Risk control method and device for member benefit service
By combining multi-dimensional risk control verification of users with external risk control services and dynamically updating risk control tags, the flexibility issue of risk control in membership benefits services has been resolved, achieving personalized risk control and improved user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
- Filing Date
- 2025-04-01
- Publication Date
- 2026-06-16
Smart Images

Figure CN120338481B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to one or more embodiments in the field of computer network technology, and in particular to a risk control method and apparatus for membership rights services. Background Technology
[0002] In the digital age, various industries have launched unique membership benefits services to enhance user loyalty and improve the consumer experience. However, these services also bring numerous risks, such as fraud, abuse of benefits, and data breaches. These risks can not only lead to direct economic losses but also damage brand reputation and customer trust. Therefore, implementing effective risk control measures is crucial to ensuring the fairness, security, and sustainability of membership benefits services.
[0003] Currently, many risk control systems employ a "one-size-fits-all" strategy, applying the same risk control measures to all users. While this model is simple and easy to implement, it lacks flexibility and struggles to address the diverse risk characteristics of different users.
[0004] Therefore, designing a more flexible risk control scheme has become an urgent technical problem to be solved. Summary of the Invention
[0005] To provide a more flexible risk control solution, one or more embodiments of this specification provide a risk control method and apparatus for membership rights services.
[0006] In a first aspect, one or more embodiments of this specification provide a risk control method for membership benefits services. The method includes: in response to receiving a user's membership benefits request, obtaining the user's corresponding risk control information to be verified; determining at least one risk control factor of the risk control information to be verified in one dimension; performing internal risk control verification on the risk control information to be verified based on the risk control rules and / or risk control models corresponding to each dimension of the risk control factors, and obtaining internal risk control verification results corresponding to each dimension of the risk control factors; calculating a first security score corresponding to each dimension of the risk control factors based on the internal risk control verification results corresponding to each dimension of the risk control factors; determining a target risk code based on the first security score corresponding to each dimension of the risk control factors; when the target risk code represents a first risk type, calling an external risk control service corresponding to the first risk type to perform external risk control verification on the risk control information to be verified, and obtaining an external risk control verification result; calculating a second security score based on the external risk control verification result; and determining the risk control result corresponding to the user based on each first security score and the second security score.
[0007] In one possible implementation, determining at least one dimension of risk control factor corresponding to the risk control information to be verified includes: determining a first target risk control label corresponding to the risk control information to be verified; obtaining a set of risk control labels for the user; determining a second target risk control label from the first target risk control label, wherein the second target risk control label belongs to the risk control label in the risk control label set; and determining at least one dimension of risk control factor corresponding to the second target risk control label.
[0008] One possible implementation method further includes updating the user risk control tag set based on each first security score and second security score.
[0009] In one possible implementation, based on the risk control rules corresponding to the risk control factors of each dimension, internal risk control verification is performed on the risk control information to be verified to obtain internal risk control verification results. This includes: determining the risk control rules corresponding to the risk control factors of each dimension, wherein the risk control rules include verification items, verification conditions corresponding to each verification item, and verification results corresponding to each verification condition; extracting the target risk control information corresponding to each verification item from the risk control information to be verified; determining the target verification conditions that each target risk control information satisfies; determining the target verification results corresponding to each verification condition; and aggregating the target verification results to obtain the internal risk control verification results corresponding to the risk control factors of each dimension.
[0010] In one possible implementation, the method further includes: receiving security events related to member rights; calculating a third security score based on the security events; and updating the user risk control tag set based on the first security score, the second security score, and the third security score.
[0011] In one possible implementation, the method further includes: issuing corresponding membership benefits to the user when the target risk code represents a second risk type; and sending a notification to the user that the membership benefit request failed when the target risk code represents a third risk type.
[0012] In one possible implementation, the risk control result for a user is determined based on each first security score and second security score, including: determining the user's total security score based on each first security score and second security score; issuing corresponding membership benefits to the user if the total security score is greater than a security score threshold; and sending a notification of failed membership benefit request to the user if the total security score is less than or equal to the security score threshold.
[0013] Secondly, one or more embodiments of this specification provide a risk control device for membership benefits services, the device comprising:
[0014] The acquisition module is used to respond to a user's membership rights request and obtain the corresponding risk control information to be verified for the user.
[0015] The first determining module is used to determine at least one dimension of risk control factors corresponding to the risk control information to be verified.
[0016] The internal risk control verification module is used to perform internal risk control verification on the risk control information to be verified based on the risk control rules and / or risk control models corresponding to the risk control factors of each dimension, and to obtain the internal risk control verification results corresponding to the risk control factors of each dimension.
[0017] The security score calculation module is used to calculate the first security score corresponding to each risk control factor based on the internal risk control verification results corresponding to each risk control factor in each dimension.
[0018] The second determination module is used to determine the target risk code based on the first safety score corresponding to each risk control factor in each dimension.
[0019] The external risk control verification module is used to call the external risk control service corresponding to the first risk type to perform external risk control verification on the risk control information to be verified when the target risk code represents the first risk type, and obtain the external risk control verification result.
[0020] The security score calculation module is also used to calculate a second security score based on the external risk control verification results;
[0021] The third determination module is used to determine the risk control result corresponding to the user based on each first security score and second security score.
[0022] In one possible implementation, the first determining module is specifically used for: determining a first target risk control label corresponding to the risk control information to be verified; obtaining a set of risk control labels for the user; determining a second target risk control label from the first target risk control label, wherein the second target risk control label belongs to the risk control label in the risk control label set; and determining at least one dimension of risk control factor corresponding to the second target risk control label.
