Real-time detection security control method and system based on tokenization transaction, electronic device and storage medium
By invoking transaction management and risk control contracts on the blockchain and combining them with bank risk control nodes for real-time risk assessment, the lack of security checks and limit management in tokenized transactions is solved, thereby improving transaction security and efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING RED DATE INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2025-01-07
- Publication Date
- 2026-05-01
AI Technical Summary
The lack of real-time account security checks and flexible limit management in existing tokenized transactions exposes users' assets to potential risks, especially when facing hacker attacks or malicious operations, where traditional tokenized trading contracts struggle to provide sufficient protection.
By submitting transaction requests on the blockchain, the transaction management contract and risk control contract are invoked for verification. In conjunction with external bank risk control nodes on the blockchain, risk assessment is conducted, and transaction limits and security checks are dynamically adjusted to ensure that the transaction is executed only when the transaction risk is below a preset threshold.
It improves the accuracy of security risk assessment for tokenized transactions, enhances the protection of user assets, reduces transaction delays and insecurity factors, and improves transaction efficiency.
Smart Images

Figure CN120125241B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network technology, and in particular to a real-time detection security control method and system, electronic device and storage medium based on tokenized transactions. Background Technology
[0002] With the rapid development of internet technology, people's lives and work increasingly rely on the internet, giving rise to various internet-based services. In providing these services, user data is inevitably stored on the internet, which brings security risks such as data tampering. To solve this problem, blockchain technology was proposed, ensuring the immutability of data uploaded by users to the blockchain through its unique consensus mechanism.
[0003] In recent years, blockchain technology has made significant progress, and more and more users are using traditional services on blockchain networks for data security reasons. Specifically, through smart contracts or other blockchain technologies, users' real-world assets are mapped to tokens on the blockchain, and these tokens are used for transfer, trading, or management. The core idea of tokenization is to leverage the decentralization, transparency, and immutability of blockchain to make traditional asset trading processes more efficient and secure. Traditional tokenized deposit contracts typically map users' fiat currency deposits to on-chain tokens via smart contracts. These tokens can be transferred or traded on the blockchain network, but existing token trading lacks real-time account security checks and flexible limit management, resulting in delays and security vulnerabilities. These issues may expose user assets to potential risks.
[0004] Therefore, a real-time detection and security control scheme based on tokenized transactions is needed. Summary of the Invention
[0005] This application provides a real-time detection security control method and system, electronic device and storage medium based on tokenized transactions to address the security risks inherent in tokenized transactions in the prior art.
[0006] To achieve the above objectives, this application provides a real-time monitoring and security control method based on tokenized transactions, wherein the tokenized transactions are conducted on a blockchain by an initiator and a receiver, and the real-time monitoring and security control method includes:
[0007] The initiator of the transaction submits a transaction request to the first node of the blockchain, wherein the transaction request includes the initiator's account information on the blockchain, the recipient's account information on the blockchain, and the transaction information of the transaction.
[0008] The transaction management contract and risk control contract are invoked to verify the transaction request based on the transaction information contained in the transaction request. The risk control contract is used to communicate with the bank's risk control node set up outside the blockchain.
[0009] Based on the verification results of the transaction management contract and the risk control contract, the transaction risk corresponding to the transaction request is determined;
[0010] When the transaction risk is lower than a preset risk threshold, the first node calls the transaction contract corresponding to the transaction information to execute the transaction.
[0011] This application also provides a real-time detection and security control system based on tokenized transactions, wherein the tokenized transactions are conducted on a blockchain by an initiator and a receiver, and the system includes a blockchain and a bank risk control node set outside the blockchain.
[0012] The blockchain includes at least one first node, which is used to receive transaction requests submitted by the initiator of a transaction. The transaction request includes the initiator's account information on the blockchain, the recipient's account information on the blockchain, and transaction information. Based on the transaction information included in the transaction request, a transaction management contract and a risk control contract are invoked to verify the transaction request. Based on the verification results of the transaction management contract and the risk control contract, the transaction risk corresponding to the transaction request is determined. When the transaction risk is lower than a preset risk threshold, the transaction contract corresponding to the transaction information is invoked to execute the transaction.
[0013] The bank risk control node is used to receive the initiating account information, the receiving account information, and the transaction amount information from the first node; obtain the offline initiating account information and the offline receiving account information corresponding to the initiating account information and the receiving account information; and determine the risk of the corresponding offline initiating account and offline receiving account based on the offline initiating account information and the offline receiving account information.
[0014] This application also provides an electronic device, including:
[0015] Memory, used to store programs;
[0016] A processor is configured to run the program stored in the memory, wherein the program executes the real-time detection security control method provided in the embodiments of this application.
[0017] This application also provides a computer-readable storage medium storing a computer program executable by a processor, wherein the program, when executed by the processor, implements the real-time detection security control method provided in this application.
