A data processing method, apparatus and device

By introducing AI agents into financial operations, the risk control mechanism is automatically analyzed and updated, solving the problems of lagging risk control and low efficiency of manual identification in existing technologies, and achieving efficient resource risk control and loss response.

CN122431695APending Publication Date: 2026-07-21ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
Filing Date
2026-04-13
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

In the high-frequency iteration of financial business, the existing risk control system is lagging behind in updates, leading to risks such as exposure of resource risk points and leakage of privacy data. Manual identification is inefficient and cannot keep up with the high-frequency release pace.

Method used

An iterative resource risk prevention and control mechanism based on AI agents is adopted. The agents automatically complete risk analysis, logic evolution and script update verification in each iteration cycle, and build a dynamic risk prevention and control mechanism of continuous perception, intelligent analysis and fresh deployment. It identifies potential resource loss impact paths and generates resource risk information, and conducts confidence assessment and dataset updates.

Benefits of technology

It significantly improved the response speed and quality of resource risk prevention and control, enabled the self-evolution and continuous effectiveness of resource risks, and improved the response efficiency and coverage completeness of asset loss risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122431695A_ABST
    Figure CN122431695A_ABST
Patent Text Reader

Abstract

The embodiment of the specification discloses a data processing method, device and equipment, the method comprises: receiving program code information to be released; the program code information is carried out semantic analysis processing, and the change type corresponding to the program code information is determined; if the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then the resource risk information matched with the change information of the program code information is generated; the confidence evaluation of the generated resource risk information is carried out, and based on the confidence evaluation result obtained, the current resource risk data set is updated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of computer technology, and in particular to a data processing method, apparatus, and device. Background Technology

[0002] In the high-frequency iteration of financial operations, business logic and fields change frequently. Typical risk control systems often lag behind in updates, leading to risks such as exposed resource vulnerabilities and privacy data breaches. While a combination of manual version changes and manual risk verification is commonly used—where the risk control / testing team manually verifies code changes and updates reconciliation logic before each deployment—this approach is inefficient, prone to overlooking non-explicit risks, and cannot keep pace with the high-frequency release schedule. Therefore, a superior dynamic risk control mechanism is needed to effectively improve the responsiveness and quality of resource control. Summary of the Invention

[0003] The purpose of the embodiments in this specification is to provide a better dynamic risk prevention and control mechanism, thereby effectively improving the response speed and quality of resource prevention and control.

[0004] To achieve the above technical solution, the embodiments in this specification are implemented as follows: This specification provides a data processing method comprising: receiving program code information to be released; performing semantic parsing on the program code information to determine the change type corresponding to the program code information; if the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then generating resource risk information matching the change information of the program code information; performing confidence assessment on the generated resource risk information, and updating the current resource risk dataset based on the obtained confidence assessment result.

[0005] This specification provides a data processing apparatus comprising: a code receiving module for receiving program code information to be released; a semantic parsing module for performing semantic parsing on the program code information to determine the change type corresponding to the program code information; a resource risk determination module for generating resource risk information matching the change information of the program code information if the change type corresponding to the program code information is a preset type and the change information of the program code information includes information related to preset resource information; and an evaluation and update module for evaluating the confidence level of the generated resource risk information and updating the current resource risk dataset based on the obtained confidence level evaluation result.

[0006] This specification provides an embodiment of a data processing device, comprising: a processor; and a memory arranged to store computer-executable instructions, wherein when the executable instructions are executed, the processor: receives program code information to be published; performs semantic parsing processing on the program code information to determine the change type corresponding to the program code information; if the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then generates resource risk information matching the change information of the program code information; performs confidence assessment on the generated resource risk information, and updates the current resource risk dataset based on the obtained confidence assessment result.

[0007] This specification also provides a storage medium for storing computer-executable instructions. When executed by a processor, the executable instructions perform the following process: receiving program code information to be released; performing semantic parsing on the program code information to determine the change type corresponding to the program code information; if the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then generating resource risk information matching the change information of the program code information; performing confidence assessment on the generated resource risk information, and updating the current resource risk dataset based on the obtained confidence assessment result.

[0008] This specification also provides a computer program product, including a computer program that, when executed by a processor, implements the following process: receiving program code information to be released; performing semantic parsing processing on the program code information to determine the change type corresponding to the program code information; if the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then generating resource risk information matching the change information of the program code information; performing a confidence assessment on the generated resource risk information, and updating the current resource risk dataset based on the obtained confidence assessment result. Attached Figure Description

[0009] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Figure 1 This is a schematic diagram of the structure of a data processing system described in this specification; Figure 2 This is a schematic diagram of a data processing procedure described in this specification; Figure 3 This is a schematic diagram of another data processing procedure described in this specification; Figure 4 This is a schematic diagram illustrating a process for publishing program code information as described in this specification; Figure 5 This is a schematic diagram illustrating the script construction process described in this manual; Figure 6 This is a schematic diagram of yet another data processing procedure described in this specification; Figure 7 This is a schematic diagram of a risk-based preservation process described in this manual; Figure 8 This is a schematic diagram of a data processing device described in this specification; Figure 9 This is a schematic diagram of a data processing device described in this specification. Detailed Implementation

[0010] This specification provides a data processing method, apparatus, and device through its embodiments.

[0011] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.

[0012] This specification provides an iterative resource risk prevention and control mechanism based on AI agents. In high-frequency iterative financial transactions, business logic and fields change frequently, and conventional risk control systems often suffer from update delays, leading to the exposure of resource risks. Typically, this can be achieved through a combination of manual version changes and manual risk verification. That is, before each code deployment, the risk control / testing team manually verifies the code changes and updates the relevant reconciliation logic. However, this method is inefficient, prone to overlooking non-explicit risk logic, and cannot keep pace with the high-frequency release schedule. Alternatively, LINK code scanning and security AI auditing can be used, introducing AI mechanisms into risk control and transaction systems to identify potential anomalies. However, this is mostly used for post-event auditing, not for pre-event prevention updates. Furthermore, this method does not integrate with verification script updates and monitoring mechanisms, and it does not proactively analyze code changes. Based on conventional approaches, the following situations currently exist: Untimely updates to prevention and control measures: After field logic changes, relevant reconciliation rules cannot be dynamically adjusted; Risk identification relies on manual experience: Developers / testers need to manually analyze the impact of program code changes and asset losses, which is prone to omissions; Inefficient knowledge reuse: Historical prevention and control logic is difficult to adapt to new program code change scenarios, requiring redesign; Iteration acceleration is disconnected from prevention and control: Business version cycles are shortening, and manual response cannot keep up with the speed of changes. To address this, this specification proposes a dynamic risk prevention and control mechanism of "continuous perception - intelligent analysis - timely deployment." Through an intelligent agent, risk analysis, logic evolution, and verification script updates are automatically completed within each iteration cycle, effectively improving the response speed and quality of resource prevention and control. Specific processing details can be found in the following embodiments.

