Merchant intelligent transaction risk control management system based on table structure finite-state machine

The merchant intelligent transaction risk control management system, which uses a table-structured finite state machine, dynamically adjusts risk control strategies, solving the problem that existing technologies cannot specifically adjust risk control strategies, and improving the accuracy of transaction risk identification and system efficiency.

CN121724657AInactive Publication Date: 2026-03-24SHENZHEN HUIYI COMPUTER CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-25
Publication Date
2026-03-24
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure CN121724657A_ABST
    Figure CN121724657A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of risk control management, in particular to a merchant intelligent transaction risk control management system based on a table structure finite-state machine. The risk control configuration module is used for determining a transaction request category according to the transaction mode deviation degree and the commodity transaction adaptation degree, and determining to carry out transaction independent matching or carry out transaction combination matching based on the transaction matching degree according to a risk control state so as to determine a processing batch; the risk control analysis module is used for carrying out optimization processing or carrying out secondary judgment based on a risk control instability coefficient according to the characteristic drift coefficient of the pre-query node and the coincident transaction quantity judgment; the optimization execution module is used for adjusting the number of the pre-query nodes based on the risk identification gap rate to obtain the query nodes, and determining whether to adjust the query frequency or risk control checking time based on the memory usage rate of the query nodes based on the adjustment comparison value; and an abnormity identification module. The accuracy of transaction risk identification can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of risk control management technology, and in particular to a merchant intelligent transaction risk control management system based on a table-structured finite state machine. Background Technology

[0002] With the explosive growth of e-commerce, mobile payment, and online transactions, merchants face numerous risks such as fraudulent transactions and payment security, leading to increased financial losses and rising operating costs. Therefore, improving the accuracy of transaction risk identification is a technical problem that urgently needs to be solved by those skilled in the art.

[0003] Chinese Patent Publication No. CN119205331A discloses a transaction risk control method and system. The method includes: obtaining platform transaction information through a transaction risk control system; setting up a transaction data transmission and processing mechanism to process and detect the platform transaction information and obtain the transaction information transmission results; establishing an information feature analysis model based on the platform transaction information, and using the information feature analysis model to analyze the transaction information transmission results to obtain transaction feature information of the online trading platform; and analyzing the platform transaction status based on the transaction feature information and the platform transaction information to ensure the risk control and safe operation of the online trading platform. However, the above solution has the following problems: it cannot adjust the risk control strategy according to the actual status of the transaction request, resulting in insufficient accuracy in transaction risk identification. Summary of the Invention

[0004] To address this issue, the present invention provides a merchant intelligent transaction risk control management system based on a table-structured finite state machine, which overcomes the problem in the prior art that the risk control strategy cannot be adjusted according to the actual state of the transaction request, resulting in insufficient accuracy in transaction risk identification.

[0005] To achieve the above objectives, the present invention provides a merchant intelligent transaction risk control management system based on a table-structured finite state machine, comprising: The transaction acquisition module is used to acquire several transaction requests; The risk control configuration module, which is connected to the transaction acquisition module, is used to determine the transaction request category based on the transaction mode deviation and the commodity transaction adaptability, and to determine whether to perform individual transaction matching or transaction combination matching based on the transaction matching degree to determine the processing batch based on the risk control status; wherein, the risk control status is determined based on the proportion of a certain type of transaction request and the load anomaly degree; The risk control analysis module, which is connected to the risk control configuration module, is used to determine the number of query nodes based on the degree of abnormal impact, and to determine the pre-query nodes based on the combination of related nodes or the node impact value based on the degree of association redundancy and risk coupling. It also determines whether to perform optimization processing or make a secondary judgment based on the characteristic drift coefficient and the number of matching transactions of the pre-query nodes. An optimization execution module, which is connected to the risk control analysis module, is used to adjust the number of pre-query nodes based on the risk identification gap rate to obtain query nodes during optimization processing, and to determine whether to adjust the query frequency or risk control verification time based on the memory usage rate of the query nodes based on the adjustment comparison value. An anomaly identification module, which is connected to the risk control configuration module, the risk control analysis module, and the optimization execution module, is used to identify anomalies in the risk control stages of the table structure finite state machine based on the query content of each query node within the risk control verification time. The risk control stages include the receiving account risk control stage, the receiving transaction risk control stage, the expenditure account risk control stage, and the expenditure transaction risk control stage.

[0006] Furthermore, the risk control configuration module determines that transaction requests with a transaction mode deviation greater than or equal to a preset transaction mode deviation or a commodity transaction adaptability less than a preset commodity transaction adaptability are classified as a type of transaction request. The risk control configuration module classifies transaction requests that have a transaction mode deviation less than the preset transaction mode deviation and a commodity transaction suitability greater than or equal to the preset commodity transaction suitability as Class II transaction requests.

[0007] Furthermore, the risk control configuration module responds to risk control states where the proportion of a certain type of transaction request is greater than or equal to a preset proportion of a certain type of transaction request or the load anomaly degree is greater than or equal to a preset load anomaly degree, and performs transaction combination matching based on the transaction matching degree; The risk control configuration module responds to risk control states where the proportion of a certain type of transaction request is less than the preset proportion of a certain type of transaction request and the load anomaly degree is less than the preset load anomaly degree, and performs individual transaction matching.

[0008] Furthermore, the risk control analysis module determines the number of query nodes based on the degree of anomaly impact; The number of query nodes corresponding to a single processing batch is positively correlated with the degree of anomaly impact corresponding to that processing batch.

[0009] Furthermore, if the risk control analysis module responds with a correlation redundancy greater than or equal to a preset correlation redundancy or a risk coupling degree greater than or equal to a preset risk coupling degree, it determines the pre-query node based on the combination of correlation nodes. The risk control analysis module responds with a redundancy degree less than the preset redundancy degree and a risk coupling degree less than the preset risk coupling degree, and determines the pre-query node based on the node influence value.

[0010] Furthermore, if the risk control analysis module responds with a feature drift coefficient greater than or equal to a preset feature drift coefficient or the number of matching transactions is less than a preset number of matching transactions, it determines that optimization processing should be performed.

