Business Processing Method, Apparatus and Electronic Device
By obtaining the security authentication records of trusted users and judging the geographical location changes of the target user, the security authentication level is exempted or reduced, which solves the frequent security authentication problems caused by user geographical location changes and improves the user experience.
Patent Information
- Application Number
- CN202111404875.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-12-24
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2039-12-24
AI Technical Summary
In the prior art, when e-commerce companies conduct risk control when users' geographical location changes, the problem of security authentication frequently interfering with users' normal use, especially when users travel or outbound travel affects transaction behavior.
By receiving the service request of the target user, judging its geographical location changes, obtaining the security authentication record of the trusted user, and determining whether to exempt or lower the security authentication level of the target user based on the security authentication geographical location, time and level of the trusted user, and then processing the service request.
It reduces the disturbance rate of business request operations of security authentication to the target user, improves the user experience, and reduces unnecessary security authentication steps.
Smart Images

Figure CN113918905B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of Internet technologies, and in particular, to a service processing method, apparatus, and electronic device.
Background Art
[0002] In the existing related technologies, e-commerce companies will all perform risk control to ensure the security of users' accounts and transactions. When performing risk control, it is generally judged based on the base station information and / or geographical location information that the user often uses. When it is found that the user is in a brand-new geographical location, the risk of the user's account being stolen is very high. Therefore, various identity verifications will be enabled, such as entering a mobile phone verification code, etc.
[0003] However, this risk control scenario often disturbs the normal use of users. For example, when a user travels, the change in geographical location information will cause the user to perform verification; even when a user travels abroad without international roaming enabled, this verification will directly affect the normal user operation behavior and block the normal transaction behavior.
Summary of the Invention
[0004] The embodiments of this specification provide a service processing method, apparatus, and electronic device to process the service request of a target user according to the security authentication record of the target user's trusted user, reduce the operation interruption rate of the security authentication for the target user's service request, and improve the usage experience of the target user.
[0005] In a first aspect, one or more embodiments of this specification provide a service processing method, including: receiving a service request sent by a target user; determining the geographical location where the target user is currently located according to the service request; judging whether the target user has performed a security authentication at the current geographical location within a first predetermined period before the current moment; if the target user has not performed a security authentication at the current geographical location within the first predetermined period before the current moment, then obtaining the trusted user of the target user according to the type of the service request, and obtaining the security authentication record of the trusted user; and processing the service request according to the security authentication record of the trusted user.
[0006] In one possible implementation manner, the processing of the service request according to the security authentication record of the trusted user includes: obtaining the geographical location, authentication time, and security authentication level of the trusted user for security authentication from the security authentication record of the trusted user; if the geographical location where the trusted user conducts security authentication and the geographical location where the target user is currently located belong to the same region and the distance is within a predetermined range, and the time difference between the authentication time of the trusted user for security authentication and the time when the target user sends the service request is less than or equal to a second predetermined duration, and the security authentication level of the trusted user is not lower than the security authentication level required for the service request, then perform security authentication on the target user; after the target user passes the security authentication, process the service request.
[0007] In one possible implementation manner, the performing of security authentication on the target user includes: exempting the target user from performing security authentication for the service request; or reducing the security authentication level of the target user for the service request.
[0008] In one possible implementation manner, the obtaining of the trusted user of the target user according to the type of the service request includes: determining the security authentication level required for the service request according to the type of the service request; obtaining the trusted user matching the security authentication level required for the service request from the trusted users of the target user.
[0009] In one possible implementation manner, before obtaining the security authentication record of the trusted user, it further includes: obtaining the historical data of the target user; and performing data cleaning on the historical data, calculating using the cleaned data to obtain the trusted user of the target user and the corresponding security authentication level of the trusted user; or obtaining the trusted user set by the target user and the corresponding security authentication level of the trusted user.
[0010] In one possible implementation manner, before obtaining the security authentication record of the trusted user, it further includes: when the trusted user makes a service request, performing security authentication on the trusted user; saving the security authentication record of the trusted user, where the security authentication record of the trusted user includes the geographical location, authentication time, and security authentication level of the trusted user for security authentication.
[0011] Second aspect, one or more embodiments of this specification provide a service processing device, including: a receiving module, configured to receive a service request sent by a target user; an obtaining module, configured to determine the geographical location where the target user is currently located according to the service request received by the receiving module; a judging module, configured to judge whether the target user has performed a security authentication at the current geographical location within a first predetermined time period before the current moment; the obtaining module is further configured to, when the target user has not performed a security authentication at the current geographical location within the first predetermined time period before the current moment, obtain a trusted user of the target user according to the type of the service request, and obtain the security authentication record of the trusted user; a processing module, configured to process the service request according to the security authentication record of the trusted user.
[0012] In one possible implementation manner, the processing module includes: an information obtaining sub-module, configured to obtain, from the security authentication record of the trusted user, the geographical location, authentication time, and security authentication level at which the trusted user performs the security authentication; a security authentication sub-module, configured to perform a security authentication on the target user when the geographical location at which the trusted user performs the security authentication and the geographical location where the target user is currently located belong to the same area, and the distance is within a predetermined range, and the time difference between the authentication time at which the trusted user performs the security authentication and the time when the target user sends the service request is less than or equal to a second predetermined time period, and the security authentication level of the trusted user is not lower than the security authentication level required for the service request; a service processing sub-module, configured to process the service request after the target user passes the security authentication.
