Real-time payment authorization method and device for enterprise fund flow, equipment and medium

By integrating a shadow account engine into the payment risk control gateway, enhanced payment requests are generated and budget pre-freezing and compliance determination are performed, solving the problem of the disconnect between budget control and payment actions in the enterprise payment system, and realizing real-time compliance response and efficient reconciliation.

CN122453408APending Publication Date: 2026-07-24北京合思信息技术有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
北京合思信息技术有限公司
Filing Date
2026-04-30
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

In existing technologies, enterprise payment systems cannot achieve real-time binding of budget control and payment actions, leading to risks such as overspending and illegal cash withdrawals. Furthermore, compliance determination relies on the core expense control database or manual rules, which cannot meet the millisecond-level response requirements, resulting in low reconciliation efficiency.

Method used

Integrate a shadow account engine into the payment risk control gateway to build a shadow account system. The shadow account engine generates enhanced payment requests and performs budget pre-freezing and compliance judgment in combination with business context information. Payment permissions are granted only when the budget pre-freezing is successful and the compliance judgment is passed.

Benefits of technology

It has enabled the pre-mandatory binding of budget control and payment actions, significantly improving the speed of compliance response and the efficiency of business and financial reconciliation, and ensuring an automatic closed loop of resource locking and compliance judgment before expenditure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122453408A_ABST
    Figure CN122453408A_ABST
Patent Text Reader

Abstract

The application provides a kind of real-time payment authorization method, device, equipment and medium for enterprise fund flow, it is related to payment authorization technical field, comprising: receiving the original payment request initiated by user through associated terminal, and the enhanced payment request is generated in combination with the business context information associated with original payment request;Through shadow account engine, according to the target budget unit of the enhanced payment request to which it belongs, perform budget pre-freezing operation;Generate compliance determination rules matched with enhanced payment request, to use compliance determination rules to determine the compliance of enhanced payment request;When budget pre-freezing operation is successful and compliance determination passes, grant payment authority for enhanced payment request, to release the payment instruction corresponding to enhanced payment request to external fund settlement account.The application realizes the prior forced binding of budget control and payment action, and significantly improves the compliance response speed and the efficiency of industry and finance reconciliation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of payment authorization technology, and in particular to a real-time payment authorization method, apparatus, equipment and medium for corporate cash flow. Background Technology

[0002] Currently, corporate spending is shifting from "personal advance payment" to "corporate payment," but bank card payment systems and corporate expense control systems have long been disconnected: banks only deduct funds without knowing the purpose of the transaction; expense control systems only manage approval processes and cannot intervene in the instant of payment. This results in risks such as overspending, illegal cash withdrawals, and misuse of company cards only being discovered after the fact, and financial losses are often irrecoverable.

[0003] In existing technologies, enterprises typically employ two methods to implement payment control: Method 1, Post-Payment Reconciliation: After payment, the expense control system downloads the transaction record through direct bank-enterprise connection and then compares it with the reimbursement documents for verification. This method relies on the bank's T+1 end-of-day reconciliation, creating a risk control vacuum period and failing to prevent irregular payments that have already occurred. Method 2, Advance Payment Approval: Employees pay in advance and then submit a reimbursement application. Only after the expense control system approves the application will the finance department transfer funds to the employee's account. This method shifts the control point to the reimbursement stage, failing to constrain the payment behavior itself, resulting in a poor employee experience, and still carries the risk of misappropriation of advance payments.

[0004] Neither of the above two methods deploys real-time decision-making capabilities at the payment risk control gateway layer. Their fundamental flaws are: 1. Budget control is separated from payment actions, lacking a strong pre-emptive constraint mechanism; 2. Compliance judgment relies on the core expense control database or manual rules, failing to meet millisecond-level response requirements; 3. The lack of a mandatory binding relationship between business documents and cash flow leads to low reconciliation efficiency and difficulties in expense collection. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide a real-time payment authorization method, device, equipment and medium for enterprise cash flow, which realizes the pre-mandatory binding of budget control and payment actions, and significantly improves the speed of compliance response and the efficiency of business and financial reconciliation.

[0006] In a first aspect, the present invention provides a real-time payment authorization method for enterprise cash flow. The method is applied to a payment risk control gateway, which integrates a shadow account engine. The shadow account engine is used to maintain a shadow account system isolated from external fund settlement accounts. The method includes: Receive the original payment request initiated by the user through the associated terminal, and generate an enhanced payment request by combining the business context information associated with the original payment request; Through the shadow account engine, a budget pre-freeze operation is performed on the target budget unit to which the enhanced payment request belongs; Generate compliance determination rules for matching enhanced payment requests, and use these rules to determine the compliance of enhanced payment requests. When the budget pre-freeze operation is successful and the compliance assessment is passed, payment authority is granted to the enhanced payment request to release the payment instruction corresponding to the enhanced payment request to the external fund settlement account.

[0007] In one implementation, performing a budget pre-freeze operation on the target budget unit to which the enhanced payment request belongs includes: The target budget unit to which the enhanced payment request belongs is determined based on the business document identifier contained in the enhanced payment request; Determine whether the remaining virtual budget of the target budget unit exceeds the transaction amount of the enhanced payment request; If so, then perform a budget pre-freeze operation on the remaining virtual budget of the target budget unit according to the transaction amount; If not, then terminate the budget pre-freeze operation.

[0008] In one implementation, generating compliance determination rules for enhanced payment request matching includes: Based on the enhanced payment request, a decision tree is compiled from the pre-configured enterprise expense control strategy to obtain the compliance determination rules for matching the enhanced payment request.

