Business risk control method, device, equipment, computer storage medium and program

By utilizing dynamic information scoring and enhanced verification in mobile payments through risk control modules, the problem of traditional identity verification being easily compromised has been solved, enabling more efficient identification and handling of counterfeit risks and improving fund security.

CN115994762BActive Publication Date: 2026-05-19CHINA UNIONPAY
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA UNIONPAY
Filing Date
2023-01-29
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

In existing mobile payment systems, traditional identity verification methods are easily compromised by fraud teams, leading to account holders facing the risk of impersonation and making it difficult to guarantee the safety of funds.

Method used

The risk control module determines a risk score based on the dynamic information of the account and device, and performs enhanced verification when a risk is determined, including at least two verification items. The appropriate enhanced verification method is selected based on the risk level, and the risk is handled accordingly.

Benefits of technology

It improves the accuracy and prevention of counterfeiting, reduces the risk of counterfeiting, and ensures the safety of users' funds.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115994762B_ABST
    Figure CN115994762B_ABST
Patent Text Reader

Abstract

The application discloses a business risk control method and device, equipment, a computer storage medium and a program. According to a service request of a target service sent by a service module, a risk control module determines a first account and a first device corresponding to the target service, determines account dynamic information corresponding to the first account and device dynamic information corresponding to the first device, determines whether the target service possibly has a risk according to the account dynamic information and the device dynamic information, requests the service module to perform enhanced verification on the target service in the case that it is determined that the target service possibly has a risk, determines a risk probability that the first account and / or the first device are impersonated according to an enhanced verification result, and disposes the first account and / or the first device based on the risk probability. According to the embodiment of the application, whether the target service possibly has a risk is determined from two dimensions according to the account dynamic information and the device dynamic information, which is more accurate, and the difficulty of impersonation is improved by using the enhanced verification result and subsequent linkage disposal means.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of mobile payment, and in particular relates to a business risk control method, device, equipment, computer storage medium and program. Background Technology

[0002] Currently in the mobile payment field, verifying the identity of the account holder is a key step in ensuring the safety of the account holder's funds. Commonly used verification methods include password verification, verification code verification, and biometric verification, among which biometric verification includes facial verification.

[0003] However, as the internet black market develops into an industrialized industry, traditional identity verification mechanisms, including passwords and SMS verification codes, are easily obtained or cracked by fraud teams at a low cost. Although facial recognition has a higher defense capability than traditional identity verification methods, it is also vulnerable to being cracked, which leads to account holders facing a great risk of being impersonated.

[0004] Therefore, in order to ensure the safety of account holders' funds, there is an urgent need for a solution that can effectively prevent the risk of fraud. Summary of the Invention

[0005] This application provides a business risk control method, apparatus, device, computer storage medium, and program that can determine the risk of a business based on the dynamic information of the account and device, using an enhanced verification mechanism and focusing on the enhanced verification results. This can accurately identify the risks existing in the business, thereby facilitating the prevention of risky businesses.

[0006] In a first aspect, embodiments of this application provide a business risk control method, applied to a risk control module, the method comprising:

[0007] In response to receiving a business request for a target business from a business module, the first account and the first device corresponding to the target business are determined, wherein the first account is the business initiator account in the target business, and the first device is the device operated by the first account in the target business;

[0008] Determine the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device between the second time and the first time, wherein the first time is the time when the business request is received, and the second time is the time before the first time;

[0009] Determine whether the target business may pose a risk based on account activity information and device activity information;

[0010] In response to the determination that the target business may have risks, an enhanced verification request is sent to the business module so that the business module performs enhanced verification on the target business in accordance with the target enhanced verification method corresponding to the enhanced verification request. The target enhanced verification method includes at least two verification items.

[0011] Receive the enhanced verification result returned by the business module in response to the enhanced verification request;

[0012] The probability of the first account and / or the first device being impersonated is determined based on the enhanced verification results, and the first account and / or the first device are dealt with based on the probability of impersonation.

[0013] As one possible approach, determining whether a target business may pose a risk is based on account dynamic information and device dynamic information, including:

[0014] Obtain a preset risk scoring rule set containing at least one rule, where each rule corresponds to a score;

[0015] Identify target rules that match the risk scoring rule set with account dynamic information and device dynamic information;

[0016] Determine the risk score corresponding to the target business based on the score corresponding to the target rule;

[0017] The risk score is compared with a preset scoring threshold;

[0018] If the risk score exceeds the scoring threshold, it is determined that the target business may pose a risk.

[0019] As one possible implementation, the method also includes the following steps before sending the enhanced verification request to the business module:

[0020] Based on the pre-defined correspondence between risk scores and risk levels, the risk level of the target business is determined according to the risk score corresponding to the target business.

[0021] Based on the pre-defined correspondence between risk levels and enhanced verification methods, the enhanced verification method corresponding to the risk level of the target business is taken as the target enhanced verification method;

[0022] Generate an enhanced verification request corresponding to the target enhanced verification method.

[0023] As one possible implementation, determining the probability of the first account being impersonated based on the enhanced verification result includes:

[0024] Based on the enhanced verification results, determine the enhanced verification score corresponding to the first account in the target business;

[0025] The first cumulative enhanced verification score of the first account between the second time point and the first time point is determined based on the enhanced verification score.

[0026] Determine the first cumulative number of enhanced verifications for the first account between the second and first time points;

[0027] Determine the first deviation value between the first cumulative augmentation verification count and the first cumulative augmentation verification score;

[0028] In response to a first deviation value exceeding a preset first deviation value threshold, the first account is marked as a high-risk account with a high probability of risk.

[0029] As one possible implementation, the first account can be dealt with based on risk probability, including:

[0030] In response to marking the first account as a high-risk account with a high probability of risk, a first control instruction is sent to the business module. The first control instruction is used to instruct the first account to refuse to initiate business requests again within a first time period.

[0031] As one possible implementation, the first account can be dealt with based on risk probability, including:

[0032] In response to marking the first account as a high-risk account with a high probability of risk, the first account is sent to the customer service representative so that the customer service representative can investigate the reason why the enhanced verification failed for the user associated with the first account.

[0033] In response to receiving a correction message from a customer agent who has determined that the reason given by the user for failing enhanced verification is reasonable, the high-risk account label for the first account is removed.

