Service risk control method and device based on system direct connection and electronic equipment
By using direct system connection and multi-level authentication, risk control measures are automatically matched and dynamic passwords are generated, which solves the breakpoints and data security problems in the control of high-risk user accounts in existing technologies, and achieves more efficient and secure risk control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-25
- Publication Date
- 2026-03-31
AI Technical Summary
The existing financial system has gaps in the operation of account risk control for high-risk users, making the risks uncontrollable, prone to oversight and mismanagement, and the existing identity verification methods are easily cracked, making it difficult to guarantee data security.
By acquiring account tags and automatically matching risk control measures, the system connects directly to the audit end for multi-level identity verification and generates dynamic passwords for secondary identity verification to ensure data security.
It eliminates system breakpoints, reduces operational steps, improves the accuracy of risk control and data security, and avoids the risks of missed or incorrect management and identity verification.
Smart Images

Figure CN121770845A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of risk control technology, and in particular to a business risk control method based on system direct connection, a business risk control device based on system direct connection, an electronic device, a computer-readable storage medium, and a computer program product. Background Technology
[0002] Existing financial systems typically issue corresponding risk control measures for accounts with risks. Currently, for high-risk users, operators need to manually issue risk control measures for various accounts under that user's name in each system. First, operators need to determine the attributes and current risk control status of each account. After authorizing each account individually, they sequentially query the current risk control status and incident records of all accounts under that user's name. If necessary, they also need to query basic account information to obtain more auxiliary information such as account purpose to determine whether risk control is applicable. Then, they need to distinguish different account types and sequentially open the corresponding risk control maintenance transaction system orders for each type of account. After authorizing each account individually, they sequentially execute risk control on all accounts under the client's name. When risk control is successful, they retain evidence or take a screenshot of the successful transaction output interface. Finally, they upload the screenshot or evidence of the risk control implementation, add notes as needed to explain the risk control implementation status, and complete the feedback operation. However, manual risk control of high-risk user accounts has gaps and risks that are uncontrollable, making it easy to miss or mismanage. Furthermore, during the risk control process, operators usually use fixed keys or receive dynamic passwords via the internet, SMS, or email for authentication. Fixed keys are easily cracked, and existing dynamic passwords need to be transmitted remotely through communication networks, which poses a risk of malicious hijacking and makes it difficult to guarantee data security. Summary of the Invention
[0003] This application provides a business risk control method based on direct system connection, a business risk control device based on direct system connection, an electronic device, a computer-readable storage medium, and a computer program product to solve the problems of existing account risk control operations having breakpoints, uncontrollable risks, and being prone to omissions and mismanagement.
[0004] The first aspect of this application provides a business risk control method based on direct system connection, including: Obtain account tags for each account of the target user; If the current account is determined to be the target account based on the account tag, the initial risk control measures for the target account are determined according to the account tag; The account tag and initial risk control measures are hidden and sent to the auditing end. In response to the query request of the auditing end, a first-level identity verification request is returned to the auditing end. The auditing end is then verified based on its response to the first-level identity verification request, and the response information of the auditing end during the response process is collected. If the first-level authentication is successful, a dynamic password is generated based on the response information. The second-level authentication is performed on the auditing end based on the dynamic password. If the second-level authentication is successful, the account tag and initial risk control measures of the target account are displayed to the auditing end. The system receives the target risk control measures for the target account determined by the review end based on the account tag, and executes the target risk control measures on the target account.
[0005] Optionally, the account tag includes at least the account category and current risk control status of the corresponding account. Determining the current account as the target account based on the account tag includes: The account category and current risk control status are matched with a preset risk account identification table, wherein the risk account identification table includes at least a combination of account categories and risk control statuses for different risk accounts; If the account category and current risk control status match any combination of account category and risk control status in the risk account identification table, the current account is determined to be the target account. Determining initial risk control measures for the target account based on the account tags includes: The account category and current risk control status are matched with a preset risk control measures table, wherein the risk control measures table includes at least the risk control measures corresponding to different combinations of account categories and risk control statuses; The risk control measures corresponding to the combination of the account category and the current risk control status in the risk control measures table are determined as the initial risk control measures for the target account. The auditing terminal's response to the authentication request includes at least the auditing terminal's account and password; based on the auditing terminal's response to the authentication request, the auditing terminal performs first-level authentication, including: The auditing account and password are matched with a preset primary identity verification table, which includes at least combinations of accounts and passwords corresponding to different auditing ends. If the auditing account and password match any combination of account and password in the Level 1 authentication table, the auditing end is determined to have passed the Level 1 authentication.
