Risk account identification method and device, equipment and storage medium
By decrypting and jointly analyzing encrypted data from foreign exchange management agencies and banks in a trusted execution environment, and using knowledge graphs to identify risky accounts, the problems of low identification accuracy and efficiency caused by a single data source in foreign exchange transactions are solved, and efficient and accurate risk account identification is achieved.
Patent Information
- Application Number
- CN202511107682.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-09-19
AI Technical Summary
Existing methods for identifying risky accounts in foreign exchange trading rely on a single data source, resulting in low identification accuracy and efficiency. In addition, multi-party secure computing or federated learning methods based on cryptography are inefficient in data processing.
In a trusted execution environment, transaction regulators receive encrypted data uploaded by foreign exchange management agencies and participating banks, conduct joint analysis after decryption, and use knowledge graphs to identify risky accounts, avoiding direct data interaction.
It improves the accuracy and efficiency of identifying risky accounts in foreign exchange transactions, enhances the security and efficiency of data processing, and reduces complex encryption protocol interactions.
Smart Images

Figure CN120672449A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of financial technology, and in particular to a method, apparatus, device and storage medium for identifying risky accounts. Background Art
[0002] Currently, the methods used to identify risky foreign exchange accounts primarily rely on foreign exchange transaction data held by foreign exchange management agencies, which is an overly single data source. This single data source makes it difficult to effectively capture suspicious transaction characteristics in foreign exchange transactions, significantly reducing the accuracy of risk account identification.
[0003] In order to solve the above problems, the cryptography-based multi-party secure computing or federated learning method is proposed. In the process of obtaining multi-party data, in order to determine the security of each party's data, complex encryption protocol interactions are required, and the data processing efficiency is low, thereby reducing the efficiency of identifying risky accounts. Summary of the Invention
[0004] The present invention provides a risk account identification method, apparatus, device and storage medium to improve the accuracy and efficiency of identifying risk accounts in foreign exchange transactions.
[0005] According to one aspect of the present invention, a method for identifying risky accounts is provided. The method is performed by a transaction supervisor and includes:
[0006] In a trusted execution environment, receiving an encrypted list of suspicious accounts uploaded by a foreign exchange administration agency and a first encrypted knowledge graph uploaded by at least one participating bank;
[0007] Decrypting the encrypted list of suspicious accounts and the first encrypted knowledge graph uploaded by at least one participating bank, respectively, to obtain a list of suspicious accounts and at least one first transaction knowledge graph; wherein the list of suspicious accounts is generated by the foreign exchange administration agency based on foreign exchange transaction data within a target time period; and the first transaction knowledge graph is constructed by the participating banks based on transfer transaction data within the target time period;
[0008] A list of risky accounts in foreign exchange transactions is determined based on the list of suspicious accounts and the edge information in each first transaction knowledge graph.
[0009] According to another aspect of the present invention, a risk account identification device is provided. The device is deployed at a transaction supervisor, and includes:
[0010] A data acquisition module is configured to receive, in a trusted execution environment, an encrypted list of suspicious accounts uploaded by a foreign exchange administration agency and a first encrypted knowledge graph uploaded by at least one participating bank;
[0011] A data decryption module is configured to decrypt the encrypted list of suspicious accounts and the first encrypted knowledge graph uploaded by at least one participating bank, respectively, to obtain the list of suspicious accounts and at least one first transaction knowledge graph; wherein the list of suspicious accounts is generated by the foreign exchange administration agency based on foreign exchange transaction data within a target time period; and the first transaction knowledge graph is constructed by the participating banks based on transfer transaction data within the target time period;
[0012] The risk account list determination module is used to determine the risk account list in foreign exchange transactions based on the suspicious account list and the edge information in each first transaction knowledge graph.
[0013] According to another aspect of the present invention, an electronic device is provided, comprising:
[0014] at least one processor;
[0015] and a memory communicatively connected to at least one processor; wherein,
[0016] The memory stores a computer program that can be executed by at least one processor. The computer program is executed by the at least one processor so that the at least one processor can execute the risk account identification method of any embodiment of the present invention.
[0017] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the risk account identification method of any embodiment of the present invention when executed.
[0018] According to another aspect of the present invention, a computer program product is provided, comprising a computer program, which implements the risk account identification method according to any embodiment of the present invention when executed by a processor.
