Financial data security verification system
Through the multi-dimensional verification model and dynamic adjustment mechanism, the problem of insufficient identification and response of traditional financial data verification systems in complex trading modes is solved, accurate identification and refined management of transaction risks is achieved, and the security and efficiency of the system are improved.
Patent Information
- Application Number
- CN202510779589.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-06-12
AI Technical Summary
When facing complex trading models, traditional financial data verification systems are difficult to identify abnormal transactions, lack multi-dimensional analysis capabilities, and cannot dynamically optimize verification strategies, resulting in misjudgment or misjudgment, and lack flexibility in handling unstructured data and different trading scenarios, and cannot respond to risk events in a refined manner.
Using a multi-dimensional verification model, abnormal operation characteristics are extracted through the feature analysis module, combined with the pattern recognition module, the trading nodes are decomposed, the credibility evaluation value is calculated, the verification indicators are dynamically adjusted, and a three-level response mechanism is established to achieve refined management of transaction risks.
It realizes accurate identification and dynamic response to transaction risks, improves the accuracy and efficiency of verification, avoids misjudgment and misjudgment, and ensures the security of user assets and the convenience of transactions.
Smart Images

Figure CN120297983A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of financial data security, and specifically to a financial data security verification system. Background Art
[0002] In the context of the rapid development of the digital economy, the security of financial data and the reliability of transactions have become the core concerns of enterprises and individuals. With the continuous innovation of fintech, financial transaction scenarios have become increasingly complex, and transaction channels show a trend of diversification, such as online payment, cross-border transactions, electronic bills, etc. At the same time, account types have also become more diverse, including corporate public accounts, personal savings accounts, credit card accounts, etc. These changes have brought increasingly severe security challenges while enhancing transaction convenience, and traditional financial data verification methods have gradually exposed many defects.
[0003] Most traditional verification systems are based on single-dimensional rule settings. For example, they only make risk judgments based on transaction amount thresholds or historical transaction frequencies, lacking multi-dimensional and three-dimensional analysis of transaction behaviors. Such a simple rule engine is difficult to effectively identify complex abnormal transaction patterns, such as new types of financial crimes like cumulative cash withdrawals through high-frequency small transfers and money laundering through cross-account related transactions. In addition, the parameter adjustment mechanism of traditional systems is rigid and unable to dynamically optimize verification strategies according to real-time transaction data, resulting in a lag in response to emerging risks and prone to misjudgment or missed judgment. For example, when a new type of fraud transaction method appears, the traditional system may not be able to effectively intercept it due to failure to update verification indicators in time, posing a threat to the asset security of users.
[0004] In terms of transaction link analysis, traditional systems lack in-depth exploration of the relevance between transaction nodes. They only view each transaction in isolation, ignoring information such as temporal correlation, amount correlation, and account correlation between transactions, and it is difficult to discover risk chains hidden in complex transaction networks. For example, multiple seemingly independent low-frequency transactions may form an abnormal fund flow link through related transaction factors. Due to the inability of traditional systems to identify this relevance, such risk transactions are easily overlooked.
[0005] At the same time, with the increase in unstructured transaction data, such as natural language instructions, graphical transaction vouchers, etc., traditional systems have problems with insufficient parsing capabilities when processing these data, unable to effectively extract key operation elements, resulting in impacts on the accuracy and efficiency of the verification process. In addition, traditional systems lack flexible strategy adaptation capabilities when dealing with different transaction scenarios and are unable to dynamically adjust verification strategies according to changes in the transaction environment (such as operating devices, network IP addresses, etc.), making it difficult to meet diverse security requirements.
[0006] In addition, existing financial data verification systems also have deficiencies in the risk response mechanism. For risk events of different levels, there is a lack of refined hierarchical response strategies, and often a "one-size-fits-all" approach is adopted. Either all are released, leading to potential risks, or all are intercepted, affecting the normal transaction efficiency. For example, for minor abnormal transactions, the account may be directly frozen, causing inconvenience to users, while for serious risk transactions, insufficiently strict measures may be taken, resulting in the expansion of risks. Summary of the Invention
[0007] The purpose of the present invention is to provide a financial data security verification system to solve the problems raised in the above background technology.
[0008] To achieve the above purpose, the present invention provides the following technical solution: A financial data security verification system, the method includes: A data receiving module, used to obtain a financial transaction data set to be verified, and construct a multi-dimensional verification model according to the account type and transaction channel; A feature analysis module, used to extract abnormal operation features in historical transaction records, and generate a transaction risk feature table in combination with the multi-dimensional verification model, where the transaction risk feature table includes verification indicators and authorization parameter correction values; A pattern recognition module, used to decompose the historical transaction records, identify high-frequency transaction nodes and low-frequency transaction nodes, and divide associated transaction factors and independent transaction factors; An index calculation module, used to generate a credibility evaluation value of the transaction link based on the associated transaction factors and independent transaction factors; A parameter adjustment module, used to determine the dynamic adjustment gradient of the transaction risk feature table according to the credibility evaluation value, and update the transaction risk feature table based on the dynamic adjustment gradient to form an optimized transaction risk feature table; A verification execution module, used to trigger the blocking or release operation of the account transaction permission according to the optimized transaction risk feature table.
[0009] Preferably, the system further includes: A transaction comparison unit, used to match the current transaction request with the operation type of the historical transaction records to determine whether they belong to the same-source transaction; A time window acquisition unit, used to record the start timestamp of the current request and the completion timestamp of the previous transaction if it is determined to be the same-source transaction; A frequency analysis unit, used to calculate the time window overlap degree of the two transactions and compare it with a preset frequency threshold to determine whether to allow the execution of the current transaction; A transaction interception unit, used to terminate the transaction execution and generate a high-frequency operation log if the time window overlap degree exceeds the preset frequency threshold; The permission determination unit is used to allocate an independent verification channel to process the current transaction request if the operation type matching results are inconsistent.
[0010] Preferably, the pattern recognition module includes: Arrange all transaction nodes in a transaction time series to generate an analysis link, randomly select adjacent transaction node pairs, obtain the corresponding transaction amount readings and subsequent transaction amount readings, and calculate the absolute value of the change rate of the amount readings; Determine the amount peak and benchmark value in the full transaction data, and calculate the overall amount fluctuation range; Obtain the ratio of the absolute value of the change rate to the fluctuation range; Calculate the transaction correlation deviation amount between the transaction node pairs; Identify the maximum correlation degree and minimum correlation degree among all nodes, and calculate the global correlation degree difference range; Obtain the proportional value of the transaction correlation deviation amount to the difference range; Normalize the amount ratio and the correlation degree ratio to obtain a real-time credibility parameter; Traverse the remaining transaction node pairs to generate a set of associated transaction factors, and calculate the mean of all real-time credibility parameters as an independent transaction factor.
[0011] Preferably, the index calculation module includes: Set the safety threshold and risk threshold of the associated transaction factor; Screen the compliant transaction set according to the safety threshold, and screen the suspicious transaction set according to the risk threshold; Calculate the positive deviation value of the compliant transaction from the safety threshold, and arrange them in ascending order of the deviation value to form a safety sorting queue; Calculate the negative deviation value of the suspicious transaction from the risk threshold, and arrange them in descending order of the deviation value to form a risk sorting queue; Match the elements of the safety queue and the risk queue item by item to form a credibility pair group, and calculate the credibility evaluation value based on all credibility pair groups.
[0012] Preferably, the index calculation module further includes: Count the effective number of the credibility pair groups, and calculate the absolute value of the difference between the safety element and the risk element in each group respectively; Identify the median value and extreme difference value among all absolute difference values, and calculate the distribution balance parameter of all absolute difference values; Calculate the credibility evaluation value according to the median value, extreme difference value and distribution balance parameter.
