A data processing method and related apparatus
By generating business identifiers and alarm information when account characteristic values change abnormally, the problem of difficulty in quickly locating and analyzing abnormal asset changes in existing technologies is solved, thereby improving asset security and processing efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2022-02-21
- Publication Date
- 2026-06-02
AI Technical Summary
In existing technologies, asset verification methods are difficult to locate and analyze abnormal asset changes in a timely manner. Especially when an account involves multiple businesses, it is difficult to quickly identify abnormal businesses and issue alerts, resulting in significant account security risks.
By acquiring information on changes in account characteristic values and corresponding credential information, a business identifier is generated, and an alarm message is generated when the characteristic value changes abnormally, so as to quickly indicate abnormal business.
It enables rapid location and alerting of abnormal business operations, improving asset security and processing efficiency.
Smart Images

Figure CN116680640B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data analysis technology, and in particular to a data processing method and related apparatus. Background Technology
[0002] As the economy continues to develop, people's assets are also increasing, making fund security a key concern. The platform offers users various asset storage options, such as asset storage through banks and third-party asset management software.
[0003] To ensure the security of storage users' assets, relevant technologies involve equipment or personnel verifying the flow of these assets to promptly detect any abnormal changes. However, the asset verification methods in these technologies struggle to locate and analyze abnormal assets in a timely manner. For example, when a storage account involves asset changes across multiple business transactions, it is difficult to identify the abnormal transactions and issue alerts promptly, posing a significant security risk to the account. Summary of the Invention
[0004] To address the aforementioned technical issues, this application provides a data processing method. This method can serve as a background algorithm to internally detect user account information, ensuring user information security. The processing device can generate a corresponding business identifier for each change in account characteristic values. Therefore, even if an account involves multiple businesses, when abnormal characteristic value changes occur, the processing device can quickly generate alarm information based on the business identifier, rapidly indicating the presence of abnormal business activities.
[0005] The embodiments of this application disclose the following technical solutions:
[0006] In a first aspect, embodiments of this application disclose a data processing method, the method comprising:
[0007] Obtain account feature value change information of the target account within a target time period, and first credential information corresponding to the account feature value change information. The first credential information is used to request feature value transfer, and the account feature value change information is used to identify the feature value change of the target account within the target time period.
[0008] In response to a mismatch between the feature value change amount identified by the account feature value change information and the feature value transfer amount requested by the first credential information, a business identifier corresponding to the account feature value change information is obtained, and the business identifier is generated based on the first credential information.
[0009] Generate a first alarm message corresponding to the service identifier. The first alarm message is used to indicate that the service corresponding to the service identifier has an abnormal change in feature value.
[0010] Secondly, embodiments of this application disclose a data processing apparatus, which includes a first acquisition unit, a first response unit, and a generation unit:
[0011] The first acquisition unit is used to acquire account feature value change information of the target account within a target time period, and first credential information corresponding to the account feature value change information. The first credential information is used to request feature value transfer, and the account feature value change information is used to identify the feature value change of the target account within the target time period.
[0012] The first response unit is configured to, in response to a mismatch between the feature value change amount identified by the account feature value change information and the feature value transfer amount requested by the first credential information, obtain a business identifier corresponding to the account feature value change information, wherein the business identifier is generated based on the first credential information;
[0013] The generation unit is used to generate a first alarm message corresponding to the service identifier, the first alarm message being used to indicate that the service corresponding to the service identifier has an abnormal change in feature value.
[0014] In one possible implementation, the account feature value change information includes first transaction history information and / or first feature value balance information, wherein the first transaction history information is used to identify the feature value transfer of the target account within the target time period, and the first feature value balance change information is used to identify the feature value balance change of the target account within the target time period.
[0015] The first response unit is specifically used for:
[0016] In response to the mismatch between the feature value transfer amount identified by the first transaction information and the feature value transfer amount requested by the first credential information, the business identifier is obtained.
[0017] In response to a mismatch between the feature value transfer amount requested by the first credential information and the feature value balance change amount identified by the first feature value balance information, the business identifier is obtained.
[0018] In one possible implementation, the device further includes a second acquisition unit and a second response unit:
[0019] The second acquisition unit is used to acquire the feature value transfer threshold corresponding to the service identifier, wherein the feature value transfer threshold is determined based on the historical transaction information corresponding to the service identifier;
[0020] The second response unit is configured to generate the first alarm information corresponding to the service identifier in response to the feature value transfer amount identified by the first flow information exceeding the feature value transfer threshold.
[0021] In one possible implementation, the apparatus further includes a third acquisition unit, a first determination unit, a second determination unit, and a third determination unit:
[0022] The third acquisition unit is used to acquire the second transaction information and / or the second voucher information corresponding to the business identifier within the target time period. The second transaction information includes the first transaction information corresponding to multiple accounts within the target time period, and the second voucher information includes the first voucher information corresponding to multiple accounts within the target time period.
[0023] The first determining unit is configured to determine the feature value inflow and feature value outflow corresponding to the business identifier within the target time period based on the second transaction information and / or the second voucher information;
[0024] The second determining unit is used to determine the revenue and expenditure deviation corresponding to the business identifier in the target time period based on the amount of feature value transferred in and the amount of feature value transferred out.
[0025] The third determining unit is used to determine whether the business corresponding to the business identifier is normal based on the income and expenditure deviation and the business evaluation conditions corresponding to the business identifier. The business evaluation conditions are generated based on the historical transaction information corresponding to the business identifier.
[0026] In one possible implementation, the target time period includes multiple sub-time periods, and the first response unit is specifically used for:
[0027] Determine the first sub-transaction log information and the first sub-voucher information corresponding to each sub-time period;
[0028] Based on the feature value transfer amount identified by the first sub-transaction information and the feature value transfer amount requested by the first sub-voucher information, determine the feature value transfer amount difference corresponding to each sub-time period;
[0029] In response to the absolute value of the sum of the feature value transfer differences corresponding to the multiple sub-time periods exceeding a first threshold, the service identifier is obtained.
