-end system 104, determine the transaction response result according to the response message, and send it to the mobile SDK 101;

[0103] The Open Banking backend system 104 is used to receive access tokens, conduct risk assessments, and send the assessment results to the Open Banking API gateway 103; receive transaction message requests, and based on the transaction message requests, conduct anti-overprivilege verification and transaction behavior analysis to obtain response messages, and send the response messages to the Open Banking API gateway 103.

[0104] As can be seen from the above, in the embodiment of the present invention, by setting the mobile SDK 101, it receives the user identification information sent by the application program and collects the application program usage information; based on the user identification information and the application program usage information, it obtains communication messages, and sends the communication messages to the SDK authentication service interface of the cooperative institution server 102 for identity identification and authentication; enters the entry address of the product returned by the Open Banking API gateway 103, uses the access token and the secret key to generate encrypted transaction messages, and sends them to the Open Banking API gateway 103; sets the cooperative institution server 102 to receive the communication messages sent by the mobile SDK 101, and based on the communication messages, conducts identity identification and authentication on the application program; after successful identity identification and authentication, it converts the communication messages to obtain a token application request message, and sends the token application request message to the Open Banking API gateway 103; sets the Open Banking API gateway 103 to be used to receive the token application request message sent by the cooperative institution server 102, generates an access token based on the token application request message, and sends the access token to the Open Banking backend system 104; based on the assessment results feedback by the Open Banking backend system 104, it returns to the mobile SDK 101: the entry address of the product, the access token, and the secret key; receives the encrypted transaction messages sent by the mobile SDK 101, and based on the encrypted transaction messages, sends a transaction message request to the Open Banking backend system 104; receives the response messages returned by the Open Banking backend system 104, determines the transaction response results based on the response messages, and sends them to the mobile SDK 101; sets the Open Banking backend system 104 to receive access tokens, conduct risk assessments, and send the assessment results to the Open Banking API gateway 103; receive transaction message requests, and based on the transaction message requests, conduct anti-overprivilege verification and transaction behavior analysis to obtain response messages, and send the response messages to the Open Banking API gateway 103. Using the access token for business process association realizes a Session (time domain)-like management mechanism, avoids the existence of horizontal and vertical overprivilege, and avoids the occurrence of serious vulnerabilities such as maliciously skipping business verification steps, thereby preventing user data leakage and reducing the occurrence of losses to funds.

[0105] In a specific embodiment, since the API service life cycle of Open Banking is divided into two stages: SDK initialization and mobile SDK 101 page mode transactions, specifically in implementation, the mobile SDK 101 is specifically used for:

[0106] When the mobile SDK 101 is initialized, it receives the user identification information sent by the application APP and collects the application usage information; based on the user identification information and the application usage information, it obtains a communication message and sends the communication message to the SDK authentication service interface of the partner institution server 102 for identity recognition and authentication;

[0107] When the mobile SDK 101 conducts a page mode transaction, it opens the web view Webview control and jumps to the entry address of the product; it assembles the access token into the transaction message and encrypts the transaction message using a key to generate an encrypted transaction message, which is sent to the open banking API gateway 103.

[0108] Among them, when receiving the user identification information sent by the application, collecting the application usage information, the mobile terminal provides the product name and access scenario that it hopes to use to the SDK, and provides the relevant information for identifying the currently logged-in user of the APP, such as information like Cookie (data stored on the user's local terminal), Session ID, etc.; the APP calls the SDK, and the SDK collects the application usage information, including: the device information of the mobile terminal, the APP application information, and the running environment detection information.

[0109] Specifically in implementation, the partner institution server 102 is specifically used for:

[0110] When the mobile SDK 101 is initialized, it receives the communication message sent by the mobile SDK 101, and based on the communication message, verifies whether the application is a counterfeit. If the verification result is not a counterfeit, it is determined that the identity recognition and authentication is successful;

[0111] After the identity recognition and authentication is successful, based on the communication message, it determines the user identity information;

[0112] It converts the user identity information into the identity information of the open banking system, and uses the identity information of the open banking system to replace the user identity information in the communication message to obtain a token application request message, and sends the token application request message to the open banking API gateway 103.

[0113] Correspondingly, when the mobile SDK 101 is initialized, the open banking API gateway 103 is specifically used for:

[0114] Receiving the token application request message sent by the partner institution server 102, and based on the token application request message, conducting permission verification;

[0115] After the permission verification passes, it generates an access token and sends the access token to the product service backend component of the open banking backend system 104;

[0116] Receive the user factor information and primary transaction account information returned by the product service backend component, and cache them in Redis with the access token as the key and the user factor information and primary transaction account information as the values;

[0117] According to the information cached in Redis, initiate a risk assessment request to the risk control platform of the open banking backend system 104, and receive the assessment result feedback by the risk control platform;

[0118] Determine whether to approve the access of the mobile SDK 101 according to the assessment result feedback by the risk control platform;

[0119] When approving the access of the mobile SDK 101, return to the mobile SDK 101: the entry address of the product, the access token, and the secret key.

[0120] Among them, the entry address of the product refers to the H5 (HTML 5) access address.

[0121] Furthermore, when the mobile SDK 101 is initialized, the open banking backend system 104 includes:

[0122] The product service backend component is used to receive the access token sent by the open banking API gateway 103, identify the access token, and obtain the user factor information and primary transaction account information of the user; return the user factor information and primary transaction account information of the user to the open banking API gateway 103;

[0123] The risk control platform is used to receive the risk assessment request initiated by the open banking API gateway 103, determine the application usage information and user factor information according to the risk assessment request; use the application usage information and user factor information to conduct a risk assessment, determine the assessment result, and feedback the assessment result to the open banking API gateway 103.