[0013] In one possible implementation manner, the security authentication sub-module is specifically configured to exempt the target user from performing the security authentication for the service request; or reduce the security authentication level for the target user to perform the service request.
[0014] In one possible implementation manner, the obtaining module is specifically configured to determine the security authentication level required for the service request according to the type of the service request; and obtain a trusted user that matches the security authentication level required for the service request from the trusted users of the target user.
[0015] In one possible implementation manner, the obtaining module is further configured to obtain the historical data of the target user; and perform data cleaning on the historical data, and calculate using the cleaned data to obtain the trusted user of the target user and the security authentication level corresponding to the trusted user; or obtain the trusted user set by the target user and the security authentication level corresponding to the trusted user.
[0016] In one possible implementation, the device further includes: a security authentication module, configured to perform security authentication on the trusted user when the trusted user makes a service request before the acquisition module acquires the security authentication record of the trusted user; and save the security authentication record of the trusted user, where the security authentication record of the trusted user includes the geographical location, authentication time, and security authentication level at which the trusted user performs security authentication.
[0017] In a third aspect, one or more embodiments of this specification provide an electronic device, including: at least one processor; and at least one memory communicatively connected to the processor, where: the memory stores program instructions executable by the processor, and the processor can execute the method described above by invoking the program instructions.
[0018] In a fourth aspect, one or more embodiments of this specification provide a non-transitory computer-readable storage medium, where the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions cause the computer to execute the method described above.
[0019] In the above technical solutions, after receiving a service request sent by a target user, determine the geographical location where the target user is currently located according to the above service request, and then determine whether the target user has performed security authentication at the current geographical location within a first predetermined period before the current moment; if the target user has not performed security authentication at the current geographical location within the first predetermined period before the current moment, then obtain the trusted user of the target user according to the type of the above service request, and obtain the security authentication record of the trusted user; finally, process the above service request according to the security authentication record of the trusted user, so as to realize processing the service request of the target user according to the security authentication record of the trusted user of the target user, reduce the operation interruption rate of the security authentication to the service request of the target user, and improve the usage experience of the target user.
Description of the Drawings
[0020] To more clearly illustrate the technical solutions of one or more embodiments of this specification, the following will briefly introduce the drawings required for the embodiments. Obviously, the drawings in the following description are only some embodiments of this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0021] Figure 1 It is a flowchart of an embodiment of the service processing method of this specification;
[0022] Figure 2 It is a flowchart of another embodiment of the service processing method of this specification;
[0023] Figure 3 It is a flowchart of another embodiment of the service processing method in this specification;
[0024] Figure 4 It is a flowchart of another embodiment of the service processing method in this specification;
[0025] Figure 5 It is a flowchart of another embodiment of the service processing method in this specification;
[0026] Figure 6 It is a schematic structural diagram of an embodiment of the service processing device in this specification;
[0027] Figure 7 It is a schematic structural diagram of another embodiment of the service processing device in this specification;
[0028] Figure 8 It is a schematic structural diagram of an embodiment of the electronic device in this specification.
Detailed Implementation Manner
[0029] In order to better understand the technical solutions of one or more embodiments of this specification, the following describes one or more embodiments of this specification in detail with reference to the accompanying drawings.
[0030] It should be clear that the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by this specification.
[0031] The terms used in one or more embodiments of this specification are only for the purpose of describing specific embodiments, and are not intended to limit this specification. The singular forms "a", "the" and "said" used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0032] Generally, when a user travels to another place, he / she goes out with family and friends. Therefore, among the relatives and friends who travel together, after a relatively strict security authentication (such as face authentication) is performed on the first person's operation in a different place, the security authentication interruption for the subsequent others should be reduced.
[0033] Based on the above scenario, the embodiments of this specification provide a service processing method, which reduces the operation interruption rate of the target user when making a service request according to the security authentication records of the target user's trusted users.
[0034] Figure 1 It is a flowchart of an embodiment of the service processing method in this specification, asFigure 1 As shown in the figure, the above service processing method may include:
[0035] Step 101: Receive a service request sent by a target user.
[0036] Step 102: Determine the geographical location where the target user is currently located according to the above service request.
[0037] Specifically, the geographical location where the target user is currently located may be determined according to the source address carried in the above service request; or the geographical location where the target user is currently located may be determined according to the base station used by the target user to send the above service request. This embodiment does not limit the method for determining the geographical location where the target user is currently located.
[0038] In specific implementation, the geographical location where the target user is currently located may be a geographical location different from the target user's usual residence, that is to say, the target user makes the above service request in a different place.
[0039] Step 103: Determine whether the target user has performed a security authentication at the current geographical location within a first predetermined time period before the current moment.
[0040] If yes, execute Step 104; if the target user has not performed a security authentication at the current geographical location within the first predetermined time period before the current moment, execute Step 105.
[0041] Among them, the above first predetermined time period can be set by itself according to system performance and / or implementation requirements, etc. in specific implementation. This embodiment does not limit the length of the above first predetermined time period. For example, the above first predetermined time period can be 5 days.
[0042] Step 104: Process the above service request.
