Scoring card model analysis processing method, system, electronic device and storage medium

By compiling the scorecard model into bytecode and encrypting it, and combining the RSA algorithm and digital signature technology, the security and computational efficiency issues of the scorecard model during transmission are solved, realizing secure delivery and convenient use of the model, which is applicable to fields such as finance and credit.

CN120744885BActive Publication Date: 2025-11-28ANHUI CREDIT REPORTING CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511257100.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-04
Publication Date
2025-11-28
Estimated Expiration
2045-09-04

AI Technical Summary

Technical Problem

Existing technologies are insufficient in terms of model confidentiality, computational efficiency, and execution environment dependence of scorecard models, and cannot meet the requirements for efficient and secure privacy computing.

Method used

The scorecard model is compiled into an intermediate bytecode file and encrypted using the Fernet symmetric encryption algorithm. A decryption tool corresponding to the encrypted file is generated, and a digital signature is generated using the RSA algorithm to ensure the security of the model during transmission and the legitimacy of the data.

Benefits of technology

Ensure that the scorecard model remains encrypted throughout the entire delivery process to prevent the leakage of model logic and algorithm details. This ensures that the data end can securely and conveniently call and use the model, avoiding the risk of unauthorized access and reducing the risk of model leakage or misuse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744885B_ABST
    Figure CN120744885B_ABST
Patent Text Reader

Abstract

The application provides a scoring card model analysis processing method and system, electronic equipment and a storage medium, relates to the field of model processing, and the method comprises the steps of obtaining a scoring card model based on a text form, compiling the scoring card model into an intermediate bytecode file through a compiler; encrypting the intermediate bytecode file to obtain an encrypted file; digitally signing the encrypted file to generate a signature file; generating a decryption tool and encoding the public key of the asymmetric key in the decryption tool to obtain a target decryption tool; and sending the encrypted file, the target decryption tool and the signature file to a data end for use. The application can ensure that the scoring card model is always in an encrypted state during the entire delivery process, preventing the model logic and algorithm details from being leaked; the data end can call and use the model without decrypting the specific content of the model, which not only ensures the convenience of the data end, but also avoids the risk of unauthorized access to the model.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of model processing, in particular to a scoring card model analysis processing method and system, an electronic device and a storage medium. BACKGROUND

[0002] The scoring card model is mainly used in the fields of finance and credit; the scoring card model is a quantitative tool for evaluating the credit risk or specific attributes of an object, and is widely used in the fields of financial risk control, credit approval, market marketing, etc. It selects characteristic variables highly related to the target, uses statistical methods to build a model, assigns corresponding weights and scores to each variable, and finally obtains a comprehensive score by weighted summation. The score can directly reflect the risk level of the evaluated object or the strength of the target attribute, helping decision makers quickly make judgments about whether to grant credit and the credit limit, with strong objectivity, high interpretability, convenient operation, etc. It can effectively improve decision-making efficiency and reduce risks.

[0003] In related technologies, the scoring card model is protected by encryption, which can realize the calling and execution of the prediction task by the data party without decrypting the model. Solving the risk of data leakage and protecting privacy in multi-party collaborative computing is crucial. Although existing privacy computing technologies have made significant progress in protecting model and data security, there are still deficiencies in computing efficiency, communication overhead, model secrecy and the universality of the execution environment, which cannot fully meet the demand for efficient and secure privacy computing in actual applications. SUMMARY

[0004] In view of the deficiencies of the prior art, the present application provides a scoring card model analysis processing method and system, an electronic device and a storage medium, which solve the problems of model secrecy, computing efficiency and execution environment dependence of the prior art in scoring card model.

[0005] To achieve the above purpose, the present application is realized by the following technical solutions:

[0006] In a first aspect, an embodiment of the present application provides a scoring card model analysis processing method, which comprises: obtaining a scoring card model in a text form, a logical structure of the scoring card model complying with a preset syntax rule; determining a compiler corresponding to the syntax rule, and compiling the scoring card model into an intermediate bytecode file through the compiler; wherein the intermediate bytecode file is a syntax tree in a byte string form; performing encryption processing on the intermediate bytecode file using a Fernet symmetric encryption algorithm to obtain an encrypted file; generating a pair of asymmetric keys including a public key and a private key based on an RSA algorithm, performing digital signature on the encrypted file using the private key to generate a signature file; generating a decryption tool corresponding to the encrypted file and encoding the public key of the asymmetric key in the decryption tool to obtain a target decryption tool; wherein the target decryption tool is used for verifying the signature file, decrypting the encrypted file and providing a decision engine; and sending the encrypted file, the target decryption tool and the signature file to a data end for use.

[0007] According to the first aspect of the embodiment of the present application, the foregoing determining the compiler corresponding to the syntax rule and compiling the scoring card model into the intermediate bytecode file can specifically include the following steps: performing lexical analysis and syntax analysis on the scoring card model based on a lightweight parsing tool library pyparsing; and implementing keyword recognition, identifier parsing, operator parsing, logical operation parsing and conditional statement parsing on the scoring card model through pyparsing code writing to compile the intermediate bytecode file.