[0124] After the initialization of the mobile SDK 101 is completed, the mobile SDK 101 page mode transaction can be carried out. At this time, the Javascript event triggered by the H5 application in the mobile SDK 101 calls the Javascript Bridge component in the Webview control; assemble the access token into the message and perform basic encryption and signature processing, and send it to the open banking API gateway 103 after processing.

[0125] Correspondingly, the open banking API gateway 103 is specifically used for:

[0126] Receive the encrypted transaction message sent by the mobile SDK 101 and decrypt the encrypted transaction message;

[0127] Perform token verification on the decrypted transaction message. After successful verification, send a transaction message request to the product service backend component of the open banking backend system 104;

[0128] Receive the response message returned by the open banking backend system 104. Based on the response message, determine the transaction response result and send the transaction response result to the mobile SDK 101.

[0129] At this time, the product service backend component in the open banking backend system 104 is used to receive the transaction message request sent by the open banking API gateway 103, record the processing status of the business process in the cache according to the transaction message request; obtain the user identity information from the user element information cached in Redis, and compare the obtained user identity information with the transaction identity information in the transaction message request for anti-overprivilege comparison; after the comparison passes, process the corresponding transaction; push the relevant information of the transaction to the risk control platform; receive the transaction behavior analysis result feedback by the risk control platform, generate a response message, and return it to the open banking API gateway 103;

[0130] The risk control platform in the open banking backend system 104 is used to receive the relevant information of the transaction pushed by the product service backend component, perform transaction behavior analysis based on the relevant information of the transaction, determine the transaction behavior analysis result, and feedback it to the product service backend component.

[0131] The following gives a specific example to illustrate how the embodiment of the present invention performs API service security control for open banking.

[0132] According to the network definition, an SDK is generally a collection of application software development tools used by software engineers for specific software packages, software frameworks, hardware platforms, operating systems, etc. Generally speaking, an SDK is a tool kit that can implement the functions of a software product. Currently, some functional SDKs can be operated as products. Users of the SDK do not need to develop each function of the product, which can reduce the cost of implementing product functions and improve development efficiency. The sharing of third-party data and services is achieved through SDK technology. In specific applications, the SDK is a better tool for integrating into mobile scenarios. For example, Bank A cooperates with Social Platform B. If Bank A wants to embed some of its services on Platform B, Bank A can integrate the services into B's App through the SDK, and B can directly call Bank A's services. An API is a kind of ability or specification. Generally, an SDK can contain multiple APIs.

[0133] The participants in the commercial bank application programming interface (API) service mainly include C-end users, application cooperation institutions, and commercial banks. Commercial banks provide API services to application parties and users through direct connection via API or indirect connection via SDK, realizing the external output of commercial bank services. The open platform outputs services externally and provides the following two access modes for users:

[0134] (1) Interface mode. The user designs and develops the function interface by himself according to the bank's business process and implementation requirements to meet the design style of the cooperative institution's network application and the specific product service requirements.

[0135] (2) Page mode. The cooperative institution does not need to develop the function interface. The bank develops and designs the function interface for customers to use, and the customer transaction process is completed on the bank side. This mode embeds the China Construction Bank application software development kit (SDK) at the application end, with built-in message encryption and decryption, and calls controls with relatively high threshold requirements such as GPS, camera, and face recognition to achieve the purpose of quick access.

[0136] In this example, the API business security control system of the open bank provided in the above embodiment is used to perform network security control on the C-end user system of the open bank. The general idea is as follows: The cooperative institution integrates the SDK released by the open bank into its own APP and integrates the characteristic financial products in the "page mode" of the bank into its own business scenario. By exchanging user identities between the server and the server, the transfer of user identities between the cooperative institution and the bank system is realized, the cross-authorization of the C-end users of the cooperative institution is realized, and the security of the system is improved. The business process is associated in the form of an access token to implement a session-like management mechanism, effectively solving serious vulnerabilities such as horizontal privilege escalation, vertical privilege escalation, and malicious skipping of business verification steps, so as to prevent the occurrence of events such as user data leakage or financial losses. The mobile SDK collects device information and SDK running environment information and accesses the risk control platform, providing more decision-making data sources for risk control and channel anti-fraud, and improving the overall security level of the platform. And the SDK side solves the problem that the current security protection of the open bank cannot implement separate authorization management for mobile devices by collecting device information. Flexible sensitive information protection mechanisms such as a secure soft keyboard are used to ensure that the input of C3-class sensitive information is completed on the bank side, improving the financial data security closed-loop system.

[0137] Specifically, since the page mode involved in this specific example is implemented based on the mobile SDK, the life cycle of the open bank API business service is divided into two processes: SDK initialization and normal transaction. The specific design is as Figure 2 and Figure 3 shown.

[0138] The mobile SDK provides basic message encryption and signing functions, and controls the entire session process through access tokens. The overall process can be described as follows:

[0139] During the initialization phase of the mobile SDK, the App passes the information used to identify its own users to the SDK. The SDK also assembles the device App application information, hardware information, and App operating environment information collected from the mobile device into a communication message and sends it to the SDK authentication service interface of the partner institution to apply for an access token for the Open Banking API.

[0140] The partner institution needs to detect whether the App is a fake App and authenticate the identity information sent up. At the same time, it needs to convert its own user system into the identity information of the bank system in accordance with the method agreed with the bank, such as ID number, mobile phone number, bank card number, etc. (This step can be skipped for products that do not need to connect to the user system). After that, assemble the message and call the service of the open bank's API gateway through the server SDK to apply for an access token;

[0141] The risk control platform uses a rule engine to identify risks using the bank's powerful risk data, and generates a negative watch list to promptly block high-risk access token transactions. After authentication, the mobile access token, a pair of keys for encryption and signing, and the product's entry URL address are returned.

[0142] When the mobile SDK receives the final response message, the mobile SDK calls Webview to directly pull up the H5 page. During the normal transaction phase of the mobile SDK, it only needs to communicate with the API gateway of the open bank. The basic service of the mobile SDK uses the access token obtained above and the negotiated process key to ensure the security of the communication message.

