Large-scale enterprise online banking centralized management system and method

By utilizing a centralized management system for large enterprise online banking, and employing a design that allows for remote activation and automatic retrieval of USB tokens, combined with RPA tools, the system addresses the issues of low efficiency and poor security in USB token management for large enterprises. It achieves centralized management and automated operation of USB tokens, thereby improving both security and efficiency.

CN121766982APending Publication Date: 2026-03-31太保科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-22
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Large enterprise subsidiaries often suffer from low efficiency and poor security in managing USB tokens due to their multi-level structure and numerous partner banks. They require manual on-site application and return, making it difficult to monitor the usage status of USB tokens in real time.

Method used

This invention provides a centralized management system for online banking for large enterprises, including subsidiary clients, head office servers, and USB token management devices. The system activates USB tokens through remote requests and authorization commands, automatically reclaims USB tokens, and integrates RPA tools to achieve automated operation and risk monitoring. The USB tokens are centrally stored in a dedicated device.

Benefits of technology

It improves the efficiency of U-shield management, simplifies the operation process, eliminates the risk of U-shield theft and loss, enhances security, and realizes the automation and real-time monitoring of U-shield use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121766982A_ABST
    Figure CN121766982A_ABST
Patent Text Reader

Abstract

The invention discloses a large-scale enterprise online banking centralized management system and method. The system comprises a client of a subsidiary company, a headquarter server of a headquarter company and a USB key management device. The client is used for sending a target USB key use request to the headquarters server; the headquarter server is used for responding to a target USB key use request sent by the client, generating an authorization instruction based on application information in the target USB key use request, and sending the authorization instruction to the client; the client is further used for determining a target USB key from the USB key management equipment and activating the target USB key based on the target USB key identifier in the authorization instruction, so that the user establishes connection with the bank E-bank system by using the target USB key and then performs interactive operation with the bank E-bank system; and when the client completes the interaction operation or the operation time of the interaction operation is longer than the effective duration in the authorization instruction, the client sends a recovery instruction to the USB key management equipment, so that the USB key management equipment closes the target USB key, thereby improving the efficiency and safety of USB key management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, and in particular to a centralized management system and method for online banking of large enterprises. Background Technology

[0002] As large enterprises continue to expand their cross-regional operations and extend their business layout, the number of partner banks is increasing daily. Online banking, as a core channel for corporate fund settlement and account management, is seeing a significant increase in its usage frequency and importance. Meanwhile, the online banking USB key, a hardware security tool provided by banks for online banking identity authentication and operation authorization, is an essential device for enterprises to log in to online banking, process payments, and reconcile accounts in scenarios without direct bank-enterprise connections.

[0003] However, large enterprises typically have multiple layers of subsidiaries and numerous partner banks. Many small and medium-sized banks, in an effort to control costs, have not developed direct bank-enterprise connection interfaces. This necessitates that each subsidiary assign a dedicated person to safeguard its USB token (U-shield). When subsidiaries conduct payment or other transactions, they must manually apply for U-shield usage permission, retrieve the token in person, and return it after completing the online banking transaction. This makes it difficult for headquarters to monitor the real-time usage status of U-shields in small and medium-sized bank accounts, resulting in extremely low management efficiency and poor security. Summary of the Invention

[0004] Based on the above problems, this application provides a centralized management system and method for online banking for large enterprises, with the aim of improving the efficiency and security of U-shield management.

[0005] The embodiments of this application disclose the following technical solutions:

[0006] In the first aspect, this application provides a centralized management system for online banking of large enterprises, the system including client terminals of subsidiaries, headquarters server of the head office, and U-shield management device;

[0007] The client is used to send a request to use the target USB key to the headquarters server;

[0008] The headquarters server is used to respond to the target USB key usage request sent by the client, generate an authorization instruction based on the application information in the target USB key usage request, and send the authorization instruction to the client;

[0009] The client is also used to determine the target U-shield from the U-shield management device and activate the target U-shield based on the target U-shield identifier in the authorization instruction, so that the user can use the target U-shield to establish a connection with the bank's online banking system and perform interactive operations with the bank's online banking system; when the client completes the interactive operation or the operation time of the interactive operation exceeds the valid duration in the authorization instruction, the client sends a retrieval instruction to the U-shield management device, so that the U-shield management device closes the target U-shield.

[0010] Optionally, in the system described above, the client includes a U-shield remote call module and an online banking interaction module;

[0011] The U-shield remote call module is used to establish a connection with the U-shield management device and obtain the target U-shield corresponding to the target U-shield identifier from the U-shield management device;

[0012] The online banking interaction module is used to establish a connection with the bank's online banking system by calling the target USB key, and after establishing the connection, it interacts with the bank's online banking system in response to the user's operation.

[0013] Optionally, in the system described above, the headquarters server includes an access control module;

[0014] The permission control module is used to respond to the target U-shield usage request sent by the client, verify the user identity permissions in the application information using a preset role permission model, and generate the authorization instruction after the verification is successful; the preset role permission model is used to set different U-shield usage permissions for different user roles and the operation scope corresponding to different usage permissions.