[0009] In one implementation, compliance determination of enhanced payment requests is performed using compliance determination rules, including: Iterate through all nodes included in the compliance judgment rule, and perform the following operations for each node: extract the parameters to be judged corresponding to the node from the enhanced payment request, substitute the parameters to be judged into the rule expression of the node, and obtain the judgment result output by the node for the parameters to be judged; Based on the judgment results output by each node, compliance judgment is performed on the enhanced payment request.

[0010] In one implementation, an enhanced payment request is generated by combining the business context information associated with the original payment request, including: Based on the business document identifier contained in the original payment request, collect the business context information corresponding to the original payment request. The business context information includes one or more of the following: address information, device fingerprint information, and consumption scenario tag information. An enhanced payment request is generated based on the original payment request and business context information.

[0011] In one implementation, performing a budget pre-freeze operation on the remaining virtual budget of the target budget unit to which the enhanced payment request belongs, further includes: When the original payment request is generated based on a virtual credit card, permission matching is performed on the enhanced payment request based on the usage permissions bound to the virtual credit card; If the permissions are successfully matched, perform a budget pre-freeze operation on the remaining virtual budget of the target budget unit to which the enhanced payment request belongs; If the permission matching fails, terminate the budget pre-freeze operation.

[0012] In one implementation, after releasing the payment instruction corresponding to the enhanced payment request to an external funds settlement account based on payment authority, the method further includes: Receive payment results from external fund settlement accounts; If the payment result is successful, perform a deduction operation on the remaining virtual budget of the target budget unit to which the enhanced payment request belongs, so as to obtain a new remaining virtual budget for the target budget unit; In the event of a payment failure, an unfreeze and rollback operation is performed on the remaining virtual budget of the target budget unit to which the enhanced payment request belongs, in order to restore the remaining virtual budget of the target budget unit.

[0013] Secondly, the present invention also provides a real-time payment authorization device for enterprise cash flow. The device is applied to a payment risk control gateway, which integrates a shadow account engine. The shadow account engine is used to maintain a shadow account system isolated from external fund settlement accounts. The device includes: The request enhancement module is used to receive the original payment request initiated by the user through the associated terminal, and generate an enhanced payment request by combining the business context information associated with the original payment request; The pre-freeze module is used to perform budget pre-freeze operations on the target budget unit to which it belongs in accordance with the enhanced payment request through the shadow account engine; The compliance determination module is used to generate compliance determination rules for matching enhanced payment requests, so as to use the compliance determination rules to determine the compliance of enhanced payment requests; The payment authorization module is used to grant payment permissions to enhanced payment requests when the budget pre-freeze operation is successful and the compliance judgment is passed, so as to release the payment instructions corresponding to the enhanced payment requests to external fund settlement accounts.

[0014] Thirdly, the present invention also provides an electronic device including a processor and a memory, the memory storing computer-executable instructions executable by the processor, the processor executing the computer-executable instructions to implement any of the methods provided in the first aspect.

[0015] Fourthly, the present invention also provides a computer-readable storage medium storing computer-executable instructions, which, when invoked and executed by a processor, cause the processor to implement any of the methods provided in the first aspect.

[0016] This invention provides a real-time payment authorization method, apparatus, device, and medium for enterprise cash flow, applied to a payment risk control gateway. The payment risk control gateway integrates a shadow account engine, which maintains a shadow account system isolated from external fund settlement accounts. First, it receives the original payment request initiated by the user through an associated terminal and generates an enhanced payment request based on the business context information associated with the original payment request. Then, through the shadow account engine, it performs a budget pre-freeze operation on the target budget unit to which the enhanced payment request belongs, and simultaneously generates compliance judgment rules matching the enhanced payment request to perform compliance judgment on the enhanced payment request. Finally, when the budget pre-freeze operation is successful and the compliance judgment is passed, payment authority is granted to the enhanced payment request to release the payment instruction corresponding to the enhanced payment request to the external fund settlement account. The above method integrates a shadow account engine into the payment risk control gateway to build a shadow account system that is logically isolated from external fund settlement accounts, enabling refined mapping and independent control of enterprise budget units. It generates enhanced payment requests based on business context and executes budget pre-freezing operations for target budget units accordingly, ensuring resource locking before expenditure. It simultaneously generates and executes matching compliance judgment rules to complete millisecond-level automated compliance verification. Payment permissions are granted only under the dual conditions of successful budget pre-freezing and compliance judgment. Thus, without relying on bank system modifications, it achieves pre-mandatory coupling of payment actions and budget control, real-time controllable budget usage, and automatic closed-loop compliance judgment, significantly improving the certainty, compliance, and traceability of fund expenditures.

[0017] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention are realized and obtained through the structures particularly pointed out in the description and the drawings.

[0018] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0019] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0020] Figure 1 A flowchart illustrating a real-time payment authorization method for enterprise cash flow provided in an embodiment of the present invention; Figure 2 A timing diagram of a real-time payment authorization method for enterprise cash flow provided in an embodiment of the present invention; Figure 3 A decision logic diagram of a real-time payment authorization method for enterprise cash flow provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of a real-time payment authorization device for enterprise cash flow provided in an embodiment of the present invention; Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0021] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0022] Currently, existing technologies have the following problems: (1) Delayed risk control: Traditional risk control relies on post-event audits or reimbursement reviews. Funds have already been actually withdrawn, resulting in high recovery costs and irreversible risks. (2) Coarse-grained limits: Bank cards only support daily / monthly total limit control and cannot implement dynamic and differentiated limits based on dimensions such as "business trip location", "project affiliation", and "merchant type". (3) Disconnect between budget and payment: Budget data in the financial ERP (Enterprise Resource Planning) cannot be synchronized in real time and applied to the bank deduction process, resulting in "ERP showing over budget, but bank card can still successfully deduct funds".