[0030] In one possible implementation, the device further includes a third response unit:
[0031] The third response unit is used to cancel the second alarm information corresponding to the multiple sub-time periods in response to the absolute value of the sum of the feature value transfer difference values corresponding to the multiple sub-time periods not exceeding the first threshold. The second alarm information is generated in response to the absolute value of the feature value transfer difference values corresponding to the sub-time periods exceeding the second threshold. The second alarm information is used to indicate that the feature value transfer corresponding to the sub-time period is abnormal.
[0032] The generation unit is specifically used for:
[0033] Based on the second alarm information corresponding to the multiple sub-time periods, the first alarm information corresponding to the service identifier is generated.
[0034] Thirdly, embodiments of this application disclose a computer device, the device including a processor and a memory:
[0035] The memory is used to store program code and transmit the program code to the processor;
[0036] The processor is used to execute the data processing method described in the first aspect according to the instructions in the program code.
[0037] Fourthly, embodiments of this application disclose a computer-readable storage medium for storing a computer program for executing the data processing method described in the first aspect.
[0038] Fifthly, embodiments of this application disclose a computer program product including instructions that, when run on a computer, cause the computer to perform the data processing method described in the first aspect.
[0039] As can be seen from the above technical solution, during the feature value security check, the system can obtain the target account's feature value change information within a target time period, as well as the first credential information corresponding to this feature value change information. This first credential information is used to request feature value transfer, and the account feature value change information is used to identify the feature value changes within the target time period. If there are no abnormalities in the feature value changes within the target time period, the feature value transfer amount requested by the first credential information should match the feature value change amount identified by the account feature value change information. If the feature value change amount identified by the account feature value change information does not match the feature value transfer amount requested by the first credential information, it indicates that an abnormal feature value change has occurred in the account feature value change information. In this case, the processing device can obtain the business identifier corresponding to the account feature value change information. This business identifier is generated based on the first credential information. Through this business identifier, the business corresponding to the account feature value change information can be determined, thereby generating a first alarm message indicating an abnormal feature value change in this business. This allows relevant personnel to promptly be aware of the abnormal business and take appropriate action, further improving the security of the feature values. Attached Figure Description
[0040] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0041] Figure 1 A schematic diagram illustrating a data processing method in a practical application scenario provided by an embodiment of this application;
[0042] Figure 2 A flowchart illustrating a data processing method provided in an embodiment of this application;
[0043] Figure 3 A schematic diagram illustrating a data processing method provided in an embodiment of this application;
[0044] Figure 4 A schematic diagram illustrating a data processing method provided in an embodiment of this application;
[0045] Figure 5 A server architecture diagram for data processing is provided in the embodiments of this application;
[0046] Figure 6 A flowchart illustrating a data processing method in a practical application scenario provided in this application embodiment;
[0047] Figure 7A schematic diagram illustrating a data processing method in a practical application scenario provided by an embodiment of this application;
[0048] Figure 8 A structural block diagram of a data processing apparatus provided in an embodiment of this application;
[0049] Figure 9 A structural diagram of a computer device provided in an embodiment of this application;
[0050] Figure 10 This is a structural diagram of a server provided in an embodiment of this application. Detailed Implementation
[0051] The embodiments of this application will now be described with reference to the accompanying drawings.
[0052] Effective and secure management of user-stored feature values has always been a key concern for technical personnel in this field. Current technologies primarily manage feature values by verifying the consistency between transaction records and voucher information. However, transaction records in these technologies only record the transfer of feature values and do not record the corresponding business transactions. This makes it difficult to quickly locate abnormal business transactions when problems arise with feature value transaction records, resulting in low efficiency in feature value management. This is especially problematic in scenarios where accounts involve multiple business transactions, potentially leading to significant account security risks.
[0053] To address the aforementioned technical issues, this application provides a data processing method. The processing device can generate a corresponding business identifier for each account feature value change information. Thus, when an abnormal feature value change occurs, an alarm message can be quickly generated based on the business identifier, which can quickly indicate the presence of an abnormal business.
[0054] Understandably, this method can be applied to processing devices capable of data processing, such as terminal devices or servers with data processing functions. This method can be executed independently by a terminal device or server, or it can be applied in network scenarios where a terminal device and a server communicate, executing in cooperation. The terminal device can be a computer, mobile phone, or similar device. The server can be understood as an application server or a web server; in actual deployment, this server can be a standalone server or a cluster of servers.
[0055] To facilitate understanding of the technical solutions provided in the embodiments of this application, a data processing method provided in the embodiments of this application will be introduced next in conjunction with a practical application scenario.
[0056] See Figure 1 , Figure 1This is a schematic diagram of a data processing method in a practical application scenario provided by an embodiment of this application. In this practical application scenario, the processing device is a server 101, and the account feature value transfer information can be transaction information that can reflect the account feature value transfer situation.
[0057] During feature value verification, server 101 can obtain the first transaction record information of the target account within the target time period, as well as the first voucher information corresponding to the first transaction record information. This first voucher information is used to request feature value transfer, meaning it can trigger the first transaction record information. Understandably, if all feature value transfers are normal, the amount of feature value transfer requested by the first voucher information should match the amount of feature value transfer identified by the first transaction record information. Based on this, server 101 can determine whether the first voucher information and the first transaction record information match. If the amount of feature value transfer identified by the first transaction record information does not match the amount of feature value transfer requested by the first voucher information, it indicates that the first transaction record information is abnormal. In this case, to quickly locate the abnormality, server 101 can obtain the business identifier corresponding to the first transaction record information. This business identifier is generated based on the first voucher information and is used to identify the business corresponding to the first transaction record information. Server 101 can generate the first alarm information corresponding to the service identifier. The first alarm information is used to indicate that the service corresponding to the service identifier has experienced an abnormal transfer of feature value, so that relevant personnel can be notified of the abnormal service in a timely manner and handle it, thereby protecting the security of the feature value account and improving the processing efficiency.
[0058] Next, with reference to the accompanying drawings, a data processing method provided by an embodiment of this application will be described.
[0059] See Figure 2 , Figure 2 A flowchart of a data processing method provided in this application embodiment, the method including:
[0060] S201: Obtain the account feature value change information of the target account within the target time period, and the first credential information corresponding to the account feature value change information.
