Resource transfer request processing method and device, electronic equipment and storage medium
By dynamically adapting the authentication method for resource transfer requests and selecting the appropriate authentication method based on the risk level, the security vulnerabilities and inefficiencies caused by fixed authentication methods in existing technologies are resolved, achieving a balance between security and efficiency.
Patent Information
- Application Number
- CN202511055767.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-30
- Publication Date
- 2025-11-11
AI Technical Summary
The fixed authentication method for resource transfer requests in existing technologies leads to frequent security vulnerabilities in high-risk scenarios and low efficiency in low-risk scenarios, making it impossible to balance security and efficiency.
By determining the risk level of the resource transfer request, the corresponding authentication method is dynamically adapted, including manual authentication, static password authentication, SMS verification, dynamic password authentication, and facial recognition authentication, and the appropriate authentication method is selected for authentication based on the risk level.
It enables dynamic adjustment of authentication methods under different risk levels, improving the security and efficiency of resource transfer requests and maximizing user experience.
Smart Images

Figure CN120930145A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a resource transfer request processing method, apparatus, electronic device and storage medium. Background Technology
[0002] In today's booming digital transactions, resource transfer operations are becoming increasingly frequent, making the security of resource transfers crucial. Related technologies often employ fixed authentication methods for resource transfer requests. This leads to security vulnerabilities in high-risk resource transfer scenarios due to insufficient authentication strength, resulting in user resource loss; conversely, in low-risk scenarios, excessive authentication wastes user time and effort, impacting resource transfer efficiency and user experience. Therefore, this paper proposes a resource transfer request processing method that dynamically adapts authentication to different risk levels, balancing security and efficiency to improve the security of resource transfer requests. Summary of the Invention
[0003] This invention provides a resource transfer request processing method, apparatus, electronic device, and storage medium to achieve dynamic adaptation to authentication in scenarios with different risk levels, balancing security and efficiency, thereby improving the security of resource transfer requests.
[0004] According to one aspect of the present invention, a resource transfer request processing method is provided, the method comprising:
[0005] In response to a first resource transfer request initiated by the target object, determine the resource transfer risk level corresponding to the first resource transfer request;
[0006] Based on the correspondence between resource transfer risk levels and preset authentication methods, determine the target authentication method corresponding to the resource transfer risk level;
[0007] The target object's object information is authenticated using the target authentication method. If authentication is successful, the first resource transfer request is processed. According to another aspect of the present invention, a resource transfer request processing apparatus is provided. The apparatus includes:
[0008] The risk level determination module is used to determine the resource transfer risk level corresponding to the first resource transfer request in response to the first resource transfer request initiated by the target object.
[0009] The authentication method determination module is used to determine the target authentication method corresponding to the resource transfer risk level based on the correspondence between the resource transfer risk level and the preset authentication method;
[0010] The request processing model is used to authenticate the object information of the target object through the target authentication method, and to process the first resource transfer request if the authentication is successful.
[0011] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0012] One or more processors;
[0013] Storage device for storing one or more programs.
[0014] When the one or more programs are executed by the one or more processors, the one or more processors implement the resource transfer request processing method as described in any of the embodiments of this disclosure.
[0015] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement any of the resource transfer request processing methods of the present invention.
[0016] The technical solution of this invention determines the resource transfer risk level corresponding to the first resource transfer request in response to the first resource transfer request initiated by the target object. Therefore, based on the correspondence between the resource transfer risk level and the preset authentication method, a target authentication method corresponding to the resource transfer risk level can be determined. By setting corresponding authentication methods for different risk levels, adaptive adjustment is achieved, maximizing user experience while ensuring the security of resource transfer request processing. The target authentication method is used to authenticate the object information of the target object. If authentication is successful, the first resource transfer request is processed, effectively ensuring the security of the resource transfer request. The technical solution of this invention solves the technical problem in related technologies where fixed authentication methods are often used for resource transfer requests, resulting in poor authentication flexibility. It achieves dynamic adaptation to authentication scenarios with different risk levels, balancing security and efficiency, thereby improving the security of resource transfer requests.