[0023] Based on this, the present invention provides a real-time payment authorization method, device, equipment and medium for enterprise cash flow, which realizes the pre-mandatory binding of budget control and payment actions, and significantly improves compliance response speed and business-finance reconciliation efficiency.

[0024] To facilitate understanding of this embodiment, a detailed description of a real-time payment authorization method for enterprise cash flow disclosed in this embodiment of the invention will be provided first. This method is applied to a payment risk control gateway, which integrates a shadow account engine. The shadow account engine is used to maintain a shadow account system isolated from external fund settlement accounts; see [link to previous document]. Figure 1 The diagram illustrates a real-time payment authorization method for enterprise cash flow, which mainly includes the following steps S102 to S108: Step S102: Receive the original payment request initiated by the user through the associated terminal, and generate an enhanced payment request by combining the business context information associated with the original payment request.

[0025] In one example, when a user initiates a payment through a mobile app, they submit an initial payment request in the form of an "order." The order explicitly carries a business document identifier field. The system captures business context information associated with this identifier field, including: the current travel application ID, GPS coordinates, device fingerprint, and consumption scenario tag. The initial payment request parameters and business context information are then encapsulated into an enhanced payment request. The device fingerprint is a unique identifier generated by fusing terminal hardware, system, and operating environment characteristics, while the consumption scenario tag is a semantic classification identifier determined in real-time based on geographic location, time, and merchant attributes.

[0026] Step S104: Through the shadow account engine, perform a budget pre-freeze operation on the target budget unit to which the enhanced payment request belongs.

[0027] In one example, to avoid delays in bank API calls, the system constructs a shadow account system on the payment risk control gateway side, logically isolated from the bank's main account. Before initiating a bank deduction, the remaining virtual budget of the corresponding department / project is atomically pre-frozen based on business context information; if the remaining virtual budget of the shadow account system is insufficient, the transaction is directly blocked at the gateway layer, without initiating any API calls to the bank.

[0028] Step S106: Generate compliance determination rules for matching enhanced payment requests, and use the compliance determination rules to determine the compliance of enhanced payment requests.

[0029] In one example, corporate expense control policies (such as "no spending during vacation", "no dining outside work area", and "maximum amount per transaction") are compiled into lightweight, executable compliance judgment rules for enhanced payment request matching, and deployed to the payment risk control gateway or edge nodes. Based on this, millisecond-level compliance judgments are performed on the business context information contained in the enhanced payment request.

[0030] Step S108: When the budget pre-freeze operation is successful and the compliance judgment is passed, grant payment authority to the enhanced payment request to release the payment instruction corresponding to the enhanced payment request to the external fund settlement account.

[0031] In one instance, once the shadow account completes the atomic pre-freezing of the target budget unit and all compliance judgment rules are passed, the payment risk control gateway generates a payment authorization token with a digital signature. This token embeds a unique identifier for the enhanced payment request, a freeze snapshot hash value, an authorization timestamp, and a validity period. The gateway then calls the standard bank-enterprise direct connection interface to encapsulate the token and the original payment instruction parameters into a payment message that conforms to the bank's required format. This message is then sent to the bank to which the external funds settlement account belongs via an encrypted channel, thus completing the release of the payment instruction.

[0032] The real-time payment authorization method for enterprise cash flow provided in this invention integrates a shadow account engine into the payment risk control gateway to construct a shadow account system that is logically isolated from external fund settlement accounts, thereby achieving refined mapping and independent control of enterprise budget units. It generates enhanced payment requests based on business context and executes budget pre-freezing operations for the target budget unit accordingly, ensuring resource locking before expenditure. It simultaneously generates and executes matching compliance judgment rules to complete millisecond-level automated compliance verification. Payment permissions are granted only under the dual conditions of successful budget pre-freezing and compliance judgment. This achieves pre-mandatory coupling of payment actions and budget control, real-time controllable budget usage, and automatic closed-loop compliance judgment without relying on bank system modifications, significantly improving the certainty, compliance, and traceability of fund expenditures.

[0033] For ease of understanding, embodiments of the present invention provide, as follows: Figure 2 The diagram illustrates a sequence diagram of a real-time payment authorization method for enterprise cash flow, involving users / payment terminals, payment risk control gateways, shadow accounts / budget engines, decentralized risk control rules, and banks / card organizations. Specifically: User / Payment Terminal: Initiates a payment request (amount, merchant, token) to the payment risk control gateway, along with device fingerprint and LBS information.

[0034] Payment Risk Control Gateway: After receiving the payment request from the user / payment terminal, it performs context enhancement (associating the application ID). Then it performs parallel verification: (1) it requests a budget pre-freeze from the shadow account / budget engine and receives the successful freeze (locked quota) information returned by the shadow account / budget engine. (2) it sends the information to the sinking risk control rules for real-time compliance judgment (MCC, time, location). If the verification fails, the transaction is rejected, the reason for the violation is returned to the user / payment terminal, and the shadow account / budget engine is triggered to unfreeze (Rollback); if the verification passes, a formal deduction instruction is sent to the bank / card organization. Afterwards, it receives the bank / card organization's successful deduction (Transaction Success) information, performs asynchronous updates, notifies the shadow account / budget engine to convert to actual deduction (Commit), and pushes the consumption voucher / electronic receipt to the user / payment terminal.

[0035] Shadow Account / Budget Engine: Receives a budget pre-freeze request from the payment risk control gateway, freezes the amount, and returns a successful freeze message. If it receives an unfreeze instruction triggered by the payment risk control gateway, it executes the unfreeze operation. If it receives an asynchronous update notification from the payment risk control gateway, it converts the pre-frozen amount into actual deductions.

[0036] Downward risk control rules: Receive information sent by the payment risk control gateway to make real-time compliance judgments (MCC, time, location), and return the judgment result (Allow or fail) to the payment risk control gateway after the judgment.

