Abnormal take-out transaction order detection method and system equipment based on multi-terminal cooperation

By employing a multi-terminal collaborative method for detecting abnormal food delivery orders, and utilizing encryption/decryption and multi-level verification mechanisms, the problem of geolocation tampering and cross-platform payment anomalies in internet finance scenarios has been solved, thereby improving detection accuracy and fund security.

CN122053102APending Publication Date: 2026-05-15CHINA CONSTRUCTION BANK
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA CONSTRUCTION BANK
Filing Date
2025-12-11
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing technologies in internet finance and local life service scenarios have problems such as geolocation tampering and cross-platform payment anomalies, resulting in platform fund losses and low detection accuracy, and lack of multi-terminal collaborative prevention and control mechanisms.

Method used

By encrypting the user's mobile phone number through a third-party platform, the client decrypts and performs device environment detection, the server verifies the location information, and the backend system dynamically intercepts the abnormal food delivery order detection through multi-terminal collaboration.

Benefits of technology

It improves the accuracy of detecting abnormal food delivery orders, effectively prevents geolocation tampering and cross-platform arbitrage, and safeguards the platform's fund security and business fairness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053102A_ABST
    Figure CN122053102A_ABST
Patent Text Reader

Abstract

The invention discloses an abnormal take-out transaction order detection method and system equipment based on multi-terminal collaboration, and relates to the field of network security, and the method comprises the steps that when a third-party platform generates a take-out order, the mobile phone number of a user is encrypted and then transmitted to a client along with order information; the client carries out decryption to obtain a decrypted user mobile phone number, extracts a pre-stored user login mobile phone number, carries out equipment environment detection according to the preference of order information, and sends the order and the positioning information to the server if the positioning detection is passed, and sends the decrypted and login mobile phone number to the background; the server side verifies the positioning information, and sends the order and the positioning information to the background when the verification is passed; and the background performs dynamic interception detection according to the order and the positioning information, if the interception detection passes comparison and decryption with the login mobile phone number, the payment process is allowed if the decryption is consistent with the login mobile phone number, and the take-out transaction order is determined to be abnormal if the decryption is not consistent. According to the invention, the abnormal take-out transaction order in the Internet finance composite business scene can be accurately detected through multi-terminal cooperation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method and system for detecting abnormal food delivery orders based on multi-terminal collaboration. Background Technology

[0002] This section is intended to provide background or context for the embodiments of the invention set forth in the claims. The description herein is not an admission that it is prior art simply because it is included in this section.

[0003] In internet finance and local life services scenarios, the methods of cheating through technical means are becoming increasingly complex, and the main technical problems are as follows:

[0004] Technical issues related to geolocation tampering: Using risky software (such as Fake Location), rooted devices, or VPN tools to tamper with GPS / IP location information, impersonating local users to fraudulently obtain platform subsidies (such as regionally limited coupons or local merchant subsidies), resulting in financial losses for the platform.

[0005] Technical issues with cross-platform payment anomalies: After logging into a local life platform, a user switches to a third-party platform account and uses their own coupons to pay for other people's orders. Traditional verification methods, which do not link the third-party order's mobile phone number to the platform's login mobile phone number, cannot identify such abnormal transaction behavior.

[0006] Therefore, existing technologies have not designed a multi-terminal collaborative prevention and control mechanism to address the technical problems of the aforementioned complex business scenarios. The accuracy of detecting abnormal food delivery orders in existing internet finance complex business scenarios is low, and there is an urgent need for a system that can build a full-link system through multi-terminal linkage to avoid abnormal transactions. Summary of the Invention

[0007] This invention provides a method for detecting abnormal food delivery orders based on multi-terminal collaboration, used to accurately detect abnormal food delivery orders in internet finance composite business scenarios through multi-terminal collaboration. The method includes:

[0008] When a third-party platform generates a food delivery order, it encrypts the user's mobile phone number and transmits the encrypted mobile phone number to the client along with the food delivery order information.

[0009] When the client receives the food delivery order information, it uses the agreed key to decrypt the encrypted user's mobile phone number to obtain the decrypted user's mobile phone number, extracts the pre-stored user login mobile phone number, performs device environment detection for the discounts in the order information, and obtains the location information detection result. If the location information detection result is successful, the order information and location information are sent to the server, and the decrypted user's mobile phone number and user login mobile phone number are sent to the backend system.

[0010] The server verifies the location information based on the order information and the location information. When the location information verification is successful, the order information and the location information are sent to the backend system.

[0011] The backend system performs dynamic interception and detection based on order information and location information. If the dynamic interception and detection result is successful, the decrypted user's mobile phone number is compared with the user's login mobile phone number. If they match, the payment process is allowed. If they do not match, the food delivery order is determined to be an abnormal food delivery order.