[0018] The real-time detection security control method, system, electronic device, and storage medium based on tokenized transactions provided in this application embodiment involve the transaction initiator submitting a transaction request to a first node of the blockchain. Based on the transaction information contained in the request, a transaction management contract and a risk control contract for communication with a bank risk control node located outside the blockchain are invoked to verify the transaction request. Based on the verification results of the transaction management contract and the risk control contract, the transaction risk corresponding to the transaction request is determined. When the transaction risk is lower than a preset risk threshold, the first node invokes the transaction contract corresponding to the transaction information to execute the transaction. Therefore, this application embodiment can jointly verify the risk of user-initiated transactions based on the blockchain and a bank risk control node outside the blockchain. This allows for a comprehensive assessment of the security risk of the transaction conducted on the blockchain by integrating various information related to the transaction on the blockchain and information recorded in the offline bank risk control system, greatly improving the accuracy of security risk assessment.
[0019] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0020] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:
[0021] Figure 1 A flowchart illustrating an embodiment of the real-time detection security control method based on tokenized transactions provided in this application;
[0022] Figure 2 A system block diagram of an embodiment of the real-time detection and security control system based on tokenized transactions provided in this application;
[0023] Figure 3 A schematic diagram of the structure of an embodiment of the electronic device provided in this application. Detailed Implementation
[0024] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
[0025] Example 1
[0026] With the rapid development of internet technology, the internet has become deeply integrated into people's lives and work, and various internet-based services have sprung up like mushrooms after rain. In the process of providing these services, user data inevitably needs to be stored on the internet. However, this data storage method also brings a series of security risks, such as data tampering. To address these risks, blockchain technology has emerged. With its unique consensus mechanism, blockchain can effectively ensure the immutability of data uploaded by users to the chain, thus providing a brand-new solution for data security.
[0027] In recent years, blockchain technology has achieved rapid development, and its application scenarios have gradually expanded. More and more users, prioritizing data security, are beginning to try innovative forms of traditional services on blockchain networks. In particular, blockchain technologies such as smart contracts are used to digitize real-world assets and map them to tokens on the blockchain. These tokens can be used to transfer, trade, or manage assets. The core concept of tokenization lies in fully leveraging the decentralized, transparent, and immutable characteristics of blockchain technology, thereby making the transaction process of traditional assets more efficient, secure, and trustworthy.
[0028] Taking tokenized deposit contracts as an example, the traditional implementation typically involves mapping a user's fiat currency deposits to on-chain tokens via smart contracts. These tokens can be freely transferred or traded within the blockchain network, but existing token trading models still have some shortcomings. For instance, the lack of real-time account security checks and flexible limit management mechanisms can not only lead to transaction delays but also increase the likelihood of assets facing potential risks. These issues urgently need to be addressed through technological innovation and mechanism optimization to further enhance the security and practicality of blockchain technology in asset management and trading.
[0029] For example, in actual token-based transactions, there is a lack of real-time account security checks. For instance, in token trading, trading contracts typically do not proactively check the security of trading accounts (such as whether private keys have been leaked or accounts have been attacked). This allows transactions to still be executed even when users face security threats. Furthermore, token transactions on the blockchain usually lack transaction limits or checks. Even if some contracts support limit settings, these settings are often pre-configured, fixed rules that cannot be dynamically adjusted based on real-time user needs or changes in the trading environment. This static configuration can lead to two situations: Excessively high limits: If limits are set too high, hackers could steal large amounts of assets in a single transaction if a user's account is attacked. Excessively low limits: If limits are set too low, users may be restricted during normal transactions, affecting transaction efficiency. In addition, existing trading contracts typically have limited monitoring of transaction behavior and cannot determine in real-time whether transactions are abnormal (such as whether fraud is involved).
[0030] These issues pose potential risks when user assets are traded on the blockchain, especially when faced with hacking or malicious operations, where traditional tokenized trading contracts struggle to provide adequate protection.
[0031] To address these issues in existing technologies, this application proposes a real-time security detection scheme for tokenized transactions. For example, Figure 1 This illustrates a real-time detection security control method for tokenized transactions according to embodiments of this application, such as... Figure 1 As shown, the real-time detection security control method may include:
[0032] S101, the transaction initiator submits a transaction request to the first node of the blockchain.
[0033] In step S101, the user can use their terminal to log in to a blockchain node that implements the real-time detection security control method according to embodiments of this application to initiate a transaction request on the blockchain. In embodiments of this application, the transaction request may include the initiating account information of the transaction initiator on the blockchain, the receiving account information of the transaction recipient on the blockchain, and the transaction information. For example, the transaction information included in the transaction request may be the type of transaction, such as a transfer, and the amount of the transaction, such as the transfer quantity.
[0034] S102, based on the transaction information contained in the transaction request, invoke the transaction management contract and risk control contract to verify the transaction request.
