Account settlement security verification method and device, equipment and storage medium

By obtaining user operation information and determining the dynamic verification mode according to preset risk control strategies, the problem of low flexibility in the verification method in the prior art is solved, and the security and flexibility of the account settlement system are improved.

CN119991123APending Publication Date: 2025-05-13CHONGQING ZUOSHIFU IND CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510085686.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the prior art, the verification method is low in flexibility and cannot be dynamically adjusted according to user operation characteristics, resulting in low security and unable to meet diversified needs.

Method used

By obtaining the operation information of the target user, including operation type, operation time, IP address, amount value, operation continuity and operation correlation, determine the target verification mode corresponding to the operation information based on the preset risk control strategy, select the single-factor verification mode or the multi-factor verification mode, and verify the operation information based on the target verification mode.

Benefits of technology

It improves the flexibility of the account settlement system in security verification, enhances security, and can dynamically adjust the verification mode according to user operation characteristics to meet diverse needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119991123A_ABST
    Figure CN119991123A_ABST
Patent Text Reader

Abstract

The invention discloses an account settlement security verification method and device, equipment and a storage medium. The method comprises the following steps: acquiring operation information of a target user; the operation information carries a plurality of pieces of information to be verified, including an operation type, operation time, an IP address, an amount value, operation continuity and operation relevance; determining a target verification mode corresponding to the operation information according to a preset risk control strategy and the plurality of pieces of to-be-verified information; the target verification mode is a single-factor verification mode or a multi-factor verification mode; and verifying the operation information based on the target verification mode. According to the invention, the flexibility of the security verification mode of the account settlement system can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to an account settlement security verification method, device, equipment and storage medium. Background Art

[0002] The single-factor verification mode currently widely used in the market only verifies the user's operating intention through a fixed method. Although some platforms allow users to choose the verification method, they are actually limited to using fixed methods, which has low security and cannot be dynamically adjusted according to user operating characteristics, making it difficult to meet diverse needs; some platforms use a fixed two-factor verification mode, which verifies the user's operating intention through two fixed methods. Although the security is improved compared to single-factor verification, the verification method is fixed and unchanged, and it also lacks flexibility. It cannot be dynamically adjusted according to user behavior characteristics, and there are still security risks. Summary of the invention

[0003] The purpose of the embodiments of the present application is to provide an account settlement security verification method, device, equipment and storage medium to solve the problem of low flexibility of the verification method in the prior art.

[0004] In order to achieve the above-mentioned purpose, the first aspect of the present application provides an account settlement security verification method, which is applied to an account settlement system, and the method comprises:

[0005] Obtain the target user's operation information; the operation information contains multiple pieces of information to be verified, including operation type, operation time, IP address, amount, operation continuity, and operation relevance;

[0006] Determine the target verification mode corresponding to the operation information according to the preset risk control strategy and multiple pieces of information to be verified; the target verification mode is a single-factor verification mode or a multi-factor verification mode;

[0007] Verify the operation information based on the target verification mode.

[0008] In an embodiment of the present application, operation types include account login, account transaction, account recharge and account withdrawal; determining the target verification mode corresponding to the operation information according to the preset risk control strategy and multiple information to be verified includes: identifying the operation type and determining the corresponding preset risk threshold; determining the operation safety value corresponding to the operation information according to the operation time, IP address, amount value, operation continuity and operation correlation; judging the operation safety value and the preset risk threshold based on the preset risk control strategy to determine the target verification mode corresponding to the operation information.

[0009] In an embodiment of the present application, the operation safety value and the preset risk threshold are judged based on the preset risk control strategy to determine the target verification mode corresponding to the operation information, including: comparing the operation safety value with the preset risk threshold; when the operation safety value is less than the preset risk threshold, determining the verification mode to be a multi-factor verification mode; when the operation safety value is greater than or equal to the preset risk threshold, determining the verification mode to be a single-factor verification mode.