[0015] Optionally, in the system described above, the system further includes an RPA tool cluster, and the client includes an RPA driver module;

[0016] The RPA driver module is used to extract business data from the enterprise ERP system and transmit the business data and the online banking form filling rules of the bank's online banking system to the RPA tool cluster; the business data includes scanned attachments;

[0017] The RPA tool cluster is used to identify key information in the scanned attachments using optical character recognition technology, cross-validate it with the business data, and automatically enter the verified business data and submit the operation request based on the online banking form filling rules.

[0018] Optionally, in the system described above, the RPA tool cluster is also used to capture the fund change data fed back by the bank's online banking system in real time, and synchronize the fund change data to the client and the headquarters server;

[0019] The headquarters server is also used to compare the fund change data with a preset risk threshold, and when the fund change data is greater than the preset risk threshold, generate an early warning instruction and send it to the online banking interaction module.

[0020] The online banking interaction module is also used to suspend the interaction operation in response to the warning command.

[0021] Optionally, in the system described above, the headquarters server further includes a log auditing module and a U-shield full lifecycle management module;

[0022] The log auditing module is used to obtain the full-process log from the client after the U-shield management device closes the target U-shield; the full-process log includes application information, activation records, interaction operation details, and closure status;

[0023] The U-shield full lifecycle management module is used to store the full process log and update the lifecycle ledger corresponding to the target U-shield. The lifecycle ledger stores the application, issuance, use, loss reporting and cancellation information of the target U-shield.

[0024] Optionally, in the system described above, the U-shield management device includes a main control unit, an adjustable slot unit, an interface adapter unit, and a power supply unit; the adjustable slot unit contains multiple retractable and rotatable slots; each slot is equipped with a U-shield clamping device of a different specification; the interface adapter unit adapts to U-shields with different interface types; and the power supply unit provides independent and stable power to each slot.

[0025] Secondly, this application provides a centralized management method for online banking for large enterprises, applied to any of the centralized management systems for online banking for large enterprises described in the above embodiments, the method comprising:

[0026] In response to the client's request to use the target USB key, the headquarters server generates an authorization instruction based on the application information in the target USB key usage request and sends the authorization instruction to the client;

[0027] Based on the target U-shield identifier in the authorization instruction, the client determines the target U-shield from the U-shield management device and activates the target U-shield, so that the user can use the target U-shield to establish a connection with the bank's online banking system and perform interactive operations with the bank's online banking system.

[0028] When the client completes the interactive operation or the operation time of the interactive operation exceeds the valid duration in the authorization instruction, the client sends a revocation instruction to the U-shield management device, so that the U-shield management device closes the target U-shield.

[0029] Thirdly, this application provides an electronic device, the device including: a processor, and a memory communicatively connected to the processor;

[0030] The memory stores the instructions that the computer executes;

[0031] The processor executes computer execution instructions stored in the memory to implement the centralized management method for online banking of large enterprises as described in any of the above embodiments.

[0032] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the centralized management method for large enterprise online banking described in any of the above embodiments.

[0033] Compared with the prior art, this application has the following beneficial effects:

[0034] The system described in this application includes client terminals for subsidiaries, a headquarters server for the head office, and USB key management devices. Clients remotely submit USB key usage requests, and the headquarters server responds online and generates authorization instructions based on the request information. This eliminates the need for subsidiary personnel to apply for and register on-site, breaking down geographical limitations and procedural barriers, and significantly shortening the preparation time before USB key activation. Subsequently, clients can directly locate and activate the target USB key from the management device based on the authorization instructions, replacing the tedious manual searching and unplugging of USB keys. Furthermore, the USB key retrieval process is automatically triggered upon completion of the operation or after a timeout, eliminating the need for manual return and simplifying the entire USB key usage process, thus improving the efficiency of online banking transactions. Simultaneously, because the headquarters server generates authorization instructions based on the application information in the target USB key usage request, the risk of USB key theft and misuse is eliminated at the source. The centralized storage of USB keys in dedicated management devices avoids the problems of loss and confusion caused by scattered manual storage. Moreover, the entire process of USB key activation and deactivation is automatically controlled by the system according to rules, and the automatic deactivation design after a timeout further prevents security risks caused by forgetting to return the keys. Therefore, while improving the efficiency of centralized management of online banking USB keys, it also enhances security. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 A schematic diagram of the structure of a centralized online banking management system for large enterprises provided in this application embodiment;

[0037] Figure 2 A topology diagram of a centralized online banking management system for large enterprises provided in this application embodiment;

[0038] Figure 3 A flowchart illustrating a centralized management method for online banking for large enterprises, provided as an embodiment of this application;

[0039] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0040] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with specific embodiments and accompanying drawings. It should be particularly noted that the embodiments described in this application are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0041] As described earlier, large enterprises are continuously expanding their cross-regional operations and extending their business layouts, resulting in an increasing number of partner banks, encompassing various types including large state-owned banks, joint-stock banks, and local small and medium-sized banks. Online banking, as a core channel for corporate fund settlement and account management, is experiencing a significant increase in usage frequency and importance. The online banking USB key is a hardware security tool provided by banks for online banking identity authentication and operation authorization. It has a built-in encryption chip that stores user digital certificates, ensuring the security of online banking operations by verifying user identity. It is an essential device for enterprises to log in to online banking, process payments, and reconcile accounts in scenarios without direct bank-enterprise connections.

