Banking data processing method, device and electronic equipment
By dynamically judging the activation of the risk detection function and generating configuration lists in bank data processing methods, obtaining the data to be detected by multiple application modules, and conducting comprehensive risk detection, the problems of inefficient risk detection and difficulty in adapting to changes in user behavior in the existing technology are solved, and more efficient and flexible risk detection is achieved.
Patent Information
- Application Number
- CN202510193720.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-02-21
AI Technical Summary
In the prior art, the use of static rule models for risk detection is inefficient and difficult to adapt to rapidly changing user behavior, and lacks flexibility.
In the bank data processing method, dynamically determine whether the risk detection function is enabled, a configuration list is generated based on the scene information of the current business scenario, and the data to be detected by multiple application modules are obtained, and comprehensive risk detection is performed.
It improves the efficiency and flexibility of risk detection, can understand user behavior and potential risks more comprehensively, overcomes the limitations of the static rule model, and improves the security of transactions.
Smart Images

Figure CN119693113B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and particularly to a method, device and electronic device for processing bank - related data. Background Art
[0002] In the financial field and bank applications, detecting risks in users' behaviors in application programs is an important measure to ensure transaction security.
[0003] In the prior art, a static rule model is usually used to detect risks in a large amount of operation data of users collected in application programs. For example, for a large amount of operation data of users in a bank transfer application program, a static rule model is used for risk detection, and this static rule model performs risk detection based on predefined rules and thresholds.
[0004] However, due to the large amount of data to be detected, the efficiency of using a static rule model for detection is low, and the static rule model is also difficult to adapt to rapidly changing user behaviors and lacks a certain degree of flexibility. Summary of the Invention
[0005] This application provides a method, device and electronic device for processing bank - related data, which is used to solve the problems of low efficiency in using a static rule model for risk detection in the prior art, difficulty in adapting to rapidly changing user behaviors, and lack of a certain degree of flexibility.
[0006] In a first aspect, this application provides a method for processing bank - related data, which is applied to a target application program. The method includes:
[0007] In response to a transaction request initiated by a user through the target application program, obtain the behavior data of the user in the target application program, and determine whether to enable the risk detection function according to the behavior data; the behavior data includes at least one type of data related to the business activities of the bank;
[0008] If it is determined to enable the risk detection function, then according to the scenario information corresponding to the current business scenario, determine the configuration list for risk detection corresponding to the target application program, and the configuration list is used to indicate: the associated application program corresponding to the current business scenario determined from multiple application programs;
[0009] Among them, different associated application programs correspond to interfaces of their respective application program modules; the application program modules include a communication module, a call module, a media management module, and a browser module;
[0010] Obtain the data to be detected from the interfaces of the application modules corresponding to the associated application programs based on a preset interface, where the data to be detected includes at least one of the text data of the communication module, the call record data of the call module, the image data of the media management module, and the browsing record data of the browser module;
[0011] Determine a target detection method from at least one detection method to perform risk detection on the data to be detected and the behavior data, and execute the transaction operation corresponding to the transaction request after the risk detection passes.
[0012] Optionally, the multiple application programs are determined through a pre-stored configuration file; the scenario information includes: business information and user information; the configuration file is used to indicate: the associated application programs corresponding to different scenario information.
[0013] Optionally, the method further includes:
[0014] Visually display a configuration page; the configuration page includes multiple configuration options, and the configuration options are used to configure: risk preference information and application program authorization information;
[0015] In response to a touch operation of the user on the multiple configuration options in the configuration page, adjust the associated application programs corresponding to at least part of the scenario information in the configuration file to obtain an adjusted configuration file.
[0016] Optionally, the configuration file further includes: an active duration threshold pre-configured for each application program; according to the scenario information corresponding to the current business scenario, determine a configuration list for risk detection corresponding to the target application program, including:
[0017] Determine at least one candidate associated application program according to the scenario information and the configuration file;
[0018] Obtain the active duration of the at least one candidate associated application program, and determine the final associated application program from the at least one candidate associated application program according to the active duration and the active duration threshold.
[0019] Optionally, according to the scenario information corresponding to the current business scenario, determining a configuration list for risk detection corresponding to the target application program includes:
[0020] Determine the current risk level according to the scenario information corresponding to the current business scenario;
[0021] Based on the current risk level, determine a configuration list for risk detection corresponding to the target application program; different risk levels correspond to different numbers of associated application programs.
[0022] Optionally, the application module further includes a clipboard service module, which obtains the behavior data of the user in the target application and determines whether to enable the risk detection function according to the behavior data, including:
[0023] Obtain the behavior data from the clipboard service module based on the preset interface;
[0024] Parse the behavior data to identify the account information to be traded and the transaction amount;
[0025] Conduct a preliminary risk detection on the account information to be traded and the transaction amount, and determine whether to enable the risk detection function based on the result of the preliminary risk detection.
[0026] Optionally, the method further includes:
[0027] After the risk detection passes, determine the location information of the user's first device and the location information of the second device that has a binding relationship with the first device;
[0028] Determine the target verification strategy based on the location information of the first device and the location information of the second device;
[0029] Use the target verification strategy to perform security verification on the transaction request.
[0030] Optionally, the method further includes:
[0031] Obtain the user identity information of the user in the target application;
[0032] Use a preset protocol to obtain the device information of self-service terminals within a preset time and / or a preset area from the cloud, and determine whether the user identity information exists in the device information;
[0033] When it is determined that the user identity information exists in the device information and the business status of the user in the current business scenario is unfinished, generate a prompt message based on the transaction request of the user in the target application.
[0034] In a second aspect, the present application provides a bank-related data processing device, which is applied to a target application. The device includes:
[0035] A judgment module, configured to, in response to a transaction request initiated by a user through a target application, obtain the behavior data of the user in the target application and determine whether to enable the risk detection function according to the behavior data; the behavior data includes at least one type of data related to the business activities of the bank;
[0036] A determination module, configured to, when determining that the risk detection function is enabled, determine a configuration list for risk detection corresponding to the target application according to the scenario information corresponding to the current business scenario, where the configuration list is used to indicate: an associated application corresponding to the current business scenario determined from multiple applications; wherein different associated applications correspond to interfaces of their respective application modules; the application modules include a communication module, a call module, a media management module, and a browser module;
[0037] An acquisition module, configured to acquire data to be detected from the interfaces of the application modules corresponding to the associated applications based on a preset interface, where the data to be detected includes at least one of text data of the communication module, call record data of the call module, image data of the media management module, and browsing record data of the browser module;
[0038] A detection module, configured to determine a target detection method from at least one detection method to perform risk detection on the data to be detected and the behavior data, and execute a transaction operation corresponding to the transaction request after the risk detection passes.
[0039] In a third aspect, the present application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;
[0040] The memory stores computer-executable instructions;
[0041] The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of the first aspects.