[0043] Specifically, the security authentication record of the target user at the current geographical location within the first predetermined time period before the current moment can be obtained, and the security authentication level in the above security authentication record can be obtained. If the security authentication level is not lower than the security authentication level required by the above service request, the above service request can be directly processed; if the security authentication level in the above security authentication record is lower than the security authentication level required by the above service request, the target user needs to be authenticated according to the security authentication level required by the above service request. After the target user passes the security authentication, the above service request is processed.
[0044] Step 105: According to the type of the above service request, obtain the trusted users of the above target user and obtain the security authentication records of the above trusted users.
[0045] Step 106: Process the above service request according to the security authentication record of the above trusted user.
[0046] In the above service processing method, after receiving a service request sent by a target user, determine the geographical location where the target user is currently located according to the above service request, and then determine whether the target user has performed a security authentication at the current geographical location within a first predetermined period of time before the current moment; if the target user has not performed a security authentication at the current geographical location within the first predetermined period of time before the current moment, then obtain the trusted users of the above target user according to the type of the above service request, and obtain the security authentication records of the above trusted users; finally, process the above service request according to the security authentication records of the above trusted users, so as to realize processing the service request of the target user according to the security authentication records of the trusted users of the target user, reducing the operation interruption rate of the security authentication to the service request of the target user, and improving the user experience of the target user.
[0047] Figure 2 It is a flowchart of another embodiment of the service processing method in this specification. As Figure 2 shown, in the embodiment shown in this specification Figure 1 Step 106 may include:
[0048] Step 201: Obtain the geographical location, authentication time, and security authentication level at which the above trusted user performs security authentication from the security authentication records of the above trusted user.
[0049] In this embodiment, when a user is in a different place and makes a service request such as an account operation or a payment operation, the server will detect the risk of the above user's operation in a different place, and thus will perform a relatively strict security authentication on the above user. After the user performs a security authentication, the server will save the security authentication record of the user. The above security authentication record may include the following fields: user identifier (Identifier; hereinafter referred to as: ID), geographical location where the security authentication is performed, authentication time, and security authentication level. Specifically, an example of the security authentication record may be shown in Table 1.
[0050] Table 1
[0051]
[0052] The above security authentication level may be the level of the security authentication product. The above security authentication products may include dozens of types such as passwords, SMS verification codes, face recognition, and answers to reserved questions for authentication. The levels of the above security authentication products may be shown in Table 2. The higher the security authentication level, the higher the interruption rate of the security authentication, and the lower the risk after authentication is passed.
[0053] Table 2
[0054] Security authentication product Security authentication level SMS verification code 3 Reserved question answer 3 Password 3 Face recognition 5
[0055] Step 202: If the geographical location where the above-mentioned trusted user conducts security authentication and the geographical location where the target user is currently located belong to the same region, and the distance is within a predetermined range, and the time difference between the authentication time when the above-mentioned trusted user conducts security authentication and the time when the above-mentioned target user sends a service request is less than or equal to a second predetermined duration, and the security authentication level of the above-mentioned trusted user is not lower than the security authentication level required for the above-mentioned service request, then conduct security authentication for the above-mentioned target user.
[0056] Specifically, the situation that the geographical location where the above-mentioned trusted user conducts security authentication and the geographical location where the target user is currently located belong to the same region can be: the geographical location where the above-mentioned trusted user conducts security authentication and the geographical location where the target user is currently located are in the same administrative region. For example: the same county or the same city, etc.; the above-mentioned predetermined range can be set by itself according to system performance and / or implementation requirements, etc. in specific implementation. This embodiment does not limit the size of the above-mentioned predetermined range. For example, the above-mentioned predetermined range can be 10 kilometers.
[0057] The above-mentioned second predetermined duration can be set by itself according to system performance and / or implementation requirements, etc. in specific implementation. This embodiment does not limit the length of the above-mentioned second predetermined duration. For example, the above-mentioned second predetermined duration can be 1 day.
[0058] As described above, the above-mentioned security authentication level is the level of the security authentication product. Different service requests require different security authentication products for security authentication. Therefore, different service requests require different security authentication levels. For example, non-fund type service requests may only need to use passwords or SMS verification codes for security authentication. As shown in Table 2, the security authentication level required for non-fund type service requests is 3. For fund type service requests, face recognition may be required for security authentication. As shown in Table 2, the security authentication level required for fund type service requests is 5.
[0059] Specifically, conducting security authentication for the above-mentioned target user can be: exempting the target user from conducting security authentication for the above-mentioned service request; or, reducing the security authentication level of the target user for the service request.
[0060] In specific implementation, assume that the geographical location where the above-mentioned trusted user conducts security authentication is in the same city as the geographical location where the target user is currently located, and the distance is within 10 kilometers. Also, assume that the time difference between the authentication time when the above-mentioned trusted user conducts security authentication and the time when the above-mentioned target user sends a service request is less than or equal to 1 day, and the security authentication level of the above-mentioned trusted user is 5, while the security authentication level required for the above-mentioned service request is 3. In this way, it can be determined that the security level of the above-mentioned target user for the above-mentioned service request is greater than the security authentication level required for the above-mentioned service request, and it is considered that the credibility of the target user appearing at the current geographical location is relatively high.
[0061] Furthermore, the security authentication for the above-mentioned service request of the target user can be waived; or, the security authentication level for the above-mentioned service request of the target user can be reduced. For example, originally, the target user needed to perform face recognition for a service request, but now only needs a password. Thus, the operation interruption rate of the security authentication for the service request of the target user can be reduced, and the usage experience of the target user can be improved.