[0008] According to the first aspect of the embodiment of the present application, the keyword recognition includes: defining common keywords in the scoring card model including IF, THEN and ELSE, so that the compiling tool can accurately distinguish control statements, variables or operators; the identifier parsing includes: identifying variables in the model as identifiers to ensure correct reference in the model logic; the operator parsing includes: correctly identifying mathematical and logical operators through the parser to ensure that the calculation logic in the model can be correctly executed; the logical operation parsing includes: identifying and parsing various logical expressions including mathematical operations, string operations and logical judgments, and parsing the various logical expressions into a tree structure for subsequent execution; and the conditional statement parsing includes: processing multi-level logical conditions through the parsing of the conditional structure, and ensuring that the logical conditions can be correctly executed.

[0009] According to the first aspect of the embodiment of the present application, the decision engine is an executor for logical reasoning of the syntax tree generated by the compiler to provide interpretation and running functions for the syntax tree; the execution flow corresponding to the executor includes: expression evaluation, application of logical operators, execution of function calls, processing of IN and NOT IN operators, and overall evaluation process.

[0010] According to a first aspect of the embodiments of the present application, the expression evaluation includes: processing the expression evaluation in a recursive manner to support the calculation of numbers, variables, function calls and complex logical expressions; processing each sub-expression by parsing the nodes of the syntax tree and combining the results; the application of logical operators includes: processing logical operators, comparison operators and mathematical operators, and performing corresponding logical judgment or mathematical operation by recursively parsing the expression; the execution of function calls includes: in the syntax tree, if a function call is encountered, the parameters of the call are recursively processed, and the corresponding function definition is found in the interpreter, the function is executed and the result is returned; the processing of IN and NOT IN operators includes: by matching the left operand with each element in the right list, the left expression is first evaluated recursively, and then the right list is matched one by one; the overall evaluation process includes: the parser traverses each node in the syntax tree from top to bottom, applies the corresponding rules to evaluate, and calculates the results of the sub-expressions through function calls or operator calculations, and finally the evaluation result of the entire conditional expression is returned to the caller.

[0011] According to the first aspect of the embodiments of the present application, when the foregoing target decryption tool runs at the data end, the scoring card model analysis processing method can further include the following steps: verifying whether the signature file and the public key are legal through the target decryption tool; decrypting the decrypted file to restore the syntax tree and load it into the memory after the signature file and the public key are verified; executing the decrypted syntax tree in the memory and receiving the sample features to be predicted; and performing specific logic according to the structure of the syntax tree, and evaluating the conditional expression and the function call through the parsing and execution of the syntax tree to obtain the prediction information.

[0012] According to the first aspect of the embodiments of the present application, the preset syntax rule includes an IF statement, a THEN statement, an ELSE IF statement, an ELSE statement and an expression; in the IF statement, each condition starts with IF and only one IF, IF is followed by an expression, and the expression is followed by a THEN keyword; in the THEN statement, the THEN part performs related operations when the IF or ELSE IF condition is true; in the ELSE IF statement, the ELSE IF statement exists after the IF and before the ELSE, and is used as an optional condition branch for further judgment; the ELSE statement is used to process the case where all conditions are not met; the expression supports mathematical operations, logical operations and function operations for conditional judgment and result calculation.

[0013] In a second aspect, an embodiment of the present application provides a scoring card model analysis processing system, which comprises an obtaining module, a compiling module, an encryption module, a signature module and a generating module. The obtaining module is configured to obtain a scoring card model in a text form, and a logical structure of the scoring card model complies with a preset syntax rule. The compiling module is configured to determine a compiler corresponding to the syntax rule, and compile the scoring card model into an intermediate bytecode file through the compiler. The intermediate bytecode file is a syntax tree in a byte string form. The encryption module is configured to perform encryption processing on the intermediate bytecode file using a Fernet symmetric encryption algorithm to obtain an encrypted file. The signature module is configured to generate a pair of asymmetric keys including a public key and a private key based on an RSA algorithm, perform digital signature on the encrypted file using the private key, and generate a signature file. The generating module is configured to generate a decryption tool corresponding to the encrypted file and encode the public key of the asymmetric keys in the decryption tool to obtain a target decryption tool. The target decryption tool is configured to verify the signature file, decrypt the encrypted file and provide a decision engine. A sending module is configured to send the encrypted file, the target decryption tool and the signature file to a data end for use.

[0014] In a third aspect, an embodiment of the present application provides an electronic device, which comprises a processor, a memory and a program stored in the memory and executable on the processor. The program is executed by the processor to implement the scoring card model analysis processing method in the first aspect.

[0015] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, which stores a program or instructions. The program or instructions are executed by a processor to implement the scoring card model analysis processing method in the first aspect.

[0016] The present application provides a scoring card model analysis processing method, system, electronic device and storage medium. Compared with the prior art, the present application has the following beneficial effects:

[0017] The present application compiles the scoring card model into an intermediate bytecode file in a string form, and performs encryption processing on the intermediate bytecode file through a Fernet symmetric encryption algorithm to obtain an encrypted file. The scoring card model is always in an encrypted state in the entire delivery process, and the model logic and algorithm details are prevented from being leaked. The scoring card model is prevented from being stolen or reverse cracked in the transmission process. The present application further generates a decryption tool corresponding to the encrypted file, performs digital signature on the encrypted file using a private key to generate a signature file, and encodes a public key of an asymmetric key in the decryption tool to obtain a target decryption tool. The data end can call and use the model without decrypting the specific content of the model on the premise that the target decryption tool is used, and the internal structure or algorithm of the model does not need to be known. The present application not only ensures the convenience of the data end, but also avoids the risk of unauthorized access to the model. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description only constitute some embodiments of the present application, and other drawings can be obtained by those of ordinary skill in the art without any creative effort on the basis of these drawings.

