Risk early warning method, device, equipment and medium

By acquiring and analyzing business information from third-party institutions calling API interfaces, and using big data models and rules to assess risks, the problem of difficult manual screening in the management of API interfaces for financial institutions has been solved, achieving efficient risk warning and security management.

CN121961709APending Publication Date: 2026-05-01INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
INDUSTRIAL AND COMMERCIAL BANK OF CHINA
Filing Date
2025-06-30
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Financial institutions have a large number of open API interfaces, which makes manual management and risk assessment difficult, inefficient and costly.

Method used

By acquiring business information from third-party organizations when they call API interfaces, including identification information, business status information, response information, and address information, a pre-trained API monitoring big data model and preset rules are used to determine whether risk warnings are needed, and risk warning information is issued when necessary, and API interface permissions are suspended or closed.

Benefits of technology

It improved the efficiency of risk assessment, reduced manpower and material costs, and ensured the secure management and use of API interfaces.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121961709A_ABST
    Figure CN121961709A_ABST
Patent Text Reader

Abstract

The invention provides a risk early warning method which can be applied to the technical field of big data. The method comprises the following steps: obtaining service information when a third-party mechanism calls a specified API interface to process a service, the specified API interface being an API interface opened by a financial mechanism, the service information at least comprises at least one of identification information of the third-party mechanism, service state information of the service, response information of the specified API interface and address information of the third-party mechanism; and determining whether risk early warning is needed based on the service information. The invention further provides a risk early warning device and equipment and a storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of big data, specifically to a risk warning method, device, equipment, and medium. Background Technology

[0002] In related technologies, many financial institutions will develop financial services to the outside world in the form of API interfaces in order to better expand their business. These API interfaces can be called by other financial or non-financial third-party platforms to help their customers complete various services such as utility bill payments, online payments, and acquiring. Some financial institutions may have thousands of open API interfaces, which are difficult to manage manually and risk assessment, requiring a lot of manpower and resources. Summary of the Invention

[0003] In view of the above problems, this disclosure provides a risk warning method, device, equipment and medium.

[0004] According to a first aspect of this disclosure, a risk warning method is provided, comprising: obtaining business information when a third-party institution calls a specified API interface to process business, wherein the specified API interface is an API interface opened by a financial institution, and the business information includes at least one of the following: the identification information of the third-party institution, the business status information of the business, the response information of the specified API interface, and the address information of the third-party institution; and determining whether a risk warning is required based on the business information.

[0005] According to embodiments of this disclosure, determining whether a risk warning is needed based on the business information includes:

[0006] Based on preset rules, it is determined whether the transaction instruction received by the specified API interface is an instruction issued by the target object. The target object is a third-party institution with the financial institution whose contract status is "signed". The "signed" status is used to authorize the third-party institution to connect to the specified API interface to process specified business.

[0007] If the transaction instruction received by the API interface is not issued by the target object, a risk warning message will be issued.

[0008] According to embodiments of this disclosure, the method further includes:

[0009] Add a target field to the input field of the specified API interface, the target field representing the identification information of the third-party organization;

[0010] The step of determining whether a transaction instruction received by the API interface is an instruction issued by the target object based on preset rules includes:

[0011] Determine whether the target field exists in the input fields of the API interface;

[0012] The target field is not present in the input fields of the API interface, and the transaction instruction received by the API interface is not an instruction issued by the target object;

[0013] If the target field exists in the input fields of the API interface, it is determined that the transaction instruction received by the API interface is an instruction issued by the target object.

[0014] According to embodiments of this disclosure, the business status information includes business status, API interface status, and third-party institution contract status. Determining whether a risk warning is needed based on the business information includes:

[0015] When the business is closed and the third-party institution's contract status is open, a risk warning message will be issued;

[0016] When the business status is open, the API interface status is closed, and the third-party institution's contract status is closed, a risk warning message will be issued.

[0017] According to embodiments of this disclosure, determining whether a risk warning is needed based on the business information includes:

[0018] Determine whether the response information of the specified API interface includes first information and / or the identity information of the second-party user, wherein the first information represents the second-party user's information regarding the handling of the business;

[0019] If the response information of the specified API interface includes the first information, a risk warning message is issued;

[0020] If the response information of the specified API interface includes the identity information of the second-party user, a risk warning message will be issued.

