Dynamic adjustment method for mobile payment password-free limit
By constructing a device security state vector and analyzing transaction behavior, the mobile payment limit is dynamically adjusted, which solves the problem of insufficient joint perception of device environment and behavior in existing technologies, and achieves more accurate risk control and user experience stability.
Patent Information
- Application Number
- CN202511258519.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-04
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-09-04
AI Technical Summary
Existing technologies lack the ability to jointly perceive device environment and behavior in mobile payment scenarios, resulting in transactions being approved even when risks are not accurately quantified, posing potential risks.
By collecting discrete data on network environment, device unlocking method, SIM card status, system integrity, and application environment, a device security state vector is constructed, a device security product attenuation value is generated, and the password-free payment limit is dynamically adjusted in conjunction with transaction behavior analysis.
It improves the flexibility, security, and targeting of credit limit response without interfering with the user's payment experience, avoids excessive approval or false rejection of transactions due to environmental changes or behavioral deviations, and enhances the dynamic adjustment accuracy and risk control capabilities of the password-free payment limit.
Smart Images

Figure CN120806949A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of mobile payment, in particular to a dynamic adjustment method of mobile payment password-free quota. BACKGROUND
[0002] The dynamic adjustment method of mobile payment password-free quota is used for generating a control mechanism of password-free payment quota dynamically according to transaction behavior and device security state in a mobile payment scene, and the core use thereof is to realize accurate perception and real-time inhibition of password-free transaction risk without interfering with the payment experience of users.
[0003] Although the prior art has supported setting a control mechanism according to transaction behavior and device state in a password-free payment scene, it lacks the ability of joint perception of device environment and behavior. In terms of device state determination, the common way is mostly based on whether it is rooted or whether the network is secure, and it is difficult to make refined judgments under the change of various security state combinations, resulting in that the transaction is still released when the risk is not accurately quantified, and potential hidden dangers are buried. Therefore, improvement is needed. SUMMARY
[0004] The purpose of the present application is to solve the shortcomings in the prior art and provide a dynamic adjustment method of mobile payment password-free quota.
[0005] In order to achieve the above-mentioned purpose, the present application adopts the following technical scheme, a dynamic adjustment method of mobile payment password-free quota, comprising the following steps: When initiating a payment request, the payment terminal collects the discrete states of network environment, device unlocking mode, SIM card state, system integrity and application environment in real time, establishes a device security state vector; Based on the payment protocol, the device security state vector is called to generate a device security product attenuation value, the highest password-free quota reference value set by the user is operated with the device security product attenuation value, and a comprehensive device security score is obtained; After receiving the payment request, the payment server extracts the transaction amount, the payee account information, the commodity category information and the transaction time information, establishes a cognitive load factor set, calculates based on each factor in the cognitive load factor set, and obtains a transaction cognitive load score; The transaction cognitive load score is compared with the set cognitive load threshold value, a transaction risk level determination result is established, the comprehensive device security score is taken as the basic quota, and the transaction risk level determination result is called to generate a dynamic password-free payment quota.
[0006] Preferably, the device security state vector acquisition step is: The payment terminal extracts the current network connection type, screen unlocking mode, whether the SIM card is inserted and the operator's home, whether the system is tampered with, and the container environment attribute of the running application after receiving the signal of the user initiating the payment request, and generates five discrete states of network connection type, screen unlocking mode, SIM card state identification, system verification state, and container environment attribute; According to the five discrete states of network connection type, screen unlocking mode, SIM card state identification, system verification state, and container environment attribute, each discrete state is one-to-one mapped according to the security level value, and the mapping result is sequentially assigned as the network environment component, the device unlocking mode component, the SIM card state component, the system integrity component, and the application environment component. Based on the network environment component, the device unlocking mode component, the SIM card state component, the system integrity component, and the application environment component, a column vector is sequentially arranged in a unified order, and each component is stored according to the vector structure, generating a device security state vector.
[0007] Preferably, the device security product attenuation value acquisition step is: Based on the device security state vector, sequentially extract the network environment component, the device unlocking mode component, the SIM card state component, the system integrity component, and the application environment component, and calculate the device security product attenuation value.
[0008] Preferably, the comprehensive device security score acquisition step is: According to the device security product attenuation value and the highest password-free quota reference value, calculate the comprehensive device security score.
[0009] Preferably, the acquisition step of the cognitive load factor set is: After the payment server receives the payment request, it extracts the transaction amount field, the payee account identifier field, the product category field, and the transaction time field from the request one by one, and records them to the transaction parameter buffer area according to the preset structure, obtaining the transaction amount field, the payee account identifier field, the product category field, and the transaction time field. According to the transaction amount field, the payee account identifier field, the product category field, and the transaction time field, the mean, frequency, and time distribution index of the corresponding field of the user in the transaction history database are called respectively, and the methods of deviation value extraction, frequency statistics, and window difference calculation are used to calculate the amount deviation factor, the payee strangeness factor, the product category rarity factor, and the time sensitivity factor, obtaining the cognitive load factor set.
[0010] Preferably, the transaction cognitive load score acquisition step is: According to the cognitive load factor set, calculate the transaction cognitive load score.
[0011] Preferably, the transaction risk level determination result obtaining step is: Based on the transaction cognitive load score, the transaction cognitive load score is compared with the system preset cognitive load threshold value, if the transaction cognitive load score is greater than or equal to the cognitive load threshold value, it is determined that the transaction is in a high risk state, otherwise it is determined to be in an acceptable state, and a transaction risk level determination result is generated.