[0034] As one possible implementation, the probability of the first device being spoofed is determined based on the enhanced verification results, including:

[0035] Based on the enhanced verification results, determine the enhanced verification score corresponding to the first device in the target service;

[0036] The second cumulative enhanced verification score of the first device between the second time point and the first time point is determined based on the enhanced verification score.

[0037] Determine the second cumulative enhanced verification count of the first device between the second time point and the first time point;

[0038] Determine the second deviation value between the second cumulative augmentation verification count and the second cumulative augmentation verification score;

[0039] In response to a second deviation value being greater than a preset second deviation value threshold, the first device is marked as a high-risk device with a high probability of risk.

[0040] As one possible implementation, the first device is disposed of based on risk probability, including:

[0041] In response to marking the first device as a high-risk device with a high probability of risk, a second control instruction is sent to the service module. The second control instruction is used to instruct the first device to refuse to initiate a service request again within a second time period.

[0042] Secondly, this application also provides a business risk control device for use in a risk control module, the device comprising:

[0043] The static information determination unit is used to determine the first account and the first device corresponding to the target service in response to receiving a service request for the target service sent by the service module. The first account is the service initiator account in the target service, and the first device is the device operated by the first account in the target service.

[0044] The dynamic information determination unit is used to determine the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device between the second time and the first time, wherein the first time is the time when the business request is received, and the second time is the time before the first time;

[0045] The risk prediction unit is used to determine whether there may be risks in the target business based on account dynamic information and device dynamic information.

[0046] An enhanced verification unit is used to send an enhanced verification request to a business module in response to the determination that a target business may have a risk, so that the business module performs enhanced verification on the target business according to the target enhanced verification method corresponding to the enhanced verification request, wherein the target enhanced verification method includes at least two verification items;

[0047] The verification result receiving unit is used to receive the enhanced verification result returned by the business module in response to the enhanced verification request;

[0048] The risk assessment unit is used to determine the probability of the first account and / or the first device being impersonated based on the enhanced verification result.

[0049] The disposal unit is used to dispose of the first account and / or the first device based on the risk probability.

[0050] Thirdly, embodiments of this application also provide an electronic device, the device comprising: a processor and a memory storing computer program instructions;

[0051] When the processor executes the computer program instructions, it implements the business risk control method as described in the first aspect.

[0052] Fourthly, an embodiment of the present application further provides a computer-readable storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the business risk control method described in the first aspect is implemented.

[0053] Fifthly, an embodiment of the present application further provides a computer program product. When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device is caused to execute the business risk control method described in the first aspect.

[0054] For a business risk control method, device, equipment, computer storage medium and program provided by an embodiment of the present application, after a risk control module receives a business request of a target business sent by a business module, a first account and a first device corresponding to the target business are determined, and between a second moment and a first moment, account dynamic information corresponding to the first account and device dynamic information corresponding to the first device are determined. Whether the target business may have a risk is determined according to the account dynamic information and the device dynamic information. In the case where it is determined that the target business may have a risk, the business module is requested to perform enhanced verification on the target business using at least two verification items, the risk probability that the first account and / or the first device is counterfeited is determined according to the enhanced verification result, and the first account and / or the first device is disposed of based on the risk probability. According to the embodiment of the present application, whether the target business may have a risk is determined from two dimensions according to the account dynamic information and the device dynamic information, which is more accurate, and the counterfeiting difficulty is increased by using the enhanced verification result and subsequent linkage disposal means. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced below. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.

[0056] Figure 1 is a framework diagram of an application scenario provided by an embodiment of the present application;

[0057] Figure 2 is a schematic flowchart of a business risk control method provided by an embodiment of the present application;

[0058] Figure 3 is a schematic flowchart of a risk determination process for a first account provided by an embodiment of the present application;

[0059] Figure 4 is a schematic flowchart of a risk determination process for a first device provided by an embodiment of the present application;

[0060] Figure 5 is a schematic structural diagram of a business risk control device provided by an embodiment of the present application;

[0061] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0062] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.

[0063] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.

[0064] With the continuous development of digital transformation, mobile payment is being used more and more widely. Mobile payment refers to a service method in which users use mobile phones and other terminal devices to pay for goods or services. Mobile payment is typically implemented based on various financial applications on these devices. To ensure the security of users' account funds, these financial applications usually require user identity verification. Biometric technology, including facial recognition, has become a crucial verification method in various financial applications. Applications typically use facial recognition to verify users in specific business scenarios such as account opening, login, fund transfer, payment, and activation of business permissions.

[0065] While facial recognition verification offers greater protection compared to traditional methods like passwords and SMS verification codes, the industrialization of the internet black market means that some criminals can obtain user photos and use related technologies to impersonate users for facial liveness detection and verification. This exposes users to significant risks of impersonation, which could potentially lead to financial losses.

[0066] In view of this, this application provides a business risk control method that can identify risks of a business transaction based on the contextual operating environment information of the account and device corresponding to the transaction, combined with enhanced verification, thereby ensuring the safety of users' funds.

[0067] The business risk control method provided in this application embodiment can be applied to mobile payment scenarios.

[0068] See Figure 1 This is a framework diagram of a mobile payment application scenario provided in an embodiment of this application, such as... Figure 1 As shown, the system mainly includes a business module 100 and a risk control module 110. Communication is possible between the business module 100 and the risk control module 110, as well as between the risk control module 110 and the customer service agent 120. The business module 100 primarily provides users with services such as login, card binding, payment, and fund transfer. The risk control module is mainly used for risk identification of transactions initiated by the business module 100.

[0069] See Figure 2 This is a flowchart illustrating a business risk control method provided in an embodiment of this application, such as... Figure 2 As shown in the embodiments of this application, the business risk control method mainly includes the following steps:

[0070] S21. The business module sends a business request for the target business to the risk control module;

[0071] S22. The risk control module responds to the business request and determines the first account and the first device corresponding to the target business, wherein the first account is the business initiator account in the target business, and the first device is the device operated by the first account in the target business;

[0072] S23. The risk control module determines the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device between the second time and the first time, wherein the first time is the time when the business request is received, and the second time is the time before the first time;

[0073] S24. The risk control module determines whether the target business may pose a risk based on account dynamic information and device dynamic information;

[0074] S25. In response to the potential risks in the target business, the risk control module sends an enhanced verification request to the business module;

[0075] S26. The business module performs enhanced verification on the target business according to the target enhanced verification method corresponding to the enhanced verification request, wherein the target enhanced verification method includes at least two verification items;

[0076] S27. The risk control module receives the enhanced verification result returned by the service module in response to the enhanced verification request;

[0077] S28. The risk control module determines the risk probability that the first account and / or the first device is counterfeited according to the enhanced verification result, and disposes of the first account and / or the first device based on the risk probability.