[0035] In step S102, the first node that received the user-submitted transaction request in step S101 can invoke the transaction management contract and risk control contract deployed on the blockchain based on the transaction information contained in the transaction request to perform security risk verification on the transaction request. In this embodiment, the transaction management contract may include an account contract deployed on the blockchain for verifying the blockchain account information contained in the transaction request, and may also include a limit verification contract for verifying the security risk of, for example, the amount contained in the transaction information. Furthermore, the risk control contract may be a verification contract that communicates with a bank risk control node located outside the blockchain. In this embodiment, the risk control contract may be a sender / receiver contract used only to generate a bank data acquisition request based on the account information and transaction information in the transaction request, and may forward the offline account information and offline limit information sent by the bank risk control node to the transaction management contract for comprehensive security risk assessment.
[0036] Furthermore, in step S102, after the risk control contract sends the account information and transaction information in the transaction request to the bank's risk control node located outside the blockchain, the bank's risk control node conducts a security risk assessment of the initiator and recipient accounts involved in the transaction request offline based on the bank's risk control system, and sends the assessment result to the risk control contract. The risk control contract then forwards the offline risk assessment result to the transaction management contract for a comprehensive assessment in conjunction with account verification and transaction limits on the blockchain. Alternatively, in this embodiment, the transaction management contract may not directly conduct a risk assessment after obtaining the initiator's account information and recipient's account information and / or the transaction limit information contained in the transaction request. Instead, it may wait to receive offline information such as the initiator's and recipient's offline account information or offline account security assessment information, transaction limit information, and / or transaction risk control information from the offline bank's risk control node, and then conduct a comprehensive risk assessment by integrating these online and offline information.
[0037] For example, in this embodiment, in step S102, the transaction management contract can first call the account contract to verify the legality of the blockchain initiating account and the blockchain receiving account corresponding to the initiating account information and the receiving account information of the receiving party as the transaction object, based on the initiating account information of the party submitting the transaction request and the receiving account information of the receiving party. Then, the transaction management contract can call the verification contract to determine the limit information of the blockchain receiving account corresponding to the receiving account information based on the receiving account information and the transaction information. In particular, in this embodiment, the initiating party's account can be securely verified when the first node receives the transaction request sent by the user in step S101, and the receiving party's account information can be securely verified through the transaction management contract in step S102. However, the account information of both the initiating party and the receiving party can also be securely verified through the transaction management contract in step S102. This application does not limit this.
[0038] Furthermore, as mentioned above, after the transaction management contract obtains the account information of the initiator's and recipient's accounts, the first node can invoke the risk control contract to obtain the offline receiving account information corresponding to the blockchain receiving account from the bank's risk control node set up outside the blockchain, either before, simultaneously with, or after the security verification of the account information by the transaction management contract. The first node then determines the risk of the offline receiving account corresponding to the offline receiving account information based on the offline receiving account information and transaction information. In addition, in this embodiment, the risk control contract can also obtain the corresponding offline initiator's account information from the bank's risk control node based on the initiator's account information, and determine the risk of the offline initiator's account based on the offline initiator's account information and transaction information. For example, the risk control contract can obtain the account information of the transaction object at the bank or all offline banks from the bank's risk control node, such as account number and historical transaction records, and then determine whether the transaction amount is excessively high compared to the recipient's offline historical transaction records based on the transaction amount. For example, if the receiving account of the counterparty in a transaction opened at an offline bank has historical transaction amounts that have not exceeded a preset amount A in the previous three months, but the transaction amount of this transaction is 100 times A, i.e., 100A, then the risk control contract can determine that the receiving account has a high account risk. The risk control contract can then send this high-risk information, such as the current transaction amount being 100 times the historical transaction amount, to the transaction management contract. Alternatively, in this embodiment, the risk control contract can directly send the obtained account information and historical transaction records to the transaction management contract, which will then conduct a security risk assessment based on this information and generate real-time transaction restriction information based on the determined risk and the limit information determined by the transaction management contract. For example, the transaction management contract can determine the comprehensive risk of the recipient of this transaction based on the account risk information of the blockchain receiving account and the risk of the offline receiving account, and then determine the transaction risk based on this comprehensive risk, the real-time transaction restriction information generated by the risk control contract, and the legality.
[0039] Furthermore, in this embodiment, in step S102, the transaction management contract can call the account contract to verify the legality of the blockchain initiating account and the blockchain receiving account corresponding to the initiating account information and the receiving account information of the transaction object, based on the initiating account information of the initiating party sending the transaction request and the receiving account information of the receiving party. Then, the transaction management contract can call the verification contract to determine the limit information of the blockchain receiving account corresponding to the receiving account information based on the receiving account information and the transaction information. Simultaneously or after the security verification process performed by the transaction management contract, the transaction management contract can send the initiating account information, the receiving account information, and the transaction amount information contained in the transaction information to the risk control contract. Since the risk control contract can communicate with the bank risk control node set up outside the blockchain, it can send the received initiating account information, receiving account information, and transaction amount information from the blockchain to the bank risk control node set up outside the blockchain. After receiving this information sent by the risk control contract on the blockchain, the bank risk control node can obtain the offline initiating account information and offline receiving account information corresponding to the initiating account information and the receiving account information.
