Cancellation after verification risk identification method and device, and storage medium

By receiving verification requests, obtaining identification information and verification information, querying the history of verification card, using the verification rule engine and behavior analysis model to identify risks, and only performing verification actions when the risk identification passes, solving the problem of easy stolen card fraud, realizing the balance of security and convenience.

CN120374119AActive Publication Date: 2025-07-25SHENZHEN QIYUN INFORMATION TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510847887.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-07-25
Estimated Expiration
2045-06-24

AI Technical Summary

Technical Problem

The verification card is easily stolen, resulting in high risks and hidden dangers during the verification process.

Method used

By receiving the verification request, obtaining identification information and verification information, querying the history of the verification card, using the verification rule engine and behavior analysis model to identify risks, and performing verification actions only when the risk identification passes.

Benefits of technology

It significantly improves the security of the verification process, ensures the security of convenient verification methods such as facial recognition and QR code recognition, and provides a more secure and efficient verification experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120374119A_ABST
    Figure CN120374119A_ABST
Patent Text Reader

Abstract

The invention discloses a cancel-after-verification risk identification method and device and a storage medium, and belongs to the technical field of cancel-after-verification systems. The method comprises the steps of receiving a cancel-after-verification request, obtaining identification information and cancel-after-verification information in the cancel-after-verification request, querying a cancel-after-verification card corresponding to the identification information, obtaining a historical cancel-after-verification record of the cancel-after-verification card, loading a risk identification rule through a cancel-after-verification rule engine, performing risk identification on the historical cancel-after-verification record and the cancel-after-verification information, and obtaining risk assessment information. And identifying abnormal interaction information in the cancel-after-verification request through the behavior analysis model, adjusting the risk assessment information according to the abnormal interaction information, determining a risk identification result, and executing a cancel-after-verification action of the cancel-after-verification card based on the cancel-after-verification information when the risk identification result is successful. According to the method, the potential risk in the verification process is evaluated by introducing the risk identification rule, so that the potential safety hazard caused by verification only depending on basic information is avoided, and the safety of the verification process is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of write-off systems, and particularly to a risk identification method, device, and storage medium for write-off. Background Art

[0002] Based on the high compatibility and data processing capabilities of big data and cloud technology, the write-off card and the write-off platform can provide users with various different write-off methods such as face recognition, inputting the card number, or QR code recognition, etc., to improve the convenience during the use of the write-off card.

[0003] However, the convenient write-off method also brings potential security risks of being easily stolen and swiped. In this case, non-owners of the write-off card can also perform the act of stealing and swiping the write-off card through the write-off identification information corresponding to any write-off card. This results in a relatively high risk during the write-off process of the write-off card.

[0004] The above content is only used to assist in understanding the technical solution of this application, and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main purpose of this application is to provide a risk identification method, device, and storage medium for write-off, aiming to solve the technical problem of relatively high risk during the write-off process due to the easy theft and swiping of the write-off card.

[0006] To achieve the above purpose, this application provides a risk identification method for write-off, and the method includes the following steps: Receive a write-off request, and obtain the identification information and write-off information in the write-off request; Query the write-off card corresponding to the identification information, and obtain the historical write-off records of the write-off card; Load risk identification rules through a write-off rule engine, perform risk identification on the historical write-off records and the write-off information, and obtain risk assessment information; Identify abnormal interaction information in the write-off request through a behavior analysis model, and adjust the risk assessment information according to the abnormal interaction information to determine the risk identification result; When the risk identification result is passed, perform the write-off action of the write-off card based on the write-off information.

[0007] In an embodiment, the step of loading risk identification rules through a write-off rule engine, performing risk identification on the historical write-off records and the write-off information, and obtaining risk assessment information includes: Obtain the write-off location in the write-off information, and obtain the target write-off time and target write-off location corresponding to the target historical write-off record in the historical write-off records; Use the current system time as the verification time of the verification information, and determine the verification time interval between the verification time and the target verification time; When the verification time interval is less than the time interval threshold, calculate the verification distance between the verification position and the target verification position; If the verification distance is greater than the distance threshold, determine that there is a risk in the verification information.

[0008] In one embodiment, the step of identifying abnormal interaction information in the verification request through the behavior analysis model, adjusting the risk assessment information according to the abnormal interaction information, and determining the risk identification result further includes: Collect the interaction data corresponding to the verification request, and generate an interaction time series and an interaction operation trajectory according to the interaction time corresponding to the interaction data; Use the interaction time series and the interaction operation trajectory as the operation behavior data of the verification request, and input them into a pre-trained behavior analysis model to obtain an abnormal operation probability value; When the abnormal operation probability value exceeds the probability threshold, trigger an identity verification action based on biometrics; Adjust the risk assessment information according to the verification result of the identity verification action, and determine the risk identification result.

[0009] In one embodiment, the step of using the interaction time series and the interaction operation trajectory as the operation behavior data of the verification request, inputting them into a pre-trained behavior analysis model, and obtaining an abnormal operation probability value includes: Extract operation feature data according to the behavior heat distribution map corresponding to the operation behavior data, as well as the interaction time series and the interaction operation trajectory; Match the operation feature data with preset abnormal operation features to obtain the matching degree of the operation feature data; Based on preset weight values, perform a weighted sum calculation on the matching degrees of different operation feature data to obtain the abnormal operation probability value.