[0078] Among them, the target service can be services such as account opening, login, transfer, payment, opening service permissions, etc.

[0079] The second moment and the first moment are included between the second moment and the first moment.

[0080] A service risk control method provided by an embodiment of the present application. After the risk control module receives the service request of the target service sent by the service module, it determines the first account and the first device corresponding to the target service, and determines the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device between the second moment and the first moment. It determines whether the target service may have risks according to the account dynamic information and the device dynamic information. When it is determined that the target service may have risks, it requests the service module to use at least two verification items to perform enhanced verification on the target service, determines the risk probability that the first account and / or the first device is counterfeited according to the enhanced verification result, and disposes of the first account and / or the first device based on the risk probability. According to the embodiment of the present application, it is determined whether the target service may have risks from two dimensions according to the account dynamic information and the device dynamic information, which is more accurate, and the difficulty of counterfeiting is increased by using the enhanced verification result and subsequent linkage disposal means.

[0081] In some embodiments, each time the user initiates a service in the service module, the service module can input service information related to the service into the risk control module, and the risk control module can record this service information. Thus, in S23, the risk control module can determine the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device according to the service information input by the service module between the second moment and the first moment. The time span between the second moment and the first moment can be represented by T, and the value of T can be set according to specific situations. For example, it can be 1 hour, 1 day, 1 month, etc.

[0082] As an example, the service information may include the account information of the service initiator, the registration time of the service initiator's account, the information of the device operated by the service initiator's account in the service, the geographical information corresponding to the service initiation, etc. In addition to the above information, for some specific services, some specific information may also be included. For example, for transaction services, the service information may also include the service responder information, the transaction amount, etc.

[0083] In S23, the risk control module can perform quantitative calculations on the business information between the second time and the first time, thereby determining the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device.

[0084] The account activity information corresponding to the first account information may include one or more of the following:

[0085] Number of devices associated with the first account from the second moment to the first moment The trading intensity of the first account from the second moment to the first moment, as shown by the number of transactions. Did the first account switch spaces between the second and first moments? etc. Among them, devices associated with the account are those that the account has operated on, and switching locations refers to changes in the corresponding geographical information.

[0086] The device dynamic information corresponding to the first device may include: the number of accounts associated with the first device from the second moment to the first moment. Among them, the accounts associated with the device are those that have operated the device.

[0087] As an example, a profile tagging engine can be set up in the risk control module to perform real-time updates and calculations on the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device.

[0088] The account dynamics information corresponding to the first account and the device dynamics information corresponding to the first device can reflect the dynamic changes of the first account and the first device within a time span T. When the applicant discovers that there is a risk to the account and / or device, there will usually be some patterns in their dynamic changes within a time span T. For example, the account will frequently be associated with different devices, the device will frequently be associated with different accounts, the geographical location of the account will frequently change, the number of transactions will increase significantly, etc. Therefore, based on the account dynamics information corresponding to the first account and the device dynamics information corresponding to the first device, it is possible to make a preliminary judgment on whether the account and / or device in the target transaction may be at risk, that is, to determine whether the target transaction may be at risk.

[0089] In some embodiments, when the risk control module determines whether a target transaction may pose a risk based on the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device in S24, it may perform the following steps:

[0090] Obtain a preset risk scoring rule set containing at least one rule, where each rule corresponds to a score;

[0091] Identify target rules that match the risk scoring rule set with account dynamic information and device dynamic information;

[0092] Determine the risk score corresponding to the target business based on the score corresponding to the target rule;

[0093] The risk score is compared with a preset scoring threshold;

[0094] If the risk score exceeds the scoring threshold, it is determined that the target business may pose a risk.

[0095] The risk scoring rule set can be set based on account dynamic information and device dynamic information, according to the actual situation.

[0096] As an example, a risk scoring rule set may include one or more of the following rules:

[0097] An account receives a score of 60 if the number of devices associated with it within a time span T exceeds the first threshold; a score of 60 if the number of accounts associated with a device within a time span T exceeds the second threshold; a score of 30 if the account switches locations within a time span T; a score of 60 if the number of transactions an account makes within a time span T exceeds the third threshold; and a score of 90 if the number of devices associated with an account within a time span T exceeds both the first and second thresholds.

[0098] As an example, determining the risk score for a target business based on the score corresponding to the target rule can include:

[0099] If no target rule exists, the risk score corresponding to the target business can be set to 0;

[0100] If there is only one target rule, the score corresponding to the target rule can be used as the risk score corresponding to the target business.

[0101] If there are multiple target rules, the sum or maximum value of the scores of the multiple target rules can be used as the risk score corresponding to the target business.

[0102] Generally, the higher the risk score of a business, the greater the likelihood that the business is at risk. Therefore, a scoring threshold can be set in advance based on the actual situation. After determining the risk score of the target business, the risk score of the target business is compared with the scoring threshold. If the risk score of the target business is greater than the scoring threshold, it is determined that the target business may be at risk. If the risk score of the target business is not greater than the scoring threshold, it is determined that the target business is not at risk.

[0103] The above method determines the risk score of the target business based on risk scoring rules, and then determines whether the target business may have risks based on the risk score and scoring threshold. It has the advantage of being easy to implement, and the risk scoring rules and scoring thresholds can be set according to the actual situation. Thus, the above method is more adaptable and can be applied to different business scenarios.

[0104] In some embodiments, in response to the possibility that the target service may be at risk, enhanced verification of the target service can be performed by executing S25-S28 to further determine whether the target service is indeed at risk.

[0105] Before executing S25, you can first determine the target enhancement verification method to be used for enhancing the target service.

