Verification mode determination method and device, equipment, medium and product
By acquiring user contextual data and using individual behavioral baseline models and machine learning models for risk scoring, the rigidity and frequent triggering of traditional identity verification methods are solved, enabling flexible risk assessment and user-friendly verification strategies.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-19
- Publication Date
- 2026-03-24
AI Technical Summary
Traditional authentication methods, while ensuring security, suffer from problems such as rigid authentication triggering rules, inability to adapt to changes, frequent triggering of strong authentication, and poor user experience.
By acquiring the user's current contextual data, baseline deviation is compared based on a pre-built individual behavior baseline model and contextual data. High-risk judgment and weighted calculation are performed using a machine learning model to output a risk score, and a flexible verification strategy is determined based on the score.
It achieves both accuracy and flexibility in risk assessment, avoiding the "one-size-fits-all" risk control approach of traditional verification methods, thus ensuring both security and improving user experience.
Smart Images

Figure CN121724628A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of artificial intelligence, big data and financial technology, and more specifically to a method, apparatus, equipment, medium and product for determining a verification method. Background Technology
[0002] When using applications such as mobile banking and securities trading, users often engage in critical financial operations (e.g., transfers, payments, changes to financial accounts), requiring identity verification to ensure security. Traditional technologies employ strong identity verification for almost all critical operations, such as SMS verification codes, facial recognition, and fingerprints combined with digital passwords. However, while ensuring security, traditional technologies have the following drawbacks: 1. Verification trigger rules are relatively simple and rigid, unable to adapt dynamically; 2. Verification trigger rules are conservative, potentially triggering inappropriate verification methods (e.g., low-risk operations triggering strong verification); 3. Verification triggers are too frequent (e.g., frequent, low-risk operations triggering multiple strong verifications), resulting in a poor user experience. Summary of the Invention
[0003] In view of the above problems, according to a first aspect of this application, a method for determining a verification method is provided, the method comprising: in response to a user initiating a key operation, acquiring current contextual data; performing a baseline deviation comparison based on a pre-constructed individual behavior baseline model and the contextual data; determining a high risk based on the contextual data and preset high-risk contextual conditions; using a machine learning model to perform a weighted calculation based on the baseline deviation comparison result and the high-risk determination result, and outputting a risk score; and determining and executing a corresponding verification strategy based on the risk score.
[0004] According to an embodiment of this application, after determining and executing the corresponding verification strategy based on the risk score, the method further includes: continuously calculating and updating the risk score based on continuously updated context data; and adjusting and executing the corresponding verification strategy based on the updated risk score.
[0005] According to an embodiment of this application, the individual behavior baseline model is trained based on the user's historical transaction habit information, historical operation habit information, historical commonly used environment information, and historical commonly used device information; the contextual data includes current transaction mode information, current key operation context information, current operation information, current environment information, and current device information; the preset high-risk context conditions include: the current environment information is determined to be a high-risk environment, and / or, the current device information is determined to be a high-risk device, and / or, the current transaction mode information is determined to be a high-risk transaction mode.
[0006] According to an embodiment of this application, determining and executing the corresponding verification strategy based on the risk score includes: determining and executing a first verification strategy in response to the risk score being in a low-risk range; determining and executing a second verification strategy in response to the risk score being in a medium-risk range; and determining and executing a third verification strategy in response to the risk score being in a high-risk range.
[0007] According to the embodiments of this application, the first verification strategy is an authentication-free strategy or a simple verification strategy, the second verification strategy is a historically commonly used verification strategy or a user preference verification strategy, and the third verification strategy is a complex verification strategy.
[0008] According to an embodiment of this application, after executing the corresponding verification strategy, the method further includes: recording the risk score, the verification strategy, and the verification result; and optimizing the machine learning model using the risk score, the verification strategy, and the verification result.
[0009] A second aspect of this application provides a verification method determination apparatus, the apparatus comprising: a data acquisition module for acquiring current contextual data in response to a user initiating a key operation; a baseline comparison module for performing a baseline deviation comparison based on a pre-built individual behavior baseline model and the contextual data; a high-risk determination module for determining high risk based on the contextual data and preset high-risk contextual conditions; a risk scoring module for using a machine learning model to perform a weighted calculation based on the baseline deviation comparison result and the high-risk determination result, and outputting a risk score; and a strategy execution module for determining and executing the corresponding verification based on the risk score.
