Write-off risk identification method, equipment and storage medium
By receiving revocation requests, obtaining identification and revocation information, querying the revocation card's historical records, identifying potential risks using risk identification rules and behavioral analysis models, and executing revocation actions when risk identification is successful, the problem of revocation cards being easily stolen and fraudulently used has been solved, achieving a safe and efficient revocation process.
Patent Information
- Application Number
- CN202510847887.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-06-24
AI Technical Summary
Cards used for verification are easily stolen and used fraudulently, resulting in a high risk of fraud during the verification process.
By receiving reversal requests, obtaining identification and reversal information, querying the historical records of reversal cards, identifying potential risks using risk identification rules and behavioral analysis models, and executing reversal actions when risk identification is successful.
It significantly improves the security of the reconciliation process, avoids potential security risks, supports a variety of convenient reconciliation methods, and provides a safe and efficient reconciliation experience.
Smart Images

Figure CN120374119B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of write-off system technology, and in particular to a risk identification method, device and storage medium for write-off. Background Technology
[0002] Based on the high compatibility and data processing capabilities of big data and cloud technologies, the verification card and verification platform can provide users with a variety of verification methods, such as facial recognition, card number input, or QR code recognition, to improve the convenience of using the verification card.
[0003] However, the convenient verification method also brings security risks of fraudulent transactions. In such cases, even someone other than the cardholder can use the verification identifier information corresponding to any card to commit fraudulent transactions. This results in a high level of risk during the card verification process.
[0004] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention
[0005] The main purpose of this application is to provide a risk identification method, device and storage medium for verification, which aims to solve the technical problem that verification cards are easily stolen and used, resulting in high risk in the verification process.
[0006] To achieve the above objectives, this application provides a risk identification method for write-offs, the method comprising the following steps:
[0007] Receive a reversal request and obtain the identification information and reversal information from the reversal request;
[0008] Query the verification card corresponding to the identification information and obtain the historical verification records of the verification card;
[0009] By loading risk identification rules through the reimbursement rule engine, risk identification is performed on the historical reimbursement records and the reimbursement information to obtain risk assessment information.
[0010] By using a behavioral analysis model, abnormal interaction information in the write-off request is identified, and the risk assessment information is adjusted based on the abnormal interaction information to determine the risk identification result;
[0011] When the risk identification result is passed, the verification action of the verification card is performed based on the verification information.
[0012] In one embodiment, the step of loading risk identification rules through an write-off rule engine, identifying risks in the historical write-off records and the write-off information, and obtaining risk assessment information includes:
[0013] Obtain the reversal location from the reversal information, and obtain the target reversal time and target reversal location corresponding to the target historical reversal record from the historical reversal records;
[0014] Use the current system time as the verification time of the verification information, and determine the verification time interval between the verification time and the target verification time;
[0015] When the verification time interval is less than the time interval threshold, the verification distance between the verification location and the target verification location is calculated;
[0016] If the verification distance is greater than a distance threshold, the verification information is deemed to be at risk.
[0017] In one embodiment, the step of identifying abnormal interaction information in the reimbursement request through a behavioral analysis model, adjusting the risk assessment information based on the abnormal interaction information, and determining the risk identification result further includes:
[0018] Collect the interaction data corresponding to the reimbursement request, and generate an interaction time sequence and interaction operation trajectory based on the interaction time corresponding to the interaction data;
[0019] The interaction time series and the interaction operation trajectory are used as the operation behavior data of the reimbursement request and input into the pre-trained behavior analysis model to obtain the abnormal operation probability value.
[0020] When the probability value of the abnormal operation exceeds the probability threshold, a biometric authentication action is triggered.
[0021] Based on the verification result of the identity verification action, the risk assessment information is adjusted to determine the risk identification result.
[0022] In one embodiment, the step of inputting the interaction time series and the interaction operation trajectory as the operation behavior data of the reimbursement request into a pre-trained behavior analysis model to obtain the abnormal operation probability value includes:
[0023] Based on the behavior heatmap corresponding to the operation behavior data, as well as the interaction time series and the interaction operation trajectory, operation feature data is extracted;
[0024] The operation feature data is matched with preset abnormal operation features to obtain the matching degree of the operation feature data;
[0025] Based on preset weight values, the matching degrees of different operation feature data are weighted and summed to obtain the probability value of abnormal operation.
[0026] In one embodiment, after the steps of identifying abnormal interaction information in the reimbursement request through a behavioral analysis model, adjusting the risk assessment information based on the abnormal interaction information, and determining the risk identification result, the method further includes:
[0027] When the risk identification result indicates that the revocation information is at risk, an authentication request is output.
[0028] Obtain the feedback information of the authentication request, and execute the authentication action corresponding to the feedback information to obtain the authentication information;
[0029] The verification card information of the verification card is compared with the identity verification information to obtain the identity verification result;
[0030] When the authentication result is successful, the verification action of the verification information is performed.