[0062] Step 203: After the above-mentioned target user passes the security authentication, process the above-mentioned service request.
[0063] Figure 3 This is a flowchart of another embodiment of the service processing method in this specification. As Figure 3 shown, in the embodiment shown in this specification Figure 1 Step 105 may include:
[0064] Step 301: Determine the security authentication level required for the above-mentioned service request according to the type of the above-mentioned service request.
[0065] Among them, the above-mentioned first security authentication record includes the security authentication record of the target user at the current geographical location within the first predetermined duration before the current moment.
[0066] Specifically, different service requests require different security authentication products for security authentication, so different service requests require different security authentication levels. For example, non-fund type service requests may only require password or SMS verification code for security authentication. As shown in Table 2, the security authentication level required for non-fund type service requests is 3. For fund type service requests, face recognition may be required for security authentication. As shown in Table 2, the security authentication level required for fund type service requests is 5.
[0067] Step 302: Obtain a trusted user that matches the security authentication level required for the above-mentioned service request from the trusted users of the above-mentioned target user.
[0068] Specifically, the server saves a list of trusted users for the target user. In the list of trusted users, the identifiers of the trusted users and the corresponding security authentication levels are saved, as shown in Table 3.
[0069] Table 3
[0070]
[0071] Therefore, after determining the security authentication level required for the above business request, the trusted user matching the security authentication level required for the above business request can be obtained from the list of trusted users of the target user.
[0072] Step 303: Obtain the security authentication records of the above trusted users.
[0073] Furthermore, before obtaining the security authentication records of the above trusted users, when the above trusted user makes a business request, the trusted user is subject to security authentication, and the security authentication records of the above trusted user are saved. The security authentication records of the above trusted user include the geographical location, authentication time, and security authentication level of the above trusted user for security authentication.
[0074] Figure 4 This is a flowchart of another embodiment of the business processing method in this specification. As Figure 4 shown, in the embodiment shown in this specification Figure 1 before step 105, it may further include:
[0075] Step 401: Obtain the historical data of the above target user; and perform data cleaning on the above historical data, calculate using the cleaned data, and obtain the trusted users of the above target user and the corresponding security authentication levels of the above trusted users; or, obtain the trusted users set by the above target user and the corresponding security authentication levels of the above trusted users.
[0076] Specifically, referring to Table 3, the security authentication levels of different trusted relatives and friends are different. For example, for a trusted user who has a close relationship with the target user, the security authentication level can be 3. When the target user makes a non - fund - type business request, the security level of the above target user for the business request can be determined according to the security authentication records of the trusted user with a close relationship; for a trusted user who has a kinship with the target user, such as the parents, spouse, children, or siblings of the target user, etc., the security level can be 5. When the target user makes a fund - type business request, the security level of the above target user for the business request can be determined according to the security authentication records of the trusted user with a kinship with the target user.
[0077] In this embodiment, the trust relationship between the target user and the trusted user is one - way and non - transitive.
[0078] In specific implementation, obtaining the trusted users of the above target user and the corresponding security authentication levels of the trusted users can perform data cleaning on the historical data of the above target user offline, or a product entry can be developed for users to set by themselves. For example: for the fund types of third-party payment platforms, it can be calculated offline based on data such as consumption, acquiring, housing, and / or bills that users A and B are in a father-son relationship, or an entry can be opened for users to set by themselves.
[0079] Figure 5 It is a schematic diagram of another embodiment of the business processing method in this specification. As Figure 5 shown, the above business processing method may include:
[0080] Step 501, receive a business request sent by a target user.
[0081] Step 502, determine the geographical location where the target user is currently located according to the above business request.
[0082] Judge whether the target user has performed security authentication at the current geographical location within a first predetermined time period before the current moment. If so, process the above business request; if the target user has not performed security authentication at the current geographical location within the first predetermined time period before the current moment, then execute step 503.
[0083] Among them, the above first predetermined time period can be set by itself according to system performance and / or implementation requirements, etc. in specific implementation. This embodiment does not limit the length of the above first predetermined time period. For example, the above first predetermined time period can be 5 days.
[0084] Step 503, according to the type of the above business request, obtain the trusted users of the above target user, and obtain the security authentication records of the trusted users.
[0085] Among them, the above first security authentication record includes the security authentication record of the target user at the current geographical location within the first predetermined time period before the current moment. That is to say, if the target user has not performed security authentication at the current geographical location within the first predetermined time period before the current moment, then it is necessary to obtain the trusted users of the above target user and obtain the security authentication records of the trusted users.
[0086] Step 504, from the security authentication records of the trusted users, obtain the geographical location, authentication time, and security authentication level at which the trusted users perform security authentication.
[0087] Step 505, if the geographical location where the above-mentioned trusted user conducts security authentication and the geographical location where the target user is currently located belong to the same region, and the distance is within a predetermined range, and the time difference between the authentication time when the above-mentioned trusted user conducts security authentication and the time when the above-mentioned target user sends a service request is less than or equal to a second predetermined duration, and the security authentication level of the above-mentioned trusted user is not lower than the security authentication level required for the above-mentioned service request, then the target user is exempted from the security authentication for the above-mentioned service request; or, the security authentication level for the target user to send a service request is reduced.
[0088] Step 506, process the above-mentioned service request.