[0010] A third aspect of this application provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method.
[0011] A fourth aspect of this application provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the method.
[0012] The fifth aspect of this application provides a computer program product including a computer program or instructions that, when executed by a processor, implement the steps of the method.
[0013] The above one or more embodiments have the following advantages or beneficial effects: The verification method provided in this application obtains current contextual data when a user initiates a critical operation. Based on a pre-built individual behavior baseline model and the contextual data, a baseline deviation comparison is performed. Furthermore, a high-risk judgment is made based on the contextual data and preset high-risk situational conditions. Then, a machine learning model is used to perform a weighted calculation based on the baseline deviation comparison result and the high-risk judgment result, outputting a risk score to achieve risk assessment. Based on the risk score, a corresponding verification strategy is determined and executed. This method can integrate multiple data sources and calculate the risk score in real time according to the user's current context to measure the magnitude of risk. Using the individual behavior baseline model as a standard, the degree to which the current operation deviates from the standard can be judged to some extent through comparison results. Combined with preset high-risk situational conditions, the accuracy of risk assessment is ensured. Using a machine learning model to calculate the risk score and execute the corresponding verification strategy ensures that the determination of the verification method has a certain degree of flexibility, avoiding the "one-size-fits-all" risk control scheme triggered by simple limit mechanisms in traditional verification methods. This ensures both verification security and user experience.
[0014] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the invention. Attached Figure Description
[0015] The above-mentioned contents, other objects, features and advantages of this application will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:
[0016] Figure 1 The illustration schematically depicts an application scenario of a verification method, apparatus, device, medium, and product according to embodiments of this application.
[0017] Figure 2 A flowchart illustrating the verification method determination method according to an embodiment of this application is shown in the schematic diagram.
[0018] Figure 3 This schematically illustrates a structural block diagram of a verification method determination device according to an embodiment of this application;
[0019] Figure 4 A block diagram schematically illustrates an electronic device suitable for implementing a verification mode determination method according to an embodiment of this application. Detailed Implementation
[0020] The embodiments of this application will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of this application. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of this application for ease of explanation. However, it will be apparent that one or more embodiments may be implemented without these specific details. Furthermore, descriptions of well-known structures and technologies are omitted in the following description to avoid unnecessarily obscuring the concepts of this application.
[0021] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0022] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0023] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).
[0024] First, the technical terms used in this application are explained and clarified as follows.
[0025] The individual behavior baseline model is a quantitative model of normal user behavior. It stores the user's historical and normalized operation data, environmental data, and device data, and establishes a unique reference standard (i.e., baseline) for normal behavior for the user.
[0026] A machine learning model is a program or decision-making machine that can learn (train) from experience and optimize itself. It consists of three basic elements: input, model structure, and output.
[0027] Traditional technologies employ strong authentication methods for almost all critical operations, such as SMS verification codes, facial recognition, and fingerprints combined with digital passwords. However, while ensuring security, traditional technologies also have the following drawbacks: 1. Verification triggering rules are relatively simple and rigid, unable to adapt dynamically; 2. Verification triggering rules are conservative, potentially triggering inappropriate verification methods (e.g., low-risk operations triggering strong verification); 3. Verification triggering is too frequent (e.g., high-frequency, low-risk user operations triggering multiple strong verifications), resulting in a poor user experience.
[0028] Based on this, embodiments of this application provide a method for determining a verification method, the method comprising: establishing an individual behavior baseline model based on the user's historical operation behavior; obtaining current contextual data in response to the user initiating a key operation; performing a baseline deviation comparison based on the contextual data and the individual behavior baseline model; determining a high risk based on the contextual data and preset high-risk contextual conditions; using a machine learning model to perform a weighted calculation based on the baseline deviation comparison result and the high-risk determination result, and outputting a risk score; and determining and executing a corresponding verification strategy based on the risk score.