[0031] In one embodiment, the step of obtaining feedback information of the authentication request and performing the authentication action corresponding to the feedback information to obtain authentication information includes:
[0032] The device information of the verification terminal is obtained from the feedback information;
[0033] Based on the device information, determine the candidate verification strategies and their priorities;
[0034] Based on the priority, a target verification strategy is selected from the candidate verification strategies;
[0035] Execute the authentication action corresponding to the target authentication policy to obtain the authentication information.
[0036] In one embodiment, the step of querying the redemption card corresponding to the identification information and obtaining the historical redemption records of the redemption card includes:
[0037] Based on the identification information field in the verification request, the identification information type of the identification information is identified, wherein the identification information type includes biometric information, identity identification information and / or verification card identification information;
[0038] Based on the identification information type, query the database for the verification card corresponding to the identification information;
[0039] Obtain the verification card information of the verification card, and the historical verification records in the verification card information.
[0040] In one embodiment, after the step of querying the redemption card corresponding to the identification information and obtaining the historical redemption records of the redemption card, the method further includes:
[0041] Obtain the user identity information corresponding to the verification card, and determine the target verification card associated with the user identity information;
[0042] From the target redemption card information of the target redemption card, obtain the cross-card historical redemption record corresponding to the user identity information;
[0043] Based on the risk identification rules and the cross-card historical reversal records, cross-card risk identification is performed on the reversal information;
[0044] The identification results of the cross-card risk identification are incorporated into the risk assessment information.
[0045] In addition, to achieve the above objectives, this application also provides a risk identification device for write-off, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the risk identification method for write-off as described above.
[0046] In addition, to achieve the above objectives, this application also provides a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the risk identification method for write-off as described above.
[0047] One or more technical solutions proposed in this application have at least the following technical effects:
[0048] This application receives verification requests, obtains the identification and verification information, queries the corresponding verification card, retrieves its historical verification records, and performs risk identification on the verification card and information based on risk identification rules and historical verification records. Verification is only executed when the risk identification is successful. By introducing risk identification rules, potential risks in the verification process are assessed, avoiding security vulnerabilities caused by relying solely on basic information verification, thus significantly improving the security of the verification process. Simultaneously, while ensuring security, this solution still supports various convenient verification methods, such as facial recognition, card number input, or QR code recognition, satisfying users' needs for convenience while ensuring the reliability of the verification process, thereby providing users and merchants with a safer and more efficient verification experience. Attached Figure Description
[0049] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0050] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0051] Figure 1 This is a flowchart illustrating the first embodiment of the risk identification method for write-off in this application;
[0052] Figure 2 This is a flowchart illustrating the second embodiment of the risk identification method for write-off in this application;
[0053] Figure 3 This is a flowchart illustrating the third embodiment of the risk identification method for write-off in this application;
[0054] Figure 4 This is a flowchart illustrating the fourth embodiment of the risk identification method for write-off in this application;
[0055] Figure 5 This is a flowchart illustrating the fifth embodiment of the risk identification method for write-off in this application;
[0056] Figure 6 This is a schematic diagram of the structure of a risk identification device for verifying the hardware operating environment involved in the embodiments of this application.
[0057] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0058] It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.
[0059] To better understand the above technical solutions, the following will provide a detailed explanation of the technical solutions in conjunction with the accompanying drawings and specific implementation methods.
[0060] The main solution of this application embodiment is as follows: receiving a reversal request, obtaining identification information and reversal information from the reversal request; querying the reversal card corresponding to the identification information, obtaining the historical reversal records of the reversal card; loading risk identification rules through a reversal rule engine, performing risk identification on the historical reversal records and the reversal information, and obtaining risk assessment information; identifying abnormal interaction information in the reversal request through a behavior analysis model, adjusting the risk assessment information according to the abnormal interaction information, and determining the risk identification result; when the risk identification result is passed, executing the reversal action of the reversal card based on the reversal information.
[0061] While the technologies used in card verification and platforms offer users various convenient verification methods such as facial recognition, card number input, or QR code scanning, they also introduce security risks that can lead to fraudulent transactions. In such cases, even those who are not the cardholders can use the verification identifier information associated with any card to commit fraudulent transactions. This results in a high level of risk during the card verification process.
[0062] This application receives verification requests, obtains their identification and verification information, queries the corresponding verification card, retrieves its historical verification records, and performs risk identification on the verification card and information based on risk identification rules and historical verification records. Verification is only executed when the risk identification is successful. By introducing risk identification rules, the potential risks in the verification process can be comprehensively assessed, avoiding security vulnerabilities caused by relying solely on basic information verification, and significantly improving the security of the verification process. Simultaneously, while ensuring security, this solution still supports various convenient verification methods, such as facial recognition, card number input, or QR code recognition, satisfying users' needs for convenience while ensuring the reliability of the verification process, thus providing users and merchants with a safer and more efficient verification experience.
