Risk control management method and device, equipment, storage medium and product
By using programmable network cards and multicast packaging technology in the risk control management system, the commissioned messages are efficiently detected and distributed, which solves the problem of delayed processing in traditional risk control management solutions and improves the security and stability of the transaction system.
Patent Information
- Application Number
- CN202510178906.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-06-27
AI Technical Summary
Due to the centralized deployment method, traditional risk control management solutions have large processing delays, which affect the efficiency and security of the transaction system.
The commissioned message is detected through a programmable network card to obtain risk declaration orders, and based on multicast packaging, the commissioned message and return message are distributed to multiple risk control nodes, and risk control management is carried out according to multiple risk control nodes and preset risk control strategies.
It realizes efficient cross-detection detection and risk control management of entrusted messages, quickly identify potential risks, reduce information processing delays, and improve transaction security and stability.
Smart Images

Figure CN120219073A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of financial risk control, and particularly to a risk control management method, device, equipment, storage medium and product. Background Art
[0002] The main business function of risk control management for transactions is to monitor whether there are abnormal transactions in the trading of a single customer or the customer's trading in the target individual stocks at the order data stream level. This is mainly to monitor the errors in the program trading of the client side or human errors, and to prevent potential knock-on transactions that may cause violations due to differences in strategies within the same account or related different accounts.
[0003] In the prior art, the risk control node and the counter node are connected through a message bus. All the entrusted messages sent by the counter and all the transaction information received are published to the risk control node through the message bus. Before each entrustment sent by the counter, it is necessary to wait for the calculation result returned by the risk control node to determine whether the entrustment can be directly declared. The risk control calculation node needs to obtain all the in-transit entrustments and their transaction information. Therefore, due to the traditional solution being deployed in a centralized manner, the processing delay of risk control management is relatively large. Summary of the Invention
[0004] The main purpose of this application is to provide a risk control management method, device, equipment, storage medium and product, aiming to solve the technical problem of relatively large processing delay caused by the centralized deployment method in the traditional risk control management solution.
[0005] To achieve the above purpose, this application proposes a risk control management method, and the method includes:
[0006] Detecting knock-on of the entrusted message through a programmable network card to obtain a risk declaration order, and distributing the entrusted message and the return message to multiple risk control nodes based on multicast encapsulation;
[0007] Performing risk control management on the risk declaration order according to the multiple risk control nodes and a preset risk control strategy.
[0008] In an embodiment, the step of detecting knock-on of the entrusted message through a programmable network card to obtain a risk declaration order, and distributing the entrusted message and the return message to multiple risk control nodes includes:
[0009] Receiving the entrusted message sent by the client through the programmable network card, and determining whether it is necessary to perform knock-on risk control inspection on the entrusted message according to the security category of the entrusted message;
[0010] If it is not necessary to perform knock-on risk control inspection on the entrusted message, sending the entrusted message to the trading gateway through the first message transmission channel for the trading process;
[0011] If it is necessary to conduct a contra risk control inspection on the entrusted message, then conduct a contra comparison on the entrusted message to obtain a comparison result, and determine whether it is necessary to modify the entrusted message according to the comparison result;
[0012] If it is necessary to modify the entrusted message, then modify the entrusted message according to a preset modification rule to obtain a risk declaration order, and block the subsequent trading process of the risk declaration order through a rejection message;
[0013] Distribute the entrusted message and the return message to multiple risk control nodes through multicast encapsulation and mirror replication.
[0014] In one embodiment, after the step of if it is necessary to modify the entrusted message, then modify the entrusted message according to a preset modification rule to obtain a risk declaration order, and block the subsequent trading process of the risk declaration order through a rejection message, further includes:
[0015] Receive the return message of the risk declaration order, and obtain a first return message and a second return message by mirror replicating the return message;
[0016] Update the risk control storage table based on the first return message to obtain an updated risk control storage table, and send the second return message to the counter switch through a preset communication method and a second message transmission channel based on the User Datagram Protocol multicast method;
[0017] Monitor each entrusted message sent by the client based on the risk control storage table and the counter switch.
[0018] In one embodiment, the risk control storage table includes an order table and a price level table. The step of updating the risk control storage table based on the first return message to obtain an updated risk control storage table, and sending the second return message to the counter switch through a preset communication method and a second message transmission channel based on the User Datagram Protocol multicast method includes:
[0019] Store the entrusted message and the first return message through the order table, and record the market buy and sell price level information through the price level table;
[0020] Obtain each entrusted message in real time, and update and adjust the order table and the price level table according to each entrusted message to obtain an updated risk control storage table;
[0021] Send the second return message to the counter switch through a preset communication method and a second message transmission channel based on the User Datagram Protocol multicast method.
[0022] In one embodiment, the step of performing risk control management on the risk declaration order according to the multiple risk control nodes and the preset risk control strategy includes:
[0023] The multiple risk control nodes parse the multicast data packet, extract the risk declaration order, and perform a risk assessment on the risk declaration order to obtain an assessment result;
[0024] According to the assessment result and the preset risk control strategy, perform risk control management on the risk declaration order.
[0025] In one embodiment, after the step of performing risk control management on the risk declaration order according to the multiple risk control nodes and the preset risk control strategy, it further includes:
[0026] Set system parameters through a configuration register to obtain updated system parameters, and apply the updated system parameters to perform risk control management on the risk declaration order;
[0027] And / or,
[0028] Initialize the system settings through a reset register to obtain initialized system settings, and apply the initialized system settings to perform risk control management on the risk declaration order.
