System applied to fund supervision and bank interaction

By integrating with the identity authentication center, link management module, bank vault management module, and instruction management module, the problem of inconsistent interfaces when the enterprise's fund system is directly connected to multiple banks is solved, achieving low-cost, efficient fund management and unified security control.

CN121883142APending Publication Date: 2026-04-17CHENGDU FANGLIAN CLOUD CODE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHENGDU FANGLIAN CLOUD CODE TECH CO LTD
Filing Date
2026-01-06
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

When a company's financial system is directly connected to multiple banks, the interface standards are inconsistent, the development and maintenance costs are high, the system integration is complex, the business processes are fragmented, it is difficult to unify risk control, there are security vulnerabilities, and data silos hinder the generation and management of a global financial view.

Method used

The system employs an access and identity authentication center, a link management module, a bank database management module, and an instruction management module to achieve business access and identity authentication, uniformly configure communication channels, and abstract bank-business interaction operations into instructions for standardized encapsulation and integration.

Benefits of technology

It achieves "one-time access, multiple uses", reducing the bank's access cost and development cycle, improving system agility and fund security, and providing global fund data and precise management support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121883142A_ABST
    Figure CN121883142A_ABST
Patent Text Reader

Abstract

The invention discloses a system applied to fund supervision and bank interaction, and the system comprises an access and identity authentication center which is used for achieving business access and identity authentication; the link management module is used for uniformly configuring, scheduling, monitoring and maintaining all physical and logic communication channels between the system and an external system; the bank library management module is used for centrally and uniformly managing basic information, connection configuration and access control strategies of all cooperative banks; and the instruction management module is used for abstracting all interactive operations of the bank and the business system into instructions to realize thorough decoupling of the business logic and the bank. According to the invention, cleaning and conversion of multi-source and heterogeneous bank data can be automatically completed, real-time and accurate global fund data are provided for enterprises, and accurate fund management and intelligent decision are effectively supported.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of fund supervision technology, and in particular to a system for fund supervision and interaction with banks. Background Technology

[0002] Currently, when enterprise treasury systems connect directly to multiple banks, they face core challenges such as inconsistent interface standards and high development and maintenance costs. The traditional point-to-point connection model necessitates repeated customized development for each bank, resulting in a "siloed" architecture. This leads to complex system integration, fragmented business processes, and difficulties in unified risk control. Furthermore, the lack of standardized interface protocols and message standards necessitates repetitive customized development for each bank, resulting in high system coupling, long development cycles, and enormous maintenance costs. In addition, fragmented transaction channels create data silos, hindering the generation and efficient management of a comprehensive treasury view. Core business logic and risk control strategies (such as approval and limit control) are scattered across various connection points, making unified management impossible and posing security vulnerabilities. Moreover, the inconsistent data formats returned by different banks create data silos, making it difficult for enterprises to quickly obtain a comprehensive and unified treasury view, thus limiting the efficiency of fund allocation and data analysis.

[0003] Therefore, there is an urgent need for a centralized technical solution to standardize, encapsulate, and integrate heterogeneous banking service capabilities. Summary of the Invention

[0004] The purpose of this invention is to provide a system for fund supervision and bank interaction, so as to achieve unified access, centralized management and control and capability reuse, thereby improving system agility and significantly reducing operation and maintenance costs.

[0005] This invention is achieved using the following technical solution: a system for fund supervision and bank interaction, comprising: Access and identity authentication center, used to enable business access and identity authentication; The link management module is used to uniformly configure, schedule, monitor, and maintain all physical and logical communication channels between this system and external systems. The bank database management module is used to centrally and uniformly manage the basic information, connection configuration, and access control policies of all partner banks. The instruction management module is used to abstract all interactions between the bank and the business system into instructions, thereby achieving complete decoupling of business logic from the bank.

[0006] Furthermore, the access and identity authentication center includes an application management module. This application management module is oriented towards business systems. When a business system needs to access the system, it provides a registration service and generates a globally unique application code as an identity identifier for all subsequent interactions.

[0007] Furthermore, the business system includes one or more of the following: existing housing fund system, pre-sale fund system, property fund system, and financial system.

[0008] Furthermore, the access and identity authentication center also includes a client management module. This client management module is designed for specific calling terminals or user terminals, assigning a unique client identifier to each terminal and generating a pair of asymmetric encryption keys based on national cryptographic algorithms to ensure communication security.

[0009] Furthermore, the link management module adopts a dual-link architecture, specifically including a business link and a bank link. The business link is the entry channel for receiving requests from various internal business systems, while the bank link is the exit channel for proactively initiating requests to the gateways of various banks.

