Data object risk processing method, device and server
Through intelligent risk processing methods, using feature data matching and rule processing, the problem of low risk identification and processing efficiency of data objects in the financial field is solved, efficient and fine risk identification and processing is achieved, and resource utilization is optimized.
Patent Information
- Application Number
- CN202210825812.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-14
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2042-07-14
AI Technical Summary
In the prior art, data object risk identification and processing in the financial field relies on manual methods, resulting in low efficiency and prone to errors, and lack of effective solutions.
Intelligent risk processing methods are adopted to obtain the characteristic data of the target object, use local databases and shared databases for matching and querying, combine risk lists and processing rules to finely distinguish risk types, and automatically process them according to different types of characteristic data.
It realizes the intelligence, efficiency and refinement of data object risk identification and processing, improves processing efficiency, reduces errors, and optimizes the overall processing process through resource allocation.
Smart Images

Figure CN115222239B_ABST
Abstract
Description
Technical Field
[0001] This specification belongs to the field of artificial intelligence technology, and in particular relates to a method, device, and server for risk management of data objects. Background Art
[0002] In the financial sector, it is often necessary to identify and address risks associated with important data objects (e.g., banknotes, transaction orders, etc.). Risks associated with data objects can arise from their own attributes (e.g., forged or fraudulent orders) or from the actions associated with them (e.g., suspected illegal transactions).
[0003] However, based on existing methods, most of the above-mentioned different types of risks rely on manual identification by staff, and then manual risk management, which results in relatively low overall processing efficiency and is prone to errors.
[0004] To address the above issues, no effective solutions have been proposed so far. Summary of the Invention
[0005] This specification provides a data object risk management method, device and server, which can intelligently, efficiently and accurately automatically realize risk identification and risk management of target objects, improve processing efficiency and reduce processing errors.
[0006] This specification provides a data object risk management method, which is applied to a first node server and includes:
[0007] Acquire first-category characteristic data of a target object; wherein the first-category characteristic data at least includes serial number information of the target object;
[0008] Matching the first type of feature data with a preset local database to obtain a corresponding matching result; wherein the preset local database stores a plurality of preset risk lists; the plurality of preset risk lists respectively correspond to a plurality of risk types; the preset risk lists include risk prefix information of the corresponding risk types;
[0009] According to the matching results, if the matching is successful, the target risk type that matches the target object is determined;
[0010] Detecting whether the target risk type belongs to a first risk type; wherein the first risk type includes risk types related to attribute characteristics of the target object;
[0011] If it is determined that the target risk type belongs to the first risk type, extracting second-type feature data of the target object according to a first processing rule that matches the first risk type; wherein the second-type feature data includes attribute characteristics of the target object; and performing risk processing on the target object according to the first processing rule and the second-type feature data;
[0012] When it is determined that the target risk type belongs to the second risk type, the shared database is queried according to the second processing rule that matches the second risk type to obtain the historical behavior records of the target object; wherein the second risk type includes the risk type involving the behavioral characteristics of the target object; the shared database stores the behavior records of data objects whose risk types belong to the second risk type uploaded by each node server; risk processing is performed on the target object according to the second processing rule and the historical behavior records of the target object.
[0013] In one embodiment, the second type of characteristic data includes at least one of the following: weight of the target object, ink thickness of the target object, color of the target object, and paper quality of the target object.
[0014] In one embodiment, risk processing for the target object is performed based on the first processing rule and the second type of feature data, including:
[0015] According to the first processing rule, calling the preset risk object identification model to process the second type of feature data of the target object to obtain the corresponding target identification result;
[0016] According to the target identification results, determine whether the target object is a risk object;
[0017] When the target object is determined to be a risk object, the target object is saved; and first-category risk warning information about the target object is generated.
[0018] In one embodiment, the shared database comprises a blockchain-based database.
[0019] In one embodiment, risk processing for the target object is performed based on the second processing rule and the historical behavior record of the target object, including:
[0020] According to the second processing rule, obtaining third-category feature data of the target object; wherein the third-category feature data includes behavioral features of the target object;
[0021] Construct the current behavior record of the target object based on the behavior characteristics and the serial number information of the target object;
[0022] Determine whether the target object is a data object involved in risky behavior based on the target object's historical and current behavior records;
[0023] When the target object is determined to be a data object involved in risky behavior, the current behavior record is stored in a shared database; and second-category risk warning information about the target object is generated.
[0024] In one embodiment, determining whether the target object is a data object involved in risky behavior based on the historical behavior records and current behavior records of the target object includes: calling a preset risk behavior identification model to process the historical behavior records and current behavior records of the target object to determine whether the target object is a data object involved in risky behavior.
[0025] In one embodiment, the third type of feature data includes at least one of the following: location information of the target object, source information of the target object, and destination information of the target object.
[0026] In one embodiment, when the target object is determined to be a data object involving risky behavior, the method further includes:
[0027] According to the second processing rule, a target mark is set on the target object; wherein the target mark is used to instruct other node servers to track and monitor the behavioral characteristics of the target object.
[0028] In one embodiment, the method further comprises:
[0029] According to the preset protocol rules, the remaining amount of local computing resources is counted at each preset time interval as the remaining information of the computing resources;
[0030] Broadcasting remaining information of computing resources to other node servers in the system; and obtaining remaining information of computing resources broadcast by other node servers.
[0031] In one embodiment, after obtaining the first type of feature data of the target object, the method further includes:
[0032] Check whether the remaining amount of local computing resources meets the requirements;
[0033] When it is determined that the remaining amount of local computing resources does not meet the requirements, based on the remaining information of the current computing resources of other node servers in the system, a node server whose remaining amount of current computing resources meets the requirements is determined from other node servers as the target node server;
[0034] According to a preset protocol rule, an assistance processing request is generated; and the assistance processing request is sent to a target node server; wherein the assistance processing request carries at least the first type of characteristic data of the target object.
[0035] In one embodiment, after sending the assistance processing request to the target node server, the method further includes:
[0036] Receive the target processing result fed back by the target node server; wherein, the target node server responds to the assistance processing request according to the preset protocol rules, and obtains the target processing result by performing data processing on the target object.
[0037] This specification also provides a data object risk processing device, which is applied to a first node server and includes:
[0038] An acquisition module, configured to acquire first-category characteristic data of a target object; wherein the first-category characteristic data at least includes serial number information of the target object;
[0039] a matching module, configured to match the first type of feature data with a preset local database to obtain a corresponding matching result; wherein the preset local database stores a plurality of preset risk lists; the plurality of preset risk lists respectively correspond to a plurality of risk types; and the preset risk lists include risk prefix information of the corresponding risk types;
[0040] A determination module is used to determine the target risk type that matches the target object based on the matching result if the matching is successful;
[0041] A detection module, configured to detect whether the target risk type belongs to a first risk type; wherein the first risk type includes risk types involving attribute characteristics of the target object;
[0042] an extraction module, configured to extract, when determining that the target risk type belongs to the first risk type, second-category feature data of the target object according to a first processing rule that matches the first risk type; wherein the second-category feature data includes attribute features of the target object;
[0043] The processing module is used to perform risk processing on the target object according to the first processing rule and the second type of feature data.