[0010] In one embodiment, after the step of identifying abnormal interaction information in the verification request through the behavior analysis model, adjusting the risk assessment information according to the abnormal interaction information, and determining the risk identification result, it further includes: When the risk identification result is that there is a risk in the verification information, output an identity verification request; Obtain the feedback information of the identity verification request, and perform the identity verification action corresponding to the feedback information to obtain identity verification information; Compare the verification card information of the verification card with the identity verification information to obtain an identity verification result; When the authentication result is passed, perform the write-off action of the write-off information.

[0011] In one embodiment, the steps of obtaining the feedback information of the authentication request and performing the authentication action corresponding to the feedback information to obtain the authentication information include: In the feedback information, obtain the device information of the write-off terminal; According to the device information, determine the candidate verification policies and determine the priorities of the candidate verification policies; Based on the priorities, select the target verification policy from the candidate verification policies; Perform the authentication action corresponding to the target verification policy to obtain the authentication information.

[0012] In one embodiment, the steps of querying the write-off card corresponding to the identification information and obtaining the historical write-off records of the write-off card include: Based on the identification information field in the write-off request, identify the identification information type of the identification information, where the identification information type includes biometric information, identity identification information, and / or write-off card identification information; Based on the identification information type, query the write-off card corresponding to the identification information in the database; Obtain the write-off card information of the write-off card and the historical write-off records in the write-off card information.

[0013] In one embodiment, after the steps of querying the write-off card corresponding to the identification information and obtaining the historical write-off records of the write-off card, it further includes: Obtain the user identity information corresponding to the write-off card and determine the target write-off card associated with the user identity information; In the target write-off card information of the target write-off card, obtain the cross-card historical write-off records corresponding to the user identity information; According to the risk identification rules and the cross-card historical write-off records, perform cross-card risk identification on the write-off information; Incorporate the identification result of the cross-card risk identification into the risk assessment information.

[0014] In addition, to achieve the above object, the present application further provides a risk identification device for write-off, and the device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the risk identification method for write-off as described above.

[0015] In addition, to achieve the above object, the present application also provides a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium, and when the computer program is executed by a processor, the steps of the risk identification method for verification as described above are implemented.

[0016] One or more technical solutions proposed by the present application have at least the following technical effects: By receiving a verification request, obtaining the identification information and verification information therein, then querying the corresponding verification card, obtaining its historical verification records, and performing risk identification on the verification card and verification information based on the risk identification rules and historical verification records, and only performing the verification action when the risk identification passes. Thus, by introducing the risk identification rules, the potential risks in the verification process are evaluated, avoiding the security risks caused by relying solely on basic information verification, and significantly improving the security of the verification process. At the same time, on the basis of ensuring security, this solution can still support a variety of convenient verification methods, such as face recognition, inputting the card number or QR code recognition, etc., which not only meets the user's demand for convenience but also ensures the reliability of the verification process, thereby providing a more secure and efficient verification experience for users and merchants. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present application and, together with the specification, are used to explain the principles of the present application.

[0018] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0019] Figure 1 It is a schematic flowchart of the first embodiment of the risk identification method for verification of the present application; Figure 2 It is a schematic flowchart of the second embodiment of the risk identification method for verification of the present application; Figure 3 It is a schematic flowchart of the third embodiment of the risk identification method for verification of the present application; Figure 4 It is a schematic flowchart of the fourth embodiment of the risk identification method for verification of the present application; Figure 5 It is a schematic flowchart of the fifth embodiment of the risk identification method for verification of the present application; Figure 6 It is a schematic structural diagram of the risk identification device for verification of the hardware operating environment involved in the solution of the embodiment of the present application.

[0020] The realization, functional features and advantages of the present application will be further described in conjunction with embodiments and with reference to the accompanying drawings. Detailed implementation manners

[0021] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0022] In order to better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the drawings of the specification and specific implementation manners.

[0023] The main solution of the embodiment of the present application is: receiving a verification request, obtaining the identification information and verification information in the verification request; querying the verification card corresponding to the identification information, and obtaining the historical verification record of the verification card; loading a risk identification rule through a verification rule engine, performing risk identification on the historical verification record and the verification information to obtain risk assessment information; identifying abnormal interaction information in the verification request through a behavior analysis model, and adjusting the risk assessment information according to the abnormal interaction information to determine a risk identification result; when the risk identification result is passed, performing a verification action on the verification card based on the verification information.

[0024] In the related art, while the verification card and the verification platform provide users with a variety of different convenient verification methods such as face recognition, inputting a card number or two-dimensional code recognition, etc., it also brings potential security risks of being easily stolen and swiped. In this case, non-owners of the verification card can also perform the act of stealing and swiping the verification card through the verification identification information corresponding to any verification card. This leads to a relatively high risk hidden danger in the verification process of the verification card.

