Data processing method, device and equipment and readable storage medium
By obtaining verification palmprint features and business features, and combining the palmprint feature library and historical business database for multi-dimensional risk identification, the problems of environmental anomalies and forged palmprints in palm swiping verification are solved, and the security of business execution is improved.
Patent Information
- Application Number
- CN202410316933.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-19
- Publication Date
- 2025-09-19
AI Technical Summary
Existing palm swiping verification technology cannot effectively identify risks such as environmental anomalies, palm print forgery, and similar palm prints, resulting in illegal users being able to use forged palm prints to successfully perform unauthorized business, reducing the security of business execution.
By obtaining and verifying palmprint features and business features, combined with the palmprint feature library and historical business database, multi-dimensional risk identification is performed, including the measurement of object identity risk and execution risk, and corresponding execution strategies are formulated to improve security.
Through multi-dimensional risk identification solutions, we can more effectively explore the risk levels in palmprint recognition and business, formulate different execution strategies, and thus improve the execution security of palm print business.
Smart Images

Figure CN120672102A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a data processing method, apparatus, device, and readable storage medium. Background Art
[0002] With the development of artificial intelligence (AI) technology, palm swipe verification is being applied in many scenarios, such as access control, payment, and clocking in. Palm swipe verification is a mobile authentication method based on biometrics. After activating palm swipe verification, users scan their palm print in the palm print recognition area of the device. Once the palm print is recognized, verification is complete. Compared with facial recognition and QR code scanning, palm swipe verification offers advantages such as reduced privacy leakage and ease of use.
[0003] In the related art, the specific method of palm swiping verification is: collect the palm print information provided by the user; then, compare the collected palm print information with the palm print information registered for this account, so that the comparison result can be used to determine whether the palm swiping verification is passed. If the comparison is successful, the palm swiping verification is passed, and the user can successfully perform the business indicated by this palm swiping (such as opening access control, payment, etc.). This method is relatively simple and cannot identify risk issues such as environmental anomalies, palm print forgery, palm print misidentification, and similar palm prints. Illegal users can use forged palm prints and similar palm prints to successfully perform businesses that they do not have permission to do, and the execution security of palm swiping services is very low. Summary of the Invention
[0004] The embodiments of the present application provide a data processing method, apparatus, device, and readable storage medium, which can improve the execution security of the palm-swiping service.
[0005] On the one hand, an embodiment of the present application provides a data processing method, including:
[0006] In response to the service request, obtaining a palm print feature for verifying the service request and a service feature of a target service requested by the service request;
[0007] Obtaining a palmprint feature database and a historical business database associated with a target business, wherein the palmprint feature database stores reference palmprint features of multiple reference objects; and the historical business database stores multiple historical business features, which are generated based on historical business data of the target business.
[0008] Matching the verified palm print features with the palm print feature database to determine the first risk of the target business, which is used to measure the risk level of the target business's object identity;
[0009] Compare the business characteristics of the target business with the historical business characteristics in the historical business database to determine the secondary risk of the target business. The secondary risk is used to measure the execution risk level of the target business.
[0010] Determining an execution strategy for the target business based on the first risk and the second risk; and executing the target business according to the determined execution strategy.
[0011] In one aspect, an embodiment of the present application provides a data processing device, including:
[0012] A response module, configured to respond to a service request and obtain a palm print feature for verifying the service request and a service feature of a target service requested by the service request;
[0013] An acquisition module is used to acquire a palmprint feature library and a historical business database associated with a target business, wherein the palmprint feature library stores reference palmprint features of multiple reference objects; and the historical business database stores multiple historical business features, which are generated based on historical business data of the target business.
[0014] A risk determination module is used to match the verified palm print features with the palm print feature library to determine the first risk of the target business, where the first risk is used to measure the risk level of the target business's subject identity;
[0015] The risk determination module is further used to compare the business characteristics of the target business with the historical business characteristics in the historical business database to determine the second risk of the target business. The second risk is used to measure the execution risk level of the target business.
[0016] The policy determination module is configured to determine an execution policy for the target business based on the first risk and the second risk; and execute the target business according to the determined execution policy.
[0017] In one embodiment, the number of verification palmprint features is N, and the N verification palmprint features belong to different modalities; the number of palmprint feature libraries is N, and the N palmprint feature libraries belong to different modalities; N is a positive integer;
[0018] The specific implementation method of the risk determination module performing similarity cross-matching on N verified palmprint features and N palmprint feature libraries, and determining a set of similar objects of N verified palmprint features from multiple reference objects, includes:
[0019] The verification palmprint features and the palmprint feature library with the same modality are determined as a similarity matching group, and N similarity matching groups are obtained;
[0020] Based on the verification palmprint features and the palmprint feature library contained in each similarity matching group, a similar palmprint feature set corresponding to each similarity matching group is determined; the similar palmprint feature set corresponding to the similarity matching group includes one or more reference palmprint features;
[0021] The intersection of N similar palmprint feature sets is obtained, and the set consisting of the reference objects indicated by each reference palmprint feature contained in the intersection is determined as the similar object set of N verified palmprint features.
[0022] In one embodiment, the risk determination module determines a similar palmprint feature set corresponding to each similarity matching group from multiple reference objects based on the verified palmprint features and the palmprint feature library contained in each similarity matching group, including:
[0023] Determine any one of the N similarity matching groups as a target matching group, determine the verification palmprint features contained in the target matching group as target palmprint features, and determine the palmprint feature library contained in the target matching group as a target palmprint feature library;
[0024] Calculating the feature similarity between the target palmprint feature and each reference palmprint feature in the target palmprint feature library to obtain multiple feature similarities;
[0025] Determine a feature similarity greater than a similarity threshold among the multiple feature similarities as a candidate similarity;
[0026] The reference palmprint features indicated by the candidate similarities in the target palmprint feature library are combined into a similar palmprint feature set corresponding to the target palmprint feature library.
[0027] In one embodiment, the risk determination module determines the first risk of the target business based on the social attribute information of each reference object in the similar object set. The specific implementation method includes:
[0028] Get the permission holder of the target business;
[0029] Determine all reference objects other than the permission holder object in the similar object set as similar objects of the permission holder object;
[0030] Perform relationship analysis on the social attribute information of each similar object and the permission holder object to obtain the social relationship attributes between each similar object and the permission holder object; the social relationship attributes include relationship-possessing attributes and relationship-non-possessing attributes;
[0031] If any similar object in the similar object set has a social relationship attribute with the permission holder, the first risk of the target business is determined to be the risk of abnormal acquaintance identity;
[0032] If there is no similar object in the similar object set, and the social relationship attribute between the target business object and the business object is a relationship-possessing attribute, then the first risk of the target business is determined to be a common identity anomaly risk.
[0033] In one embodiment, the risk determination module determines a specific implementation method of the first risk of the target business based on the number of objects and the business type of the target business, including:
[0034] If the number of objects is less than the valid value, and the target business is the palmprint registration business, the first risk of the target business is determined to be the identity risk;
[0035] If the number of objects is less than the valid value, and the target business is a resource payment business, the first risk of the target business is determined to be a common identity abnormality risk;
[0036] If the number of objects is equal to the valid value, and the target business is the palmprint registration business, then the first risk of the target business is determined to be the common identity abnormality risk;
[0037] If the number of objects is equal to the valid value, and the target business is a resource payment business, it is determined that the first risk of the target business is the identity risk.
[0038] In one embodiment, the risk determination module compares the business characteristics of the target business with the historical business characteristics in the historical business database to determine the second risk of the target business. The specific implementation method includes:
[0039] Obtain the business object associated with the target business, obtain the account characteristics associated with the business object from the business characteristics of the target business, and obtain the historical account characteristics associated with the business object from the historical business database;
[0040] Compare the account characteristics associated with the business object with historical account characteristics to determine the account risk of the target business;
[0041] Extracting content features of the business content of the target business from the business features of the target business, and extracting historical content features associated with the business content of the target business from a historical business database;
[0042] Compare the content characteristics of the target business with historical content characteristics to determine the content risk of the target business;
[0043] Determine the secondary risk of the target business based on account risk and content risk.
[0044] In one embodiment, the risk determination module compares the account characteristics associated with the business object with historical account characteristics to determine the abnormal account risk of the target business. The specific implementation method includes:
[0045] Input the account characteristics and historical account characteristics associated with the business object into the account risk prediction model;
[0046] Through the account risk prediction model, the account characteristics associated with the business object are compared and analyzed with historical account characteristics to determine the account risk prediction value;
[0047] If the account risk prediction value is greater than the account abnormality threshold, the account risk of the target business is determined to be account abnormality risk;
[0048] If the account risk prediction value is less than the account abnormality threshold, the account risk of the target business is determined to be no risk.
[0049] In one embodiment, the risk determination module determines the second risk of the target business based on the account risk and the content risk, including:
[0050] If the account risk is an abnormal account risk, or the content risk is an abnormal content risk, the second risk of the target business is determined to be an abnormal execution risk;
[0051] If the account risk is that there is no risk for the account and the content risk is that there is no risk for the content, the second risk of the target business is determined to be a reasonable execution risk.
[0052] In one embodiment, the policy determination module determines a specific implementation of the execution policy of the target business based on the first risk and the second risk, including:
[0053] If the object identity risk level measured by the first risk is lower than the first level threshold, and the execution risk level measured by the second risk is lower than the second level threshold, then determining that the execution strategy for the target business is the direct execution strategy;
[0054] If the object identity risk level measured by the first risk is lower than the first level threshold, and the execution risk level measured by the second risk is higher than the second level threshold, determining that the execution strategy of the target business is an interception execution strategy;
[0055] If the object identity risk level measured by the first risk is higher than a first level threshold, and the execution risk level measured by the second risk is lower than a second level threshold, then determining that the execution strategy for the target business is the additional verification execution strategy;
[0056] If the object identity risk level measured by the first risk is higher than a first level threshold, and the execution risk level measured by the second risk is higher than a second level threshold, the execution strategy of the target business is determined to be an interception execution strategy.
[0057] In one aspect, an embodiment of the present application provides a computer device, including: a processor and a memory;
[0058] The memory stores a computer program, and when the computer program is executed by the processor, the processor executes the method in the embodiment of the present application.
[0059] On one hand, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. The computer program includes program instructions. When the program instructions are executed by a processor, the method in the embodiment of the present application is executed.
[0060] In one aspect of the present application, a computer program product is provided, comprising a computer program stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium and executes the computer program, causing the computer device to perform the method provided in one aspect of the embodiments of the present application.