[0019] Figure 1 is a flowchart of a scoring card model analysis processing method provided by an embodiment of the present application;

[0020] Figure 2 is an exemplary interaction schematic diagram between a model end and a data end of a scoring card model analysis processing method provided by an embodiment of the present application;

[0021] Figure 3 is a structural schematic diagram of a scoring card model analysis processing system provided by an embodiment of the present application;

[0022] Figure 4 is a structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0023] In order to make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application are described clearly and completely. Obviously, the described embodiments are some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without any creative effort belong to the protection scope of the present application.

[0024] It should be noted that, in this document, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. Moreover, the terms “include”, “contain” or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement “including a…” does not exclude the presence of another identical element in the process, method, article or device including the element.

[0025] The embodiment of the application provides a scoring card model analysis processing method, system, electronic equipment and storage medium, and solves the problems of model confidentiality, calculation efficiency and execution environment dependence of the prior art.

[0026] In order to better understand the above technical solutions, the above technical solutions will be described in detail below in combination with the drawings of the specification and specific embodiments.

[0027] First, a scoring card model analysis processing method provided by the embodiment of the application will be introduced.

[0028] The flowchart of the scoring card model analysis processing method provided by the embodiment of the application is shown in Figure 1 The scoring card model analysis processing method can include the following steps S110-S160.

[0029] S110, a scoring card model based on a text form is obtained, and the logical structure of the scoring card model follows a preset syntax rule.

[0030] S120, a compiler corresponding to the syntax rule is determined, and the scoring card model is compiled into an intermediate bytecode file through the compiler; wherein the intermediate bytecode file is a syntax tree in the form of a byte string.

[0031] S130, the intermediate bytecode file is encrypted using a Fernet symmetric encryption algorithm to obtain an encrypted file.

[0032] S140, a pair of asymmetric keys including a public key and a private key is generated based on an RSA algorithm, the encrypted file is digitally signed using the private key to generate a signature file.

[0033] S150, a decryption tool corresponding to the encrypted file is generated, and the public key of the asymmetric key is encoded in the decryption tool to obtain a target decryption tool; wherein the target decryption tool is used to verify the signature file, decrypt the encrypted file and provide a decision engine.

[0034] S160, the encrypted file, the target decryption tool and the signature file are sent to a data end for use.

[0035] The foregoing is a specific implementation of the scoring card model analysis processing method provided by the embodiment of the present application. It can be understood that the present application compiles the scoring card model into an intermediate bytecode file in the form of a string, and performs encryption processing through the Fernet symmetric encryption algorithm to obtain an encrypted file, which can ensure that the scoring card model is always in an encrypted state during the entire delivery process, preventing the model logic and algorithm details from being leaked. There is no need to worry about the scoring card model being stolen or reverse-engineered during transmission. Compared with the prior art that relies on a third-party private computing platform, the model end and the data end of the present application directly interact in a mode that reduces dependence on external systems, eliminates the risk of external leakage, and ensures the privacy protection of the scoring card model.

[0036] In addition, the present application also generates a decryption tool corresponding to the encrypted file, uses a private key to digitally sign the encrypted file to generate a signature file, and encodes the public key of the asymmetric key in the decryption tool to obtain a target decryption tool. The data end can call and use the model without decrypting the specific content of the model through the target decryption tool, without knowing the internal structure or algorithm of the model. The present application not only ensures the convenience of the data end, but also avoids the risk of unauthorized access to the model. Compared with the traditional model transmission method, the data end of the present application only contacts the encrypted scoring card model, and can execute the model task without knowing the specific content of the scoring card model, reducing the risk of model leakage or abuse and significantly improving the privacy of the data end.

[0037] In one example, the scoring card model is composed of a series of linear IF-ELSE statements, and multi-layer nested structures are prohibited to ensure simple and parallel logic.

[0038] The foregoing preset syntax rules include IF statements, THEN statements, ELSE IF statements, ELSE statements, and expressions.

[0039] In the IF statement, each condition starts with IF and has only one IF, followed by an expression, and the expression is followed by a THEN keyword; for example: IF x = 1 THEN.

[0040] In the THEN statement, the THEN part performs related operations when the IF or ELSE IF condition is true; for example: THEN score = 100.

[0041] In the ELSE IF statement, the ELSE IF statement exists after the IF and before the ELSE, and is an optional condition branch for further judgment;

[0042] ELSE statement is used to handle all conditions that are not met; expression supports mathematical operations (such as +, -, *, / ), logical operations (such as and, or) and function operations (such as cats(), sum()) for conditional judgment and result calculation.

[0043] In some embodiments, the aforementioned determining the compiler corresponding to the syntax rule, and compiling the scoring card model into an intermediate bytecode file by the compiler, i.e., the aforementioned S120 can specifically include the following steps:

[0044] S210, performing lexical analysis and syntax analysis on the scoring card model based on a lightweight parsing tool library pyparsing;

[0045] S220, through writing pyparsing code, keyword recognition, identifier parsing, operator parsing, logical operation parsing and conditional statement parsing of the scoring card model are implemented to compile an intermediate bytecode file.