[0042] In summary, the present application provides a method, apparatus, and electronic device for processing bank - related data, which are applied to a target application. In response to a transaction request initiated by a user through the target application, the behavior data of the user in the target application is obtained. Then, based on the behavior data of the user in the target application, that is, at least one type of data related to the business activities of the bank, it is determined whether to enable the risk detection function. This dynamic enabling mechanism can be determined dynamically according to specific circumstances, which can reduce unnecessary detections and thus improve the overall efficiency. Further, if it is determined that the risk detection function needs to be enabled, a configuration list is generated according to the specific information of the current business scenario. The configuration list indicates which associated applications need to participate in the risk detection. This configuration is dynamically generated based on the current business requirements and user behavior patterns. Then, based on a preset interface, the data to be detected is obtained from the interfaces of the application program modules corresponding to the associated applications determined from the configuration list. For example, the data to be detected includes at least one of the text data of the communication module, the call record data of the call module, the image data of the media management module, and the browsing record data of the browser module. Further, by combining the user behavior data from the target application and the data to be detected obtained from the associated applications, comprehensive risk detection is performed, and after the risk detection passes, the transaction operation corresponding to the transaction request is executed. The combination of such multi - source data enables risk detection to more comprehensively understand user behavior and potential risks, overcomes the dependence and limitations of the static rule model on a single data source. The combination of such multi - source data makes risk detection not limited to the data of a single application program, thereby improving the accuracy of detection and enhancing the security of transactions. Therefore, through these dynamic and flexible mechanisms, the present application can effectively respond to the rapid changes in user behavior by selectively reading the data of associated applications according to the actual situation, improving the efficiency and flexibility of risk detection, especially the efficiency and flexibility of risk detection in banking business. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application and, together with the specification, are used to explain the principles of the present application.
[0044] Figure 1 FIG. is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0045] Figure 2 FIG. is a schematic flowchart of a method for processing bank - related data provided by an embodiment of the present application;
[0046] Figure 3 FIG. is a schematic structural diagram of an apparatus for processing bank - related data provided by an embodiment of the present application;
[0047] Figure 4 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of the present application.
[0048] Through the above-mentioned accompanying drawings, specific embodiments of the present application have been shown, and more detailed descriptions will be provided hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed Embodiments
[0049] For the convenience of clearly describing the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles. For example, the first device and the second device are only used to distinguish different devices, and do not limit their sequence. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and "first", "second", etc. do not necessarily mean different.
[0050] It should be noted that in the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0051] In the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B may be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one (item)" or similar expressions hereinafter refer to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, c may be single or multiple.
[0052] In the technical solutions of the present application, the processing of collection, storage, use, processing, transmission, provision, and disclosure of information such as financial data or user data complies with the provisions of relevant laws and regulations and does not violate public order and good customs. It should be noted that in the embodiments of the present application, some industry-existing solutions such as certain software, components, models, etc. may be mentioned, and they should be considered exemplary. Their purpose is only to illustrate the feasibility in the implementation of the technical solutions of the present application, but it does not mean that the applicant has already or necessarily used this solution.
[0053] In a possible implementation, a static rule model can be used to perform risk detection on a large amount of operation data of users collected in an application. For example, for a large amount of operation data of users in a bank transfer application, the static rule model is used to perform risk detection. The static rule model performs risk detection based on predefined rules and thresholds.
[0054] However, due to the large amount of data to be detected, the efficiency of using the static rule model for detection is low, and the static rule model is also difficult to adapt to the rapidly changing user behaviors and lacks a certain degree of flexibility.
[0055] In view of the above problems, the present application provides a method for processing bank-related data, which is applied to a target application, such as an online banking application. Specifically, in response to a transaction request initiated by a user through the target application, behavior data of the user in the target application is obtained. Then, based on the behavior data of the user in the target application, that is, based on at least one type of data related to the business activities of the bank, it is determined whether to enable the risk detection function. This dynamic enabling mechanism can be determined dynamically according to specific situations, which can reduce unnecessary detections and thus improve the overall efficiency. Further, if it is determined that the risk detection function needs to be enabled, a configuration list is generated according to the specific information of the current business scenario. The configuration list indicates which associated applications need to participate in the risk detection. This configuration is dynamically generated based on the current business requirements and user behavior patterns. Then, based on a preset interface, data to be detected is obtained from the interfaces of the application program modules corresponding to the associated applications determined from the configuration list. For example, the data to be detected includes at least one of text data of a communication module, call record data of a call module, image data of a media management module, and browsing record data of a browser module. Further, by combining the user behavior data from the target application and the data to be detected obtained from the associated applications, comprehensive risk detection is performed, and after the risk detection passes, the transaction operation corresponding to the transaction request is executed. The combination of such multi-source data enables risk detection to more comprehensively understand user behaviors and potential risks, overcomes the dependence and limitations of the static rule model on a single data source. The combination of such multi-source data makes the risk detection not limited to the data of a single application, thereby improving the accuracy of detection and enhancing the security of transactions. Therefore, through these dynamic and flexible mechanisms, the present application can effectively respond to the rapid changes of user behaviors by selectively reading the data of associated applications according to the actual situation, and improve the efficiency and flexibility of risk detection, especially the efficiency and flexibility of risk detection in banking business.
[0056] Exemplarily, Figure 1 FIG. is a schematic diagram of an application scenario provided for an embodiment of the present application, such as Figure 1As shown, this application scenario can be applied to the process of making transfers using a bank transfer application. This application scenario includes: the user's first terminal device 101, the bank transfer system 102, and the recipient's second terminal device 103; the first terminal device 101 and the second terminal device 103 are installed with a bank transfer application (Application, APP), and the display interface of this APP has multiple applications.
[0057] Specifically, when the user transfers a certain amount to a certain recipient, the user can perform corresponding transfer operations on the first terminal device 101. However, in the case where the recipient is a stranger or the transfer behavior is a financial fraud event, there are certain security risks. Therefore, a method is needed to help users identify fraud means for mobile bank transfers.
[0058] During the process of the user making a transfer to the second terminal device 103 by performing corresponding transfer operations on the first terminal device 101, the user needs to open the bank transfer APP on the first terminal device 101, and then input transaction data, such as inputting the bank card number, transfer amount, etc. After the bank transfer APP detects the transaction request initiated by the user in the bank transfer APP, such as a transfer request, it determines whether to enable the risk detection function based on the behavior data of the above operations. For example, if the transfer amount is greater than the threshold, or if the user is determined to be an elderly person based on the behavior data, the risk detection function can be started.
[0059] Furthermore, determine the configuration list for risk detection required according to the current transfer scenario. This configuration list includes the associated applications corresponding to the current transfer scenario determined from multiple applications in the first terminal device 101, such as associated applications like text messages and call records. Then, obtain the data to be detected from the associated applications, such as the text message content within the last day, the call frequency with a certain person, etc. Then, perform risk detection on these data to be detected and the behavior data of the user in the target application to identify whether there is a fraud event for mobile bank transfers, thereby increasing the security of transfer transactions.