[0017] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 A flowchart illustrating a resource transfer request processing method provided in an embodiment of the present invention;
[0020] Figure 2 A flowchart illustrating a resource transfer request processing method provided in an embodiment of the present invention;
[0021] Figure 3 This is an example diagram of a decision tree authentication method applicable to resource transfer request processing provided in an embodiment of the present invention;
[0022] Figure 4 This is a schematic diagram of the structure of a resource transfer request processing device provided in an embodiment of the present invention;
[0023] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0024] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0025] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0026] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.
[0027] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this disclosed technical solution, based on the prompt message.
[0028] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0029] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.
[0030] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.
[0031] Figure 1 This is a flowchart illustrating a resource transfer request processing method provided in an embodiment of the present invention. This embodiment is applicable to situations involving the processing of resource transfer requests. The method can be executed by a resource transfer request processing device, which can be implemented in hardware and / or software and can be configured in electronic devices such as computers or servers. Figure 1 As shown, the method in this embodiment includes:
[0032] S110. In response to the first resource transfer request initiated by the target object, determine the resource transfer risk level corresponding to the first resource transfer request.
[0033] The target object can be understood as the object that initiates the resource transfer request at the current moment. The first resource transfer request can be understood as the target object initiating a resource transfer request at the current moment. In this embodiment of the invention, the first resource transfer request may include resource transfer data. The resource transfer data may include at least the request time, the information of the receiving resource object, and the amount of resources to be transferred. The resource transfer risk level can be understood as the risk level of the resource transfer.
[0034] Specifically, in response to a first resource transfer request initiated by the target object, the first resource transfer request is analyzed to obtain resource transfer data within the first resource transfer request. Based on this resource transfer data, the resource transfer risk level corresponding to the resource transfer request can be determined. In this embodiment of the invention, determining the resource transfer risk level corresponding to the resource transfer request based on the resource transfer data may include: extracting features from the resource transfer data to obtain resource transfer features, and then determining the resource transfer risk level corresponding to the resource transfer request based on these features.
[0035] In this embodiment of the invention, the number of resource transfer features can be multiple; determining the resource transfer risk level corresponding to the resource transfer request based on the resource transfer features can include: determining whether a preset risk feature exists among the resource transfer features; if so, determining the resource transfer risk level corresponding to the resource transfer request based on the risk level corresponding to the preset risk feature. It can be understood that when there is only one resource transfer feature, it can be determined whether the resource transfer feature is a preset risk feature; if so, the risk level corresponding to the preset risk feature can be determined as the resource transfer risk level corresponding to the resource transfer request.
[0036] Optionally, determining the resource transfer risk level corresponding to the resource transfer request based on the risk level corresponding to a preset risk feature specifically includes: when there are multiple preset risk features, determining a target risk feature among them; wherein the target risk feature corresponds to the highest risk level; and using the risk level corresponding to the target risk feature as the resource transfer risk level corresponding to the resource transfer request; when there is only one preset risk feature, determining the risk level corresponding to the preset risk feature as the resource transfer risk level corresponding to the resource transfer request. It is understood that if it is determined that no preset risk feature exists among the resource transfer features, the resource transfer risk level corresponding to the resource transfer request can be determined as the lowest risk level.
[0037] S120. Based on the correspondence between the resource transfer risk level and the preset authentication method, determine the target authentication method corresponding to the resource transfer risk level.
[0038] In this embodiment of the invention, different authentication methods are set for different resource transfer risk levels. The advantage is that security requirements can be accurately matched. For example, in low-risk scenarios, the task process is simplified, which can ensure basic security while avoiding cumbersome user operations and significantly improve business efficiency; in high-risk scenarios, protection is strengthened, which can effectively block risks. This differentiated authentication method for different resource transfer risk levels can adaptively adjust the authentication method according to the resource transfer risk level, which can maximize user experience while ensuring the security of resource transfer request processing.