[0013] The data processing methods provided in one or more embodiments of this specification are applicable to the data processing implementation environment. (Refer to...) Figure 1 The implementation environment includes at least: Client 100 and server 200. Furthermore, server 200 may include multiple different intelligent agents, algorithms, etc., among which: Client 100 can run on terminal devices, which can be mobile phones, personal computers, tablets, e-book readers, wearable devices, devices that interact with information based on AR (Augmented Reality) and VR (Virtual Reality), and laptop computers, etc. Client 100 can be installed on terminal devices. Client 100 can be an application, a browser, or a subroutine embedded in an application, etc.

[0014] Server 200 can run on a server, which can be one or more servers, a server cluster consisting of several servers, or a cloud server of a cloud computing platform, etc. Server 200 can be installed on the server. Server 200 can be an application or a subroutine embedded in an application, etc. Multiple different intelligent agents and algorithms can be integrated into server 200, or server 200 can call any one or more of multiple different intelligent agents and algorithms to perform corresponding operations.

[0015] In addition, it may include a database 300, which may be set in the server on which the server 200 runs or outside the server on which the server 200 runs. The database 300 may store program code information, resource risk datasets and other related information.

[0016] In this implementation environment, client 100 can write program code information and send the written program code information to server 200 as program code information to be published. Server 200 can perform semantic parsing processing on the program code information to determine the change type corresponding to the program code information. If the change type corresponding to the program code information is a preset type and the change information of the program code information includes information related to preset resource information, then resource risk information matching the change information of the program code information is generated. Then, the confidence level of the generated resource risk information can be evaluated, and the current resource risk dataset can be updated based on the obtained confidence level evaluation result.

[0017] like Figure 2 As shown in the embodiments of this specification, a data processing method is provided. The execution subject of this method can be a terminal device or a server, etc. The terminal device can be a mobile terminal device such as a mobile phone or tablet computer, or a computer device such as a laptop or desktop computer, or an IoT device (specifically, a smartwatch, in-vehicle device, etc.). The server can be a single server or a server cluster composed of multiple servers, etc. The server can be a backend server in fields such as finance or online shopping, or a backend server of an application, etc. This embodiment uses a server as the execution subject for detailed description. For the case where the execution subject is a terminal device, please refer to the following server case processing, which will not be repeated here. The method may specifically include the following steps: In step S202, the program code information to be released is received.

[0018] The program code information can be any type of program code, written in a specified programming language, such as C, C++, Java, Python, etc., depending on the specific circumstances. In this embodiment, the program code information could be code to be contributed to an open-source project, or it could be code used to develop new features for a specific business within a designated organization or institution, depending on the actual situation.

[0019] In implementation, program code information to be released can be obtained in various ways. For example, a user writes program code to contribute to an open-source project or to develop new functionality for an organization's internal business. Then, a program code submission page can be accessed via a terminal device. This page may include a program code input box, an OK button, a Cancel button, and a result output box. The user can enter the program code information to be released in the program code input box on this page. After entering the information, the user can click the OK button. At this time, the terminal device can obtain the program code information entered by the user in the program code input box and generate a code release request based on the obtained program code information. This code release request can then be sent to the server. The server can receive the code release request and extract the program code information to be released from it. Alternatively, technicians can write program code information and then directly input this program code information into the server. The server can then obtain the program code information to be released. Specific settings can be configured according to actual circumstances; this embodiment does not limit this approach.

[0020] In step S204, semantic parsing processing is performed on the program code information to determine the change type corresponding to the program code information.

[0021] The change types can include various types, such as field type, logic modification type, program code deletion type, etc. In practical applications, other change types can also be set, which can be set according to the actual situation.

[0022] In implementation, semantic parsing of program code information can be performed in various ways. For example, code diff analysis rules can be used to perform semantic parsing of program code information. These rules can be used to compare and perform logical semantic analysis of program code information, and can be used to identify business logic change points. The code diff analysis rules can include the Longest Common Subsequence (LCS) algorithm. Based on the LCS algorithm, the code diff analysis rules use dynamic programming to find the maximum similarity between two pieces of program code information, generating the minimum edit operation sequence. Additionally, time complexity optimization strategies can be set in the code diff analysis rules to control the complexity of the above calculation process. Through the synergistic effect of the LCS algorithm and time complexity optimization strategies in the code diff analysis rules, semantic parsing of program code information can be achieved, ultimately determining the change information in the program code information and the corresponding change type.

[0023] In step S206, if the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to the preset resource information, then resource risk information matching the change information of the program code information is generated.

[0024] The preset type can be set according to the actual situation. For example, the preset type can be a type related to resources or a type involving resources. Specifically, the preset type can include field type, logic modification type, etc.

[0025] In implementation, after determining the change type corresponding to the program code information using the above methods, the specific content of the change type can be extracted to determine if it is a preset type. If so, it can be determined whether the change information of the program code information involves resources, that is, whether the change information of the program code information includes information related to preset resource information. If so, the risk point corresponding to the resource risk information matching the change information of the program code information can be determined, and hypothetical information or test information for this risk point can be generated. The hypothetical information or test information for this risk point can include information related to this risk point, such as factors that may lead to resource loss or information related to resource logic errors. The specific settings can be configured according to the actual situation. Then, based on the generated hypothetical information or test information for this risk point, the resource risk information matching the change information of the program code information can be determined.

[0026] In step S208, the generated resource risk information is assessed for confidence level, and the current resource risk dataset is updated based on the obtained confidence level assessment results.

[0027] In implementation, the existence of corresponding risk points can be determined based on the generated resource risk information, and the confidence level of the risk point can be calculated. The calculated confidence level value can be used as the confidence evaluation result of the generated resource risk information. If the obtained confidence evaluation result is higher than the preset confidence threshold, the risk point can be determined to exist. At this time, the generated resource risk information can be used to update the current resource risk dataset. That is, the generated resource risk information can be added to the current resource risk dataset, or the generated resource risk information can be used to update the corresponding resource risk information in the current resource risk dataset, ultimately resulting in an updated resource risk dataset. In practical applications, the resource risk information in the resource risk dataset can be stored or presented in the form of a list or list. Specifically, the resource risk dataset can include the correspondence between risk point identifiers and resource risk information, and multiple different correspondences can be set in the risk point list.

[0028] This specification provides a data processing method. By receiving program code information to be released, semantic parsing is performed on the program code information to determine the corresponding change type. If the change type is a preset type and the change information includes information related to preset resource information, resource risk information matching the change information is generated. Finally, the generated resource risk information is assessed for confidence level, and the current resource risk dataset is updated based on the assessment results. This method, by identifying iterative logic in the program code information, evolving prevention scripts, and automatically updating monitoring links, constructs a self-evolving and continuously effective resource prevention system, significantly improving the response efficiency and coverage completeness of asset loss risks. Furthermore, it understands the "semantics" of business changes, not just their "syntax," thereby identifying potential asset loss impact paths.