[0060] Among them, the target detection method can be determined from at least one preset detection method, and risk detection is performed on these data to be detected and the behavior data of the user in the target application. This application does not specifically limit the method for selecting the target detection method. For example, methods such as preset rule matching and machine learning models can be used to select the target detection method. This at least one detection method can be a detection method customized by the bank or a risk detection method formulated according to business requirements.
[0061] Optionally, if the result of the risk detection is safe, in response to the transfer request of the first terminal device 101, the bank transfer system 102 automatically completes the transfer operation for the customer, that is, transfers the corresponding amount to the payee's account. Correspondingly, the payee can view it based on the APP of the second terminal device 103.
[0062] Among them, the terminal device can also be referred to as a user terminal, user equipment (UE), mobile station (MS), mobile terminal, terminal, etc. In practical applications, the user terminal is, for example: desktop computer, notebook, personal digital assistant (PDA), personal computer (PC), smart phone, tablet computer, in-vehicle device, wearable device (such as smart watch, smart bracelet), smart home device (such as smart display device), etc. The embodiments of the present application do not make specific limitations thereto.
[0063] It should be noted that the embodiments of the present application do not make specific limitations on the scenarios for performing risk detection on the application bank data processing method. The above are only illustrative examples. Optionally, the target application can be an application related to the business activities of the bank, such as a bank wealth management APP, a bank digital wallet APP, a credit card management APP, etc. The embodiments of the present application do not make specific limitations thereto.
[0064] It should be noted that the main application scenarios in the present application and the content described in the following embodiments are business scenarios related to the bank or financial industry, and will not be elaborated hereinafter.
[0065] The technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail below with specific embodiments. These several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be elaborated in some embodiments. The embodiments of the present application will be described below with reference to the drawings.
[0066] Figure 2 It is a schematic flowchart of a bank data processing method provided by an embodiment of the present application. The bank data processing method can be applied to the target application of the above terminal device, such as Figure 2 As shown, the bank data processing method includes the following steps:
[0067] S201. In response to a transaction request initiated by a user through a target application, obtain the user's behavior data in the target application, and determine whether to enable the risk detection function according to the behavior data; the behavior data includes at least one type of data related to the business activities of the bank.
[0068] In the embodiments of the present application, the transaction request may be a transfer request, a credit card consumption request, a wealth management product purchase request, etc. The embodiments of the present application do not specifically limit the type of the transaction request. The transaction requests generated in different types of target applications are different, or the transaction requests corresponding to different transaction operations executed in the target application are different.
[0069] Therefore, the behavior data in the target application covers multiple aspects of bank operations, including customer information, transaction records, financial data, operation data, etc. For example, it may include the user's login information, access path, click behavior, operation frequency, timestamp, etc. The embodiments of the present application do not specifically limit the content of the behavior data.
[0070] Exemplarily, after a user initiates a transaction request through a target application, the target application can analyze the collected behavior data to identify the user's operation mode and behavior characteristics. The analysis method may include statistical analysis, pattern recognition, machine learning models, etc., in order to extract useful information from a large amount of data. Further, based on the analysis of the operation mode and behavior characteristics, determine whether there are abnormalities or potential risks. For example, if abnormal access frequencies, abnormal geographical location logins, abnormal transaction operation behaviors, etc. are detected, the risk detection function can be enabled.
[0071] It should be noted that the embodiments of the present application do not specifically limit the process and methods used to analyze the behavior data to determine whether to enable the risk detection function. The above is only an example for illustration.
[0072] It can be understood that by obtaining and analyzing the user behavior data to timely determine whether to enable the risk detection function, potential security threats such as account hijacking and fraud behaviors can be more effectively prevented, improving the overall security.
[0073] S202. If it is determined to enable the risk detection function, then according to the scenario information corresponding to the current business scenario, determine the configuration list for risk detection corresponding to the target application. The configuration list is used to indicate: the associated application corresponding to the current business scenario determined from multiple applications, where different associated applications correspond to the interfaces of their respective application modules; the application modules include a communication module, a call module, a media management module, and a browser module.
[0074] In the embodiments of the present application, the scenario information may include the type of operation the user is performing, business information, user information, user permissions, etc. The embodiments of the present application do not limit the specific content corresponding to the scenario information.
[0075] In the present application, the communication module is used to obtain text data, such as the message content and sending records of text messages, emails, etc.; the call module is used to obtain call record data, including call time, duration, frequency, and participants; the media management module is used to obtain image data, such as pictures uploaded or received by the user; the browser module is used to obtain browsing record data, such as the websites visited and timestamps.
[0076] Since the configuration list is used to indicate the associated application programs that need to be involved in the risk detection process, this means that the data sources to be monitored and analyzed can be dynamically adjusted according to different business scenarios. These associated application programs may be other application programs that have data interaction, access permissions, or functional associations with the target application program. By identifying these associated application programs, more comprehensive data to be detected can be obtained from the interfaces of the application program modules corresponding to these associated application programs.
[0077] Exemplarily, a configuration list can be dynamically generated according to the specific business scenario, and thus risk detection can be carried out more targeted. This targeting ensures that the detection process can accurately identify potential risks associated with the current operation.
[0078] S203. Obtain the data to be detected from the interfaces of the application program modules corresponding to the associated application programs. The data to be detected includes at least one of the text data of the communication module, the call record data of the call module, the image data of the media management module, and the browsing record data of the browser module.
[0079] In the present application, the data to be detected is obtained from the interfaces of specific application program modules of different associated application programs through a preset unified interface. For example, the text message content and call records are obtained from the communication module and the call module. Correspondingly, the behavior data of the user is obtained from the target application program. For example, the behavior data obtained from a bank transfer APP may include: transaction data, that is, the transaction records of the user in the bank transfer APP, such as purchase history, amount, and transaction time, etc.; historical browsing data, that is, the browsing history of the user in the bank transfer APP, such as the pages visited and the stay time, etc.
[0080] It should be noted that obtaining data from different application program modules enables the handling of diverse risk scenarios, especially scenarios such as communication fraud, abnormal transactions, and the spread of inappropriate content.
[0081] S204. Determine a target detection method from at least one detection method to perform risk detection on the data to be detected and the behavior data, and execute the transaction operation corresponding to the transaction request after the risk detection passes.
[0082] In this application, the data to be detected obtained from the associated application can be integrated with the user behavior data in the target application, and then the integrated data can be used for risk detection.
[0083] Optionally, the above integration process may involve steps such as data cleaning, format conversion, and data matching to ensure the effective combination of data from different sources; the risk detection process may involve various analysis techniques, such as pattern recognition, anomaly detection, machine learning algorithms, etc., to identify potential security threats or abnormal behaviors. The embodiments of this application do not make specific limitations on the integration process and the risk detection process.