[0011] Furthermore, if the risk control analysis module's response feature drift coefficient is less than the preset feature drift coefficient and the number of matching transactions is greater than or equal to the preset number of matching transactions, a secondary determination is made based on the risk control instability coefficient. The risk control analysis module responds when the risk control instability coefficient is greater than or equal to the preset risk control instability coefficient, and then performs a secondary judgment for optimization.

[0012] Furthermore, the optimization execution module adjusts the number of pre-query nodes based on the risk identification gap rate; The increase in the number of pre-query nodes corresponding to a single processing batch is positively correlated with the risk identification gap rate corresponding to that processing batch.

[0013] Furthermore, the optimization execution module adjusts the query frequency or risk control verification time based on memory usage for query nodes whose adjustment comparison value is less than the preset adjustment comparison value.

[0014] Furthermore, if the optimized execution module responds to a memory usage rate that is less than a preset memory usage rate, it determines to reduce the query frequency. If the optimized execution module responds to a memory usage rate greater than or equal to a preset memory usage rate, it determines to increase the risk control verification time.

[0015] Compared with the prior art, the beneficial effects of the present invention are that, in the technical solution of the present invention, the risk correlation strength of the current transaction environment and the real-time processing redundancy of the risk control system are effectively reflected by the proportion of a type of transaction request and the degree of load anomaly. Then, based on the risk control status, the individual matching of transactions or the combination matching of transactions based on the matching degree are adaptively selected, which is conducive to improving the risk interception coverage and processing efficiency of the risk control system, while reducing the misjudgment rate of normal transactions and the system operating cost.

[0016] Furthermore, this invention effectively reflects the risk level and transaction characteristic correlation depth of a single processing batch through the anomaly impact degree, and then determines the number of query nodes based on the anomaly impact degree. This is conducive to achieving differentiated and precise allocation of risk control query resources, thereby improving the risk control analysis depth and identification accuracy of high-risk batches, while reducing resource redundancy consumption of low-risk batches and ensuring the overall operating efficiency of the system.

[0017] Furthermore, this invention effectively reflects the resource redundancy level of the risk control query node cluster and the correlation coupling strength of the query tasks through association redundancy and risk coupling. Then, based on the combination of associated nodes or based on the node influence value, the pre-query nodes are determined, which helps to streamline invalid query nodes, integrate overlapping resources and associated tasks, thereby reducing system computing power consumption and database access pressure, reducing query latency, avoiding duplicate queries and resource waste, improving the resource utilization efficiency of the node cluster, optimizing the response speed of risk control decisions, and ensuring the accuracy and reliability of query results.

[0018] Furthermore, this invention effectively reflects the volatility of abnormal transaction characteristics and the sufficiency of matching with historical similar transactions by using feature drift coefficients and the number of matching transactions. Then, optimization processing is performed based on the feature drift coefficients and the number of matching transactions of the pre-query node, or a secondary judgment is made based on the risk control instability coefficient. This helps to avoid the risk control misjudgment and missed judgment risks caused by feature failure, insufficient samples, or node instability in advance, thereby improving the accuracy and dynamic adaptability of transaction risk control management and improving the reliability of risk identification capabilities.

[0019] Furthermore, this invention effectively reflects the completeness and comprehensiveness of the pre-query nodes' coverage of abnormal transaction states by using the risk identification gap rate. Based on the risk identification gap rate, the number of pre-query nodes is adjusted, which helps to accurately match node resources with risk identification needs, avoid risk omissions due to insufficient number of nodes or efficiency losses caused by node redundancy, thereby improving the coverage of the pre-query node combination for various abnormal risk control stages, strengthening the risk control system's ability to identify complex transaction anomalies, and ultimately achieving a dynamic balance between risk control accuracy and execution efficiency. Attached Figure Description

[0020] Figure 1 This is a module connection diagram of the merchant intelligent transaction risk control management system based on a table-structured finite state machine according to the present invention; Figure 2 This is a flowchart illustrating the present invention's method for determining whether to perform individual transaction matching or combined transaction matching based on transaction matching degree according to risk control status. Figure 3 This is a flowchart illustrating the process of determining the pre-query node based on the combination of related nodes or the influence value of nodes according to the redundancy and risk coupling of the present invention. Figure 4 This is a flowchart illustrating the optimization process based on the characteristic drift coefficient of the pre-query node and the number of matching transactions, or the secondary determination based on the risk control instability coefficient, as described in this invention. Detailed Implementation

[0021] To make the objectives and advantages of the present invention clearer, the present invention will be further described below with reference to embodiments; it should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.

[0022] Preferred embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0023] Please see Figures 1 to 4 As shown, this invention provides a merchant intelligent transaction risk control management system based on a table-structured finite state machine, comprising: The transaction acquisition module is used to acquire several transaction requests; The risk control configuration module, which is connected to the transaction acquisition module, is used to determine the transaction request category based on the transaction mode deviation and the commodity transaction adaptability, and to determine whether to perform individual transaction matching or transaction combination matching based on the transaction matching degree to determine the processing batch based on the risk control status; wherein, the risk control status is determined based on the proportion of a certain type of transaction request and the load anomaly degree; The risk control analysis module, which is connected to the risk control configuration module, is used to determine the number of query nodes based on the degree of abnormal impact, and to determine the pre-query nodes based on the combination of related nodes or the node impact value based on the degree of association redundancy and risk coupling. It also determines whether to perform optimization processing or make a secondary judgment based on the characteristic drift coefficient and the number of matching transactions of the pre-query nodes. An optimization execution module, which is connected to the risk control analysis module, is used to adjust the number of pre-query nodes based on the risk identification gap rate to obtain query nodes during optimization processing, and to determine whether to adjust the query frequency or risk control verification time based on the memory usage rate of the query nodes based on the adjustment comparison value. An anomaly identification module, which is connected to the risk control configuration module, the risk control analysis module, and the optimization execution module, is used to identify anomalies in the risk control stages of the table structure finite state machine based on the query content of each query node within the risk control verification time. The risk control stages include the receiving account risk control stage, the receiving transaction risk control stage, the expenditure account risk control stage, and the expenditure transaction risk control stage.

