Secure Cash Withdrawal System and Method for Bank ATMs Based on Palm Vein Recognition

CN122575002APending Publication Date: 2026-08-14浙江微特电子信息有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-22
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0002]传统银行自助柜员机主要依赖银行卡与密码的组合方式进行身份认证,用户需插入银行卡并输入密码后方可执行取款操作;此方式存在多项安全隐患,包括密码在输入过程中易被旁观者窥视或通过非法加装的侧录设备截获,银行卡存在丢失、被盗及被复制的风险,导致盗刷与冒用事件频发;近年来,部分金融机构开始探索将生物特征识别技术引入自助柜员机的身份认证环节,其中指纹识别是应用较为广泛的方案,但指纹特征易在接触面上残留且存在通过硅胶膜等材料伪造的风险;掌静脉识别技术因其采集的是人体皮下静脉血管的纹路分布,具有非接触、难伪造、活体依赖等优势,逐步受到关注;然而,现有引入掌静脉识别的自助柜员机方案大多将其作为替代密码或指纹的单一模态认证手段,仅在取款流程的初始身份验证环节使用一次,验证通过后即全权授予交易权限,缺乏与后续交易操作过程的深度集成

Benefits of technology

通过在银行自助柜员机中引入掌静脉识别技术实现无卡化身份认证,利用近红外成像采集用户皮下静脉血管纹路并与预构建的注册模板库进行匹配,有效规避了传统银行卡与密码组合方式中存在的密码窥视、银行卡丢失盗刷及指纹伪造等安全隐患,同时通过注册一致性分值对模板质量进行量化评估并据此对匹配结果执行质量加权修正,降低了因注册采集质量差异导致的误匹配风险;在身份认证通过后,并非直接授予完整交易权限,而是进一步采集用户在取款操作过程中的多维度交易行为数据,包括取款金额选择、操作耗时、按键输入节奏、输入修正行为与余额查询习惯,形成结构化的交易行为特征向量,并与基于用户历史取款记录提取的交易行为基线向量进行逐项偏离度分析,有效弥补了身份验证通过后缺乏对交易操作过程持续校验的安全缺口,能够识别身份验证通过但操作行为异于用户本人习惯的异常情形;在偏离度分析中,通过有向偏离度修正机制根据不同行为维度的偏离方向对安全风险的差异化指示意义进行方向敏感性调整,通过维度间偏离共现模式检测识别多维度协同偏离所指示的特定安全威胁场景,有效克服了传统行为异常检测中各维度独立评判或等权汇总而无法捕获组合式风险特征的不足;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122575002A_ABST
    Figure CN122575002A_ABST
Patent Text Reader

Abstract

This invention belongs to the field of financial security technology and discloses a secure withdrawal system and method for bank ATMs based on palm vein recognition. The system includes: collecting the user's palm vein pattern features when the user initiates a withdrawal request, matching them with a pre-built registered palm vein template library, determining the user's identity and associating it with the corresponding bank account based on the matching results, and simultaneously evaluating the identity matching score; collecting the user's current transaction behavior feature vector and transaction behavior baseline vector, and obtaining a behavior deviation score through item-by-item deviation analysis; cross-validating the behavior deviation score and the identity matching score, generating a transaction authorization decision based on the cross-validation results, and executing transaction feedback processing based on the transaction authorization decision. This invention constructs a complete closed-loop secure withdrawal system, comprehensively improving the security protection capabilities of bank ATM withdrawal transactions while ensuring user convenience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of financial security technology, and more specifically, to a secure withdrawal system and method for bank ATMs based on palm vein recognition. Background Technology

[0002] Traditional bank ATMs primarily rely on a combination of bank card and PIN for authentication. Users must insert their bank card and enter their PIN before withdrawing cash. This method presents several security risks, including the vulnerability of PINs to being observed by onlookers or intercepted by illegally installed skimming devices during input, and the risk of lost, stolen, or copied bank cards, leading to frequent cases of fraudulent transactions and misuse. In recent years, some financial institutions have begun exploring the integration of biometric identification technology into the authentication process of ATMs. Fingerprint recognition is a widely used solution, but fingerprint features are easily left on contact surfaces and are susceptible to forgery using materials such as silicone films. Palm vein recognition technology, which collects the distribution of subcutaneous vein patterns, offers advantages such as being non-contact, difficult to forge, and dependent on liveness detection, and is gradually gaining attention. However, most existing ATM solutions incorporating palm vein recognition treat it as a single-modal authentication method, replacing PINs or fingerprints, using it only once in the initial identity verification stage of the withdrawal process. Once verification is successful, full transaction privileges are granted, lacking deep integration with subsequent transaction operations.

[0003] Furthermore, existing ATM solutions based on palm vein recognition do not continuously verify the user's behavioral characteristics during the transaction process after identity verification is successful. This makes it impossible to identify abnormal situations where identity verification is successful but the transaction behavior deviates from the user's usual habits. In real-world scenarios, even if palm vein verification is successful, the operator may still be in an involuntary state, and their behavior will often deviate from their normal habits, such as withdrawing amounts far exceeding daily limits, operating at an unusually rapid pace, or hesitating. However, existing systems lack the ability to collect, model, and analyze the deviation of such behavioral characteristics, failing to provide secondary security verification during the transaction phase. Simultaneously, existing systems lack a linkage mechanism between identity authentication results and transaction risk control decisions, failing to cross-analyze the confidence level of identity matching and the degree of deviation in transaction behavior to achieve differentiated authorization decisions. Therefore, there is an urgent need for a secure ATM withdrawal system that can deeply integrate palm vein identity authentication with transaction behavior feature verification and achieve differentiated transaction authorization through two-factor cross-validation.

[0004] In view of this, the present invention proposes a secure withdrawal system and method for bank ATMs based on palm vein recognition to solve the above problems. Summary of the Invention

[0005] To overcome the aforementioned deficiencies of the prior art and achieve the above objectives, the present invention provides the following technical solution: a secure cash withdrawal method for bank ATMs based on palm vein recognition, comprising: When a user initiates a withdrawal request, the palm vein pattern features of the user are collected, and the palm vein pattern features are matched with a pre-built registered palm vein template library. Based on the matching results, the user's identity is determined and associated with the corresponding bank account, while the identity matching score is evaluated. After a user enters the withdrawal operation interface, the user's transaction operation behavior data is collected, including the withdrawal amount input value, the duration of stay on the operation interface, the key input rhythm interval sequence and whether the balance is checked, to form a feature vector of the current transaction behavior. Obtain the historical withdrawal records corresponding to the bank accounts associated with the user's identity, and extract the corresponding user's transaction behavior baseline vector from the historical withdrawal records; Based on the current transaction behavior feature vector and the transaction behavior baseline vector, the behavior deviation score is obtained through item-by-item deviation analysis. The behavior deviation score is then cross-validated with the identity matching score, and a transaction authorization decision is generated based on the cross-validation results. Transaction feedback processing is executed based on the transaction authorization decision. Transaction feedback processing includes baseline incremental correction and abnormal transaction risk control processing.

[0006] Furthermore, methods for pre-constructing a registered palm vein template library include: Obtain the unique user code and bound bank card number of each registered user who has activated the palm vein withdrawal service; obtain the palm vein registration image set collected by each registered user during the registration phase, which contains multiple palm vein near-infrared images; preprocess each palm vein near-infrared image in each palm vein registration image set sequentially to obtain a standardized palm vein image; extract texture features from each standardized palm vein image to obtain a texture feature vector. For each registered user, a registration consistency score is calculated based on the corresponding palm vein registration image set, and the quality of the corresponding palm vein registration image set is determined. The element-wise mean of all texture feature vectors in the qualified palm vein registration image set is calculated to obtain the registration template vector. The registration template vector is normalized to obtain the standard template vector. The standard template vector, user unique code, bound bank card number and registration consistency score of each registered user are integrated to form the palm vein registration template of each registered user, and a registration palm vein template library is constructed by summarizing them.

[0007] Furthermore, methods for identifying users and linking them to corresponding bank accounts include: When a user initiates a withdrawal request at a bank ATM, a near-infrared image of the palm vein is captured. Image quality is checked on the near-infrared image, and preprocessing is performed on the qualified images to obtain a standardized palm vein image. This standardized image is then input into a pre-trained palm vein feature extraction network to obtain a texture feature vector. Finally, the texture feature vector is normalized to obtain the palm vein texture features. The original matching similarity between the palm vein pattern features and the standard template vector of each palm vein registration template is calculated. The template quality is then weighted and corrected based on the registration consistency score. The corrected matching similarity is used to determine whether the identity authentication is successful. If the identity authentication is successful, the palm vein registration template with the highest corrected matching similarity is taken as the best matching template. The corresponding user unique code and the bound bank card number are extracted to confirm the user's identity and associate it with the bank account.

[0008] Furthermore, methods for forming the feature vector of a given transaction include: When a user enters the withdrawal operation interface, the transaction behavior recording engine is automatically started to generate the corresponding operation event record. The operation event record includes the operation event type, the operation occurrence timestamp, and additional event data. According to the time sequence of the operation occurrence timestamps corresponding to each operation event record, all operation event records generated by the user in the current withdrawal operation are stored in sequence to form the operation event sequence of the current transaction, and the integrity of the operation event sequence is checked. Based on the sequence of operation events that have passed integrity verification, the withdrawal amount input value, the duration of the operation interface, the key input rhythm interval sequence, and the balance query mark are extracted, and the number of input corrections is calculated. Based on the key input rhythm interval sequence, the average key interval duration and key rhythm fluctuation are extracted. The balance query mark is converted into a numerical form. The withdrawal amount input value, the duration of the operation interface, the average key interval duration, the key rhythm fluctuation, the number of input corrections, and the balance query mark value are arranged in order to form the feature vector of the current transaction behavior.