[0084] Therefore, by obtaining various types of data from multiple application modules, more comprehensive risk analysis can be performed. This comprehensiveness helps to identify complex risks across modules. Moreover, by obtaining the data to be detected in the application module corresponding to the associated application and the behavior data in the target application for comprehensive analysis, anomalies and potential threats can be identified more accurately, improving the accuracy of detection, and thus providing a more secure user experience. Therefore, through the use of interfaces and modular design, different data sources and detection methods can be flexibly integrated and extended. This flexibility enables rapid adaptation to new risks and business requirements. By selecting a suitable target detection method, the use of computing resources can be optimized, unnecessary analysis and processing can be avoided, and the efficiency can be improved while also enhancing the reliability of the detection results and user trust.
[0085] In this way, after a transaction request initiated by a user through a target application, by analyzing the user's behavior in the early stage, a more in-depth risk detection function can be enabled only when potential risks are detected. This on-demand enabling strategy reduces unnecessary computational burdens, improves overall efficiency, and through real-time analysis of user behavior data, can quickly respond to potential security threats. This quick response ability is crucial for protecting user data and security. Further, a configuration list can be dynamically generated so that, according to changes in business requirements, applications relevant to the current scenario can be selected. This flexibility enables adaptation to different business scenarios and user behavior patterns, improving adaptability. Furthermore, by identifying and leveraging data from associated applications, cross-application collaborative risk detection can be achieved. This collaborative ability improves the comprehensiveness and depth of detection. By integrating data from multiple applications, user behavior can be analyzed more comprehensively, helping to identify complex risks and anomalies that cannot be revealed by a single data source, thus improving the accuracy of detection. Moreover, through more comprehensive and accurate risk detection, potential risks can be more effectively prevented, improving overall security and the user experience.
[0086] Optionally, the multiple applications are determined by a pre-stored configuration file; the scenario information includes: business information and user information; the configuration file is used to indicate: the associated applications corresponding to different scenario information.
[0087] In the embodiments of the present application, a pre-stored configuration file is used to determine the association relationship between multiple applications. This configuration file contains the mapping relationship between different scenario information and associated applications. This pre-stored configuration file can provide a mechanism for quick lookup and matching to determine the associated applications required for risk detection according to scenario information. This mechanism enables quick adaptation to different business scenarios and user requirements.
[0088] Among them, the scenario information consists of business information and user information. The business information includes the current transaction type, operation process, business goals set by the user, etc. For example, the transaction type can indicate that the current business scenario is passwordless payment, and the business goals set by the user can indicate weak detection or strong detection, etc.; the user information includes the user's role, permissions, historical behavior data, etc. For example, the user's role can indicate an elderly person or a young person. In the embodiments of the present application, the specific content corresponding to the business information and user information is not limited, and it can be set based on the actual application scenario requirements.
[0089] Optionally, configuration files can be updated and adjusted based on changes in business requirements and user behavior to quickly adapt to new business scenarios and changing user behavior patterns. The use of configuration files makes updates and maintenance easier. When business requirements change or new applications are added, only the configuration files need to be updated, thereby reducing development and maintenance costs.
[0090] In this way, by using pre-stored configuration files, associated applications can be quickly determined, and by pre-configuring the relationship between scenario information and associated applications, the complexity of real-time judgment is simplified and the burden of real-time calculation and judgment is reduced. This efficiency improvement helps to maintain good performance under high load conditions and improves accuracy in different scenarios. The use of configuration files ensures that the selection of associated applications is based on proven logic and rules, which can provide a fast search mechanism and respond to different business scenarios and user requests more quickly.
[0091] Optionally, the method further includes:
[0092] Visually displaying a configuration page; the configuration page includes a plurality of configuration options, and the configuration options are used to configure: risk preference information and application authorization information;
[0093] In response to a user's touch operation on the plurality of configuration options on the configuration page, an associated application corresponding to at least a portion of the scene information in the configuration file is adjusted to obtain an adjusted configuration file.
[0094] In the embodiment of the present application, risk preference information refers to the user's ability to set preferences for different risk levels, and the risk preference information is used to adjust the associated applications corresponding to each scenario information; application authorization information refers to the user's ability to manage which applications are authorized to access data or participate in risk detection, which involves the configuration and adjustment of application permissions.
[0095] Optionally, the multiple configuration options may include: strategy configuration options, recommended label options and risk preference rule options; the strategy configuration options include risk detection strategies, account unblocking strategies and risk reminder strategies; the recommended label options include at least one type of risk factors required for risk detection.
[0096] Risk detection strategy refers to how users can configure risk detection, including the selection of algorithms to be used, detection frequency, and the depth and breadth of detection.
[0097] Account unblocking policy refers to the conditions and processes that users can set when their account is blocked, such as the verification steps required, the supporting documents to be submitted, or the waiting time.
[0098] The risk reminder strategy refers to that users can define how to remind users or administrators when risks are detected, including the ways and content of reminders. For example, reminders can be sent via text messages, emails, etc.
[0099] Therefore, the setting of policy configuration options allows users to perform refined management of risk detection, account management, and risk reminders.
[0100] Exemplarily, users can select at least one type of risk factor as a recommended tag. These tags are used to identify specific risk factors that require risk detection, such as "high-value transactions", "abnormal login locations", etc. The recommended tag option is used to focus on specific risk factors to improve the pertinence and effectiveness of detection, enabling users to select the most relevant risk factors for detection according to actual needs.
[0101] Users can also set personal or organizational risk preference rules, which define the tolerance for different risk levels and response strategies. For example, users can choose to strictly monitor high-risk operations and adopt a lenient strategy for low-risk operations; users can also adjust the response strategy through the risk preference rule option to optimize the user experience. For example, to reduce unnecessary alerts or verification steps, one can choose to adopt multiple strategies or collect more information about associated application programs for verification for the elderly, while adopting fewer strategies or verifying the information of associated application programs for the young.
[0102] In this step, a visual configuration page is provided through the terminal device. Users can view and manage multiple configuration options through this page. Further, users select or adjust configuration options on the configuration page through touch operations, and the terminal device responds to these operations to adjust at least part of the associated application programs corresponding to the scenario information in the configuration file. For example, adding new associated application programs, removing no-longer-needed application programs, or modifying the permissions of existing application programs. Furthermore, according to the touch operations of the user, an adjusted configuration file is generated. This configuration file can reflect the user's latest risk preferences and application program authorization settings and is used to guide the subsequent risk detection and management process.