[0029] In practical applications, the specific processing method for assessing the confidence level of the generated resource risk information in step S208 can vary. The following provides another optional processing method, which may specifically include the processing steps S2082 and S2084. Based on this, in the above... Figure 2 Based on this, the specific steps included in this method can be as follows: Figure 3 As shown.

[0030] In step S2082, the generated resource risk information is semantically supplemented by the product requirement document corresponding to the preset resource information to obtain the supplemented resource risk information.

[0031] In implementation, such as Figure 4As shown, product requirement documents corresponding to the aforementioned risk points can be obtained, as well as product requirement documents corresponding to other resource information related to the risk points. In this way, the generated resource risk information can be semantically supplemented by the product requirement documents corresponding to the obtained preset resource information, so as to make the above resource risk information more complete and obtain the supplemented resource risk information, thereby improving the accuracy and efficiency of subsequent risk identification.

[0032] In step S2084, a confidence assessment is performed on the supplemented resource risk information.

[0033] In practice, the confidence level of the supplemented resource risk information can be calculated according to the preset confidence level calculation formula, and the calculated confidence level value can be used as the confidence level assessment result of the supplemented resource risk information.

[0034] In practical applications, if the above-mentioned preset type is a field type, then the following steps A2 to A6 can also be performed.

[0035] In step A2, if the change type corresponding to the program code information is a field type, the change information of the program code information is determined, and the first intelligent agent performs semantic annotation processing on the change information of the program code information to obtain the field information corresponding to the change information of the program code information.

[0036] The first intelligent agent can be an entity capable of performing one or more different functions. It may include one or more different processing rules (such as data query rules, feature extraction rules, etc.), one or more network models (such as convolutional neural network models, recurrent neural network models, etc.), and one or more different large models (such as large language models (e.g., large language models for text modality, or large language models for speech modality, etc.), multimodal large models (e.g., large models for text and image modality, or large models for speech and image modality), full-modality large models, or discriminative large models, etc.). Furthermore, the first intelligent agent can run on a server, which can be one or more servers, a server cluster consisting of several servers, or a cloud server on a cloud computing platform, etc. In this embodiment, the first intelligent agent can be used to perform semantic annotation processing on program code.

[0037] In implementation, the architecture of the first intelligent agent can be pre-constructed using specified algorithms and / or models, and this first intelligent agent can be trained using a large amount of sample data to obtain the trained first intelligent agent. If the change type corresponding to the program code information is a field type (e.g., ... Figure 4(As shown in the example of newly added fields, etc.), then the changes to the program code information can be determined. Then, the changes to the program code information can be input into the first intelligent agent. The first intelligent agent performs semantic annotation processing on the changes to the program code information to obtain the semantic annotation information of the changes to the program code information, that is, the field information corresponding to the changes to the program code information.

[0038] In step A4, based on the field information corresponding to the change information in the program code information, the resource tag information that matches the field information is searched from the resource knowledge base.

[0039] The resource knowledge base can be constructed using expert knowledge, or it can be directly obtained from a specified database, depending on the actual situation.

[0040] In implementation, such as Figure 4 As shown, risk pattern matching can be used to search for resource tag information that matches the newly added field information in the resource tag information contained in the resource knowledge base.

[0041] In step A6, if resource tag information matching the above field information exists in the resource knowledge base, it is determined that the change information of the program code information includes information related to the preset resource information.

[0042] In practical applications, the above-mentioned resource knowledge base can also be constructed through the following steps B02 to B10.

[0043] In step B02, resource-related field information is obtained from one or more different databases.

[0044] One or more different databases can be pre-specified databases, databases of program code collected from the Internet, databases of specified scripts, etc., and can be set according to the actual situation.

[0045] In step B04, the first intelligent agent performs semantic annotation processing on the perceived resource-related field information to obtain the resource tag information corresponding to the perceived resource-related field information.

[0046] In implementation, the perceived resource-related field information can be input into the first intelligent agent. The first intelligent agent performs semantic annotation processing on the perceived resource-related field information to obtain the resource tag information corresponding to the perceived resource-related field information, such as "payment amount", "account balance", "handling fee", etc., and automatically classifies them into the specified resource field library.

[0047] In step B06, the second intelligent agent extracts key information corresponding to the perceived resource-related field information from the database. The key information includes one or more of the following: source information, purpose information, data type, and update frequency.

[0048] The second intelligent agent can be an entity capable of performing one or more different functions. It may include one or more different processing rules (such as data query rules, feature extraction rules, etc.), one or more network models (such as convolutional neural network models, recurrent neural network models, etc.), and one or more different large models (such as large language models (e.g., large language models for text modality, or large language models for speech modality, etc.), multimodal large models (e.g., large models for text and image modality, or large models for speech and image modality), full-modality large models, or discriminative large models, etc.). Furthermore, the second intelligent agent can run on a server, which can be one or more servers, a server cluster consisting of several servers, or a cloud server on a cloud computing platform, etc. In this embodiment, the second intelligent agent can be used to extract key information related to specified fields.

[0049] In implementation, the architecture of the second agent can be pre-constructed using specified algorithms and / or models. This second agent can then be trained using a large amount of sample data to obtain the trained agent. Through this second agent, key information such as the source, purpose, data type, and update frequency of field information can be extracted, thereby forming a standardized field model. Furthermore, it allows for the unification of business meaning and logical modeling at the field level.

[0050] In step B08, a field topology graph is constructed based on the dependencies and business flow information between different fields in the perceived resource-related field information, combined with the database table structure.

[0051] The database and table structure can include the hierarchical relationship between a specified database and different tables, the relationship between different databases, and the association relationship between different tables.

[0052] In addition, a topology visualization engine can be set up, which can render the information of the field topology graph into a visual structure diagram. Users can perform interactive operations such as viewing resource flow, retrieving field status, and identifying coverage through the nodes of the field topology graph.

[0053] In step B10, a resource knowledge base is constructed based on the field topology map, the resource tag information corresponding to the perceived resource-related field information, and the key information corresponding to the perceived resource-related field information.

[0054] In implementation, all the above-mentioned field models, field topology maps, resource tag information corresponding to the perceived resource-related field information, and key information corresponding to the perceived resource-related field information can be stored in the resource knowledge base to provide data support for subsequent resource maintenance and intelligent reasoning.

[0055] In practical applications, one or more different databases include one or more of the database corresponding to the verification script, the database corresponding to the DataBase data, and the database corresponding to the system source code.

