Transaction security control method and device based on multiple identity verification, and medium

Through the multi-factor identity verification method, combining payment information, membership number, payment openid and face image comparison, the problem of traditional identity verification being easily attacked is solved, effective verification of non-member customers' identities and identification of fraud risks, and improved transaction security.

CN120047149APending Publication Date: 2025-05-27SHENZHEN EVOMOTION DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510078557.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

Traditional identity verification methods rely on single identity information verification and are susceptible to attacks by forged identities or illegal accounts. They especially have major loopholes in identity verification for non-member customers, making it difficult to effectively link with the blacklist database, resulting in the system being unable to identify fraud risks in a timely manner.

Method used

The transaction security control method based on multi-factor authentication is adopted to determine the identity status by obtaining the payment information of customers, and perform multiple matching verifications in combination with the blacklist database, including membership number, payment openid and face image comparison, ensuring the authenticity and accuracy of the identity verification.

Benefits of technology

Effectively identify and prevent theft and fraud, minimize the risks of identity forgery and fraud through multiple verification methods, improve transaction security, and ensure the rights and interests of customers and merchants.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120047149A_ABST
    Figure CN120047149A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of identity verification. The method comprises the steps of obtaining payment information submitted by a customer through payment terminal equipment, generating customer identity state information, obtaining a member verification result according to the customer identity state information, and if the customer is a non-member, sending the member verification result to a server; if the openid verification result shows that matching fails, secondary matching verification is carried out in the preset blacklist database through the payment openid again to obtain a second openid verification result, and if the second openid verification result shows that matching fails, the face image of the customer is obtained to obtain a face verification result. If the face verification result is matched successfully, reminding information is generated, and if the face verification result is matched unsuccessfully, transaction continuing information is generated. The method has the effects of realizing omnibearing verification of the identity of the customer and avoiding loopholes of a single verification mode.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of identity authentication, and in particular, to a transaction security control method, device, and medium based on multi-factor authentication. Background Art

[0002] With the rapid development of electronic payment technology, payment security has become a core challenge in retail and commercial transactions. Especially in some high-risk transaction environments, merchants need to effectively identify potential risky customers through various means to prevent criminals from committing fraud by misusing others' identities or other illegal means.

[0003] However, although traditional identity authentication methods can ensure the authenticity of customers' identities to a certain extent, these methods mostly rely on single identity information verification and are vulnerable to attacks by forged identities or illegal accounts. Especially for non-member customers, there are significant loopholes in their identity authentication, making it difficult to effectively link with existing blacklist databases, resulting in the system's inability to promptly detect customers or criminals at risk of fraud and thus failing to effectively prevent potential theft. Summary of the Invention

[0004] To achieve a comprehensive verification of customers' identities and avoid loopholes in single verification methods, the present application provides a transaction security control method, device, and medium based on multi-factor authentication.

[0005] The first object of the above invention of the present application is achieved through the following technical solutions: A transaction security control method based on multi-factor authentication, the transaction security control method based on multi-factor authentication includes: Obtain payment information submitted by a customer through a payment terminal device, judge the identity status of the customer according to the payment information, and generate customer identity status information; According to the customer identity status information, if the customer is a member, query a preset blacklist database through the member number, and match and verify the member number with the member records in the preset blacklist database to obtain a member verification result; Based on the member verification result, if the customer is a non-member, match and verify through the payment openid with the non-member records in the preset blacklist database to obtain an openid verification result; Based on the openid verification result, if the openid verification result is a match failure, then when the identity status of the customer is a member, perform a secondary match verification through the payment openid in the preset blacklist database again to obtain a second openid verification result; If the second openid verification result fails to match, obtain the face image of the customer, and compare it with the face images recorded in the preset blacklist database to obtain a face verification result; Based on the face verification result, if the face verification result matches successfully, generate a reminder message; if the face verification result fails to match, generate a continue transaction message, which is used to allow the customer to continue to complete the transaction.

[0006] By adopting the above technical solution, by judging the payment information submitted by the customer, the identity status of the customer can be accurately obtained, ensuring the authenticity of the customer's identity. Secondly, combined with the blacklist database for multiple matching verifications, it can effectively identify whether there are criminals or customers marked as abnormal persons, preventing fraud such as theft. Especially during the verification process, if the customer's identity is a non-member, comparing with the blacklist through the payment openid further improves the verification accuracy, and can conduct in-depth verification through secondary verification and face image comparison when necessary, minimizing the risk of identity forgery and fraud. Finally, through these multiple identity verification measures, corresponding reminder messages or continue transaction messages can be generated according to the verification results, helping merchants respond in real time and take necessary preventive measures, thus effectively enhancing transaction security, reducing theft, and ensuring the rights and interests of customers and merchants.

[0007] In a preferred example, the present application can be further configured as: obtaining the payment information submitted by the customer through the payment terminal device, judging the identity status of the customer according to the payment information, and generating customer identity status information, including: Obtain identity identification information from the payment information, and judge the identity status of the customer based on the identity identification information to obtain the customer identity status information.

[0008] By adopting the above technical solution, the identity identification information can be accurately extracted from the customer's payment information, and the identity status of the customer can be judged based on this information. It can effectively identify whether the customer is a member or a non-member.