[0089] Figure 6 The figure is a schematic structural diagram of an embodiment of the service processing device in this specification. The service processing device in this embodiment can be implemented as an electronic device or a part of an electronic device to implement the service processing method provided in the embodiments of this specification. As Figure 6 shown, the above-mentioned service processing device may include: a receiving module 61, an obtaining module 62, a judging module 63, and a processing module 64;
[0090] Among them, the receiving module 61 is used to receive a service request sent by a target user.
[0091] The obtaining module 62 is used to determine the geographical location where the above-mentioned target user is currently located according to the service request received by the receiving module 61; specifically, the obtaining module 62 may determine the geographical location where the target user is currently located according to the source address carried in the above-mentioned service request; or the obtaining module 62 may determine the geographical location where the target user is currently located according to the base station used by the target user to send the above-mentioned service request. This embodiment does not limit the manner in which the obtaining module 62 determines the geographical location where the target user is currently located.
[0092] In specific implementation, the geographical location where the target user is currently located may be a geographical location different from the target user's usual residence, that is to say, the target user makes the above-mentioned service request in a different place.
[0093] Among them, the above-mentioned first predetermined duration may be set by itself according to system performance and / or implementation requirements, etc. in specific implementation. This embodiment does not limit the length of the above-mentioned first predetermined duration. For example, the above-mentioned first predetermined duration may be 5 days.
[0094] The judging module 63 is used to judge whether the above-mentioned target user has conducted security authentication at the current geographical location within the first predetermined duration before the current moment;
[0095] The obtaining module 62 is further configured to, when the target user has not performed a security authentication at the current geographical location within a first predetermined duration before the current moment, obtain the trusted users of the target user according to the type of the service request, and obtain the security authentication records of the trusted users.
[0096] The processing module 64 is configured to process the service request according to the security authentication records of the trusted users.
[0097] Wherein, the security level is used to indicate the security degree of the target user for performing the service request.
[0098] In the above service processing device, after the receiving module 61 receives a service request sent by a target user, the obtaining module 62 determines the current geographical location of the target user according to the service request, and then the judging module 63 judges whether the target user has performed a security authentication at the current geographical location within a first predetermined duration before the current moment; if the target user has not performed a security authentication at the current geographical location within a first predetermined duration before the current moment, the obtaining module 62 obtains the trusted users of the target user according to the type of the service request, and obtains the security authentication records of the trusted users; finally, the processing module 64 processes the service request according to the security authentication records of the trusted users, so that the service request of the target user can be processed according to the security authentication records of the trusted users of the target user, the operation disturbance rate of the security authentication to the service request of the target user is reduced, and the usage experience of the target user is improved.
[0099] Figure 7 This is a schematic structural diagram of another embodiment of the service processing device in this specification. Compared with Figure 6 the service processing device shown, the difference is that in the service processing device provided in this embodiment, the processing module 64 may include: an information obtaining sub-module 641, a security authentication sub-module 642, and a service processing sub-module 643.
[0100] The information obtaining sub-module 641 is configured to obtain the geographical location, authentication time, and security authentication level of the trusted user for performing security authentication from the security authentication records of the trusted user.
[0101] In this embodiment, when a user is in a different place and makes a service request such as an account operation or a payment operation, the service processing device will detect the risk of the user's operation in a different place, and thus will perform a relatively strict security authentication on the user. After the user passes the security authentication, the service processing device will save the user's security authentication record. The above security authentication record may include the following fields: user identifier (Identifier; hereinafter referred to as: ID), geographical location where the security authentication is performed, authentication time, and security authentication level. Specifically, an example of the security authentication record can be shown in Table 1.
[0102] The above security authentication level can be the level of the security authentication product. The above security authentication products can include dozens of types such as passwords, SMS verification codes, face recognition, and answers to reserved questions for authentication. The levels of the above security authentication products can be shown in Table 2. The higher the security authentication level, the higher the disturbance rate of the security authentication and the lower the risk after successful authentication.
[0103] The security authentication sub-module 642 is configured to perform security authentication on the target user when the geographical location where the trusted user performs security authentication belongs to the same region as the geographical location where the target user is currently located, and the distance is within a predetermined range, and the difference between the authentication time when the trusted user performs security authentication and the time when the target user sends the service request is less than or equal to a second predetermined duration, and the security authentication level of the trusted user is not lower than the security authentication level required for the service request.
[0104] Specifically, the geographical location where the trusted user performs security authentication belonging to the same region as the geographical location where the target user is currently located can be that the geographical location where the trusted user performs security authentication and the geographical location where the target user is currently located are in the same administrative region. For example: the same county or the same city, etc.; the above-mentioned predetermined range can be set according to system performance and / or implementation requirements, etc. in specific implementation. This embodiment does not limit the size of the above-mentioned predetermined range. For example, the above-mentioned predetermined range can be 10 kilometers;
[0105] The above-mentioned second predetermined duration can be set according to system performance and / or implementation requirements, etc. in specific implementation. This embodiment does not limit the length of the above-mentioned second predetermined duration. For example, the above-mentioned second predetermined duration can be 1 day;
[0106] As described above, the above security authentication level is the level of the security authentication product. Different service requests require different security authentication products for security authentication. Therefore, the security authentication levels required for different service requests are different. For example, a non-fund type service request may only require password or SMS verification code for security authentication. As shown in Table 2, the security authentication level required for a non-fund type service request is 3. For a fund type service request, face recognition may be required for security authentication. As shown in Table 2, the security authentication level required for a fund type service request is 5.