[0106] As an example, a default enhanced verification method can be preset. When enhanced verification is required, this default enhanced verification method is used as the target enhanced verification method. The verification items included in the default enhanced verification method can be set according to actual needs. For example, the verification items can be password (PWD) + SMS verification code (SMS), password (PWD) + face verification (FACE), or SMS verification code (SMS) + face verification (FACE), etc.

[0107] This method allows for the rapid identification of target enhancement verification methods, and is highly efficient.

[0108] As an example, the following steps can also be used to determine the target enhancement verification method:

[0109] Based on the pre-defined correspondence between risk scores and risk levels, the risk level of the target business is determined according to the risk score corresponding to the target business.

[0110] Based on the pre-defined correspondence between risk levels and enhanced verification methods, the enhanced verification method corresponding to the risk level of the target business is taken as the target enhanced verification method;

[0111] Generate an enhanced verification request corresponding to the target enhanced verification method.

[0112] Based on the principle that the higher the risk score, the greater the possibility of risk in the business, a correspondence between risk scores and risk levels can be established in advance. The risk levels can be divided into three levels: high, medium, and low. Each risk level can correspond to a risk score range. In this way, after determining that the target business may have risks, the risk score range of the risk score attribute corresponding to the target business can be determined, and the risk level corresponding to the range can be used as the risk level of the target business.

[0113] Enhanced verification methods are pre-defined according to the actual situation for each risk level, with higher risk levels requiring more complex methods to be compromised. For example, a high-risk level might use SMS verification code + facial recognition (FACE), a medium-risk level might use password (PWD) + facial recognition (FACE), and a low-risk level might use password (PWD) + SMS verification code. Therefore, if the target service is determined to be high-risk, then SMS verification code + facial recognition (FACE) will be the target enhanced verification method.

[0114] In this way, the target business can be verified in a tiered manner based on risk level. Different levels of enhanced verification methods with varying degrees of difficulty are used for different risk levels. The higher the risk level, the more difficult it is to break the enhanced verification method. This increases the difficulty of counterfeiting and effectively prevents counterfeiting, thereby ensuring the safety of users' funds.

[0115] After determining the target enhanced verification method, the risk control module can generate an enhanced verification request corresponding to the target enhanced verification method and send the enhanced verification request to the business module. After receiving the enhanced verification request, the business module can perform enhanced verification on the target business by executing S26.

[0116] In some embodiments, the specific implementation of S26 may include:

[0117] The business module parses the received enhanced verification request to determine the target enhanced verification method corresponding to the enhanced verification request, and then verifies the business initiator of the target business by calling the verification module corresponding to the verification items contained in the target enhanced verification method.

[0118] For example, if the target-enhanced verification method includes facial verification and SMS verification code verification, the business module can turn on the camera to perform facial verification on the business initiator of the target business, and send a verification code to the mobile phone number associated with the first account for SMS verification code verification.

[0119] When the business module verifies the business initiator, it can generate a corresponding verification result for each verification item. The verification result indicates whether the verification failed or passed. Verification failure and failure to perform verification (i.e., abandoning verification) are both considered as verification failure. The verification results of all verification items included in the target verification method are used as the enhanced verification result corresponding to the target business, and this enhanced verification result is returned to the risk control module.

[0120] In some embodiments, after receiving the enhanced verification result of the target business returned by the business module, the risk control module can determine the risk probability of the first account and / or the first device being impersonated based on the enhanced verification result in S28, and take action on the first account and / or the first device based on the risk probability, so as to conduct dual intervention on the subsequent behavior of the risky account and the risky device, thereby improving the accuracy of impersonation fraud identification and the efficiency of risk prevention and control.

[0121] In some embodiments, such as Figure 3 As shown, the specific implementation method of the risk control module in S28 determining the risk probability of the first account being impersonated based on the enhanced verification results may include the following steps:

[0122] S31. Based on the enhanced verification results, determine the enhanced verification score corresponding to the first account in the target business;

[0123] S32. Determine the first cumulative enhanced verification score of the first account between the second time point and the first time point based on the enhanced verification score corresponding to the first account in the target business;

[0124] S33. Determine the first cumulative enhanced verification count for the first account between the second time point and the first time point;

[0125] S34. Determine the first deviation value between the first cumulative augmented verification count and the first cumulative augmented verification score;

[0126] S35. In response to the first deviation value being greater than a preset first deviation value threshold, the first account is marked as a high-risk account with a high risk probability.

[0127] The correspondence between various enhanced verification methods and their corresponding enhanced verification results and scores can be pre-defined. Thus, after obtaining the enhanced verification result corresponding to the target service, the verification score corresponding to that enhanced verification result can be determined in S31 based on this correspondence, and this verification score will be used as the enhanced verification score for the target service of the first account. The enhanced verification score of the first account can be used with S... u,t express.

[0128] As an example, the correspondence between the enhanced verification results and scores for various enhanced verification methods can be shown in Table 1 below:

[0129] Table 1

[0130]

[0131]

[0132] Based on Table 1 above, taking the target enhanced verification method as SMS verification code + face verification as an example, if the enhanced verification result corresponding to the target service is SMS verification successful and face verification fails, then the enhanced verification score of the first account is 0.4.

[0133] In S32, the first cumulative enhanced verification score of the first account between the second time point and the first time point is determined based on the enhanced verification score of the first account. This is the determination of the cumulative enhanced verification score of the first account between the second time point and the first time point.

[0134] As an example, the enhanced verification scores for each service corresponding to the first account between the second and first time points can be summed, and the sum can be used as the first cumulative enhanced verification score for the first account between the second and first time points. The first cumulative enhanced verification score can be represented by unique visitors (UV). s,t It means that UV s,t =∑ t=T S u,t In the formula, t represents time, and T represents the time span between the second moment and the first moment.

[0135] In S33, the cumulative number of enhanced verifications performed by the first account as the business initiator account between the second time point and the first time point can be determined, and this cumulative number is used as the first cumulative enhanced verification count. The first cumulative enhanced verification count can be represented by UV (unique visitors). t It means that UV t =∑ t∈T u, where u represents the number of times the first account has enhanced verification.

[0136] After obtaining UV s,t and UV t Next, calculate UV. t With UV s,t The deviation value is taken as the first deviation value. The first deviation value is compared with the preset first deviation value threshold. If it is determined that the first deviation value is greater than the first deviation value threshold, the first account is marked as a high-risk account. The first deviation threshold can be set according to the actual situation.