[0061] In an embodiment of the present application, a multi-dimensional risk identification solution is provided for palm swiping services. Specifically, after receiving a service request, based on the target service of this service request, the palm print features (called verification palm print features) and service features of this time can be collected. Then, based on the verification palm print features of this time and the reference palm print features of multiple reference objects stored in the palm print feature library, the object identity risk level of the target service can be identified and measured to obtain the first risk in the dimension of object identity; based on the service features of this time and the historical service features stored in the historical service database, the execution risk level of the target service can be identified and measured to obtain the second risk in the execution of the target service; based on the first risk and the second risk of different dimensions, it can be comprehensively determined whether there is a risk in the execution of the target service, and based on the comprehensive determination result, the execution strategy of the target service can be determined, and then the target service can be executed according to the execution strategy. It should be understood that through multi-dimensional risk identification, the risk level in palm print identification and service can be more effectively excavated. For risks of different dimensions, this application can also formulate different execution strategies, thereby improving the execution security of the palm swiping service. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0063] Figure 1 This is a schematic diagram of the architecture of a multi-dimensional risk identification system provided by an exemplary embodiment of the present application;
[0064] Figure 2This is a flow chart of a data processing method provided in an embodiment of the present application;
[0065] Figure 3 This is a schematic diagram of a liveness detection provided by an embodiment of the present application;
[0066] Figure 4 This is a flow chart of determining a set of similar objects through similarity cross matching provided by an embodiment of the present application;
[0067] Figure 5 This is a schematic diagram of measuring the risk level of an object's identity through similarity cross-matching provided in an embodiment of the present application;
[0068] Figure 6 This is a schematic diagram of an architecture of a palm-swipe payment architecture provided by an embodiment of the present application;
[0069] Figure 7 is a structural diagram of a data processing device provided in an embodiment of the present application;
[0070] Figure 8 It is a structural diagram of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0071] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0072] The embodiments of the present application involve artificial intelligence and related technologies. For ease of understanding, artificial intelligence and related technical terms and concepts will be briefly explained below.
[0073] 1. Artificial Intelligence (AI):
[0074] Artificial intelligence (AI) refers to the theories, methods, techniques, and application systems that use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to achieve optimal results. AI technology is an interdisciplinary discipline encompassing a wide range of fields, encompassing both hardware and software technologies. Foundational AI technologies generally include sensors, specialized AI chips, cloud computing, distributed storage, big data processing, operating / interaction systems, and mechatronics. AI software technologies primarily encompass computer vision, speech processing, natural language processing, and machine learning / deep learning.
[0075] 2. Machine Learning (ML):
[0076] Machine learning is a multidisciplinary field that encompasses probability theory, statistics, approximation theory, convex analysis, and algorithmic complexity theory. It specifically studies how computers can simulate or implement human learning behaviors to acquire new knowledge or skills and reorganize existing knowledge structures to continuously improve their performance. Machine learning is at the core of artificial intelligence and the fundamental way to make computers intelligent. Its applications span all areas of artificial intelligence. Machine learning and deep learning typically include techniques such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and self-learning.
[0077] 3. Computer Vision (CV)
[0078] Computer vision is the study of how machines can "see." Specifically, it refers to machine vision, which uses cameras and computers to replace the human eye in identifying and measuring objects. Further image processing is performed to transform the computer-generated images into images more suitable for human observation or transmission to instrumentation. As a scientific discipline, computer vision studies related theories and technologies, aiming to build artificial intelligence systems capable of extracting information from images or multidimensional data. Computer vision technologies typically include image processing, image recognition, image semantic understanding, image retrieval, optical character recognition (OCR), video processing, video semantic understanding, video content / behavior recognition, three-dimensional object reconstruction, 3D technology, virtual reality, augmented reality, simultaneous localization and mapping, and common biometric recognition technologies such as facial recognition and fingerprint recognition.
[0079] 4. Palm map:
[0080] A palm image refers to an image of a subject's hand or foot captured by a capture device (e.g., a camera, infrared sensor, etc.). The subject here can be any object with hands or feet, such as a person, animal, or other object. The palm image data corresponding to the palm image can have different forms, including but not limited to at least one of the following: a first form, a second form, and a third form. The first form of palm image data can be a color image, which refers to a color image of the hand or foot, captured by a color sensor using natural light imaging. The second form of palm image data can be a depth map, which is obtained by capturing speckle-structured infrared light with an infrared sensor and then analyzing the speckle with a depth unit. In 3D computer graphics and computer vision, a depth map is an image or image channel that contains information about the distance from the surface of a scene object to the viewpoint. Each pixel in the depth map represents the vertical distance between the depth camera plane and the plane of the object being photographed, typically represented in 16 bits, in millimeters. The second form of palm image data can be an infrared image (or IR map), which refers to an infrared image of the hand or foot output by an infrared image sensor.
[0081] In the embodiments of this application, machine learning technology can be specifically applied to model training. For example, it can be specifically applied to the training of the account risk prediction model mentioned later. By using machine learning to train the model, the results output by the model can be made increasingly accurate and reasonable. Computer vision technology can be applied to palm print feature recognition to identify palm print features.
[0082] In actual applications, palm swiping verification (or palm swiping authentication) technology has been applied to many scenarios. Specifically, different objects (for example, users) can first authorize the activation of palm swiping authentication to perform different services (for example, access control services, clocking in services, payment services, etc.) through palm swiping authentication. The objects can enter their own palm prints in the device that requests the activation of palm swiping authentication to register their own palm prints. In this way, when the subsequent objects want to perform this service, they can authenticate by swiping their palms on the palm swiping device. For example, if the target object wants to perform the access control service, the target object can enter his or her palm on the palm swiping device. Based on the palm of the target object, the palm image data of this service can be determined. By identifying or extracting the palm print features of different palm image data, the palm print features of the palm image data can be obtained; based on the palm print features, the object identity matching can be performed on the object that entered the palm image data this time to determine whether the object identity has been authenticated. After the authentication has been passed, the palm swiping object can perform this service. Traditional technologies use overly simplistic authentication methods in palm-swipe authentication scenarios, failing to identify the various risks inherent in these scenarios. This creates opportunities for unauthorized parties to illegally execute services, significantly increasing the probability of unauthorized users passing authentication and reducing the security of service execution. To enhance security in palm-swipe service scenarios, this application provides a multi-dimensional risk identification solution for the palm-swipe process that addresses the limitations of traditional palm-swipe authentication and conducts multi-dimensional risk detection on service execution, thereby enhancing service execution security.Among them, the multi-dimensional risk identification scheme in the palm swiping process involved in this scheme can include at least four consecutive steps: 1. First, if an object (such as a user) enters his or her palm through a palm swiping device to request to execute a target business (for example, access control business, payment business, clocking in business, etc.), then the processor can receive the business request initiated by this object regarding this target business, and then the processor can respond to the business request and obtain the palm image data collected on the palm swiping device; 2. The palm print features of the palm image data are extracted, and the extracted palm print features can be used as the verification of this business request. At the same time, the relevant business features of the target business can be obtained (the business features can be set based on the actual needs of the business. For example, when the business is a payment business, the business features can be set as the time of this payment, merchant information, the amount of this payment, the device information of this payment, the payment frequency of this payment on the same day, the amount distribution on the same day, etc.); 3. Match the palm print features of this verification with the palm print feature library to determine the identity risk level of the target business object, wherein the palm print feature library here refers to a preset database for storing palm print features of different objects, and the various Each palmprint feature can be understood as a reference palmprint feature for palmprint feature comparison, and the object to which each palmprint feature in the palmprint feature library belongs can also be correspondingly referred to as a reference object. Through matching processing, the risk level of the identity of the requesting party initiating this service request can be determined. If the risk level is low, then it can be considered that the probability of the identity of the requesting party being at risk is low. 4. In addition to matching the verification palmprint feature with the palmprint feature library, the present application also compares the service features of the target service with the historical service features in the historical service database to determine the execution risk level of the target service. The historical service database here can refer to a preset database for storing relevant execution data of different services. This historical service database will store historical service features of different historical services. Through comparison processing, the risk level of the execution of this target service can be determined. If the risk level is low, then it can be considered that there is no risk in executing this target service. 5. Based on the risks determined in steps 3 and 4 above, the execution risk of this target service is comprehensively determined, and then the execution strategy for the target service (for example, direct execution strategy, interception execution strategy, or verification execution strategy) is determined. The target service can be executed according to the determined execution strategy.
[0083] For example, taking the target business as payment business, an object wants to transfer resources belonging to a certain business object to another object by swiping its palm. Then, after the palm-swiping object enters a palm, this application can obtain the palm print features of the palm entered by the palm-swiping object and use it as the verification palm print features; then, based on the solution provided by this solution, it can be determined whether there is a risk in the identity of the palm-swiping object (for example, the risk that the palm-swiping object and the object to which the resources for this payment belong are not the same person), and it can also be determined whether there is a risk in the execution of this payment; in this way, the risks of this payment business can be comprehensively identified from multiple dimensions, and the execution strategy of this payment business can be specified based on the determined risks.
[0084] It can be seen that the multi-dimensional risk identification solution provided by the embodiment of the present application can identify possible risks of the business based on different dimensions. Through multi-dimensional risk identification, it can more effectively explore the risk level in palmprint recognition and business. For risks of different dimensions, the present application can also formulate different execution strategies, thereby improving the execution security of the palm swiping business.
[0085] The multi-dimensional risk identification solution provided in the embodiments of the present application can be applied to various palm-swiping business scenarios, including but not limited to: access control business scenarios, payment business scenarios, clock-in business scenarios, etc. Since the solution provided in the present application can improve the security of palm-swiping business and effectively improve business coverage to a certain extent (such as expanding applicable scenarios), that is to say, the several application scenarios given above are only examples and do not limit the application scenarios to which the solution provided in the embodiments of the present application is applicable.
[0086] Furthermore, the solution provided in the embodiment of the present application can be executed by a computer device, which may include a palm-swipe device or a server. The computer device may also include a palm-swipe device and a server. To facilitate understanding of the multi-dimensional risk identification solution provided in the embodiment of the present application, the following is combined with Figure 1 The multi-dimensional risk identification system shown introduces the application scenarios involved in the embodiments of the present application; wherein, Figure 1 This is a schematic diagram of the architecture of a multi-dimensional risk identification system provided by an exemplary embodiment of the present application. Figure 1 As shown, the system includes a palm-swiping device 101 and a server 102; wherein:
[0087] 1) The palm-swiping device 101 may be, but is not limited to, a device with image data acquisition capabilities, such as a camera, camcorder, scanner, or lidar, or various desktop computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices with integrated image acquisition devices. IoT devices may include smart speakers, smart TVs, smart air conditioners, and smart car-mounted devices. Portable wearable devices may include smart watches, smart bracelets, and head-mounted devices.
[0088] 2) The server 102 may be a server corresponding to the palm-swiping device, and is used to interact with the palm-swiping device for data exchange so as to provide computing and application service support for the palm-swiping device. Specifically, the server is a background server corresponding to the application deployed in the palm-swiping device, and is used to interact with the palm-swiping device to provide computing and application servers for the application. The server 102 may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0089] The palm-brush device 101 and the server 102 may be connected directly or indirectly via wired or wireless communication, which is not limited in this application. In addition, the embodiment of this application does not limit the number of palm-brush devices and servers; Figure 1 The number of palm-swiping devices 101 and servers 102 is only one for example. In actual applications, multiple distributed servers may be included, which is specially explained here.