[0006] Optionally, the response information of the auditing terminal during the response process includes: location change information of the external input device during the auditing terminal's response process; generating a dynamic password based on the response information includes: The system receives position change information from the external input device, which is collected by the auditing end during the response process. Based on the location change information of the external input device, a first dynamic password is generated according to a preset dynamic password generation algorithm; The auditing terminal performs secondary authentication based on the dynamic password, including: After generating the first dynamic password, a secondary authentication request is returned to the auditing terminal; The system receives the response from the auditing end to the secondary authentication request and obtains the second dynamic password, which is generated by the auditing end based on the location change information of the external input device and according to the dynamic password generation algorithm. The first dynamic password is matched with the second dynamic password. If the first dynamic password matches the second dynamic password, it is determined that the auditing end has passed the second-level authentication.
[0007] Optionally, the location change information of the external input device is collected by the verification terminal through the following steps: Obtain the start and end positions of the external input device in each acquisition cycle; For each collection cycle, the interval distance between the start position and the end position is determined, and the moving speed of the external input device within the current collection cycle is determined based on the interval distance, until the auditing end completes the response to the first-level identity verification request, thereby obtaining the moving speed set of the external input device and obtaining the position change information of the external input device.
[0008] Optionally, the dynamic password generation algorithm includes: Randomly select multiple target movement speeds from the set of movement speeds; The movement speed of each target is normalized. The normalized target movement speeds are converted into a specified number format to obtain the target number sequence in the specified number format; The initial encrypted character sequence of the target number sequence is obtained by calculating the target number sequence using a specified encryption algorithm; Obtain the current time, and perform a specified operation on the initial encrypted character sequence using the current time as a random source to obtain the target encrypted character sequence of the target number; The first N characters of the target encrypted character sequence are used as the first dynamic password.
[0009] Optionally, the normalized target moving speeds are converted into a specified number format to obtain a target number sequence in the specified number format, including: Determine the baseline calculation factor; The normalized target movement speeds are multiplied by the benchmark calculation factor, and the calculation results obtained by the multiplication operation are rounded down to obtain the integer part of each calculation result. Arrange the integer parts of each calculation result according to the execution order of the multiplication operation to obtain the target number sequence in the specified base format.
[0010] Optionally, a specified operation is performed on the initial encrypted character sequence using the current time as a random source to obtain the target encrypted character sequence of the target number, including: Determine the reference time, and determine the time interval between the current time and the reference time; The time interval is converted into a representation of a preset minimum time unit, and the resulting character sequence is converted into a specified base format to obtain an initial random source character sequence; If the length of the initial random source character sequence is less than the length of the initial encrypted character sequence, a padding operation is performed on the initial random source character sequence with a specified character until the length of the initial random source character sequence is the same as the length of the initial encrypted character sequence, thus obtaining the target random source character sequence; or If the length of the initial random source character sequence is greater than the length of the initial encrypted character sequence, the characters in the initial random source character sequence are discarded until the length of the initial random source character sequence is the same as the length of the initial encrypted character sequence, thus obtaining the target random source character sequence; Perform a specified operation on the target random source character sequence and the initial encrypted character sequence to obtain the target encrypted character sequence of the target number.
[0011] A second aspect of this application provides a business risk control device based on direct system connection, comprising: The data acquisition module is configured to obtain account tags for each account of the target user; The risk account identification module is configured to determine the initial risk control measures for the target account based on the account tag if the current account is determined to be the target account based on the account tag. The first identity verification module is configured to send the account tag and initial risk control measures to the auditing end after hiding them, respond to the query request of the auditing end, return a first-level identity verification request to the auditing end, perform first-level identity verification on the auditing end based on the auditing end's response to the first-level identity verification request, and collect the response information of the auditing end during the response process. The second authentication module is configured to generate a dynamic password based on the response information when the first-level authentication is successful, perform second-level authentication on the auditing end based on the dynamic password, and if the second-level authentication is successful, display the account tag and initial risk control measures of the target account to the auditing end. The risk control measures execution module is configured to receive the target risk control measures for the target account determined by the review end based on the account tag, and execute the target risk control measures on the target account.
[0012] In a third aspect, this application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method described above.
[0013] In a fourth aspect, this application provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, are used to implement the method described above.