[0042] In existing technologies, for banks with direct bank-enterprise connection interfaces, enterprises can achieve centralized management of online banking operations by directly connecting to their internal systems. However, many small and medium-sized banks have not developed direct bank-enterprise connection interfaces in order to control R&D costs. Enterprises need to rely on physical USB tokens to handle related business, and their management model generally suffers from decentralization: each subsidiary keeps its own USB token for its respective bank. The specifications and interface forms of USB tokens from different banks are different, and manual storage is prone to confusion and loss. When subsidiaries conduct business, they need to apply for USB token usage rights offline, pick up the USB token on-site, and return it after the operation is completed. The process is cumbersome and time-consuming, which is not only inefficient, but also prone to business failure or financial loss due to human error.

[0043] After research, the inventors proposed a centralized management system and method for online banking for large enterprises, which enables centralized management of online banking USB tokens and improves the efficiency and security of USB token management.

[0044] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.

[0045] See Figure 1 This figure is a schematic diagram of the structure of a centralized online banking management system for large enterprises provided in an embodiment of this application. Figure 1 As shown, the system includes a subsidiary's client 11, a head office server 12, and a U-shield management device 13; wherein, the subsidiary's client 11 is used to send a target U-shield usage request to the head office server 12; wherein, the target U-shield usage request is generated by the client 11 after receiving the operation request sent by the user, and the target U-shield usage request includes business-related application information, such as user identity and permissions, business type, usage duration, etc.

[0046] The headquarters server 12 is used to respond to the target U-shield usage request sent by the client 11, generate an authorization instruction based on the application information in the target U-shield usage request, and send the authorization instruction to the client 11; wherein, the authorization instruction includes, but is not limited to, the target U-shield identifier that is allowed to be used and the validity period.

[0047] As one possible approach, the headquarters server 12 includes an access control module 121. Specifically, the access control module 121 is used to respond to the target U-shield usage request sent by the client 11, verify the user identity permissions in the application information using a preset role permission model, and generate an authorization instruction after the verification is successful; the preset role permission model is used to set different U-shield usage permissions for different user roles and the operation scope corresponding to different usage permissions.

[0048] Specifically, the access control module 121 is used to respond in real time to the target U-shield usage request sent by the client 11. First, it extracts key data such as user identity permissions, target U-shield identifier, and business type from the application information of the request. Then, it uses a preset role-based access control (RBAC) model to verify the permission level corresponding to the user identity, confirming whether the user has the permission to use the target U-shield, and whether the business type and operation limit applied for are within the operation range corresponding to the permission level. After the verification is passed, an authorization instruction containing the allowed target U-shield identifier, validity period, and corresponding operation range is generated. The preset role permission model is used to set differentiated U-shield usage permissions for user roles in different positions of the enterprise, such as ordinary financial personnel and financial managers of subsidiaries, as well as the specific operation range corresponding to different usage permissions. The specific operation range includes, but is not limited to, the allowed business types and payment amount thresholds.

[0049] By combining the access control module with the preset role access model for verification, precise control over the use of the U-shield can be achieved, eliminating risks such as unauthorized use and operation beyond the scope from the source, effectively preventing the theft and abuse of the U-shield, and ensuring the security and compliance of corporate fund operations.

[0050] Client 11 is also used to parse the authorization instruction after receiving it. Based on the target U-shield identifier in the authorization instruction, after establishing communication with the U-shield management device 13, the client determines the target U-shield from the U-shield management device 13 based on the target U-shield identifier and activates the target U-shield to enable the user to use the target U-shield to establish a connection with the bank's online banking system and then perform interactive operations with the bank's online banking system. It can be understood that the user needs to use the activated target U-shield to complete the identity authentication with the bank's online banking system and establish a connection before carrying out online banking interactive operations.

[0051] When the client 11 detects that the user has completed the online banking interaction operation, or detects that the duration of the interaction operation exceeds the valid duration set in the authorization instruction, the client 11 sends a recycling instruction to the U-shield management device 13. After receiving the recycling instruction, the U-shield management device 13 performs the operation of closing the target U-shield, terminating its usage state, and then closing the target U-shield.