[0009] Furthermore, methods for extracting the baseline vector of transaction behavior include: Based on the linked bank card number used when linking the bank account, retrieve all historical withdrawal records associated with the corresponding linked bank card number to form a historical withdrawal record set; perform timeliness filtering and abnormal record removal on the historical withdrawal record set in sequence to obtain a valid historical record set, and perform a record sufficiency determination on the valid historical record set; if the record sufficiency determination fails, obtain the baseline reference vector and baseline discrete vector of the corresponding user from the preset default behavior baseline configuration; If the record sufficiency determination is passed, a corresponding baseline weight is sequentially assigned to each historical withdrawal record in the valid historical record set. Based on the baseline weight and all historical withdrawal records in the valid historical record set, the baseline reference value and baseline discrete value corresponding to each feature dimension in the feature vector of the current transaction behavior are calculated, and a baseline reference vector and a baseline discrete vector are formed. The baseline reference vector and the baseline discrete vector are then integrated to form the transaction behavior baseline vector.

[0010] Furthermore, methods for obtaining behavioral deviation scores through item-by-item deviation analysis include: For each feature dimension in the current transaction behavior feature vector and the transaction behavior baseline vector, perform a dimension-wise standardized deviation calculation to obtain the standardized deviation of each feature dimension; perform a directed deviation correction on the standardized deviation of each feature dimension to obtain the directed deviation of each feature dimension. Perform inter-dimensional deviation co-occurrence pattern detection on the directed deviation of each feature dimension to obtain the co-occurrence pattern amplification factor; sum the directed deviations of all feature dimensions to obtain the basic deviation total score; and dynamically amplify and correct the basic deviation total score according to the co-occurrence pattern amplification factor to obtain the amplified deviation score. Obtain the number of valid records associated with the baseline vector of transaction behavior and the markers of users with insufficient baseline. Calculate the baseline confidence coefficient based on the number of valid records and the markers of users with insufficient baseline. Adjust the amplified deviation score according to the baseline confidence coefficient to obtain the behavior deviation score.

[0011] Furthermore, methods for cross-validating behavioral deviation scores and identity matching scores include: Obtain the identity matching score, perform a reverse transformation on the identity matching score to obtain the identity uncertainty; perform a two-factor cross-risk assessment on the identity uncertainty and behavioral deviation score to obtain the cross-risk index; assess the basic cross-risk value and the joint anomaly coupling amount based on the identity uncertainty and behavioral deviation scores respectively; determine the cross-risk index based on the basic cross-risk value, the joint anomaly coupling amount, and the preset coupling amplification coefficient. The cross-risk index is adaptively adjusted based on the withdrawal amount input value: the baseline reference value of the withdrawal amount is obtained from the baseline reference vector, and the baseline discrete value of the withdrawal amount is obtained from the baseline discrete vector; the amount deviation multiple is calculated based on the withdrawal amount input value, the baseline reference value of the withdrawal amount, and the baseline discrete value of the withdrawal amount; the decision boundary adjustment factor is determined based on the amount deviation multiple; the cross-risk index is adaptively adjusted based on the decision boundary adjustment factor to obtain the adjusted cross-risk index.

[0012] Furthermore, methods for generating transaction authorization decisions based on cross-validation results include: Preset direct authorization risk thresholds and transaction rejection risk thresholds, and compare them with the adjusted cross-risk index; determine the transaction authorization decision based on the comparison results. The transaction authorization decision includes direct authorization of cash disbursement, triggering secondary palm vein collection for transaction confirmation, and rejecting the transaction and triggering an alarm; when secondary palm vein collection for transaction confirmation is triggered, the secondary palm vein confirmation process is executed. The secondary palm vein confirmation process is as follows: First, it is determined whether the user's palm is detected within a preset waiting time. If not, the transaction authorization decision is updated to reject the transaction and an alarm is triggered. If yes, a near-infrared image of the secondary palm vein is acquired, and image quality verification is performed. If the image quality verification is successful, preprocessing, texture feature extraction, and normalization are performed on the near-infrared image of the secondary palm vein to obtain the secondary palm vein texture features. For the secondary palm vein texture features, the secondary template matching similarity between the feature and the standard template vector corresponding to the best matching template, as well as the consistency similarity between the feature and the palm vein texture features, are calculated and compared with the preset secondary confirmation template matching threshold and consistency threshold. Based on the comparison results, the transaction authorization decision is updated to directly authorize cash dispensing or reject the transaction and trigger an alarm.

[0013] Furthermore, the methods for executing transaction feedback processing based on transaction authorization decisions include: If the transaction authorization decision is to directly authorize cash disbursement, then baseline incremental correction is performed. The method for performing baseline incremental correction is as follows: a baseline update suitability determination is performed on the current transaction behavior feature vector to determine whether it is marked as a suitable correction vector; for a suitable correction vector, the corresponding adaptive update step size is found from the preset update step size mapping table based on the number of valid records and the behavior deviation score; based on the adaptive update step size, the baseline reference values ​​of each feature dimension in the baseline reference vector are incrementally updated, and the baseline discrete values ​​of each feature dimension in the baseline discrete vector are collaboratively updated. If the transaction authorization decision is to reject the transaction and trigger an alarm, then abnormal transaction risk control processing will be performed. The method for performing abnormal transaction risk control processing is as follows: generate an abnormal transaction risk control event record, perform risk level classification and labeling on the abnormal transaction risk control event record, and push the abnormal transaction risk control event record to the bank's security monitoring center in real time.

[0014] The secure withdrawal system for bank ATMs based on palm vein recognition, implementing the aforementioned secure withdrawal method for bank ATMs based on palm vein recognition, includes: The identity authentication module is used to collect the palm vein pattern features of users when they initiate a withdrawal request, match the palm vein pattern features with a pre-built registered palm vein template library, determine the user's identity and associate it with the corresponding bank account based on the matching results, and evaluate the identity matching score. The feature acquisition module is used to collect user transaction behavior data after the user enters the withdrawal operation interface, including the withdrawal amount input value, the duration of the operation interface, the key input rhythm interval sequence and whether the balance is checked, to form a feature vector of the current transaction behavior. The baseline extraction module is used to obtain the historical withdrawal records corresponding to the bank accounts associated with the user's identity, and extract the corresponding user's transaction behavior baseline vector from the historical withdrawal records; The cross-validation module is used to obtain the behavior deviation score by analyzing the deviation of each item based on the feature vector of the current transaction behavior and the baseline vector of the transaction behavior, and to cross-validate the behavior deviation score with the identity matching score, and generate a transaction authorization decision based on the cross-validation results; The transaction feedback module is used to execute transaction feedback processing based on transaction authorization decisions. Transaction feedback processing includes baseline incremental correction and abnormal transaction risk control processing.

[0015] The technical effects and advantages of the secure withdrawal system and method for bank ATMs based on palm vein recognition in this invention are as follows: By introducing palm vein recognition technology into bank ATMs to achieve cardless identity authentication, near-infrared imaging is used to collect the subcutaneous vein patterns of users and match them with a pre-built registration template library. This effectively avoids security risks associated with traditional bank card and password combinations, such as password snooping, lost card fraud, and fingerprint forgery. Simultaneously, a registration consistency score is used to quantitatively evaluate template quality and perform quality-weighted corrections on the matching results, reducing the risk of mismatches due to differences in registration collection quality. After successful identity authentication, full transaction permissions are not immediately granted; instead, multi-dimensional transaction behavior data during the withdrawal process is further collected, including withdrawal amount selection, operation time, key input rhythm, input correction behavior, and other data. Balance inquiry habits are used to form a structured transaction behavior feature vector, and a deviation analysis is performed on each item of the transaction behavior baseline vector extracted from the user's historical withdrawal records. This effectively makes up for the security gap of lacking continuous verification of the transaction operation process after identity verification, and can identify abnormal situations where identity verification is passed but the operation behavior is different from the user's own habits. In the deviation analysis, a directional deviation correction mechanism is used to adjust the directional sensitivity of the differentiated indication of security risks according to the deviation direction of different behavioral dimensions. By detecting the co-occurrence pattern of deviation between dimensions, specific security threat scenarios indicated by multi-dimensional collaborative deviations are identified. This effectively overcomes the shortcomings of traditional behavior anomaly detection, which independently judges or equally weights each dimension and cannot capture combined risk features. By combining identity matching scores and behavioral deviation scores through a joint anomaly coupling factor for cross-risk assessment, this method captures the superlinear risk superposition effect arising from the simultaneous existence of identity authentication uncertainty and behavioral deviation. Furthermore, an adaptive adjustment mechanism based on the amount gradient dynamically adjusts the severity of risk assessment according to the degree of deviation in the withdrawal amount, achieving deep linkage between the identity authentication and behavioral verification dimensions. This overcomes the shortcomings of identity authentication results and transaction risk control decisions being independent and lacking cross-analysis. Based on the cross-risk index, a three-tiered differentiated transaction authorization decision is implemented: direct authorization for cash disbursement, triggering secondary palm vein confirmation, and transaction rejection with alarm. In the secondary confirmation stage, the matching degree between the collected sample and the registration template, as well as the initial verification, are simultaneously verified. The consistency of authentication samples prevents presentation deception attacks during the time interval between initial authentication and secondary confirmation. After a transaction is completed, a baseline update eligibility determination and a queue of transactions to be observed prevent a single authorized transaction with a large deviation from immediately polluting the user's behavior baseline. At the same time, by observing whether subsequent transactions show a consistent deviation pattern, occasional anomalies and continuous habit changes are distinguished, enabling the behavior baseline to adaptively follow the real evolution of user operating habits. Ultimately, a complete closed-loop secure withdrawal system is constructed, from identity authentication, behavior collection, baseline modeling, cross-validation to feedback correction. This system comprehensively improves the security protection capabilities of bank ATM withdrawal transactions while ensuring user convenience. Attached Figure Description

[0016] Figure 1 This is a schematic diagram of a secure withdrawal system for a bank ATM based on palm vein recognition, according to Embodiment 1 of the present invention. Figure 2 This is a flowchart of the secure withdrawal method for bank ATMs based on palm vein recognition, according to Embodiment 2 of the present invention. Detailed Implementation

[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. Example 1:

[0018] Please see Figure 1 As shown in the figure, the secure withdrawal system for bank ATMs based on palm vein recognition described in this embodiment includes an identity authentication module, a feature acquisition module, a baseline extraction module, a cross-validation module, and a transaction feedback module; each module is connected via wired and / or wireless means to realize data transmission between modules.