[0023] In one possible implementation, the device further includes an update module for updating the user risk control tag set based on each first security score and second security score.
[0024] In one possible implementation, the internal risk control verification module is specifically used to: determine the risk control rules corresponding to each dimension of risk control factors, wherein the risk control rules include verification items, verification conditions corresponding to each verification item, and verification results corresponding to each verification condition; extract the target risk control information corresponding to each verification item from the risk control information to be verified; determine the target verification conditions satisfied by each target risk control information; determine the target verification results corresponding to each verification condition; and aggregate the target verification results to obtain the internal risk control verification results corresponding to each dimension of risk control factors.
[0025] In one possible implementation, the device further includes:
[0026] The receiving module is used to receive security events related to member rights;
[0027] The security score calculation module is also used to calculate a third security score based on security events;
[0028] The update module is used to update the user risk control tag set based on each first security score, second security score, and third security score.
[0029] Thirdly, one or more embodiments of this specification also provide an electronic device, which includes a memory and a processor; the memory is used to store a computer program product; the processor is used to execute the computer program product stored in the memory, and when the computer program product is executed, it implements the method of the first aspect described above.
[0030] Fourthly, one or more embodiments of this specification also provide a computer-readable storage medium storing computer program instructions that, when executed, implement the method described in the first aspect.
[0031] In summary, one or more embodiments of this specification provide a risk control method and apparatus for membership benefits services. The method first determines at least one dimension of risk control factors requiring user risk control verification. Then, internal risk control verification is performed on the determined at least one dimension of risk control factors, and the internal risk control verification result is converted into a first security score. Next, a target risk code is determined using the first security score. Then, different risk control methods are executed based on different target risk codes. For example, if the target risk code represents a first risk type, the external risk control service corresponding to the first risk type is invoked to perform external risk control verification on the risk control information to be verified, obtaining the external risk control verification result; the external risk control verification result is then converted into a second security score; finally, based on each first security score and second security score, the risk control result corresponding to the user is determined.
[0032] In this way, by quantifying the internal risk control verification results as a security score, the risk code corresponding to the user can be dynamically matched according to the security score. Then, the corresponding risk control verification operation can be further executed based on the risk characteristics of the user, thereby improving the flexibility of the risk control plan and realizing personalized risk control. Attached Figure Description
[0033] To more clearly illustrate the technical solutions of one or more embodiments of this specification, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of one or more embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0034] Figure 1 A schematic diagram of the architecture of a membership rights service system provided for one or more embodiments of this specification;
[0035] Figure 2 A flowchart illustrating a risk control method for a membership benefits service provided in one or more embodiments of this specification;
[0036] Figure 3 A flowchart illustrating another risk control method for membership benefits services provided in one or more embodiments of this specification;
[0037] Figure 4 A structural block diagram of a risk control device for a membership rights service provided in one or more embodiments of this specification;
[0038] Figure 5 This is a structural block diagram of an electronic device provided for one or more embodiments of this specification. Detailed Implementation
[0039] The present specification describes one or more embodiments in further detail below with reference to the accompanying drawings and examples. Through these descriptions, the features and advantages of one or more embodiments of the present specification will become clearer and more apparent.
[0040] The term “exemplary” as used herein means “serving as an example, embodiment, or illustration.” Any embodiment illustrated herein as “exemplary” is not necessarily to be construed as superior to or better than other embodiments. Although various aspects of embodiments are shown in the accompanying drawings, the drawings are not necessarily drawn to scale unless specifically indicated otherwise.
[0041] Furthermore, the technical features described below in one or more embodiments of this specification may be combined with each other as long as they do not conflict with each other.
[0042] To facilitate understanding, the application scenarios of the technical solutions provided in one or more embodiments of this specification will be described below.
[0043] In the digital age, various industries have launched unique membership benefits services to enhance user loyalty and improve the consumer experience. However, these services also bring numerous risks, such as fraud, abuse of benefits, and data breaches. These risks can not only lead to direct economic losses but also damage brand reputation and customer trust. Therefore, implementing effective risk control measures is crucial to ensuring the fairness, security, and sustainability of membership benefits services.
[0044] Currently, many risk control systems employ a "one-size-fits-all" strategy, applying the same risk control measures to all users. While this model is simple and easy to implement, it lacks flexibility and struggles to address the differentiated risk characteristics of different user groups.
[0045] To enhance the flexibility of risk control measures, this specification provides one or more embodiments of a risk control method and apparatus for membership benefits services. This method can implement different risk control schemes for users with different risk characteristics based on security scores and risk codes, thereby improving the flexibility of risk control measures and achieving personalized risk control.
[0046] This specification provides one or more embodiments of a risk control method for membership rights services that can be applied to... Figure 1 The membership benefits service system shown.
[0047] like Figure 1 As shown, the membership benefits service system may include an internal membership benefits service system and an external membership benefits service system. The internal membership benefits service system may include a membership benefits center, a benefits redemption unit, an internal risk control unit, and a security score calculation unit. The external membership benefits service system may include an external risk control unit.