[0063] To better understand the above technical solutions, exemplary embodiments of this application will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of this application are shown in the drawings, it should be understood that this application can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of this application and to fully convey the scope of this application to those skilled in the art.
[0064] It should be noted that the executing entity in this embodiment can be a verification system, or a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device or risk identification device for verification that can achieve the above functions. This embodiment does not specifically limit it in this regard. The following uses a verification system as an example to describe this embodiment and the following embodiments.
[0065] Based on this, embodiments of this application provide a risk identification method for write-off, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the risk identification method for write-off in this application.
[0066] In this embodiment, the risk identification method for write-off includes steps S10 to S40:
[0067] Step S10: Receive a reversal request and obtain the identification information and reversal information in the reversal request;
[0068] In this embodiment, the verification system receives user verification requests and performs actions such as retrieving verification card information and executing verification. After using a verification card for consumption or services, a user can submit a verification request to the verification system through a verification terminal. This verification request includes verification information for the current transaction, as well as identification information used to identify the user, allowing the verification system to obtain the relevant information required for the verification. The identification information is a unique identifier used to identify the verification card or user, such as the card number, user biometric information, or phone number. The verification information includes detailed data for the verification, such as the amount, time, and location.
[0069] It should be noted that during the creation of identification information, when it is necessary to obtain user-related card numbers, biometric information, or phone numbers as the basis for creating identification information, a privacy information acquisition authorization process is also set up. This ensures that users understand, before entering their privacy information, that the information obtained will be used to generate the corresponding identification information.
[0070] Specifically, the verification system can be deployed on a cloud server, receiving verification requests sent by verification terminals via network interfaces and other means, and then executing verification actions. Alternatively, the verification system can be deployed on the verification terminal, triggering verification requests by acquiring user input information, and synchronizing the data to the cloud database after completing the verification action.
[0071] As an optional implementation, when the verification system is deployed on a cloud server, it receives verification requests from verification terminals via a network interface. These requests are sent in encrypted data packets to ensure data security and integrity. Upon receiving the request, the system uses a specific decryption algorithm to decrypt the data packets and extract the identification and verification information. The identification information is used for subsequent verification card lookups, while the verification information is used for risk identification and verification operations.
[0072] For example, after a user makes a payment using a verification card at a shopping mall, the POS system generates a verification request, which includes the user's card number as identification information, as well as verification information such as the payment amount, time, and cash register location. This request is sent via the internet to the cloud server of the verification risk identification system. After receiving the verification request, the cloud server decrypts and extracts the data to obtain the identification information and verification information.
[0073] As an alternative implementation, when the verification system is deployed locally on the verification terminal, the system can obtain the information of the goods to be verified by scanning the barcode at the terminal, and generate verification information by combining the verification location and the current system time. Simultaneously, the system can obtain authorized identification information from the user through facial recognition via a camera, scanning the QR code on the verification card with a QR code scanner, or receiving the card number or mobile phone number entered by the user, and then generate a verification request by combining the identification information and the verification information.
[0074] Step S20: Query the verification card corresponding to the identification information and obtain the historical verification records of the verification card;
[0075] In this embodiment, the historical reconciliation record contains a detailed record of all completed reconciliation actions for the reconciliation card, including information such as the time, amount, and location of each reconciliation. The reconciliation system uses the identification information extracted from the reconciliation request as a query key to retrieve data from the local database or cloud database. The reconciliation system locates the corresponding reconciliation card and its information by retrieval, and obtains the historical reconciliation record of the card from the card information.
[0076] In one embodiment, the verification system can extract identification information based on the identification information field in the verification request and identify the identification information type corresponding to the identification information. The identification information type may optionally include biometric information, identity identification information, and / or verification card identification information. Based on the identification information type, the verification system can query the corresponding verification card in the database to obtain the verification card information and the historical verification records within that verification card information.
[0077] For example, the reimbursement system can dynamically carry the original data of identification information for different reimbursement methods through the credentials field in the reimbursement request, thus achieving compatibility between different reimbursement methods. The reimbursement system can identify the identification information type by specific characters in the field, such as the last three characters, and compare the identification information with all information of the same identification information type in the database to determine the corresponding reimbursement card and reimbursement card information.
[0078] In another implementation, after obtaining the identification information, the verification system can also directly traverse the corresponding verification cards in the database stored in the verification card information based on the identification information. For example, assuming the identification information is card number "123***78", the system queries the database using this card number as an index, finds the corresponding verification card, and obtains the verification card record. This record contains all verification records of the card since January 1, 2023, such as a purchase of 100 yuan at supermarket A on January 5, 2023, and a purchase of 200 yuan at restaurant B on January 10, 2023.
