Data verification method and device

By performing data verification, field verification and anti-re-checking on transaction message data, the problem of transaction message data being tampered, forged or repeated submission during transmission is solved, and the security and reliability of the data are improved.

CN120074930APending Publication Date: 2025-05-30太保科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510230137.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In modern financial trading systems, transaction message data is easily tampered, forged or repeatedly submitted during transmission, resulting in poor data security and reliability.

Method used

In response to the successful decryption of the transaction message data using the key, data verification, field verification and re-re-proof verification are performed on the transaction message data to ensure the integrity and uniqueness of the data.

Benefits of technology

It effectively reduces the risk of transaction packet data being tampered, forged or repeated submission, and improves the security and reliability of transaction packet data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074930A_ABST
    Figure CN120074930A_ABST
Patent Text Reader

Abstract

The invention discloses a data verification method and device, which can be applied to the field of data processing, and comprises the following steps: in response to successful decryption of transaction message data by using a key, verifying the transaction message data, the verification comprising data verification, field verification and anti-re-verification, and the verification comprising data verification, field verification and anti-re-verification; and when the result of the data verification represents that the transaction message data is consistent with the transaction message data sent by the client, the result of the field verification represents that the field of the transaction message data accords with the preset field rule, and the result of the anti-re-verification represents that the target transaction message data repeated with the transaction message data does not exist, determining that the data verification succeeds. According to the application, the integrity and uniqueness of the transaction message data are ensured by combining the data verification, the field verification and the anti-re-verification, and the data verification is determined to be successful only when the three kinds of verification are passed. Therefore, the risk that the transaction message data is tampered, forged or repeatedly submitted is effectively reduced, and the security and reliability of the transaction message data are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing, and particularly to a data verification method and apparatus. Background Art

[0002] In modern financial trading systems, the accuracy and security of trading message data are of crucial importance. With the development of network technology, trading data faces risks of being tampered with, forged, or resubmitted during transmission, resulting in poor security and reliability of trading message data.

[0003] Therefore, how to improve the security and reliability of trading message data is a technical problem that those skilled in the art urgently need to solve. Summary of the Invention

[0004] This application provides a data verification method to improve the security and reliability of trading message data, and this application also provides a data verification apparatus.

[0005] In a first aspect, this application provides a data verification method, including:

[0006] In response to successful decryption of trading message data using a key, verifying the trading message data, where the verification includes data verification, field verification, and anti-duplication verification;

[0007] When the result of data verification indicates that the trading message data is consistent with the trading message data sent by the client, the result of field verification indicates that the fields of the trading message data conform to preset field rules, and the result of anti-duplication verification indicates that there is no target trading message data that duplicates the trading message data, it is determined that the data verification is successful.

[0008] Optionally, that the fields of the trading message data conform to preset field rules includes:

[0009] The type of the target field of the trading message data conforms to a preset type, the field value of the target field is within a preset range, and the field format conforms to a preset standard.

[0010] Optionally, that there is no target trading message data that duplicates the trading message data includes:

[0011] There is no target trading message data with the same trading object as the trading message data and the trading amount within a threshold range.

[0012] Optionally, the method further includes:

[0013] Generating a data report according to the trading message data, where the data report includes trading frequency, trading amount, and trading time;

[0014] Perform risk identification based on the data report. If the result of the risk identification indicates the existence of a risk, an alarm is issued.

[0015] Optionally, the performing risk identification based on the data report includes:

[0016] Input the data corresponding to the data report into a pre-trained risk identification model to obtain a risk score;

[0017] When the risk score is greater than the score threshold, determine that the result of the risk identification is the existence of a risk.

[0018] In a second aspect, the present application also provides a data verification device, and the device includes:

[0019] A response unit, configured to, in response to successful decryption of the transaction message data using a key, verify the transaction message data, and the verification includes data verification, field verification, and anti-duplication verification;

[0020] A determination unit, configured to determine that the data verification is successful when the result of the data verification indicates that the transaction message data is consistent with the transaction message data sent by the client, the result of the field verification indicates that the fields of the transaction message data conform to the preset field rules, and the result of the anti-duplication verification indicates that there is no target transaction message data that duplicates the transaction message data.

[0021] Optionally, the fields of the transaction message data conforming to the preset field rules include:

[0022] The type of the target field of the transaction message data conforms to the preset type, the field value of the target field is within the preset range, and the field format conforms to the preset standard.

[0023] Optionally, the non-existence of target transaction message data that duplicates the transaction message data includes:

[0024] There is no target transaction message data with the same transaction object as the transaction message data and the transaction amount within the threshold range.