[0021] According to embodiments of this disclosure, determining whether a risk warning is needed based on the business information includes:

[0022] Obtain the number of the designated agreement between the third-party institution and the financial institution;

[0023] Determine the identification information of the third-party organization corresponding to the number and / or the historical address information of the third-party organization;

[0024] If the identification information of the third-party organization is not the same as the identification information of the corresponding third-party organization, a risk warning message will be issued;

[0025] If the historical address information is not found in the address information of the third-party organization, a risk warning will be issued.

[0026] According to embodiments of this disclosure, the method further includes:

[0027] If a risk warning is issued, the business will be suspended and / or the third-party organization's permission to call the specified API interface will be revoked.

[0028] According to embodiments of this disclosure, determining whether a risk warning is needed based on the business information includes:

[0029] The business information is input into a pre-trained API monitoring big data model to obtain a result indicating whether a risk warning is needed. The pre-trained API monitoring big data model is trained by using business information from third-party organizations calling specified API interfaces to process business as a training set.

[0030] A second aspect of this disclosure provides a risk warning device, the device comprising:

[0031] The acquisition module is used to acquire business information when a third-party institution calls a specified API interface to process business. The specified API interface is an API interface opened by a financial institution. The business information includes at least one of the following: the identification information of the third-party institution, the business status information of the business, the response information of the specified API interface, and the address information of the third-party institution.

[0032] The determination module is used to determine whether a risk warning is needed based on the business information.

[0033] A third aspect of this disclosure provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method described above.

[0034] A fourth aspect of this disclosure also provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the above-described method.

[0035] The fifth aspect of this disclosure also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described method. Attached Figure Description

[0036] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0037] Figure 1 This illustration schematically depicts application scenarios of the risk warning method, apparatus, device, and medium according to embodiments of the present disclosure.

[0038] Figure 2 A flowchart illustrating a risk warning method according to an embodiment of the present disclosure is shown schematically;

[0039] Figure 3 A flowchart illustrating another risk warning method according to an embodiment of this disclosure is shown schematically;

[0040] Figure 4 A flowchart illustrating another risk warning method according to an embodiment of this disclosure is shown schematically;

[0041] Figure 5 A flowchart illustrating another risk warning method according to an embodiment of this disclosure is shown schematically;

[0042] Figure 6 A flowchart illustrating another risk warning method according to an embodiment of this disclosure is shown schematically;

[0043] Figure 7 A schematic diagram illustrating the structure of a risk warning device according to an embodiment of the present disclosure is shown; and

[0044] Figure 8 A block diagram schematically illustrates an electronic device suitable for implementing a risk warning method according to an embodiment of the present disclosure. Detailed Implementation

[0045] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0046] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0047] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0048] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).

[0049] In the technical solution disclosed herein, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, necessary confidentiality measures have been taken, and they do not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse.

[0050] In scenarios involving automated decision-making using personal information, the methods, devices, and systems provided in this disclosure all offer users corresponding entry points for choosing to agree to or reject the automated decision-making results. If the user chooses to reject, the process proceeds to the expert decision-making stage. Here, "automated decision-making" refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, or economic, health, and credit status through computer programs, and then making a decision. Here, "expert decision-making" refers to the activity of making decisions by personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise.

[0051] This disclosure provides a risk warning method, comprising: obtaining business information when a third-party institution calls a specified API interface to process business, wherein the specified API interface is an API interface opened by a financial institution, and the business information includes at least one of the following: the identifier information of the third-party institution, the business status information, the response information of the specified API interface, and the address information of the third-party institution; and determining whether a risk warning is needed based on the business information. This method solves the problems of difficulty, low efficiency, and high cost associated with manual investigation, and ensures the secure management and use of financial institution API interfaces.

[0052] Figure 1 The diagram illustrates an application scenario of the risk warning method according to an embodiment of the present disclosure.

[0053] like Figure 1As shown, application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.

[0054] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send messages, etc. The first terminal device 101, the second terminal device 102, and the third terminal device 103 can develop financial services externally via API interfaces, which can be called by other financial or non-financial institutions to help customers complete various financial transactions such as utility bill payments, online payments, and acquiring on the third-party platform.