[0143] Among them, when conducting risk identification, some preset risk control rules are generally applied, as shown in Table 1:

[0144] Table 1

[0145]

[0146] This specific example is applied to the "page mode" of indirect connection of SDK, which involves the field of protection of personal financial sensitive information in open banking business. It provides an SDK-oriented authentication partner identity (B-side) and cross-authorization solution for end users (C-side), and a design and implementation of an end-to-end protection mechanism for C3 sensitive information data using a secure soft keyboard during a two-factor authentication process, which can meet the security construction of a general open banking business system.

[0147] This specific example provides an efficient identity authentication mechanism, realizing the interconnection between the user systems of cooperative institutions and bank user systems. For parameter passing behaviors between important merchants and banks (such as customer identity identifiers), through the interface mode, the server-to-server exchange is used to obtain and use de-identified, random, and tokenized identifiers. Using such identifiers to achieve the information closed-loop of the mobile SDK, avoiding risks such as leakage and theft of customer sensitive information. In the design of bank products, for important transactions, two-factor or other methods can be adopted to conduct secondary authentication for C-end users, enabling the bank to effectively protect the security of user funds and user data.

[0148] This specific example also provides a method for protecting C3-class sensitive information such as user payment, login, and query passwords in two-factor or multi-factor authentication. The mobile SDK provides functions to prevent terminal screen recording and screenshotting, and a white-box key-based H5 secure soft keyboard is deployed on the open bank server side. Ensure that C3-class sensitive information will not be cached by the terminal during input on the terminal H5 secure soft keyboard, but can only be restored at the API gateway, and then sent to the product service component using an end-to-end encryption mechanism, effectively ensuring that C3-class sensitive information will not be intercepted and leaked in the communication messages between the terminal H5 application and the open bank platform system.

[0149] This specific example also provides a mechanism for collecting device information through the SDK. During the SDK initialization and transaction process, collect the current mobile device information: such as Mac address, the current IP address of the mobile phone, android's packageName; ios's testBundleID or bundleID, mobile device identification code (MEID Mobile Equipment Identifier) or the unique identification code of the device, and at the same time collect whether the APP running environment and the operating system are rooted.

[0150] Furthermore, this specific example also provides a terminal-based risk control mechanism in the field of open banking. Such as Figure 4 As shown, combined with the buried point technology, all transaction data and user behaviors are incorporated into the data warehouse. Using big data, streaming computing machine learning, and artificial intelligence, with the help of a data analysis engine, clean, screen, and process the data, and automatically generate a negative observation list and a risk control strategy formation mechanism. The terminal device identification information, application information, physical address where the transaction occurs, frequency, and user identity information of C-end users from cooperative institutions are comprehensively used to conduct a terminal security score for the products of the connected open bank, and risk prevention and control are accurately and effectively carried out through risk modeling and rule engines. On the premise of respecting customer data privacy, realize real-time security monitoring, early warning, and real-time blocking of malicious and high-risk transactions suspected of fraud for daily transactions.

[0151] Therefore, the advantages of this specific example are as follows:

[0152] Through the cooperation of the page mode among the cooperative institution, the API gateway, and the product components of the backend, the products of the open bank are integrated into the huge user system of the cooperative institution, greatly improving the user experience. By means of cross-authorization with the cooperative institution, mobile clients are acquired, and the products that have been output can attract traffic for the C-end, increase the bank's user group, and bring a large number of transaction volumes.

[0153] Through the page mode, the bank can launch services that require the use of professional controls such as face recognition and OCR recognition, reducing the threshold for the cooperative institution and the bank to cooperate in launching financial-related services.

[0154] The collection of device information in the page mode allows the API of the open bank to access the bank's powerful risk control system, reducing the risks brought about by the launch of new forms of business.

[0155] Using the H5 secure soft keyboard can protect sensitive data of Class C3 and meet regulatory requirements.

[0156] The implementation of the above specific application is only for example, and the rest of the implementation manners will not be elaborated one by one.

[0157] Based on the same inventive concept, the embodiment of the present invention also provides a method for controlling the security of the API service of an open bank. Since the principle of the problem solved by the method for controlling the security of the API service of the open bank is similar to that of the API service security control system of the open bank, the implementation of the method for controlling the security of the API service of the open bank can refer to the implementation of the API service security control system of the open bank, and the repeated parts will not be elaborated. As Figure 5 shown, it specifically includes:

[0158] Step 501: The mobile SDK receives the user identification information sent by the application program and collects the application program usage information; according to the user identification information and the application program usage information, a communication message is obtained, and the communication message is sent to the SDK authentication service interface of the cooperative institution server for identity recognition authentication;

[0159] Step 502: The cooperative institution server receives the communication message sent by the mobile SDK and performs identity recognition authentication on the application program according to the communication message; after the identity recognition authentication is successful, the communication message is converted to obtain a token application request message, and the token application request message is sent to the open bank API gateway;

[0160] Step 503: The open bank API gateway receives the token application request message sent by the cooperative institution server, generates an access token according to the token application request message, and sends the access token to the open bank backend system;

[0161] Step 504: The open banking back-end system receives the access token, conducts a risk assessment, and sends the assessment result to the open banking API gateway;

[0162] Step 505: The open banking API gateway returns to the mobile SDK the entry address, access token, and key of the product according to the assessment result feedback by the open banking back-end system;

[0163] Step 506: The mobile SDK enters the entry address of the product returned by the open banking API gateway, generates an encrypted transaction message using the access token and key, and sends it to the open banking API gateway;

[0164] Step 507: The open banking API gateway receives the encrypted transaction message sent by the mobile SDK, and sends a transaction message request to the open banking back-end system according to the encrypted transaction message;

[0165] Step 508: The open banking back-end system receives the transaction message request, conducts anti-overauthorization verification and transaction behavior analysis according to the transaction message request, obtains a response message, and sends the response message to the open banking API gateway;

[0166] Step 509: The open banking API gateway receives the response message returned by the open banking back-end system, determines the transaction response result according to the response message, and sends it to the mobile SDK.