[0079] Step S30: Load risk identification rules through the reimbursement rule engine, identify risks in the historical reimbursement records and the reimbursement information, and obtain risk assessment information;
[0080] In this embodiment, the reimbursement system uses a reimbursement rule engine to load, process, and parse predefined risk identification rules, as well as to implement custom configuration and dynamic updates of these rules. Risk identification rules refer to a series of logic and conditions used to determine whether a reimbursement operation carries risk, including rules related to time intervals, geographical locations, and transaction amounts. The reimbursement system inputs historical reimbursement records and information into the rule engine, extracting information such as reimbursement time, reimbursement amount, and / or reimbursement location. By loading preset risk identification rules through the rule engine, and based on one or more of the reimbursement time, reimbursement amount, and reimbursement location, it executes risk identification actions to obtain risk assessment information.
[0081] Specifically, the system activates the reimbursement rule engine, loads preset risk identification rules from a configuration file or database, and uses the acquired historical reimbursement records and information as input data. It then compares and analyzes these rules against each preset risk identification rule. The reimbursement rule engine determines whether a risk exists based on the logic of the rules. Specifically, the engine can verify single pieces of information based on whether the reimbursement amount exceeds a preset threshold or whether the reimbursement location is within the user's regular activity area. Alternatively, it can combine multiple pieces of information for verification, such as using the reimbursement time and location to determine if the same card has been frequently reimbursed at different locations within a short period.
[0082] As an optional implementation, step S30 includes steps S31 to S34:
[0083] Step S31: Obtain the reversal location in the reversal information, and obtain the target reversal time and target reversal location corresponding to the target historical reversal record in the historical reversal record;
[0084] Step S32: Use the current system time as the verification time of the verification information, and determine the verification time interval between the verification time and the target verification time;
[0085] Step S33: When the verification time interval is less than the time interval threshold, calculate the verification distance between the verification location and the target verification location;
[0086] Step S34: If the verification distance is greater than the distance threshold, it is determined that the verification information is at risk.
[0087] In this embodiment, the verification location is the specific geographical location information where the verification operation occurred. This is typically obtained by the verification terminal's positioning module, such as GPS coordinates or base station positioning information, or determined based on the merchant location associated with the verification terminal in the verification system. The verification system can obtain the current system time and use it as the verification time for this verification information. It then calculates the difference between this verification time and the target verification time in the target historical verification record to obtain the verification time interval. By comparing the verification time interval with a time interval threshold, if the verification time interval is greater than the threshold, it is determined that the verification information is risk-free, or risk identification of other content in the verification information is performed. If it is less than the threshold, the distance between the verification location and the target verification location is further calculated or obtained through the positioning system. The obtained verification distance is compared with a distance threshold. When the verification distance is greater than the distance threshold, since the user cannot traverse a long distance in a short time, it indicates that the same verification card has been verified in multiple locations within a short period, and the verification system determines that the current verification information is risky.
[0088] As another optional implementation, the verification system can also sequentially identify individual information in the verification information and verification records based on preset risk identification rules. For example, if the number of verifications exceeds a threshold within a preset time period of the current verification information, or the total amount of verifications exceeds a threshold, or the verification time does not match the corresponding product type, the verification system determines that there is a risk.
[0089] Step S40: Identify abnormal interaction information in the write-off request through a behavior analysis model, and adjust the risk assessment information according to the abnormal interaction information to determine the risk identification result;
[0090] In this embodiment, the verification system can also obtain the interaction information corresponding to the verification information at the verification terminal, thereby determining whether the interaction information is abnormal interaction information implemented by a robot or script program. Specifically, the verification system is equipped with a behavior analysis model that can obtain the interaction information in the verification request and identify abnormal interaction information through time series, trajectory analysis, and other methods.
[0091] Furthermore, based on this abnormal interaction information, the reimbursement system will further adjust the risk assessment information to determine the risk identification result.
[0092] Step S50: When the risk identification result is passed, perform the verification action of the verification card based on the verification information.
[0093] In this embodiment, the risk identification result includes "passed" and "risk exists." When the risk identification result indicates a risk, the verification system will output an error message or perform a secondary verification action. When the risk identification result is "passed," the corresponding verification action will be performed based on the verification information, and the verification card information will be updated by deducting the balance or updating the status.
[0094] Optionally, the verification system will update the balance and status of the verification card based on data such as the amount and time in the verification information, and add this verification record to the historical verification record. Simultaneously, the system may send a notification to the user's terminal indicating successful verification, informing the user that the verification operation has been completed.
[0095] This application embodiment receives a verification request, obtains its identification and verification information, queries the corresponding verification card, retrieves its historical verification records, and performs risk identification on the verification card and verification information based on risk identification rules and historical verification records. Verification is only executed when the risk identification is successful. By introducing risk identification rules, potential risks in the verification process can be comprehensively assessed, avoiding security risks caused by relying solely on basic information verification, and significantly improving the security of the verification process. Simultaneously, while ensuring security, this solution still supports various convenient verification methods, such as facial recognition, card number input, or QR code recognition, satisfying users' needs for convenience while ensuring the reliability of the verification process, thus providing users and merchants with a safer and more efficient verification experience.