[0090] Based on the solution and system architecture described above, the following points need to be explained:
[0091] ① The above-mentioned embodiments of this application Figure 1The system shown is for the purpose of more clearly illustrating the technical solution of the embodiment of the present application, and does not constitute a limitation on the technical solution provided by the embodiment of the present application. A person skilled in the art will appreciate that, with the evolution of the system architecture and the emergence of new business scenarios, the technical solution provided by the embodiment of the present application is equally applicable to similar technical problems. For example, the above is an introduction to an application scenario of the present solution by taking the example of the execution subject "computer device" of the embodiment of the present application including a palm-brush device and a server, that is, the palm-brush device and the server jointly execute the solution provided by the embodiment of the present application; it should be understood that, in actual applications, the computer device can also be a palm-brush device or a server, that is, it supports the palm-brush device or the server to independently execute the solution provided by the embodiment of the present application.
[0092] ② The collection and processing of relevant data in the embodiments of this application should be strictly in accordance with the requirements of relevant laws and regulations. The acquisition of personal information must be subject to the knowledge or consent of the individual subject (or the legal basis for obtaining the information), and subsequent data use and processing must be carried out within the scope of authorization of laws and regulations and the subject of personal information. For example, when the embodiments of this application are applied to specific products or technologies, such as obtaining the user's application attribute characteristics and social association relationships, the user's permission or consent must be obtained, and the collection, use and processing of relevant data (such as palm images and palm print data) must comply with the relevant laws, regulations and standards of the relevant region.
[0093] Based on the above-described solution, the present embodiment proposes a more detailed data processing method. The data processing method proposed in the present embodiment will be described in detail below with reference to the accompanying drawings. Figure 2 , Figure 2 This is a flow chart of a data processing method provided by an embodiment of the present application, which can be executed by the server in the aforementioned system. Figure 2 As shown, the process may include at least the following steps S201 to S205:
[0094] Step S201: In response to a service request, obtaining a palm print feature for verifying the service request and a service feature of a target service requested by the service request.
[0095] In this application, a business request may refer to a request to execute a business. If an object (for example, a user) wants to execute a business, the object may initiate a business request. If the business needs to be executed after palm swiping verification, the object needs to provide a palm information to the palm swiping device simultaneously when initiating the business request. Specifically, the object may collect palm image data by calling the camera on the palm swiping device. In this way, the server may obtain the palm image data provided by the object on the palm swiping device, and extract a palm print feature based on the palm image data. The server needs to perform verification based on the palm print feature to determine the identity of the object providing the palm image data. In this application, it may be referred to as a verified palm print feature.
[0096] That is to say, the palm print features for verification in this application refer to the palm print features of the palm image data provided by the object initiating the service request. The object initiating the service request can be called the target object or the request object. The request object can be determined based on the specific service scenario. For example, in the shopping service scenario, the request object can be a shopper; in the game service scenario, the request object can be a game user; in the live broadcast service scenario, the request object can refer to a live broadcaster. That is to say, the service in this application can refer to the service determined based on the specific service scenario. For example, the service can refer to the login service, payment service, redemption service, etc. in a certain service scenario. The target service in this application can refer to any service, and the service features of the target service can be set based on the actual needs of the service. For example, when the target service is a payment service, the service features can be set to the time of this payment, merchant information, the relationship between the payment account and merchant information, the location information of this payment, the amount of this payment, the device information of this payment, the frequency of daily payments, the daily amount distribution, the items included in this payment, etc.
[0097] In the process of collecting the palm image data of the requesting object by the palm scanning device, liveness detection can be performed on the requesting object to ensure that the requesting object does not use a static palm image, a video containing a palm, or a 3D model to scan the palm. For details, please refer to the liveness detection process for more information. Figure 3 , Figure 3This is a schematic diagram of liveness detection provided by an embodiment of the present application. The palm image data of the first form, second form and third form of the requested object can be collected from multiple angles through the camera module of the palm-swiping device (including color sensor, infrared light, infrared sensor, 3D structured light) to obtain color image, infrared image and depth image. Based on the infrared sensor, speckle infrared image can also be obtained. In addition, the thermal sensor of the palm-swiping device can also perform thermal sensing on other signals of the requested object to obtain thermal sensing information, and send the color image, infrared image, depth image, speckle infrared image and thermal sensing information to the liveness recognition component. The body recognition component can calculate and process the color image, infrared image, depth image, speckle infrared image and thermal sensor information through the corresponding liveness detection algorithm, and finally obtain a liveness detection result (including a liveness detection pass result and a liveness detection fail result). When the liveness detection result is a liveness detection pass result, the subsequent steps S202-S205 can be executed; when the liveness detection result is a liveness detection fail result, it can be indicated that there is a liveness abnormality risk in this target business, and the execution of this target business can be rejected (that is, the execution strategy of the target business is directly determined to be an interception execution strategy).
[0098] It should also be noted that the palm-swiping device may be cracked and controlled by illegal users to perform simulated operations. At this time, any data reported by the palm-swiping device is unreliable. It can be seen that the palm-swiping device also has risks, which will affect the execution security of the target business. In order to improve the security of the execution of the target business in multiple dimensions, this application can also detect the device risks of the palm-swiping device to determine whether it is controlled. Specifically, risk detection can be performed on the root, simulator, repackaging, frida plug-in, xposed, etc. of the palm-swiping device. In addition to the detection capabilities on the terminal, the risk detection here will also collect data (for example, in the payment business, the relationship between the palm-swiping device and the user, the relationship between the device and the merchant, the switching behavior bound to the device, the transaction behavior of the device, etc.) and perform data verification in the background to ensure the accuracy of the detection results. This application will use multiple detection results for comprehensive judgment to determine whether the device risk of the palm-swiping device is an abnormal device risk or no risk exists in the device. When the liveness detection result is a pass result and the palm-swiping device does not have any abnormal risk, the subsequent step S202 can be executed; otherwise, if the liveness detection result is a fail result or the device has an abnormal risk, the execution of this business can be intercepted.
[0099] Step S202: obtaining a palmprint feature database and a historical service database associated with the target service. The palmprint feature database stores reference palmprint features of multiple reference objects; the historical service database stores multiple historical service features, which are generated based on historical service data of the target service.
[0100] In this application, a database can be used to store the palmprint features of different objects (such as users). These palmprint features can include the palmprint features registered by a certain object. The palmprint features used to store the palmprint features of different objects can be called a palmprint feature library. The palmprint features stored in the palmprint feature library can be used as a reference for subsequent palmprint verification, so they can be called reference palmprint features. The object to which each reference palmprint feature belongs can be called a reference object. In addition, this application can also use a database to store the features of different executed services. These executed services can be called historical services (such as a payment service or login service), and historical service features are the service features of historical services.
[0101] It is worth noting that the palm image data in the present application contains different forms (such as the first form, the second form and the third form), and the palm print features obtained based on the palm image data of different forms will also correspond to different forms. Based on this, the present application can configure different palm print feature libraries for different forms. That is to say, there will be multiple verification palm print features in the present application, and the form (or mode) to which each verification palm print feature belongs will be different, and there will also be multiple palm print feature libraries, and the form to which each palm print feature library belongs will also be different.
[0102] Step S203 : matching the verified palmprint feature with the palmprint feature database to determine the first risk of the target business. The first risk is used to measure the risk level of the target business's object identity.
[0103] In this application, the target business may correspond to an object with authority holding the target business. The authority holding the target business is the object that holds the execution authority of the target business. After the requesting object initiates a business request for the target business, it is necessary to authenticate the requesting object based on the verification palm print feature provided by the requesting object through palm swiping to verify whether the requesting object is the authority holding object of this target business. Only after the verification is passed can the target business be successfully executed. Otherwise, it will not be passed and the target business will not be executed. For example, taking the target business as a payment business, this payment business refers to transferring a resource data of object a to object b, then object a can be used as the authority holding object of this payment business. Since this resource data belongs to object a, only object a has the authority to transfer resource data; for another example, taking the target business as a community residents’ access control service as an example, only residents in the community have the authority to open the community access control, then each resident in this community can be used as the authority holding object of the community access control service.
[0104] It should be understood that, based on the above, there will be multiple verification palmprint features and palmprint feature libraries in this application. This application can combine verification palmprint features and palmprint feature libraries of different modalities to provide a similarity cross-matching identity authentication method to verify whether the requesting object is the authority holder of the target business. Through similarity cross-matching, the degree of risk in the identity of the requesting object can be determined (it can also be understood as the probability of risk). This degree can be referred to as the object identity risk degree in this application. If the requesting object has an identity risk, then the execution of the target business will also be risky. It can be seen that a risk of the target business can be identified through similarity cross-matching. This risk can be called the first risk. The first risk can be used to measure the degree of risk in the identity of the requesting object, that is, the object identity risk degree of the target business.
[0105] In a specific implementation, taking the case where both the verification palmprint features and the palmprint feature library have N (N is a positive integer, usually greater than 1, that is, the modalities of the palm image data include N kinds, the palm image data of one modality may correspond to a verification palmprint feature, and each modality may also correspond to a palmprint feature library) as an example, the specific implementation process of matching the verification palmprint features with the palmprint feature library to determine the first risk of the target business may include but is not limited to: first, the N verification palmprint features and the N palmprint feature libraries may be cross-matched for similarity, and a similar object set of N verification palmprint features may be determined from multiple reference objects through similarity cross-matching. It is understandable that each reference object in the similar object set here, its corresponding reference palmprint feature in the palmprint feature library will have a high similarity with the verification palmprint feature. In the case where there are multiple highly similar palmprint features, it will bring certain interference to the palm swipe verification, and the palm swipe verification may be incorrectly verified, affecting the accuracy of the palm swipe verification. Therefore, after obtaining the similar object set, the present application,
[0106] The similar object set can be used to further determine whether the identity of the requesting object is at risk.