[0029] In addition, to achieve the above object, the present application also proposes a risk control management device, and the risk control management device includes:
[0030] A data detection module, configured to perform a knock detection on the entrustment message through a programmable network card to obtain a risk declaration order, and distribute the entrustment message and the return message to multiple risk control nodes based on multicast encapsulation;
[0031] A risk control management module, configured to perform risk control management on the risk declaration order according to the multiple risk control nodes and the preset risk control strategy.
[0032] In addition, to achieve the above object, the present application also proposes a risk control management device, and the device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the risk control management method as described above.
[0033] In addition, to achieve the above object, the present application also proposes a storage medium, and the storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, it implements the steps of the risk control management method as described above.
[0034] In addition, to achieve the above object, the present application further provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the risk control management method described above.
[0035] In the technical solution proposed by the present application, the programmable network card is used to perform knock detection on the entrusted message to obtain a risk declaration order, and based on multicast encapsulation, the entrusted message and the return message are distributed to multiple risk control nodes. The risk declaration order is managed for risk control according to multiple risk control nodes and a preset risk control strategy. Through the processing ability of the programmable network card and the high efficiency of multicast encapsulation, the present application realizes efficient knock detection and risk control management of the entrusted message, can quickly identify potential risk entrustments, generate risk declaration orders accordingly, copy the entrusted message and the return message to multiple risk control nodes, ensuring the timeliness and accuracy of risk control. According to the preset risk control strategy, multiple risk control nodes jointly manage the risk declaration order, improving the transaction security and stability while reducing the information processing delay. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0037] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0038] Figure 1 It is a schematic flowchart provided for Embodiment 1 of the risk control management method of the present application;
[0039] Figure 2 It is a schematic diagram of traditional risk control management;
[0040] Figure 3 It is a schematic flowchart of the improved process of the risk control management method of the present application;
[0041] Figure 4 It is a schematic flowchart provided for Embodiment 2 of the risk control management method of the present application;
[0042] Figure 5 It is a schematic flowchart of the implementation process of the risk control management method of the present application;
[0043] Figure 6 It is a schematic diagram of the module structure of the risk control management device in the embodiment of the present application;
[0044] Figure 7It is a schematic diagram of the device structure of the hardware operating environment involved in the risk control management method in the embodiments of the present application.
[0045] The implementation, functional features and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. Specific embodiments
[0046] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0047] To better understand the technical solutions of the present application, the following will be described in detail with reference to the accompanying drawings of the specification and specific embodiments.
[0048] In the prior art, risk control is connected to the counter end via a message bus, and each entrustment needs to wait for confirmation by the risk control node. Due to the centralized deployment, the processing delay of risk control management is relatively large.
[0049] Therefore, in order to overcome the above defects, the present application provides a solution. Through the processing ability of the programmable network card and the high efficiency of multicast encapsulation, efficient knock detection of entrustment messages and risk control management are realized. Potential risky entrustments can be quickly identified, and risk declaration orders are generated accordingly. The risk declaration orders are copied to multiple risk control nodes to ensure the rapid dissemination of information. According to the preset risk control strategy, multiple risk control nodes collaboratively manage the risk declaration orders, improving the security and stability of transactions while reducing the information processing delay.
[0050] It should be noted that the execution subject of each embodiment of the present application can be a computing service system with data processing, network communication, and program running functions, such as an electronic system, a risk control management system, etc. that can implement the above functions. The following takes the risk control management system as an example (hereinafter referred to as the "system") to illustrate the following embodiments.
[0051] Based on this, the embodiments of the present application provide a risk control management method, referring to Figure 1 , Figure 1 It is a flowchart of the first embodiment of the risk control management method of the present application.
[0052] In this embodiment, the risk control management method includes steps S10 to S20:
[0053] Step S10, perform knock detection on the entrustment message through the programmable network card to obtain a risk declaration order, and distribute the entrustment message and the return message to multiple risk control nodes based on multicast encapsulation.
[0054] In the existing technical architecture, the risk control node and the counter node are connected through a message bus. This design does provide an effective way to transmit information in real time. However, this centralized deployment method has gradually exposed some problems in practical applications, especially in terms of processing efficiency and latency. Figure 2 As shown ( Figure 2 Schematic diagram of traditional risk control management). Before sending each order, the counter needs to wait for the calculation results returned by the risk control node to determine whether the order can be directly declared. Although this waiting mechanism ensures the compliance and security of the transaction, it also increases the processing delay of the system. Especially during peak trading periods, the calculation pressure of the risk control node increases, which may lead to a longer time to return the results, thus affecting the efficiency of the entire trading system. In addition, the risk control calculation node needs to fully obtain the in-transit orders and their transaction information in order to perform real-time risk calculation and assessment. This need for information acquisition also further increases the processing burden of the risk control node.
[0055] To this end, the risk control management method of this application improves the existing technology, such as Figure 3 As shown ( Figure 3 Schematic diagram of the improved process of the risk control management method for this application), when the trading gateway (Trade GateWay, TGW) receives the order and the transaction, it copies the original order message and the transaction message / return message, and uses the User Datagram Protocol (User Datagram Protocol, UDP) multicast encapsulation. The trading gateway that needs to receive the order message and the transaction message / return message joins the corresponding multicast group, and uses the multicast capability of the switch to realize the multicast replication of the message, and finally all the order and transaction information are received on all trading gateways. In order to improve efficiency, the programmable capability of the ultra-low latency computing development platform (Nano-latency DataProcessing Platform, NDPP) can be used, and the replication of the order message and the return message is realized by hardware. The increased latency compared to the L1 switch solution is controllable (related to the performance of the switch, and the switch with better performance is within 1 microsecond), the network configuration is simple, and the expansion is good, without changing the broker's network usage habits (the trading network still uses the L2 switch), and the flooding range of the transaction information can be controlled through different multicast groups.