[0096] Based on the same inventive concept, this application also provides a second embodiment, referring to... Figure 2 , Figure 2 This is a flowchart illustrating the second embodiment of the risk identification method for write-off in this application.
[0097] In this embodiment, the risk identification method for write-offs further includes steps S35-S38:
[0098] Step S35: Collect the interaction data corresponding to the reconciliation request, and generate an interaction time sequence and interaction operation trajectory based on the interaction time corresponding to the interaction data;
[0099] In this embodiment, when a user interacts with the system during the submission of a verification request, various interaction data are generated, such as records of clicks, inputs, and swipes. Simultaneously, based on the timestamp of each interaction, i.e., the interaction time, these are arranged chronologically to form a corresponding time series data, i.e., an interaction time series, reflecting the continuity of each interaction. Connecting different interaction actions based on the interaction time series yields a corresponding interaction operation trajectory. The interaction operation trajectory refers to the trajectory of a series of user actions during the verification request process, reflecting the user's operating habits and behavioral patterns. The verification system generates an interaction time series by arranging these interaction times chronologically. Simultaneously, it combines the interaction operations sequentially to form the interaction operation trajectory.
[0100] Step S36: Input the interaction time series and the interaction operation trajectory as the operation behavior data of the reimbursement request into the pre-trained behavior analysis model to obtain the abnormal operation probability value;
[0101] Step S37: When the probability value of the abnormal operation exceeds the probability threshold, a biometric authentication action is triggered;
[0102] Step S38: Based on the verification result of the identity verification action, adjust the risk assessment information and determine the risk identification result.
[0103] In this embodiment, the behavior analysis model is a machine learning model that, through training on a large amount of normal user operation behavior data, can identify the probability of normal and abnormal operation behaviors. The abnormal operation behaviors include abnormal human-machine interactions.
[0104] Specifically, the generated interaction time series and interaction operation trajectories are used as operation behavior data and input into a pre-trained behavior analysis model. The behavior analysis model analyzes and calculates this data, outputting a probability value representing the probability that the operation is a robot operation, i.e., the probability value of an abnormal operation. The behavior analysis model can be based on deep learning, trained on a pre-defined training set, and its parameters and / or abnormal operation features adjusted based on test results to generate the behavior analysis model.
[0105] Optionally, the behavior analysis model can extract a behavior heatmap from the operation behavior data, and extract operation feature data from the interaction time series and interaction operation trajectory. This operation feature data is then matched with abnormal operation features, and the matching degree of different features is weighted and summed based on preset weight values to obtain the probability value of abnormal operation. It should be noted that, based on the different characteristics of abnormal operations and human operations, the behavior analysis model can identify whether an operation is abnormal from different feature perspectives such as operation trajectory, operation frequency, operation time, and operation regularity. For example, human operations may exhibit fluctuations in operation frequency, while human-machine operations are relatively uniform. The behavior analysis model can determine whether an operation is abnormal based on the regularity of interaction frequency in the operation behavior data. Alternatively, human operations often exhibit a certain degree of jitter; the behavior analysis model can also identify abnormal operations in overly smooth interaction operation trajectories.
[0106] Furthermore, the verification system compares the obtained probability value of abnormal operations with a probability threshold. When the probability value exceeds the threshold, an abnormal operation is determined to have occurred. Since human-machine, script-based, or robot-based operations typically cannot provide corresponding biometric information, the verification system triggers a biometric authentication action, requiring the user to provide biometric information for verification. The system adjusts the risk identification result based on the verification result. If the verification result is successful, it indicates the user's identity is genuine, and the risk identification result may be adjusted to successful. If the verification result is unsuccessful, the risk identification result may remain in effect.
[0107] This embodiment generates operational behavior data by collecting interaction data from verification requests and uses a pre-trained behavior analysis model to obtain human-machine operation probability values. When the probability value exceeds a probability threshold, a biometric-based identity verification action is triggered, and the risk identification result is adjusted based on the verification result. This method can effectively identify robot operations and abnormal operational behaviors, further improving the accuracy and security of verification risk identification.
[0108] Since the system described in Embodiment 2 of this application is a system used to implement the method of Embodiment 1 of this application, those skilled in the art can understand the specific structure and variations of the system based on the method described in Embodiment 1 of this application, and therefore will not be described again here. All systems used in the method of Embodiment 1 of this application fall within the scope of protection of this application.
[0109] Based on the same inventive concept, this application also provides a third embodiment, referring to... Figure 3 , Figure 3 This is a flowchart illustrating the third embodiment of the risk identification method for write-off in this application.
[0110] In this embodiment, after performing the verification action of the verification card based on the verification information when the risk identification result is passed, as described in step S50, steps S51 to S54 are further included:
[0111] Step S51: When the risk identification result indicates that the reversal information is at risk, output an authentication request;
[0112] In this embodiment, based on its compatibility with multiple verification methods, the verification system can perform secondary risk verification through identity authentication when the risk identification result indicates a risk. When the risk identification module of the verification risk identification system determines that the verification information is risky, the system generates and sends an identity authentication request to the verification terminal, or outputs the identity authentication request on the verification terminal's display screen. This request typically includes prompts and operation instructions required for verification, such as requiring the user to provide biometric information or enter a verification code, or allowing the user to choose from different identity authentication requests.
