Method, device, storage medium and electronic device for payment risk control

By identifying the screen sharing status of user devices and performing risk control operations, the problem of fraudsters committing fraud through screen sharing is solved, reducing the risk of funds being defrauded in payment scenarios.

CN119887208BActive Publication Date: 2026-01-13ALIPAY COM CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411856566.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2026-01-13
Estimated Expiration
2044-12-16

AI Technical Summary

Technical Problem

Fraudsters use screen sharing to commit fraud, and existing technologies are insufficient to effectively warn and intercept such activities, resulting in a high risk of users being defrauded in payment scenarios.

Method used

By identifying the screen sharing status of a user's device, risk control operations are performed to warn or block payment behavior, including obtaining screen sharing status, risk quantification information, and sensitive information analysis to determine risk control strategies.

Benefits of technology

This effectively reduces the risk of users being misled into fraud while sharing their screens, and reduces financial losses in payment scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119887208B_ABST
    Figure CN119887208B_ABST
Patent Text Reader

Abstract

Embodiments of the present specification disclose a method, device, storage medium and electronic equipment for payment risk control, relating to the technical field of computer. The method comprises: in response to a payment trigger operation performed by a user, obtaining a screen sharing state corresponding to a user device currently used by the user; if the screen sharing state indicates that the user device is currently in screen sharing, performing a risk control operation corresponding to the payment trigger operation according to the screen sharing state. Embodiments of the present specification can obviously reduce the risk of the user being guided to fraud in the screen sharing state by sensing whether a potential fraudster is in a screen sharing environment, thereby performing pre-protection, early warning or timely blocking and intercepting, and can greatly reduce the risk of the user being cheated of funds in a payment scenario.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, and in particular, to a method and device for payment risk control, a storage medium and an electronic device. BACKGROUND

[0002] In the prior art, fraudsters can implement fraudulent behavior through a screen sharing function. Fraudsters often induce victims to download a certain regular video conference software for communication. Since there are many such regular video conference software manufacturers, and the market demand is large and can be applied to various conference scenarios, it is impossible to limit the functions thereof, and the effect of early warning and countermeasures through the video conference software end is very small. SUMMARY

[0003] The embodiments of the present application provide a method and device for payment risk control, a storage medium and an electronic device.

[0004] The embodiments of the present application provide a method for payment risk control. By identifying whether a user is in a high-risk environment susceptible to fraud in a screen sharing state when the user performs a payment trigger operation according to a screen sharing state corresponding to a user device currently used by the user, performing a risk control operation corresponding to the payment trigger operation, and by sensing whether a potential victim is in a screen sharing environment, pre-protection, early warning or timely blocking and interception can be performed, the risk of the user being induced to commit fraud in the screen sharing state can be significantly reduced, and the risk of the user being cheated of funds in a payment scenario can be greatly reduced. The method comprises the following steps.

[0005] In response to a payment trigger operation performed by a user, a screen sharing state corresponding to a user device currently used by the user is obtained.

[0006] If the screen sharing state indicates that the user device is currently in screen sharing, a risk control operation corresponding to the payment trigger operation is performed according to the screen sharing state.

[0007] Further, the obtaining of the screen sharing state corresponding to the user device currently used by the user comprises at least one of the following:

[0008] According to recording screen information corresponding to a current screen of the user device currently used by the user, the screen sharing state corresponding to the user device is determined.

[0009] According to screen projection information corresponding to the current screen of the user device currently used by the user, the screen sharing state corresponding to the user device is determined.

[0010] Further, the performing of the risk control operation corresponding to the payment trigger operation according to the screen sharing state comprises:

[0011] determining corresponding risk quantification information according to the screen sharing state;

[0012] performing a risk control operation corresponding to the payment trigger operation according to the risk quantification information.

[0013] Further, the screen sharing state includes operation record and screen sharing duration information of the user equipment during screen sharing;

[0014] The method further includes:

[0015] determining corresponding risk quantification information according to the operation record, the screen sharing duration information, device risk quantification information of the user equipment, and transaction magnitude quantification information of the user.

[0016] Further, the determining corresponding risk quantification information according to the operation record, the screen sharing duration information, device risk quantification information of the user equipment, and transaction magnitude quantification information of the user includes:

[0017] determining corresponding risk quantification information according to the operation record, the screen sharing duration information, device risk quantification information of the user equipment, transaction magnitude quantification information of the user, and social relationship quantification information between the user and a payment object corresponding to the payment trigger operation.

[0018] Further, the screen sharing state includes screen content of the user equipment being shared;

[0019] The method further includes:

[0020] performing a risk control operation corresponding to the payment trigger operation according to the screen content of the user equipment being shared.

[0021] Further, the performing a risk control operation corresponding to the payment trigger operation according to the screen content of the user equipment being shared includes:

[0022] performing a risk control operation corresponding to the payment trigger operation according to sensitive information contained in the screen content of the user equipment being shared.

[0023] Further, the performing a risk control operation corresponding to the payment trigger operation according to sensitive information contained in the screen content of the user equipment being shared includes:

[0024] According to the association information between the sensitive information contained in the screen content shared by the user equipment and the screen rendering content of the user equipment within a preset time range before the screen sharing start time, a risk control operation corresponding to the payment trigger operation is performed.