[0046] In one example, keyword recognition includes: by defining common keywords in the scoring card model including IF, THEN and ELSE, so that the compiling tool can accurately distinguish control statements, variables or operators;

[0047] Identifier parsing includes: identifying variables in the model as identifiers to ensure correct references in the model logic;

[0048] Operator parsing includes: correctly identifying mathematical and logical operators by the parser to ensure that the calculation logic in the model can be correctly executed;

[0049] Logical operation parsing includes: identifying and parsing various logical expressions including mathematical operations, string operations and logical judgments, and parsing various logical expressions into a tree structure for subsequent execution;

[0050] Conditional statement parsing includes: processing multi-level logical conditions by parsing the conditional structure, and ensuring that the logical conditions can be correctly executed.

[0051] In the embodiments of the present application, it can be understood that based on these rules, the present application generates an intermediate bytecode file of the scoring card model, i.e., a syntax tree T, and the scoring card will no longer be displayed in plaintext.

[0052] For example, for the expression if x>10 then y = 5, the syntax tree T is represented as:

[0053]

[0054] The generated syntax tree T exists in the form of a byte string (bytes type), and after the syntax tree T is generated, the application uses the Fernet symmetric encryption algorithm to encrypt the byte string.

[0055] In some embodiments, the decision engine is an executor of logical reasoning on the syntax tree generated by the compiler to provide interpretation and running functions to the syntax tree; the corresponding execution process of the executor includes expression evaluation, application of logical operators, execution of function calls, processing of IN and NOT IN operators, and overall evaluation process.

[0056] In one example, expression evaluation includes processing expression evaluation in a recursive manner, supporting the calculation of numbers, variables, function calls, and complex logical expressions; by parsing the nodes of the syntax tree, each sub-expression is evaluated step by step, and the results are combined.

[0057] It can be understood that the principle of expression evaluation is that for an input expression , first check whether it is a constant, a variable or a function name. If it is a constant, return the value directly; if it is a variable, take the value from the input variable mapping; if it is a function name, recursively pass the expression into the corresponding function execution environment to perform function call evaluation.

[0058] The application of logical operators includes processing logical operators (such as AND, OR), comparison operators (such as >, <, =, etc.), and mathematical operators (such as +, -, *, / ), by recursively parsing expressions, performing corresponding logical judgments or mathematical operations.

[0059] It can be understood that the principle of the application of logical operators is that the application of operators is based on the parsing of infix expressions. First, evaluate the left child expression, then apply the operator to evaluate the right child expression. This process can be represented as:

[0060]

[0061] For mathematical operators such as addition and subtraction, a similar processing mode is followed:

[0062]

[0063] The execution of function calls includes that in the syntax tree, if a function call is encountered, the parameters of the call are recursively processed, and the corresponding function definition is found in the interpreter, the function is executed and the result is returned.

[0064] It can be understood that the principle of function call execution is that suppose there is a function f that accepts a set of parameters: During the execution of the syntax tree, each parameter The evaluation is performed to generate the actual parameters: The corresponding function f is then looked up in the function dictionary and called:

[0065]

[0066] The processing of the IN and NOT IN operators includes: first evaluating the left expression recursively, and then matching each element in the right list.

[0067] It can be understood that the processing of the IN and NOT IN operators corresponds to the principle that, for the expression , the value of is first evaluated, and then is compared with each element of :

[0068]

[0069] Similarly, the NOT IN operator is implemented by negation:

[0070]

[0071] The overall evaluation process includes: the parser traverses each node in the syntax tree from top to bottom, applies the corresponding rules to evaluate, and returns the evaluation result of the entire conditional expression to the caller through the function call or operator calculation of the sub-expression.

[0072] In some embodiments, when the target decryption tool runs at the data end, the scoring card model analysis processing method further includes:

[0073] S310, verifying whether the signature file and the public key are legal through the target decryption tool;

[0074] S320, after the signature file and the public key are verified, decrypting the decrypted file to restore the syntax tree and loading it into the memory;

[0075] S330, executing the decrypted syntax tree in the memory, and receiving the sample features that need to be predicted;

[0076] S340, performing specific logic according to the structure of the syntax tree, and evaluating the conditional expression and function call through the parsing and execution of the syntax tree to obtain the prediction information.

[0077] In the embodiments of the present application, it can be understood that the present application relates to the interaction of the model end and the data end, the data end receives the encrypted file, the target decryption tool and the signature file sent by the model end; the data end executes the target decryption tool and inputs the encrypted file, the signature file and the sample features to be predicted; the target decryption tool first verifies the legality of the digital signature to ensure that the model comes from a trusted source; after verification, the target decryption tool can use a symmetric decryption algorithm to decrypt the encrypted model into an intermediate bytecode file corresponding to the syntax tree; the decrypted model is only loaded into the memory and will not be exposed in plaintext form; the target decryption tool executes the decrypted syntax tree in the memory based on the sample features, and returns the prediction result in JSON format after the model calculation is completed, ensuring the structure and consistency of data transmission.

[0078] Based on this, the present application ensures the double security of the model and the data by encrypting the scoring card model and delivering it to the data end. The data end completes the prediction task by calling the encrypted model without decrypting the model, avoiding the risk of reverse cracking of the model, while meeting the demand of privacy calculation. The present scheme has wide application prospect, especially suitable for the data security and model protection demand in the fields of finance and credit.