[0055] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0056] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). For instance, it could be a server that supports the business operations of a financial institution. Server 105 can analyze and process received requests and other data, and feed back the processing results (such as risk warning results obtained or generated based on requests) to the terminal devices.

[0057] It should be noted that the risk warning method provided in this embodiment can generally be executed by server 105. Correspondingly, the risk warning device provided in this embodiment can generally be located in server 105. The risk warning method provided in this embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the risk warning device provided in this embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.

[0058] It should be understood that Figure 1The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0059] The following will be based on Figure 1 The described scene, through Figures 2-6 The risk warning method of the disclosed embodiments is described in detail.

[0060] Figure 2 A flowchart illustrating a risk warning method according to an embodiment of the present disclosure is shown.

[0061] like Figure 2 As shown, the risk warning method in this embodiment includes operations S210 to S220.

[0062] In operation S210, business information is obtained when a third-party organization calls a specified API interface to process business.

[0063] According to the embodiments of this disclosure, the designated API interface is an API interface opened by a financial institution, allowing third-party institutions (such as technology companies, merchants, etc.) to call the API interface to carry out business such as payment, payment, and acquiring after successfully connecting to the API interface.

[0064] Among them, third-party institutions refer to external partners who are not financial institutions and integrate financial services into their own businesses by calling APIs, such as e-commerce platforms calling payment interfaces to complete transactions.

[0065] According to embodiments of this disclosure, the business information includes at least one of the following: the identification information of a third-party organization, the business status information of the business, the response information of a specified API interface, and the address information of the third-party organization.

[0066] According to embodiments of this disclosure, the third-party organization identification information can be a unique identifier used to distinguish different callers. For example, the third-party organization identification information may be the organization's ID, the key used by the third-party organization to use the API interface, etc.

[0067] According to embodiments of this disclosure, business status information can refer to the business relationships and operational status between financial institutions, third-party institutions, and API interfaces. Business status information may include key statuses such as business status, API interface status, and third-party institution contract status.

[0068] Business status can refer to whether a certain business (such as loan, payment, account management, etc.) is open (can be processed) or closed (cannot be processed).

[0069] API interface status can refer to whether the API interface provided by the financial institution is available (open) or unavailable (closed).

[0070] The contract status of a third-party organization can refer to the authorization status of the third-party organization in this business, such as "contracted (can be called)" or "closed (cannot be called)".

[0071] According to embodiments of this disclosure, API response information may be feedback data returned by a financial institution's API interface to a third-party institution after processing a transaction request.

[0072] According to embodiments of this disclosure, the address information of a third-party institution can refer to the network identity identifier of the third-party institution that calls the API interface of a financial institution. For example, the address information can be an IP address (IPv4 / IPv6): used to identify the network location of the request source; and an ASN (Autonomous System Number): identifying the network operator to which the IP belongs.

[0073] When operating S220, based on business information, determine whether a risk warning is needed.

[0074] Based on business information analysis, potential risks are identified, such as: abnormal behavior detection: high frequency of failed calls from the same institution within a short period of time (possibly a credential stuffing attack); geographical risks: sudden switching of IP addresses to high-fraud areas overseas; abnormal status: a large number of "successful transactions" but actual funds not received (possibly forged responses); and risk of association: an institution's ID has been marked as blacklisted or associated with historical violations.

[0075] According to embodiments of this disclosure, by obtaining business information when a third-party institution calls a specified API interface to process business, where the specified API interface is an API interface opened by a financial institution, the business information includes at least one of the following: the third-party institution's identification information, the business status information, the response information of the specified API interface, and the third-party institution's address information. Based on this business information, it is determined whether a risk warning is needed. This can solve the technical problems of difficult, inefficient, and costly manual investigation, and ensure the secure management and use of financial assets and customer information by financial institutions.

[0076] According to the embodiments of this disclosure, business information is input into a pre-trained API monitoring big data model to obtain a result on whether risk warning is needed. The pre-trained API monitoring big data model is trained by using business information from third-party organizations calling specified API interfaces to process business as a training set.