[0012] Preferably, the dynamic password-free payment quota obtaining step is: According to the transaction risk level determination result, select the quota suppression coefficient matched with the determination result from the quota suppression coefficient preset mapping table, and call the comprehensive device security score as the basic quota value, calculate the quota suppression coefficient and the basic quota value, and generate the initial calculation result of the dynamic password-free quota; Based on the initial calculation result of the dynamic password-free quota, unit conversion, numerical precision interception and field identification additional processing are performed, and transaction request number and user unique identification fields are added, to generate a dynamic password-free payment quota.
[0013] Compared with the prior art, the advantages and positive effects of the present application are: The present application can structureally depict the device security before the transaction is initiated by collecting and constructing a security state vector based on the network environment, device unlocking mode, SIM card state, system integrity and application environment discrete state, and capture the security fluctuation characteristics of the device during operation; the security product attenuation value generated by the security state vector is combined with the highest password-free quota benchmark value set by the user to output the comprehensive device security score in the form of a nonlinear function, so that the quantification filtering of the device trustworthiness is realized before the quota calculation stage; at the transaction behavior analysis level, the cognitive load factor set is constructed by extracting the transaction amount, payee account information, commodity category and transaction time, forming a structured risk representation for user behavior, avoiding misjudgment caused by static judgment of a single indicator; the cognitive load score is compared with the set threshold value to output the transaction risk level, and the quota suppression coefficient is dynamically retrieved based on the level, and the dynamic password-free payment quota is output after the device security score is calculated, so that the final quota result has both device trust support and response to transaction risk changes. Through this processing chain, the flexibility, security and pertinence of the quota response are improved while maintaining the stability of the user experience, and the excessive release or misjudgment of the transaction caused by environmental changes or behavior deviation is avoided, and the dynamic regulation accuracy and risk control ability of the password-free payment quota are improved. BRIEF DESCRIPTION OF DRAWINGS
[0014] Figure 1 The present application is a step schematic diagram. DETAILED DESCRIPTION
[0015] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and not intended to limit the present application.
[0016] Please refer to Figure 1 The present application provides a technical solution, a dynamic adjustment method of mobile payment password-free amount, comprising the following steps: When initiating a payment request, the payment terminal collects the discrete states of network environment, device unlocking method, SIM card state, system integrity and application environment in real time, and establishes a device security state vector; Based on the payment protocol, the device security state vector is called to generate a device security product attenuation value, the user's highest password-free amount reference value is operated with the device security product attenuation value, and a comprehensive device security score is obtained; After receiving the payment request, the payment server extracts the transaction amount, the payee account information, the commodity category information and the transaction time information, establishes a cognitive load factor set, calculates based on each factor in the cognitive load factor set, and obtains a transaction cognitive load score; The transaction cognitive load score is compared with the set cognitive load threshold value, the transaction risk level determination result is established, the comprehensive device security score is taken as the basic amount, and the transaction risk level determination result is called to generate a dynamic password-free payment amount.
[0017] The acquisition step of the device security state vector is: After receiving the signal of the user initiating the payment request, the payment terminal extracts the current network connection type, screen unlocking method, whether the SIM card is inserted and the operator belongs to, whether the system is tampered with and the container environment attribute of the running application, generates five discrete states of network connection type, screen unlocking method, SIM card state identifier, system verification state and container environment attribute; According to the five discrete states of network connection type, screen unlocking method, SIM card state identifier, system verification state and container environment attribute, each discrete state is one-to-one mapped according to the security level value, and the mapping result is assigned as network environment component, device unlocking method component, SIM card state component, system integrity component and application environment component in turn; Based on the network environment component, the device unlocking method component, the SIM card state component, the system integrity component and the application environment component, a column vector is arranged in turn according to a unified order, and each component is stored according to the vector structure, and a device security state vector is generated.
[0018] Specifically, the payment terminal, after receiving the signal of the user initiating the payment request, acquires various device state information by calling the operating system underlying interface, and the specific execution process is as follows: first, the network state management interface is called to query the specific type of the current active network, and to distinguish whether it is a cellular mobile network or a wireless local area network. If it is a cellular mobile network, it is further identified as a technology generation, such as the fifth generation mobile communication technology (5G) or the fourth generation mobile communication technology (4G). If it is a wireless local area network, its service set identifier (SSID) is obtained, and it is compared with a locally stored trusted network list automatically accumulated from the user's historical connection records or manually confirmed. If the SSID exists in the trusted list, it is marked as a trusted wireless network, otherwise it is marked as a public or unknown network, so as to obtain the specific state of the network connection type. Secondly, the device lock screen management service is called to check whether the device has enabled a secure lock screen. If it is enabled, it is further queried to determine whether it is based on biometric identification (such as fingerprint or facial recognition) or based on password or pattern, and the specific state of the screen unlocking method is obtained. Thirdly, the phone service interface is called to query the SIM card state, to confirm whether the physical SIM card or eSIM card is in place and in a usable state, and to read its mobile network operator code when available, and to compare it with the historical record of the device's first activation or commonly used operator to determine whether there is a SIM card replacement or home location anomaly, and to form a SIM card state identifier. Then, the system integrity self-checking program is executed, which calculates the checksum of the system core partition and compares it with the baseline checksum pre-installed at the factory or updated through official channels to detect whether the system files have been tampered with illegally. At the same time, a hardware-level security authentication interface provided by the trusted execution environment, such as Google's SafetyNet Attestation or Huawei's SafetyDetect, is called to obtain an encrypted signature report on the device bootloader state and system integrity level. Based on the above two inspection results, it is determined whether the system has been tampered with. Finally, the list of currently running application processes and the installed application package name are scanned, and a feature library of known risky applications and frameworks (such as Xposed, Magisk, etc. injection or virtualization tools) is periodically updated from the payment server to match the payment application running in a tampered or potentially monitored container environment. The query and detection results of the above five dimensions are respectively fixed as the network connection type, the screen unlocking method, the SIM card state identifier, the system verification state, and the container environment attribute.