[0019] The identity authentication module is used to collect the palm vein pattern features of users when they initiate a withdrawal request, match the palm vein pattern features with a pre-built registered palm vein template library, determine the user's identity and associate it with the corresponding bank account based on the matching results, and evaluate the identity matching score.

[0020] Methods for pre-building a registered palm vein template library include: The system retrieves account registration information for each registered user who has activated the palm vein withdrawal service from the bank account management system (the core business management platform used to manage and maintain bank customer account information and service activation status). A registered user is a customer who has completed palm vein information entry and bound their bank account at a bank counter or self-service registration terminal. Account registration information includes a unique user code and the bound bank card number. The unique user code is a predefined unique identifier for the registered user. The system also retrieves a set of palm vein registration images collected during the registration phase from the palm vein registration acquisition system (a near-infrared imaging acquisition device used to collect palm vein images of users at bank counters or self-service registration terminals). This set of palm vein registration images contains multiple consecutive near-infrared images of the palm veins collected by the same registered user during the registration phase. Each near-infrared palm vein image is a grayscale image containing information about the distribution of subcutaneous vein patterns, captured by a near-infrared camera after the user's palm is illuminated by a near-infrared light source. Each near-infrared image of a palm vein in each registered image set is preprocessed sequentially to obtain a standardized palm vein image. Specifically, for each near-infrared image of a palm vein, a region of interest (ROI) extraction is performed. ROI extraction refers to locating and extracting the central region of the palm containing effective vein pattern information from the complete near-infrared image of the palm vein. The specific method for ROI extraction is as follows: Adaptive grayscale thresholding is performed on the near-infrared image of the palm vein using the Otsu thresholding method to separate the palm region from the background region of the acquisition window, obtaining a foreground mask of the palm. Contour detection is performed on the foreground mask of the palm to extract the outer contour of the palm region. Based on the outer contour of the palm, the mean of the x-coordinate and the mean of the y-coordinate of all pixel coordinates are calculated to obtain the center coordinates of the palm. A sub-image is cropped according to a preset cropping window size, centered on the center coordinates of the palm. The mouth size is preset by those skilled in the art based on the imaging parameters of the palm vein acquisition device and the statistical characteristics of the palm size; the Otsu thresholding method and contour detection are well-known techniques in the art, and their specific implementation processes will not be elaborated here; histogram equalization is performed on the cropped sub-image to enhance the gray-level contrast between the vein patterns and the surrounding tissue; Gaussian filtering is performed on the enhanced sub-image to suppress noise interference introduced during the acquisition process, resulting in a standardized palm vein image; histogram equalization refers to an image enhancement method that improves image contrast by redistributing the distribution of image pixel gray-level values ​​to make the gray-level histogram more uniform; Gaussian filtering refers to a spatial domain filtering method that uses a Gaussian kernel function to perform convolution operations on the image to smooth noise; both histogram equalization and Gaussian filtering are well-known techniques in the art, and will not be elaborated here. For each standardized palm vein image, texture features are extracted to obtain texture feature vectors. Specifically, a pre-trained palm vein feature extraction network is used to perform deep feature encoding on the standardized palm vein images, outputting texture feature vectors. The palm vein feature extraction network is a feature encoding model based on a convolutional neural network architecture and trained on a large-scale palm vein image dataset, capable of mapping standardized palm vein images into highly discriminative feature vectors. The output layer of the palm vein feature extraction network is a fully connected layer, outputting a real-number vector of a preset dimension as the texture feature vector. The dimension of the texture feature vector is preset by those skilled in the art based on the balance between feature representation capability and computational efficiency. The network structure design and training method of the convolutional neural network are well-known technologies in the field and will not be elaborated further here. For each registered user, a registration consistency score is calculated based on the corresponding palm vein registration image set, and the quality of the corresponding palm vein registration image set is determined according to the registration consistency score. Specifically, the cosine similarity between any two texture feature vectors among all texture feature vectors corresponding to the same registered user is calculated to obtain multiple similarity values ​​between vectors. The average of all similarity values ​​between vectors is calculated to obtain the registration consistency score. The registration consistency score reflects the stability of features among multiple palm vein images collected by the same user; a higher registration consistency score indicates better registration collection quality. The registration consistency score is compared with a preset registration consistency threshold, which is preset by those skilled in the art according to the registration quality standards of the palm vein recognition system. If the registration consistency score is less than the registration consistency threshold, the corresponding palm vein registration image set is deemed unqualified, and the corresponding registered user is required to re-collect images. If the registration consistency score is greater than or equal to the registration consistency threshold, the corresponding palm vein registration image set is deemed qualified. The element-wise mean of all texture feature vectors in the qualified palm vein registration image set is calculated to obtain the registration template vector. The element-wise mean calculation involves calculating the arithmetic mean of elements at the same position in all texture feature vectors to form a mean vector with the same dimension as a single texture feature vector. The registration template vector is then normalized using the L2 norm to obtain a standard template vector. The standard template vector, user unique code, bound bank card number, and registration consistency score for each registered user are integrated to form the palm vein registration template for each user. Finally, the palm vein registration templates of all registered users are compiled to construct a registered palm vein template library.

[0021] Methods for collecting palm vein pattern features of users include: When a user initiates a withdrawal request at a bank ATM, the palm vein acquisition sensor installed on the ATM's control panel is activated. The palm vein acquisition sensor is a non-contact palm vein imaging module that integrates a near-infrared light source and a near-infrared camera. The user is guided to place their palm above the acquisition window of the palm vein acquisition sensor to acquire a near-infrared image of the palm vein at that time. Image quality verification is performed on the current palm vein near-infrared image. Specifically, the image width and height in pixels of the current palm vein near-infrared image are obtained, and the product of the image width and height in pixels is calculated to obtain the total number of pixels in the image. The Otsu thresholding method is used to perform adaptive grayscale thresholding segmentation on the current palm vein near-infrared image to obtain a palm foreground region mask. Morphological closing operations are then performed on the palm foreground region mask to fill the small holes inside the foreground region, thus obtaining the palm region mask. Morphological closing operations are a well-known technique in the field and will not be elaborated upon here. Pixels in the palm region mask are marked as foreground pixels, and the total number of foreground pixels in the palm region mask is counted to obtain the number of pixels in the palm region. The ratio of the number of pixels in the palm region to the total number of pixels in the image is calculated to obtain the effective pixel ratio. The effective pixel ratio reflects whether the palm fully covers the acquisition area. A preset effective pixel ratio threshold is defined by the relevant technical field. Technicians pre-set the imaging standards of the palm vein acquisition device. If the effective pixel ratio is less than the effective pixel ratio threshold, the palm positioning is deemed insufficient, and the user is prompted to reposition their palm and re-acquire the image. If the effective pixel ratio is greater than or equal to the effective pixel ratio threshold, the gray values ​​of all foreground pixels within the palm region mask in the current palm vein near-infrared image are extracted, and the standard deviation is calculated to obtain the gray standard deviation. The gray standard deviation reflects the contrast level between the vein patterns and surrounding tissues in the image. A larger gray standard deviation indicates a more significant gray difference between the vein patterns and the background, resulting in higher acquisition quality. A lower contrast threshold is preset, which is pre-set by those skilled in the art based on the minimum contrast requirements for palm vein image pattern recognition. If the gray standard deviation is less than the lower contrast threshold, the image contrast is deemed insufficient, and the user is prompted to adjust their palm posture and re-acquire the image. If the gray standard deviation is greater than or equal to the lower contrast threshold, the image quality is deemed acceptable. Perform the same preprocessing operation as in the registration stage on the qualified palm vein near-infrared image of the current time to obtain the standardized palm vein image of the current time; input the standardized palm vein image of the current time into the palm vein feature extraction network to obtain the texture feature vector of the current time; perform L2 norm normalization on the texture feature vector of the current time to obtain the palm vein texture features.

[0022] Methods for identifying users and linking them to corresponding bank accounts include: The cosine similarity between the palm vein pattern features and the standard template vector of each palm vein registered template in the registered palm vein template library is calculated to obtain the original matching similarity corresponding to each palm vein registered template. Template quality weighting is then applied to each original matching similarity to obtain the corresponding corrected matching similarity. Specifically, the registration consistency score corresponding to each palm vein registered template is obtained; a standard consistency benchmark value is preset, which is pre-set by those skilled in the art according to the template quality evaluation standard of the palm vein recognition system; the ratio of the registration consistency score to the standard consistency benchmark value is calculated to obtain the template quality coefficient; if the template quality coefficient is greater than one, it is set to one; the product of the original matching similarity and the template quality coefficient is calculated to obtain the corrected matching similarity corresponding to each palm vein registered template; wherein, the corrected matching similarity is used to reflect the matching confidence level after template registration quality correction. For palm vein registered templates with lower registration quality, their matching scores are appropriately reduced to decrease the risk of mismatches caused by differences in the quality of palm vein registered templates. All palm vein registration templates are sorted from highest to lowest according to their corresponding modified matching similarity, generating a registration template sequence. The palm vein registration template ranked first in the sequence is marked as the best matching template, and the modified matching similarity corresponding to the second-ranked palm vein registration template is marked as the second-best matching similarity. The modified matching similarity corresponding to the best matching template is compared with a preset identity verification threshold, which is preset by those skilled in the art according to the security level requirements of the palm vein recognition system. If the modified matching similarity is less than the identity verification threshold, the identity authentication is deemed to have failed, and the user is denied access to the withdrawal operation interface. If the modified matching similarity is greater than or equal to the identity verification threshold, the identity authentication is deemed to have passed. The corresponding user unique code and bound bank card number are extracted from the best matching template. The user's identity is determined based on the user unique code, the corresponding bank account is associated based on the bound bank card number, and the user is allowed to access the withdrawal operation interface.