[0014] In a fifth aspect, this application provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0015] This application, when conducting risk control on user accounts, obtains account tags for each user's account, identifies risks for each account based on these tags, and automatically matches risk control measures. Through direct system connection, it sends risk account information and risk control measures to the auditors for confirmation. During the confirmation process, multi-level identity verification is performed on the auditors, and dynamic passwords are generated in real time by collecting the auditors' identity verification response information, effectively improving the data security of user account information. This application eliminates system breakpoints, effectively reduces the number of steps required by operators, and maximizes the accuracy of risk control measures through multi-level confirmation and other automatic verification measures. Attached Figure Description
[0016] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0017] Figure 1 A flowchart illustrating the business risk control method based on direct system connection provided in this application embodiment; Figure 2 This is a schematic diagram of the risk account risk control logic provided in the embodiments of this application; Figure 3 A schematic diagram of a business risk control device based on direct system connection provided in an embodiment of this application; Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0018] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for illustration and explanation of the embodiments of this application and are not intended to limit the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0020] It should be noted that if the embodiments of this application involve directional indicators (such as up, down, left, right, front, back, etc.), the directional indicators are only used to explain the relative positional relationship and movement of each component in a certain specific posture (as shown in the figure). If the specific posture changes, the directional indicators will also change accordingly.
[0021] Furthermore, if the embodiments of this application involve descriptions such as "first" or "second," these descriptions are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, features defined with "first" or "second" may explicitly or implicitly include at least one of those features. Additionally, the technical solutions of various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. If the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed in this application. It is understood that in the technical solutions of this application, the acquisition, collection, storage, use, processing, transmission, provision, disclosure, and application of data all comply with the provisions of relevant laws and regulations. It should be noted that in the embodiments of this application, certain software, components, models, and other existing industry solutions may be mentioned. These should be considered exemplary, and their purpose is merely to illustrate the feasibility of implementing the technical solutions of this application, but does not mean that the applicant has already used or necessarily used such solutions.
[0022] In the current financial system, when determining whether an account is eligible for risk control, staff need to check different menus for each account, which is cumbersome. When implementing risk control, the existing process requires staff to authorize each account before sequentially implementing risk control on all accounts under the customer's name, which is also cumbersome and carries the risk of missing or mismanaging accounts. After implementing risk control, the existing process requires staff to upload a screenshot of the successful risk control result to the high-risk user identification task to prove that risk control has been implemented on the corresponding user, which is also cumbersome and makes it difficult to confirm whether the final risk control measures implemented meet the approval requirements.
[0023] To solve the above problems, such as Figure 1 As shown, the first aspect of this application provides a business risk control method based on direct system connection, comprising: S100, Obtain account tags for each account of the target user; S200. If the current account is determined to be the target account based on the account tag, the initial risk control measures for the target account shall be determined based on the account tag. S300: After hiding the account tag and initial risk control measures, send them to the auditing end. In response to the query request from the auditing end, return a first-level authentication request to the auditing end. Perform first-level authentication on the auditing end based on the auditing end's response to the first-level authentication request, and collect the response information of the auditing end during the response process. S400: If the first-level identity verification is successful, a dynamic password is generated based on the response information. The second-level identity verification is performed on the auditing end based on the dynamic password. If the second-level identity verification is successful, the account tag of the target account and the initial risk control measures are displayed to the auditing end. S500: The receiving and reviewing end determines the target risk control measures for the target account based on the account tag, and executes the target risk control measures on the target account.
[0024] Thus, when conducting risk control on user accounts, this application obtains account tags for each user's account, identifies risks for each account based on these tags, and automatically matches risk control measures. Through direct system connection, the risk account information and risk control measures are sent to the auditors for confirmation. During the confirmation process, multi-level identity verification is performed on the auditors, and dynamic passwords are generated in real time by collecting the auditors' identity verification response information, effectively improving the data security of user account information. This application eliminates system breakpoints, effectively reduces the number of steps required by operators, and maximizes the accuracy of risk control measures through multi-level confirmation and other automatic verification measures.
[0025] In step S100, the system first obtains the account tags of each account of the target user. These account tags include account status information, such as account category and current risk control status. After obtaining the account tags, in step S200, the system confirms the scope of accounts to be subject to risk control based on the account status information. For example, if the current risk control status of an account shows abnormal transactions, then that account is identified as a target account for risk control. The system automatically matches an initial risk control measure for that account, such as suspending non-counter risk management operations. Alternatively, if the account category shows that the account is a pension account, since the risk of such accounts is controllable, no risk control is required. Through the above process, the system identifies the risks of each account of the user. For the identified scope of accounts to be subject to risk control, this application integrates and displays the risk control status of each target account in a dashboard format. Based on the current risk control status of each account and special account tags (such as credit card repayment accounts, social security accounts, etc.), the system automatically matches preliminary risk control measures for each account according to the configuration rules.