[0040] For example, user A obtains an initiating account on the blockchain by registering, and similarly, user B, as a counterparty in the transaction, can also obtain a receiving account by registering on the blockchain. Furthermore, users A and B can open offline accounts within the banking system, thus also possessing offline initiating and receiving accounts. These accounts can all be identified using the users' registration information, for example, uniquely identified by their identity identifiers. Therefore, the risk control contract can obtain, for example, the user's identity identifier based on their account information on the blockchain, and then send this identifier to the offline bank risk control node. This allows the bank risk control node to obtain the offline account information of the initiator and receiver of the transaction based on the identity identifier. The bank risk control node can then determine the risk level of the corresponding offline initiating and receiving accounts based on this obtained offline initiating and receiving account information.
[0041] For example, a bank's risk control node can determine whether an account has transaction risk based on the transaction records of users A and B in the bank's system. Specifically, for example, the bank's risk control node can first determine the current security of the offline initiating account and the offline receiving account. Then, the bank's risk control node can obtain the historical transaction records corresponding to the account based on the account information, and calculate or determine the transaction frequency based on the transaction records to determine the first transaction risk based on the transaction frequency. For example, if the historical transactions of the initiating party's offline account are all spaced more than a month apart, i.e., the transaction frequency is very low, then the transaction risk of the offline initiating account can be determined to be high based on the transaction frequency. The bank's risk control node can also obtain the corresponding historical transaction amounts based on the offline initiating account and / or the offline receiving account, and determine the second transaction risk based on the historical transaction amounts. Specifically, if user A's historical transaction amounts are small and there are no large transactions, then user A's transaction risk in small transactions can be determined to be low, but if the transaction amounts are large, then user A's transaction risk is high.
[0042] After determining the risk level, the bank's risk control node can send the risk level information to the risk control contract. The risk control contract then verifies the transaction restrictions based on the risk level determined by the bank's risk control node and the transaction amount information sent by the transaction management contract, and sends the transaction restriction verification result to the transaction management contract.
[0043] S103. Based on the verification results of the transaction management contract and the risk control contract, determine the transaction risk corresponding to the transaction request.
[0044] S104 When the transaction risk is lower than the preset risk threshold, the first node calls the transaction contract corresponding to the transaction information to execute the transaction.
[0045] In step S103, the transaction risk corresponding to the transaction request can be determined based on the verification results of the transaction management contract and the risk control contract. When the transaction risk is lower than a preset risk threshold, the corresponding transaction contract can be invoked to execute the transaction in step S104. For example, in this embodiment, the risk control contract can generate real-time transaction restriction information based on the determined risk and the limit information determined by the transaction management contract. Then, the transaction management contract determines the transaction risk based on the real-time transaction restriction information and legality. In other words, in this embodiment, in step S103, the transaction management contract can determine the corresponding transaction risk based on its verification results of the legality of the user's blockchain account and the transaction amount, combined with the risk assessment results of the offline account sent by the risk control contract. Alternatively, the first node can determine the corresponding transaction risk by combining the verification results of the legality of the user's blockchain account and the transaction amount obtained by the transaction management contract with the risk assessment results of the offline account obtained by the risk control contract.
[0046] Furthermore, after the first node executes the transaction by invoking the transaction contract, in this embodiment, the first node can also obtain the execution result of the transaction contract and generate transaction execution information, which is then sent to the bank's risk control node via a risk control contract. After obtaining the execution result of the transaction on the blockchain, the bank's risk control node verifies the transaction execution information based on the offline account information received. For example, it can verify whether the offline accounts of both parties correspond to the accounts on the blockchain, and whether the transaction amount is reasonable compared to historical offline transaction amounts. When the verification is successful, the bank's risk control node can send the execution verification information to the first node. The first node can generate record information for the transaction based on the execution verification information sent by the offline bank's risk control node and the execution result it obtained, and broadcast this information to other nodes on the blockchain. Thus, the blockchain can write the execution result of the transaction contract and the verification information from the secondary verification performed by the offline bank's risk control node on the transaction result together as transaction result information into the block.
[0047] Therefore, the real-time security control method based on tokenized transactions provided in this application involves the transaction initiator submitting a transaction request to a first node on the blockchain. Based on the transaction information included in the request, the method invokes a transaction management contract and a risk control contract for communication with a bank risk control node located outside the blockchain to verify the transaction request. Based on the verification results of the transaction management contract and the risk control contract, the transaction risk corresponding to the transaction request is determined. When the transaction risk is lower than a preset risk threshold, the first node invokes the transaction contract corresponding to the transaction information to execute the transaction. Therefore, this application embodiment can jointly verify the risk of user-initiated transactions based on the blockchain and a bank risk control node outside the blockchain. This allows for a comprehensive assessment of the security risk of the transaction on the blockchain by integrating various information related to the transaction on the blockchain and information recorded in the offline bank risk control system, greatly improving the accuracy of security risk assessment.