[0012] This invention also provides an abnormal food delivery transaction order detection system based on multi-terminal collaboration, used to accurately detect abnormal food delivery transaction orders in internet finance composite business scenarios through multi-terminal collaboration. The system includes:

[0013] A third-party platform is used to encrypt the mobile phone number of the user who places the order when generating a food delivery order, and then transmit the encrypted mobile phone number to the client along with the food delivery order information.

[0014] The client is used to decrypt the encrypted user's mobile phone number using an agreed key when it receives the food delivery order information, extract the pre-stored user login mobile phone number, perform device environment detection for the discounts in the order information, obtain the location information detection result, and if the location information detection result is successful, send the order information and location information to the server, and send the decrypted user's mobile phone number and user login mobile phone number to the backend system.

[0015] The server is used to verify the location information based on the order information and the location information. When the location information verification is successful, the order information and the location information are sent to the backend system.

[0016] The backend system is used to perform dynamic interception and detection based on order information and location information. If the dynamic interception and detection result is successful, the decrypted user's mobile phone number is compared with the user's login mobile phone number. If they match, the payment process is allowed. If they do not match, the food delivery order is determined to be an abnormal food delivery order.

[0017] This invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the above-described method for detecting abnormal food delivery orders based on multi-terminal collaboration.

[0018] This invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method for detecting abnormal food delivery orders based on multi-terminal collaboration.

[0019] This invention also provides a computer program product, which includes a computer program that, when executed by a processor, implements the above-described method for detecting abnormal food delivery orders based on multi-terminal collaboration.

[0020] In this embodiment of the invention, the abnormal food delivery order detection scheme based on multi-terminal collaboration, compared with existing technical solutions, involves the following steps: When a third-party platform generates a food delivery order, it encrypts the user's mobile phone number and transmits the encrypted user's mobile phone number along with the food delivery order information to the client; when the client receives the food delivery order information, it uses an agreed-upon key to decrypt the encrypted user's mobile phone number, extracts the pre-stored user login mobile phone number, performs device environment detection based on the order information discounts, obtains the location information detection result, and if the location information detection result is successful, it sends the order information and location information to the server, and then decrypts the data. The system sends the user's mobile phone number and login mobile phone number to the backend system. The server verifies the location information based on the order information and location information. If the location information verification is successful, the server sends the order information and location information to the backend system. The backend system performs dynamic interception detection based on the order information and location information. If the dynamic interception detection result is successful, the decrypted user's mobile phone number is compared with the user's login mobile phone number. If they match, the payment process is allowed. If they do not match, the food delivery order is determined to be an abnormal food delivery order. This system can accurately detect abnormal food delivery orders in Internet finance composite business scenarios through multi-terminal collaboration, thereby improving the accuracy of abnormal food delivery order detection. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:

[0022] Figure 1 This is a flowchart illustrating the abnormal food delivery order detection method based on multi-terminal collaboration in an embodiment of the present invention.

[0023] Figure 2 This is a flowchart illustrating an abnormal food delivery order detection method based on multi-terminal collaboration in another embodiment of the present invention.

[0024] Figure 3 This is a flowchart illustrating an abnormal food delivery order detection method based on multi-terminal collaboration in another embodiment of the present invention.

[0025] Figure 4This is a flowchart illustrating an abnormal food delivery order detection method based on multi-terminal collaboration in another embodiment of the present invention.

[0026] Figure 5 This is a schematic diagram of the structure of the abnormal food delivery transaction order detection system based on multi-terminal collaboration in an embodiment of the present invention;

[0027] Figure 6 This is a schematic diagram of a computer device structure according to an embodiment of the present invention. Detailed Implementation

[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings. Here, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.

[0029] The acquisition, transmission, storage, use, and processing of data in this application all comply with relevant laws and regulations.

[0030] It should be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.

[0031] Figure 1 This is a flowchart illustrating the abnormal food delivery order detection method based on multi-terminal collaboration in an embodiment of the present invention, as shown below. Figure 1 As shown, the method includes the following steps:

[0032] Step 101: When generating a food delivery order, the third-party platform encrypts the user's mobile phone number and transmits the encrypted user's mobile phone number to the client along with the food delivery order information.

[0033] Step 102: When the client receives the food delivery order information, it uses the agreed key to decrypt the encrypted user's mobile phone number to obtain the decrypted user's mobile phone number, extracts the pre-stored user login mobile phone number, performs device environment detection for the discounts in the order information, and obtains the location information detection result. If the location information detection result is successful, the order information and location information are sent to the server, and the decrypted user's mobile phone number and user login mobile phone number are sent to the backend system.