[0137] Because when performing enhanced verification on the first account, only if all verification items in the enhanced verification method pass the verification will the enhanced verification score for the first account be 1, which means the unique visitors (UV) for the first account will be 1. s,t It will only add 1 if it does, otherwise it will be less than 1, which is the UV value. s,t Add a value less than 1, and for each enhanced verification performed by the first account, regardless of the verification result, the UV (unique visitors) will increase. t The UV will increase by 1. This shows that only when all enhanced verifications for the first account between the first and second moments pass will the UV increase. s,tOnly then will it be with UV t If they are equal, that is, the first deviation value is 0; otherwise, UV s,t It will be less than UV t In other words, the first deviation value is greater than 0, and the larger the first deviation value, the higher the degree to which the first account is operated by someone other than the user, which means the higher the probability that the first account is at risk. Therefore, when the first deviation value is greater than the first deviation threshold, it can be determined that the first account is at high risk and the first account is marked as a high-risk account.

[0138] Based on the idea that fraudsters have time costs and leave abnormal traces when attacking accounts, the above method is used to reverse-judge the probability of an account being suspicious based on the behavioral data of the account between the second and first moments, thereby identifying high-risk accounts.

[0139] In some embodiments, to reduce frequent operations by high-risk accounts and mitigate the adverse effects of business requests made by high-risk accounts, after marking a first account as a high-risk account, the risk control module can take action on the first account, which may include:

[0140] Send a first control instruction to the business module. The first control instruction is used to indicate that the first account should not initiate a business request again within the first time period.

[0141] By restricting the first account from initiating business requests again within a certain time period through the first control command, that is, by controlling the first account, fraudsters can effectively prevent the first account from using it to commit fraud.

[0142] In some embodiments, the first duration can be determined as follows:

[0143] The first deviation value, the account dynamic information corresponding to the first account, and / or the device dynamic information corresponding to the first device are linearly normalized and then added together to obtain the first sum value, which is used as the first time length.

[0144] For example, the first time length can be calculated using the following formula:

[0145]

[0146] In the formula, R u This indicates the first time length, and Normal() represents the normalization function.

[0147] The normalization function can be set according to the actual situation. Normalization is performed because there may be differences in units between the first deviation value, account dynamic information, and device dynamic information. For example... The range of values ​​for is natural numbers, while Because it indicates whether the first account has switched spaces, its value is either 0 or 1, where 0 represents no and 1 represents yes. Therefore, the two have different dimensions. The purpose of linear normalization is to eliminate the influence of differences in physical quantity values ​​and dimensions, establish a unified scale for all physical quantities, and consider the variation patterns of experimental data within this scale.

[0148] By using the above method, the first time length is determined based on the first deviation value, account dynamic information, and device dynamic information, which enables adaptive adjustment of the control duration for different accounts.

[0149] In some embodiments, to further improve the accuracy of high-risk labeling, self-correction can be performed after the first account is labeled as a high-risk account, so as to prevent accounts that do not pose a risk from being labeled as high-risk accounts.

[0150] As an example, the risk module can communicate with customer service agents. Based on this, the self-correction of the risk control module can include taking the following actions against the first account:

[0151] Send the first account to the customer service representative so that the representative can investigate the reason why the enhanced verification failed for the user associated with the first account.

[0152] In response to receiving a correction message from a customer agent who has determined that the reason given by the user for failing enhanced verification is reasonable, the high-risk account label for the first account is removed.

[0153] When a customer service representative investigates why enhanced verification failed for a user associated with the first account, they can call the user using the number associated with the first account and ask if the user initiated the corresponding business request. If so, they can then verify the reason for the previous enhanced verification failure. If the customer service representative confirms that the reason given by the user is reasonable, they can send corrective information back to the risk control module to notify the risk control module to remove the high-risk account label from the first account.

[0154] Furthermore, the interaction time between the risk control module and customer service agents can be controlled within a third time period to ensure the timeliness of risk identification and self-correction. The third time period can be set according to the actual situation.

[0155] The self-correction mechanism described above can prevent accounts that do not pose a risk from being marked as high-risk accounts, thus improving the accuracy of risk account marking.

[0156] The above describes the process of risk assessment for the first account based on the enhanced verification results. The following describes the process of risk assessment for the first device based on the enhanced verification results.

[0157] In some embodiments, such as Figure 4As shown, the specific implementation method of the risk control module in S28 determining the risk probability of the first device being counterfeited based on the enhanced verification results may include the following steps:

[0158] S41. Based on the enhanced verification results, determine the enhanced verification score corresponding to the first device in the target service;

[0159] S42. Determine the second cumulative enhanced verification score of the first device between the second time and the first time based on the enhanced verification score corresponding to the first device in the target service;

[0160] S43. Determine the second cumulative enhanced verification count of the first device between the second time point and the first time point;

[0161] S44. Determine the second deviation value between the second cumulative augmented verification count and the second cumulative augmented verification score;

[0162] S45. In response to the second deviation value being greater than a preset second deviation value threshold, the first device is marked as a high-risk device with a high risk probability.

[0163] In this context, the enhanced verification scores corresponding to the first account and the first device in the target service are the same; both are verification scores corresponding to the enhanced verification results. Therefore, the method for determining the enhanced verification score corresponding to the first device in the target service in S41 can be found in the description of S31, and will not be repeated here. The enhanced verification score of the first device can be represented by S... d,t express.

[0164] Similarly, the implementation of S42-S45 is similar to that of S32-S35.

[0165] In S42, the enhanced verification scores corresponding to each service of the first device between the second time point and the first time point can be summed, and the sum is used as the second cumulative enhanced verification score of the first device between the second time point and the first time point. The second cumulative enhanced verification score can be represented by DV. s,t It indicates that DV s,t =∑ t=T S d,t .

[0166] In S43, the cumulative number of enhanced verifications performed by the device acting as the service initiator account between the second and first time points can be determined, and this cumulative number is used as the second cumulative enhanced verification count. The second cumulative enhanced verification count can be represented by a DV (Digital Video Recorder). t It indicates that DV t =∑ t∈T d, where d represents the number of enhanced verifications for the first device.