[0061] The target account is the account that requires feature value verification. Feature value is a form of asset representation, which can be virtual assets or have corresponding physical assets, financial products, etc. Users can transfer their feature values to other users to obtain other users' goods, services, etc. The target account is the account used by the user to store and manage feature values, such as an account registered by the user in asset management software. Feature values are not necessarily monetary storage data; they can also be other data that can be transferred between different accounts, such as data content stored between different storage devices, or the quantity of goods stored between different warehouses.
[0062] To verify whether there are any issues with the flow of feature values in the target account, the processing device can acquire account feature value change information and first voucher information within a target time period. This target time period can be a preset unit of time for analysis, such as one day or multiple days. The first voucher information is used to request feature value transfer, and the account feature value change information is used to identify the feature value changes within the target time period. That is, the first voucher information is crucial in triggering the account feature value change information; only after receiving the first voucher information will the corresponding changes be made to the feature values in the target account. For example, the first voucher information can be a payment voucher, deposit order, withdrawal order, etc.
[0063] S202: In response to the mismatch between the feature value transfer amount identified by the account feature value change information and the feature value transfer amount requested by the first credential information, obtain the business identifier corresponding to the account feature value change information.
[0064] Understandably, since account feature value changes are triggered by credential information, if the feature value changes in the target account are normal, the amount of feature value change indicated by the account feature value change information should match the amount of feature value transfer requested by the first credential information. For example, the amount of change indicated by the account feature value change information should be consistent with the requested transfer amount. If they do not match, it indicates that there has been an abnormal feature value change in the target account.
[0065] To enable rapid analysis of abnormal feature value changes, the processing device can determine a business identifier for each account feature value change. This business identifier identifies the business corresponding to the account feature value change. This business identifier is generated based on the voucher information corresponding to the account feature value change. Since this voucher information is typically generated based on the business involved in the target account, a relatively accurate business identifier can be determined using this voucher information.
[0066] Based on this, in this embodiment of the application, in response to the mismatch between the feature value change amount identified by the account feature value change information and the feature value transfer amount requested by the first credential information, the processing device can obtain the business identifier corresponding to the account feature value change information, which is generated based on the first credential information.
[0067] S203: Generate the first alarm information corresponding to the service identifier.
[0068] To enable relevant equipment or personnel to promptly process abnormal account characteristic value changes, the processing equipment can generate a first alarm message based on the service identifier. This first alarm message indicates that an abnormal characteristic value change has occurred in the service corresponding to the service identifier. Thus, this first alarm message can promptly notify the service of the anomaly, facilitating the processing of the abnormal account characteristic value change. Since this application can quickly locate abnormal services based on the service identifier corresponding to the account characteristic value change information, even if the target account involves characteristic value transfers across multiple services, the processing equipment can accurately identify the abnormal information and issue an alarm in a timely manner.
[0069] As can be seen from the above technical solution, during the feature value security check, the system can obtain the target account's feature value change information within a target time period, as well as the first credential information corresponding to this feature value change information. This first credential information is used to request feature value transfer, and the account feature value change information is used to identify the feature value changes within the target time period. If there are no abnormalities in the feature value changes within the target time period, the feature value transfer amount requested by the first credential information should match the feature value change amount identified by the account feature value change information. If the feature value change amount identified by the account feature value change information does not match the feature value transfer amount requested by the first credential information, it indicates that an abnormal feature value change has occurred in the account feature value change information. In this case, the processing device can obtain the business identifier corresponding to the account feature value change information. This business identifier is generated based on the first credential information. Through this business identifier, the business corresponding to the account feature value change information can be determined, thereby generating a first alarm message indicating an abnormal feature value change in this business. This allows relevant personnel to promptly be aware of the abnormal business and take appropriate action, further improving the security of the feature values.
[0070] The account characteristic value change information can include multiple types. In one possible implementation, the account characteristic value change information can include first transaction information and / or first characteristic value balance information. The first transaction information is used to identify the characteristic value transfer of the target account within the target time period, and the first characteristic value balance change information is used to identify the characteristic value balance change of the target account within the target time period.
[0071] Regarding account feature value change information, including first transaction history information, if the feature value transfer amount identified by the first transaction history information does not match the feature value transfer amount requested by the first voucher information, the processing device can obtain the aforementioned business identifier and issue an alarm. Regarding account feature value change information, including first feature value balance information, it is understood that the feature value balance change is due to a feature value transfer, which is based on voucher information. Therefore, under normal circumstances, the feature value change amount identified by the first feature value balance information should match the feature value transfer amount requested by the first voucher information. If they do not match, it indicates an anomaly in the transaction history information within the target time period. Based on this, in response to the mismatch between the feature value transfer amount requested by the first voucher information and the feature value balance change amount identified by the first feature value balance information, the processing device can also obtain the aforementioned business identifier and perform corresponding alarm operations.
[0072] like Figure 3 As shown in this embodiment, voucher information, transaction history information, and balance information can be mutually verified to check the characteristic values in the account. For example, such as Figure 4 As shown, the processing equipment can verify the transit account B. Inflow records are the transactions entering the transit account B, and outflow records are the transactions leaving the transit account B. Figure 4 In the data, deposit and withdrawal orders are document information, corresponding to 100 and 80 respectively. The processing equipment can then determine the corresponding transaction information for these document information. Specifically, deposit order 100 corresponds to an inflow of 90, and withdrawal order 80 corresponds to an outflow of 60. Therefore, both the inflow and outflow transactions are abnormal. Regarding the account balance, the total characteristic value transfer amount x determined from the document information should be 20, while the actual balance characteristic value change is 30, further indicating an anomaly in the transaction information.
[0073] Understandably, the normal operation of a business can be reflected in the corresponding transaction log information. This application mainly analyzes the business situation through single transaction log information and total transaction log information within a certain period, as shown below:
[0074] First, the processing device can obtain the feature value transfer threshold corresponding to the service identifier. This feature value transfer threshold is determined based on the historical transaction information corresponding to the service identifier, and it can identify the amount of feature value transfer under normal business conditions. Therefore, when the amount of feature value transfer identified by the first transaction information exceeds this feature value transfer threshold, it indicates that an anomaly has occurred in the service corresponding to the first transaction information. Based on this, during feature value verification, in response to the feature value transfer amount identified by the first transaction information exceeding the feature value transfer threshold, the processing device can generate a first alarm message corresponding to the service identifier, so as to issue an alarm for the service corresponding to the first transaction information.