[0025] The present application receives a verification request, obtains the identification information and verification information therein, then queries the corresponding verification card, obtains its historical verification record, and performs risk identification on the verification card and the verification information based on the risk identification rule and the historical verification record, and only performs the verification action when the risk identification passes. Thus, through the introduction of the risk identification rule, the potential risks in the verification process can be comprehensively evaluated, avoiding the security hidden danger caused by only relying on basic information verification, and significantly improving the security of the verification process. At the same time, on the basis of ensuring security, this solution can still support a variety of convenient verification methods such as face recognition, inputting a card number or two-dimensional code recognition, etc., which not only meets the user's demand for convenience, but also ensures the reliability of the verification process, thereby providing a more secure and efficient verification experience for users and merchants.

[0026] To better understand the above technical solution, the exemplary embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to enable a more thorough understanding of the present application and to fully convey the scope of the present application to those skilled in the art.

[0027] It should be noted that the execution subject of this embodiment can be a write-off system, or a computing service device with data processing, network communication, and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device capable of implementing the above functions, a risk identification device for write-off, etc. This embodiment does not make specific limitations in this regard. The following takes the write-off system as an example to illustrate this embodiment and the following embodiments.

[0028] Based on this, the embodiments of the present application provide a risk identification method for write-off, referring to Figure 1 , Figure 1 which is a schematic flowchart of the first embodiment of the risk identification method for write-off of the present application.

[0029] In this embodiment, the risk identification method for write-off includes steps S10 to S40: Step S10: Receive a write-off request, and obtain the identification information and write-off information in the write-off request; In this embodiment, the write-off system receives the user's write-off request and performs actions such as retrieving write-off card information and performing write-off. After the user uses the write-off card for consumption or service, the user can submit a write-off request to the write-off system through the write-off terminal. The write-off request contains the write-off information of this transaction and the identification information used to represent the user's identity, so that the write-off system can obtain the relevant information required for this write-off. Among them, the identification information is a unique identifier for identifying the write-off card or the user's identity, such as a card number, user biometric information, or a telephone number. The write-off information contains the detailed data of this write-off, such as the amount, time, location, etc.

[0030] It should be noted that during the process of creating the identification information, when it is necessary to obtain privacy information such as the user's card number, user biometric information, or telephone number as the basis for creating the identification information, a privacy information acquisition authorization process is also set. So that before the user inputs the privacy information, it is clear that the privacy information will be used to generate the corresponding identification information after being acquired.

[0031] Specifically, the write-off system can be deployed on a cloud server. By receiving a write-off request sent by a write-off terminal through a network interface or other means, it performs the write-off action. Alternatively, the write-off system can also be deployed in the write-off terminal. By obtaining the input information of the user, it triggers a write-off request and synchronizes the data to the cloud database after completing the write-off action.

[0032] As an alternative implementation, when the write-off system is deployed on a cloud server, the write-off system receives a write-off request from a write-off terminal through a network interface. The request is sent in the form of an encrypted data packet to ensure the security and integrity of the data. After receiving the request, the system uses a specific decryption algorithm to decrypt the data packet and extracts the identification information and write-off information therein. The identification information is used for subsequent write-off card queries, while the write-off information is used for risk identification and write-off operations.

[0033] Exemplarily, after a user uses a write-off card for payment in a shopping mall, the cashier system generates a write-off request, which includes the user card number as the identification information, as well as write-off information such as the payment amount, time, and cashier location. The request is sent to the cloud server of the write-off risk identification system through the Internet. After receiving the write-off request, the cloud server decrypts and extracts the data to obtain the identification information and write-off information.

[0034] As another alternative implementation, when the write-off system is deployed locally on the write-off terminal, the write-off system can generate write-off information by combining the write-off location and the current system time with the information of the goods to be written off obtained by scanning the barcode by the write-off terminal. At the same time, the write-off system can obtain the identification information authorized by the user by face recognition through a camera device, or by scanning the QR code on the write-off card with a QR code scanner, or by receiving the card number or mobile phone number input by the user, etc., and thus generates a write-off request by combining the identification information and the write-off information.

[0035] Step S20: Query the write-off card corresponding to the identification information and obtain the historical write-off record of the write-off card; In this embodiment, the historical write-off record contains detailed records of all completed write-off actions of the write-off card, including information such as the time, amount, and location of each write-off. The write-off system uses the identification information extracted from the write-off request as a query key to retrieve in the local database or the cloud database. The write-off system locates the corresponding write-off card and write-off card information through the retrieval and obtains the historical write-off record of the write-off card from the write-off card information.

[0036] In one embodiment, the write-off system may extract identification information based on the identification information field in the write-off request and identify the type of identification information corresponding to the identification information. The type of identification information may optionally include biometric information, identity identification information, and / or write-off card identification information. The write-off system may query the write-off card corresponding to the identification information in the corresponding data item of the database based on the type of identification information, obtain the write-off card information of the write-off card, and the historical write-off records in the write-off card information.

[0037] Exemplarily, the write-off system may dynamically carry the original data of the identification information in different write-off methods through the credentials field in the write-off request to achieve compatibility of different write-off methods. The write-off system may identify the type of identification information of the identification information through specific characters in the field, such as the last three characters, and compare the identification information with all information of the same type of identification information in the database to determine the corresponding write-off card and write-off card information.