[0024] The application scenario of this invention is transaction risk monitoring. This invention utilizes several historical records, each of which records at least one transaction risk monitoring process, including the deviation of the transaction pattern, the adaptability of the commodity transaction, the proportion of a certain type of transaction request, and the load anomaly. Each historical record also has a corresponding qualified mark, which records whether the transaction risk monitoring process meets the user's needs. The qualified mark can be recorded manually. The qualified mark records whether the historical record meets the user's needs. It is understood that determining whether the user's needs are met based on self-defined indicators (e.g., the number of anomalies) is a method that is already mastered by those skilled in the art and will not be elaborated here. The number of anomalies is the cumulative number of transaction requests that are judged as "abnormal" but actually have no risk after risk control verification, or judged as "normal" but actually have risks.

[0025] A risk control check determines a transaction to be "abnormal" because the existence of a single transaction request indicates an abnormal status during a risk control phase. A single transaction request is a request for a single receiving account to receive funds from a single spending account. Each transaction request corresponds to a transaction request information, which includes, but is not limited to, the spending account, the receiving account, the transaction amount, and the IP address. This invention sets up several risk control query nodes, which are respectively connected to the risk control configuration module, risk control analysis module, optimization execution module, and anomaly identification module. When each node performs a risk query task, it will simultaneously establish connections with multiple databases and initiate queries, and specifically extract feature data related to the four risk control stages, such as account registration duration, remaining days of document validity, consistency between mobile phone number real name and account real name, and transaction frequency. When identifying anomalies in the risk control stages of a finite state machine based on the query content of each query node within the risk control verification period, each query node extracts the unique feature data corresponding to each stage of the transaction request through multiple database connections within the risk control verification period. Each query node uses the extracted feature data of a single risk control stage in each query to obtain the judgment result of a single risk control stage through the pre-trained model of that risk control stage. The result is either "normal" or "abnormal". When determining the "normal" or "abnormal" state of a single stage, the judgment rule of "any node being abnormal means the stage is abnormal" is adopted. If any query node in the same risk control stage is judged as "abnormal", then the stage is determined to be in an abnormal state; otherwise, it is in a normal state. When any risk control stage is in an abnormal state, an anomaly warning is issued.

[0026] The pre-trained model corresponding to a single risk control stage is a binary classification model trained with the feature data of that risk control stage as input and "(normal / abnormal)" as output. The historical labeled data consists of the historical feature data of that stage and the corresponding manually confirmed "normal / abnormal" labels. The training of the pre-trained model is a common technique used by those skilled in the art, and will not be elaborated on in detail.

[0027] For a single transaction request, the table-structured finite state machine starts from the risk control stage of the receiving account (initial state). The risk control analysis module drives the query node to extract the specific features of the current stage and complete the "normal / abnormal" judgment. The result is passed as an input signal to the state machine. The state machine matches the next state and the action corresponding to "current stage + input signal" according to the preset state transition table. If the input is "normal", it enters the next risk control stage (e.g., receiving account → receiving transaction history → expenditure account → expenditure transaction history). If the input is "abnormal", it directly enters the abnormal warning state, triggers the warning and terminates the process. If all stages are judged as "normal", the process ends and the transaction is allowed to execute. The preset state transition table is the basis for the table-structured finite state machine to implement the risk control stage. The core configuration table of the automated workflow clearly records the corresponding mapping relationship of four key pieces of information in a fixed format: "current risk control stage, query node judgment input, next stage, and execution action". The current risk control stage includes four core stages: receiving account, receiving transaction history, expenditure account, and expenditure transaction history, as well as an abnormal warning status. The query node judgment input is only of two types: "normal (all nodes judged to be normal)" or "abnormal (any node judged to be abnormal)". The table presets the next workflow stage corresponding to different stages with different judgment results (e.g., if the receiving account stage is judged to be normal, it enters the receiving transaction history stage; if any stage is judged to be abnormal, it directly enters the abnormal warning status). This is technical content that is easy for those skilled in the art to understand, and will not be elaborated further.

[0028] Specifically, the risk control configuration module determines that transaction requests with a transaction mode deviation greater than or equal to a preset transaction mode deviation or a commodity transaction adaptability less than a preset commodity transaction adaptability are classified as a type of transaction request. The risk control configuration module classifies transaction requests that have a transaction mode deviation less than the preset transaction mode deviation and a commodity transaction suitability greater than or equal to the preset commodity transaction suitability as Class II transaction requests.

[0029] Specifically, for a single transaction request, the receiving account and the expenditure account corresponding to the transaction request are respectively recorded as the target receiving account and the target expenditure account; The formula for calculating the deviation degree D of the trading pattern is: D = max{|A−A30| / A30,|F−F30| / F30} × 100%; Where A is the transaction amount corresponding to the transaction request, A30 is the average transaction amount corresponding to each transaction request of the target receiving account in the past 30 days, F is the number of transactions of the target receiving account in the 24 hours before the current time, and the transactions include receipts and payments; F is the ratio of the number of transactions of the target receiving account in the 30 days before the current time to 30. The product transaction suitability is the average of the suitability coefficients corresponding to each product in the transaction request. The suitability coefficient for a single product is calculated as follows: 1 - |Actual transaction amount - Product base amount| / Product base amount × First weight coefficient + Number of transactions corresponding to delivery addresses that appear ≥ 3 times / Number of transactions for this product by the target payment account in the 24 hours prior to the current time × Second weight coefficient; Both the first and second weight coefficients are 0.5; The product base amount for a single product is the average of the transaction amounts for this product corresponding to each transaction request for the target payment account that sold this product in the 30 days prior to the current time. Users can determine the values ​​of preset transaction mode deviation and preset product transaction adaptability based on actual application scenarios. The greater the user's requirement for the precision of transaction risk control management, the smaller the value of preset transaction mode deviation and the larger the value of preset product transaction adaptability. A method for determining the values ​​of preset transaction mode deviation and preset product transaction adaptability is provided, which takes the average value of the transaction mode deviation and the average value of the product transaction adaptability corresponding to each type of transaction request in the historical records that can meet the user's needs as the preset transaction mode deviation and preset product transaction adaptability, respectively.