[0113] Step S52: Obtain feedback information of the authentication request, and execute the authentication action corresponding to the feedback information to obtain authentication information;
[0114] In this embodiment, when the verification system receives feedback information regarding an authentication request, it can execute an authentication action that matches the feedback information. Specifically, when the feedback information does not specify an authentication policy, the verification system can determine the authentication policy to adopt based on preset rules; conversely, when the feedback information does specify an authentication policy, the verification system can also execute the authentication action based on that policy.
[0115] As an optional implementation, when the feedback information includes an authentication policy, the verification system will determine the system module to be invoked based on the authentication policy and invoke it to perform the authentication action that conforms to the authentication policy. For example, when the authentication policy is facial recognition, the verification terminal will respond to the verification system's instruction and obtain the user's facial feature information through a camera device. Alternatively, when the authentication policy is SMS recognition, the verification system will send a verification code SMS to the mobile phone number in the feedback information.
[0116] As an alternative implementation, the verification system can also obtain the device information of the verification terminal from the feedback information, and determine the candidate verification strategies and their priorities based on this information. For example, verification via mobile phone SMS is more easily accepted by users and therefore has a higher priority. Facial recognition, on the other hand, is more cumbersome and therefore has a lower priority. The verification system can dynamically adjust the priority of different candidate verification strategies based on the number of verification attempts. Specifically, the verification system can prioritize and select a target verification strategy from the candidate strategies, then execute the corresponding identity verification action to obtain identity verification information.
[0117] Optionally, based on the user identity information corresponding to the verification card, the verification system can also calculate the scores of different candidate verification strategies by weighted summation based on priority and the current user's authentication preference, and select the candidate verification strategy with the highest score as the target verification strategy.
[0118] Step S53: Compare the verification card information of the verification card with the identity verification information to obtain the identity verification result;
[0119] Step S54: When the authentication result is successful, perform the verification action of the verification information.
[0120] In this embodiment, the verification system compares the user's identity information or SMS QR code in the verification card information with the obtained identity verification information to obtain the identity verification result, i.e., whether the identity verification information matches the user's identity information. When the identity verification information matches the user's identity information, i.e., the identity verification result is successful, the verification system can execute the verification action corresponding to the verification information.
[0121] This application embodiment uses dual authentication to further verify the user's identity information when the current reversal fails risk identification, thereby improving the accuracy of risk identification for reversal.
[0122] Since the system described in Embodiment 3 of this application is a system used to implement the method of Embodiment 1 of this application, those skilled in the art can understand the specific structure and variations of the system based on the method described in Embodiment 1 of this application, and therefore will not be described again here. All systems used in the method of Embodiment 1 of this application fall within the scope of protection of this application.
[0123] Based on the same inventive concept, this application also provides a fourth embodiment, referring to... Figure 4 , Figure 4 This is a flowchart illustrating the fourth embodiment of the risk identification method for write-off in this application.
[0124] In this embodiment, the risk identification method for write-offs further includes steps S61-S64:
[0125] Step S61: Obtain the user identity information corresponding to the verification card, and determine the target verification card associated with the user identity information;
[0126] Step S62: Obtain the cross-card historical reimbursement record corresponding to the user identity information from the target reimbursement card information of the target reimbursement card;
[0127] Step S63: Based on the risk identification rules and the cross-card historical reversal records, perform cross-card risk identification on the reversal information;
[0128] Step S64: Incorporate the identification results of the cross-card risk identification into the risk assessment information.
[0129] In this embodiment, a single user may have multiple verification cards simultaneously, all associated with the user's identity information. The target verification card is any verification card other than the one currently being verified for that user. The verification system can query the user's identity information and determine the user's other verification cards, i.e., the target verification card, by leveraging the association between the verification card and the user's identity information.
[0130] Furthermore, by acquiring the historical reimbursement records of the target reimbursement card, the reimbursement system can perform cross-card risk identification for all reimbursement records and information of a single user, thereby reducing the possibility of one of a user's multiple reimbursement cards being fraudulently used. The reimbursement system can load risk identification rules based on a rule engine to perform cross-card risk identification on the user's historical reimbursement records. The reimbursement system will simultaneously adjust risk assessment information based on the results of the cross-card risk identification. These risk identification rules can be cross-card risk identification rules or the same as the risk identification rules for a single reimbursement card.
[0131] Based on the user identity information corresponding to the redemption card, this application embodiment uses risk control rules to identify cross-card risks for different redemption cards of the user, and incorporates the results into the overall risk assessment information, thereby comprehensively assessing the user's redemption behavior on multiple cards, effectively identifying potential cross-card risks, and further enhancing the security and risk control capabilities of the redemption process.