[0025] Further, the performing of the risk control operation corresponding to the payment trigger operation according to the sensitive information contained in the screen content shared by the user equipment comprises:

[0026] According to the association information between the sensitive information contained in the screen content shared by the user equipment and the operation object corresponding to the payment trigger operation, a risk control operation corresponding to the payment trigger operation is performed.

[0027] Further, the screen sharing state comprises an operation record corresponding to the user equipment during the screen sharing;

[0028] According to the screen sharing state, a risk control operation corresponding to the payment trigger operation is performed.

[0029] According to the operation record corresponding to the user equipment during the screen sharing, a risk control operation corresponding to the payment trigger operation is performed.

[0030] Further, the performing of the risk control operation corresponding to the payment trigger operation according to the operation record corresponding to the user equipment during the screen sharing comprises:

[0031] According to the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing, a risk control operation corresponding to the payment trigger operation is performed.

[0032] Further, the performing of the risk control operation corresponding to the payment trigger operation according to the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing comprises:

[0033] According to the association information between the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing and the historical operation performed by the user equipment within a preset time range before the screen sharing start time, a risk control operation corresponding to the payment trigger operation is performed.

[0034] Further, the performing of the risk control operation corresponding to the payment trigger operation according to the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing comprises:

[0035] According to the association information between the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing and the payment trigger operation, a risk control operation corresponding to the payment trigger operation is performed.

[0036] The embodiment of the present specification also provides a device for payment risk control, comprising:

[0037] a screen sharing state obtaining module, configured to obtain a screen sharing state corresponding to a user device currently used by a user in response to a payment trigger operation performed by the user;

[0038] a payment risk control module, configured to perform a risk control operation corresponding to the payment trigger operation according to the screen sharing state if the screen sharing state indicates that the user device is currently in screen sharing.

[0039] The embodiment of the present specification also provides a storage medium, which stores a computer program, and the computer program is adapted to be loaded by a processor and execute the steps of the above method.

[0040] The embodiment of the present specification also provides an electronic device, comprising a processor and a memory, wherein the memory stores a computer program, and the computer program is adapted to be loaded by the processor and execute the steps of the above method.

[0041] In the embodiment of the present specification, by identifying whether the user is in a high-risk environment of screen sharing fraud when the user performs a payment trigger operation according to the screen sharing state corresponding to the user device currently used by the user, performing a risk control operation corresponding to the payment trigger operation, and by sensing whether a potential fraudster is in a screen sharing environment, pre-protection, early warning or timely blocking and interception can be performed, which can significantly reduce the risk of the user being guided to fraud in the screen sharing state and greatly reduce the risk of the user being cheated of funds in the payment scenario. BRIEF DESCRIPTION OF DRAWINGS

[0042] Figure 1 A flowchart of a method for payment risk control is provided for the embodiment of the present specification.

[0043] Figure 2 A structural diagram of a device for payment risk control is provided for the embodiment of the present specification.

[0044] Figure 3 A structural diagram of an electronic device is provided for the embodiment of the present specification. DETAILED DESCRIPTION

[0045] For the purposes of the present description, the technical solutions and advantages thereof will be more apparent from the following description of specific embodiments of the present description and corresponding drawings. Obviously, the described embodiments are only some of the embodiments of the present description, rather than all the embodiments. Based on the embodiments in the present description, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present description.

[0046] Please refer to Figure 1 A flowchart of a method for payment risk control is provided for the embodiments of the present description. In the embodiments of the present description, the method for payment risk control is applied to a device for payment risk control (hereinafter referred to as "payment risk control device") or an electronic device configured with a payment risk control device. The following will be described in detail with respect to the flowchart shown in Figure 1 The method for payment risk control can specifically include the following steps:

[0047] S102, in response to a payment trigger operation performed by a user, obtaining a screen sharing state corresponding to a user device currently used by the user.

[0048] In some embodiments, the payment trigger operation includes, but is not limited to, any operation performed by the user for triggering a payment behavior, for example, an operation for triggering a payment code (e.g., the user clicks a "payment code" button), an operation for triggering a transfer or sending a red packet (e.g., the user clicks a "transfer" button or a "send red packet" button), an operation for triggering entering a payment page (e.g., the user clicks a "payment" button), an operation for triggering opening or logging into a payment application (e.g., the user clicks an icon of the payment application on the desktop of the user device currently used by the user, or the user clicks a "login" button), it should be noted that the above payment trigger operations are only examples, rather than limitations, and those skilled in the art should understand that any operation for triggering a specific payment behavior can be included within the scope of protection of the present description.

[0049] In some embodiments, in response to a payment trigger operation performed by a user, a screen sharing state corresponding to a user device currently used by the user is obtained, wherein the user device includes but is not limited to any kind of electronic product that can be interacted with the user (for example, through a touch panel), such as a smart phone, a tablet computer, a PC (Personal Computer), etc., and the electronic product can use any operating system, such as an Android operating system, an iOS operating system, a Windows operating system, etc. In some embodiments, in addition to including indication information for indicating whether the user device is currently in screen sharing, the screen sharing state also includes but is not limited to a screen sharing duration, a screen sharing start time, screen content of the user device being shared, an operation record corresponding to the user device during the screen sharing, etc., and the specific content of the screen sharing state is not limited in the present specification. In some embodiments, screen sharing refers to that a user shares screen content of a user device currently used by the user in real time to others, and through screen sharing, participants can see the desktop, application program or specific window of the sharer.