[0075] Secondly, in one possible implementation, the processing device can also perform a comprehensive analysis of the transaction information of multiple accounts corresponding to the business within a certain time period to determine whether the business is proceeding normally. The processing device can obtain the second transaction information and / or second voucher information corresponding to the business identifier within the target time period. The second transaction information includes the first transaction information corresponding to multiple accounts within the target time period, and the second voucher information includes the first voucher information corresponding to multiple accounts within the target time period.
[0076] The processing device can determine the characteristic value inflow and characteristic value outflow corresponding to the business identifier within the target time period based on the second transaction information and / or the second voucher information. The characteristic value inflow is the amount of characteristic values transferred into these accounts under this business within the target time period, and the characteristic value outflow is the amount of characteristic values transferred out of these accounts under this business within the target time period. It is understood that when a business is operating normally, its revenue and expenditure characteristics should be stable over a period of time. Based on this, the processing device can determine the revenue and expenditure deviation corresponding to the business identifier within the target time period based on the characteristic value inflow and characteristic value outflow. This revenue and expenditure deviation reflects the revenue and expenditure deviation of the business corresponding to the business identifier within the target time period. The processing device can determine whether the business corresponding to the business identifier is normal based on the revenue and expenditure deviation and the business evaluation conditions corresponding to the business identifier. These business evaluation conditions are generated based on the historical transaction information corresponding to the business identifier; that is, the business evaluation conditions can analyze the revenue and expenditure of the business under normal conditions from the perspective of historical transaction flow.
[0077] Understandably, due to the time required for feature value transfer, the requested feature value may not immediately appear in the account transaction history after the voucher information is generated. For example, an account may have a voucher information indicating a transfer of feature value 100; however, because this feature value is still in transit, the corresponding transaction history for that voucher information is not yet available for verification at that time. Therefore, to achieve more accurate verification, in one possible implementation, the target time period includes multiple sub-time periods, each of which can be a small cycle for feature value verification.
[0078] The processing device can determine the first sub-transaction information and the first sub-voucher information corresponding to each sub-time period. Then, based on the feature value transfer amount identified by the first sub-transaction information and the feature value transfer amount requested by the first sub-voucher information, it determines the difference in feature value transfer amounts for each sub-time period. The processing device can combine the feature value transfer amounts of multiple sub-time periods to determine whether there are any problems with feature value transfer within the target time period, thereby ensuring that the feature values have sufficient transfer time.
[0079] The processing device can preset a first threshold, which is used to determine whether the differences in feature value transfer amounts across multiple sub-periods within the target time period are balanced; for example, it can be set to 0. If the absolute value of the sum of the feature value transfer amount differences across multiple sub-periods exceeds the first threshold, it indicates that abnormal transaction information does exist in those sub-periods. At this point, the processing device can obtain the aforementioned business identifier to generate an alarm message. In this way, the processing device can provide a buffer period for feature value transfer, avoiding directly classifying feature values that are in normal transfer process but have not yet reached the account as abnormal transaction information, further improving the rationality of feature value verification.
[0080] If the absolute value of the sum of the feature value transfer differences corresponding to multiple sub-time periods does not exceed a first threshold, it indicates that there is no actual abnormal transaction information in the multiple sub-time periods within the target time period. At this point, the processing device can cancel multiple second alarm messages corresponding to the sub-time periods. These second alarm messages are generated in response to the absolute value of the feature value transfer differences corresponding to the sub-time periods exceeding the second threshold. The second threshold is used to determine whether the feature value transfer differences corresponding to each sub-time period are abnormal; for example, it can be set to 0. When the feature value transfer difference is not 0, it indicates that the transaction information and voucher information within that sub-time period do not match. In this way, the processing device can perform self-checks on the generated second alarm messages periodically based on the target time period, thereby automatically eliminating second alarm messages caused by normal reasons such as slow feature value transfer speed.
[0081] On the other hand, when the absolute value of the sum of the feature value transfer differences corresponding to multiple sub-periods exceeds the first threshold, the processing device can generate the first alarm information corresponding to the service identifier based on the second alarm information corresponding to the multiple sub-periods. This enables the first alarm information to accurately reflect which sub-periods have abnormal flow conditions, so that relevant personnel can conduct more accurate analysis.
[0082] To facilitate understanding of the technical solutions provided in the embodiments of this application, a data processing method provided in the embodiments of this application will be described below in conjunction with a practical application scenario. In this practical application scenario, the data processing method can be applied to... Figure 5 The server architecture shown. See also Figure 6 , Figure 6 A flowchart illustrating a data processing method in a practical application scenario provided in this application embodiment, the method comprising:
[0083] S601: Perform feature value verification task.
[0084] S602: Determine if the data source is ready. If it is ready, proceed to S604. If it is not ready, obtain the statement of account through step S603. The statement of account contains voucher information, transaction information and balance information.
[0085] S604: Journal entry (running log).
[0086] When a transaction occurs, a journal entry is first generated, which then drives a change in the account balance. After the account balance changes, a subsidiary ledger is generated. At the end of the day, a general ledger is generated based on the journal entry. Depending on business needs, the account balance can also be modified first, and then a journal entry can be generated asynchronously. However, regardless of whether the accounting entries are generated first or asynchronously, the consistency between the journal entry and the subsidiary ledger balance must be ensured. This is guaranteed by a check performed by the system at the end of the day.
[0087] S605: Generate general ledger.
[0088] S606: General ledger calculation balance.
[0089] In this step, the processing equipment can determine whether there are any abnormalities in the transfer of characteristic values on the account by using voucher information, transaction information, and balance information.
[0090] The accounting system is divided into two main modules: daytime and end-of-day. During the daytime, business-driven accounting completes the recording of transactions. The system uses different transaction codes and sets entry rules based on different business scenarios, splitting entries and modifying balances. At the end of the day, a balance check is performed to ensure the consistency and accuracy of the accounting system data, and a general ledger is generated. The specific implementation steps are as follows:
[0091] Step 1: Daytime Income
[0092] Journal entries record the ins and outs of every financial activity.
[0093] Specific elements: transaction date, account number, account, debit / credit, account, transaction amount, etc.