[0023] Methods for assessing identity matching scores include: The difference between the corrected matching similarity and the second-best matching similarity corresponding to the best matching template is calculated to obtain the matching discrimination score. The matching discrimination score reflects the degree of identification advantage of the best matching template relative to other registered templates. A higher matching discrimination score indicates a stronger exclusiveness of the match between the current user and the best matching template, and a higher degree of uniqueness in identity determination. Based on the image quality verification results of the current palm vein near-infrared image, the acquisition quality factor is calculated. Specifically, the ratio of the effective pixel percentage to the effective pixel percentage threshold is calculated to obtain the pixel sufficiency rate. If the pixel sufficiency rate is greater than one, it is set to one. The ratio of the grayscale standard deviation to the contrast lower limit threshold is calculated to obtain the contrast sufficiency rate. If the contrast sufficiency rate is greater than one, it is set to one. The mean of the pixel sufficiency rate and the contrast sufficiency rate is calculated to obtain the acquisition quality factor. The acquisition quality factor reflects the degree to which the quality level of the current palm vein acquisition image supports the reliability of identity matching. A higher acquisition quality factor indicates more sufficient acquisition conditions and higher reliability of the matching results. Corresponding matching degree weights are set for the modified matching similarity, matching discrimination, and collection quality factor. Each matching degree weight is pre-set by a person skilled in the art based on the comprehensive security assessment strategy of the palm vein recognition system. Based on each matching degree weight, the modified matching similarity, matching discrimination, and collection quality factor are weighted and summed to obtain the identity matching degree score. The identity matching degree score is used to comprehensively reflect the reliability and confidence level of the current user identity authentication result. The higher the identity matching degree score, the higher the confidence level of identity authentication.

[0024] The feature acquisition module is used to collect user transaction behavior data after the user enters the withdrawal operation interface, including the withdrawal amount input value, the duration of the operation interface, the rhythm interval sequence of key input, and whether the balance is checked, to form a feature vector of the current transaction behavior.

[0025] Methods for collecting user transaction behavior data include: When a user enters the withdrawal interface, the ATM's operating system automatically activates the transaction behavior recording engine. This engine is a pre-deployed event listening and timestamp recording program in the ATM's application layer, used to capture and record in real time the various operations performed by the user on the withdrawal interface. By listening to the input signals from the ATM's touchscreen interface and physical keyboard interface, the engine generates corresponding operation event records when it detects a user's operation. The operation event records include the operation event type, the timestamp of the operation, and additional event data. The operation event type identifies the specific category of the operation performed by the user, including interface entry events, numeric keypad input events, delete keypad input events, balance inquiry events, and amount confirmation events. Interface entry events are automatically generated by the transaction behavior recording engine when a user enters the withdrawal operation interface after identity authentication. Numeric keypad input events are generated when a user enters an amount using the numeric keypad or touchscreen numeric buttons. Delete keypad input events are generated when a user presses the delete or back button to cancel the entered number. Balance inquiry events are generated when a user clicks the balance inquiry function button in the withdrawal operation interface. Amount confirmation events are generated when a user completes the withdrawal amount input and clicks the confirmation button to submit the withdrawal request. The operation timestamp is the precise time recorded by the ATM system clock when the corresponding operation event occurs. Additional event data is supplementary information associated with a specific operation event type. For numeric keypad input events, the additional event data is the numeric keypad value pressed by the user; for amount confirmation events, the additional event data is the final withdrawal amount confirmed by the user; for interface entry events, delete keypad input events, and balance inquiry events, the additional event data is empty. The transaction behavior recording engine stores all operation event records generated during the current withdrawal operation in chronological order according to the timestamps of the corresponding operations, forming an operation event sequence for the current transaction, and performs integrity checks on the operation event sequence. Specifically, it determines whether the operation event sequence contains both an interface entry event record (operation event record of type interface entry event) and an amount confirmation event record (operation event record of type amount confirmation event). If the operation event sequence is missing an interface entry event record or an amount confirmation event record, it is determined that the operation event sequence is incomplete, and subsequent feature extraction operations are not performed; if the operation event sequence contains both an interface entry event record and an amount confirmation event record, it is determined that the operation event sequence is complete, and subsequent feature extraction operations continue.

[0026] Based on the sequence of operation events that passed the integrity check, extract the withdrawal amount input value, the duration of time spent on the operation interface, the key input rhythm interval sequence, and the balance query marker. The method for extracting the withdrawal amount input value is as follows: locate the amount confirmation event record from the operation event sequence, and obtain the withdrawal amount value from the corresponding additional event data as the withdrawal amount input value; wherein, the withdrawal amount input value is the withdrawal amount that the user finally confirms and submits in the current withdrawal operation, which is used to reflect the user's amount selection behavior in the current transaction; different users usually have a relatively stable personal preference range for daily withdrawal amounts. If the current withdrawal amount deviates significantly from the common range of the user's historical withdrawal amounts, it may indicate that there is an anomaly in the transaction behavior; The method for extracting the duration of the user interface dwell time is as follows: Locate the interface entry event record and the amount confirmation event record from the operation event sequence, and obtain the operation occurrence timestamps corresponding to the interface entry event record and the amount confirmation event record respectively; calculate the time difference between the operation occurrence timestamp of the amount confirmation event record and the operation occurrence timestamp of the interface entry event record to obtain the duration of the user interface dwell time; wherein, the duration of the user interface dwell time is used to reflect the overall operation time taken from the user entering the withdrawal operation interface to completing the withdrawal amount confirmation; an excessively long duration of the user interface dwell time may indicate that the user hesitated or was interfered with during the operation, while an abnormally short duration of the user interface dwell time may indicate that the operator was too hasty in the transaction process or that the behavior pattern is different from the normal habits of the account holder; The method for extracting the key input rhythm interval sequence is as follows: Extract all operation event records of type numeric key input events from the operation event sequence and mark them as numeric key input event records; obtain the operation occurrence timestamp corresponding to each numeric key input event record and arrange them in chronological order to form a key timestamp sequence; if the key timestamp sequence contains at least two operation occurrence timestamps, calculate the time difference between the latter and former operation occurrence timestamps for every two adjacent operation occurrence timestamps in the key timestamp sequence to obtain the key interval duration; arrange all key interval durations to form the key input rhythm interval sequence; if the key timestamp sequence contains only... A timestamp or no timestamp indicates that the user directly selected the withdrawal amount via the preset amount shortcut button on the withdrawal interface instead of manually entering it digit by digit using the numeric keypad, and the key input rhythm interval sequence is marked as an empty sequence. The key input rhythm interval sequence records the time interval distribution between each key press when the user enters the withdrawal amount digit by digit, reflecting the user's key input rhythm characteristics and operational proficiency. Each user's key input rhythm usually has relatively fixed personal characteristics, such as key press speed and rhythm uniformity. If the key press rhythm differs significantly from the user's historical key press rhythm, it may indicate that the current operator is not the account holder or that the operator is in an abnormal operation state. The method for extracting the balance query marker is as follows: traverse all operation event records in the operation event sequence and determine whether a balance query event record exists; where a balance query event record is an operation event record with the operation event type of balance query event; if a balance query event record exists, set the balance query marker to the queried state; if no balance query event record exists, set the balance query marker to the unqueried state; the balance query marker is used to reflect whether the user performed an account balance query operation during the current withdrawal operation; different users' habits of checking their balance before withdrawal usually have individual stability. Some users are accustomed to checking their account balance before each withdrawal, while some users directly enter the amount to complete the withdrawal. If the balance query behavior is inconsistent with the user's historical habits, it can be used as a reference factor to help determine whether the transaction behavior is abnormal.

[0027] Methods for generating feature vectors for a given transaction include: Based on the operation event sequence, the number of operation event records with the operation event type of delete key input is counted to obtain the input correction count. The input correction count reflects the number of times the user performs delete or rollback operations during the process of entering the withdrawal amount. The higher the input correction count, the greater the possibility that the user made an input error or hesitated during the amount input process. In normal withdrawal scenarios, users usually have a clear idea of ​​their expected withdrawal amount, and the input correction count is relatively small. If the input correction count is significantly higher than the normal level of the user's historical operations, it may indicate that the operator is uncertain about the withdrawal amount or is affected by external factors. Based on the key input rhythm interval sequence, statistical features of the key rhythm are extracted. These features include the average key interval duration and the key rhythm fluctuation. Specifically, if the key input rhythm interval sequence is empty, both the average key interval duration and the key rhythm fluctuation are set to preset default values. These default values ​​are pre-set by those skilled in the art based on the key operation statistical characteristics of ATM users, providing a benchmark reference value for the corresponding feature dimension when the user does not input the amount digit by digit using the numeric keypad. If the key input rhythm interval sequence is not empty, the mean of all key interval durations in the sequence is calculated to obtain the average key interval duration, and the standard deviation of all key interval durations is calculated to obtain the key rhythm fluctuation. The average key interval duration reflects the overall speed level of the user's key operation; a smaller average key interval duration indicates a faster input speed. The key rhythm fluctuation reflects the stability of the user's key operation rhythm; a smaller fluctuation indicates a more stable and uniform key rhythm, while a larger fluctuation indicates a more irregular key rhythm. The balance query marker is converted into a numerical value. Specifically, if the balance query marker is in a queried state, the balance query marker value is set to one; if the balance query marker is in a non-queried state, the balance query marker value is set to zero. The withdrawal amount input value, the duration of the operation interface, the average interval of key presses, the key press rhythm fluctuation, the number of input corrections, and the balance query marker value are arranged in the above fixed order to form the current transaction behavior feature vector. The current transaction behavior feature vector contains six feature dimensions, corresponding to the user's amount selection behavior, operation time behavior, key press speed characteristics, key press rhythm stability characteristics, input correction behavior, and balance query behavior in the current withdrawal operation. The current transaction behavior feature vector is used to represent the comprehensive behavioral pattern characteristics of the user in the current withdrawal operation in a structured numerical vector form, so as to identify whether the current transaction operation behavior deviates from the user's historical operation habits.

[0028] The baseline extraction module is used to obtain the historical withdrawal records corresponding to the bank accounts associated with the user's identity, and extract the corresponding user's transaction behavior baseline vector from the historical withdrawal records.