[0013] Preferably, the parameter adjustment module includes: Set the primary credibility threshold and the advanced credibility threshold; Configure a basic adjustment coefficient, an intermediate adjustment coefficient, and an enhancement adjustment coefficient; When the credibility evaluation value is higher than the high-level credibility threshold, the basic adjustment coefficient is enabled; when the credibility evaluation value is between the primary and high-level credibility thresholds, the intermediate adjustment coefficient is enabled; when the credibility evaluation value is lower than the primary credibility threshold, the enhancement adjustment coefficient is enabled.
[0014] Preferably, the parameter adjustment module further includes: Multiply the dynamic adjustment gradient by the authorized parameter correction value to generate the final authorized parameter; Match the preset permission mapping rule to determine the expected verification index corresponding to the final authorized parameter; Integrate the final authorized parameter and the expected verification index to construct the optimized transaction risk feature table.
[0015] Preferably, the data receiving module further includes: Integrate transaction flow data, account attribute data, and operation environment data in real time to construct a transaction behavior feature map; Calculate the abnormal boundary of transaction behavior according to the transaction behavior feature map, and activate the secondary verification process when it is detected that the transaction feature exceeds the security boundary; Generate a risk / compliance matrix under different transaction scenarios through association rule mining, and generate an optimal verification strategy set.
[0016] Preferably, the system divides a three-level response mechanism according to the degree of abnormal boundary breakthrough: the first level triggers the adjustment of the account transaction limit, the second level starts cross-channel transaction verification, and the third level freezes the account fund transfer and sends an artificial review instruction.
[0017] Preferably, the transaction comparison unit includes: parsing the key operation elements in the unstructured transaction instruction through text feature extraction technology, storing the vectorized templates of historical transaction conflict events and their handling strategies, and when a transaction conflict is detected, retrieving the adapted handling solution from the strategy library through pattern matching, and generating a verification priority adjustment instruction.
[0018] Compared with the prior art, the beneficial effects of the present invention are: At the data processing level, the data receiving module constructs a transaction behavior feature map by integrating transaction flow, account attributes, and operation environment data, and can capture the abnormal boundary of transaction behavior in real time. This multi-dimensional data fusion method breaks through the limitations of traditional single-dimensional verification, enabling the system to comprehensively judge transaction risks from multiple dimensions such as transaction amount, time, channel, and device. For example, when it is detected that the device IP of a certain transaction does not match the usual login location of the account, and at the same time the transaction amount exceeds the historical average level, the system will activate the secondary verification process to effectively prevent risks caused by device theft or account information leakage.
[0019] The combination of the feature analysis module and the pattern recognition module realizes the in-depth mining of historical transaction data. By extracting abnormal operation features and identifying high-frequency / low-frequency transaction nodes, the system can accurately distinguish associated transaction factors from independent transaction factors, and then generate a transaction risk feature table. This ability to analyze transaction relevance enables the system to discover risk links that are difficult to detect by traditional methods, such as accumulating and transferring funds through high-frequency small transactions or using low-frequency transactions for money laundering. For example, the system can identify seemingly independent but actually associated abnormal transaction combinations by analyzing the amount change rate and correlation deviation amount between adjacent nodes in the transaction time series, and issue early warnings of potential risks in a timely manner.
[0020] The index calculation module classifies, screens, and sorts transaction data by setting safety thresholds and risk thresholds to form a credibility evaluation value. This quantitative evaluation method enables the system to objectively and accurately judge the risk level of transactions, avoiding the subjectivity and arbitrariness of human judgment. At the same time, by statistically calculating the absolute value of the difference between credibility pairs and calculating the distribution balance parameter, the system can further refine the evaluation dimension and improve the reliability of the evaluation results. For example, the smaller the positive deviation value of a compliant transaction from the safety threshold, the safer the transaction, and the system can give priority to releasing it; while the larger the negative deviation value of a suspicious transaction from the risk threshold, the higher the risk, and the system will take more stringent verification measures.
[0021] The dynamic adjustment mechanism of the parameter adjustment module is a major innovation of the present invention. By setting different levels of credibility thresholds and configuring corresponding adjustment coefficients, the system can automatically adjust the verification indicators and authorization parameters of the transaction risk feature table according to the credibility evaluation value. This dynamic optimization ability enables the system to adapt to changes in the transaction environment in real time and respond to emerging risks in a timely manner. For example, when the credibility evaluation value is higher than the high-level credibility threshold, it indicates that the current transaction environment is safe, and the system will enable the basic adjustment coefficient, appropriately relax the verification conditions, and improve transaction efficiency; while when the credibility evaluation value is lower than the primary credibility threshold, the system will enable the enhanced adjustment coefficient, tighten the verification indicators, and strengthen risk prevention and control.
[0022] New modules such as the transaction comparison unit and the time window acquisition unit further improve the system's risk prevention and control capabilities. The transaction comparison unit analyzes unstructured transaction instructions through text feature extraction technology, can effectively process complex data such as natural language instructions, and improves the accuracy of verification. The time window acquisition unit and the frequency analysis unit can identify high-frequency operation anomalies, such as the behavior of initiating the same-source transaction multiple times within a short period of time, by calculating the overlap degree of transaction time windows, intercept possible malicious operations in a timely manner and generate logs, providing a basis for subsequent audits. The authority determination unit ensures special processing of transactions with mismatched operation types by allocating independent verification channels, avoiding risk omissions.
[0023] The establishment of the three - level response mechanism realizes the refined management of risk events. According to the degree of abnormal boundary breakthrough, the system triggers different - level response measures such as adjusting the account transaction limit, cross - channel transaction verification, freezing the account fund transfer, and sending an artificial review instruction. This can not only effectively prevent risks but also avoid the impact of excessive interception on normal transactions. For example, for minor abnormal transactions, the system only adjusts the transaction limit to remind users to pay attention to account security; for serious risk transactions, it immediately freezes the fund transfer and initiates an artificial review to maximize the protection of user asset security. Brief Description of the Drawings
[0024] Figure 1 It is the working principle diagram of the financial data security verification system described in the present invention; Figure 2 It is the design diagram of transaction comparison and frequency control; Figure 3 It is the design diagram of the processing flow of the pattern recognition module; Figure 4 It is the design diagram of the processing flow of the index calculation module; Figure 5 It is the functional diagram of the expansion of the data receiving module. Detailed Embodiment
[0025] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0026] Please refer to Figures 1-5 , a financial data security verification system involved in the present invention, and the specific implementation steps are as follows: The system includes a data receiving module, a feature analysis module, a pattern recognition module, an index calculation module, a parameter adjustment module, and a verification execution module. Each module collaborates to achieve the security verification of financial data.
[0027] Data Receiving Module: Obtain the financial transaction data set to be verified, and construct a multi-dimensional verification model according to the account type (such as enterprise account, personal account) and transaction channel (such as online banking, mobile payment, counter). For example, different verification dimension weights are set for the large transfer scenario of enterprise accounts and the small and high-frequency consumption scenario of personal accounts. This module integrates real-time transaction flow data, account attribute data (such as account balance, transaction history frequency), and operating environment data (such as IP address, device model) to construct a transaction behavior feature map, calculates the abnormal boundary of transaction behavior through the map, and activates the secondary verification process when it detects that the transaction features exceed the security boundary. At the same time, a risk / compliance matrix under different transaction scenarios is generated through association rule mining to form an optimal verification strategy set.