[0019] The technical solution of an embodiment of the present invention is implemented by a transaction supervisor, specifically comprising: receiving, within a trusted execution environment, an encrypted list of suspicious accounts uploaded by a foreign exchange administration and a first encrypted knowledge graph uploaded by at least one participating bank; decrypting the encrypted list of suspicious accounts and the first encrypted knowledge graph uploaded by at least one participating bank, respectively, to obtain a list of suspicious accounts and at least one first transaction knowledge graph; wherein the list of suspicious accounts is generated by the foreign exchange administration based on foreign exchange transaction data within a target time period; and the first transaction knowledge graph is constructed by the participating banks based on transfer transaction data within the target time period; and determining a list of risky accounts in foreign exchange transactions based on the suspicious account list and the side information in each first transaction knowledge graph. In the above technical solution, in the process of identifying risky accounts in foreign exchange transactions, the transaction supervisor, within its trusted execution environment, determines the list of risky accounts in foreign exchange transactions by jointly analyzing the list of suspicious accounts generated based on foreign exchange transaction data from the foreign exchange administration and the first transaction knowledge graph constructed based on transfer transaction data from the participating banks. This improves the ability to capture suspicious transaction characteristics in foreign exchange transactions, thereby improving the accuracy of identifying risky accounts in foreign exchange transactions and, in turn, improving the accuracy of the list of risky accounts. At the same time, compared with cryptography-based multi-party secure computing or federated learning methods, the above-mentioned technical solution eliminates a large number of complex encryption protocol interactions. All multi-party data involved are efficiently processed in the trusted execution environment of the transaction regulator, which significantly improves the processing efficiency of multi-party data, thereby improving the efficiency of identifying risky accounts in foreign exchange transactions, and further increasing the speed of determining the list of risky accounts.
[0020] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0022] Figure 1 This is a flow chart of a method for identifying risky accounts provided according to the first embodiment of the present invention;
[0023] Figure 2A This is a flow chart of a method for identifying risky accounts provided according to the second embodiment of the present invention;
[0024] Figure 2BA first transaction knowledge graph provided according to the second embodiment of the present invention;
[0025] Figure 3 This is a schematic diagram of the structure of a risk account identification device provided according to the third embodiment of the present invention;
[0026] Figure 4 2 is a schematic diagram of the structure of an electronic device that implements the risk account identification method according to an embodiment of the present invention. DETAILED DESCRIPTION
[0027] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "target", "candidate", "first" and "second" in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0029] In addition, it should be noted that the information collected in the present invention is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data comply with the relevant laws, regulations and standards of relevant countries and regions, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0030] Example 1
[0031] Figure 1 This is a flow chart of a method for identifying risky accounts provided in the first embodiment of the present invention. This embodiment is applicable to identifying risky accounts in foreign exchange transactions. The method can be executed by a risky account identification device, which can be implemented in the form of hardware and / or software and can be configured in an electronic device. Figure 1As shown, the method is executed by the transaction supervisor, including:
[0032] S101. In a trusted execution environment, receive an encrypted list of suspicious accounts uploaded by a foreign exchange administration agency and a first encrypted knowledge graph uploaded by at least one participating bank.
[0033] Transaction regulators refer to government agencies, industry organizations, or specific authorized entities that supervise, manage, and regulate market trading activities in accordance with the law to maintain market order, ensure fair trading, and protect the legitimate rights and interests of trading participants. A trusted execution environment (TEE) is a secure, isolated execution environment with independent computing and storage space, secured by hardware (such as a CPU). It should be noted that the TEE is deployed within the transaction regulator. A foreign exchange administration agency refers to a department or agency authorized by the government or prescribed by law responsible for formulating, supervising, and enforcing foreign exchange management laws and policies. The suspicious account list is used to record accounts in foreign exchange transactions that exhibit suspicious transaction characteristics. Participating banks refer to banks involved in foreign exchange transactions. It should be noted that each participating bank corresponds to one first encrypted knowledge graph.
[0034] The first encrypted knowledge graph refers to the encrypted first transaction knowledge graph; the first transaction knowledge graph is constructed based on transfer transaction data within a target time period by participating banks. The target time period can be pre-set based on actual business needs or based on the expert experience of those skilled in the art, and is not specifically limited in this embodiment of the present invention. Transfer transaction data includes, but is not limited to, transaction entities, transaction time, transaction frequency, and transfer relationships. It should be noted that the account nodes in the first transaction knowledge graph represent the transaction entities in the transfer transaction data, and the edges represent the transfer relationships between the transaction entities in the transfer transaction data. Each edge in the first transaction knowledge graph contains the following edge information: transfer amount, number of transfer transactions, and edge weight. For example, when account A transfers to account B, the edge weight between accounts A and B is equal to the ratio of account A's transfer amount to the total amount of transfers received by account B within the target time period.
[0035] Specifically, the transaction supervisor receives, in its trusted execution environment, an encrypted list of suspicious accounts uploaded by the foreign exchange administration agency and a first encrypted knowledge graph uploaded by at least one participating bank.
[0036] S102. Decrypt the encrypted suspicious account list and the first encrypted knowledge graph uploaded by at least one participating bank respectively to obtain the suspicious account list and at least one first transaction knowledge graph.