[0037] Banks / card organizations: Receive formal deduction instructions sent by the payment risk control gateway, execute the deduction operation, and return a transaction success message to the payment risk control gateway if the deduction is successful.

[0038] The embodiments of the present invention further provide, as follows: Figure 3The diagram illustrates the decision logic of a real-time payment authorization method for enterprise cash flow. When the payment risk control gateway receives a payment request, it first performs context parsing (Who / Where / What) to clarify information such as the payment-related entity, location, and content. Next, it determines whether the MCC merchant is compliant: if the merchant is on the blacklist, the transaction is directly intercepted and a risk control log is recorded, followed by a payment failure. If the merchant is on the whitelist or graylist, it further determines whether the LBS (Location Based Services) / time compliance is met. If the LBS / time is non-compliant (e.g., cross-regional payments or late-night payments), the transaction is intercepted, a risk control log is recorded, and a payment failure is returned. If the LBS / time is compliant, it then determines whether the shadow account balance is sufficient. If the shadow account balance is insufficient, the transaction is intercepted, a risk control log is recorded, and a payment failure is returned. If the shadow account balance is sufficient, a Pre-Freeze operation is performed to generate frozen transaction records, and then the bank interface is called. If the bank returns a failure, a Rollback operation is executed to release the credit limit and a payment failure message is returned; if the bank returns a success message, a Commit operation is executed to deduct the actual budget and a payment success message is returned.

[0039] exist Figure 2 , Figure 3 Based on this, this invention provides a specific implementation method for a real-time payment authorization method for enterprise cash flow. This method differs from traditional expense control systems that rely on delayed models such as "post-event reconciliation" or "employee advance payment." It is adaptable to various payment media, including physical bank cards, virtual cards (VCCs), and enterprise e-commerce platforms. Within a millisecond window after the payment instruction is issued, it completes budget allocation, compliance checks, and transaction authorization, achieving "blocking non-compliant payments and assuming compliance upon successful payment." Specifically, it includes: (a) Payment Intent Replenishment and Context Enhancement.

[0040] In one implementation, business context information corresponding to the original payment request is collected based on the business document identifier contained in the original payment request. The business context information includes one or more of address information, device fingerprint information, and consumption scenario tag information. An enhanced payment request is generated based on the original payment request and the business context information.

[0041] Specifically, the payment risk control gateway extracts business document identification fields (such as travel application ID and purchase order number) from the original payment request and simultaneously obtains the business context information corresponding to the business document identification fields. Among them, the address information is taken from the terminal's GPS positioning coordinates and timestamp, the device fingerprint information is taken from the pre-calculated and cached terminal unique identifier (a hash value generated based on hardware characteristics and operating environment), and the consumption scenario tag information is output in real time by the lightweight rule engine (matching the preset tag library according to address, time, merchant type and document status). The necessary fields of the original payment request (amount, payee, currency, channel type) are assembled with one or more of the above context information according to the standard JSON Schema, and a digital signature and request time stamp are added to generate a complete and tamper-proof enhanced payment request.

[0042] (ii) Local shadow accounts are frozen in real time.

[0043] Shadow accounts are the core carrier for achieving "bank-level" refined fund management on the enterprise side in this embodiment of the invention. They adopt a strictly separated, two-way verification two-layer account structure: L1 Real Fund Account: Mapped one-to-one with the physical settlement account opened by the bank, carrying the actual fund balance, and serving as the sole basis for final external settlement and determination of rights and responsibilities; L2 Virtual Budget Account: Established by dividing according to the enterprise organizational dimension (department / project / employee), storing only the credit limit, allocated budget and frozen / occupied status, without involving actual fund transfers, and is a purely logical management unit.

[0044] The synchronization strategy implements a dual-track mechanism of "T+0 real-time mapping and T+0 end-of-day strong consistency verification": each L2 pre-freezing, unfreezing or actual deduction operation triggers the L1 expected balance calculation in real time (based on the budget execution progress model) and generates a snapshot to be verified; at the end of each day, the system automatically downloads the bank's L1 statement through direct bank-enterprise connection, compares the cumulative L2 execution result with the actual L1 amount, automatically issues warnings for deviations and supports manual intervention correction.

[0045] Furthermore, all L2 budget state changes are executed via Check-and-Set (CAS) operations using Redis atomic Lua scripts, which strictly verify the version number and available balance to ensure zero overspending and strong consistency in budget deductions and state updates under scenarios with tens of thousands of concurrent payments (such as centralized travel ticket bookings), effectively implementing overdraft protection.

[0046] Based on the aforementioned shadow account system, this embodiment of the invention provides a specific implementation method for real-time freezing of local shadow accounts. It can determine the target budget unit to which the enhanced payment request belongs based on the business document identifier contained in the enhanced payment request; determine whether the remaining virtual budget of the target budget unit exceeds the transaction amount of the enhanced payment request; if so, perform a budget pre-freeze operation on the remaining virtual budget of the target budget unit according to the transaction amount; if not, terminate the budget pre-freeze operation.

[0047] Specifically, the shadow account engine parses the business document identifier field in the enhanced payment request, locates the corresponding target budget unit level by level through a pre-defined mapping relationship table (such as travel application ID-project number-cost center-budget subject), and reads the current remaining virtual budget balance of the unit from the shadow account engine; it calls the atomic deduction interface of the shadow account engine to verify whether the balance is greater than or equal to the transaction amount using an optimistic locking mechanism; if the verification passes, an indivisible pre-freeze operation is performed, locking the amount from the available balance and generating a unique freeze snapshot (including freeze ID, timestamp, and associated request ID); if the verification fails, an insufficient balance error code is returned, no status change is generated, and the subsequent process is terminated.