[0028] Feature Analysis Module: Extract abnormal operation features from historical transaction records, such as large transfers during non-working hours, high-frequency transactions after logging in from an IP address in a different location, etc. Combine with the multi-dimensional verification model to generate a transaction risk feature table, which contains verification indicators (such as transaction amount threshold, time interval threshold) and authorization parameter correction values (such as permission level adjustment coefficient). For example, if historical data shows that the fraud rate is relatively high in large transfers during non-working hours for a certain type of account, then reduce the authorization parameter correction value during this period in the transaction risk feature table and increase the strictness of the verification indicators.
[0029] Pattern Recognition Module: Decompose historical transaction records, arrange all transaction nodes in the transaction time series to generate an analysis link. Randomly select adjacent transaction node pairs, obtain the corresponding transaction amount readings and subsequent transaction amount readings, and calculate the absolute value of the change rate of the amount readings; determine the amount peak and benchmark value in the full transaction data, and calculate the overall amount fluctuation range; obtain the ratio of the absolute value of the change rate to the fluctuation range. At the same time, calculate the transaction correlation deviation amount between transaction node pairs, identify the maximum correlation and minimum correlation in all nodes, obtain the global correlation difference range, and then obtain the ratio of the transaction correlation deviation amount to the difference range. Normalize the amount ratio and correlation ratio to obtain a real-time credibility parameter, traverse the remaining transaction node pairs to generate a set of associated transaction factors, and calculate the mean of all real-time credibility parameters as an independent transaction factor. Through the above process, identify high-frequency transaction nodes (such as intensive transaction nodes at fixed times of each day) and low-frequency transaction nodes (such as quarterly large transfer nodes), and divide associated transaction factors (such as node pairs with relatively small continuous transaction amount fluctuations) and independent transaction factors (such as isolated abnormal amount transaction nodes).
[0030] Index calculation module: Generate a credibility evaluation value for the transaction link based on the related transaction factor and the independent transaction factor. Set the safety threshold and risk threshold for the related transaction factor, screen the compliant transaction set according to the safety threshold, and screen the suspicious transaction set according to the risk threshold. Calculate the positive deviation value of the compliant transaction from the safety threshold, and form a safety sorting queue in ascending order of the deviation value; calculate the negative deviation value of the suspicious transaction from the risk threshold, and form a risk sorting queue in descending order of the deviation value. Match the elements of the safety queue and the risk queue item by item to form a credibility pair group, count the effective number of the credibility pair group, calculate the absolute value of the difference between the safety element and the risk element in each group respectively, identify the median value and the extreme difference value among all the absolute values of the differences, calculate the distribution balance parameter of all the absolute values of the differences, and finally calculate the credibility evaluation value based on the median value, the extreme difference value, the distribution balance parameter and the credibility pair group.
[0031] Parameter adjustment module: Determine the dynamic adjustment gradient of the transaction risk characteristic table according to the credibility evaluation value. Set the primary credibility threshold and the advanced credibility threshold, and configure the basic adjustment coefficient, the intermediate adjustment coefficient and the enhanced adjustment coefficient. When the credibility evaluation value is higher than the advanced credibility threshold, the basic adjustment coefficient is enabled; when it is between the primary and advanced credibility thresholds, the intermediate adjustment coefficient is enabled; when it is lower than the primary credibility threshold, the enhanced adjustment coefficient is enabled. Multiply the dynamic adjustment gradient by the authorized parameter correction value to generate the final authorized parameter, match the preset permission mapping rule to determine the expected verification index corresponding to the final authorized parameter, and integrate the final authorized parameter and the expected verification index to construct an optimized transaction risk characteristic table.
[0032] Verification execution module: Trigger the blocking or release operation of the account transaction permission according to the optimized transaction risk characteristic table. For example, if the optimized verification index shows that the risk level of a certain transaction exceeds the preset threshold, block the transaction and generate a risk prompt; if the risk level is within the safe range, release the transaction and record the verification result.
[0033] The present invention will be further described below in conjunction with Embodiments 1 to 5: Embodiment 1:
[0034] The specific implementation manner of the system in this embodiment involves the collaborative working mechanism of the transaction comparison unit, the time window acquisition unit, the frequency analysis unit, the transaction interception unit and the permission determination unit to achieve refined verification of transaction operations.
[0035] The transaction comparison unit analyzes the key operation elements in the unstructured transaction instructions through text feature extraction technology. In practical applications, unstructured transaction instructions may exist in various forms, such as the remarks information filled in by users during transfer, the text content after voice instruction conversion, etc. The system uses natural language processing technology to perform operations such as word segmentation, part-of-speech tagging, and named entity recognition on these texts, and extracts key information such as transaction amount, payee account, and operation type. For example, for the remarks information "Pay the goods payment of last month to XX Company", the system identifies "XX Company" as the payee through named entity recognition technology, and determines "Pay" as the operation type through keyword matching.
[0036] Meanwhile, the system stores the vectorized templates of historical transaction conflict events and their handling strategies. Historical transaction conflict events include duplicate payments, transactions initiated after abnormal account logins, etc. Each event and its handling strategy are converted into vector form and stored in the database for quick retrieval and matching. When receiving a new transaction request, the system first matches the current transaction request with the historical transaction records in terms of operation type to determine whether they belong to the same-source transactions. The matching of operation types is based on a predefined operation type classification system, such as transfer, payment, query, etc. The system extracts the operation type keywords in the current transaction request and the historical transaction records, calculates the semantic similarity, and if the similarity exceeds the preset threshold, it is determined to be the same-source transaction.
[0037] If it is determined to be the same-source transaction, the time window acquisition unit starts to work. This unit records the start timestamp of the current request and the completion timestamp of the previous transaction. The recording of timestamps uses a high-precision clock to ensure the accuracy of time recording. For example, the system will record the exact time when the current transaction request arrives at the server, as well as the time when the previous same-source transaction is completed, accurate to the millisecond level.
[0038] The frequency analysis unit calculates the time window overlap degree of the two transactions based on the timestamps recorded by the time window acquisition unit. The calculation of the time window overlap degree takes into account the duration and interval time of the transactions. For example, if there is partial overlap between the two transactions on the time axis, the system will calculate the proportion of the overlapping duration in the total transaction duration as the time window overlap degree. At the same time, the system compares the preset frequency threshold, which is dynamically adjusted according to different account types and transaction scenarios. For example, the upper limit of the number of daily similar transactions for enterprise accounts may be set to 100 times, while that for personal accounts may be 20 times. The system will regularly adjust these thresholds based on historical transaction data and risk assessment results.
[0039] If the overlap degree of the time window exceeds the preset frequency threshold, the transaction interception unit immediately terminates the transaction execution and generates a high-frequency operation log. The high-frequency operation log contains detailed information about the transaction request, such as transaction time, transaction amount, operation type, initiating device, etc. The log is stored in an encrypted manner to ensure the security and integrity of the data. At the same time, the system marks the high-frequency operation event as a suspicious transaction and sends it to the risk monitoring center for further analysis.
[0040] If the operation type matching results are inconsistent, the permission determination unit allocates an independent verification channel to process the current transaction request. The independent verification channel adopts additional verification methods, such as dynamic verification codes, biometric identification, etc. For example, for high-risk transaction operations, the system will require the user to enter a mobile dynamic verification code for verification; for transactions involving large amounts of funds, the system may require the user to perform fingerprint recognition or facial recognition. These additional verification methods enhance the security of transactions and effectively prevent unauthorized transaction operations.
[0041] When processing unstructured transaction instructions, the system validates the effectiveness of the key operation elements parsed out. For example, for the payee account extracted, the system will verify whether its format conforms to the standard format of bank accounts and whether there are abnormal differences from the payee accounts in historical transactions. If any abnormalities are found, the system will trigger a further verification process, such as asking the user to confirm the payee information.
[0042] The system also regularly updates and maintains the vectorized templates of historical transaction conflict events. As new transaction conflict events occur, the system adds these events and their disposal strategies to the template library and optimizes and adjusts the existing templates. At the same time, the system classifies and manages the template library, dividing it according to dimensions such as transaction type, risk level, etc., for quick retrieval and matching.