[0167] In a specific embodiment, when specifically implementing Step 501, it includes:

[0168] When the mobile SDK is initialized, the mobile SDK receives the user identification information sent by the application program and collects the application program usage information; wherein, the application program usage information includes: the device information of the mobile terminal, the APP application information, and the running environment detection information.

[0169] According to the user identification information and the application program usage information, a communication message is obtained, and the communication message is sent to the SDK authentication service interface of the cooperative institution server for identity identification authentication.

[0170] When specifically implementing, the specific implementation process of Step 502 is as Figure 6 shown and includes:

[0171] Step 601: The cooperative institution server receives the communication message sent by the mobile SDK, verifies whether the application program is counterfeit according to the communication message, and if the verification result is not counterfeit, it is determined that the identity identification authentication is successful;

[0172] Step 602: After the identity identification authentication is successful, the user identity information is determined according to the communication message;

[0173] Step 603: Convert the user identity information into the identity information of the open banking system, and use the identity information of the open banking system to replace the user identity information in the communication message to obtain a token application request message, and send the token application request message to the open banking API gateway.

[0174] In a specific embodiment, the specific implementation process of step 503 is as Figure 7 shown, including:

[0175] Step 701: When the mobile SDK is initialized, the open banking API gateway receives the token application request message sent by the cooperative institution's server, and performs permission verification according to the token application request message;

[0176] Step 702: After the permission verification passes, generate an access token and send the access token to the product service backend component of the open banking backend system;

[0177] Step 703: Receive the user factor information and the main transaction account information returned by the product service backend component, and cache them in Redis with the access token as the key and the user factor information and the main transaction account information as the values;

[0178] Step 704: According to the information cached in Redis, initiate a risk assessment request to the risk control platform of the open banking backend system.

[0179] In a specific embodiment, the implementation process of step 504 is as Figure 8 shown, including:

[0180] Step 801: The product service backend component receives the access token sent by the open banking API gateway, identifies the access token, and obtains the user factor information and the main transaction account information of the user; return the user factor information and the main transaction account information of the user to the open banking API gateway;

[0181] Step 802: The risk control platform receives the risk assessment request initiated by the open banking API gateway, determines the application usage information and the user factor information according to the risk assessment request; uses the application usage information and the user factor information to perform a risk assessment, determines the assessment result, and feeds back the assessment result to the open banking API gateway.

[0182] Correspondingly, the implementation process of step 505 is as Figure 9 shown, including:

[0183] Step 901: When the mobile SDK is initialized, the open banking API gateway receives the assessment result fed back by the risk control platform;

[0184] Step 902: Determine whether to approve the access of the mobile SDK according to the assessment result fed back by the risk control platform.

[0185] Step 903: When approving the access of the mobile SDK, return to the mobile SDK: the entry address of the product, the access token, and the key.

[0186] When conducting a transaction in the page mode of the mobile SDK, the specific implementation process of step 506 is as Figure 10 shown and includes:

[0187] Step 1001: The mobile SDK opens the web view control and jumps to the entry address of the product;

[0188] Step 1002: Assemble the access token into the transaction message, and use the key to encrypt the transaction message to generate an encrypted transaction message, and send it to the open banking API gateway.

[0189] Further, the implementation process of step 507 is as Figure 11 shown and includes:

[0190] Step 1101: When conducting a transaction in the page mode of the mobile SDK, receive the encrypted transaction message sent by the mobile SDK and decrypt the encrypted transaction message;

[0191] Step 1102: Perform token verification on the decrypted transaction message. After the verification passes, send a transaction message request to the product service backend component of the open banking backend system.

[0192] Specifically, when implemented, the implementation process of step 508 is as Figure 12 shown and includes:

[0193] Step 1201: The product service backend component receives the transaction message request sent by the open banking API gateway. According to the transaction message request, record the processing status of the business process in the cache; obtain the user identity information from the user element information cached in Redis, and compare the obtained user identity information with the transaction identity information in the transaction message request for anti-overprivilege comparison; after the comparison passes, process the corresponding transaction; push the relevant information of the transaction to the risk control platform;

[0194] Step 1202: The risk control platform receives the relevant information of the transaction pushed by the product service backend component, conducts transaction behavior analysis based on the relevant information of the transaction, determines the transaction behavior analysis result, and feeds it back to the product service backend component;

[0195] Step 1203: The product service backend component receives the transaction behavior analysis result fed back by the risk control platform, generates a response message, and returns it to the open banking API gateway.

[0196] Figure 13 It is a schematic block diagram of the system composition of the electronic device 1300 according to the embodiment of the present application. AsFigure 13 As shown, the electronic device 1300 may include a central processing unit 1301 and a memory 1302; the memory 1302 is coupled to the central processing unit 1301. It should be noted that this Figure 13 is exemplary; other types of structures may also be used to supplement or replace this structure to implement telecommunication functions or other functions.

