Transaction processing method
By uniformly executing the parsing, format conversion, and encryption of financial transaction request messages on the server side of the target financial institution, the problems of high upgrade and maintenance costs and dispersed security risks in bank-enterprise direct connection technology are solved, and efficient and secure cross-institutional transaction processing is achieved.
Patent Information
- Application Number
- CN202511517626.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-22
- Publication Date
- 2026-02-24
AI Technical Summary
Existing bank-enterprise direct connection technologies suffer from high upgrade and maintenance costs, chaotic version management, dispersed security risks, high interface change and maintenance costs, and difficulty in synchronizing security patches, resulting in low efficiency and insufficient security in cross-institutional transaction processing.
The system uniformly performs parsing, format conversion, and encryption of financial transaction request messages on the target financial institution's server side. This ensures that the message format conforms to the technical specifications of the third-party financial institution's access service. The encryption process is completed internally within the financial institution, and the message is decrypted and forwarded to the third-party financial institution's access service using the communication service system.
It improves the success rate of cross-institutional transactions and system interoperability, reduces the risk of key leakage and abuse, increases transaction processing speed and system maintainability, and enhances security control capabilities and user experience.
Smart Images

Figure CN121567359A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of Internet technology, and in particular to a transaction processing method. Background Technology
[0002] Against the backdrop of deep global economic integration and accelerated digital transformation, enterprises have significantly increased their demands for the complexity and real-time nature of cash management. To meet the needs of modern enterprises for efficient, intelligent, and collaborative operations, Bank-Enterprise Direct Connection (BDC), as a crucial practice for the deep integration of fintech and the real economy, establishes direct connections between core financial (banking) systems and business platforms such as Enterprise Resource Planning (ERP) and financial management systems. This enables the deep integration of cash flow, information flow, and business flow, and has become a key infrastructure for enterprises to optimize cash flow management, improve financial decision-making efficiency, and build intelligent treasury systems. Under this trend, financial institutions urgently need to build a secure, flexible, and scalable transaction processing mechanism to support the high-frequency, high-reliability transaction needs of corporate clients across systems and institutions, promoting the deep embedding of financial services into the entire business operation process. Summary of the Invention
[0003] This disclosure provides a transaction processing method to at least partially solve one of the technical problems in related technologies. The technical solution of this disclosure is as follows: According to a first aspect of the present disclosure, a transaction processing method is provided, applied to a server of a target financial institution, comprising: in response to receiving a financial transaction request message, parsing the financial transaction request message to obtain message information of the financial transaction request message; wherein the financial transaction request message is sent by a business system deployed by the target financial institution in response to a logged-in service object triggering a target transaction; based on the message information, performing format conversion and encryption on the financial transaction request message to obtain an encrypted message; and according to the message information, sending the encrypted message to the communication service system of the service object, so that the communication service system can decrypt the encrypted message, and forwarding the decrypted message to a third-party financial institution access service for transaction processing associated with the target transaction.
[0004] According to a second aspect of the present disclosure, a transaction processing apparatus is provided, comprising: a parsing module, configured to parse a financial transaction request message in response to receiving such a message, to obtain message information of the financial transaction request message; wherein the financial transaction request message is sent by a business system deployed by a target financial institution in response to a logged-in service object triggering a target transaction; a processing module, configured to perform format conversion and encryption on the financial transaction request message based on the message information, to obtain an encrypted message; and a sending module, configured to send the encrypted message to the communication service system of the service object according to the message information, so that the communication service system can decrypt the encrypted message and forward the decrypted message to a third-party financial institution access service for transaction processing associated with the target transaction.
[0005] According to a third aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to execute the instructions to implement the transaction processing method as described in the first aspect of the present disclosure.
[0006] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided that, when instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to perform a transaction processing method as described in the first aspect of the present disclosure.
[0007] According to a fifth aspect of the present disclosure, a computer program product is provided, comprising: a computer program that, when executed by a processor, implements the transaction processing method as described in the first aspect of the present disclosure.