[0009] In a preferred example, the present application can be further configured as: based on the openid verification result, if the openid verification result fails to match, and in the case that the identity status of the customer is a member, perform a secondary matching verification through the payment openid in the preset blacklist database to obtain a second openid verification result, and then further include: If the openid verification result matches successfully, generate the reminder message, which is used to prompt the supermarket staff that the customer is in the blacklist and has been marked as an abnormal person, reminding the staff to pay attention to the customer's behavior.

[0010] By adopting the above technical solution, when the openid verification result of the customer matches successfully, a reminder message can be automatically generated to timely notify the supermarket staff that the customer is on the blacklist and has been marked as an abnormal person. This measure can effectively improve the vigilance of the staff, prompting them to observe the behavior of the customer more carefully, thereby preventing the occurrence of possible fraud or other improper behaviors.

[0011] In a preferred example, the present application can be further configured as follows: If the second openid verification result fails to match, the face image of the customer is obtained and compared with the face images recorded in the preset blacklist database to obtain a face verification result. After that, it further includes: If the second openid verification result matches successfully, the reminder message is generated.

[0012] By adopting the above technical solution, when the second openid verification result matches successfully, a reminder message can be automatically generated to timely inform the staff that the identity of the customer has been verified and there is no abnormality. This mechanism helps to improve the fluency of the transaction process, and at the same time ensures that the staff can focus on other potential risk factors and avoid excessive intervention in the transactions of risk-free customers. The automatically generated reminder message further optimizes the transaction security management process, ensuring more accurate and efficient verification and monitoring of the customer's identity.

[0013] In a preferred example, the present application can be further configured as follows: The transaction security control method based on multi-factor authentication further includes: Based on the customer identity status information, the transaction behavior characteristic information of the customer is obtained, and the transaction behavior characteristic information is input into a behavior analysis model to obtain a transaction behavior characteristic judgment result; By dynamically marking the transaction behavior characteristic judgment result, a status information to be concerned about is generated, and the status information to be concerned about includes normal status information to be concerned about, warning status information to be concerned about, and high-concern status information to be concerned about.

[0014] By adopting the above technical solution, it is possible to accurately evaluate whether there is an abnormality in the customer's transaction behavior based on the customer identity status information and the transaction behavior characteristic information, and timely discover potential risks. After inputting the customer's transaction behavior into the behavior analysis model, the obtained transaction behavior characteristic judgment result provides an important basis for subsequent risk assessment. By dynamically marking these judgment results to generate different levels of status information to be concerned about (such as normal, warning, and high-concern status), it is possible to monitor the customer's transaction behavior performance in real time and take targeted measures.

[0015] In a preferred example, the present application can be further configured as follows: obtaining the transaction behavior characteristic information of the customer, inputting the transaction behavior characteristic information into a behavior analysis model, and obtaining a transaction behavior characteristic judgment result, including: Comparing the transaction behavior characteristic information with the normal transaction mode in the behavior analysis model to determine whether the customer's transaction behavior exhibits abnormal characteristics, and obtaining a transaction behavior characteristic judgment result.

[0016] By adopting the above technical solution, it is possible to effectively analyze and compare the customer's transaction behavior in real time, ensuring that potential abnormal behaviors can be detected in a timely manner during the transaction process. By comparing the transaction behavior characteristic information of the customer with the preset normal transaction mode, it is possible to accurately determine whether the customer exhibits abnormal characteristics.

[0017] In a preferred example, the present application can be further configured as follows: dynamically marking the transaction behavior characteristic judgment result to generate a to-be-monitored status information, where the to-be-monitored status information includes general to-be-monitored status information, warning to-be-monitored status information, and high-level to-be-monitored status information, including: According to the transaction behavior characteristic judgment result, evaluating the transaction behavior risk level of the customer, classifying the risk level information into low risk, medium risk, and high risk, and dynamically marking the transaction behavior of the customer; If the risk level is the low risk, generating the general to-be-monitored status information, where the general to-be-monitored status information is used to prompt the supermarket personnel to pay mild attention to the customer; If the risk level is the medium risk, generating the warning to-be-monitored status information, where the warning to-be-monitored status information is used to prompt the supermarket personnel to closely observe the behavior of the customer; If the risk level is the high risk, generating the high-level to-be-monitored status information, where the high-level to-be-monitored status information is used to prompt the supermarket personnel to monitor the behavior of the customer in real time.

[0018] By adopting the above technical solution, it is possible to achieve accurate risk assessment and dynamic monitoring of the customer's transaction behavior. By evaluating the risk level of the transaction behavior and generating different to-be-monitored status information according to different risk levels, it is possible to provide accurate reminders for supermarket staff, ensuring that the staff can take corresponding attention measures according to the risk situation of the customer. When the customer's transaction behavior is identified as low risk, the staff can pay mild attention. When the risk level is medium risk, it is necessary to observe the customer's behavior more closely, and when the risk level is high risk, the staff should monitor the customer's behavior in real time, thereby greatly reducing the occurrence of potential risk events.