[0077] The input to the API monitoring big data model is real-time business information from API interface processing. The output of the API monitoring big data model can be whether a risk warning is needed, or the risk warning level, such as high risk / medium risk / low risk / normal.

[0078] The training data in the training set can cover multi-dimensional business information, including the following fields: third-party organization identification information, business status information, API response information, address information, and time-series behavioral characteristics.

[0079] Supervised learning can be used to train a big data model for API monitoring. In supervised learning, labels are defined as manually marked risk events in historical data (e.g., 1 = attack, 0 = normal). Algorithms can include random forests / XGBoost and LSTM neural networks. The training objective can be to maximize the balance between precision and recall, avoiding the false positives on legitimate requests.

[0080] Figure 3 A flowchart illustrating another risk warning method according to an embodiment of this disclosure is shown schematically.

[0081] like Figure 3 As shown, the risk warning method in this embodiment includes operations S310 to S320.

[0082] When operating S310, based on preset rules, it is determined whether the transaction instruction received by the specified API interface is an instruction issued by the target object.

[0083] According to the embodiments of this disclosure, the target object is a third-party institution with a signed contract status with a financial institution. The signed contract status is used to authorize the third-party institution to connect to a specified API interface to process specified business.

[0084] The target entity refers to a third-party institution that has signed a formal agreement with a financial institution and has legal access to call the API. It must meet the following requirements: have a unique institution number (such as ORG_2023_001), have a contract status of "signed" (not "under testing", "terminated", "business closed" or "blacklisted"), and have a clear scope of authorized business (such as only allowing calls to the payment interface and prohibiting calls to the account query interface).

[0085] When operating the S320, if the transaction instruction received by the API interface is not issued by the target object, a risk warning message is issued.

[0086] According to embodiments of this disclosure, a target field can be added to the input field of a specified API interface, and the target field represents the identification information of a third-party organization.

[0087] For example, all API requests must include the third-party organization ID field (e.g., client_id: ORG_2023_001).

[0088] According to embodiments of this disclosure, it can be determined whether a target field exists in the input fields of an API interface. If the target field does not exist in the input fields of the API interface, the transaction instruction received by the API interface is not an instruction issued by the target object. If the target field exists in the input fields of the API interface, it is determined that the transaction instruction received by the API interface is an instruction issued by the target object.

[0089] Understandably, the API interface input fields have been expanded to include a new target field. When a financial institution receives a transaction instruction from a third-party institution, it checks whether the target field is present in the new check fields. If not, the transaction is rejected. If it is present, the financial institution checks whether the identifier information of the third-party institution represented by the target field matches the saved identifier information of the contracted third-party institution. If the comparison is successful, the third-party institution is considered the target and the transaction is processed. Furthermore, if the check finds that the third-party institution is the target but its contract status is abnormal, a risk warning is issued.

[0090] Figure 4 A flowchart illustrating another risk warning method according to an embodiment of this disclosure is shown schematically.

[0091] like Figure 4 As shown, the risk warning method in this embodiment includes operations S410 to S420.

[0092] When operating S410, if the business status is closed and the third-party institution's contract status is open, a risk warning message is issued.

[0093] In this embodiment of the disclosure, a risk warning is issued when the business status is closed, the API interface status is closed, and the third-party institution contract status is open. A risk warning is also issued when the business status is closed, the API interface status is open, and the third-party institution contract status is open.

[0094] When operating S420, if the business status is open, the API interface status is closed, and the third-party institution's contract status is closed, a risk warning message will be issued.

[0095] In some embodiments of this disclosure, no risk warning information needs to be issued when the business status is open, the API interface status is open, and the third-party institution's contract status is signed. No risk warning information needs to be issued when the business status is closed, the API interface status is closed, and the third-party institution's contract status is closed.

[0096] According to embodiments of this disclosure, when it is detected that the service has been shut down, but the API interface is not shut down or the status of the contracted customer is not updated synchronously, a risk warning message is issued and manual intervention is required for investigation.

[0097] Figure 5 A flowchart illustrating another risk warning method according to an embodiment of this disclosure is shown schematically.

[0098] like Figure 5 As shown, the risk warning method in this embodiment includes operations S510 to S530.

[0099] In operation S510, determine whether the response information of the specified API interface includes first information and / or the identity information of the second-party user.