[0029] The verification method provided in this application obtains current contextual data when a user initiates a critical operation. It then performs a baseline deviation comparison based on a pre-built individual behavior baseline model and the contextual data. Furthermore, it determines high risk based on the contextual data and preset high-risk scenario conditions. A machine learning model is then used to perform a weighted calculation based on the baseline deviation comparison result and the high-risk determination result, outputting a risk score to achieve risk assessment. Based on the risk score, a corresponding verification strategy is determined and executed. This method can integrate multiple data sources and calculate the risk score in real time according to the user's current context to measure the magnitude of risk. Using the individual behavior baseline model as a standard, the degree to which the current operation deviates from the standard can be determined through comparison results. Combined with preset high-risk scenario conditions, the accuracy of risk assessment is ensured. Using a machine learning model to calculate the risk score and execute the corresponding verification strategy ensures a certain degree of flexibility in determining the verification method, avoiding the "one-size-fits-all" risk control scheme triggered by simple limit mechanisms in traditional verification methods. This approach ensures both verification security and user experience.
[0030] It should be noted that the verification method determination method, apparatus, equipment, medium, and product provided in the embodiments of this application can be used in the fields of artificial intelligence technology, big data technology, and fintech technology, and can also be used in various fields other than artificial intelligence technology, big data technology, and fintech technology. The application fields of the verification method determination method, apparatus, equipment, medium, and product provided in the embodiments of this application are not limited.
[0031] In the technical solution of this application, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.
[0032] Figure 1 The illustration schematically depicts an application scenario of a verification method, apparatus, device, medium, and product according to embodiments of this application.
[0033] like Figure 1 As shown, application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.
[0034] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0035] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0036] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0037] It should be noted that the verification method determination method provided in this application embodiment can generally be executed by server 105. Correspondingly, the verification method determination device provided in this application embodiment can generally be located in server 105. The verification method determination method provided in this application embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the verification method determination device provided in this application embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.
[0038] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0039] Figure 2 A flowchart illustrating a verification method determination method according to an embodiment of this application is shown schematically.
[0040] like Figure 2 As shown, method 200 specifically includes operations S210 to S250.
[0041] In operation S210, in response to a user-initiated key operation, the current context data is obtained.
[0042] In this embodiment, critical operations refer to financial operations that may require identity verification, such as transfers, payments, and changes to financial accounts. When a user initiates a critical operation, contextual data is collected.
[0043] Optionally, before responding to a user-initiated critical operation, the method further includes: determining the critical operation in response to the user-initiated operation.
[0044] In this embodiment, when a user initiates an operation, a critical operation determination is performed. This operation can include various actions performed by the user. If the critical operation determination result indicates that the operation is critical, then the current context data is acquired (i.e., operation S210). If the critical operation determination result indicates that the operation is non-critical, then context data acquisition is not required. In other words, the user's operation at this time does not involve financial operations such as transfers, payments, or changes to financial accounts that may require identity verification; therefore, identity verification is not necessary.
[0045] For example, the contextual data includes current transaction mode information, current key operation context information, current operation information, current environment information, and current device information.
[0046] In this embodiment, the current transaction mode information may include transaction type, transaction amount range, transaction object, and transaction frequency. The current key operation context information may include the transaction information (e.g., the transaction purpose noted by the user) and the user's behavioral path within the application before the operation. The current operation information may include the navigation path involved in the current operation, the click speed of the current operation, and the input mode used in the current operation. The current environment information may include the current network type, current network identifier, current network latency, current operation location, and current operation time. The current device information may include the currently installed applications, current device model, current operating system, and current application version.
[0047] In this way, by using the current transaction mode information, current key operation context information, current operation information, current environment information, and current device information in the contextual data, the real-time information of the current user can be obtained, which facilitates the subsequent steps of risk score calculation.
[0048] In operation S220, a baseline deviation comparison is performed based on a pre-built individual behavior baseline model and the contextual data.
[0049] In this embodiment, with the user's authorization, historical user behavior can be continuously collected. The individual behavior baseline model can be formed by pre-setting some baseline data based on experience or statistical data, or it can be constructed after continuously collecting a certain amount of historical user behavior. Then, as the user's historical behavior accumulates, the individual behavior baseline model is also continuously trained and updated, so that the model is more in line with the user's personality. The individual behavior baseline model is compared with the contextual data to determine the baseline deviation. Here, various historical and commonly used data in the individual behavior baseline model can be quantified and compared with various current and real-time data in the contextual data. For example, if the current transaction object is the same as the commonly used transaction object, the corresponding comparison result is a certain value; if the current transaction object is different from the commonly used transaction object, the corresponding comparison result is another value, which facilitates the subsequent steps of risk scoring calculation.
[0050] For example, the individual behavior baseline model is trained based on historical transaction habit information, historical operation habit information, historical commonly used environment information, and historical commonly used equipment information.