[0026] Specifically, determining the current account as the target account based on account tags includes: matching the account category and current risk control status with a pre-defined risk account identification table, wherein the risk account identification table includes at least combinations of account categories and risk control statuses for different risky accounts; if the account category and current risk control status match any combination of account categories and risk control statuses in the risk account identification table, the current account is determined to be the target account. For example, a risk account identification table is pre-established, which includes combinations of pre-defined account categories and risk control statuses. For instance, if an account is pre-determined to be a personal credit card with an abnormal transaction risk control status, then this combination of account category and risk control status is written into the risk account identification table. By pre-determining multiple combinations of account categories and risk control statuses identified as risky accounts, the target account can be quickly determined by looking up the table based on the account tags of each account.
[0027] Determining initial risk control measures for target accounts based on account tags includes: matching account categories and current risk control status with a pre-defined risk control measure table, wherein the risk control measure table includes at least the risk control measures corresponding to different combinations of account categories and risk control statuses; and identifying the risk control measures corresponding to the combinations of account categories and current risk control statuses in the risk control measure table as the initial risk control measures for the target account. Similarly, pre-determining the risk control measures corresponding to different combinations of account categories and risk control statuses—for example, pre-determining that when the account category is a personal savings card and the risk control status is abnormal transaction, the corresponding initial risk control measure is suspension of non-counter transactions—establishes a mapping relationship between various combinations of account categories and risk control statuses and their corresponding risk control measures. When matching initial risk control measures for each target account, the table is used to quickly match the initial risk control measures for each target account.
[0028] like Figure 2 As shown, after matching the initial risk control measures for the target account, in order to ensure the accuracy of the risk control measures for the target account, this application also sends the account tag and initial risk control measures of the target account to at least one level of review system for manual or automatic review through direct system connection. If the review determines that the current initial risk control measures do not meet the minimum risk control measures requirements, the final risk control measures for each target account are manually confirmed through the review end. When the current risk control measures meet the minimum risk control measures requirements, the risk control is performed on the target account through linkage with the corresponding system, and the risk control execution result is generated and the operation personnel at each stage are notified of the control result of the target account.
[0029] To ensure the data security of user account information, in step S300, when sending the target account's account tag and initial risk control measures to the auditing end for review, the auditing personnel are first authenticated. Specifically, when the system sends the target account's account tag and initial risk control measures to the auditing end, the system hides these information. When the auditing end requests to view the target account's account tag and initial risk control measures, it first sends a query request to the system. Upon receiving the query request, the system returns a Level 1 authentication request to the auditing end. This Level 1 authentication request can request the auditing end to verify the account password. That is, the auditing end's response to the authentication request must at least include the auditing end's account and password. Based on the auditing end's response to the authentication request, Level 1 authentication is performed on the auditing end, including: matching the auditing end's account and password with a preset Level 1 authentication table, which includes at least combinations of accounts and passwords corresponding to different auditing ends; if the auditing end's account and password match any combination of accounts and passwords in the Level 1 authentication table, the auditing end is determined to have passed Level 1 authentication. Understandably, an identity verification table is pre-built, which includes the accounts and passwords of each auditor with auditing authority. By matching the accounts and passwords, the current auditors are initially identified.
[0030] However, authentication using a single account password is insufficient to guarantee data access security. To further protect user account information security, this application further implements secondary authentication for auditors based on their response information. In this application, the response information from the auditing end during the response process includes: position change information of the external input device during the response process. This external input device can be a mouse or touchscreen input device, and the position change information is the pixel coordinate information of the mouse or touchscreen input device on the screen. The pixel coordinate information of the mouse or touchscreen input device on the screen can be implemented through a pre-configured position acquisition script or an existing mouse position acquisition program; this is not limited here. Generating a dynamic password based on the response information includes: receiving the position change information of the external input device, which is acquired by the auditing end during the response process; and generating a first dynamic password based on the position change information of the external input device and a preset dynamic password generation algorithm. For example, a mouse position collection script can be pre-deployed at each auditing end. After receiving a Level 1 authentication request at the auditing end, the script is activated to collect mouse operation information during the Level 1 authentication process, i.e., the mouse position information at various times. The auditing end sends the collected position information to the system of this application. This application generates a first dynamic password using a preset dynamic password generation algorithm. On the other hand, the auditing end generates a second dynamic password locally using the same preset dynamic password generation algorithm. After receiving a Level 2 authentication request, the auditing personnel enter the second dynamic password. The system matches the received second dynamic password with the first dynamic password generated by the system, thereby achieving Level 2 authentication of the auditing personnel. That is, in this application, the