[0039] In this embodiment of the invention, the preset authentication method includes at least one of manual authentication, static password authentication, SMS verification authentication, dynamic password authentication, and facial recognition authentication. Different resource transfer risk levels correspond to different preset authentication methods, i.e., different combinations of authentication methods. It should be noted that the number of authentication methods in different combinations can be the same or different. The target authentication method can be understood as the preset authentication method adapted to the resource transfer risk level corresponding to the resource transfer request. Specifically, a correspondence between resource transfer risk levels and preset authentication methods is preset. Thus, based on the correspondence between resource transfer risk levels and preset authentication methods, the preset authentication method corresponding to the resource transfer risk level, i.e., the target authentication method, can be determined.
[0040] In this embodiment of the invention, the resource transfer risk levels, from highest to lowest, include a first risk level, a second risk level, a third risk level, a fourth risk level, and a fifth risk level. The preset authentication methods corresponding to the first risk level may include manual authentication. The preset authentication methods corresponding to the second risk level may include static password authentication, SMS verification authentication, dynamic password authentication, and facial recognition authentication. The preset authentication methods corresponding to the third risk level include static password authentication and SMS verification authentication. The preset authentication methods corresponding to the fourth risk level include SMS verification authentication and dynamic password authentication. The preset authentication method corresponding to the fifth risk level includes static password authentication.
[0041] Based on this, when the resource transfer risk corresponding to the resource transfer request is at the first risk level, the target authentication method corresponding to that risk level can be determined to be manual authentication. When the resource transfer risk corresponding to the resource transfer request is at the second risk level, the target authentication methods corresponding to that risk level can be determined to include static password authentication, SMS verification authentication, dynamic password authentication, and facial recognition authentication. When the resource transfer risk corresponding to the resource transfer request is at the third risk level, the target authentication methods corresponding to that risk level can be determined to include static password authentication and SMS verification authentication. When the resource transfer risk corresponding to the resource transfer request is at the fourth risk level, the target authentication methods corresponding to that risk level can be determined to include SMS verification authentication and dynamic password authentication. When the resource transfer risk corresponding to the resource transfer request is at the fifth risk level, the target authentication method corresponding to that risk level can be determined to be static password authentication.
[0042] S130. The object information of the target object is authenticated through the target authentication method. If the authentication is successful, the first resource transfer request is processed.
[0043] In this embodiment of the invention, the object information of the target object can be understood as digital information submitted by the target object when making a resource transfer request, used to prove its identity and operating permissions. Optionally, the object information of the target object may include identity identification information and / or behavioral verification information. The identity identification information may be the target object's object identifier, account information, or device fingerprint. The behavioral verification information may be a static password, verification code, or biometrics.
[0044] Specifically, the object information of the target object is authenticated using the aforementioned target authentication method. If authentication is successful, the first resource transfer request can be processed. It is understood that if authentication fails, processing of the first resource transfer request can be stopped to reject the resource transfer or freeze the target object's account.
[0045] In this embodiment of the invention, authenticating the object information of the target object through the target authentication method may include: determining the authentication interface or authentication service corresponding to the target authentication method; and then, by calling the authentication interface or authentication service corresponding to the target authentication method, displaying an authentication interface or prompt information matching the target task method, so as to receive the authentication information of the target object (e.g., static password, verification code, or biometric features) and perform verification.
[0046] The technical solution of this invention determines the resource transfer risk level corresponding to the first resource transfer request in response to the first resource transfer request initiated by the target object. Therefore, based on the correspondence between the resource transfer risk level and the preset authentication method, a target authentication method corresponding to the resource transfer risk level can be determined. By setting corresponding authentication methods for different risk levels, adaptive adjustment is achieved, maximizing user experience while ensuring the security of resource transfer request processing. The target authentication method is used to authenticate the object information of the target object. If authentication is successful, the first resource transfer request is processed, effectively ensuring the security of the resource transfer request. The technical solution of this invention solves the technical problem in related technologies where fixed authentication methods are often used for resource transfer requests, resulting in poor authentication flexibility. It achieves dynamic adaptation to authentication scenarios with different risk levels, balancing security and efficiency, thereby improving the security of resource transfer requests.