[0025] Optionally, the device further includes:

[0026] A generation unit, configured to generate a data report according to the transaction message data, and the data report includes transaction frequency, transaction amount, and transaction time;

[0027] An alarm unit, configured to perform risk identification based on the data report. If the result of the risk identification indicates the existence of a risk, an alarm is issued.

[0028] Optionally, the alarm unit is specifically configured to:

[0029] Input the data corresponding to the data report into a pre-trained risk identification model to obtain a risk score;

[0030] When the risk score is greater than the score threshold, determine that the result of risk identification is that there is a risk.

[0031] In a third aspect, an embodiment of the present application provides a server, which includes a memory and a processor. The memory is used to store instructions or codes, and the processor is used to execute the instructions or codes so that the server executes the method described in the foregoing first aspect.

[0032] In a fourth aspect, an embodiment of the present application provides a computer storage medium, in which codes are stored. When the codes are run, the device running the codes implements the method described in the foregoing first aspect.

[0033] Compared with the prior art, the present application has the following beneficial effects:

[0034] In response to successful decryption of the transaction message data using the key, the present application performs verification on the transaction message data. Among them, the verification may include data verification, field verification, and anti-duplication verification. When the result of data verification indicates that the transaction message data is consistent with the transaction message data sent by the client, the result of field verification indicates that the fields of the transaction message data conform to the preset field rules, and the result of anti-duplication verification indicates that there is no target transaction message data that duplicates the transaction message data, it is determined that the data verification is successful. By combining data verification, field verification, and anti-duplication verification, the present application ensures the integrity and uniqueness of the transaction message data. Only when all three verifications pass, it is determined that the data verification is successful. Thereby effectively reducing the risk of the transaction message data being tampered with, forged, or submitted repeatedly, and improving the security and reliability of the transaction message data. Description of the Drawings

[0035] To more clearly illustrate the technical solutions in this embodiment or the prior art, the following will briefly introduce the drawings required for the description of the embodiment or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0036] Figure 1 It is a flowchart of a data verification method provided by an embodiment of the present application;

[0037] Figure 2 It is a schematic structural diagram of a specific implementation manner of a data verification device provided by the present application;

[0038] Figure 3 It is a schematic diagram of a server hardware architecture provided by an embodiment of the present application. Specific embodiments

[0039] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0040] It should be noted that a data verification method and device provided by the present application are used in the financial field and the data processing field. The above is only an example, and does not limit the application fields of the method and device names provided by the present application.

[0041] In a modern financial trading system, the accuracy and security of transaction message data are crucial. With the development of network technology, transaction data faces the risks of being tampered with during transmission (for example, an attacker may tamper with the message content through a man-in-the-middle attack, thus triggering financial fraud), forged (for example, an attacker may generate false transaction records in the system by forging transaction messages), or duplicate submission, resulting in poor security and reliability of transaction message data.

[0042] Therefore, how to improve the security and reliability of transaction message data is a technical problem that those skilled in the art urgently need to solve.

[0043] In view of this, through research, the technical solution of the present application is proposed. The present application performs verification on the transaction message data in response to successful decryption of the transaction message data using a key. Among them, the verification may include data verification, field verification, and anti-duplication verification. When the result of the data verification indicates that the transaction message data is consistent with the transaction message data sent by the client, the result of the field verification indicates that the fields of the transaction message data conform to the preset field rules, and the result of the anti-duplication verification indicates that there is no target transaction message data that duplicates the transaction message data, it is determined that the data verification is successful. The present application combines data verification, field verification, and anti-duplication verification to ensure the integrity and uniqueness of the transaction message data. When all three verifications pass, it is determined that the data verification is successful. Thus, the risk of the transaction message data being tampered with, forged, or duplicated is effectively reduced, and the security and reliability of the transaction message data are improved.

[0044] The method provided in the embodiments of the present application can be executed by software on a server. The server can be a rack server, a high-density server, a GPU server, a tower server, or can also be a blade server, a whole cabinet server, etc. The present application does not specifically limit.

[0045] To enable those skilled in the art to better understand the solution of this application, the following further detailed description of this application will be given in conjunction with the accompanying drawings and specific implementation manners. Hereinafter, an example will be given in which the method provided by the embodiments of this application is executed by a server.

[0046] Figure 1 It is a flowchart of a data verification method provided by an embodiment of this application. As Figure 1 shown, this method includes:

[0047] S101: In response to successful decryption of the transaction message data using the key, verify the transaction message data.