second-level authentication of the auditing end based on the dynamic password includes: after generating the first dynamic password, returning a second-level authentication request to the auditing end; receiving the auditing end's response to the second-level authentication request and obtaining the second dynamic password, which is generated by the auditing end based on the location change information of the external input device and according to a preset dynamic password generation algorithm; matching the first dynamic password with the second dynamic password, and if the first dynamic password and the second dynamic password are consistent, determining that the auditing end has passed the second-level authentication.In this application, the auditing end generates a dynamic password locally in real time by acquiring the auditer's mouse operation information. The system acquires the mouse operation information sent by the auditing end and generates a corresponding dynamic password remotely. The dynamic password entered by the auditer is then matched with the dynamic password generated remotely by the system to verify the auditer's identity. Since the dynamic password is generated locally on the auditing end, it does not need to be transmitted through a communication network, thus effectively preventing the dynamic password from being hijacked during transmission. The system of this application only receives the mouse operation information collected by the auditing end and uses the same algorithm as the auditing end to calculate the mouse operation information, thereby obtaining the corresponding dynamic password. In this way, even if the mouse operation information is hijacked during transmission, the hijacker cannot obtain the dynamic password, thus effectively improving the security of the verification information during the identity verification process. At the same time, since the auditer's mouse operation information is different each time for identity verification, the dynamic password generated in real time each time has a strong randomness, making the dynamic password difficult to crack. Understandably, in order to collect more mouse operation information from auditors, a virtual operation template can also be returned when returning the first-level authentication request to auditors. This virtual operation template has multiple preset controls. Auditors need to click the corresponding virtual controls in sequence according to the template before they can make the first-level authentication request. More mouse operation information can be collected through this virtual business operation template.
[0031] Specifically, in this application, the position change information of the external input device is collected by the auditing end through the following steps: obtaining the start and end positions of the external input device in each collection cycle; for each collection cycle, determining the interval distance between the start and end positions, and determining the movement speed of the external input device within the current collection cycle based on the interval distance, until the auditing end completes the response to the Level 1 authentication request, obtaining the set of movement speeds of the external input device, and thus obtaining the position change information of the external input device. For example, with a collection cycle of 100ms, the pixel coordinates of the mouse pointer at the beginning of each collection cycle and the pixel coordinates at the end of each collection cycle are collected. By the distance between the two collected pixel coordinates and the collection cycle, the movement speed of the mouse pointer in the current collection cycle can be obtained. After the auditing personnel complete the account password input operation, multiple movement speeds of the auditing personnel during the account password input operation are obtained. The multiple movement speeds are sorted according to the time order of the collection cycle to obtain the set of mouse movement speeds of the auditing personnel during the response process. Understandably, in order to improve the randomness of dynamic passwords, when collecting response information from the review end, the time the reviewer's mouse hovers can also be collected. For example, the mouse movement speed and the interval between two adjacent movements can be collected simultaneously to construct a feature dataset based on movement speed and interval. Subsequent calculations are the same as those using the movement speed set, except that the movement speed set is replaced with a feature dataset constructed based on movement speed and interval.
[0032] Understandably, in this application, the dynamic password generation algorithm used by the system server and the review end is the same. Taking the dynamic password generation on the system server as an example, the dynamic password generation algorithm of this application includes: S410. Randomly select multiple target movement speeds from the set of movement speeds. To avoid excessive data processing due to excessively large values, when generating dynamic passwords, not all feature data are calculated, but only M data points from the collected dataset are processed. Therefore, when calculating dynamic passwords, this application first randomly selects M movement data points from the obtained feature dataset as target movement speeds.
[0033] S420. Normalize the movement speed of each target. For example, the speed data can be transformed to the [0,1] interval using a conventional minimum-maximum normalization method. The normalized value of each data point is calculated as (original value - minimum value of the feature) / (maximum value of the feature - minimum value of the feature). For example, determine the maximum and minimum values among the acquired target speed values. For each target speed value, using the current target speed value as the original value, obtain the normalized value of each target speed value using the above formula.
[0034] S430. Convert the normalized target moving speeds into a specified number format to obtain a target number sequence in the specified number format. To facilitate data processing, this application converts the normalized moving speed data into a specified number format, such as binary or hexadecimal, after normalizing each feature data, i.e., the moving speed data.
[0035] Specifically, the data transformation process includes: S431. Determine the baseline calculation factor. For example, taking the conversion to binary as an example, determine the baseline calculation factor as 2.
[0036] S432. Multiply each normalized target movement speed by a baseline calculation factor, and then round the result of each multiplication operation to obtain the integer part of the result. Specifically, for each normalized movement speed data, multiply it by 2 and round it to obtain the integer part of the result. Then, for each normalized value, after performing the multiplication and rounding operation, each value can be converted to 0 or 1. If the current normalized value is the maximum value in the dataset, a specified value is used as the conversion result. For example, if the current normalized value is 1, then after multiplying by 2, its value is 2. To convert it to binary, when the normalized value is 1, it is directly set to 1 or 0.