[0008] The technical solutions provided by the embodiments of this disclosure have at least the following beneficial effects: In this technical solution, by uniformly executing the parsing, format conversion, and encryption of financial transaction request messages on the server side of the target financial institution, the direct connection exchange service program (such as the bank-enterprise direct connection exchange center service program) deployed on the service recipient's side is adjusted to the server side of the target financial institution. This ensures that all transaction requests undergo unified protocol adaptation and encryption encapsulation by the financial institution before entering the external communication link, guaranteeing that the message format conforms to the technical specifications of the third-party financial institution's access service. This effectively solves the format incompatibility problem caused by the heterogeneity of enterprise systems, improving the success rate of transaction processing and system interoperability. Simultaneously, the encryption of the messages is completed internally within the financial institution, avoiding the distribution and exposure of keys to a large number of external enterprise systems, significantly reducing the risk of leakage and misuse, and strengthening security control capabilities. Furthermore, the encrypted messages are decrypted and forwarded to the service recipient's communication service system. The third-party financial institution access service ensures data transmission security while reusing existing enterprise infrastructure such as instant messaging, improving communication efficiency and user experience, and enhancing the processing speed and efficiency of interbank transactions. Furthermore, this centralized architecture avoids the problems of version management chaos, inconsistent upgrade progress, high interface change maintenance costs, and difficulty in synchronizing security patches caused by each enterprise deploying its own direct connection exchange service program in the traditional model. This significantly improves the processing speed of inter-institutional transactions, system maintainability, and overall operational efficiency. In addition, both the service recipient and the target financial institution are equipped with visual operation interfaces, allowing both parties to monitor the service status of the third-party financial institution access service in real time. This enables the observation of the entire service status of the inter-institutional transaction process, the intervention of abnormal situations, and the traceability of operational behavior, significantly improving system transparency, self-control capabilities, and emergency response efficiency.
[0009] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0010] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure, and are not intended to unduly limit this disclosure.
[0011] Figure 1 This is a schematic flowchart of the transaction processing method shown in the first embodiment of this disclosure; Figure 2 This is a schematic flowchart of the transaction processing method shown in the second embodiment of this disclosure; Figure 3 This is a schematic flowchart of the transaction processing method shown in the third embodiment of this disclosure; Figure 4This is a schematic flowchart of the transaction processing method shown in the fourth embodiment of this disclosure; Figure 5 This is a schematic flowchart of the transaction processing method shown in the fifth embodiment of this disclosure; Figure 6 This is a schematic diagram illustrating the principle of transaction suspension as shown in the embodiments of this disclosure; Figure 7 This is a schematic diagram illustrating the principle of the transaction processing method shown in the embodiments of this disclosure; Figure 8 This is a schematic diagram of the transaction processing apparatus shown in the sixth embodiment of this disclosure; Figure 9 This is a schematic diagram of the structure of an electronic device shown in an exemplary embodiment of the present disclosure. Detailed Implementation
[0012] To enable those skilled in the art to better understand the technical solutions of this disclosure, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings.
[0013] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.
[0014] It should be noted that the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in the technical solution disclosed herein are all carried out with the consent of the user, and all comply with the provisions of relevant laws and regulations, and do not violate public order and good morals.
[0015] In traditional bank-enterprise direct connection technology implementation solutions, the common approach is to deploy the exchange center service program directly on the customer's local server (i.e., enterprise-side deployment). This architecture has several significant drawbacks: (1) High upgrade and maintenance costs: Whenever the interface specifications of financial institutions change, the technical team must implement service updates separately for each enterprise customer. (2) Version management is chaotic. Due to the different upgrade progress of various enterprise customers, financial institutions need to maintain multiple interface versions at the same time. (3) The overlapping and distributed deployment of security risks makes it impossible to synchronize security patches in a timely manner.
[0016] To address any of the above issues, this disclosure proposes a transaction processing method.
[0017] The transaction processing method of this disclosure is described below with reference to the accompanying drawings.
[0018] Figure 1 This is a flowchart illustrating the transaction processing method shown in the first embodiment of this disclosure.
[0019] like Figure 1 As shown, the transaction processing method includes steps 101 to 103, as detailed below: Step 101: In response to receiving a financial transaction request message, parse the financial transaction request message to obtain the message information of the financial transaction request message.
[0020] Among them, the financial transaction request message is sent by the business system deployed by the target financial institution in response to the logged-in service object triggering the target transaction.
[0021] To enhance transaction security, one possible approach is to receive financial transaction request messages from the target financial institution's own deployed business systems at the target financial institution's server end, and then parse these messages to extract information including transaction type, amount, account information, service recipient identifier, timestamp, and financial institution code identifier. These business systems may include, but are not limited to, treasury management systems and financial management systems deployed by financial institutions for large enterprise clients. The treasury management system is used for centralized management of the enterprise's accounts, payments, financing, and liquidity; the financial management system is used for centralized payment and fund monitoring.
[0022] It should be noted that since the financial transaction request message was initiated proactively by the business system deployed by the financial institution after the service recipient had logged in and been authenticated, its source is reliable, the data is complete, and its security is high.
[0023] Step 102: Based on the message information, the financial transaction request message is formatted and encrypted to obtain an encrypted message.
[0024] To avoid protocol incompatibility issues caused by system heterogeneity between different financial institutions and to improve the operability and success rate of cross-institutional transactions, one possible approach is to convert the financial transaction request message according to the communication protocol and data format required by the target recipient (such as a third-party financial institution access service) based on the message information, ensuring semantic consistency and field alignment. At the same time, to ensure the confidentiality and integrity of transaction data during transmission, encryption algorithms (such as SM4, AES, or RSA) are used to encrypt the converted message, generating an encrypted message.