[0094] Step 2: Generate General Ledger
[0095] Based on the journal entries, a general ledger is generated, with account transactions and balances summarized from the lowest-level accounts to the highest-level accounts.
[0096] Step 3: General Ledger Reconciliation
[0097] The formula for determining the account balance difference is: Account Balance Difference = ∑(X - Y + Z), where X represents the voucher information, such as the difference in characteristic values between orders, X = Deposit Order A - Withdrawal Order B. For example, in Scenario 3, Deposit Order A is 100, and Withdrawal Order B is 80, so X = 100 - 80 = 20; Y represents the difference between the voucher information and transaction information of the inflow account's characteristic value, i.e., Y = Deposit Order A - Inflow Transaction C. In Scenario 3, Inflow Transaction C is 100, so Y = 100 - 100 = 0; Z represents the difference between the voucher information and transaction information of the outflow account's characteristic value, i.e., Z = Withdrawal Order B - Outflow Transaction D. In Scenario 3, Withdrawal Order B is 80, and Outflow Transaction D is 60, so Z = 80 - 60 = 20. Therefore, the corresponding balance difference in Scenario 3 is X - Y + Z = 20 - 0 + 20 = 40. In fact, in the above formula, X-Y+Z=AB-(AC)+(BD)=CD, where CD is the difference between inflow and outflow, and is also the factor determining the balance difference. Therefore, the formula is valid. This formula allows for two types of verification: First, the difference in characteristic values identified by the voucher information should be the same as the balance difference, i.e., X = balance difference. If X is not equal to the balance difference, it indicates that the actual change in characteristic values differs from the change in characteristic values identified by the voucher information. Second, the transfer of characteristic values identified by the voucher information and the transaction information should be consistent, i.e., Y and Z are normally both 0, in which case X is the balance difference. Under normal circumstances, ∑Difference between inflow and outflow orders = ∑Difference between inflow and outflow transactions. However, abnormal situations cannot be ruled out. When orders drive changes in transaction information, the inflow and outflow transactions are inconsistent with the orders. This situation indicates abnormal transaction information. The table below shows the possible characteristic value verification results. The balance difference determined by this formula can be compared with X to accurately analyze whether the characteristic value transfer is abnormal, considering the transaction information, voucher information, and balance information.
[0098]
[0099] Step 4: Check the total score.
[0100] It's understandable that accounts can be divided into sub-accounts and parent accounts, such as sub-cards and parent cards in a bank account. If the general ledger doesn't match, the process moves to the detailed account reconciliation stage to pinpoint the abnormal transactions.
[0101] General ledger account balance = sum of subsidiary ledger account balances. Because business operations continue 24 / 7, subsidiary ledger balances are constantly changing, making it impossible to accurately retrieve the year-end account balances for reconciliation. Therefore, a balance snapshot can be used to reconcile with the general ledger account balances.
[0102] Audit details involve checking whether the detailed ledger matches the journal entries. For accounts that experienced balance changes on the same day, the previous day's balance is reconciled with the amount recorded in the journal entries, and the calculated balance is checked to ensure it matches the snapshot balance.
[0103] Step 5: Difference Management and Handling
[0104] Account balances provide T0 reconciliation capability. Finance departments monitor account balance discrepancies, and the system summarizes discrepancies by aging, facilitating subsequent discrepancy detection and processing. Report display: 1) Default display of the unprocessed list; 2) Filtering options: Date, Business, Account Type, Status; 3) Historical discrepancy queries can be displayed later. Figure 7 As shown, Figure 7 An interface for displaying verification results is shown. The "age" refers to the time when the verification result was generated, and the processing equipment can process verification results from multiple days together.
[0105] S607: Determine if a match is found.
[0106] If a match is found, the process will proceed directly to S608 to generate an invoice; otherwise, the process will proceed to S609 to generate an alarm message based on the business identifier corresponding to the transaction information.
[0107] S610: Start total score verification.
[0108] S611: Locate abnormal business.
[0109] The processing equipment can identify abnormal services based on the service identifier in the alarm information and analyze the abnormal services.
[0110] S612: Alarm information processing.
[0111] The processing device can be set to a target time period, such as 5 days, and will perform reviews every 5 days. If the processing device determines that the overall feature value transfer of an account within those 5 days matches, it can cancel the alarm information generated by abnormal feature value transfer on a single day within those 5 days, thus automatically handling these abnormal transaction records caused by normal factors such as feature value transfer time. If they do not match, the abnormal transaction record analysis can be switched to manual analysis.
[0112] S613: Determine if it is a data source problem.
[0113] The processing device can also check the data source. If there is a problem with the data, the verification result will also be inaccurate. At this time, it can jump to S616, directly abandon the task, and execute S617 to re-verify the feature value.
[0114] S614: Click to balance the accounts.
[0115] After automatic or manual processing by the processing equipment, once the abnormal situation in the transaction record is resolved, relevant personnel can trigger the reconciliation function in the system, execute S615, cancel the alarm information, update the adjusted transaction record information to the account information, and generate a bill.
[0116] Based on the data processing method provided in the above embodiments, this application also provides a data processing apparatus, see [link to relevant documentation]. Figure 8 , Figure 8 This application provides a structural block diagram of a data processing apparatus, which includes a first acquisition unit 801, a first response unit 802, and a generation unit 803.
[0117] The first acquisition unit 801 is used to acquire account feature value change information of the target account within a target time period, and first credential information corresponding to the account feature value change information. The first credential information is used to request feature value transfer, and the account feature value change information is used to identify the feature value change of the target account within the target time period.
[0118] The first response unit 802 is configured to, in response to a mismatch between the feature value change amount identified by the account feature value change information and the feature value transfer amount requested by the first credential information, obtain a business identifier corresponding to the account feature value change information, wherein the business identifier is generated based on the first credential information;
[0119] The generation unit 803 is used to generate a first alarm message corresponding to the service identifier, the first alarm message being used to indicate that the service corresponding to the service identifier has an abnormal change in feature value.
[0120] In one possible implementation, the account feature value change information includes first transaction history information and / or first feature value balance information, wherein the first transaction history information is used to identify the feature value transfer of the target account within the target time period, and the first feature value balance change information is used to identify the feature value balance change of the target account within the target time period.