[0051] In this embodiment, historical transaction habit information may include transaction type, transaction amount range, transaction object, and transaction frequency. Historical operation habit information may include navigation path, click speed, and input mode within relevant applications. Historical commonly used environment information may include commonly used network type, commonly used network identifier, historical network latency, historical operation location, and historical operation time. Historical commonly used device information may include historically installed applications, commonly used device models, commonly used operating systems, and application versions. The above data information may be collected as needed, with user authorization.
[0052] In this way, by using historical trading habits, historical operating habits, historical commonly used environments, and historical commonly used equipment information, a standard related to the individual user can be established, which is beneficial for subsequent steps in calculating risk scores and verifying the accuracy of strategy decisions.
[0053] In operation S230, a high-risk determination is made based on the scenario data and preset high-risk scenario conditions.
[0054] In this embodiment, some data in the contextual data inherently possess risk assessment significance. Therefore, risk assessment can be performed directly using certain data even without baseline comparison. Furthermore, judging these data solely through comparison with individual behavioral baseline models may not be accurate enough. However, by combining this with the design of preset high-risk scenario conditions, subsequent risk scoring can be ensured to be more accurate.
[0055] For example, the preset high-risk scenario conditions include: the current environment information is determined to be a high-risk environment, and / or the current device information is determined to be a high-risk device, and / or the current transaction mode information is determined to be a high-risk transaction mode.
[0056] In this embodiment, data from the current environment information can be comprehensively judged, such as network identifier security information (whether it is a known secure network identifier) and geographical location security information (whether it is a high-risk area). When the network identifier is unknown or insecure, and / or the geographical location is a high-risk area, it is determined to be a high-risk environment. Data from the current device information can be comprehensively judged, such as device permission status (original factory status or permission unlocking status with certain risks). When the device is in a non-original factory permission unlocking status, it is determined to be a high-risk device. Data from the current transaction pattern information can be comprehensively judged, such as transaction time (whether it is in the early morning or a sensitive time) and transaction frequency (whether it is an abnormal transaction frequency). When the transaction time is in the early morning or a sensitive event, and / or the transaction frequency is abnormal, it is determined to be a high-risk transaction pattern. The above judgment rules can be designed with specific judgment thresholds as needed, and the thresholds can also be adjusted as needed. For example, corresponding to high consumption periods such as holidays, the judgment threshold for abnormal transaction frequency can be appropriately relaxed.
[0057] Specifically, if the current environmental information is determined to be a high-risk environment, and / or the current equipment information is determined to be a high-risk equipment, and / or the current transaction mode information is determined to be a high-risk transaction mode, then the risk assessment result is a high-risk transaction mode. Otherwise, the risk assessment result is a non-high-risk scenario. High-risk scenarios can be assigned higher weights, while non-high-risk scenarios can be assigned lower weights.
[0058] In this way, by pre-setting high-risk scenario conditions, it is possible to directly determine whether a specific scenario is high-risk (such as high-risk environment, high-risk equipment, high-risk transaction mode, etc.) based on some data in the scenario data, so that the risk score calculation in subsequent steps can more comprehensively determine the level of risk and improve the accuracy of risk score.
[0059] When operating S240, a machine learning model is used to perform a weighted calculation based on the baseline deviation comparison results and the high-risk determination results to output a risk score.
[0060] In this embodiment, the machine learning model can select an appropriate model as needed, such as an ensemble learning model. Based on the deviation comparison results and the high-risk determination results, the model assigns weights to these results and then performs a weighted calculation to obtain a risk score.
[0061] In operation S250, the corresponding verification strategy is determined and executed based on the risk score.
[0062] In this embodiment of the application, the corresponding verification strategy is determined and executed based on the risk score output by operation S240. For example, the risk score can be 0 to 100 points, so different ranges of risk scores can be associated with different verification strategies.
[0063] For example, operation S250 includes: determining and executing a first verification strategy in response to the risk score being in a low-risk range; determining and executing a second verification strategy in response to the risk score being in a medium-risk range; and determining and executing a third verification strategy in response to the risk score being in a high-risk range.