[0044] This specification also provides a server, including a processor and a memory for storing processor-executable instructions, wherein the processor implements relevant steps of the risk processing method for the data object when executing the instructions.
[0045] This specification also provides a computer-readable storage medium having computer instructions stored thereon, which implement relevant steps of the risk handling method for the data object when the instructions are executed by a processor.
[0046] This specification also provides a computer program product, comprising a computer program, which implements the relevant steps of the risk handling method for data objects when the computer program is executed by a processor.
[0047] Based on the risk processing method, device, and server for data objects provided in this specification, the first node server can first obtain the target object's serial number information as the first type of feature data; and by matching the first type of feature data with a preset local database, further determine the target risk type that matches the target object if the match is successful; and then distinguish whether the above-mentioned target risk type is the first type of risk type involving the attribute characteristics of the target object or the second type of risk type involving the behavioral characteristics of the target object. Specifically, if it is determined that the target risk type belongs to the first type of risk type, the second type of feature data involving the attributes of the target object can be specifically extracted according to the first processing rule that matches the first type of risk type; and risk processing is performed on the target object according to the first processing rule and the second type of feature data; conversely, if it is determined that the target risk type belongs to the second type of risk type, the shared database can be first queried according to the second processing rule that matches the second type of risk type to obtain the target object's historical behavior record; at the same time, according to the second processing rule, the third type of feature data involving the behavior of the target object and the serial number information of the target object are obtained and the current behavior record of the target object is constructed; and then risk processing is performed on the target object according to the second processing rule, the target object's historical behavior record, and the current behavior record. This allows for precise and comprehensive differentiation of different risk types, and for each risk type, intelligent, efficient, and targeted automatic risk identification and risk management for the target object, improving processing efficiency and reducing processing errors. Furthermore, according to preset protocol rules, the remaining amount of local computing resources is counted at preset time intervals as remaining computing resource information, and this remaining computing resource information is broadcast to other node servers in the system. Furthermore, if it is determined that the current remaining amount of local computing resources does not meet the requirements, the system can accurately determine, based on the current remaining computing resource information of other node servers in the system, a target node server whose current remaining amount of computing resources meets the requirements. Then, according to the preset protocol rules, a request for assistance processing is generated and sent to the target node server. This allows for the effective and reasonable deployment and utilization of the computing resources of other node servers in the system, timely assisting the first node server in completing relevant data processing, further improving overall processing efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the embodiments of this specification, the following will briefly introduce the drawings required for use in the embodiments. The drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0049] Figure 1 This is a flowchart of a data object risk management method provided by an embodiment of this specification;
[0050] Figure 2 This is a schematic diagram of an embodiment of a data object risk processing method provided by an embodiment of this specification, in a scenario example;
[0051] Figure 3 This is a schematic diagram of an embodiment of a data object risk processing method provided by an embodiment of this specification, in a scenario example;
[0052] Figure 4 This is a schematic diagram of an embodiment of a data object risk processing method provided by an embodiment of this specification, in a scenario example;
[0053] Figure 5 This is a schematic diagram of an embodiment of a data object risk processing method provided by an embodiment of this specification, in a scenario example;
[0054] Figure 6 This is a schematic diagram of the structure of a server provided by an embodiment of this specification;
[0055] Figure 7 This is a schematic diagram of the structural composition of a risk processing device for a data object provided by an embodiment of this specification. DETAILED DESCRIPTION
[0056] To help those skilled in the art better understand the technical solutions in this specification, the following will provide a clear and complete description of the technical solutions in the embodiments of this specification, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. All other embodiments derived by those skilled in the art based on the embodiments in this specification without creative effort shall fall within the scope of protection of this specification.
[0057] See Figure 1 As shown, the embodiment of this specification provides a data object risk management method, wherein the method is specifically applied to the first node server side. When implemented, the method may include the following contents:
[0058] S101: Acquire first-category feature data of a target object; wherein the first-category feature data at least includes serial number information of the target object;
[0059] S102: Matching the first type of feature data with a preset local database to obtain a corresponding matching result; wherein the preset local database stores a plurality of preset risk lists; the plurality of preset risk lists respectively correspond to a plurality of risk types; the preset risk lists include risk prefix information of the corresponding risk types;
[0060] S103: Based on the matching result, if the matching is successful, determining the target risk type that matches the target object;
[0061] S104: Detect whether the target risk type belongs to the first risk type; wherein the first risk type includes risk types related to attribute characteristics of the target object;
[0062] S105: If it is determined that the target risk type belongs to the first risk type, extracting second-type feature data of the target object according to a first processing rule that matches the first risk type; wherein the second-type feature data includes attribute characteristics of the target object; and performing risk processing on the target object according to the first processing rule and the second-type feature data;
[0063] S106: When it is determined that the target risk type belongs to the second risk type, the shared database is queried according to the second processing rule that matches the second risk type to obtain the historical behavior records of the target object; wherein the second risk type includes the risk type involving the behavioral characteristics of the target object; the shared database stores the behavior records of data objects whose risk types belong to the second risk type uploaded by each node server; and risk processing is performed on the target object according to the second processing rule and the historical behavior records of the target object.
[0064] Based on the above embodiments, the first node server deployed locally can accurately and comprehensively distinguish different risk types; and for different risk types, it can automatically perform risk identification and risk processing of target objects intelligently, efficiently and in a targeted manner, thereby improving processing efficiency and reducing processing errors.
[0065] In some embodiments, the target objects may specifically include transaction data objects in transaction data processing scenarios that are subject to risk detection and risk management. Specifically, the target objects may include at least one of the following: transaction orders, transfer requests, banknotes, and the like. Of course, it should be noted that the target objects listed above are merely illustrative. In specific implementations, depending on the specific application scenario and processing requirements, the target objects may also include other types of data objects in other application scenarios. This specification does not limit this.
[0066] In some embodiments, the risk handling method for the data object can be specifically applied to the first node server side.
[0067] The first node server mentioned above can be specifically understood as a node server that is different from the central server and is deployed in a sub-region (for example, a certain network point, or a certain branch, etc.) and is mainly responsible for processing relevant business data in the sub-region. Figure 2 shown.
[0068] The first node server may specifically include a node server deployed in the first sub-region, capable of performing functions such as data transmission and data processing. Furthermore, the first node server, along with other node servers deployed in other sub-regions (e.g., the second node server deployed in the second sub-region, the third node server deployed in the third sub-region, ... the Nth node server deployed in the Nth sub-region, etc.), and a central server (e.g., a server deployed at the headquarters or management center), are connected according to preset protocol rules to form a corresponding business data processing system (e.g., the XX Bank transaction data processing system, hereinafter referred to as the system), to jointly perform specific business data processing. The preset protocol rules may specifically include those based on a consensus protocol and / or those based on a network neuron mechanism. Based on the aforementioned protocol rules, the node servers and the central server may also jointly use and maintain a shared database. The shared database will be described in detail later.