[0030] Specifically, the risk control configuration module responds to risk control states where the proportion of a certain type of transaction request is greater than or equal to the preset proportion of a certain type of transaction request or the load anomaly degree is greater than or equal to the preset load anomaly degree, and performs transaction combination matching based on the transaction matching degree; The risk control configuration module responds to risk control states where the proportion of a certain type of transaction request is less than the preset proportion of a certain type of transaction request and the load anomaly degree is less than the preset load anomaly degree, and performs individual transaction matching.

[0031] Specifically, the risk control status includes a first risk control status and a second risk control status. The first risk control status is when the proportion of a type of transaction request is greater than or equal to the preset proportion of a type of transaction request or the load anomaly is greater than or equal to the preset load anomaly. The second risk control status is when the proportion of a type of transaction request is less than the preset proportion of a type of transaction request and the load anomaly is less than the preset load anomaly. The percentage of type 1 transaction requests is the ratio of the number of type 1 transaction requests collected at the current time to the total number of transaction requests collected at the current monitoring time. The load anomaly is the average memory usage of each risk control query node at the current moment. The memory usage of each risk control query node at the current moment is monitored by the Linux free or top command. The user can determine the preset values ​​for the proportion of a certain type of transaction request and the preset load anomaly level based on the actual application scenario. The smaller the preset values ​​for the proportion of a certain type of transaction request and the preset load anomaly level, the greater the user's need for transaction combination matching. The system provides a preset value for the proportion of a certain type of transaction request and the preset load anomaly level, detects the user's historical transaction combination matching history, and records the average proportion of a certain type of transaction request and the average load anomaly level corresponding to the historical history that can meet the user's needs as the preset proportion of a certain type of transaction request and the preset load anomaly level, respectively. In transaction combination matching based on transaction matching degree, combination analysis is performed on each transaction request at the current time. When performing combination analysis on a single transaction request at the current time, the transaction request is recorded as the target transaction request. Other transaction requests at the current time that are not recorded in the associated combination are recorded as reference transaction requests. The set of reference transaction requests with a transaction matching degree greater than the target transaction request and the target transaction request is recorded as an associated combination. Combination analysis is continued for other transaction requests that are not recorded in the associated combination until all transaction requests at the current time are recorded in the associated combination. Then the combination analysis stops, and each associated combination is recorded as a processing batch. The matching degree of two transaction requests = transaction trajectory overlap rate / preset transaction trajectory overlap rate × trajectory weight coefficient + (1 - feature difference / preset feature difference) × feature weight coefficient, the trajectory weight coefficient is 0.6, and the feature weight coefficient is 0.4; The overlap rate of the transaction trajectories corresponding to the two transaction requests is the ratio of the number of intersection elements to the number of union elements. The elements include IP address, MAC address, browser identifier, mobile phone IMEI code, shipping address, and bound mobile phone number; the intersection elements are the number of elements that exist in both transaction requests, and the number of union elements is the number of elements after deduplication of all elements in the merged two transaction requests. The reference value of the abnormal characteristics corresponding to a single transaction request = transaction mode deviation / preset transaction mode deviation × deviation weight coefficient + (1 - commodity transaction adaptability / preset commodity transaction adaptability) × adaptability weight coefficient, where both the deviation weight coefficient and the adaptability weight coefficient are 0.5; Feature difference = absolute value of the difference between the abnormal feature reference values ​​corresponding to the two transaction requests / larger value of the abnormal feature reference values ​​corresponding to the two transaction requests; Users can determine the preset values ​​for transaction trajectory overlap rate, preset feature difference, and preset transaction matching degree based on their actual application scenarios. The greater the user's need to improve the accuracy of transaction request similarity in associated combinations, the higher the values ​​of preset transaction trajectory overlap rate and preset transaction matching degree, and the lower the value of preset feature difference. One preset value for these three values ​​is provided: preset transaction trajectory overlap rate of 60%, preset feature difference of 25%, and preset transaction matching degree of 68%. In individual transaction matching, each transaction request is recorded as a processing batch. Understandably, the proportion of a certain type of transaction request and the load anomaly level effectively reflect the risk correlation strength of the current transaction environment and the real-time processing redundancy of the risk control system. When the risk control status is that the proportion of a certain type of transaction request is greater than or equal to the preset proportion of a certain type of transaction request or the load anomaly level is greater than or equal to the preset load anomaly level, it indicates that the correlation of high-risk characteristics in the transaction pool has significantly increased, or the system no longer has sufficient processing resources to support the fine-grained review of a single transaction. Therefore, transaction combination matching is performed based on the transaction matching degree. When the risk control status is that the proportion of a certain type of transaction request is less than the preset proportion of a certain type of transaction request and the load anomaly level is less than the preset load anomaly level, it indicates that the risk characteristics of most transactions in the transaction pool are independent of each other, and the system has sufficient processing resources to carry out precise verification of a single transaction. Therefore, transactions are matched separately.

[0032] Specifically, the risk control analysis module determines the number of query nodes based on the degree of impact of the anomaly; The number of query nodes corresponding to a single processing batch is positively correlated with the degree of anomaly impact corresponding to that processing batch.