[0050] In some embodiments, the screen sharing state of the user device currently used by the user can be obtained by calling an interface provided by the user device, or can also be obtained from a notification message sent by the user device, for example, the user device sends a corresponding notification message when the screen sharing state changes, for example, the user device sends a corresponding notification message every preset time interval during the screen sharing process. In this regard, the specific obtaining method of the screen sharing state of the user device is not limited in the specification. For example, taking a mobile phone or tablet computer using an iOS operating system as an example, the current screen of the user device can be determined by calling the API of UIScreen (UIScreen is a class in iOS development, used to represent the screen of the device). Whether the current screen is being recorded, mirrored or sent by Airplay (Airplay), when UIScreen.isCaptured is true, it indicates that the current screen of the user device is being recorded, mirrored or sent by Airplay. Therefore, it can be determined that the user device is currently in screen sharing. When UIScreen.isCaptured is false, it can be determined that the user device is not currently in screen sharing. For another example, when the screen recording state changes, UIKit (UIKit is a set of frameworks in iOS development used to build user interfaces) sends a UIScreenCapturedDidChange notification (notification message). UIScreenCapturedDidChangeNotification is a notification in the iOS system, used to inform the application whether the current screen is being recorded. When the recording state of the screen changes, UIKit sends this notification. By listening to this notification, it can be determined whether the current screen of the user device is being recorded, and further determine whether the user device is currently in screen sharing.

[0051] S104, if the screen sharing state indicates that the user device is currently in screen sharing, performing a risk control operation corresponding to the payment trigger operation according to the screen sharing state.

[0052] In some embodiments, if the screen sharing state indicates that the user device is currently in screen sharing, a risk control operation corresponding to the payment trigger operation currently performed by the user is further determined according to the screen sharing state, and the risk control operation is performed, wherein the risk control operation includes but is not limited to any risk control operation on the payment trigger operation, for example, the risk control operation can be to block the payment behavior triggered by the payment trigger operation, that is, to stop the payment behavior, or it can also be to interact with the user for the payment trigger operation to determine whether to continue the payment behavior triggered by the payment trigger operation, or it can also be to release the payment behavior triggered by the payment trigger operation, that is, to continue the payment behavior. For example, if the payment trigger operation is an operation for triggering the display of a payment code, the risk control operation corresponding to the payment trigger operation can be to prohibit the display of the payment code, and for example, if the payment trigger operation is an operation for triggering a transfer, the risk control operation corresponding to the payment trigger operation can be to block the transfer, or it can also be to interact with the user for the payment trigger operation to determine whether to continue the transfer, or it can also be to release the transfer.

[0053] In some embodiments, the corresponding risk control operation needs to be determined according to the screen sharing state, for example, the risk control operation mapped by the screen sharing state is obtained according to the mapping relationship between the preset screen sharing state and the risk control operation, for example, the risk control operation mapped by the screen sharing duration in the screen sharing state is obtained, for example, the risk control operation output by the risk control prediction model is obtained by inputting the screen sharing state into the trained risk control prediction model, and in this regard, the model structure, model parameters and model training method of the risk control prediction model are not limited in this specification, for example, the screenshots of the user device obtained at preset time intervals during screen sharing are input into a trained risk control prediction model, and the risk control operation output by the risk control prediction model is obtained.

[0054] In the embodiments of the present specification, by determining whether the user is in a high-risk environment of screen sharing when the user performs the payment trigger operation according to the screen sharing state of the user device currently used by the user, performing the risk control operation corresponding to the payment trigger operation, and by sensing whether the potential fraudster is in the screen sharing environment, pre-protection, early warning or timely blocking and interception can be performed, which can significantly reduce the risk of the user being guided to fraud in the screen sharing state, and can greatly reduce the risk of the user being cheated of funds in the payment scenario.

[0055] In some embodiments, the performing, according to the screen sharing state, a risk control operation corresponding to the payment trigger operation comprises: determining corresponding risk quantification information according to the screen sharing state; and performing, according to the risk quantification information, a risk control operation corresponding to the payment trigger operation. In some embodiments, the risk quantification information is used to quantify the degree of risk of the current payment environment of the user device, for example, the risk quantification information can be in numerical form, or can also be in string form (for example, high risk, medium risk, low risk, etc.), and the specific form of the risk quantification information is not limited in the specification. In some embodiments, it is necessary to determine the corresponding risk quantification information according to the screen sharing state, for example, inputting the screen sharing state into a preset function relationship to obtain the risk quantification information output by the function relationship, for example, inputting the screen sharing duration in the screen sharing state into a preset function relationship to obtain the risk quantification information output by the function relationship, for example, inputting the screen sharing state into a trained risk quantification model to obtain the risk quantification information output by the risk quantification model, and the model structure, model parameters and model training method of the risk quantification model are not limited in the specification. For example, inputting the screenshots of the user device obtained at a preset time interval during the screen sharing into a trained risk quantification model to obtain the risk quantification information output by the risk quantification model. In some embodiments, it is also necessary to determine the risk control operation corresponding to the payment trigger operation currently performed by the user according to the obtained risk quantification information, and perform the risk control operation, for example, if the risk quantification information is in numerical form, the numerical interval in which the risk quantification information falls can be determined according to the risk quantification information, and the risk control operation mapped by the numerical interval in which the risk quantification information falls is determined as the risk control operation corresponding to the payment trigger operation based on the preset mapping relationship between the numerical interval and the risk control operation, for example, if the risk quantification information is in string form, the risk control operation mapped by the risk quantification information is determined as the risk control operation corresponding to the payment trigger operation based on the preset mapping relationship between the string and the risk control operation.