[0029] Methods for obtaining historical withdrawal records include: Based on the linked bank card number used when linking the bank account, the system retrieves all historical withdrawal records associated with the corresponding linked bank card number from the transaction behavior record database (i.e., a structured data storage platform used to store and manage the operational behavior characteristic data generated by each registered user during past withdrawal transactions), forming a historical withdrawal record set. The historical withdrawal record is used to record the operational behavior characteristic data automatically saved by the system each time a registered user completes a withdrawal transaction, specifically including the transaction record code, transaction completion timestamp, historical withdrawal amount, historical operation dwell time, historical average key press interval, historical key press rhythm fluctuation, historical input correction count, and historical balance query marker value. Among them, the transaction record code is a unique identifier for each historical withdrawal record; the transaction completion timestamp is the time recorded by the system when the corresponding withdrawal transaction is completed; the historical withdrawal amount is the withdrawal amount finally confirmed by the user in the corresponding withdrawal transaction, corresponding to the withdrawal amount input value in the current transaction behavior feature vector; the historical operation dwell time is the operation time taken by the user from entering the withdrawal operation interface to completing the amount confirmation in the corresponding withdrawal transaction, corresponding to the operation interface dwell time in the current transaction behavior feature vector; the historical average key interval is the average time interval between each key press when the user enters the amount digit by digit in the corresponding withdrawal transaction, corresponding to the average key interval duration in the current transaction behavior feature vector; the historical key rhythm fluctuation is the degree of fluctuation of the user's key interval duration in the corresponding withdrawal transaction, corresponding to the key rhythm fluctuation degree in the current transaction behavior feature vector; the historical input correction count is the number of times the user performed the delete or rollback operation in the corresponding withdrawal transaction, corresponding to the number of input corrections in the current transaction behavior feature vector; and the historical balance query flag is a numerical flag indicating whether the user performed the balance query operation in the corresponding withdrawal transaction, corresponding to the balance query flag value in the current transaction behavior feature vector. It should be noted that all the operational behavior feature data in the historical withdrawal records are persistently stored in the transaction behavior record database by the subsequent transaction feedback module after each previous withdrawal transaction is completed normally. The module writes the values ​​of each feature dimension in the corresponding current transaction behavior feature vector, along with the transaction record code and the transaction completion timestamp, into the transaction behavior record database.

[0030] Methods for extracting baseline vectors of transaction behavior include: The historical withdrawal record set is sequentially subjected to timeliness filtering and abnormal record removal to obtain a valid historical record set. The method for performing timeliness filtering is as follows: a baseline time window for behavior is preset, which is pre-set by those skilled in the art based on the time stability characteristics of users' withdrawal behavior habits; the current system time is obtained, and for each historical withdrawal record in the historical withdrawal record set, the time interval between the corresponding transaction completion timestamp and the current system time is calculated; if the time interval exceeds the baseline time window, the corresponding historical withdrawal record is excluded; all historical withdrawal records that are not excluded are summarized to form a timeliness-filtered record set. The method for removing abnormal records is as follows: The mean and standard deviation of the historical withdrawal amounts corresponding to all historical withdrawal records in the time-sensitive record set are calculated to obtain the mean and standard deviation of the amounts. For each historical withdrawal record in the time-sensitive record set, it is determined whether the absolute value of the deviation between the corresponding historical withdrawal amount and the mean amount exceeds a preset multiple of the standard deviation of the amount. The preset multiple is pre-set by a person skilled in the art based on the sensitivity requirements of abnormal behavior detection. If it exceeds this multiple, the corresponding historical withdrawal record is removed. The same abnormal record removal operation is performed on the historical operation dwell time, and all remaining historical withdrawal records are summarized to form a valid historical record set. Abnormal record removal is used to exclude atypical operation behavior records caused by special circumstances in previous withdrawals, avoiding interference with the representativeness of the behavior baseline. The system performs a record sufficiency determination on the valid historical record set. Specifically, it counts the number of historical withdrawal records contained in the valid historical record set to obtain the number of valid records. A minimum baseline sample size is preset, which is pre-set by a person skilled in the art based on the minimum requirements for the statistical reliability of behavioral baselines. The number of valid records is compared with the minimum baseline sample size. If the number of valid records is less than the minimum baseline sample size, it is determined that the historical behavioral data of the corresponding user is insufficient to construct a reliable individual behavioral baseline. The corresponding user is marked as a user with insufficient baseline, and a default baseline reference vector and a default baseline discrete vector are obtained from the preset default behavioral baseline configuration, which are used as the baseline reference vector and the baseline discrete vector, respectively. The default behavioral baseline configuration is pre-configured by a person skilled in the art based on the statistical characteristics of withdrawal behavior of the entire user group of ATMs, and is used to provide a general behavioral reference standard when the individual user's historical data is insufficient. If the number of valid records is greater than or equal to the minimum baseline sample size, it is determined that the historical behavioral data of the corresponding user meets the baseline construction requirements, and the baseline extraction operation continues.

[0031] Based on the transaction completion timestamps of each historical withdrawal record in the valid historical record set, a corresponding time decay weight is assigned to each historical withdrawal record. Specifically, the time interval corresponding to each historical withdrawal record in the valid historical record set is obtained, and an initial decay weight is assigned to each historical withdrawal record sequentially according to a decreasing rule: the smaller the time interval, the greater the weight; and the larger the time interval, the smaller the weight. The initial decay weight is used to give more recent transaction records a higher weight in the baseline calculation, reflecting the characteristic that user behavior may gradually change over time. The specific decay rate of the initial decay weight is preset by those skilled in the art based on the time evolution characteristics of user behavior. The initial decay weights of all historical withdrawal records in the valid historical record set are sequentially normalized to obtain the time decay weight corresponding to each historical withdrawal record. For each feature dimension in the current transaction behavior feature vector, the time decay weight corresponding to each historical withdrawal record is used as the baseline weight. Based on the baseline weight, the weighted average of the operational behavior feature data of each historical withdrawal record in the valid historical record set on the corresponding feature dimension is calculated to obtain the baseline reference value of each feature dimension. Specifically, based on the baseline weight, the weighted average of historical withdrawal amount, historical operation dwell time, historical average key press interval, historical key press rhythm fluctuation, historical input correction count, and historical balance query mark value in all historical withdrawal records is calculated to obtain the baseline reference values ​​for withdrawal amount, operation dwell time, key press interval, key press fluctuation, correction count, and balance query. These are then arranged in the same feature dimension order as the current transaction behavior feature vector to form the baseline reference vector. The baseline reference vector is used to characterize the typical operational habit level of the corresponding user on each behavioral dimension. For each feature dimension in the current transaction behavior feature vector, the weighted standard deviation of the operational behavior feature data of each historical withdrawal record relative to the corresponding baseline reference value is calculated based on the baseline weight, resulting in the baseline discrete value of each feature dimension (i.e., the baseline discrete value of withdrawal amount, the baseline discrete value of operation dwell time, the baseline discrete value of key press interval, the baseline discrete value of key press fluctuation, the baseline discrete value of correction times, and the baseline discrete value of balance query). The weighted standard deviation is a conventional statistical calculation method in this field and will not be elaborated upon here. For each baseline discrete value, if the baseline discrete value of a certain feature dimension is zero or close to zero, the corresponding baseline discrete value is replaced with a preset minimum discrete value. The minimum discrete protection value is preset by those skilled in the art based on the dimensional characteristics of each feature dimension data. This is to prevent division by zero anomalies or oversensitivity in subsequent deviation analysis due to the high consistency of historical data for that feature dimension. The baseline discrete values ​​of each feature dimension are arranged sequentially according to the same feature dimension order as the feature vector of the current transaction behavior to form a baseline discrete vector. The baseline discrete vector is used to reflect the normal fluctuation range of the corresponding user's historical operation behavior on different feature dimensions. The larger the baseline discrete value, the greater the fluctuation of the behavior habits on the corresponding feature dimension. The smaller the baseline discrete value, the more stable the behavior habits on the corresponding feature dimension. The baseline reference vector and the baseline discrete vector are integrated to form the transaction behavior baseline vector. At the same time, the number of valid records and the baseline insufficient user flag are also associated with the transaction behavior baseline vector. The transaction behavior baseline vector is used to represent the central level and normal fluctuation range of the corresponding user's historical operating habits in each feature dimension in a structured numerical form. The number of valid records is used to reflect the historical sample size on which the current baseline is based. The baseline insufficient user flag is used to identify whether the current baseline is a personalized baseline built based on individual historical data.

[0032] The cross-validation module is used to obtain the behavior deviation score by analyzing the deviation of each item based on the feature vector of the current transaction behavior and the baseline vector of the transaction behavior. The behavior deviation score is then cross-validated with the identity matching score, and a transaction authorization decision is generated based on the cross-validation results.