[0019] The second inventive object of the present application is achieved by the following technical solutions: A transaction security control device based on multi-factor authentication, the transaction security control device based on multi-factor authentication includes: A payment information collection and identity status judgment module, configured to obtain payment information submitted by a customer through a payment terminal device, judge the identity status of the customer according to the payment information, and generate customer identity status information; A membership verification module, configured to, according to the customer identity status information, if the customer is a member, query a preset blacklist database through the membership number, and match and verify the membership number with the membership records in the preset blacklist database to obtain a membership verification result; A non-member verification module, configured to, based on the membership verification result, if the customer is a non-member, match and verify through the payment openid with the non-member records in the preset blacklist database to obtain an openid verification result; A secondary verification module, configured to, based on the openid verification result, if the openid verification result is a match failure, and when the identity status of the customer is a member, perform a secondary match verification through the payment openid in the preset blacklist database again to obtain a second openid verification result; A face verification module, configured to, if the second openid verification result is a match failure, obtain a face image of the customer, and compare it with the face images recorded in the preset blacklist database to obtain a face verification result; A transaction processing decision module, configured to, through the face verification result, if the face verification result is a match success, generate a reminder information, if the face verification result is a match failure, generate a continue transaction information, and the continue transaction information is used to allow the customer to continue to complete the transaction.

[0020] By adopting the above technical solution, by judging the payment information submitted by the customer, the customer identity status can be accurately obtained to ensure the authenticity of the customer identity. Secondly, by combining with the blacklist database for multiple matching verifications, it can effectively identify whether there are lawbreakers or customers who have been marked as abnormal persons, preventing the occurrence of fraud such as theft. Especially during the verification process, if the customer identity is a non-member, by comparing the payment openid with the blacklist, the verification accuracy is further improved, and in case of necessity, in-depth verification can be carried out through secondary verification and face image comparison, minimizing the risk of identity forgery and fraud. Finally, through these multiple identity verification measures, corresponding reminder information or continue transaction information can be generated according to the verification results, helping merchants to respond in real time and take necessary preventive measures, thereby effectively enhancing the transaction security, reducing theft behavior, and ensuring the rights and interests of customers and merchants.

[0021] The above object three of the present application is achieved by the following technical solution: A computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the above transaction security control method based on multiple identity verifications are implemented.

[0022] The above object four of the present application is achieved by the following technical solution: A computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, the steps of the above transaction security control method based on multiple identity verifications are implemented.

[0023] In summary, the present application includes at least one of the following beneficial technical effects: 1. By judging the payment information submitted by the customer, the customer identity status can be accurately obtained to ensure the authenticity of the customer identity. Secondly, by combining with the blacklist database for multiple matching verifications, it can effectively identify whether there are lawbreakers or customers who have been marked as abnormal persons, preventing the occurrence of fraud such as theft. Especially during the verification process, if the customer identity is a non-member, by comparing the payment openid with the blacklist, the verification accuracy is further improved, and in case of necessity, in-depth verification can be carried out through secondary verification and face image comparison, minimizing the risk of identity forgery and fraud. Finally, through these multiple identity verification measures, corresponding reminder information or continue transaction information can be generated according to the verification results, helping merchants to respond in real time and take necessary preventive measures, thereby effectively enhancing the transaction security, reducing theft behavior, and ensuring the rights and interests of customers and merchants; 2. It can accurately evaluate whether there are abnormalities in the customer's transaction behavior based on the customer identity status information and transaction behavior characteristic information, and timely discover potential risks. After inputting the customer's transaction behavior into the behavior analysis model, the obtained judgment results of transaction behavior characteristics provide an important basis for subsequent risk assessment. By dynamically marking these judgment results to generate different levels of status information to be concerned about (such as normal, warning, and highly concerned status), it can monitor the customer's transaction behavior in real time and take targeted measures; 3. It can achieve precise risk assessment and dynamic monitoring of the customer's transaction behavior. By evaluating the risk level of the transaction behavior and generating different status information to be concerned about according to different risk levels, it can provide accurate reminders for supermarket staff to ensure that the staff can take corresponding attention measures according to the customer's risk situation. When the customer's transaction behavior is identified as low risk, the staff can pay mild attention. When the risk level is medium risk, they need to observe the customer's behavior more closely. And when the risk level is high risk, the staff should monitor the customer's behavior in real time, thus greatly reducing the occurrence of potential risk events. Description of the Drawings

[0024] Figure 1 is a flowchart of a transaction security control method based on multi-factor authentication in an embodiment of the present application; Figure 2 is an implementation flowchart in step S10 of the transaction security control method based on multi-factor authentication in an embodiment of the present application; Figure 3 is an implementation flowchart after step S40 of the transaction security control method based on multi-factor authentication in an embodiment of the present application; Figure 4 is an implementation flowchart after step S50 of the transaction security control method based on multi-factor authentication in an embodiment of the present application; Figure 5 is an implementation flowchart after step S60 of the transaction security control method based on multi-factor authentication in an embodiment of the present application; Figure 6 is an implementation flowchart in step S70 of the transaction security control method based on multi-factor authentication in an embodiment of the present application; Figure 7 is an implementation flowchart in step S80 of the transaction security control method based on multi-factor authentication in an embodiment of the present application; Figure 8 is a principle block diagram of a transaction security control device for multi-factor authentication in an embodiment of the present application; Figure 9 is a schematic diagram of a device in an embodiment of the present application. Detailed Embodiment

[0025] The present application will be further described in detail below with reference to the accompanying drawings.