[0048] Based on the aforementioned shadow account system, this embodiment of the invention provides another specific implementation method for real-time freezing of local shadow accounts. When the original payment request is generated based on a virtual credit card, permission matching is performed on the enhanced payment request based on the usage permissions bound to the virtual credit card. If the permission matching is successful, a budget pre-freeze operation is performed on the remaining virtual budget of the target budget unit to which the enhanced payment request belongs. If the permission matching fails, the budget pre-freeze operation is terminated.

[0049] Specifically, when the original payment request originates from a Virtual Credit Card (VCC), the payment risk control gateway parses its card number or token identifier and queries the VCC management module in real time to obtain the usage permission metadata bound to the card, including the Merchant Category Code (MCC), single / daily cumulative limit, valid time window, geographical location whitelist, and consumption scenario label. The actual transaction elements in the enhanced payment request (merchant MCC, transaction amount, GPS coordinates, occurrence time, and consumption scenario label) are compared item by item with the above permission metadata: if all match (e.g., MCC within the allowed range, amount ≤ remaining limit, time within the validity period, GPS in the whitelist area, and scenario label consistent), the permission is considered to have passed; otherwise, it is considered to have failed. Only if the permission is successfully matched is the budget pre-freeze operation of the target budget unit executed; if any permission verification fails, the process is immediately terminated without triggering any budget freeze, and the corresponding rejection code (e.g., "MCC mismatch" or "limit exceeded") is returned.

[0050] The embodiments of the present invention further improve the above-mentioned shadow account system. The shadow account system is a multi-branch tree structure. The root node of the multi-branch tree structure is the "enterprise total budget pool". Each non-root node has a unique parent node identifier and can serve as the parent node of multiple child nodes. In the multi-branch tree structure, each node corresponds to a budget slice unit, which includes department-level budget slices, project-level budget slices and employee-level budget slices.

[0051] Based on this, the pre-freezing operation includes: (1) The shadow account engine traverses the multi-branch tree structure level by level from the budget slice unit associated with the enhanced payment request, based on the parent node identifier of the budget slice unit. It queries the allocated amount, currently frozen amount, and inherited amount of each parent budget slice unit, and uses the formula "Amount available for inheritance = Amount allocated". Current frozen amount "Inherited quota" calculates the quota value that the parent unit can currently use for inheritance by the lower unit; (2) Add up the current inheritable quotas of all superior budget slice units to obtain the total inheritable quota for the entire inheritance path; (3) When the total inheritable amount is greater than or equal to the transaction amount of the enhanced payment request, perform a multi-node atomic freeze operation: increase the current frozen amount of the budget slice unit associated with the enhanced payment request by the transaction amount; increase the inherited amount of each parent budget slice unit that the budget slice unit passes through in the traversal path by the transaction amount; generate a budget inheritance occupancy record under the budget slice unit associated with the enhanced payment request, the record including: the inheritance source node identifier, the inherited occupancy amount, and the budget period deadline.

[0052] (III) Risk control rules are implemented at the grassroots level and dynamic decision-making is carried out.

[0053] In one implementation, the enterprise expense control strategy can be directly compiled into a lightweight rule set and deployed to the payment risk control gateway to perform second-level compliance determination on enhanced payment requests. To ensure that the end-to-end latency of the critical payment path is strictly controlled within 200 milliseconds, this embodiment of the invention moves all risk control decisions to the payment gateway side for execution.

[0054] Strategy compilation: The reimbursement rules described in natural language in the enterprise expense control policy (such as "employees are prohibited from making consumption during their leave" and "a single transaction exceeding 5,000 yuan requires secondary approval") are automatically converted into structured, verifiable multi-level decision trees or Drools rule files through the rule parsing engine, supporting version management and hot reloading. Edge deployment: High-frequency blocking rules (such as merchant category code MCC blacklist, payment ban for vacation status, and restrictions on large transactions outside the work location) are preloaded into the local memory of the payment gateway. When executed, there is no need to call the backend core database or remote services, achieving millisecond-level response. Dynamic MCC Mapping: To address the issue of inaccurate or missing MCC codes reported by some acquiring institutions, the system has a built-in lightweight merchant knowledge base. Combining LBS location information, historical transaction patterns, and semantic recognition of merchant names, it calibrates and corrects MCC codes in real time (for example, mapping the vague merchant name "XXX Industrial Co., Ltd." to the accurate industry category "Catering Services"), thus blocking behaviors that bypass risk control based on MCC codes from the source.

[0055] In another implementation, compliance rules for matching enhanced payment requests can be dynamically generated, and these rules can be used to perform compliance checks on enhanced payment requests within seconds. Specifically, this includes: (1) Based on the enhanced payment request, the pre-configured enterprise expense control strategy is compiled into a decision tree to obtain the compliance judgment rules for matching the enhanced payment request.