[0033] Methods for obtaining behavioral deviation scores through item-by-item deviation analysis include: The baseline reference vector and baseline discrete vector are extracted from the transaction behavior baseline vector, and the number of associated valid records and the markers of users with insufficient baselines are obtained. For each feature dimension in the current transaction behavior feature vector and the transaction behavior baseline vector, a dimension-wise standardized deviation calculation is performed to obtain the standardized deviation of each feature dimension. Specifically, for each feature dimension, the absolute value of the deviation between the corresponding value in the current transaction behavior feature vector and the corresponding baseline reference value in the baseline reference vector is calculated, and the ratio of the corresponding absolute value of the deviation to the corresponding baseline discrete value in the baseline discrete vector is calculated to obtain the standardized deviation of the corresponding feature dimension. The standardized deviation reflects the degree to which the user's current operation deviates from the central level of their historical behavior habits in the corresponding feature dimension. Standardization is performed using the baseline discrete value as a scale to make feature dimensions with different dimensions and numerical ranges comparable. Directed deviation correction is performed on the standardized deviation of each feature dimension to obtain the directed deviation of each feature dimension. Directed deviation correction refers to the process of adjusting the direction sensitivity of the standardized deviation based on the direction of deviation of the current operation value relative to the baseline reference value. Positive deviation refers to the case where the corresponding value in the feature vector of the current transaction is greater than the corresponding baseline reference value in the baseline reference vector, and negative deviation refers to the case where the corresponding value in the feature vector of the current transaction is less than the corresponding baseline reference value in the baseline reference vector. In actual withdrawal scenarios, the direction of deviation of different feature dimensions has significantly different indicative significance for security risks. For example, the financial risk implied when the withdrawal amount is significantly higher than the user's usual level is significantly higher than when the withdrawal amount is lower than the usual level, and an abnormally fast operation speed is more likely to indicate that the operator is in a state of coercion or pressure than a slow operation speed. A pre-defined set of directed correction rules is provided, which includes the risk deviation direction and direction amplification coefficient corresponding to each feature dimension. The risk deviation direction identifies the deviation direction with higher security risk in the corresponding feature dimension. The direction amplification coefficient amplifies the standardized deviation when the actual deviation direction matches the risk deviation direction. Each risk deviation direction and direction amplification coefficient is pre-set by those skilled in the art based on the security risk characteristics of bank withdrawal transactions. Specifically, for the feature dimensions corresponding to the withdrawal amount input value, key rhythm fluctuation, and input correction times, the risk deviation direction is positive. For the feature dimension corresponding to the duration of time spent on the operation interface, the risk deviation direction is bidirectional, meaning that both positive and negative deviations are considered risky. For the feature dimension corresponding to the average key interval duration, the risk deviation direction is negative. For the feature dimension corresponding to the balance query marker value, the standardized deviation is directly used as the directed deviation. For each feature dimension that requires directional deviation correction, determine whether the actual deviation direction of the corresponding value in the feature vector of the current transaction behavior relative to the corresponding baseline reference value is consistent with the corresponding risk deviation direction. If consistent, the product of the standardized deviation and the corresponding directional amplification factor is used as the directional deviation. If inconsistent, the standardized deviation is used directly as the directional deviation. For feature dimensions with bidirectional risk deviation, regardless of the actual deviation direction, the product of the standardized deviation and the corresponding directional amplification factor is used as the directional deviation.

[0034] The directional deviation of each feature dimension is analyzed using inter-dimensional deviation co-occurrence pattern detection to obtain the co-occurrence pattern amplification factor. Inter-dimensional deviation co-occurrence pattern detection refers to the process of matching and analyzing the combination of deviation states of each feature dimension in the current transaction with a preset risk deviation co-occurrence pattern. This is used to identify situations where multiple feature dimensions deviate simultaneously and form a specific risk combination. In actual withdrawal security risk scenarios, behavioral deviation in a single dimension may be caused by normal individual differences or accidental factors, but when multiple dimensions deviate simultaneously along a specific risk direction and form a synergistic deviation combination, it usually indicates a higher security risk. For example, a significantly higher withdrawal amount coupled with an abnormally faster operation speed may indicate that the operator is under duress; a higher withdrawal amount coupled with an excessive number of input corrections may indicate that the operator has uncertainty about the transaction amount. A pre-defined risk co-occurrence pattern library is provided, containing multiple risk co-occurrence patterns. Each risk co-occurrence pattern includes a set of participating dimensions, a deviation activation threshold for each participating dimension, and a corresponding co-occurrence amplification coefficient. The set of participating dimensions specifies the combination of feature dimensions involved in the corresponding risk co-occurrence pattern. The deviation activation threshold determines whether the directed deviation of the corresponding feature dimension reaches the threshold condition for triggering the corresponding risk co-occurrence pattern. The co-occurrence amplification coefficient is the coefficient used to amplify the overall behavioral deviation when the corresponding risk co-occurrence pattern is triggered. Each risk co-occurrence pattern is pre-set by those skilled in the art based on typical security threat scenarios of bank withdrawal transactions. For each risk co-occurrence pattern in the risk co-occurrence pattern library, determine whether the directed deviation of all feature dimensions in the corresponding participating dimension set is greater than or equal to the corresponding deviation activation threshold. If the condition is met, the corresponding risk co-occurrence pattern is determined to be triggered; otherwise, it is determined that the corresponding risk co-occurrence pattern has not been triggered. If there is no triggered risk co-occurrence pattern in the risk co-occurrence pattern library, the co-occurrence pattern amplification factor is set to one. If there is a triggered risk co-occurrence pattern, obtain the co-occurrence amplification coefficients corresponding to all triggered risk co-occurrence patterns and mark them as trigger amplification coefficients. Select the maximum value among all trigger amplification coefficients as the co-occurrence pattern amplification factor.

[0035] The directed deviations of all feature dimensions are summed to obtain the total baseline deviation score. The product of the total baseline deviation score and the co-occurrence pattern amplification factor is used as the amplified deviation score. The baseline confidence coefficient is calculated based on the number of valid records and the baseline insufficient user markers. The amplified deviation score is adjusted for baseline confidence based on the baseline confidence coefficient to obtain the behavioral deviation score. The baseline confidence coefficient reflects the statistical reliability of the current trading behavior baseline vector. A higher baseline confidence coefficient indicates a more reliable baseline and more credible results for the behavioral deviation analysis. Specifically, if the corresponding user is marked as a user with insufficient baseline, the baseline confidence coefficient is set to a preset minimum confidence value; the minimum confidence value is preset by a person skilled in the art based on the representativeness level of the default behavioral baseline configuration; if the corresponding user is not marked as a user with insufficient baseline, the number of valid records is compared with a preset confidence saturation sample size; if the number of valid records is greater than or equal to the confidence saturation sample size, the baseline confidence coefficient is set to one; if the number of valid records is less than the confidence saturation sample size, the ratio of the number of valid records to the confidence saturation sample size is set to... The baseline confidence coefficient is used as the baseline confidence coefficient. The confidence saturation sample size is pre-set by a person skilled in the art based on the minimum sample size required for statistical convergence of the behavioral baseline. The behavioral deviation score is obtained by multiplying the amplified deviation score by the baseline confidence coefficient. The behavioral deviation score is used to comprehensively reflect the degree of deviation of the current transaction operation from the user's historical behavioral habits. The higher the behavioral deviation score, the greater the degree of deviation of the current operation from the user's normal habits. When the baseline confidence is low, the behavioral deviation score is appropriately compressed to avoid misjudging normal transactions due to unreliable baseline.

[0036] Methods for cross-validating behavioral deviation scores and identity matching scores include: The identity matching score is obtained, and then the identity matching score is reverse-converted to obtain the identity uncertainty. Specifically, a theoretical upper limit for the identity matching score is preset, which is pre-set by those skilled in the art based on the matching score range of the palm vein recognition system. The difference between the theoretical upper limit and the identity matching score is divided by the theoretical upper limit to obtain the identity uncertainty. The identity uncertainty is used to reflect the degree of uncertainty remaining in the identity authentication result; the higher the identity matching score, the lower the identity uncertainty. A two-factor cross-risk assessment was performed on the scores of identity uncertainty and behavioral deviation to obtain a cross-risk index. Specifically, corresponding cross weights were set for the scores of identity uncertainty and behavioral deviation. Each cross weight was pre-set by a person skilled in the art based on the relative importance of identity authentication and behavioral verification dimensions in security decision-making. Based on each cross weight, the scores of identity uncertainty and behavioral deviation were weighted and summed to obtain the basic cross-risk value. The product of identity uncertainty and behavioral deviation score is calculated to obtain the joint anomaly coupling quantity. This joint anomaly coupling quantity is used to capture the superlinear risk superposition effect generated when identity authentication uncertainty and behavioral deviation coexist. When the identity matching score is high, the identity uncertainty is low, and even if the behavioral deviation score is high, the joint anomaly coupling quantity remains small, indicating that the additional risk of behavioral deviation is controllable under the premise of high identity certainty. When both identity uncertainty and behavioral deviation scores are at high levels, the joint anomaly coupling quantity increases significantly, reflecting the additional security risk brought about by the superposition of dual anomaly signals. A preset coupling amplification factor is used, which is pre-set by those skilled in the art according to the security strategy of dual-factor risk superposition. The product of the joint anomaly coupling quantity and the coupling amplification factor is calculated, and the sum of the product calculation result and the basic cross-risk value is used as the cross-risk index. The cross-risk index is adaptively adjusted based on the withdrawal amount input. This adaptive adjustment refers to a mechanism that dynamically adjusts the stringency of transaction risk assessment based on the deviation of the current withdrawal amount from the user's usual withdrawal level. Higher withdrawal amounts involve a greater risk of financial loss and therefore require stricter security standards. Specifically, the withdrawal amount input is obtained from the current transaction behavior feature vector, the baseline reference value is obtained from the baseline reference vector, and the baseline discrete value is obtained from the baseline discrete vector. The absolute value of the deviation between the withdrawal amount input and the baseline reference value is calculated, and the corresponding absolute deviation is expressed as a percentage. The deviation multiple is calculated by comparing the value with the baseline discrete value of the withdrawal amount; a preset amount gradient adjustment coefficient is set by those skilled in the art based on the security strategy gradient corresponding to different amount levels; if the amount deviation multiple is less than or equal to one, the decision boundary adjustment factor is set to one, indicating that the current withdrawal amount is within the user's normal fluctuation range, and no additional adjustment is made to the cross-risk index; if the amount deviation multiple is greater than one, the result of multiplying the amount deviation multiple and the amount gradient adjustment coefficient plus one is used as the decision boundary adjustment factor; the product of the cross-risk index and the decision boundary adjustment factor is used as the adjusted cross-risk index; Methods for generating transaction authorization decisions based on cross-validation results include: The system presets a direct authorization risk threshold and a transaction rejection risk threshold. Both the direct authorization risk threshold and the transaction rejection risk threshold are preset by those skilled in the art based on the bank's security management strategy for cash withdrawal transactions. The direct authorization risk threshold is lower than the transaction rejection risk threshold. The direct authorization risk threshold is used to define the upper limit of cross-risk that can be directly authorized for cash withdrawal, while the transaction rejection risk threshold is used to define the lower limit of cross-risk that should be rejected and trigger an alarm. The system compares the adjusted cross-risk index with the direct authorization risk threshold and the transaction rejection risk threshold. If the adjusted cross-risk index is less than or equal to the direct authorization risk threshold, a transaction authorization decision is generated to directly authorize cash dispensing, indicating that the identity authentication confidence of this transaction is high and the transaction behavior is consistent with the user's historical habits, the transaction risk is within a controllable range, and the ATM is allowed to directly execute the cash dispensing operation. If the adjusted cross-risk index is greater than the direct authorization risk threshold but less than the transaction rejection risk threshold, a transaction authorization decision is generated to trigger secondary palm vein sampling for transaction confirmation, indicating that this transaction has a medium security risk and requires further confirmation of the operator's identity through secondary biometric verification. If the adjusted cross-risk index is greater than or equal to the transaction rejection risk threshold, a transaction authorization decision is generated to reject the transaction and trigger an alarm, indicating that this transaction has a high security risk, the system refuses to execute the cash dispensing operation, and sends an alarm message to the bank's security monitoring center.