[0052] In this embodiment, the system includes a subsidiary's client, a headquarters server, and a USB key management device. The client submits a USB key usage request remotely, and the headquarters server responds online and generates an authorization command based on the application information. This eliminates the need for subsidiary personnel to apply for and register on-site, breaking down geographical limitations and process barriers, and significantly shortening the preparation time before USB key activation. The client can then directly locate and activate the target USB key from the management device based on the authorization command, replacing the tedious manual searching and unplugging of the USB key. Furthermore, the USB key retrieval process is automatically triggered upon completion of the operation or after a timeout, eliminating the need for manual return and simplifying the entire USB key usage process, thus improving the efficiency of online banking transactions. Simultaneously, since the headquarters server generates the authorization command based on the application information in the target USB key usage request, the risk of USB key theft and misuse is eliminated at the source. The centralized storage of USB keys in a dedicated management device avoids the problems of loss and confusion caused by manual, dispersed storage. Moreover, the entire process of USB key activation and deactivation is automatically controlled by the system according to rules, and the automatic deactivation design after a timeout further prevents security risks caused by forgetting to return the keys. Therefore, while improving the efficiency of centralized management of online banking USB keys, it also enhances security.

[0053] As one possible implementation, the client 11 includes a U-shield remote invocation module 111 and an online banking interaction module 112. The U-shield remote invocation module 111 is used to establish a connection with the U-shield management device 13 and obtain the target U-shield corresponding to the target U-shield identifier from the U-shield management device 13. The online banking interaction module 112 is used to establish a connection with the bank's online banking system by invoking the target U-shield, and after establishing the connection, it interacts with the bank's online banking system in response to user operations.

[0054] Specifically, after receiving the authorization instruction from the headquarters server 12, the U-shield remote call module 111 establishes an encrypted communication connection with the U-shield management device 13. Based on the target U-shield identifier in the authorization instruction, it accurately locates the corresponding target U-shield in the U-shield management device 13 and triggers the device activation process, including interface adaptation and independent power supply, thereby obtaining the right to use the target U-shield. The online banking interaction module 112 then simulates a browser kernel to automatically open the target bank's online banking login page, completes identity authentication by calling the activated target U-shield, establishes a stable connection with the bank's online banking system, and responds to user-initiated operation instructions such as payment and reconciliation, and performs data interaction and corresponding business operations with the bank's online banking system. In this embodiment, the U-Shield remote invocation module enables secure remote invocation of the U-Shield through encrypted communication and precise activation mechanisms, eliminating the need for users to pick up and manually insert / remove the U-Shield on-site. This breaks geographical limitations and solves the process breakpoint problem of traditional decentralized management. The online banking interaction module simplifies the online banking operation process through automated login, identity authentication, and business interaction, avoiding cumbersome manual steps and improving business processing efficiency. At the same time, it relies on U-Shield identity authentication and encrypted communication to ensure the security of the interaction process.

[0055] As one feasible approach, the U-shield management device includes a main control unit, an adjustable slot unit, an interface adapter unit, and a power supply unit. The adjustable slot unit contains multiple retractable and rotatable slots. Each slot is equipped with a U-shield clamping device of a different specification. The interface adapter unit adapts to U-shields with different interface types. The power supply unit provides independent and stable power to each slot.

[0056] In this embodiment, the USB key management device 13 can connect to the client 11 via USB or Ethernet. The USB key management device 13 can adopt a modular design, including a main control unit 131, an adjustable slot unit 132, an interface adapter unit 133, and a power supply unit 134. The adjustable slot unit 132 can be designed with 10-50 retractable and rotatable slots, each equipped with an adaptive clamping device, supporting USB keys of different specifications with lengths of 5-15cm and widths of 3-8cm. The interface adapter unit 133 integrates multiple interfaces such as USB 2.0, USB 3.0, and Type-C, adapting to USB keys with different interface types through an interface conversion module. The power supply unit 134 uses a wide voltage range of 100-240V, providing independent and stable power to each slot to prevent damage to the USB keys due to voltage fluctuations. It is understood that, to improve the security of storing a large number of USB keys, the USB key management device may also include a security encryption unit 135 to ensure the security of the USB key management device. As one possible approach, when client 11 enables the target U-shield based on the target U-shield identifier in the authorization command, the main control unit 131 drives the interface adapter unit 133 to establish communication with the target U-shield, and the security encryption unit 135 encrypts the transmitted data, for example, using Advanced Encryption Standard (AES) encryption. During use, the main control unit 131 monitors the connection status and power supply status of the target U-shield in real time. If disconnection or abnormal power supply occurs, alarm information is immediately sent to client 11 and headquarters server 12. After use, the main control unit 131 controls the adjustable slot unit 132 to reset, cuts off the power supply to the target U-shield, and records the usage log.

[0057] As one possible approach, the system also includes a cluster of Robotic Process Automation (RPA) tools 14, and the client 11 includes an RPA driver module 113.

[0058] The RPA driver module 113 extracts business data from the Enterprise Resource Planning (ERP) system and transmits the business data and online banking form-filling rules from the bank's online banking system to the RPA tool cluster 14. The business data includes scanned attachments. The RPA tool cluster 14 uses optical character recognition (OCR) technology to identify key information in the scanned attachments, cross-validates it with the business data, and automatically enters the validated business data based on the online banking form-filling rules before submitting the operation request. The RPA tool cluster 14 can be executed by the subsidiary's client 11 or scheduled by the head office server.