[0010] In the embodiment of the present application, the single-factor verification mode is one of account and password verification, mobile phone text message verification, email verification and UKEY verification.

[0011] In the embodiment of the present application, the multi-factor verification mode is multiple of account and password verification, mobile phone text message verification, email verification and UKEY verification.

[0012] In an embodiment of the present application, when the target verification mode is a single-factor verification mode, the method further includes: detecting that verification of the operation information based on the single-factor verification mode fails; switching the target verification mode to a multi-factor verification mode and re-verifying the operation information.

[0013] The second aspect of the present application provides an account settlement security verification device, which is applied to an account settlement system, and the device includes: an acquisition module, which is used to obtain the operation information of the target user; the operation information carries multiple information to be verified, including operation type, operation time, IP address, amount value, operation continuity and operation correlation; a determination module, which is used to determine the target verification mode corresponding to the operation information according to a preset risk control strategy and multiple information to be verified; the target verification mode is a single-factor verification mode or a multi-factor verification mode; a verification module, which is used to verify the operation information based on the target verification mode.

[0014] A third aspect of the present application provides a computer device, including:

[0015] a memory configured to store instructions; and

[0016] The processor is configured to call instructions from the memory and implement the above method when executing the instructions.

[0017] A fourth aspect of the present application provides a computer program product, including a computer program, which implements the above method when executed by a processor.

[0018] A fifth aspect of the present application provides a machine-readable storage medium, on which instructions are stored, and the instructions are used to enable a machine to execute the above method.

[0019] Through the above technical solution, the operation information of the target user is first obtained, and the operation information carries multiple information to be verified, including operation type, operation time, IP address, amount value, operation continuity and operation relevance; then, the target verification mode corresponding to the operation information is determined according to the preset risk control strategy and multiple information to be verified; the target verification mode is a single-factor verification mode or a multi-factor verification mode; finally, the operation information is verified based on the target verification mode, thereby improving the flexibility of the account settlement system during security verification.

[0020] Other features and advantages of the embodiments of the present application will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The accompanying drawings are used to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the following specific implementations, they are used to explain the embodiments of the present application, but do not constitute a limitation on the embodiments of the present application. In the accompanying drawings:

[0022] Figure 1 A flowchart of an account settlement security verification method according to an embodiment of the present application is schematically shown;

[0023] Figure 2 A structural block diagram of an account settlement security verification device according to an embodiment of the present application is schematically shown;

[0024] Figure 3 The schematic diagram shows a structural block diagram of a controller according to an embodiment of the present application. DETAILED DESCRIPTION

[0025] In order to make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the specific implementation methods described herein are only used to illustrate and explain the embodiments of the present application, and are not used to limit the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0026] It should be noted that if the embodiments of the present application involve directional indications (such as up, down, left, right, front, back...), the directional indications are only used to explain the relative position relationship, movement status, etc. between the components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication will also change accordingly.

[0027] In addition, if there are descriptions involving "first", "second", etc. in the embodiments of the present application, the descriptions of "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or suggesting their relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In addition, the technical solutions between the various embodiments can be combined with each other, but they must be based on the ability of ordinary technicians in the field to implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by this application.

[0028] Figure 1 The following schematically shows a flow chart of an account settlement security verification method according to an embodiment of the present application. Figure 1 As shown, an embodiment of the present application provides an account settlement security verification method, which is applied to an account settlement system. The method may include the following steps.

[0029] Step 101: Obtain the target user's operation information; the operation information carries multiple pieces of information to be verified, including operation type, operation time, IP address, amount value, operation continuity and operation relevance.