[0034] Step 103: The server verifies the location information based on the order information and location information. If the location information verification is successful, the server sends the order information and location information to the backend system.

[0035] Step 104: The backend system performs dynamic interception detection based on order information and location information. If the dynamic interception detection result is successful, the decrypted user's mobile phone number is compared with the user's login mobile phone number. If they match, the payment process is allowed. If they do not match, the food delivery order is determined to be an abnormal food delivery order.

[0036] In this embodiment of the invention, the abnormal food delivery order detection method based on multi-terminal collaboration operates as follows: When a third-party platform generates a food delivery order, it encrypts the user's mobile phone number and transmits the encrypted user's mobile phone number along with the food delivery order information to the client. When the client receives the food delivery order information, it uses an agreed-upon key to decrypt the encrypted user's mobile phone number, extracts the pre-stored user login mobile phone number, performs device environment detection based on the order information's discounts, and obtains location information detection results. If the location information detection result is successful, the order information and location information are sent to the server, and the decrypted user's mobile phone number and user login mobile phone number are sent to the backend system. The server performs location information verification based on the order information and location information. If the location information verification is successful, the order information and location information are sent to the backend system. The backend system performs dynamic interception detection based on the order information and location information. If the dynamic interception detection result is successful, the decrypted user's mobile phone number is compared with the user login mobile phone number. If they match, the payment process is allowed; if they do not match, the food delivery order is determined to be an abnormal food delivery order.

[0037] Compared with existing technical solutions, the abnormal food delivery order detection method based on multi-terminal collaboration provided in this invention can accurately detect abnormal food delivery orders in Internet finance composite business scenarios through multi-terminal collaboration, thereby improving the accuracy of abnormal food delivery order detection.

[0038] The following is combined Figures 2 to 4 This paper provides a detailed introduction to the abnormal food delivery order detection method based on multi-terminal collaboration.

[0039] I. Multi-terminal Collaborative Prevention and Control Plan for Geographic Location Tampering

[0040] By using technical means to avoid the risk of falsified location information, this embodiment of the invention constructs a three-level prevention and control system: client device environment detection, server request secondary verification, and dynamic interception by the anti-fraud engine of the backend system, covering all risk points from the device layer to the behavior layer.

[0041] (a) Client device environment detection: Blocking location-based cheating at the source

[0042] As the user's entry point, the client identifies and blocks high-risk device environments through the following strategies:

[0043] In step 102 above, a device environment check is performed on the discount for the order information to obtain the location information detection result. If the location information detection result is successful, the order information and location information are sent to the server, and the decrypted user's mobile phone number and user login mobile phone number are sent to the backend system. Specifically:

[0044] In one embodiment, in step 102 above, the device environment detection for the discounts in the order information to obtain the location information detection result may include the following device risk software installation detection operation: for business scenarios involving discounts, collect the user's mobile application software installation list, and when it is detected that the software in the user's mobile application software installation list belongs to the risk software in the preset risk software feature library, determine that the takeaway transaction order is an abnormal takeaway transaction order.

[0045] In practice, the detection of risky software installation involves the following steps: For business scenarios involving subsidies (such as regionally restricted coupon redemption), the client proactively collects the user's mobile app installation list and pre-sets a risky software signature database (such as location fraud tools like "monkey clone" and "Fake Location"). If risky software is detected, the user's location-related operations (such as subsidy redemption) are restricted or blocked.

[0046] In one embodiment, in step 102 above, the device environment detection for the discount of the order information is performed to obtain the location information detection result, which may include the following root device disabling operation: when it is determined whether the user's mobile phone has obtained root privileges, the takeaway transaction order is determined to be an abnormal takeaway transaction order.

[0047] In practice, rooted devices are disabled by integrating a root status detection module to verify in real time whether the device has obtained root privileges (hackers can hijack the GPS interface and forge data through root access). If root status is detected, the user is directly prohibited from using geolocation verification functions (such as placing orders with local merchants).

[0048] In one embodiment, in step 102 above, the device environment detection for the discounts on the order information is performed to obtain the location information detection result, which may include the following VPN connection management operation: when the VPN on the user's mobile phone is detected to be active, the takeaway transaction order is determined to be an abnormal takeaway transaction order.

[0049] In practice, VPN connection management involves monitoring whether a device has a VPN enabled (VPNs can bypass IP location restrictions). If VPN activation is detected, users are prohibited from logging in or using functions requiring precise location tracking (such as regionally restricted subsidy collection).