[0056] In practical applications, the field topology graph is constructed in a hierarchical structure, consisting of multiple elements such as business domain information, database information, table information, field information, and verification scripts. For example, the field topology graph can be a four-level graph consisting of business domain-database-table-field information, or a five-level graph consisting of business domain-database-table-field information-verification scripts, etc. The specific configuration can be determined according to the actual situation.

[0057] Through steps B2 to B10, intelligent association and real-time perception of resource elements can be achieved, overcoming bottlenecks such as low efficiency, large coverage blind spots, and difficulty in knowledge transfer caused by manual maintenance. This provides a standardized and intelligent data infrastructure for resource security prevention and control, possessing cross-domain promotion value. Furthermore, through the collaboration of multiple intelligent agents, the automatic generation and dynamic updating of resources can be completed. Moreover, a computable resource security map can be constructed, connecting the entire chain of "business → data → logic → monitoring" to achieve structured location of risk points. By dynamically perceiving changes in data structure, the automatic updating of resources and rules is driven, ensuring data consistency.

[0058] In practical applications, the above verification script can be implemented through the following steps C2 to C8.

[0059] In step C2, description information for the first resource risk information is obtained.

[0060] Among them, the first resource risk information can be the resource risk information corresponding to any risk point.

[0061] In step C4, the descriptive information of the first resource risk information is extracted to obtain the target element information.

[0062] In implementation, such as Figure 5 As shown, semantic understanding can be performed on the descriptive information of the first resource risk information, and based on the results of semantic understanding, element extraction can be performed on the descriptive information to obtain target element information. The target element information can be information about elements used to construct the verification script or related to constructing the verification script. For example, it can include one or more of the following: table-related information, corresponding field-related information, condition information, and thresholds.

[0063] In step C6, based on the target element information, the verification type that matches the target element information is determined.

[0064] The verification type can include various types, such as TM verification type, TH verification type, T1 verification type, etc.

[0065] In implementation, such as Figure 5 As shown, a pre-defined correspondence between element information and verification types can be established. After obtaining the target element information, the verification type corresponding to the target element information can be obtained based on the above correspondence. The obtained verification type corresponding to the target element information can be used as the verification type that matches the target element information. If the target element information contains multiple elements, the verification type corresponding to each element can be obtained through the above correspondence. If the verification types corresponding to multiple elements are the same, the obtained verification type is used as the verification type that matches the target element information. If the verification types corresponding to multiple elements are different, the number of each verification type can be counted, and the verification type corresponding to the maximum number can be used as the verification type that matches the target element information. The specific settings can be configured according to the actual situation.

[0066] In step C8, based on the determined verification type, a corresponding verification template is determined, and based on the target element information and the determined verification template, a verification script corresponding to the first resource risk information is generated by the third intelligent agent.

[0067] The third intelligent agent can be an entity capable of performing one or more different functions. It can include one or more different processing rules (such as data query rules, feature extraction rules, etc.), one or more network models (such as convolutional neural network models, recurrent neural network models, etc.), and one or more different large models (such as large language models (e.g., large language models for text modality, or large language models for speech modality, etc.), multimodal large models (e.g., large models for text and image modality, or large models for speech and image modality), full-modality large models, or discriminative large models, etc.). Furthermore, the third intelligent agent can run on a server, which can be one or more servers, a server cluster consisting of several servers, or a cloud server on a cloud computing platform, etc. In this embodiment, the third intelligent agent can be used to generate verification scripts corresponding to a certain resource risk information (or a certain risk point).

[0068] In implementation, such as Figure 5As shown, different verification templates can be set for different verification types. In practical applications, the verification template corresponding to the TM verification type can be the TM verification template, the verification template corresponding to the TH verification type can be the TH verification template, the verification template corresponding to the T1 verification type can be the T1 verification template, and so on. After determining the verification type in the above way, the corresponding verification template can be determined based on the verification type and the pre-set corresponding verification template. For example, if the verification type is TM verification, then the corresponding verification template can be the TM verification template.

[0069] The architecture of a third-party agent can be pre-constructed using specified algorithms and / or models. This agent can be trained using a large amount of sample data to obtain a trained third-party agent. Target element information and a defined verification template can be input into the third-party agent. The agent, combining the target element information and the defined verification template, fills the verification template with the target element information and makes necessary adjustments (such as deleting redundant information, supplementing missing information, and adding necessary transfer codes (or acceptance codes, etc.)). Finally, a verification script corresponding to the first resource risk information can be generated.

[0070] Among them, such as Figure 5 As shown, the specific process of filling the target element information into the determined verification template using a third-party intelligent agent, combined with the target element information and the determined verification template, can be achieved by the third-party intelligent agent generating corresponding SQL statements. These SQL statements can then be used to fill the target element information into the determined verification template, modify relevant information in the determined verification template using the target element information, or delete redundant information (or erroneous information, or information contradicting the target element information, etc.) from the determined verification template. Furthermore, the specific process of making necessary adjustments to the filled verification template can also be achieved by the third-party intelligent agent generating corresponding SQL statements using the target element information and the determined verification template, and then using these SQL statements to implement the above specific processing. For details, please refer to the foregoing content; further elaboration is not required here.

[0071] In practical applications, the verification script constructed above can be optimized in the following ways, specifically including the following: optimizing the verification script corresponding to the first resource risk information to obtain an optimized verification script. The optimization process includes index building and / or partition prompt information building.

[0072] In implementation, such as Figure 5As shown, optimization strategies can be preset, such as optimization strategies for index building and partition suggestion information building. The specific strategies can be set according to actual needs. The verification script corresponding to the first resource risk information can be optimized using the preset optimization strategies. For example, the index building optimization strategy can be used to build index information for the verification script corresponding to the first resource risk information, or the partition suggestion information building optimization strategy can be used to build index information for the verification script corresponding to the first resource risk information, etc., ultimately resulting in an optimized verification script.

[0073] In practical applications, the aforementioned preset type can be a processing logic class, and the specific processing method of step S206 can vary. The following provides another optional processing method, which specifically includes the processing of steps S2062 and S2064. Based on this, in the above... Figure 2 Based on this, the specific steps included in this method can be as follows: Figure 6 As shown.

[0074] In step S2062, if the change type corresponding to the program code information is a processing logic class, then the change information of the program code information is determined, and the impact range of the change information of the program code information on the upstream and downstream program codes corresponding to the program code information is obtained.

[0075] The processing logic class can include types such as modifying logical relationships and modifying logical calculation rules.

[0076] In implementation, if the change type corresponding to the program code information is a processing logic class (for example, such as...), Figure 4 By analyzing the modified logic branch shown, the changes to the program code information can be determined. Then, the changes to the program code information can be analyzed. Based on the analysis results, the impact of the changes to the program code information on other program codes (including the depth and breadth of the impact) can be determined. Based on the degree of impact, the scope of the impact on the upstream and downstream program codes corresponding to the program code information can be determined.