[0107] Specifically, the present application may set a valid value (for example, a value of 1), which may be used as a comparison value for the number of reference objects contained in the similar object set. If the number of objects is greater than the valid value, it may be considered that there are at least two reference palmprint features in the palmprint feature library that are sufficiently similar to the verification palmprint feature. In this case, it is not ruled out that the requesting object may be a palmprint-similar object of the authority holder of the target business, rather than the authority holder himself. In other words, in this case, it may be considered that the requesting object is at risk of not being the authority holder himself, so it may be considered that the requesting object has an identity abnormality risk in this case. On this basis, the present application can determine whether these reference objects are acquainted with the permission-holding object based on the social attribute information of each reference object in the similar object set. In this way, the acquaintance between the reference objects in the similar object set and the permission-holding object can be used to determine whether there is a risk of an acquaintance requesting to execute the target business beyond the authority of the target business. If so, the privacy information of the requesting object of this target business can be verified. It should be noted that since the acquaintances of the permission-holding object are likely to know a lot of basic information about the permission-holding object, the privacy information of the requesting object can be verified. Specifically, the requesting object can be required to enter more privacy information of the permission-holding object (such as the last 7 digits of the ID card, date of birth, etc.). If the requesting object passes the verification of the privacy information, it can be considered that the requesting object is indeed the permission-holding object himself and can execute the target business; otherwise, it can be considered that the requesting object is not the permission-holding object and the execution of this target business can be intercepted. Of course, if it is determined that the reference object in the similar object set does not have an acquaintance relationship with the authority holder, then it can be considered that there is no risk of an acquaintance requesting to execute the target business beyond the authority for this target business. At this time, it may be that only a stranger illegally requests the target business. In this case, the basic information of the requesting object can be verified. Because the possibility of the stranger knowing the basic information of the authority holder is small, the basic information verification can be performed. Specifically, the requesting object can be required to enter more basic information of the authority holder (such as the last 4 digits of the mobile phone). If the requesting object passes the verification of the basic information, it can be considered that the requesting object is indeed the authority holder himself and can execute the target business; otherwise, it can be considered that the requesting object is not the authority holder and the execution of this target business can be intercepted.
[0108] That is to say, after determining the similar object set, if the number of reference objects contained in the similar object set is greater than the valid value, the first risk of the target business can be determined based on the social attribute information of each reference object in the similar object set. Its specific implementation process may include but is not limited to: first, the permission holding object of the target business can be obtained; then, all reference objects other than the permission holding object in the similar object set can be determined as similar objects of the permission holding object; after determining the similar objects of the permission holding object, the relationship analysis can be performed between each similar object and the social attribute information of the permission holding object to obtain the social relationship attributes between each similar object and the permission holding object; wherein, the social attribute information of the present application may include the real-name information of the object, the execution relationship of the business (here it can be defined by a specific business scenario, for example, the execution relationship of the payment business can refer to the payment transaction relationship), the commonly used execution location of the business and other information. By comparing this information, it can be determined whether there is a possibility of acquaintance between the two objects, and a social relationship attribute can be obtained. Accordingly, the social relationship attribute will include relationship-possessing attributes and relationship-non-possessing attributes. , the relationship having attributes can indicate the existence of an acquaintance relationship, and the relationship not having the relationship can indicate the non-existence of an acquaintance relationship; if there is any similar object in the similar object set, and the social relationship attribute between it and the authority holding object is the relationship having attributes, then it can be determined that the first risk of the target business is the acquaintance identity abnormality risk, and the acquaintance identity abnormality risk is the risk that the requesting object is an acquaintance friend of the authority holding object of the target business; if there is no similar object in the similar object set, and the social relationship attribute between it and the business object is the relationship having attributes (that is, the social relationship attribute between any similar object in the similar object set and the business object is the relationship not having attributes), then it can be determined that the first risk of the target business is the ordinary identity abnormality risk, and the ordinary identity abnormality risk is the characterization that the requesting object is not the authority holding object of the target business, but may be an ordinary object (non-acquaintance stranger) with a palm print similar to that of the authority holding object. Since compared with ordinary objects, acquaintances know more information about the permission holder, and acquaintances are likely to use some of the known information to pass palm verification, it can be considered that the risk level of acquaintance identity abnormality risk is greater than the risk level of ordinary identity abnormality risk. For risks of different risk levels, this application can adopt information verification methods of different difficulty levels. For example, for requesting objects with the risk of acquaintance identity abnormality, this application can adopt an information verification method with higher difficulty, requiring the requesting object to enter more private information of the permission holder; for requesting objects with the risk of ordinary identity abnormality, this application can adopt an information verification method with lower difficulty, requiring the requesting object to enter some basic information of the permission holder.
[0109] Correspondingly, if the number of reference objects contained in the similar object set is less than or equal to the valid value, the first risk of the target business can be jointly determined based on the number of objects and the business type of the target business. The specific implementation process may include but is not limited to: if the number of objects is less than the valid value, and the target business is a palmprint registration business, then the first risk of the target business can be determined as the identity risk. It should be understood that the palmprint registration business can be understood as a palm swipe verification service activation. When the user activates the palm swipe verification, the user is required to enter the palm image data to obtain the user's palm print features. Then, the user's palm print features can be registered. When the user wants to perform a certain business in the future, he can perform the business by swiping his palm. During the activation phase, the present application can also authenticate the object requesting to register the palm print feature to detect whether the object requesting to enter the palm print feature is the person himself or another object with a similar palm print. In actual applications, when an object that has not registered the palm print feature registers the palm print feature for the first time, there should not be a reference palm print feature with a sufficiently large similarity in the palm print feature library that can be matched. In this case, if the number of objects is less than the valid value (value 1), it can be considered that the requesting object does not have an identity risk at this time, and the first risk of the target business can be determined to be the identity risk. If the number of objects is less than the valid value and the target business is a resource payment business, the first risk of the target business can be determined to be the ordinary identity abnormality risk; it should be understood that when the target business is a resource payment business, if the number of objects is less than the valid value 1, then it can be considered that there is no similar reference palmprint feature that can be matched in the palmprint feature library, then it can be considered that the verification palmprint feature provided by the requesting object is not the palmprint feature of the authority holding object, and it is determined that there is a risk in the identity of the requesting object (that is, the requesting object may be an object that is unknown to the authority holding object and whose palmprint is not similar), and the first risk of the target business is determined to be the ordinary identity abnormality risk. When it is determined that the requesting object has an ordinary identity abnormality risk, the basic information of the requesting object can be verified.
[0110] Furthermore, if the number of objects is equal to the valid value and the target business is the palmprint registration business, the first risk of the target business is determined to be the ordinary identity abnormality risk; it should be understood that in actual applications, when an object that has not registered its palmprint features registers its palmprint features for the first time, there should not be a reference palmprint feature in the palmprint feature library that can be matched with a sufficiently high similarity. If a similar reference palmprint feature is matched, then it can also be considered that the requesting object has an identity risk at this time. The verification palmprint feature provided by the requesting object may not be the palmprint feature of the permission holder. It can be determined as an ordinary identity abnormality risk, and the basic information of the requesting object is additionally verified. If the number of objects is equal to the valid value and the target business is a resource payment business, it can be determined that the first risk of the target business is that the identity does not have a risk; it should be understood that in actual applications, after the user registers the palm print feature, if a reference palm print feature is matched in the palm print feature library, then it can be considered that the matched reference palm print feature is the palm print feature of the permission holding object, so it can be directly considered that there is no risk to its identity. Of course, after matching the reference palm print feature, it is also possible to further detect whether the matched reference palm print feature is the palm print feature of the permission holding object. If the real-name information of the matched reference palm print feature is indeed the permission holding object, then it can be considered that the request object does not have an identity risk. Otherwise, it can be considered that the request object has an identity risk and needs to be verified.
[0111] In summary, through the similarity cross-matching in this step, it can be determined whether the requesting object has the risk of acquaintance identity abnormality, ordinary identity abnormality or identity non-possessing risk. The risk level of acquaintance identity abnormality will be greater than the risk level of ordinary identity abnormality, and the risk level of ordinary identity abnormality will be greater than the risk level of identity non-possessing risk. Based on different risk levels, this application can determine different execution strategies for this target business. For example, the higher the risk level, the more difficult the information verification can be. In this way, the identity of the requesting object can be protected as much as possible.
[0112] Step S204 : comparing the business characteristics of the target business with the historical business characteristics in the historical business database to determine a second risk of the target business. The second risk is used to measure the execution risk level of the target business.
[0113] In the present application, in addition to verifying the identity of the requesting object by verifying the palm print features, the present application can also verify through the business features of the target business to verify whether there is a risk in the execution of this target business. For example, the present application can verify whether there is a risk in executing the target business by comparing the business features of the target business with the historical business features in the historical business database. In a specific implementation, the specific method of comparing the business features of the target business with the historical business features in the historical business database to determine the second risk of the target business may include but is not limited to: first, the business object associated with the target business may be obtained. This business object may refer to the account number of the permission holder of the target business. This account number can be used to uniquely represent the permission holder. Then, the account number characteristics associated with the business object may be obtained from the business characteristics of the target business. The account number characteristics here can be specifically set based on the different target businesses. For example, taking the target business as a payment business, the account number characteristics may include: the payment environment of this account, the payment device, and the merchant of payment. , payment time and frequency on the same day, distribution of payment amount on the same day and other characteristics; for example, taking the target business as the access control business, the account characteristics may include: the time, location, frequency of this account's access control, etc. After obtaining the account characteristics, the historical account characteristics associated with the business object can be obtained from the historical business database. Correspondingly, the historical account characteristics in the historical business database are the common payment environment, common payment devices, common payment merchants, historical payment time and frequency, historical payment amount distribution and other characteristics of this business object in the historical time period; then, the account characteristics associated with the business object are compared with the historical account characteristics to determine the account risk of the target business.
[0114] In actual applications, there may be different types of risks in an account, such as: the risk of account impersonation, the risk caused by account jumping from one location to another, the risk of the account not being operated by the user, the risk of the account being attacked, etc. For different types of account risks, this application can use different account risk prediction models to compare the account features with the historical account features to determine whether the account has any type of account risk. Specifically, the account features associated with the business object and the historical account features can be input into the account risk prediction model; through the account risk prediction model, the account features associated with the business object and the historical account features can be compared and analyzed, and an account risk prediction value can be output, wherein the account risk prediction model here can include an account impersonation risk prediction model, an account jumping risk prediction model, and an account not being operated by the user risk prediction model. Each account risk prediction model can output an account risk prediction value, and then the account risk prediction values output by each model can be weighted and summed, and the result of the weighted summation can be used as the final determined account risk prediction value.
[0115] The specific method for determining the total account risk prediction value through the account risk prediction model can be shown as formula (1):
[0116]
[0117] Among them, as shown in formula (1), a i It can be used to represent the weight value of a certain model (such as the risk prediction model of the i-th account). The weight value of each model can be adaptively configured based on different scenarios and can be dynamically adjusted as the business changes. Usually, its initial value is an average value; f(m i ) is the prediction result of the ith model (the account risk prediction value output by the ith model). After obtaining the total account risk prediction value, it can be compared with the account abnormality threshold. This account abnormality threshold can refer to the risk baseline value at which the account is at risk. For example, it can be set to 0.3, 0.4, etc. If the account risk prediction value is greater than this account abnormality threshold, it can be determined that the account of the target business is at risk, and its account risk can be determined as an account abnormality risk; and if the account risk prediction value is less than the account abnormality threshold, it can be determined that the account of the target business is not at risk, and its account risk can be determined as an account without risk. It should be understood that the higher the account risk prediction value, the higher the corresponding risk level will be, and the higher the degree of risk of the account will be.