[0025] In some embodiments, such as Figure 2 As shown, step 102 includes steps 1021 to 1025, as detailed below: Step 1021: Based on the financial institution identifier in the message information, determine the target message template that matches the financial institution identifier from multiple candidate message templates.
[0026] To avoid parsing failures, missing fields, or business logic mismatches caused by differences in data standards among different financial institutions, this embodiment extracts the financial institution identifier contained in the message information, such as the institution code or access system ID of the third-party financial institution. Based on this financial institution identifier, a matching search is performed among multiple predefined candidate message templates to select a target message template that is compatible with the communication protocol of the third-party financial institution's access service. It should be noted that the target message template can define structured requirements such as field order, data type, required / optional fields, and encoding rules.
[0027] Step 1022: Based on the target message template, the message information is format-converted to obtain a converted message.
[0028] To ensure semantic consistency and format compliance of transaction data during cross-system transmission, as an example, based on the data structure defined by the target message template, the fields of the message data in the message information are mapped, reorganized, type-converted, and semantically adapted to generate a structured message that conforms to the interface specifications of the target financial institution, i.e., a converted message.
[0029] Step 1023: Using the first encryption algorithm, digitally sign the converted message and generate signature data.
[0030] To prevent transaction messages from being tampered with during transmission, as an example, after obtaining the converted message, a first encryption algorithm, such as an asymmetric algorithm like SM2 or RSA, is used to digitally sign the message. For instance, its hash value is first calculated, and then the hash value is encrypted using the financial institution's private key to generate unique signature data. It should be noted that this signature data is strongly bound to the financial transaction request message and can be used to verify the authenticity of the message's source and the integrity of its content.
[0031] Step 1024: The formatted message is encrypted using the second encryption algorithm to generate a ciphertext message.
[0032] To prevent message data from being stolen or leaked during network transmission, as an example, a second encryption algorithm, such as symmetric encryption algorithms like SM4 or AES, is used to encrypt the converted formatted message while generating signature data, thus generating a ciphertext message.
[0033] Step 1025: Encapsulate the signature data and the ciphertext message to obtain the encrypted message.
[0034] To avoid information loss and parsing errors, as an example, the generated signature data and ciphertext message are combined according to a predefined encapsulation structure to form a unified data packet, i.e., an encrypted message. This encapsulation structure, for example, is JSON encapsulation and typically includes metadata such as ciphertext, signature, algorithm identifier, timestamp, and sequence number, ensuring that the receiver can correctly parse and verify it.
[0035] In summary, based on the financial institution identifier in the message information, the system automatically matches the corresponding target message template and converts the original transaction data accordingly. This ensures that the generated converted message accurately adapts to the interface specifications of different third-party financial institutions, effectively solving the format incompatibility problem caused by differences in protocols between systems and improving the interoperability and processing success rate of cross-institutional transactions. Furthermore, a first encryption algorithm is used to digitally sign the converted message, generating signature data to ensure the integrity and verifiability of the transaction content and prevent data from being tampered with or forged during transmission. Simultaneously, a second encryption algorithm is used to encrypt the message, generating ciphertext messages to ensure the confidentiality of sensitive information and prevent information leakage. Finally, the signature data and ciphertext messages are structurally encapsulated to form a unified encrypted message, which not only supports the receiver to decrypt and verify the signature according to standard procedures but also enhances the transmission reliability and system adaptability of the message in complex network environments.
[0036] Step 103: Based on the message information, send the encrypted message to the communication service system of the service recipient so that the communication service system can decrypt the encrypted message and forward the decrypted message to the third-party financial institution access service for transaction processing associated with the target transaction.
[0037] To improve transaction efficiency, one possible approach is to generate an encrypted message and, based on the message information, send it to the communication service system used by the corresponding service recipient. This communication service system then decrypts the encrypted message locally using a pre-shared key and forwards the decrypted message to the corresponding third-party financial institution access service via a trusted connection, thus completing cross-institutional transaction processing. It should be noted that the third-party financial institution access service refers to the technical service interface provided by a financial institution for receiving and processing transaction requests from systems outside the institution (such as enterprise systems, other banks, platform service providers, etc.).
[0038] In some embodiments, such as Figure 3 As shown, step 103 includes steps 1031 to 1032, as follows: Step 1031: Determine the communication service system of the service object to which the encrypted message is to be routed, based on the object identifier in the message information.
[0039] To ensure accurate transmission of encrypted messages and avoid mistransmission, as an example, after generating the encrypted message, the unique identifier of the service object, i.e., the object identifier, such as enterprise ID, user account, organization code, etc., is extracted from the message information. Based on the object identifier, a preset routing mapping table is queried to determine the communication service system to which the service object is bound. It should be noted that the mapping relationship can be pre-configured or dynamically registered.