[0047] Figure 2 This is a flowchart illustrating a resource transfer request processing method provided by an embodiment of the present invention. Optionally, based on the foregoing embodiments, determining the resource transfer risk level corresponding to the first resource transfer request includes: determining a first resource transfer request feature corresponding to the first resource transfer request; inputting the first resource transfer request feature into a pre-trained decision tree model to obtain a feature risk level corresponding to the first resource transfer request feature, which is then used as the resource transfer risk level corresponding to the resource transfer request. Technical features that are the same as or similar to those in the above embodiments will not be repeated here.
[0048] like Figure 2 As shown, the method in this embodiment specifically includes:
[0049] S210. In response to the first resource transfer request initiated by the target object, determine the first resource transfer request feature corresponding to the first resource transfer request.
[0050] The first resource transfer request feature can be understood as the resource transfer request feature corresponding to the first resource transfer request. In this embodiment of the invention, the first resource transfer request feature may include basic resource transfer features, resource transfer association features, resource transfer environment features, resource transfer security features, transferred resource features, and resource transfer behavior features of the resource transfer initiating object.
[0051] The basic characteristics of resource transfer can include resource transfer time characteristics (e.g., time period or frequency), resource transfer method, resource transfer geographical location, and transferred resource quantity characteristics. In this embodiment of the invention, the basic characteristics of resource transfer can be used to identify whether a resource transfer request is at an abnormal time. Resource transfer association characteristics can include the risk rating of the resource recipient, the blacklist status of associated accounts, and the complexity of the resource link. Through the analysis of resource transfer association characteristics, stronger auditing can be implemented for accounts involving high-risk areas or multi-layered nested transfers. Resource transfer environment characteristics can include network environment (VPN / proxy detection) and biometric authentication environment lighting / background noise characteristics. By using resource transfer environment characteristics, it is possible to identify whether the resource transfer environment is abnormal, in order to determine whether there is an abnormal network environment, abnormal biometric authentication environment parameters, or artificial intelligence spoofing attacks, etc.
[0052] The resource transfer security features can include the number of times a preset security rule is triggered, preset security warning signals (such as the splitting of large resources), and verification results conforming to security regulations. The resource transfer features can include the resource transfer limits, average amount, maximum amount, and minimum amount of the resource transfer object within a preset time period. In this embodiment of the invention, the resource transfer features can be used to determine whether a large number of resource transfers pose a risk of account theft. The resource transfer behavior features of the resource transfer initiator can include the characteristics of the resource transfer operation device, historical risk records, and account activity. This feature can be used to identify abnormal operation speeds to determine whether the account has been compromised.
[0053] In this embodiment of the invention, in response to a first resource transfer request initiated by a target object, determining the first resource transfer request characteristics corresponding to the first resource transfer request may specifically include: in response to a first resource transfer request initiated by a target object, analyzing the first resource transfer request to obtain basic resource transfer characteristics, resource transfer association characteristics, resource transfer environment characteristics, resource transfer security characteristics, transferred resource characteristics, and resource transfer behavior characteristics of the resource transfer initiating object.
[0054] S220. Input the first resource transfer request feature into the pre-trained decision tree model to obtain the feature risk level corresponding to the first resource transfer request feature, which is used as the resource transfer risk level corresponding to the first resource transfer request.
[0055] The decision tree model can be used to determine the resource transfer risk level corresponding to the first resource transfer request based on its first resource transfer request characteristics. The feature risk level can be understood as the risk level of the first resource transfer request characteristics.
[0056] Specifically, a decision tree model is pre-trained, resulting in a fully trained decision tree model. The first resource transfer request feature can then be input into the pre-trained decision tree model to obtain its output, which is the feature risk level corresponding to the first resource transfer request feature. This feature risk level can then be used as the resource transfer risk level corresponding to the first resource transfer request.
[0057] In this embodiment of the invention, the method of obtaining the decision tree model may specifically include: determining a feature dataset, wherein the feature dataset includes multiple second resource transfer request features, wherein the second resource transfer request features are obtained based on resource transfer requests initiated by resource transfer initiating objects at historical moments; calculating the information gain of all second resource transfer request features based on a preset information gain calculation method, selecting the second resource transfer request feature with the largest information gain as the partitioning basis of the root node, and dividing the feature dataset into at least two subsets according to the selected feature; for each subset, repeatedly executing the step of calculating the information gain of all second resource transfer request features based on the preset information gain calculation method, selecting the second resource transfer request feature with the largest information gain in each subset to continue partitioning, generating child nodes, and continuously recursively, until a preset stopping condition is reached, so as to construct a decision tree model including a decision tree.