[0121] The first response unit 802 is specifically used for:
[0122] In response to the mismatch between the feature value transfer amount identified by the first transaction information and the feature value transfer amount requested by the first credential information, the business identifier is obtained.
[0123] In response to a mismatch between the feature value transfer amount requested by the first credential information and the feature value balance change amount identified by the first feature value balance information, the business identifier is obtained.
[0124] In one possible implementation, the device further includes a second acquisition unit and a second response unit:
[0125] The second acquisition unit is used to acquire the feature value transfer threshold corresponding to the service identifier, wherein the feature value transfer threshold is determined based on the historical transaction information corresponding to the service identifier;
[0126] The second response unit is configured to generate the first alarm information corresponding to the service identifier in response to the feature value transfer amount identified by the first flow information exceeding the feature value transfer threshold.
[0127] In one possible implementation, the apparatus further includes a third acquisition unit, a first determination unit, a second determination unit, and a third determination unit:
[0128] The third acquisition unit is used to acquire the second transaction information and / or the second voucher information corresponding to the business identifier within the target time period. The second transaction information includes the first transaction information corresponding to multiple accounts within the target time period, and the second voucher information includes the first voucher information corresponding to multiple accounts within the target time period.
[0129] The first determining unit is configured to determine the feature value inflow and feature value outflow corresponding to the business identifier within the target time period based on the second transaction information and / or the second voucher information;
[0130] The second determining unit is used to determine the revenue and expenditure deviation corresponding to the business identifier in the target time period based on the amount of feature value transferred in and the amount of feature value transferred out.
[0131] The third determining unit is used to determine whether the business corresponding to the business identifier is normal based on the income and expenditure deviation and the business evaluation conditions corresponding to the business identifier. The business evaluation conditions are generated based on the historical transaction information corresponding to the business identifier.
[0132] In one possible implementation, the target time period includes multiple sub-time periods, and the first response unit 802 is specifically used for:
[0133] Determine the first sub-transaction log information and the first sub-voucher information corresponding to each sub-time period;
[0134] Based on the feature value transfer amount identified by the first sub-transaction information and the feature value transfer amount requested by the first sub-voucher information, determine the feature value transfer amount difference corresponding to each sub-time period;
[0135] In response to the absolute value of the sum of the feature value transfer differences corresponding to the multiple sub-time periods exceeding a first threshold, the service identifier is obtained.
[0136] In one possible implementation, the device further includes a third response unit:
[0137] The third response unit is used to cancel the second alarm information corresponding to the multiple sub-time periods in response to the absolute value of the sum of the feature value transfer difference values corresponding to the multiple sub-time periods not exceeding the first threshold. The second alarm information is generated in response to the absolute value of the feature value transfer difference values corresponding to the sub-time periods exceeding the second threshold. The second alarm information is used to indicate that the feature value transfer corresponding to the sub-time period is abnormal.
[0138] The generation unit 803 is specifically used for:
[0139] Based on the second alarm information corresponding to the multiple sub-time periods, the first alarm information corresponding to the service identifier is generated.
[0140] This application also provides a computer device, which will be described below with reference to the accompanying drawings. Please refer to... Figure 9 As shown in the figure, this application provides a device, which can also be a terminal device. The terminal device can be any smart terminal, including mobile phones, tablets, personal digital assistants (PDAs), point-of-sale (POS) terminals, in-vehicle computers, etc. Taking a mobile phone as an example:
[0141] Figure 9 This diagram illustrates a partial structural representation of a mobile phone related to the terminal device provided in this embodiment. (Reference) Figure 9 The mobile phone includes components such as a radio frequency (RF) circuit 710, a memory 720, an input unit 730, a display unit 740, a sensor 750, an audio circuit 760, a Wi-Fi module 770, a processor 780, and a power supply 790. Those skilled in the art will understand that... Figure 9 The mobile phone structure shown does not constitute a limitation on the mobile phone and may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0142] The following is combined Figure 9 A detailed introduction to each component of a mobile phone:
[0143] RF circuit 710 can be used for receiving and transmitting signals during information transmission or calls. Specifically, it receives downlink information from the base station and processes it with processor 780; additionally, it transmits uplink data to the base station. Typically, RF circuit 710 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier (LNA), and a duplexer. Furthermore, RF circuit 710 can also communicate wirelessly with networks and other devices. The aforementioned wireless communication can use any communication standard or protocol, including but not limited to Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Long Term Evolution (LTE), email, and Short Messaging Service (SMS).
[0144] The memory 720 can be used to store software programs and modules. The processor 780 executes various mobile phone functions and data processing by running the software programs and modules stored in the memory 720. The memory 720 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, applications required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 720 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0145] The input unit 730 can be used to receive input numerical or character information, and to generate key signal inputs related to user settings and function control of the mobile phone. Specifically, the input unit 730 may include a touch panel 731 and other input devices 732. The touch panel 731, also known as a touch screen, can collect touch operations performed by the user on or near it (such as operations performed by the user using a finger, stylus, or any suitable object or accessory on or near the touch panel 731), and drive the corresponding connected devices according to a pre-set program. Optionally, the touch panel 731 may include two parts: a touch detection device and a touch controller. The touch detection device detects the user's touch position and the signal generated by the touch operation, and transmits the signal to the touch controller; the touch controller receives touch information from the touch detection device, converts it into touch point coordinates, and sends it to the processor 780, and can also receive and execute commands sent by the processor 780. In addition, the touch panel 731 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch panel 731, the input unit 730 may also include other input devices 732. Specifically, other input devices 732 may include, but are not limited to, one or more of the following: physical keyboard, function keys (such as volume control buttons, power buttons, etc.), trackball, mouse, joystick, etc.
[0146] The display unit 740 can be used to display information input by the user or information provided to the user, as well as various menus of the mobile phone. The display unit 740 may include a display panel 741, which may optionally be configured as a Liquid Crystal Display (LCD), Organic Light-Emitting Diode (OLED), or similar display panel. Further, a touch panel 731 may cover the display panel 741. When the touch panel 731 detects a touch operation on or near it, it transmits the information to the processor 780 to determine the type of touch event. Subsequently, the processor 780 provides corresponding visual output on the display panel 741 based on the type of touch event. Although in Figure 9 In this embodiment, the touch panel 731 and the display panel 741 are two separate components to realize the input and output functions of the mobile phone. However, in some embodiments, the touch panel 731 and the display panel 741 can be integrated to realize the input and output functions of the mobile phone.