[0048] The Membership Rights Center acts as a caller. After a user accesses the Membership Rights Center, it can invoke the Rights Redemption Unit to perform basic risk control checks on the user. If the basic risk control checks pass, it can invoke the internal risk control unit to perform multi-dimensional risk control factor checks on the user. Then, it can use the Security Score Calculation Unit to calculate the first security score corresponding to the internal risk control check result. Next, the Membership Rights Center can execute the next action based on the target risk code corresponding to the first security score. For example, if the target risk code corresponding to the first security score indicates no risk, the corresponding membership rights are issued to the user. Alternatively, if the target risk code corresponding to the first security score indicates risk, an external risk control service can be invoked to perform external risk control checks on the target risk type corresponding to the target risk code. Then, the Security Score Calculation Unit can use the Security Score Calculation Unit to calculate the second security score corresponding to the external risk control check result. Finally, based on the first and second security scores, the user's corresponding risk control result can be determined.
[0049] Thus, the risk control method for membership benefits services provided in one or more embodiments of this specification quantifies the internal risk control verification results as a security score, so as to dynamically match the risk code corresponding to the user based on the security score, and then further execute the corresponding risk control verification operation based on the risk characteristics of the user, thereby improving the flexibility of the risk control scheme and realizing personalized risk control.
[0050] Furthermore, after internal risk control checks identify risks, further verification using external risk control services can fully utilize external risk control resources and enhance overall risk prevention and control capabilities. Secondly, by combining internal and external risk control checks, genuine risks can be identified more accurately, avoiding misjudgments of legitimate users, thereby improving user experience and reducing the false positive rate.
[0051] The following describes an embodiment of the risk control method for membership benefits services provided by one or more embodiments of this specification.
[0052] See Figure 2 and Figure 3 , Figure 2 This is a flowchart illustrating a risk control method for a membership benefits service provided in one or more embodiments of this specification. Figure 3 This is a flowchart illustrating another risk control method for membership benefits services provided in one or more embodiments of this specification. This method can be applied to servers, terminal devices, or other similar devices. Figure 1 The following describes a membership benefits service system. The system is used as an example to illustrate the implementation details. Figure 2 and Figure 3 As shown, the method may include the following steps:
[0053] S102, in response to receiving a user's membership rights request, obtains the user's corresponding risk control information to be verified.
[0054] Taking online shopping as an example, when a user initiates a request for membership benefits (such as redeeming coupons with points or enjoying exclusive member discounts), the system needs to perform risk control verification on the request to ensure its legality and security.
[0055] For example, a user initiates a membership benefits request by clicking "Redeem Points" or "Use Member Discount" through the front-end interface of a shopping platform (such as an app or webpage). In response to receiving the membership benefits request, the system obtains the risk control information to be verified for that user.
[0056] Optionally, the risk control information to be verified can include risk control information from multiple dimensions. For example, the risk control information to be verified can include user attribute information, behavioral information, order information, membership information, etc. For example, behavioral information can include the frequency of using membership benefits, the frequency of transactions, etc.; order information can include product information, price information, purchase channel information, etc.; membership information can include membership level, accumulated points, etc.
[0057] S104, determine at least one risk control factor corresponding to the risk control information to be verified.
[0058] In one or more embodiments of this specification, the internal risk control unit may be pre-configured with multiple dimensions of risk control factors. For example, multiple dimensions of risk control factors may include customer risk factors, traffic risk factors, repeat risk factors, ratio risk factors, restriction risk factors, credibility risk factors, etc.
[0059] Then, based on the risk control information to be verified, at least one risk control factor that the user needs to verify can be determined from the above multiple risk control factors.
[0060] In one possible implementation, determining the risk control factor of at least one dimension corresponding to the risk control information to be verified can be achieved in the following way: first, determine the first target risk control tag corresponding to the risk control information to be verified; then, obtain the risk control tag set for the user; next, determine the second target risk control tag from the first target risk control tag, the second target risk control tag belonging to the risk control tag set; finally, determine the risk control factor of at least one dimension corresponding to the second target risk control tag.
[0061] For example, a risk control tag mapping table can be pre-set, which can include multiple risk control tags and the keywords corresponding to each risk control tag. In this way, keywords can be extracted from the risk control information to be verified, and then the risk control tag corresponding to the extracted keywords can be determined based on the risk control tag mapping table, that is, the first target risk control tag.
[0062] In one or more embodiments of this specification, risk control tag sets can be configured separately for different users. The initial risk control tag sets for each user may contain the same risk control tags, and with each subsequent risk control management of a user, the risk control tags in each user's risk control tag set can be updated based on the previous risk control results. In this way, the risk control tags contained in the risk control tag sets of different users may be different, thereby enabling the use of different dimensions of risk control factors for internal risk control verification for different users.
[0063] For example, if a user's total security score in their previous risk control result is higher than the first security score threshold, the number of risk control tags in that user's risk control tag set can be reduced. This allows for quick internal risk control verification for users with high security. Conversely, if a user's total security score in their previous risk control result is lower than the second security score threshold, the number of risk control tags in that user's risk control tag set can be increased. This allows for individual risk control verification for users with low security, thereby improving risk control capabilities for them.
[0064] Thus, some risk control tags in the first target risk control tag set may not belong to the user's risk control tag set. Therefore, after determining the first target risk control tag set, we can further determine the risk control tags that belong to the risk control tag set, i.e., the second risk control tag set. Then, we determine at least one dimension of risk control factors corresponding to the second risk control tag set. Each dimension of risk control factors can correspond to one or more second risk control tags.