[0118] It is worth noting that the account risk prediction model in this application can be any artificial intelligence model with prediction or classification capabilities. For example, the xgb classification model can be used. In order to improve the accuracy of the model output results, this application can use machine learning technology to train various account risk prediction models to improve the accuracy of their output results. For example, taking the account fraud risk prediction model as an example, a large number of sample historical account features of sample accounts can be collected, and the account fraud risk prediction model can be trained offline to improve the accuracy of the model's output results. Among them, for the positive samples of this model, the sample historical account features of normal accounts can be used, and the negative samples can be the sample historical account features of historical fraud accounts that have committed fraud. For example, taking the account cross-region jump risk prediction model as an example, the sample historical account features of a large number of sample accounts can be collected, and the account cross-region jump risk prediction model can be used to accumulate historical long-term features, and the current account features can be combined in real time to determine the combination strategy, and finally output a risk prediction value for account cross-region jump (for example, if the account login device of the target business this time is a new device and the location this time is a new city, then the model will output a larger prediction value; however, if the account login device of the target business this time is a commonly used device, then although the location this time is a new city, the model will also output a smaller prediction value).
[0119] In addition to risk detection of the target business account, risk detection can also be performed on the business content of the target business. The business content of the target business needs to be determined based on the target business. Taking the target business as the payment business as an example, the business content of the target business can include payment amount, payment merchant, payment items, payment frequency, transaction relationship in payment, etc. This application can compare the current business content of the target business with the historical business content of many historical businesses to determine whether the business content of the current target business has risks. Specifically, the content features of the business content of the target business can be extracted from the business features of the target business, and the historical content features associated with the business content of the target business can be extracted from the historical business database. Then, the content features of the target business are compared with the historical content features to determine the content risk of the target business. The content risk can include the risk of abnormal content and the risk of non-existence of content. For example, taking the target business as a payment business, in a specific application, assuming that this payment business is to pay 3,000 yuan to a payment merchant, but by comparing with the historical content features, other reference objects usually pay less than 100 yuan to this merchant, so this payment business is likely to be abnormal; or, assuming that this payment business is to pay 3,000 yuan to a payment merchant, but by comparing with the historical content features, the target business's permission holder has never paid to this merchant or the amount paid to this merchant has not exceeded 20 yuan, then this payment business is likely to be abnormal. It is worth noting that when the target business is a payment business, in order to reduce fraud in the payment scenario, this application can count the payment relationships with fraud risks based on the historical payment businesses and complaint information that have been executed. In this way, after receiving the business request of the target business, through the comparison of content features, it is found that this payment relationship hits the payment relationship with fraud risks. At this time, it can be determined that the business content of the target business has a content abnormality risk.
[0120] Furthermore, after determining the account risk and content risk, the second risk of the target business can be determined based on the account risk and content risk (i.e., the risk level of executing the target business is measured by jointly measuring the account risk and content risk, i.e., measuring the execution risk of the target business). The specific implementation process of determining the second risk of the target business based on the account risk and content risk may include, but is not limited to: comprehensive consideration can be given. If the account risk is an abnormal account risk, or the content risk is an abnormal content risk, then the second risk of the target business can be determined as an abnormal execution risk. It should be understood that when there is a risk in the account or an abnormality in the business content, there is a risk in executing the target business, so the second risk of the target business can be determined as an abnormal execution risk; and if the account risk is that there is no risk in the account, and the content risk is that there is no risk in the content, then the second risk of the target business can be determined as a reasonable execution risk. It should be noted that as long as there is a risk in the account or there is an abnormality in the business content, the execution risk level of the target business can be considered to be severe. When there is no risk in the account and there is no abnormality in the business content, the execution risk level of the target business can be considered to be mild.
[0121] Step S205 : determining an execution strategy for the target business based on the first risk and the second risk; and executing the target business according to the determined execution strategy.
[0122] In this application, after determining the first risk and the second risk, a combined judgment can be made to determine the overall execution risk level of the target business, and then based on the overall execution risk level of the target business, the execution strategy of the target business is determined. Specifically, if the identity risk level of the object measured by the first risk is lower than the first level threshold, and the execution risk level measured by the second risk is lower than the second level threshold, it can be indicated that the identity of the requesting object of the target business has a low risk level, and the business content of the target business has a low risk level. At this time, the execution strategy of the target business can be determined as a direct execution strategy, that is, there is no need to verify the information of the requesting object or intercept the target business, and the target business can be executed (such as executing a payment business and paying the resource data indicated by the target business to the corresponding user); for example, assuming that the first risk determined in the previous article is that the identity does not have a risk, it can be seen that the identity of the current requesting object has a low risk level, and the second risk is a reasonable content risk, it can be seen that the risk level of the current business content is also low. At this time, it can be considered that there is no problem with the identity of the requesting object and the business content is reasonable, and the target business can be directly executed.
[0123] If the object identity risk level measured by the first risk is lower than the first level threshold, and the execution risk level measured by the second risk is higher than the second level threshold, then the execution strategy of the target business can be determined as an interception execution strategy; it should be understood that in this case, although the identity of the requesting object has a low level of risk, due to the high level of risk in the business content, the target business still cannot be executed and needs to be intercepted. For example, assuming that the first risk determined in the previous article is that the identity has no risk, it can be seen that the identity of the current requesting object has a low level of risk, and the second risk is the content abnormality risk, it can be seen that the current business content has a high level of risk. At this time, it can be considered that there is no problem with the identity of the requesting object, but the business content is abnormal and unreasonable, and the target business can be intercepted.
[0124] If the object identity risk level measured by the first risk is higher than the first level threshold, and the execution risk level measured by the second risk is lower than the second level threshold, then the execution strategy of the target business can be determined as the verification execution strategy; it should be understood that in this case, although the risk level of the business content is low, the risk level of the identity of the requesting object is high. Since the risk level of the requesting object is high, but the business content is reasonable and there is no abnormality, then in order to reduce the situation where the requesting object is misidentified as a non-authorized object, the information of the requesting object can be verified. Among them, if the requesting object is an acquaintance identity abnormality risk, then the privacy information of the requesting object can be verified, and if the requesting object is an ordinary identity abnormality risk, then the basic information of the requesting object can be verified. If the requesting object passes the verification, the target business can be executed.
[0125] If the subject identity risk level measured by the first risk exceeds a first threshold, and the execution risk level measured by the second risk exceeds a second threshold, the target service execution strategy may be determined to be an interception strategy. It should be understood that if both the subject identity risk level of the target service and the service content risk level are high, the target service may be directly intercepted and not executed.
[0126] It is worth noting that when the target business is a payment business, after identifying the first risk and the second risk of the target business, the payment amount of the authority holder in subsequent payment businesses can also be controlled based on the first risk and the second risk. In this way, the security of subsequent payment businesses can also be ensured.
[0127] It should be understood that the solution provided by the embodiments of the present application can identify the acquaintance identity risks, general identity risks and various content risks existing in the palm-swiping business (the palm-swiping business can refer to any business that supports palm-swiping verification and re-execution), which is more comprehensive and effective for risk identification; at the same time, the present application has different execution strategies for target businesses based on the different levels of object identity risk and execution risk. For example, for acquaintance identity risks, it is necessary to verify privacy information rather than basic information, which can further improve the execution security of the target business.
[0128] Furthermore, to understand the similarity interaction matching process mentioned above, please refer to Figure 4 , Figure 4 This is a flow chart of a method for determining a set of similar objects by similarity cross matching provided by an embodiment of the present application. Figure 2 In the corresponding embodiment, the process of performing similarity cross matching on N verification palmprint features and N palmprint feature libraries and determining a set of similar objects of N verification palmprint features from multiple reference objects is as follows: Figure 4 As shown, the process may include at least the following steps S401 to S403:
[0129] In step S401, the verification palmprint features and the palmprint feature library belonging to the same modality are determined as a similarity matching group, and N similarity matching groups are obtained.
[0130] Specifically, based on the above, each verification palmprint feature belongs to a different modality, and the palmprint feature library also belongs to a different modality. However, the N modes corresponding to N verification palmprint features are also the N modes of N palmprint feature libraries. To facilitate distinction, verification palmprint features and palmprint feature libraries belonging to the same modality can be grouped together. This group can be called a similarity matching group, so N verification palmprint features can correspond to N similarity matching groups.
[0131] Step S402: determining a similar palmprint feature set corresponding to each similarity matching group based on the verification palmprint features and the palmprint feature library contained in each similarity matching group; the similar palmprint feature set corresponding to the similarity matching group contains one or more reference palmprint features.
[0132] Specifically, based on the verification palmprint features and the palmprint feature library included in each similarity matching group, reference palmprint features similar to the verification palmprint features can be selected from the palmprint feature library, thereby obtaining a similar palmprint feature set. That is, the specific implementation process of determining the similar palmprint feature set corresponding to each similarity matching group from multiple reference objects based on the verification palmprint features and palmprint feature library contained in each similarity matching group may include but is not limited to: first, for easy distinction, any similarity matching group among the N similarity matching groups may be determined as a target matching group, and the verification palmprint features contained in the target matching group may be determined as the target palmprint features, and the palmprint feature library contained in the target matching group may be determined as the target palmprint feature library; then, the feature similarity between the target palmprint features and each reference palmprint feature in the target palmprint feature library may be calculated, thereby obtaining multiple feature similarities; the feature similarity greater than the similarity threshold among the multiple feature similarities may be determined as a candidate similarity; further, the reference palmprint features indicated by the candidate similarity in the target palmprint feature library may be used to form the similar palmprint feature set corresponding to the target palmprint feature library. For any similarity matching group, it may also be used as a target matching group and the corresponding similar palmprint feature set may be determined according to the above process.
[0133] Step S403: Obtain the intersection of N similar palmprint feature sets, and determine the set consisting of the reference objects indicated by each reference palmprint feature contained in the intersection as the similar object set of N verified palmprint features.
[0134] Specifically, a similar palmprint feature set corresponding to a similarity matching group can be understood as a similar palmprint feature set corresponding to a modality. This application can cross-validate it to find reference palmprint features that have similarity in palmprint features under multiple modalities. Then, after determining N similar object sets, the intersection between the N similar palmprint feature sets can be taken. The reference object indicated by each reference palmprint feature contained in this intersection is the similar object set of the N verified palmprint features.
[0135] It should be understood that by cross-matching the similarities between palmprint feature libraries of multiple modalities, similar objects can be extracted from multiple reference objects more accurately. In this way, risk detection of the identity of the requesting object can be performed based on similar objects with higher accuracy.
[0136] To understand the specific process of detecting the risk level of the target identity (i.e. the first risk of the target business) through similarity cross matching, please refer to Figure 5 , Figure 5 This is a schematic diagram of measuring the risk level of an object's identity through similarity cross-matching provided by an embodiment of the present application. Figure 5As shown, taking the different modalities of color, infrared, and depth as an example, after collecting color, infrared, and depth palm image data, they can be input into a convolutional neural network. The convolutional neural network can then extract palmprint features from each palm image data, which can be used as verification palmprint features. The verification palmprint features of the three different modalities can then be compared with the corresponding palmprint feature libraries. This can yield similar palmprint feature sets corresponding to the different modalities. For example, the similar palmprint feature set corresponding to the color modality is similar palmprint feature set 1, the similar palmprint feature set corresponding to the infrared modality is similar palmprint feature set 2, and the similar palmprint feature set corresponding to the depth modality is similar palmprint feature set 3. Furthermore, similar palmprint feature sets 1, 2, and 3 can be cross-matched to obtain a similar object set. Based on the number of objects contained in this similar object set and the objects' social attribute information, the identity risk of the requesting party for the target service can be collectively identified.
