Data processing method and apparatus

By using the enterprise's private key and the bank's public key to encrypt transaction messages in the bank-enterprise direct connection front-end machine, the problem of low operational efficiency caused by frequent logins in the bank-enterprise direct connection is solved, and efficient interaction that can send transaction instructions without logging in is achieved.

CN116596647BActive Publication Date: 2026-08-04BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BANK OF CHINA
Filing Date
2023-04-19
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

In direct bank-enterprise interaction, the frequent login and cancellation of bank accounts by enterprises leads to low operational efficiency and affects the user experience.

Method used

When the enterprise bank account is not logged in, the enterprise private key and bank public key stored in the bank-enterprise direct connection front-end machine are used to encrypt the transaction message, generate the encrypted transaction message, and send it to the bank server.

Benefits of technology

It enables the sending of transaction instructions without logging into a bank account, improving operational efficiency and enhancing the user experience for businesses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116596647B_ABST
    Figure CN116596647B_ABST
Patent Text Reader

Abstract

The application provides a data processing method and device, which can be used in the field of network security. The method is applied to a bank-enterprise direct connection front-end machine in a client host, the client host further comprises an enterprise financial system in communication connection with the bank-enterprise direct connection front-end machine, the private key of the enterprise and the public key of the bank are stored in the bank-enterprise direct connection front-end machine, and the method comprises the following steps: in the case that the bank account of the enterprise is not logged in, in response to the current transaction message sent through the enterprise financial system, the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine are called, the current transaction message is encrypted based on the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine, the encrypted current transaction message is obtained, and the encrypted current transaction message is sent to the bank server. The method can realize the login-free of the enterprise, that is, the transaction instruction can be sent to the bank server without logging in the bank account of the enterprise, the operation efficiency of the enterprise is improved, and the use experience of the enterprise is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity and can be applied to the financial sector, particularly to a data processing method and apparatus. Background Technology

[0002] With the development of e-commerce technology, in order to reduce financial costs and improve financial efficiency, more and more enterprises are switching from traditional global wide area network online banking to direct bank-enterprise connections when interacting with banks.

[0003] In the interaction of related technologies for direct bank-enterprise connections, enterprises need to log in to their bank accounts first in order to communicate with the bank's server through the logged-in bank accounts.

[0004] However, the transaction messages sent by a company to the bank's server through its client host are not always continuous. For example, if a company sends its first transaction message to the bank's server through its client host at the first moment of the day, and then sends a second transaction message to the bank's server through its client host at the second moment after an interval of half an hour or even an hour, the bank's server will prompt the company to perform a login operation first. Although this improves security to some extent, it also reduces the company's operational efficiency and brings a bad user experience to the company. Summary of the Invention

[0005] This application provides a data processing method and apparatus to solve the problem of low efficiency caused by repeated logins.

[0006] In a first aspect, this application provides a data processing method, which is applied to a bank-enterprise direct connection front-end machine in a client host. The client host further includes an enterprise financial system communicatively connected to the bank-enterprise direct connection front-end machine, wherein the bank-enterprise direct connection front-end machine stores the enterprise's private key and the bank's public key; the method includes:

[0007] If the enterprise's bank account is not logged in, in response to the current transaction message sent through the enterprise's financial system, the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine are invoked.

[0008] The current transaction message is encrypted based on the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine to obtain the encrypted current transaction message.

[0009] Send the encrypted current transaction message to the bank server.

[0010] In some embodiments, the current transaction message is encrypted based on the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine to obtain an encrypted current transaction message, including:

[0011] The current transaction message is signed using the private key of the enterprise stored in the bank-enterprise direct connection front-end machine to obtain the signed current transaction message.

[0012] The signed current transaction message is encrypted using the bank's public key stored in the bank-enterprise direct connection front-end machine to obtain the encrypted current transaction message.

[0013] In some embodiments, the current transaction message is encrypted based on the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine to obtain an encrypted current transaction message, including:

[0014] The current transaction message is encrypted using the bank's public key stored in the bank-enterprise direct connection front-end machine to obtain the processed current transaction message.

[0015] The processed current transaction message is signed using the private key of the enterprise stored in the bank-enterprise direct connection front-end machine to obtain the encrypted current transaction message.

[0016] In some embodiments, the method further includes:

[0017] Receive an encrypted response message sent by the bank server, wherein the response message is a feedback to the encrypted transaction message;

[0018] The public key of the bank stored in the bank-enterprise direct connection front-end machine is used to verify the signature of the encrypted response message to obtain the response message;

[0019] The response message is sent to the enterprise's financial system.

[0020] In some embodiments, the bank-enterprise direct connection front-end machine further stores historical attribute information of the enterprise's historical transaction messages, wherein the historical attribute information includes: historical type distribution information and historical time interval distribution information; when the enterprise's bank account is not logged in, in response to the current transaction message sent through the enterprise's financial system, the method further includes:

[0021] Obtain the current attribute information of the current transaction message, the current attribute information including: current time and current type information;

[0022] Calculate the confidence level of the current transaction message based on the historical attribute information and the current attribute information;

[0023] The step of calling the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine includes: if the confidence level is greater than a preset threshold, then calling the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine.