[0038] In another embodiment, after obtaining the identification information, the write-off system may also directly traverse the corresponding write-off card in the write-off card information stored in the database based on the identification information. Exemplarily, assuming the identification information is the card number "123***78", the system queries in the database with this card number as the index, finds the corresponding write-off card, and obtains the write-off card record, which contains all the write-off records of this card since January 1, 2023, such as consuming 100 yuan in Supermarket A on January 5, 2023, and consuming 200 yuan in Restaurant B on January 10, 2023, etc.

[0039] Step S30: Load the risk identification rules through the write-off rule engine, perform risk identification on the historical write-off records and the write-off information, and obtain risk assessment information; In this embodiment, the write-off system loads, processes, and parses predefined risk identification rules through the write-off rule engine, and realizes the custom configuration and dynamic update of the risk identification rules. The risk identification rules refer to a series of logics and conditions for judging whether there are risks in the write-off operation, including rules such as time interval, geographical location, and consumption amount. The write-off system inputs the historical write-off records and the write-off information into the rule engine, extracts information such as the write-off time, write-off amount, and / or write-off location in the historical write-off records and the write-off information. By loading the preset risk identification rules through the rule engine, based on one or more of the write-off time, the write-off amount, and the write-off location, perform risk identification actions to obtain risk assessment information.

[0040] Specifically, the system starts the write-off rule engine, loads the preset risk identification rules from the configuration file or database, and uses the obtained historical write-off records and write-off information as input data to perform one-by-one comparison and analysis according to multiple preset risk identification rules. The write-off rule engine will judge whether there is a risk based on the logic of the rules. Among them, the write-off rule engine can verify individual information based on whether the write-off amount is greater than the preset amount threshold, or whether the write-off location is within the user's regular activity area, etc., or can also verify multiple pieces of information in combination. For example, it can judge whether there is a situation where the same card is frequently written off at different locations within a short period of time by combining the write-off time and the write-off location.

[0041] As an alternative implementation, step S30 includes steps S31 to S34: Step S31: Obtain the write-off location in the write-off information, and obtain the target write-off time and target write-off location corresponding to the target historical write-off record in the historical write-off records; Step S32: Use the current system time as the write-off time of the write-off information, and determine the write-off time interval between the write-off time and the target write-off time; Step S33: When the write-off time interval is less than the time interval threshold, calculate the write-off distance between the write-off location and the target write-off location; Step S34: If the write-off distance is greater than the distance threshold, judge that the write-off information has a risk.

[0042] In this embodiment, the write-off location is the specific geographical location information where the current write-off operation occurs, usually obtained by the positioning module of the write-off terminal, such as GPS coordinates or base station positioning information, or determined based on the merchant location associated with the write-off terminal in the write-off system. The write-off system can obtain the current system time, use it as the write-off time of the current write-off information, and calculate the difference between the write-off time and the target write-off time in the target historical write-off record to obtain the write-off time interval. By comparing the write-off time interval with the time interval threshold, if the write-off time interval is greater than the time interval threshold, it is judged that the write-off information has no risk, or the risk identification of other contents in the write-off information is performed. If it is less than the threshold, the distance between the write-off location and the target write-off location is further calculated or obtained through the positioning system, and the obtained write-off distance is compared with the distance threshold. When the write-off distance is greater than the distance threshold, since the user cannot cross a long distance in a short period of time, it indicates that the same write-off card has been written off in multiple places within a short period of time, and the write-off system judges that the current write-off information has a risk.

[0043] As another alternative implementation, the write-off system can also identify the individual information in the write-off information and write-off records one by one based on the preset risk identification rules. For example, within the preset time period of the current write-off information, if the number of write-offs is greater than the number threshold, or the total write-off amount is greater than the amount threshold, and the write-off time does not match the corresponding commodity type, etc., the write-off system determines that there is a risk.

[0044] Step S40: Identify the abnormal interaction information in the write-off request through the behavior analysis model, and adjust the risk assessment information according to the abnormal interaction information to determine the risk identification result; In this embodiment, the write-off system can also obtain the interaction information corresponding to the write-off information at the write-off terminal, so as to determine whether the interaction information is abnormal interaction information implemented by a robot or a script program. Among them, a behavior analysis model is deployed in the write-off system, which can obtain the interaction information in the write-off request and identify the abnormal interaction information therein through methods such as time series and trajectory analysis.

[0045] Furthermore, based on the abnormal interaction information, the write-off system will further adjust the risk assessment information to determine the risk identification result.

[0046] Step S50: When the risk identification result is passed, perform the write-off action of the write-off card based on the write-off information.

[0047] In this embodiment, the risk identification result includes passed and there is a risk. Among them, when the risk identification result is that there is a risk, the write-off system will output an abnormal prompt message or perform a secondary verification action. When the risk identification result is passed, the corresponding write-off action is performed based on the write-off information, and the write-off card information is updated by deducting the balance or updating the status, etc.

[0048] Optionally, the write-off system will update the balance, status, etc. of the write-off card according to the data such as the amount and time in the write-off information, and add the current write-off record to the historical write-off records. At the same time, the system may send a write-off success notification to the user terminal to inform the user that the write-off operation has been completed.