[0064] In this embodiment, the risk score is divided into three ranges: high, medium, and low. The specific score division can be designed as needed. For the low-risk range, a first verification strategy can be implemented, such as reducing the number of verifications and using a simpler verification method, such as fingerprint verification. For the medium-risk range, a second verification strategy can be implemented, such as some relatively stronger verification methods, such as facial recognition verification. For the high-risk range, a third verification strategy can be implemented, such as some complex or hybrid strong verification methods, such as facial recognition combined with voice recognition.
[0065] In this way, the risk score range can be divided into high, medium and low risk, and corresponding verification strategies can be implemented to balance security and user experience during the transaction process.
[0066] Furthermore, the first verification strategy is an authentication-free strategy or a simple verification strategy, the second verification strategy is a historically commonly used verification strategy or a user preference verification strategy, and the third verification strategy is a complex verification strategy.
[0067] In this embodiment, when the risk score is in the low-risk range, an exemption strategy or a simple verification strategy is determined and executed. The exemption strategy eliminates verification steps in the current critical operation, while the simple verification strategy uses relatively simple verification methods, such as fingerprint verification. When the risk score is in the medium-risk range, a historically frequently used verification strategy or a user-preferred verification strategy is determined and executed. The historically frequently used verification strategy determines the user's preferred verification method as the current verification method, while the user-preferred verification strategy determines the current verification method based on the user's self-defined verification method priority or historical verification method adjustment information (e.g., the user frequently switches to fingerprint verification when the verification method can be adjusted in the past). When the risk score is in the high-risk range, a complex verification strategy is determined and executed. A complex verification strategy can also be understood as a hybrid verification strategy, such as a combination of fingerprint verification and facial verification, or facial verification and voice recognition, to ensure that the user's identity meets the authorization requirements for the current operation.
[0068] Thus, the first verification strategy allows users to skip verification or use only simple verification when performing low-risk operations, avoiding frequent verification triggers and improving the user experience during low-risk operations. The second verification strategy allows users to use commonly used or preferred verification methods according to their habits or preferences when performing medium-risk operations, improving verification efficiency and ease of use, and also improving the user experience during medium-risk operations to some extent. The third verification strategy requires users to use a more conservative and complex verification strategy when performing high-risk operations to ensure the accuracy and security of verification, and also allows resources to be concentrated on high-risk operations, improving risk control efficiency.
[0069] Optionally, in response to the risk score falling within the high-risk range, the method further includes: determining whether to trigger a manual review mechanism based on the current transaction pattern information in the contextual data. For example, the current transaction pattern information might indicate that the transaction amount has reached a set threshold or other data has reached a preset threshold, requiring manual review to confirm the security of the current operation. This ensures that clearly high-risk operations are covered by manual review, thereby maximizing security.
[0070] Furthermore, after operation S250, the method further includes: continuously calculating and updating the risk score based on continuously updated contextual data; and adjusting and executing the corresponding verification strategy based on the updated risk score.
[0071] In this embodiment, after determining and executing the verification strategy based on the risk score, it is also necessary to continuously update the contextual data to continuously calculate and update the risk score. Based on the updated risk score, the verification strategy is dynamically adjusted in real time. For example, during a critical operation, if operation S250 determines that the risk score is in a low-risk range, a verification-free strategy is determined and executed. However, if the user suddenly changes to an unfamiliar network identifier, increases the transaction amount, and changes the payee to an unfamiliar recipient, the updated risk score may now be in a medium-risk (or high-risk) range. Therefore, the verification strategy needs to be adjusted accordingly.
[0072] This enables real-time dynamic adjustment of the verification strategy based on the risk score, resulting in better practicality and flexibility.
[0073] Furthermore, after executing the corresponding verification strategy, the method further includes: recording the risk score, the verification strategy, and the verification result; and optimizing the machine learning model using the risk score, the verification strategy, and the verification result.
[0074] In this embodiment of the application, after each execution of the corresponding verification strategy, the risk score and verification strategy are recorded, and the user's verification result (verification successful, verification failed, verification canceled, blocked by risk control, etc.) is obtained. Optionally, user evaluation (user's evaluation of the convenience of the verification process) can also be recorded. These risk scores, verification strategies, verification results and user evaluations are input into the machine learning model to optimize and train the machine learning model.
[0075] In this way, through continuous feedback and optimization learning, the machine learning model can continuously improve the accuracy of calculating risk scores.
[0076] The following describes some exemplary scenarios of using the verification method determination method of the embodiments of this application.