[0037] S433. Arrange the integer parts of each calculation result according to the execution order of the multiplication operation to obtain the target number sequence in the specified base format. Sort the 0s or 1s obtained after multiplication and rounding in order to obtain the binary target number sequence.
[0038] S440. The target number sequence is calculated using a specified encryption algorithm to obtain an initial encrypted character sequence. In this application, the specified encryption algorithm can be the SM3 hash algorithm. After processing the target number sequence using the hash algorithm, a 256-bit hash value is obtained as the initial encrypted character sequence. To further reduce the computational load, this application can also limit the obtained hash value. For example, the hash value can be limited to N bits, and the first N values can be used to form the initial encrypted character sequence; or the hash value can be first converted to an integer, and then the integer value can be limited to N bits to avoid excessively large values.
[0039] S450. Obtain the current time, and perform a specified operation on the initial encrypted character sequence using the current time as a random source to obtain the target encrypted character sequence of the target number. Specifically, this includes: S451. Determine the base time and the time interval between the current time and the base time. For example, take 0:00 every day as the base time, obtain the timestamp of the current time, and calculate the time interval between the current time and the base time. For example, if the current time is 13:00, then the time interval is 13h.
[0040] S452. Convert the time interval into a preset minimum time unit representation, and convert the obtained character sequence into the specified base format to obtain the initial random source character sequence. For example, if the calculated time interval is 13h, using ms as the minimum time unit, convert it into ms representation, for example, convert it into 46800000ms, and then perform binary conversion to obtain the initial random source character sequence 10110010100001110010000000.
[0041] S453. If the length of the initial random source character sequence is less than the length of the initial encrypted character sequence, perform a padding operation on the initial random source character sequence with a specified character until the length of the initial random source character sequence is the same as the length of the initial encrypted character sequence, and obtain the target random source character sequence; for example, if the data length of the obtained initial random source character sequence is less than the length of the initial encrypted character sequence, then perform padding operation on the initial random source character sequence with 0 or 1, or randomly perform padding operation on the initial random source character sequence with 0 or 1, until the length of the initial random source character sequence after the padding operation is the same as the length of the initial encrypted character sequence.
[0042] Alternatively, if the length of the initial random source character sequence is greater than the length of the initial encrypted character sequence, characters in the initial random source character sequence are discarded until the length of the initial random source character sequence matches the length of the initial encrypted character sequence, thus obtaining the target random source character sequence. For example, if the length of the obtained initial random source character sequence is greater than the length of the initial encrypted character sequence, then character discarding is performed starting from the end of the initial random source character sequence, or characters in the initial random source character sequence are randomly discarded until the length of the initial random source character sequence matches the length of the initial encrypted character sequence.
[0043] S454. Perform a specified operation on the target random source character sequence and the initial encrypted character sequence, for example, perform an XOR operation to obtain the target encrypted character sequence of the target number.
[0044] S460. Use the first N characters of the target encrypted character sequence as the first dynamic password. For example, take the first 6 or 8 characters of the target encrypted character sequence as the final dynamic password.
[0045] In step S400, after the server generates a dynamic password, it sends a secondary authentication request to the auditing end. The auditing end inputs the dynamic password calculated by the auditing end, and the server matches the dynamic password input by the auditing end with the dynamic password calculated by the server. This achieves authentication without transmitting the dynamic password, avoiding the risk of dynamic password hijacking. After successful authentication, the auditing end can view the target user's target account information and confirm the initial risk control measures for the target account. It is understandable that the auditing end can be multi-level. Taking a financial system as an example, personnel at various levels of the branch and higher-level institutions review the risk control measures, confirming the final risk control measures for each account. At the end of the approval process, in step S500, the system automatically verifies whether the measures meet the minimum risk control requirements. If all rules are met, the system links various systems to perform risk control on the account. Simultaneously, after performing risk control operations on each account, this application also links various systems to retrieve the execution results of each risk control transaction and notifies personnel at each level in the process. For risk control operations that fail, the operators can re-initiate the risk control process.
[0046] This application integrates and displays the risk control status of all types of customer accounts in a dashboard format, intuitively presenting the current risk control status from a customer perspective. Based on configurable rules, the system calculates preliminary risk control measures for operational staff reference. Furthermore, it integrates previously scattered risk control functions for various accounts across different systems into a unified interface. Through manual confirmation processes at each level and automatic system verification to ensure measures meet minimum risk control requirements, it maximizes the accuracy of risk control measures, reducing operational and compliance risks. It also captures and sends the results of linked risk control actions to all responsible personnel. For failed risk control actions, personnel can re-initiate the risk control process, effectively mitigating operational risks.