[0056] In some embodiments, the screen sharing state includes operation records corresponding to the user equipment during screen sharing and screen sharing duration information; wherein the determining of the corresponding risk quantification information according to the screen sharing state comprises: determining the corresponding risk quantification information according to the operation records, the screen sharing duration information, device risk quantification information corresponding to the user equipment, and transaction volume quantification information corresponding to the user. In some embodiments, the operation records include operation information related to at least one operation performed by the user equipment during screen sharing, which includes but is not limited to operation time, operation target, operation object, operation content, operation type, operation result, etc., which are not limited in the present specification. In some embodiments, at least one operation in the operation records can be classified according to the operation information of the at least one operation, such as page access type, fund operation type, account operation type, etc., each classification corresponds to a preset variable, so that the variable corresponding to the operation records can be obtained. In some embodiments, device risk quantification information can be formed by a preset algorithm according to device information of the user equipment, such as model, operating system version, whether device binding has been changed, whether it is a commonly used device, etc., and the device risk quantification information is used to represent the risk level of the user equipment (e.g., trusted, medium risk, high risk, etc.) in the form of variables. In some embodiments, the user's historical transactions are divided according to the time dimension to dynamically monitor the transaction volume of the user. The transaction volume quantification information of the user is obtained, and the transaction volume quantification information is used to represent the transaction risk level of the user in the form of variables. In some embodiments, the variables corresponding to the operation records, the screen sharing duration information, the device risk quantification information, and the transaction volume quantification information can be multiplied by the respective self-defined weights corresponding to each variable, and then summed up, and the corresponding risk quantification information is determined according to the calculated result, which can be directly used as the risk quantification information, or the calculated result can be multiplied by a preset self-defined weight to obtain the risk quantification information, or the calculated result can be mapped to the risk quantification information or the numerical interval to which the calculated result falls according to a preset mapping relationship, or the calculated result can be input into a trained risk quantification model to obtain the risk quantification information output by the model, and the specific way of obtaining the risk quantification information from the weighted sum result is not limited in the present specification.

[0057] In some embodiments, the determining the corresponding risk quantification information according to the operation record, the screen sharing duration information, the device risk quantification information corresponding to the user equipment, and the transaction magnitude quantification information corresponding to the user comprises: determining the corresponding risk quantification information according to the operation record, the screen sharing duration information, the device risk quantification information corresponding to the user equipment, the transaction magnitude quantification information corresponding to the user, and the social relationship quantification information between the user and the payment object corresponding to the payment trigger operation. In some embodiments, if the payment trigger operation has a corresponding payment object, for example, if the payment trigger operation is an operation for triggering a transfer or sending a red packet, the payment object corresponding to the payment trigger operation is a transfer object or a red packet sending object. In this case, the social relationship between the user and the payment object needs to be quantified to obtain the corresponding social relationship quantification information, which is used to represent the risk degree of the social relationship between the user and the payment object in the form of a variable. For example, the corresponding social relationship quantification information can be generated according to whether the payment object is a friend of the user, the historical transaction record between the user and the payment object, the transaction content of this time, the message note of the user about this time, and the like. The present specification does not limit this. In some embodiments, the operation record corresponding variable, the screen sharing duration information, the device risk quantification information, the transaction magnitude quantification information, and the social relationship quantification information can be respectively multiplied by the respective self-defined weights corresponding to the respective variables, and then summed, and the corresponding risk quantification information is determined according to the calculated result. The specific way of obtaining the risk quantification information according to the calculation result obtained by the weighted summation has been described in detail in the foregoing, and will not be described here.

[0058] In some embodiments, the screen sharing state includes screen content shared by the user device; and wherein the performing, according to the screen sharing state, the risk control operation corresponding to the payment trigger operation comprises: performing, according to the screen content shared by the user device, the risk control operation corresponding to the payment trigger operation. In some embodiments, the screen sharing state includes screen content shared by the user device, and the screen content includes, but is not limited to, a page identifier, a page name, a page type, page presentation content (e.g., text or image), a page sharing duration, a page start sharing time, a page end sharing time, and the like of a current display page of the user device during screen sharing, and the present specification does not limit the same. In some embodiments, the risk control operation corresponding to the payment trigger operation performed by the user can be determined according to the screen content shared by the user device, and the risk control operation is performed, for example, according to the page identifier of the current display page of the user device during screen sharing in the screen content, a sensitive level corresponding to the current display page is determined, and then a risk control operation mapped by the sensitive level is taken as the risk control operation corresponding to the payment trigger operation based on a preset mapping relationship between the sensitive level and the risk control operation, and for another example, according to the page type of the current display page of the user device during screen sharing in the screen content, it is first determined whether the current display page is a sensitive page, and if so, according to the page sharing duration of the sensitive page in the screen content, a risk control operation mapped by a time interval in which the page sharing duration falls is taken as the risk control operation corresponding to the payment trigger operation based on a preset mapping relationship between the time interval and the risk control operation.