[0100] According to the embodiments of this disclosure, the first information represents the second-party user's information regarding the handling of the business, referring to the business status or process details exposed in the API response. For example, the first information may be "Please check after 3 working days after submitting the application materials" (indicating that the user has submitted an application), "Your loan approval is being processed" (exposing the business progress), "The user is under review on the blacklist," etc.

[0101] According to embodiments of this disclosure, the second-party user identity information may refer to sensitive personal data of customers that are directly or indirectly exposed in the response, such as complete or partial mobile phone numbers (e.g., 133XXXX1111), ID card numbers (e.g., 110102319880818XXXX), bank card numbers, names, and other PII (Personal Identification Information).

[0102] When operating the S520, if the response information of the specified API interface includes the first information, a risk warning message is issued.

[0103] When operating S530, if the response information of a specified API interface includes the identity information of a second-party user, a risk warning message is issued.

[0104] According to embodiments of this disclosure, if the response information contains identity information, a risk warning should be issued, and the error information should be manually reviewed to determine whether it should be modified.

[0105] Figure 6 A flowchart illustrating another risk warning method according to an embodiment of this disclosure is shown schematically.

[0106] like Figure 6 As shown, the risk warning method in this embodiment includes operations S610 to S640.

[0107] In operation S610, obtain the number of the designated agreement between the third-party institution and the financial institution.

[0108] The protocol number is a unique business identifier (such as CONTRACT_2023_XYZ) assigned by the financial institution to each contracted third-party institution, which is used to associate all its API call behavior.

[0109] In operation S620, determine the identification information of the third-party organization corresponding to the number and / or the historical address information of the third-party organization.

[0110] The identification information can be unique information that identifies a third-party organization, such as the organization ID (CLIENT_123), API key, or unified social credit code.

[0111] Historical address information can be a fixed IP address or IP range that a financial institution requires a third-party institution to register when accessing the API interface, or it can be an IP address or IP range that the third-party institution frequently uses. For example, it can record the third-party institution's historically frequently used IP addresses / IP ranges (such as 90% of requests in the past 30 days coming from 203.0.113.0 / 24).

[0112] When operating S630, a risk warning is issued if the identification information of a third-party organization is not the same as that of the corresponding third-party organization.

[0113] For example, an API call might carry the protocol number CONTRACT_2023_XYZ, but the third-party organization's identifier might be CLIENT_456 (not CLIENT_123, which is not bound to the protocol).

[0114] When operating S640, a risk warning is issued if the address information of a third-party institution does not contain historical address information.

[0115] For example, the historical IP address for protocol number CONTRACT_2023_XYZ is 203.0.113.1, but this call comes from 198.51.100.1 (an unregistered IP address).

[0116] According to the embodiments of this disclosure, it is possible to detect whether there are frequent changes in IP addresses or behaviors from different third-party organizations under the same protocol number. If so, a risk warning will be issued, and manual intervention will be required to investigate the risks.

[0117] According to embodiments of this disclosure, in the event of a risk warning, business operations are suspended and / or the permission for third-party organizations to call specified API interfaces is closed.

[0118] Based on the above-mentioned risk warning method, this disclosure also provides a risk warning device. The following will combine... Figure 7 The device is described in detail.

[0119] Figure 7 A schematic block diagram of a risk warning device according to an embodiment of the present disclosure is shown.

[0120] like Figure 7 As shown, the risk warning device 700 of this embodiment includes an acquisition module 710 and a determination module 720.

[0121] The acquisition module 710 is used to acquire business information when a third-party institution calls a specified API interface to process business. The specified API interface is an API interface opened by a financial institution. The business information includes at least one of the following: the identification information of the third-party institution, the business status information, the response information of the specified API interface, and the address information of the third-party institution. In one embodiment, the acquisition module 710 can be used to perform the operation S210 described above, which will not be repeated here.

[0122] The determination module 720 is used to determine whether a risk warning is needed based on business information. In one embodiment, the determination module 720 can be used to perform the operation S220 described above, which will not be repeated here.