[0059] Specifically, after the client 11 establishes a connection with the bank's online banking system via the target USB key, the RPA driver module 113 accurately extracts business data from the enterprise ERP system. This business data includes, but is not limited to, payer account information, payee information, payment amount, purpose, and scanned attachments. Simultaneously, it acquires the corresponding bank's online banking form-filling rules, which include, but are not limited to, field format requirements and interface element positioning standards. The business data and online banking form-filling rules are then transmitted to the RPA tool cluster 14. The RPA tool cluster 14 receives and parses the transmitted data and rules, extracts key information from the scanned attachments (such as payee account information and amount) using Optical Character Recognition (OCR) technology, and performs bidirectional cross-validation with the ERP business data transmitted by the RPA driver module 113. After confirming that the information is consistent and correct, it completes field format conversion and precise field positioning according to the online banking form-filling rules, automatically inputs the validated business data into the online banking interface, and automatically submits an operation request to the bank's online banking system after completion. Understandably, if a field error occurs during the validation process, such as an incorrect number of digits in the payee's account number, an error message can be returned and the problematic field can be located.

[0060] In the above embodiments, through the collaborative operation of the RPA driver module and the RPA tool cluster, the entire process of online banking operations, from data extraction and verification to data entry and submission, is fully automated. There is no need for manual intervention in the data entry and verification process, which significantly reduces problems such as field errors and missing information that are prone to occur when manually filling out forms, ensuring the accuracy and consistency of business data, and also significantly saves business processing time and improves the efficiency of online banking operations. At the same time, the automated process strictly follows the online banking form filling rules, which not only ensures operational compliance but also improves the automation effect of centralized management of corporate online banking.

[0061] As another feasible approach, the RPA tool cluster 14 is also used to capture real-time fund change data fed back by the bank's online banking system and synchronize the fund change data to the client 11 and the headquarters server 12. The headquarters server 12 is also used to compare the fund change data with a preset risk threshold, and when the fund change data exceeds the preset risk threshold, it generates an early warning command and sends it to the online banking interaction module 112; the online banking interaction module 112 is also used to suspend interactive operations in response to the early warning command.

[0062] Specifically, during the execution of online banking interaction operations, the RPA tool cluster 14 captures real-time data on account balances, transaction details, and other fund change data from the bank's online banking system and synchronizes this data to the client 11 and the headquarters server 12 in a timely manner, ensuring that both ends have real-time awareness of fund dynamics and data consistency. After receiving the synchronized fund change data, the headquarters server 12 uses built-in risk verification logic to accurately compare the data with preset risk thresholds to comprehensively check whether the fund changes exceed the limits. The risk thresholds include, but are not limited to, single payment limits and daily cumulative payment limits. When the detected fund change data exceeds the preset risk threshold, an early warning instruction is immediately generated, containing specific data triggering the risk, threshold standards, and a pause operation instruction, and sent to the online banking interaction module 112. At this time, the online banking interaction module 112 receives the early warning instruction in real time, quickly responds, and pauses the currently ongoing online banking interaction operation. It also provides feedback to the user on the reason for the operation pause and the corresponding early warning prompt, awaiting further processing. For example, execution can be resumed only after the headquarters approves the operation. Understandably, RPA tool cluster 14 can also automatically start the online banking reconciliation process at a preset time node every day at midnight, extract all transaction details from the bank's online banking system, compare them one by one with the corresponding payment records in the enterprise's ERP system, accurately identify discrepancies such as inconsistent amounts and missing records, and generate a detailed reconciliation discrepancy table.

[0063] In the above embodiments, the risk comparison mechanism of real-time synchronization of fund change data with the headquarters server through the RPA tool cluster enables real-time risk monitoring of the entire online banking fund operation process. It can promptly detect and intercept abnormal transactions exceeding the preset risk threshold, effectively avoiding losses caused by abnormal fund changes. The online banking interaction module responds to the warning command to suspend operation, which can further prevent the risk from escalating from the execution end, ensuring the security and compliance of the enterprise's fund operations. At the same time, the fund change data is synchronized to the client and the headquarters server in real time, ensuring that both parties can keep abreast of the risk dynamics and improving the timeliness and effectiveness of the enterprise's control over online banking fund risks.

[0064] As one possible approach, the headquarters server 12 also includes a log auditing module 122 and a U-shield full lifecycle management module 123.

[0065] The log auditing module 122 is used to obtain the full process log from the client 11 after the U-shield management device 13 closes the target U-shield. The full process log includes application information, activation records, interaction operation details, and closure status. The U-shield full lifecycle management module 123 is used to store the full process log and update the lifecycle ledger corresponding to the target U-shield. The lifecycle ledger stores the application, issuance, use, loss reporting, and cancellation information of the target U-shield.

