Operational risk verification method, device, equipment and storage medium

By dynamically configuring the operational risk verification of the bank's integrated production and operation and maintenance platform and utilizing target operation data and identification information, the problems of heavy development workload and poor flexibility in existing technologies are solved, and efficient risk verification and maintenance are achieved.

CN115131137BActive Publication Date: 2025-09-23AGRICULTURAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210876321.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-25
Publication Date
2025-09-23
Estimated Expiration
2042-07-25

Smart Images

  • Figure CN115131137B_ABST
    Figure CN115131137B_ABST
Patent Text Reader

Abstract

The present invention discloses an operation risk verification method, apparatus, device, and storage medium. The method comprises the following steps: obtaining target operation data and target operation identification information corresponding to a target operation to be verified; determining target risk verification configuration information based on the correspondence between risk verification configuration information and operation identification information and the target operation identification information, wherein the target risk verification configuration information includes at least one target risk indicator configuration information corresponding to a target risk indicator, and the target risk indicator configuration information includes a verification logic expression and a risk value corresponding to the verification logic expression; matching the target operation data with each verification logic expression, and determining the target risk degree corresponding to the target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression; and determining a risk verification result based on the target risk degree corresponding to the target risk indicator, thereby realizing dynamic configuration of risk verification and improving the flexibility of risk verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to an operation risk verification method, device, equipment and storage medium. Background Art

[0002] As operational requirements diversify, the number of application operations supported by integrated banking production and operations platforms is increasing. The operation platform module of this platform provides a range of operational functions, including data operations, application operations, and delivery pipelines. For example, operations can include database queries, modifications, table structure changes, application startup and shutdown, verification, phasing in and out, and command execution.

[0003] To ensure operational security, risk verification is often required for user operations. Currently, this is typically accomplished by writing separate risk verification code for each operation and executing it. However, due to the large number of operations requiring verification, writing fixed risk verification code for each operation significantly increases development workload. Modifying the verification logic also requires revising the existing verification code, resulting in limited flexibility and reduced platform verification maintenance efficiency. Summary of the Invention

[0004] The present invention provides an operational risk verification method, apparatus, device and storage medium to achieve dynamic configuration of risk verification, improve the flexibility of risk verification, thereby reducing development workload and improving verification and maintenance efficiency.

[0005] According to one aspect of the present invention, there is provided an operational risk verification method, comprising:

[0006] Obtain target operation data and target operation identification information corresponding to the target operation to be verified;

[0007] Determining target risk verification configuration information corresponding to the target operation based on a correspondence between pre-configured risk verification configuration information and operation identification information and the target operation identification information, wherein the target risk verification configuration information includes at least one target risk indicator configuration information corresponding to a target risk indicator, and the target risk indicator configuration information includes a verification logic expression and a risk value corresponding to the verification logic expression;

[0008] Matching the target operation data with each of the verification logic expressions, and determining the target risk degree corresponding to the target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression;

[0009] Based on the target risk level corresponding to the target risk indicator, a risk verification result corresponding to the target operation is determined.

[0010] According to another aspect of the present invention, there is provided an operation risk verification device, comprising:

[0011] A target operation data acquisition module is used to obtain target operation data and target operation identification information corresponding to the target operation to be verified;

[0012] a verification configuration information determination module, configured to determine target risk verification configuration information corresponding to the target operation based on a correspondence between pre-configured risk verification configuration information and operation identification information and the target operation identification information, wherein the target risk verification configuration information includes at least one target risk indicator configuration information corresponding to a target risk indicator, and the target risk indicator configuration information includes a verification logic expression and a risk value corresponding to the verification logic expression;

[0013] a target risk level determination module, configured to match the target operation data with each of the verification logic expressions, and determine the target risk level corresponding to the target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression;

[0014] The risk verification result determination module is used to determine the risk verification result corresponding to the target operation based on the target risk level corresponding to the target risk indicator.

[0015] According to another aspect of the present invention, an electronic device is provided, comprising:

[0016] at least one processor; and a memory communicatively coupled to the at least one processor;

[0017] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the operational risk verification method described in any embodiment of the present invention.

[0018] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the operation risk verification method described in any embodiment of the present invention when executed.

[0019] The technical solution of the embodiment of the present invention obtains target operation data and target operation identification information corresponding to the target operation to be verified, and determines target risk verification configuration information corresponding to the target operation based on the correspondence between pre-configured risk verification configuration information and the operation identification information and the target operation identification information. The target risk verification configuration information includes at least one target risk indicator configuration information corresponding to the target risk indicator, and the target risk indicator configuration information includes a verification logic expression and a risk value corresponding to the verification logic expression. The target operation data is matched with each verification logic expression in the target risk verification configuration information, and the target risk level corresponding to the target risk indicator is determined based on the target risk value corresponding to the successfully matched target verification logic expression. The risk verification result corresponding to the target operation is determined based on the target risk level corresponding to the target risk indicator. Therefore, only the risk verification configuration information corresponding to each operation to be verified needs to be configured, and the risk verification of the operation is performed based on the configured risk verification configuration information. This greatly reduces the development workload. When the verification logic needs to be modified, only the risk verification configuration information needs to be modified, without modifying the logic code. This achieves dynamic configuration of risk verification, improves the flexibility of risk verification, and thereby improves verification maintenance efficiency.