[0197] In one embodiment, the functions of the API service security control system of the open bank may be integrated into the central processing unit 1301. Among them, the central processing unit 1301 may be configured to perform the following controls:

[0198] The mobile SDK is used to receive the user identification information sent by the application, collect the application usage information; obtain the communication message according to the user identification information and the application usage information, send the communication message to the SDK authentication service interface of the cooperative institution server for identity identification and authentication; enter the entry address of the product returned by the open bank API gateway, generate an encrypted transaction message using the access token and the key, and send it to the open bank API gateway;

[0199] The cooperative institution server is used to receive the communication message sent by the mobile SDK, and perform identity identification and authentication on the application according to the communication message; after the identity identification and authentication is successful, convert the communication message to obtain a token application request message, and send the token application request message to the open bank API gateway;

[0200] The open bank API gateway is used to receive the token application request message sent by the cooperative institution server, generate an access token according to the token application request message, and send the access token to the open bank back-end system; according to the evaluation result feedback by the open bank back-end system, return to the mobile SDK: the entry address of the product, the access token and the key; receive the encrypted transaction message sent by the mobile SDK, and send a transaction message request to the open bank back-end system according to the encrypted transaction message; receive the response message returned by the open bank back-end system, determine the transaction response result according to the response message, and send it to the mobile SDK;

[0201] The open bank back-end system is used to receive the access token, perform risk assessment, and send the evaluation result to the open bank API gateway; receive the transaction message request, perform anti-over-authorization verification and transaction behavior analysis according to the transaction message request to obtain a response message, and send the response message to the open bank API gateway.

[0202] As can be seen from the above description, the electronic device provided by the embodiment of the present application sets a mobile SDK to receive the user identification information sent by the application and collect the application usage information; according to the user identification information and the application usage information, a communication message is obtained, and the communication message is sent to the SDK authentication service interface of the cooperative institution server for identity identification and authentication; enter the entry address of the product returned by the open banking API gateway, and use the access token and key to generate an encrypted transaction message and send it to the open banking API gateway; set the cooperative institution server to receive the communication message sent by the mobile SDK and, according to the communication message, perform identity identification and authentication on the application; after successful identity identification and authentication, convert the communication message to obtain a token application request message and send the token application request message to the open banking API gateway; set the open banking API gateway to receive the token application request message sent by the cooperative institution server, generate an access token according to the token application request message, and send the access token to the open banking back-end system; according to the evaluation result feedback by the open banking back-end system, return to the mobile SDK: the entry address of the product, the access token, and the key; receive the encrypted transaction message sent by the mobile SDK and, according to the encrypted transaction message, send a transaction message request to the open banking back-end system; receive the response message returned by the open banking back-end system, determine the transaction response result according to the response message, and send it to the mobile SDK; set the open banking back-end system to receive the access token, perform risk assessment, and send the assessment result to the open banking API gateway; receive the transaction message request, perform anti-over-authorization verification and transaction behavior analysis according to the transaction message request to obtain a response message, and send the response message to the open banking API gateway. Using the access token for business process association realizes a Session (time domain)-like management mechanism, avoids the existence of horizontal and vertical over-authorization, and avoids the occurrence of serious vulnerabilities such as maliciously skipping business verification steps, thereby avoiding user data leakage and reducing the occurrence of financial losses.

[0203] In another embodiment, the API business security control system of the open banking can be separately configured from the central processing unit 1301. For example, the API business security control system of the open banking can be configured as a chip connected to the central processing unit 1301, and the API business security control function of the open banking is realized through the control of the central processing unit.

[0204] As Figure 13 shown, the electronic device 1300 may further include: a communication module 1303, an input unit 1304, an audio processor 1305, a display 1306, and a power supply 1307. It should be noted that the electronic device 1300 does not necessarily have to include Figure 13 all the components shown in Figure 13For components not shown, reference may be made to the prior art.

[0205] As Figure 13 shown, the central processing unit 1301, sometimes also referred to as a controller or operation control, may include a microprocessor or other processor device and / or logic device. The central processing unit 1301 receives inputs and controls the operation of the various components of the electronic device 1300.

[0206] Among them, the memory 1302, for example, may be one or more of a buffer, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory, or other suitable devices. The above information related to failures can be stored, and in addition, programs for executing relevant information can also be stored. And the central processing unit 1301 can execute the program stored in the memory 1302 to implement information storage or processing, etc.

[0207] The input unit 1304 provides inputs to the central processing unit 1301. The input unit 1304 is, for example, a key or a touch input device. The power supply 1307 is used to supply power to the electronic device 1300. The display 1306 is used to display display objects such as images and texts. The display may be, for example, an LCD display, but is not limited thereto.

[0208] The memory 1302 may be a solid-state memory. For example, it may be a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It may also be such a memory that stores information even when powered off, can be selectively erased, and has more data. Examples of such a memory are sometimes referred to as EPROMs, etc. The memory 1302 may also be some other type of device. The memory 1302 includes a buffer memory 1321 (sometimes referred to as a buffer). The memory 1302 may include an application / function storage section 1322, which is used to store application programs and function programs or the processes for operating the electronic device 1300 through the central processing unit 1301.

[0209] The memory 1302 may also include a data storage section 1323, which is used to store data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage section 1324 of the memory 1302 may include various drivers of the electronic device for communication functions and / or for executing other functions of the electronic device (such as a messaging application, an address book application, etc.).

[0210] The communication module 1303 is the transmitter / receiver 1303 that transmits and receives signals via the antenna 1308. The communication module (transmitter / receiver) 1303 is coupled to the central processing unit 1301 to provide input signals and receive output signals, which can be the same as in the case of a conventional mobile communication terminal.

[0211] Based on different communication technologies, multiple communication modules 1303 can be provided in the same electronic device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, etc. The communication module (transmitter / receiver) 1303 is also coupled to the speaker 1309 and the microphone 1310 via the audio processor 1305 to provide an audio output via the speaker 1309 and receive an audio input from the microphone 1310, thereby implementing the usual telecommunications functions. The audio processor 1305 can include any suitable buffers, decoders, amplifiers, etc. Additionally, the audio processor 1305 is also coupled to the central processing unit 1301, so that it is possible to record on the local device through the microphone 1310 and play the sound stored on the local device through the speaker 1309.