[0079] In some embodiments, how to use the encrypted scoring card model of the present application to evaluate the risk of the applicant in the credit application scenario is now shown, ensuring the double privacy and security of the model and the data without the help of a third-party platform. The scoring card model is directly delivered to the data end after encryption, and the data end calls the model to complete the risk assessment without decrypting the model. The specific process is as follows, please refer to Figure 2 .

[0080] (1) Scene description

[0081] A financial institution designs a scoring card model to evaluate the risk of credit applicants, and the evaluation basis includes annual income, credit record, debt ratio, etc. In order to ensure the confidentiality of the model and the privacy of the data, the financial institution adopts the encrypted scoring card model scheme of the present application to deliver the trained model to the credit audit platform (data end) after encryption.

[0082] (2) Model end operation process (financial institution)

[0083] 2.1. Design the scoring card model:

[0084] The financial institution designs a scoring card model according to the credit risk evaluation demand. The scoring items include annual income, credit record, debt ratio, working years, property situation and loan history, the model logic adopts linear IF-ELSE statement, and the generated model file is saved as risk_scorecard_model.txt in text format, wherein the scoring logic content is as follows:

[0085] IF annual income > 50,000 THEN

[0086] score = score + 150

[0087] ELSE IF annual income > 30,000 THEN

[0088] score = score + 100

[0089] ELSE

[0090] score = score + 50

[0091] IF credit record >= 750 THEN

[0092] score = score + 250

[0093] ELSE IF credit record >= 600 THEN

[0094] score = score + 150

[0095] ELSE

[0096] score = score + 50

[0097] IF debt ratio < 30% THEN

[0098] score = score + 120

[0099] ELSE IF debt ratio < 50% THEN

[0100] score = score + 80

[0101] ELSE

[0102] score = score + 40

[0103] IF length of employment > 10 THEN

[0104] score = score + 80

[0105] ELSE IF length of employment > 5 THEN

[0106] score = score + 50

[0107] ELSE

[0108] score = score + 20

[0109] IF owns a home THEN

[0110] score = score + 50

[0111] ELSE

[0112] score = score + 20

[0113] IF loan history on-time payment THEN

[0114] score = score + 90

[0115] ELSE

[0116] score = score + 50

[0117] 2.2 Model Compilation and Encryption:

[0118] The financial institution uses the encryption tool encrypt_tool.bin to directly compile and encrypt the scorecard model file risk_scorecard_model.txt.

[0119] The tool accepts the scorecard model file as input and generates the encrypted bytecode file encrypted_risk_scorecard_model.enc. The entire process includes compilation and encryption operations, without the need for separate compilation tools.

[0120] 2.3. Generate Asymmetric Key and Digital Signature:

[0121] The encryption tool generates a pair of asymmetric keys (2048 bits) using the RSA algorithm. The encryption tool also uses the generated private key to digitally sign the encrypted model file, generating the file signature.sig, and the public key is embedded in the decryption tool for verifying the legitimacy of the model file. This process is also automatically completed in the encryption tool.

[0122] 2.4. Deliver Model and Decryption Tool:

[0123] The financial institution delivers the following files to the credit review platform (data side); encrypted file (encrypted scorecard model file): encrypted_risk_scorecard_model.enc

[0124] Target decryption tool: decrypt_tool.bin

[0125] Signature file: signature.sig

[0126] These files ensure that the data side can run the model and complete the credit application risk assessment under the premise of security.

[0127] (3) Data End Operation Flow (Credit Audit Platform)

[0128] 3.1 Receive Model and Decryption Tool:

[0129] The credit audit platform receives the encrypted file encrypted_risk_scorecard_model.enc, the target decryption tool decrypt_tool.bin, and the digital signature file signature.sig provided by the financial institution.

[0130] 3.2 Input Prediction Sample Data:

[0131] The credit audit platform prepares sample data of credit applicants (e.g., annual income, credit record, debt ratio, etc.) and stores it as a JSON file format input_data.json with the following content:

[0132] {

[0133] "annual income": 60000,

[0134] "credit record": 720,

[0135] "debt ratio": 35,

[0136] "work tenure": 8,

[0137] "property status": true,

[0138] "loan history on time": true

[0139] }

[0140] 3.3 Run Decryption Tool:

[0141] The audit platform runs the target decryption tool decrypt_tool.bin in the server and inputs the following parameters:

[0142] Encrypted file: encrypted_risk_scorecard_model.enc

[0143] Signature file: signature.sig

[0144] Sample data file: input_data.json

[0145] The target decryption tool first verifies the legality of the signature file to confirm that the model comes from a trusted source. After verification, the tool uses the public key to verify the signature and decrypt the encrypted model, loading it into memory in bytecode form to perform the scoring task.

[0146] 3.4 Execute the scoring card model and return the result:

[0147] The decryption tool executes the scoring card model in memory, combining the input sample data to calculate the applicant's risk score. After the calculation is completed, the decryption tool returns the prediction result in JSON format, generating a file output_result.json with the following content:

[0148] {

[0149] "Risk Score": 650,

[0150] "Evaluation Result": "Medium Risk"

[0151] }

[0152] (4) Implementation effect

[0153] Through this embodiment, the financial institution successfully delivers the encrypted scoring card model to the data end for use, and the credit review platform can perform risk assessment on credit applicants without decrypting the model. The entire process ensures the confidentiality of the scoring card model and the privacy of the applicant's data, avoiding the risk of model reverse engineering, while simplifying the dependence on external platforms. This solution not only effectively improves the confidentiality and calculation efficiency of the scoring card model, but also reduces communication overhead and computational complexity. It is suitable for large-scale financial risk assessment scenarios.