[0019] According to the network connection type, screen unlocking method, SIM card state identifier, system verification state and container environment attribute generated in the previous step, the system will assign a quantitative security score to each discrete state. This process is completed through a pre-set "discrete state to security score" mapping table. The mapping table is constructed based on risk analysis of massive historical transaction data. By statistically analyzing the fraud transaction rate under different device state combinations, the security contribution of each state is quantified. The specific mapping relationship is set as follows: for the network connection type, the discrete state marked as "trusted wireless network" or "4G / 5G cellular network" is mapped to the highest security level, level value 1.0, while "public or unknown network" is mapped to 0.6, and "2G / 3G network or no network" is mapped to 0.2. For the screen unlocking method, "biometric identification" is mapped to 1.0, "6-digit or more numeric or complex character password" is mapped to 0.8, "pattern or simple password" is mapped to 0.5, and "no security lock screen" is mapped to 0.1. For the SIM card state identifier, "native frequently used SIM card" is mapped to 1.0, "newly replaced SIM card" is mapped to 0.7, and "no SIM card or flight mode" is mapped to 0.4. For the system verification state, "passing system checksum and hardware-level security authentication" is mapped to 1.0, "passing system checksum but hardware authentication fails" is mapped to 0.5, and "detecting system tampering or Root" is mapped to 0.1. For the container environment attribute, "standard application running environment" is mapped to 1.0, "detecting running in an emulator or virtualization container" is mapped to 0.5, and "detecting injection or Hooking framework" is mapped to 0.2. The setting logic of the security level value is that the baseline security state (such as biometric unlocking) is defined as 1.0, and the level values of other states are converted by associating the risk rate. For example, if it is found that the fraud transaction rate of public network is 70% higher than that of trusted network, its security level value is set to about 1 / (1+0.7), which is about 0.6, to reflect its increased relative risk. After completing the mapping table construction, the system will read the specific values of the five discrete states one by one, and find the corresponding security level value in the mapping table. Then the five values found are assigned to five new variables respectively to generate the network environment component, device unlocking method component, SIM card state component, system integrity component and application environment component.
[0020] Based on the network environment component, the device unlocking method component, the SIM card state component, the system integrity component and the application environment component generated in the previous process, the system needs to integrate these dispersed components into a unified data structure. This process first establishes a fixed and unchanging order, which is defined in the technical specification of the payment protocol and is fixed in the software development kit of the payment terminal. This ensures that all clients use a completely consistent vector structure. For example, the fixed order is defined as the network environment component in the first place, the device unlocking method component in the second place, the SIM card state component in the third place, the system integrity component in the fourth place, and the application environment component in the fifth place. The system strictly follows this order and fills the five component values obtained into a data array in order, thereby logically forming a five-dimensional column vector. For example, if the five component values obtained in a payment request are 1.0, 1.0, 0.7, 1.0 and 0.5, the column vector is mathematically represented as Subsequently, in order to facilitate transmission in the data packet of the payment request, the column vector is organized into a standardized data format. The system creates a temporary and lightweight data object in the memory of the application program. This object is not written to any permanent storage to prevent data leakage risks. It encapsulates the vector into a key-value pair structure, such as a JSON object represented as {"version": 1, "vector_values": [1.0, 1.0, 0.7, 1.0, 0.5]}, which contains the version number for subsequent structure upgrade and the component value array arranged in the predetermined order. This structured and encapsulated data object containing five ordered and secure components is finally defined and generated as the device security state vector.
[0021] The steps for obtaining the device security product attenuation value are as follows: Based on the device security state vector, the network environment component, the device unlocking method component, the SIM card state component, the system integrity component and the application environment component are sequentially extracted to calculate and generate the device security product attenuation value.
[0022] Specifically, based on the device security state vector, which is a structured data object containing five preset sequential components, the system first parses this vector in a fixed order, extracting the network environment component, the device unlocking method component, the SIM card state component, the system integrity component, and the application environment component one by one, for example, the system reads the component value array from the received device security state vector, assigns the first element to the network environment component, the second element to the device unlocking method component, and so on, until the fifth element is assigned to the application environment component. This extraction process does not involve any transformation of the numerical values, but only data positioning and reading operations. After successfully extracting all five components, the system performs the core product operation, which is to multiply the five independent security component values sequentially, with the value range between 0 and 1. The design logic of this multiplication operation is based on the cumulative effect of risk, that is, any significant reduction in one security dimension will disproportionately lower the overall security level. For example, a device may have a component value of 1.0 in network, unlocking method, SIM card, and system integrity, but if its application environment is detected as running under a framework, resulting in an application environment component value of 0.2, the final product result will be directly lowered to 0.2 (the calculation process is 1.0 × 1.0 × 1.0 × 1.0 × 0.2), which accurately reflects the disruptive impact of a single serious vulnerability on overall security. For another example, a device in a medium security state has a network environment of public network (component value 0.6), uses pattern unlocking (component value 0.5), and the remaining three are in ideal state (component value 1.0), then the calculation result is 0.6 × 0.5 × 1.0 × 1.0 × 1.0, which is 0.3. This calculation process is completed instantaneously in the processor, and the final product result is the device security product attenuation value.