[0024] In some embodiments, calculating the confidence level of the current transaction message based on the historical attribute information and the current attribute information includes:

[0025] Based on the current type information and the historical type distribution information, the type probability is calculated, wherein the type probability is the ratio of the current type information to the historical type distribution information;

[0026] Based on the current time and the historical time interval distribution information, a time probability is calculated, wherein the time probability is the ratio of the current time in the historical time interval distribution information;

[0027] The confidence level is calculated based on the type probability and the time probability.

[0028] In some embodiments, the method further includes:

[0029] If the confidence level is not greater than the preset threshold, a prompt message is output through the enterprise financial system;

[0030] The notification message is used to prompt the user to log in to the company's bank account.

[0031] Secondly, this application provides a data processing apparatus, which is applied to a bank-enterprise direct connection front-end machine in a client host. The client host further includes an enterprise financial system communicatively connected to the bank-enterprise direct connection front-end machine, and the bank-enterprise direct connection front-end machine stores the enterprise's private key and the bank's public key; the apparatus includes:

[0032] The first calling unit is used to call the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine in response to the current transaction message sent through the enterprise's financial system when the enterprise's bank account is not logged in.

[0033] The encryption unit is used to encrypt the current transaction message based on the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine, so as to obtain the encrypted current transaction message.

[0034] The first sending unit is used to send the encrypted current transaction message to the bank server.

[0035] In some embodiments, the encryption unit includes:

[0036] The first signing subunit is used to sign the current transaction message according to the private key of the enterprise stored in the bank-enterprise direct connection front-end machine, so as to obtain the signed current transaction message.

[0037] The first encryption subunit is used to encrypt the signed current transaction message according to the bank's public key stored in the bank-enterprise direct connection front-end machine, so as to obtain the encrypted current transaction message.

[0038] In some embodiments, the encryption unit includes:

[0039] The second signature subunit is used to encrypt the current transaction message according to the bank's public key stored in the bank-enterprise direct connection front-end machine to obtain the processed current transaction message.

[0040] The second encryption subunit is used to sign the processed current transaction message according to the private key of the enterprise stored in the bank-enterprise direct connection front-end machine, so as to obtain the encrypted current transaction message.

[0041] In some embodiments, the apparatus further includes:

[0042] A receiving unit is configured to receive an encrypted response message sent by the bank server, wherein the response message is a feedback to the encrypted transaction message;

[0043] The second calling unit is used to call the bank's public key stored in the bank-enterprise direct connection front-end machine to perform signature verification on the encrypted response message and obtain the response message.

[0044] The second sending unit is used to send the response message to the enterprise's financial system.

[0045] In some embodiments, the bank-enterprise direct connection front-end machine further stores historical attribute information of the enterprise's historical transaction messages, wherein the historical attribute information includes: historical type distribution information and historical time interval distribution information; the device further includes:

[0046] The acquisition unit is used to acquire the current attribute information of the current transaction message, the current attribute information including: current time and current type information;

[0047] A calculation unit is used to calculate the confidence level of the current transaction message based on the historical attribute information and the current attribute information;

[0048] The first calling unit is used to call the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine if the confidence level is greater than a preset threshold.

[0049] In some embodiments, the computing unit includes:

[0050] The first calculation subunit is used to calculate the type probability based on the current type information and the historical type distribution information, wherein the type probability is the ratio of the current type information in the historical type distribution information;

[0051] The second calculation subunit is used to calculate the time probability based on the current time and the historical time interval distribution information, wherein the time probability is the ratio of the current time in the historical time interval distribution information;

[0052] The third calculation subunit is used to calculate the confidence level based on the type probability and the time probability.

[0053] In some embodiments, the apparatus further includes:

[0054] An output unit is configured to output a notification message through the enterprise financial system if the confidence level is not greater than the preset threshold.

[0055] The notification message is used to prompt the user to log in to the company's bank account.

[0056] Thirdly, this application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0057] The memory stores computer-executed instructions;

[0058] The processor executes computer execution instructions stored in the memory to implement the method as described in any of the first aspects.

[0059] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any of the first aspects.

[0060] Fifthly, this application provides a computer program product including a computer program that, when executed by a processor, implements the steps of the method as described in any of the first aspects.

[0061] The data processing method and apparatus provided in this application are applied to a bank-enterprise direct connection front-end machine in a client host. The client host also includes an enterprise financial system communicatively connected to the bank-enterprise direct connection front-end machine. The bank-enterprise direct connection front-end machine stores the enterprise's private key and the bank's public key. The method includes: when the enterprise's bank account is not logged in, in response to a current transaction message sent through the enterprise financial system, calling the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine, and encrypting the current transaction message based on the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine to obtain the encrypted current transaction message. The EasyMessage feature sends encrypted current transaction messages to the bank server. In this embodiment, by storing the enterprise's private key and the bank's public key in the bank-enterprise direct connection front-end machine, the system can encrypt the current transaction message by calling the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine and send the encrypted current transaction message to the bank server even when the enterprise's bank account is not logged in. This technical feature supports login-free operation for enterprises, that is, enterprises can still send transaction instructions to the bank server without logging into their bank accounts, thereby improving the enterprise's operational efficiency and user experience. Attached Figure Description

[0062] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0063] Figure 1 This is a schematic diagram illustrating the data processing method of this application.