[0154] In some embodiments, the present application provides a scoring card model analysis processing system 400, as shown in Figure 3 which can include the following modules:

[0155] An acquisition module 410 is configured to acquire a scoring card model based on a text form, and the logical structure of the scoring card model complies with a preset syntax rule;

[0156] A compilation module 420 is configured to determine a compiler corresponding to the syntax rule, and compile the scoring card model into an intermediate bytecode file through the compiler; wherein the intermediate bytecode file is a syntax tree in the form of a byte string;

[0157] An encryption module 430 is configured to perform encryption processing on the intermediate bytecode file using a Fernet symmetric encryption algorithm to obtain an encrypted file;

[0158] A signature module 440 is configured to generate a pair of asymmetric keys including a public key and a private key based on an RSA algorithm, use the private key to digitally sign the encrypted file, and generate a signed file;

[0159] The generating module 450 is configured to generate a decryption tool corresponding to the encrypted file, encode the public key of the asymmetric key in the decryption tool, and obtain a target decryption tool; the target decryption tool is used to verify the signature file, decrypt the encrypted file, and provide the decision engine.

[0160] The sending module 460 is configured to send the encrypted file, the target decryption tool, and the signature file to the data end for use.

[0161] According to embodiments of the present application, any multiple modules of the acquiring module 410, the compiling module 420, the encrypting module 430, the signing module 440, the generating module 450, and the sending module 460 can be combined in one module, or any one of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of the modules can be combined with at least part of the functions of other modules, and implemented in one module.

[0162] Figure 3 Each module in the system has the function of implementing each step of the aforementioned scorecard model analysis processing method, and can achieve the corresponding technical effects. For brevity of description, it will not be repeated here.

[0163] In some embodiments, the present application provides an electronic device, a structural schematic diagram of which is shown in Figure 4

[0164] The electronic device can include a processor 510 and a memory 520 storing computer program instructions.

[0165] Specifically, the processor 510 described above can include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or can be configured to implement one or more integrated circuits of embodiments of the present application.

[0166] The memory 520 can include a mass storage for data or instructions. By way of example and not limitation, the memory 520 can include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive or a combination of two or more of these. Where appropriate, the memory 520 can include removable or non-removable (or fixed) media. Where appropriate, the memory 520 can be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, the memory 520 is a non-volatile solid-state memory.

[0167] ​The memory 520 can include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Thus, generally, the memory 520 includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software that, when executed (e.g., by the one or more processors), is configured to perform the operations described above in connection with any of the scorecard model analysis processing methods of the embodiments.

[0168] The processor 510 implements any of the scorecard model analysis processing methods of the embodiments described above by reading and executing computer program instructions stored in the memory 520.

[0169] In one example, the electronic device can further include a communication interface 530 and a bus 500. As shown, the processor 510, the memory 520, and the communication interface 530 are connected through the bus 500 and complete communication with each other. Figure 4

[0170] The communication interface 530 is mainly used to realize the communication between the modules, devices, units, and / or equipment in the embodiments of the present application.

[0171] The bus 500 includes hardware, software, or both, which couples the components of the online data traffic billing device to each other. By way of example, and not limitation, the bus can include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand (IB) interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or another suitable bus or a combination of two or more of these. Where suitable, the bus 500 can include one or more buses. Although particular buses are described and shown in the embodiments of the present application, the present application contemplates any suitable bus or interconnect.

[0172] In addition, in combination with the scorecard model analysis processing method in the above embodiments, the embodiments of the present application can provide a computer storage medium to realize. The computer storage medium has computer program instructions stored thereon; the computer program instructions are executed by the processor to realize any of the scorecard model analysis processing methods in the above embodiments.

[0173] ​It is to be understood that the application is not limited to particular configurations and processes described herein and shown in the drawings. The detailed description is not to be taken as limiting the application. In the above embodiments, several specific steps are described and illustrated in order to provide a thorough understanding of the application. However, the application can be practiced with fewer or additional steps, and in a different order. The application is to be limited only by the claims.

[0174] The functional blocks shown in the structural block diagrams above can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, and the like. When implemented in software, the elements of the application are program or code segments that are used to perform the required tasks. The program or code segments can be stored in a machine-readable medium, or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. A "machine-readable medium" includes any medium that can store or transfer information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, and the like. The code segments can be downloaded via computer networks such as the Internet, intranets, and the like.

[0175] It is also to be understood that the example embodiments described herein are based on a series of steps or apparatuses to describe some methods or systems. However, the application is not limited to the order of the steps described above, that is, the steps can be performed in the order mentioned in the embodiments, or in an order different from the embodiments, or several steps can be performed simultaneously.

[0176] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other processing devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other processing devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. Alternatively, computer program implemented steps can be implemented by special purpose logic circuitry, for example, an FPGA or an ASIC, to implement the various processes.

[0177] Compared with the prior art, the present application has the following beneficial effects:

[0178] 1、The present application compiles the scoring card model into bytecode and encrypts it into an intermediate file, ensuring that the scoring card model is always in an encrypted state during the entire delivery process, thereby preventing the model logic and algorithm details on the model side from being leaked. The model side does not need to worry about the model being stolen or reverse-engineered during transmission.