[0077] Scenario 1: At 10:00 AM, a user logs into mobile banking via fingerprint at home using their usual Wi-Fi and transfers 5,000 yuan to their pre-linked spouse's account (a common historical transaction). System identification: The time of day is normal, the location is normal, the network is trustworthy, the device is secure, the recipient is familiar, and the amount is within the normal range. The calculated risk score is extremely low, placing it in the low-risk range. Therefore, the transfer can be completed directly without verification.
[0078] Scenario 2: A user is traveling on business and connects to the hotel's Wi-Fi. At 3 PM, they pay 10,000 yuan to a new supplier (with a note indicating it's for business procurement). The system recognizes the change in location, unfamiliar network, and new payee. The calculated risk score falls within the medium-risk range. Therefore, it prompts "This transaction requires enhanced verification" and uses the most convenient and commonly used facial recognition verification method for the user.
[0079] Scenario 3: At 1 AM, a user connects to a public Wi-Fi network in an unfamiliar location and attempts to transfer a large sum of money (the transaction amount is close to the account balance) to a new overseas account. The system identifies the following: abnormal time, high-risk location, high-risk network, new recipient, and huge amount. The calculated risk score is extremely high, placing the user in a high-risk range. Therefore, the system can enforce dual verification methods of "facial recognition and SMS verification code" and display a prominent risk warning. Under certain conditions, the system can also trigger risk control in the background, prompting manual review.
[0080] The verification method provided in the above embodiments of this application acquires current contextual data when a user initiates a critical operation. Based on a pre-built individual behavior baseline model and the contextual data, a baseline deviation comparison is performed. A high-risk assessment is then made based on the contextual data and preset high-risk scenario conditions. A machine learning model is then used to perform a weighted calculation based on the baseline deviation comparison result and the high-risk assessment result, outputting a risk score to achieve risk judgment. Based on the risk score, a corresponding verification strategy is determined and executed. This method can integrate multiple data sources and calculate the risk score in real time according to the user's current context to measure the magnitude of risk. Using the individual behavior baseline model as a standard, the degree to which the current operation deviates from the standard can be judged to some extent through comparison results. Combined with preset high-risk scenario conditions, the accuracy of risk judgment is ensured. Using a machine learning model to calculate the risk score and execute the corresponding verification strategy ensures that the determination of the verification method has a certain degree of flexibility, avoiding the "one-size-fits-all" risk control scheme triggered by simple limit mechanisms in traditional verification methods. This ensures both verification security and user experience.
[0081] Specifically, the verification method provided in this application brings the following beneficial effects:
[0082] 1. Continuously update scenario data and risk scores, and dynamically adjust verification strategies in real time based on risk scores, resulting in better practicality and flexibility.
[0083] 2. By leveraging historical trading habits, operational habits, frequently used environments, and commonly used devices within the individual behavioral baseline model, a user-specific standard can be established. This facilitates subsequent steps in risk scoring calculation and verifying the accuracy of strategy decisions. Real-time user information can be obtained from contextual data, including current trading patterns, key operational contexts, operational details, environmental conditions, and device information, enabling subsequent risk scoring calculations. By pre-setting high-risk scenario conditions, risk can be directly assessed based on data within the contextual data, further aiding in risk scoring calculations.
[0084] 3. Risk scores are categorized into high, medium, and low risks, with corresponding verification strategies applied to balance security and user experience. The first verification strategy allows users to skip verification or use simpler methods for low-risk operations, preventing frequent verification triggers and improving the user experience. The second strategy allows users to use familiar or preferred verification methods for medium-risk operations, improving efficiency and ease of use, further enhancing the user experience. The third strategy requires users to use a more conservative and complex verification strategy for high-risk operations to ensure accuracy and security, allowing resources to be concentrated on high-risk operations and improving risk control efficiency.
[0085] 4. Through continuous feedback and optimization learning, the machine learning model continuously improves the accuracy of risk scoring calculation.
[0086] Based on the verification method described above, this application also provides a verification method determination apparatus. The following will be combined with... Figure 3 The device is described in detail.
[0087] Figure 3 The diagram illustrates the structure of a verification method determination device according to an embodiment of this application.
[0088] like Figure 3 As shown, the device 300 in this embodiment includes a data acquisition module 310, a baseline comparison module 320, a high-risk determination module 330, a risk scoring module 340, and a strategy execution module 350.