[0056] In one optional implementation, based on the consumption scenario tag and geographic location tag included in the enhanced payment request, the root node type of the decision tree is determined. A preset topology template corresponding to the root node type is loaded. The preset topology template defines the number of nodes, node names, and parent-child connection relationships between nodes in the multi-layer structured decision tree. Business behavior features corresponding to the enhanced payment request are extracted, and a subset of policy rules matching the business behavior features is extracted from the pre-configured enterprise expense control strategy. This subset of policy rules is injected into the judgment condition statements of each node in the preset topology template to obtain rule expressions, thereby generating a multi-layer structured decision tree. Specifically: First, the consumption scenario tag and geolocation tag carried in the enhanced payment request are analyzed, and the root node type of the decision tree to which this request belongs is determined according to the preset mapping relationship table. The mapping relationship table records the root node type identifiers corresponding to the combinations of various consumption scenario tags (such as "domestic business travel and dining", "overseas airport shopping", "online SaaS service procurement") and geolocation tags (such as "GPS coordinates are located in Chaoyang District, Beijing" and "IP location is Singapore"). After determining the root node type, load the preset topology template associated with that type identifier; the preset topology template is stored in JSON format, explicitly declaring the number of levels of the decision tree, the number of nodes at each level, the unique name of each node and its parent-child connection relationship, without containing any business logic or judgment conditions; Next, extract the business behavior features corresponding to the enhanced payment request, including but not limited to transaction amount, time of occurrence, merchant category code, budget unit affiliation, approval status, device fingerprint type, and consumption frequency features; Subsequently, all enabled policy rules are retrieved from the enterprise expense control policy library, and policy rules whose applicable condition fields have semantic matching relationships with the extracted business behavior features are selected to form a policy rule subset; the matching is based on field name consistency and data type compatibility judgment, for example, the "single transaction amount limit" policy matches the transaction amount field in the request, and the "disable in non-working location" policy matches the geolocation tag field; Finally, the system injects each rule in the policy rule subset into the corresponding node's judgment condition placeholder according to its applicable priority and the order of each node in the preset topology template, generating a structured and executable rule expression. The judgment condition of each node is a standardized template, which forms a complete multi-layer structured decision tree after injection, for subsequent compliance judgment calls.

[0057] (2) Traverse all nodes included in the compliance judgment rule and perform the following operations on each node: extract the parameters to be judged corresponding to the node from the enhanced payment request, substitute the parameters to be judged into the rule expression of the node, and obtain the judgment result output by the node for the parameters to be judged.

[0058] Specifically, the system visits each node in the multi-layered structured decision tree composed of compliance judgment rules in a preset traversal order (starting from the root node, proceeding layer by layer with breadth-first or depth-first search). For the currently visited node, the system parses the parameter reference fields declared in its bound rule expression and extracts the parameter value to be judged from the structured payload of the enhanced payment request. The parameter value is then substituted into the rule expression and evaluated by the Aviator expression engine to obtain a Boolean judgment result (true or false). This result is the local judgment conclusion output by the node for this request.

[0059] (3) Based on the judgment results output by each node, perform compliance judgment on the enhanced payment request.

[0060] Specifically, the judgment results output by all nodes are collected, and the final compliance judgment is performed according to the topology of the decision tree and the preset logical aggregation method of each node: if any mandatory node (marked as "AND path key node") outputs false, the overall judgment is non-compliant; if all leaf nodes output true, or the preset majority voting threshold is met (such as "at least 80% of non-empty leaf nodes are true"), and no veto node is triggered, the overall judgment is compliant.

[0061] (iv) Payment instruction injection and execution.

[0062] In practice, formal payment instructions are only sent to banks, bank card organizations, or third-party payment channels under the dual premise that the shadow account is successfully pre-frozen and the overall compliance judgment is passed. At the same time, the business document number is embedded in the summary field (Remark) of the bank message or the reserved field agreed upon in the agreement to achieve precise anchoring of business flow and fund flow, and to provide structured data entry support for automated reconciliation and fee collection.

[0063] (v) Transaction status synchronization and actual deduction.

[0064] Receive payment results from external fund settlement accounts; if the payment result is successful, perform a deduction operation on the remaining virtual budget of the target budget unit to which the enhanced payment request belongs, so as to obtain a new remaining virtual budget for the target budget unit; if the payment result fails, perform an unfreeze and rollback operation on the remaining virtual budget of the target budget unit to which the enhanced payment request belongs, so as to restore the remaining virtual budget of the target budget unit.

[0065] In practical applications, the system monitors the final deduction result notification returned by the bank. If the deduction is successful, the pre-freeze status of the transaction in the corresponding shadow account is updated to "Committed," and the available amount in the company's real budget ledger is deducted simultaneously. If the deduction fails (including any unsuccessful status such as insufficient bank balance, transaction timeout, or rejection code return), an atomic unfreeze rollback is immediately executed within the shadow account engine to fully release the original pre-freeze amount, ensuring that the virtual budget status is strictly consistent with the actual fund status.

[0066] (vi) Instant push of consumption vouchers.

[0067] In practical applications, the bank's payment success signal serves as a deterministic trigger event, instantly pushing structured electronic receipts to the user's terminal and automatically initiating associated invoice collection tasks (including pre-filled information such as invoice header, tax number, and amount). Simultaneously, a fee record with a status of "paid, awaiting receipt" is generated, binding the original business document, payment voucher number, and invoice collection ID, thus achieving closed-loop management across the entire chain from business application, budget control, fund payment to invoice collection.

[0068] This invention also provides a system architecture corresponding to the above method, used to support the reliable execution of the entire real-time payment authorization process. The system includes: (1) a payment gateway layer: a high-performance asynchronous I / O gateway built on Netty or Vert.x, supporting millisecond-level protocol conversion (ISO8583). (1) JSON) and management of tens of thousands of concurrent long connections; (2) Rule calculation layer: integrate Flink CEP (complex event processing) to realize real-time detection of streaming risk control events, and combine Aviator lightweight expression engine to complete context-aware dynamic rule matching; (3) Data storage layer: Shadow account status: use Redis Cluster storage, enable AOF (Append-Only File) persistence to ensure consistency; Transaction flow: implement database sharding and table sharding based on ShardingSphere, and MySQL is sharded according to natural month time; Risk control log: written to Elasticsearch to support real-time retrieval and multi-dimensional audit analysis; Security mechanism: full-link communication uses national cryptographic SM2 / SM4 encryption; sensitive fields such as card number and CVV (Card Verification Value) are uniformly tokenized before being written to disk, and the original information does not leave the domain.