[0103] In this application, a visual interface is provided to make complex configurations intuitive and easy to understand. Users can operate more conveniently. Through the visual interface, complex configuration management becomes more intuitive and simple. Users can perform effective configurations without in-depth understanding of the internal structure, which reduces the usage threshold. Since multiple configuration options are provided on this configuration page, users are allowed to adjust at least some of the associated application programs corresponding to the scenario information according to their own needs and personal preferences. This flexibility enables adaptation to different business environments and user needs, improving user satisfaction. Moreover, through the precise configuration of the configuration file by users, the risk management strategy can be optimized. This optimization helps to improve the reliability and accuracy of detection results, better control data access permissions, enhance security, and make risk management more efficient and personalized.
[0104] Optionally, the configuration file further includes: an active duration threshold pre-configured for each application program; determining a configuration list for risk detection corresponding to the target application program according to the scenario information corresponding to the current business scenario, including:
[0105] Determining at least one candidate associated application program according to the scenario information and the configuration file;
[0106] Obtaining the active duration of the at least one candidate associated application program, and determining the final associated application program from the at least one candidate associated application program according to the active duration and the active duration threshold.
[0107] In this application, the active duration threshold for each application program can be predefined in the configuration file. This active duration threshold represents the minimum usage time for which an application program is considered "active" within a specific time period. If the active duration of an application program exceeds this active duration threshold, it indicates that the application program should be detected with emphasis.
[0108] Exemplarily, at least one candidate associated application program can be identified according to the scenario information of the current business scenario and the configuration file. These candidate application programs can be those initially considered likely to be relevant to the current business scenario. Further, the actual active duration of each candidate associated application program is obtained, and the actual active duration of each candidate associated application program is compared with its corresponding active duration threshold. The associated application programs whose active duration reaches or exceeds the threshold are regarded as the final associated application programs, and these associated application programs will be used in the subsequent risk detection process because they are considered to have sufficient activity and relevance in the current business scenario.
[0109] Among them, obtaining the actual active duration of each candidate associated application can be achieved by monitoring data such as the usage logs and access frequencies of the applications. The embodiments of the present application do not specifically limit the method for obtaining the active duration of the associated applications.
[0110] Therefore, through the screening of the active duration, it can be ensured that the truly active and relevant applications in the current business scenario participate in the risk detection. This relevance improves the accuracy and effectiveness of the detection. Moreover, only the applications with an active duration greater than the threshold are selected for detection, avoiding the waste of resources on inactive or irrelevant applications. This optimization helps to improve the detection efficiency and response speed, reduces the unnecessary computational burden, and by ensuring that the applications participating in the detection have sufficient activity, it can also reduce the false detections caused by irrelevant data and improve the reliability of the detection results.
[0111] Optionally, according to the scenario information corresponding to the current business scenario, determine the configuration list for risk detection corresponding to the target application, including:
[0112] According to the scenario information corresponding to the current business scenario, determine the current risk level;
[0113] Based on the current risk level, determine the configuration list for risk detection corresponding to the target application; different risk levels correspond to different numbers of associated applications.
[0114] Exemplarily, the target application can evaluate and determine the current risk level according to the current business scenario information, such as the transaction type, user information, transaction operation, etc. The risk level can be divided into multiple levels such as low, medium, high, etc. The embodiments of the present application do not specifically limit the division of the risk level.
[0115] Furthermore, after determining the risk level, applications related to this risk level can be selected according to predefined policies or rules, so as to generate a configuration list based on the selected associated applications; different risk levels will correspond to different numbers and types of associated applications. For example, a high risk level corresponds to multiple associated applications, such as multiple associated applications like SMS, browser, file management, call, etc. need to be detected, and a low risk level corresponds to one associated application, such as a certain application opened in the recent period needs to be detected. The embodiments of the present application do not limit the specific number and type of associated applications required for risk detection corresponding to different risk levels, and they can be set based on the actual application scenario requirements.
[0116] In this way, the present application can dynamically select associated application programs for risk detection according to real-time business scenarios and risk situations. This flexibility enables it to adapt to changing environments and threats, enhancing overall security. Moreover, by determining different numbers of associated application programs for detection in the current business scenario based on the risk level, computing resources can be utilized more effectively, avoiding unnecessary overhead, and improving the accuracy and effectiveness of risk detection while enhancing overall efficiency and performance.
[0117] Optionally, the application program module further includes a clipboard service module that obtains the behavior data of the user in the target application program and determines whether to enable the risk detection function based on the behavior data, including:
[0118] Obtain the behavior data from the clipboard service module based on the preset interface;
[0119] Parse the behavior data to identify the account information and transaction amount to be traded;
[0120] Conduct a preliminary risk detection on the account information and transaction amount to be traded, and determine whether to enable the risk detection function based on the result of the preliminary risk detection.
[0121] In the present application, the behavior data of the user can also be obtained from the clipboard service module through a preset interface. The clipboard service module is used to obtain the content copied, cut, and pasted by the user, and this content may contain sensitive information such as account information and transaction amount.
[0122] Exemplarily, after obtaining the content copied by the user from the clipboard service module based on the preset interface, the content can be parsed to identify the account information and transaction amount to be traded therein. Further, a preliminary risk detection is conducted on the identified account information and transaction amount to be traded, such as checking the legality of the account information, the reasonableness of the transaction amount, and the matching degree with the user's historical behavior, etc. The embodiments of the present application do not make specific limitations on the content of the preliminary detection.
[0123] Further, based on the result of the preliminary risk detection, it is determined whether a more in-depth risk detection function needs to be enabled. If the preliminary detection result shows potential risks or anomalies, a comprehensive risk detection process is enabled, that is, S202 - S204 is executed.
[0124] Among them, identifying the account information and transaction amount to be traded may include methods such as text parsing and pattern recognition to accurately extract relevant financial information. The embodiments of the present application do not make specific limitations on the identification method.
[0125] In this way, by obtaining data through the clipboard service module, the copy and paste operations performed by the user in the application can be captured. These operations may involve sensitive transaction information. Further, by parsing the clipboard data, transaction-related information can be accurately identified and extracted, so as to perform more targeted initial risk detection. As a quick screening step, this initial risk detection can effectively filter out low-risk operations and only enable comprehensive detection for high-risk operations. This hierarchical detection strategy optimizes the utilization of resources and improves the detection efficiency. Through rapid initial detection, the detection and response time can be shortened, unnecessary comprehensive risk detection can be reduced, the user experience can be improved, and the user will not be frequently triggered by normal copy and paste operations to security alerts. At the same time, a safer transaction environment can be enjoyed, that is, potential security threats such as fraudulent transactions and account information leakage can be identified and prevented earlier, improving the overall security.
[0126] Optionally, the method further includes:
[0127] After the risk detection passes, determine the location information of the first device of the user and the location information of the second device having a binding relationship with the first device;
[0128] Determine a target verification strategy based on the location information of the first device and the location information of the second device;
[0129] Use the target verification strategy to perform security verification on the transaction request.