[0050] In one embodiment, in step 102 above, the device environment detection for the discounts in the order information is performed to obtain the location information detection result, which may include the following H5 page geofence detection: When configuring H5 marketing activities, the following geographical location control detection is added: When the coupon claim request in the takeaway transaction order is a coupon claim request where the client's location information is located outside the specified area, the takeaway transaction order is determined to be an abnormal takeaway transaction order.

[0051] In practice, H5 page geofencing: When configuring H5 marketing campaigns, add geolocation control logic to reject coupon requests from non-designated areas based on user-submitted GPS information, ensuring that the campaign area restrictions are effective.

[0052] In one embodiment, such as Figure 2 As shown, the above-mentioned abnormal food delivery order detection based on multi-terminal collaboration may also include step 102': if the location information detection result is unsuccessful, the food delivery order is determined to be an abnormal food delivery order.

[0053] (ii) Server-side request for secondary verification: verifying the authenticity of location information

[0054] As the core processing node for transactions, the server performs secondary verification on the location information sent by the client to ensure data reliability.

[0055] In step 103 above, the server verifies the location information based on the order information and the location information. When the location information verification is successful, the server sends the order information and the location information to the backend system.

[0056] In one embodiment, in step 103 above, the server performs location information verification based on order information and location information, which may include: the server comparing the location information sent by the client with the coupon redemption area configured in the operation backend; if the location is inconsistent or the location information cannot be obtained due to the user's lack of authorization, an error is triggered and the coupon redemption is blocked, thus determining that the takeaway transaction order is an abnormal takeaway transaction order.

[0057] In practice, the coupon claim request is verified as follows: After a user initiates a coupon claim request, the server compares the GPS location information sent by the client with the coupon claim area configured in the operations backend. If the location does not match or GPS cannot be obtained (e.g., the user has not authorized it), an error is triggered and the coupon claim is blocked.

[0058] In one embodiment, in step 103 above, the server performs location information verification based on order information and location information, which may include: if the distance between the location information sent by the client and the location information of the merchant is greater than a preset distance threshold, the server triggers an error and blocks the coupon claiming, thus determining that the food delivery order is an abnormal food delivery order.

[0059] In practice, order request verification is performed as follows: For orders from local merchants, the server verifies the distance between the user's GPS and the merchant's GPS (with a preset distance threshold, such as 5 kilometers); merchants are exempt from this rule to balance risk control and user experience.

[0060] In one embodiment, such as Figure 3 As shown, the above-mentioned abnormal food delivery order detection based on multi-terminal collaboration may also include step 103': when the location information verification fails, the food delivery order is determined to be an abnormal food delivery order.

[0061] (iii) Real-time anti-cheating engine in the backend system dynamically intercepts and identifies abnormal behavior patterns.

[0062] The real-time anti-fraud engine, based on a rule-based engine, uses a dynamic threshold determination mechanism to intercept batches of abnormal orders in real time.

[0063] In step 104 above, the backend system performs dynamic interception detection based on order information and location information. If the dynamic interception detection result is passed, the decrypted user's mobile phone number is compared with the user's login mobile phone number. If they match, the payment process is allowed. If they do not match, the food delivery order is determined to be an abnormal food delivery order.

[0064] In one embodiment, if the dynamic interception detection result is "failed," determining the food delivery order as an abnormal food delivery order in step 104 above may include:

[0065] If the location data of the user's mobile phone number, IP address, or GPS location is inconsistent with the merchant's location data, the food delivery order is determined to be a current out-of-town order.

[0066] If the number of out-of-town orders received by the same merchant within the preset monitoring period for the current out-of-town order exceeds the preset threshold, the current out-of-town order is determined to be an abnormal food delivery transaction order.

[0067] In practice, the system intercepts out-of-town orders by collecting data on the user's mobile phone number location, IP address location, GPS location, and merchant location in real time. Out-of-town orders are defined as orders whose location does not match the merchant's. If the number of out-of-town orders received by the same merchant within a monitoring window (e.g., 30 minutes) exceeds a threshold (e.g., 10 orders), it is considered fraudulent, and subsequent out-of-town orders are blocked.

[0068] In one embodiment, if the dynamic interception detection result is "failed," determining the food delivery order as an abnormal food delivery order in step 104 above may include:

[0069] Determine the displacement speed of the current food delivery order and the user's adjacent food delivery orders;

[0070] If the displacement speed exceeds a preset displacement speed threshold, the food delivery order is determined to be an abnormal food delivery order; the displacement speed is the displacement speed distance difference divided by the time difference.

[0071] In practice, GPS instantaneous interception involves calculating the displacement speed (V = distance difference / time difference) of two consecutive orders from the user. If the speed exceeds a threshold (such as 1000 km / h), it is determined to be GPS tampering and cheating, the current order is marked as abnormal, and subsequent location-related operations of the user are blocked.