[0043] When the time window collection unit is working, the system considers the impact of factors such as network latency on the timestamp record. To ensure the accuracy of the timestamp, the system uses the Network Time Protocol (NTP) to synchronize with an authoritative time server and regularly calibrates the local clock. At the same time, the system records the timestamps of the transaction request at each processing link for subsequent analysis and troubleshooting.
[0044] When calculating the overlap degree of the time window, the frequency analysis unit considers the periodic characteristics of the transactions. For example, some enterprise accounts may make batch payments on fixed dates every month, and these transactions have obvious periodicity. The system will identify these periodic characteristics by analyzing historical transaction data and make corresponding adjustments when calculating the overlap degree of the time window to avoid misjudgment.
[0045] After terminating the execution of a transaction, the transaction interception unit will send a clear prompt message to the user. The prompt message will explain the reason for the transaction interception and provide corresponding solutions. For example, it will prompt the user that "your transaction frequency is too high. To ensure the security of your account, the transaction has been temporarily intercepted. Please try again later." At the same time, the system will record the user's feedback on the prompt message for further optimizing the prompt content.
[0046] When the permission determination unit allocates an independent verification channel, it will select an appropriate verification method according to the risk level of the transaction. The assessment of the risk level is based on multiple factors, such as the transaction amount, transaction time, attributes of the payee's account, etc. For example, for a large amount of transfer transactions initiated at night, the system will consider its risk level to be relatively high, and thus allocate a more stringent verification channel, requiring the user to conduct multiple verification methods.
[0047] The system will also audit and track the entire transaction verification process. The audit log records the processing track of the transaction request, including information such as the time of each processing link, processing result, and participating processing units. These audit logs can be used for post-event compliance inspections and problem troubleshooting to ensure that the system's operations comply with relevant laws, regulations, and internal regulations.
[0048] In practical applications, the system will flexibly adjust the working parameters and strategies of each unit according to different business scenarios and user requirements. For example, for VIP customers of financial institutions, the system may relax certain verification standards to provide a more convenient transaction experience; while for newly registered users or users with a relatively high risk level, the system will strengthen the verification efforts to ensure account security. Embodiment 2:
[0049] The specific implementation method of the system in this embodiment involves the core workflow of the pattern recognition module. By steps such as constructing an analysis link for transaction nodes, calculating the transaction amount change rate, analyzing the correlation deviation amount, and generating real-time credibility parameters, the accurate identification and risk assessment of transaction behaviors are achieved.
[0050] When generating an analysis link by arranging all transaction nodes in the transaction time series, the system first preprocesses the obtained historical transaction records. The transaction records contain multi-dimensional data such as timestamps, transaction amounts, transaction types, account information, etc. The system will sort these transaction nodes in chronological order to form a complete transaction timeline. During the sorting process, the system will handle possible timestamp anomalies, such as missing or out-of-order timestamps, and correct them through interpolation methods or by synchronizing with other system times.
[0051] After randomly selecting adjacent pairs of trading nodes, the system obtains the corresponding transaction amount readings and calculates the absolute value of the change rate. For example, if the previous transaction amount is 5000 yuan and the subsequent transaction amount is 6000 yuan, the absolute value of the change rate is 20%. To ensure the accuracy of the calculation, the system validates the effectiveness of the transaction amount and excludes outliers caused by system failures or data transmission errors. At the same time, the system records the basic information of each pair of trading nodes, including transaction time, transaction object, transaction purpose, etc., for subsequent analysis.
[0052] When determining the amount peak and benchmark value in the full set of transaction data, the system traverses all transaction records to find the historical maximum transaction amount as the amount peak. The determination of the benchmark value adopts a combination of multiple statistical methods. For example, statistical quantities such as the average value and median of all transaction amounts are calculated, and classification calculations are performed according to transaction types and account attributes. For enterprise accounts and personal accounts, the system sets different benchmark value calculation methods respectively to reflect the transaction characteristics of different account types.
[0053] When calculating the overall amount fluctuation range, the system considers the periodic and seasonal factors of transactions. The transaction amounts in some industries may show regular fluctuations within a specific time period. For example, the transaction amounts in the retail industry usually increase significantly during holidays. The system uses time series analysis methods to identify these periodic fluctuations and makes corresponding adjustments when calculating the fluctuation range.
[0054] After obtaining the ratio of the absolute value of the change rate to the fluctuation range, the system standardizes this ratio and maps it to the 0 - 1 interval for subsequent comprehensive analysis with other indicators. Standardization can eliminate the dimensional differences between different transaction types and accounts, making the indicators comparable.
[0055] When calculating the transaction correlation deviation amount between pairs of trading nodes, the system analyzes from multiple dimensions. In the time dimension, the length of the transaction time interval is considered; in the amount dimension, the correlation between the two transaction amounts is analyzed; in the transaction object dimension, the relationship between the two trading parties is examined. For example, if the payee of two transactions is the same account, the transaction time interval is short, and the amounts have a certain proportional relationship, then these two transactions are considered to have a high degree of correlation.
[0056] After identifying the maximum correlation degree and minimum correlation degree among all nodes and obtaining the global correlation degree difference range, the system compares the correlation deviation amount of each pair of trading nodes with this difference range and calculates the proportional value. This proportional value reflects the position of the correlation degree of this pair of trading nodes in the overall correlation degree distribution, which helps to identify abnormally correlated transactions.
[0057] When normalizing the amount ratio and the correlation ratio to obtain the real-time credibility parameter, the system will adopt the method of weighted average and set different weights for the amount ratio and the correlation ratio according to different business scenarios and risk preferences. For example, in a financial transaction scenario with higher risks, a higher weight may be given to the correlation ratio because abnormal transaction correlations often indicate potential risks.
[0058] When traversing the remaining trading node pairs to generate the associated transaction factor set, the system will perform the same analysis process on each pair of trading nodes and calculate their real-time credibility parameters. To improve the processing efficiency, the system will adopt parallel computing technology to process multiple trading node pairs simultaneously. The generated associated transaction factor set contains the credibility parameters of all trading node pairs, and these parameters will serve as important bases for subsequent risk assessments.
[0059] When calculating the mean value of all real-time credibility parameters as the independent transaction factor, the system will perform outlier processing on the credibility parameters. For credibility parameters that deviate significantly from the normal range, the system will conduct further verification to determine whether it is data abnormality or real trading risk. When calculating the mean value, the system will perform weighting according to the importance and risk level of the trading nodes to ensure that the credibility parameters of important trading nodes have a greater impact on the independent transaction factor.
[0060] The system will also visually display the generated associated transaction factor set and the independent transaction factor. In the form of charts and reports, it intuitively presents the association relationships and risk distributions among trading nodes. This helps risk managers quickly identify potential risk points and take corresponding preventive measures.
[0061] In practical applications, the system will dynamically adjust the construction method of the analysis link and the parameter calculation method according to different trading scenarios and business requirements. For high-frequency small-amount transactions, the system may pay more attention to the time interval and frequency of transactions; for large-amount transfer transactions, the system will focus on analyzing the changes in transaction amounts and the risk characteristics of payees.
[0062] The system will regularly conduct retrospective analysis on historical transaction data to verify the accuracy and effectiveness of the pattern recognition module. By comparing the suspicious transactions identified by the system with the actual risk events that occurred, the system's risk identification ability is evaluated, and the analysis model and parameters are optimized and adjusted according to the evaluation results.
[0063] To ensure the stability and reliability of the system, the pattern recognition module adopts a distributed computing architecture. A large amount of transaction data is dispersed to multiple computing nodes for parallel processing, which improves the system's processing ability and fault tolerance. At the same time, the system also sets up a data backup and recovery mechanism to ensure that data and services can be quickly restored in case of failures.