[0212] Embodiments of the present invention also provide a computer-readable storage medium capable of implementing all the steps in the open bank API service security control method in the above embodiments. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, all the steps of the open bank API service security control method in the above embodiments are implemented. For example, when the processor executes the computer program, the following steps are implemented:

[0213] The mobile SDK receives the user identification information sent by the application and collects the application usage information; based on the user identification information and the application usage information, a communication message is obtained, and the communication message is sent to the SDK authentication service interface of the cooperative institution server for identity recognition authentication;

[0214] The cooperative institution server receives the communication message sent by the mobile SDK and performs identity recognition authentication on the application according to the communication message; after the identity recognition authentication is successful, the communication message is converted to obtain a token application request message, and the token application request message is sent to the open bank API gateway;

[0215] The open bank API gateway receives the token application request message sent by the cooperative institution server, generates an access token according to the token application request message, and sends the access token to the open bank back-end system;

[0216] The open bank back-end system receives the access token, performs a risk assessment, and sends the assessment result to the open bank API gateway;

[0217] The Open Banking API Gateway returns to the Mobile SDK the entry address, access token, and secret key of the product based on the evaluation results feedback by the Open Banking back-end system;

[0218] The Mobile SDK enters the entry address of the product returned by the Open Banking API Gateway, generates an encrypted transaction message using the access token and secret key, and sends it to the Open Banking API Gateway;

[0219] The Open Banking API Gateway receives the encrypted transaction message sent by the Mobile SDK and sends a transaction message request to the Open Banking back-end system based on the encrypted transaction message;

[0220] The Open Banking back-end system receives the transaction message request, performs anti-overprivilege verification and transaction behavior analysis based on the transaction message request, obtains a response message, and sends the response message to the Open Banking API Gateway;

[0221] The Open Banking API Gateway receives the response message returned by the Open Banking back-end system, determines the transaction response result based on the response message, and sends it to the Mobile SDK.

[0222] In summary, the API service security control system and method for Open Banking provided by the embodiments of the present invention have the following advantages:

[0223] By setting up the mobile SDK, receive the user identification information sent by the application, and collect the application usage information; based on the user identification information and the application usage information, obtain a communication message, and send the communication message to the SDK authentication service interface of the cooperative institution's server for identity authentication; enter the entry address of the product returned by the open banking API gateway, and use the access token and key to generate an encrypted transaction message and send it to the open banking API gateway; set up the cooperative institution's server to receive the communication message sent by the mobile SDK, and based on the communication message, authenticate the identity of the application; after successful identity authentication, convert the communication message to obtain a token application request message, and send the token application request message to the open banking API gateway; set up the open banking API gateway to receive the token application request message sent by the cooperative institution's server, generate an access token based on the token application request message, and send the access token to the open banking back-end system; according to the evaluation result feedback by the open banking back-end system, return to the mobile SDK: the entry address of the product, the access token, and the key; receive the encrypted transaction message sent by the mobile SDK, and based on the encrypted transaction message, send a transaction message request to the open banking back-end system; receive the response message returned by the open banking back-end system, determine the transaction response result based on the response message, and send it to the mobile SDK; set up the open banking back-end system to receive the access token, conduct a risk assessment, and send the assessment result to the open banking API gateway; receive the transaction message request, conduct anti-overprivilege verification and transaction behavior analysis based on the transaction message request to obtain a response message, and send the response message to the open banking API gateway. By using the access token for business process association, a Session (time domain)-like management mechanism is realized, avoiding the existence of horizontal and vertical overprivilege, and avoiding the occurrence of serious vulnerabilities such as maliciously skipping business verification steps, thereby avoiding the leakage of user data and reducing the occurrence of losses to funds.

[0224] Although the present invention provides method operation steps as described in the embodiments or flowcharts, based on routine or non-creative labor, there may be more or fewer operation steps. The step order listed in the embodiments is only one way among the execution orders of numerous steps and does not represent the only execution order. When the actual device or client product is executed, it can be executed in the order of the method shown in the embodiments or the drawings or in parallel (for example, in an environment with parallel processors or multi-threaded processing).

[0225] Those skilled in the art should understand that the embodiments of this specification can be provided as methods, apparatuses (systems) or computer program products. Therefore, the embodiments of this specification can take the form of all-hardware embodiments, all-software embodiments, or embodiments combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) that contain computer-usable program code.

[0226] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems) and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0227] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means realizes the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0228] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0229] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For the relevant parts, reference can be made to the description of the method embodiment. In this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. The orientation or positional relationship indicated by terms such as "upper" and "lower" is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus cannot be understood as a limitation of the present invention. Unless otherwise expressly specified and limited, the terms "installed", "connected" and "coupled" shall be construed broadly. For example, it can be a fixed connection, a detachable connection or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the internal communication of two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances. It should be noted that, without conflict, the embodiments and features in the embodiments of the present invention can be combined with each other. The present invention is not limited to any single aspect, nor to any single embodiment, nor to any arbitrary combination and / or permutation of these aspects and / or embodiments. Moreover, each aspect and / or embodiment of the present invention can be used alone or in combination with one or more other aspects and / or their embodiments.

[0230] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or equivalently replace some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered by the scope of the claims and the specification of the present invention.