[0065] It should be noted that before executing step S104, basic verification and cross-verification can be performed on the risk control information to be verified; if the basic verification and cross-verification pass, step S104 is executed. For example, basic verification may include checking whether there are missing items or errors in the risk control information to be verified. Cross-verification can be used to verify the consistency relationship between different risk control information in the risk control information to be verified.
[0066] S106, based on the risk control rules and / or risk control models corresponding to the risk control factors of each dimension, perform internal risk control verification on the risk control information to be verified, and obtain the internal risk control verification results corresponding to the risk control factors of each dimension.
[0067] One or more embodiments in this specification can pre-configure corresponding risk control rules or risk control models for each dimension of risk control factors. For example, some dimensions of risk control factors are configured with corresponding risk control rules, while other dimensions of risk control factors are configured with corresponding risk control models. Another example is that all dimensions of risk control factors are configured with corresponding risk control models. Yet another example is that all dimensions of risk control factors are configured with corresponding risk control rules.
[0068] In one possible implementation, internal risk control verification of the risk control information to be verified is performed based on the risk control rules corresponding to the risk control factors of each dimension. This can be achieved as follows: First, determine the risk control rules corresponding to the risk control factors of each dimension. The risk control rules include verification items, verification conditions corresponding to each verification item, and verification results corresponding to each verification condition. Then, extract the target risk control information corresponding to each verification item from the risk control information to be verified. Next, determine the target verification conditions that each target risk control information satisfies. And, determine the target verification results corresponding to each verification condition. Finally, aggregate the target verification results to obtain the internal risk control verification results corresponding to the risk control factors of each dimension.
[0069] In this way, the verification items and verification conditions can be dynamically configured to adapt to the risk control needs of different scenarios.
[0070] One possible implementation involves performing internal risk control verification on the risk control information to be verified based on the risk control models corresponding to the risk control factors of each dimension. This can be achieved as follows: the risk control information to be verified is input into the risk control models corresponding to the risk control factors of each dimension. Then, the risk control models corresponding to the risk control factors of each dimension output their respective internal risk control verification results.
[0071] In this way, by utilizing risk control rules and / or risk control models to conduct internal risk control verification of the risk control information to be verified based on multiple dimensions of risk control factors, it is possible to more comprehensively assess risks and reduce the limitations of single-dimensional assessments. On the other hand, compared to relying on external risk control services for risk control verification, internal risk control verification is faster and more real-time, eliminating the need for users to wait for verification results for extended periods, thereby improving transaction conversion rates.
[0072] It should be noted that the risk control models corresponding to the risk control factors in each dimension can be pre-trained risk control models, and this specification does not limit this in one or more embodiments. For specific training of the risk control models, please refer to relevant technologies, which will not be elaborated here.
[0073] S108. Based on the internal risk control verification results corresponding to the risk control factors of each dimension, calculate the first safety score corresponding to the risk control factors of each dimension.
[0074] Each risk control factor can be converted into a safety score based on its own safety score conversion rules. For example, risk control factors with different levels of internal risk control verification results can each have a different safety score. Another example is risk control factors with either passed or failed verification results; a passed verification corresponds to a certain safety score, while a failed verification may result in no safety score or a negative safety score.
[0075] For example, taking a user's risk control factors of at least one dimension, including customer risk factors and traffic risk factors, the internal risk control verification result corresponding to the customer risk factor is that the customer risk is level one, and the first security score corresponding to level one customer risk is X1. The internal risk control verification result corresponding to the traffic risk factor is that the verification is passed, and the first security score corresponding to the verification is X2.
[0076] S110 determines the target risk code based on the first safety score corresponding to each risk control factor in each dimension.
[0077] One or more embodiments of this specification can pre-classify risk types, and each risk type corresponds to a risk code. For example, risk types include: untrusted person, requires facial verification, and no risk, where the risk code corresponding to untrusted person is RSK0010001, the risk code corresponding to requiring facial verification is RSK0010002, and the risk code corresponding to no risk is RSK0010003.
[0078] Different risk codes can be matched with the first security score corresponding to one or more risk control factors. For example, if the total security score of all risk control factors is higher than the first security score threshold, the target risk code is "no risk"; if the total security score of all risk control factors is lower than the second security score threshold, the target risk code is "untrustworthy"; if the total security score of all risk control factors is between the first and second security score thresholds, and the security score corresponding to the customer risk factor is lower than the third security score threshold, the target risk code is "requires facial verification".
[0079] By quantifying the internal risk control verification results into a first security score, it becomes easier to dynamically match the corresponding risk code based on the first security score, thus quickly identifying the corresponding risk type. This allows for further risk control measures to be implemented for specific risk types.
[0080] S112, when the target risk code represents the first risk type, call the external risk control service corresponding to the first risk type to perform external risk control verification on the risk control information to be verified, and obtain the external risk control verification result.
[0081] In one or more embodiments of this specification, after receiving the feedback target risk code, the user rights center can perform a matching operation based on the risk type corresponding to the received target risk code.
[0082] Among them, risk types that require further risk control verification through external risk control services can be called the first risk type; risk types that do not require further risk control verification and whose characterization verification passes can be called the second risk type; and risk types that do not require further risk control verification and whose characterization verification fails can be called the third risk type.
[0083] For example, if the target risk code represents the first risk type, and the target risk code requires facial verification, the Member Rights Center can call an external facial verification service to perform facial verification on the user and obtain the external risk control verification result.
[0084] As another example, when the target risk code represents a second risk type, taking the target risk code representing no risk as an example, the Membership Rights Center can issue corresponding membership rights to users.