[0072] In one embodiment, such as Figure 4 As shown, the above-mentioned abnormal food delivery order detection based on multi-terminal collaboration may also include step 104': if the dynamic interception detection result is unsuccessful, the food delivery order is determined to be an abnormal food delivery order.

[0073] II. Multi-terminal Collaborative Verification Solution for Identity Forgery and Information Segmentation

[0074] To address the risks of fragmented identity information across systems and misuse during the payment process, this invention achieves accurate verification of identity authenticity through multi-terminal linkage, including client-side information expansion, server-side cross-system reverse lookup, dynamic matching in the payment system, and backend module verification.

[0075] (a) Coupon redemption process: multi-factor information upload and cross-system reverse lookup

[0076] The inventors also discovered the following technical problems in the existing technology: identity forgery and information fragmentation: inconsistent user identifiers across systems (e.g., inconsistent user IDs between the local life platform and the rights and benefits platform) or others impersonating users, leading to unauthorized users misusing coupons; in the payment process, different payment methods (e.g., payment method A, legal digital currency payment) correspond to independent numbering systems, making traditional verification logic prone to misjudgment or overlooking the risk of misuse. It is precisely because the inventors discovered the above problems that they proposed the following further optimized technical solution.

[0077] Client-side field expansion: When a user initiates a coupon redemption transaction, the client adds a channel number (such as on the APP or mini-program) and a channel user number (a unique identifier within the local life platform) to the existing data. These, along with the mobile phone number, form the three essential user elements, which are then encapsulated in the transaction request and sent to the benefits platform.

[0078] Cross-system reverse lookup of the rights and benefits platform (server-side): The rights and benefits platform locates the transaction channel based on the channel number, and combines the channel user number and mobile phone number to look up the unique user ID in the rights and benefits platform system; compare this ID with the user ID to which the coupon belongs (the original ID recorded when it was issued), if they match, the verification is successful, otherwise the transaction is blocked.

[0079] Client-side result control: After receiving the verification result, the client allows the coupon to be redeemed if successful, and blocks the payment if it fails.

[0080] As can be seen from the above, in one embodiment, the above-mentioned abnormal food delivery order detection based on multi-terminal collaboration may also include: forming a user three-element system by combining the channel identifier, the channel user number, and the mobile phone number, and verifying the user attribution of the discount information in the food delivery order through the user three-element system.

[0081] (ii) Payment process: Dynamic matching and verification of payment methods

[0082] Payment system identification and extraction: When a user selects a payment method (such as payment method A wallet, fiat digital currency payment), the payment system extracts the customer number (C1 or C2) corresponding to the payment method.

[0083] Backend module dynamic verification: The backend verification module obtains the original customer number (C0) of the user who placed the order and dynamically adjusts the verification logic according to the payment method: In the case of payment method A, C1=C0 is verified, and in the case of payment in legal digital currency, C2=C0 is verified.

[0084] Payment system feedback: If the verification is successful, the payment will continue; if it fails, an error code will be returned and a message will be displayed indicating that the payment was unsuccessful and that the account should be verified.

[0085] III. Cross-Platform Payment Anomaly Multi-Terminal Collaborative Detection Solution

[0086] To address the risk of coupon arbitrage caused by cross-platform account switching, this invention implements cross-platform linkage through third-party platform information transmission, dual-end number extraction on the client side, and consistency verification of the cashier system to proactively intercept payment anomalies.

[0087] (a) Standardized transmission of information on third-party platforms

[0088] When a third-party platform generates a food delivery order, it uses the order user's mobile phone number (T1) as a required field, encrypts it using AES to generate T1', and transmits it to the local life platform client along with the order information. That is, in step 101 above, the third-party platform encrypts the order user's mobile phone number when generating the food delivery order, and transmits the encrypted mobile phone number to the client along with the food delivery order information.

[0089] (ii) Extraction of dual-end numbers from client terminals

[0090] After receiving the encrypted order information, the client uses the agreed-upon key to decrypt it and obtain T1, and then extracts the local life platform login phone number (L1). That is, in step 102 above, when the client receives the food delivery transaction order information, it uses the agreed-upon key to decrypt the encrypted user phone number to obtain the decrypted user phone number, and then extracts the pre-stored user login phone number.

[0091] (III) Consistency verification and control of the cashier system in the back-end system

[0092] The backend system's cashier system compares T1 and L1: if they match, payment is allowed; if they don't match, the process is terminated, an order error is indicated, the current account and the mobile phone number used to place the order are inconsistent, and the order is marked as invalid. In other words, if the dynamic interception detection result is passed, the decrypted user's mobile phone number is compared with the user's login mobile phone number. If they match, the payment process is allowed; if they don't match, the food delivery order is determined to be an abnormal order.