[0023] The comprehensive device security score is obtained by the following steps: According to the device security product attenuation value and the highest password-free quota benchmark value, the comprehensive device security score is calculated, and the calculation formula is: ; Wherein, is the comprehensive device security score, is the highest password-free quota benchmark value set by the user, with the unit of [currency], , represents the device security product attenuation value, is the th security state component, is the system risk sensitivity coefficient, dimensionless, controlling the steepness of the function, is the security state response threshold, dimensionless, representing the system's acceptable security level boundary, and a Sigmoid function is constructed to smooth the output quota control coefficient.
[0024] Specifically, the formula: The benefit of the formula is that it introduces the standard Sigmoid function to smoothly and nonlinearly map the discrete and multi-dimensional device security status to a continuous quota control coefficient, avoiding the drastic jump of the free-password quota caused by a small change in the security score, and improving the stability of the user experience. Specifically, first, the formula uses the device security product attenuation value , which reflects the multiplier effect when multiple safety risk factors are superimposed, that is, a single serious risk can significantly reduce the overall safety assessment. Take the square root , which smoothes the rapid decline of the product attenuation value due to multiplication, making the function's response to changes in security status more moderate in most intervals, and only showing high sensitivity near key risk points. Moreover, through the system risk sensitivity coefficient and security status response thresholds These two adjustable parameters give the risk control model great flexibility. Payment service providers can dynamically adjust the risk control model based on the overall market fraud situation, user risk level or risk strategy for a specific activity period. value to change the sensitivity of the quota to risk, adjust The value is used to raise or lower the security baseline that triggers the quota suppression, and finally the quota control coefficient between 0 and 1 is combined with the user-defined maximum password-free quota baseline value. Multiplying together, it realizes the organic combination of personalized settings and dynamic risk control; The steps for obtaining (the maximum password-free limit benchmark value) are as follows: this parameter is set by the user independently in the client of the payment application. The acquisition process is that after the user logs in to the payment application, navigate to the "Settings" menu and select the "Password-free Payment" option in the "Payment Settings". The system will display a limit setting interface, allowing the user to enter or select a specific value within a valid range preset by the payment service provider (for example, RMB 100 to RMB 2,000 for ordinary users). This value represents the maximum risk limit for a single password-free transaction that the user is willing to bear. After the user confirms the input, the value is encrypted and transmitted to the payment server and stored in the database associated with the user's account as the benchmark upper limit for all subsequent calculations of password-free payment limits. For example, the user sets this benchmark value to RMB 1,000 based on his or her consumption habits and risk preferences. In subsequent calculations, The value of is 1000; The steps for obtaining the (device security product attenuation value) are as follows: this parameter is the direct output result of the previous step of this method and does not need to be recalculated in this step. Its value is based on the five security components in the device security state vector (network environment component , device unlocking mode component , SIM card state component , system integrity component , application environment component ) are multiplied, that is, , which quantifies the comprehensive security level of the device at the current moment, with a value range between 0 and 1, and the closer the value is to 1, the safer the device, and the closer the value is to 0, the higher the risk. For example, in the previous step, according to a device state using a public network (component value 0.6), pattern unlocking (component value 0.5), and the remaining three ideal components (component values are all 1.0), the device security product decay value is calculated to be 0.3, then in this formula calculation, this result is directly called, and is set to 0.3; The acquisition step of (system risk sensitivity coefficient) is that this parameter is a dimensionless coefficient, which is used to control the steepness of the Sigmoid function curve, that is, the sensitivity of the free amount to the change of the device security situation. Its value is determined by the risk control department of the payment service provider based on statistical analysis of a large amount of historical transaction data. The specific setting process is as follows: first, collect records containing the value of each transaction and whether the transaction is finally confirmed as fraud, and build a large-scale data set, then, with as the independent variable and whether the transaction is fraud (yes = 1, no = 0) as the dependent variable, perform logistic regression analysis, and the regression model will fit a coefficient, which directly reflects the degree of influence of security level change on fraud probability. This regression coefficient is used as the basis for setting the value of , and is fine-tuned in combination with business strategy, for example, after analyzing hundreds of millions of transactions in the last quarter, the logistic regression model shows that the coefficient of is 9.87, and the risk team combines the current strategy of moderately improving risk sensitivity to round up the value of and set it to 10, which will be fixed in the risk control strategy configuration of the payment server; The acquisition step of (security state response threshold) is that this parameter defines the boundary of the security level considered acceptable by the system, which corresponds to the input point of the free amount control coefficient 0.5 in the Sigmoid function. Its value is also based on risk strategy and data analysis, aiming to define a critical point between "safe" and "suspicious". The setting process is that risk analysts first define a business-acceptable minimum device security product decay value, which is determined by referring to the historical average fraud loss rate at different levels, for example, analysis shows that when Below 0.25, the fraud loss rate starts to exponentially grow beyond the business tolerance, therefore, the safety threshold is set as the critical point, since the actual value used in the formula as input, the safety status response threshold is calculated as the square root of the critical point, i.e. This threshold means that when a device's value is exactly 0.5, the amount of password-free it gets will be half of the user-set baseline, this setting makes the amount of password-free of devices whose safety status is exactly around the critical point to be significantly but not overly aggressively suppressed; Calculation process: According to the above parameter acquisition steps, now we bring in specific numerical values for calculation, the specific parameters are: Maximum password-free baseline value ; Device safety product decay value ; System risk sensitivity coefficient ; Safety status response threshold ; The calculation process is as follows: First, calculate the value of : ; Second, calculate the power of the exponential part of the Sigmoid function: ; Next, calculate the power value of the exponential term : ; Then, calculate the denominator of the Sigmoid function: ; Calculate the complete amount control coefficient: ; Finally, calculate the comprehensive device safety score : ; The result shows that under the current device safety status, the calculated comprehensive device safety score is 617.1, this value has the same unit as the maximum password-free baseline value (e.g. yuan), it represents a dynamically adjusted password-free upper limit based on the current safety status of the device, this score 617.1 is higher than half of the user-set baseline value 1000 yuan (500 yuan), because the The value (0.5477) is slightly higher than the safe state response threshold (0.5), indicating that the device security state is determined by the system to be slightly better than the "acceptable" boundary level, and therefore a coefficient of more than 50% is given. The comprehensive device security score will be used as the basic quota to enter the subsequent process of combining transaction risk for final quota determination.