[0037] Specifically, the transaction supervisor decrypts the encrypted list of suspicious accounts through a preset decryption algorithm in its trusted execution environment to obtain the list of suspicious accounts; at the same time, the transaction supervisor decrypts the first encrypted knowledge graph uploaded by each participating bank through a preset decryption algorithm to obtain the first transaction knowledge graph corresponding to each first encrypted knowledge graph.
[0038] The list of suspicious accounts is generated by the foreign exchange administration agency based on foreign exchange transaction data within the target time period. Specifically, the foreign exchange administration agency constructs a second transaction knowledge graph based on the foreign exchange transaction data within the target time period; and the foreign exchange administration agency performs risk screening on account nodes in the second transaction knowledge graph based on foreign exchange transaction regulatory rules to obtain a list of suspicious accounts.
[0039] The second transaction knowledge graph refers to the knowledge graph constructed by foreign exchange management agencies based on foreign exchange transaction data within a target time period. Foreign exchange transaction regulatory rules refer to the guidelines formulated by transaction regulators that systematically manage foreign exchange trading behavior, market participants, and capital flows through laws, regulations, and policies.
[0040] Specifically, the foreign exchange administration agency uses a knowledge graph construction tool to take the trading entities in the foreign exchange trading data within the target time period as account nodes, and the foreign exchange trading relationships between the trading entities in the foreign exchange trading data within the target time period as edges, to obtain a second trading knowledge graph; for each account node in the second trading knowledge graph, the foreign exchange administration agency detects whether the account node satisfies at least one regulatory sub-rule in the foreign exchange trading regulatory rules based on the account trading information of the account node; if so, the risk value of the account node is determined based on the number of regulatory sub-rules satisfied by the account node; and the account unique identifier and risk value of the account node are added to the list of suspicious accounts.
[0041] For each account node in the second transaction knowledge graph, the account transaction information for that account node includes, but is not limited to, the number of foreign exchange sources and the total amount of foreign exchange received during the target time period. The number of regulatory sub-rules refers to the total number of regulatory sub-rules in the foreign exchange transaction regulatory rules that the account node meets. The risk value refers to the probability that the account node will become a risky account node.
[0042] The risk value of the account node is determined based on the number of regulatory sub-rules satisfied by the account node. Specifically, the following steps may be performed: matching the number of regulatory sub-rules satisfied by the account node with the number of candidate rules in a preset risk value determination table to obtain the number of successfully matched candidate rules, which is recorded as the number of matched rules; and based on the one-to-one correspondence between the number of candidate rules and candidate risk values in the preset risk value determination table, obtaining the candidate risk value corresponding to the number of matched rules from the preset risk value determination table as the risk value of the account node. The number of candidate rules refers to the number of rules in the preset risk value determination table; and the candidate risk value refers to the risk value in the preset risk value determination table.
[0043] It is understandable that the generation of a list of suspicious accounts by the foreign exchange administration agency based on foreign exchange transaction data within the target time period and in accordance with foreign exchange transaction regulatory rules, on the one hand, improves the authority and accuracy of the list of suspicious accounts; on the other hand, the generation of a list of suspicious accounts by the foreign exchange administration agency based on foreign exchange transaction data within the target time period, rather than the transaction regulator directly obtaining the foreign exchange transaction data from the foreign exchange administration agency and generating the list of suspicious accounts based on the foreign exchange transaction data from the foreign exchange administration agency in its internal trusted execution environment, achieves the secure isolation of the foreign exchange transaction data from the foreign exchange administration agency and avoids the direct leakage of the foreign exchange transaction data from the foreign exchange administration agency.
[0044] Among them, the first transaction knowledge graph is constructed by participating banks based on transfer transaction data within the target time period. Specifically, it can be: participating banks use knowledge graph construction tools to use transaction subjects in the transfer transaction data within the target time period as account nodes, and use transfer relationships between transaction subjects in the transfer transaction data within the target time period as edges to obtain the first transaction knowledge graph.
[0045] It should be noted that the number of first transaction knowledge graphs is equal to the number of participating banks, that is, one participating bank corresponds to one first transaction knowledge graph.
[0046] It can be understood that the participating banks construct the first transaction knowledge graph based on the transfer transaction data within the target time period, rather than the transaction regulator directly obtaining the transfer transaction data on the participating banks' side and constructing the first transaction knowledge graph based on the transfer transaction data on the participating banks' side in its internal trusted execution environment. This achieves the secure isolation of the transfer transaction data on the participating banks' side and avoids the direct leakage of the transfer transaction data on the participating banks' side.
[0047] S103: Determine a list of risky accounts in foreign exchange transactions based on the list of suspicious accounts and the edge information in each first transaction knowledge graph.
[0048] Among them, risk accounts refer to accounts that need to be monitored, managed or subject to special risk control measures due to the risks involved in foreign exchange transactions.