[0056] The risk control management method of this application mainly detects matched orders and controls risk behaviors. When the risk control detects a risk declaration, there are two processing methods. One is to continue to change the risk declaration into an illegal order and transmit it to the exchange system, and the exchange front-end rejects the declaration. The other is to directly intercept the risk declaration and send a risk warning message to the trading desk at the same time. Among them, the risk control management system provides a configurable interface to select these two processing methods; the processing methods for different risk types can be configured separately. This application integrates the matched order detection logic into a programmable network card. By integrating the programmable network card to replace the network card on the existing trading link, it can solve the problems that the existing risk control management system cannot perform pre-control and has strong system coupling; in addition, this application is developed based on the programmable network card, effectively utilizing the characteristics of the hardware, and can greatly reduce the verification delay, thus also solving the problem of poor performance of the existing risk control management system. The risk control management method of this application can be applied to multiple financial trading and supervision scenarios, such as securities exchanges and financial markets, futures trading and derivatives markets, trading systems and supervision platforms of banks and investment companies, etc.
[0057] It should be noted that a programmable network card is a network interface card with flexible programming capabilities. It allows users to customize the processing flow of network data through programming. In a financial trading system, a programmable network card can efficiently process a large amount of trading data and provide low-latency and high-throughput network communication; matched orders, also known as opposite-side orders or collusion, usually refer to the behavior where both parties respectively play the roles of seller and buyer and conduct transactions according to the agreed trading varieties, prices, quantities and other conditions. In the field of financial risk control, matched order detection aims to identify and prevent such transactions that may be fraudulent or market-manipulative; multicast is a network communication method that allows data to be sent from a single sender to multiple receivers at the same time, and multicast encapsulation is to package the data to be sent according to the multicast protocol for transmission in the network; risk control nodes are key components in the risk control management system. They are responsible for receiving and processing risk declaration orders and conducting risk assessment and decision-making according to preset risk control strategies.
[0058] It should be understood that through the programmable network card, the system can capture and analyze trading data in real time, and use specific algorithms or models to detect matched order behaviors. When an abnormal trading pattern is detected, such as the trading prices, quantities, etc. of both parties being highly consistent and occurring frequently, the system will mark it as a risk declaration order. Then, multicast encapsulation can be used to copy the risk declaration order to multiple risk control nodes for parallel processing. By copying the entrustment message and the return message to multiple risk control nodes, the system can achieve redundant backup and load balancing, improving the reliability and stability of the system. At the same time, multiple risk control nodes can also work together to jointly address financial risks.
[0059] Step S20: Perform risk control management on the risk declaration order according to the multiple risk control nodes and the preset risk control strategies.
[0060] It can be understood that performing risk control management on the risk declaration order according to multiple risk control nodes and preset risk control strategies makes full use of the parallel processing ability and redundant backup characteristics of multiple risk control nodes. In risk control management, multiple risk control nodes first parse the received multicast data packets to extract the key information of the risk declaration order. Subsequently, these nodes conduct a detailed risk assessment on the order based on the preset risk control strategies. These strategies cover multiple aspects such as risk identification, quantitative assessment, and risk response. Based on the results of the risk assessment, the risk control nodes make decisions to determine whether further risk control measures need to be taken. If necessary, the nodes will execute corresponding operations according to the preset strategies, such as rejecting the transaction, restricting the transaction amount, or requiring additional verification, etc., to ensure the safe conduct of the transaction. Therefore, step S20 may include: the multiple risk control nodes parse the multicast data packets to extract the risk declaration order, and conduct a risk assessment on the risk declaration order to obtain an assessment result; according to the assessment result and the preset risk control strategies, perform risk control management on the risk declaration order.
[0061] Further, to adapt to new risk challenges, after step S20, it may further include: setting system parameters through a configuration register to obtain updated system parameters, and applying the updated system parameters to perform risk control management on the risk declaration order; and / or, initializing the system settings through a reset register to obtain initialized system settings, and applying the initialized system settings to perform risk control management on the risk declaration order.
[0062] It can be understood that the configuration and update of system parameters usually rely on the configuration register. Register configuration is a hardware configuration method that can control the behavior and functions of hardware devices by setting the values of registers. And the configuration register allows administrators or the system to automatically adjust system parameters, which may include transaction limits, risk thresholds, risk control strategy trigger conditions, etc. When system parameters need to be updated, the configuration register can be accessed through a specific interface or program to modify the parameters and obtain the updated system parameters. These updated parameters are then applied to the risk control management process to conduct a more accurate and effective assessment and management of the risk declaration order.
[0063] On the other hand, when the system needs to be reset or initialized, the reset register can be used to restore the system to its factory settings or preset initial state. Initializing through the reset register can ensure that the system starts running in a consistent and predictable manner, thereby reducing the risk of risk control failure caused by inconsistent system states. The initialized system settings are also applied to the risk control management process to ensure that risk declaration orders are evaluated and managed in a unified and standardized environment.