[0049] In the embodiment of the present application, by receiving a write-off request, the identification information and write-off information therein are obtained, and then the corresponding write-off card is queried to obtain its historical write-off records. Based on the risk identification rules and historical write-off records, risk identification is performed on the write-off card and write-off information. The write-off action is only executed when the risk identification passes. Thus, by introducing the risk identification rules, potential risks in the write-off process can be comprehensively evaluated, avoiding security risks caused by relying solely on basic information verification, and significantly improving the security of the write-off process. At the same time, on the basis of ensuring security, this solution can still support a variety of convenient write-off methods, such as face recognition, inputting the card number or QR code recognition, etc., which not only meets the user's demand for convenience but also ensures the reliability of the write-off process, thereby providing a safer and more efficient write-off experience for users and merchants.

[0050] Based on the same inventive concept, the present application also provides a second embodiment. Refer to Figure 2 , Figure 2 which is a schematic flowchart of the second embodiment of the risk identification method for write-off of the present application.

[0051] In this embodiment, the risk identification method for write-off further includes steps S35 to S38: Step S35: Collect the interaction data corresponding to the write-off request, and generate an interaction time series and an interaction operation trajectory according to the interaction time corresponding to the interaction data; In this embodiment, when the user interacts with the system during the process of submitting a write-off request, various interaction data will be generated, such as operation records of clicks, inputs, swipes, etc. At the same time, based on the time stamps of each interaction operation, that is, the interaction time, the corresponding time series data is arranged in chronological order, that is, the interaction time series, to reflect the continuity of each interaction data occurrence. Among them, by connecting different interaction actions based on the interaction time series, the corresponding interaction operation trajectory can be obtained. The interaction operation trajectory refers to the trajectory of a series of operation behaviors of the user during the write-off request process, reflecting the user's operation habits and behavior patterns. The write-off system generates an interaction time series by arranging these interaction times in chronological order. At the same time, the interaction operations are combined in sequence to form an interaction operation trajectory.

[0052] Step S36: Use the interaction time series and the interaction operation trajectory as the operation behavior data of the write-off request, and input them into a pre-trained behavior analysis model to obtain an abnormal operation probability value; Step S37: When the abnormal operation probability value exceeds the probability threshold, trigger an identity verification action based on biometrics; Step S38: Adjust the risk assessment information according to the verification result of the identity verification action, and determine the risk identification result.

[0053] In this embodiment, the behavior analysis model is a machine learning model that can identify the probabilities of normal operation behaviors and abnormal operation behaviors through training on a large amount of normal user operation behavior data. Among them, the abnormal operation behaviors include human-machine abnormal operations.

[0054] Specifically, the generated interaction time series and interaction operation trajectory are used as operation behavior data and input into a pre-trained behavior analysis model. The behavior analysis model analyzes and calculates these data and outputs a probability value indicating the probability that the operation behavior is a robot operation, that is, the abnormal operation probability value. Among them, the behavior analysis model can be based on deep learning. It trains a preset model to be trained through a training set and adjusts the model parameters and / or abnormal operation features based on the test results to generate a behavior analysis model.

[0055] Optionally, the behavior analysis model can extract the behavior heat distribution map from the operation behavior data, and extract operation feature data from the interaction time series and interaction operation trajectory, match the operation feature data with the abnormal operation features, and perform weighted summation calculation on the matching degrees of different features based on a preset weight value to obtain the abnormal operation probability value. It should be noted that based on the different characteristics of abnormal operations and manual operations, the behavior analysis model can identify whether it is an abnormal operation from different feature angles such as operation trajectory, operation frequency, operation time, and operation regularity. For example, there will be fluctuations in the operation frequency during manual operation intervals, while human-machine operations are relatively uniform. The behavior analysis model can judge whether it is an abnormal operation based on the regularity of the interaction frequency in the operation behavior data. Or, human operations usually have a certain degree of jitter, and the behavior analysis model can also identify abnormal operations in overly smooth interaction operation trajectories.

[0056] Furthermore, the verification system compares the obtained abnormal operation probability value with a probability threshold. When the probability value exceeds the probability threshold, it is determined that there is an abnormal operation. Based on the characteristics that human-machine operations, script operations, or robot operations usually cannot provide corresponding biometric information, the verification system will trigger a biometric-based identity verification action and require the user to provide biometric information for verification. The system adjusts the risk identification result according to the verification result of the identity verification action. If the verification result is passed, it means that the user identity is real, and the risk identification result may be adjusted to passed. If the verification result is not passed, the risk identification result may still remain risky.

[0057] In this embodiment, by collecting the interaction data of the verification request, operation behavior data is generated, and the human-machine operation probability value is obtained by using a pre-trained behavior analysis model. When the probability value exceeds the probability threshold, an identity verification action based on biometric features is triggered, and the risk identification result is adjusted according to the verification result. This method can effectively identify robot operations and abnormal operation behaviors, and further improve the accuracy and security of risk identification for verification.

[0058] Since the system introduced in the second embodiment of this application is the system adopted for implementing the method in the first embodiment of this application, based on the method introduced in the first embodiment of this application, those skilled in the art can understand the specific structure and variations of the system, so it will not be elaborated here. Any system adopted by the method in the first embodiment of this application falls within the scope of protection of this application.

[0059] Based on the same inventive concept, this application also provides a third embodiment. Refer to Figure 3 , Figure 3 which is a schematic flowchart of the third embodiment of the risk identification method for verification of this application.