[0069] Specifically, the first node server and other node servers may be, for example, an electronic device having data computing, storage, and network interaction functions. Alternatively, the first node server and other node servers may be software programs running on the electronic device to provide support for data processing, storage, and network interaction. In this embodiment, the number of servers included in the first node server and other node servers is not specifically limited. The first node server and other node servers may be one server, several servers, or a server cluster formed by several servers.
[0070] Each node server is connected to the terminal devices deployed in its sub-area.
[0071] Taking the transaction data processing scenario as an example, see Figure 2 As shown, the first sub-area is also equipped with a first collection terminal (e.g., a cashier machine, a camera, etc.), a first data collection and management terminal (e.g., a serial number collection and management terminal), and a first user terminal deployed on the staff side of the first sub-area.
[0072] Among them, the first acquisition end is connected to the first data acquisition management terminal; the first data acquisition management terminal is connected to the first node server; and the first node server is connected to the first user terminal.
[0073] Specifically, the first user terminal and other user terminals can be used by staff members as front-end devices capable of performing functions such as data collection and data transmission. Specifically, the first user terminal and other user terminals can be electronic devices such as desktop computers, tablet computers, laptop computers, and smartphones. Alternatively, the first user terminal and other user terminals can be software applications that can run on these electronic devices. For example, they can be a client application for the XX Bank transaction data branch management program running on a desktop computer.
[0074] The cashier machines described above can be used to count banknotes and other data objects and identify their authenticity. Specifically, the cashier machines can at least identify characteristic data such as the serial number of a banknote. Specifically, the cashier machines described above can include devices such as banknote counters, sorting machines, and foreign currency detectors.
[0075] The aforementioned serial number collection and management terminal can be used to aggregate the received serial number information and generate a corresponding FSN file, which can then be uploaded. Specifically, the FSN file can be understood as the serial number file in the banking system, primarily used for data processing in the system's stages of uploading, managing, and applying serial number information.
[0076] In specific implementations, the first collection terminal can collect characteristic data of the target object and transmit it to the first data collection and management terminal. The first data collection and management terminal can aggregate the characteristic data of the target object and then transmit the aggregated characteristic data of the target object to the first node server. Based on the specific situation, the first node server can locally or with the assistance of the system perform risk identification and risk management for the target object based on the characteristic data of the target object, and feedback the final processing results to the first user terminal. The first terminal can display the processing results of the target object to the staff of the first sub-area.
[0077] In some embodiments, when the first acquisition terminal detects a target object flowing into or out of the first sub-area, it can trigger the collection of identification information of the target object, such as serial number information, as the first type of characteristic data of the target object. Specifically, the first type of characteristic data can be understood as identification information that can be used to indicate the target object.
[0078] The serial number information mentioned above can be specifically understood as the serial number of the banknote. Typically, the serial number of a banknote is a character number used to record the banknote issuance sequence, for example, FA00008888. Furthermore, under normal circumstances, the serial number information of each banknote is unique, meaning that there is a one-to-one correspondence between the banknote and its serial number information.
[0079] Of course, the serial number information listed above is merely illustrative. In practice, other identifying information that can identify the target object may also be collected as the first type of feature data, depending on the specific type of target object and the specific application scenario. For example, the order number of a transaction order may also be collected as the first type of feature data.
[0080] The first data collection and management terminal receives the first-category feature data of the target object collected by the first collection terminal, performs appropriate preprocessing, for example, generating a corresponding FSN file based on the serial number information of the target object, and then uploads the first-category feature data of the target object in the form of an FSN file to the first node server. Accordingly, the first node server can obtain the first-category feature data of the target object.
[0081] In some embodiments, the first node server is further connected to a preset local database. The preset local database may store multiple preset risk lists. Each of the multiple preset risk lists may correspond to a risk type. Furthermore, each preset risk list may include risk identification information for the corresponding risk type, such as risk prefix information for the corresponding risk type. The multiple preset risk lists may be provided by the system's central server and regularly updated.
[0082] Specifically, taking banknotes as an example, the preset risk list may include a preset counterfeit currency risk list and a preset risk list involving risky transactions. Specifically, the preset risk list involving risky transactions may include multiple preset risk lists involving various types of illegal transactions. For example, a preset risk list involving credit defaults, a preset risk list involving suspicious funds transfers, and so on.
[0083] In specific implementation, the central server can regularly interact with the supervision platform for data, and regularly organize and summarize relevant records of data objects processed in the system, so as to timely and regularly update multiple preset risk lists in the preset local database.
[0084] In some embodiments, during specific implementation, the first node server may match the first-category characteristic data of the target object with multiple preset risk lists in a preset local database. If it is determined that the first-category characteristic data of the target object is identical to the risk prefix information in a preset risk list, the match is determined to be successful, and the risk type corresponding to the preset risk list is recorded as the matching result. Conversely, if it is determined that the first-category characteristic data of the target object is identical to the risk prefix information in all preset risk lists, the match is determined to be unsuccessful, as the matching result.
[0085] In some embodiments, if the matching result fails, the target object is determined to be unaware of the risk, and subsequent data processing may not be triggered. Conversely, if the matching result succeeds, the target object may be assigned a risk type corresponding to a preset risk list matched to the target object, as the target risk type. Furthermore, the target risk type may be detected as belonging to the first or second risk type.
[0086] The first risk type may specifically include risk types related to the target object's own attribute characteristics, such as the target object being a counterfeit currency or an invalid transaction order.
[0087] The second type of risk mentioned above may specifically include risk types where the target object's own attributes are risk-free, but the risk types involve the target object's behavioral characteristics, such as using the target object to participate in illegal transactions.
[0088] In some embodiments, the first node server may also be configured with a risk classification table provided by the central server. The first node server may determine whether the target risk type belongs to the first risk type or the second risk type based on the risk classification table.
[0089] In some embodiments, the first node server is also pre-configured with a first processing rule and a second processing rule. The first processing rule matches the first type of risk and may specifically include an identification rule and a processing rule for further risk identification and risk treatment for a target object based on the attribute characteristics of the data object. The second processing rule matches the second type of risk and may specifically include an identification rule and a processing rule for further risk identification and risk treatment for a target object based on the behavioral characteristics of the data object.
[0090] The first processing rule and the second processing rule may be generated by the central server in advance by collating and learning historical identification and processing records of data objects belonging to different types of risks, and then sent to the first node server.
[0091] In some embodiments, during specific implementation, when it is determined that the target risk type belongs to the first type of risk type, the first node server can control the first collection end through the first data collection management terminal to collect the attribute characteristics of the target object according to the first processing rule matching the first type of risk type, and obtain the second type of feature data of the target object.