[0033] Specifically, the abnormal impact degree corresponding to a single processing batch = mean of abnormal features / preset mean of abnormal features × third weight coefficient + trajectory interaction impact degree / preset trajectory interaction impact degree × fourth weight coefficient, where the third weight coefficient is 0.6 and the fourth weight coefficient is 0.4. The average value of the anomaly characteristics corresponding to a single processing batch is the average value of the reference values ​​of the anomaly characteristics corresponding to each transaction request in that processing batch. The trajectory interaction impact degree corresponding to a single processing batch is the average of the trajectory overlap average of each transaction request. The trajectory overlap average of a single transaction request is the average of the transaction trajectory overlap rate between that transaction request and all other transaction requests in the processing batch except for that transaction request. It should be noted that if the number of transaction requests in a single processing batch is 1, then the trajectory interaction impact degree corresponding to that processing batch is 0. Users can determine the values ​​of the preset mean of abnormal features and the preset interaction influence degree based on the actual application scenario. The greater the user's requirement for the precision of transaction risk control management, the smaller the values ​​of the preset mean of abnormal features and the preset interaction influence degree should be. A method for determining the values ​​of the preset mean of abnormal features and the preset interaction influence degree is provided, which takes the average value of the mean of abnormal features and the average value of the interaction influence degree of the trajectory corresponding to each processing batch in the historical records that can meet the user's needs as the preset mean of abnormal features and the preset interaction influence degree, respectively. The number of query nodes corresponding to a single processing batch = the abnormal impact degree corresponding to the processing batch / the preset abnormal impact degree × the number threshold, where the number threshold is 4; The preset value of the anomaly impact level can be determined by the user based on the actual application scenario. The greater the user's need to improve the accuracy of transaction risk control management, the smaller the preset value of the anomaly impact level will be. One preset value of the anomaly impact level is provided, which is 0.63.

[0034] Specifically, the risk control analysis module responds when the correlation redundancy is greater than or equal to the preset correlation redundancy or the risk coupling degree is greater than or equal to the preset risk coupling degree, and determines the pre-query node based on the combination of correlation nodes. The risk control analysis module responds with a redundancy degree less than the preset redundancy degree and a risk coupling degree less than the preset risk coupling degree, and determines the pre-query node based on the node influence value.

[0035] Specifically, the correlation redundancy is the average of the extreme values ​​of the number of databases corresponding to each risk control query node. For a single risk control query node, the risk control query node is recorded as the target risk control query node, and other risk control query nodes other than the target risk control query node are recorded as reference risk control query nodes. The extreme value of the number of databases corresponding to the target risk control query node is the maximum value among the number of identical databases corresponding to the target risk control query node and each reference risk control query node. The number of identical databases corresponding to any two risk control query nodes is the number of identical databases that can be connected between the two risk control query nodes. The risk coupling degree is the average of the query associations corresponding to each risk control query node, and the average of the query associations corresponding to the target risk control query node is the average of the query associations between the target risk control query node and each reference risk control query node. The method for confirming the query relevance is as follows: for any two risk control query nodes, detect the number of times in the historical records that can meet the user's needs that the two risk control query nodes are simultaneously used as query nodes for a transaction request, and record the average hash similarity of the query content of the two query nodes in each number of times as the query relevance. The feature data queried by a single risk control query node corresponding to a single transaction request within the risk control verification time is converted into a hash value using a hash function. The hash function can be MD5 or SHA-256. The hash similarity = 1 - (Hamming distance between two hash values ​​ / total number of bits in the hash value). The Hamming distance between two hash values ​​refers to the number of positions where the corresponding binary bits are different after the hash values ​​are aligned bit by bit. The values ​​of preset association redundancy and preset risk coupling can be determined by the user according to the actual application scenario. The greater the user's need to determine the pre-query node based on the combination of associated nodes, the smaller the values ​​of preset association redundancy and preset risk coupling. A method for determining the values ​​of preset association redundancy and preset risk coupling is provided. The average value of association redundancy and the average value of risk coupling corresponding to each processing batch in the historical records where the user determines the pre-query node based on the combination of associated nodes and can meet the user's needs are detected. These are respectively denoted as preset association redundancy and preset risk coupling. In determining the pre-query nodes based on the associated node combination, correlation analysis is performed on each risk control query node. When performing correlation analysis on a single risk control query node, the risk control query node is recorded as the target risk control query node. Other risk control query nodes that are not recorded in the associated node combination are recorded as reference risk control query nodes. The set of reference risk control query nodes with a node correlation degree greater than the preset node correlation degree and the target risk control query node is recorded as an associated node combination. Correlation analysis continues for risk control query nodes that are not recorded in the associated node combination until each risk control query node is recorded in the corresponding associated node combination. Then the correlation analysis stops. For a single processing batch, associated node combinations are selected in descending order of the average node influence value until the number of selected associated node combinations reaches the number of query nodes corresponding to the processing batch. In each associated node combination, the risk control query node with the largest node influence value in the associated combination is selected as the pre-query node. It is important to note that when the total number of associated node combinations is less than the number of query nodes required for processing the batch, all combinations are first selected in descending order of average influence value (one risk control query node with the largest influence value is selected for each combination). The remaining gap is filled by selecting nodes from all unselected nodes in descending order of node influence value (the risk control query node with the largest influence value is selected for each unselected node in each combination) until the number of query nodes for the batch is met.