[0064] During the data transmission process, the system adopts encryption technology to ensure the security and integrity of transaction data. Sensitive information, such as transaction amounts, account information, etc., is encrypted to prevent data from being stolen or tampered with during transmission.
[0065] The system is also integrated with other security systems, such as anti-money laundering systems, fraud detection systems, etc. Through data sharing and collaborative analysis, it realizes the comprehensive monitoring and prevention of transaction risks. For example, when the pattern recognition module detects a suspicious transaction, it will promptly transmit the relevant information to the anti-money laundering system for further investigation and processing.
[0066] The analysis results of the pattern recognition module are fed back to the risk assessment system in real time. Based on these results, the risk assessment system dynamically adjusts the risk level of the account and takes corresponding risk control measures. For example, for accounts with a relatively high risk level, the system may limit their transaction amounts or require additional identity verification. Example 3:
[0067] The specific implementation method of the system in this embodiment involves the core workflow of the indicator calculation module. Through steps such as statistical analysis of the credibility pair group, calculation of the absolute value of the difference, identification of the median and extreme value differences, and calculation of the distribution equilibrium parameter, it realizes the precise assessment of transaction risks.
[0068] After generating the credibility pair group, the system first counts its effective quantity. The credibility pair group is formed by pairwise matching of the elements in the security sorting queue and the risk sorting queue. The elements in the security sorting queue are the positive deviation values of compliant transactions and the security threshold, arranged in ascending order of the deviation values; the elements in the risk sorting queue are the negative deviation values of suspicious transactions and the risk threshold, arranged in descending order of the deviation values. The system will traverse the two queues and match the elements in the corresponding positions to form the credibility pair group. For example, the first element in the security sorting queue forms a pair with the first element in the risk sorting queue, and so on. During the matching process, the system will check the validity of the elements, such as whether the elements are within a reasonable range and whether there are conflicts with other data. Only valid element pairs can be counted in the effective quantity of the credibility pair group.
[0069] When calculating the absolute value of the difference between the security element and the risk element in each group, the system will perform a subtraction operation on the security element (the deviation value of the compliant transaction) and the risk element (the deviation value of the suspicious transaction) in each pair of credibility pair groups and take the absolute value. For example, in a pair of credibility pair groups, the deviation value of the security element is 8% and the deviation value of the risk element is -12%, then the absolute value of their difference is 20%. The system will perform the same calculation on all credibility pair groups to obtain a series of absolute value of difference data.
[0070] When identifying the median value among all absolute differences, the system sorts these absolute differences in ascending order. If the number of data points is odd, the middle number is the median; if the number of data points is even, the average of the two middle numbers is the median. The median reflects the central tendency of the data, can avoid the influence of extreme values, and provides a relatively robust statistic.
[0071] The range is calculated by finding the maximum and minimum values among all absolute differences, and then subtracting the minimum value from the maximum value. The range reflects the fluctuation range of the data and can intuitively show the degree of dispersion of the data. For example, if the maximum value of the absolute differences is 35% and the minimum value is 5%, the range is 30%.
[0072] When calculating the distribution equilibrium parameter of all absolute differences, the system considers the distribution pattern of the data. The distribution equilibrium parameter measures the degree of uniformity of the data distribution in each interval. The system divides the value range of the absolute differences into several intervals, counts the number of data points in each interval, and calculates the variance or standard deviation of these numbers of data points. The smaller the variance or standard deviation, the more uniform the data distribution and the higher the distribution equilibrium parameter; conversely, the larger the variance or standard deviation, the more uneven the data distribution and the lower the distribution equilibrium parameter.
[0073] Based on the median, range, and distribution equilibrium parameter, the system calculates the credibility evaluation value by weighted summation. The median, range, and distribution equilibrium parameter respectively reflect the central tendency, fluctuation range, and degree of uniformity of the data distribution, and their importance for credibility evaluation is different. The system assigns different weights to these three parameters, and the size of the weights is determined by training with historical data. For example, in some business scenarios, more attention may be paid to the central tendency of the data, so a higher weight is given to the median; in other scenarios, more attention may be paid to the fluctuation range of the data, so a higher weight is given to the range.
[0074] In the calculation process, the system introduces two formulas to precisely describe this process. The first formula is:
[0075] Among them, represents the average value of the absolute differences, represents the effective number of credibility pairs, represents the th security element (deviation value of compliant transactions) in the credibility pair, represents the th risk element (deviation value of suspicious transactions) in the credibility pair, Represents the absolute value of the difference between the two. This formula is used to calculate the average value of all absolute differences, providing basic data for subsequent statistical analysis.
[0076] The second formula is:
[0077] Where, Represents the credibility evaluation value, Represents the median value, Represents the range value, Represents the distribution balance parameter, 、 、 Represent the weights of the median value, range value and distribution balance parameter respectively, and satisfy . This formula comprehensively considers the influence of the median value, range value and distribution balance parameter on the credibility evaluation through weighted summation, and finally obtains an evaluation value that comprehensively reflects the trading risk.
[0078] The system will standardize the calculated credibility evaluation value and map it to the range of 0 - 100 for easy understanding and application. The standardization process can eliminate the differences between different business scenarios and data sources, making the credibility evaluation value comparable.
[0079] In practical applications, the system will adjust the weight parameters in the formula according to different business requirements and risk preferences. For businesses with a lower risk tolerance, the system may increase the weight of the range value to more sensitively capture abnormal fluctuations; for businesses with a higher risk tolerance, the system may increase the weight of the distribution balance parameter and pay more attention to the overall distribution of data.
[0080] The system will regularly conduct retrospective analysis on historical data to verify the accuracy and effectiveness of the credibility evaluation value. By comparing the credibility evaluation value calculated by the system with the actual risk events that occurred, the prediction ability of the evaluation model is evaluated, and the weight parameters in the formula are optimized and adjusted according to the evaluation results.
[0081] To improve the calculation efficiency, the system adopts distributed computing technology, distributing a large number of computing tasks to multiple computing nodes for simultaneous processing. This not only speeds up the calculation speed but also improves the fault tolerance and reliability of the system.
[0082] In terms of data storage, the system adopts a high-performance database system that can quickly store and retrieve a large amount of transaction data and calculation results. At the same time, the system also sets up a data backup and recovery mechanism to ensure the security and integrity of the data.
[0083] The system will feedback the credibility assessment value to the risk monitoring system in real time. The risk monitoring system classifies and warns about transactions based on the size of the assessment value. For transactions with a relatively low credibility assessment value, the system will issue a high-risk warning, prompting risk management personnel to conduct further investigations and handling; for transactions with a relatively high credibility assessment value, the system will consider their risks to be low and give normal clearance.
[0084] The system will also dynamically track and analyze the credibility assessment value. As transactions continue to occur, the system will continuously update the credibility assessment value to promptly detect potential risk change trends. For example, if the credibility assessment value of a certain account continuously decreases, even if the current transaction does not trigger a high-risk warning, the system will increase the monitoring intensity of this account to prevent possible risks.
[0085] Through the above implementation methods, the system realizes the precise assessment of transaction risks, can provide a scientific and reliable basis for risk decision-making, effectively prevent financial risks, and ensure the security of user accounts and funds. Example 4:
[0086] The specific implementation method of the system in this embodiment focuses on the core function of the parameter adjustment module, and realizes the adaptive adjustment of the verification strategy by driving the dynamic optimization of the transaction risk feature table through the credibility assessment value. The following combines specific examples of different business scenarios to detail the full process operation from credibility assessment to strategy implementation.