[0040] Step 1032: Send the encrypted message to the communication service system of the service recipient so that the communication service system can decrypt the encrypted message and forward the decrypted message to the third-party financial institution access service for transaction processing associated with the target transaction.
[0041] Furthermore, after identifying the target communication service system, the encrypted message is sent to the communication service system through a standard interface. Upon receiving the encrypted message, the communication service system decrypts the message locally using a pre-shared key or certificate, and forwards the decrypted message to the corresponding access service through a secure connection (such as an API channel) established between it and the third-party financial institution, for subsequent transaction processing, such as payment execution and account inquiry.
[0042] As an example, the financial institution identifier corresponding to the third-party financial institution access service to which the decrypted message is to be routed is obtained from the decrypted message; based on the financial institution identifier, the third-party financial institution access service to which the decrypted message is to be routed is determined from multiple financial institution access services; the decrypted message is forwarded to the third-party financial institution access service for transaction processing associated with the target transaction.
[0043] In other words, the system extracts the institutional identifier of the target third-party financial institution from the decrypted message and dynamically matches the corresponding financial institution access service among multiple access services based on this identifier. Then, it forwards the decrypted message to the service endpoint, achieving precise routing and automated processing of transaction messages. Since the institutional identifier is built into the message information, it does not rely on external configuration or manual intervention. The system can automatically identify the target recipient, significantly improving the flexibility and scalability of cross-institutional transactions. Furthermore, by forwarding the decrypted message to the third-party financial institution access service through the enterprise's communication service system, the enterprise can connect to multiple financial institutions through a unified entry point, avoiding the duplication of developing and maintaining multiple sets of interfaces, and greatly reducing integration costs and operational burden.
[0044] In some embodiments, such as Figure 4As shown, after step 103, the target financial institution's client is used to execute steps 104 to 105, as follows: Step 104: Receive the service status indicators of the third-party financial institution access service sent by the communication service system.
[0045] Among them, the service status indicator is sent by the third-party financial institution access service during the transaction processing associated with the target transaction based on the decrypted message.
[0046] To enable financial institutions to promptly grasp the current status and potential anomalies of transaction execution, as an example, during the process of a third-party financial institution's access service executing decrypted transaction messages and handling related to the target transaction—such as payment execution, account verification, and settlement confirmation—service status indicators reflecting the system's operational status and transaction progress can be generated in real time. These indicators include system availability, response latency, transaction success rate, error codes, and processing stage. These status indicators are output by the third-party financial institution's access service, relayed through the service recipient's communication service system, and ultimately received by the target financial institution's client.
[0047] Step 105: Visualize the service status indicators.
[0048] To transform system status and transaction progress into intuitive and easy-to-understand information, thereby improving users' cognitive efficiency and operational experience in cross-institutional transaction processes, as an example, after receiving service status indicators, they are presented to financial institution operations personnel through a graphical interface. The displayed content may include, but is not limited to, transaction progress bars, status change timelines, anomaly alarm prompts, historical success rate trend charts, etc.
[0049] In summary, by receiving service status indicators from third-party financial institutions accessing the service forwarded by the communication service system, the target financial institution can obtain real-time operational information on transaction processing; furthermore, by visualizing the service status indicators, the financial institution's operations personnel can monitor the entire transaction execution process in real time.
[0050] In some embodiments, such as Figure 5 As shown, step 105 may be followed by step 106, as detailed below: Step 106: In response to triggering the first service pause component in the service status management interface of the client, send the first service pause command to the backend associated with the service object.
[0051] The first service suspension command is used to execute the service command script associated with the third-party financial institution access service in order to shut down the third-party financial institution access service.
[0052] In this embodiment, when the first service pause component is triggered by a financial institution operator in the client's service status management interface, for example, by triggering a "Pause Access" button, a first service pause instruction is generated in response to this operation and sent to the backend associated with the current service object (such as an enterprise customer). This first service pause instruction carries identification information of the third-party financial institution's access service and is used to trigger the execution of a pre-configured service command script associated with the specific third-party financial institution's access service. This script may include multiple service operation instructions, such as pausing the service, closing the API connection, and terminating message queue consumption, thereby achieving a logical or physical shutdown of the third-party financial institution's access service.
[0053] In summary, financial institutions can quickly and accurately suspend specific service connections in scenarios such as abnormal transactions, system upgrades, security incidents, or compliance reviews; and through scripted command execution, there is no need for manual login to remote systems or modification of configurations, which improves emergency response efficiency and operational consistency.
[0054] To enable enterprise customers to understand the operational status of third-party financial institution access services in a timely manner, as an example, in response to triggering the status monitoring component in the currently displayed visualization interface, a status monitoring command is sent to the backend. The status monitoring command is used to monitor the service status of the third-party financial institution access service; the service status indicators of the third-party financial institution access service sent by the backend are received; and the service status indicators are displayed in the visualization interface.