[0064] Figure 2 A schematic diagram illustrating a data processing method according to one embodiment of the application;

[0065] Figure 3 A schematic diagram illustrating a data processing method according to another embodiment of the application;

[0066] Figure 4 This is a schematic diagram of a data processing apparatus according to an embodiment of this application;

[0067] Figure 5 This is a schematic diagram of a data processing apparatus according to another embodiment of this application;

[0068] Figure 6 This is a block diagram of the client host in an embodiment of this application.

[0069] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to specific embodiments. Detailed Implementation

[0070] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0071] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with relevant laws, regulations and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0072] It should be noted that the data processing method and apparatus of this application relate to the field of network security and can be used in areas other than finance. The application fields of the data processing method and apparatus of this application are not limited.

[0073] To facilitate understanding of the technical solutions of this application, at least some of the technical terms involved in this application are explained as follows:

[0074] Direct bank-enterprise connection, also known as direct bank-enterprise link or bank-enterprise docking, is a new access method that allows online banking systems to directly connect with corporate financial systems. Enterprises connect their financial systems to the banking system through data interfaces.

[0075] The bank-enterprise direct connection front-end server, also known as the bank-enterprise front-end server or front-end server system, is developed by banks and is generally deployed on the client host. Specifically, it can be deployed independently or embedded in the enterprise's financial system.

[0076] With the development of e-commerce technology, in order to reduce financial costs and improve financial efficiency, more and more enterprises are switching from traditional World Wide Web (WWAN) online banking to direct bank-enterprise connections when interacting with banks.

[0077] In the design of direct bank-enterprise connections, such as Figure 1 As shown, a bank-enterprise direct connection front-end server and the enterprise financial system can be installed on the enterprise's client host. The enterprise financial system sends transaction messages (such as transaction request messages) to the bank-enterprise direct connection front-end server based on user (such as the enterprise's financial staff) operations.

[0078] Correspondingly, the bank-enterprise direct connection front-end receives the transaction message sent by the enterprise's financial system and sends the transaction message to the bank's server.

[0079] Correspondingly, the bank server receives the transaction message sent by the bank-enterprise direct connection front-end machine, generates a response message (such as a response transaction request message, or a response transaction message) based on the transaction message, and sends the response message to the bank-enterprise direct connection front-end machine.

[0080] Correspondingly, the bank-enterprise direct connection front-end receives the response message sent by the bank server and sends a response message to the enterprise's financial system.

[0081] Before the aforementioned interaction process, businesses need to log into their bank accounts to communicate with the bank's server. For example, a business sends a login command to the bank's server via a client host. After verification by the bank's server, the server stores the business's identity information (i.e., the business's bank account information, etc.) in memory to keep the business's bank account online.

[0082] Through the above interaction process, enterprises can send transaction messages to the bank server through the client host. The online status of the enterprise's bank account can last for about half an hour after the enterprise's last operation. After that, the bank server will release memory and clear the enterprise's login information, that is, the enterprise's bank account will be in an offline state. Of course, the enterprise can also actively initiate a logout command.

[0083] In other words, a company must be logged into its bank account before it can send transaction messages to the bank server through its client host; otherwise, the bank server may prompt the company to log into its bank account first.

[0084] However, the transaction messages sent by a company to the bank's server through its client host are not always continuous. For example, if a company sends its first transaction message to the bank's server through its client host at the first moment of the day, and then sends a second transaction message to the bank's server through its client host at the second moment after an interval of half an hour or even an hour, the bank's server will prompt the company to perform a login operation first. Although this improves security to some extent, it also reduces the company's operational efficiency and brings a bad user experience to the company.

[0085] To avoid the aforementioned technical problems, this application proposes an inventive technical concept: The enterprise's private key and the bank's public key are stored in the bank-enterprise direct connection front-end machine. When the enterprise's bank account is not logged in, if the enterprise sends a transaction message to the bank-enterprise direct connection front-end machine through its corporate financial system on the client host, the front-end machine uses the enterprise's private key and the bank's public key stored in the front-end machine. Based on these stored keys, the front-end machine encrypts the transaction message to obtain an encrypted transaction message, which is then sent to the bank server.

[0086] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0087] Please see Figure 2 , Figure 2 This is a schematic diagram illustrating a data processing method according to one embodiment. The method is applied to a bank-enterprise direct connection front-end machine in a client host. The client host also includes an enterprise financial system communicatively connected to the bank-enterprise direct connection front-end machine. The bank-enterprise direct connection front-end machine stores the enterprise's private key and the bank's public key. Figure 2 As shown, the method includes:

[0088] S201: In the absence of login to the enterprise's bank account, respond to the current transaction message sent through the enterprise's financial system by retrieving the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine.