[0049] Specifically, the transaction supervisor determines the list of risky accounts in foreign exchange transactions in its trusted execution environment based on the list of suspicious accounts and the side information in each first transaction knowledge graph and a preset risky account identification algorithm.
[0050] The technical solution of an embodiment of the present invention is implemented by a transaction supervisor, specifically comprising: receiving, within a trusted execution environment, an encrypted list of suspicious accounts uploaded by a foreign exchange administration and a first encrypted knowledge graph uploaded by at least one participating bank; decrypting the encrypted list of suspicious accounts and the first encrypted knowledge graph uploaded by at least one participating bank, respectively, to obtain a list of suspicious accounts and at least one first transaction knowledge graph; wherein the list of suspicious accounts is generated by the foreign exchange administration based on foreign exchange transaction data within a target time period; and the first transaction knowledge graph is constructed by the participating banks based on transfer transaction data within the target time period; and determining a list of risky accounts in foreign exchange transactions based on the suspicious account list and the side information in each first transaction knowledge graph. In the above technical solution, in the process of identifying risky accounts in foreign exchange transactions, the transaction supervisor, within its trusted execution environment, determines the list of risky accounts in foreign exchange transactions by jointly analyzing the list of suspicious accounts generated based on foreign exchange transaction data from the foreign exchange administration and the first transaction knowledge graph constructed based on transfer transaction data from the participating banks. This improves the ability to capture suspicious transaction characteristics in foreign exchange transactions, thereby improving the accuracy of identifying risky accounts in foreign exchange transactions and, in turn, improving the accuracy of the list of risky accounts. At the same time, compared with cryptography-based multi-party secure computing or federated learning methods, the above-mentioned technical solution eliminates a large number of complex encryption protocol interactions. All multi-party data involved are efficiently executed in the trusted execution environment of the transaction regulator, which significantly improves the processing efficiency of multi-party data, thereby improving the efficiency of identifying risky accounts in foreign exchange transactions, and further increasing the speed of determining the list of risky accounts.
[0051] On the basis of the above embodiment, as an optional method of the embodiment of the present invention, after determining the list of risky accounts in foreign exchange transactions, the transaction supervisor can also feed back the risky account list to each participating bank through the secure channel between it and each participating bank, so that each participating bank can enrich its customer labeling system based on the risky account list and enhance each participating bank's own monitoring ability of customer risks.
[0052] On the basis of the above embodiment, as an optional method of the embodiment of the present invention, after determining the list of risk accounts in foreign exchange transactions, the transaction supervisor may also generate a risk evidence chain corresponding to the risk account list based on the association relationship between each risk account identifier in the risk account list and its associated starting point; thereafter, the risk account list and the risk evidence chain corresponding to the risk account list are fed back to the foreign exchange administration agency so that the foreign exchange administration agency can subsequently supervise and control the risk accounts.
[0053] Example 2
[0054] Figure 2A This is a flowchart of a method for identifying risky accounts provided in Example 2 of the present invention. Based on the above example, this example further optimizes "determining the list of risky accounts in foreign exchange transactions based on the list of suspicious accounts and the side information in each first transaction knowledge graph" and provides an optional implementation plan. It should be noted that for parts not described in detail in the example of the present invention, reference can be made to the relevant descriptions of other examples. Figure 2A As shown, the method is executed by the transaction supervisor, including:
[0055] S201. In a trusted execution environment, receive an encrypted list of suspicious accounts uploaded by a foreign exchange administration agency and a first encrypted knowledge graph uploaded by at least one participating bank.
[0056] S202. Decrypt the encrypted suspicious account list and the first encrypted knowledge graph uploaded by at least one participating bank respectively to obtain the suspicious account list and at least one first transaction knowledge graph.
[0057] Among them, the list of suspicious accounts is generated by the foreign exchange management agency based on the foreign exchange transaction data within the target time period; the first transaction knowledge graph is constructed by the participating banks based on the transfer transaction data within the target time period.
[0058] S203. For each first transaction knowledge graph, determine a candidate risk node in the first transaction knowledge graph according to the list of suspicious accounts.
[0059] Among them, the candidate risk node refers to the account node in the first transaction knowledge graph that may have foreign exchange transaction risks. Specifically, for each first transaction knowledge graph, the transaction supervisor uses a secure matching protocol to match the suspicious account identifiers in the suspicious account list with the account nodes in the first transaction knowledge graph in its trusted execution environment, and obtains the account node corresponding to each suspicious account identifier in the suspicious account list in the first transaction knowledge graph as the risk propagation node; in the first transaction knowledge graph, the account node directly pointed to by each risk propagation node is used as the candidate risk node in the first transaction knowledge graph, for example, see Figure 2B ,like Figure 2BThe A account node in is the risk propagation node, then Figure 2B The B account node and the C account node are candidate risk nodes.