[0010] Furthermore, the link management module also includes a health management submodule and a log management submodule. The health management submodule periodically sends heartbeat or harmless test commands to all enabled bank links and dynamically updates the link status based on the response results. The log management submodule records the communication details of each link, including one or more of the following: basic link information, request information, response information, performance indicators, and status.

[0011] Furthermore, the bank database management module is used to manage basic bank information and, through a binding and authorization mechanism, ensures that bank service capabilities can be securely, compliantly, and efficiently scheduled and used. The binding and authorization mechanism includes application binding, bank link binding, and link authorization instructions, wherein the link authorization instructions execute the principle of least privilege.

[0012] Furthermore, the instructions include standard instructions and custom instructions. Standard instructions are predefined instructions for operations with strong generality and fixed business models, while custom instructions are instructions created for personalized and complex processes in specific business scenarios.

[0013] Furthermore, the instruction management module also includes a parameter management submodule, which predefines the set of standard input parameters required for the execution of each instruction template. Each parameter includes a name, type, whether it is required, validation rules, and example value data.

[0014] The beneficial effects of this invention are as follows: This invention standardizes and encapsulates heterogeneous banking services through a technology platform, achieving "one-time access, multiple reuses," significantly reducing subsequent bank integration costs and development cycles, and improving system agility. By centralizing payment, inquiry, and other business processes and risk control strategies within the platform, it enables end-to-end monitoring and unified security governance of all enterprise fund transactions, significantly enhancing fund security. Furthermore, this invention can automatically clean and transform multi-source, heterogeneous banking data, providing enterprises with real-time, accurate global fund data, effectively supporting precise fund management and intelligent decision-making. Attached Figure Description

[0015] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the structures shown in these drawings without creative effort.

[0016] Figure 1 This is a system block diagram of the present invention. Detailed Implementation

[0017] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0018] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0019] The following detailed description of some embodiments of the present invention is provided in conjunction with the accompanying drawings. Unless otherwise specified, the following embodiments and features can be combined with each other.

[0020] See Figure 1A system for fund supervision and bank interaction includes: an access and identity authentication center for business access and identity authentication; a link management module for unified configuration, scheduling, monitoring, and maintenance of all physical and logical communication channels between this system and external systems; a bank database management module for centralized and unified management of basic information, connection configurations, and access control policies of all cooperating banks; and an instruction management module for abstracting all interactive operations between the bank and the business system into instructions, achieving complete decoupling of business logic from the bank. The access and identity authentication center includes an application management module, which is oriented towards the business system. When the business system needs to access, it provides a registration service and generates a globally unique application code as an identity identifier in all subsequent interaction processes.

[0021] In summary, this invention mainly comprises several modules: application management, client management, link management, bank database, and instruction management. These five modules constitute a logically rigorous technical platform management system. Application / client management solves the problem of "who can use it," bank database / link management solves the problem of "where to connect and how to connect," while instruction management solves the core problem of "what to do and how to do it." Through modular design, the system achieves high configurability, scalability, and maintainability. Its core is to standardize the interaction interface between the business system and the bank. Common requests (such as "payment") are standardized through the platform, then routed to the target bank according to the configuration, and the bank's response is converted back to a standard format and returned to the business system. The entire process is transparent to the business system, achieving decoupling between the business and bank interfaces.

[0022] The Access and Identity Authentication Center serves as the sole external entry point and security barrier for the entire technology platform. Its core design goal is to standardize business access and securely authenticate identities. By abstracting the requester into two layers—"application" and "client"—it enables refined management of upstream and downstream business systems, ensuring that every call to the platform is trustworthy, controllable, and traceable. Specifically, application management defines "which system can do what," while client management pinpoints "which terminal is operating and verifying its authenticity." Together, they form a multi-layered, in-depth security defense system. Furthermore, the Access and Identity Authentication Center utilizes asymmetric encryption authentication based on national cryptographic algorithms, effectively preventing identity impersonation and data tampering, meeting financial-grade security compliance requirements, and implementing multi-level permission and resource control from the system to the terminal. This allows any transaction to be accurately traced back to the source application and specific client, providing a solid foundation for security auditing.

[0023] Application management targets the logical entity of a business system, such as a housing inventory fund system, a pre-sale fund system, a property fund system, and a financial system. When a business system needs to connect to the middle platform, it must register in this module. The system will assign it a globally unique application code (sceneCode), which will serve as the identity identifier for that business system in all subsequent interactions.

[0024] Client management, building upon application management, further refines the process down to specific calling terminals or users, and is crucial for achieving high-security auditing and fine-grained control. A business system (application) can have multiple clients. For example, the finance and production modules of an ERP system can function as two independent clients. Each client is assigned a unique client identifier (appKey), and the system dynamically generates a pair of asymmetric encryption keys based on Chinese cryptographic algorithms (such as SM2) for each client: a private key and a public key. This is the core of authentication and secure communication, and every API call follows this process. Request signature (client): Before initiating a request, the client concatenates the request parameters (such as timestamps, random numbers, and business data) into a string to be signed according to predetermined rules.