[0064] In this embodiment, through the processing ability of the programmable network card and the efficiency of multicast encapsulation, efficient contra trading detection and risk control management of entrusted messages are achieved. Potential risk entrustments can be quickly identified, and based on this, risk declaration orders are generated. The entrusted messages and return messages are copied to multiple risk control nodes, ensuring the timeliness and accuracy of risk control. According to the preset risk control strategy, multiple risk control nodes collaboratively manage the risk declaration orders, improving the security and stability of transactions while also reducing the information processing delay.
[0065] Based on the first embodiment of this application, in the second embodiment of this application, the same or similar content as in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 4 , and the step S10 may include steps S101 to S105:
[0066] Step S101, receiving the entrusted message sent by the client through the programmable network card, and judging whether it is necessary to perform contra trading risk control inspection on the entrusted message according to the security category of the entrusted message.
[0067] It should be understood that when the client submits entrusted messages (i.e., buy and sell instructions), these messages first enter the trading system through the programmable network card, and the system will make a preliminary judgment based on the security category information in the entrusted messages. Among them, the security category usually refers to different types of financial instruments such as stocks, bonds, and funds. Different security categories may face different market risks and fraud behavior patterns. Therefore, the system needs to conduct differentiated risk control management on them. For certain specific security categories, such as those with active high-frequency trading, large price fluctuations, or historical contra trading fraud behaviors, the system may automatically trigger the contra trading risk control inspection mechanism, which aims to conduct a detailed comparison and analysis of the entrusted messages through specific algorithms or models to identify possible contra trading behaviors.
[0068] During the knock - on risk control inspection process, the system comprehensively considers multiple factors, such as the account relationship between the trading parties, the deviation degree of the trading price from the market price, the trading frequency, etc. If the system detects an abnormal trading pattern, such as the trading parties frequently conducting transactions under similar conditions and there is a significant deviation between the trading price and the market price, then these order messages may be marked as risk declaration orders and trigger further risk control measures.
[0069] Step S102, if it is not necessary to conduct a knock - on risk control inspection on the order message, the order message is sent to the trading gateway through the first message transmission channel for the trading process.
[0070] It can be understood that if, after judgment, it is determined that the order message does not require a knock - on risk control inspection, then the system directly sends the order message to the trading gateway through the first message transmission channel to continue the subsequent trading process.
[0071] It should be noted that the first message transmission channel generally refers to an efficient and secure data transmission path that connects different components of the trading system, ensuring that data can be transmitted accurately and in a timely manner. On this channel, the order message is encapsulated into a specific data format and necessary metadata (such as timestamp, message type, etc.) is added so that the trading gateway can correctly parse and process it; the trading gateway is a key component in the financial trading system, which is responsible for receiving order messages from clients or the trading system and forwarding them to the exchange or clearing institution for matching or clearing.
[0072] After receiving the order message sent through the first message transmission channel, the trading gateway will perform a series of processes, such as verifying the legality of the message, checking the account balance, etc., to ensure the smooth progress of the transaction. If all checks pass, the trading gateway will send the order message to the exchange or clearing institution and wait for the matching or clearing result. At the same time, the trading gateway will also feedback the trading result to the trading system so that the system can update the account information, generate trading records, etc.
[0073] Step S103, if it is necessary to conduct a knock - on risk control inspection on the order message, conduct a knock - on comparison on the order message to obtain a comparison result, and judge whether it is necessary to modify the order message according to the comparison result.
[0074] It should be understood that when the entrusted message received by the programmable network card is determined to require knock-on risk control inspection, the system will conduct a knock-on comparison on the entrusted message that needs to be inspected for knock-on risk control. This step may involve comparing the current entrusted message with historical transaction data in the system, other simultaneously submitted entrusted messages, or preset knock-on behavior patterns. The purpose of the comparison is to identify any possible abnormal trading behaviors, especially those that may constitute knock-on fraud. The knock-on comparison can include multi-dimensional analysis, such as the account relationship between the trading parties, the deviation degree of the trading price from the market price, the consistency of the trading volume, the proximity of the trading time, etc. After the comparison is completed, the system will generate a comparison result, which may be a simple binary judgment (such as the existence / non-existence of knock-on behavior), or a complex report containing detailed comparison data and risk assessment.
[0075] Next, the system determines whether to modify the entrusted message based on the comparison result. If the comparison result shows signs of knock-on behavior or highly suspected knock-on behavior, the system may take a series of measures to prevent potential risks. These measures can include rejecting the entrustment: directly rejecting the current entrusted message and not allowing it to enter the trading process; modifying the entrustment: adjusting certain parameters in the entrusted message, such as the trading price, quantity, or trading time, to reduce the risk of knock-on behavior; delaying the processing: temporarily shelving the entrusted message and waiting for further manual review or verification of more trading data; triggering an alarm: sending an alarm to the system administrator or the risk control team to notify them of the potential knock-on risk for further investigation and handling.
[0076] It should be noted that when the system conducts knock-on risk control inspection on the entrusted message, it usually follows a series of preset rules and strategies. These rules and strategies can be formulated based on factors such as historical transaction data, market behavior patterns, and legal and regulatory requirements, and are continuously adjusted and optimized as the market environment changes. In addition, when the system conducts comparison and processing on the entrusted message, it will also fully consider the privacy protection and compliance requirements of the trading parties. Ensure that while effectively identifying knock-on behavior, the legitimate rights and interests of the trading parties are not violated.
[0077] Step S104, if it is necessary to modify the entrusted message, then modify the entrusted message according to the preset modification rules to obtain a risk declaration order, and prevent the subsequent trading process of the risk declaration order through a rejection message.