[0123] According to embodiments of this disclosure, determining whether a risk warning is needed based on business information includes: determining, based on preset rules, whether the transaction instruction received by the specified API interface is an instruction issued by the target object, wherein the target object is a third-party institution with a financial institution whose contract status is "signed" and the "signed" status is used to authorize the third-party institution to connect to the specified API interface to process the specified business; and issuing a risk warning message if the transaction instruction received by the API interface is not an instruction issued by the target object.

[0124] According to embodiments of this disclosure, the apparatus 700 further includes: an adding module, configured to add a target field to an input field of a specified API interface, the target field representing the identification information of a third-party organization; determining whether a transaction instruction received by the API interface is an instruction issued by a target object based on preset rules includes: determining whether a target field exists in the input field of the API interface; if a target field does not exist in the input field of the API interface, the transaction instruction received by the API interface is not an instruction issued by the target object; if a target field exists in the input field of the API interface, the transaction instruction received by the API interface is determined to be an instruction issued by the target object.

[0125] According to embodiments of this disclosure, the business status information includes business status, API interface status, and third-party institution contract status. Based on the business information, determining whether a risk warning is needed includes: issuing a risk warning when the business status is closed and the third-party institution contract status is open; and issuing a risk warning when the business status is open, the API interface status is closed, and the third-party institution contract status is closed.

[0126] According to embodiments of this disclosure, determining whether a risk warning is needed based on business information includes: determining whether the response information of a specified API interface includes first information and / or the identity information of a second-party user, wherein the first information represents the second-party user's business processing information; issuing a risk warning if the response information of the specified API interface includes the first information; and issuing a risk warning if the response information of the specified API interface includes the identity information of a second-party user.

[0127] According to embodiments of this disclosure, determining whether a risk warning is needed based on business information includes: obtaining the number of a designated agreement between a third-party institution and a financial institution; determining the identification information of the third-party institution corresponding to the number and / or the historical address information of the third-party institution; issuing a risk warning if the identification information of the third-party institution is not the same as the identification information of the corresponding third-party institution; and issuing a risk warning if the address information of the third-party institution does not contain historical address information.

[0128] According to embodiments of this disclosure, the device 700 further includes: a suspension module, used to suspend business and / or disable the permission of third-party organizations to call specified API interfaces when a risk warning information is issued.

[0129] According to embodiments of this disclosure, determining whether a risk warning is needed based on business information includes:

[0130] The business information is input into the pre-trained API monitoring big data model to obtain the result of whether risk warning is needed. The pre-trained API monitoring big data model is trained by using the business information of third-party institutions calling the specified API interface to process business as the training set.

[0131] According to embodiments of this disclosure, any plurality of modules in the acquisition module 710 and the determination module 720 may be combined into one module, or any one of these modules may be split into multiple modules. Alternatively, at least a portion of the functionality of one or more of these modules may be combined with at least a portion of the functionality of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the acquisition module 710 and the determination module 720 may be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the acquisition module 710 and the determination module 720 may be at least partially implemented as a computer program module, which, when run, can perform corresponding functions.

[0132] Figure 8 A block diagram schematically illustrates an electronic device suitable for implementing a risk warning method according to an embodiment of the present disclosure.

[0133] like Figure 8 As shown, an electronic device 800 according to an embodiment of this disclosure includes a processor 801, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage portion 808 into a random access memory (RAM) 803. The processor 801 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 801 may also include onboard memory for caching purposes. The processor 801 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this disclosure.

[0134] RAM 803 stores various programs and data required for the operation of electronic device 800. Processor 801, ROM 802, and RAM 803 are interconnected via bus 804. Processor 801 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 802 and / or RAM 803. It should be noted that programs may also be stored in one or more memories other than ROM 802 and RAM 803. Processor 801 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.

[0135] According to embodiments of this disclosure, the electronic device 800 may further include an input / output (I / O) interface 805, which is also connected to a bus 804. The electronic device 800 may also include one or more of the following components connected to the input / output (I / O) interface 805: an input section 806 including a keyboard, mouse, etc.; an output section 807 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 808 including a hard disk, etc.; and a communication section 809 including a network interface card such as a LAN card, modem, etc. The communication section 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to the input / output (I / O) interface 805 as needed. A removable medium 811, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 810 as needed so that computer programs read from it can be installed into the storage section 808 as needed.