[0058] The feature dataset can be understood as a dataset including multiple second resource transfer request features. In this embodiment of the invention, the multiple second resource transfer request features can originate from the same resource transfer request or from different resource transfer requests. When the multiple second resource transfer request features originate from different resource transfer requests, the different resource transfer requests can be collected in real-time or in batches from the same data source; or they can be collected in real-time or in batches from different data sources. Multi-source data collection can involve obtaining resource transfer requests from databases, interfaces, and web pages. Real-time or batch collection can adapt to different scenario requirements.
[0059] In this embodiment of the invention, when resource transfer requests originate from different data sources, the request information of the resource transfer requests can be integrated. Specifically, this includes data fusion processing and data transformation processing. Data fusion processing integrates data from different data sources to form a unified data view. Data transformation converts the data into a unified format and structure for easier subsequent processing. In this embodiment of the invention, after obtaining the integrated request information, the integrated request information can be stored. Specifically, this can include temporary storage and persistent storage. Temporary storage temporarily stores the cleaned and integrated data for use by subsequent modules. Persistent storage stores the data in a database or data warehouse for long-term use and analysis.
[0060] In this embodiment of the invention, the second resource transfer request feature can be understood as the feature of a resource transfer request initiated by a resource transfer initiating object at a historical time. It is understood that the second resource transfer request feature may include basic resource transfer features, resource transfer association features, resource transfer environment features, resource transfer security features, transferred resource features, and resource transfer behavior features of the resource transfer initiating object. In this embodiment of the invention, the second resource transfer request feature can be obtained based on a resource transfer request initiated by a resource transfer initiating object at a historical time. Specifically, the second resource transfer request feature can be obtained by feature extraction of the request information and / or request content of the resource transfer request initiated by the resource transfer initiating object at a historical time.
[0061] In this embodiment of the invention, the feature dataset is obtained by acquiring request information of resource transfer requests initiated by multiple resource transfer initiating objects at multiple historical moments. Based on each request information, the characteristics of the resource transfer requests initiated by the multiple resource transfer initiating objects at different historical moments are determined, thus obtaining multiple second resource transfer request features. Therefore, a dataset containing multiple second resource transfer request features can be obtained, i.e., the feature dataset is obtained.
[0062] In this embodiment of the invention, before calculating the information gain of all the second resource transfer request features based on a preset information gain calculation method, the method further includes: performing data preprocessing on the request information of resource transfer requests initiated by the resource transfer initiating object at historical times. The data preprocessing includes data deduplication, missing data handling, and outlier detection. In this embodiment, data deduplication avoids redundancy. Missing data handling may include filling in or deleting missing data to ensure data integrity. Outlier detection prevents it from interfering with subsequent analysis.
[0063] Specifically, based on a preset information gain calculation method, the information gain of all second resource transfer request features is calculated. Then, the second resource transfer request feature with the largest information gain from each information entropy is selected as the basis for splitting the root node. The feature dataset can then be divided into at least two subsets based on the selected feature. For each subset, the step of calculating the information gain of all second resource transfer request features based on the preset information gain calculation method is repeated, selecting the second resource transfer request feature with the largest information gain in each subset for further splitting, generating child nodes, and recursively continuing until a preset stopping condition is reached, thereby constructing a decision tree model including a decision tree.
[0064] Alternatively, the preset information gain calculation method can be expressed by the following formula:
[0065] IG=H(S)-∑(|S_v| / |S|)*H(S_v)
[0066] Where IG represents the information gain of the second resource transfer request feature. S represents the feature dataset. S_v represents the subset of the feature dataset S after feature partitioning. H() represents the function used to calculate the entropy of the dataset.
[0067] In this embodiment of the invention, the preset stopping condition may at least include the decision tree reaching a preset depth threshold and the sum of the information gains of all nodes in the decision tree being less than a preset gain threshold. The preset depth threshold can be set according to actual needs and is not specifically limited here. The preset gain threshold can also be set according to actual needs and is not specifically limited here.