[0036] The average node impact value corresponding to a single associated node combination is the average of the node impact values ​​of each risk control query node in that associated node combination and the node impact value corresponding to that processing batch. The node correlation between any two risk control query nodes = number of identical databases / preset number of identical databases × quantity weight coefficient + query correlation / preset query correlation × correlation weight coefficient, where both the quantity weight coefficient and the correlation weight coefficient are 0.5; Users can determine the preset values ​​for the number of identical databases and the preset query relevance based on their actual application scenarios. The greater the user's need for precision in transaction risk control management, the smaller the preset values ​​for the number of identical databases and the preset query relevance will be. One preset value for the number of identical databases and the preset query relevance is provided: the preset number of identical databases is 5 and the preset query relevance is 0.62. The value of the preset node correlation degree can be determined by the user according to the actual application scenario. The greater the user's requirement for the accuracy of the similarity of risk control query nodes in the combination of related nodes, the greater the value of the preset node correlation degree. One preset node correlation degree value is provided, with a preset node correlation degree of 0.7. When determining the pre-query node based on the node impact value, for a single processing batch, risk control query nodes are selected in descending order of node impact value until the number of selected risk control query nodes reaches the number of query nodes corresponding to the processing batch, and each selected risk control query node is recorded as a pre-query node. The node impact value of a single risk control query node and a single processing batch is calculated as follows: (1 - the memory utilization rate of the risk control query node at the current moment / preset memory utilization rate) × memory weight coefficient + the effective query coefficient of the processing batch and the risk control query node / preset effective query coefficient × query weight coefficient. Both the memory weight coefficient and the query weight coefficient are 0.5. The effective query coefficient is the average of the query pass rates of each transaction request in the processing batch and the corresponding risk control query node. The query pass rate of a single transaction request and a single risk control query node = the number of effective transaction requests / the total number of transaction requests in the history where the risk control query node queries the transaction request and the feature difference of the transaction request is less than the preset feature difference. Transaction requests in the history where the risk control query node queries the transaction request and the feature difference of the transaction request is less than the preset feature difference that can meet the user's needs are recorded as effective transaction requests. Users can determine the preset memory utilization rate and preset effective query coefficient values ​​based on their actual application scenarios. The greater the user's need to improve the accuracy of transaction risk control management, the smaller the preset memory utilization rate and the larger the preset effective query coefficient value. One preset memory utilization rate and preset effective query coefficient value is provided: preset memory utilization rate is 65% and preset effective query coefficient is 87%. It is understandable that the correlation redundancy and risk coupling degree effectively reflect the resource redundancy level of the risk control query node cluster and the correlation coupling strength of the query tasks. When the correlation redundancy is greater than or equal to the preset correlation redundancy or the risk coupling degree is greater than or equal to the preset risk coupling degree, it indicates that there are many duplicate accessible database resources among the nodes, or the characteristics of the query tasks are highly correlated, which is prone to resource waste and query redundancy. Therefore, the pre-query node is determined based on the combination of related nodes. When the correlation redundancy is less than the preset correlation redundancy and the risk coupling degree is less than the preset risk coupling degree, it indicates that the resource overlap among the nodes is low and the query tasks are relatively independent with no obvious correlation coupling. Therefore, the pre-query node is determined based on the node influence value.

[0037] Specifically, if the risk control analysis module responds with a feature drift coefficient greater than or equal to a preset feature drift coefficient or the number of matching transactions is less than a preset number of matching transactions, it determines that optimization processing should be performed.

[0038] Specifically, the feature drift coefficient is the average of the node drift degree corresponding to each pre-query node, and the node drift degree corresponding to a single pre-query node is the standard deviation of the abnormal feature reference values ​​corresponding to each transaction request queried by that pre-query node in the historical records that can meet the user's needs. The number of matching transactions is the average of the average number of similar transaction requests corresponding to each pre-query node. The average number of similar transaction requests corresponding to a single pre-query node is the average of the number of similar transaction requests corresponding to each transaction request in a single processing batch. The number of similar transaction requests corresponding to a single transaction request in a single processing batch is the number of transaction requests in the historical records that can meet the user's needs, where the feature difference between the transaction request queried by the risk control query node and the transaction request is less than the preset feature difference. The formula for calculating the number of matching transactions K is:

[0039] Where n is the total number of pre-query nodes in a single processing batch, and m is the total number of transaction requests included in a single processing batch. The number of valid transaction requests corresponding to the i-th pre-query node and the j-th transaction request (the number of transaction requests in the historical records that can meet the user's needs, where the feature difference between the pre-query node and the transaction request is less than the preset feature difference), where i is 1, 2...n and j is 1, 2...m; Users can determine the values ​​of the preset feature drift coefficient and the preset number of matching transactions based on their actual application scenarios. The greater the user's need to improve the accuracy of transaction risk control management, the smaller the value of the preset feature drift coefficient and the larger the value of the preset number of matching transactions. A method for determining the values ​​of the preset feature drift coefficient and the preset number of matching transactions is provided. The method detects the historical records of secondary judgment based on the risk control index of the associated feature data of the pre-query node. The average value of the feature drift coefficient and the average value of the number of matching transactions corresponding to the historical records that meet the user's needs are respectively recorded as the preset feature drift coefficient and the preset number of matching transactions.

[0040] Specifically, if the risk control analysis module responds with a feature drift coefficient that is less than a preset feature drift coefficient and the number of matching transactions is greater than or equal to a preset number of matching transactions, a secondary determination is made based on the risk control instability coefficient. The risk control analysis module responds when the risk control instability coefficient is greater than or equal to the preset risk control instability coefficient, and then performs a secondary judgment for optimization.

[0041] Specifically, if the risk control analysis module responds with a risk control instability coefficient that is less than the preset risk control instability coefficient, no optimization processing is required for the secondary judgment.

[0042] The risk control instability coefficient is the average of the instability reference values ​​corresponding to each pre-query node; The instability reference value for a single pre-query node is the standard deviation of the effective query coefficients of each risk control query node in the associated node combination to which the pre-query node belongs. The value of the preset risk control instability coefficient can be determined by the user based on the actual application scenario. The greater the user's need to improve the accuracy of transaction risk control management, the smaller the value of the preset risk control instability coefficient should be. A method for determining the value of the preset risk control instability coefficient is provided, which involves detecting historical records that have undergone secondary judgment and optimization processing, and recording the average value of the risk control instability coefficients corresponding to the historical records that meet the user's needs as the preset risk control instability coefficient.

[0043] Understandably, the feature drift coefficient and the number of matching transactions effectively reflect the volatility of abnormal trading characteristics and the sufficiency of matching with historical similar transactions. When the feature drift coefficient is greater than or equal to the preset feature drift coefficient or the number of matching transactions is less than the preset number of matching transactions, it indicates that the volatility of abnormal trading characteristics exceeds the acceptable range, or that the matching with historical similar transactions is insufficient, resulting in insufficient risk control adaptability and reference reliability, thus requiring optimization. When the feature drift coefficient is less than the preset feature drift coefficient and the number of matching transactions is greater than or equal to the preset number of matching transactions, it indicates that the trading characteristics are abnormal. The volatility is controllable, and there are sufficient historical similar transactions to match, so the basic risk control adaptability meets the standards. Therefore, a secondary judgment is made based on the risk control instability coefficient. The risk control instability coefficient effectively reflects the query operation stability of the pre-query node combination. Its essence is to quantify the consistency and volatility controllability of the execution status between nodes. When the risk control instability coefficient is greater than or equal to the preset risk control instability coefficient, it indicates that the instability of the node combination operation may lead to feature extraction deviation. Even if the basic conditions meet the standards, it will still affect the accuracy of risk control. Therefore, when the risk control instability coefficient is greater than or equal to the preset risk control instability coefficient, a secondary judgment is made for optimization.