[0078] It is understandable that when it is determined that the entrusted message needs to be modified to prevent wash trading risks, the system will modify the entrusted message according to the preset modification rules. Among them, the preset modification rules may include adjusting key parameters such as transaction price, quantity, time, or restricting the accounts of both trading parties. For example, if the system detects that a certain transaction may constitute a wash trading behavior, it may automatically adjust the transaction price to make it closer to the market price, thereby reducing the possibility of wash trading. Or, the system may limit the trading frequency or trading amount of certain accounts within a certain period of time to prevent them from manipulating the market through high-frequency trading or large-scale trading.
[0079] After being modified, the original entrusted message will be transformed into a risk declaration order, which contains the modified transaction parameters and is marked as a high-risk or transaction requiring special attention. Subsequently, the system sends a rejection message to block the subsequent trading process of the risk declaration order. Among them, the rejection message is a clear signal indicating that the order has been rejected by the system due to potential risks, meaning that the order will not be sent to the trading gateway for matching and will not be included in the clearing and settlement processes of the trading system.
[0080] Step S105, distribute the entrusted message and the return message to multiple risk control nodes through multicast encapsulation and mirror replication.
[0081] It should be understood that when processing the risk declaration order, the entrusted message and the return message are quickly and securely distributed to multiple risk control nodes for parallel processing based on multicast encapsulation. Specifically, when the system modifies the entrusted message according to the preset modification rules to generate a risk declaration order, the system will copy all the entrusted messages and transaction messages, and obtain the multicast configuration information, which may include key parameters such as the multicast address, multicast port, and encapsulation protocol. Next, the entrusted message and the return message are encapsulated using the preset encapsulation protocol. During the encapsulation process, the entrusted message and the return message will be embedded in the payload of the multicast data packet, and at the same time, the system will add necessary multicast header information, such as the destination multicast address and the source IP address. In addition, to ensure the integrity and correctness of the data packet, the system will also add a checksum error detection mechanism.
[0082] Once the encapsulation is completed, according to the multicast configuration information, the multicast data packets are distributed to multiple risk control nodes. These risk control nodes are distributed in different geographical locations or network regions to ensure comprehensive monitoring and processing of risk declaration orders. By using multicast routing protocols (such as PIM-SM or PIM-DM), the system can efficiently manage the transmission paths of multicast data packets and ensure that the data packets can accurately reach the target nodes. When the risk control nodes receive the multicast data packets, they perform decapsulation and parsing on them, and then conduct risk assessment and judgment on the risk declaration orders according to the preset risk control rules. If there are potential risks in the risk declaration orders, the risk control nodes will generate detailed risk control reports and take corresponding measures to prevent further progress of the transaction, such as rejecting the order or freezing the account, etc.
[0083] In this embodiment, the programmable network card receives the entrustment message sent by the client, determines whether the entrustment message needs to be checked for matched order risk control according to the security category of the entrustment message. If no matched order risk control check is required, the entrustment message is sent to the trading gateway through the first message transmission channel for the trading process. If required, the entrustment message is subjected to matched order comparison to obtain a comparison result and determine whether the entrustment message needs to be modified. If so, it is modified according to the preset modification rules to obtain a risk declaration order, and the subsequent trading process of the risk declaration order is blocked through a rejection message. Based on multicast encapsulation, the entrustment message and the return message are copied to multiple risk control nodes. This embodiment can implement differentiated risk control strategies for different types of securities entrustments, reduce unnecessary checks, accelerate the trading process, accurately identify risks in a timely manner through precise comparison for entrustments that require matched order risk control, modify the entrustment content as needed, prevent potential risk transactions, and ensure security through the rejection mechanism. By using multicast encapsulation technology, the entrustment message and the return message are efficiently distributed to multiple risk control nodes to achieve parallel processing and rapid response.
[0084] As an implementation manner, after the above step S104 in this embodiment, it may further include: receiving the return message of the risk declaration order, obtaining the first return message and the second return message by mirroring and replicating the return message; updating the risk control storage table based on the first return message to obtain the updated risk control storage table, and sending the second return message to the counter switch through the preset communication method and the second message transmission channel based on the User Datagram Protocol multicast method; monitoring each entrustment message sent by the client based on the risk control storage table and the counter switch.
[0085] It is understandable that when a return message of a risk declaration order is received, mirror replication is first performed to generate two identical return messages: the first return message and the second return message. The first return message is used to update the risk control storage table, which is an important data structure in the system for recording and analyzing risk information. It contains various risk control rules and historical transaction data. By updating the risk control storage table, the system can reflect the current market risks and trading conditions in real time. Among them, mirror replication is a data backup technology that creates a copy of the data during data transmission to ensure the security and reliability of the data.
[0086] Meanwhile, using the User Datagram Protocol multicast method, the second return message is sent to the counter-end switch through a preset communication method and a second message transmission channel. The counter-end switch is the core device in the trading system for processing trading instructions and information. It can forward trading instructions to the exchange or clearing institution and receive trading results from these institutions. After completing the above steps, the system can monitor each entrustment message sent by the client based on the updated risk control storage table and the counter-end switch.
[0087] Specifically, the system will compare and analyze each entrustment message with the rules in the risk control storage table to determine whether there is a risk. If the system detects a risk in a certain entrustment message, it will immediately trigger the risk control mechanism, such as rejecting the entrustment message, freezing the relevant account, or issuing an alarm. At the same time, the relevant risk information will be recorded in the risk control storage table.