[0047] like Figure 3 As shown, in a second aspect, this application provides a business risk control device based on direct system connection, comprising: The data acquisition module is configured to obtain account tags for each account of the target user; The risk account identification module is configured to determine the initial risk control measures for the target account based on the account tag if the current account is determined to be the target account based on the account tag. The first identity verification module is configured to send the account tag and initial risk control measures to the auditing end after hiding them. In response to the query request from the auditing end, it returns a first-level identity verification request to the auditing end. Based on the auditing end's response to the first-level identity verification request, it performs first-level identity verification on the auditing end and collects the response information of the auditing end during the response process. The second identity verification module is configured to generate a dynamic password based on the response information after the first-level identity verification is successful, and perform second-level identity verification on the auditing end based on the dynamic password. If the second-level identity verification is successful, the account tag of the target account and the initial risk control measures are displayed to the auditing end. The risk control measures execution module is configured to receive target risk control measures for the target account determined by the audit end based on the account tag, and execute the target risk control measures on the target account.
[0048] It should be noted that the division of the various modules in the above device is merely a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, these modules can be implemented entirely in software via processing elements; they can be fully implemented in hardware; or some modules can be implemented by processing elements calling software, while others are implemented in hardware. For example, the data acquisition module can be a separate processing element, or it can be integrated into a chip in the above device. Alternatively, it can be stored as program code in the memory of the above device, and its functions can be called and executed by a processing element. The implementation of other modules is similar. Moreover, these modules can be fully or partially integrated together, or they can be implemented independently. The processing element here can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above modules can be completed through integrated logic circuits in the hardware of the processor element or through software instructions.
[0049] In a third aspect, this application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method described above.
[0050] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 4 As shown, the electronic device may include: transceiver 121, processor 122, and memory 123.
[0051] Processor 122 executes computer execution instructions stored in memory, causing processor 122 to perform the scheme in the above embodiments. Processor 122 may be a general-purpose processor, including CPU, network processor (NP), etc.; it may also be a digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0052] The memory 123 is connected to the processor 122 via the system bus and completes communication between them. The memory 123 is used to store computer program instructions.
[0053] Transceiver 121 can be used to obtain the task to be run and its configuration information.
[0054] The system bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The system bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in the diagram, but this does not indicate that there is only one bus or one type of bus. Transceivers are used to enable communication between database access devices and other computers (e.g., clients, read-write libraries, and read-only libraries). Memory may include random access memory (RAM) and may also include non-volatile memory.
[0055] The electronic device provided in this application embodiment can be the terminal device described in the above embodiments.
[0056] In a fourth aspect, this application provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, are used to implement the method described above.
[0057] In a fifth aspect, this application provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0058] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0059] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A business risk control method based on direct system connection, characterized in that, include: Obtain account tags for each account of the target user; If the current account is determined to be the target account based on the account tag, the initial risk control measures for the target account are determined according to the account tag; The account tag and initial risk control measures are hidden and sent to the auditing end. In response to the query request of the auditing end, a first-level identity verification request is returned to the auditing end. The auditing end is then verified based on its response to the first-level identity verification request, and the response information of the auditing end during the response process is collected. If the first-level authentication is successful, a dynamic password is generated based on the response information. The second-level authentication is performed on the auditing end based on the dynamic password. If the second-level authentication is successful, the account tag and initial risk control measures of the target account are displayed to the auditing end. The system receives the target risk control measures for the target account determined by the review end based on the account tag, and executes the target risk control measures on the target account.
2. The business risk control method based on direct system connection according to claim 1, characterized in that, The account tag includes at least the account category and current risk control status of the corresponding account. Determining the current account as the target account based on the account tag includes: The account category and current risk control status are matched with a preset risk account identification table, wherein the risk account identification table includes at least a combination of account categories and risk control statuses for different risk accounts; If the account category and current risk control status match any combination of account category and risk control status in the risk account identification table, the current account is determined to be the target account. Determining initial risk control measures for the target account based on the account tags includes: The account category and current risk control status are matched with a preset risk control measures table, wherein the risk control measures table includes at least the risk control measures corresponding to different combinations of account categories and risk control statuses; The risk control measures corresponding to the combination of the account category and the current risk control status in the risk control measures table are determined as the initial risk control measures for the target account. The auditing terminal's response to the authentication request includes at least the auditing terminal's account and password; based on the auditing terminal's response to the authentication request, the auditing terminal performs first-level authentication, including: The auditing account and password are matched with a preset primary identity verification table, which includes at least combinations of accounts and passwords corresponding to different auditing ends. If the auditing account and password match any combination of account and password in the Level 1 authentication table, the auditing end is determined to have passed the Level 1 authentication.