[0025] Use your own SM2 private key to digitally sign this string.

[0026] The signature result, AppKey, and business data are sent together to the middleware gateway.

[0027] Verification of signatures and identity (middle platform): After receiving the request, the middleware gateway first finds the SM2 public key corresponding to the client that is pre-stored in the client management based on the AppID and ClientID in the AppKey.

[0028] Use the public key to verify the received signature. If the verification is successful, it proves that the request did indeed come from a legitimate client and that the data was not tampered with during transmission, thus completing the client's authentication.

[0029] Data encryption and secure response (optional enhanced security): For responses to highly sensitive data, the middleware can use the client's SM2 public key to encrypt the returned results, ensuring that only the client holding the corresponding private key can decrypt and view them.

[0030] Similarly, when a client uploads highly sensitive data, it can also use the middleware's public key (pre-assigned to the client) for encryption.

[0031] The core responsibility of the link management module is to uniformly configure, schedule, monitor, and maintain all physical and logical communication channels between the technology platform and external systems (including upstream business systems and downstream banking systems). Its design goal is to achieve high availability, load balancing, rapid fault recovery, and end-to-end observability of communication links. Specifically, it adopts a dual-link architecture, clearly dividing the links into "business links" and "banking links," achieving traffic separation and fine-grained management. The link management module can collaborate with the bank database to obtain basic connection information and security credentials from the bank, and with instruction management to provide the optimal and most stable communication channel for upcoming bank instructions, and receive the execution results of the instructions to update the link status and record logs.

[0032] The business link refers to the entry channel through which the technology platform receives requests from various internal business systems. It focuses on "who accesses me"; its configuration includes: service address and port: the API gateway address exposed externally by the platform; context path: paths divided for different businesses or versions, such as / api / v1 / payment, / api / v2 / query; protocol and policy: configuring the protocol used (e.g., HTTPS), connection timeout, read / write timeout, etc.

[0033] The bank link refers to the outbound channel initiated by the technology platform to the gateways of various banks. It focuses on "how I connect to the bank"; its configuration includes: Bank gateway address: the target bank's interface IP or domain name and port, such as https: / / ebank.icbc.com.cn:443. Communication protocol: adapting to the requirements of different banks, such as HTTPS and HTTP.

[0034] The link management module also includes a health management submodule and a logging submodule. The health management submodule manages the lifecycle and health of the links. The system periodically (e.g., every 30 seconds) sends "heartbeats" or harmless test commands (such as balance inquiries) to all enabled bank links. Based on the response results (success, timeout, connection rejection, etc.), the link status is dynamically updated. If healthy (continuous successes), the link is marked green and usable; if faulty (continuous failures exceeding a threshold), the link is marked red and automatically disabled. The logging submodule is crucial for achieving end-to-end observability, recording the details of each communication through the link. Log entries include: basic link information: link ID, destination address, protocol; request information: complete outgoing message (anonymized), request timestamp, associated business transaction number; response information: original message returned by the bank, response timestamp, HTTP status code, business status code; performance metrics: total request time, connection establishment time, network transmission time; status: success / failure, with error code and reason recorded for failure.

[0035] It's important to note that the value and uses of logs include: Problem troubleshooting and localization: When a transaction encounters a problem, the specific request log can be quickly located using the business transaction number, allowing for examination of the original sent and received messages and rapid determination of whether the issue stems from a network problem, a bank-side problem, or a message format problem. Performance analysis: Statistical analysis of the average response time of the transaction chain identifies performance bottlenecks, providing data support for optimization. Auditing and reconciliation: Providing tamper-proof communication credentials for reconciliation with banks or to meet compliance audit requirements. Capacity planning: Analyzing traffic data provides a basis for future system expansion decisions.

[0036] The core responsibility of the bank database management module is to centrally and uniformly manage the basic information, connection configurations, and access control policies of all partner banks. Its design goal is to achieve the digitization, service-orientation, and strategic management of bank resources, ensuring that bank service capabilities can be securely, compliantly, and efficiently scheduled and used through flexible binding and authorization mechanisms. This module provides basic bank information management services, establishing a complete digital profile for each bank.