[0020] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0022] Figure 1 This is a flow chart of an operational risk verification method provided by Example 1 of the present invention;

[0023] Figure 2 This is a flow chart of an operational risk verification method provided by Embodiment 2 of the present invention;

[0024] Figure 3 This is a verification flow chart based on indicator verification condition generation involved in the second embodiment of the present invention;

[0025] Figure 4 This is a schematic diagram of the structure of an operation risk verification device provided by the third embodiment of the present invention;

[0026] Figure 5It is a structural diagram of an electronic device for implementing the operation risk verification method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0027] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0028] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0029] Example 1

[0030] Figure 1 A flowchart of an operational risk verification method is provided for the first embodiment of the present invention. This embodiment is applicable to the case of performing risk verification on operations performed by users, and in particular, to the case of performing risk verification on operations in a bank's integrated production and operation platform. The method can be performed by an operational risk verification device, which can be implemented in the form of hardware and / or software, and can be integrated into an electronic device. Figure 1 As shown, the method includes:

[0031] S110: Obtain target operation data and target operation identification information corresponding to the target operation to be verified.

[0032] Here, an operation can refer to any operation that can be performed in the operation and maintenance platform. For example, an operation can be, but is not limited to, a database query operation. A target operation can refer to a currently executed operation that requires risk verification. The target operation data can include the operation parameters involved in the target operation and the corresponding operation parameter values. For example, the operation parameters can be the basic parameters required to calculate the risk indicators corresponding to the operation, and the corresponding operation parameter values ​​can refer to the specific values ​​of the basic parameters. The target operation can involve multiple operation parameters. The target operation identification information can be information used to uniquely identify the target operation to distinguish different operations.

[0033] Specifically, it is detected whether the operation currently being executed in the platform is a preset verification operation, that is, a pre-set operation that needs to be verified. If so, the currently executed operation can be used as the target operation for risk verification, and the target operation data and target operation identification information corresponding to the target operation can be obtained, so that risk verification can be performed only on the operations that need to be verified in the platform.

[0034] S120. Based on the correspondence between the pre-configured risk verification configuration information and the operation identification information and the target operation identification information, determine the target risk verification configuration information corresponding to the target operation, wherein the target risk verification configuration information includes at least one target risk indicator configuration information corresponding to the target risk indicator, and the target risk indicator configuration information includes a verification logic expression and a risk value corresponding to the verification logic expression.

[0035] In particular, corresponding risk verification configuration information can be pre-configured for each operation to be verified. The risk verification configuration information corresponding to each operation can contain the same configuration items. For example, the target risk verification configuration information corresponding to the target operation may include at least one target risk indicator configuration information corresponding to the target risk indicator. In particular, the target risk indicator can be an indicator used to measure the risk level of the target operation. The number of target risk indicators can be one or more. Each target risk indicator can be evaluated from one or more risk perspectives, and each risk perspective can correspond to a target risk indicator configuration information. Each target risk indicator configuration information may include a verification logic expression and a risk value corresponding to the verification logic expression. In particular, the verification logic expression is an expression constructed by one or more operation parameters, which is used to verify whether the target operation has the operational risk under the risk perspective. The risk value may refer to the size of the operational risk after satisfying the verification logic expression.

[0036] Specifically, corresponding risk verification configuration information can be pre-configured for each operation to be verified. Based on the operation identification information corresponding to each operation to be verified, a correspondence between the risk verification configuration information and the operation identification information can be established. Thus, when risk verification of a target operation is required, the target risk verification configuration information corresponding to the target operation identification information can be determined based on this correspondence, thereby obtaining the target risk verification configuration information corresponding to the target operation. For example, the target risk verification configuration information can include two target risk indicator configuration information corresponding to one target risk indicator.

[0037] S130: Match the target operation data with each verification logic expression, and determine the target risk degree corresponding to the target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression.

[0038] Specifically, for each target risk indicator configuration information corresponding to the target risk indicator, the target operation data can be matched with the verification logic expression in the target risk indicator configuration information. If the match is successful, that is, the verification logic expression is satisfied, it indicates that the target operation has the risk value corresponding to the verification logic expression. In this case, this risk value can be used as the target risk value. If the match fails, that is, the verification logic expression is not satisfied, it indicates that the target operation does not have the risk value corresponding to the verification logic expression. By fusing all target risk values ​​corresponding to the target verification logic expression, the target risk level corresponding to the target risk indicator of the target operation can be obtained.