[0136] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.

[0137] According to embodiments of this disclosure, the computer-readable storage medium can be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 802 and / or RAM 803 and / or one or more memories other than ROM 802 and RAM 803 described above.

[0138] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to enable the computer system to implement the risk warning method provided in the embodiments of this disclosure.

[0139] When the computer program is executed by the processor 801, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0140] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 809, and / or installed from a removable medium 811. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0141] In such an embodiment, the computer program can be downloaded and installed from a network via communication section 809, and / or installed from removable medium 811. When the computer program is executed by processor 801, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0142] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on a user's computing device, partially on a user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0143] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0144] Those skilled in the art will understand that the features described in the various embodiments of this disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments of this disclosure can be combined and / or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0145] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A risk warning method, characterized in that, The method includes: Obtain business information when a third-party institution calls a specified API interface to process business, wherein the specified API interface is an API interface opened by a financial institution, and the business information includes at least one of the following: the identification information of the third-party institution, the business status information of the business, the response information of the specified API interface, and the address information of the third-party institution; Based on the aforementioned business information, determine whether a risk warning is required.

2. The method according to claim 1, characterized in that, The determination of whether a risk warning is needed based on the business information includes: Based on preset rules, it is determined whether the transaction instruction received by the specified API interface is an instruction issued by the target object. The target object is a third-party institution with the financial institution whose contract status is "signed". The "signed" status is used to authorize the third-party institution to connect to the specified API interface to process specified business. If the transaction instruction received by the API interface is not issued by the target object, a risk warning message will be issued.

3. The method according to claim 1 or 2, characterized in that, The method further includes: Add a target field to the input field of the specified API interface, the target field representing the identification information of the third-party organization; The step of determining whether a transaction instruction received by the API interface is an instruction issued by the target object based on preset rules includes: Determine whether the target field exists in the input fields of the API interface; The target field is not present in the input fields of the API interface, and the transaction instruction received by the API interface is not an instruction issued by the target object; If the target field exists in the input fields of the API interface, it is determined that the transaction instruction received by the API interface is an instruction issued by the target object.

4. The method according to claim 1, characterized in that, The business status information includes business status, API interface status, and third-party institution contract status. Determining whether a risk warning is needed based on this business information includes: When the business is closed and the third-party institution's contract status is open, a risk warning message will be issued; When the business status is open, the API interface status is closed, and the third-party institution's contract status is closed, a risk warning message will be issued.

5. The method according to claim 1, characterized in that, The determination of whether a risk warning is needed based on the business information includes: Determine whether the response information of the specified API interface includes first information and / or the identity information of the second-party user, wherein the first information represents the second-party user's information regarding the handling of the business; If the response information of the specified API interface includes the first information, a risk warning message is issued; If the response information of the specified API interface includes the identity information of the second-party user, a risk warning message will be issued.

6. The method according to claim 1, characterized in that, The determination of whether a risk warning is needed based on the business information includes: Obtain the number of the designated agreement between the third-party institution and the financial institution; Determine the identification information of the third-party organization corresponding to the number and / or the historical address information of the third-party organization; If the identification information of the third-party organization is not the same as the identification information of the corresponding third-party organization, a risk warning message will be issued; If the historical address information is not found in the address information of the third-party organization, a risk warning will be issued.

7. The method according to claim 1, characterized in that, The method further includes: If a risk warning is issued, the business will be suspended and / or the third-party organization's permission to call the specified API interface will be revoked.

8. The method according to any one of claims 1 to 7, characterized in that, The determination of whether a risk warning is needed based on the business information includes: The business information is input into a pre-trained API monitoring big data model to obtain a result indicating whether a risk warning is needed. The pre-trained API monitoring big data model is trained by using business information from third-party organizations calling specified API interfaces to process business as a training set.

9. A risk warning device, characterized in that, The device includes: The acquisition module is used to acquire business information when a third-party institution calls a specified API interface to process business. The specified API interface is an API interface opened by a financial institution. The business information includes at least one of the following: the identification information of the third-party institution, the business status information of the business, the response information of the specified API interface, and the address information of the third-party institution. The determination module is used to determine whether a risk warning is needed based on the business information.

10. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 8.

11. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 8.