[0068] For example, a decision tree is constructed with a preset depth threshold of 6, meaning the decision tree has 6 layers. Specifically, the first layer of the decision tree is the root node, corresponding to resource transfer security features. By inputting the number of security rule triggers, security warning signals, and verification results conforming to security rules, it is determined whether a security rule has been triggered to determine whether to enter the ultra-high-risk branch; if not, it proceeds to the next layer, the second layer of feature segmentation (resource transfer behavior features of the resource transfer initiator). The second layer of the decision tree corresponds to resource transfer behavior features. By inputting operating habits (device type / biometric authentication speed), historical risk records, and account activity, it is determined whether the behavior of the resource transfer initiator is abnormal. If so, it proceeds to the high-risk branch; otherwise, it proceeds to the next layer of feature segmentation (resource transfer association features).
[0069] The third layer of the decision tree corresponds to resource transfer association features. By inputting the risk rating of the resource recipient (e.g., whitelist, graylist, blacklist), the blacklist status of associated accounts, and the complexity of the funding chain, it determines whether the account is high-risk. If so, it proceeds to the high-risk branch; otherwise, it proceeds to the next layer of feature segmentation (basic resource transfer features). The fourth layer of the decision tree corresponds to basic resource transfer features. By inputting the resource transfer time (time period / frequency), resource transfer channel, resource transfer geographical location, and resource quantity characteristics, it determines whether the transaction time is abnormal. If so, it proceeds to the medium-risk branch; otherwise, it proceeds to the next layer of feature segmentation (transferred resource features).
[0070] The fifth layer of the decision tree corresponds to resource transfer characteristics. It determines whether a resource transfer is large-scale by inputting the daily, monthly, and annual resource transfer limits, average transfer amount, maximum, and minimum transfer amounts of the initiating resource transfer target. If so, it proceeds to the medium-risk branch; otherwise, it proceeds to the next layer of feature segmentation (resource transfer environment characteristics). The sixth layer of the decision tree corresponds to resource transfer environment characteristics. It determines whether the environment is abnormal by inputting the network environment (VPN / proxy detection) and biometric authentication environment lighting / background noise. If so, it proceeds to the low-to-medium risk branch; otherwise, it proceeds to the low-risk branch. See also... Figure 3 An example diagram of certification based on this decision tree for risk assessment.
[0071] In this embodiment of the invention, the training methods for the decision tree model may include:
[0072] First, the decision tree model parameters are initialized by boosting the training model through forward distribution to optimize the parameters, that is, the decision tree model parameters f0(x) = 0 are initialized. The model at step K can be represented as follows:
[0073] f K (x)=f K-1 (x)+T(x,α K )
[0074] Among them, f K-1 (x) can be represented as the model at step K-1. T can be represented as the feature training set T = {{x1,y1},{x2,y2},......,{xN,yN}}. Where X i Y represents sample data. i This represents the label corresponding to the sample data. Here, i represents the index of the current sample, and N represents the number of samples. α K This can be represented as the next step decision tree parameter, which can be calculated using the following risk minimization formula:
[0075]
[0076] Where arg can represent the calculation of the average value, L can represent the loss function, N can represent the total number of samples, i can represent the index of the current sample, and y can represent the total number of samples. i x represents the current sample data. i The label represents the current sample.
[0077] S230. Based on the correspondence between the resource transfer risk level and the preset authentication method, determine the target authentication method corresponding to the resource transfer risk level.
[0078] S240. The object information of the target object is authenticated through the target authentication method. If the authentication is successful, the first resource transfer request is processed.
[0079] The technical solution of this invention determines a first resource transfer request feature corresponding to the first resource transfer request; inputs the first resource transfer request feature into a pre-trained decision tree model to obtain a feature risk level corresponding to the first resource transfer request feature, which is then used as the resource transfer risk level corresponding to the resource transfer request, thereby achieving a relatively fast and accurate determination of the resource transfer risk level corresponding to the resource transfer request.