[0030] In the embodiment of the present application, the information to be verified can be a key data field in the operation information that needs to be reviewed, which is used to determine the authenticity and risk level of the operation; through this information, abnormal behavior or potential threats are identified to provide a basis for the subsequent selection of the verification mode. The operation type can refer to the specific behavior of the user in the account system, such as login, transaction, recharge or withdrawal. The operation type is the basis for risk assessment, and different risk thresholds can be set according to different behaviors. The operation time can be used to detect abnormal operation behavior, such as login or transaction in abnormal time period, which may indicate that the account is stolen. The IP address can identify abnormal geographical location operations, such as frequent switching of regions or operations from high-risk areas. The amount value can be used to assess the sensitivity of the operation, and large transactions may trigger stricter verification. Operation continuity can refer to whether the user has performed a series of continuous operations in a short period of time, such as multiple logins, transactions or withdrawals; used to detect potential malicious operations, such as brute force or batch transactions. Operation relevance can refer to the logical connection between multiple operations, such as whether transactions and recharges have a reasonable order or the frequent occurrence of the same operation type; used to help determine whether the operation conforms to the normal user behavior pattern, thereby identifying potential attack behaviors or abnormal operations.

[0031] Step 102: Determine a target verification mode corresponding to the operation information according to a preset risk control strategy and multiple pieces of information to be verified; the target verification mode is a single-factor verification mode or a multi-factor verification mode.

[0032] In the embodiment of the present application, the preset risk control strategy can be a rule or algorithm formulated in advance to evaluate the risk of user operations. It can include specific risk parameters, judgment logic, and models generated based on historical data. As the basic framework for evaluation, the operation information is risk analyzed to determine which verification mode to use. The preset risk control strategy can quickly respond to common risks and is scalable to respond to new threats. The target verification mode can be used to ensure that the verification matches the risk level, which does not affect the experience of normal users and can perform sufficient security verification for high-risk operations. The single-factor verification mode can be a lightweight verification method that only requires verification of one factor, such as a password or SMS verification code. It is suitable for low-risk operations, providing a convenient user experience and basic security. The multi-factor verification mode requires verification of multiple factor combinations (such as password plus SMS verification code or UKEY verification) to confirm the user identity with higher intensity. It is mainly used for high-risk operations, increasing the complexity of verification, ensuring account security, and reducing the possibility of being attacked. By adopting a flexible verification method, under the premise of ensuring security, not only the flexibility of the account settlement system is improved, but also the user experience can be optimized, reflecting the intelligence and precision of risk management.

[0033] Step 103: Verify the operation information based on the target verification mode.

[0034] In the embodiment of the present application, verification may refer to reviewing or verifying the operation information to ensure the authenticity and legality of the operation. By verifying the operation information, potential abnormal behavior or attacks can be effectively intercepted to protect account security.

[0035] Through the above technical solution, the operation information of the target user is first obtained, and the operation information carries multiple information to be verified, including operation type, operation time, IP address, amount value, operation continuity and operation relevance; then, the target verification mode corresponding to the operation information is determined according to the preset risk control strategy and multiple information to be verified; the target verification mode is a single-factor verification mode or a multi-factor verification mode; finally, the operation information is verified based on the target verification mode, thereby improving the flexibility of the account settlement system during security verification.

[0036] In an embodiment of the present application, operation types include account login, account transaction, account recharge and account withdrawal; determining the target verification mode corresponding to the operation information according to the preset risk control strategy and multiple information to be verified may include: identifying the operation type and determining the corresponding preset risk threshold; determining the operation safety value corresponding to the operation information according to the operation time, IP address, amount value, operation continuity and operation correlation; judging the operation safety value and the preset risk threshold based on the preset risk control strategy to determine the target verification mode corresponding to the operation information.