[0055] In other words, when an enterprise customer triggers the status monitoring component in the currently displayed visualization interface, such as by triggering the "View Service Status" button, the enterprise's front-end responds to this operation by sending a status monitoring command to the enterprise's back-end. This command is used to initiate an active detection or subscription mechanism for the operational status of the third-party financial institution's access service. For example, by calling health check interfaces, querying heartbeat signals, obtaining transaction processing queue status, or subscribing to event streams, service status indicators that reflect key information such as service availability, response latency, transaction success rate, error codes, and processing stages are collected in real time. After receiving these indicators, the back-end sends them back to the front-end, which then dynamically displays the service status indicators in a graphical manner in the visualization interface.
[0056] To enhance enterprises' real-time control over cross-institutional transactions and improve risk response efficiency, as an example, such as Figure 6As shown, the front-end associated with the service object responds to the user triggering the second service pause component in the visualization interface. For example, if the user triggers the "Emergency Interruption" button or the "Pause Transaction" switch in the visualization interface, a second service pause instruction is generated and sent to the back-end associated with the front-end. This instruction is used to call the service command script associated with the access service of the third-party financial institution. The script contains predefined automated operation logic, such as disconnecting the network connection with the access service of the third-party financial institution, stopping the forwarding of transaction messages, canceling the session token, or suspending a specific transaction channel, thereby realizing the rapid shutdown or isolation of the access service of the third-party financial institution.
[0057] To enable businesses to promptly understand the status of third-party financial institution access services, as an example, the visual interface also displays at least one of the following: dynamic function icons, status indicator lights, and viewing controls. The dynamic function icons can dynamically adjust their display form, animation effects, or position status based on the real-time progress of transaction processing or the risk level assessed by the system, intuitively conveying the current execution stage and risk level of the transaction to the user. Real-time progress can include "message being sent," "awaiting settlement," or "transaction successful," and risk levels can include low, medium, and high risk. Status indicator lights are associated with various preset color codes; for example, green indicates normal communication, yellow indicates response delay, and red indicates connection interruption or service unavailability. These visual signals help users quickly identify the current communication status of third-party financial institution access services. The viewing controls are used to retrieve and display operation records within a set time range, including message sending and receiving times, processing results, error codes, and other key data. This allows users to retrospectively analyze abnormal events and accurately pinpoint the root cause of service failures or transaction failures.
[0058] Furthermore, the front-end is also used to display the root cause of the fault in real time through pop-up windows in the visual interface when an anomaly is detected in the access service of a third-party financial institution. For example, the root cause may be "interface timeout" or "network connection interruption". At the same time, the pop-up window also presents repair suggestions related to the fault type, such as "suggest switching to a backup channel", to guide users to take appropriate repair strategies. In this way, complex system-level problems are transformed into understandable diagnostic information and actionable operation guidelines, which can quickly respond without technical personnel having to delve into logs or rely on external support. This significantly improves the efficiency and accuracy of anomaly handling and enhances the intelligent operation and maintenance capabilities of the system and the user experience.
[0059] To clearly illustrate the above embodiments, examples are given below.
[0060] For example, such as Figure 7As shown, the direct-connect switching service program is deployed on the financial institution side, enabling unified message reception, parsing, routing, and encryption. It supports automatic conversion of various message formats such as XML and JSON, ensuring cross-system compatibility. In terms of deployment mode, a dual-active architecture can be adopted, where two data centers run synchronously and serve as backups for each other, ensuring business continuity and supporting horizontal scaling. A visual operation and maintenance platform is established on the financial institution side, displaying core indicators such as message traffic and transaction success rate, while also implementing transaction anomaly alarm functions, achieving visualization of the message lifecycle from sending to receiving. On the enterprise side, service operation management has achieved full-process visualization. The operation and maintenance system adopts an intuitive graphical interface design, allowing users to complete service start / stop, status monitoring, and other operations with simple button clicks. For example… (1) Adopting a user interface (UI) design specification that conforms to the standard, all function buttons are equipped with intuitive icons and status indicator lights, so that non-technical personnel can quickly grasp the operation logic; (2) The service status is clearly visible through a dual prompting mechanism of color coding (green for running / red for stopping) and dynamic icons; (3) It integrates the automatic archiving function of service operation logs, and users can view the operation records of the last 30 days at any time, which is convenient for fault traceability; (4) When the service is abnormal, the system will automatically pop up a concise fault guide and provide one-click repair suggestions to reduce the number of technical support requests and effectively reduce operation and maintenance costs.