[0087] Suppose an enterprise merchant account on an e-commerce platform completed 200 transactions within a month. The system analyzed the compliance and suspiciousness of its transaction link through the index calculation module and obtained a credibility assessment value of 0.85. The preset primary credibility threshold of the parameter adjustment module is 0.7, the high-level credibility threshold is 0.8, the configured basic adjustment coefficient is 1.0, the intermediate adjustment coefficient is 1.2, and the enhanced adjustment coefficient is 1.5. Since 0.85 is higher than the high-level credibility threshold, the system determines that the transaction credibility of this account is relatively high and enables the basic adjustment coefficient.
[0088] In another example, a personal user continuously initiated transfers to 3 unfamiliar accounts between 2 am and 5 am, with a cumulative amount of 80,000 yuan. After the system extracted its transaction characteristics, the calculated credibility assessment value was 0.62, which is between the primary credibility threshold (0.7) and the lower risk threshold. Therefore, the intermediate adjustment coefficient of 1.2 was enabled. If the credibility assessment value of an account is as low as 0.5 due to multiple abnormal large transfers, which is lower than the primary credibility threshold, the enhanced adjustment coefficient of 1.5 is triggered, indicating that the verification intensity needs to be significantly increased.
[0089] Taking the enterprise merchant account as an example, the correction value of the authorization parameter in its initial transaction risk characteristic table is 0.9 (the benchmark coefficient for adjusting transaction permissions). Based on the credibility evaluation value of 0.85 and the basic adjustment coefficient of 1.0, the dynamic adjustment gradient is , which is multiplied by the correction value of the authorization parameter to obtain the final authorization parameter as . This parameter indicates that the transaction permissions of this account can be moderately relaxed, but the basic verification intensity needs to be maintained.
[0090] For an individual account with high-frequency transfers in the early morning, assuming that the correction value of its authorization parameter is 0.8 (the system defaults to setting lower initial permissions for individual accounts), the product of the credibility evaluation value of 0.62 and the intermediate adjustment coefficient of 1.2 is , and the final authorization parameter is . This parameter indicates that the transaction risk has increased and the permissions need to be tightened. If an account triggers the risk rules multiple times and the correction value of the authorization parameter is 1.0 (the initial highest permission), the product of the credibility evaluation value of 0.5 and the enhanced adjustment coefficient of 1.5 is 0.75, and the final authorization parameter is . Although the value seems high, considering its risk level, the system will match more stringent verification indicators.
[0091] The pre-set permission mapping rules of the system are constructed according to dimensions such as transaction type and account attributes. For example: Enterprise merchant batch payment scenario: The final authorization parameter is associated with the single-payment limit and the automatic verification ratio. If the final authorization parameter is 0.765, the corresponding expected verification indicators may be "the single-payment limit is adjusted from 100,000 yuan to 120,000 yuan" (due to high credibility, the limit is moderately increased) and "the automatic verification ratio is increased from 80% to 90%" (reducing manual intervention).
[0092] Individual account cross-border remittance scenario: The final authorization parameter is associated with the complexity of identity verification and the transaction frequency limit. If the parameter is 0.5952, the corresponding indicators may be "double verification of face recognition + dynamic token is required for each remittance" and "the upper limit of the number of remittances per day is reduced from 3 times to 2 times".
[0093] High-risk suspicious transaction scenario: When the final authorization parameter is lower than 0.6, the rule library compulsorily associates indicators such as "frontier manual review" and "fund flow tracking". For example, if the final authorization parameter of an account is 0.55, the system will require that each transaction exceeding 10,000 yuan must be manually confirmed by risk control personnel before it can be executed.
[0094] The underlying logic of the permission mapping rules is based on historical risk data. For example, statistics show that when the final authorization parameter of an enterprise account is higher than 0.7, the transaction fraud rate is lower than 0.1%, so the limit is allowed to be moderately relaxed; while when the individual account parameter is lower than 0.6, the fraud rate rises to 5%, and verification measures need to be strengthened.
[0095] Taking the batch payment scenario of enterprise merchants as an example, the optimized transaction risk feature table includes: Final authorization parameter: 0.765 (reflecting the credibility of the current transaction link).
[0096] Expected verification indicators: Single payment limit: 120,000 yuan (a 20% increase compared to the original threshold); Automatic verification condition: When the counterparty is a historical cooperative merchant, manual review is waived; Abnormal interception rule: When the single payment amount exceeds 150% of the limit, block immediately and trigger an alarm.
[0097] In the scenario of cross-border remittance for personal accounts, the content of the optimized table is as follows: Final authorization parameter: 0.5952; Expected verification indicators: Forced trigger of dual verification: Each remittance must pass face recognition and mobile dynamic verification code; Transaction time limit: Remittance can only be initiated on weekdays from 9:00 to 18:00; Cumulative amount monitoring: When the total cross-border remittance amount exceeds 50,000 yuan within 7 days, a fund usage certificate needs to be submitted.
[0098] For high-risk accounts that trigger the enhanced adjustment coefficient (such as the final authorization parameter of 0.55), the optimized table will include extreme control measures: Final authorization parameter: 0.55; Expected verification indicators: Suspension of non-counter transaction permissions (only counter operations are retained); Proof of payee qualification (such as invoices, contracts) is required for each transaction; The risk level is marked as "extremely high risk" and included in the real-time monitoring white list.
[0099] Suppose a manufacturing enterprise account initiates two transactions on May 20, 2025: ① The first transaction: Pay 500,000 yuan for the goods to a long-term cooperative supplier at 10:00 am, and the transaction channel is the enterprise online banking.
[0100] Data reception module: Identify as an enterprise account and online banking channel, and build a verification model including dimensions such as transaction frequency and historical cooperation duration with the payee.
[0101] Feature analysis module: Extract compliance features such as "this supplier accounts for 30% of the transactions in the past 3 months" and "transaction times are all on weekday mornings", generate an initial risk feature table, with the authorized parameter correction value of 0.9, and the verification indicator is "single limit of 1 million yuan, automatic verification".
[0102] Pattern Recognition Module: This transaction forms an associated transaction factor with the previous 3 transactions with the same supplier. The amount fluctuation is less than 5%, and the degree of association is high, generating a real-time credibility parameter of 0.9.
[0103] Indicator Calculation Module: Combining other independent transaction factors, the calculated credibility evaluation value is 0.88, which is higher than the advanced credibility threshold.
[0104] Parameter Adjustment Module: Enable the basic adjustment coefficient of 1.0, and the final authorization parameter is , after matching the rules, the single-transaction limit remains at 1 million yuan, and the automatic verification passes, allowing the transaction to be released.
[0105] ② The second transaction: At 15:00 on the same day, pay 800,000 yuan to a newly registered unfamiliar account, with the postscript "equipment purchase".
[0106] Data Receiving Module: Detect that the payee is a newly opened account, trigger the "unfamiliar transaction" risk dimension, and construct a model including dimensions such as account duration and sudden increase in transaction amount.
[0107] Feature Analysis Module: Extract abnormal features such as "new payee" and "amount exceeding 4 times the average transaction amount of this account". The correction value of the authorization parameter for the initial risk feature table is 0.7, and the verification indicator is "single-transaction limit of 500,000 yuan, requiring approval by the financial director".
[0108] Pattern Recognition Module: This transaction has no association with historical transactions, is determined as an independent transaction factor, and the real-time credibility parameter is 0.6.
[0109] Indicator Calculation Module: The credibility evaluation value is 0.63, which is between the primary and advanced credibility thresholds.
[0110] Parameter Adjustment Module: Enable the intermediate adjustment coefficient of 1.2, and the final authorization parameter is , after matching the rules, the single-transaction limit is lowered to 300,000 yuan (70% of the original threshold of 500,000 yuan), and dual approval by the financial director and the legal person is required.