[0167] After obtaining DV tand DV s,t Next, calculate DV. t With DV s,t The deviation value is used as the second deviation value. The second deviation value is compared with the preset second deviation value threshold. If it is determined that the second deviation value is greater than the second deviation value threshold, the first device is marked as a high-risk account. The second deviation threshold can be set according to the actual situation.

[0168] Similar to the principle of risk assessment for the first account, only when all enhanced verifications of the first device between the second and first moments pass can the DV be considered safe. s,t Only then will it be with DV t If they are equal, that is, the second deviation value is 0; otherwise, DV s,t It will be smaller than DV t That is, the second deviation value is greater than 0, and the larger the second deviation value is, the higher the degree to which the first device is operated by someone other than the user, which means the higher the probability that the first device is at risk. Therefore, when the second deviation value is greater than the second deviation threshold, it can be determined that the first device is at high risk and the first device is marked as a high-risk device.

[0169] Based on the idea that fraudsters have time costs and leave abnormal traces when attacking devices, the above method is used to reverse-judge the probability of a device's suspiciousness based on the behavioral data of the device between the second and first moments, thereby identifying high-risk devices.

[0170] In some embodiments, in order to reduce the frequent operation of high-risk devices and mitigate the adverse effects caused by high-risk devices making business requests, after marking the first device as a high-risk device, the risk control module may take the following actions on the first device:

[0171] A second control instruction is sent to the service module. The second control instruction is used to instruct the first device to reject any further service requests within a second time period.

[0172] Specifically, "refusing the first device to initiate a service request again within the second time period" means refusing all accounts on the first device to initiate a service request again within the second time period, which is equivalent to controlling suspected risky behaviors of other user accounts on the same device.

[0173] By restricting the first device from initiating business requests again within a second time period through the second control command, that is, by controlling the first device, fraudsters can effectively prevent the first device from using it to commit fraud.

[0174] In some embodiments, the second duration can be determined as follows:

[0175] The second deviation value, the account dynamic information corresponding to the first account, and / or the device dynamic information corresponding to the first device are linearly normalized and then added together to obtain the second sum value, which is used as the second time length.

[0176] For example, the first time length can be calculated using the following formula:

[0177]

[0178] In the formula, R d This indicates the second time duration.

[0179] By using the above method, the first time length is determined based on the first deviation value, account dynamic information, and device dynamic information, which enables adaptive adjustment of the control duration for different accounts.

[0180] In some embodiments, after the first time period expires, the risk control module removes the high-risk account label from the first account, and after the second time period expires, the risk control module removes the high-risk device label from the first device. Furthermore, the risk control module can handle all factors, including t and UV. t UV s,t DV t DV s,t R u R d Reinitialize, and then proceed to the next decision loop.

[0181] It should be noted that the timeliness requirement for a single business request in both the business module and the risk control module is at the millisecond level. While multiple user accounts may initiate business requests and participate in enhanced verification, different business requests can coexist in parallel from a temporal perspective. However, in the case of the same account and device, the control of high-risk accounts and devices, and the reinitialization of all factors, are sequential until the control period expires or a notification to lift control is triggered.

[0182] In some embodiments, after receiving the enhanced verification result of the target business returned by the business module, the risk control module can also determine whether the target business has any risk based on the enhanced verification result. Specifically, it determines whether each verification item passes the verification based on the enhanced verification result. If it is determined that any verification item fails or is abandoned, it can be determined that the target business has a risk. If it is determined that all verification items pass the verification, it can be determined that the target business has no risk.

[0183] By using the above methods, when there is a potential risk to the target business, at least two verification items can be used to enhance the verification of the target business, thereby increasing the difficulty of the verification being breached. If the enhanced verification cannot be breached, when a fake user attempts to verify, the verification will fail or be abandoned. Based on this, the impersonation risk of the target business can be effectively identified according to the enhanced verification results.

[0184] In some embodiments, if it is determined that there is no risk to the target business, the business can be processed normally.

[0185] In some embodiments, if it is determined that there is a risk in the target business, the target business can be terminated to prevent adverse effects from continuing to process the business under risky conditions.

[0186] The following example illustrates the business risk control method provided in this application embodiment.

[0187] Suppose account C1 logs into device D1 and initiates 10 transaction requests in the business module within one day, while only one account, C1, is logged into D1 on that day. The risk control module will then evaluate these 10 transaction requests and determine that they are all suspected of being made by someone else. For each request, the module will return an enhanced verification method (password + facial recognition) to the business module, i.e., UV (unique visitors). t =10, DV t =10. If each enhanced verification fails, the verification score for each transaction recorded in Table 1 is 0. Therefore, the risk control module records the cumulative verification score for C1 and D1 for that day as 0, i.e., UV. s,t =0, DV s,t =0. Because the verification of C1 and D1 failed multiple times, the UV index decreased. t -UV t,t The first deviation value and DV obtained t -DV s,t If the obtained second deviation values ​​all exceed their respective thresholds, the risk control module will mark C1 as a high-risk account and D1 as a high-risk device, and will block subsequent transactions of C1 and D1. Control will be lifted only after the blocking time window expires or the account holder confirms a reasonable reason for the verification failure through manual outbound calling.

[0188] This application provides a business risk control method that combines multiple dimensions of the user account's environment, including device, space, and time sequence. It focuses on enhanced verification, including the frequency of facial verification and the feedback of verification results, to determine the risk probability of the account and the risk probability of the device on which the account is located. This allows for dual intervention in the subsequent behavior of risky accounts and risky devices, improving the accuracy of identifying fraudulent activities and the efficiency of risk prevention. Based on the business risk control method provided in the above embodiments, this application also provides specific implementation methods for a business risk control device. Please refer to the following embodiments.

[0189] See Figure 5 The business risk control device provided in this application embodiment may include the following units:

[0190] The static information determination unit 501 is used to determine the first account and the first device corresponding to the target service in response to receiving a service request for the target service sent by the service module. The first account is the service initiator account in the target service, and the first device is the device operated by the first account in the target service.