[0088] Furthermore, the risk control storage table includes an order table and a price level table. The steps of updating the risk control storage table based on the first return message to obtain the updated risk control storage table and sending the second return message to the counter-end switch through the User Datagram Protocol multicast method via a preset communication method and a second message transmission channel may include: storing the entrustment message and the first return message through the order table, and recording the market buy and sell price level information through the price level table; obtaining each entrustment message in real time, and updating and adjusting the order table and the price level table according to each entrustment message to obtain the updated risk control storage table; sending the second return message to the counter-end switch through the User Datagram Protocol multicast method via a preset communication method and a second message transmission channel.
[0089] The risk control storage table usually contains multiple sub-tables. Among them, the order table is mainly used to store commission messages and related return messages. Whenever the system receives a new commission message or return message, it will be recorded in the order table, enabling real-time tracking of the status and changes of each order. The price level table is used to record the bid and ask price level information of the market, which is usually updated and adjusted according to the real-time trading data of the market to ensure that it reflects the latest market conditions. When the system receives the return message of a risk declaration order, it will first make a mirror copy, which is respectively used to update the order table and send it to the counter-end switch. By storing the commission message and the first return message in the order table, at the same time, each commission message is obtained in real time, and the order table and the price level table are updated and adjusted according to these messages. After updating the risk control storage table, the second return message is sent to the counter-end switch using the User Datagram Protocol multicast method through the preset communication method and the second message transmission channel.
[0090] For ease of understanding, reference is made to Figure 5 for illustration, but it does not limit the risk control management method of this application. Figure 5 This is a schematic diagram of the implementation process of the risk control management method of this application. It should be noted that the programmable network card configuration can be: supporting 4 x 10G optical ports, corresponding to MAC0 - MAC3 (i.e., the message transmission channels) respectively, supporting a PCIE3x16 host interface. Among them, PCIE (Peripheral Component Interconnect Express) is a bus used to connect peripherals; the BASE DMA interface supports the complete TCP / IP protocol stack; USER DMA is a basic user interface, only used for software and hardware data interaction; DMA (Direct Memory Access) is direct memory access; BAR-1 (Base Address Register) is the address space where the network card is mapped to the upper computer through PCIE, used for interaction with software services; DDR (Double Data Rate Synchronous Dynamic Random Access Memory) is double data rate synchronous dynamic random access memory; BRAM (Block RAM) is the block RAM unit integrated inside the Field Programmable Gate Array (FPGA).
[0091] Based on the above content, the steps of risk control management can include:
[0092] 1. Client query / management message
[0093] Client management messages mainly involve request messages such as counter login and logout, as well as corresponding login and logout confirmation response messages. When the risk control management system receives such messages, it will directly send the messages to the trading gateway through the MAC1 interface without any processing, ensuring that the management messages can be transmitted quickly and accurately between the client and the trading gateway (i.e., TGW), thus guaranteeing the normal operation of the trading system and the smoothness of the management process.
[0094] 2. Client entrustment messages
[0095] The entrustment messages sent by the client will be judged according to the security category. For security categories that require knock - on risk control checks, the risk control management system will conduct knock - on comparison. If the comparison result shows no knock - on behavior, the original entrustment order will be directly sent to the trading gateway through MAC1 to continue the subsequent trading process. However, if there is a knock - on behavior, the risk control management system will take intervention measures. It can modify the original entrustment order to generate a rejection order in the exchange front - end link, thus preventing the occurrence of the knock - on behavior, and then send the modified order to the trading gateway through MAC1.
[0096] 3. Risk control rejection messages
[0097] For the entrustment messages that fail the knock - on risk control check, while sending them to the trading gateway through MAC1, the risk control management system will copy a copy of the message and transmit it to the risk control monitoring system for recording through USER DMA uplink. The USERDMA technology allows data to be directly transmitted between the device and the memory without passing through CPU processing, which can improve the data transmission efficiency and ensure that the risk control monitoring system can record the rejection messages in a timely and accurate manner.
[0098] 4. Return messages
[0099] The trading gateway is directly connected to BASE DMA, and the return communication link between the trading counter and the TGW remains unchanged, only performing mirror copy processing. When the trading gateway receives the return message from the exchange, it will mirror - copy the message. In this way, even if there are problems during data transmission, the data can be restored through the copy, guaranteeing the stable operation of the trading system.
[0100] 5. Exchange return message (mirror)
[0101] While the return message returned by the exchange is uploaded to the trading desk through BASE DMA, it will be mirrored. The copied message is divided into two parts: one part needs to be transmitted to the risk control module to update and maintain various storage tables, such as the order table, transaction table, etc., to ensure that the risk control management system can keep abreast of the latest trading situation in real time and provide accurate data basis for risk control; the other part is sent to the counter switch through port MAC2 in the form of UDP multicast, so that other trading counter machines can receive the confirmation response and transaction return message of this machine. This method realizes the sharing and synchronization of information, improves the cooperation efficiency between trading counters, and at the same time provides the risk monitoring program with the function of controlling the replication switch, which can flexibly turn on or off the replication and transmission of messages according to needs.
[0102] 6. Return Message (Multicast)
[0103] The return multicast message is sent by other trading counter machines to the switch, sharing various return messages such as declaration response, order cancellation response, and transaction return with all trading counters. These messages are only transmitted to the risk control module to update and maintain various storage tables, such as the order table, transaction table, etc. In this way, the risk control management system can obtain the trading information of other trading counters in real time, comprehensively grasp the operation status of the entire trading system, and provide more comprehensive and accurate data support for risk control and decision-making.