[0059] In some embodiments, the performing, according to the screen content shared by the user device, a risk control operation corresponding to the payment trigger operation comprises: performing, according to sensitive information contained in the screen content shared by the user device, a risk control operation corresponding to the payment trigger operation. In some embodiments, the sensitive information contained in the screen content can be obtained according to the page presentation content of the current display page of the user device in the screen sharing. The specific method can be to obtain the sensitive information contained in the page presentation content by keyword recognition on the text information in the page presentation content, or to obtain the sensitive information contained in the page presentation content by image content recognition on the image information in the page presentation content. The present specification does not limit the way of obtaining sensitive information from the page presentation content. In some embodiments, after obtaining the sensitive information contained in the screen content shared by the user device, the risk control operation corresponding to the payment trigger operation currently performed by the user can be determined according to the sensitive information, and the risk control operation is performed. For example, according to the sensitive degree level corresponding to the sensitive information, based on the mapping relationship between the preset sensitive degree level and the risk control operation, the risk control operation mapped by the sensitive degree level is taken as the risk control operation corresponding to the payment trigger operation. For another example, the sensitive information is directly input into a trained risk control prediction model, and the risk control operation output by the model is taken as the risk control operation corresponding to the payment trigger operation.

[0060] In some embodiments, the performing, according to the sensitive information contained in the screen content shared by the user device, a risk control operation corresponding to the payment trigger operation comprises: performing, according to association information between the sensitive information contained in the screen content shared by the user device and screen presentation content of the user device within a preset time range before the screen sharing start time, the risk control operation corresponding to the payment trigger operation. In some embodiments, the preset time range can be a time range of a predetermined length of time before the screen sharing start time, or can also be a time range from the last boot time or the last unlock time of the user device to the screen sharing start time, and the present specification does not limit this. In some embodiments, the screen presentation content of the user device within the preset time range before the screen sharing start time includes, but is not limited to, the page identifier, the page name, the page type, the page presentation content (such as text or image), the page sharing duration, the page start sharing time, the page end sharing time, and the like of the current display page within the preset time range before the screen sharing start time of the user device, and the present specification does not limit this. In some embodiments, according to the association information between the sensitive information contained in the screen content shared by the user device and the screen presentation content of the user device within the preset time range before the screen sharing start time, the risk control operation corresponding to the payment trigger operation currently performed by the user is determined and the risk control operation is performed. The association information can refer to the degree of association between the sensitive information and the screen presentation content, and the risk control operation is determined according to the degree of association, for example, according to the numerical value interval into which the degree of association corresponds, and based on the mapping relationship between the preset numerical value interval and the risk control operation, the risk control operation mapped by the numerical value interval is taken as the risk control operation corresponding to the payment trigger operation, or the association information can also refer to the degree of guidance in semantic logic between the sensitive information and the screen presentation content, and the degree of guidance is used to represent the degree of guidance of the screen presentation content in semantic logic to the sensitive information, and then the corresponding risk control operation is determined according to the degree of guidance, for example, according to the mapping relationship between the preset degree of guidance and the risk control operation, the risk control operation mapped thereby is taken as the risk control operation corresponding to the payment trigger operation.

[0061] In some embodiments, the performing the risk control operation corresponding to the payment trigger operation according to the sensitive information contained in the screen content shared by the user equipment comprises: performing the risk control operation corresponding to the payment trigger operation according to association information between the sensitive information contained in the screen content shared by the user equipment and an operation object corresponding to the payment trigger operation. In some embodiments, if the payment trigger operation is an operation for triggering display of a payment code, the corresponding operation object is the payment code; if the payment trigger operation is an operation for triggering entry into a payment page, the corresponding operation object is the payment page; if the payment trigger operation is an operation for triggering opening or logging in to a payment application, the corresponding operation object is the payment application; and if the payment trigger operation is an operation for triggering a transfer or sending of a red packet, the corresponding operation object is a transfer object or a red packet sending object. In some embodiments, the risk control operation corresponding to the payment trigger operation currently performed by the user is determined according to association information between the sensitive information contained in the screen content shared by the user equipment and the operation object corresponding to the payment trigger operation, and the risk control operation is performed. The association information can refer to an association degree between the sensitive information and the operation object, and the risk control operation corresponding to the payment trigger operation is determined according to the association degree. For example, a risk control operation mapped according to a preset mapping relationship between the association degree and the risk control operation is taken as the risk control operation corresponding to the payment trigger operation. Alternatively, the association information can refer to a guiding degree in semantic logic between the sensitive information and the operation object, and the guiding degree is used to represent a degree of a guiding role played by the sensitive information in semantic logic on the operation object. Then, the risk control operation corresponding to the payment trigger operation is determined according to the guiding degree. For example, a risk control operation mapped according to a mapping relationship between a numerical interval in which a numerical value corresponding to the guiding degree falls and the risk control operation is taken as the risk control operation corresponding to the payment trigger operation.