[0039] S140. Determine a risk verification result corresponding to the target operation based on the target risk level corresponding to the target risk indicator.

[0040] Specifically, if there is only one target risk indicator, the target risk level corresponding to the target risk indicator is determined as the risk verification result corresponding to the target operation. If there are at least two target risk indicators, the target risk levels corresponding to the target risk indicators are fused to determine the risk verification result corresponding to the target operation. For example, the target risk levels corresponding to at least two target risk indicators can be listed and combined, and the obtained combination result can be used as the risk verification result corresponding to the target operation so that the risk level of each target risk indicator can be intuitively viewed. Alternatively, the target risk levels corresponding to at least two target risk indicators can be weighted and summed, and the total risk level obtained can be used as the risk verification result corresponding to the target operation. After determining the risk verification result corresponding to the target operation, information corresponding to the risk verification result can be recorded based on the determined risk verification result corresponding to the target operation. For example, Table 1 provides an example of a risk verification result record table.

[0041] Table 1 A risk verification result record information

[0042]

[0043] The operation number can refer to target operation identification information, which is used to uniquely identify the target operation to distinguish different operations. For example, the operation number can be, but is not limited to, DOP_dataChangeApply. The target operation given in Table 1 corresponds to only one target risk indicator, which corresponds to a target risk level of 20.

[0044] Specifically, after determining the risk verification results for the target operation based on the target risk indicator's corresponding target risk level, you can view the risk verification results on the visualization page. The table displays key information, including the operation number, module, verification time, verification result, and verification details.

[0045] The technical solution of this embodiment obtains target operation data and target operation identification information corresponding to the target operation to be verified, and determines the target risk verification configuration information corresponding to the target operation based on the correspondence between pre-configured risk verification configuration information and the operation identification information and the target operation identification information. The target risk verification configuration information includes at least one target risk indicator configuration information corresponding to the target risk indicator, and the target risk indicator configuration information includes a verification logic expression and a risk value corresponding to the verification logic expression. The target operation data is matched with each verification logic expression in the target risk verification configuration information, and the target risk level corresponding to the target risk indicator is determined based on the target risk value corresponding to the successfully matched target verification logic expression. The risk verification result corresponding to the target operation is determined based on the target risk level corresponding to the target risk indicator. Therefore, it is only necessary to configure the risk verification configuration information corresponding to each operation to be verified, and perform risk verification of the operation based on the configured risk verification configuration information. This greatly reduces the development workload. When the verification logic needs to be modified, only the risk verification configuration information needs to be modified, without modifying the logic code. This achieves dynamic configuration of risk verification, improves the flexibility of risk verification, and further improves verification maintenance efficiency.

[0046] Based on the above technical solution, the "verification logic expression" in S120 may include: at least one parameter verification condition or at least two parameter verification conditions connected by logical operators; wherein, the parameter verification conditions may include: operation parameters, parameter values ​​and relational operators used to connect operation parameters and parameter values; logical operators may include but are not limited to: at least one of: "and", "or" and "not".

[0047] Operation parameters refer to the basic parameters required to calculate the risk indicator corresponding to the operation and can be set on the left side of the relational operator. Operation parameter types can include, but are not limited to, Boolean, Int, Float, and String. Parameter values ​​can refer to the specific numerical value of the operation parameter or another operation parameter and can be set on the right side of the relational operator. For example, Table 2 provides an example of parameter verification condition configuration information.

[0048] Table 2 Configuration information of parameter verification conditions

[0049]

[0050] The Boolean type in the operation parameter type has only two parameter forms, namely True (true) or False (false) in the parameter value type. The Int / Float type parameter form in the operation parameter type can be any numerical value or a parameter item that is not an operation parameter. The String type parameter form in the operation parameter type can be a character set by self-entry or a parameter item that is not an operation parameter. Contains can mean "contains". Start with can mean "start with". End with can mean "end with". Length of can mean a length limit.

[0051] On the basis of the above technical solution, "determining the target risk degree corresponding to the target risk indicator based on the target risk value corresponding to the successfully matched target verification logical expression" in S130 may include: if there is only one successfully matched target verification logical expression, then the target risk value corresponding to the target verification logical expression is determined as the target risk degree corresponding to the target risk indicator; if there are at least two successfully matched target verification logical expressions, then the target risk values ​​corresponding to each target verification logical expression are added, and the obtained addition result is determined as the target risk degree corresponding to the target risk indicator.

[0052] Specifically, for each target risk indicator configuration information corresponding to the target risk indicator, the target operation data can be matched with the verification logic expression in the target risk indicator configuration information. If there is only one successfully matched target verification logic expression, it is only necessary to determine the target risk value corresponding to the successfully matched target verification logic expression, and determine the corresponding target risk value as the target risk degree of the target risk indicator; if there are at least two successfully matched target verification logic expressions, the target risk values ​​corresponding to each target verification logic expression are added, and the obtained addition result is determined as the target risk degree corresponding to the target risk indicator, so that the configured multiple verification logic expressions can be used to more comprehensively and accurately determine the target risk degree corresponding to the target risk indicator, further improving the accuracy of risk verification.