[0048] Example 2
[0049] Figure 2 This is a system block diagram of one embodiment of the real-time detection and security control system based on tokenized transactions provided in this application. Figure 2 As shown in the embodiments of this application, the real-time detection security control system may include: blockchain 1 and bank risk control node 2. In this embodiment, blockchain 1 may include at least one first node 11, and transaction management contracts and risk control contracts may be deployed on blockchain 1.
[0050] In this embodiment of the application, the first node 11 on blockchain 1 can be used to receive a transaction request submitted by the initiator of the transaction; to verify the transaction request by calling the transaction management contract and the risk control contract according to the transaction information contained in the transaction request; to determine the transaction risk corresponding to the transaction request based on the verification results of the transaction management contract and the risk control contract; and to execute the transaction by calling the transaction contract corresponding to the transaction information when the transaction risk is lower than a preset risk threshold.
[0051] For example, user A, as the initiator of a transaction, can use their terminal to log in to blockchain 1 of the real-time detection security control system according to an embodiment of this application, and send a transaction request to the first node 11 to conduct a transaction on the blockchain. In this embodiment, the transaction request may include the initiator's account information on blockchain 1, the recipient's account information on blockchain 1, and the transaction information. For example, the transaction information included in the transaction request may be the type of transaction, such as a transfer, and the amount of the transaction, such as the transfer quantity.
[0052] Upon receiving a user-submitted transaction request, the first node 11 can invoke the transaction management contract and risk control contract deployed on blockchain 1 based on the transaction information contained in the transaction request to perform security risk verification on the transaction request. In this embodiment, the transaction management contract may include an account contract deployed on blockchain 1 for verifying the blockchain account information contained in the transaction request, and may also include a limit verification contract for verifying the security risk of, for example, the amount contained in the transaction information. Furthermore, the risk control contract may be a verification contract that communicates with a bank risk control node 2 located outside the blockchain. In this embodiment, the risk control contract may be a sender / receiver contract used only to generate a bank data acquisition request based on the account information and transaction information in the transaction request, and may forward offline account information and offline limit information received from the bank risk control node to the transaction management contract for comprehensive security risk assessment.
[0053] Furthermore, after the risk control contract sends the account information and transaction information from the transaction request to the bank risk control node 2 located outside the blockchain, the bank risk control node 2 conducts a security risk assessment of the initiator and recipient accounts involved in the transaction request offline based on the bank's risk control system. The assessment result is then sent to the risk control contract, which forwards the offline risk assessment result to the transaction management contract for a comprehensive assessment, combining it with account verification and transaction limits on blockchain 1. Alternatively, in this embodiment, the transaction management contract may not directly conduct a risk assessment after obtaining the initiator's and recipient's account information and / or transaction limit information contained in the transaction request. Instead, it waits to receive offline account information or offline account security assessment information, transaction limit information, and / or transaction risk control information from the offline bank risk control node 2 before conducting a comprehensive risk assessment by integrating these online and offline information.
[0054] For example, in this embodiment, the transaction management contract can first call the account contract to verify the legitimacy of the blockchain initiating account and the blockchain receiving account corresponding to the initiating account information and the receiving account information of the receiving party as the transaction object, based on the initiating account information of the party submitting the transaction request and the receiving account information of the receiving party. Then, the transaction management contract can call the verification contract to determine the limit information of the blockchain receiving account corresponding to the receiving account information based on the receiving account information and the transaction information. In particular, in this embodiment, the first node 11 can perform security verification on the initiating party's account when receiving the transaction request sent by the user, and perform security verification on the receiving party's account information by calling the transaction management contract. However, it can also call the transaction management contract later to perform security verification on the account information of both the initiating party and the receiving party of the transaction. This application does not limit this.
[0055] Furthermore, as mentioned above, after the transaction management contract obtains the account information of the initiator's and recipient's accounts, the first node 11 can invoke the risk control contract to obtain the offline receiving account information corresponding to the blockchain receiving account from the bank risk control node 2 set outside the blockchain, either before, simultaneously with, or after the security verification of the account information by the transaction management contract. The risk of the offline receiving account corresponding to the offline receiving account information is then determined based on the offline receiving account information and transaction information. In addition, in this embodiment, the risk control contract can also obtain the corresponding offline initiator's account information from the bank risk control node 2 based on the initiator's account information, and determine the risk of the offline initiator's account based on the offline initiator's account information and transaction information. For example, the risk control contract can obtain the account information of the transaction object at the bank or all offline banks from the bank risk control node 2, such as account number and historical transaction records, and then determine whether the transaction amount is excessively high compared to the recipient's offline historical transaction records based on the transaction amount. For example, if the receiving account of the counterparty in a transaction opened at an offline bank has historical transaction amounts that have not exceeded a preset amount A in the previous three months, but the transaction amount of this transaction is 100 times A, i.e., 100A, then the risk control contract can determine that the receiving account has a high risk. Then the risk control contract can send this high risk information, such as the current transaction amount being 100 times the historical transaction amount, to the transaction management contract.