[0191] The dynamic information determination unit 502 is used to determine the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device between the second time and the first time, wherein the first time is the time when the service request is received, and the second time is the time before the first time;

[0192] Risk prediction unit 503 is used to determine whether the target business may be at risk based on account dynamic information and device dynamic information;

[0193] The enhanced verification unit 504 is used to send an enhanced verification request to the business module in response to determining that the target business may have risks, so that the business module performs enhanced verification on the target business according to the target enhanced verification method corresponding to the enhanced verification request, wherein the target enhanced verification method includes at least two verification items;

[0194] The verification result receiving unit 505 is used to receive the enhanced verification result returned by the business module in response to the enhanced verification request;

[0195] Risk assessment unit 506 is used to determine the probability of the first account and / or the first device being impersonated based on the enhanced verification results.

[0196] Disposal unit 507 disposes of the first account and / or the first device based on the risk probability.

[0197] A service risk control device provided by an embodiment of the present application. After the risk control module receives a service request for a target service sent by the service module, it determines a first account and a first device corresponding to the target service, and determines the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device between a second moment and a first moment. It determines whether the target service may have a risk according to the account dynamic information and the device dynamic information. In the case where it is determined that the target service may have a risk, it requests the service module to perform enhanced verification on the target service using at least two verification items, and determines the risk probability that the first account and / or the first device is counterfeited according to the enhanced verification result, so as to dispose of the first account and / or the first device based on the risk probability. According to the embodiment of the present application, it determines whether the target service may have a risk from two dimensions according to the account dynamic information and the device dynamic information, which is more accurate. Using the enhanced verification result and subsequent linkage disposal means improves the difficulty of counterfeiting and ensures the user's fund safety.

[0198] In some embodiments, the risk prediction unit 503 is specifically configured to:

[0199] Obtain a preset risk scoring rule set including at least one rule, where each rule corresponds to a score respectively;

[0200] Determine a target rule in the risk scoring rule set that matches the account dynamic information and the device dynamic information;

[0201] Determine the risk score corresponding to the target service according to the score corresponding to the target rule;

[0202] Compare the risk score with a preset score threshold;

[0203] In response to the risk score being greater than the score threshold, determine that the target service may have a risk.

[0204] In some embodiments, the device may further include: an enhanced verification request generation unit, specifically configured to:

[0205] Before sending an enhanced verification request to the service module, determine the risk level of the target service according to the risk score corresponding to the target service based on the preset correspondence between the risk score and the risk level;

[0206] Based on the preset correspondence between the risk level and the enhanced verification method, use the enhanced verification method corresponding to the risk level of the target service as the target enhanced verification method;

[0207] Generate an enhanced verification request corresponding to the target enhanced verification method.

[0208] In some embodiments, the risk determination unit 506 is specifically configured to: [[ID=三十五]]

[0209] Based on the enhanced verification results, determine the enhanced verification score corresponding to the first account in the target business;

[0210] The first cumulative enhanced verification score of the first account between the second time point and the first time point is determined based on the enhanced verification score.

[0211] Determine the first cumulative number of enhanced verifications for the first account between the second and first time points;

[0212] Determine the first deviation value between the first cumulative augmentation verification count and the first cumulative augmentation verification score;

[0213] In response to a first deviation value exceeding a preset first deviation value threshold, the first account is marked as a high-risk account.

[0214] In some embodiments, the processing unit 507 is specifically used for:

[0215] In response to marking the first account as a high-risk account with a high probability of risk, a first control instruction is sent to the business module. The first control instruction is used to instruct the first account to refuse to initiate business requests again within a first time period.

[0216] In some embodiments, the processing unit 507 is specifically used for:

[0217] In response to marking the first account as a high-risk account with a high probability of risk, the first account is sent to the customer service representative so that the customer service representative can investigate the reason why the enhanced verification failed for the user associated with the first account.

[0218] In response to receiving a correction message from a customer agent who has determined that the reason given by the user for failing enhanced verification is reasonable, the high-risk account label for the first account is removed.

[0219] In some embodiments, the risk determination unit 506 is specifically used for:

[0220] Based on the enhanced verification results, determine the enhanced verification score corresponding to the first device in the target service;

[0221] The second cumulative enhanced verification score of the first device between the second time point and the first time point is determined based on the enhanced verification score.

[0222] Determine the second cumulative enhanced verification count of the first device between the second time point and the first time point;

[0223] Determine the second deviation value between the second cumulative augmentation verification count and the second cumulative augmentation verification score;

[0224] In response to a second deviation value being greater than a preset second deviation value threshold, the first device is marked as a high-risk device with a high probability of risk.

[0225] In some embodiments, the processing unit 507 is specifically used for:

[0226] In response to marking the first device as a high-risk device with a high probability of risk, a second control instruction is sent to the service module. The second control instruction is used to instruct the first device to refuse to initiate a service request again within a second time period.

[0227] The business risk control device provided in this application embodiment can realize the various processes implemented in the above-described business risk control method embodiment. To avoid repetition, it will not be described again here.

[0228] Figure 6 A schematic diagram of the hardware structure of the electronic device provided in an embodiment of this application is shown.

[0229] The electronic device may include a processor 601 and a memory 602 storing computer program instructions.

[0230] Specifically, the processor 601 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.

[0231] Memory 602 may include mass storage for data or instructions. For example, and not limitingly, memory 602 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 602 may include removable or non-removable (or fixed) media. Where appropriate, memory 602 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 602 is non-volatile solid-state memory.

[0232] Memory 602 may include read-only memory (ROM), random access memory (RAM), disk storage media device, optical storage media device, flash memory device, electrical, optical, or other physical / tangible memory storage device. Therefore, typically, memory 602 includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it can perform the operations described in any of the business risk control methods in the above embodiments.

[0233] The processor 601 reads and executes computer program instructions stored in the memory 602 to implement any of the business risk control methods in the above embodiments.

[0234] In one example, the electronic device may also include a communication interface 603 and a bus 610. For example, Figure 6 As shown, the processor 601, memory 602, and communication interface 603 are connected through bus 610 and complete communication with each other.

[0235] The communication interface 603 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0236] Bus 610 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 610 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.

[0237] Furthermore, in conjunction with the XX method in the above embodiments, this application embodiment can provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the business risk control methods in the above embodiments.

[0238] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.

[0239] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.

[0240] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0241] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0242] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.