[0053] On the basis of the above technical solution, before S110 "obtaining the target operation data and target operation identification information corresponding to the target operation to be verified", it can also include: configuring the verification logic expression corresponding to each operation to be verified and the risk value corresponding to the verification logic expression through the visual configuration page, and obtaining the risk verification configuration information corresponding to each operation; based on the operation identification information corresponding to each operation and the obtained risk verification configuration information, generating a correspondence between the risk verification configuration information and the operation identification information.

[0054] Among them, the visualization configuration page can support the configuration of the verification logic expression corresponding to each operation that needs to be verified and the risk value corresponding to the verification logic expression. For example, you can directly fill in or trigger the selection operation in the configuration item corresponding to the risk indicator on the visualization configuration page to obtain the risk indicator configured by the user for the current operation, and directly fill in or trigger the selection operation in the configuration item corresponding to the verification logic expression on the visualization configuration page to obtain the verification logic expression configured by the user for the current operation, and manually fill in or trigger the selection operation in the configuration item corresponding to the risk value to obtain the risk value configured by the user for the verification logic expression, so as to configure a risk indicator configuration information corresponding to the risk indicator. Similarly, the user can configure multiple risk indicator configuration information for the risk indicator based on business needs, and then obtain the risk verification configuration information corresponding to the operation based on all risk indicator configuration information corresponding to each risk indicator configured by the user.

[0055] Specifically, through the visual configuration page, the verification logic expression corresponding to each operation that needs to be verified and the risk value corresponding to the verification logic expression are configured to obtain the risk verification configuration information corresponding to each operation, and based on the operation identification information corresponding to each operation that needs to be verified, a correspondence between the risk verification configuration information and the operation identification information is established. Therefore, when it is necessary to perform risk verification on the target operation, the target risk verification configuration information corresponding to the target operation identification information can be directly determined based on the correspondence, thereby realizing the configurability of the risk verification logic and further improving the flexibility of information configuration.

[0056] Example 2

[0057] Figure 2 This is a flowchart of an operational risk verification method provided in the second embodiment of the present invention. Based on the above embodiment, when the number of target risk indicators is at least two, the target risk verification configuration information of this embodiment also includes: indicator verification sequence information corresponding to each target risk indicator, and on this basis, the step of "matching the target operation data with each verification logic expression, and determining the target risk degree corresponding to the target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression" is further optimized. The explanations of the terms that are the same as or corresponding to the above disclosed embodiments are not repeated here. Figure 2 As shown, the method includes:

[0058] S210: Obtain target operation data and target operation identification information corresponding to the target operation to be verified.

[0059] S220. Based on the correspondence between the pre-configured risk verification configuration information and the operation identification information and the target operation identification information, determine the target risk verification configuration information corresponding to the target operation, wherein, when the number of target risk indicators is at least two, the target risk verification configuration information also includes indicator verification sequence information corresponding to each target risk indicator.

[0060] The indicator verification sequence information may be based on the order of indicator verification, and may arrange the target risk indicators in sequence. For example, the higher the ranking of the target risk indicator, the earlier the target risk indicator is verified.

[0061] Specifically, corresponding risk verification configuration information can be pre-configured for each operation to be verified. Based on the operation identification information corresponding to each operation to be verified, a correspondence between the risk verification configuration information and the operation identification information can be established. Thus, when risk verification of a target operation is required, the target risk verification configuration information corresponding to the target operation identification information can be determined based on this correspondence, thereby obtaining the target risk verification configuration information corresponding to the target operation. When there are at least two target risk indicators, the target risk indicators can be verified sequentially based on the indicator verification sequence information corresponding to each target risk indicator in the target risk verification configuration information, thereby meeting the user's personalized needs.

[0062] S230: Use the first target risk indicator in the indicator verification sequence information as the current target risk indicator.

[0063] The first target risk indicator may refer to a target risk indicator having the highest priority in indicator verification sequence information, that is, a target risk indicator ranked highest.

[0064] Specifically, the first target risk indicator in the indicator verification sequence information is used as the current target risk indicator, so that the risk verification of the target operation is first performed based on the first target risk indicator.

[0065] S240: Match the target operation data with each verification logic expression corresponding to the current target risk indicator, and determine the current target risk level corresponding to the current target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression.

[0066] Specifically, for each current target risk indicator configuration information corresponding to the current target risk indicator, the target operation data can be matched with each verification logic expression corresponding to the current target risk indicator. If the match is successful, that is, the verification logic expression is satisfied, it indicates that the target operation has the risk value corresponding to the verification logic expression. At this time, this risk value can be used as the current target risk value. If the match fails, that is, the verification logic expression is not satisfied, it indicates that the target operation does not have the risk value corresponding to the verification logic expression. By fusing all current target risk values ​​corresponding to the target verification logic expression, the current target risk level corresponding to the current target risk indicator of the target operation can be obtained.