[0025] The obtaining step of the cognitive load factor set is: After the payment server receives the payment request, it extracts the transaction amount field, payee account identifier field, commodity category field and transaction time field from the request one by one, and records them to the transaction parameter buffer area according to the preset structure, obtaining the transaction amount field, payee account identifier field, commodity category field and transaction time field; According to the transaction amount field, payee account identifier field, commodity category field and transaction time field, the mean, frequency and time distribution indexes of the corresponding fields of the user in the transaction history database are called respectively, and the methods of deviation value extraction, frequency statistics and window difference calculation are used to calculate the amount deviation factor, payee strangeness factor, category rarity factor and time sensitivity factor, obtaining the cognitive load factor set.
[0026] Specifically, after receiving the payment request, the request arrives at the application gateway of the server in the form of an encrypted HTTPS message. The gateway first verifies the digital signature of the message using a pre-set asymmetric key to confirm the legitimacy of the request source. After verification, the server decrypts the payload of the request using a session key and parses it from the original byte stream into a structured data object following a predefined JSON format. This data object contains the user identification, device information, encrypted payment credentials, and detailed parameters of the transaction. The core business logic layer of the server then iterates through the JSON object to accurately extract four key pieces of transaction information by accessing specific key names. Specifically, it reads the field with the key name "amount" to obtain the transaction amount, reads the field with the key name "payeeId" to obtain the unique identifier of the payee's account, reads the field with the key name "categoryCode" to obtain the standard classification code of the corresponding goods or services, and reads the field with the key name "timestamp" to obtain the transaction initiation timestamp generated by the payment terminal, which conforms to the ISO 8601 standard. The four pieces of extracted data, namely the transaction amount, the payee account identifier, the product category, and the transaction time, are immediately written to a memory cache area associated with the unique ID of the current transaction request. This cache area is a high-efficiency key-value storage structure, such as Redis or an in-process hash table, whose pre-set structure ensures that the subsequent risk calculation engine can access these parameters with extremely low latency. Finally, the transaction amount field, the payee account identifier field, the product category field, and the transaction time field are obtained, which can be used for real-time analysis.
[0027] Based on the transaction amount field, payee account identification field, commodity category field, and transaction time field obtained from the transaction parameter buffer in the previous step, the system starts four independent calculation tasks in parallel to generate four cognitive load factors. First, for the calculation of the amount deviation factor, the system uses the user's unique identification as an index to initiate a query to the transaction history database, retrieve all successful transaction records of the user in the past 90 days, and calculate the average and standard deviation of these transaction amounts. Then, by calculating the absolute value of the difference between the current transaction amount and the historical average, the difference is divided by the historical standard. The difference is obtained by taking a dimensionless deviation multiple as the amount deviation factor. For example, if the user's historical average consumption is 80 yuan, the standard deviation is 50 yuan, and the current transaction is 300 yuan, then the amount deviation factor is the absolute value of (300-80) divided by 50, which is 4.4. Secondly, for the calculation of the payee's unfamiliarity factor, the system uses the current payee's account identification field to query the user's transaction counterparty list in the past year and count the total number of times the payee appears. The payee's unfamiliarity factor is defined as the reciprocal of the number of appearances plus one. If the payee appears for the first time, the number of appearances is 0, the factor value is 1. If there have been 19 transactions, the factor value is 1 divided by (19+1), which is 0.05. Again, for the calculation of the category rarity factor, the system analyzes the distribution frequency of all commodity categories in the user's transaction records in the past year, and calculates the percentage of the current commodity category. The category rarity factor is set to the inverse of the percentage plus a smoothing term of 0.01. If a category's transaction accounted for 2%, its rarity factor is 1 divided by 0.02, which is 50. Finally, for the calculation of the time sensitivity factor, the system first calculates the user's historical transaction timestamps. Group and count by hour to identify the two most active time periods of users, such as 9:00 a.m. to 11:00 a.m. and 7:00 p.m. to 9:00 p.m., and then calculate the time difference between the current transaction time and the nearest boundary of these two active time periods in hours. If the current transaction is at 3:00 a.m. and the distance to the nearest boundary (9:00 p.m. or 9:00 a.m.) is 6 hours, then the time sensitivity factor is 6. Through the above four independent calculation processes, the system will eventually combine the amount deviation factor, recipient unfamiliarity factor, category rarity factor and time sensitivity factor to obtain a set of cognitive load factors.
[0028] The steps to obtain the transaction cognitive load score are: Based on the cognitive load factor set, the transaction cognitive load score is calculated using the following formula: ; in, is the transaction cognitive load score, is the normalized amount deviation factor, which represents the standard deviation multiple of the transaction amount compared to the historical average. is a normalized receiver strangeness factor, representing the proportion of receiver accounts that do not appear in the historical records, is a normalized category rarity factor, representing the reciprocal offset value of the proportion of the category in the historical transactions, is a normalized time sensitivity factor, representing the degree of deviation of the transaction time from the user's common active time period, are the base coefficients corresponding to the four normalized factors respectively, is the interaction coefficient of the amount and the receiver strangeness factor, is the collaborative risk term between the amount and the receiver.