[0060] In this embodiment, as described in step S50, after performing the verification action of the verification card based on the verification information when the risk identification result is passed, steps S51 to S54 are further included: Step S51: When the risk identification result indicates that the verification information is risky, output an identity verification request; In this embodiment, based on the characteristic of being compatible with multiple different verification methods, the verification system can, when the risk identification result is risky, perform secondary risk verification through identity verification. When the risk identification module of the risk identification system for verification determines that the verification information is risky, the system will generate and send an identity verification request to the verification terminal, or output the identity verification request on the display screen of the verification terminal. This request usually includes the prompt information and operation guidelines required for verification, such as asking the user to provide biometric information or enter a verification code, or allowing the user to select from different identity verification requests.

[0061] Step S52: Obtain the feedback information of the identity verification request, and perform the identity verification action corresponding to the feedback information to obtain identity verification information; In this embodiment, when the verification system receives the feedback information of the identity verification request, it can perform the identity verification action matching the feedback information. Among them, when the feedback information does not have a specified identity verification policy, the verification system can determine the identity verification policy to be adopted based on a preset rule, and when the feedback information has a specified identity verification policy, the verification system can also perform the identity verification action based on this identity verification policy.

[0062] As an alternative implementation, when the feedback information includes an authentication policy, the write-off system will determine the system modules to be mobilized based on the authentication policy and mobilize them to perform authentication actions that comply with the authentication policy. For example, when the authentication policy is face recognition, the write-off terminal will respond to the write-off system instruction and obtain the user's face feature information through a camera device. Or, when the authentication policy is SMS recognition, the write-off system will send a verification code SMS to the mobile phone number based on the mobile phone number in the feedback information.

[0063] As another alternative implementation, the write-off system can also obtain the device information of the write-off terminal from the feedback information and determine the alternative verification policies and the priorities of the alternative verification policies based on the device information. For example, verification by mobile phone SMS is more easily received by users and thus has a higher priority. While face recognition operations are more cumbersome and thus have a lower priority. The write-off system can dynamically adjust the policy priorities based on the verification times of different alternative verification policies. Among them, the write-off system can select the target verification policy from the alternative verification policies according to the priority and execute the authentication action corresponding to the target verification policy to obtain the authentication information.

[0064] Optionally, based on the user identity information corresponding to the write-off card, the write-off system can also calculate the scores of different alternative verification policies by weighted summation based on the priority and the current tendency of the user's identity verification, and select the alternative verification policy with the highest score as the target verification policy.

[0065] Step S53: Compare the write-off card information of the write-off card with the authentication information to obtain an authentication result; Step S54: When the authentication result is passed, perform the write-off action of the write-off information.

[0066] In this embodiment, the write-off system compares the user identity information or SMS two-dimensional code information corresponding to the write-off card information in the write-off card information with the obtained authentication information to obtain an authentication result, that is, whether the authentication information matches the user identity information. Among them, when the authentication information matches the user identity information, that is, when the authentication result is passed, the write-off system can perform the write-off action corresponding to the write-off information.

[0067] Through dual identity authentication in the embodiments of the present application, when the current write-off fails to identify risks, the verification of the user identity information is further carried out to improve the accuracy of risk identification for write-off.

[0068] Since the system introduced in the third embodiment of this application is the system adopted for implementing the method of the first embodiment of this application, based on the method introduced in the first embodiment of this application, those skilled in the art can understand the specific structure and variations of this system, so it will not be elaborated here. Any system adopted by the method of the first embodiment of this application falls within the scope of protection of this application.

[0069] Based on the same inventive concept, this application also provides a fourth embodiment. Refer to Figure 4 , Figure 4 which is a schematic flowchart of the fourth embodiment of the risk identification method for write-off of this application.

[0070] In this embodiment, the risk identification method for write-off further includes steps S61 to S64: Step S61: Obtain the user identity information corresponding to the write-off card, and determine the target write-off card associated with the user identity information; Step S62: In the target write-off card information of the target write-off card, obtain the cross-card historical write-off record corresponding to the user identity information; Step S63: According to the risk identification rule and the cross-card historical write-off record, perform cross-card risk identification on the write-off information; Step S64: Incorporate the identification result of the cross-card risk identification into the risk assessment information.

[0071] In this embodiment, the same user may have multiple write-off cards at the same time, which are associated with the user identity information. The target write-off card is other write-off cards of this user except the currently written-off card. The write-off system can query the user identity information through the association relationship between the write-off card and the user identity information, and determine other write-off cards of this user, that is, the target write-off card.

[0072] Furthermore, by obtaining the historical write-off records of the target write-off card, the write-off system can perform cross-card risk identification on all the write-off records and write-off information of a single user to reduce the situation that one of the multiple write-off cards of the user is stolen and swiped. The write-off system can load the risk identification rule based on the rule engine and perform cross-card risk identification on the cross-card historical write-off record of the user. The write-off system will synchronously adjust the risk assessment information based on the identification result of the cross-card risk identification. Among them, this risk identification rule can be a cross-card risk identification rule or the same as the risk identification rule of a single write-off card.