[0061] The transaction processing method of this disclosure uniformly executes the parsing, format conversion, and encryption of financial transaction request messages on the server side of the target financial institution. This involves adapting the direct connection exchange service program deployed on the service recipient side of related technologies to the server side of the target financial institution. This ensures that all transaction requests undergo unified protocol adaptation and encryption encapsulation by the financial institution before entering the external communication link, guaranteeing that the message format conforms to the technical specifications of the target system. This effectively solves the format incompatibility problem caused by the heterogeneity of enterprise systems, improving the success rate of transaction processing and system interoperability. Simultaneously, the message encryption is completed internally within the financial institution, avoiding the distribution of keys to a large number of external enterprise systems. This architecture significantly reduces the risk of leakage and misuse, and strengthens security control capabilities. Furthermore, by sending encrypted messages to the communication service system of the service recipient for decryption and forwarding to the third-party financial institution, it ensures the security of data transmission and reuses the enterprise's existing instant messaging and other infrastructure to improve communication efficiency and user experience, thereby increasing the processing speed and efficiency of interbank transactions. In addition, this centralized architecture avoids the problems of chaotic version management, inconsistent upgrade progress, high interface change maintenance costs, and difficulty in synchronizing security patches caused by the deployment of direct connection exchange service programs by enterprises on the traditional side. It significantly improves the processing speed of inter-institutional transactions, system maintainability, and overall operating efficiency.
[0062] Corresponding to the transaction processing method provided in the above embodiments, this disclosure also provides a transaction processing apparatus. Since the transaction processing apparatus provided in this disclosure corresponds to the transaction processing method provided in the above embodiments, the implementation of the transaction processing method is also applicable to the transaction processing apparatus provided in this disclosure, and will not be described in detail in this disclosure.
[0063] Figure 8 This is a schematic diagram of the transaction processing apparatus shown in the sixth embodiment of this disclosure.
[0064] like Figure 8 As shown, the transaction processing device 800 includes: a parsing module 810, a processing module 820, and a sending module 830.
[0065] The parsing module 810 is used to parse the financial transaction request message upon receiving it to obtain its message information. The financial transaction request message is sent by the business system deployed by the target financial institution in response to a logged-in service object triggering a target transaction. The processing module 820 is used to convert and encrypt the format of the financial transaction request message based on the message information to obtain an encrypted message. The sending module 830 is used to send the encrypted message to the service object's communication service system according to the message information, so that the communication service system can decrypt the encrypted message and forward the decrypted message to a third-party financial institution access service for transaction processing associated with the target transaction.
[0066] As one possible implementation, the message information carries the object identifier of the service object; the sending module 830 is used to determine the communication service system of the service object to which the encrypted message is to be routed based on the object identifier in the message information; the encrypted message is sent to the communication service system of the service object so that the communication service system can decrypt the encrypted message, and the decrypted message is forwarded to the third-party financial institution access service for transaction processing associated with the target transaction.
[0067] As one possible implementation, the decrypted message is forwarded by the forwarding module by performing the following steps: obtaining the financial institution identifier corresponding to the third-party financial institution access service to which the decrypted message is to be routed from the decrypted message; determining the third-party financial institution access service to which the decrypted message is to be routed from multiple financial institution access services based on the financial institution identifier; and forwarding the decrypted message to the third-party financial institution access service for transaction processing associated with the target transaction.
[0068] As one possible implementation, the processing module 820 is used to determine a target message template that matches the financial institution identifier from multiple candidate message templates based on the financial institution identifier in the message information; based on the target message template, the message information is formatted to obtain a converted message; a first encryption algorithm is used to digitally sign the formatted message using a first encryption algorithm to generate signature data; a second encryption algorithm is used to encrypt the formatted message to generate a ciphertext message; and the signature data and the ciphertext message are encapsulated to obtain an encrypted message.
[0069] As one possible implementation, the client of the target financial institution includes a receiving module and a display module. The receiving module is used to receive service status indicators of the third-party financial institution access service sent by the communication service system. The service status indicators are sent by the third-party financial institution access service during the transaction processing associated with the target transaction based on the decrypted message. The display module is used to visualize the service status indicators.
[0070] As one possible implementation, the client of the target financial institution also includes a pause module. The pause module is used to respond to the first service pause component in the service status management interface of the client and send a first service pause command to the backend associated with the service object. The first service pause command is used to execute the service command script associated with the access service of the third-party financial institution to shut down the access service of the third-party financial institution.
[0071] As one possible implementation, the front-end associated with the service object includes: a sending module, a receiving module, and a display module.
[0072] The sending module is used to send status monitoring instructions to the backend in response to the status monitoring component in the currently displayed visualization interface; the status monitoring instructions are used to monitor the service status of third-party financial institutions accessing the service; the receiving module is used to receive the service status indicators of the third-party financial institutions accessing the service sent by the backend; and the display module is used to display the service status indicators in the visualization interface.
[0073] As one possible implementation, the front-end associated with the service object also includes: a pause module; the pause module is used to send a second service pause command to the back-end in response to triggering the second service pause component in the visual interface; wherein, the second service pause command is used to close the third-party financial institution access service associated with the service command script.