[0029] Specifically, the formula is: The formula has the advantage that it builds a multi-dimensional, non-linear transaction risk assessment model that can more accurately characterize fraudulent transactions than a simple linear weighted sum. The core innovation of this formula is the introduction of the interaction coefficient and the collaborative risk term The collaborative risk term is specifically used to capture the exponential growth of the compound risk when both "large transaction" and "strange receiver" high-risk factors appear at the same time, which is a typical pattern of malicious behavior such as fraud and fraud. A simple linear model cannot effectively express the synergistic amplification effect of this risk. By taking the geometric mean of the normalized values of the two factors, this term not only reflects the correlation between the two, but also makes the growth rate of the square root form between linear and square, which can effectively amplify the risk signal while avoiding the excessive domination of extreme values on the total score. In addition, all factors in the formula are normalized to eliminate the differences in dimensions and numerical ranges of different risk dimensions, making the distribution of weight coefficients more interpretable and fair. Finally, through weighted summation, the risk from user transaction behavior habits other than device security is quantified into a single, intuitive transaction cognitive load score. The acquisition step of the normalized amount deviation factor is that this parameter represents the degree of deviation of the current transaction amount from the user's normal consumption habits. First, the original amount deviation factor calculated in the previous step is obtained, which is the standard deviation multiple of the difference between the transaction amount and the historical mean. Since there is no upper limit in theory, it needs to be normalized to map to the [0, 1] interval. The normalization uses a linear scaling method with a threshold cut-off, and the specific calculation formula is: wherein is the preset upper limit threshold of the amount deviation, which is set based on statistical analysis of historical fraud cases on the entire platform. Analysis shows that when the amount deviation exceeds 8 standard deviations, the growth of fraud probability tends to flatten out, but the risk is already extremely high, so is set to 8, which prevents extreme large transaction from causing disproportionate impact on the risk score. For example, if the amount deviation factor of the user is calculated in the previous step is 4.4, its normalized value is The acquisition step of the normalized receiver strangeness factor is that this parameter quantifies the strangeness of the current transaction counterparty to the user, and its original factor is The value range of the receiver frequency plus one reciprocal is naturally in the interval (0, 1], the larger the value, the more strange, which already has good comparability, so its normalization process is an identity mapping, and no additional transformation is needed, that is This direct use method retains the nonlinear relationship embodied in the original factor based on the reciprocal of the transaction frequency, that is, the strangeness from 0 times to 1 time decreases most significantly, which conforms to the user's cognitive process from complete strangeness to familiarity, for example, if the current receiver is a first-time transaction, its frequency is 0, and the original factor is , then the value of the normalized receiver strangeness factor is 1.0; The acquisition step of the normalized category rarity factor is that this parameter measures whether the goods or services purchased by the user belong to its regular consumption category, and the original category rarity factor is The value range of the category history proportion reciprocal is large, which needs to be normalized, and the normalization method also uses linear scaling with threshold truncation, and the calculation formula is: The logarithmic transformation is used here because the distribution of category frequency often has long-tail characteristics, and directly using the reciprocal will cause the factor value of the extremely low frequency category to be too large, and the logarithmic transformation can effectively compress the data range while preserving its size relationship. The upper threshold is set to 500 according to the analysis of the distribution of all user category rarity, which covers most cases, for example, if the historical proportion of a user purchasing a certain category is 0.5%, the original factor is ; The acquisition step of the normalized time sensitivity factor is that this parameter reflects whether the transaction time is in the user's non-active period, and the original factor is the hour difference between the current time and the boundary of the latest active period, the larger the value, the higher the risk, and the normalization formula is: , and the upper threshold Set to 12 hours, because in a 24-hour cycle, the maximum difference between any time point and a certain time period does not exceed 12 hours, this setting enables it to linearly reflect the degree of deviation, for example, if the previous step calculates the time sensitivity factor is 6 hours, then the normalized value is ; The acquisition step of the base coefficient and the interaction coefficient is that these weight coefficients are not manually set, but are obtained by training a logistic regression model on a large amount of historical transaction data containing "fraud" and "normal" labels. The input features of the model are the aforementioned five parts: and the synergistic risk term The optimization goal of the model is to maximize the log-likelihood function, and the regression coefficients of each input feature solved by the gradient descent algorithm are used as the weights here. The size of these coefficients directly reflects the contribution of the corresponding factor to the judgment of whether the transaction is fraudulent. For example, after training on 1 billion transactions in the past 6 months, the standardized regression coefficients are: ; Calculation process: According to the above parameter acquisition step, the specific numerical values are calculated as follows: Normalized amount deviation factor ; Normalized payee strangeness factor ; Normalized category rarity factor ; Normalized time sensitivity factor ; Base coefficient ; Interaction coefficient ; The calculation process is as follows: First, calculate the value of the synergistic risk term: ; Next, calculate the value of each weighted term: ; ; ; ; ; Finally, add all the terms to get the transaction cognitive load score : The result shows that the transaction cognitive load score of this transaction is 0.8768, which is a dimensionless value between 0 and 1.15 (the sum of all weights), which comprehensively evaluates the degree of deviation of the transaction from the user's historical behavior pattern in the four dimensions of amount, payee, category and time, and especially considers the synergistic effect of amount and payee abnormality. The higher the score, the greater the degree of abnormality of the transaction, and the higher the potential risk. A score close to 0.9 is usually considered a high-risk signal because it deviates significantly from the "normal" transaction space learned by the model. The score will be directly used for comparison with the preset threshold in the next step to determine the final risk level of the transaction.