[0067] S250 , detecting whether the current target risk indicator is the last target risk indicator, if not, executing step S260 , if yes, executing step S270 .

[0068] Specifically, by detecting whether the current target risk indicator is the last target risk indicator in the indicator verification sequence information, it is determined whether all target risk indicators have been verified, that is, whether the cyclic verification operation is completed.

[0069] S260 : Determine the next target risk indicator based on the indicator verification sequence information and the current target risk indicator, and return the next target risk indicator as the current target risk indicator to execute step S240 .

[0070] The next target risk indicator may refer to the target risk indicator next to the current target risk indicator in the indicator verification sequence information. For example, when the current target risk indicator is the first target risk indicator, the next target risk indicator is the second target risk indicator.

[0071] Specifically, when the current target risk indicator is not the last target risk indicator, it indicates that the cyclic verification has not yet ended. At this time, the next target risk indicator of the current target risk indicator can be determined based on the position of the current target risk indicator in the indicator verification sequence information, and the next target risk indicator can be used as the current target risk indicator to return to execute the S240 operation, so that the target operation can be verified based on the next target risk indicator, so that the target risk degree corresponding to each target risk indicator can be determined in sequence.

[0072] S270. Determine a risk verification result corresponding to the target operation based on the target risk level corresponding to the target risk indicator.

[0073] Specifically, when the current target risk indicator is the last target risk indicator, it indicates that all target risk indicators have been verified. At this time, the risk verification result corresponding to the target operation can be determined based on the target risk levels corresponding to all target risk indicators.

[0074] The technical solution of this embodiment is that when the number of target risk indicators is at least two, the target risk verification configuration information also includes indicator verification sequence information corresponding to each target risk indicator, and the first target risk indicator in the indicator verification sequence information is used as the current target risk indicator. The target operation data is matched with each verification logic expression corresponding to the current target risk indicator, and the current target risk level corresponding to the current target risk indicator is determined based on the target risk value corresponding to the successfully matched target verification logic expression. Based on the indicator verification sequence information and the current target risk indicator, the next target risk indicator is determined, and the next target risk indicator is returned as the current target risk indicator to perform the operation of matching the target operation data with each verification logic expression corresponding to the current target risk indicator, until the target risk level corresponding to the last target risk indicator is determined, so that the pre-configured indicator verification sequence information can be used for sequential verification, which further improves the flexibility of the configuration and meets the personalized needs of users.

[0075] Based on the above technical solution, the "target risk verification configuration information" in S220 can also include: the indicator verification conditions corresponding to each target risk indicator, the first verification operation performed after the indicator verification conditions are met, and the second verification operation performed after the indicator verification conditions are not met.

[0076] The indicator verification condition may refer to a verification operation selection condition pre-set based on verification requirements. For example, the indicator verification condition may refer to a target risk level greater than or equal to a preset threshold, i.e., a threshold condition for the indicator. Each target operation may include one or more target risk indicators. Each target risk indicator may correspond to an indicator verification condition, a first verification operation, and a second verification operation.

[0077] Specifically, the target risk verification configuration information may further include indicator verification conditions corresponding to each target risk indicator, and verification operations may be performed based on the indicator verification conditions corresponding to each target risk indicator. If the indicator verification conditions are met, a first verification operation is performed; if the indicator verification conditions are not met, a second verification operation is performed.

[0078] On the basis of the above technical solution, "determining the next target risk indicator based on the indicator verification sequence information and the current target risk indicator" in S250 may include: detecting whether the current target risk level meets the current indicator verification condition corresponding to the current target risk indicator according to the current target risk level corresponding to the current target risk indicator; if the current indicator verification condition is met, determining the next target risk indicator based on the first verification operation performed after the current target risk indicator meets the current indicator verification condition; if the current indicator verification condition is not met, determining the next target risk indicator based on the second verification operation performed after the current target risk indicator does not meet the current indicator verification condition.