[0060] S204. For each candidate risk node in the first transaction knowledge graph, obtain an account node directly pointing to the candidate risk node from the first transaction knowledge graph as a starting point corresponding to the candidate risk node.
[0061] For example, see Figure 2B ,like Figure 2B The C account node in is a candidate risk node, then Figure 2B The account nodes that directly point to the C account node include: A account node, B account node, D account node and E account node, that is, Figure 2B The starting points corresponding to the C account node are the A account node, the B account node, the D account node, and the E account node.
[0062] S205: Determine a risk value of the candidate risk node based on the list of suspicious accounts, the starting point corresponding to the candidate risk node, and the edge information in the first transaction knowledge graph.
[0063] Specifically, for each starting point corresponding to the candidate risk node, the risk value of the starting point is obtained from the list of suspicious accounts, and the edge weight between the starting point and the candidate risk node is obtained from the edge information in the first transaction knowledge graph as the edge weight of the starting point; the risk contribution factor of the starting point is determined; and the risk value of the candidate risk node is determined based on the risk value, edge weight, and risk contribution factor of each starting point corresponding to the candidate risk node. The risk contribution factor is used to reflect the contribution of a starting point to the candidate risk node becoming a target risk node. A target risk node is a node in the first transaction knowledge graph that presents foreign exchange trading risks.
[0064] More specifically, for the kth (k=1,2,…,K) starting point corresponding to the jth (j=1,2,…,M) candidate risk node in the ith (i=1,2,…,N) first transaction knowledge graph, the risk value of the starting point is obtained from the suspicious account list using the account unique identifier of the starting point as an index; the edge weight between the starting point and the jth candidate risk node in the ith first transaction knowledge graph is obtained from the edge information in the ith first transaction knowledge graph as the edge weight of the starting point; the risk contribution factor of the starting point is determined based on the transaction time or transaction frequency in the account transaction data of the starting point; and the risk value, edge weight, and risk contribution factor of each starting point corresponding to each candidate risk node in the ith first transaction knowledge graph are used to determine the risk value of the jth candidate risk node in the ith first transaction knowledge graph using the following risk value calculation formula:
[0065]
[0066] Where VaR represents the risk value of the j-th candidate risk node in the i-th first transaction knowledge graph; k represents the k-th starting point corresponding to the j-th candidate risk node in the i-th first transaction knowledge graph; K represents the total number of starting points corresponding to the j-th candidate risk node in the i-th first transaction knowledge graph; R k W represents the risk value of the kth starting point corresponding to the jth candidate risk node in the i-th first transaction knowledge graph; k represents the edge weight of the kth starting point corresponding to the jth candidate risk node in the i-th first transaction knowledge graph; α k Represents the risk contribution factor of the kth starting point corresponding to the jth candidate risk node in the i-th first transaction knowledge graph. Where N represents the total number of first transaction knowledge graphs; M represents the total number of candidate risk nodes in the i-th first transaction knowledge graph.
[0067] For example, if Figure 2B The C account node in the example is a candidate risk node, and its corresponding starting points are the A account node, the B account node, the D account node, and the E account node. The risk values of the A account node, the B account node, the D account node, and the E account node are all 1, the edge weights are all 0.8, and the risk contribution factors are all 1. Based on the above risk value calculation formula, we can know that Figure 2B The risk value of the C account node is 0.32, that is, (1*0.8*1)+(1*0.8*1)+(1*0.8*1)+(1*0.8*1)=0.32.
[0068] It can be understood that for each candidate risk node in the first transaction knowledge graph, the risk value of the candidate risk node is determined based on the risk value, edge weight and risk contribution factor of each starting point corresponding to the candidate risk node, and the influence of each starting point corresponding to the candidate risk node on its risk value is taken into account, so that the determination of the risk value of the candidate risk node is more accurate and scientific, that is, the accuracy of the risk value of the candidate risk node in the first transaction knowledge graph is improved.
[0069] S206: Determine a target risk node in the first transaction knowledge graph according to the risk value and risk threshold of each candidate risk node in the first transaction knowledge graph.
[0070] The target risk node refers to a node in the first transaction knowledge graph that presents foreign exchange trading risk. Specifically, the risk value of each candidate risk node in the first transaction knowledge graph is compared with a risk threshold. The candidate risk node in the first transaction knowledge graph whose risk value is greater than or equal to the risk threshold is determined as the target risk node in the first transaction knowledge graph. The risk threshold can be pre-set based on actual business needs or the expert experience of those skilled in the art. For example, the risk threshold can be 4, and this is not specifically limited in the present embodiment.
[0071] S207: Determine a list of risky accounts in foreign exchange transactions based on target risk nodes in each first transaction knowledge graph.