[0104] 7. Monitoring and Management Message
[0105] The risk monitoring program has the ability to read the information of the order table and price level table in memory. The order table stores the detailed information of all orders, such as order number, security code, entrusted quantity, entrusted price, etc.; the price level table records the market buy and sell price level information, such as the best bid price, best ask price, best bid quantity, best ask quantity, etc. By reading this information, the monitoring program can understand the execution situation of orders and the market buy and sell status in real time, providing basic data for risk monitoring and analysis. At the same time, the risk monitoring program can also configure the information of the order table and price level table, update and adjust these data according to actual needs to meet the requirements of risk control and management.
[0106] 8. Register Configuration
[0107] The risk control monitoring program controls the risk control anti-spoofing system of the ultra-low latency computing development platform through register configuration. In the risk control anti-spoofing system of the ultra-low latency computing development platform, register configuration can implement functions such as system configuration and reset. For example, system parameters such as risk control thresholds and monitoring frequencies can be set by configuring registers; the system can also be restarted by resetting the registers to restore it to its initial state, thus ensuring the normal operation and stable working of the system. This method provides flexible control means for the risk control monitoring program, enabling rapid configuration and adjustment of the risk control management system according to actual needs, and improving the system's response speed and adaptability.
[0108] In this way, the risk control management method of this application can compress the risk control calculation latency to within 200 nanoseconds, and the average penetration latency is about 150 nanoseconds, enabling the risk control management system to quickly respond to entrustment requests and perform anti-spoofing verification in a timely manner. The low-latency risk control verification ability enables the trading system to process trading requests faster, providing a faster trading experience for investors. The risk control management method of this application supports multiple deployment scenarios, can be deployed on the trading system side or the exchange gateway side, also supports multiple sets of systems to be synchronously accessed through the mirror interface, supports multiple business models such as proprietary trading, brokerage, institutional, and asset management, and can adapt to all counters (central trading counter, ultra-fast trading counter, QFII special counter, bond settlement counter, DMA counter, investment trading system, etc.), supports primary and standby dual network card deployment, and realizes high availability through the primary and standby mode.
[0109] In this embodiment, after receiving the risk declaration order return message, two copies of the return message are obtained through mirror replication. One copy updates the risk control storage table to support decision-making, and the other copy is quickly multicast to the counter end. By combining the risk control storage table and the counter end information, the entrustment message is monitored in real time to ensure the safety and compliance of transactions and improve the risk control efficiency. The entrustment and the first return message are stored in the order table, and the market buying and selling information is recorded in the price level table. The two tables are updated in real time to obtain the risk control storage table, and then through multicast, the second return message is quickly transmitted to the counter end switch through the preset channel and the second message path to ensure real-time synchronization of trading data and rapid risk control response.
[0110] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the risk control management method of this application. Based on this technical concept, more forms of simple transformations are within the protection scope of this application.
[0111] This application also provides a risk control management device. Please refer to Figure 6 and the risk control management device includes:
[0112] A data detection module 10, configured to perform spoofing detection on the entrustment message through a programmable network card to obtain a risk declaration order, and based on multicast encapsulation, distribute the entrustment message and the return message to multiple risk control nodes;
[0113] The risk control management module 20 is used to perform risk control management on the risk declaration order according to the multiple risk control nodes and the preset risk control strategy.
[0114] The risk control management device provided by this application adopts the risk control management method in the above embodiment, and can solve the technical problem of large processing delay caused by the centralized deployment method in the traditional risk control management solution. Compared with the prior art, the beneficial effects of the risk control management device provided by this application are the same as those of the risk control management method provided by the above embodiment, and other technical features in the risk control management device are the same as the features disclosed in the method of the above embodiment, which will not be elaborated here.
[0115] This application provides a risk control management device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the risk control management method in the first embodiment above.
[0116] Next, refer to Figure 7 , which shows a schematic structural diagram of a risk control management device suitable for implementing the embodiments of this application. The risk control management device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Desctions), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The risk control management device shown is only an example and should not impose any limitations on the functions and usage scopes of the embodiments of this application.
[0117] As Figure 7As shown, the risk control management device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the risk control management device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the risk control management device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a risk control management device with various systems, it should be understood that it is not required to implement or have all the shown systems. Instead, more or fewer systems may be implemented or had.
[0118] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device, or installed from the storage device 1003, or installed from the ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are executed.
[0119] The risk control management device provided by the present application adopts the risk control management method in the above embodiment, and can solve the technical problem of large processing delay caused by the centralized deployment method in the traditional risk control management solution. Compared with the prior art, the beneficial effects of the risk control management device provided by the present application are the same as those of the risk control management method provided by the above embodiment, and other technical features in the risk control management device are the same as those disclosed in the method of the previous embodiment, and will not be elaborated here.
[0120] It should be understood that each part disclosed in this application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.
[0121] As described above, the above are only specific embodiments of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
[0122] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the risk control management method in the above embodiments.
[0123] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems, or devices, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM) or a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or combined with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.
[0124] The above computer-readable storage medium can be included in the risk control management device; it can also exist separately without being assembled into the risk control management device.
[0125] The above computer-readable storage medium carries one or more programs, which when executed by the risk control management device, cause the risk control management device to: perform knock detection on the entrustment message through a programmable network card, obtain a risk declaration order, and based on multicast encapsulation, distribute the entrustment message and the return message to multiple risk control nodes, and perform risk control management on the risk declaration order according to the multiple risk control nodes and the preset risk control strategy.