[0092] In some embodiments, the second type of characteristic data may specifically include at least one of the following: weight of the target object, ink thickness of the target object, color of the target object, paper quality of the target object, etc.
[0093] Of course, the second type of characteristic data listed above is merely an illustrative example. In practice, depending on the specific type of target object and specific processing requirements, the second type of characteristic data may also include other types of attribute features. For example, key anti-counterfeiting identification of the target object, signature information of the target object, and so on.
[0094] In some embodiments, see Figure 3 As shown, the risk processing for the target object based on the first processing rule and the second type of characteristic data may include the following when it is specifically implemented:
[0095] S1: According to the first processing rule, calling the preset risk object identification model to process the second type of feature data of the target object to obtain the corresponding target identification result;
[0096] S2: Determine whether the target object is a risk object based on the target identification result;
[0097] S3: When the target object is determined to be a risk object, the target object is saved; and first-category risk warning information about the target object is generated.
[0098] In some embodiments, the preset risk object identification model can be specifically understood as a neural network model that can predict and output a probability value of a data object being a risk object based on the second-category feature data of the input data object. The preset risk object identification model can be pre-trained by the central server using the second-category feature data of sample objects.
[0099] In some embodiments, after obtaining the target identification result, the first node server may determine whether the predicted probability value is greater than a preset probability threshold based on the target result. If the predicted probability value is determined to be greater than the preset probability threshold, the target object may be determined to be a risky object. For example, a banknote may be determined to be counterfeit, or a transaction order may be determined to be invalid. Conversely, if the predicted probability value is determined to be less than or equal to the preset probability threshold, the target object may be determined not to be a risky object.
[0100] In some embodiments, when it is determined that the target object is a risk object, the original business data processing involving the target object can be suspended, and the target object can be intercepted and saved. Furthermore, a corresponding risk label can be added to the target object. At the same time, a first type of risk warning information about the risk of the target object's own attributes will be generated; and the above-mentioned first type of risk warning information will be sent to the first user terminal in a timely manner to wait for further processing by the staff of the first sub-area. In addition, a risk identification and processing record for the target object can also be generated, and the risk identification and processing record can be uploaded to the central server; or uploaded to the system's shared database. The above-mentioned first type of risk warning information can also be sent to the supervision platform for further processing.
[0101] In some embodiments, the first node server may also be configured with a preset risk signature library. The preset risk signature library stores a plurality of risk signatures that can indicate risky objects. The risky investments in the preset risk signature library may be obtained by clustering the second-category signature data of risk objects historically processed by all node servers in the system by the central server.
[0102] During specific implementation, the first node server may also match the second type of feature data of the target object with a preset risk feature library to obtain a corresponding risk matching result; and then determine whether the target object is a risk object based on the risk matching result.
[0103] In some embodiments, after detecting whether the target risk type belongs to the first risk type, when the method is specifically implemented, refer to Figure 4 As shown, it can also include the following:
[0104] S1: When it is determined that the target risk type belongs to the second risk type, querying a shared database according to a second processing rule matching the second risk type to obtain historical behavior records of the target object; wherein the second risk type includes risk types involving behavioral characteristics of the target object; the shared database stores behavior records of data objects belonging to the second risk type uploaded by each node server;
[0105] S2: Perform risk processing on the target object according to the second processing rule and the historical behavior record of the target object.
[0106] In some embodiments, the shared database may specifically store behavior records of data objects identified and uploaded by each node server as posing the second risk type. The data object behavior records may specifically include a flow record of the data object within the subregion where the node server is located, as determined by the node server. The data object behavior records may include at least identification information of the data object, such as the data object's serial number.
[0107] In some embodiments, the shared database may specifically include a blockchain-based database. This can fully utilize the immutability and security of blockchain, allowing multiple node servers in the system to safely and reliably maintain and use the shared database.
[0108] In some embodiments, during specific implementation, the first node server may search the shared database based on the serial number information of the target object, and find the behavior record containing the serial number information of the target object from the shared database as the historical behavior record of the target object.
[0109] In some embodiments, see Figure 4 As shown, the risk processing for the target object based on the second processing rule and the historical behavior record of the target object may include the following contents during specific implementation:
[0110] S1: Acquire third-category feature data of a target object according to a second processing rule; wherein the third-category feature data includes behavioral features of the target object;
[0111] S2: Construct the current behavior record of the target object based on the behavior characteristics of the target object and the target object's prefix number information;
[0112] S3: Determine whether the target object is a data object involved in risky behavior based on the target object's historical behavior records and current behavior records;
[0113] S4: When it is determined that the target object is a data object involved in risky behavior, the current behavior record is stored in a shared database; and second-category risk warning information about the target object is generated.
[0114] In some embodiments, the third category of characteristic data may specifically include at least one of the following: location information of the target object (for example, the area number of the first sub-area through which the target object currently flows, etc.), source information of the target object (for example, the account number of the initiating account when the target object flows through the first sub-area, etc.), destination information of the target object (for example, the account number of the receiving account when the target object flows through the first sub-area, etc.), etc. Of course, the third category of characteristic data listed above is only a schematic illustration. During specific implementation, according to the specific type of the target object and the specific processing requirements, the third category of characteristic data may also include other types of behavioral characteristics. For example, the third category of characteristic data also includes: a postscript description when the target object flows through the first sub-area, etc.
[0115] It should be noted that all user-related information and data mentioned in this manual are obtained and used with the user's knowledge and consent. Furthermore, the collection, use, and processing of such information and data are in compliance with relevant legal provisions.
[0116] In some embodiments, the first node server may combine the behavior characteristics of the target object flowing through the first sub-area with the serial number information of the target object to obtain the current behavior record of the target object.
[0117] In some embodiments, during specific implementation, the first node server can combine the historical behavior records and current behavior records of the target object to obtain a complete behavior record of the target object; and then further determine whether the target object is a data object involving risky behavior based on the complete behavior record of the target object.
[0118] In some embodiments, the above-mentioned determination of whether the target object is a data object involving risky behavior based on the historical behavior records and current behavior records of the target object may specifically include: calling a preset risk behavior identification model to process the historical behavior records and current behavior records of the target object to determine whether the target object is a data object involving risky behavior.
[0119] During specific implementation, the first node server may process the complete behavior record of the target object by calling a preset risk behavior identification model to determine whether the target object is a data object involving risky behavior.
[0120] The pre-set risk behavior identification model can be specifically understood as a neural network model that can predict whether a behavior is risky based on input behavior records. Before implementation, the central server can obtain and use the behavior records of sample subjects to train the pre-set risk behavior identification model.
[0121] Specifically, when the first node server determines that the behavior involved in the target object is a risky behavior based on the complete behavior record of the target object through a preset risky behavior identification model, it can determine that the target object is a data object involved in risky behavior.