[0072] Specifically, the account unique identifier and risk value of each target risk node in the first transaction knowledge graph are added to a blank risk list to obtain a list of risky accounts in foreign exchange transactions.
[0073] The technical solution of the embodiment of the present invention is implemented by the transaction supervisor, specifically: in a trusted execution environment, receiving the encrypted suspicious account list uploaded by the foreign exchange administration agency and the first encrypted knowledge graph uploaded by at least one participating bank; decrypting the encrypted suspicious account list and the first encrypted knowledge graph uploaded by at least one participating bank respectively to obtain the suspicious account list and at least one first transaction knowledge graph; wherein the suspicious account list is generated by the foreign exchange administration agency based on the foreign exchange transaction data within the target time period; the first transaction knowledge graph is constructed by the participating banks based on the transfer transaction data within the target time period; for each first transaction knowledge graph, according to the suspicious account list, Determine candidate risk nodes in the first transaction knowledge graph; for each candidate risk node in the first transaction knowledge graph, obtain an account node directly pointing to the candidate risk node from the first transaction knowledge graph as the starting point corresponding to the candidate risk node; determine the risk value of the candidate risk node based on the list of suspicious accounts, the starting point corresponding to the candidate risk node, and the edge information in the first transaction knowledge graph; determine target risk nodes in the first transaction knowledge graph based on the risk values and risk thresholds of each candidate risk node in the first transaction knowledge graph; and determine a list of risky accounts in foreign exchange transactions based on the target risk nodes in each first transaction knowledge graph. In the above technical solution, the transaction supervisor, in its trusted execution environment, analyzes and calculates the first transaction knowledge graph corresponding to each participating bank based on the list of suspicious accounts provided by the foreign exchange administration agency, thereby determining the target risk node in the first transaction knowledge graph corresponding to each participating bank, and then determines a list of risky accounts in foreign exchange transactions based on the target risk nodes in each first transaction knowledge graph. By comprehensively analyzing multi-party data within the transaction regulator's trusted execution environment, the list of risky accounts in foreign exchange transactions is determined. This solves the problem of a single data source and improves the ability to capture suspicious transaction characteristics in foreign exchange transactions, thereby increasing the accuracy of identifying risky accounts in foreign exchange transactions and, in turn, improving the accuracy of the risky account list. At the same time, within the transaction regulator's trusted execution environment, efficient processing of multi-party data is achieved. Compared to cryptography-based multi-party secure computing or federated learning methods, this significantly improves the efficiency of multi-party data processing, thereby improving the efficiency of identifying risky accounts in foreign exchange transactions and, in turn, speeding up the determination of the risky account list.
[0074] On the basis of the above embodiment, as an optional method of the embodiment of the present invention, after obtaining the target risk node in each first transaction knowledge graph, in order to further explore the potential risk nodes in each first transaction knowledge graph, for each first transaction knowledge graph, the target risk node in the first transaction knowledge graph can also be used as a new risk propagation node. In the first transaction knowledge graph, the node directly pointed to by each new risk propagation node is used as a new candidate risk node in the first transaction knowledge graph; the target risk node in the first transaction knowledge graph is iteratively determined until all account nodes in the first transaction knowledge graph are traversed, thereby obtaining all target risk nodes in the first transaction knowledge graph that have been verified by multiple propagation.
[0075] Example 3
[0076] Figure 3 This is a schematic diagram of the structure of a risk account identification device provided by the third embodiment of the present invention. This embodiment is applicable to the situation of identifying risk accounts in foreign exchange transactions. The device can be implemented in the form of hardware and / or software and can be configured in an electronic device. Figure 3 As shown, the device is deployed on the transaction supervisor side and includes:
[0077] The data acquisition module 301 is configured to receive, in a trusted execution environment, an encrypted list of suspicious accounts uploaded by a foreign exchange administration agency and a first encrypted knowledge graph uploaded by at least one participating bank;
[0078] Data decryption module 302 is configured to decrypt the encrypted suspicious account list and the first encrypted knowledge graph uploaded by at least one participating bank, respectively, to obtain the suspicious account list and at least one first transaction knowledge graph. The suspicious account list is generated by the foreign exchange administration agency based on foreign exchange transaction data within a target time period; the first transaction knowledge graph is constructed by the participating banks based on transfer transaction data within the target time period.
[0079] The risk account list determination module 303 is used to determine the risk account list in foreign exchange transactions based on the suspicious account list and the edge information in each first transaction knowledge graph.