[0137] It should be understood that the multi-dimensional risk identification solution provided by the present application can support multi-factor and full-process identity authentication in the palm-swiping business (such as the target business) to detect whether there are risks in the palm-swiping business (for example: whether there is a risk that the requesting object is an acquaintance, whether there is a risk that the requesting object is a stranger with similar palm prints, whether there is a risk that the payment amount is abnormal, whether there is an abnormal risk in the location of the palm-swiping, whether there is an abnormality in the merchant of the palm-swiping payment, etc.). After detecting the risks in the palm-swiping business from multiple dimensions, the total risk of the target business can be comprehensively obtained through the multi-dimensional risks. For example, after obtaining the first risk and the second risk of the target business through the solution described above, the present application can comprehensively obtain the risk level of the total business risk of the target business based on the risk level of the first risk and the risk level of the second risk. Then, the present application can stratify the risk level of the target business, and then carry out differentiated intervention on the palm-swiping business according to the different levels of risk. For example, if the detected first risk is lower than the first level threshold and the risk level of the second risk is higher than the second level threshold, then it can be considered that there is a greater risk at the execution level of this target business, and the risk level of the total business risk can be considered to be very high. At this time, this target business can be directly intercepted and the execution of this target business can be refused; if the detected risk level of the first risk is higher than the first level threshold and the risk level of the second risk is lower than the second level threshold, then it can be considered that the requesting object of this target business may be at risk. If there is a risk of acquaintance identity for this requesting object, then a higher level of information verification can be performed on the requesting object (for example, requesting the requesting object to enter some private information of the permission holder, or requesting the requesting object to provide other biometric information of the permission holder (such as fingerprint information, facial information, or QR code information, etc.)). If there is a general identity risk for this requesting object, then a lower level of information verification can be performed on the requesting object (for example, asking the requesting object to enter some basic information of the permission holder). Among them, in some feasible embodiments, when the detected first risk is lower than the first degree threshold and the second risk is also lower than the second degree threshold, it can be considered that there is no risk in the identity and execution level of the requesting object for this target business, and the target business can be considered to be a trusted business. At this time, all interventions in this target business can be reduced, and the target business can be directly executed; of course, when the detected first risk is higher than the first degree threshold and the second risk is also higher than the second degree threshold, it can be considered that there is risk in the identity and execution level of the requesting object for this target business, and the target business can be considered to be an extremely untrustworthy business. At this time, the target business can be directly intercepted. By stratifying and differentially intervening in the risks of the target business as described above, the probability of interception of risky businesses can be accurately improved, thereby improving the security and convenience of the palm-swiping business.
[0138] Further, see Figure 6 , Figure 6 This is a schematic diagram of a payment architecture provided by an embodiment of the present application. This architecture is described by taking the payment business as an example. Figure 6 As shown, this architecture can at least include: palm-swipe activation service component, palm-swipe payment service component, palm-swipe information reporting component, palmprint identity authentication service component, payment security policy service component, asynchronous data reporting service component, real-time feature query service component, real-time feature analysis and calculation service component, external tag interface, real-time relationship feature storage component, relationship update component, and decision engine. The following will explain each component:
[0139] The palm swiping activation service component can be used to enable users to activate the palm swiping verification function. When users activate the palm swiping function, the palm swiping activation can be authenticated through the palm print identity authentication service component.
[0140] The palm-swiping payment service component can be used by users to make payments by swiping their palms.
[0141] The palm swiping information reporting component can report the palm image data entered by the user to the asynchronous data reporting service component, and can also report the payment characteristics of various payment services.
[0142] The real-time feature analysis and calculation service component can extract the palm print features from the reported palm image data to obtain the verification palm print features, and send the payment service and the verification palm print features of this payment service to the real-time feature query service component.
[0143] The real-time feature query service component can store the real-time features uploaded by the real-time feature analysis and calculation service component and store them for query by the payment security policy service component and the palmprint identity authentication service component.
[0144] The relationship update component can calculate and count payment relationships with fraud risks offline based on historical payment characteristics and complaint information, and update payment relationships with fraud risks in real time based on the updates of historical payment characteristics and complaint information.
[0145] The real-time relationship feature storage component can receive the real-time features and obtain the real-time relationship features of the real-time payment relationship therefrom.
[0146] The external tag interface can store payment relationships that are at risk of fraud.
[0147] The payment security policy service component can obtain the payment characteristics and historical payment characteristics of the current payment business based on the above components, and compare the payment characteristics of the current payment business with the historical payment characteristics to verify whether the payment content of the payment business has risks.
[0148] The palmprint identity authentication service component can obtain the verification palmprint features and reference palmprint features of this payment business based on the above components, and perform similarity cross-matching between the verification palmprint features of this payment business and the reference palmprint features to verify whether the requesting party of the payment business has identity risks.
[0149] The decision engine can determine the execution strategy for this payment transaction based on the identity risks and content risks identified by the above components.
[0150] It should be understood that Figure 6 The architecture shown is only an exemplary architecture made to facilitate understanding of each link, and it does not have practical reference significance. The design of the specific architecture and the functions implemented by each component can be configured based on actual business needs. This application does not limit this and is specifically explained here.
[0151] Further, see Figure 7 , Figure 7 This is a structural diagram of a data processing device provided in an embodiment of the present application. The data processing device may be a computer program (including program code) running on a computer device, for example, the data processing device is an application software; the data processing device may be used to execute Figure 3 As shown in the method. Figure 7 As shown, the data processing device 1 may include: a response module 11 , an acquisition module 12 , a risk determination module 13 and a strategy determination module 14 .
[0152] A response module 11 is configured to respond to a service request and obtain a palm print feature for verifying the service request and a service feature of a target service requested by the service request;
[0153] An acquisition module 12 is configured to acquire a palmprint feature database and a historical service database associated with a target service, wherein the palmprint feature database stores reference palmprint features of multiple reference objects; and the historical service database stores multiple historical service features, which are generated based on historical service data of the target service.
[0154] The risk determination module 13 is used to match the verified palm print feature with the palm print feature library to determine the first risk of the target business, where the first risk is used to measure the risk level of the target business's subject identity;
[0155] The risk determination module 13 is further configured to compare the business characteristics of the target business with the historical business characteristics in the historical business database to determine a second risk of the target business, where the second risk is used to measure the execution risk level of the target business.
[0156] The policy determination module 14 is configured to determine an execution policy for the target service based on the first risk and the second risk; and execute the target service according to the determined execution policy.
[0157] The specific implementation of the response module 11, the acquisition module 12, the risk determination module 13 and the strategy determination module 14 can be found in the above Figure 2 The description of steps S201 to S205 in the corresponding embodiment will not be repeated here.
[0158] In one embodiment, the number of verification palmprint features is N, and the N verification palmprint features belong to different modalities; the number of palmprint feature libraries is N, and the N palmprint feature libraries belong to different modalities; N is a positive integer;
[0159] The specific implementation method of the risk determination module 13 performing similarity cross matching on N verified palmprint features and N palmprint feature libraries, and determining a set of similar objects of N verified palmprint features from multiple reference objects, includes:
[0160] The verification palmprint features and the palmprint feature library with the same modality are determined as a similarity matching group, and N similarity matching groups are obtained;
[0161] Based on the verification palmprint features and the palmprint feature library contained in each similarity matching group, a similar palmprint feature set corresponding to each similarity matching group is determined; the similar palmprint feature set corresponding to the similarity matching group includes one or more reference palmprint features;
[0162] The intersection of N similar palmprint feature sets is obtained, and the set consisting of the reference objects indicated by each reference palmprint feature contained in the intersection is determined as the similar object set of N verified palmprint features.
[0163] In one embodiment, the risk determination module 13 determines a similar palmprint feature set corresponding to each similarity matching group from multiple reference objects based on the verification palmprint features and the palmprint feature library contained in each similarity matching group, including:
[0164] Determine any one of the N similarity matching groups as a target matching group, determine the verification palmprint features contained in the target matching group as target palmprint features, and determine the palmprint feature library contained in the target matching group as a target palmprint feature library;
[0165] Calculating the feature similarity between the target palmprint feature and each reference palmprint feature in the target palmprint feature library to obtain multiple feature similarities;
[0166] Determine a feature similarity greater than a similarity threshold among the multiple feature similarities as a candidate similarity;
[0167] The reference palmprint features indicated by the candidate similarities in the target palmprint feature library are combined into a similar palmprint feature set corresponding to the target palmprint feature library.
[0168] In one embodiment, the risk determination module 13 determines the first risk of the target business based on the social attribute information of each reference object in the similar object set. Specifically, the implementation method includes:
[0169] Get the permission holder of the target business;
[0170] Determine all reference objects other than the permission holder object in the similar object set as similar objects of the permission holder object;
[0171] Perform relationship analysis on the social attribute information of each similar object and the permission holder object to obtain the social relationship attributes between each similar object and the permission holder object; the social relationship attributes include relationship-possessing attributes and relationship-non-possessing attributes;
[0172] If any similar object in the similar object set has a social relationship attribute with the permission holder, the first risk of the target business is determined to be the risk of abnormal acquaintance identity;
[0173] If there is no similar object in the similar object set, and the social relationship attribute between the target business object and the business object is a relationship-possessing attribute, then the first risk of the target business is determined to be a common identity anomaly risk.
[0174] In one embodiment, the risk determination module 13 determines a specific implementation method of the first risk of the target business based on the number of objects and the business type of the target business, including:
[0175] If the number of objects is less than the valid value, and the target business is the palmprint registration business, then the first risk of the target business is determined to be the identity risk;
[0176] If the number of objects is less than the valid value, and the target business is a resource payment business, the first risk of the target business is determined to be a common identity abnormality risk;
[0177] If the number of objects is equal to the valid value, and the target business is the palmprint registration business, then the first risk of the target business is determined to be the common identity abnormality risk;
[0178] If the number of objects is equal to the valid value, and the target business is a resource payment business, it is determined that the first risk of the target business is the identity risk.
[0179] In one embodiment, the risk determination module 13 compares the business characteristics of the target business with the historical business characteristics in the historical business database to determine the specific implementation method of the second risk of the target business, including:
[0180] Obtain the business object associated with the target business, obtain the account characteristics associated with the business object from the business characteristics of the target business, and obtain the historical account characteristics associated with the business object from the historical business database;
[0181] Compare the account characteristics associated with the business object with historical account characteristics to determine the account risk of the target business;
[0182] Extracting content features of the business content of the target business from the business features of the target business, and extracting historical content features associated with the business content of the target business from a historical business database;
[0183] Compare the content characteristics of the target business with historical content characteristics to determine the content risk of the target business;
[0184] Determine the secondary risk of the target business based on account risk and content risk.