[0093] In summary, the embodiments of the present invention construct a system that covers the entire chain of preventing abnormal transactions or orders through multi-terminal collaboration, encompassing device environment, user identity, and transaction behavior.

[0094] Geolocation tampering prevention: The client blocks risky software, root access, and VPN interference at the device level; the server verifies the authenticity of the location at the request level; and the real-time engine intercepts abnormal orders at the behavior level. The three work together to cover all scenarios of location fraud.

[0095] Identity forgery verification: The client expands multi-element information, the rights and interests platform performs cross-system reverse lookup of user ID, the payment system dynamically matches payment method number, and the backend module performs precise verification, solving the problems of information fragmentation and impersonation across systems.

[0096] Cross-platform payment anomaly detection: Third-party platforms transmit encrypted mobile phone numbers in a standardized manner, the client extracts the numbers from both ends, the cashier system verifies consistency, and intercepts cross-platform account switching arbitrage behavior.

[0097] The multi-terminal collaboration mechanism achieves closed-loop management from risk identification to interception through information synchronization, rule linkage, and dynamic verification. While ensuring that normal users are unaware of the risks, it significantly improves the platform's ability to prevent fraudulent location, identity forgery, and cross-platform arbitrage, providing core technical support for the security of funds and the fairness of business in internet finance and local life services.

[0098] This invention also provides a device for detecting abnormal food delivery orders based on multi-terminal collaboration, as described in the following embodiments. Since the principle behind this device's problem-solving is similar to that of the method for detecting abnormal food delivery orders based on multi-terminal collaboration, the implementation of this device can refer to the implementation of the method for detecting abnormal food delivery orders based on multi-terminal collaboration; repeated details will not be elaborated further.

[0099] Figure 5 This is a schematic diagram of the structure of the abnormal food delivery transaction order detection system based on multi-terminal collaboration in an embodiment of the present invention, as shown below. Figure 5 As shown, the system equipment includes:

[0100] Third-party platform 01 is used to encrypt the mobile phone number of the user who placed the order when generating a food delivery order, and transmit the encrypted mobile phone number to the client along with the food delivery order information;

[0101] Client 02 is used to decrypt the encrypted user's mobile phone number using an agreed key when receiving food delivery order information, extract the pre-stored user login mobile phone number, perform device environment detection for the discounts in the order information, obtain the location information detection result, and if the location information detection result is successful, send the order information and location information to the server, and send the decrypted user's mobile phone number and user login mobile phone number to the backend system.

[0102] Server 03 is used to verify the location information based on the order information and the location information. When the location information verification is successful, the order information and the location information are sent to the backend system.

[0103] The backend system 04 is used to perform dynamic interception detection based on order information and location information. If the dynamic interception detection result is passed, the decrypted user's mobile phone number is compared with the user's login mobile phone number. If they match, the payment process is allowed. If they do not match, the food delivery order is determined to be an abnormal food delivery order.

[0104] In one embodiment, the client is specifically used to perform device environment detection for the discounts in the order information and obtain the location information detection results, including the following device risk software installation detection operation: for business scenarios involving discounts, collect the user's mobile application software installation list, and when it is detected that the software in the user's mobile application software installation list belongs to the risk software in the preset risk software feature library, determine that the takeaway transaction order is an abnormal takeaway transaction order.

[0105] In one embodiment, the client is specifically used to perform device environment detection for the discounts in the order information and obtain the location information detection result, including the following root device disabling operation: when it is determined whether the user's mobile phone has obtained root privileges, the takeaway transaction order is determined to be an abnormal takeaway transaction order.

[0106] In one embodiment, the client is specifically used to perform device environment detection for the discounts in the order information and obtain location information detection results, including the following VPN connection control operation: when the VPN on the user's mobile phone is detected to be active, the takeaway transaction order is determined to be an abnormal takeaway transaction order.

[0107] In one embodiment, the client is specifically used to perform device environment detection for the discounts in the order information and obtain location information detection results, including the following H5 page geofence detection: When configuring H5 marketing activities, the following geographical location control detection is added: When the coupon claim request in the takeaway transaction order is a coupon claim request whose client location information is located outside the specified area, the takeaway transaction order is determined to be an abnormal takeaway transaction order.

[0108] In one embodiment, the client is further configured to: determine that the food delivery order is an abnormal food delivery order if the location information detection result is unsuccessful.

[0109] In one embodiment, the server is further configured to: determine that the food delivery order is an abnormal food delivery order when the location information verification fails.