[0080] The technical solution of an embodiment of the present invention is implemented by a transaction supervisor, specifically comprising: receiving, within a trusted execution environment, an encrypted list of suspicious accounts uploaded by a foreign exchange administration and a first encrypted knowledge graph uploaded by at least one participating bank; decrypting the encrypted list of suspicious accounts and the first encrypted knowledge graph uploaded by at least one participating bank, respectively, to obtain a list of suspicious accounts and at least one first transaction knowledge graph; wherein the list of suspicious accounts is generated by the foreign exchange administration based on foreign exchange transaction data within a target time period; and the first transaction knowledge graph is constructed by the participating banks based on transfer transaction data within the target time period; and determining a list of risky accounts in foreign exchange transactions based on the suspicious account list and the side information in each first transaction knowledge graph. In the above technical solution, in the process of identifying risky accounts in foreign exchange transactions, the transaction supervisor, within its trusted execution environment, determines the list of risky accounts in foreign exchange transactions by jointly analyzing the list of suspicious accounts generated based on foreign exchange transaction data from the foreign exchange administration and the first transaction knowledge graph constructed based on transfer transaction data from the participating banks. This improves the ability to capture suspicious transaction characteristics in foreign exchange transactions, thereby improving the accuracy of identifying risky accounts in foreign exchange transactions and, in turn, improving the accuracy of the list of risky accounts. At the same time, compared with cryptography-based multi-party secure computing or federated learning methods, the above-mentioned technical solution eliminates a large number of complex encryption protocol interactions. All multi-party data involved are efficiently executed in the trusted execution environment of the transaction regulator, which significantly improves the processing efficiency of multi-party data, thereby improving the efficiency of identifying risky accounts in foreign exchange transactions, and further increasing the speed of determining the list of risky accounts.
[0081] Optionally, the device further includes a suspicious account list generation module, wherein the suspicious account list generation module includes:
[0082] A second transaction knowledge graph construction unit is configured for the foreign exchange administration agency to construct a second transaction knowledge graph based on foreign exchange transaction data within a target time period;
[0083] The suspicious account list generating unit is used by the foreign exchange administration agency to perform risk screening on the account nodes in the second transaction knowledge graph based on foreign exchange transaction supervision rules to obtain a suspicious account list.
[0084] Optionally, a suspicious account list generating unit is used to:
[0085] For each account node in the second transaction knowledge graph, the foreign exchange administration agency detects, based on the account transaction information of the account node, whether the account node satisfies at least one regulatory sub-rule in the foreign exchange transaction regulatory rules;
[0086] If so, the risk value of the account node is determined based on the number of regulatory sub-rules that the account node meets;
[0087] Add the unique account ID and risk value of the account node to the list of suspicious accounts.
[0088] Optionally, the risk account list determination module 303 includes:
[0089] a candidate risk node determination unit, configured to determine, for each first transaction knowledge graph, a candidate risk node in the first transaction knowledge graph based on the list of suspicious accounts;
[0090] a starting point determining unit, configured to obtain, for each candidate risk node in the first transaction knowledge graph, an account node directly pointing to the candidate risk node from the first transaction knowledge graph as a starting point corresponding to the candidate risk node;
[0091] a risk value determining unit, configured to determine a risk value of the candidate risk node based on the list of suspicious accounts, the starting point corresponding to the candidate risk node, and the edge information in the first transaction knowledge graph;
[0092] a target risk node determining unit, configured to determine a target risk node in the first transaction knowledge graph based on a risk value and a risk threshold of each candidate risk node in the first transaction knowledge graph;
[0093] The risk account list determination unit is used to determine the risk account list in foreign exchange transactions based on the target risk nodes in each first transaction knowledge graph.
[0094] Optionally, a risk value determination unit is used to:
[0095] For each starting point corresponding to the candidate risk node, obtain the risk value of the starting point from the suspicious account list, and obtain the edge weight between the starting point and the candidate risk node from the edge information in the first transaction knowledge graph as the edge weight of the starting point;
[0096] Determine the risk contribution factor of the starting point;
[0097] The risk value of the candidate risk node is determined based on the risk values, edge weights, and risk contribution factors of each starting point corresponding to the candidate risk node.
[0098] Optionally, the target risk node determination unit is specifically configured to:
[0099] The risk value of each candidate risk node in the first transaction knowledge graph is compared with the risk threshold, and the candidate risk nodes in the first transaction knowledge graph whose risk values are greater than or equal to the risk threshold are determined as target risk nodes in the first transaction knowledge graph.
[0100] The risk account identification device provided in the embodiment of the present invention can execute the risk account identification method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing each risk account identification method.
[0101] According to an embodiment of the present invention, the present invention further provides an electronic device, a readable storage medium and a computer program product.
[0102] Example 4
[0103] Figure 4 A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0104] like Figure 4 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by the at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12 and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0105] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0106] Processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any other suitable processor, controller, microcontroller, etc. Processor 11 executes the various methods and processes described above, such as the risky account identification method.
[0107] In some embodiments, the risk account identification method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the risk account identification method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the risk account identification method in any other appropriate manner (for example, by means of firmware).