[0066] Specifically, after the U-shield management device 13 performs the operation of closing the target U-shield, the log audit module 122 actively obtains the full-process log of the U-shield usage from the client 11. The full-process log covers in detail the target U-shield's usage application information, activation record, online banking interaction details, and closing status. After receiving the full-process log transmitted by the log audit module 122, the U-shield full lifecycle management module 123 classifies and stores the log data according to preset archiving rules to ensure its integrity and security. At the same time, based on the usage records in the log, it updates the lifecycle ledger corresponding to the target U-shield in real time. The lifecycle ledger system stores the key information of the target U-shield from application, issuance, each use, loss reporting to cancellation, forming a coherent lifecycle data chain.

[0067] The application information includes, but is not limited to, applicant identity, business type, and application duration; activation records include, but are not limited to, activation time, device response status, and interface compatibility; online banking interaction details include, but are not limited to, operation type, execution time, and involved financial data; and closure status includes, but is not limited to, closure reason and closure time. Additionally, the full-process log may include permission change logs, and the log audit module can respond to user query requests, querying by time, department, personnel, business type, etc., with log data retained for over 10 years. Key information throughout the process includes, but is not limited to, application information (including but not limited to subsidiary applications and headquarters approval followed by allocation); distribution information (including but not limited to logistics information association and receipt confirmation); usage information (including but not limited to the time, operator, and business type of each use); loss reporting information (including but not limited to subsidiary applications and headquarters freezing); and cancellation information (including but not limited to archiving of scrapped U-shield information).

[0068] Understandably, the U-shield's lifecycle ledger can also store basic U-shield information, user information, and operating rules. Basic U-shield information includes, but is not limited to, bank name, account number, U-shield identifier, specifications, and issuing department; user information includes, but is not limited to, name, department, position, and access level; operating rules include, but are not limited to, payment amount thresholds and U-shield usage duration limits.

[0069] In the above embodiments, the log auditing module enables the complete collection and archiving of the entire process log of U-shield usage, providing detailed data support for subsequent compliance audits and problem tracing, and solving the problems of easy omissions and difficulty in querying traditional manual log registration; the U-shield full lifecycle management module ensures that the headquarters can accurately grasp the full lifecycle status of each U-shield by updating the ledger in real time, realizing the digitalization and refinement of U-shield management, avoiding management oversights caused by unclear status, and providing accurate data basis for subsequent management actions such as U-shield loss reporting and cancellation, further strengthening the standardization and reliability of centralized U-shield management.

[0070] Based on the above embodiments, the client 11 of the system may further include a local monitoring module 114; the headquarters server 12 may further include an operation monitoring module 124. The local monitoring module 114 can be used to display the U-shield status and operation progress in real time. If a local network interruption occurs, it automatically pauses the operation and saves the progress, resuming execution after the network is restored. The operation monitoring module 124 can be used to receive operation data uploaded by the operation client 11 and the RPA cluster 14 in real time, displaying the U-shield usage status, online banking operation progress, and fund changes in a visual interface. When an unauthorized operation occurs, it immediately triggers an alert and freezes the operation.

[0071] As a specific implementation method, consider a large manufacturing enterprise group with more than 10 subsidiaries nationwide. One subsidiary in East China needs to pay a supplier 200,000 yuan for raw material purchases. The cooperating receiving bank is a local small-to-medium-sized bank, which lacks a direct bank-enterprise connection and requires online banking payments via a USB key (U-shield). The subsidiary has deployed the client application 11 and USB key management device 13 of the large enterprise online banking centralized management system described in this application. The adjustable slot of the USB key management device 13 holds the target USB key corresponding to the small-to-medium-sized bank. The USB key is identified as UD20240518, has a Type-C interface, and measures 8cm in length and 4cm in width. The group headquarters has a headquarters server 12. The specific implementation process is as follows:

[0072] Subsidiary finance personnel log in to client 11 and initiate a request to use the target USB key. The request includes information such as the transaction type (online banking payment), the target USB key identifier (UD20240518), a usage duration of 2 hours, the payment order number (CG20240608001), and payee information. Client 11 encrypts the request and sends it to headquarters server 12. Upon receiving the request, headquarters server 12 verifies the applicant's identity through the access control module and checks the target USB key's status (idle or not reported lost) through the USB key lifecycle management module. If the applicant is a subsidiary finance personnel with payment permissions up to 500,000 RMB, an authorization instruction is generated after successful verification. This instruction includes the target USB key identifier (UD20240518), the operation permission scope (payment-only transactions only), a maximum amount of 500,000 RMB, and a validity period of 2 hours. The authorization instruction is then sent to the subsidiary's client 11. After receiving the authorization command, the subsidiary's client 11 establishes encrypted communication with the U-shield management device 13 via the U-shield remote call module and sends an activation command carrying the target U-shield identifier. The main control unit of the U-shield management device 13 drives the adjustable slot unit to adjust the slot where the target U-shield is located to the working position. The interface adapter unit automatically matches its Type-C interface and establishes communication. The power supply unit provides an independent and stable power supply to the U-shield, completing the activation of the target U-shield and simultaneously sending a status signal indicating that the U-shield has been activated back to the client 11. The subsidiary's financial personnel use the online banking interaction module of the client 11 to simulate a browser kernel to open the online banking login page of the small and medium-sized bank, call the activated target U-shield to complete identity authentication, and after successfully establishing a connection with the bank's online banking system, enter information such as the payment amount and the receiving account to complete the payment operation and submit it. After the bank's online banking system issues a successful payment receipt, the subsidiary's finance personnel confirm the completion of the interaction on client 11. Client 11 immediately sends a retrieval command to the U-shield management device 13. Upon receiving the command, the main control unit of the U-shield management device 13 cuts off the power supply to the target U-shield, controls the adjustable slot unit to reset, retracts the currently used slot to its storage position, and records the U-shield's usage log, including the user, usage duration (45 minutes), and successful transaction result. If the finance personnel do not complete the operation within the 2-hour validity period, client 11 will automatically trigger the timeout mechanism and send a retrieval command to the U-shield management device 13 without manual intervention. The U-shield management device 13 then closes the target U-shield according to the above process, avoiding the security risks caused by prolonged U-shield inactivity.