[0130] In the embodiment of the present application, after the risk detection passes, it is possible to prepare to process the user's transaction request such as a transfer request. However, when transferring money, security verification of the transaction data is still required, such as SMS verification, password verification, face verification, gesture verification and other methods. After the verification passes, the transaction transfer can be carried out. However, for different user groups, there are corresponding different verification strategies. Existing verification strategies, such as SMS verification and face verification, lack a certain degree of security. For example, when transferring money to the elderly, due to the weak security awareness of the elderly, only using the existing strategies for security verification has low security.
[0131] Therefore, after the risk detection is passed, the location information of the user's first device can be obtained. At the same time, the second device that has a binding relationship with the first device can be obtained. For example, the location information of the terminal device of the user's children or other associated persons. Then, based on the location information of the two devices obtained, a target verification policy suitable for the current scenario can be determined to perform security verification on the transfer request. For example, if the location information of the two devices shows that they are geographically close, a relatively loose verification policy may be selected. At this time, the user's children or other associated persons can help view the transfer information of the first device; if the location information shows that they are far apart, a more strict verification policy or more types of verification policies may be selected to enhance the security of the verification.
[0132] Among them, the method of obtaining location information can be implemented through technologies such as the Global Positioning System (GPS) and Wireless Fidelity (Wi-Fi) positioning. The embodiments of the present application do not limit this.
[0133] In this way, by combining the location information of the devices, the user's real environment and behavior can be judged more accurately. Then, the verification policy can be dynamically adjusted according to the location information of the devices, avoiding unnecessary strict verification processes, thereby improving the security of the transfer request. Since the present application can dynamically select the verification policy according to the real-time location information, this flexibility enables it to adapt to different usage scenarios and risk levels, and then quickly respond to potential risks, perform timely security verification and processing. This real-time risk management ability is crucial for protecting the user's assets and information security, and thus greatly improves the user experience.
[0134] Optionally, the method further includes:
[0135] Obtaining the user identity information of the user in the target application;
[0136] Using a preset protocol to obtain the device information of self-service terminals within a preset time and / or a preset area from the cloud, and determining whether the user identity information exists in the device information;
[0137] When it is determined that the user identity information exists in the device information and the business status of the user in the current business scenario is not completed, a prompt message is generated based on the transaction request of the user in the target application.
[0138] In the embodiments of the present application, the user's identity information can be extracted from the target application. This identity information can include the user's account identification (ID), username, ID card number, etc., which are used to uniquely identify the user.
[0139] Exemplarily, the device information of the self-service terminal within a specific time and / or specific area can be obtained from the cloud using a preset protocol. The device information may include the geographical location of the self-service terminal, usage records, and user identity information interacting therewith, etc. Then, it is checked whether the user identity information is included in the device information obtained from the self-service terminal. This step is used to determine whether the user has used the self-service terminal within the preset time and / or area.
[0140] Furthermore, it is also necessary to check whether the business status of the user in the current business scenario is unfinished, that is, to determine whether the user has completed the corresponding business at the corresponding network point or counter service. If it is determined that the user identity information exists in the self-service terminal device information and the business status of the user in the current business scenario is unfinished, that is, the user has not completed the corresponding business at the corresponding network point or counter service, but the user has initiated a transfer request in the target application program, then a prompt message can be generated to remind the user to complete the unfinished business or warn of possible risks.
[0141] Among them, the prompt message can be sent to the user's terminal device or the staff's terminal device. The embodiments of the present application do not make specific limitations on this.
[0142] Optionally, the possible risk may be that, on the premise that the staff reminds that there is a risk in the current business, the user fails to complete the transaction successfully at the counter but continues to make a transfer on the terminal device. The embodiments of the present application do not make specific limitations on the scenarios where possible risks occur. The above is only an example for illustration.
[0143] Therefore, by checking the user identity information and business status, potential security risks can be identified, such as suspicious transactions initiated by the user at different locations simultaneously. This multi-level verification improves the overall security. And by identifying the unfinished business status of the user and giving a prompt when the user initiates a new transaction request, business conflicts or incorrect operations can also be prevented, thereby helping to maintain the integrity and consistency of the business process. In particular, the prompt message can help the user identify unfinished tasks or potential problems, thus avoiding unnecessary troubles and delays. This proactive reminder can improve the user experience and satisfaction.
[0144] Optionally, the method further includes:
[0145] After the risk detection is passed, the target verification strategy can also be determined based on the environmental information of the user and / or the user's behavior data, so as to use the target verification strategy to perform security verification on the transfer request; among them, the environmental information can include light intensity information, noise volume information, etc. For example, in the case of too dark light intensity, the SMS verification strategy can be determined, and at this time, the face verification strategy is not suitable. In the case of noisy noise volume, the gesture verification strategy can be determined, and at this time, the audio-visual verification strategy is not suitable.
[0146] Exemplarily, the behavior data can be the data generated by the user's multiple behavior operations in the target application. For example, the user purchases financial products multiple times in a certain APP, and each purchase requires security verification using a verification strategy. At this time, if the time interval between purchasing financial products is less than the threshold or the types are similar, the target verification strategy can be determined by referring to the previous (last) verification strategy.
[0147] In this way, by reusing the previous verification strategy, the time and resources required for re-evaluation and strategy formulation can be reduced, the verification process can be simplified and accelerated, and thus the customer experience can be improved.
[0148] Therefore, this application can also formulate a more personalized verification strategy based on the specific environment and behavior data of the user, ensure that the verification process is both safe and does not affect the user experience, and dynamically adjust the verification strategy according to real-time environmental and behavior changes, making it more adaptable.
[0149] Optionally, using similar steps to the bank data processing method, data in other application scenarios can also be processed for risk detection. Only the type of behavior data is different from that in the bank data processing method, and other processing processes are similar. For example, it can be applied to the following application scenarios: when the user logs in or performs sensitive operations, detect the risk of account theft according to the behavior data corresponding to the user's login or sensitive operations in the APP and the data of the associated application; when the user conducts transactions, analyze the behavior data corresponding to the user's transactions in the APP and the data of the associated application in real time to detect potential fraud behaviors; during the game process, analyze the behavior data of the player in the APP and the data of the associated application to identify and prevent cheating behaviors; when an employee accesses sensitive data, combine the behavior data of the user's operations in the APP and the data of the associated applications (such as document management systems, mail services) to detect potential data leakage risks, etc.
[0150] Correspondingly, if applied to different application scenarios, the types of the corresponding target applications may be different, and the number of target applications is at least one.
[0151] Exemplarily, obtain the behavior data of the user in at least one type of target application, and determine whether to enable the risk detection function according to the behavior data; the at least one type of target application may include: transaction applications, game applications, financial management applications, enterprise management applications, etc.; if it is determined to enable the risk detection function, then according to the scenario information corresponding to the current business scenario, determine a configuration list for risk detection corresponding to at least one type of target application, where the configuration list is used to indicate: the associated applications corresponding to the current business scenario determined from multiple applications; among them, different associated applications correspond to the interfaces of their respective application modules; obtain the data to be detected from the interfaces of the application modules corresponding to the associated applications based on the preset interfaces, determine the target detection method from at least one detection method to perform risk detection on the data to be detected and the behavior data, and execute the corresponding transaction operation after the risk detection passes.