[0107] In this embodiment, the security authentication sub-module 642 is specifically configured to exempt the above target user from performing the security authentication for the above service request; or, reduce the security authentication level of the target user for the above service request.
[0108] In specific implementation, assume that the geographical location where the above trusted user performs security authentication is in the same city as the geographical location where the target user is currently located, and the distance is within 10 kilometers, and the time difference between the authentication time when the above trusted user performs security authentication and the time when the above target user sends a service request is less than or equal to 1 day, and the security authentication level of the above trusted user is 5, and the security authentication level required for the above service request is 3. In this way, the security authentication sub-module 642 can determine that the security level of the above target user for the above service request is not lower than the security authentication level required for the above service request, and consider that the credibility of the target user appearing at the current geographical location is relatively high.
[0109] Furthermore, the security authentication sub-module 642 can exempt the target user from performing the security authentication for the above service request; or, reduce the security authentication level of the above target user for the service request. For example, the above target user originally needed face recognition for the service request, but now only needs a password; thus, the operation disturbance rate of the security authentication for the target user's service request can be reduced, and the user experience of the target user can be improved.
[0110] The service processing sub-module 643 is configured to process the above service request after the above target user passes the security authentication.
[0111] In this embodiment, the acquisition module 62 is specifically configured to determine the security authentication level required for the above service request according to the type of the above service request; and acquire a trusted user matching the security authentication level required for the above service request from the trusted users of the above target user.
[0112] Specifically, different service requests require different security authentication products for security authentication. Therefore, the required security authentication levels for different service requests are different. For example, non-fund service requests may only require password or SMS verification code for security authentication. As shown in Table 2, the required security authentication level for non-fund service requests is 3. For fund service requests, face recognition may be required for security authentication. As shown in Table 2, the required security authentication level for fund service requests is 5.
[0113] The service processing device stores a list of trusted users for the target user. In the list of trusted users, the identifiers of the trusted users and the corresponding security authentication levels of the trusted users are stored, as shown in Table 3.
[0114] Therefore, after the obtaining module 62 determines the security authentication level required for the above service request, it can obtain the trusted user that matches the security authentication level required for the above service request from the list of trusted users of the target user.
[0115] In this embodiment, the obtaining module 62 is further configured to obtain the historical data of the above target user; and perform data cleaning on the above historical data, calculate using the cleaned data, and obtain the trusted users of the above target user and the corresponding security authentication levels of the trusted users; or, obtain the trusted users set by the above target user and the corresponding security authentication levels of the trusted users.
[0116] Specifically, referring to Table 3, the corresponding security authentication levels of different trusted relatives and friends are different. For example, for a trusted user who has a close relationship with the target user, the security authentication level can be 3. When the target user makes a non-fund service request, the security level of the target user for the service request can be determined according to the security authentication record of the trusted user with a close relationship; for a trusted user who has a kinship with the target user, such as: the target user's parents, spouse, children or siblings, etc., the security level can be 5. When the target user makes a fund service request, the security level of the target user for the service request can be determined according to the security authentication record of the trusted user with a kinship with the target user.
[0117] In this embodiment, the trust relationship between the target user and the trusted user is one-way and non-transferable.
[0118] In specific implementation, the obtaining module 62 can obtain the trusted users of the target user and the corresponding security authentication levels of the trusted users, and can perform data cleaning on the historical data of the target user offline, or can develop a product entrance for the user to set by themselves. For example, for the fund types of a third-party payment platform, it can be calculated offline based on data such as consumption, acquiring, housing, and / or bills that users A and B are in a father-son relationship, or an entrance can be opened for the user to set by themselves.
[0119] Furthermore, the above business processing device may further include: a security authentication module 64;
[0120] The security authentication module 64 is used to perform security authentication on the trusted user when the trusted user makes a service request before the obtaining module 62 obtains the security authentication record of the trusted user; and save the security authentication record of the trusted user, where the security authentication record of the trusted user includes the geographical location, authentication time, and security authentication level when the trusted user performs security authentication.
[0121] Figure 8 It is a schematic structural diagram of an embodiment of an electronic device in this specification. As Figure 8 shown, the above electronic device may include at least one processor; and at least one memory communicatively connected to the processor, where: the memory stores program instructions executable by the processor, and the processor can execute the service processing method provided by the embodiment of this specification by invoking the program instructions.
[0122] Among them, the above electronic device can be a server, for example: a cloud server. This embodiment does not limit the form of the above electronic device.
[0123] Figure 8 It shows a block diagram of an exemplary electronic device suitable for implementing one or more embodiments of this specification. Figure 8 The shown electronic device is only an example and should not bring any limitation to the functions and usage scope of one or more embodiments of this specification.
[0124] As Figure 8 shown, the electronic device is presented in the form of a general-purpose computing device. The components of the electronic device may include, but are not limited to: one or more processors 410, a memory 430, and a communication bus 440 connecting different system components (including the memory 430 and the processing unit 410).
[0125] The communication bus 440 represents one or more of several types of bus architectures, including a memory bus or memory controller, a peripheral bus, an Accelerated Graphics Port, a processor, or a local bus using any of the various bus architectures. By way of example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnection (PCI) bus.