[0089] For example, the execution subject in this embodiment can be a data processing device, which can be a client host, such as a desktop computer or other terminal device. Specifically, it can be a bank-enterprise direct connection front-end machine in the client host. The bank-enterprise direct connection front-end machine can be a processor, a chip, etc. This embodiment does not limit the scope.

[0090] This step can be understood as follows: Even if the company's bank account is not logged into the bank's server, the company can still send transaction messages to the bank-enterprise direct connection front-end through the company's financial system. In order to distinguish this transaction message from other transaction messages, we can call this transaction message the current transaction message.

[0091] Correspondingly, when the bank-enterprise direct connection front-end receives the current transaction message sent by the enterprise's financial system, it can access the enterprise's private key and the bank's public key stored within it.

[0092] The enterprise's private key is a private certificate issued by the bank to the enterprise.

[0093] S202: Encrypt the current transaction message based on the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine to obtain the encrypted current transaction message.

[0094] In this embodiment, the encryption process is equivalent to providing two encryption procedures: one based on the enterprise's private key and the other based on the bank's public key. This embodiment does not limit the order of the two encryption procedures, that is, it does not limit the specific implementation of the encryption process.

[0095] By combining the company's private key and the bank's public key to perform multi-dimensional encryption on the current transaction message, it is possible to prevent the current transaction message from being tampered with, ensure the legitimacy of the company's identity, and verify the authenticity and validity of the current transaction message.

[0096] In some embodiments, an encryption procedure based on the enterprise's private key may be performed first, followed by an encryption procedure based on the bank's public key. For example, S202 may include the following steps:

[0097] The first step is to sign the current transaction message using the private key of the enterprise stored in the bank-enterprise direct connection front-end machine, and obtain the signed current transaction message.

[0098] The second step is to encrypt the signed current transaction message using the bank's public key stored in the bank-enterprise direct connection front-end machine, thus obtaining the encrypted current transaction message.

[0099] In other words, in this embodiment, the current transaction message can be first encrypted using the enterprise's private key, and then a second encryption process can be performed using the bank's public key.

[0100] In other embodiments, encryption based on the bank's public key may be performed first, followed by encryption based on the enterprise's private key. For example, S202 may include the following steps:

[0101] The first step is to encrypt the current transaction message using the bank's public key stored in the bank-enterprise direct connection front-end machine to obtain the processed current transaction message.

[0102] The second step is to use the enterprise's private key stored in the bank-enterprise direct connection front-end machine to sign the processed current transaction message, thereby obtaining the encrypted current transaction message.

[0103] In other words, in this embodiment, the current transaction message can be first encrypted using the bank's public key, and then a second encryption process can be performed using the company's private key.

[0104] In this embodiment, the enterprise's private key and the bank's public key can be combined to encrypt the current transaction message in different orders, so as to achieve flexibility and diversity in encryption processing.

[0105] In this embodiment, there is no limit to the amount of content to be encrypted; all content can be encrypted, or only a portion of the content can be encrypted.

[0106] For example, the encryption process can be performed on the entire current transaction message, or it can be performed on a portion of the current transaction message.

[0107] In some embodiments, if the encryption process is performed on the entire current transaction message, key information can be extracted from the entire current transaction message based on preset keywords, and then the extracted key information can be encrypted. The preset keywords are stored in the bank-enterprise direct connection front-end server.

[0108] S203: Send the encrypted current transaction message to the bank server.

[0109] Correspondingly, the bank server receives the encrypted current transaction message sent by the bank-enterprise direct connection front-end machine.

[0110] Based on the above analysis, this application provides a data processing method. This method is applied to a bank-enterprise direct connection front-end machine in a client host. The client host also includes an enterprise financial system communicatively connected to the bank-enterprise direct connection front-end machine. The bank-enterprise direct connection front-end machine stores the enterprise's private key and the bank's public key. The method includes: when the enterprise's bank account is not logged in, in response to a current transaction message sent through the enterprise financial system, calling the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine, and encrypting the current transaction message based on the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine to obtain encrypted data. The system sends an encrypted current transaction message to the bank server. In this embodiment, by storing the enterprise's private key and the bank's public key in the bank-enterprise direct connection front-end machine, the system can encrypt the current transaction message by calling the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine and send the encrypted current transaction message to the bank server even when the enterprise's bank account is not logged in. This technical feature supports login-free operation for enterprises, that is, enterprises can still send transaction instructions to the bank server without logging into their bank accounts, thereby improving the enterprise's operational efficiency and user experience.

[0111] To facilitate readers' understanding of the application, the following is combined with... Figure 3 The data processing methods described in this application are explained in detail. Figure 3This is a schematic diagram of a data processing method according to another embodiment of the application. The method is applied to a bank-enterprise direct connection front-end machine in a client host. The client host also includes an enterprise financial system that is communicatively connected to the bank-enterprise direct connection front-end machine. The bank-enterprise direct connection front-end machine stores the enterprise's private key and the bank's public key. The bank-enterprise direct connection front-end machine also stores the historical attribute information of the enterprise's historical transaction messages. The historical attribute information includes: historical type distribution information and historical time interval distribution information.