[0044] Specifically, the optimization execution module adjusts the number of pre-query nodes based on the risk identification gap rate; The increase in the number of pre-query nodes corresponding to a single processing batch is positively correlated with the risk identification gap rate corresponding to that processing batch.

[0045] Specifically, the risk identification gap rate corresponding to a single processing batch is the average gap coefficient of each pre-query node corresponding to that processing batch. For a single pre-query node, extract the abnormal transaction requests found in the historical records that can meet the user's needs, and detect the abnormal risk control stage corresponding to each transaction request. The gap coefficient corresponding to the pre-query node is 1 - the minimum number of abnormal transaction requests corresponding to each abnormal risk control stage / the total number of abnormal transaction requests. Due to the mutual exclusion constraint of the state of the finite state machine in the table structure, each abnormal transaction request corresponds to only one abnormal risk control stage in a single judgment. When adjusting the number of pre-query nodes based on the risk identification gap rate, if the risk identification gap rate is greater than or equal to the preset risk identification gap rate, the increase in the number of pre-query nodes will be set to 1.46 times the original number of pre-query nodes; if the risk identification gap rate is less than the preset risk identification gap rate, the increase in the number of pre-query nodes will be set to 1.22 times the original number of pre-query nodes. The value of the preset risk identification gap rate can be determined by the user according to the actual application scenario. The greater the user's need to improve the accuracy of transaction risk control management, the smaller the value of the preset risk identification gap rate should be. A method for determining the value of the preset risk identification gap rate is provided, which is the average value of the risk identification gap rate corresponding to each processing batch in the historical records that can meet the user's needs and do not require optimization. It should be noted that when increasing the number of pre-query nodes, if the original determination was based on the combination of related nodes, the combination of related nodes with the fewest selected pre-query nodes will be selected first in descending order of the average node impact value. From each selected combination, the risk control query node that has not been selected and has the largest node impact value will be selected as the pre-query node, until the number of selected related node combinations reaches the number of new nodes corresponding to this processing batch. If the original determination was based on the node impact value, then the unselected risk control query nodes are selected as pre-query nodes in descending order of node impact value, until the number of selected associated node combinations reaches the increase value of the number of query nodes corresponding to the processing batch; each selected pre-query node and the initially selected pre-query node are recorded as query nodes.

[0046] Specifically, the optimization execution module adjusts the query frequency or risk control verification time based on memory usage for query nodes whose adjustment comparison value is less than the preset adjustment comparison value.

[0047] Specifically, the optimization execution module does not need to adjust the query frequency or risk control verification time based on memory usage for query nodes whose adjustment comparison value is greater than or equal to the preset adjustment comparison value.

[0048] The adjustment comparison value is the ratio of the difference in the risk control instability coefficient to the increase rate of the number of pre-query nodes, and the increase rate of the number of pre-query nodes is the ratio of the increase in the number of pre-query nodes to the initially determined number of pre-query nodes. Risk control instability coefficient difference = Risk control instability coefficient of each pre-query node before adjustment of the number of pre-query nodes - Risk control instability coefficient of each pre-query node after adjustment of the number of pre-query nodes; The preset adjustment comparison value can be determined by the user according to the actual application scenario. The greater the user's need to improve the accuracy of risk control management, the smaller the preset adjustment comparison value should be. A method for setting the preset adjustment comparison value is provided, which detects the historical records of user adjustments to query frequency or risk control verification time based on memory usage, and records the minimum value among the adjustment comparison values ​​corresponding to the historical records that meet the user's needs as the preset adjustment comparison value.

[0049] Specifically, the optimization execution module determines to reduce the query frequency when the memory usage rate is less than the preset memory usage rate. If the optimized execution module responds to a memory usage rate greater than or equal to a preset memory usage rate, it determines to increase the risk control verification time.

[0050] Specifically, the memory usage rate for a single query node is the memory usage rate of that query node at the current moment; When adjusting the query frequency, for a single transaction request of a single query node, the reduction in query frequency = adjustment comparison value / preset adjustment comparison value × query frequency threshold corresponding to the transaction request. The query frequency threshold corresponding to a single transaction request is 26% of the initial query frequency of the transaction request. When increasing the risk control verification time, for a single transaction request of a single query node, the increase in risk control verification time = adjusted comparison value / preset adjusted comparison value × risk control verification time threshold corresponding to the transaction request. The risk control verification time threshold corresponding to a single transaction request is 39% of the initial risk control verification time of the transaction request. It should be noted that the maximum risk control verification time for a single transaction request shall not exceed 60 minutes to avoid affecting the normal transaction flow. If the risk control verification time exceeds 60 minutes after the increase adjustment, it will be set to 60 minutes by default. The initial query frequency for a single transaction request = abnormal feature reference value / preset abnormal feature reference value × baseline query frequency. The baseline query frequency is 6 minutes. The query frequency for a single transaction request is the time interval between two consecutive risk control queries performed by each query node corresponding to the transaction request. The initial risk control verification time for a single transaction request is 30 minutes. The risk control verification time refers to the preset time window for conducting risk queries, analysis and judgment on a single transaction request. Its core function is to provide sufficient query data and analysis period for risk judgment. Multiple queries are performed within this time. The principle is that the characteristics of transaction risk may change dynamically over time. Multiple queries can capture real-time risk signals, reduce the random error of a single query, and improve the accuracy and comprehensiveness of risk identification through multiple rounds of data verification.

[0051] The user can determine the preset abnormal feature reference value according to the actual application scenario. The greater the user's need to improve the accuracy of risk control management, the smaller the preset abnormal feature reference value should be. One preset abnormal feature reference value is provided, which is 0.5.