[0080] Figure 4 This is a schematic diagram of a resource transfer request processing device provided in an embodiment of the present invention. Figure 4 As shown, the device includes: a risk level determination module 310, an authentication method determination module 320, and a request processing model 330.
[0081] The risk level determination module 310 is used to determine the resource transfer risk level corresponding to the first resource transfer request in response to the first resource transfer request initiated by the target object; the authentication method determination module 320 is used to determine the target authentication method corresponding to the resource transfer risk level based on the correspondence between the resource transfer risk level and the preset authentication method; and the request processing model 330 is used to authenticate the object information of the target object through the target authentication method, and process the first resource transfer request if the authentication is successful.
[0082] The technical solution of this invention determines the resource transfer risk level corresponding to the first resource transfer request in response to the first resource transfer request initiated by the target object. Therefore, based on the correspondence between the resource transfer risk level and the preset authentication method, a target authentication method corresponding to the resource transfer risk level can be determined. By setting corresponding authentication methods for different risk levels, adaptive adjustment is achieved, maximizing user experience while ensuring the security of resource transfer request processing. The target authentication method is used to authenticate the object information of the target object. If authentication is successful, the first resource transfer request is processed, effectively ensuring the security of the resource transfer request. The technical solution of this invention solves the technical problem in related technologies where fixed authentication methods are often used for resource transfer requests, resulting in poor authentication flexibility. It achieves dynamic adaptation to authentication scenarios with different risk levels, balancing security and efficiency, thereby improving the security of resource transfer requests.
[0083] The risk level determination module 310 is used to determine the first resource transfer request feature corresponding to the first resource transfer request; input the first resource transfer request feature into a pre-trained decision tree model to obtain the feature risk level corresponding to the first resource transfer request feature, which is used as the resource transfer risk level corresponding to the first resource transfer request.
[0084] Optionally, the device further includes a decision tree model acquisition module. The decision tree model acquisition module is used to: determine a feature dataset, wherein the feature dataset includes multiple second resource transfer request features, wherein the second resource transfer request features are obtained based on resource transfer requests initiated by resource transfer initiating objects at historical moments; calculate the information gain of all second resource transfer request features based on a preset information gain calculation method, select the second resource transfer request feature with the largest information gain as the partitioning criterion for the root node, and partition the feature dataset into at least two subsets based on the selected feature; for each subset, repeatedly execute the step of calculating the information gain of all second resource transfer request features based on the preset information gain calculation method, select the second resource transfer request feature with the largest information gain in each subset to continue partitioning, generate child nodes, and recursively continue until a preset stopping condition is reached, so as to construct a decision tree model including a decision tree.
[0085] Optionally, the device further includes data preprocessing, wherein the data preprocessing is used to preprocess the request information of the resource transfer request initiated by the resource transfer initiating object at a historical time before calculating the information gain of all the second resource transfer request features based on a preset information gain calculation method; wherein the data preprocessing includes data deduplication processing, data missing value processing, and data outlier detection processing.
[0086] Optionally, the preset stopping condition includes at least the decision tree depth reaching a preset depth threshold and the sum of the information gains of all nodes in the decision tree being less than a preset gain threshold.
[0087] Optionally, the first resource transfer request features include basic resource transfer features, resource transfer association features, resource transfer environment features, resource transfer security features, transferred resource features, and resource transfer behavior features of the resource transfer initiator.
[0088] Optionally, the resource transfer risk levels, from highest to lowest, include a first risk level, a second risk level, a third risk level, a fourth risk level, and a fifth risk level; wherein, the preset authentication methods corresponding to the first risk level include manual authentication; the preset authentication methods corresponding to the second risk level include static password authentication, SMS verification authentication, dynamic password authentication, and facial recognition authentication; the preset authentication methods corresponding to the third risk level include static password authentication and SMS verification authentication; the preset authentication methods corresponding to the fourth risk level include SMS verification authentication and dynamic password authentication; and the preset authentication method corresponding to the fifth risk level includes static password authentication.
[0089] The resource transfer request processing apparatus provided in this embodiment of the invention can execute the resource transfer request processing method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method.
[0090] It is worth noting that the various units and modules included in the above-mentioned resource transfer request processing device are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the protection scope of the embodiments of the present invention.