[0073] See Figure 2 This figure is a topology diagram of a centralized online banking management system for large enterprises provided in an embodiment of this application. Figure 2As shown in the diagram, this topology diagram illustrates the distributed architecture of the centralized online banking management system for large enterprises provided in this application embodiment. The headquarters management node deploys a database server and a management platform server, which interact through data read / write to achieve access control / monitoring and data storage / processing functions. The subsidiary operation nodes deploy operation clients, U-shield management devices, and an RPA tool cluster including payment form filling RPA and fund-related RPA. The operation clients communicate with the management platform server for instruction issuance / data synchronization, with the U-shield management devices for drive control and U-shield status feedback, and with the RPA tool cluster for automated operation and fund data synchronization. They also achieve linkage with the U-shield management devices through remote U-shield / operation calls. The bank's online banking system, as an external interaction object, feeds back fund data to the RPA tool cluster, forming a closed loop of business operation and data transmission with the operation clients and the RPA tool cluster.

[0074] See Figure 3 This figure is a flowchart illustrating a centralized management method for online banking in large enterprises, as provided in an embodiment of this application. Figure 3 As shown, in a large enterprise online banking centralized management system applied to any of the above embodiments, the method includes:

[0075] S101: In response to the client's request to use the target U-shield, the headquarters server generates an authorization instruction based on the application information in the target U-shield request and sends the authorization instruction to the client.

[0076] S102: Based on the target U-shield identifier in the authorization instruction, the client identifies the target U-shield from the U-shield management device and activates the target U-shield so that the user can use the target U-shield to establish a connection with the bank's online banking system and perform interactive operations with the bank's online banking system.

[0077] S103: When the client completes the interactive operation or the operation time of the interactive operation exceeds the valid duration in the authorization instruction, the client sends a revocation instruction to the U-shield management device so that the U-shield management device can close the target U-shield.

[0078] The centralized management method for online banking of large enterprises provided in this application embodiment is similar in implementation principle and beneficial effects to the technical solution shown in the above system embodiment, and will not be repeated here.

[0079] See Figure 3 The figure is a schematic diagram of the structure of an electronic device provided in an embodiment of this application, including:

[0080] Memory 11 is used to store computer programs;

[0081] The processor 12 is used to implement the steps of the centralized management method for online banking of large enterprises as described in any of the above method embodiments when executing the computer program.

[0082] In this embodiment, the device can be an in-vehicle computer, a PC (Personal Computer), or a terminal device such as a smartphone, tablet computer, handheld computer, or portable computer.

[0083] The device may include a memory 11, a processor 12, and a bus 13.

[0084] The memory 11 includes at least one type of readable storage medium, such as flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 11 can be an internal storage unit of the device, such as the hard disk of the device. In other embodiments, the memory 11 can also be an external storage device of the device, such as a plug-in hard disk, SmartMedia Card (SMC), Secure Digital (SD) card, Flash Card, etc. Furthermore, the memory 11 can include both internal and external storage units of the device. The memory 11 can be used not only to store application software and various types of data installed on the device, such as program code executing centralized management methods for large enterprise online banking, but also to temporarily store data that has been output or will be output. In some embodiments, the processor 12 can be a Central Processing Unit (CPU).

[0085] In some embodiments, processor 12 may be a central processing unit (CPU), controller, microcontroller, microprocessor or other data processing chip, used to run program code stored in memory 11 or process data, such as program code for executing a centralized management method for large enterprise online banking.

[0086] This bus 13 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 3 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0087] Furthermore, the device may also include a network interface 14, which may optionally include a wired interface and / or a wireless interface (such as a Wi-Fi interface, a Bluetooth interface, etc.), typically used to establish communication connections between the device and other electronic devices.