[0052] It is understandable that adjusting the comparison value effectively reflects the degree of improvement in the stability of the risk control architecture and the matching efficiency of the increase in the number of nodes after the increase in the number of pre-query nodes. When the adjusted comparison value is less than the preset adjusted comparison value, it means that the stability improvement brought about by the increase in the number of nodes has not reached the expected standard. Simply increasing the number of nodes cannot meet the risk control accuracy requirements. Therefore, the query frequency or risk control verification time is adjusted based on the memory usage rate. Memory usage effectively reflects the system resource load status of the current query node during operation. When the memory usage is less than the preset memory usage, it indicates that the system resources are sufficient and there is no resource pressure. Therefore, the query frequency is reduced. When the memory usage rate is greater than or equal to the preset memory usage rate, it indicates that the system resources are close to or have reached their capacity limit. Continuing to maintain the original query intensity may cause the system to lag. Therefore, the risk control verification time is increased.

[0053] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.

Claims

1. A merchant intelligent transaction risk control management system based on a table-structured finite state machine, characterized in that, include: The transaction acquisition module is used to acquire several transaction requests; The risk control configuration module, which is connected to the transaction acquisition module, is used to determine the transaction request category based on the transaction mode deviation and the commodity transaction adaptability, and to determine whether to perform individual transaction matching or transaction combination matching based on the transaction matching degree to determine the processing batch based on the risk control status; wherein, the risk control status is determined based on the proportion of a certain type of transaction request and the load anomaly degree; The risk control analysis module, which is connected to the risk control configuration module, is used to determine the number of query nodes based on the degree of abnormal impact, and to determine the pre-query nodes based on the combination of related nodes or the node impact value based on the degree of association redundancy and risk coupling. It also determines whether to perform optimization processing or make a secondary judgment based on the characteristic drift coefficient and the number of matching transactions of the pre-query nodes. An optimization execution module, which is connected to the risk control analysis module, is used to adjust the number of pre-query nodes based on the risk identification gap rate to obtain query nodes during optimization processing, and to determine whether to adjust the query frequency or risk control verification time based on the memory usage rate of the query nodes based on the adjustment comparison value. An anomaly identification module, which is connected to the risk control configuration module, the risk control analysis module, and the optimization execution module, is used to identify anomalies in the risk control stages of the table structure finite state machine based on the query content of each query node within the risk control verification time. The risk control stages include the receiving account risk control stage, the receiving transaction risk control stage, the expenditure account risk control stage, and the expenditure transaction risk control stage.

2. The merchant intelligent transaction risk control management system based on a table-structured finite state machine as described in claim 1, characterized in that, The risk control configuration module determines that transaction requests with a transaction mode deviation greater than or equal to the preset transaction mode deviation or a commodity transaction adaptability less than the preset commodity transaction adaptability are classified as Class I transaction requests. The risk control configuration module classifies transaction requests that have a transaction mode deviation less than the preset transaction mode deviation and a commodity transaction suitability greater than or equal to the preset commodity transaction suitability as Class II transaction requests.

3. The merchant intelligent transaction risk control management system based on a table-structured finite state machine according to claim 2, characterized in that, The risk control configuration module responds to risk control states where the proportion of a certain type of transaction request is greater than or equal to the preset proportion of a certain type of transaction request or the load anomaly degree is greater than or equal to the preset load anomaly degree, and performs transaction combination matching based on transaction matching degree; The risk control configuration module responds to risk control states where the proportion of a certain type of transaction request is less than the preset proportion of a certain type of transaction request and the load anomaly degree is less than the preset load anomaly degree, and performs individual transaction matching.

4. The merchant intelligent transaction risk control management system based on a table-structured finite state machine according to claim 1, characterized in that, The risk control analysis module determines the number of query nodes based on the degree of impact of the anomaly. The number of query nodes corresponding to a single processing batch is positively correlated with the degree of anomaly impact corresponding to that processing batch.

5. The merchant intelligent transaction risk control management system based on a table-structured finite state machine according to claim 4, characterized in that, The risk control analysis module responds when the correlation redundancy is greater than or equal to the preset correlation redundancy or the risk coupling degree is greater than or equal to the preset risk coupling degree, and determines the pre-query node based on the combination of correlation nodes. The risk control analysis module responds with a redundancy degree less than the preset redundancy degree and a risk coupling degree less than the preset risk coupling degree, and determines the pre-query node based on the node influence value.

6. The merchant intelligent transaction risk control management system based on a table-structured finite state machine according to claim 5, characterized in that, If the risk control analysis module responds with a feature drift coefficient greater than or equal to a preset feature drift coefficient or the number of matching transactions is less than a preset number of matching transactions, it determines that optimization processing should be performed.

7. The merchant intelligent transaction risk control management system based on a table-structured finite state machine according to claim 6, characterized in that, The risk control analysis module responds to a feature drift coefficient that is less than a preset feature drift coefficient and the number of matching transactions is greater than or equal to a preset number of matching transactions. The determination is based on a secondary determination of the risk control instability coefficient. The risk control analysis module responds when the risk control instability coefficient is greater than or equal to the preset risk control instability coefficient, and then performs a secondary judgment for optimization.

8. The merchant intelligent transaction risk control management system based on a table-structured finite state machine according to claim 1, characterized in that, The optimization execution module adjusts the number of pre-query nodes based on the risk identification gap rate. The increase in the number of pre-query nodes corresponding to a single processing batch is positively correlated with the risk identification gap rate corresponding to that processing batch.

9. The merchant intelligent transaction risk control management system based on a table-structured finite state machine according to claim 8, characterized in that, The optimization execution module adjusts the query frequency or risk control verification time based on memory usage for query nodes whose adjustment comparison value is less than the preset adjustment comparison value.

10. The merchant intelligent transaction risk control management system based on a table-structured finite state machine according to claim 9, characterized in that, The optimized execution module responds when the memory usage rate is less than the preset memory usage rate, and determines to reduce the query frequency accordingly. If the optimized execution module responds to a memory usage rate greater than or equal to a preset memory usage rate, it determines to increase the risk control verification time.

Citation Information

Patent Citations

  • Transaction risk control method and system

    CN119205331A