[0185] In one embodiment, the risk determination module 13 compares the account characteristics associated with the business object with the historical account characteristics to determine the specific implementation method of the abnormal account risk of the target business, including:
[0186] Input the account characteristics and historical account characteristics associated with the business object into the account risk prediction model;
[0187] Through the account risk prediction model, the account characteristics associated with the business object are compared and analyzed with historical account characteristics to determine the account risk prediction value;
[0188] If the account risk prediction value is greater than the account abnormality threshold, the account risk of the target business is determined to be account abnormality risk;
[0189] If the account risk prediction value is less than the account abnormality threshold, the account risk of the target business is determined to be no risk.
[0190] In one embodiment, the risk determination module 13 determines the specific implementation method of the second risk of the target business based on the account risk and the content risk, including:
[0191] If the account risk is an abnormal account risk, or the content risk is an abnormal content risk, the second risk of the target business is determined to be an abnormal execution risk;
[0192] If the account risk is that there is no risk for the account and the content risk is that there is no risk for the content, the second risk of the target business is determined to be a reasonable execution risk.
[0193] In one embodiment, the policy determination module 14 determines a specific implementation of the execution policy of the target business based on the first risk and the second risk, including:
[0194] If the object identity risk level measured by the first risk is lower than the first level threshold, and the execution risk level measured by the second risk is lower than the second level threshold, then determining that the execution strategy for the target business is the direct execution strategy;
[0195] If the object identity risk level measured by the first risk is lower than the first level threshold, and the execution risk level measured by the second risk is higher than the second level threshold, determining that the execution strategy of the target business is an interception execution strategy;
[0196] If the object identity risk level measured by the first risk is higher than a first level threshold, and the execution risk level measured by the second risk is lower than a second level threshold, then determining that the execution strategy for the target business is the additional verification execution strategy;
[0197] If the object identity risk level measured by the first risk is higher than a first level threshold, and the execution risk level measured by the second risk is higher than a second level threshold, the execution strategy of the target business is determined to be an interception execution strategy.
[0198] In an embodiment of the present application, a multi-dimensional risk identification solution is provided for palm swiping services. Specifically, after receiving a service request, based on the target service of this service request, the palm print features (called verification palm print features) and service features of this time can be collected. Then, based on the verification palm print features of this time and the reference palm print features of multiple reference objects stored in the palm print feature library, the object identity risk level of the target service can be identified and measured to obtain the first risk in the dimension of object identity; based on the service features of this time and the historical service features stored in the historical service database, the execution risk level of the target service can be identified and measured to obtain the second risk in the execution of the target service; based on the first risk and the second risk of different dimensions, it can be comprehensively determined whether there is a risk in the execution of the target service, and based on the comprehensive determination result, the execution strategy of the target service can be determined, and then the target service can be executed according to the execution strategy. It should be understood that through multi-dimensional risk identification, the risk level in palm print identification and service can be more effectively excavated. For risks of different dimensions, this application can also formulate different execution strategies, thereby improving the execution security of the palm swiping service.
[0199] Further, see Figure 8 , Figure 8 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present application. Figure 8As shown, the above-mentioned computer device 8000 may include: a processor 8001, a network interface 8004 and a memory 8005. In addition, the above-mentioned computer device 8000 also includes: a user interface 8003, and at least one communication bus 8002. The communication bus 8002 is used to realize the connection and communication between these components. The user interface 8003 may include a display screen (Display), a keyboard (Keyboard), and the user interface 8003 may optionally include a standard wired interface and a wireless interface. The network interface 8004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 8005 may be a high-speed RAM memory, or a non-volatile memory (non-volatile memory), such as at least one disk memory. The memory 8005 may optionally also be at least one storage device located away from the aforementioned processor 8001. As Figure 8 As shown, the memory 8005 as a computer-readable storage medium may include an operating system, a network communication module, a user interface module, and a device control application.
[0200] exist Figure 8 In the computer device 8000 shown, the network interface 8004 can provide network communication functions; the user interface 8003 is mainly used to provide an interface for user input; and the processor 8001 can be used to call the device control application stored in the memory 8005 to achieve:
[0201] In response to the service request, obtaining a palm print feature for verifying the service request and a service feature of a target service requested by the service request;
[0202] Obtaining a palmprint feature database and a historical business database associated with a target business, wherein the palmprint feature database stores reference palmprint features of multiple reference objects; and the historical business database stores multiple historical business features, which are generated based on historical business data of the target business.
[0203] Matching the verified palm print features with the palm print feature database to determine the first risk of the target business, which is used to measure the risk level of the target business's object identity;
[0204] Compare the business characteristics of the target business with the historical business characteristics in the historical business database to determine the secondary risk of the target business. The secondary risk is used to measure the execution risk level of the target business.
[0205] Determining an execution strategy for the target business based on the first risk and the second risk; and executing the target business according to the determined execution strategy.
[0206] In one embodiment, the number of verification palmprint features is N, and the N verification palmprint features belong to different modalities; the number of palmprint feature libraries is N, and the N palmprint feature libraries belong to different modalities; N is a positive integer;
[0207] When performing similarity cross matching on N verification palmprint features and N palmprint feature libraries and determining a similar object set of N verification palmprint features from multiple reference objects, the processor 8001 specifically performs the following steps:
[0208] The verification palmprint features and the palmprint feature library with the same modality are determined as a similarity matching group, and N similarity matching groups are obtained;
[0209] Based on the verification palmprint features and the palmprint feature library contained in each similarity matching group, a similar palmprint feature set corresponding to each similarity matching group is determined; the similar palmprint feature set corresponding to the similarity matching group includes one or more reference palmprint features;
[0210] The intersection of N similar palmprint feature sets is obtained, and the set consisting of the reference objects indicated by each reference palmprint feature contained in the intersection is determined as the similar object set of N verified palmprint features.
[0211] In one embodiment, when determining a similar palmprint feature set corresponding to each similarity matching group from a plurality of reference objects based on the verification palmprint features and the palmprint feature library contained in each similarity matching group, the processor 8001 specifically performs the following steps:
[0212] Determine any one of the N similarity matching groups as a target matching group, determine the verification palmprint features contained in the target matching group as target palmprint features, and determine the palmprint feature library contained in the target matching group as a target palmprint feature library;
[0213] Calculating the feature similarity between the target palmprint feature and each reference palmprint feature in the target palmprint feature library to obtain multiple feature similarities;
[0214] Determine a feature similarity greater than a similarity threshold among the multiple feature similarities as a candidate similarity;
[0215] The reference palmprint features indicated by the candidate similarities in the target palmprint feature library are combined into a similar palmprint feature set corresponding to the target palmprint feature library.
[0216] In one embodiment, when determining the first risk of the target business based on the social attribute information of each reference object in the similar object set, the processor 8001 specifically performs the following steps:
[0217] Get the permission holder of the target business;
[0218] Determine all reference objects other than the permission holder object in the similar object set as similar objects of the permission holder object;
[0219] Perform relationship analysis on the social attribute information of each similar object and the permission holder object to obtain the social relationship attributes between each similar object and the permission holder object; the social relationship attributes include relationship-possessing attributes and relationship-non-possessing attributes;
[0220] If any similar object in the similar object set has a social relationship attribute with the permission holder, the first risk of the target business is determined to be the risk of abnormal acquaintance identity;
[0221] If there is no similar object in the similar object set, and the social relationship attribute between the target business object and the business object is a relationship-possessing attribute, then the first risk of the target business is determined to be a common identity anomaly risk.
[0222] In one embodiment, when determining the first risk of the target business based on the number of objects and the business type of the target business, the processor 8001 specifically performs the following steps:
[0223] If the number of objects is less than the valid value, and the target business is the palmprint registration business, the first risk of the target business is determined to be the identity risk;
[0224] If the number of objects is less than the valid value and the target business is a resource payment business, the first risk of the target business is determined to be a common identity abnormality risk;
[0225] If the number of objects is equal to the valid value, and the target business is the palmprint registration business, then the first risk of the target business is determined to be the common identity abnormality risk;
[0226] If the number of objects is equal to the valid value, and the target business is a resource payment business, it is determined that the first risk of the target business is the identity risk.
[0227] In one embodiment, when comparing the service characteristics of the target service with the historical service characteristics in the historical service database to determine the second risk of the target service, the processor 8001 specifically performs the following steps:
[0228] Obtain the business object associated with the target business, obtain the account characteristics associated with the business object from the business characteristics of the target business, and obtain the historical account characteristics associated with the business object from the historical business database;
[0229] Compare the account characteristics associated with the business object with historical account characteristics to determine the account risk of the target business;
[0230] Extracting content features of the business content of the target business from the business features of the target business, and extracting historical content features associated with the business content of the target business from a historical business database;
[0231] Compare the content characteristics of the target business with historical content characteristics to determine the content risk of the target business;
[0232] Determine the secondary risk of the target business based on account risk and content risk.
[0233] In one embodiment, when comparing the account characteristics associated with the business object with historical account characteristics to determine the abnormal account risk of the target business, the processor 8001 specifically performs the following steps:
[0234] Input the account characteristics and historical account characteristics associated with the business object into the account risk prediction model;
[0235] Through the account risk prediction model, the account characteristics associated with the business object are compared and analyzed with historical account characteristics to determine the account risk prediction value;
[0236] If the account risk prediction value is greater than the account abnormality threshold, the account risk of the target business is determined to be account abnormality risk;
[0237] If the account risk prediction value is less than the account abnormality threshold, the account risk of the target business is determined to be no risk.
[0238] In one embodiment, when determining the second risk of the target business based on the account risk and the content risk, the processor 8001 specifically performs the following steps:
[0239] If the account risk is an abnormal account risk, or the content risk is an abnormal content risk, the second risk of the target business is determined to be an abnormal execution risk;
[0240] If the account risk is that there is no risk for the account and the content risk is that there is no risk for the content, the second risk of the target business is determined to be a reasonable execution risk.
[0241] In one embodiment, when determining the execution strategy of the target service based on the first risk and the second risk, the processor 8001 specifically performs the following steps:
[0242] If the object identity risk level measured by the first risk is lower than the first level threshold, and the execution risk level measured by the second risk is lower than the second level threshold, then determining that the execution strategy for the target business is the direct execution strategy;
[0243] If the object identity risk level measured by the first risk is lower than the first level threshold, and the execution risk level measured by the second risk is higher than the second level threshold, determining that the execution strategy of the target business is an interception execution strategy;
[0244] If the object identity risk level measured by the first risk is higher than a first level threshold, and the execution risk level measured by the second risk is lower than a second level threshold, then determining that the execution strategy for the target business is the additional verification execution strategy;
[0245] If the object identity risk level measured by the first risk is higher than a first level threshold, and the execution risk level measured by the second risk is higher than a second level threshold, the execution strategy of the target business is determined to be an interception execution strategy.