[0111] Verification Execution Module: Since the transaction amount of 800,000 yuan exceeds the adjusted limit, the system automatically blocks the transaction and prompts the user "The transaction amount exceeds the current account authority. Please submit dual approval."
[0112] The system will regularly review the effectiveness of the optimized transaction risk characteristic table. For example, for the high-frequency transfer scenario of individual accounts with the intermediate adjustment coefficient enabled, observe whether the incidence of risk events for similar transactions after adjustment has decreased (without involving specific data verification). If it is found that the strategy effect of a certain scenario is not good, such as the verification of unfamiliar transactions of enterprise accounts is still frequently missed, the system will manually adjust the permission mapping rules and add the indicator of "mandatory manual review for the first transaction of the new payee", which does not need to be triggered by the credibility evaluation value, forming a dual prevention and control of the rule layer and the dynamic adjustment layer.
[0113] Through the above process, the parameter adjustment module realizes the automatic mapping from data characteristics to verification strategies, which not only ensures the smoothness of high-credibility transactions, but also prevents potential risks by dynamically tightening permissions, forming an adaptive security protection system covering the entire transaction link. Example 5:
[0114] The specific implementation method of the system in this embodiment focuses on the extended functions of the data receiving module, and realizes multi-level prevention and control of transaction risks through the linkage of the construction of the transaction behavior feature map, the abnormal boundary response mechanism and the conflict event handling strategy. The following combines specific examples of different business scenarios to detail the full process operation from data integration to response execution.
[0115] Suppose enterprise customer A of a commercial bank initiates multiple transactions on May 23, 2025. The data receiving module integrates the following data in real time: Transaction flow data: Transfer 3 million yuan to an affiliated enterprise at 9:00 am and transfer 5 million yuan to an unfamiliar account at 14:00 pm, both through the online banking channel.
[0116] Account attribute data: This account is a VIP enterprise account with an average daily transaction amount of 2 million yuan, and the historical transaction counterparts are concentrated in 5 affiliated enterprises.
[0117] Operation environment data: The IP address of the morning transaction is the enterprise office address, and the IP address of the afternoon transaction is a certain overseas region.
[0118] Based on these data, the system constructs a transaction behavior feature map and marks the characteristics of the two transactions: Morning transaction: Belongs to the feature combination of "transfer to affiliated enterprise", "operation during working hours", and "IP address compliance", falling into the "safe area" of the map.
[0119] Afternoon transaction: Includes features such as "large amount transfer to unfamiliar account", "overseas IP login", and "transaction amount suddenly increased by 150%", triggering the "abnormal boundary warning" in the map.
[0120] The relationship between features is presented through a visual interface in the atlas. For example, the correlation between overseas IP and unfamiliar accounts reaches 80%, and the deviation of large - amount transfers from historical transaction amounts reaches 150%. Risk managers can intuitively see the risk - feature distribution of the account and determine whether to activate the secondary verification process.
[0121] Regarding the abnormal boundary breakthrough triggered by afternoon transactions, the system automatically matches a three - level response mechanism according to the degree of breakthrough: First - level response (limit adjustment): If the abnormal feature of the account is "login from overseas IP" but the transaction amount does not exceed 100% of the historical average, the system triggers a first - level response and adjusts the remaining daily transaction limit from 8 million yuan to 5 million yuan. For example, when an account of a retail enterprise logs in through a new device during non - working hours and initiates a small - amount transfer, the system determines that the risk is low and only adjusts the limit without blocking the transaction.
[0122] Second - level response (cross - channel verification): If the transaction simultaneously includes features such as "unfamiliar account" and "amount increased by 50%", such as a 5 - million - yuan transfer by customer A, the system starts a second - level response. After the user submits a transfer request, the system automatically sends a text message verification code to the reserved mobile phone number and requires it to be entered within 10 minutes. If the user fails to complete the verification in time, the transaction will be temporarily suspended.
[0123] Third - level response (funds freezing and manual review): If the transaction involves triple anomalies of "overseas IP", "unfamiliar account", and "amount exceeding the historical peak" (such as an account suddenly transferring 10 million yuan to an overseas unknown account, far exceeding its historical maximum transaction amount of 5 million yuan), the system immediately freezes the fund transfer of the account and sends a manual review instruction to the risk control department. Risk control personnel need to verify materials such as transaction contracts and payee qualifications within 1 hour, and the freeze can be lifted only after confirmation.
[0124] In another example, individual user B transfers a cumulative amount of 100,000 yuan to 4 different accounts through mobile banking within 1 hour (his historical average daily transfer amount is 20,000 yuan). The system detects features such as "high - frequency trading" and "diversified transfers to multiple accounts", calculates that the degree of abnormal boundary breakthrough is at the second level, and initiates cross - channel verification, requiring the user to pass double verification of face recognition and fingerprint recognition before continuing the operation.
[0125] When the user submits an unstructured transaction instruction, such as filling in "urgent payment, please give priority to processing" in the transfer remarks, the transaction comparison unit analyzes the key operation elements through text feature extraction technology: Keyword extraction: Identify words such as "urgent payment" and "give priority to processing", and determine that the transaction may have timeliness requirements.
[0126] Historical conflict matching: The system searches the historical transaction conflict event database and finds that phishing attacks have occurred in similar "urgent payment" scenarios. Attackers use emergency rhetoric to induce users to ignore the verification process.
[0127] Strategy library call: Based on the vectorized template, the system matches the disposal plan of "urgent transactions require additional manual review" from the strategy library, generates a verification priority adjustment instruction, and upgrades the verification level of the transaction from "automatic verification" to "manual priority verification".
[0128] In another case, user C initiated a transaction through voice command: "Transfer 5,000 yuan to Zhang San for payment of goods". The system analyzed that "Zhang San" was a non-historical payee and "payment of goods" was a new purpose type, triggering a conflict event of "non-historical counterparty + new transaction purpose". The system immediately searched the policy library and found that such scenarios required "verifying the identity information of the payee and confirming the authenticity of the transaction", so it sent a message to the user: "It is detected that you are transferring money to a new payee. Please confirm whether it is your own operation and provide the last four digits of the payee's ID number for verification."
[0129] The transaction process of a technology company account D on May 24, 2025 is as follows: Normal transaction stage: At 10:00 am, a payment of RMB 1 million is made to Supplier E, with the note "Material payment in May 2025". The system interprets the "Supplier E" in the instruction as a historical partner, and the "Material payment" is for regular use. It is determined to be a same-source transaction, and no additional verification is required, and it is automatically released.
[0130] Abnormal triggering stage: At 15:30 in the afternoon, 2 million yuan was transferred to personal account F, with the note "equipment purchase deposit". The data receiving module detected features such as "the recipient is a personal account", "the transaction amount exceeds the company's regular purchase amount by 150%", and "the purpose deviates from the company's business scope", and constructed an abnormal feature map, calculating the abnormal boundary breakthrough level as level three. The system immediately froze the account funds flow and sent an early warning SMS to the company's financial director: "Your account transferred 2 million yuan to personal account F, there is an abnormal risk, the funds have been frozen, please log in to the system as soon as possible to submit the transaction voucher for manual review."
[0131] Manual review stage: The financial manager logs into the system and uploads the equipment purchase contract, deposit receipt and other materials with personal account F. The risk control personnel found that Party A of the contract is a technology company and Party B is the individual business owner to which F belongs. The transaction is real and legal but exceeds the scope of the system's preset risk model. Based on the review results, the system adjusts the transaction behavior feature map of the account, includes "individual business purchase" in the compliance scenario, unfreezes funds, and updates the risk / compliance matrix to prevent similar transactions from triggering a level 3 response again.