[0126] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0127] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and this module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0128] The modules involved in the embodiments described in this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation on the unit itself in some cases.
[0129] The readable storage medium provided by this application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the above risk control management method, which can solve the technical problem of large processing delays caused by the centralized deployment method in traditional risk control management solutions. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by this application are the same as those of the risk control management method provided by the above embodiments, and will not be elaborated here.
[0130] This application also provides a computer program product, including a computer program, which implements the steps of the risk control management method as described above when executed by a processor.
[0131] The computer program product provided by this application can solve the technical problem of large processing delays caused by the centralized deployment method in traditional risk control management solutions. Compared with the prior art, the beneficial effects of the computer program product provided by this application are the same as those of the risk control management method provided by the above embodiments, and will not be elaborated here.
[0132] The above are only some embodiments of this application, and do not limit the patent scope of this application. Any equivalent structural transformation made by using the content of the specification and drawings of this application under the technical concept of this application, or direct / indirect application in other related technical fields, is included in the patent protection scope of this application.
Claims
1. A risk control management method, characterized in that: The method comprises the following steps: Through the programmable network card, the entrustment message is tested against each other to obtain the risk declaration order, and the entrustment message and the return message are distributed to multiple risk control nodes based on multicast encapsulation; The risk reporting order is managed through risk control according to the multiple risk control nodes and preset risk control strategies.
2. The risk control management method according to claim 1, characterized in that: The step of performing cross-trading detection on the entrustment message through the programmable network card to obtain the risk declaration order, and distributing the entrustment message and the return message to multiple risk control nodes based on multicast encapsulation includes: Receiving the entrustment message sent by the client through the programmable network card, and judging whether it is necessary to perform a knock-on risk control check on the entrustment message according to the securities category of the entrustment message; If there is no need to perform a knock-on risk control check on the entrustment message, the entrustment message is sent to the transaction gateway through the first message transmission channel to carry out the transaction process; If it is necessary to conduct a knock-to-match risk control check on the entrustment message, then a knock-to-match comparison is performed on the entrustment message to obtain a comparison result, and it is determined whether the entrustment message needs to be modified according to the comparison result; If the entrustment message needs to be modified, the entrustment message is modified according to the preset modification rules to obtain the risk declaration order, and the subsequent transaction process of the risk declaration order is blocked through a rejection message; The delegation message and the return message are distributed to multiple risk control nodes through multicast encapsulation and mirror replication.
3. The risk control management method according to claim 2, characterized in that: After the step of modifying the entrustment message according to a preset modification rule if the entrustment message needs to be modified, obtaining a risk declaration order, and blocking subsequent transaction processes of the risk declaration order through a rejection message, the method further includes: Receiving a feedback message of the risk declaration order, and obtaining a first feedback message and a second feedback message by mirroring the feedback message; Based on the first report message, the risk control storage table is updated to obtain an updated risk control storage table, and based on the user datagram protocol multicast mode, the second report message is sent to the counter end switch through the preset communication mode and the second message transmission channel; Based on the risk control storage table and the counter-side switch, each delegation message sent by the client is monitored.
4. The risk control management method according to claim 3, characterized in that: The risk control storage table includes an order table and a gear table, and the step of updating the risk control storage table based on the first report message to obtain the updated risk control storage table, and sending the second report message to the counter-end switch through a preset communication method and a second message transmission channel based on a user datagram protocol multicast method includes: The entrustment message and the first return message are stored in an order table, and the market buying and selling position information is recorded in a position table; Acquire each entrustment message in real time, and update and adjust the order table and the gear table according to each entrustment message to obtain an updated risk control storage table; Based on the user datagram protocol multicast mode, the second report message is sent to the counter end switch through a preset communication mode and a second message transmission channel.
5. The risk control management method according to any one of claims 1 to 4, characterized in that: The step of performing risk control management on the risk declaration order according to the multiple risk control nodes and the preset risk control strategy includes: The multiple risk control nodes extract the risk declaration order by parsing the multicast data packet, and perform risk assessment on the risk declaration order to obtain an assessment result; Perform risk control management on the risk reporting order based on the assessment results and preset risk control strategies.
6. The risk control management method according to any one of claims 1 to 4, characterized in that: After the step of performing risk control management on the risk declaration order according to the multiple risk control nodes and the preset risk control strategy, the method further includes: Setting system parameters by configuring registers to obtain updated system parameters, and applying the updated system parameters to perform risk control management on the risk declaration order; and / or, The system settings are initialized by resetting the register to obtain the initialized system settings, and the initialized system settings are applied to perform risk control management on the risk declaration order.
7. A risk control management device, characterized in that: The risk control management device comprises: The data detection module is used to perform cross-trading detection on the entrustment message through the programmable network card, obtain the risk declaration order, and distribute the entrustment message and return message to multiple risk control nodes based on multicast encapsulation; The risk control management module is used to perform risk control management on the risk reporting order according to the multiple risk control nodes and preset risk control strategies.
8. A risk control management device, characterized in that: The risk control management device includes: a memory, a processor, and a risk control management program stored in the memory and executable on the processor. When the risk control management program is executed by the processor, the risk control management method according to any one of claims 1 to 6 is implemented.
9. A storage medium, characterized in that: The storage medium stores a risk control management program, and when the risk control management program is executed by the processor, the risk control management method according to any one of claims 1 to 6 is implemented.
10. A computer program product, characterized in that The computer program product includes a risk control management program, and when the risk control management program is executed by a processor, the risk control management method according to any one of claims 1 to 6 is implemented.