[0037] In the embodiment of the present application, the operation type may refer to the specific behavior category performed by the user in the system, including account login, account transaction, account recharge and account withdrawal. By classifying different operation types, corresponding risk assessment logic can be assigned. For example, account login: usually the starting point of identity authentication, assessing whether there is abnormal device or abnormal IP login. Account transaction: involving capital flow, it is necessary to judge the rationality of the transaction amount and behavior pattern. Account recharge: generally involves the source of account funds, and its legality and abnormal fluctuations in the amount need to be assessed. Account withdrawal: directly involves capital outflow, and the authenticity and risk of the operation need to be assessed. The preset risk threshold may refer to the risk tolerance range set in advance for different operation types, such as the risk level standard triggered by the amount, time, frequent IP switching, etc. As a benchmark value, it is compared with the operation safety value to determine whether a higher intensity verification is required. High-risk operation types (such as withdrawals) may have a lower risk threshold, triggering strict verification. Low-risk operation types (such as login) may have a higher risk threshold. The operation safety value can calculate the risk score of the operation behavior by analyzing information such as user operation time, IP address, amount value, operation continuity and correlation. The risk score can reflect the security of the current operation. The lower the value, the higher the risk. For example, logging in at an abnormal time (such as logging in late at night) may reduce the security value. Cross-regional IP switching or large-value transactions may further reduce the security value. Continuous failed operations or unrelated behaviors may seriously reduce the security value. The operation time can refer to the specific time point when the user operation occurs, and special monitoring is performed on the behavior in abnormal time periods (such as early morning operations). The IP address can refer to the network address of the source of the operation behavior, which is used to determine whether the geographical location is abnormal. For example, frequent location switching may indicate that the account has been stolen. The amount value can refer to the amount of funds involved in the transaction or operation, which is used to assess the sensitivity of the operation. For example, large withdrawals are more risky than small transactions. Operation continuity can refer to whether there are multiple similar operations in a short period of time, such as continuous logins or frequent withdrawals, which is used to detect the possibility of brute force or batch operations. Operation correlation can refer to the logical relationship between operations, such as whether withdrawals are made immediately after recharging, or whether multiple operations are in line with user behavior patterns, which is used to help determine the rationality of operations and detect abnormal behavior patterns.

[0038] In an embodiment of the present application, judging the operation safety value and the preset risk threshold based on the preset risk control strategy to determine the target verification mode corresponding to the operation information may include: comparing the operation safety value with the preset risk threshold; when the operation safety value is less than the preset risk threshold, determining the verification mode to be a multi-factor verification mode; when the operation safety value is greater than or equal to the preset risk threshold, determining the verification mode to be a single-factor verification mode.

[0039] In the embodiment of the present application, when the operation safety value is greater than or equal to the risk threshold, the risk is low, and the single-factor verification mode is selected to improve the user experience. When the operation safety value is less than the risk threshold, the risk is high, and the multi-factor verification mode is switched to further verify the legality of the operation. This effectively prevents the risks caused by the operation being forged or the account being hijacked, while optimizing the operation process of normal users and improving the flexibility of the account settlement system.

[0040] In the embodiment of the present application, the single-factor verification mode is one of account and password verification, mobile phone text message verification, email verification and UKEY verification.

[0041] In the embodiment of the present application, the multi-factor verification mode is multiple of account and password verification, mobile phone text message verification, email verification and UKEY verification.

[0042] In an embodiment of the present application, when the target verification mode is a single-factor verification mode, the method further includes: detecting that verification of the operation information based on the single-factor verification mode fails; switching the target verification mode to a multi-factor verification mode and re-verifying the operation information.

[0043] Figure 2 The following schematically shows a structural block diagram of an account settlement security verification device according to an embodiment of the present application. Figure 2 As shown, an embodiment of the present application provides an account settlement security verification device, which is applied to an account settlement system and may include: an acquisition module 210, used to obtain operation information of a target user; the operation information carries multiple information to be verified, including operation type, operation time, IP address, amount value, operation continuity and operation correlation; a determination module 220, used to determine a target verification mode corresponding to the operation information according to a preset risk control strategy and multiple information to be verified; the target verification mode is a single-factor verification mode or a multi-factor verification mode; a verification module 230, used to verify the operation information based on the target verification mode.