[0079] For example, Table 3 provides an example of verification condition configuration information. The current target risk indicator may refer to "Indicator 1," and based on the current target risk level corresponding to the current target risk indicator, it may be detected whether the current target risk level satisfies the current indicator verification condition corresponding to the current target risk indicator. For example, the current indicator verification condition corresponding to the current target risk indicator may refer to the "Indicator 1 Threshold Condition" in Table 3, such as if the risk level of Indicator 1 is greater than or equal to a preset threshold level. If the current indicator verification condition is not satisfied, the next target risk indicator is determined based on a second verification operation performed after the current target risk indicator does not satisfy the current indicator verification condition. For example, if the Indicator 1 Threshold Condition is not satisfied, the verification operation of "Indicator 2" is performed. At this time, Indicator 2 may be used as the next target risk indicator, and the process returns to step S240 to determine the risk level corresponding to Indicator 2. If the Indicator 1 Threshold Condition is satisfied, Indicator 3 may be used as the next target risk indicator, and the process returns to step S240 to determine the risk level corresponding to Indicator 3. Similarly, the target risk indicators are verified in sequence until the verification operation is completed. The verification operation can be ended, and the risk verification result corresponding to the target operation can be determined based on the target risk degree corresponding to each verified target risk indicator. Therefore, based on the configured verification conditions, only part of the target risk indicators can be verified, which further improves the verification flexibility and further meets the user's personalized needs.

[0080] Table 3 A verification condition configuration information

[0081]

[0082] It should be noted that after the user completes the configuration of the verification conditions, the first verification operation, and the second verification operation on the visual configuration page, the flowchart generation button can be triggered so that the configuration terminal can generate a corresponding flowchart based on the verification condition information configured by the user and display it on the visual configuration page. For example, the flowchart converted from the verification condition configuration information in Table 3 is as follows: Figure 3As shown, the user can quickly check whether there are any configuration errors based on the generated flowchart. When an error occurs, the user can reconfigure by triggering the modify button until the generated flowchart has no problems. In this way, the accuracy of the user configuration can be further guaranteed by generating a flowchart, thereby improving the user configuration experience.

[0083] Based on the above technical solution, the indicator verification condition corresponding to the target risk indicator is a verification expression, or an empty condition, wherein the verification expression includes: the risk degree parameter corresponding to the target risk indicator, the preset risk degree threshold, and the relational operator used to connect the risk degree parameter and the preset risk degree threshold; the first verification operation or the second verification operation includes: the next target risk indicator to be executed or the end of the verification operation.

[0084] The null condition may refer to no verification condition. For example, the verification condition for indicator 2 in Table 3 is a null condition. The structure of the verification expression can be seen in Table 2.

[0085] Based on the above technical solution, "determining the risk verification result corresponding to the target operation based on the target risk level corresponding to the target risk indicator" may include: determining the risk verification result corresponding to the target operation based on the target risk levels obtained after the verification operation is completed.

[0086] Specifically, for target operations with at least two target risk indicators, the risk levels of each target obtained after the verification operation are completed can be combined to determine the risk verification result corresponding to the target operation. By using configured verification conditions, only some target risk indicators can be verified, further increasing verification flexibility and meeting user personalized needs.

[0087] Example 3

[0088] Figure 4 This is a schematic diagram of the structure of an operation risk verification device provided by the third embodiment of the present invention. Figure 4 As shown, the device includes: a target operation data acquisition module 310, a verification configuration information determination module 320, a target risk level determination module 330 and a risk verification result determination module 340.

[0089] Among them, the target operation data acquisition module is used to obtain the target operation data and target operation identification information corresponding to the target operation to be verified; the verification configuration information determination module is used to determine the target risk verification configuration information corresponding to the target operation based on the correspondence between the pre-configured risk verification configuration information and the operation identification information and the target operation identification information, wherein the target risk verification configuration information includes at least one target risk indicator configuration information corresponding to the target risk indicator, and the target risk indicator configuration information includes a verification logic expression and a risk value corresponding to the verification logic expression; the target risk level determination module is used to match the target operation data with each verification logic expression, and determine the target risk level corresponding to the target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression; the risk verification result determination module is used to determine the risk verification result corresponding to the target operation based on the target risk level corresponding to the target risk indicator.

[0090] The technical solution of this embodiment obtains target operation data and target operation identification information corresponding to the target operation to be verified, and determines the target risk verification configuration information corresponding to the target operation based on the correspondence between pre-configured risk verification configuration information and the operation identification information and the target operation identification information. The target risk verification configuration information includes at least one target risk indicator configuration information corresponding to the target risk indicator, and the target risk indicator configuration information includes a verification logic expression and a risk value corresponding to the verification logic expression. The target operation data is matched with each verification logic expression in the target risk verification configuration information, and the target risk level corresponding to the target risk indicator is determined based on the target risk value corresponding to the successfully matched target verification logic expression. The risk verification result corresponding to the target operation is determined based on the target risk level corresponding to the target risk indicator. Therefore, it is only necessary to configure the risk verification configuration information corresponding to each operation to be verified, and perform risk verification of the operation based on the configured risk verification configuration information. This greatly reduces the development workload. When the verification logic needs to be modified, only the risk verification configuration information needs to be modified, without modifying the logic code. This achieves dynamic configuration of risk verification, improves the flexibility of risk verification, and further improves verification maintenance efficiency.

[0091] Optionally, the verification logic expression includes: at least one parameter verification condition or at least two parameter verification conditions connected by a logical operator;

[0092] The parameter verification conditions include: operation parameters, parameter values, and relational operators for connecting the operation parameters and parameter values; logical operators include at least one of: "and", "or", and "not".