[0030] The acquisition step of the transaction risk level determination result is: Based on the transaction cognitive load score, the transaction cognitive load score is compared with the system preset cognitive load threshold value by value. If the transaction cognitive load score is greater than or equal to the cognitive load threshold value, it is determined that the transaction is in a high-risk state, otherwise it is determined to be in an acceptable state, and a transaction risk level determination result is generated.
[0031] Specifically, based on the transaction cognitive load score calculated in the previous process, the system compares this score with a dynamically adjusted cognitive load threshold, which is not a fixed value but is determined through continuous analysis of historical transaction data on the platform. The specific method is as follows: the risk analysis team first extracts all transaction records from the data warehouse in the past three months, each record is attached with its calculated transaction cognitive load score and a clear label (i.e. "fraud" or "normal", this label comes from the user's complaint, case investigation or automated fraud detection system after the event), using this large labeled data set, the system constructs a receiver operating characteristic curve (ROC), by moving the decision threshold from 0 to the highest score point by point, calculate the true positive rate (the proportion of fraud transactions identified) and false positive rate (the proportion of normal transactions misjudged as fraud) at each threshold point, according to business goals, for example, maximize the true positive rate while controlling the false positive rate below 0.1%, the risk strategy department selects the best threshold point from the ROC curve, for example, after analysis, it is found that when the threshold is set to 0.75, 85% of fraud transactions can be captured, while only 0.08% of normal transactions are incorrectly intercepted, this balance point is considered the optimal choice in the current business cycle, therefore, the system presets the cognitive load threshold to 0.75, this threshold will be automatically recalculated and updated every week, after obtaining the threshold, the system performs a simple floating point size comparison, for example, if the transaction cognitive load score calculated in the previous step is 0.8768, the system determines that 0.8768 is greater than or equal to 0.75, therefore, the risk level of this transaction is determined as "high risk state", otherwise, if the calculated score is 0.6, it is determined that it is less than 0.75, the risk level is "acceptable state", finally, this binary determination result is packaged into a data structure containing a state code and a description text, generating the transaction risk level determination result.
[0032] The steps for obtaining the dynamic password-free payment limit are as follows: According to the transaction risk level determination result, select the limit suppression coefficient matched with the determination result from the limit suppression coefficient preset mapping table, and call the comprehensive device security score as the basic limit value, calculate the limit suppression coefficient and the basic limit value, generate the initial calculation result of the dynamic password-free limit; Based on the initial calculation result of the dynamic password-free limit, perform unit conversion, numerical precision interception and field identification addition processing, add transaction request number and user unique identification fields, generate dynamic password-free payment limit.
[0033] Specifically, according to the transaction risk level determination result generated in the previous step, the system immediately queries the corresponding suppression coefficient from a globally configured "quota suppression coefficient preset mapping table" loaded in memory, which is a simple key-value pair set, the content of which is defined by the risk management strategy team and solidified in the configuration file of the payment server, and the table is constructed according to the risk mitigation measures to be taken under different risk levels. The specific mapping relationship is that when the transaction risk level determination result is "acceptable state", the system considers that the current transaction conforms to the user's regular behavior pattern, and the risk is within the controllable range, so the corresponding quota suppression coefficient is set to 1.0, indicating that no quota suppression is performed, and the quota based on device security assessment is completely adopted; when the transaction risk level determination result is "high risk state", the system considers that the transaction has significant fraud possibility and needs to take the strongest intervention measures, at this time the corresponding quota suppression coefficient is set to 0.0, the purpose of this is to directly reduce the dynamic password-free quota to zero, thereby forcing the user to perform strong identity verification such as password, fingerprint or facial recognition to complete the payment. After querying the matching quota suppression coefficient, the system concurrently retrieves the comprehensive device security score calculated in the previous step from the current transaction session context, which is a monetary value representing the available quota based on the device environment, for example, 617.1 yuan. Subsequently, the system performs a multiplication operation to multiply the comprehensive device security score with the queried quota suppression coefficient, for example, if the determination result is "high risk state", the calculation process is 617.1 multiplied by 0.0, and the result is 0.0; if the determination result is "acceptable state", the calculation process is 617.1 multiplied by 1.0, and the result is 617.1. The final numerical result of this multiplication operation is the initial calculation result of the dynamic password-free quota.
[0034] Based on the initial calculation result of the dynamic password-free limit generated in the previous step, the system will perform a series of standardization and packaging processes on this original floating point number. First, unit conversion and numerical precision truncation. The core account module of the payment system uniformly adopts the smallest monetary unit for processing. For example, for the RMB, the smallest unit is "fen". Therefore, the system will multiply the initial calculation result in "yuan" by 100 and perform an integer operation. For example, if the initial calculation result is 617.1 yuan, the converted result is 61710 fen. If the initial calculation result is 0.0 yuan, the converted result is still 0 fen. Next, in order to comply with the financial message specification, the system will format this integer value to a specific precision. For example, for scenarios that require display in yuan, the system will divide it by 100 and truncate it to two decimal places, resulting in 617.10 or 0.00. Subsequently, field identification is added. The system creates a new data object, stores the processed value as the core field, and adds multiple necessary context identification fields. These fields are directly read from the current transaction session cache, including a transaction request number that uniquely identifies this payment request, such as a 32-bit string generated by a timestamp and a random number, and a user unique identification field that identifies the payment initiator, such as the user's internal ID or encrypted mobile phone number. This process integrates the dispersed calculation result and transaction context information into a unified, self-contained data structure, such as a JSON object {"dynamic_limit_in_cents": 0, "formatted_limit": "0.00", "currency": "CNY", "transaction_id": "...", "user_id":"..."}. This complete data structure containing the final limit, currency unit, transaction, and user identification is the final generated dynamic password-free payment limit.