[0089] The data acquisition module 310 is used to acquire current contextual data in response to a key operation initiated by the user. In one embodiment, the data acquisition module 310 can be used to perform the operation S210 described above, which will not be repeated here.
[0090] The baseline comparison module 320 is used to perform baseline deviation comparison based on a pre-built individual behavior baseline model and the contextual data. In one embodiment, the baseline comparison module 320 can be used to perform the operation S220 described above, which will not be repeated here.
[0091] The high-risk determination module 330 is used to determine high risk based on the scenario data and preset high-risk scenario conditions. In one embodiment, the high-risk determination module 330 can be used to perform the operation S230 described above, which will not be repeated here.
[0092] The risk scoring module 340 is used to perform a weighted calculation based on the baseline deviation comparison results and the high-risk determination results using a machine learning model, and outputs a risk score. In one embodiment, the risk scoring module 340 can be used to perform the operation S240 described above, which will not be repeated here.
[0093] The strategy execution module 350 is used to determine and execute the corresponding verification strategy based on the risk score. In one embodiment, the strategy execution module 350 can be used to execute the operation S250 described above, which will not be repeated here.
[0094] According to an embodiment of this application, the apparatus 300 further includes a strategy adjustment module, which is used to continuously calculate and update the risk score based on continuously updated context data; and to adjust and execute the corresponding verification strategy based on the updated risk score.
[0095] According to an embodiment of this application, the individual behavior baseline model in the baseline comparison module 320 is trained based on the user's historical transaction habit information, historical operation habit information, historical commonly used environment information, and historical commonly used device information; the contextual data in the baseline comparison module 320 and the high-risk determination module 330 includes current transaction mode information, current key operation context information, current operation information, current environment information, and current device information; the preset high-risk contextual conditions in the high-risk determination module 330 include: the current environment information is determined to be a high-risk environment, and / or, the current device information is determined to be a high-risk device, and / or, the current transaction mode information is determined to be a high-risk transaction mode.
[0096] According to an embodiment of this application, the strategy execution module 350 is specifically configured to determine and execute a first verification strategy in response to the risk score being in a low-risk range; determine and execute a second verification strategy in response to the risk score being in a medium-risk range; and determine and execute a third verification strategy in response to the risk score being in a high-risk range.
[0097] According to an embodiment of this application, the first verification strategy in the strategy execution module 350 is an verification-free strategy or a simple verification strategy, the second verification strategy is a historically commonly used verification strategy or a user preference verification strategy, and the third verification strategy is a complex verification strategy.
[0098] According to an embodiment of this application, the apparatus 300 further includes a model optimization module for recording the risk score, the verification strategy, and the verification result; and optimizing the machine learning model using the risk score, the verification strategy, and the verification result.
[0099] According to embodiments of this application, any multiple modules among the data acquisition module 310, baseline comparison module 320, high-risk determination module 330, risk scoring module 340, policy execution module 350, policy adjustment module, and model optimization module can be merged into one module, or any one of these modules can be split into multiple modules. Alternatively, at least some of the functions of one or more of these modules can be combined with at least some of the functions of other modules and implemented in one module. According to embodiments of this application, at least one of the data acquisition module 310, baseline comparison module 320, high-risk determination module 330, risk scoring module 340, policy execution module 350, policy adjustment module, and model optimization module can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the data acquisition module 310, baseline comparison module 320, high-risk determination module 330, risk scoring module 340, strategy execution module 350, strategy adjustment module, and model optimization module can be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.
[0100] Figure 4 A block diagram schematically illustrates an electronic device suitable for implementing a verification mode determination method according to an embodiment of this application.
[0101] like Figure 4 As shown, an electronic device 400 according to an embodiment of this application includes a processor 401, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 402 or a program loaded from a storage portion 408 into a random access memory (RAM) 403. The processor 401 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 401 may also include onboard memory for caching purposes. The processor 401 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this application.
[0102] RAM 403 stores various programs and data required for the operation of electronic device 400. Processor 401, ROM 402, and RAM 403 are interconnected via bus 404. Processor 401 executes various operations of the method flow according to embodiments of this application by executing programs in ROM 402 and / or RAM 403. It should be noted that the programs may also be stored in one or more memories other than ROM 402 and RAM 403. Processor 401 may also execute various operations of the method flow according to embodiments of this application by executing programs stored in said one or more memories.