[0085] As another example, when the target risk code represents a third type of risk, taking the example that the target risk code represents an untrustworthy person, the Member Rights Center can send a notification to the user that the member rights request failed.
[0086] In this way, by quantifying internal risk control verification results into security scores and dynamically matching corresponding risk codes based on these scores, different risk control verification operations can be executed according to the risk type corresponding to different risk codes. This improves the flexibility of the risk control scheme and enables personalized risk control. Furthermore, after internal risk control verification identifies risks requiring facial verification, further verification by calling the corresponding external risk control service can more accurately identify genuine risks, avoid misjudging legitimate users, improve user experience, and reduce the false positive rate.
[0087] S114, based on the external risk control verification results, the second security score is calculated.
[0088] Similarly, external risk control verification results can be converted into security scores based on the corresponding security score conversion rules. Please refer to the description of step S108 for details, which will not be repeated here.
[0089] S116, based on each first security score and second security score, determine the risk control result corresponding to the user.
[0090] In one possible implementation, the risk control result corresponding to the user is determined based on each first security score and second security score. This can be achieved by: determining the security weight value corresponding to each first security score and second security score respectively; then, using each security weight value, weighting the first security score and second security score to obtain the total security score.
[0091] For example, taking a user's risk control factors at least in one dimension, including customer risk factors and traffic risk factors, as an example, the security weight value corresponding to the customer risk factor is W1, the security weight value corresponding to the traffic risk factor is W2, and the security weight value corresponding to the second security score is W3. The first security score after conversion from the internal risk control verification result corresponding to the customer risk factor is X1, and the first security score after conversion from the internal risk control verification result corresponding to the traffic risk factor is X2. The second security score is X3. Thus, the user's total security score is (W1... · X1+W2 · X2+W3 · X3).
[0092] Then, based on the user's total security score and a security score threshold, the corresponding risk control result for the user can be determined. For example, if the total security score is greater than the security score threshold, the corresponding membership benefits can be issued to the user. If the total security score is less than or equal to the security score threshold, the user can be notified that the membership benefit request failed. If the total security score is less than the security score threshold, it can also be recorded as a risk event and saved in the log.
[0093] In this way, by outputting complex risk control results as security scores, the user's security credibility can be displayed more intuitively, enhancing the interpretability of the risk control solution.
[0094] Optionally, one or more embodiments of this specification may also receive security events related to membership rights; calculate a third security score based on the security events; and then update the user risk control tag set based on the first security score, the second security score, and the third security score.
[0095] For example, the system can receive feedback from other channels or applications regarding security events related to membership benefits performed by the user. For instance, the system may receive feedback from other channels or applications regarding large points rewards or partner points exchange events for that user.
[0096] Different security events correspond to different security scores. For example, a large points reward event corresponds to a third security score of +1, while a partner points exchange event corresponds to a third security score of -3. This allows for updating a user's total security score based on security events. Furthermore, the user's risk control tag set is updated based on the updated total security score.
[0097] In this way, by synchronizing internal and external behaviors, a closed loop of behavior and feedback is formed. The system can continuously adjust its risk control plan based on user behavior and feedback, thereby achieving self-optimization.
[0098] Optionally, in one or more embodiments of this specification, the external risk control verification results and security events can be cached in a message queue. Then, the security score calculation unit can consume the message queue and calculate a second security score based on the obtained external risk control verification results, and calculate a third security score based on the obtained security events.
[0099] In this way, internal and external risk control logic can be executed asynchronously, thereby improving the system's response speed and flexibility.
[0100] This specification describes a risk control method for one or more implementations of the membership benefits service. First, it identifies at least one risk control factor requiring user risk control verification. Then, it performs internal risk control verification on the identified risk control factor and converts the internal verification result into a first security score. Next, it uses the first security score to determine a target risk code. Then, it executes different risk control methods based on different target risk codes. For example, if the target risk code represents a first risk type, it calls the corresponding external risk control service to perform external risk control verification on the risk control information to be verified, obtaining the external risk control verification result; this result is then converted into a second security score. Finally, based on the first and second security scores, it determines the corresponding risk control result for the user.
[0101] In this way, firstly, by quantifying the internal risk control verification results as a security score, it is possible to dynamically match the risk code corresponding to the user based on the security score. Then, based on the risk characteristics of the user, further risk control verification operations can be performed, thereby improving the flexibility of the risk control plan and realizing personalized risk control.
[0102] Secondly, by updating the risk control tags in each user's risk control tag set based on their previous risk control results, the system ensures that different users have different risk control tags in their sets. This allows for the application of different risk control factors for internal risk control verification tailored to different users. Furthermore, by introducing a second security score and a third security score to update the risk control tags in a user's risk control tag set, and through the synchronization of internal and external channel behaviors, a closed loop of behavior and feedback is formed. The system can continuously adjust its risk control plan based on user behavior and feedback, thereby achieving self-optimization.
[0103] Third, by combining internal and external risk control verification, we can more accurately identify real risks, avoid misjudging normal users, thereby improving user experience and reducing the false positive rate.
[0104] Fourth, by utilizing risk control rules and / or risk control models, internal risk control verification is performed on the risk control information to be verified using multiple dimensions of risk control factors. On the one hand, this allows for a more comprehensive assessment of risk and reduces the limitations of single-dimensional assessment. On the other hand, compared to relying on external risk control services for risk control verification, internal risk control verification is faster and more real-time, eliminating the need for users to wait for verification results for extended periods, thus improving transaction conversion rates.