[0077] In step S2064, if the change information of the program code information includes information related to the preset resource information, then based on the second resource risk information corresponding to the change information of the program code information and the third resource risk information corresponding to the aforementioned scope of influence, resource risk information matching the change information of the program code information is generated.

[0078] In implementation, determining whether the change information in the program code information includes information related to preset resource information can be achieved through the above method (steps A2 to A6 above): the first intelligent agent performs semantic annotation processing on the change information in the program code information to obtain the field information corresponding to the change information in the program code information; based on the field information corresponding to the change information in the program code information, resource tag information matching the field information is searched in the resource knowledge base; if resource tag information matching the above field information exists in the resource knowledge base, it is determined that the change information in the program code information includes information related to preset resource information. Specific processing details can be found in the aforementioned related content and will not be repeated here. Figure 4 As shown, if the change information in the program code information includes information related to the preset resource information, then the second resource risk information corresponding to the change information in the program code information and the third resource risk information corresponding to the above-mentioned scope of influence can be combined to generate resource risk information that matches the change information in the program code information.

[0079] In addition, such as Figure 4 As shown, if the change type corresponding to the program code information is program code deletion, then failure detection can be performed on the corresponding resource risk information (or the corresponding historical risk point). Through failure detection, it can be determined whether the deleted program code information corresponding to the change information is risk protection logic information. If so, the resource risk information (or the corresponding historical risk point) can be marked and marked as failure status. Then, the current resource risk dataset can be updated, and the failure resource risk information (or the corresponding historical risk point) can be output.

[0080] In practical applications, corresponding risk prevention and preservation mechanisms can be set for different risk points, and the preservation engine can be set to execute the above risk prevention and preservation mechanisms. For details, please refer to the processing of steps D2 to D6 below.

[0081] In step D2, retrieve each resource risk information from the resource risk dataset.

[0082] In implementation, such as Figure 7 As shown, the preservation engine can monitor whether there are program code information release events in the code repository. If there are program code information release events in the code repository, it can trigger the processing of step D2, that is, it can pull each resource risk information or historical risk point in the current business domain from the resource risk dataset or the corresponding risk point library.

[0083] In step D4, for each resource risk information, the following processing is performed: verifying whether each resource risk information is valid, detecting whether the program code information associated with each resource risk information exists, evaluating whether the processing logic corresponding to each resource risk information matches the corresponding program code information, and obtaining the corresponding processing result.

[0084] In implementation, such as Figure 7 As shown, the preservation engine can pre-set corresponding algorithms or processing rules. These algorithms or rules can verify the validity of each resource risk information, detect the existence of program code information associated with each resource risk information, and evaluate whether the processing logic corresponding to each resource risk information matches the corresponding program code information. Through the above processing, the results of each process can be obtained. Then, the results of each process can be merged to obtain the final processing result.

[0085] In step D6, a resource risk handling strategy is generated based on the obtained processing results, and the resource risk handling strategy is executed to update the resource risk dataset.

[0086] In implementation, such as Figure 7 As shown, the preservation engine can analyze the processing results and determine potential risks, their scope of impact, and severity based on the analysis. Then, it can generate corresponding resource risk management strategies based on this information. These strategies can then be executed to mitigate the risks and the resource risk dataset can be updated.

[0087] In practical applications, resource risk handling strategies include one or more of the following: an alarm strategy for risk failure corresponding to the fourth resource risk information in the resource risk dataset; a resource risk information migration strategy where the field identifier corresponding to the fifth resource risk information in the resource risk dataset changes, but the semantic change of the field information corresponding to the fifth resource risk information is less than a preset threshold; and a resource risk map update strategy where the program code information is newly added program code information and the program code information does not trigger a preset risk related to the preset resource information but expands the scope of influence of the preset risk.

[0088] This specification provides a data processing method. By receiving program code information to be released, semantic parsing is performed on the program code information to determine the corresponding change type. If the change type is a preset type and the change information includes information related to preset resource information, resource risk information matching the change information is generated. Finally, the generated resource risk information is assessed for confidence level, and the current resource risk dataset is updated based on the assessment results. This method, by identifying iterative logic in the program code information, evolving prevention scripts, and automatically updating monitoring links, constructs a self-evolving and continuously effective resource prevention system, significantly improving the response efficiency and coverage completeness of asset loss risks. Furthermore, it understands the "semantics" of business changes, not just their "syntax," thereby identifying potential asset loss impact paths.

[0089] Furthermore, by sensing changes to fields, logic, and business paths in code or documents through the database, and analyzing the changed content through intelligent agents, the system extracts the resource operation logic involved, such as adding or deleting fields and modifying calculation formulas. Based on the field topology graph and logic chain, it infers the resource paths and verification points that may be affected by the changes. In addition, through semantic and graph joint judgment, it recommends and intelligently generates new verification rules, supporting the generation and execution logic updates of verification scripts. Code changes trigger adaptive updates of verification rules and risk coverage logic, ensuring that the protection mechanism remains consistent with the system. Verification elements are extracted from the description information of the change information, automatically generating deployable verification scripts and improving script deployment efficiency. Combining historical loss cases with the change context, high-risk logic points in the new version are identified, and existing prevention and control measures are linked to strengthen protection points. It supports the verification of recommended protection and feedback on the effect, forming a closed-loop evolution mechanism of "identification-generation-verification-iteration". It supports collaborative updates of resource prevention and control rules by development, testing, and risk control roles during the change process, opening up the protection link and improving execution efficiency.

[0090] The above describes the data processing method provided in the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a data processing device, such as... Figure 8 As shown.

[0091] The data processing device includes: a code receiving module 801, a semantic parsing module 802, a resource risk determination module 803, and an evaluation and update module 804, wherein: The code receiving module 801 receives the program code information to be published; The semantic parsing module 802 performs semantic parsing processing on the program code information to determine the change type corresponding to the program code information; The resource risk determination module 803 generates resource risk information that matches the change information of the program code information if the change type corresponding to the program code information is a preset type and the change information of the program code information includes information related to the preset resource information. The evaluation and update module 804 evaluates the confidence level of the generated resource risk information and updates the current resource risk dataset based on the obtained confidence level evaluation results.

[0092] In this embodiment of the specification, the evaluation update module 804 includes: The supplementary unit semantically supplements the generated resource risk information by using the product requirement document corresponding to the preset resource information to obtain the supplemented resource risk information. The assessment unit performs a confidence assessment on the supplemented resource risk information.

[0093] In this embodiment of the specification, the preset type is a field class, and the device further includes: The annotation module determines the change information of the program code information if the change type corresponding to the program code information is a field type, and performs semantic annotation processing on the change information of the program code information through the first intelligent agent to obtain the field information corresponding to the change information of the program code information. The search module searches for resource tag information that matches the field information based on the field information corresponding to the change information of the program code information from the resource knowledge base; If the resource knowledge base contains resource tag information that matches the field information, the determination module determines that the change information of the program code information includes information related to the preset resource information.