Claims

1. An API business security control system for open banking, characterized in that, it includes: A mobile SDK, which is used to receive the user identification information sent by the application and collect the application usage information; According to the user identification information and the application usage information, obtain a communication message, and send the communication message to the SDK authentication service interface of the cooperative institution server for identity authentication; Enter the entry address of the product returned by the open banking API gateway, generate an encrypted transaction message using the access token and the key, and send it to the open banking API gateway; The cooperative institution server is used to receive the communication message sent by the mobile SDK, and authenticate the identity of the application according to the communication message; after the identity authentication is successful, convert the communication message to obtain a token application request message, and send the token application request message to the open banking API gateway; The open banking API gateway is used to receive the token application request message sent by the cooperative institution server, generate an access token according to the token application request message, and send the access token to the open banking back-end system; According to the evaluation result feedback by the open banking back-end system, return to the mobile SDK: the entry address of the product, the access token and the key; receive the encrypted transaction message sent by the mobile SDK, and send a transaction message request to the open banking back-end system according to the encrypted transaction message; Receive the response message returned by the open banking back-end system, determine the transaction response result according to the response message, and send it to the mobile SDK; The open banking back-end system is used to receive the access token, conduct a risk assessment, and send the assessment result to the open banking API gateway; Receive the transaction message request, conduct anti-overprivilege verification and transaction behavior analysis according to the transaction message request to obtain a response message, and send the response message to the open banking API gateway; Among them, the mobile SDK is specifically used for: When the mobile SDK is initialized, it receives the user identification information sent by the application and collects the application usage information; according to the user identification information and the application usage information, obtain a communication message, and send the communication message to the SDK authentication service interface of the cooperative institution server for identity authentication; among them, the mobile side provides the product name and access scenario that it hopes to use to the SDK, and provides the relevant information used to identify the currently logged-in user of the APP, including Cookie and Session ID; the APP calls the SDK, and the SDK collects the application usage information, including: the device information of the mobile side, the APP application information and the running environment detection information; During the page mode transaction of the mobile SDK, open the web view control and jump to the entry address of the product; assemble the access token into the transaction message, and encrypt the transaction message using the key to generate an encrypted transaction message, and send it to the open banking API gateway; Use the access token for business process association to implement a class-Session management mechanism.

2. The API service security control system for open banking as described in claim 1, characterized in that, the cooperative institution server is specifically used for: receiving the communication message sent by the mobile SDK, and verifying whether the application is counterfeited according to the communication message. If the verification result is not counterfeited, it is determined that the identity recognition authentication is successful; after the identity recognition authentication is successful, determining the user identity information according to the communication message; converting the user identity information into the identity information of the open banking system, using the identity information of the open banking system to replace the user identity information in the communication message, obtaining a token application request message, and sending the token application request message to the open banking API gateway.

3. The API service security control system for open banking as described in claim 2, characterized in that, when the mobile SDK is initialized, the open banking API gateway is specifically used for: receiving the token application request message sent by the cooperative institution server, and performing permission verification according to the token application request message; after the permission verification is passed, generating an access token, and sending the access token to the product service backend component of the open banking backend system; receiving the user element information and the main transaction account information returned by the product service backend component, and caching them in Redis with the access token as the key and the user element information and the main transaction account information as the values; initiating a risk assessment request to the risk control platform of the open banking backend system according to the information cached in Redis, and receiving the evaluation result feedback by the risk control platform; determining whether to approve the access of the mobile SDK according to the evaluation result feedback by the risk control platform; when approving the access of the mobile SDK, returning to the mobile SDK: the entry address of the product, the access token, and the secret key.

4. The API service security control system for open banking as described in claim 3, characterized in that, the open banking backend system includes: a product service backend component, which is used for receiving the access token sent by the open banking API gateway, identifying the access token, and obtaining the user element information and the main transaction account information of the user; returning the user element information and the main transaction account information of the user to the open banking API gateway; a risk control platform, which is used for receiving the risk assessment request initiated by the open banking API gateway, determining the application usage information and the user element information according to the risk assessment request; performing risk assessment by using the application usage information and the user element information, determining the assessment result, and feeding back the assessment result to the open banking API gateway.

5. The API service security control system for open banking as described in claim 3, characterized in that, when the mobile SDK performs page mode transactions, the open banking API gateway is specifically used for: receiving the encrypted transaction message sent by the mobile SDK, and decrypting the encrypted transaction message; performing token verification on the decrypted transaction message, and after the verification is passed, sending a transaction message request to the product service backend component of the open banking backend system. Receive the response message returned by the open banking back-end system, determine the transaction response result according to the response message, and send the transaction response result to the mobile SDK.

6. The API service security control system of the open banking as described in claim 5, characterized in that the open banking back-end system includes: A product service back-end component, which is used to receive the transaction message request sent by the open banking API gateway, record the processing status of the business process in the cache according to the transaction message request; obtain the user identity information from the user element information cached in Redis, and compare the obtained user identity information with the transaction identity information in the transaction message request for anti-over-authorization comparison; after the comparison passes, process the corresponding transaction; push the relevant information of the transaction to the risk control platform; receive the transaction behavior analysis result fed back by the risk control platform, generate a response message, and return it to the open banking API gateway; A risk control platform, which is used to receive the relevant information of the transaction pushed by the product service back-end component, perform transaction behavior analysis according to the relevant information of the transaction, determine the transaction behavior analysis result, and feed it back to the product service back-end component.

7. An API service security control method for open banking, characterized in that it includes: The mobile SDK receives the user identification information sent by the application and collects the application usage information; According to the user identification information and the application usage information, obtain a communication message, and send the communication message to the SDK authentication service interface of the cooperative institution server for identity authentication; The cooperative institution server receives the communication message sent by the mobile SDK, and performs identity authentication on the application according to the communication message; after the identity authentication is successful, convert the communication message to obtain a token application request message, and send the token application request message to the open banking API gateway; The open banking API gateway receives the token application request message sent by the cooperative institution server, generates an access token according to the token application request message, and sends the access token to the open banking back-end system; The open banking back-end system receives the access token, performs a risk assessment, and sends the assessment result to the open banking API gateway; The open banking API gateway returns to the mobile SDK according to the assessment result fed back by the open banking back-end system: the entry address of the product, the access token, and the key; The mobile SDK enters the entry address of the product returned by the open banking API gateway, generates an encrypted transaction message using the access token and the key, and sends it to the open banking API gateway; The open banking API gateway receives the encrypted transaction message sent by the mobile SDK, and sends a transaction message request to the open banking back-end system according to the encrypted transaction message; The open banking back-end system receives the transaction message request, performs anti-over-authorization verification and transaction behavior analysis according to the transaction message request, obtains a response message, and sends the response message to the open banking API gateway; The open banking API gateway receives the response message returned by the open banking back-end system, determines the transaction response result according to the response message, and sends it to the mobile SDK; Among them, the mobile SDK receives the user identification information sent by the application program, and collects the application program usage information; according to the user identification information and the application program usage information, a communication message is obtained, and the communication message is sent to the SDK authentication service interface of the partner institution server for identity recognition authentication, including: When the mobile SDK is initialized, it receives the user identification information sent by the application program, and collects the application program usage information; according to the user identification information and the application program usage information, a communication message is obtained, and the communication message is sent to the SDK authentication service interface of the partner institution server for identity recognition authentication; among them, the mobile terminal provides the product name and access scenario that it hopes to use to the SDK, and provides the relevant information for identifying the currently logged-in user of the APP to the SDK, including Cookie and Session ID; the APP calls the SDK, and the SDK collects the application program usage information, including: the device information of the mobile terminal, the APP application information, and the running environment detection information; When the mobile SDK conducts a page-mode transaction, it opens a web view control and jumps to the entry address of the product; assembles the access token into the transaction message, and encrypts the transaction message with the key to generate an encrypted transaction message, and sends it to the open banking API gateway; Use the access token for business process association to implement a class-Session management mechanism.