[0093] Optionally, the target risk level determination module 330 is specifically configured to:

[0094] If there is only one successfully matched target verification logic expression, the target risk value corresponding to the target verification logic expression is determined as the target risk level corresponding to the target risk indicator;

[0095] If there are at least two successfully matched target verification logic expressions, the target risk values ​​corresponding to each target verification logic expression are added together, and the obtained addition result is determined as the target risk degree corresponding to the target risk indicator.

[0096] Optionally, when the number of target risk indicators is at least two, the target risk verification configuration information further includes: indicator verification sequence information corresponding to each target risk indicator;

[0097] The target risk level determination module 330 further includes:

[0098] The current target risk indicator determination submodule is used to take the first target risk indicator in the indicator verification sequence information as the current target risk indicator;

[0099] The current target risk level determination submodule is used to match the target operation data with each verification logic expression corresponding to the current target risk indicator, and determine the current target risk level corresponding to the current target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression;

[0100] The next target risk indicator determination submodule is used to determine the next target risk indicator based on the indicator verification sequence information and the current target risk indicator, and return the next target risk indicator as the current target risk indicator to perform the operation of matching the target operation data with each verification logic expression corresponding to the current target risk indicator.

[0101] Optionally, the target risk verification configuration information further includes: an indicator verification condition corresponding to each target risk indicator, a first verification operation performed when the indicator verification condition is met, and a second verification operation performed when the indicator verification condition is not met;

[0102] The next target risk indicator determination submodule is specifically used to:

[0103] According to the current target risk level corresponding to the current target risk indicator, detect whether the current target risk level meets the current indicator verification condition corresponding to the current target risk indicator; if the current indicator verification condition is met, determine the next target risk indicator based on the first verification operation performed after the current target risk indicator meets the current indicator verification condition; if the current indicator verification condition is not met, determine the next target risk indicator based on the second verification operation performed after the current target risk indicator does not meet the current indicator verification condition.

[0104] Optionally, the indicator verification condition corresponding to the target risk indicator is a verification expression, or an empty condition, wherein the verification expression includes: a risk degree parameter corresponding to the target risk indicator, a preset risk degree threshold, and a relational operator for connecting the risk degree parameter and the preset risk degree threshold; the first verification operation or the second verification operation includes: the next target risk indicator to be executed or the end of the verification operation.

[0105] Optionally, the risk verification result determination module 340 is specifically configured to determine a risk verification result corresponding to the target operation based on each target risk level obtained after the verification operation is completed.

[0106] Optionally, the device further comprises:

[0107] The corresponding relationship generation module is used to configure the verification logic expression and the risk value corresponding to each operation to be verified through a visual configuration page before obtaining the target operation data and target operation identification information corresponding to the target operation to be verified, so as to obtain the risk verification configuration information corresponding to each operation; based on the operation identification information corresponding to each operation and the obtained risk verification configuration information, generate the corresponding relationship between the risk verification configuration information and the operation identification information.

[0108] The operational risk verification device provided in the embodiment of the present invention can execute the operational risk verification method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0109] It is worth noting that in the embodiment of the above-mentioned operational risk verification device, the various modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the various functional modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention.

[0110] Example 4

[0111] Figure 5 A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0112] like Figure 5 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0113] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0114] Processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any other suitable processor, controller, microcontroller, etc. Processor 11 executes the various methods and processes described above, such as the operational risk verification method.

[0115] In some embodiments, the operational risk verification method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the operational risk verification method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to execute the operational risk verification method via any other suitable means (e.g., via firmware).

[0116] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0117] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0118] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0119] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0120] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0121] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.

[0122] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0123] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. An operational risk verification method, characterized in that: include: Obtain target operation data and target operation identification information corresponding to the target operation to be verified; Determining target risk verification configuration information corresponding to the target operation based on a correspondence between pre-configured risk verification configuration information and operation identification information and the target operation identification information, wherein the target risk verification configuration information includes at least one target risk indicator configuration information corresponding to a target risk indicator, and the target risk indicator configuration information includes a verification logic expression and a risk value corresponding to the verification logic expression; Matching the target operation data with each of the verification logic expressions, and determining the target risk degree corresponding to the target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression; Determining a risk verification result corresponding to the target operation based on a target risk level corresponding to the target risk indicator; Wherein, when the number of the target risk indicators is at least two, the target risk verification configuration information further includes: indicator verification sequence information corresponding to each of the target risk indicators; The matching of the target operation data with each of the verification logic expressions and determining the target risk degree corresponding to the target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression includes: The first target risk indicator in the indicator verification sequence information is used as the current target risk indicator; the target operation data is matched with each of the verification logic expressions corresponding to the current target risk indicator, and the current target risk degree corresponding to the current target risk indicator is determined based on the target risk value corresponding to the successfully matched target verification logic expression; the next target risk indicator is determined based on the indicator verification sequence information and the current target risk indicator, and the next target risk indicator is returned as the current target risk indicator to execute the operation of matching the target operation data with each of the verification logic expressions corresponding to the current target risk indicator.