[0147] The mobile phone may also include at least one sensor 750, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor. The ambient light sensor can adjust the brightness of the display panel 741 according to the ambient light level, and the proximity sensor can turn off the display panel 741 and / or backlight when the phone is moved to the ear. As a type of motion sensor, an accelerometer sensor can detect the magnitude of acceleration in various directions (generally three axes). When stationary, it can detect the magnitude and direction of gravity and can be used for applications that recognize the phone's posture (such as landscape / portrait switching, related games, magnetometer posture calibration), vibration recognition-related functions (such as pedometer, taps), etc. Other sensors that may be configured in the mobile phone, such as gyroscopes, barometers, hygrometers, thermometers, and infrared sensors, will not be described in detail here.
[0148] Audio circuit 760, speaker 761, and microphone 762 provide an audio interface between the user and the mobile phone. Audio circuit 760 converts received audio data into electrical signals and transmits them to speaker 761, where speaker 761 converts them into sound signals for output. On the other hand, microphone 762 converts collected sound signals into electrical signals, which are received by audio circuit 760, converted into audio data, and then processed by processor 780 before being transmitted via RF circuit 710 to, for example, another mobile phone, or the audio data can be output to memory 720 for further processing.
[0149] WiFi is a short-range wireless transmission technology. Through the WiFi module 770, mobile phones can help users send and receive emails, browse web pages, and access streaming media, providing users with wireless broadband internet access. Although Figure 9 The WiFi module 770 is shown, but it is understood that it is not an essential component of a mobile phone and can be omitted as needed without changing the essence of the invention.
[0150] The processor 780 is the control center of the mobile phone, connecting various parts of the phone through various interfaces and lines. It performs various functions and processes data by running or executing software programs and / or modules stored in the memory 720, and by calling data stored in the memory 720. Optionally, the processor 780 may include one or more processing units; preferably, the processor 780 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may also not be integrated into the processor 780.
[0151] The mobile phone also includes a power supply 790 (such as a battery) that supplies power to various components. Preferably, the power supply can be logically connected to the processor 780 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system.
[0152] Although not shown, mobile phones may also include a camera, Bluetooth module, etc., which will not be described in detail here.
[0153] In this embodiment, the processor 780 included in the terminal device also has the following functions:
[0154] Obtain account feature value change information of the target account within a target time period, and first credential information corresponding to the account feature value change information. The first credential information is used to request feature value transfer, and the account feature value change information is used to identify the feature value change of the target account within the target time period.
[0155] In response to a mismatch between the feature value change amount identified by the account feature value change information and the feature value transfer amount requested by the first credential information, a business identifier corresponding to the account feature value change information is obtained, and the business identifier is generated based on the first credential information.
[0156] Generate a first alarm message corresponding to the service identifier. The first alarm message is used to indicate that the service corresponding to the service identifier has an abnormal change in feature value.
[0157] This application also provides a server; please refer to [link / reference]. Figure 10 As shown, Figure 10 This is a structural diagram of a server 800 provided in an embodiment of this application. The server 800 can vary significantly due to different configurations or performance. It may include one or more Central Processing Units (CPUs) 822 (e.g., one or more processors) and a memory 832, and one or more storage media 830 (e.g., one or more mass storage devices) for storing application programs 842 or data 844. The memory 832 and storage media 830 can be temporary or persistent storage. The program stored in the storage media 830 may include one or more modules (not shown in the diagram), each module including a series of instruction operations on the server. Furthermore, the CPU 822 may be configured to communicate with the storage media 830 and execute the series of instruction operations in the storage media 830 on the server 800.
[0158] Server 800 may also include one or more power supplies 826, one or more wired or wireless network interfaces 850, one or more input / output interfaces 858, and / or one or more operating systems 841, such as Windows Server. TM Mac OS X TM Unix TM Linux TM FreeBSD TM etc.
[0159] The steps performed by the server in the above embodiments can be based on Figure 10 The server structure shown.
[0160] This application also provides a computer-readable storage medium for storing a computer program that executes any one of the data processing methods described in the foregoing embodiments.
[0161] This application also provides a computer program product including instructions, which, when run on a computer, causes the computer to execute the data processing method provided in any of the above embodiments.
[0162] It is understood that in the specific implementation of this application, data related to user information (such as the account description information of a user's media account) is involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0163] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium can be at least one of the following media: read-only memory (ROM), RAM, magnetic disk, or optical disk, etc., and other media capable of storing program code.
[0164] It should be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for the device and system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments. The device and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the solution in this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0165] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A data processing method, characterized in that, The method includes: Obtain account feature value change information of the target account within a target time period, and first credential information corresponding to the account feature value change information. The first credential information is used to request feature value transfer. The account feature value change information is used to identify the feature value change of the target account within the target time period. The account feature value change information includes first transaction information and / or first feature value balance information. The first transaction information is used to identify the feature value transfer of the target account within the target time period, and the first feature value balance change information is used to identify the feature value balance change of the target account within the target time period. In response to the mismatch between the feature value transfer amount identified by the first transaction information and the feature value transfer amount requested by the first credential information, the business identifier corresponding to the account feature value change information is obtained. In response to a mismatch between the feature value transfer amount requested by the first credential information and the feature value balance change amount identified by the first feature value balance information, the business identifier corresponding to the account feature value change information is obtained. The business identifier is generated based on the first credential information corresponding to the account feature value change information. Generate a first alarm message corresponding to the service identifier. The first alarm message is used to indicate that the service corresponding to the service identifier has an abnormal change in feature value.
2. The method according to claim 1, characterized in that, The method further includes: Obtain the feature value transfer threshold corresponding to the service identifier, wherein the feature value transfer threshold is determined based on the historical transaction information corresponding to the service identifier; In response to the feature value transfer amount identified by the first flow information exceeding the feature value transfer threshold, the first alarm information corresponding to the service identifier is generated.