[0074] As one possible implementation, the visual interface also displays at least one of the following: dynamic function icons; wherein the dynamic function icons are used to indicate the transaction processing progress or risk level of the third-party financial institution accessing the service; status indicator lights; wherein the status indicator lights are associated with multiple color codes, wherein the color codes are used to indicate the current communication status of the third-party financial institution accessing the service; and a viewing control; wherein the viewing control is used to view the operation records within a set time period, and the operation records are used to locate the root cause of the failure in the third-party financial institution accessing the service.
[0075] As one possible implementation, the display module is also used to display the root cause of the failure and related repair suggestions in a pop-up window in the visualization interface when the access service of a third-party financial institution is abnormal; the repair suggestions are used to indicate the strategy for repairing the access service of the third-party financial institution.
[0076] The transaction processing apparatus of this disclosure performs unified parsing, format conversion, and encryption of financial transaction request messages on the server side of the target financial institution. This involves adapting the direct connection exchange service program (such as the bank-enterprise direct connection exchange center service program) deployed on the service recipient side to the server side of the target financial institution. This ensures that all transaction requests undergo unified protocol adaptation and encryption encapsulation by the financial institution before entering the external communication link, guaranteeing that the message format conforms to the technical specifications of the target system (such as third-party financial institution access services). This effectively solves the format incompatibility problem caused by the heterogeneity of enterprise systems, improving the success rate of transaction processing and system interoperability. Simultaneously, the message encryption is completed internally within the financial institution. This approach avoids distributing and exposing keys to numerous external enterprise systems, significantly reducing the risk of leakage and misuse, and strengthening security control capabilities. Furthermore, by sending encrypted messages to the communication service system of the service recipient for decryption and forwarding to third-party financial institutions, data transmission security is ensured. It also reuses existing enterprise infrastructure such as instant messaging, improving communication efficiency and user experience, thereby increasing the processing speed and efficiency of interbank transactions. In addition, this centralized architecture avoids the problems of chaotic version management, inconsistent upgrade progress, high interface change maintenance costs, and difficulty in synchronizing security patches caused by enterprises deploying their own direct connection exchange service programs in the traditional model. This significantly improves the processing speed of inter-institutional transactions, system maintainability, and overall operational efficiency.
[0077] In an exemplary embodiment, an electronic device is also proposed.
[0078] The electronic devices include: processor; Memory used to store processor-executable instructions; The processor is configured to execute instructions to implement the transaction processing method as proposed in any of the foregoing embodiments.
[0079] As an example, Figure 9 This is a schematic diagram of the structure of an electronic device 900 as shown in an exemplary embodiment of this disclosure, as follows: Figure 9 As shown, the aforementioned electronic device 900 may further include: The system includes a memory 910 and a processor 920, and a bus 930 connecting different components (including the memory 910 and the processor 920). The memory 910 stores a computer program, which, when executed by the processor 920, implements the transaction processing method described in this embodiment.
[0080] Bus 930 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. For example, these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.
[0081] Electronic device 900 typically includes a variety of electronic device readable media. These media can be any available media that can be accessed by electronic device 900, including volatile and non-volatile media, removable and non-removable media.
[0082] The memory 910 may also include computer system readable media in the form of volatile memory, such as random access memory (RAM) 940 and / or cache memory 950. The electronic device 900 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, the storage system 960 may be used to read and write non-removable, non-volatile magnetic media (…). Figure 9 Not shown; usually referred to as a "hard drive"). Although Figure 9 As not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 930 via one or more data media interfaces. Memory 910 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of this disclosure.
[0083] A program / utility 980 having a set (at least one) of program modules 970 may be stored, for example, in memory 910. Such program modules 970 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 970 typically perform the functions and / or methods described in the embodiments of this disclosure.
[0084] Electronic device 900 can also communicate with one or more external devices 990 (e.g., keyboard, pointing device, display 991, etc.), and with one or more devices that enable a user to interact with electronic device 900, and / or with any device that enables electronic device 900 to communicate with one or more other computing devices (e.g., network card, modem, etc.). This communication can be performed via input / output (I / O) interface 992. Furthermore, electronic device 900 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 993. As shown, network adapter 993 communicates with other modules of electronic device 900 via bus 930. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 900, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0085] The processor 920 performs various functional applications and data processing by running programs stored in the memory 910.
[0086] It should be noted that the implementation process and technical principles of the electronic device in this embodiment are explained in the foregoing description of the transaction processing method of this disclosure embodiment, and will not be repeated here.
[0087] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, such as a memory including instructions, which can be executed by a processor of an electronic device to perform the transaction processing method proposed in any of the above embodiments. Optionally, the computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.
[0088] In an exemplary embodiment, a computer program product is also provided, including a computer program / instructions, characterized in that the computer program / instructions, when executed by a processor, implement the transaction processing method proposed in any of the above embodiments.