[0122] In some embodiments, when the target object is determined to be a data object involving risky behavior, the method may also include the following content when implemented: according to the second processing rule, a target mark is set on the target object; wherein, the target mark is used to instruct other node servers to track and monitor the behavioral characteristics of the target object.
[0123] In specific implementations, if the target object is determined to be a data object involved in risky behavior, a second type of risk warning information regarding the risk of the behavior involved in the target object will be generated. This second type of risk warning information will be promptly sent to the first user terminal for further processing by staff in the first sub-area. This second type of risk warning information can also be sent to the supervision platform for further processing. In addition, a risk identification and processing record for the target object can be generated and uploaded to the central server.
[0124] Furthermore, in the case where it is determined that the target object is a data object involved in risky behavior, the first node server can also determine whether it is necessary to continue tracking and monitoring based on the second processing rule and the complete behavior record of the target object. In the case where it is determined that tracking and monitoring is no longer necessary (for example, the currently collected and stored behavior records can already constitute a sufficient and complete chain of evidence), the original business data processing involving the target object can also be suspended, and the target object can be intercepted and saved; at the same time, a third type of prompt information is generated to indicate that the risky behavior involved in the target object can be processed; and the above third type of risk prompt information is sent to the first user terminal to prompt the staff of the first sub-area to handle it. The above third type of risk prompt information can also be sent to the supervision platform for further processing.
[0125] In some embodiments, when a preset risk behavior identification model is used to determine that the behavior involved in the target object is not a risky behavior based on the target object's complete behavior record, it can be determined that the target object is not a data object involved in risky behavior. In this case, subsequent processing may not be triggered. Of course, in some cases, according to the second processing rule, a focus tag can also be set on the above-mentioned target object so that when the target object flows through other sub-areas, other node servers can pay attention to the target object in a timely manner and continue to pay attention to the behavior involved in the target object in other sub-areas.
[0126] In some embodiments, when the method is implemented, it may also include the following: according to preset protocol rules, the remaining amount of local computing resources is counted at preset time intervals as the remaining information of computing resources; the remaining information of computing resources is broadcast to other node servers in the system; and, the remaining information of computing resources broadcast by other node servers is obtained.
[0127] Specifically, the first node server can broadcast its latest remaining information of computing resources to other node servers in the system at preset time intervals (for example, every 5 minutes, etc.) according to the protocol rules based on the network neuron mechanism; at the same time, it can know the latest remaining information of computing resources of other node servers.
[0128] In some embodiments, after obtaining the first type of feature data of the target object, refer to Figure 5 As shown, when the method is specifically implemented, it may further include:
[0129] S1: Check whether the remaining amount of local computing resources meets the requirements;
[0130] S2: When it is determined that the remaining amount of local computing resources does not meet the requirement, based on the remaining information of the current computing resources of other node servers in the system, a node server whose remaining amount of current computing resources meets the requirement is determined from the other node servers as the target node server;
[0131] S3: Generate an assistance processing request according to a preset protocol rule; and send the assistance processing request to the target node server; wherein the assistance processing request carries at least the first type of feature data of the target object.
[0132] In some embodiments, the above-mentioned target object may specifically include multiple data objects; and the first node server is currently performing risk identification and risk processing on several other data objects. Therefore, after receiving the first type of characteristic data of the target object, the first node server can first estimate the target computing resource amount required for risk identification and risk processing of the target object based on the first type of characteristic data of the target object; at the same time, determine the current remaining amount of computing resources; and then compare the target computing resource amount with the current remaining amount of computing resources to determine whether the current remaining amount of local computing resources meets the requirements. If it is determined that the target computing resource amount is greater than or equal to the current remaining amount of computing resources, it can be determined that the requirements are not met.
[0133] If it is determined that the current remaining amount of local computing resources does not meet the requirements, the first node server can, based on the remaining information of the current computing resources of other node servers in the system, identify a node server whose remaining amount of computing resources meets the requirements from among the other node servers and use it as the target node server. This allows the target node server's computing resources to be temporarily scheduled for use in risk identification and risk management for the target object. Furthermore, the first node server can generate an assistance request based on pre-set protocol rules and send the assistance request to the target node server.
[0134] In some embodiments, if the first node server determines that the remaining local computing resources do not meet the required amount, it may first send an assistance request to the central server. The central server will dispatch an appropriate node server to temporarily assist in risk identification and risk management for the target object based on the remaining computing resources of each node server.
[0135] In some embodiments, after the assistance processing request is sent to the target node server, the specific implementation of the method may also include the following: receiving the target processing result fed back by the target node server; wherein, the target node server responds to the assistance processing request according to preset protocol rules, and obtains the target processing result by performing data processing on the target object.
[0136] In some embodiments, when the method is implemented, it may also include: receiving an assistance processing request sent by other node servers; responding to the assistance processing request, calling local computing resources to perform corresponding risk identification and risk processing, and obtaining corresponding processing results; and then feeding back the processing results to the node server.
[0137] As can be seen from the above, based on the risk processing method for data objects provided in the embodiments of this specification, the first node server can first obtain the serial number information of the target object as the first type of feature data; and by matching the first type of feature data with the preset local database, if the match is successful, further determine the target risk type that matches the target object; then distinguish whether the above-mentioned target risk type is the first type of risk type involving the attribute characteristics of the target object or the second type of risk type involving the behavioral characteristics of the target object; if it is determined that the target risk type belongs to the first type of risk type, the second type of feature data involving the attributes of the target object can be extracted in a targeted manner according to the first processing rule matching the first type of risk type; and risk processing is performed on the target object according to the first processing rule and the second type of feature data; on the contrary, if it is determined that the target risk type belongs to the second type of risk type, the shared database can be queried first according to the second processing rule matching the second type of risk type to obtain the historical behavior record of the target object; at the same time, according to the second processing rule, the third type of feature data involving the behavior of the target object is obtained and constructed according to the current behavior record of the target object; and then risk processing is performed on the target object according to the second processing rule, the historical behavior record and the current behavior record of the target object. This allows for precise and comprehensive differentiation of different risk types, and for each risk type, intelligent, efficient, and targeted automatic risk identification and risk management for the target object, improving processing efficiency and reducing processing errors. Furthermore, according to preset protocol rules, the remaining amount of local computing resources is counted at preset time intervals as remaining computing resource information, and this remaining computing resource information is broadcast to other node servers in the system. Furthermore, if it is determined that the current remaining amount of local computing resources does not meet the requirements, the remaining computing resource information of other node servers in the system can be used to determine a target node server from the other node servers whose current remaining amount of computing resources meets the requirements. Then, according to the preset protocol rules, a request for assistance processing is generated and sent to the target node server. This allows for the effective and reasonable allocation and utilization of computing resources in the system, timely assisting the first node server in completing relevant data processing, further improving overall processing efficiency.