[0112] For example, the number of historical transaction messages can be one or multiple. To improve the effectiveness and reliability of the interaction, the number of historical transaction messages can be multiple. In some embodiments, the number of historical transaction messages can be the number of transaction messages within a preset time period.

[0113] The preset time period can be determined based on demand, historical records, and experiments, and this embodiment does not impose any limitations. For example, the preset time period can be one month, longer than one month, or shorter than one month.

[0114] Historical transaction type distribution information can be understood as the distribution of transaction types in historical transaction messages. For example, if there are N types of historical transaction messages (N is a positive integer greater than or equal to 1), the historical transaction type distribution information can be the ratio of each type to the number of historical transaction messages. These types include, but are not limited to, transfers and queries.

[0115] Historical time interval distribution information can be understood as the distribution of time intervals in which historical transaction messages occurred. For example, each historical transaction message corresponds to a specific time interval, and the historical time interval distribution information can be the ratio of the number of identical time intervals to the total number of time intervals. The time interval can be the time interval from the start to the end of an interaction based on a transaction message.

[0116] S301: When the enterprise's bank account is not logged in, in response to the current transaction message sent through the enterprise's financial system, the bank-enterprise direct connection front-end machine obtains the current attribute information of the current transaction message.

[0117] The current attribute information includes: current time and current type information.

[0118] For example, current attribute information is used to characterize the attributes of the current transaction message, and the current attribute information can characterize the current transaction message from at least the time dimension and the type dimension. The time dimension refers to the time when the current transaction message is sent through the enterprise financial system; for ease of distinction, we can refer to this time as the current time. The type dimension refers to the type of the current transaction message.

[0119] S302: The bank-enterprise direct connection front-end machine calculates the confidence level of the current transaction message based on historical and current attribute information.

[0120] The confidence level is used to characterize the reliability of the current transaction message as a genuine transaction message. Relatively speaking, the higher the confidence level, the higher the reliability of the current transaction message, indicating that it is more likely to be a genuine transaction message initiated by the enterprise.

[0121] In this embodiment, historical attribute information can be understood as the transaction messages initiated by the enterprise through the client host in the past, and current attribute information can be understood as the transaction messages initiated by the enterprise through the client host at present. By referring to the transaction messages initiated by the enterprise through the client host in the past, the reliability of the transaction messages initiated by the enterprise through the client host at present can be determined, which can avoid the occurrence of erroneous transactions without login and improve the effectiveness and authenticity of the interaction between the enterprise through the client host and the bank server.

[0122] In some embodiments, S302 may include the following steps:

[0123] The first step is to calculate the type probability based on the current type information and the historical type distribution information, where the type probability is the ratio of the current type information to the historical type distribution information.

[0124] For example, based on the above analysis, if the current type information indicates that the current transaction message is of type A, and the historical type distribution information can determine the ratio of each type to the number of historical transaction messages, then it can be determined whether the historical transaction messages include type A. If so, the ratio of type A to the number of historical transaction messages can be determined based on the historical type distribution information, and this ratio can be used as the type probability.

[0125] The second step is to calculate the time probability based on the current time and the historical time interval distribution information. The time probability is the ratio of the current time in the historical time interval distribution information.

[0126] For example, by combining the above analysis, the time interval to which the current time belongs can be determined, and the ratio of the number of historical time intervals to the number of all time intervals can be determined, and this ratio can be determined as the time probability.

[0127] The third step is to calculate the confidence level based on the type probability and the time probability.

[0128] For example, the type probability has a first coefficient, the time probability has a second coefficient, and the sum of the first and second coefficients is 1. The magnitude of the first and second coefficients can be determined based on requirements, historical records, and experiments, etc., and this embodiment does not limit it.

[0129] Correspondingly, the confidence level can be obtained by weighting the type probability, the first coefficient, the time probability, and the second coefficient.

[0130] In this embodiment, by calculating the type probability and time probability separately, and then combining the type probability and time probability to calculate the confidence level, the confidence level can be made to have high validity and reliability, thereby improving the security and reliability of login-free access.

[0131] S303: If the confidence level is greater than the preset threshold, the bank-enterprise direct connection front-end machine will call the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine.

[0132] Similarly, the preset threshold can be determined based on demand, historical records, and experiments, and this embodiment does not impose any limitations.

[0133] For example, for scenarios with relatively high reliability, the preset threshold can be relatively high; conversely, for scenarios with relatively low reliability, the preset threshold can be relatively low.

[0134] For example, the bank-enterprise direct connection front-end machine stores a preset threshold. When the bank-enterprise direct connection front-end machine calculates the confidence level, it retrieves the preset threshold and compares the preset threshold with the confidence level. If the confidence level is greater than the preset threshold, it retrieves the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine.

[0135] Correspondingly, in other embodiments, if the confidence level is not greater than (i.e., less than or equal to) a preset threshold, a prompt message is output through the enterprise's financial system. This prompt message is used to remind users to log in to the enterprise's bank account.