[0179] 2、The encryption tool in the present application can automatically complete the compilation and encryption of the scoring card model, without the need for manual complex compilation and encryption operations. The encryption tool not only simplifies the operation, but also improves the efficiency and consistency of model generation, enabling the model to be safely delivered to the data side for prediction and analysis.

[0180] 3、The present application integrates RSA algorithm and digital signature technology to ensure the legality and security of the scoring card model during transmission and use on the data side. The data side verifies the model signature through the decryption tool to confirm that the model has not been tampered with or forged, and then securely decrypts and executes the model to ensure the privacy of the model.

[0181] 4、In the present application, the data side can call and use the encrypted model without decrypting the specific content of the model through the decryption tool. The data side only needs to load the encrypted scoring card model through the local decryption tool and directly input data for prediction or evaluation without knowing the internal structure or algorithm of the model. Based on this, the present application not only ensures the convenience of the data side, but also avoids the risk of unauthorized access to the model.

[0182] 5、The encrypted scoring card model in the present application can be decrypted and executed locally on the data side without the need for a third-party privacy computing platform. Through direct delivery and use between the model side and the data side, the secure delivery and evaluation of the model can be completed. The entire model interaction and use process is completed independently between the model side and the data side, greatly reducing the dependence on external platforms, simplifying the system architecture, and reducing deployment and maintenance costs.

[0183] 6、The encrypted scoring card model of the present application is a bytecode file that can run independently in multiple computing environments, avoiding dependence on specific hardware devices (such as trusted execution environments). This makes the present application have wider applicability and higher flexibility, enabling safe and efficient execution in different computing scenarios and meeting diverse actual needs.

[0184] 7、Compared with existing multi-party collaborative computing or secret sharing technology, the present application does not require frequent data exchange and complex collaborative computing operation. The data party only needs to call the delivered encryption model locally for calculation, without relying on external privacy computing platform or multi-party participation, significantly reducing communication overhead and computational complexity, thereby improving overall computing efficiency.

[0185] The above examples are only used to illustrate the technical solutions of the present application, but not to limit it; although the present application has been described in detail with reference to the foregoing examples, those skilled in the art should understand that the technical solutions recorded in the foregoing examples can be modified, or some technical features can be replaced by equivalents; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A scoring card model analysis processing method, characterized by, The method comprises the following steps: obtain a scorecard model in a text form, a logical structure of the scorecard model following preset syntax rules; determine a compiler corresponding to the syntax rules, and compile the scorecard model into an intermediate bytecode file through the compiler; wherein the intermediate bytecode file is a syntax tree in a byte string form; encrypt the intermediate bytecode file using a Fernet symmetric encryption algorithm to obtain an encrypted file; generate a pair of asymmetric keys including a public key and a private key based on an RSA algorithm, and use the private key to digitally sign the encrypted file to generate a signature file; generate a decryption tool corresponding to the encrypted file and encode the public key of the asymmetric key in the decryption tool to obtain a target decryption tool; wherein the target decryption tool is used to verify the signature file, decrypt the encrypted file, and provide a decision engine; send the encrypted file, the target decryption tool, and the signature file to a data terminal for use; The determination of the compiler corresponding to the syntax rules and the compilation of the scorecard model into an intermediate bytecode file comprises: perform lexical analysis and syntax analysis on the scorecard model based on a lightweight parsing tool library pyparsing; compile the intermediate bytecode file by writing pyparsing code to realize keyword recognition, identifier parsing, operator parsing, logical operation parsing, and conditional statement parsing of the scorecard model; The keyword recognition comprises defining common keywords in the scorecard model including IF, THEN, and ELSE, so that the compiler can accurately distinguish control statements, variables, or operators; The identifier parsing comprises identifying variables in the model as identifiers to ensure correct references in the model logic; The operator parsing comprises correctly identifying mathematical and logical operators by the parser to ensure that the calculation logic in the model can be correctly executed; The logical operation parsing comprises identifying and parsing various logical expressions including mathematical operations, string operations, and logical judgments, and parsing the various logical expressions into a tree structure for subsequent execution; The conditional statement parsing comprises processing multi-level logical conditions by parsing the conditional structure and ensuring that the logical conditions can be correctly executed; The decision engine is an executor for logical reasoning of the syntax tree generated by the compiler to provide interpretation and running functions for the syntax tree; the execution flow corresponding to the executor comprises expression evaluation, application of logical operators, execution of function calls, processing of IN and NOT IN operators, and overall evaluation process; The expression evaluation comprises processing expression evaluation in a recursive manner, supporting calculation of numbers, variables, function calls, and complex logical expressions; by parsing the nodes of the syntax tree, each sub-expression is evaluated step by step, and the results are combined; The application of logical operators comprises processing logical operators, comparison operators, and mathematical operators, and performing corresponding logical judgment or mathematical operation by recursively parsing expressions; The execution of the function call includes: in the syntax tree, if a function call is encountered, the parameters of the call are processed recursively, and the corresponding function definition is found in the interpreter, the function is executed and the result is returned; The processing of the IN and NOT IN operators includes: first, recursively evaluate the left side expression by matching the left side operand with each element in the right side list, and then match the right side list one by one; The overall evaluation process includes: the parser traverses each node in the syntax tree from top to bottom, applies the corresponding rules for evaluation, and calculates the results of function calls or operator sub-expressions, and finally the evaluation result of the entire conditional expression is returned to the caller.