[0044] Through the above technical solution, first, the acquisition module 210 acquires the operation information of the target user, and the operation information carries multiple information to be verified, including operation type, operation time, IP address, amount value, operation continuity and operation relevance; then, the determination module 220 determines the target verification mode corresponding to the operation information according to the preset risk control strategy and multiple information to be verified; the target verification mode is a single-factor verification mode or a multi-factor verification mode; finally, the verification module 230 verifies the operation information based on the target verification mode, thereby improving the flexibility of the account settlement system during security verification.

[0045] Figure 3 The structure block diagram of a computer device according to an embodiment of the present application is schematically shown. Figure 3As shown, an embodiment of the present application provides a computer device, including:

[0046] Memory 310, configured to store instructions; and

[0047] The processor 320 is configured to call instructions from the memory and implement the above-mentioned account settlement security verification method when executing the instructions.

[0048] An embodiment of the present application also provides a computer program product, including a computer program, which implements the above-mentioned account settlement security verification method when executed by a processor.

[0049] An embodiment of the present application also provides a machine-readable storage medium, on which instructions are stored, and the instructions are used to enable a machine to execute the above-mentioned account settlement security verification method.

[0050] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0051] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0052] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0053] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0054] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0055] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0056] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0057] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0058] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.

Claims

1. A method for verifying the security of account settlement, characterized in that: Applied to an account settlement system, the method comprises: Obtaining the target user's operation information; the operation information carries multiple pieces of information to be verified, including operation type, operation time, IP address, amount value, operation continuity, and operation relevance; Determine a target verification mode corresponding to the operation information according to a preset risk control strategy and the multiple pieces of information to be verified; the target verification mode is a single-factor verification mode or a multi-factor verification mode; The operation information is verified based on the target verification mode.

2. The method according to claim 1, characterized in that The operation types include account login, account transaction, account recharge and account withdrawal; Determining the target verification mode corresponding to the operation information according to the preset risk control strategy and the plurality of information to be verified includes: Identify the operation type and determine the corresponding preset risk threshold; Determine an operation safety value corresponding to the operation information according to the operation time, the IP address, the amount value, the operation continuity and the operation relevance; The operation safety value and the preset risk threshold are judged based on the preset risk control strategy to determine the target verification mode corresponding to the operation information.

3. The method according to claim 2, characterized in that The judging of the operation safety value and the preset risk threshold based on the preset risk control strategy to determine the target verification mode corresponding to the operation information includes: comparing the operation safety value with a preset risk threshold; When the operation safety value is less than the preset risk threshold, determining that the verification mode is the multi-factor verification mode; When the operation safety value is greater than or equal to the preset risk threshold, the verification mode is determined to be the single-factor verification mode.

4. The method according to any one of claims 1 to 3, characterized in that The single-factor verification mode is one of account and password verification, mobile phone SMS verification, email verification and UKEY verification.

5. The method according to any one of claims 1 to 3, characterized in that: The multi-factor verification mode is multiple of account and password verification, mobile phone text message verification, email verification and UKEY verification.

6. The method according to any one of claims 1 to 3, characterized in that When the target verification mode is the single factor verification mode, the method further includes: detecting that verification of the operation information based on the single factor verification mode fails; The target verification mode is switched to a multi-factor verification mode and the operation information is re-verified.

7. An account settlement security verification device, characterized in that: Applied to account settlement systems, including: The acquisition module is used to acquire the operation information of the target user; the operation information carries multiple pieces of information to be verified, including operation type, operation time, IP address, amount value, operation continuity and operation relevance; A determination module, configured to determine a target verification mode corresponding to the operation information according to a preset risk control strategy and the plurality of information to be verified; the target verification mode is a single-factor verification mode or a multi-factor verification mode; A verification module is used to verify the operation information based on the target verification mode.

8. A computer device, characterized in that: include: a memory configured to store instructions; as well as A processor is configured to call the instructions from the memory and implement the method according to any one of claims 1 to 6 when executing the instructions.

9. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

10. A machine-readable storage medium, characterized in that: The machine-readable storage medium stores instructions, which are used to enable a machine to execute the method according to any one of claims 1 to 6.