[0048] When a client has a business change and generates transaction message data, the server can generate a pair of keys (including a public key and a private key), send the public key to the client so that the client encrypts the transaction message, and the server receives the encrypted transaction message data sent by the client and decrypts it using the private key, which can ensure the security and integrity of the transaction message data during transmission. In response to successful decryption of the transaction message data using the key, the server can verify the transaction message data.

[0049] Exemplarily, the verification can include data verification, field verification, and anti-duplication verification. Data verification is used to verify the authenticity and accuracy of the transaction message data. Field verification is used to verify that the transaction insulation data complies with transaction rules and business rules. Anti-duplication verification is used to prevent duplicate transactions.

[0050] S102: When the result of the data verification indicates that the transaction message data is consistent with the transaction message data sent by the client, the result of the field verification indicates that the fields of the transaction message data conform to the preset field rules, and the result of the anti-duplication verification indicates that there is no target transaction message data that duplicates the transaction message data, determine that the data verification is successful.

[0051] When the result of the data verification indicates that the transaction message data is consistent with the transaction message data sent by the client, the result of the field verification indicates that the fields of the transaction message data conform to the preset field rules, and the result of the anti-duplication verification indicates that there is no target transaction message data that duplicates the transaction message data, determine that the data verification is successful.

[0052] Specifically, for the fields of the transaction message data to conform to the preset field rules, it can include: the type of the target field of the transaction message data conforms to the preset type, the field value of the target field is within the preset range, and the field format conforms to the preset standard.

[0053] Exemplarily, for example, the actual data of the "transaction amount" field in the transaction message data is "1234.56", which is a decimal number, and its preset type is an integer. Then, the type of the target field does not conform to the preset type. If the actual data is "1234", the type of the target field is an integer, which conforms to the preset type.

[0054] For example, the field value of the "transaction amount" field in the transaction message data is "5000", and its preset range is "0 to 10000". Then, the field value of the target field is within the preset range. For another example, if the field value is "20000", the field value of the target field is not within the preset range.

[0055] For example, the format of the "transaction date" field in the transaction message data is "2025 / 02 / 19", and its preset standard is YYYY-MM-DD. Then, the field format of the target field does not conform to the preset standard. If the format of the "transaction date" field in the transaction message data is "2025-02-19", the field format of the target field conforms to the preset standard "YYYY-MM-DD".

[0056] In some possible implementations, there is no target transaction message data that duplicates the transaction message data, which may include: there is no target transaction message data with the same transaction object as the transaction message data and the transaction amount within the threshold range.

[0057] Exemplarily, for example, the threshold range can be set to 2000. The transaction object in the transaction message data is "Customer A" and the transaction amount is 200,000. Then, the server can determine whether there is target transaction message data with the transaction object also being "Customer A" and the difference between the transaction amount and 200,000 being within 2000. If not, it can be determined that there is no duplicate transaction.

[0058] In some possible implementations, in the embodiments of the present application, a data report can also be generated according to the transaction message data. Among them, the data report can include transaction frequency, transaction amount, transaction time, etc. Then, risk identification can be performed according to the data report. If the result of the risk identification indicates that there is a risk, an alarm can be issued.

[0059] Specifically, the data corresponding to the data report can be input into a pre-trained risk identification model to obtain a risk score. When the risk score is greater than the score threshold, it can be determined that the result of the risk identification is that there is a risk, and then an alarm can be issued.

[0060] In some possible implementations, a high-risk threshold can also be set so that limited resources can be concentrated on handling high-risk events. For example, when the risk score is greater than or equal to the high-risk threshold, it is determined that the transaction may have a relatively high risk. For high-risk alerts, a more urgent notification method (such as a phone alert) can be adopted. When the risk score is less than the high-risk threshold, it is determined that the transaction may have a relatively low risk. For low-risk alerts, relevant personnel can be notified by email or instant messaging tools.

[0061] In some possible implementations, in the embodiments of the present application, the alert threshold can also be dynamically adjusted based on the output of the risk identification model and historical data. For example, the threshold can be adjusted according to historical data and business requirements to reduce false alarms or missed alarms. By performing risk identification and corresponding alerts in this way, relevant personnel can take measures in a timely manner to avoid the further expansion of risks. Moreover, using the model to automatically identify risks reduces the workload of manual review, while improving the accuracy and efficiency of risk identification. The model can process a large amount of data and quickly give a risk score, helping financial institutions or enterprises better manage risks.

[0062] In some possible implementations, a transaction threshold can also be set. When the value of the transaction amount in the data report is greater than or equal to the transaction threshold, it can be determined that the transaction is a large transaction, and then a notice information can be sent to relevant personnel to remind them to pay attention to this transaction.