[0035] The above is only a preferred embodiment of the present application, and does not limit the application in other forms. Any skilled person in the art can modify or change the above disclosed technical content to equivalent embodiments applied to other fields, but any simple modification, equivalent change and modification made according to the technical essence of the present application to the above embodiments without departing from the technical solution content of the present application still falls within the protection scope of the present application.
Claims
1. A method for dynamically adjusting the password-free limit of mobile payment, characterized in that: The following steps are involved: When initiating a payment request, the payment terminal collects the discrete states of the network environment, device unlocking method, SIM card status, system integrity, and application environment in real time to establish a device security state vector; Based on the payment protocol, the device security state vector is called to generate a device security product decay value, and the maximum password-free limit benchmark value set by the user is calculated with the device security product decay value to obtain a comprehensive device security score; After receiving the payment request, the payment server extracts the transaction amount, payee account information, product category information, and transaction time information, establishes a cognitive load factor set, and calculates the transaction cognitive load score based on each factor in the cognitive load factor set; Comparing the transaction cognitive load score with a set cognitive load threshold to establish a transaction risk level determination result, using the comprehensive device security score as a base limit, and invoking the transaction risk level determination result to generate a dynamic password-free payment limit; The steps for obtaining the device security state vector are: After receiving the payment request signal from the user, the payment terminal extracts the device's current network connection type, screen unlock method, whether the SIM card is inserted and the carrier it belongs to, whether the system has been tampered with, and the container environment properties of the running application, generating five discrete states: network connection type, screen unlock method, SIM card status identifier, system verification status, and container environment properties. According to the five discrete states of the network connection type, screen unlocking method, SIM card status identifier, system verification status and container environment attributes, each discrete state is mapped one by one according to the security level value, and the mapping results are assigned values of network environment component, device unlocking method component, SIM card status component, system integrity component and application environment component in sequence; Based on the network environment component, device unlocking method component, SIM card status component, system integrity component and application environment component, they are arranged in a unified order to form a column vector, and each component is organized and stored according to a vector structure to generate a device security status vector.
2. The method for dynamically adjusting the mobile payment password-free limit according to claim 1, characterized in that: The steps for obtaining the equipment safety product attenuation value are as follows: Based on the device security status vector, the network environment component, the device unlocking method component, the SIM card status component, the system integrity component and the application environment component are sequentially extracted to calculate and generate a device security product attenuation value.
3. The method for dynamically adjusting the mobile payment password-free limit according to claim 1, characterized in that: The steps for obtaining the comprehensive device safety score are as follows: The comprehensive device security score is calculated based on the device security product attenuation value and the maximum password-free quota benchmark value.
4. The method for dynamically adjusting the mobile payment password-free limit according to claim 1, characterized in that: The steps for obtaining the cognitive load factor set are: After receiving the payment request, the payment server extracts the transaction amount field, the payee account identification field, the product category field, and the transaction time field from the request item by item, and records them in the transaction parameter buffer according to the preset structure, thereby obtaining the transaction amount field, the payee account identification field, the product category field, and the transaction time field; According to the transaction amount field, payee account identification field, product category field and transaction time field, the mean, frequency and time distribution indicators of the corresponding fields of the user in the transaction history database are called respectively, and the deviation value extraction, frequency statistics and window difference calculation methods are used to calculate the amount deviation factor, payee unfamiliarity factor, category rarity factor and time sensitivity factor to obtain a set of cognitive load factors.
5. The method for dynamically adjusting the mobile payment password-free limit according to claim 1, characterized in that: The steps for obtaining the transaction cognitive load score are as follows: A transaction cognitive load score is calculated based on the cognitive load factor set.
6. The method for dynamically adjusting the mobile payment password-free limit according to claim 1, characterized in that: The steps for obtaining the transaction risk level determination result are: Based on the transaction cognitive load score, the transaction cognitive load score is compared with a cognitive load threshold preset by the system. If the transaction cognitive load score is greater than or equal to the cognitive load threshold, the transaction is determined to be in a high-risk state; otherwise, it is determined to be in an acceptable state, and a transaction risk level determination result is generated.
7. The method for dynamically adjusting the mobile payment password-free limit according to claim 1, characterized in that: The steps for obtaining the dynamic password-free payment limit are: Based on the transaction risk level determination result, a quota suppression coefficient that matches the determination result is selected from a preset quota suppression coefficient mapping table, and the comprehensive device security score is retrieved as a basic quota value. The quota suppression coefficient and the basic quota value are calculated to generate an initial calculation result of the dynamic password-free quota; Based on the initial calculation result of the dynamic password-free limit, unit conversion, numerical precision truncation and field identification additional processing are performed, and the transaction request number and user unique identification field are added to generate a dynamic password-free payment limit.
Citation Information
Patent Citations
Payment device, terminal and payment method
CN106327197A
Payment method and device
CN107844977A
Digital currency off-line payment method, mobile phone and off-line payment system
CN113393222A
Micro-password-free payment method and device
CN114169877A
Small-amount password-free limit control method and device
CN114445065A
Cited By
Security access and credibility authentication system for electricity utilization information acquisition terminal
CN121711167A