2. The scoring card model analysis processing method of claim 1, wherein, When the target decryption tool runs at the data end, the scoring card model analysis processing method further includes: Verify whether the signature file and the public key are legal through the target decryption tool; Decrypt the decrypted file to restore the syntax tree and load it into the memory after the signature file and the public key are verified; Execute the decrypted syntax tree in the memory and receive the sample features that need to be predicted; According to the structure of the syntax tree, perform specific logic, and evaluate the conditional expressions and function calls through the analysis and execution of the syntax tree to obtain the prediction information.

3. The scoring card model analysis processing method according to claim 1 or 2, characterized by, The preset syntax rules include IF statements, THEN statements, ELSE IF statements, ELSE statements, and expressions; In the IF statement, each condition starts with IF and only one IF, followed by an expression, and then a THEN keyword; In the THEN statement, when the IF or ELSE IF condition is true, the THEN part performs related operations; In the ELSE IF statement, the ELSE IF statement exists after the IF and before the ELSE, as an optional condition branch for further judgment; The ELSE statement is used to handle the case where all conditions are not met; the expression supports mathematical operations, logical operations, and function operations for conditional judgment and result calculation.

4. A scoring card model analytics processing system, characterized by, It includes: An acquisition module is configured to acquire a scoring card model based on a text form, wherein a logical structure of the scoring card model complies with preset syntax rules; A compiling module is configured to determine a compiler corresponding to the syntax rules, and to compile the scoring card model into an intermediate bytecode file through the compiler; wherein the intermediate bytecode file is a syntax tree in the form of a byte string; An encryption module is configured to encrypt the intermediate bytecode file using a Fernet symmetric encryption algorithm to obtain an encrypted file; A signing module is configured to generate a pair of asymmetric keys including a public key and a private key based on an RSA algorithm, to digitally sign the encrypted file using the private key, and to generate a signature file; A generation module is configured to generate a decryption tool corresponding to the encrypted file and to encode the public key of the asymmetric key in the decryption tool to obtain a target decryption tool; wherein the target decryption tool is configured to verify the signature file, decrypt the encrypted file, and provide a decision engine. The sending module is configured to send the encrypted file, the target decryption tool and the signature file to a data terminal for use; The compiler corresponding to the syntax rule is determined, and the scoring card model is compiled into an intermediate bytecode file through the compiler, including: The scoring card model is subjected to lexical analysis and syntax analysis based on a lightweight parsing tool library pyparsing; The keywords of the scoring card model are identified, the identifiers are parsed, the operators are parsed, the logical operations are parsed, and the conditional statements are parsed through the pyparsing code to compile the intermediate bytecode file; The keyword identification includes defining common keywords in the scoring card model including IF, THEN and ELSE, so that the compiling tool can accurately distinguish control statements, variables or operators; The identifier parsing includes identifying variables in the model as identifiers to ensure correct references in the model logic; The operator parsing includes correctly identifying mathematical and logical operators through the parser to ensure that the calculation logic in the model can be correctly executed; The logical operation parsing includes identifying and parsing various logical expressions including mathematical operations, string operations and logical judgments, and parsing the various logical expressions into a tree structure for subsequent execution; The conditional statement parsing includes parsing the conditional structure to handle multiple levels of logical conditions and ensure that the logical conditions can be correctly executed; The decision engine is an executor for logical reasoning of the syntax tree generated by the compiler to provide interpretation and running functions for the syntax tree; the execution flow corresponding to the executor includes expression evaluation, application of logical operators, execution of function calls, processing of IN and NOT IN operators, and overall evaluation process; The expression evaluation includes processing expression evaluation in a recursive manner, supporting calculation of numbers, variables, function calls and complex logical expressions; by parsing the nodes of the syntax tree, each sub-expression is evaluated and the results are combined; The application of the logical operator includes processing logical operators, comparison operators and mathematical operators, and performing corresponding logical judgment or mathematical operation by recursively parsing expressions; The function call execution includes that, in the syntax tree, if a function call is encountered, the parameters of the call are recursively processed, and the corresponding function definition is found in the interpreter, the function is executed and the result is returned; The IN and NOT IN operator processing includes matching the left operand with each element in the right side list, first recursively evaluating the left expression, and then matching the right side list one by one; The overall evaluation process includes that the parser traverses each node in the syntax tree from top to bottom, applies the corresponding rules for evaluation, and calculates the results of the sub-expressions through function calls or operators, and finally the evaluation result of the entire conditional expression is returned to the caller.

5. An electronic device, comprising: The method comprises the following steps: The method comprises the following steps: A processor, a memory, and a program stored on the memory and executable on the processor, the program, when executed by the processor, implements the scoring card model analysis processing method of any one of claims 1 to 3.

6. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a program or instructions, the program or instructions, when executed by the processor, implements the scoring card model analysis processing method of any one of claims 1 to 3.

Citation Information

Patent Citations

  • Data processing method, device, apparatus, and storage medium

    CN109255209A

  • Data transmission method, device, system and equipment

    CN114024710A

  • Privacy-protecting risk score information query method, device, system and equipment

    CN114124343A

  • Bytecode file encryption deployment method and device, equipment and storage medium

    CN119026093A