[0056] Of course, in this embodiment, the risk control contract can also directly send the acquired account information and historical transaction records to the transaction management contract, which will then conduct a security risk assessment based on this information and generate real-time transaction restriction information based on the determined risk and the limit information determined by the transaction management contract. For example, the transaction management contract can determine the overall risk of the recipient of this transaction based on the account risk information of the blockchain-receiving account and the risk of the offline receiving account, and then determine the transaction risk based on the overall risk, the real-time transaction restriction information generated by the risk control contract, and the legality.
[0057] Furthermore, in this embodiment, the transaction management contract can invoke the account contract to verify the legality of the blockchain initiating account and the blockchain receiving account corresponding to the initiating account and receiving account information based on the initiating account information of the party sending the transaction request and the receiving account information of the party receiving the transaction. Then, the transaction management contract can invoke the verification contract to determine the limit information of the blockchain receiving account corresponding to the receiving account information based on the receiving account information and the transaction information. Simultaneously or after the security verification process performed by the transaction management contract, the transaction management contract can send the initiating account information, the receiving account information, and the transaction amount information contained in the transaction information to the risk control contract. Since the risk control contract can communicate with the bank risk control node 2 set up outside the blockchain, it can send the received initiating account information, receiving account information, and transaction amount information from the blockchain to the bank risk control node 2 set up outside the blockchain. After receiving this information from the risk control contract on the blockchain, the bank risk control node 2 can obtain the offline initiating account information and offline receiving account information corresponding to the initiating account information and the receiving account information.
[0058] For example, user A obtains an initiating account on blockchain 1 by registering on blockchain 1, and similarly, user B, as a counterparty in the transaction, can also obtain a receiving account on blockchain 1 by registering on blockchain 1. Furthermore, users A and B can open offline accounts within the banking system, thus also possessing offline initiating and receiving accounts. These accounts can all be identified using the user's registration information. For example, they can be uniquely identified using the user's identity identifier. Therefore, the risk control contract can obtain, for example, the user's identity identifier based on their account information on blockchain 1, and then send this identity identifier to the offline bank risk control node 2, enabling bank risk control node 2 to obtain the offline account information of the initiator and receiver of the transaction based on this identity identifier. Then, bank risk control node 2 can determine the risk level of the corresponding offline initiating and receiving accounts based on the obtained offline initiating and receiving account information.
[0059] For example, bank risk control node 2 can determine whether an account has transaction risk based on the transaction records of users A and B in the bank's system. Specifically, for example, bank risk control node 2 can first determine the current security of the offline initiating account and the offline receiving account. Then, the bank risk control node can obtain the historical transaction records corresponding to the account based on the account information, and calculate or determine the transaction frequency based on the transaction records to determine the first transaction risk based on the transaction frequency. For example, if the historical transactions of the initiating party's offline account are all spaced more than a month apart, i.e., the transaction frequency is very low, the transaction risk of the offline initiating account can be determined to be high based on the transaction frequency. Bank risk control node 2 can also obtain the corresponding historical transaction amount based on the offline initiating account and / or the offline receiving account, and determine the second transaction risk based on the historical transaction amount. Specifically, if user A's historical transaction amount is small and there are no large transactions, then user A's transaction risk in small transactions can be determined to be low, but if the transaction amount is large, then user A's transaction risk is high.
[0060] After determining the risk, the bank's risk control node 2 can send the risk to the risk control contract. The risk control contract will then verify the transaction restrictions based on the risk determined by the bank's risk control node and the transaction amount information sent by the transaction management contract, and send the transaction restriction verification result to the transaction management contract.
[0061] The first node 11 can determine the transaction risk corresponding to a transaction request based on the verification results of the transaction management contract and the risk control contract. When the transaction risk is lower than a preset risk threshold, it can call the corresponding transaction contract to execute the transaction. For example, in this embodiment, the risk control contract can generate real-time transaction restriction information based on the determined risk and the limit information determined by the transaction management contract. Then, the transaction management contract determines the transaction risk based on the real-time transaction restriction information and legality. In other words, in this embodiment, the first node 11 can call the transaction management contract to determine the corresponding transaction risk based on its verification results of the legality of the user's blockchain account and the transaction amount, combined with the risk assessment results of the offline account sent by the risk control contract. Alternatively, the first node 11 can determine the corresponding transaction risk by combining the verification results of the legality of the user's blockchain account and the transaction amount obtained by the transaction management contract with the risk assessment results of the offline account obtained by the risk control contract.
[0062] Furthermore, after the first node 11 executes the transaction by invoking the transaction contract, in this embodiment, the first node 11 can also obtain the execution result of the transaction contract and generate transaction execution information, which is then sent to the bank risk control node 2 via the risk control contract. After obtaining the execution result of the transaction on the blockchain, the bank risk control node 2 verifies the transaction execution information based on the offline received account information. For example, it can verify whether the offline accounts of both parties correspond to the accounts on the blockchain, and whether the transaction amount is reasonable compared to historical offline transaction amounts. When the verification is successful, the bank risk control node can send the execution verification information to the first node 11. The first node 11 can generate record information for the transaction based on the execution verification information sent by the offline bank risk control node and the execution result it obtained, and broadcast it to other nodes of blockchain 1. Thus, blockchain 1 can write the execution result of the transaction contract and the verification information of the secondary verification performed by the offline bank risk control node for the transaction result together as transaction result information into the block.