3. The business risk control method based on direct system connection according to claim 1, characterized in that, The response information of the auditing terminal during the response process includes: the location change information of the external input device during the response process; and the generation of a dynamic password based on the response information, including: The system receives position change information from the external input device, which is collected by the auditing end during the response process. Based on the location change information of the external input device, a first dynamic password is generated according to a preset dynamic password generation algorithm; The auditing terminal performs secondary authentication based on the dynamic password, including: After generating the first dynamic password, a secondary authentication request is returned to the auditing terminal; The system receives the response from the auditing end to the secondary authentication request and obtains the second dynamic password, which is generated by the auditing end based on the location change information of the external input device and according to the dynamic password generation algorithm. The first dynamic password is matched with the second dynamic password. If the first dynamic password matches the second dynamic password, it is determined that the auditing end has passed the second-level authentication.
4. The business risk control method based on direct system connection according to claim 3, characterized in that, The location change information of the external input device is collected by the verification terminal through the following steps: Obtain the start and end positions of the external input device in each acquisition cycle; For each collection cycle, the interval distance between the start position and the end position is determined, and the moving speed of the external input device within the current collection cycle is determined based on the interval distance, until the auditing end completes the response to the first-level identity verification request, thereby obtaining the moving speed set of the external input device and obtaining the position change information of the external input device.
5. The business risk control method based on direct system connection according to claim 4, characterized in that, The dynamic password generation algorithm includes: Randomly select multiple target movement speeds from the set of movement speeds; The movement speed of each target is normalized. The normalized target movement speeds are converted into a specified number format to obtain the target number sequence in the specified number format; The initial encrypted character sequence of the target number sequence is obtained by calculating the target number sequence using a specified encryption algorithm; Obtain the current time, and perform a specified operation on the initial encrypted character sequence using the current time as a random source to obtain the target encrypted character sequence of the target number; The first N characters of the target encrypted character sequence are used as the first dynamic password.
6. The business risk control method based on direct system connection according to claim 5, characterized in that, The normalized target movement speeds are converted into a specified number format to obtain a target number sequence in the specified number format, including: Determine the baseline calculation factor; The normalized target movement speeds are multiplied by the benchmark calculation factor, and the calculation results obtained by the multiplication operation are rounded down to obtain the integer part of each calculation result. Arrange the integer parts of each calculation result according to the execution order of the multiplication operation to obtain the target number sequence in the specified base format.
7. The business risk control method based on direct system connection according to claim 5, characterized in that, Using the current time as a random source, perform a specified operation on the initial encrypted character sequence to obtain the target encrypted character sequence of the target number, including: Determine the reference time, and determine the time interval between the current time and the reference time; The time interval is converted into a representation of a preset minimum time unit, and the resulting character sequence is converted into the specified base format to obtain an initial random source character sequence; If the length of the initial random source character sequence is less than the length of the initial encrypted character sequence, a padding operation is performed on the initial random source character sequence with a specified character until the length of the initial random source character sequence is the same as the length of the initial encrypted character sequence, thus obtaining the target random source character sequence; or If the length of the initial random source character sequence is greater than the length of the initial encrypted character sequence, the characters in the initial random source character sequence are discarded until the length of the initial random source character sequence is the same as the length of the initial encrypted character sequence, thus obtaining the target random source character sequence; Perform a specified operation on the target random source character sequence and the initial encrypted character sequence to obtain the target encrypted character sequence of the target number.
8. A business risk control device based on direct system connection, characterized in that, include: The data acquisition module is configured to obtain account tags for each account of the target user; The risk account identification module is configured to determine the initial risk control measures for the target account based on the account tag if the current account is determined to be the target account based on the account tag. The first identity verification module is configured to send the account tag and initial risk control measures to the auditing end after hiding them, respond to the query request of the auditing end, return a first-level identity verification request to the auditing end, perform first-level identity verification on the auditing end based on the auditing end's response to the first-level identity verification request, and collect the response information of the auditing end during the response process. The second authentication module is configured to generate a dynamic password based on the response information when the first-level authentication is successful, perform second-level authentication on the auditing end based on the dynamic password, and if the second-level authentication is successful, display the account tag and initial risk control measures of the target account to the auditing end. The risk control measures execution module is configured to receive the target risk control measures for the target account determined by the review end based on the account tag, and execute the target risk control measures on the target account.
9. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as claimed in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-7.
11. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-7.