[0152] It can be understood that for the specific implementation principles and effects of the above data processing method, reference can be made to the relevant descriptions and effects of the bank - type data processing method in the above embodiments, and no further elaboration will be made here. In the foregoing embodiments, the bank - type data processing method provided by the embodiments of the present application has been introduced. In order to implement each function in the method provided by the embodiments of the present application, the electronic device as the execution subject may include a hardware structure and / or software module, and implement the above - mentioned functions in the form of a hardware structure, a software module, or a combination of a hardware structure and a software module. Whether a certain function among the above - mentioned functions is executed in the form of a hardware structure, a software module, or a combination of a hardware structure and a software module depends on the specific application and design constraints of the technical solution.
[0153] For example, Figure 3 FIG. is a schematic structural diagram of a bank - type data processing device provided by an embodiment of the present application. As Figure 3 shown, the bank - type data processing device 300 is applied to a target application. The bank - type data processing device 300 includes:
[0154] A judgment module 310, configured to obtain the behavior data of the user in the target application in response to a transaction request initiated by the user through the target application, and determine whether to enable the risk detection function according to the behavior data; the behavior data includes at least one type of data related to the business activities of the bank.
[0155] A determination module 320, configured to, when determining that the risk detection function is enabled, determine a configuration list for risk detection corresponding to a target application according to scenario information corresponding to the current business scenario, where the configuration list is used to indicate: associated applications corresponding to the current business scenario determined from multiple applications; among them, different associated applications correspond to interfaces of their respective application modules; the application modules include a communication module, a call module, a media management module, and a browser module;
[0156] An acquisition module 330, configured to acquire data to be detected from interfaces of application modules corresponding to the associated applications based on a preset interface, where the data to be detected includes at least one of text data of the communication module, call record data of the call module, image data of the media management module, and browsing record data of the browser module;
[0157] A detection module 340, configured to determine a target detection method from at least one detection method to perform risk detection on the data to be detected and the behavior data, and execute a transaction operation corresponding to the transaction request after the risk detection passes.
[0158] Optionally, the multiple applications are determined through a pre-stored configuration file; the scenario information includes: business information and user information; the configuration file is used to indicate: associated applications corresponding to different scenario information.
[0159] Optionally, the banking data processing device 300 further includes a configuration module, and the configuration module is configured to:
[0160] Visually display a configuration page; the configuration page includes multiple configuration options, and the configuration options are used to configure: risk preference information and application authorization information;
[0161] In response to a touch operation of the user on the multiple configuration options on the configuration page, adjust the associated applications corresponding to at least part of the scenario information in the configuration file to obtain an adjusted configuration file.
[0162] Optionally, the configuration file further includes: an active duration threshold corresponding to each pre-configured application; the determination module 320 is specifically configured to:
[0163] Determine at least one candidate associated application according to the scenario information and the configuration file;
[0164] Obtain the active duration of the at least one candidate associated application, and determine the final associated application from the at least one candidate associated application according to the active duration and the active duration threshold.
[0165] Optionally, the determining module 320 is specifically configured to:
[0166] Determine the current risk level according to the scenario information corresponding to the current business scenario;
[0167] Based on the current risk level, determine a configuration list for risk detection corresponding to the target application; different risk levels correspond to different numbers of associated applications.
[0168] Optionally, the application module further includes a clipboard service module. The judging module 310 is specifically configured to:
[0169] Obtain behavior data from the clipboard service module based on the preset interface;
[0170] Parse the behavior data to identify the account information and transaction amount to be traded;
[0171] Perform a primary risk detection on the account information and transaction amount to be traded, and determine whether to enable the risk detection function based on the result of the primary risk detection.
[0172] Optionally, the banking data processing device 300 further includes a verification module. The verification module is used to:
[0173] After the risk detection passes, determine the location information of the user's first device and the location information of the second device that has a binding relationship with the first device;
[0174] Determine a target verification policy based on the location information of the first device and the location information of the second device;
[0175] Use the target verification policy to perform a security verification on the transaction request.
[0176] Optionally, the banking data processing device 300 further includes a prompt module. The prompt module is used to:
[0177] Obtain the user identity information of the user in the target application;
[0178] Use a preset protocol to obtain the device information of self-service terminals within a preset time and / or preset area from the cloud, and determine whether the user identity information exists in the device information;
[0179] When it is determined that the user identity information exists in the device information and the business status of the user in the current business scenario is unfinished, generate a prompt message based on the transaction request of the user in the target application.
[0180] It should be noted that for the specific implementation principles and effects of the above bank data processing device, reference can be made to the relevant descriptions and effects corresponding to the above embodiments, and no further elaboration will be provided here.
[0181] An embodiment of the present application also provides a schematic structural diagram of an electronic device. Figure 4 As a schematic structural diagram of an electronic device provided by an embodiment of the present application, as Figure 4 shown, the electronic device may include: a processor 401 and a memory 402 communicatively connected to the processor; the memory 402 stores a computer program; the processor 401 executes the computer program stored in the memory 402, so that the processor 401 executes the method described in any one of the above embodiments.
[0182] Among them, the memory 402 and the processor 401 may be connected through a bus 403.
[0183] An embodiment of the present application also provides a computer-readable storage medium, which stores computer program execution instructions. When the computer execution instructions are executed by a processor, they are used to implement the method described in any one of the foregoing embodiments of the present application.
[0184] An embodiment of the present application also provides a chip for running instructions. The chip is used to execute the method described in any one of the foregoing embodiments executed by an electronic device in any one of the foregoing embodiments of the present application.
[0185] An embodiment of the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it can implement the method described in any one of the foregoing embodiments executed by an electronic device in any one of the foregoing embodiments of the present application.
[0186] In several embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of devices or modules can be in electrical, mechanical or other forms.
[0187] The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical units, that is, they may be located in one place, or they may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to implement the solution of this embodiment.
[0188] In addition, in each embodiment of the present application, each functional module may be integrated into a processing unit, or each module may exist physically alone, or two or more modules may be integrated into one unit. The unit formed by the above modules may be implemented in the form of hardware, or in the form of a hardware plus a software functional unit.
[0189] The integrated module implemented in the form of a software functional module may be stored in a computer-readable storage medium. The above software functional module stored in a storage medium includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute some steps of the methods described in the various embodiments of the present application.