[0110] In one embodiment, the server is specifically used to: compare the location information sent by the client with the coupon redemption area configured in the operations backend; if the location is inconsistent or the location information cannot be obtained due to the user's lack of authorization, trigger an error and block the coupon redemption, thus determining that the food delivery order is an abnormal food delivery order.

[0111] In one embodiment, the server is specifically used to: when the distance between the location information sent by the client and the location information on the merchant's end is greater than a preset distance threshold, trigger an error and block the coupon claim, thus determining that the food delivery order is an abnormal food delivery order.

[0112] In one embodiment, the backend system is further configured to determine that the food delivery order is an abnormal food delivery order if the dynamic interception detection result is unsuccessful.

[0113] In one embodiment, the backend system is specifically used for:

[0114] If the location data of the user's mobile phone number, IP address, or GPS location is inconsistent with the merchant's location data, the food delivery order is determined to be a current out-of-town order.

[0115] If the number of out-of-town orders received by the same merchant within the preset monitoring period for the current out-of-town order exceeds the preset threshold, the current out-of-town order is determined to be an abnormal food delivery transaction order.

[0116] In one embodiment, the backend system is specifically used for:

[0117] Determine the displacement speed of the current food delivery order and the user's adjacent food delivery orders;

[0118] If the displacement speed exceeds a preset displacement speed threshold, the food delivery order is determined to be an abnormal food delivery order; the displacement speed is the displacement speed distance difference divided by the time difference.

[0119] In one embodiment, the client is further configured to combine the channel identifier, the channel user number, and the mobile phone number to form the three user elements, and the server is further configured to verify the user attribution of the discount information in the food delivery transaction order through the three user elements.

[0120] Based on the aforementioned inventive concept, such as Figure 6 As shown, the present invention also proposes a computer device 500, including a memory 510, a processor 520, and a computer program 530 stored in the memory 510 and executable on the processor 520. When the processor 520 executes the computer program 530, it implements the aforementioned abnormal takeaway transaction order detection method based on multi-terminal collaboration.

[0121] This invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method for detecting abnormal food delivery orders based on multi-terminal collaboration.

[0122] This invention also provides a computer program product, which includes a computer program that, when executed by a processor, implements the above-described method for detecting abnormal food delivery orders based on multi-terminal collaboration.

[0123] In this embodiment of the invention, the abnormal food delivery order detection scheme based on multi-terminal collaboration, compared with existing technical solutions, involves the following steps: When a third-party platform generates a food delivery order, it encrypts the user's mobile phone number and transmits the encrypted user's mobile phone number along with the food delivery order information to the client; when the client receives the food delivery order information, it uses an agreed-upon key to decrypt the encrypted user's mobile phone number, extracts the pre-stored user login mobile phone number, performs device environment detection based on the order information discounts, obtains the location information detection result, and if the location information detection result is successful, it sends the order information and location information to the server, and then decrypts the data. The system sends the user's mobile phone number and login mobile phone number to the backend system. The server verifies the location information based on the order information and location information. If the location information verification is successful, the server sends the order information and location information to the backend system. The backend system performs dynamic interception detection based on the order information and location information. If the dynamic interception detection result is successful, the decrypted user's mobile phone number is compared with the user's login mobile phone number. If they match, the payment process is allowed. If they do not match, the food delivery order is determined to be an abnormal food delivery order. This system can accurately detect abnormal food delivery orders in Internet finance composite business scenarios through multi-terminal collaboration, thereby improving the accuracy of abnormal food delivery order detection.

[0124] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0125] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0126] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0127] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0128] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for detecting abnormal food delivery orders based on multi-terminal collaboration, characterized in that, include: When a third-party platform generates a food delivery order, it encrypts the user's mobile phone number and transmits the encrypted mobile phone number to the client along with the food delivery order information. When the client receives the food delivery order information, it uses the agreed key to decrypt the encrypted user's mobile phone number to obtain the decrypted user's mobile phone number, extracts the pre-stored user login mobile phone number, performs device environment detection for the discounts in the order information, and obtains the location information detection result. If the location information detection result is successful, the order information and location information are sent to the server, and the decrypted user's mobile phone number and user login mobile phone number are sent to the backend system. The server verifies the location information based on the order information and the location information. When the location information verification is successful, the order information and the location information are sent to the backend system. The backend system performs dynamic interception and detection based on order information and location information. If the dynamic interception and detection result is successful, the decrypted user's mobile phone number is compared with the user's login mobile phone number. If they match, the payment process is allowed. If they do not match, the food delivery order is determined to be an abnormal food delivery order.