[0138] An embodiment of this specification also provides a server, including a processor and a memory for storing processor executable instructions, and the processor can perform the following steps according to the instructions when specifically implemented: obtaining first-category feature data of a target object; wherein the first-category feature data at least includes the serial number information of the target object; matching the first-category feature data with a preset local database to obtain a corresponding matching result; wherein the preset local database stores a plurality of preset risk lists; the plurality of preset risk lists correspond to a plurality of risk types respectively; the preset risk lists include the risk serial number information of the corresponding risk types; according to the matching result, if the match is successful, determining the target risk type that matches the target object; detecting whether the target risk type belongs to the first-category risk type; wherein the first-category risk type includes the risk type involving the attribute characteristics of the target object; if it is determined that the target risk type belongs to the first-category risk type, extracting second-category feature data of the target object according to a first processing rule that matches the first-category risk type; wherein the second-category feature data includes the attribute characteristics of the target object; performing risk processing on the target object according to the first processing rule and the second-category feature data.
[0139] In order to complete the above instructions more accurately, refer to Figure 6 As shown, the embodiment of this specification also provides another specific server, wherein the server includes a network communication port 601, a processor 602 and a memory 603, and the above structures are connected through internal cables so that each structure can perform specific data interaction.
[0140] The network communication port 601 can be used to obtain first-category feature data of the target object; wherein the first-category feature data at least includes serial number information of the target object.
[0141] The processor 602 can be specifically used to match the first type of feature data with a preset local database to obtain a corresponding matching result; wherein the preset local database stores a plurality of preset risk lists; the plurality of preset risk lists correspond to a plurality of risk types respectively; the preset risk list contains risk serial number information of the corresponding risk type; according to the matching result, if the match is successful, the target risk type that matches the target object is determined; it is detected whether the target risk type belongs to the first type of risk type; wherein the first type of risk type includes risk types involving attribute characteristics of the target object; when it is determined that the target risk type belongs to the first type of risk type, according to the first processing rule that matches the first type of risk type, the second type of feature data of the target object is extracted; wherein the second type of feature data includes attribute characteristics of the target object; according to the first processing rule and the second type of feature data, risk processing is performed on the target object.
[0142] The memory 603 may be specifically used to store corresponding instruction programs.
[0143] In this embodiment, the network communication port 601 can be a virtual port that is bound to different communication protocols, thereby being capable of sending or receiving different data. For example, the network communication port can be a port responsible for web data communication, a port responsible for FTP data communication, or a port responsible for email data communication. Furthermore, the network communication port can also be a physical communication interface or communication chip. For example, it can be a wireless mobile network communication chip, such as GSM or CDMA; it can also be a Wi-Fi chip; or it can be a Bluetooth chip.
[0144] In this embodiment, the processor 602 may be implemented in any suitable manner. For example, the processor may take the form of a microprocessor or a processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, an embedded microcontroller, etc. This specification is not intended to limit this.
[0145] In this embodiment, the memory 603 may include multiple levels. In a digital system, anything that can store binary data can be a memory. In an integrated circuit, a circuit with a storage function that has no physical form is also called a memory, such as RAM, FIFO, etc. In a system, a storage device with a physical form is also called a memory, such as a memory stick, TF card, etc.
[0146] An embodiment of this specification also provides a computer storage medium based on the risk processing method of the above-mentioned data object, wherein the computer storage medium stores computer program instructions, which, when executed, implement the following: obtaining first-category feature data of a target object; wherein the first-category feature data at least includes the serial number information of the target object; matching the first-category feature data with a preset local database to obtain a corresponding matching result; wherein the preset local database stores a plurality of preset risk lists; the plurality of preset risk lists correspond to a plurality of risk types respectively; the preset risk lists include the risk serial number information of the corresponding risk types; based on the matching result, if the match is successful, determining the target risk type that matches the target object; detecting whether the target risk type belongs to the first-category risk type; wherein the first-category risk type includes the risk type involving the attribute characteristics of the target object; if it is determined that the target risk type belongs to the first-category risk type, extracting second-category feature data of the target object according to a first processing rule that matches the first-category risk type; wherein the second-category feature data includes the attribute characteristics of the target object; and performing risk processing on the target object according to the first processing rule and the second-category feature data.
[0147] In this embodiment, the storage medium includes, but is not limited to, random access memory (RAM), read-only memory (ROM), cache, hard disk drive (HDD), or memory card. The memory can be used to store computer program instructions. The network communication unit can be an interface configured in accordance with the standards specified by the communication protocol for network connection communication.
[0148] In this embodiment, the functions and effects specifically implemented by the program instructions stored in the computer storage medium can be explained in comparison with other implementations and will not be repeated here.
[0149] An embodiment of the present specification also provides a computer program product, comprising a computer program, which, when executed by a processor, implements the following steps: obtaining first-category feature data of a target object; wherein the first-category feature data includes at least serial number information of the target object; matching the first-category feature data with a preset local database to obtain a corresponding matching result; wherein the preset local database stores a plurality of preset risk lists; the plurality of preset risk lists correspond to a plurality of risk types respectively; the preset risk lists include risk serial number information of the corresponding risk types; based on the matching result, if the match is successful, determining a target risk type that matches the target object; detecting whether the target risk type belongs to the first-category risk type; wherein the first-category risk type includes risk types involving attribute characteristics of the target object; if it is determined that the target risk type belongs to the first-category risk type, extracting second-category feature data of the target object according to a first processing rule that matches the first-category risk type; wherein the second-category feature data includes attribute characteristics of the target object; and performing risk processing on the target object according to the first processing rule and the second-category feature data.
[0150] See Figure 7 As shown, at the software level, the embodiment of this specification further provides a risk processing device for data objects, which may specifically include the following structural modules:
[0151] The acquisition module 701 may be specifically configured to acquire first-category feature data of a target object; wherein the first-category feature data at least includes serial number information of the target object;
[0152] Matching module 702 may be specifically configured to match the first type of feature data with a preset local database to obtain a corresponding matching result; wherein the preset local database stores a plurality of preset risk lists; the plurality of preset risk lists respectively correspond to a plurality of risk types; and the preset risk lists include risk prefix information for the corresponding risk types;
[0153] The determination module 703 may be specifically configured to determine the target risk type that matches the target object based on the matching result, if the matching is successful;
[0154] The detection module 704 may be specifically configured to detect whether the target risk type belongs to a first risk type; wherein the first risk type includes risk types related to attribute characteristics of the target object;
[0155] The first processing module 705 may be specifically configured to, when determining that the target risk type belongs to the first risk type, extract second-type feature data of the target object according to a first processing rule that matches the first risk type; wherein the second-type feature data includes attribute characteristics of the target object; and perform risk processing on the target object according to the first processing rule and the second-type feature data;
[0156] The second processing module 706 can be specifically used to query the shared database to obtain the historical behavior records of the target object according to the second processing rule that matches the second risk type when it is determined that the target risk type belongs to the second risk type; wherein the second risk type includes the risk type involving the behavioral characteristics of the target object; the shared database stores the behavior records of data objects whose risk types belong to the second risk type uploaded by each node server; and risk processing is performed on the target object according to the second processing rule and the historical behavior records of the target object.