[0190] It should be understood that the above processor may be a central processing unit (CPU for short), or other general-purpose processors, digital signal processors (DSP for short), application specific integrated circuits (ASIC for short), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the application can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0191] The memory may include high-speed random access memory (RAM for short), and may also include non-volatile memory (NVM for short), such as at least one disk memory, and may also be a USB flash drive, a mobile hard disk, a read-only memory, a magnetic disk or an optical disc, etc.
[0192] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, the bus in the drawings of the present application is not limited to only one bus or one type of bus.
[0193] The above storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM for short), electrically erasable programmable read only memory (EEPROM for short), erasable programmable read only memory (EPROM for short), programmable read only memory (PROM for short), read only memory (ROM for short), magnetic memory, flash memory, a magnetic disk or an optical disc. The storage medium can be any available medium accessible by a general-purpose or special-purpose computer.
[0194] An exemplary storage medium is coupled to the processor, enabling the processor to read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC for short). Of course, the processor and the storage medium can also exist as discrete components in an electronic device or a master device.
[0195] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0196] Furthermore, it should be noted that although the steps in the flowchart are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowchart can include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0197] In the above embodiments, the descriptions of the respective embodiments each have their own emphasis. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as falling within the scope described in this specification.
[0198] Those skilled in the art will readily conceive of other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present application are pointed out by the claims.
[0199] As described above, the above is only the specific implementation manner of the embodiments of the present application, but the protection scope of the embodiments of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the embodiments of the present application should be covered within the protection scope of the embodiments of the present application. Therefore, the protection scope of the embodiments of the present application should be subject to the protection scope of the claims.
Claims
1. A banking data processing method, characterized in that: Applied to a target application, the method comprises: In response to a transaction request initiated by a user through a target application, obtaining behavior data of the user in the target application, and determining whether to enable a risk detection function according to the behavior data; the behavior data includes at least one type of data related to the business activities of the bank; If it is determined to enable the risk detection function, a configuration list for risk detection corresponding to the target application is determined according to the scenario information corresponding to the current business scenario, wherein the configuration list is used to indicate: associated applications corresponding to the current business scenario determined from multiple applications; wherein different associated applications correspond to interfaces of respective application modules; the application modules include a communication module, a call module, a media management module and a browser module; the multiple applications are determined by pre-stored configuration files; the scenario information includes: business information and user information; the configuration file is used to indicate: associated applications corresponding to different scenario information; Based on a preset interface, the data to be detected is obtained from the interface of the application module corresponding to the associated application, wherein the data to be detected includes at least one of the text data of the communication module, the call record data of the call module, the image data of the media management module, and the browsing record data of the browser module; a target detection method is determined from at least one detection method to perform risk detection on the data to be detected and the behavior data, and a transaction operation corresponding to the transaction request is executed after the risk detection passes; The method further includes: visually displaying a configuration page; the configuration page includes a plurality of configuration options, the configuration options being used to configure: risk preference information and application authorization information; In response to a user's touch operation on the plurality of configuration options on the configuration page, adjusting the associated application corresponding to at least part of the scene information in the configuration file to obtain an adjusted configuration file; The method further includes: after the risk detection passes, determining the location information of the first device of the user and the location information of the second device having a binding relationship with the first device; Determining a target verification strategy based on the location information of the first device and the location information of the second device; The transaction request is securely verified using the target verification strategy.
2. The method according to claim 1, characterized in that The configuration file also includes: a pre-configured active duration threshold corresponding to each application; and a configuration list for risk detection corresponding to the target application is determined according to the scenario information corresponding to the current business scenario, including: Determining at least one candidate associated application according to the scenario information and the configuration file; The active duration of the at least one candidate associated application is obtained, and a final associated application is determined from the at least one candidate associated application according to the active duration and an active duration threshold.
3. The method according to claim 1, characterized in that According to the scenario information corresponding to the current business scenario, determine the configuration list for risk detection corresponding to the target application, including: Determine the current risk level based on the scenario information corresponding to the current business scenario; A configuration list for risk detection corresponding to the target application is determined based on the current risk level; different risk levels correspond to different numbers of associated applications.
4. The method according to claim 1, characterized in that The application module also includes a clipping service module, which obtains the user's behavior data in the target application and determines whether to enable the risk detection function according to the behavior data, including: Acquiring behavior data from the clipping service module based on the preset interface; Parsing the behavior data to identify the account information and transaction amount to be traded; An initial risk detection is performed on the account information and transaction amount to be traded, and based on the result of the initial risk detection, it is determined whether to enable the risk detection function.
5. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: Obtaining user identity information of the user in the target application; Obtaining device information of self-service terminals within a preset time and / or preset area from the cloud using a preset protocol, and determining whether the user identity information exists in the device information; When it is determined that the user identity information exists in the device information and the business status of the user in the current business scenario is unfinished, prompt information is generated based on the transaction request of the user in the target application.
6. A banking data processing device, characterized in that: Applied to a target application, the device comprises: a judgment module, configured to respond to a transaction request initiated by a user through a target application, obtain behavior data of the user in the target application, and judge whether to enable the risk detection function according to the behavior data; the behavior data includes at least one type of data related to the business activities of the bank; A determination module, for determining, after determining to enable the risk detection function, a configuration list for risk detection corresponding to a target application according to scenario information corresponding to a current business scenario, wherein the configuration list is used to indicate: associated applications corresponding to the current business scenario determined from a plurality of applications; wherein different associated applications correspond to interfaces of respective application modules; the application modules include a communication module, a call module, a media management module, and a browser module; the plurality of applications are determined by pre-stored configuration files; the scenario information includes: business information and user information; the configuration file is used to indicate: associated applications corresponding to different scenario information; an acquisition module, configured to acquire the data to be detected from the interface of the application module corresponding to the associated application based on a preset interface, wherein the data to be detected includes at least one of the text data of the communication module, the call record data of the call module, the image data of the media management module, and the browsing record data of the browser module; A detection module, configured to determine a target detection method from at least one detection method to perform risk detection on the data to be detected and the behavior data, and execute a transaction operation corresponding to the transaction request after the risk detection passes; It also includes a configuration module, wherein the configuration module is used to: Visually displaying a configuration page; the configuration page includes a plurality of configuration options, and the configuration options are used to configure: risk preference information and application authorization information; In response to a user's touch operation on the plurality of configuration options on the configuration page, adjusting the associated application corresponding to at least part of the scene information in the configuration file to obtain an adjusted configuration file; It also includes a verification module, the verification module is used to: After the risk detection passes, determining the location information of the first device of the user and the location information of the second device having a binding relationship with the first device; Determining a target verification strategy based on the location information of the first device and the location information of the second device; The transaction request is securely verified using the target verification strategy.
7. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Anti-fraud monitoring method based on scene recognition
CN114841705A
Security detection method and device, equipment, storage medium and program product
CN116881884A
Anti-fraud transfer method and device, electronic equipment and storage medium
CN117611175A
Data processing method and device, equipment, storage medium and program product
CN118278741A