[0069] In summary, the core technical points of the embodiments of the present invention include: (1) Shadow account pre-freezing mechanism: On the payment risk control gateway side, a virtual budget account system is logically isolated from the bank's physical account. By simulating bank-level deduction semantics locally (including quota verification, atomic freezing, and status rollback), millisecond-level and strongly consistent real-time occupancy control of department, project and employee-level budget units can be achieved without relying on the bank's real-time interface response.

[0070] (2) Payment context enhancement technology: At the gateway layer, the original payment request is dynamically bound to the associated business documents (such as travel application form, purchase order, expense reimbursement form) in real time. The structured context information (including budget subject, cost center, geographical location, equipment fingerprint, consumption scenario label, etc.) is automatically completed through the unique business document identifier to form an enhanced payment request with complete business semantics, providing a calculable basis for pre-risk control.

[0071] (3) Edge-side dynamic MCC correction mechanism: A lightweight merchant knowledge base is deployed in the payment gateway memory. Combining LBS location information, historical transaction patterns, merchant name semantic recognition and industry classification rules, the fuzzy or incorrect MCC codes reported by the acquiring institution are mapped and corrected in milliseconds when a transaction occurs (such as accurately classifying "XX Industry" as "Catering Services"). MCC white / black list matching is performed simultaneously to effectively prevent MCC bypass risks.

[0072] (4) Virtual Card Dynamic Lifecycle Management: Using business documents as the trigger source, the virtual credit card (VCC) lifecycle is automatically controlled: the card issuance and credit limit injection are triggered when the document is approved. When a transaction occurs, precise authorization is implemented according to preset rules (merchant category, amount threshold, geofence, time limit constraint). After the transaction is completed or expires, the remaining credit limit is automatically recovered and the card is cancelled.

[0073] Based on the above-mentioned core technical points, the technical effects that can be achieved by the embodiments of the present invention include: (1) Strong budget control: Relying on shadow account technology, the budget control point is rigidly moved forward to the gateway layer before payment is initiated, so as to realize real-time quota verification and atomic pre-freezing of each expenditure, thereby eliminating "payment without budget" and "deduction of over budget" from the mechanism, and achieving true hard budget control.

[0074] (2) Extreme risk control: For typical violation scenarios such as misuse of public funds, consumption outside of working hours, and cashing out of high-risk merchants, based on the multi-dimensional context contained in the enhanced payment request (such as GPS positioning, device fingerprint, consumption scenario label, MCC code and vacation status), rule matching and dynamic interception are completed within milliseconds, blocking compliance risks before funds flow out.

[0075] (3) No reimbursement experience: All payments are executed after budget locking, permission verification, and compliance judgment under the business document. The transaction itself has complete business authenticity and compliance certificate. Employees do not need to submit invoices, explain the purpose or go through the reimbursement process repeatedly, which significantly reduces the operational burden and improves the terminal experience and organizational operational efficiency.

[0076] (4) Open and compatible architecture: The embodiments of the present invention are deployed between the enterprise-side payment risk control gateway and the expense control application layer, without intruding into the bank's core system, nor relying on the underlying interface open capabilities of a specific bank; through standardized protocol adaptation, it can quickly connect to multiple commercial banks, bank card organizations and mainstream third-party payment platforms, and has good SaaS delivery and large-scale replication capabilities.

[0077] Based on the foregoing embodiments, this invention provides a real-time payment authorization device for enterprise cash flow. This device is applied to a payment risk control gateway, which integrates a shadow account engine. The shadow account engine is used to maintain a shadow account system isolated from external fund settlement accounts. (See [link to relevant documentation]). Figure 4 The diagram shows a real-time payment authorization device for enterprise cash flow. The device mainly includes the following parts: The request enhancement module 402 is used to receive the original payment request initiated by the user through the associated terminal, and generate an enhanced payment request by combining the business context information associated with the original payment request; The pre-freeze module 404 is used to perform a budget pre-freeze operation on the target budget unit to which it belongs in accordance with the enhanced payment request through the shadow account engine; The compliance determination module 406 is used to generate compliance determination rules for matching enhanced payment requests, so as to use the compliance determination rules to determine the compliance of enhanced payment requests; The payment authorization module 408 is used to grant payment permissions to the enhanced payment request when the budget pre-freeze operation is successful and the compliance judgment is passed, so as to release the payment instruction corresponding to the enhanced payment request to the external fund settlement account.

[0078] The real-time payment authorization device for enterprise cash flow provided in this invention integrates a shadow account engine into the payment risk control gateway to construct a shadow account system that is logically isolated from external fund settlement accounts, thereby achieving refined mapping and independent control of enterprise budget units. It generates enhanced payment requests based on business context and executes budget pre-freezing operations for the target budget unit accordingly, ensuring resource locking before expenditure. It simultaneously generates and executes matching compliance judgment rules to complete millisecond-level automated compliance verification. Payment permissions are granted only under the dual conditions of successful budget pre-freezing and compliance judgment. This achieves pre-mandatory coupling of payment actions and budget control, real-time controllable budget usage, and automatic closed-loop compliance judgment without relying on bank system modifications, significantly improving the certainty, compliance, and traceability of fund expenditures.

[0079] The device provided in this embodiment of the invention has the same implementation principle and technical effect as the aforementioned method embodiment. For the sake of brevity, any parts not mentioned in the device embodiment can be referred to the corresponding content in the aforementioned method embodiment.

[0080] This invention provides an electronic device, specifically, the electronic device includes a processor and a memory; the memory stores a computer program, which, when run by the processor, executes the method described in any of the above embodiments.

[0081] Figure 5 The present invention provides a schematic diagram of the structure of an electronic device 100, which includes a processor 50, a memory 51, a bus 52 and a communication interface 53. The processor 50, the communication interface 53 and the memory 51 are connected through the bus 52. The processor 50 is used to execute executable modules, such as computer programs, stored in the memory 51.