[0062] In some embodiments, the screen sharing state includes an operation record corresponding to the user device during the screen sharing; and the performing the risk control operation corresponding to the payment trigger operation according to the screen sharing state includes performing the risk control operation corresponding to the payment trigger operation according to the operation record corresponding to the user device during the screen sharing. In some embodiments, the operation record includes operation information related to at least one operation performed by the user device during the screen sharing, which includes but is not limited to operation time, operation target, operation object, operation content, operation type, operation result, etc., and the present specification is not limited thereto. In some embodiments, the risk control operation corresponding to the payment trigger operation currently performed by the user can be determined according to the operation record corresponding to the user device during the screen sharing, and the risk control operation is performed, for example, the operation record is input into a trained risk control prediction model, and the risk control operation output by the model is taken as the risk control operation corresponding to the payment trigger operation, and for another example, the operation type of at least one operation in the operation record is determined, and the risk control operation mapped by the operation type is taken as the risk control operation corresponding to the payment trigger operation based on a preset mapping relationship between operation types and risk control operations.

[0063] In some embodiments, the performing the risk control operation corresponding to the payment trigger operation according to the operation record corresponding to the user device during the screen sharing includes performing the risk control operation corresponding to the payment trigger operation according to a sensitive operation involved in the operation record corresponding to the user device during the screen sharing. In some embodiments, the sensitive operation involved in at least one operation in the operation record can be determined according to operation information of the at least one operation, and then the risk control operation corresponding to the payment trigger operation currently performed by the user is determined according to the sensitive operation, and the risk control operation is performed, for example, the sensitive operation corresponding to the sensitive level information is determined according to the sensitive operation, and the risk control operation mapped by the sensitive level information is taken as the risk control operation corresponding to the payment trigger operation based on a preset mapping relationship between sensitive level information and risk control operations, and for another example, the operation content of the sensitive operation is input into a trained risk control prediction model, and the risk control operation output by the model is taken as the risk control operation corresponding to the payment trigger operation.

[0064] In some embodiments, the performing the risk control operation corresponding to the payment trigger operation according to the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing comprises: performing the risk control operation corresponding to the payment trigger operation according to the association information between the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing and the historical operation performed within a preset time range before the screen sharing start time. In some embodiments, the preset time range can be a time range of a predetermined time length before the screen sharing start time, or can also be a time range from the last boot time or the last unlock time of the user equipment to the screen sharing start time, and the present specification does not limit this. In some embodiments, the risk control operation corresponding to the payment trigger operation performed by the user can be determined according to the association information between the operation information of at least one operation in the operation record corresponding to the user equipment during the screen sharing and the operation information of the historical operation performed within the preset time range before the screen sharing start time, and the risk control operation is performed, wherein the operation information includes but is not limited to operation time, operation target, operation object, operation content, operation type, operation result, etc., and the present specification does not limit this. In some embodiments, the association information can refer to the association degree between the sensitive operation and the historical operation, and the risk control operation is determined according to the association degree, for example, according to the numerical interval in which the numerical value corresponding to the association degree falls, and based on the mapping relationship between the preset numerical interval and the risk control operation, the risk control operation mapped by the numerical interval is taken as the risk control operation corresponding to the payment trigger operation, or the association information can also refer to the guiding degree of the historical operation to the sensitive operation, and the guiding degree is used to represent the degree of guiding effect of the historical operation on the sensitive operation, and then the corresponding risk control operation is determined according to the guiding degree, for example, according to the mapping relationship between the preset guiding degree and the risk control operation, the risk control operation mapped thereby is taken as the risk control operation corresponding to the payment trigger operation.

[0065] In some embodiments, the performing, according to the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing, the risk control operation corresponding to the payment trigger operation, comprises: performing, according to the association information between the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing and the payment trigger operation, the risk control operation corresponding to the payment trigger operation. In some embodiments, the risk control operation corresponding to the payment trigger operation performed by the user can be determined according to the association information between the operation information of the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing and the payment trigger operation, and the risk control operation is performed. The association information can refer to the degree of association between the sensitive operation and the payment trigger operation, and the risk control operation corresponding to the payment trigger operation is determined according to the degree of association. For example, according to the mapping relationship between the preset degree of association and the risk control operation, the risk control operation mapped by the degree of association is taken as the risk control operation corresponding to the payment trigger operation. Alternatively, the association information can also refer to the degree of guidance of the sensitive operation to the payment trigger operation, and the degree of guidance is used to represent the degree of guidance of the sensitive operation to the payment trigger operation. Then, the corresponding risk control operation is determined according to the degree of guidance. For example, according to the numerical interval to which the degree of guidance falls, and based on the mapping relationship between the preset numerical interval and the risk control operation, the risk control operation mapped by the numerical interval is taken as the risk control operation corresponding to the payment trigger operation.

[0066] Figure 2 A structural schematic diagram of a device for payment risk control provided by an embodiment of the present specification is provided. The device for payment risk control (hereinafter referred to as “payment risk control device 1”) can be realized by software, hardware or a combination of both to become all or part of an electronic device. According to some embodiments, the payment risk control device 1 comprises a screen sharing state obtaining module 11 and a payment risk control module 12.

[0067] The screen sharing state obtaining module is configured to obtain a screen sharing state corresponding to a user equipment currently used by a user in response to a payment trigger operation performed by the user.