[0063] Therefore, the real-time detection and security control system based on tokenized transactions provided in this application embodiment involves the transaction initiator submitting a transaction request to the first node of the blockchain. Based on the transaction information contained in the request, the system invokes a transaction management contract and a risk control contract for communication with a bank risk control node located outside the blockchain to verify the transaction request. Based on the verification results of the transaction management contract and the risk control contract, the system determines the transaction risk corresponding to the transaction request. When the transaction risk is lower than a preset risk threshold, the first node invokes the transaction contract corresponding to the transaction information to execute the transaction. Therefore, this application embodiment can jointly verify the risk of user-initiated transactions based on the blockchain and the bank risk control node outside the blockchain. This allows for a comprehensive assessment of the security risk of the transaction on the blockchain by integrating various information related to the transaction on the blockchain and information related to the transaction recorded in the offline bank risk control system, greatly improving the accuracy of security risk assessment.
[0064] Example 3
[0065] The above describes the internal functions and structure of a blockchain deployment server, which can be implemented as an electronic device. Figure 3 A schematic diagram illustrating the structure of an embodiment of the electronic device provided in this application. (See attached diagram.) Figure 3 As shown, the electronic device includes a memory 31 and a processor 32.
[0066] Memory 31 is used to store programs. In addition to the programs described above, memory 31 can also be configured to store various other data to support operation on the electronic device. Examples of this data include instructions for any application or method used to operate on the electronic device, contact data, phonebook data, messages, pictures, videos, etc.
[0067] The memory 31 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.
[0068] Processor 32 is not limited to a central processing unit (CPU), but may also be a graphics processing unit (GPU), a field-programmable gate array (FPGA), an embedded neural network processor (NPU), or an artificial intelligence (AI) chip. Processor 32 is coupled to memory 31 and executes the program stored in memory 31. When the program runs, it executes the real-time detection security control method of Embodiment 1 described above.
[0069] Furthermore, such as Figure 3 As shown, the electronic device may also include other components such as a communication component 33, a power supply component 34, an audio component 35, and a display 36. Figure 3 The diagram only shows some components and does not mean that the electronic device includes only these components. Figure 3 The components shown.
[0070] Communication component 33 is configured to facilitate wired or wireless communication between electronic devices and other devices. The electronic devices can access wireless networks based on communication standards, such as WiFi, 3G, 4G, or 5G, or combinations thereof. In one exemplary embodiment, communication component 33 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 33 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0071] Power supply component 34 provides power to various components of the electronic device. Power supply component 34 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the electronic device.
[0072] Audio component 35 is configured to output and / or input audio signals. For example, audio component 35 includes a microphone (MIC) configured to receive external audio signals when the electronic device is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 31 or transmitted via communication component 33. In some embodiments, audio component 35 also includes a speaker for outputting audio signals.
[0073] Display 36 includes a screen, which may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touchscreen to receive input signals from a user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can detect not only the boundaries of the touch or swipe action, but also the duration and pressure associated with the touch or swipe operation.
[0074] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0075] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A real-time detection and security control method based on tokenized transactions, characterized in that, The tokenized transaction is conducted on the blockchain by the initiator and the recipient, and the real-time detection security control method includes: The initiator of the transaction submits a transaction request to the first node of the blockchain, wherein the transaction request includes the initiator's account information on the blockchain, the recipient's account information on the blockchain, and the transaction information of the transaction. The transaction management contract and risk control contract are invoked to verify the transaction request based on the transaction information contained in the transaction request. The risk control contract is used to communicate with the bank's risk control node set up outside the blockchain. Based on the verification results of the transaction management contract and the risk control contract, the transaction risk corresponding to the transaction request is determined; When the transaction risk is lower than a preset risk threshold, the first node calls the transaction contract corresponding to the transaction information to execute the transaction.
2. The real-time detection and safety control method according to claim 1, characterized in that, The step of verifying the transaction request by invoking the transaction management contract and the risk control contract based on the transaction information contained in the transaction request includes: The transaction management contract calls the account contract based on the initiating account information and the receiving account information to verify the legitimacy of the blockchain initiating account and the blockchain receiving account corresponding to the initiating account information and the receiving account information; The transaction management contract calls the verification contract based on the receiving account information and the transaction information to determine the limit information of the blockchain receiving account corresponding to the receiving account information; The risk control contract obtains offline receiving account information corresponding to the blockchain receiving account from a bank risk control node set up outside the blockchain based on the receiving account information; The risk control contract determines the risk level of the offline receiving account corresponding to the offline receiving account information based on the offline receiving account information and the transaction information, and The determination of the transaction risk corresponding to the transaction request based on the verification results of the transaction management contract and the risk control contract includes: The risk control contract generates real-time transaction restriction information based on the determined risk level and the limit information determined by the transaction management contract. The transaction risk is determined by the transaction management contract based on the real-time transaction restriction information and the legality.