[0089] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.
[0090] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.
Claims
1. A transaction processing method, characterized in that, Applied to the server side of the target financial institution, including: In response to receiving a financial transaction request message, the financial transaction request message is parsed to obtain the message information of the financial transaction request message; wherein, the financial transaction request message is sent by the business system deployed by the target financial institution in response to a logged-in service object triggering a target transaction; Based on the message information, the financial transaction request message is format-converted and encrypted to obtain an encrypted message; Based on the message information, the encrypted message is sent to the communication service system of the service object, so that the communication service system can decrypt the encrypted message and forward the decrypted message to the third-party financial institution access service for transaction processing associated with the target transaction.
2. The method according to claim 1, characterized in that, The message information carries the object identifier of the service object; The step of sending the encrypted message to the communication service system of the service recipient according to the message information, so that the communication service system can decrypt the encrypted message, and forward the decrypted message to the third-party financial institution access service for transaction processing associated with the target transaction, includes: Based on the object identifier in the message information, determine the communication service system of the service object to which the encrypted message is to be routed; The encrypted message is sent to the communication service system of the service object, so that the communication service system can decrypt the encrypted message and forward the decrypted message to the access service of a third-party financial institution for transaction processing associated with the target transaction.
3. The method according to claim 1 or 2, characterized in that, The decrypted message is forwarded using the following steps: From the decrypted message, obtain the financial institution identifier corresponding to the third-party financial institution access service to which the decrypted message is to be routed; Based on the financial institution identifier, determine the third-party financial institution access service to which the decrypted message is to be routed from among multiple financial institution access services; The decrypted message is forwarded to the third-party financial institution's access service for transaction processing associated with the target transaction.
4. The method according to claim 1, characterized in that, The step of format conversion and encryption of the financial transaction request message based on the message information to obtain an encrypted message includes: Based on the financial institution identifier in the message information, a target message template matching the financial institution identifier is determined from multiple candidate message templates; Based on the target message template, the message information is format-converted to obtain a converted message; The first encryption algorithm is used to digitally sign the formatted message and generate signature data. The formatted message is encrypted using a second encryption algorithm to generate a ciphertext message; The signature data and the ciphertext message are encapsulated to obtain the encrypted message.
5. The method according to claim 1, characterized in that, The client application of the target financial institution is used to perform the following operations: Receive the service status indicators of the third-party financial institution access service sent by the communication service system. The service status indicator is sent by the third-party financial institution access service during the transaction processing associated with the target transaction based on the decrypted message. The service status indicators are displayed visually.
6. The method according to claim 5, characterized in that, The method further includes: In response to triggering the first service pause component in the service status management interface of the client, a first service pause command is sent to the backend associated with the service object; The first service pause instruction is used to execute a service command script associated with the third-party financial institution access service to shut down the third-party financial institution access service.
7. The method according to claim 6, characterized in that, The front-end associated with the service object is used to perform the following operations: In response to triggering the status monitoring component in the currently displayed visualization interface, a status monitoring instruction is sent to the backend; wherein, the status monitoring instruction is used to monitor the service status of the third-party financial institution's access service; Receive service status indicators of third-party financial institution access services sent by the backend. The service status indicators are displayed in the visualization interface.
8. The method according to claim 7, characterized in that, The front end is also used to perform the following operations: In response to triggering the second service pause component in the visualization interface, a second service pause command is sent to the backend; The second service suspension instruction is used in the service command script associated with the third-party financial institution access service to shut down the third-party financial institution access service.
9. The method according to claim 7, characterized in that, The visualization interface also displays at least one of the following: Dynamic function icons; wherein, the dynamic function icons are used to indicate the transaction processing progress or risk level of the third-party financial institution's access service; Status indicator light; wherein the status indicator light is associated with multiple color codes, wherein the color codes are used to indicate the current communication status of the third-party financial institution's access service; View control; wherein, the view control is used to view the operation records within a set time period, and the operation records are used to locate the root cause of the failure of the third-party financial institution's access service.
10. The method according to claim 9, characterized in that, The front end is also used to perform the following operations: When the access service of the third-party financial institution is abnormal, the root cause of the failure and the repair suggestions associated with the root cause are displayed in the visualization interface via a pop-up window; wherein, the repair suggestions are used to indicate the strategy for repairing the access service of the third-party financial institution.
Citation Information
Patent Citations
Cross-operating-system message exchange method and device and control system
CN115834737A
Financial resource cloud access method in bank-enterprise direct connection non-hosting mode and bank-enterprise direct connection platform
CN117240897A
Enterprise-level customer information business processing system based on rsa encryption algorithm
CN117879822A
Message interaction method and device, storage medium and electronic equipment
CN119011192A
Prepositional system based on finance industry
CN1932875A