[0136] For example, if the confidence level is not greater than a preset threshold, the bank-enterprise direct connection front-end machine can send a prompt message to the enterprise's financial system.

[0137] Correspondingly, the enterprise's financial system receives a notification message sent by the bank-enterprise direct connection front-end server. The enterprise's financial system can display the notification message through the display device on the client host.

[0138] Correspondingly, staff operating the client host (such as finance personnel) can see the prompt message displayed on the device and log in to their account as prompted by the message.

[0139] In this embodiment, if there are risks associated with not requiring login, the client host can output a prompt message to remind the enterprise to log in, thereby improving the security and reliability of the current transaction message interaction.

[0140] S304: The bank-enterprise direct connection front-end machine encrypts the current transaction message based on the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine, and obtains the encrypted current transaction message.

[0141] Similarly, the implementation principle of S304 can be found in the description of S202, and will not be repeated here.

[0142] S305: The bank-enterprise direct connection front-end machine sends the encrypted current transaction message to the bank server.

[0143] Similarly, the implementation principle of S305 can be found in the description of S203, and will not be repeated here.

[0144] S306: The bank server decrypts the encrypted current transaction message to obtain the current transaction message.

[0145] Decryption is the reverse process of encryption.

[0146] For example, based on the above analysis, if the encrypted current transaction message is obtained by first signing the current transaction message based on the enterprise's private key, and then encrypting the signed current transaction message based on the bank's public key, then the decryption process may include: the bank server first decrypts the encrypted current transaction message based on the bank's private key to obtain the signed current transaction message, and then verifies the signature of the signed current transaction message based on the enterprise's public key to obtain the current transaction message.

[0147] For example, based on the above analysis, if the encrypted current transaction message is obtained by first encrypting the current transaction message based on the bank's public key and then signing the processed current transaction message based on the enterprise's private key, then the decryption process may include: the bank server first verifies the signature of the encrypted current transaction message based on the enterprise's public key, and then decrypts the processed current transaction message based on the bank's private key to obtain the signed current transaction message.

[0148] S307: The bank server generates a response message based on the current transaction message and encrypts the response message based on the bank's private key to obtain the encrypted response message.

[0149] S308: The bank server sends an encrypted response message to the bank-enterprise direct connection front-end machine.

[0150] Correspondingly, the bank-enterprise direct connection front-end receives the encrypted response message sent by the bank's server.

[0151] S309: The bank-enterprise direct connection front-end machine calls the bank's public key stored in the bank-enterprise direct connection front-end machine to perform signature verification on the encrypted response message and obtain the response message.

[0152] S310: The bank-enterprise direct connection front-end machine sends a response message to the enterprise's financial system.

[0153] Correspondingly, the enterprise's financial system receives response messages sent by the bank-enterprise direct connection front-end machine.

[0154] It should be understood that the above examples are merely illustrative of possible implementations of this embodiment and should not be construed as limiting the data processing method of this embodiment. For example, at least some technical features can be added, removed, or adjusted based on the above examples to obtain new embodiments.

[0155] Based on the above technical concept, this application also provides a data processing device.

[0156] Please see Figure 4 , Figure 4 This is a schematic diagram of a data processing apparatus according to an embodiment of this application.

[0157] The data processing device is applied to the bank-enterprise direct connection front-end machine in the client host. The client host also includes the enterprise financial system that is communicatively connected to the bank-enterprise direct connection front-end machine. The bank-enterprise direct connection front-end machine stores the enterprise's private key and the bank's public key. Figure 4 As shown, the data processing device 400 includes:

[0158] The first invocation unit 401 is used to invoke the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine in response to the current transaction message sent through the enterprise's financial system when the enterprise's bank account is not logged in.

[0159] The encryption unit 402 is used to encrypt the current transaction message based on the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine, so as to obtain the encrypted current transaction message.

[0160] The first sending unit 403 is used to send the encrypted current transaction message to the bank server.

[0161] Please see Figure 5 , Figure 5 This is a schematic diagram of a data processing apparatus according to another embodiment of this application.

[0162] The data processing device is applied to the bank-enterprise direct connection front-end machine in the client host. The client host also includes an enterprise financial system that is communicatively connected to the bank-enterprise direct connection front-end machine. The bank-enterprise direct connection front-end machine stores the enterprise's private key and the bank's public key. It also stores historical attribute information of the enterprise's historical transaction messages, including historical type distribution information and historical time interval distribution information. Figure 5 As shown, the data processing device 500 includes:

[0163] The acquisition unit 501 is used to acquire the current attribute information of the current transaction message, the current attribute information including: current time and current type information.

[0164] The calculation unit 502 is used to calculate the confidence level of the current transaction message based on the historical attribute information and the current attribute information.

[0165] In some embodiments, combined with Figure 5 It can be seen that the computing unit 502 includes:

[0166] The first calculation subunit 5021 is used to calculate the type probability based on the current type information and the historical type distribution information, wherein the type probability is the ratio of the current type information in the historical type distribution information.