[0037] In addition, the bank vault management module also provides application binding, bank link binding, and link authorization instructions. Application binding (permission isolation and business orientation) solves the problem of "which business system has the right to access which bank," enabling on-demand allocation of bank service capabilities. Binding relationship: Many-to-many relationship between banks and applications. Permission isolation: Prevents business systems from accessing unauthorized banks, meeting enterprise internal control and compliance requirements. Even if an application obtains a legitimate AppKey, it can only access the bank it is bound to. Resource planning: Clearly defines the funding channel range for each business system, facilitating cost allocation and business planning. Bank link binding (resource scheduling and high availability) solves the problem of "which specific communication paths are used when accessing a bank." Binding relationship: Associates a bank with the bank links pre-configured in the link management module that lead to that bank. A bank can be bound to multiple links (such as primary links, backup links, and links from different data centers). Link authorization instructions (refined risk control and process control): This is the most refined control level, solving the problem of "which specific operations are allowed to be performed on a specific link." Authorize one or more instruction templates for a single banking transaction. Instruction templates are defined in the instruction management module, encapsulating specific business actions (such as "single payment instruction" and "balance inquiry instruction") and their processing logic. The authorization of instructions for a transaction follows the principle of least privilege: even if the transaction is operational, only explicitly authorized operations can be executed, greatly reducing errors and potential risks.

[0038] The instruction management module abstracts all interactions between the bank and its business systems into instructions. Its design goal is to completely decouple business logic from the bank's specific implementation. Through template-based and configurable methods, it transforms complex financial transactions into standardized, reusable, and monitorable "instructions," thereby giving the middle platform extremely high flexibility. These instructions mainly include: Standard instructions: Predefined instructions for operations with strong generality and fixed business models. They are abstracted and encapsulated best practices that can be reused across business systems. Custom instructions: Instructions created to meet the personalized and complex processes of specific business scenarios, enabling business process innovation without modifying the underlying code.

[0039] In addition, the instruction management module includes a parameter management submodule, which predefines the set of standard input parameters required for the execution of each instruction template. Each parameter contains metadata such as name, type (e.g., string, number, amount), whether it is required, validation rules (e.g., regular expression, range), and example value.

[0040] For the foregoing embodiments, in order to simplify the description, they are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, because according to this application, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to this application.

[0041] The above embodiments describe the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Modifications and variations made by those skilled in the art without departing from the spirit and scope of the invention should be within the protection scope of the appended claims.

Claims

1. A system for application in funds monitoring and bank interaction, characterized by, include: Access and identity authentication center, used to enable business access and identity authentication; The link management module is used to uniformly configure, schedule, monitor, and maintain all physical and logical communication channels between this system and external systems. The bank database management module is used to centrally and uniformly manage the basic information, connection configuration, and access control policies of all partner banks. The instruction management module is used to abstract all interactions between the bank and the business system into instructions, thereby achieving complete decoupling of business logic from the bank.

2. The system for fund supervision and bank interaction as described in claim 1, characterized in that, The access and identity authentication center includes an application management module. This module is oriented towards business systems. When a business system needs to access the system, it provides a registration service and generates a globally unique application code, which serves as an identity identifier for all subsequent interactions.

3. A system for fund supervision and bank interaction as described in claim 2, characterized in that, The business system includes one or more of the following: existing housing fund system, pre-sale fund system, property fund system, and financial system.

4. A system for fund supervision and bank interaction as described in claim 2, characterized in that, The access and identity authentication center also includes a client management module. This module is designed for specific calling terminals or user terminals, assigns a unique client identifier to each terminal, and generates a pair of asymmetric encryption keys based on national cryptographic algorithms to ensure communication security.

5. A system for fund supervision and bank interaction as described in claim 1, characterized in that, The link management module adopts a dual-link architecture, specifically including a business link and a bank link. The business link is the entry channel for receiving requests from various internal business systems, while the bank link is the exit channel for proactively initiating requests to the gateways of various banks.

6. A system for fund supervision and bank interaction as described in claim 5, characterized in that, The link management module also includes a health management submodule and a log management submodule. The health management submodule periodically sends heartbeat or harmless test commands to all enabled bank links and dynamically updates the link status based on the response results. The log management submodule records the communication details of each link, including one or more of the following: basic link information, request information, response information, performance indicators, and status.

7. A system for fund supervision and bank interaction as described in claim 1, characterized in that, The bank database management module is used to manage basic bank information and ensures that bank service capabilities can be securely, compliantly, and efficiently scheduled and used through a binding and authorization mechanism. The binding and authorization mechanism includes application binding, bank link binding, and link authorization instructions, wherein the link authorization instructions execute the principle of least privilege.

8. A system for fund supervision and bank interaction as described in claim 1, characterized in that, The instructions include standard instructions and custom instructions. Standard instructions are predefined instructions for operations with strong generality and fixed business models, while custom instructions are instructions created for personalized and complex processes in specific business scenarios.

9. A system for fund supervision and bank interaction as described in claim 8, characterized in that, The instruction management module also includes a parameter management submodule, which predefines the set of standard input parameters required for the execution of each instruction template. Each parameter includes name, type, whether it is required, verification rules, and example value data.