[0132] Since the system described in Embodiment 4 of this application is a system used to implement the method of Embodiment 1 of this application, those skilled in the art can understand the specific structure and variations of the system based on the method described in Embodiment 1 of this application, and therefore will not be described again here. All systems used in the method of Embodiment 1 of this application fall within the scope of protection of this application.
[0133] Based on the same inventive concept, this application also provides a fifth embodiment, referring to... Figure 5 , Figure 5This is a flowchart illustrating the fifth embodiment of the risk identification method for write-off in this application.
[0134] In this embodiment, the risk identification method for write-offs further includes steps S71-S73:
[0135] Step S71: Obtain the reconciliation action information of the reconciliation action, and determine the reconciliation amount, reconciliation location and / or reconciliation time in the reconciliation action information;
[0136] Step S72: Associate the reimbursement amount, the reimbursement location, and / or the reimbursement time with the reimbursement information to generate a reimbursement record;
[0137] Step S73: Update the verification card information of the verification card and update the verification record to the historical verification record of the verification card information.
[0138] In this embodiment, after executing a reconciliation action, the reconciliation system will also generate a reconciliation record based on the reconciliation action information and the reconciliation information, for subsequent reconciliation actions and risk identification work.
[0139] As an optional implementation, the reconciliation system can synchronize reconciliation records to a local database or a cloud database. Based on database join operations, the system associates the extracted reconciliation amount, location, and time with the original reconciliation information. For example, using the reconciliation information as the primary key and the reconciliation amount, location, and time as join fields, a complete reconciliation record is generated and updated in the historical reconciliation records of the reconciliation card information. Simultaneously, the system also updates information such as the balance in the reconciliation card information based on the reconciliation action.
[0140] As an alternative implementation, the verification system can also be based on blockchain to form a complete storage of verification records. The verification system packages the verification amount, verification location, and verification time along with the verification information into a block, and adds this block to the verification card's blockchain in a consensus manner to form transaction evidence.
[0141] Since the system described in Embodiment 5 of this application is a system used to implement the method of Embodiment 1 of this application, those skilled in the art can understand the specific structure and variations of the system based on the method described in Embodiment 1 of this application, and therefore will not be described again here. All systems used in the method of Embodiment 1 of this application fall within the scope of protection of this application.
[0142] This application provides a risk identification device for write-offs, the device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the risk identification method for write-offs in Embodiment 1 described above.
[0143] The following is for reference. Figure 6 The diagram illustrates a structural schematic of a risk identification device suitable for implementing the write-off process in the embodiments of this application. The risk identification device for write-off in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital radio receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 6 The risk identification device shown for write-off is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0144] like Figure 6As shown, the risk identification device for write-offs may include a processing unit 1001 (e.g., a core processor, graphics processor, etc.), which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 1002 or a program loaded from storage device 1003 into random access memory (RAM) 1004. The random access memory 1004 also stores various programs and data required for the operation of the risk identification device for write-offs. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to I / O interface 1006: input devices 1007 including, for example, touchscreens, touchpads, keyboards, mice, image sensors, microphones, accelerometers, gyroscopes, etc.; output devices 1008 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 1003 including, for example, magnetic tapes, hard disks, etc.; and communication devices 1009. Communication device 1009 allows the risk identification device for write-offs to communicate wirelessly or wiredly with other devices to exchange data. Although the figure shows a risk identification device for write-offs with various systems, it should be understood that it is not required to implement or possess all the systems shown. More or fewer systems may be implemented alternatively.
[0145] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from read-only memory 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0146] The risk identification device for card cancellation provided in this application, employing the risk identification method for card cancellation in the above embodiments, can solve the technical problem of high risk during the cancellation process due to the ease with which cancellation cards can be fraudulently used. Compared with the prior art, the beneficial effects of the risk identification device for card cancellation provided in this application are the same as those of the risk identification method for card cancellation provided in the above embodiments, and other technical features of the risk identification device for card cancellation are the same as those disclosed in the previous embodiment method, and will not be repeated here.
[0147] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0148] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0149] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to perform the risk identification method for write-off in the above embodiments.
[0150] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, radio frequency (RF), etc., or any suitable combination thereof.
[0151] The aforementioned computer-readable storage medium may be included in the risk identification device for write-off; or it may exist independently and not be assembled into the risk identification device for write-off.
[0152] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by the risk identification device for verification, the risk identification device for verification causes the device to: receive a verification request and obtain identification information and verification information from the verification request; query the verification card corresponding to the identification information and obtain the historical verification records of the verification card; load risk identification rules through a verification rule engine, perform risk identification on the historical verification records and the verification information, and obtain risk assessment information; identify abnormal interaction information in the verification request through a behavior analysis model, adjust the risk assessment information according to the abnormal interaction information, and determine the risk identification result; and when the risk identification result is passed, execute the verification action of the verification card based on the verification information.