[0167] The second calculation subunit 5022 is used to calculate the time probability based on the current time and the historical time interval distribution information, wherein the time probability is the ratio of the current time in the historical time interval distribution information.

[0168] The third calculation subunit 5023 is used to calculate the confidence level based on the type probability and the time probability.

[0169] The first calling unit 503 is used to call the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine if the confidence level is greater than a preset threshold.

[0170] The encryption unit 504 is used to encrypt the current transaction message based on the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine, so as to obtain the encrypted current transaction message.

[0171] In some embodiments, combined with Figure 5 It is known that the encryption unit 504 includes:

[0172] The first signature subunit 5041 is used to sign the current transaction message according to the private key of the enterprise stored in the bank-enterprise direct connection front-end machine to obtain the signed current transaction message.

[0173] The first encryption subunit 5042 is used to encrypt the signed current transaction message according to the bank's public key stored in the bank-enterprise direct connection front-end machine, so as to obtain the encrypted current transaction message.

[0174] In some embodiments, combined with Figure 5 It is known that the encryption unit 504 includes:

[0175] The second signature subunit 5043 is used to encrypt the current transaction message according to the bank's public key stored in the bank-enterprise direct connection front-end machine to obtain the processed current transaction message.

[0176] The second encryption subunit 5044 is used to sign the processed current transaction message according to the private key of the enterprise stored in the bank-enterprise direct connection front-end machine to obtain the encrypted current transaction message.

[0177] The first sending unit 505 is used to send the encrypted current transaction message to the bank server.

[0178] The receiving unit 506 is used to receive the encrypted response message sent by the bank server, wherein the response message is a feedback to the encrypted transaction message.

[0179] The second calling unit 507 is used to call the bank's public key stored in the bank-enterprise direct connection front-end machine to perform signature verification processing on the encrypted response message, and obtain the response message.

[0180] The second sending unit 508 is used to send the response message to the enterprise financial system.

[0181] The output unit 509 is used to output a prompt message through the enterprise financial system if the confidence level is not greater than the preset threshold.

[0182] The notification message is used to prompt the user to log in to the company's bank account.

[0183] Based on the above technical concept, this application also provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0184] The memory stores computer-executed instructions;

[0185] The processor executes computer execution instructions stored in the memory to implement the data processing method as described in any of the above embodiments.

[0186] Based on the above technical concept, this application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the data processing method described in any of the above embodiments.

[0187] Based on the above technical concept, this application provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method as described in any of the first aspects.

[0188] Based on the above analysis, it can be seen that the client host includes the bank-enterprise direct connection front-end machine and the enterprise financial system. Figure 6 This is a block diagram of a client host according to an embodiment of this application. The client host may be a mobile phone, computer, digital broadcasting terminal, messaging device, game console, tablet device, medical device, fitness device, personal digital assistant, etc.

[0189] The client host 600 may include one or more of the following components: processing component 601, memory 602, power supply component 603, multimedia component 604, audio component 605, input / output (I / O) interface 606, sensor component 607, and communication component 608.

[0190] Processing component 601 typically controls the overall operation of client host 600, such as operations associated with display, telephone calls, data communication, camera operation, and recording. Processing component 601 may include one or more processors 6011 to execute instructions to complete all or part of the steps of the methods described above. Furthermore, processing component 601 may include one or more modules to facilitate interaction between processing component 601 and other components. For example, processing component 601 may include a multimedia module to facilitate interaction between multimedia component 604 and processing component 601.

[0191] Memory 602 is configured to store various types of data to support operation on client host 600. Examples of this data include instructions for any application or method operating on client host 600, contact data, phonebook data, messages, pictures, videos, etc. Memory 602 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0192] Power supply component 603 provides power to various components of client host 600. Power supply component 603 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to client host 600.

[0193] Multimedia component 604 includes a screen that provides an output interface between the client host 600 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of the touch or swipe action but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 604 includes a front-facing camera and / or a rear-facing camera. When the client host 600 is in an operating mode, such as a shooting mode or a video mode, the front-facing camera and / or the rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.

[0194] Audio component 606 is configured to output and / or input audio signals. For example, audio component 606 includes a microphone (MIC) configured to receive external audio signals when the client host 600 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 605 or transmitted via communication component 608. In some embodiments, audio component 606 also includes a speaker for outputting audio signals.

[0195] Input / output interface 606 provides an interface between processing component 601 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, start buttons, and lock buttons.

[0196] Sensor assembly 607 includes one or more sensors for providing status assessments of various aspects of client host 600. For example, sensor assembly 607 may detect the on / off state of client host 600, the relative positioning of components such as the display and keypad of client host 600, changes in position of client host 600 or a component of client host 600, the presence or absence of user contact with client host 600, the orientation or acceleration / deceleration of client host 600, and temperature changes of client host 600. Sensor assembly 607 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 607 may also include an optical sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 607 may also include an accelerometer, gyroscope, magnetometer, pressure sensor, or temperature sensor.

[0197] Communication component 608 is configured to facilitate wired or wireless communication between client host 600 and other devices. Client host 600 can access wireless networks based on communication standards, such as WiFi, 2G, or 3G, or combinations thereof. In one exemplary embodiment, communication component 608 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 608 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0198] In an exemplary embodiment, the client host 600 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.