[0157] In some embodiments, the second type of characteristic data may specifically include at least one of the following: weight of the target object, ink thickness of the target object, color of the target object, paper quality of the target object, etc.
[0158] In some embodiments, when the first processing module 705 is implemented, risk processing for the target object can be performed according to the first processing rules and the second type of feature data in the following manner: according to the first processing rules, call the preset risk object identification model to process the second type of feature data of the target object to obtain the corresponding target identification result; according to the target identification result, determine whether the target object is a risk object; if it is determined that the target object is a risk object, save the target object; and generate the first type of risk warning information about the target object.
[0159] In some embodiments, the shared database may specifically include a blockchain-based database.
[0160] In some embodiments, when the second processing module 706 is implemented, risk processing for the target object can be performed according to the second processing rules and the historical behavior records of the target object in the following manner: according to the second processing rules, the third type of characteristic data of the target object is obtained; wherein, the third type of characteristic data includes the behavioral characteristics of the target object; according to the behavioral characteristics of the target object and the serial number information of the target object, the current behavior record of the target object is constructed; according to the historical behavior record and current behavior record of the target object, it is determined whether the target object is a data object involving risky behavior; in the case where it is determined that the target object is a data object involving risky behavior, the current behavior record is stored in a shared database; and the second type of risk warning information about the target object is generated.
[0161] In some embodiments, when the second processing module 706 is implemented, it can determine whether the target object is a data object involved in risky behavior based on the historical behavior records and current behavior records of the target object in the following manner: call a preset risk behavior identification model to process the historical behavior records and current behavior records of the target object to determine whether the target object is a data object involved in risky behavior.
[0162] In some embodiments, the third type of feature data may specifically include at least one of the following: location information of the target object, source information of the target object, destination information of the target object, etc.
[0163] In some embodiments, when the target object is determined to be a data object involving risky behavior, the second processing module 706, when implemented, can also be used to set a target mark on the target object according to the second processing rule; wherein, the target mark is used to instruct other node servers to track and monitor the behavioral characteristics of the target object.
[0164] In some embodiments, when the device is implemented, it can also be used to count the remaining amount of local computing resources at preset time intervals according to preset protocol rules as remaining information of computing resources; broadcast the remaining information of computing resources to other node servers in the system; and obtain the remaining information of computing resources broadcast by other node servers.
[0165] In some embodiments, after the acquisition module 701 acquires the first type of characteristic data of the target object, the device can also be used to detect whether the current remaining amount of local computing resources meets the requirements when it is implemented; when it is determined that the current remaining amount of local computing resources does not meet the requirements, based on the current remaining information of computing resources of other node servers in the system, a node server whose current remaining amount of computing resources meets the requirements is determined from other node servers as the target node server; according to the preset protocol rules, an assistance processing request is generated; and the assistance processing request is sent to the target node server; wherein, the assistance processing request carries at least the first type of characteristic data of the target object.
[0166] In some embodiments, after the assistance processing request is sent to the target node server, the device can also be used to receive the target processing result fed back by the target node server when it is implemented; wherein, the target node server responds to the assistance processing request according to preset protocol rules, and obtains the target processing result by performing data processing on the target object.
[0167] It should be noted that the units, devices or modules described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. For the convenience of description, the above devices are described in terms of functions and are divided into various modules and described separately. Of course, when implementing this specification, the functions of each module can be implemented in the same or multiple software and / or hardware, or the module that implements the same function can be implemented by a combination of multiple sub-modules or sub-units. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0168] As can be seen from the above, the risk processing device for the data object provided in the embodiment of this specification can first obtain the serial number information of the target object as the first type of feature data; and by matching the first type of feature data with the preset local database, in the case of successful matching, further determine the target risk type that matches the target object; and then distinguish whether the above target risk type is the first type of risk type involving the attribute characteristics of the target object or the second type of risk type involving the behavioral characteristics of the target object; in the case of determining that the target risk type belongs to the first type of risk type, the second type of feature data involving the attributes of the target object can be extracted in a targeted manner according to the first processing rule that matches the first type of risk type; and risk processing for the target object can be performed according to the first processing rule and the second type of feature data. In this way, different risk types can be distinguished precisely and comprehensively; and risk processing for the target object can be performed intelligently, efficiently and automatically for different risk types, thereby improving processing efficiency and reducing processing errors. Furthermore, according to preset protocol rules, the remaining amount of local computing resources is counted at preset time intervals as remaining computing resource information; and this remaining computing resource information is broadcast to other node servers in the system. Furthermore, if it is determined that the current remaining amount of local computing resources does not meet the requirements, a target node server whose remaining amount of computing resources meets the requirements can be determined from the other node servers based on the current remaining computing resource information of other node servers in the system; and then, according to the preset protocol rules, an assistance processing request is generated and sent to the target node server. This allows for the effective and reasonable allocation and utilization of computing resources in the system, timely assisting the first node server in completing relevant data processing, and further improving overall processing efficiency.
[0169] Although this specification provides the method operation steps as described in the embodiments or flow charts, more or fewer operation steps may be included based on conventional or non-creative means. The order of steps listed in the embodiments is only one way of executing the order of many steps and does not represent the only execution order. When the device or client product in practice is executed, it can be executed in sequence or in parallel according to the method shown in the embodiments or the drawings (for example, a parallel processor or a multi-threaded processing environment, or even a distributed data processing environment). The term "comprise", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, product or device including a series of elements includes not only those elements, but also includes other elements that are not explicitly listed, or also includes elements inherent to such process, method, product or device. In the absence of more restrictions, it is not excluded that there are other identical or equivalent elements in the process, method, product or device including the elements. Words such as first and second are used to represent names and do not represent any particular order.
[0170] Those skilled in the art will also appreciate that, in addition to implementing the controller in pure computer-readable program code, it is entirely possible to implement the same functionality by logically programming the method steps in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, embedded microcontrollers, and the like. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be considered structures within the hardware component. Alternatively, the devices for implementing various functions can be considered both software modules implementing the method and structures within the hardware component.
[0171] This specification may be described in the general context of computer-executable instructions, such as program modules, executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, classes, and the like that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in both local and remote computer storage media, including storage devices.
[0172] Through the description of the above embodiments, it can be seen that those skilled in the art can clearly understand that this specification can be implemented by means of software plus the necessary general hardware platform. Based on this understanding, the technical solution of this specification can essentially be embodied in the form of a software product. This computer software product can be stored in a storage medium such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a mobile terminal, a server, or a network device, etc.) to execute the methods described in various embodiments or certain parts of the embodiments of this specification.