[0026] In one embodiment, as Figure 1 shown, the present application discloses a transaction security control method based on multi-factor authentication, which specifically includes the following steps: S10: Obtain the payment information submitted by the customer through the payment terminal device, judge the identity status of the customer according to the payment information, and generate customer identity status information.

[0027] Specifically, in order to obtain the payment information submitted by the payment terminal device, the system will exchange data through the secure interface with the payment terminal device to read the information input by the customer during the payment process, including the payment method, customer identifier (such as membership number, mobile phone number, payment account, etc.) and transaction details. After reading the payment information, the system judges its identity status. This process includes identifying whether the customer is a registered member of this supermarket or just a customer for a temporary transaction. This judgment is achieved by matching the membership information records in the database. If the customer identifier in the payment information is consistent with the information in the membership database record, the identity status is confirmed as a member; otherwise, the identity status is confirmed as a non-member. After the system completes the identity status judgment, the obtained customer identity status is recorded as customer identity status information.

[0028] S20: According to the customer identity status information, if the customer is a member, query the preset blacklist database through the membership number, and match and verify the membership number with the membership records in the preset blacklist database to obtain a membership verification result.

[0029] Specifically, the system first enters the preset blacklist database according to the membership identifier in the customer identity status information, and searches whether there is a corresponding record of the customer's membership number in the database. The query process calls the search interface of the database, and uses the membership number as the key field to compare item by item with the membership blacklist information stored in the database to verify whether there is a matching record. If a record with the same membership number is found in the blacklist database, the membership verification result is marked as a successful match; if not, it is marked as a failed match.

[0030] S30: Based on the membership verification result, if the customer is a non-member, match and verify the non-member records in the preset blacklist database through the payment openid to obtain an openid verification result.

[0031] In this embodiment, the payment openid refers to the unique identifier generated by a specific payment platform (such as WeChat or Alipay) when the customer makes a payment. The openid of each customer is unique on the payment platform and is associated with the customer's payment account.

[0032] Specifically, to verify whether a customer's openid is in the non - member blacklist, the system will first obtain the customer's payment openid. The system extracts this openid information through the secure communication interface of the payment terminal device and uses it as a query condition to input into the non - member data of the blacklist database. Then, the system calls the matching query function of the database to compare the obtained openid with the openids of the non - member blacklist recorded in the database one by one and calculates their matching degree. The matching process usually adopts a strict character consistency matching algorithm to ensure that there are no duplicate or mis - matched openids in the blacklist. If an exactly the same openid record is found in the database, the openid verification result is successful; if no same record is found, the openid verification result is failed.

[0033] S40: Based on the openid verification result, if the openid verification result is failed, when the customer's identity status is a member, perform a secondary matching verification again through the payment openid in the preset blacklist database to obtain the second openid verification result.

[0034] Specifically, when the system finds that the openid verification result is failed and the customer's identity status is a member, it will initiate a secondary matching verification of the payment openid. The system re - inputs the payment openid into the query interface of the blacklist database and retrieves all the openid records in the database again to ensure that there are no matching records of this payment openid in the entire database. The system executes this verification process to prevent omissions caused by data update delays or other factors. Once a match between the payment openid and the blacklist record is found in the database, the second openid verification result is successful; otherwise, the second openid verification result is failed.

[0035] S50: If the second openid verification result is failed, obtain the customer's face image and compare it with the face images recorded in the preset blacklist database to obtain the face verification result.

[0036] Specifically, when the second openid verification result fails to match, the system will initiate the operation of collecting the customer's face image to further verify the identity. The system obtains the real-time image through the camera of the payment terminal device, extracts the face feature data of the customer, such as facial contour, facial feature positions, and other biometric features. This face information is used as input and compared one by one with the stored blacklist face images, and the face recognition algorithm is used to calculate the similarity score. If the similarity score is higher than the set matching threshold, the face verification result is a successful match, indicating that the customer may be consistent with a certain record in the blacklist; if it is lower than the threshold, the face verification result is a failed match.

[0037] S60: Based on the face verification result, if the face verification result is a successful match, a reminder message is generated; if the face verification result is a failed match, a continue transaction message is generated, and the continue transaction message is used to allow the customer to continue to complete the transaction.

[0038] Specifically, the system generates corresponding processing information based on the face verification result. When the face verification result is a successful match, the system generates a reminder message and sends it to the supermarket monitoring terminal or the employee mobile device to inform the relevant staff that the customer is on the blacklist and may have abnormal behavior, so as to guide the staff to conduct further observation or intervention; the content of the reminder message includes the customer's basic information, risk warnings, and recommended countermeasures. If the face verification result is a failed match, the system generates a continue transaction message to ensure that the normal transaction process of the customer is not interrupted.

[0039] In one embodiment, as Figure 2 shown, in step S10, that is, obtaining the payment information submitted by the customer through the payment terminal device, judging the identity status of the customer according to the payment information, and generating the customer identity status information, including: S101: Obtain the identity identification information from the payment information, judge the identity status of the customer based on the identity identification information, and obtain the customer identity status information.