[0073] Based on the user identity information corresponding to the write-off card, this embodiment of this application performs cross-card risk identification on the write-off information of different write-off cards of the user by using the risk control rule, and incorporates the result into the overall risk assessment information, so as to comprehensively evaluate the write-off behavior of the user on multiple cards, effectively identify potential cross-card risks, and further enhance the security and risk control ability of the write-off process.

[0074] Since the system introduced in the fourth embodiment of this application is the system adopted for implementing the method in the first embodiment of this application, based on the method introduced in the first embodiment of this application, those skilled in the art can understand the specific structure and variations of the system, so it will not be elaborated here. Any system adopted for the method in the first embodiment of this application falls within the scope of protection of this application.

[0075] Based on the same inventive concept, the present application also provides a fifth embodiment. Refer to Figure 5 , Figure 5 which is a schematic flowchart of the fifth embodiment of the risk identification method for write-off in this application.

[0076] In this embodiment, the risk identification method for write-off further includes steps S71 to S73: Step S71: Obtain the write-off action information of the write-off action, and determine the write-off amount, write-off location, and / or write-off time in the write-off action information; Step S72: Associate the write-off amount, the write-off location, and / or the write-off time with the write-off information to generate a write-off record; Step S73: Update the write-off card information of the write-off card, and update the write-off record to the historical write-off record of the write-off card information.

[0077] In this embodiment, after the write-off system executes the write-off action, it will also generate a write-off record based on the write-off action information of the write-off action and the write-off information for subsequent write-off actions and risk identification work.

[0078] As an alternative implementation, the write-off system can synchronize the write-off record to a local database or a cloud database. Based on the association operation of the database, the write-off amount, write-off location, and write-off time extracted are associated with the original write-off information. For example, using the write-off information as the primary key and the write-off amount, location, and time as associated fields, a complete write-off record is generated and updated to the historical write-off record of the write-off card information. At the same time, the write-off system will also update information such as the balance in the write-off card information based on the write-off action.

[0079] As another alternative implementation, the write-off system can also form a complete storage of the write-off record based on the blockchain. The write-off system packs the write-off amount, write-off location, and write-off time with the write-off information into a block, and adds this block to the blockchain of the write-off card in a consensus manner to form a transaction deposit.

[0080] Since the system described in Embodiment 5 of the present application is the system adopted for implementing the method of Embodiment 1 of the present application, based on the method described in Embodiment 1 of the present application, those skilled in the art can understand the specific structure and variations of the system, so it will not be elaborated here. Any system adopted for the method of Embodiment 1 of the present application falls within the scope of protection of the present application.

[0081] The present application provides a risk identification device for write-off, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the risk identification method for write-off in the above-mentioned Embodiment 1.

[0082] Refer to the following Figure 6 , which shows a schematic structural diagram of a risk identification device for write-off suitable for implementing the embodiments of the present application. The risk identification device for write-off in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistant), PADs (Portable Application Description: tablet computers), PMPs (Portable Media Player: portable multimedia players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 6 The risk identification device for write-off shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.

[0083] As shown in Figure 6As shown, the risk identification device for write-off can include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1002 or the program loaded from the storage device 1003 into the random access memory (RAM) 1004. In the random access memory 1004, various programs and data required for the operation of the risk identification device for write-off are also stored. The processing device 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other through a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems can be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the risk identification device for write-off to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a risk identification device for write-off having various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems can be implemented or had alternatively.

[0084] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device, or installed from the storage device 1003, or installed from the read-only memory 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiments disclosed in the present application are executed.

[0085] The risk identification device for write-off provided by the present application adopts the risk identification method in the above embodiments, and can solve the technical problem that the write-off card is easily stolen and swiped, resulting in a relatively high risk hidden danger in the write-off process. Compared with the prior art, the beneficial effects of the risk identification device for write-off provided by the present application are the same as those of the risk identification method provided by the above embodiments, and other technical features in the risk identification device for write-off are the same as those disclosed in the method of the previous embodiment, and will not be elaborated here.

[0086] It should be understood that each part disclosed in this application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0087] As described above, the above are only specific embodiments of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0088] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the risk identification method for verification in the above embodiments.

[0089] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or combined with an instruction execution system, device, or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, radio frequency (RF), etc., or any suitable combination of the above.

[0090] The above computer-readable storage medium can be included in the risk identification device for verification; it can also exist separately without being assembled into the risk identification device for verification.

[0091] The above computer-readable storage medium carries one or more programs, which, when executed by the risk identification device for write-off, cause the risk identification device for write-off to: receive a write-off request, and obtain the identification information and write-off information in the write-off request; query the write-off card corresponding to the identification information, and obtain the historical write-off records of the write-off card; load risk identification rules through a write-off rule engine, perform risk identification on the historical write-off records and the write-off information, and obtain risk assessment information; identify abnormal interaction information in the write-off request through a behavior analysis model, and adjust the risk assessment information according to the abnormal interaction information to determine a risk identification result; when the risk identification result is passed, perform the write-off action of the write-off card based on the write-off information.

[0092] Computer program code for performing the operations of the present application may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0093] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0094] The modules involved in the embodiments of the present application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.

[0095] The readable storage medium provided by the present application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned risk identification method for verification and can solve the technical problem that verification cards are easily stolen and swiped, resulting in a relatively high risk hidden danger in the verification process. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as those of the risk identification method for verification provided by the above embodiments and will not be elaborated here.