[0108] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0109] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0110] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0111] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0112] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0113] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0114] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0115] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A method for identifying risky accounts, characterized in that: Executed by a transaction supervisor, the method includes: In a trusted execution environment, receiving an encrypted list of suspicious accounts uploaded by a foreign exchange administration agency and a first encrypted knowledge graph uploaded by at least one participating bank; Decrypting the encrypted suspicious account list and the first encrypted knowledge graph uploaded by the at least one participating bank, respectively, to obtain a suspicious account list and at least one first transaction knowledge graph; wherein the suspicious account list is generated by the foreign exchange administration agency based on foreign exchange transaction data within a target time period; and the first transaction knowledge graph is constructed by the participating banks based on transfer transaction data within the target time period; A list of risky accounts in foreign exchange transactions is determined based on the list of suspicious accounts and the side information in each first transaction knowledge graph.
2. The method according to claim 1, characterized in that The list of suspicious accounts is generated by the foreign exchange administration agency based on foreign exchange transaction data within the target time period and includes: The foreign exchange administration agency constructs a second transaction knowledge graph based on foreign exchange transaction data within a target time period; The foreign exchange administration agency performs risk screening on the account nodes in the second transaction knowledge graph based on foreign exchange transaction regulatory rules to obtain a list of suspicious accounts.
3. The method according to claim 2, characterized in that The foreign exchange administration agency performs risk screening on the account nodes in the second transaction knowledge graph based on foreign exchange transaction regulatory rules to obtain a list of suspicious accounts, including: For each account node in the second transaction knowledge graph, the foreign exchange administration agency detects, based on the account transaction information of the account node, whether the account node satisfies at least one regulatory sub-rule in the foreign exchange transaction regulatory rules; If yes, then determine the risk value of the account node based on the number of regulatory sub-rules that the account node meets; Add the unique account ID and risk value of the account node to the list of suspicious accounts.
4. The method according to claim 1, wherein Determining a list of risky accounts in foreign exchange transactions based on the list of suspicious accounts and the side information in each first transaction knowledge graph includes: For each first transaction knowledge graph, determining a candidate risk node in the first transaction knowledge graph according to the list of suspicious accounts; For each candidate risk node in the first transaction knowledge graph, obtain an account node directly pointing to the candidate risk node from the first transaction knowledge graph as the starting point corresponding to the candidate risk node; Determining a risk value of the candidate risk node based on the suspicious account list, the starting point corresponding to the candidate risk node, and the edge information in the first transaction knowledge graph; Determining a target risk node in the first transaction knowledge graph based on the risk value and risk threshold of each candidate risk node in the first transaction knowledge graph; A list of risky accounts in foreign exchange transactions is determined based on target risk nodes in each first transaction knowledge graph.
5. The method according to claim 4, characterized in that The step of determining the risk value of the candidate risk node based on the suspicious account list, the starting point corresponding to the candidate risk node, and the edge information in the first transaction knowledge graph includes: For each starting point corresponding to the candidate risk node, obtain the risk value of the starting point from the suspicious account list, and obtain the edge weight between the starting point and the candidate risk node from the edge information in the first transaction knowledge graph as the edge weight of the starting point; Determine the risk contribution factor of the starting point; The risk value of the candidate risk node is determined based on the risk values, edge weights, and risk contribution factors of each starting point corresponding to the candidate risk node.
6. The method according to claim 4, characterized in that The step of determining a target risk node in the first transaction knowledge graph according to the risk value and the risk threshold of each candidate risk node in the first transaction knowledge graph includes: The risk value of each candidate risk node in the first transaction knowledge graph is compared with the risk threshold, and the candidate risk nodes in the first transaction knowledge graph whose risk values are greater than or equal to the risk threshold are determined as target risk nodes in the first transaction knowledge graph.
7. A risk account identification device, characterized in that: Deployed at the transaction supervisor, the device includes: A data acquisition module is configured to receive, in a trusted execution environment, an encrypted list of suspicious accounts uploaded by a foreign exchange administration agency and a first encrypted knowledge graph uploaded by at least one participating bank; a data decryption module, configured to decrypt the encrypted suspicious account list and the first encrypted knowledge graph uploaded by the at least one participating bank, respectively, to obtain a suspicious account list and at least one first transaction knowledge graph; wherein the suspicious account list is generated by the foreign exchange administration agency based on foreign exchange transaction data within a target time period; and the first transaction knowledge graph is constructed by the participating banks based on transfer transaction data within the target time period; The risk account list determination module is used to determine the risk account list in foreign exchange transactions based on the suspicious account list and the edge information in each first transaction knowledge graph.
8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the risk account identification method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the risk account identification method according to any one of claims 1 to 6 when executed.
10. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the risk account identification method according to any one of claims 1 to 6 is implemented.