[0105] It is understood that the above embodiments are merely examples, and modifications can be made to the above embodiments in actual implementation. Those skilled in the art will understand that any modifications to the above embodiments that do not require creative effort fall within the protection scope of one or more embodiments of this specification, and will not be described again in the embodiments.
[0106] Based on the same inventive concept, one or more embodiments of this specification also provide a risk control device for membership rights services. Since the principle by which this device solves the problem is similar to the aforementioned method, the implementation of the risk control device for membership rights services can refer to the implementation of the aforementioned risk control method for membership rights services, and repeated details will not be described again.
[0107] See Figure 4 , Figure 4 This is a structural block diagram of a risk control device for a membership benefits service provided in one or more embodiments of this specification. Figure 4 As shown, the risk control device 300 for the membership benefits service may include: an acquisition module 301, a first determination module 302, an internal risk control verification module 303, a security score calculation module 304, a second determination module 305, an external risk control verification module 306, and a third determination module 307. Among them,
[0108] The acquisition module 301 is used to obtain the user's corresponding risk control information to be verified in response to receiving the user's membership rights request;
[0109] The first determining module 302 is used to determine at least one dimension of risk control factors corresponding to the risk control information to be verified;
[0110] The internal risk control verification module 303 is used to perform internal risk control verification on the risk control information to be verified based on the risk control rules and / or risk control models corresponding to the risk control factors of each dimension, and to obtain the internal risk control verification results corresponding to the risk control factors of each dimension.
[0111] The security score calculation module 304 is used to calculate the first security score corresponding to each risk control factor based on the internal risk control verification results corresponding to each risk control factor in each dimension.
[0112] The second determination module 305 is used to determine the target risk code based on the first safety score corresponding to each risk control factor in each dimension.
[0113] The external risk control verification module 306 is used to call the external risk control service corresponding to the first risk type to perform external risk control verification on the risk control information to be verified when the target risk code represents the first risk type, and obtain the external risk control verification result.
[0114] The safety score calculation module 304 is also used to calculate the second safety score based on the external risk control verification results;
[0115] The third determination module 307 is used to determine the risk control result corresponding to the user based on each first security score and second security score.
[0116] In one possible implementation, the first determining module 302 is specifically used for: determining a first target risk control label corresponding to the risk control information to be verified; obtaining a set of risk control labels for the user; determining a second target risk control label from the first target risk control label, wherein the second target risk control label belongs to the risk control label in the risk control label set; and determining at least one dimension of risk control factor corresponding to the second target risk control label.
[0117] In one possible implementation, the device further includes an update module for updating the user risk control tag set based on each first security score and second security score.
[0118] In one possible implementation, the internal risk control verification module 303 is specifically used to: determine the risk control rules corresponding to each dimension of risk control factors, wherein the risk control rules include verification items, verification conditions corresponding to each verification item, and verification results corresponding to each verification condition; extract the target risk control information corresponding to each verification item from the risk control information to be verified; determine the target verification conditions satisfied by each target risk control information; determine the target verification results corresponding to each verification condition; and aggregate the target verification results to obtain the internal risk control verification results corresponding to each dimension of risk control factors.
[0119] In one possible implementation, the device further includes:
[0120] The receiving module is used to receive security events related to member rights;
[0121] The security score calculation module 304 is also used to calculate a third security score based on security events;
[0122] The update module is used to update the user risk control tag set based on each first security score, second security score, and third security score.
[0123] In one possible implementation, the device further includes:
[0124] The distribution module is used to distribute corresponding membership benefits to users when the target risk code represents a second risk type.
[0125] The notification module is used to notify users of failed membership benefit requests when the target risk code represents a third risk type.
[0126] In one possible implementation, the third determining module 307 is specifically used to determine the user's total security score based on each first security score and second security score; if the total security score is greater than the security score threshold, to issue corresponding membership benefits to the user; if the total security score is less than or equal to the security score threshold, to send a notification to the user that the membership benefit request failed.
[0127] See Figure 5 , Figure 5 This is a structural block diagram of an electronic device provided for one or more embodiments of this specification. Figure 5 As shown, the electronic device 400 may include a processor 401 and a memory 402; the memory 402 may be coupled to the processor 401. It is worth noting that... Figure 5 This is an example; other types of structures can also be used to supplement or replace this structure to achieve telecommunications functions or other functions.
[0128] In one possible implementation, the function of the risk control device 300 for membership benefits services can be integrated into the processor 401. The processor 401 can be configured to perform the following operations:
[0129] In response to receiving a user's membership benefit request, the system obtains the user's risk control information to be verified; determines at least one risk control factor corresponding to the risk control information to be verified; performs internal risk control verification on the risk control information to be verified based on the risk control rules and / or risk control models corresponding to each risk control factor, and obtains the internal risk control verification results corresponding to each risk control factor; calculates a first security score corresponding to each risk control factor based on the internal risk control verification results corresponding to each risk factor; determines a target risk code based on the first security score corresponding to each risk factor; if the target risk code represents a first risk type, calls the external risk control service corresponding to the first risk type to perform external risk control verification on the risk control information to be verified, and obtains the external risk control verification result; calculates a second security score based on the external risk control verification result; and determines the risk control result corresponding to the user based on the first security score and the second security score.
[0130] In another possible implementation, the risk control device 300 for membership benefits services can be configured separately from the processor 401. For example, the risk control device 300 for membership benefits services can be configured as a chip connected to the processor 401, and the risk control of membership benefits services can be achieved through the control of the processor 401.