[0173] The various embodiments in this specification are described in a progressive manner. References to the common or similar parts of the various embodiments are sufficient. Each embodiment focuses on the differences from the other embodiments. This specification can be used in a variety of general-purpose or specialized computer system environments or configurations. For example, personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable electronic devices, network PCs, minicomputers, mainframe computers, and distributed computing environments that include any of the above systems or devices.
[0174] Although the present specification has been described through embodiments, those skilled in the art will appreciate that there are many modifications and variations to the present specification without departing from the spirit of the present specification. It is intended that the appended claims include these modifications and variations without departing from the spirit of the present specification.
Claims
1. A data object risk management method, characterized in that: Applied to the first node server, including: Acquire first-category characteristic data of a target object; wherein the first-category characteristic data at least includes serial number information of the target object; Matching the first type of feature data with a preset local database to obtain a corresponding matching result; wherein the preset local database stores a plurality of preset risk lists; the plurality of preset risk lists respectively correspond to a plurality of risk types; the preset risk lists include risk prefix information of the corresponding risk types; According to the matching results, if the matching is successful, the target risk type that matches the target object is determined; Detecting whether the target risk type belongs to a first risk type; wherein the first risk type includes risk types related to attribute characteristics of the target object; If it is determined that the target risk type belongs to the first risk type, extracting second-type feature data of the target object according to a first processing rule that matches the first risk type; wherein the second-type feature data includes attribute characteristics of the target object; performing risk processing on the target object according to the first processing rule and the second-type feature data; wherein the second-type feature data includes at least one of the following: weight of the target object, ink thickness of the target object, color of the target object, and paper quality of the target object; When it is determined that the target risk type belongs to the second risk type, the shared database is queried according to the second processing rule that matches the second risk type to obtain the historical behavior records of the target object; wherein the second risk type includes the risk type involving the behavioral characteristics of the target object; the shared database stores the behavior records of data objects whose risk types belong to the second risk type uploaded by each node server; risk processing is performed on the target object according to the second processing rule and the historical behavior records of the target object.
2. The method according to claim 1, characterized in that Based on the first processing rules and the second type of characteristic data, risk processing is performed on the target object, including: According to the first processing rule, calling the preset risk object identification model to process the second type of feature data of the target object to obtain the corresponding target identification result; According to the target identification results, determine whether the target object is a risk object; When the target object is determined to be a risk object, the target object is saved; and first-category risk warning information about the target object is generated.
3. The method according to claim 1, characterized in that The shared database includes a blockchain-based database.
4. The method according to claim 3, characterized in that Based on the second processing rule and the historical behavior records of the target object, risk processing is performed on the target object, including: According to the second processing rule, obtaining third-category feature data of the target object; wherein the third-category feature data includes behavioral features of the target object; Construct the current behavior record of the target object based on the behavior characteristics and the serial number information of the target object; Determine whether the target object is a data object involved in risky behavior based on the target object's historical and current behavior records; When the target object is determined to be a data object involved in risky behavior, the current behavior record is stored in a shared database; and second-category risk warning information about the target object is generated.
5. The method according to claim 4, characterized in that Determine whether the target object is a data object involved in risky behavior based on the historical behavior records and current behavior records of the target object, including: calling a preset risk behavior identification model to process the historical behavior records and current behavior records of the target object to determine whether the target object is a data object involved in risky behavior.
6. The method according to claim 4, characterized in that The third type of feature data includes at least one of the following: location information of the target object, source information of the target object, and destination information of the target object.
7. The method according to claim 4, characterized in that In the case where the target object is determined to be a data object involving risky behavior, the method further includes: According to the second processing rule, a target mark is set on the target object; wherein the target mark is used to instruct other node servers to track and monitor the behavioral characteristics of the target object.
8. The method according to claim 1, characterized in that The method further comprises: According to the preset protocol rules, the remaining amount of local computing resources is counted at each preset time interval as the remaining information of the computing resources; Broadcasting remaining information of computing resources to other node servers in the system; and obtaining remaining information of computing resources broadcast by other node servers.
9. The method according to claim 8, characterized in that After obtaining the first type of feature data of the target object, the method further includes: Check whether the remaining amount of local computing resources meets the requirements; When it is determined that the remaining amount of local computing resources does not meet the requirements, based on the remaining information of the current computing resources of other node servers in the system, a node server whose remaining amount of current computing resources meets the requirements is determined from other node servers as the target node server; According to a preset protocol rule, an assistance processing request is generated; and the assistance processing request is sent to a target node server; wherein the assistance processing request carries at least the first type of characteristic data of the target object.
10. The method according to claim 9, characterized in that After sending the assistance processing request to the target node server, the method further includes: Receive the target processing result fed back by the target node server; wherein, the target node server responds to the assistance processing request according to the preset protocol rules, and obtains the target processing result by performing data processing on the target object.
11. A risk processing device for a data object, characterized in that: Applied to the first node server, including: An acquisition module, configured to acquire first-category characteristic data of a target object; wherein the first-category characteristic data at least includes serial number information of the target object; a matching module, configured to match the first type of feature data with a preset local database to obtain a corresponding matching result; wherein the preset local database stores a plurality of preset risk lists; the plurality of preset risk lists respectively correspond to a plurality of risk types; and the preset risk lists include risk prefix information of the corresponding risk types; A determination module is used to determine the target risk type that matches the target object based on the matching result if the matching is successful; A detection module, configured to detect whether the target risk type belongs to a first risk type; wherein the first risk type includes risk types involving attribute characteristics of the target object; A first processing module is configured to, when determining that the target risk type belongs to the first risk type, extract second-type feature data of the target object according to a first processing rule that matches the first risk type; wherein the second-type feature data includes attribute characteristics of the target object; perform risk processing on the target object according to the first processing rule and the second-type feature data; wherein the second-type feature data includes at least one of the following: weight of the target object, ink thickness of the target object, color of the target object, and paper quality of the target object; The second processing module is used to query the shared database to obtain the historical behavior records of the target object according to the second processing rules that match the second risk type when it is determined that the target risk type belongs to the second risk type; wherein the second risk type includes risk types involving behavioral characteristics of the target object; the shared database stores the behavior records of data objects whose risk types belong to the second risk type uploaded by each node server; and perform risk processing on the target object according to the second processing rules and the historical behavior records of the target object.
12. A server, characterized in that: The method comprises a processor and a memory for storing processor-executable instructions, wherein the processor implements the steps of the method according to any one of claims 1 to 10 when executing the instructions.
13. A computer-readable storage medium, characterized in that Computer instructions are stored thereon, and when the instructions are executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.
14. A computer program product, characterized in that The invention comprises a computer program, which implements the steps of the method according to any one of claims 1 to 10 when the computer program is executed by a processor.
Citation Information
Patent Citations
Block chain wallet address evaluation method, device and system and storage medium
CN111028083A
Business data processing method and device and server
CN111428971A