[0096] The above are only some embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structural transformation made by using the content of the specification and drawings of the present application under the technical concept of the present application, or direct / indirect application in other related technical fields is included in the patent protection scope of the present application.

Claims

1. A risk identification method for write-off, characterized in that, The method described above includes the following steps: Receive a write-off request, and obtain the identification information and write-off information in the write-off request; Query the write-off card corresponding to the identification information, and obtain the historical write-off records of the write-off card; Load risk identification rules through a write-off rule engine, perform risk identification on the historical write-off records and the write-off information, and obtain risk assessment information; Identify abnormal interaction information in the write-off request through a behavior analysis model, and adjust the risk assessment information according to the abnormal interaction information to determine a risk identification result; When the risk identification result is passed, perform the write-off action of the write-off card based on the write-off information.

2. The method according to claim 1, characterized in that, The step of loading risk identification rules through a write-off rule engine, performing risk identification on the historical write-off records and the write-off information, and obtaining risk assessment information includes: Obtain the write-off location in the write-off information, and obtain the target write-off time and target write-off location corresponding to the target historical write-off record in the historical write-off records; Take the current system time as the write-off time of the write-off information, and determine the write-off time interval between the write-off time and the target write-off time; When the write-off time interval is less than the time interval threshold, calculate the write-off distance between the write-off location and the target write-off location; If the write-off distance is greater than the distance threshold, it is determined that the write-off information is risky.

3. The method according to claim 1, wherein The step of identifying abnormal interaction information in the write-off request through a behavior analysis model, adjusting the risk assessment information according to the abnormal interaction information, and determining the risk identification result further includes: Collect the interaction data corresponding to the write-off request, and generate an interaction time series and an interaction operation track according to the interaction time corresponding to the interaction data; Use the interaction time series and the interaction operation track as the operation behavior data of the write-off request, and input them into a pre-trained behavior analysis model to obtain an abnormal operation probability value; When the abnormal operation probability value exceeds the probability threshold, trigger an identity verification action based on biometrics; Adjust the risk assessment information according to the verification result of the identity verification action, and determine the risk identification result.

4. The method according to claim 3, wherein The step of using the interaction time series and the interaction operation track as the operation behavior data of the write-off request, inputting them into a pre-trained behavior analysis model, and obtaining an abnormal operation probability value includes: Extract operation feature data according to the behavior heat distribution map corresponding to the operation behavior data, as well as the interaction time series and the interaction operation track; Match the operation feature data with preset abnormal operation features to obtain the matching degree of the operation feature data; Based on preset weight values, perform a weighted summation calculation on the matching degrees of different operation feature data to obtain the abnormal operation probability value.

5. The method according to claim 1, characterized in that After the step of identifying abnormal interaction information in the write-off request through a behavior analysis model, adjusting the risk assessment information according to the abnormal interaction information, and determining the risk identification result, it further includes: When the risk identification result is that the write-off information is risky, output an identity verification request; Obtain the feedback information of the authentication request, and perform the authentication action corresponding to the feedback information to obtain authentication information; Compare the write-off card information of the write-off card with the authentication information to obtain an authentication result; When the authentication result is passed, perform the write-off action of the write-off information.

6. The method according to claim 5, wherein The step of obtaining the feedback information of the authentication request, and performing the authentication action corresponding to the feedback information to obtain authentication information includes: In the feedback information, obtain the device information of the write-off terminal; According to the device information, determine the candidate verification strategies, and determine the priority levels of the candidate verification strategies; Based on the priority levels, select a target verification strategy from the candidate verification strategies; Perform the authentication action corresponding to the target verification strategy to obtain the authentication information.

7. The method according to claim 1, characterized in that The step of querying the write-off card corresponding to the identification information and obtaining the historical write-off record of the write-off card includes: Based on the identification information field in the write-off request, identify the type of the identification information, where the type of the identification information includes biometric information, identity identification information, and / or write-off card identification information; Based on the type of the identification information, query the write-off card corresponding to the identification information in the database; Obtain the write-off card information of the write-off card and the historical write-off record in the write-off card information.

8. The method according to claim 1, characterized in that, After the step of querying the write-off card corresponding to the identification information and obtaining the historical write-off record of the write-off card, it further includes: Obtain the user identity information corresponding to the write-off card, and determine the target write-off card associated with the user identity information; In the target write-off card information of the target write-off card, obtain the cross-card historical write-off record corresponding to the user identity information; According to the risk identification rule and the cross-card historical write-off record, perform cross-card risk identification on the write-off information; Incorporate the identification result of the cross-card risk identification into the risk assessment information.

9. A risk identification device for write-off, characterized in that, The device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the write-off risk identification method according to any one of claims 1 to 8.

10. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, it implements the steps of the write-off risk identification method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Anomaly detection device and method for security information interaction

    CN103544429A

  • Payment anomaly detection method and system

    CN105631668A

  • Method and device for providing unusual transaction

    CN106611316A

  • Identity authentication method and system based on user behavior model

    CN106911668A

  • Behavior recognition method and device, storage medium and electronic equipment

    CN112231700A

Cited By

  • Risk detection system and risk detection method

    CN120952951A