[0131] Furthermore, in some alternative implementations, the electronic device 400 may also include: a communication module, an input unit, an audio processor, a display, a power supply, etc. It is worth noting that the electronic device 400 is not necessarily required to include these components. Figure 5 All components shown; in addition, the electronic device 400 may also include Figure 5 For components not shown, please refer to existing technologies.
[0132] In some alternative implementations, the processor 401, sometimes also referred to as a controller or operating control, may include a microprocessor or other processor device and / or logic device, which receives input and controls the operation of various components of the electronic device 400.
[0133] The memory 402 may be, for example, one or more of a cache, flash memory, hard drive, removable media, volatile memory, non-volatile memory, or other suitable devices. It may store information related to the risk control device 300 for membership benefits services, and may also store programs for executing that information. The processor 401 may execute the program stored in the memory 402 to perform information storage or processing, etc.
[0134] An input unit can provide input to the processor 401. This input unit may be, for example, a button or touch input device. A power supply can be used to provide power to the electronic device 400. A display can be used to display images and text, etc. This display may be, for example, an LCD display, but is not limited to this.
[0135] Memory 402 can be a solid-state memory, such as read-only memory (ROM), random access memory (RAM), SIM card, etc. It can also be a memory that retains information even when power is off, can be selectively erased, and contains more data; examples of this type of memory are sometimes referred to as EPROM, etc. Memory 402 can also be some other type of device. Memory 402 includes buffer memory (sometimes referred to as a buffer). Memory 402 may include an application / function storage unit for storing application programs and function programs or processes for executing the operation of electronic device 400 via processor 401.
[0136] The memory 402 may also include a data storage unit for storing data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit of the memory 402 may include various drivers for the computer device for communication functions and / or for performing other functions of the computer device (such as messaging applications, address book applications, etc.).
[0137] The communication module is a transmitter / receiver that sends and receives signals via an antenna. The communication module (transmitter / receiver) is coupled to the processor 401 to provide input signals and receive output signals, which is the same as in a conventional mobile communication terminal.
[0138] Based on different communication technologies, multiple communication modules can be configured in the same computer device, such as cellular network modules, Bluetooth modules, and / or wireless LAN modules. The communication module (transmitter / receiver) is also coupled to a speaker and microphone via an audio processor to provide audio output through the speaker and receive audio input from the microphone, thereby enabling typical telecommunications functions. The audio processor may include any suitable buffer, decoder, amplifier, etc. Additionally, the audio processor is coupled to processor 401, enabling on-device recording via the microphone and on-device playback of stored sound via the speakers.
[0139] One or more embodiments of this specification also provide a computer-readable storage medium capable of implementing all steps of the risk control method for membership benefits services in the above embodiments. The computer-readable storage medium stores a computer program that, when executed by a processor, implements all steps of the risk control method for membership benefits services in the above embodiments.
[0140] While one or more embodiments of this specification provide method operation steps as shown in the embodiments or flowcharts, more or fewer operation steps may be included based on conventional or non-inventive labor. The order of steps listed in the embodiments is merely one possible execution order among many and does not represent the only execution order. In actual device or client product execution, the method can be executed sequentially as shown in the embodiments or drawings, or in parallel (e.g., in a parallel processor or multi-threaded processing environment).
[0141] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, apparatus (systems), or computer program products. Therefore, the embodiments of this specification can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, one or more embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0142] This specification describes one or more embodiments of a method, apparatus (system), and computer program product according to one or more embodiments of this specification with reference to flowchart illustrations and / or block diagrams. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0143] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0144] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0145] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the device and system embodiments are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0146] In this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, without necessarily requiring or implying any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Those skilled in the art will understand the specific meaning of the above terms in one or more embodiments of this specification, depending on the specific circumstances.
[0147] It should be noted that, unless otherwise specified, one or more embodiments and features thereof in this specification can be combined with each other. This specification is not limited to any single aspect, nor to any single embodiment, nor to any combination and / or substitution of such aspects and / or embodiments. Furthermore, each aspect and / or embodiment of one or more embodiments of this specification can be used alone or in combination with one or more other aspects and / or embodiments thereof.
[0148] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of one or more embodiments of this specification, and are not intended to limit them. Although one or more embodiments of this specification have been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of one or more embodiments of this specification, and they should all be covered within the scope of the claims and the specification of one or more embodiments of this specification.
[0149] The foregoing description of one or more embodiments of this specification has been provided in conjunction with optional implementation methods. However, these embodiments are merely exemplary and serve only an illustrative purpose. Based on this, various substitutions and modifications can be made to one or more embodiments of this specification, all of which fall within the protection scope of one or more embodiments of this specification.
Claims
1. A risk control method for membership benefits services, characterized in that, The method includes: In response to receiving a user's request for membership benefits, obtain the risk control information to be verified for the user; Based on the risk control information to be verified and the user's risk control tag set, at least one risk control factor of the user needs to be verified is determined from multiple risk control factors; wherein, risk control tag sets are configured for different users. Based on the risk control rules and / or risk control models corresponding to the risk control factors of each dimension, the risk control information to be verified is internally verified to obtain the internal risk control verification results corresponding to the risk control factors of each dimension. Based on the internal risk control verification results corresponding to the risk control factors of each dimension, calculate the first security score corresponding to the risk control factors of each dimension. The target risk code is determined based on the first safety score corresponding to each risk control factor in each dimension. When the target risk code represents the first risk type, the external risk control service corresponding to the target risk code is invoked to perform external risk control verification on the risk control information to be verified, and the external risk control verification result is obtained. Based on the external risk control verification results, the second security score is calculated; Based on the first security score and the second security score, the risk control result corresponding to the user is determined; If the total security score of the first security score and the second security score is higher than the first security score threshold, the number of risk control tags in the user's risk control tag set is reduced; if the total security score of the first security score and the second security score is lower than the second security score threshold, the number of risk control tags in the user's risk control tag set is increased.