2. The method as described in claim 1, characterized in that, Device environment detection is performed on the discounts in the order information to obtain the location information detection results, including the following device risk software installation detection operations: For business scenarios involving discounts, the user's mobile application software installation list is collected. When it is detected that the software in the user's mobile application software installation list belongs to the risk software in the preset risk software feature library, the takeaway transaction order is determined to be an abnormal takeaway transaction order.

3. The method as described in claim 1, characterized in that, Device environment detection is performed on the discounts in the order information to obtain location information detection results, including the following root device disabling operation: when it is determined whether the user's mobile phone has obtained root privileges, the food delivery order is determined to be an abnormal food delivery order.

4. The method as described in claim 1, characterized in that, The device environment is checked for discounts on order information, and the location information detection results are obtained. This includes the following Virtual Private Network (VPN) connection management operations: when the VPN on the user's mobile phone is detected to be active, the food delivery order is determined to be an abnormal food delivery order.

5. The method as described in claim 1, characterized in that, Device environment detection is performed on the discounts in the order information to obtain the location information detection results, including the following H5 page geofence detection using Hypertext Markup Language Version 5: When configuring H5 marketing activities, the following geographical location control detection is added: When the coupon redemption request in the takeaway transaction order is a coupon redemption request where the client's location information is located outside the specified area, the takeaway transaction order is determined to be an abnormal takeaway transaction order.

6. The method as described in claim 1, characterized in that, Also includes: If the location information detection result is unsuccessful, the food delivery order is determined to be an abnormal food delivery order.

7. The method as described in claim 1, characterized in that, Also includes: If the location information verification fails, the food delivery order is determined to be an abnormal food delivery order.

8. The method as described in claim 7, characterized in that, The server verifies the location information based on the order information and location information, including: the server compares the location information sent by the client with the coupon redemption area configured in the operation backend. If the location is inconsistent or the location information cannot be obtained due to the user's lack of authorization, an error is triggered and the coupon redemption is blocked, thus determining that the takeaway transaction order is an abnormal takeaway transaction order.

9. The method as described in claim 7, characterized in that, The server verifies the location information based on the order information and the location information, including: if the distance between the location information sent by the client and the location information on the merchant's end is greater than a preset distance threshold, the server will trigger an error and block the coupon redemption, thus determining that the food delivery order is an abnormal food delivery order.

10. The method as described in claim 1, characterized in that, Also includes: If the dynamic interception detection result is "failed", the food delivery order is determined to be an abnormal food delivery order.

11. The method as described in claim 10, characterized in that, If the dynamic interception detection result is "failed", the food delivery order is determined to be an abnormal food delivery order, including: If the location data of the user's mobile phone number, IP address, or GPS location is inconsistent with the merchant's location data, the food delivery order is determined to be a current out-of-town order. If the number of out-of-town orders received by the same merchant within the preset monitoring period for the current out-of-town order exceeds the preset threshold, the current out-of-town order is determined to be an abnormal food delivery transaction order.

12. The method as described in claim 10, characterized in that, If the dynamic interception detection result is "failed", the food delivery order is determined to be an abnormal food delivery order, including: Determine the displacement speed of the current food delivery order and the user's adjacent food delivery orders; If the displacement speed exceeds a preset displacement speed threshold, the food delivery order is determined to be an abnormal food delivery order; the displacement speed is the displacement speed distance difference divided by the time difference.

13. The method as described in claim 1, characterized in that, Also includes: The channel identifier, channel user number, and mobile phone number are combined to form the three user elements. These three user elements are used to verify that the discount information in the food delivery transaction order belongs to the user.

14. A system device for detecting abnormal food delivery transaction orders based on multi-terminal collaboration, characterized in that, include: A third-party platform is used to encrypt the mobile phone number of the user who places the order when generating a food delivery order, and then transmit the encrypted mobile phone number to the client along with the food delivery order information. The client is used to decrypt the encrypted user's mobile phone number using an agreed key when it receives the food delivery order information, extract the pre-stored user login mobile phone number, perform device environment detection for the discounts in the order information, obtain the location information detection result, and if the location information detection result is successful, send the order information and location information to the server, and send the decrypted user's mobile phone number and user login mobile phone number to the backend system. The server is used to verify the location information based on the order information and the location information. When the location information verification is successful, the order information and the location information are sent to the backend system. The backend system is used to perform dynamic interception and detection based on order information and location information. If the dynamic interception and detection result is successful, the decrypted user's mobile phone number is compared with the user's login mobile phone number. If they match, the payment process is allowed. If they do not match, the food delivery order is determined to be an abnormal food delivery order.

15. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 13.

16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method of any one of claims 1 to 13.

17. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 13.