[0126] An electronic device typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the electronic device, including volatile and nonvolatile media, removable and non-removable media.
[0127] The memory 430 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) and / or cache memory. The electronic device may further include other removable / non-removable, volatile / nonvolatile computer system storage media. Although Figure 8 not shown in the figure, a disk drive for reading and writing on a removable nonvolatile disk (such as a "floppy disk"), and an optical disk drive for reading and writing on a removable nonvolatile optical disk (such as a Compact Disc Read Only Memory (CD-ROM), a Digital Video Disc Read Only Memory (DVD-ROM), or other optical media) may be provided. In these cases, each drive may be connected to the communication bus 440 through one or more data media interfaces. The memory 430 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the various embodiments of the present specification.
[0128] A program / util utility having a set (at least one) of program modules can be stored in the memory 430. Such program modules include—but are not limited to—an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment. The program modules generally execute the functions and / or methods in the embodiments described in this specification.
[0129] The electronic device can also communicate with one or more external devices (such as a keyboard, a pointing device, a display, etc.), can also communicate with one or more devices that enable a user to interact with the electronic device, and / or can communicate with any device that enables the electronic device to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through the communication interface 420. And, the electronic device can also communicate with one or more networks (such as a Local Area Network (LAN), a Wide Area Network (WAN), and / or a public network, such as the Internet) through a network adapter ( Figure 8 not shown in the figure). The above network adapter can communicate with other modules of the electronic device through the communication bus 440. It should be understood that although Figure 8 not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, Redundant Arrays of Independent Drives (RAID) systems, tape drives, and data backup storage systems, etc.
[0130] The processor 410 executes various functional applications and data processing by running the programs stored in the memory 430, such as implementing the service processing method provided by one or more embodiments of this specification.
[0131] The embodiments of this specification also provide a non-transitory computer-readable storage medium. The above non-transitory computer-readable storage medium stores computer instructions, and the above computer instructions cause the computer to execute the service processing method provided by the embodiments of this specification.
[0132] The above non-transitory computer-readable storage medium may employ any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), or a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In this document, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device.
[0133] A computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take many forms, including - but not limited to - an electromagnetic signal, an optical signal, or any suitable combination of the foregoing. The computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.
[0134] The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including - but not limited to - wireless, wire, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0135] Computer program code for performing the operations of this specification can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a Local Area Network (LAN) or a Wide Area Network (WAN), or can be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0136] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0137] In addition, the terms "first" and "second" are used only for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" can explicitly or implicitly include at least one of the features. In the description of one or more embodiments of this specification, the meaning of "a plurality" is at least two, such as two, three, etc., unless otherwise specifically defined.
[0138] Any process or method description shown in a flowchart or described in other ways herein can be understood to represent a module, segment, or portion of code including one or more executable instructions for implementing a customized logical function or process. And the scope of the preferred embodiments of one or more embodiments of this specification includes additional implementations, where the functions can be executed in a substantially simultaneous manner or in a reverse order according to the functions involved, rather than in the order shown or discussed, which should be understood by those skilled in the art of one or more embodiments of this specification.
[0139] Depending on the context, as used herein, the word "if" can be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detected (stated condition or event)" can be interpreted as "when determined" or "in response to determining" or "when detected (stated condition or event)" or "in response to detecting (stated condition or event)".
[0140] It should be noted that the terminals involved in one or more embodiments of this specification may include, but are not limited to, personal computers (Personal Computer; hereinafter referred to as: PC), personal digital assistants (Personal Digital Assistant; hereinafter referred to as: PDA), wireless handheld devices, tablet computers, mobile phones, MP3 players, MP4 players, etc.
[0141] In several embodiments provided in this specification, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0142] In addition, in each embodiment of this specification, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of a combination of hardware and software functional units.
[0143] The integrated unit implemented in the form of software functional units can be stored in a computer-readable storage medium. The above-mentioned software functional units stored in a storage medium include several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute some steps of the methods described in the embodiments of this specification. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs.
[0144] The above are only the preferred embodiments of this specification and are not intended to limit this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this specification shall be included within the scope of protection of this specification.
Claims
1. A service processing method, characterized in that, Including: Receiving a service request sent by a target user; Determining the geographical location where the target user is currently located according to the service request; wherein, the geographical location where the target user is currently located includes a geographical location different from the permanent residence of the target user; Judging whether the target user has performed a security authentication at the current geographical location within a first predetermined time period before the current moment; If the target user has not performed a security authentication at the current geographical location within a first predetermined time period before the current moment, then according to the type of the service request, obtaining a trusted user of the target user and obtaining a security authentication record of the trusted user; Processing the service request according to the security authentication record of the trusted user; Wherein, the processing the service request according to the security authentication record of the trusted user includes: Obtaining, from the security authentication record of the trusted user, the geographical location, authentication time and security authentication level at which the trusted user performs the security authentication; If the geographical location at which the trusted user performs the security authentication belongs to the same region as the geographical location where the target user is currently located, and the distance is within a predetermined range, and the time difference between the authentication time at which the trusted user performs the security authentication and the time when the target user sends the service request is less than or equal to a second predetermined time period, and the security authentication level of the trusted user is not lower than the security authentication level required by the service request, then performing a security authentication on the target user; After the target user passes the security authentication, processing the service request.