[0103] According to embodiments of this application, the electronic device 400 may further include an input / output (I / O) interface 405, which is also connected to a bus 404. The electronic device 400 may also include one or more of the following components connected to the input / output (I / O) interface 405: an input section 406 including a keyboard, mouse, etc.; an output section 407 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 408 including a hard disk, etc.; and a communication section 409 including a network interface card such as a LAN card, modem, etc. The communication section 409 performs communication processing via a network such as the Internet. A drive 410 is also connected to the input / output (I / O) interface 405 as needed. A removable medium 411, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 410 as needed so that computer programs read from it can be installed into the storage section 408 as needed.
[0104] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of this application.
[0105] According to embodiments of this application, the computer-readable storage medium can be a non-volatile computer-readable storage medium, such as including but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this application, the computer-readable storage medium may include ROM 402 and / or RAM 403 and / or one or more memories other than ROM 402 and RAM 403 described above.
[0106] Embodiments of this application also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to enable the computer system to implement the verification method determination method provided in the embodiments of this application.
[0107] When the computer program is executed by the processor 401, it performs the functions defined in the system / apparatus of this application embodiment. According to the embodiments of this application, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0108] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and downloaded and installed via communication section 409, and / or installed from removable medium 411. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0109] In such an embodiment, the computer program can be downloaded and installed from a network via communication section 409, and / or installed from removable medium 411. When the computer program is executed by processor 401, it performs the functions defined in the system of this application embodiment. According to embodiments of this application, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0110] According to embodiments of this application, program code for executing the computer programs provided in the embodiments of this application can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0111] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0112] Those skilled in the art will understand that the features described in the various embodiments of this application can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this application. In particular, the features described in the various embodiments of this application can be combined and / or combined in various ways without departing from the spirit and teachings of this application. All such combinations and / or combinations fall within the scope of this application.
Claims
1. A method for determining a verification method, characterized in that, The method includes: Responding to key user actions, obtain current contextual data; Baseline deviation comparison is performed based on a pre-constructed individual behavior baseline model and the contextual data; High-risk assessment is made based on the aforementioned contextual data and preset high-risk contextual conditions; A risk score is output by weighting the baseline deviation comparison results and the high-risk determination results using a machine learning model. The corresponding verification strategy is determined and executed based on the risk score.
2. The method according to claim 1, characterized in that, After determining and executing the corresponding verification strategy based on the risk score, the method further includes: The risk score is continuously calculated and updated based on continuously updated contextual data; Based on the updated risk score, the corresponding verification strategy is adjusted and implemented.
3. The method according to claim 1, characterized in that, The individual behavior baseline model is trained based on the user's historical transaction habits, historical operation habits, historical commonly used environment information, and historical commonly used device information; the contextual data includes current transaction mode information, current key operation context information, current operation information, current environment information, and current device information; The preset high-risk scenario conditions include: the current environment information is determined to be a high-risk environment, and / or the current device information is determined to be a high-risk device, and / or the current transaction mode information is determined to be a high-risk transaction mode.
4. The method according to claim 1, characterized in that, The step of determining and executing the corresponding verification strategy based on the risk score includes: In response to the risk score being in the low-risk range, a first verification strategy is determined and executed. In response to the risk score being in the medium-risk range, a second verification strategy is determined and executed. In response to the risk score being in the high-risk range, a third verification strategy is determined and implemented.
5. The method according to claim 4, characterized in that, The first verification strategy is an authentication-free strategy or a simple verification strategy; the second verification strategy is a historically commonly used verification strategy or a user preference verification strategy; and the third verification strategy is a complex verification strategy.
6. The method according to claim 1, characterized in that, After executing the corresponding verification strategy, the following is also included: Record the risk score, the verification strategy, and the verification results; The machine learning model is optimized using the risk score, the verification strategy, and the verification results.
7. A verification method determination device, characterized in that, The device includes: The data acquisition module is used to obtain current contextual data in response to key user actions. The baseline comparison module is used to perform baseline deviation comparison based on a pre-built individual behavior baseline model and the contextual data; The high-risk determination module is used to determine high risk based on the scenario data and preset high-risk scenario conditions; The risk scoring module is used to perform a weighted calculation based on the baseline deviation comparison results and the high-risk judgment results using a machine learning model, and output a risk score. The strategy execution module is used to determine and execute the corresponding verification based on the risk score.
8. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 6.
10. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 6.