[0094] In the embodiments described in this specification, the device further includes: The perception module perceives resource-related field information from one or more different databases; The semantic annotation module performs semantic annotation processing on the perceived resource-related field information based on the first intelligent agent to obtain the resource tag information corresponding to the perceived resource-related field information; The information extraction module extracts key information corresponding to the perceived resource-related field information from the database through the second intelligent agent. The key information includes one or more of the following: source information, usage information, data type, and update frequency. The graph construction module constructs a field topology graph based on the dependencies and business flow information between different fields in the perceived resource-related field information, combined with the database table structure. The knowledge base construction module constructs the resource knowledge base based on the field topology map, the resource tag information corresponding to the perceived resource-related field information, and the key information corresponding to the perceived resource-related field information.

[0095] In the embodiments of this specification, the one or more different databases include one or more of the database corresponding to the verification script, the database corresponding to the DataBase data, and the database corresponding to the system source code; the field topology map is constructed in a hierarchical structure from multiple of the business domain information, library information, table information, field information, and verification script.

[0096] In the embodiments described in this specification, the device further includes: The description information acquisition module acquires description information for the first resource risk information; The element extraction module extracts elements from the descriptive information of the first resource risk information to obtain target element information; The verification type determination module determines the verification type that matches the target element information based on the target element information. The verification script generation module determines the corresponding verification template based on the determined verification type, and generates the verification script corresponding to the first resource risk information through a third intelligent agent based on the target element information and the determined verification template.

[0097] In the embodiments described in this specification, the device further includes: The script optimization module optimizes the verification script corresponding to the first resource risk information to obtain an optimized verification script. The optimization process includes index building and / or partition prompt information building.

[0098] In this embodiment of the specification, the preset type is a processing logic class, and the resource risk determination module 803 includes: The scope of influence determination unit determines the change information of the program code information if the change type corresponding to the program code information is a processing logic class, and obtains the scope of influence of the change information of the program code information on the upstream and downstream program code corresponding to the program code information. The resource risk determination unit, if the change information of the program code information includes information related to preset resource information, generates resource risk information that matches the change information of the program code information based on the second resource risk information corresponding to the change information of the program code information and the third resource risk information corresponding to the scope of influence.

[0099] In the embodiments described in this specification, the device further includes: The information retrieval module retrieves each resource risk information from the resource risk dataset; The processing module performs the following processing for each resource risk information: verifying whether each resource risk information is valid, detecting whether the program code information associated with each resource risk information exists, evaluating whether the processing logic corresponding to each resource risk information matches the corresponding program code information, and obtaining the corresponding processing result; The resource risk processing module generates a resource risk processing strategy based on the obtained processing results and executes the resource risk processing strategy to update the resource risk dataset.

[0100] In the embodiments described in this specification, the resource risk handling strategies include one or more of the following: The alarm strategy for risk failure corresponding to the fourth resource risk information in the resource risk dataset; The resource risk information migration strategy in which the field identifier corresponding to the fifth resource risk information in the resource risk dataset is changed, but the semantic change of the field information corresponding to the fifth resource risk information is less than a preset threshold. The program code information refers to newly added program code information, and the program code information does not trigger the preset risks related to preset resource information, but expands the scope of influence of the preset risks.

[0101] For ease of description, the above devices are described by dividing them into various modules or units based on their functions. Of course, when implementing one or more embodiments of this specification, the functions of each module or unit can be implemented in one or more software and / or hardware components, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely illustrative; the division of each module and unit is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or modules can be combined or integrated into another system, or some features can be ignored or not executed, etc.

[0102] This specification provides a data processing device that receives program code information to be released, performs semantic parsing on the program code information to determine the change type corresponding to the program code information. If the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then resource risk information matching the change information of the program code information is generated. Finally, the generated resource risk information can be evaluated for confidence level, and the current resource risk dataset is updated based on the obtained confidence level evaluation result. In this way, by identifying the iterative logic in the program code information, evolving the prevention and control script, and automatically updating the monitoring link, a self-evolving and continuously effective resource prevention and control system is constructed, significantly improving the response efficiency and coverage completeness of asset loss risk. Moreover, it can understand the "semantics" of business changes, not just the "syntax," thereby identifying potential asset loss impact paths.

[0103] Furthermore, by sensing changes to fields, logic, and business paths in code or documents through the database, and analyzing the changed content through intelligent agents, the system extracts the resource operation logic involved, such as adding or deleting fields and modifying calculation formulas. Based on the field topology graph and logic chain, it infers the resource paths and verification points that may be affected by the changes. In addition, through semantic and graph joint judgment, it recommends and intelligently generates new verification rules, supporting the generation and execution logic updates of verification scripts. Code changes trigger adaptive updates of verification rules and risk coverage logic, ensuring that the protection mechanism remains consistent with the system. Verification elements are extracted from the description information of the change information, automatically generating deployable verification scripts and improving script deployment efficiency. Combining historical loss cases with the change context, high-risk logic points in the new version are identified, and existing prevention and control measures are linked to strengthen protection points. It supports the verification of recommended protection and feedback on the effect, forming a closed-loop evolution mechanism of "identification-generation-verification-iteration". It supports collaborative updates of resource prevention and control rules by development, testing, and risk control roles during the change process, opening up the protection link and improving execution efficiency.

[0104] The above are the data processing apparatuses provided in the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a data processing device, such as... Figure 9 As shown.

[0105] The data processing device can provide terminal equipment or servers, etc., for the above embodiments.

[0106] Data processing devices can vary significantly in configuration and performance, and may include a communication interface 902, a user interface 904, a processor 906, and a data storage 908. These components are interconnected and communicate with each other via a system bus, network, or other connection mechanism 910. The communication interface 902 enables the data processing device 900 to communicate with other devices, access networks, and transmission networks via analog or digital modulation. For example, the communication interface 902 may include a chipset and antenna for wireless communication with a radio access network or access point. Furthermore, the communication interface 902 can be a wired interface such as Ethernet, Token Ring, or a USB port, or a wireless interface such as Wi-Fi, Bluetooth, Global Positioning System (GPS), or a wide-area wireless interface (e.g., WiMAX or LTE). Of course, the communication interface 902 may also support other forms of physical layer interfaces and standard or proprietary communication protocols. The communication interface 902 may also include multiple physical communication interfaces, such as Wi-Fi, Bluetooth, and wide-area wireless interfaces.