2. The method according to claim 1, characterized in that, Based on the risk control information to be verified and the user's risk control tag set, at least one risk control factor of the user needs to be verified from multiple risk control factors, including: Determine the first target risk control tag corresponding to the risk control information to be verified; Obtain the set of risk control tags for the user; A second target risk control label is determined from the first target risk control label, wherein the second target risk control label belongs to the risk control label set; Determine at least one dimension of risk control factors corresponding to the second target risk control label.
3. The method according to claim 1, characterized in that, Based on the risk control rules corresponding to the risk control factors of each dimension, the risk control information to be verified is subjected to internal risk control verification to obtain the internal risk control verification results, including: Determine the risk control rules corresponding to each risk control factor in each dimension. The risk control rules include verification items, verification conditions corresponding to each verification item, and verification results corresponding to each verification condition. Extract the target risk control information corresponding to each of the verification items from the risk control information to be verified; Determine the target verification conditions that each of the target risk control information segments must satisfy; Determine the target verification result corresponding to each of the aforementioned verification conditions; The verification results of each target are aggregated to obtain the internal risk control verification results corresponding to each risk control factor in each dimension.
4. The method according to claim 2, characterized in that, The method further includes: Receive security incidents related to the aforementioned membership benefits; Based on the aforementioned security events, a third security score is calculated. The user risk control tag set is updated based on the first security score, the second security score, and the third security score.
5. The method according to any one of claims 1 to 4, characterized in that, The method further includes: When the target risk code represents a second risk type, corresponding membership benefits are issued to the user; If the target risk code indicates a third risk type, a notification of failure to request membership benefits will be sent to the user.
6. The method according to claim 1, characterized in that, The step of determining the risk control result corresponding to the user based on each of the first security score and the second security score includes: Based on the first security score and the second security score, the user's total security score is determined; If the total security score is greater than the security score threshold, the corresponding membership benefits will be issued to the user. If the total security score is less than or equal to the security score threshold, a notification of failure to request membership benefits will be sent to the user.
7. A risk control device for membership benefits services, characterized in that, The device includes: The acquisition module is used to obtain the risk control information to be verified corresponding to the user in response to receiving a user's membership rights request; The first determining module is used to determine at least one risk control factor that the user needs to verify from multiple risk control factors based on the risk control information to be verified and the user's risk control tag set; wherein, risk control tag sets are configured for different users. The internal risk control verification module is used to perform internal risk control verification on the risk control information to be verified based on the risk control rules and / or risk control models corresponding to the risk control factors of each dimension, and to obtain the internal risk control verification results corresponding to the risk control factors of each dimension. The security score calculation module is used to calculate the first security score corresponding to each risk control factor based on the internal risk control verification results corresponding to each risk control factor in each dimension. The second determination module is used to determine the target risk code based on the first safety score corresponding to each risk control factor in each dimension. The external risk control verification module is used to call the external risk control service corresponding to the target risk code to perform external risk control verification on the risk control information to be verified when the target risk code represents the first risk type, and obtain the external risk control verification result. The security score calculation module is also used to calculate a second security score based on the external risk control verification results; The third determining module is used to determine the risk control result corresponding to the user based on each of the first security score and the second security score; The update module is used to reduce the risk control tags in the user's risk control tag set when the total security score of the first security score and the second security score is higher than the first security score threshold; and to increase the risk control tags in the user's risk control tag set when the total security score of the first security score and the second security score is lower than the second security score threshold.
8. The apparatus according to claim 7, characterized in that, The first determining module is specifically used for: determining a first target risk control tag corresponding to the risk control information to be verified; obtaining a set of risk control tags for the user; determining a second target risk control tag from the first target risk control tag, wherein the second target risk control tag belongs to the risk control tag in the set of risk control tags; and determining at least one dimension of risk control factor corresponding to the second target risk control tag.
9. The apparatus according to claim 7, characterized in that, The internal risk control verification module is specifically used for: determining the risk control rules corresponding to each dimension of risk control factors, wherein the risk control rules include verification items, verification conditions corresponding to each verification item, and verification results corresponding to each verification condition; extracting target risk control information corresponding to each verification item from the risk control information to be verified; determining the target verification conditions satisfied by each target risk control information; determining the target verification results corresponding to each verification condition; and aggregating the target verification results to obtain the internal risk control verification results corresponding to each dimension of risk control factors.
10. The apparatus according to claim 8, characterized in that, The device further includes: The receiving module is used to receive security events related to the member's rights and interests; The security score calculation module is also used to calculate a third security score based on the security event; The update module is used to update the user risk control tag set based on each of the first security score, the second security score, and the third security score.
11. An electronic device, characterized in that, The electronic device includes: Memory, used to store computer program products; A processor is configured to execute a computer program product stored in the memory, wherein, when the computer program product is executed, it implements the method described in any one of claims 1-6.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions, which, when executed, implement the method described in any one of claims 1-6.