8. The API service security control method of the open banking as claimed in claim 7, characterized in that The partner institution server receives the communication message sent by the mobile SDK, and conducts identity recognition authentication on the application program according to the communication message; After the identity recognition authentication is successful, the communication message is converted to obtain a token application request message, and the token application request message is sent to the open banking API gateway, including: The partner institution server receives the communication message sent by the mobile SDK, and verifies whether the application program is a fake according to the communication message. If the verification result is not a fake, it is determined that the identity recognition authentication is successful; After the identity recognition authentication is successful, the user identity information is determined according to the communication message; Convert the user identity information into the identity information of the open banking system, and use the identity information of the open banking system to replace the user identity information in the communication message to obtain a token application request message, and send the token application request message to the open banking API gateway.

9. The API service security control method of the open banking as claimed in claim 7, characterized in that The open banking API gateway receives the token application request message sent by the partner institution server, generates an access token according to the token application request message, and sends the access token to the open banking back-end system, including: When the mobile SDK is initialized, the open banking API gateway receives the token application request message sent by the cooperative institution's server, and performs permission verification according to the token application request message; After the permission verification passes, an access token is generated, and the access token is sent to the product service backend component of the open banking backend system; Receive the user factor information and the main transaction account information returned by the product service backend component, and cache them in Redis with the access token as the key and the user factor information and the main transaction account information as the values; According to the information cached in Redis, initiate a risk assessment request to the risk control platform of the open banking backend system.

10. The API service security control method of the open banking as claimed in claim 9, characterized in that, The open banking backend system receives the access token, performs a risk assessment, and sends the assessment result to the open banking API gateway, including: The product service backend component receives the access token sent by the open banking API gateway, identifies the access token, and obtains the user factor information and the main transaction account information of the user; returns the user factor information and the main transaction account information of the user to the open banking API gateway; The risk control platform receives the risk assessment request initiated by the open banking API gateway, determines the application usage information and the user factor information according to the risk assessment request; uses the application usage information and the user factor information to perform a risk assessment, determines the assessment result, and feeds back the assessment result to the open banking API gateway.

11. The API service security control method of the open banking as claimed in claim 9, characterized in that, The open banking API gateway returns to the mobile SDK the entry address, access token and key of the product according to the assessment result feedback by the open banking backend system, including: When the mobile SDK is initialized, the open banking API gateway receives the assessment result feedback by the risk control platform; According to the assessment result feedback by the risk control platform, determine whether to approve the access of the mobile SDK; When the access of the mobile SDK is approved, return to the mobile SDK the entry address, access token and key of the product.

12. The API service security control method of the open banking as claimed in claim 7, characterized in that, The mobile SDK enters the entry address of the product returned by the open banking API gateway, generates an encrypted transaction message using the access token and the key, and sends it to the open banking API gateway, including: When the mobile SDK performs a page mode transaction, the mobile SDK opens a web view control and jumps to the entry address of the product; Assemble the access token into the transaction message, and encrypt the transaction message using the key to generate an encrypted transaction message, and send it to the open banking API gateway.

13. The API service security control method of the open banking as claimed in claim 12, characterized in that, The open banking API gateway receives the encrypted transaction message sent by the mobile SDK, and sends a transaction message request to the open banking backend system according to the encrypted transaction message, including: When conducting transactions in the mobile SDK page mode, receive the encrypted transaction message sent by the mobile SDK and decrypt the encrypted transaction message; Perform token verification on the decrypted transaction message. After successful verification, send a transaction message request to the product service backend component of the open banking backend system.

14. The API service security control method for an open bank according to claim 13, characterized in that, The open banking backend system receives the transaction message request and performs anti-overprivilege verification and transaction behavior analysis based on the transaction message request to obtain a response message, and sends the response message to the open banking API gateway, including: The product service backend component receives the transaction message request sent by the open banking API gateway, records the processing status of the business process in the cache according to the transaction message request; obtains the user identity information from the user element information cached in Redis, and compares the obtained user identity information with the transaction identity information in the transaction message request for anti-overprivilege comparison; after successful comparison, process the corresponding transaction; push the relevant information of the transaction to the risk control platform; The risk control platform receives the relevant information of the transaction pushed by the product service backend component, performs transaction behavior analysis based on the relevant information of the transaction, determines the transaction behavior analysis result, and feeds it back to the product service backend component; The product service backend component receives the transaction behavior analysis result fed back by the risk control platform, generates a response message, and returns it to the open banking API gateway.

15. A computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 7 to 14.

16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program for executing the method according to any one of claims 7 to 14.

Citation Information

Patent Citations

  • Open bank-oriented network security control method and open bank platform

    CN110740136A

  • Bank open system access method and system

    CN112822258A