[0082] The memory 51 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 53 (which can be wired or wireless), such as the Internet, wide area network, local area network, metropolitan area network, etc.

[0083] Bus 52 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 5 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0084] The memory 51 is used to store programs. After receiving an execution instruction, the processor 50 executes the programs. The method executed by the device for defining the flow process disclosed in any of the foregoing embodiments of the present invention can be applied to the processor 50 or implemented by the processor 50.

[0085] Processor 50 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of processor 50 or by instructions in software form. Processor 50 can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this invention can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 51. The processor 50 reads the information in memory 51 and, in conjunction with its hardware, completes the steps of the above method.

[0086] The computer program product of the readable storage medium provided in the embodiments of the present invention includes a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the methods described in the foregoing method embodiments. For specific implementation, please refer to the foregoing method embodiments, which will not be repeated here.

[0087] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0088] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit it. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A real-time payment authorization method for enterprise cash flow, characterized in that, The method is applied to a payment risk control gateway, which integrates a shadow account engine. This shadow account engine is used to maintain a shadow account system isolated from external fund settlement accounts. The method includes: Receive the original payment request initiated by the user through the associated terminal, and generate an enhanced payment request by combining the business context information associated with the original payment request; The shadow account engine performs a budget pre-freeze operation on the target budget unit to which the enhanced payment request belongs, in accordance with the enhanced payment request. Generate compliance determination rules for matching the enhanced payment request, and use the compliance determination rules to determine the compliance of the enhanced payment request; When the budget pre-freeze operation is successful and the compliance determination is passed, payment authority is granted to the enhanced payment request to release the payment instruction corresponding to the enhanced payment request to the external fund settlement account.

2. The real-time payment authorization method for enterprise cash flow according to claim 1, characterized in that, Perform a budget pre-freeze operation on the target budget unit to which the enhanced payment request belongs, including: The target budget unit to which the enhanced payment request belongs is determined based on the business document identifier contained in the enhanced payment request; Determine whether the remaining virtual budget of the target budget unit exceeds the transaction amount of the enhanced payment request; If so, then perform a budget pre-freeze operation on the remaining virtual budget of the target budget unit according to the transaction amount; If not, then terminate the budget pre-freeze operation.

3. The real-time payment authorization method for enterprise cash flow according to claim 1, characterized in that, Generate compliance determination rules for matching the enhanced payment request, including: Based on the enhanced payment request, a decision tree is compiled from the pre-configured enterprise expense control strategy to obtain the compliance determination rules that match the enhanced payment request.

4. The real-time payment authorization method for enterprise cash flow according to claim 3, characterized in that, The compliance determination of the enhanced payment request is performed using the aforementioned compliance determination rules, including: Traverse all nodes included in the compliance determination rule, and perform the following operations for each node: extract the parameters to be determined corresponding to the node from the enhanced payment request, substitute the parameters to be determined into the rule expression of the node, and obtain the determination result output by the node for the parameters to be determined; Based on the determination results output by each node, the enhanced payment request is subject to compliance determination.

5. The real-time payment authorization method for enterprise cash flow according to claim 1, characterized in that, An enhanced payment request is generated by combining the business context information associated with the original payment request, including: Based on the business document identifier contained in the original payment request, collect the business context information corresponding to the original payment request. The business context information includes one or more of address information, device fingerprint information, and consumption scenario tag information. An enhanced payment request is generated based on the original payment request and the business context information.

6. The real-time payment authorization method for enterprise cash flow according to claim 1, characterized in that, Performing a budget pre-freeze operation on the remaining virtual budget of the target budget unit to which the enhanced payment request belongs, in accordance with the enhanced payment request, further includes: If the original payment request is generated based on a virtual credit card, permission matching is performed on the enhanced payment request based on the usage permissions bound to the virtual credit card; If the permission matching is successful, a budget pre-freeze operation is performed on the remaining virtual budget of the target budget unit to which the enhanced payment request belongs; If the permission matching fails, the budget pre-freeze operation will be terminated.

7. The real-time payment authorization method for enterprise cash flow according to claim 1, characterized in that, After releasing the payment instruction corresponding to the enhanced payment request to the external funds settlement account based on the payment authority, the method further includes: Receive payment results from the external fund settlement account; If the payment result is successful, a deduction operation is performed on the remaining virtual budget of the target budget unit to which the enhanced payment request belongs, so as to obtain the new remaining virtual budget of the target budget unit; If the payment result fails, an unfreeze and rollback operation is performed on the remaining virtual budget of the target budget unit to which the enhanced payment request belongs, so as to restore the remaining virtual budget of the target budget unit.

8. A real-time payment authorization device for enterprise cash flow, characterized in that, The device is applied to a payment risk control gateway, which integrates a shadow account engine. The shadow account engine is used to maintain a shadow account system isolated from external fund settlement accounts. The device includes: The request enhancement module is used to receive the original payment request initiated by the user through the associated terminal, and generate an enhanced payment request by combining the business context information associated with the original payment request; The pre-freeze module is used to perform a budget pre-freeze operation on the target budget unit to which it belongs, according to the enhanced payment request, through the shadow account engine; The compliance determination module is used to generate compliance determination rules for matching the enhanced payment request, so as to use the compliance determination rules to determine the compliance of the enhanced payment request; The payment authorization module is used to grant payment permissions to the enhanced payment request when the budget pre-freeze operation is successful and the compliance determination is passed, so as to release the payment instruction corresponding to the enhanced payment request to the external fund settlement account.

9. An electronic device, characterized in that, The method includes a processor and a memory, the memory storing computer-executable instructions executable by the processor, the processor executing the computer-executable instructions to implement the method of any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions that, when invoked and executed by a processor, cause the processor to perform the method according to any one of claims 1 to 7.