[0107] User interface 904 includes receiving user input and providing output to the user. Therefore, user interface 904 may include input components such as a keypad, keyboard, touch-sensitive or presence-sensitive panel, computer mouse, trackball, joystick, microphone, still camera, and video camera, and output components such as a display screen (which may be combined with a touch-sensitive panel), CRT, LCD, LED, display using DLP technology, printer, and other similar devices known or developed in the future. User interface 904 may also generate auditory output via speakers, speaker jacks, audio output ports, audio output devices, headphones, and other similar devices known or developed in the future. In some embodiments, user interface 904 may include software, circuitry, or other forms of logic capable of transmitting and receiving data from external user input / output devices. Additionally or alternatively, data processing device 900 may support remote access from other devices via communication interface 902 or another physical interface (not shown). User interface 904 may be configured to receive user input, the position and movement of which may be indicated by indicators or cursors described herein. User interface 904 may also be configured as a display device for rendering or displaying text fragments.

[0108] Processor 906 may contain one or more general-purpose processors and / or special-purpose processors.

[0109] Data storage 908 may include one or more volatile and / or non-volatile storage components and may be integrated wholly or partially with processor 906. Data storage 908 may include removable and non-removable components.

[0110] Processor 906 is capable of executing program instructions 918 (e.g., compiled or uncompiled program logic and / or machine code) stored in data storage 908 to perform the various functions described herein. Data storage 908 may contain a non-transitory computer-readable medium on which program instructions are stored, which, when executed by data processing device 900, enable data processing device 900 to perform any methods, processes, or functions disclosed in this specification and / or the accompanying drawings. Execution of program instructions 918 by processor 906 may result in processor 906 using data 912.

[0111] For example, program instructions 918 may include an operating system 922 (e.g., an operating system kernel, device drivers, and / or other modules) installed on the data processing device 900, and one or more application programs 920 (e.g., a browser, social application, or game application). Similarly, data 912 may include operating system data 916 and application data 914. Operating system data 916 is primarily accessible to the operating system 922, while application data 914 is primarily accessible to one or more application programs 920. Application data 914 may reside in a file system that is visible or hidden from the user of the data processing device 900.

[0112] Application 920 can communicate with operating system 912 through one or more application programming interfaces (APIs). These APIs help application 920 read and / or write application data 914, transmit or receive information via communication interface 902, receive or display information on user interface 904, etc.

[0113] In some terminology, application 920 may be simply referred to as "app". Furthermore, application 920 can be downloaded to data processing device 900 through one or more online app stores or app markets. However, applications can also be installed on data processing device 900 in other ways, such as through a web browser or a physical interface on data processing device 900 (e.g., a USB port).

[0114] Specifically, in this embodiment, the data processing device 900 includes a data storage 908 and one or more program instructions 918, wherein one or more program instructions 918 are stored in the data storage 908, and one or more program instructions 918 are configured to be executed by one or more processors. The one or more program instructions include computer-executable instructions for performing the following: Receive program code information to be published; The program code information is semantically parsed to determine the change type corresponding to the program code information; If the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then resource risk information matching the change information of the program code information is generated; The generated resource risk information is assessed for confidence level, and the current resource risk dataset is updated based on the obtained confidence level assessment results.

[0115] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the data processing device embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0116] This specification provides a data processing device that receives program code information to be released, performs semantic parsing on the program code information to determine the change type corresponding to the program code information. If the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then resource risk information matching the change information of the program code information is generated. Finally, the generated resource risk information can be evaluated for confidence level, and the current resource risk dataset is updated based on the obtained confidence level evaluation result. In this way, by identifying the iterative logic in the program code information, evolving the prevention and control script, and automatically updating the monitoring link, a self-evolving and continuously effective resource prevention and control system is constructed, significantly improving the response efficiency and coverage completeness of asset loss risk. Moreover, it can understand the "semantics" of business changes, not just the "syntax," thereby identifying potential asset loss impact paths.

[0117] Furthermore, based on the above Figures 1 to 7 This specification also provides a storage medium for storing computer-executable instruction information in one or more embodiments. In one specific embodiment, the storage medium may be a USB flash drive, optical disc, hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, it can realize the following process: Receive program code information to be published; The program code information is semantically parsed to determine the change type corresponding to the program code information; If the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then resource risk information matching the change information of the program code information is generated; The generated resource risk information is assessed for confidence level, and the current resource risk dataset is updated based on the obtained confidence level assessment results.

[0118] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the above-described storage medium embodiment is basically similar to the method embodiment, so the description is relatively simple; relevant parts can be referred to the description of the method embodiment.

[0119] This specification provides a storage medium that receives program code information to be released, and then performs semantic parsing processing on the program code information to determine the change type corresponding to the program code information. If the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then resource risk information matching the change information of the program code information is generated. Finally, the confidence level of the generated resource risk information can be assessed, and the current resource risk dataset can be updated based on the obtained confidence level assessment results. In this way, by identifying the iterative logic in the program code information, evolving the prevention and control script, and automatically updating the monitoring link, a self-evolving and continuously effective resource prevention and control system is constructed, significantly improving the response efficiency and coverage completeness of asset loss risks. Moreover, it can understand the "semantics" of business changes, not just the "syntax," thereby identifying potential asset loss impact paths.

[0120] Furthermore, based on the above Figures 1 to 7 This specification also provides one or more embodiments of a computer program product, including a computer program, which, when executed by a processor, can perform the following processes: Receive program code information to be published; The program code information is semantically parsed to determine the change type corresponding to the program code information; If the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then resource risk information matching the change information of the program code information is generated; The generated resource risk information is assessed for confidence level, and the current resource risk dataset is updated based on the obtained confidence level assessment results.

[0121] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the above-described embodiment of a computer program product is relatively simple in description because it is fundamentally similar to the method embodiment; relevant parts can be referred to the description of the method embodiment.

[0122] This specification provides a computer program product that receives program code information to be released, and then performs semantic parsing processing on the program code information to determine the change type corresponding to the program code information. If the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then resource risk information matching the change information of the program code information is generated. Finally, the confidence level of the generated resource risk information can be assessed, and the current resource risk dataset can be updated based on the obtained confidence level assessment results. In this way, by identifying the iterative logic in the program code information, evolving the prevention and control script, and automatically updating the monitoring link, a self-evolving and continuously effective resource prevention and control system is constructed, significantly improving the response efficiency and coverage completeness of asset loss risks. Moreover, it can understand the "semantics" of business changes, not just the "syntax," thereby identifying potential asset loss impact paths.

[0123] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims may be performed in a different order than those shown in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired results. In some embodiments, multitasking and parallel processing are possible or may be advantageous. Moreover, although one or more embodiments of this specification provide method steps as described in the embodiments or flowcharts, it is understood that the order of steps listed in the embodiments or flowcharts is merely one possible execution order among many steps and does not represent the only execution order. Therefore, when method steps are involved in the claims, adjustments to the order of those steps, or parallelism between steps, are also within the scope of protection of the claims.