[0040] Specifically, to obtain the customer's identity identification information, the system first extracts key information related to the customer's identity from the payment information received from the payment terminal device. The payment information usually includes the customer's payment account ID, the unique identifier provided by the payment platform (such as openid), and other possible identity features (such as membership number or bound mobile phone number). The system gradually filters out specific information that can be used as the customer's identity identification by parsing the data fields in the payment information to ensure accuracy. Subsequently, the system uses the extracted identity identification information to perform a matching query with the preset customer identity database. This process is achieved by calling the database query function, inputting the extracted identity identification as a condition into the database, and comparing it with the customer identity information recorded in the database (such as membership or non-membership status) to determine the customer's identity status. If the match is successful, the customer's identity status information (such as member or non-member) is returned, and finally, the customer identity status information is generated and recorded.

[0041] In one embodiment, as Figure 3 shown, after step S40, that is, based on the openid verification result, if the openid verification result is a match failure, then when the customer's identity status is a member, the payment openid is used again to perform a secondary matching verification in the preset blacklist database to obtain the second openid verification result. After that, it further includes: S401: If the openid verification result is a match success, a reminder message is generated. The reminder message is used to prompt the supermarket staff that the customer is in the blacklist and has been marked as an abnormal person, and to remind the staff to pay attention to the customer's behavior.

[0042] Specifically, when the system detects that the openid verification result is a match success, that is, it confirms that the customer's openid is consistent with the non-member record in the blacklist database, the system will immediately generate a reminder message. Integrate the risk reminder information associating the customer identity with the blacklist record into a clear reminder, and the specific content includes information such as "This customer is in the blacklist" and "Historical records indicate that this customer has abnormal behavior". This reminder message not only indicates the customer's status in the blacklist but also further provides relevant records of the customer being marked as an abnormal person. The generated reminder message is then transmitted to the designated supermarket staff through the system internal notification channel or a dedicated notification platform (such as the supermarket's management background interface, email, or in-store intelligent terminal), enabling them to receive the reminder in real time. The goal of this reminder message is to help the staff pay attention during the customer's transaction or in-store activities.

[0043] In one embodiment, as Figure 4As shown, after step S50, that is, if the second openid verification result fails to match, obtain the customer's face image, and compare it with the face images recorded in the preset blacklist database to obtain the face verification result. After that, it further includes: S501: If the second openid verification result matches successfully, generate a reminder message.

[0044] Specifically, when the system detects that the second openid verification result is a successful match, that is, it confirms that the customer's openid is consistent with the records in the blacklist database during the secondary verification, the system immediately starts the process of generating a reminder message. This process first extracts the relevant information of the customer and the marked information of this openid in the blacklist through the data processing module, and then integrates these information into a complete reminder message. The content of this reminder message includes the customer's historical records in the blacklist, the description of associated abnormal behaviors, and a reminder for supermarket staff to be vigilant about the customer's behavior. The system then sends this reminder message to the preset notification interface, such as the management terminal of in-store employees, push notifications of employee applications, or the internal monitoring system, to ensure that the staff can obtain the reminder message in a timely manner.

[0045] In one embodiment, as Figure 5 shown, after step S60, that is, based on the transaction security control method of multi-factor authentication, it further includes: S70: Based on the customer identity status information, obtain the customer's transaction behavior characteristic information, and input the transaction behavior characteristic information into the behavior analysis model to obtain a transaction behavior characteristic judgment result.

[0046] Specifically, the system first extracts key identity characteristic data from the customer identity status information, such as the customer's membership level, consumption records, historical abnormal transaction behaviors, etc. Then, the system monitors and analyzes the behavior characteristics of the customer during the current transaction, including but not limited to shopping frequency, single transaction amount, product category preferences, and transaction time. Next, the system aggregates these transaction behavior characteristic data into a comprehensive characteristic data set and inputs it into the pre-constructed behavior analysis model. This model is based on machine learning algorithms, and by identifying the differences between the customer's behavior characteristics and the normal transaction patterns, calculates and outputs a transaction behavior characteristic judgment result.

[0047] S80: Generate a to-be-monitored status information by dynamically marking the transaction behavior characteristic judgment result. The to-be-monitored status information includes normal to-be-monitored status information, warning to-be-monitored status information, and high-alert to-be-monitored status information.

[0048] Specifically, based on the data in the transaction behavior feature judgment result, the system classifies the risk level of the customer's transaction behavior according to the preset risk assessment criteria. First, the system compares the judgment result with the threshold in the normal behavior pattern, and assigns the corresponding attention level to the customer according to the deviation degree of the comparison result: if the deviation is small, it is assigned to the general attention pending state; if the deviation is medium, it is marked as the warning attention pending state; if the deviation is large, it is marked as the high attention pending state. The attention pending state information generated by the system includes the customer's identity information, transaction behavior feature data, and the risk level label of this transaction, and triggers the corresponding operation prompt according to the different levels of the state information.

[0049] In one embodiment, as Figure 6 shown, in step S70, that is, obtaining the transaction behavior feature information of the customer, inputting the transaction behavior feature information into the behavior analysis model, and obtaining the transaction behavior feature judgment result, including: S701: Comparing the transaction behavior feature information with the normal transaction mode in the behavior analysis model to determine whether the customer's transaction behavior shows abnormal features, and obtaining the transaction behavior feature judgment result.