[0132] The system regularly reviews historical transaction conflict events and updates the vectorization template and disposal strategies. For example, after discovering that a certain type of "cross-border e-commerce refund" transaction frequently triggers false interceptions, the system marks the feature combination of "cross-border e-commerce platform + refund" as a low-risk scenario and adjusts the disposal strategy to "automatic verification + amount limit" (such as a single refund not exceeding 50,000 yuan). When new fraud means emerge (such as emergency transfers in the name of a forged government agency), the risk control department manually adds the feature combination of "government agency name + emergency transfer + unfamiliar account" and configures the strategy of "forced manual verification + fund flow tracking", without relying on historical data training.
[0133] When adapting to different industries, the system supports customizing the risk / compliance matrix. For example, transactions of "drug procurement funds" for medical industry accounts are usually large in amount and directed to fixed suppliers. The system sets a separate verification strategy for them: "Transactions with the same type of suppliers are automatically released, and transactions with new suppliers require submission of procurement contracts"; while for "technical service fee" transfers of Internet industry accounts, they may be more frequent and the payees are diverse. The system then relaxes the verification criteria and only conducts manual review for transactions with an amount exceeding 500,000 yuan.
[0134] Throughout the process, the system takes measures for encrypted storage and transmission of sensitive data. For example, information such as the payee's ID number and scanned copies of transaction contracts parsed out are all processed through the AES-256 encryption algorithm, and the SSL / TLS protocol is used during the transmission process to prevent eavesdropping. The operation audit module records the timestamps and operators of each feature parsing, policy matching, and response execution, forming an immutable audit log for regulatory compliance inspections.
[0135] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device.
[0136] Although the embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A financial data security verification system, characterized in that, It includes: A data receiving module, which is used to obtain a financial transaction data set to be verified, and construct a multi-dimensional verification model according to the account type and transaction channel; A feature analysis module, which is used to extract abnormal operation features from historical transaction records, and generate a transaction risk feature table in combination with the multi-dimensional verification model, where the transaction risk feature table contains verification indicators and authorized parameter correction values; A pattern recognition module, which is used to decompose the historical transaction records, identify high-frequency transaction nodes and low-frequency transaction nodes, and divide associated transaction factors and independent transaction factors; An index calculation module, which is used to generate a credibility evaluation value of the transaction link based on the associated transaction factors and independent transaction factors; A parameter adjustment module, which is used to determine the dynamic adjustment gradient of the transaction risk feature table according to the credibility evaluation value, and update the transaction risk feature table based on the dynamic adjustment gradient to form an optimized transaction risk feature table; A verification execution module, which is used to trigger the blocking or release operation of the account transaction permission according to the optimized transaction risk feature table.
2. The financial data security verification system according to claim 1, wherein It further includes: A transaction comparison unit, which is used to match the current transaction request with the operation type of the historical transaction records to determine whether they belong to the same-source transaction; A time window collection unit, which is used to record the start timestamp of the current request and the completion timestamp of the previous transaction if it is determined to be the same-source transaction; A frequency analysis unit, which is used to calculate the time window overlap degree of the two transactions, and compare it with a preset frequency threshold to determine whether to allow the execution of the current transaction; A transaction interception unit, which is used to terminate the transaction execution and generate a high-frequency operation log if the time window overlap degree exceeds the preset frequency threshold; A permission determination unit, which is used to allocate an independent verification channel to process the current transaction request if the operation type matching results are inconsistent.
3. The financial data security verification system according to claim 1, wherein, The pattern recognition module includes: Arrange all transaction nodes in the transaction time series to generate an analysis link, randomly select adjacent transaction node pairs, obtain the corresponding transaction amount readings and subsequent transaction amount readings, and calculate the absolute value of the change rate of the amount readings; Determine the amount peak value and the benchmark value in the full transaction data, and calculate the overall amount fluctuation range; Obtain the ratio of the absolute value of the change rate to the fluctuation range; Calculate the transaction correlation deviation amount between the transaction node pairs; Identify the maximum correlation degree and the minimum correlation degree among all nodes, and calculate the global correlation degree difference range; Obtain the proportional value of the transaction correlation deviation amount to the difference range; Normalize the amount ratio and the correlation degree ratio to obtain a real-time credibility parameter; Traverse the remaining transaction node pairs to generate a set of associated transaction factors, and calculate the mean value of all real-time credibility parameters as an independent transaction factor.
4. The financial data security verification system according to claim 1, characterized in that The index calculation module includes: Set the safety threshold and risk threshold of the associated transaction factor; Screen the compliant transaction set according to the safety threshold, and screen the suspicious transaction set according to the risk threshold; Calculate the positive deviation value of the compliant transaction from the safety threshold, and arrange them in ascending order of the deviation value to form a safety sorting queue; Calculate the negative deviation value of the suspicious transaction from the risk threshold, and arrange them in descending order of the deviation value to form a risk sorting queue; Match the elements of the security queue and the risk queue item by item to form a credibility pair group, and calculate the credibility evaluation value based on all credibility pair groups.
5. The financial data security verification system according to claim 4, wherein The metric calculation module further includes: Statistical the effective number of credibility pair groups, and calculate the absolute value of the difference between the security element and the risk element in each group respectively; Identify the median value and the extreme difference value among all the absolute difference values, and calculate the distribution balance parameter of all the absolute difference values; Calculate the credibility evaluation value according to the median value, the extreme difference value and the distribution balance parameter.
6. The financial data security verification system according to claim 1, wherein The parameter adjustment module includes: Set a primary credibility threshold and a high-level credibility threshold; Configure a basic adjustment coefficient, an intermediate adjustment coefficient and an enhanced adjustment coefficient; When the credibility evaluation value is higher than the high-level credibility threshold, enable the basic adjustment coefficient. When the credibility evaluation value is between the primary and high-level credibility thresholds, enable the intermediate adjustment coefficient. When the credibility evaluation value is lower than the primary credibility threshold, enable the enhanced adjustment coefficient.
7. The financial data security verification system according to claim 1, characterized in that The parameter adjustment module further includes: Multiply the dynamic adjustment gradient by the authorized parameter correction value to generate the final authorized parameter; Match the preset permission mapping rule to determine the expected verification index corresponding to the final authorized parameter; Integrate the final authorized parameter and the expected verification index to construct the optimized transaction risk feature table.
8. The financial data security verification system according to claim 1, characterized in that, The data receiving module further includes: Integrate the transaction flow data, account attribute data and operation environment data in real time to construct a transaction behavior feature map; Calculate the abnormal boundary of the transaction behavior according to the transaction behavior feature map, and activate the secondary verification process when it is detected that the transaction feature exceeds the security boundary; Generate a risk / compliance matrix under different transaction scenarios through association rule mining, and generate an optimal verification strategy set.
9. The financial data security verification system according to claim 8, characterized in that Divide the three-level response mechanism according to the degree of abnormal boundary breakthrough: the first level triggers the adjustment of the account transaction limit, the second level starts the cross-channel transaction verification, and the third level freezes the account fund transfer and sends an artificial review instruction.
10. The financial data security verification system according to claim 2, wherein, The transaction comparison unit includes: parsing the key operation elements in the unstructured transaction instruction through the text feature extraction technology, storing the vectorized template of the historical transaction conflict event and its disposal strategy, and when a transaction conflict is detected, retrieving the adapted disposal plan from the strategy library through pattern matching, and generating a verification priority adjustment instruction.
Citation Information
Patent Citations
Transaction account supervision method and device, computer equipment and storage medium
CN112150162A
Risk control method and device for business system
CN114004708A
Risk control method and risk control platform applied to transaction system
CN116228415A
Bank anti-call fraud data model construction method based on multi-feature fusion
CN117993919A
Privacy information protection method and device
CN118153109A