2. The method according to claim 1, wherein The performing a security authentication on the target user includes: Exempting the target user from performing the security authentication for the service request; or, Lowering the security authentication level for the target user to perform the service request.
3. The method according to claim 1, wherein The obtaining a trusted user of the target user according to the type of the service request includes: Determining the security authentication level required by the service request according to the type of the service request; Obtaining a trusted user matching the security authentication level required by the service request from the trusted users of the target user.
4. The method according to claim 1 or 3, characterized in that Before the obtaining a trusted user of the target user according to the type of the service request, it further includes: Obtaining historical data of the target user; and performing data cleaning on the historical data, calculating using the cleaned data, and obtaining a trusted user of the target user and the security authentication level corresponding to the trusted user; Or, Obtaining the trusted users set by the target user and the security authentication levels corresponding to the trusted users.
5. The method according to any one of claims 1-3, characterized in that Before the obtaining the security authentication record of the trusted user, it further includes: When the trusted user makes a service request, performing a security authentication on the trusted user; Saving the security authentication record of the trusted user, where the security authentication record of the trusted user includes the geographical location, authentication time and security authentication level at which the trusted user performs the security authentication.
6. The method according to claim 1, wherein After the judging whether the target user has performed a security authentication at the current geographical location within a first predetermined time period before the current moment, it further includes: If the target user has performed a security authentication at the geographical location where the target user is currently located within a first predetermined duration before the current moment, the service request is processed.
7. The method according to claim 6, wherein, The processing of the service request includes: Obtaining the security authentication record of the target user at the geographical location where the target user is currently located within a first predetermined duration before the current moment, and obtaining the security authentication level in the security authentication record. If the security authentication level is not lower than the security authentication level required for the service request, the service request is directly processed; if the security authentication level in the security authentication record is lower than the security authentication level required for the service request, the target user is authenticated according to the security authentication level required for the service request, and after the target user passes the security authentication, the service request is processed.
8. A service processing device, characterized in that, including: A receiving module, configured to receive a service request sent by a target user; An obtaining module, configured to determine the geographical location where the target user is currently located according to the service request received by the receiving module; wherein, the geographical location where the target user is currently located includes a geographical location different from the permanent residence of the target user; A judging module, configured to judge whether the target user has performed a security authentication at the geographical location where the target user is currently located within a first predetermined duration before the current moment; The obtaining module is further configured to, when the target user has not performed a security authentication at the geographical location where the target user is currently located within a first predetermined duration before the current moment, obtain a trusted user of the target user according to the type of the service request, and obtain the security authentication record of the trusted user; A processing module, configured to process the service request according to the security authentication record of the trusted user; wherein, the processing module includes: An information obtaining sub-module, configured to obtain the geographical location, authentication time, and security authentication level at which the trusted user performs the security authentication from the security authentication record of the trusted user; A security authentication sub-module, configured to authenticate the target user when the geographical location at which the trusted user performs the security authentication and the geographical location where the target user is currently located belong to the same region, and the distance is within a predetermined range, and the time difference between the authentication time at which the trusted user performs the security authentication and the time when the target user sends the service request is less than or equal to a second predetermined duration, and the security authentication level of the trusted user is not lower than the security authentication level required for the service request; A service processing sub-module, configured to process the service request after the target user passes the security authentication.
9. The device according to claim 8, wherein The security authentication sub-module is specifically configured to exempt the target user from performing the security authentication for the service request; or, reduce the security authentication level for the target user to perform the service request.
10. The device according to claim 8, wherein The obtaining module is specifically configured to determine the security authentication level required for the service request according to the type of the service request; and obtain a trusted user matching the security authentication level required for the service request from the trusted users of the target user.
11. The apparatus according to claim 8 or 10, wherein The obtaining module is further configured to obtain historical data of the target user; and perform data cleaning on the historical data, calculate using the cleaned data, and obtain the trusted users of the target user and the corresponding security authentication levels of the trusted users; Alternatively, obtain the trusted users set by the target user and the corresponding security authentication levels of the trusted users.
12. The device according to any one of claims 8-10, characterized in that, It further includes: A security authentication module, configured to perform security authentication on the trusted user when the trusted user makes a service request before the obtaining module obtains the security authentication record of the trusted user; And save the security authentication record of the trusted user, where the security authentication record of the trusted user includes the geographical location, authentication time, and security authentication level at which the trusted user performs security authentication.
13. The apparatus according to claim 8, wherein The processing module is further configured to process the service request when the target user has performed security authentication at the current geographical location within a first predetermined period before the current moment.
14. The apparatus according to claim 13, wherein The processing module is specifically configured to obtain the security authentication record of the target user at the current geographical location within a first predetermined period before the current moment, and obtain the security authentication level in the security authentication record. If the security authentication level is not lower than the security authentication level required for the service request, directly process the service request; if the security authentication level in the security authentication record is lower than the security authentication level required for the service request, perform security authentication on the target user according to the security authentication level required for the service request, and after the target user passes the security authentication, process the service request.
15. An electronic device, characterized in that, It includes: At least one processor; And At least one memory communicatively connected to the processor, wherein: The memory stores program instructions executable by the processor, and the processor can execute the method according to any one of claims 1 to 7 by invoking the program instructions.
16. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions cause the computer to execute the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
User safety control method and device based on geographical position abnormality of mobile terminal
CN102045634A
Authentication method and device based on trust relationship
CN106941475A