[0050] Specifically, the system first extracts the data features of the normal transaction mode from the behavior analysis model. The normal transaction mode is usually generated based on a large amount of historical data and can include the transaction behavior features of different customers under normal conditions, such as common purchase frequencies, average consumption amounts, shopping preferences, product combinations, etc. Subsequently, the system inputs the transaction behavior feature information of the current customer into the model, compares it with the normal transaction mode item by item, and calculates the deviation degree of the behavior by comparing the differences of each feature value. For example, if the amount of this transaction of the customer is much higher than his historical consumption habit, or the consumption of a specific product category increases abnormally, the system will detect such abnormal deviations. The system will use the set anomaly detection algorithm (such as statistical analysis, distance measure, etc.) to determine whether the deviation degree exceeds the set threshold range. If it exceeds, it is marked as abnormal. Finally, the comparison result is output as the transaction behavior feature judgment result.

[0051] In one embodiment, as Figure 6 shown, in step S80, that is, by dynamically marking the transaction behavior feature judgment result, generating the attention pending state information, and the attention pending state information includes the general attention pending state information, the warning attention pending state information, and the high attention pending state information, including: S801: According to the transaction behavior feature judgment result, evaluate the risk level of the customer's transaction behavior, classify the risk level information into low risk, medium risk, and high risk, and dynamically mark the customer's transaction behavior.

[0052] Specifically, the system first conducts a comprehensive assessment based on the judgment results of transaction behavior characteristics. By quantitatively calculating the abnormal degrees of multiple behavior characteristics (such as consumption amount, purchase frequency, preference for specific goods, etc.), the risk value of each characteristic is determined. Then, these risk values are weighted and aggregated to obtain the overall risk score. This risk score is compared with the preset risk level threshold. If the score is in the lowest range, it is a low risk; if in the medium range, it is a medium risk; if exceeding the highest range, it is a high risk. The system marks the customer's transaction behavior as the corresponding risk level according to the range to which the risk score belongs, forming dynamic marking data and providing a judgment basis for subsequent monitoring strategies.

[0053] S802: If the risk level is low risk, generate a general attention-needed status information, which is used to prompt supermarket staff to pay mild attention to the customer.

[0054] Specifically, after the system detects that the customer's risk level is low risk, it automatically generates a general attention-needed status information. The content of this information includes the customer's basic information, risk level status, and details of minor abnormal behaviors, etc. The system will push the general attention-needed status information to relevant employees through the supermarket staff terminal device and mark this customer with a concise prompt that requires mild attention. This mild attention prompt will not interfere with the normal business of the supermarket, but only be used to remind the staff to pay a little more attention to the customer's behavior, ensure moderate vigilance against potential abnormalities, and prevent the situation from developing.

[0055] S803: If the risk level is medium risk, generate a warning attention-needed status information, which is used to prompt supermarket staff to closely observe the customer's behavior.

[0056] Specifically, when the system evaluates that the customer's risk level is medium risk, the system will automatically generate a warning attention-needed status information, marking that the customer's behavior has obvious abnormal characteristics. This information includes detailed transaction behavior characteristics, abnormal indicators, and real-time monitoring suggestions. The system sends the warning attention-needed status information to the designated employee terminal, accompanied by clear behavior monitoring instructions, prompting the staff to closely pay attention to the actions of this customer, such as whether the customer's behavior conforms to normal shopping habits, etc. This information is displayed with a prominent identifier to ensure that the staff can respond in a timely manner and conduct on-site observation and prevention in a more proactive way.

[0057] S804: If the risk level is high risk, generate a high-level attention-needed status information, which is used to prompt supermarket staff to monitor the customer's behavior in real time.

[0058] Specifically, when the system identifies that the customer's risk level is high risk, it immediately generates a highly concerned status information. This information includes the customer's detailed behavior records, specific abnormal feature descriptions, suspicious behavior types, and recommended intervention measures. The system transmits this status information to the security personnel terminal of the supermarket in real time and triggers an emergency prompt sound, requiring employees to conduct real-time monitoring near the customer.

[0059] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0060] In one embodiment, a transaction security control device based on multi-factor authentication is provided. The transaction security control device based on multi-factor authentication corresponds one-to-one with the transaction security control method based on multi-factor authentication in the above embodiment. As Figure 8 shown, the transaction security control device based on multi-factor authentication includes a payment information collection and identity status judgment module, a member verification module, a non-member verification module, a secondary verification module, a face verification module, and a transaction processing decision module. The detailed description of each functional module is as follows: The payment information collection and identity status judgment module is used to obtain the payment information submitted by the customer through the payment terminal device, judge the identity status of the customer according to the payment information, and generate customer identity status information; The member verification module is used to, according to the customer identity status information, if the customer is a member, query the preset blacklist database through the member number, and match and verify the member number with the member records in the preset blacklist database to obtain a member verification result; The non-member verification module is used to, based on the member verification result, if the customer is a non-member, match and verify through the payment openid with the non-member records in the preset blacklist database to obtain an openid verification result; The secondary verification module is used to, based on the openid verification result, if the openid verification result is a match failure, and when the customer's identity status is a member, perform a secondary match verification through the payment openid in the preset blacklist database again to obtain a second openid verification result; The face verification module is used to, if the second openid verification result is a match failure, obtain the customer's face image, and compare it with the face images recorded in the preset blacklist database to obtain a face verification result; The transaction processing decision module is used to, through the face verification result, if the face verification result is a match success, generate a reminder information, if the face verification result is a match failure, generate a continue transaction information, and the continue transaction information is used to allow the customer to continue to complete the transaction.