2. The method according to claim 1, characterized in that The verification logic expression includes: at least one parameter verification condition or at least two parameter verification conditions connected by a logical operator; wherein, The parameter verification condition includes: an operating parameter, a parameter value, and a relational operator for connecting the operating parameter and the parameter value; The logical operators include at least one of "and", "or", and "not".

3. The method according to claim 1, characterized in that The determining of the target risk level corresponding to the target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression includes: If there is only one successfully matched target verification logic expression, the target risk value corresponding to the target verification logic expression is determined as the target risk level corresponding to the target risk indicator; If there are at least two successfully matched target verification logic expressions, the target risk values ​​corresponding to each of the target verification logic expressions are added together, and the obtained addition result is determined as the target risk degree corresponding to the target risk indicator.

4. The method according to claim 1, wherein The target risk verification configuration information further includes: an indicator verification condition corresponding to each target risk indicator, a first verification operation performed when the indicator verification condition is met, and a second verification operation performed when the indicator verification condition is not met; The determining of the next target risk indicator based on the indicator verification sequence information and the current target risk indicator includes: According to the current target risk level corresponding to the current target risk indicator, detect whether the current target risk level meets the current indicator verification condition corresponding to the current target risk indicator; If the current indicator verification condition is met, determining the next target risk indicator based on the first verification operation performed after the current indicator verification condition is met, corresponding to the current target risk indicator; If the current indicator verification condition is not satisfied, the next target risk indicator is determined based on a second verification operation performed after the current target risk indicator corresponding to the current target risk indicator does not satisfy the current indicator verification condition.

5. The method according to claim 4, characterized in that The indicator verification condition corresponding to the target risk indicator is a verification expression, or a null condition, wherein the verification expression includes: a risk degree parameter corresponding to the target risk indicator, a preset risk degree threshold, and a relational operator for connecting the risk degree parameter and the preset risk degree threshold; The first verification operation or the second verification operation includes: a next target risk indicator to be executed or an end verification operation.

6. The method according to claim 4, characterized in that The determining, based on the target risk level corresponding to the target risk indicator, a risk verification result corresponding to the target operation includes: Based on the respective target risk levels obtained after the verification operation is completed, a risk verification result corresponding to the target operation is determined.

7. The method according to any one of claims 1 to 6, characterized in that Before obtaining the target operation data and target operation identification information corresponding to the target operation to be verified, the following steps are also included: Through the visual configuration page, configure the verification logic expression corresponding to each operation that needs to be verified and the risk value corresponding to the verification logic expression to obtain the risk verification configuration information corresponding to each operation; Based on the operation identification information corresponding to each operation and the obtained risk verification configuration information, a correspondence relationship between the risk verification configuration information and the operation identification information is generated.

8. An operational risk verification device, characterized in that: include: A target operation data acquisition module is used to obtain target operation data and target operation identification information corresponding to the target operation to be verified; a verification configuration information determination module, configured to determine target risk verification configuration information corresponding to the target operation based on a correspondence between pre-configured risk verification configuration information and operation identification information and the target operation identification information, wherein the target risk verification configuration information includes at least one target risk indicator configuration information corresponding to a target risk indicator, and the target risk indicator configuration information includes a verification logic expression and a risk value corresponding to the verification logic expression; a target risk level determination module, configured to match the target operation data with each of the verification logic expressions, and determine the target risk level corresponding to the target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression; a risk verification result determination module, configured to determine a risk verification result corresponding to the target operation based on a target risk degree corresponding to the target risk indicator; Wherein, when the number of the target risk indicators is at least two, the target risk verification configuration information further includes: indicator verification sequence information corresponding to each of the target risk indicators; The target risk level determination module includes: The current target risk indicator determination submodule is used to use the first target risk indicator in the indicator verification sequence information as the current target risk indicator; the current target risk level determination submodule is used to match the target operation data with each of the verification logic expressions corresponding to the current target risk indicator, and determine the current target risk level corresponding to the current target risk indicator based on the target risk value corresponding to the successfully matched target verification logic expression; the next target risk indicator determination submodule is used to determine the next target risk indicator based on the indicator verification sequence information and the current target risk indicator, and return the next target risk indicator as the current target risk indicator to execute the operation of matching the target operation data with each of the verification logic expressions corresponding to the current target risk indicator.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the operation risk verification method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the operation risk verification method according to any one of claims 1 to 7 when executed.

Citation Information

Patent Citations

  • Service control method, device and system and storage medium

    CN109636317A

  • Verification method, device and equipment and storage medium

    CN111680068A