[0088] Optionally, the device may further include a user interface 15, which may include a display, an input unit such as a keyboard, and optionally, a standard wired interface or a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, or an OLED (Organic Light-Emitting Diode) touchscreen, etc. The display may also be appropriately referred to as a screen or display unit, used to display information processed in the device and to display a visual user interface.

[0089] Figure 3 Only devices with components 11-15 are shown; those skilled in the art will understand that... Figure 3 The structure shown does not constitute a limitation on the device and may include fewer or more components than shown, or combine certain components, or have different component arrangements.

[0090] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides a computer-readable storage medium storing computer instructions for causing the computer to perform the methods described in any of the above embodiments.

[0091] It should be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for methods, apparatuses, electronic devices, and media, since they are basically similar to the method embodiments, the descriptions are relatively simple, and relevant parts can be referred to the descriptions of the method embodiments. The methods, apparatuses, electronic devices, and media described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components indicated as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the solution in this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0092] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A centralized management system for online banking for large enterprises, characterized in that, The system includes the subsidiary's client, the head office server, and the U-shield management device; The client is used to send a request to use the target USB key to the headquarters server; The headquarters server is used to respond to the target USB key usage request sent by the client, generate an authorization instruction based on the application information in the target USB key usage request, and send the authorization instruction to the client; The client is also used to determine the target U-shield from the U-shield management device and activate the target U-shield based on the target U-shield identifier in the authorization instruction, so that the user can use the target U-shield to establish a connection with the bank's online banking system and perform interactive operations with the bank's online banking system. When the client completes the interactive operation or the operation time of the interactive operation exceeds the valid duration in the authorization instruction, the client sends a revocation instruction to the U-shield management device, so that the U-shield management device closes the target U-shield.

2. The system according to claim 1, characterized in that, The client includes a USB key remote access module and an online banking interaction module; The U-shield remote call module is used to establish a connection with the U-shield management device and obtain the target U-shield corresponding to the target U-shield identifier from the U-shield management device; The online banking interaction module is used to establish a connection with the bank's online banking system by calling the target USB key, and after establishing the connection, it interacts with the bank's online banking system in response to the user's operation.

3. The system according to claim 1, characterized in that, The headquarters server includes an access control module; The permission control module is used to respond to the target U-shield usage request sent by the client, verify the user identity permissions in the application information using a preset role permission model, and generate the authorization instruction after the verification is successful; the preset role permission model is used to set different U-shield usage permissions for different user roles and the operation scope corresponding to different usage permissions.

4. The system according to claim 2, characterized in that, The system also includes an RPA tool cluster, and the client includes an RPA driver module; The RPA driver module is used to extract business data from the enterprise ERP system and transmit the business data and the online banking form filling rules of the bank's online banking system to the RPA tool cluster; the business data includes scanned attachments; The RPA tool cluster is used to identify key information in the scanned attachments using optical character recognition technology, cross-validate it with the business data, and automatically enter the verified business data and submit the operation request based on the online banking form filling rules.

5. The system according to claim 4, characterized in that, The RPA tool cluster is also used to capture fund change data fed back by the bank's online banking system in real time, and synchronize the fund change data to the client and the headquarters server; The headquarters server is also used to compare the fund change data with a preset risk threshold, and when the fund change data is greater than the preset risk threshold, generate an early warning instruction and send it to the online banking interaction module. The online banking interaction module is also used to suspend the interaction operation in response to the warning command.

6. The system according to claim 1, characterized in that, The headquarters server also includes a log auditing module and a USB key lifecycle management module; The log auditing module is used to obtain the full-process log from the client after the U-shield management device closes the target U-shield; the full-process log includes application information, activation records, interaction operation details, and closure status; The U-shield full lifecycle management module is used to store the full process log and update the lifecycle ledger corresponding to the target U-shield. The lifecycle ledger stores the application, issuance, use, loss reporting and cancellation information of the target U-shield.

7. The system according to claim 1, characterized in that, The U-shield management device includes a main control unit, an adjustable slot unit, an interface adapter unit, and a power supply unit. The adjustable slot unit contains multiple retractable and rotatable slots. Each slot is equipped with a U-shield clamping device of a different specification. The interface adapter unit adapts to U-shields with different interface types. The power supply unit provides independent and stable power to each slot.

8. A centralized management method for online banking in large enterprises, characterized in that, The method, applied to the online banking centralized management system of any one of claims 1-8, comprises: In response to the client's request to use the target USB key, the headquarters server generates an authorization instruction based on the application information in the target USB key usage request and sends the authorization instruction to the client; Based on the target U-shield identifier in the authorization instruction, the client determines the target U-shield from the U-shield management device and activates the target U-shield, so that the user can use the target U-shield to establish a connection with the bank's online banking system and perform interactive operations with the bank's online banking system. When the client completes the interactive operation or the operation time of the interactive operation exceeds the valid duration in the authorization instruction, the client sends a revocation instruction to the U-shield management device, so that the U-shield management device closes the target U-shield.

9. An electronic device, characterized in that, The device includes: a processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in claim 8.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions that, when executed by a processor, are used to implement the method of claim 8.