[0199] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 602 including instructions, which can be executed by a processor 6011 of a client host 600 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0200] The non-transitory computer-readable storage medium provided in this embodiment implements the data processing method described in any of the above embodiments when the instructions in the storage medium are executed by the processor of the terminal device.

[0201] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0202] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A data processing method, characterized in that, The method is applied to a bank-enterprise direct connection front-end machine in a client host. The client host also includes an enterprise financial system that is communicatively connected to the bank-enterprise direct connection front-end machine. The bank-enterprise direct connection front-end machine stores the enterprise's private key and the bank's public key. The method includes: If the enterprise's bank account is not logged in, in response to the current transaction message sent through the enterprise's financial system, the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine are invoked. The current transaction message is encrypted based on the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine to obtain the encrypted current transaction message. Send the encrypted current transaction message to the bank server; The bank-enterprise direct connection front-end also stores historical attribute information of the enterprise's historical transaction messages, wherein the historical attribute information includes: historical type distribution information and historical time interval distribution information; in the absence of login to the enterprise's bank account, in response to the current transaction message sent through the enterprise's financial system, the method further includes: Obtain the current attribute information of the current transaction message, the current attribute information including: current time and current type information; Calculate the confidence level of the current transaction message based on the historical attribute information and the current attribute information; The step of calling the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine includes: if the confidence level is greater than a preset threshold, then calling the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine. Based on the historical attribute information and the current attribute information, the confidence level of the current transaction message is calculated, including: Based on the current type information and the historical type distribution information, the type probability is calculated, wherein the type probability is the ratio of the current type information to the historical type distribution information; Based on the current time and the historical time interval distribution information, a time probability is calculated, wherein the time probability is the ratio of the current time in the historical time interval distribution information; The confidence level is calculated based on the type probability and the time probability.

2. The method according to claim 1, characterized in that, The current transaction message is encrypted using the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine, resulting in an encrypted current transaction message, including: The current transaction message is signed using the private key of the enterprise stored in the bank-enterprise direct connection front-end machine to obtain the signed current transaction message. The signed current transaction message is encrypted using the bank's public key stored in the bank-enterprise direct connection front-end machine to obtain the encrypted current transaction message.

3. The method according to claim 1, characterized in that, The current transaction message is encrypted using the enterprise's private key and the bank's public key stored in the bank-enterprise direct connection front-end machine, resulting in an encrypted current transaction message, including: The current transaction message is encrypted using the bank's public key stored in the bank-enterprise direct connection front-end machine to obtain the processed current transaction message. The processed current transaction message is signed using the private key of the enterprise stored in the bank-enterprise direct connection front-end machine to obtain the encrypted current transaction message.

4. The method according to any one of claims 1-3, characterized in that, The method further includes: Receive an encrypted response message sent by the bank server, wherein the response message is a feedback to the encrypted transaction message; The public key of the bank stored in the bank-enterprise direct connection front-end machine is used to verify the signature of the encrypted response message to obtain the response message; The response message is sent to the enterprise's financial system.

5. The method according to claim 1, characterized in that, The method further includes: If the confidence level is not greater than the preset threshold, a prompt message is output through the enterprise financial system; The notification message is used to prompt the user to log in to the company's bank account.

6. A data processing apparatus, characterized in that, The device is applied to a bank-enterprise direct connection front-end machine in a client host. The client host also includes an enterprise financial system that is communicatively connected to the bank-enterprise direct connection front-end machine. The bank-enterprise direct connection front-end machine stores the enterprise's private key and the bank's public key. The device includes: The first calling unit is used to call the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine in response to the current transaction message sent through the enterprise's financial system when the enterprise's bank account is not logged in. The encryption unit is used to encrypt the current transaction message based on the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine, so as to obtain the encrypted current transaction message. The first sending unit is used to send the encrypted current transaction message to the bank server; The bank-enterprise direct connection front-end machine also stores historical attribute information of the enterprise's historical transaction messages, wherein the historical attribute information includes: historical type distribution information and historical time interval distribution information; the data processing device further includes: The acquisition unit is used to acquire the current attribute information of the current transaction message, the current attribute information including: current time and current type information; A calculation unit is used to calculate the confidence level of the current transaction message based on the historical attribute information and the current attribute information; The step of calling the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine includes: if the confidence level is greater than a preset threshold, then calling the private key of the enterprise and the public key of the bank stored in the bank-enterprise direct connection front-end machine. The computing unit includes a first computing subunit, a second computing subunit, and a third computing subunit; The first calculation subunit is used to calculate the type probability based on the current type information and the historical type distribution information, wherein the type probability is the ratio of the current type information in the historical type distribution information; The second calculation subunit is used to calculate a time probability based on the current time and the historical time interval distribution information, wherein the time probability is the ratio of the current time in the historical time interval distribution information; The third calculation subunit is used to calculate the confidence level based on the type probability and the time probability.

7. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 5.