[0124] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must also be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also understand that by simply performing some logic programming on the method flow using one of these hardware description languages ​​and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.

[0125] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.

[0126] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0127] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.

[0128] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0129] The embodiments described herein are illustrated with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0130] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0131] These computer program instructions may also be loaded onto a computer or other programmable device to cause a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0132] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0133] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0134] Computer-readable media include both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0135] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical or equivalent elements in the process, method, article, or apparatus that includes said element. Furthermore, "a," "an," and "the" are not specifically singular and may include plural forms. Ordinal numbers such as "first," "second," etc., do not necessarily indicate order; they are often used to distinguish objects. For example, "first server" and "second server" usually refer to two servers, described as "first server" and "second server" to differentiate them; however, sometimes these two servers may be the same server. Moreover, in this specification, unless explicitly stated otherwise, "receiving and sending data" does not necessarily mean direct receiving and sending; it can be indirect receiving and sending (i.e., receiving and sending indirectly through one or more entities). Similarly, in this specification, unless otherwise stated, the relationships between structures can be direct or indirect.

[0136] Furthermore, the specific terms used in this specification to describe embodiments, such as "an embodiment," "one embodiment," or "some embodiments," refer to a particular feature, structure, or characteristic related to at least one embodiment of this specification. Therefore, it should be emphasized and noted that "an embodiment," "one embodiment," or "an alternative embodiment" mentioned twice or more in different locations in this specification do not necessarily refer to the same embodiment. Moreover, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of those different embodiments or examples, without contradiction.

[0137] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0138] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. One or more embodiments of this specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0139] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

[0140] The above description is merely an embodiment of this specification and is not intended to limit this document. Various modifications and variations can be made to this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims in this document.

Claims

1. A data processing method, the method comprising: Receive program code information to be published; The program code information is semantically parsed to determine the change type corresponding to the program code information; If the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then resource risk information matching the change information of the program code information is generated; The generated resource risk information is assessed for confidence level, and the current resource risk dataset is updated based on the obtained confidence level assessment results.

2. The method according to claim 1, wherein the confidence assessment of the generated resource risk information includes: The generated resource risk information is semantically supplemented by the product requirement document corresponding to the preset resource information to obtain the supplemented resource risk information. A confidence assessment was conducted on the supplemented resource risk information.

3. The method according to claim 1, wherein the preset type is a field class, and the method further includes: If the change type corresponding to the program code information is a field type, then the change information of the program code information is determined, and the change information of the program code information is semantically annotated by the first intelligent agent to obtain the field information corresponding to the change information of the program code information. Based on the field information corresponding to the change information of the program code information, search the resource tag information that matches the field information from the resource knowledge base; If the resource knowledge base contains resource tag information that matches the field information, then it is determined that the change information of the program code information includes information related to the preset resource information.

4. The method according to claim 3, further comprising: Obtain resource-related field information from one or more different databases; Based on the first intelligent agent, semantic annotation processing is performed on the perceived resource-related field information to obtain the resource tag information corresponding to the perceived resource-related field information; The second intelligent agent extracts key information corresponding to the perceived resource-related field information from the database. The key information includes one or more of the following: source information, usage information, data type, and update frequency. Based on the perceived dependencies and business flow information among different fields related to resources, and combined with the database table structure, a field topology graph is constructed. Based on the field topology map, the resource tag information corresponding to the perceived resource-related field information, and the key information corresponding to the perceived resource-related field information, the resource knowledge base is constructed.

5. The method according to claim 4, wherein the one or more different databases include one or more of the database corresponding to the verification script, the database corresponding to the DataBase data, and the database corresponding to the system source code; the field topology map is constructed in a hierarchical structure from multiple of the business domain information, library information, table information, field information, and verification script.

6. The method according to claim 5, further comprising: Obtain descriptive information regarding the risk information of the primary resource; Extract elements from the descriptive information of the first resource risk information to obtain target element information; Based on the target element information, determine the verification type that matches the target element information; Based on the determined verification type, a corresponding verification template is determined, and based on the target element information and the determined verification template, a verification script corresponding to the first resource risk information is generated by a third intelligent agent.

7. The method according to claim 6, further comprising: The verification script corresponding to the first resource risk information is optimized to obtain an optimized verification script. The optimization process includes index building and / or partition prompt information building.

8. The method according to claim 1, wherein the preset type is a processing logic class, and the step of generating resource risk information matching the change information of the program code information if the change type corresponding to the program code information is the preset type, and the change information of the program code information includes information related to the preset resource information, includes: If the change type corresponding to the program code information is a processing logic class, then determine the change information of the program code information and obtain the impact range of the change information of the program code information on the upstream and downstream program code corresponding to the program code information; If the change information in the program code information includes information related to preset resource information, then resource risk information matching the change information in the program code information is generated based on the second resource risk information corresponding to the change information in the program code information and the third resource risk information corresponding to the scope of influence.

9. The method according to any one of claims 1-8, further comprising: Retrieve information on each resource risk from the resource risk dataset; For each resource risk information, the following processing is performed: verify whether each resource risk information is valid, check whether the program code information associated with each resource risk information exists, evaluate whether the processing logic corresponding to each resource risk information matches the corresponding program code information, and obtain the corresponding processing result; Based on the obtained processing results, a resource risk handling strategy is generated and executed to update the resource risk dataset.

10. The method according to claim 9, wherein the resource risk management strategy includes one or more of the following: The alarm strategy for risk failure corresponding to the fourth resource risk information in the resource risk dataset; The resource risk information migration strategy in which the field identifier corresponding to the fifth resource risk information in the resource risk dataset is changed, but the semantic change of the field information corresponding to the fifth resource risk information is less than a preset threshold. The program code information refers to newly added program code information, and the program code information does not trigger the preset risks related to preset resource information, but expands the scope of influence of the preset risks.

11. A data processing apparatus, the apparatus comprising: The code receiving module receives information about the program code to be released. The semantic parsing module performs semantic parsing processing on the program code information to determine the change type corresponding to the program code information; The resource risk determination module generates resource risk information that matches the change information of the program code information if the change type corresponding to the program code information is a preset type and the change information of the program code information includes information related to the preset resource information. The evaluation and update module assesses the confidence level of the generated resource risk information and updates the current resource risk dataset based on the obtained confidence level assessment results.

12. A data processing apparatus, the data processing apparatus comprising: processor; as well as A memory configured to store computer-executable instructions, which, when executed, cause the processor to: Receive program code information to be published; The program code information is semantically parsed to determine the change type corresponding to the program code information; If the change type corresponding to the program code information is a preset type, and the change information of the program code information includes information related to preset resource information, then resource risk information matching the change information of the program code information is generated; The generated resource risk information is assessed for confidence level, and the current resource risk dataset is updated based on the obtained confidence level assessment results.