[0061] Optionally, the payment information collection and identity status judgment module includes: The identity recognition and status judgment sub-module is used to obtain identity identification information from the payment information, judge the identity status of the customer based on the identity identification information, and obtain the customer identity status information.

[0062] Optionally, after the secondary verification module, there is also: The blacklist reminder and behavior monitoring module is used to generate a reminder message if the openid verification result matches successfully. The reminder message is used to prompt supermarket personnel that the customer is on the blacklist and has been marked as an abnormal person, and to remind the staff to pay attention to the customer's behavior.

[0063] Optionally, after the face verification module, there is also: The secondary verification reminder module is used to generate a reminder message if the second openid verification result matches successfully.

[0064] Optionally, after the transaction processing decision module, there is also: The transaction behavior analysis module is used to obtain the transaction behavior characteristic information of the customer based on the customer identity status information, input the transaction behavior characteristic information into the behavior analysis model, and obtain the transaction behavior characteristic judgment result; The risk marking module is used to generate the to-be-monitored status information by dynamically marking the transaction behavior characteristic judgment result. The to-be-monitored status information includes the normal to-be-monitored status information, the warning to-be-monitored status information, and the high-level to-be-monitored status information.

[0065] Optionally, the transaction behavior analysis module includes: The transaction behavior anomaly detection sub-module is used to compare the transaction behavior characteristic information with the normal transaction mode in the behavior analysis model to judge whether the customer's transaction behavior shows abnormal characteristics and obtain the transaction behavior characteristic judgment result.

[0066] Optionally, the risk marking module includes: The risk level assessment sub-module is used to evaluate the transaction behavior risk level of the customer according to the transaction behavior characteristic judgment result, divide the risk level information into low risk, medium risk, and high risk, and dynamically mark the customer's transaction behavior; The mild attention marking sub-module is used to generate the normal to-be-monitored status information if the risk level is low risk. The normal to-be-monitored status information is used to prompt supermarket personnel to pay mild attention to the customer; The close observation marking sub-module is used to generate the warning to-be-monitored status information if the risk level is medium risk. The warning to-be-monitored status information is used to prompt supermarket personnel to closely observe the customer's behavior; A real-time monitoring marking sub-module is used to generate a highly concerned status information if the risk level is high-risk. The highly concerned status information is used to prompt supermarket personnel to monitor the behavior of customers in real time.

[0067] For the specific limitations of the transaction security control device based on multi-factor authentication, reference can be made to the limitations of the transaction security control method based on multi-factor authentication in the above text, which will not be elaborated here. Each module in the above transaction security control device based on multi-factor authentication can be implemented in whole or in part by software, hardware, and their combinations. The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0068] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 9 shown. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it realizes a transaction security control method based on multi-factor authentication.

[0069] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are realized: Obtain the payment information submitted by the customer through the payment terminal device, judge the identity status of the customer according to the payment information, and generate customer identity status information; According to the customer identity status information, if the customer is a member, query the preset blacklist database through the member number, and match and verify the member number with the member records in the preset blacklist database to obtain a member verification result; Based on the member verification result, if the customer is a non-member, query the preset blacklist database through the payment openid, and match and verify the openid with the non-member records in the preset blacklist database to obtain an openid verification result; Based on the OpenID verification result, if the OpenID verification result is a match failure, then when the customer's identity status is a member, the payment OpenID is used again to perform a secondary matching verification in the preset blacklist database to obtain the second OpenID verification result; If the second OpenID verification result is a match failure, then obtain the customer's face image and compare it with the face images recorded in the preset blacklist database to obtain the face verification result; Based on the face verification result, if the face verification result is a match success, then generate a reminder message, and if the face verification result is a match failure, then generate a continue transaction message, where the continue transaction message is used to allow the customer to continue to complete the transaction.

[0070] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: Obtain the payment information submitted by the customer through the payment terminal device, determine the customer's identity status according to the payment information, and generate customer identity status information; According to the customer identity status information, if the customer is a member, then query the preset blacklist database through the member number, and match and verify the member number with the member records in the preset blacklist database to obtain the member verification result; Based on the member verification result, if the customer is not a member, then query the preset blacklist database through the payment OpenID, and match and verify the OpenID with the non-member records in the preset blacklist database to obtain the OpenID verification result; Based on the OpenID verification result, if the OpenID verification result is a match failure, then when the customer's identity status is a member, the payment OpenID is used again to perform a secondary matching verification in the preset blacklist database to obtain the second OpenID verification result; If the second OpenID verification result is a match failure, then obtain the customer's face image and compare it with the face images recorded in the preset blacklist database to obtain the face verification result; Based on the face verification result, if the face verification result is a match success, then generate a reminder message, and if the face verification result is a match failure, then generate a continue transaction message, where the continue transaction message is used to allow the customer to continue to complete the transaction.