[0063] In response to the successful decryption of the transaction message data using the key, the present application performs a verification on the transaction message data. Among them, the verification can include data verification, field verification, and duplicate prevention verification. When the result of the data verification indicates that the transaction message data is consistent with the transaction message data sent by the client, the result of the field verification indicates that the fields of the transaction message data conform to the preset field rules, and the result of the duplicate prevention verification indicates that there is no target transaction message data that duplicates the transaction message data, it is determined that the data verification is successful. By combining data verification, field verification, and duplicate prevention verification, the present application ensures the integrity and uniqueness of the transaction message data. Only when all three verifications pass, it is determined that the data verification is successful. Thereby effectively reducing the risk of the transaction message data being tampered with, forged, or submitted repeatedly, and improving the security and reliability of the transaction message data.

[0064] The above are some specific implementation manners of the data verification method provided by the embodiments of the present application. Based on this, the present application also provides a corresponding device. Next, the device provided by the embodiments of the present application will be introduced from the perspective of functional modularization. This device can be correspondingly referred to the data verification method described above.

[0065] Figure 2 It is a structural block diagram of the data verification device provided by the embodiments of the present invention, which is called the second specific implementation manner. Refer toFigure 2 The device may include:

[0066] A response unit 200, configured to, upon successful decryption of transaction message data using a key, verify the transaction message data, where the verification includes data verification, field verification, and anti-duplication verification;

[0067] A determination unit 210, configured to determine that the data verification is successful when the result of the data verification indicates that the transaction message data is consistent with the transaction message data sent by the client, the result of the field verification indicates that the fields of the transaction message data conform to a preset field rule, and the result of the anti-duplication verification indicates that there is no target transaction message data that duplicates the transaction message data.

[0068] Optionally, the fields of the transaction message data conforming to a preset field rule includes:

[0069] The type of the target field of the transaction message data conforms to a preset type, the field value of the target field is within a preset range, and the field format conforms to a preset standard.

[0070] Optionally, the non-existence of target transaction message data that duplicates the transaction message data includes:

[0071] There is no target transaction message data with the same transaction object as the transaction message data and the transaction amount within a threshold range.

[0072] Optionally, the device further includes:

[0073] A generation unit, configured to generate a data report according to the transaction message data, where the data report includes a transaction frequency, a transaction amount, and a transaction time;

[0074] An alarm unit, configured to perform risk identification according to the data report, and if the result of the risk identification indicates that there is a risk, issue an alarm.

[0075] Optionally, the alarm unit is specifically configured to:

[0076] Input the data corresponding to the data report into a pre-trained risk identification model to obtain a risk score;

[0077] When the risk score is greater than a score threshold, determine that the result of the risk identification is that there is a risk.

[0078] In the device of the present application, the response unit 200 is configured to, upon successful decryption of the transaction message data using the key, perform a verification on the transaction message data. The verification may include data verification, field verification, and duplicate prevention verification. The determination unit 210 is configured to determine that the data verification is successful when the result of the data verification indicates that the transaction message data is consistent with the transaction message data sent by the client, the result of the field verification indicates that the fields of the transaction message data conform to the preset field rules, and the result of the duplicate prevention verification indicates that there is no target transaction message data that duplicates the transaction message data. By combining data verification, field verification, and duplicate prevention verification, the present application ensures the integrity and uniqueness of the transaction message data. Only when all three verifications pass is it determined that the data verification is successful. Thereby effectively reducing the risk of the transaction message data being tampered with, forged, or submitted repeatedly, and improving the security and reliability of the transaction message data.

[0079] In addition, the present application also provides a hardware architecture of a server, as Figure 3 shown. The server 1000 includes a processor 1010 and a memory 1020. The memory 1020 stores computer instructions, and the processor 1010 is configured to execute the computer instructions, causing the server 1000 to execute the data verification method shown above.

[0080] In some embodiments, the processor 1010 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0081] In some embodiments, the memory 1020 may be a volatile memory or a non-volatile memory, such as a register, etc. Specifically, a volatile memory refers to a memory in which the data stored internally is lost when the power supply is interrupted. Among them, the volatile memory is mainly a random access memory (RAM), including a static random access memory (SRAM) and a dynamic random access memory (DRAM). A non-volatile memory refers to a memory in which the data stored internally will not be lost even when the power supply is interrupted. Common non-volatile memories include read only memory (ROM), optical discs, magnetic disks, solid state drives, and various memory cards based on flash memory technology, etc.