3. The real-time detection and safety control method according to claim 1, characterized in that, The step of verifying the transaction request by invoking the transaction management contract and the risk control contract based on the transaction information contained in the transaction request includes: The transaction management contract calls the account contract based on the initiating account information and the receiving account information to verify the legitimacy of the blockchain initiating account and the blockchain receiving account corresponding to the initiating account information and the receiving account information; The transaction management contract calls the verification contract based on the receiving account information and the transaction information to determine the limit information of the blockchain receiving account corresponding to the receiving account information; The transaction management contract sends the initiating account information, the receiving account information, and the transaction amount information contained in the transaction information to the risk control contract; The risk control contract sends the initiating account information, the receiving account information, and the transaction amount information to the bank risk control node set up outside the blockchain; The bank's risk control node obtains the offline initiating account information and offline receiving account information corresponding to the initiating account information and the receiving account information based on the initiating account information and the receiving account information; The bank's risk control node determines the risk of the corresponding offline initiating account and offline receiving account based on the offline initiating account information and the offline receiving account information. The risk control contract verifies the transaction restrictions based on the risk determined by the bank's risk control node and the transaction amount information, and sends the transaction restriction verification result to the management contract.
4. The real-time detection and safety control method according to claim 3, characterized in that, The process by which the bank's risk control node determines the risk of the corresponding offline initiating account and offline receiving account based on the offline initiating account information and offline receiving account information includes: Determine the current security of the offline initiating account and the offline receiving account; The corresponding transaction frequency is obtained based on the offline initiating account and / or the offline receiving account, and the first transaction risk is determined based on the transaction frequency; Obtain the corresponding historical transaction amount based on the offline initiating account and / or the offline receiving account, and determine the second transaction risk based on the historical transaction amount.
5. The real-time detection safety control method according to claim 2, characterized in that, The method further includes: The first node generates transaction execution information based on the execution result of the transaction contract and sends it to the bank's risk control node; The bank's risk control node verifies the transaction execution information based on the account information received offline; When the verification is successful, the bank's risk control node will send the verification information to the first node. The first node generates record information for the transaction based on the execution verification information and the execution result, and broadcasts it to other nodes in the blockchain.
6. The real-time detection and safety control method according to claim 2, characterized in that, The step of verifying the transaction request by invoking the transaction management contract and the risk control contract based on the transaction information contained in the transaction request also includes: The transaction management contract obtains the account risk information of the corresponding blockchain initiating account and the account risk information of the blockchain receiving account based on the initiating account information and the receiving account information; Furthermore, the determination of the transaction risk by the transaction management contract based on the real-time transaction restriction information and the legality includes: The transaction management contract determines the overall risk of the recipient of this transaction based on the account risk information of the blockchain receiving account and the risk of the offline receiving account. The transaction risk is determined by the transaction management contract based on the overall risk, the real-time transaction restriction information, and the legality.
7. The real-time detection and safety control method according to claim 6, characterized in that, The step of verifying the transaction request by invoking the transaction management contract and the risk control contract based on the transaction information contained in the transaction request also includes: The risk control contract obtains offline initiating account information corresponding to the blockchain initiating account from a bank risk control node set up outside the blockchain based on the initiating account information. The risk control contract determines the risk of the offline initiating account corresponding to the offline initiating account information based on the offline initiating account information and the transaction information.
8. A real-time detection and security control system based on tokenized transactions, characterized in that, The tokenized transactions are conducted on the blockchain by the initiator and the recipient, and the system includes the blockchain and bank risk control nodes set up outside the blockchain. The blockchain includes at least one first node, which is used to receive transaction requests submitted by the initiator of a transaction. The transaction request includes the initiator's account information on the blockchain, the recipient's account information on the blockchain, and transaction information. Based on the transaction information included in the transaction request, a transaction management contract and a risk control contract are invoked to verify the transaction request. Based on the verification results of the transaction management contract and the risk control contract, the transaction risk corresponding to the transaction request is determined. When the transaction risk is lower than a preset risk threshold, the transaction contract corresponding to the transaction information is invoked to execute the transaction. The bank risk control node is used to receive the initiating account information, the receiving account information, and the transaction amount information from the first node; obtain the offline initiating account information and the offline receiving account information corresponding to the initiating account information and the receiving account information; and determine the risk of the corresponding offline initiating account and offline receiving account based on the offline initiating account information and the offline receiving account information.
9. An electronic device, characterized in that, include: Memory, used to store programs; A processor for running the program stored in the memory to perform the real-time detection security control method as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon that can be executed by a processor, characterized in that, When the program is executed by the processor, it implements the real-time detection security control method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Transaction restriction parameter setting method and device based on smart contract
CN113487326A
User quota allocation method and device
CN116993345A