[0153] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0154] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0155] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0156] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described risk identification method for verification. This addresses the technical problem that verification cards are easily stolen, leading to high risks during the verification process. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the risk identification method for verification provided in the above embodiments, and will not be elaborated upon here.
[0157] The above description is only part of the embodiments of the present application and does not limit the patent scope of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A risk identification method for write-offs, characterized in that, The method includes the following steps: Receive a reversal request and obtain the identification information and reversal information from the reversal request; Query the verification card corresponding to the identification information and obtain the historical verification records of the verification card; Risk identification rules are loaded through a reconciliation rule engine to identify risks in the historical reconciliation records and the reconciliation information, thereby obtaining risk assessment information. Specifically, the reconciliation location in the reconciliation information is obtained, as well as the target reconciliation time and target reconciliation location corresponding to the target historical reconciliation record in the historical reconciliation records. The current system time is used as the reconciliation time of the reconciliation information, and the reconciliation time interval between the reconciliation time and the target reconciliation time is determined. When the reconciliation time interval is less than a time interval threshold, the reconciliation distance between the reconciliation location and the target reconciliation location is calculated. If the reconciliation distance is greater than a distance threshold, the reconciliation information is deemed to pose a risk. Collect the interaction data corresponding to the reimbursement request, and generate an interaction time sequence and interaction operation trajectory based on the interaction time corresponding to the interaction data, wherein the interaction data includes operation records including clicks, inputs and / or swipes; The interaction time series and the interaction operation trajectory are used as the operation behavior data of the verification request and input into a pre-trained behavior analysis model to obtain an abnormal operation probability value. The behavior analysis model is based on deep learning, and is trained on a preset model to be trained through a training set. The model parameters and / or abnormal operation features are adjusted based on the test results. The behavior analysis model identifies abnormal operations based on the regularity of the interaction frequency in the operation behavior data and / or the smoothness of the interaction operation trajectory. The abnormal operations include abnormal human-machine operations. When the probability value of the abnormal operation exceeds the probability threshold, a biometric authentication action is triggered; based on the authentication result of the authentication action, the risk assessment information is adjusted to determine the risk identification result. When the risk identification result is passed, the verification action of the verification card is performed based on the verification information.
2. The method as described in claim 1, characterized in that, The step of inputting the interaction time series and the interaction operation trajectory as the operation behavior data of the reimbursement request into a pre-trained behavior analysis model to obtain the abnormal operation probability value includes: Based on the behavior heatmap corresponding to the operation behavior data, as well as the interaction time series and the interaction operation trajectory, operation feature data is extracted; The operation feature data is matched with preset abnormal operation features to obtain the matching degree of the operation feature data; Based on preset weight values, the matching degrees of different operation feature data are weighted and summed to obtain the probability value of abnormal operation.
3. The method as described in claim 1, characterized in that, The risk identification method for write-off also includes: When the risk identification result indicates that the revocation information is at risk, an authentication request is output. Obtain the feedback information of the authentication request, and execute the authentication action corresponding to the feedback information to obtain the authentication information; The verification card information of the verification card is compared with the identity verification information to obtain the identity verification result; When the authentication result is successful, the verification action of the verification information is performed.
4. The method as described in claim 3, characterized in that, The steps of obtaining feedback information from the authentication request and executing the authentication action corresponding to the feedback information to obtain authentication information include: The device information of the verification terminal is obtained from the feedback information; Based on the device information, determine the candidate verification strategies and their priorities; Based on the priority, a target verification strategy is selected from the candidate verification strategies; Execute the authentication action corresponding to the target authentication policy to obtain the authentication information.
5. The method as described in claim 1, characterized in that, The step of querying the redemption card corresponding to the identification information and obtaining the historical redemption records of the redemption card includes: Based on the identification information field in the verification request, the identification information type of the identification information is identified, wherein the identification information type includes biometric information, identity identification information and / or verification card identification information; Based on the identification information type, query the database for the verification card corresponding to the identification information; Obtain the verification card information of the verification card, and the historical verification records in the verification card information.
6. The method as described in claim 1, characterized in that, After the step of querying the redemption card corresponding to the identification information and obtaining the historical redemption records of the redemption card, the method further includes: Obtain the user identity information corresponding to the verification card, and determine the target verification card associated with the user identity information; From the target redemption card information of the target redemption card, obtain the cross-card historical redemption record corresponding to the user identity information; Based on the risk identification rules and the cross-card historical reversal records, cross-card risk identification is performed on the reversal information; The identification results of the cross-card risk identification are incorporated into the risk assessment information.
7. A risk identification device for write-off verification, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the risk identification method for write-off as described in any one of claims 1 to 6.
8. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the risk identification method for write-off as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Anomaly detection device and method for security information interaction
CN103544429A
Payment anomaly detection method and system
CN105631668A
Method and device for providing unusual transaction
CN106611316A
Identity authentication method and system based on user behavior model
CN106911668A
Card coupon cancel-after-verification method based on two-dimensional code
CN113159865A