3. The method according to claim 1, characterized in that, The method further includes: Obtain the second transaction information and / or second voucher information corresponding to the business identifier within the target time period. The second transaction information includes the first transaction information corresponding to multiple accounts within the target time period, and the second voucher information includes the first voucher information corresponding to multiple accounts within the target time period. Based on the second transaction information and / or the second voucher information, determine the feature value inflow and feature value outflow corresponding to the business identifier within the target time period; Based on the amount of transfers in and out of the characteristic value, determine the revenue and expenditure deviation corresponding to the business identifier within the target time period; Based on the revenue and expenditure deviation and the business evaluation criteria corresponding to the business identifier, it is determined whether the business corresponding to the business identifier is normal. The business evaluation criteria are generated based on the historical transaction information corresponding to the business identifier.
4. The method according to claim 1, characterized in that, The target time period includes multiple sub-time periods. The step of obtaining the business identifier in response to a mismatch between the feature value transfer amount identified by the first transaction information and the feature value transfer amount requested by the first voucher information includes: Determine the first sub-transaction log information and the first sub-voucher information corresponding to each sub-time period; Based on the feature value transfer amount identified by the first sub-transaction information and the feature value transfer amount requested by the first sub-voucher information, determine the feature value transfer amount difference corresponding to each sub-time period; In response to the absolute value of the sum of the feature value transfer differences corresponding to the multiple sub-time periods exceeding a first threshold, the service identifier is obtained.
5. The method according to claim 4, characterized in that, The method further includes: In response to the absolute value of the sum of the feature value transfer differences corresponding to the plurality of sub-time periods not exceeding the first threshold, the second alarm information corresponding to the plurality of sub-time periods is cancelled. The second alarm information is generated in response to the absolute value of the feature value transfer differences corresponding to the sub-time periods exceeding the second threshold. The second alarm information is used to indicate that the feature value transfer corresponding to the sub-time period is abnormal. The generation of the first alarm information corresponding to the service identifier includes: Based on the second alarm information corresponding to the multiple sub-time periods, the first alarm information corresponding to the service identifier is generated.
6. A data processing apparatus, characterized in that, The device includes a first acquisition unit, a first response unit, and a generation unit: The first acquisition unit is used to acquire account feature value change information of the target account within a target time period, and first credential information corresponding to the account feature value change information. The first credential information is used to request feature value transfer, and the account feature value change information is used to identify the feature value change of the target account within the target time period. The first response unit is configured to, in response to a mismatch between the feature value change amount identified by the account feature value change information and the feature value transfer amount requested by the first credential information, obtain a business identifier corresponding to the account feature value change information, wherein the business identifier is generated based on the first credential information corresponding to the account feature value change information; The generation unit is used to generate a first alarm message corresponding to the service identifier, and the first alarm message is used to indicate that the service corresponding to the service identifier has an abnormal change in feature value. The account feature value change information includes first transaction information and / or first feature value balance information. The first transaction information is used to identify the feature value transfer of the target account within the target time period, and the first feature value balance change information is used to identify the feature value balance change of the target account within the target time period. The first response unit is specifically used for: In response to the mismatch between the feature value transfer amount identified by the first transaction information and the feature value transfer amount requested by the first credential information, the business identifier is obtained. In response to a mismatch between the feature value transfer amount requested by the first credential information and the feature value balance change amount identified by the first feature value balance information, the business identifier is obtained.
7. The apparatus according to claim 6, characterized in that, The device further includes a second acquisition unit and a second response unit: The second acquisition unit is used to acquire the feature value transfer threshold corresponding to the service identifier, wherein the feature value transfer threshold is determined based on the historical transaction information corresponding to the service identifier; The second response unit is configured to generate the first alarm information corresponding to the service identifier in response to the feature value transfer amount identified by the first flow information exceeding the feature value transfer threshold.
8. The apparatus according to claim 6, characterized in that, The device further includes a third acquisition unit, a first determination unit, a second determination unit, and a third determination unit: The third acquisition unit is used to acquire the second transaction information and / or the second voucher information corresponding to the business identifier within the target time period. The second transaction information includes the first transaction information corresponding to multiple accounts within the target time period, and the second voucher information includes the first voucher information corresponding to multiple accounts within the target time period. The first determining unit is configured to determine the feature value inflow and feature value outflow corresponding to the business identifier within the target time period based on the second transaction information and / or the second voucher information; The second determining unit is used to determine the revenue and expenditure deviation corresponding to the business identifier in the target time period based on the amount of feature value transferred in and the amount of feature value transferred out. The third determining unit is used to determine whether the business corresponding to the business identifier is normal based on the income and expenditure deviation and the business evaluation conditions corresponding to the business identifier. The business evaluation conditions are generated based on the historical transaction information corresponding to the business identifier.
9. The apparatus according to claim 6, characterized in that, The target time period includes multiple sub-time periods, and the first response unit is specifically used for: Determine the first sub-transaction log information and the first sub-voucher information corresponding to each sub-time period; Based on the feature value transfer amount identified by the first sub-transaction information and the feature value transfer amount requested by the first sub-voucher information, determine the feature value transfer amount difference corresponding to each sub-time period; In response to the absolute value of the sum of the feature value transfer differences corresponding to the multiple sub-time periods exceeding a first threshold, the service identifier is obtained.
10. The apparatus according to claim 9, characterized in that, The device also includes a third response unit: The third response unit is used to cancel the second alarm information corresponding to the multiple sub-time periods in response to the absolute value of the sum of the feature value transfer difference values corresponding to the multiple sub-time periods not exceeding the first threshold. The second alarm information is generated in response to the absolute value of the feature value transfer difference values corresponding to the sub-time periods exceeding the second threshold. The second alarm information is used to indicate that the feature value transfer corresponding to the sub-time period is abnormal. The generation unit is specifically used for: Based on the second alarm information corresponding to the multiple sub-time periods, the first alarm information corresponding to the service identifier is generated.
11. A computer device, characterized in that, The device includes a processor and a memory: The memory is used to store program code and transmit the program code to the processor; The processor is configured to execute the data processing method according to any one of claims 1-5 according to the instructions in the program code.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program for performing the data processing method according to any one of claims 1-5.
13. A computer program product comprising instructions that, when run on a computer, causes the computer to perform the data processing method according to any one of claims 1-5.