[0071] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0072] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0073] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A transaction security control method based on multi-authentication authentication, characterized in that: The transaction security control method based on multi-factor authentication includes: Acquire payment information submitted by a customer through a payment terminal device, determine the identity status of the customer based on the payment information, and generate customer identity status information; According to the customer identity status information, if the customer is a member, the preset blacklist database is queried through the member number, the member number is matched and verified with the member record in the preset blacklist database, and a member verification result is obtained; Based on the member verification result, if the customer is a non-member, the payment openid is matched with the non-member record in the preset blacklist database to obtain an openid verification result; Based on the openid verification result, if the openid verification result is a match failure, then when the customer's identity status is a member, a second match verification is performed again in the preset blacklist database through the payment openid to obtain a second openid verification result; If the second openid verification result fails to match, obtaining the customer's face image and comparing it with the face images recorded in the preset blacklist database to obtain a face verification result; Through the face verification result, if the face verification result matches successfully, a reminder message is generated, and if the face verification result matches unsuccessfully, a transaction continuation message is generated, and the transaction continuation message is used to allow the customer to continue to complete the transaction.

2. The transaction security control method based on multi-identity authentication according to claim 1, characterized in that: The step of obtaining payment information submitted by a customer through a payment terminal device, determining the identity status of the customer based on the payment information, and generating customer identity status information includes: Acquire identity information from the payment information, determine the identity status of the customer based on the identity information, and obtain the customer identity status information.

3. The transaction security control method based on multi-identity authentication according to claim 1, characterized in that: Based on the openid verification result, if the openid verification result is a match failure, then when the identity status of the customer is a member, a second match verification is performed again in the preset blacklist database through the payment openid to obtain a second openid verification result, and then further comprising: If the openid verification result matches successfully, the reminder information is generated, and the reminder information is used to remind supermarket staff that the customer is in the blacklist and has been marked as an abnormal person, and remind the staff to pay attention to the customer's behavior.

4. The transaction security control method based on multi-identity authentication according to claim 1, characterized in that: If the second openid verification result fails to match, the facial image of the customer is obtained, and the facial image is compared with the facial image recorded in the preset blacklist database to obtain a facial verification result, and then the following further includes: If the second openid verification result matches successfully, the reminder information is generated.

5. The transaction security control method based on multi-identity authentication according to claim 1, characterized in that: The transaction security control method based on multi-factor authentication also includes: Based on the customer identity status information, acquiring the customer's transaction behavior characteristic information, inputting the transaction behavior characteristic information into the behavior analysis model, and obtaining the transaction behavior characteristic judgment result; By dynamically marking the transaction behavior feature judgment result, the attention-receiving status information is generated, and the attention-receiving status information includes ordinary attention-receiving status information, warning attention-receiving status information and high attention-receiving status information.

6. The transaction security control method based on multi-identity authentication according to claim 5, characterized in that: The acquiring of the transaction behavior characteristic information of the customer, inputting the transaction behavior characteristic information into a behavior analysis model, and obtaining a transaction behavior characteristic determination result includes: The transaction behavior characteristic information is compared with the normal transaction pattern in the behavior analysis model to determine whether the customer's transaction behavior exhibits abnormal characteristics, and obtain a transaction behavior characteristic determination result.

7. The transaction security control method based on multi-identity authentication according to claim 5, characterized in that: The dynamically marking the transaction behavior feature judgment result generates the state information to be paid attention to, and the state information to be paid attention to includes ordinary state information to be paid attention to, warning state information to be paid attention to, and high state information to be paid attention to, including: According to the transaction behavior feature judgment result, the risk level of the customer's transaction behavior is evaluated, and the risk level information is divided into low risk, medium risk and high risk to dynamically mark the customer's transaction behavior; If the risk level is the low risk, the general attention-waiting state information is generated, and the general attention-waiting state information is used to prompt the supermarket staff to pay slight attention to the customer; If the risk level is the medium risk, the warning state information is generated, and the warning state information is used to prompt the supermarket staff to closely observe the behavior of the customer; If the risk level is the high risk, the high-attention-needed status information is generated, and the high-attention-needed status information is used to prompt the supermarket staff to monitor the customer's behavior in real time.

8. A transaction security control device based on multiple identity authentication, characterized in that: The transaction security control device based on multiple identity authentication includes: The payment information collection and identity status judgment module is used to obtain the payment information submitted by the customer through the payment terminal device, judge the identity status of the customer according to the payment information, and generate the customer identity status information; A member verification module is used to query a preset blacklist database by the member number according to the customer identity status information, if the customer is a member, match and verify the member number with the member record in the preset blacklist database, and obtain a member verification result; A non-member verification module, for, based on the member verification result, if the customer is a non-member, matching and verifying the non-member record in the preset blacklist database by using the payment openid, so as to obtain an openid verification result; A secondary verification module, for performing secondary matching verification in the preset blacklist database again through the payment openid based on the openid verification result, if the openid verification result is a match failure, when the identity status of the customer is a member, to obtain a second openid verification result; A face verification module, for obtaining a face image of the customer and comparing it with the face images recorded in the preset blacklist database to obtain a face verification result if the second openid verification result fails to match; The transaction processing decision module is used to generate a reminder message if the face verification result matches successfully, and to generate a transaction continuation message if the face verification result matches unsuccessfully. The transaction continuation message is used to allow the customer to continue to complete the transaction.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the transaction security control method based on multi-authentication authentication are implemented as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the transaction security control method based on multi-authentication authentication as described in any one of claims 1 to 7 are implemented.