[0068] The payment risk control module is configured to, if the screen sharing state indicates that the user equipment is currently in screen sharing, perform a risk control operation corresponding to the payment trigger operation according to the screen sharing state.

[0069] In some embodiments, the performing, according to the screen sharing state, the risk control operation corresponding to the payment trigger operation, comprises: determining corresponding risk quantification information according to the screen sharing state; and performing, according to the risk quantification information, the risk control operation corresponding to the payment trigger operation.

[0070] In some embodiments, the screen sharing state includes operation records corresponding to the user equipment during screen sharing and screen sharing duration information; and wherein determining corresponding risk quantification information according to the screen sharing state comprises determining corresponding risk quantification information according to the operation records, the screen sharing duration information, device risk quantification information corresponding to the user equipment, and transaction magnitude quantification information corresponding to the user.

[0071] In some embodiments, determining corresponding risk quantification information according to the operation records, the screen sharing duration information, device risk quantification information corresponding to the user equipment, and transaction magnitude quantification information corresponding to the user comprises determining corresponding risk quantification information according to the operation records, the screen sharing duration information, device risk quantification information corresponding to the user equipment, transaction magnitude quantification information corresponding to the user, and social relationship quantification information between the user and a payment object corresponding to the payment trigger operation.

[0072] In some embodiments, the screen sharing state includes screen content shared by the user equipment; and wherein performing a risk control operation corresponding to the payment trigger operation according to the screen sharing state comprises performing a risk control operation corresponding to the payment trigger operation according to the screen content shared by the user equipment.

[0073] In some embodiments, performing a risk control operation corresponding to the payment trigger operation according to the screen content shared by the user equipment comprises performing a risk control operation corresponding to the payment trigger operation according to sensitive information contained in the screen content shared by the user equipment.

[0074] In some embodiments, performing a risk control operation corresponding to the payment trigger operation according to sensitive information contained in the screen content shared by the user equipment comprises performing a risk control operation corresponding to the payment trigger operation according to association information between the sensitive information contained in the screen content shared by the user equipment and screen presentation content of the user equipment within a preset time range before a screen sharing start time.

[0075] In some embodiments, performing a risk control operation corresponding to the payment trigger operation according to sensitive information contained in the screen content shared by the user equipment comprises performing a risk control operation corresponding to the payment trigger operation according to association information between the sensitive information contained in the screen content shared by the user equipment and an operation object corresponding to the payment trigger operation.

[0076] In some embodiments, the screen sharing state includes an operation record corresponding to the user equipment during the screen sharing; and the performing the risk control operation corresponding to the payment trigger operation according to the screen sharing state includes: performing the risk control operation corresponding to the payment trigger operation according to the operation record corresponding to the user equipment during the screen sharing.

[0077] In some embodiments, the performing the risk control operation corresponding to the payment trigger operation according to the operation record corresponding to the user equipment during the screen sharing includes: performing the risk control operation corresponding to the payment trigger operation according to a sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing.

[0078] In some embodiments, the performing the risk control operation corresponding to the payment trigger operation according to the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing includes: performing the risk control operation corresponding to the payment trigger operation according to association information between the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing and a historical operation performed within a preset time range before a screen sharing opening time of the user equipment.

[0079] In some embodiments, the performing the risk control operation corresponding to the payment trigger operation according to the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing includes: performing the risk control operation corresponding to the payment trigger operation according to association information between the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing and the payment trigger operation.

[0080] The device embodiments described above correspond to the method embodiments, and specific descriptions can be referred to the description of the method embodiments, which will not be repeated here. The device embodiments are based on the corresponding method embodiments and have the same technical effects as the corresponding method embodiments. Specific descriptions can be referred to the corresponding method embodiments.

[0081] The embodiments of the present specification also provide a computer storage medium, which can store a plurality of instructions, the instructions being suitable for being loaded by a processor and executing the method of the embodiments of the present specification.

[0082] The embodiments of the present specification also provide a computer program product, which stores at least one instruction, the at least one instruction being loaded by the processor and executing the method of the embodiments of the present specification.

[0083] The embodiments of the present specification also provide a computer program product, which stores at least one instruction, the at least one instruction being loaded by the processor and executing the method of the embodiments of the present specification. Figure 3 The structure schematic diagram of the electronic device is shown. As shown in the figure, Figure 3At the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and of course can also include other hardware required by the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs to implement the method of the embodiments of the present specification.

[0084] The systems, apparatuses, modules or units illustrated by the above embodiments can be specifically implemented by a computer chip or entity, or by a product with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0085] Those skilled in the art will understand that the embodiments of the present specification can be provided as a method, a system, or a computer program product. Therefore, the present specification can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present specification can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) containing computer-usable program code.

[0086] The present specification is described with reference to flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present specification. It should be understood that each flow and / or block in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks. Figure 1 The functions specified in one or more flows and / or blocks.

[0087] These computer program instructions can also be stored in a computer-readable memory that can direct the computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including instruction devices that implement the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks. Figure 1 The functions specified in one or more flows and / or blocks.

[0088] These computer program instructions can also be loaded into a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 Figure 1

[0089] It should also be noted that the term "comprising" or "comprises" when used in this specification is taken to mean the inclusion of one or more steps or elements from the group of steps or elements that have been disclosed, but not to the exclusion of other steps or elements. It is intended to recite only as many steps or elements as are explicitly included, but does not exclude other steps or elements.