[0082] In some embodiments, the memory 1020 has executable code, and the memory 1010 executes this code to implement data verification.

[0083] The communication interface 1030 is used for external communication. For example, the communication interface 1030 serves as a first interface to implement communication with a real device.

[0084] The bus may be a Peripheral Component Interconnect (PCI) bus, or an extended industry standard architecture (eisa) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of understanding, Figure 3 it is only represented by a thick line, but it does not mean that there is only one bus or one type of bus.

[0085] The embodiments of the present application also provide corresponding servers and computer storage media for implementing the solutions provided by the embodiments of the present application.

[0086] Among them, the server includes a memory and a processor. The memory is used to store instructions or code, and the processor is used to execute the instructions or code so that the server executes the method described in any embodiment of the present application.

[0087] The computer storage medium stores code, and when the code is run, the device running the code implements the method described in any embodiment of the present application.

[0088] In the embodiments of the present application, the "first", "second" (if any) in the names such as "first" and "second" are only used as name identifiers and do not represent the first and second in order.

[0089] As can be seen from the description of the above embodiments, those skilled in the art can clearly understand that all or part of the steps in the above-described embodiment methods can be implemented by means of software plus a general-purpose hardware platform. Based on such an understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as a read-only memory (ROM) / RAM, magnetic disk, optical disk, etc., including several instructions for causing a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in various embodiments or some parts of the embodiments of the present application.

[0090] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device embodiments, since they are basically similar to the method embodiments, they are described relatively simply. For the relevant parts, reference can be made to the partial description of the method embodiments. One can select some or all of the modules according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0091] The above are only exemplary embodiments of the present application and are not used to limit the protection scope of the present application.

Claims

1. A data verification method, characterized in that: include: In response to successfully decrypting the transaction message data using the key, verifying the transaction message data, the verification including data verification, field verification and anti-duplicate verification; When the result of the data verification indicates that the transaction message data is consistent with the transaction message data sent by the client, the result of the field verification indicates that the field of the transaction message data conforms to the preset field rules, and the result of the anti-duplicate verification indicates that there is no target transaction message data that is repeated with the transaction message data, the data verification is determined to be successful.

2. The method according to claim 1, characterized in that The fields of the transaction message data conform to the preset field rules, including: The type of the target field of the transaction message data complies with a preset type, the field value of the target field is within a preset range, and the field format complies with a preset standard.

3. The method according to claim 1, characterized in that The target transaction message data that does not duplicate the transaction message data includes: There is no target transaction message data having the same transaction object as the transaction message data and a transaction amount within the threshold range.

4. The method according to claim 1, characterized in that: The method further comprises: Generate a data report based on the transaction message data, the data report including transaction frequency, transaction amount and transaction time; Risk identification is performed based on the data report, and if the result of risk identification indicates that there is a risk, an alarm is issued.

5. The method according to claim 1, characterized in that The risk identification according to the data report includes: Inputting the data corresponding to the data report into a pre-trained risk identification model to obtain a risk score; When the risk score is greater than the score threshold, it is determined that the result of risk identification is that there is a risk.

6. A data verification device, characterized in that: include: A response unit, configured to verify the transaction message data in response to successful decryption of the transaction message data using the key, wherein the verification includes data verification, field verification, and anti-duplicate verification; A determination unit is used to determine that data verification is successful when the result of data verification indicates that the transaction message data is consistent with the transaction message data sent by the client, the result of field verification indicates that the field of the transaction message data conforms to the preset field rule, and the result of anti-duplicate verification indicates that there is no target transaction message data that is repeated with the transaction message data.

7. The device according to claim 6, characterized in that The fields of the transaction message data conform to the preset field rules, including: The type of the target field of the transaction message data complies with a preset type, the field value of the target field is within a preset range, and the field format complies with a preset standard.

8. The device according to claim 6, characterized in that The target transaction message data that does not duplicate the transaction message data includes: There is no target transaction message data having the same transaction object as the transaction message data and a transaction amount within the threshold range.

9. The device according to claim 6, characterized in that The device also includes: A generating unit, configured to generate a data report according to the transaction message data, wherein the data report includes transaction frequency, transaction amount and transaction time; The alarm unit is used to identify risks based on the data report, and to issue an alarm if the result of risk identification indicates that there is a risk.

10. The device according to claim 9, characterized in that The alarm unit is specifically used for: Inputting the data corresponding to the data report into a pre-trained risk identification model to obtain a risk score; When the risk score is greater than the score threshold, it is determined that the result of risk identification is that there is a risk.