Claims

1. A business risk control method, characterized in that, Applied to a risk control module, the method includes: In response to receiving a service request for a target service sent by a service module, the first account and the first device corresponding to the target service are determined, wherein the first account is the service initiator account in the target service, and the first device is the device operated by the first account in the target service; Determine the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device between the second time and the first time, wherein the first time is the time when the service request is received, and the second time is the time before the first time; Based on the account dynamic information and the device dynamic information, determine whether the target service may be at risk; In response to determining that the target service may have a risk, an enhanced verification request is sent to the service module so that the service module performs enhanced verification on the target service according to the target enhanced verification method corresponding to the enhanced verification request, wherein the target enhanced verification method includes at least two verification items; Receive the enhanced verification result returned by the service module in response to the enhanced verification request; The probability of the first account and / or the first device being impersonated is determined based on the enhanced verification result, and the first account and / or the first device is dealt with based on the probability of the impersonation. The step of determining the probability of the first account being impersonated based on the enhanced verification result includes: Based on the enhanced verification results, determine the enhanced verification score corresponding to the first account in the target service; The first cumulative enhanced verification score of the first account between the second time and the first time is determined based on the enhanced verification score. The first cumulative enhanced verification score is the sum of the enhanced verification scores of the first account between the second time and the first time. Determine the first cumulative number of enhanced verifications for the first account between the second time point and the first time point; Determine a first deviation value between the first cumulative augmented verification count and the first cumulative augmented verification score, wherein the first deviation value is the value obtained by subtracting the first cumulative augmented verification score from the first cumulative augmented verification count; In response to the first deviation value being greater than a preset first deviation value threshold, the first account is marked as a high-risk account with a high probability of risk.

2. The method according to claim 1, characterized in that, The step of determining whether the target service may pose a risk based on the account dynamic information and the device dynamic information includes: Obtain a preset risk scoring rule set containing at least one rule, wherein each rule corresponds to a score; Determine the target rules in the risk scoring rule set that match the account dynamic information and the device dynamic information; The risk score corresponding to the target business is determined based on the score corresponding to the target rule. The risk score is compared with a preset scoring threshold; If the risk score is greater than the score threshold, it is determined that the target business may be at risk.

3. The method according to claim 2, characterized in that, Before sending the enhanced verification request to the business module, the method further includes: Based on the preset correspondence between risk scores and risk levels, the risk level of the target business is determined according to the risk score corresponding to the target business; Based on the preset correspondence between risk levels and enhanced verification methods, the enhanced verification method corresponding to the risk level of the target business is taken as the target enhanced verification method; Generate the enhanced verification request corresponding to the target enhanced verification method.

4. The method according to claim 1, characterized in that, The action taken against the first account based on the risk probability includes: In response to marking the first account as a high-risk account with a high probability of risk, a first control instruction is sent to the business module. The first control instruction is used to indicate that the first account should not initiate a business request again within a first time period.

5. The method according to claim 1, characterized in that, The action taken against the first account based on the risk probability includes: In response to marking the first account as a high-risk account with a high probability of risk, the first account is sent to a customer service representative so that the customer service representative can investigate the reason why the enhanced verification failed to the user associated with the first account. In response to receiving a correction message from the customer service agent after determining that the reason given by the user for failing the enhanced verification is reasonable, the high-risk account label on the first account is removed.

6. The method according to claim 1, characterized in that, Determining the probability of the first device being counterfeited based on the enhanced verification result includes: Based on the enhanced verification results, the enhanced verification score corresponding to the first device in the target service is determined; The second cumulative enhanced verification score of the first device between the second time and the first time is determined based on the enhanced verification score. The second cumulative enhanced verification score is the sum of the enhanced verification scores of the first device between the second time and the first time. Determine the second cumulative number of enhanced verifications performed by the first device between the second time point and the first time point; Determine a second deviation value between the second cumulative augmented verification count and the second cumulative augmented verification score. The second deviation value is the value obtained by subtracting the second cumulative augmented verification score from the second cumulative augmented verification count. In response to the second deviation value being greater than a preset second deviation value threshold, the first device is marked as a high-risk device with a high probability of risk.

7. The method according to claim 6, characterized in that, The handling of the first device based on the risk probability includes: In response to marking the first device as a high-risk device with a high probability of risk, a second control instruction is sent to the service module. The second control instruction is used to indicate that the first device should be rejected from initiating a service request again within a second time period.

8. A business risk control device, characterized in that, The device, applied to a risk control module, includes: A static information determination unit is used to determine a first account and a first device corresponding to the target service in response to receiving a service request for a target service sent by a service module, wherein the first account is the service initiator account in the target service, and the first device is the device operated by the first account in the target service; The dynamic information determination unit is used to determine the account dynamic information corresponding to the first account and the device dynamic information corresponding to the first device between the second time and the first time, wherein the first time is the time when the service request is received, and the second time is the time before the first time; The risk prediction unit is used to determine whether the target business may be at risk based on the account dynamic information and the device dynamic information. An enhanced verification unit is configured to send an enhanced verification request to the service module in response to determining that the target service may have a risk, so that the service module performs enhanced verification on the target service according to the target enhanced verification method corresponding to the enhanced verification request, wherein the target enhanced verification method includes at least two verification items; The verification result receiving unit is used to receive the enhanced verification result returned by the business module in response to the enhanced verification request; The risk assessment unit is used to determine the probability of the first account and / or the first device being impersonated based on the enhanced verification result. A processing unit is configured to process the first account and / or the first device based on the risk probability. The risk assessment unit is specifically used for: Based on the enhanced verification results, determine the enhanced verification score corresponding to the first account in the target service; The first cumulative enhanced verification score of the first account between the second time and the first time is determined based on the enhanced verification score. The first cumulative enhanced verification score is the sum of the enhanced verification scores of the first account between the second time and the first time. Determine the first cumulative number of enhanced verifications for the first account between the second time point and the first time point; Determine a first deviation value between the first cumulative augmented verification count and the first cumulative augmented verification score, wherein the first deviation value is the value obtained by subtracting the first cumulative augmented verification score from the first cumulative augmented verification count; In response to the first deviation value being greater than a preset first deviation value threshold, the first account is marked as a high-risk account with a high probability of risk.

9. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the business risk control method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the business risk control method as described in any one of claims 1-7.

11. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device performs the business risk control method as described in any one of claims 1-7.