[0090] The specification can be described in the general context of computer-executable instructions, such as program modules, being executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types. Computer-executable instructions, associated data structures, and program modules represent examples of the program code means for executing steps of the methods disclosed herein. The particular sequence of steps and methods described in this specification is not the only sequence or method that can be implemented. Other sequences of steps can be provided and still be performed by the computer software implementing application specified processes.

[0091] Embodiments of the present specification are described herein with reference to flowchart illustrations and / or block diagrams of apparatus (e.g., systems) and computer-implemented methods (e.g., processes), each of which are intended to be exemplary. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. Such computer program instructions can be provided to a processor of a computer (or other programmable data processing apparatus) to produce a machine, such that the instructions, which execute via the processor of the computer (or other programmable data processing apparatus), create means for implementing the functions specified in the flowchart and / or block diagram block(s) or a means for carrying out other steps and / or functions disclosed in this specification.

[0092] The embodiments of the present specification described above are merely intended to illustrate the present specification, and are not intended to limit the present specification. The present specification can have various changes and modifications for those skilled in the art. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification shall be included in the scope of claims of the present specification.​​

Claims

1. A method for payment risk control, comprising: obtaining a screen sharing state corresponding to a user device currently used by a user in response to a payment trigger operation performed by the user; if the screen sharing state indicates that the user device is currently in screen sharing, performing a risk control operation corresponding to the payment trigger operation according to the screen sharing state; wherein the screen sharing state comprises screen content shared by the user device, and the performing of the risk control operation corresponding to the payment trigger operation according to the screen sharing state comprises: performing the risk control operation corresponding to the payment trigger operation according to association information between sensitive information contained in the screen content shared by the user device and screen presentation content of the user device within a preset time range before a screen sharing start time.

2. The method of claim 1, wherein the performing of the risk control operation corresponding to the payment trigger operation according to the screen sharing state comprises: determining corresponding risk quantification information according to the screen sharing state; and performing the risk control operation corresponding to the payment trigger operation according to the risk quantification information.

3. The method of claim 2, wherein the screen sharing state comprises operation records and screen sharing duration information of the user device during screen sharing; wherein the determining of the corresponding risk quantification information according to the screen sharing state comprises: determining the corresponding risk quantification information according to the operation records, the screen sharing duration information, device risk quantification information of the user device, and transaction magnitude quantification information of the user.

4. The method of claim 3, wherein the determining of the corresponding risk quantification information according to the operation records, the screen sharing duration information, the device risk quantification information of the user device, and the transaction magnitude quantification information of the user comprises: determining the corresponding risk quantification information according to the operation records, the screen sharing duration information, the device risk quantification information of the user device, the transaction magnitude quantification information of the user, and social relationship quantification information between the user and a payment object corresponding to the payment trigger operation.

5. The method of claim 1, wherein the screen sharing state comprises operation records of the user device during screen sharing; wherein the performing of the risk control operation corresponding to the payment trigger operation according to the screen sharing state comprises: performing the risk control operation corresponding to the payment trigger operation according to the operation records of the user device during screen sharing.

6. The method of claim 5, wherein the performing of the risk control operation corresponding to the payment trigger operation according to the operation records of the user device during screen sharing comprises: performing the risk control operation corresponding to the payment trigger operation according to sensitive operations involved in the operation records of the user device during screen sharing. 7.The method of claim 6, wherein performing the risk control operation corresponding to the payment trigger operation according to the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing comprises: performing the risk control operation corresponding to the payment trigger operation according to the association information between the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing and the historical operation performed by the user equipment within a preset time range before the screen sharing start time. 8.The method of claim 6, wherein performing the risk control operation corresponding to the payment trigger operation according to the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing comprises: performing the risk control operation corresponding to the payment trigger operation according to the association information between the sensitive operation involved in the operation record corresponding to the user equipment during the screen sharing and the payment trigger operation. 9.An apparatus for payment risk control, comprising: a screen sharing state obtaining module, configured to obtain a screen sharing state corresponding to a user equipment currently used by a user in response to a payment trigger operation performed by the user, wherein the screen sharing state comprises screen content shared by the user equipment; and a payment risk control module, configured to perform a risk control operation corresponding to the payment trigger operation according to association information between sensitive information contained in the screen content shared by the user equipment and screen presentation content of the user equipment within a preset time range before a screen sharing start time, if the screen sharing state indicates that the user equipment is currently in screen sharing. The computer program is executed by the processor to implement the steps of the method of any one of claims 1-8. comprising: a processor and a memory; wherein the memory stores a computer program, and the computer program is adapted to be loaded and executed by the processor to implement the steps of the method of any one of claims 1-8. The at least one instruction is executed by the processor to implement the steps of the method of any one of claims 1-8.

10. A storage medium having stored thereon a computer program, characterized in that ​ 11. An electronic device, comprising: ​ ​ 12. A computer program product having stored thereon at least one instruction, the computer program product comprising: ​

Citation Information

Patent Citations

  • Abnormal transaction identification method and device, equipment and storage medium

    CN114971643A

  • Event processing method and device and electronic equipment

    CN118656230A

  • Anti-fraud method and system based on shared screen monitoring

    CN118798889A