[0091] Figure 5 A schematic diagram of an electronic device 10 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0092] like Figure 5As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0093] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0094] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as resource transfer request processing methods.
[0095] In some embodiments, the resource transfer request processing method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via read-only memory (ROM) 12 and / or communication unit 19. When the computer program is loaded into random access memory (RAM) 13 and executed by processor 11, one or more steps of the resource transfer request processing method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the resource transfer request processing method by any other suitable means (e.g., by means of firmware).
[0096] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0097] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0098] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0099] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0100] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0101] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0102] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0103] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for processing resource transfer requests, characterized in that, The method includes: In response to a first resource transfer request initiated by the target object, determine the resource transfer risk level corresponding to the first resource transfer request; Based on the correspondence between resource transfer risk levels and preset authentication methods, determine the target authentication method corresponding to the resource transfer risk level; The target object's information is authenticated using the target authentication method. If the authentication is successful, the first resource transfer request is processed.
2. The method according to claim 1, characterized in that, Determining the resource transfer risk level corresponding to the first resource transfer request includes: Determine the characteristics of the first resource transfer request corresponding to the first resource transfer request; The first resource transfer request feature is input into a pre-trained decision tree model to obtain the feature risk level corresponding to the first resource transfer request feature, which is used as the resource transfer risk level corresponding to the first resource transfer request.
3. The method according to claim 2, characterized in that, The method further includes: A feature dataset is determined, wherein the feature dataset includes multiple second resource transfer request features, wherein the second resource transfer request features are obtained based on resource transfer requests initiated by the resource transfer initiating object at historical moments; Based on a preset information gain calculation method, the information gain of all second resource transfer request features is calculated, and the second resource transfer request feature with the largest information gain is selected as the partitioning criterion for the root node. The feature dataset is then divided into at least two subsets based on the selected feature. For each subset, the step of calculating the information gain of all second resource transfer request features based on a preset information gain calculation method is repeated. The second resource transfer request feature with the largest information gain in each subset is selected for further partitioning, generating child nodes. This process is repeated recursively until a preset stopping condition is reached, so as to construct a decision tree model including a decision tree.
4. The method according to claim 3, characterized in that, Before calculating the information gain of all the second resource transfer request features based on the preset information gain calculation method, the method further includes: The request information of the resource transfer request initiated by the resource transfer initiating object at a historical time is preprocessed; wherein, the data preprocessing includes data deduplication, data missing value handling, and data outlier detection processing.
5. The method according to claim 2, characterized in that, The preset stopping conditions include at least the decision tree depth reaching a preset depth threshold and the sum of the information gains of all nodes in the decision tree being less than a preset gain threshold.
6. The method according to claim 2, characterized in that, The first resource transfer request features include basic resource transfer features, resource transfer association features, resource transfer environment features, resource transfer security features, transferred resource features, and resource transfer behavior features of the resource transfer initiator.
7. The method according to claim 1, characterized in that, The resource transfer risk levels, from highest to lowest, include a first risk level, a second risk level, a third risk level, a fourth risk level, and a fifth risk level. The preset authentication methods for the first risk level include manual authentication; the preset authentication methods for the second risk level include static password authentication, SMS verification authentication, dynamic password authentication, and facial recognition authentication; the preset authentication methods for the third risk level include static password authentication and SMS verification authentication; the preset authentication methods for the fourth risk level include SMS verification authentication and dynamic password authentication; and the preset authentication method for the fifth risk level includes static password authentication.
8. A resource transfer request processing apparatus, characterized in that, include: The risk level determination module is used to determine the resource transfer risk level corresponding to the first resource transfer request in response to the first resource transfer request initiated by the target object. The authentication method determination module is used to determine the target authentication method corresponding to the resource transfer risk level based on the correspondence between the resource transfer risk level and the preset authentication method; The request processing model is used to authenticate the object information of the target object through the target authentication method, and to process the first resource transfer request if the authentication is successful.
9. An electronic device, characterized in that, Its features are, The electronic device includes: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the resource transfer request processing method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the resource transfer request processing method according to any one of claims 1-7.