[0246] It should be understood that the computer device 8000 described in the embodiment of the present application can execute the above Figures 2 to 6 The description of the data processing method in the corresponding embodiment can also be performed as described above. Figure 7 The description of the data processing device 1 in the corresponding embodiment will not be repeated here. In addition, the description of the beneficial effects of adopting the same method will not be repeated here either.
[0247] In addition, it should be noted that: the embodiment of the present application also provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program executed by the computer device 8000 for data processing mentioned above, and the computer program includes program instructions. When the processor executes the program instructions, the computer program can execute the above-mentioned data processing. Figures 2 to 6 The description of the above-mentioned data processing method in the corresponding embodiment will therefore not be repeated here. In addition, the description of the beneficial effects of adopting the same method will not be repeated. For technical details not disclosed in the computer-readable storage medium embodiment involved in this application, please refer to the description of the method embodiment of this application.
[0248] The computer-readable storage medium may be the data processing device provided in any of the aforementioned embodiments or the internal storage unit of the computer device, such as the hard disk or memory of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device. Furthermore, the computer-readable storage medium may also include both the internal storage unit of the computer device and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium may also be used to temporarily store data that has been output or is to be output.
[0249] In one aspect of the present application, a computer program product is provided, comprising a computer program stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium and executes the computer program, causing the computer device to perform the method provided in one aspect of the embodiments of the present application.
[0250] The terms "first", "second", etc. in the description, claims, and drawings of the embodiments of the present application are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, apparatus, product, or device comprising a series of steps or units is not limited to the listed steps or modules, but may optionally include steps or modules not listed, or may optionally include other step units inherent to these processes, methods, apparatuses, products, or devices.
[0251] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program that has a predetermined function and works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as processing circuits or memories) or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the function of the module or unit.
[0252] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0253] The methods and related devices provided by the embodiments of the present application are described with reference to the method flow charts and / or structural diagrams provided by the embodiments of the present application. Specifically, each process and / or block in the method flow charts and / or structural diagrams, as well as the combination of processes and / or blocks in the flow charts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 Schematic diagram of one or more processes and / or structures Figure 1 These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific way, so that the instructions stored in the computer-readable memory produce a product including the instruction device, which implements the function specified in the process. Figure 1 Schematic diagram of one or more processes and / or structures Figure 1 These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the process. Figure 1 The flow or flows and / or structures illustrate the steps of the functions specified in one block or multiple blocks.
[0254] The above disclosure is only a preferred embodiment of the present application, and certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.
Claims
1. A data processing method, characterized in that: The method comprises: In response to a service request, obtaining a palm print feature for verifying the service request and a service feature of a target service requested by the service request; Obtaining a palmprint feature library and a historical service database associated with the target service, wherein the palmprint feature library stores reference palmprint features of multiple reference objects; the historical service database stores multiple historical service features, which are generated based on historical service data of the target service; Matching the verified palmprint feature with the palmprint feature library to determine a first risk of the target business, where the first risk is used to measure the risk level of the target business's subject identity; Comparing the business characteristics of the target business with the historical business characteristics in the historical business database to determine a second risk of the target business, where the second risk is used to measure the execution risk degree of the target business; Determining an execution strategy for the target business based on the first risk and the second risk; and executing the target business according to the determined execution strategy.
2. The method according to claim 1, characterized in that The number of the verification palmprint features is N, and the N verification palmprint features belong to different modalities; the number of the palmprint feature libraries is N, and the N palmprint feature libraries belong to different modalities; N is a positive integer; The matching process of the verified palmprint feature with the palmprint feature database to determine the first risk of the target business includes: Performing similarity cross-matching on the N verification palmprint features and the N palmprint feature libraries, and determining a similar object set of the N verification palmprint features from the multiple reference objects; If the number of reference objects included in the similar object set is greater than a valid value, determining a first risk of the target business based on social attribute information of each reference object in the similar object set; If the number of reference objects included in the similar object set is less than or equal to the valid value, a first risk of the target business is determined based on the number of objects and the business type of the target business.
3. The method according to claim 2, characterized in that The similarity cross-matching of the N verification palmprint features and the N palmprint feature libraries to determine a similar object set of the N verification palmprint features from the multiple reference objects includes: The verification palmprint features and the palmprint feature library with the same modality are determined as a similarity matching group, and N similarity matching groups are obtained; Determining a similar palmprint feature set corresponding to each similarity matching group based on the verification palmprint features and the palmprint feature library contained in each similarity matching group; the similar palmprint feature set corresponding to the similarity matching group contains one or more reference palmprint features; An intersection of N similar palmprint feature sets is obtained, and a set consisting of reference objects indicated by each reference palmprint feature contained in the intersection is determined as a similar object set of the N verified palmprint features.
4. The method according to claim 3, characterized in that The determining, based on the verification palmprint features and the palmprint feature library contained in each similarity matching group, a similar palmprint feature set corresponding to each similarity matching group from the multiple reference objects includes: Determine any one of the N similarity matching groups as a target matching group, determine the verification palmprint features contained in the target matching group as target palmprint features, and determine the palmprint feature library contained in the target matching group as a target palmprint feature library; Calculating a feature similarity between the target palmprint feature and each reference palmprint feature in the target palmprint feature library to obtain a plurality of feature similarities; Determine a feature similarity greater than a similarity threshold among the multiple feature similarities as a candidate similarity; The reference palmprint features indicated by the candidate similarities in the target palmprint feature library are combined into a similar palmprint feature set corresponding to the target palmprint feature library.
5. The method according to claim 2, characterized in that The determining the first risk of the target business based on the social attribute information of each reference object in the similar object set includes: Obtain the permission holder object of the target business; Determining all reference objects in the similar object set except the permission holding object as similar objects of the permission holding object; Performing relationship analysis on the social attribute information of each similar object and the permission holding object to obtain social relationship attributes between each similar object and the permission holding object; the social relationship attributes include relationship possessing attributes and relationship not possessing attributes; If there is any similar object in the similar object set, and the social relationship attribute between the similar object and the permission holder object is a relationship-possessing attribute, then the first risk of the target business is determined to be an acquaintance identity abnormality risk; If there is no similar object in the similar object set, and the social relationship attribute between the target business object and the business object is a relationship-possessing attribute, then the first risk of the target business is determined to be a common identity anomaly risk.
6. The method according to claim 2, characterized in that The determining the first risk of the target business based on the number of objects and the business type of the target business includes: If the number of objects is less than the valid value, and the target business is a palmprint registration business, determining that the first risk of the target business is an identity risk; If the number of objects is less than the valid value, and the target business is a resource payment business, determining that the first risk of the target business is a common identity abnormality risk; If the number of objects is equal to the valid value, and the target service is a palmprint registration service, determining that the first risk of the target service is a common identity abnormality risk; If the number of objects is equal to the valid value, and the target business is a resource payment business, it is determined that the first risk of the target business is an identity risk.
7. The method according to claim 1, characterized in that The comparing the business characteristics of the target business with the historical business characteristics in the historical business database to determine the second risk of the target business includes: Acquire a business object associated with the target business, acquire account characteristics associated with the business object from the business characteristics of the target business, and acquire historical account characteristics associated with the business object from the historical business database; Comparing the account characteristics associated with the business object with historical account characteristics to determine the account risk of the target business; Extracting content features of the business content of the target business from the business features of the target business, and extracting historical content features associated with the business content of the target business from the historical business database; Comparing the content characteristics of the target business with historical content characteristics to determine the content risk of the target business; A second risk of the target business is determined based on the account risk and the content risk.
8. The method according to claim 7, characterized in that The comparing the account characteristics associated with the business object with historical account characteristics to determine the abnormal account risk of the target business includes: Inputting the account characteristics and historical account characteristics associated with the business object into an account risk prediction model; By using the account risk prediction model, the account characteristics associated with the business object are compared and analyzed with historical account characteristics to determine an account risk prediction value; If the account risk prediction value is greater than the account abnormality threshold, the account risk of the target business is determined to be an account abnormality risk; If the account risk prediction value is less than the account abnormality threshold, the account risk of the target business is determined to be no risk to the account.
9. The method according to claim 7, characterized in that The determining the second risk of the target business based on the account risk and the content risk includes: If the account risk is an abnormal account risk, or the content risk is an abnormal content risk, the second risk of the target business is determined to be an abnormal execution risk; If the account risk is that there is no risk for the account, and the content risk is that there is no risk for the content, the second risk of the target business is determined to be a reasonable execution risk.
10. The method according to claim 1, characterized in that The determining, based on the first risk and the second risk, an execution strategy for the target business includes: If the object identity risk level measured by the first risk is lower than a first level threshold, and the execution risk level measured by the second risk is lower than a second level threshold, determining that the execution strategy for the target business is a direct execution strategy; If the object identity risk level measured by the first risk is lower than a first level threshold, and the execution risk level measured by the second risk is higher than a second level threshold, determining that the execution strategy of the target business is an interception execution strategy; If the object identity risk level measured by the first risk is higher than a first level threshold, and the execution risk level measured by the second risk is lower than a second level threshold, determining that the execution strategy for the target business is an additional verification execution strategy; If the object identity risk level measured by the first risk is higher than a first level threshold, and the execution risk level measured by the second risk is higher than a second level threshold, the execution strategy of the target business is determined to be an interception execution strategy.
11. A data processing device, characterized in that: include: A response module, configured to, in response to a service request, obtain a palm print feature for verifying the service request and a service feature of a target service requested by the service request; An acquisition module is configured to acquire a palmprint feature library and a historical service database associated with the target service, wherein the palmprint feature library stores reference palmprint features of multiple reference objects; and the historical service database stores multiple historical service features, which are generated based on historical service data of the target service. a risk determination module, configured to match the verified palmprint feature with the palmprint feature library to determine a first risk of the target business, wherein the first risk is used to measure a risk level of the subject identity of the target business; The risk determination module is further configured to compare the business characteristics of the target business with the historical business characteristics in the historical business database to determine a second risk of the target business, where the second risk is used to measure the execution risk degree of the target business; a strategy determination module, configured to determine an execution strategy for the target business based on the first risk and the second risk; And, executing the target business according to the determined execution strategy.
12. A computer device, characterized in that: include: processor, memory, and network interface; The processor is connected to the memory and the network interface, wherein the network interface is used to provide a network communication function, the memory is used to store a computer program, and the processor is used to call the computer program so that the computer device executes the method according to any one of claims 1 to 10.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and the computer program is suitable for being loaded by a processor and executing the method according to any one of claims 1 to 10.
14. A computer program product, characterized in that The computer program product comprises a computer program stored in a computer-readable storage medium. The computer program is suitable for being read and executed by a processor, so as to enable a computer device having the processor to perform the method according to any one of claims 1 to 10.