[0037] When the transaction authorization decision triggers a secondary palm vein sampling for transaction confirmation, the secondary palm vein confirmation process is executed. Specifically, the ATM displays a secondary palm vein confirmation prompt on the withdrawal interface, guiding the user to place their palm above the sampling window of the palm vein sampling sensor again. At the same time, a secondary confirmation waiting timer is started. The waiting time of the secondary confirmation waiting timer is preset by those skilled in the art based on a reasonable time for the user's operation response. If the user's palm is not detected within the waiting time, the transaction authorization decision is updated to reject the transaction and an alarm is triggered. If a user's palm is detected within the waiting time, a secondary palm vein near-infrared image is acquired. The same image quality verification operation as in the identity authentication module is performed on the secondary palm vein near-infrared image. If the image quality verification fails, the user is prompted to adjust their palm posture and re-acquire the image. A maximum number of re-acquisitions is preset, which is pre-set by those skilled in the art based on the balance between user experience and security requirements. If the image quality verification still fails after the number of acquisitions of the secondary palm vein near-infrared image exceeds the maximum number of re-acquisitions, the transaction authorization decision is updated to reject the transaction and an alarm is triggered. If the image quality verification is successful, the same preprocessing and texture feature extraction operations as in the identity authentication module are performed on the secondary palm vein near-infrared image to obtain the secondary texture feature vector. The secondary texture feature vector is then subjected to L2 norm normalization to obtain the secondary palm vein texture features. The standard template vector corresponding to the best matching template and the palm vein texture features obtained during the initial authentication are obtained. The cosine similarity between the secondary palm vein texture features and the standard template vector is calculated to obtain the secondary template matching similarity. The cosine similarity between the secondary palm vein texture features and the palm vein texture features is calculated to obtain the consistency similarity. The consistency similarity is used to verify whether the biometric sample collected in the secondary confirmation process and the live sample collected during the initial identity authentication originate from the same hand during a continuous presence process. This prevents attackers from bypassing the secondary confirmation process during the time interval between the initial authentication and secondary confirmation by using deceptive methods such as adding a fake coating to the palm vein sensor surface or replaying pre-recorded palm vein images. A preset threshold for matching the secondary confirmation template and a threshold for consistency before and after confirmation are established. Both thresholds are preset by those skilled in the art based on the security standards for secondary confirmation. If the similarity of the secondary template matching is greater than or equal to the threshold for matching the secondary confirmation template and the similarity of consistency before and after confirmation is greater than or equal to the threshold for consistency before and after confirmation, the secondary confirmation is deemed to have passed, and the transaction authorization decision is updated to direct authorization for cash disbursement. If the similarity of the secondary template matching is less than the threshold for matching the secondary confirmation template or the similarity of consistency before and after confirmation is less than the threshold for consistency before and after confirmation, the secondary confirmation is deemed to have failed, and the transaction authorization decision is updated to reject the transaction and an alarm is triggered.

[0038] The transaction feedback module is used to execute transaction feedback processing based on transaction authorization decisions. Transaction feedback processing includes baseline incremental correction and abnormal transaction risk control processing.

[0039] The methods for processing transaction feedback based on transaction authorization decisions include: Depending on the type of transaction authorization decision, the corresponding transaction feedback processing is executed. Specifically, if the transaction authorization decision is to directly authorize cash disbursement, baseline incremental correction is executed; if the transaction authorization decision is to reject the transaction and trigger an alarm, abnormal transaction risk control processing is executed.

[0040] Methods for performing baseline incremental corrections include: A baseline update suitability assessment is performed on the feature vector of the current transaction behavior to determine whether it is suitable for inclusion in the update calculation of the user's corresponding transaction behavior baseline vector. Specifically, a baseline update deviation upper limit is preset, which is pre-set by those skilled in the art based on the behavior baseline stability maintenance strategy. The behavior deviation score is compared with the baseline update deviation upper limit. If the behavior deviation score is greater than the baseline update deviation upper limit, it is determined that although the operation behavior of the current transaction is authorized, the deviation is too large and it is not suitable for immediate inclusion in the baseline update. The feature vector of the current transaction behavior is marked as a transaction vector to be observed and stored in the transaction queue to be observed. If the behavior deviation score is less than or equal to the baseline update deviation upper limit, it is determined that the operation behavior of the current transaction is within the range of the user's normal habits and is suitable for inclusion in the baseline update. The feature vector of the current transaction behavior is marked as a suitable correction vector. Among them, the baseline update eligibility determination is used to prevent the user's transaction behavior baseline vector from being immediately polluted by authorized transactions due to a large single deviation but a high degree of confidence in identity authentication, thus ensuring that the transaction behavior baseline vector is representative of the user's typical operating habits; the transaction queue to be observed is used to temporarily store the feature vector of the current transaction behavior with a large deviation. When the same user shows similar deviation patterns multiple times in a row, it may indicate that the user's behavior habits are undergoing a real change, and at this time it will be included in the baseline update. For a suitable correction vector, the corresponding adaptive update step size is retrieved from the update step size mapping table based on the number of valid records and the behavioral deviation score. The update step size mapping table is pre-configured by those skilled in the art according to the behavioral baseline evolution strategy and includes update step size values ​​corresponding to combinations of different valid record number intervals and different behavioral deviation score intervals. The valid record number interval is divided into a sparse record interval, a moderate record interval, and a sufficient record interval based on the confidence saturation sample size. The behavioral deviation score interval is divided into a highly fitting interval, a generally fitting interval, and a boundary fitting interval based on the upper limit of the baseline update deviation. The update step size mapping table follows the following configuration principles: the fewer the valid records, the larger the update step size to accelerate baseline convergence; the more valid records, the smaller the update step size to maintain baseline stability; the smaller the behavioral deviation score, the more normal the update step size; and the closer the behavioral deviation score is to the upper limit, the smaller the update step size for prudent inclusion. Based on the adaptive update step size, incremental updates are performed on the baseline reference values ​​of each feature dimension in the baseline reference vector, and collaborative updates are performed on the baseline discrete values ​​of each feature dimension in the baseline discrete vector. Specifically, for each feature dimension, the difference between the corresponding value in the feature vector of the current transaction and the baseline reference value is multiplied by the adaptive update step size to obtain the incremental correction amount for the corresponding feature dimension. The baseline reference value for the corresponding feature dimension is updated based on the sum of the baseline reference value and the corresponding incremental correction amount for each feature dimension. For each feature dimension, the baseline discrete value is updated using the exponential moving average update method, based on the absolute value of the deviation between the corresponding value in the feature vector of the current transaction and the updated baseline reference value, combined with the corresponding baseline discrete value and the adaptive update step size. The exponential moving average is a conventional statistical update method in this field and will not be elaborated on further here.

[0041] Methods for implementing abnormal transaction risk control include: Generate abnormal transaction risk control event records; specifically, assign a risk control event code to the current abnormal transaction, obtain the current system time as the risk control trigger timestamp; obtain the unique device code and device deployment location information of the ATM; integrate the risk control event code, risk control trigger timestamp, unique device code, device deployment location information, unique user code, bound bank card number, identity matching score, behavior deviation score, adjusted cross-risk index, current transaction behavior feature vector, transaction authorization decision and operation event sequence into an abnormal transaction risk control event record; The abnormal transaction risk control event record is classified and labeled with risk level. Specifically, a risk level classification rule is preset, which includes multiple risk levels and their corresponding triggering conditions. Each risk level and triggering condition is preset by a person skilled in the art according to the bank's risk management system. Based on the combination of adjusting the cross-risk index, identity matching score and behavior deviation score, the risk level label of the abnormal transaction is determined according to the risk level classification rule, and the risk level label is attached to the abnormal transaction risk control event record. Abnormal transaction risk control event records are pushed to the bank's security monitoring center in real time; at the same time, abnormal transaction risk control event records are written to the risk control event storage system for persistent archiving.

[0042] This embodiment achieves cardless identity authentication by introducing palm vein recognition technology into bank ATMs. Near-infrared imaging is used to collect the user's subcutaneous vein patterns and match them with a pre-built registration template library. This effectively avoids security risks associated with traditional bank card and password combinations, such as password eavesdropping, lost card fraud, and fingerprint forgery. Simultaneously, a registration consistency score is used to quantitatively evaluate template quality and perform quality-weighted corrections on the matching results, reducing the risk of mismatches due to differences in registration collection quality. After successful identity authentication, full transaction permissions are not immediately granted; instead, multi-dimensional transaction behavior data during the withdrawal process is further collected, including withdrawal amount selection, operation time, key input rhythm, and input correction steps. To align with balance inquiry habits, a structured transaction behavior feature vector is formed. This vector is then used to perform item-by-item deviation analysis with the transaction behavior baseline vector extracted from the user's historical withdrawal records. This effectively compensates for the security gap of lacking continuous verification of the transaction process after identity verification. It can identify abnormal situations where identity verification is successful but the user's behavior deviates from their usual habits. In the deviation analysis, a directional deviation correction mechanism is used to adjust the directional sensitivity of the differentiated indication of security risks based on the deviation direction of different behavioral dimensions. By detecting the co-occurrence pattern of deviations between dimensions, specific security threat scenarios indicated by multi-dimensional collaborative deviations are identified. This effectively overcomes the shortcomings of traditional behavior anomaly detection, which relies on independent evaluation or equal weighting of each dimension and cannot capture combined risk features. This embodiment uses a joint anomaly coupling factor to perform cross-risk assessment of identity matching score and behavioral deviation score, capturing the superlinear risk superposition effect caused by the simultaneous existence of identity authentication uncertainty and behavioral deviation. Combined with an adaptive adjustment mechanism based on the amount gradient, it dynamically adjusts the strictness of risk judgment according to the degree of deviation in the withdrawal amount, achieving deep linkage between the identity authentication dimension and the behavioral verification dimension. This overcomes the shortcomings of identity authentication results and transaction risk control decisions being independent and lacking cross-analysis. Based on the cross-risk index, it implements a three-level differentiated transaction authorization decision: direct authorization of cash disbursement, triggering secondary palm vein confirmation, and transaction rejection with alarm. In the secondary confirmation stage, it simultaneously verifies the matching degree between the collected sample and the registration template. The consistency of the initial authentication sample prevents presentation deception attacks during the time interval between initial authentication and secondary confirmation. After the transaction is completed, the baseline update eligibility judgment and the transaction queue mechanism prevent a single authorized transaction with a large deviation from immediately polluting the user behavior baseline. At the same time, by observing whether subsequent transactions show a consistent deviation pattern, occasional anomalies and continuous habit changes are distinguished, so as to achieve adaptive following of the behavior baseline to the real evolution of user operating habits. Finally, a complete closed-loop secure withdrawal system is built from identity authentication, behavior collection, baseline modeling, cross-validation to feedback correction. While ensuring the convenience of user operation, it comprehensively improves the security protection capability of bank ATM withdrawal transactions. Example 2:

[0043] Please see Figure 2 As shown, parts not described in detail in this embodiment are described in Embodiment 1. A secure cash withdrawal method based on palm vein recognition for bank ATMs is provided, the method including: When a user initiates a withdrawal request, the palm vein pattern features of the user are collected, and the palm vein pattern features are matched with a pre-built registered palm vein template library. Based on the matching results, the user's identity is determined and associated with the corresponding bank account, while the identity matching score is evaluated. After a user enters the withdrawal operation interface, the user's transaction operation behavior data is collected, including the withdrawal amount input value, the duration of stay on the operation interface, the key input rhythm interval sequence and whether the balance is checked, to form a feature vector of the current transaction behavior. Obtain the historical withdrawal records corresponding to the bank accounts associated with the user's identity, and extract the corresponding user's transaction behavior baseline vector from the historical withdrawal records; Based on the current transaction behavior feature vector and the transaction behavior baseline vector, the behavior deviation score is obtained through item-by-item deviation analysis. The behavior deviation score is then cross-validated with the identity matching score, and a transaction authorization decision is generated based on the cross-validation results. Transaction feedback processing is executed based on the transaction authorization decision. Transaction feedback processing includes baseline incremental correction and abnormal transaction risk control processing. Example 3:

[0044] This application also provides an electronic device. The electronic device may include one or more processors and one or more memories. The memories store computer-readable code that, when executed by the one or more processors, can perform the secure withdrawal method for a bank ATM based on palm vein recognition as described above.

[0045] The method or system according to the embodiments of this application can also be implemented using the architecture of the electronic device shown in this application. The electronic device may include a bus, one or more CPUs, ROM, RAM, a communication port connected to a network, input / output, a hard disk, etc. The storage device in the electronic device, such as a ROM or hard disk, may store the secure withdrawal method for bank ATMs based on palm vein recognition provided in this application. Furthermore, the electronic device may also include a user interface. Of course, the architecture shown in this application is merely exemplary; when implementing different devices, one or more components in the electronic device shown in this application may be omitted according to actual needs.

[0046] Example 4

[0047] One embodiment of this application discloses a computer-readable storage medium. The computer-readable storage medium stores computer-readable instructions. When the computer-readable instructions are executed by a processor, a secure withdrawal method for a bank ATM based on palm vein recognition, as described in the above-described embodiments of this application, can be performed. The storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.

[0048] Furthermore, according to embodiments of this application, the processes described in the above-referenced flowcharts can be implemented as computer software programs. For example, this application provides a non-transitory machine-readable storage medium storing machine-readable instructions that can be executed by a processor to perform instructions corresponding to the method steps provided in this application, such as a secure withdrawal method for a bank ATM based on palm vein recognition. When this computer program is executed by a central processing unit (CPU), it performs the functions defined in the method of this application.

[0049] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

[0050] All formulas in this manual are dimensionless and calculated numerically. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters and thresholds in the formulas are set by those skilled in the art according to the actual situation.

[0051] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.

Claims

1. A secure cash withdrawal method for bank ATMs based on palm vein recognition, characterized in that, include: When a user initiates a withdrawal request, the palm vein pattern features of the user are collected, and the palm vein pattern features are matched with a pre-built registered palm vein template library. Based on the matching results, the user's identity is determined and associated with the corresponding bank account, while the identity matching score is evaluated. After a user enters the withdrawal operation interface, the user's transaction operation behavior data is collected, including the withdrawal amount input value, the duration of stay on the operation interface, the key input rhythm interval sequence and whether the balance is checked, to form a feature vector of the current transaction behavior. Obtain the historical withdrawal records corresponding to the bank accounts associated with the user's identity, and extract the corresponding user's transaction behavior baseline vector from the historical withdrawal records; Based on the current transaction behavior feature vector and the transaction behavior baseline vector, the behavior deviation score is obtained through item-by-item deviation analysis. The behavior deviation score is then cross-validated with the identity matching score, and a transaction authorization decision is generated based on the cross-validation results. Transaction feedback processing is executed based on the transaction authorization decision. Transaction feedback processing includes baseline incremental correction and abnormal transaction risk control processing.

2. The secure withdrawal method for bank ATMs based on palm vein recognition according to claim 1, characterized in that, Methods for pre-building a registered palm vein template library include: Obtain the unique user code and bound bank card number of each registered user who has activated the palm vein withdrawal service; obtain the palm vein registration image set collected by each registered user during the registration phase, which contains multiple palm vein near-infrared images; preprocess each palm vein near-infrared image in each palm vein registration image set sequentially to obtain a standardized palm vein image; extract texture features from each standardized palm vein image to obtain a texture feature vector. For each registered user, a registration consistency score is calculated based on the corresponding palm vein registration image set, and the quality of the corresponding palm vein registration image set is determined. The element-wise mean of all texture feature vectors in the qualified palm vein registration image set is calculated to obtain the registration template vector. The registration template vector is normalized to obtain the standard template vector. The standard template vector, user unique code, bound bank card number and registration consistency score of each registered user are integrated to form the palm vein registration template of each registered user, and a registration palm vein template library is constructed by summarizing them.

3. The secure withdrawal method for bank ATMs based on palm vein recognition according to claim 2, characterized in that, Methods for identifying users and linking them to corresponding bank accounts include: When a user initiates a withdrawal request at a bank ATM, a near-infrared image of the palm vein is captured. Image quality is checked on the near-infrared image, and preprocessing is performed on the qualified images to obtain a standardized palm vein image. This standardized image is then input into a pre-trained palm vein feature extraction network to obtain a texture feature vector. Finally, the texture feature vector is normalized to obtain the palm vein texture features. The original matching similarity between the palm vein pattern features and the standard template vector of each palm vein registration template is calculated. The template quality is then weighted and corrected based on the registration consistency score. The corrected matching similarity is used to determine whether the identity authentication is successful. If the identity authentication is successful, the palm vein registration template with the highest corrected matching similarity is taken as the best matching template. The corresponding user unique code and the bound bank card number are extracted to confirm the user's identity and associate it with the bank account.

4. The secure withdrawal method for bank ATMs based on palm vein recognition according to claim 3, characterized in that, Methods for generating feature vectors for a given transaction include: When a user enters the withdrawal operation interface, the transaction behavior recording engine is automatically started to generate the corresponding operation event record. The operation event record includes the operation event type, the operation occurrence timestamp, and additional event data. According to the time sequence of the operation occurrence timestamps corresponding to each operation event record, all operation event records generated by the user in the current withdrawal operation are stored in sequence to form the operation event sequence of the current transaction, and the integrity of the operation event sequence is checked. Based on the sequence of operation events that have passed integrity verification, the withdrawal amount input value, the duration of the operation interface, the key input rhythm interval sequence, and the balance query mark are extracted, and the number of input corrections is calculated. Based on the key input rhythm interval sequence, the average key interval duration and key rhythm fluctuation are extracted. The balance query mark is converted into a numerical form. The withdrawal amount input value, the duration of the operation interface, the average key interval duration, the key rhythm fluctuation, the number of input corrections, and the balance query mark value are arranged in order to form the feature vector of the current transaction behavior.

5. The secure withdrawal method for bank ATMs based on palm vein recognition according to claim 4, characterized in that, Methods for extracting baseline vectors of transaction behavior include: Based on the linked bank card number used when linking the bank account, retrieve all historical withdrawal records associated with the corresponding linked bank card number to form a historical withdrawal record set; perform timeliness filtering and abnormal record removal on the historical withdrawal record set in sequence to obtain a valid historical record set, and perform a record sufficiency determination on the valid historical record set; if the record sufficiency determination fails, obtain the baseline reference vector and baseline discrete vector of the corresponding user from the preset default behavior baseline configuration; If the record sufficiency determination is passed, a corresponding baseline weight is sequentially assigned to each historical withdrawal record in the valid historical record set. Based on the baseline weight and all historical withdrawal records in the valid historical record set, the baseline reference value and baseline discrete value corresponding to each feature dimension in the feature vector of the current transaction behavior are calculated, and a baseline reference vector and a baseline discrete vector are formed. The baseline reference vector and the baseline discrete vector are then integrated to form the transaction behavior baseline vector.

6. The secure withdrawal method for bank ATMs based on palm vein recognition according to claim 5, characterized in that, Methods for obtaining behavioral deviation scores through item-by-item deviation analysis include: For each feature dimension in the current transaction behavior feature vector and the transaction behavior baseline vector, perform a dimension-wise standardized deviation calculation to obtain the standardized deviation of each feature dimension; perform a directed deviation correction on the standardized deviation of each feature dimension to obtain the directed deviation of each feature dimension. Perform inter-dimensional deviation co-occurrence pattern detection on the directed deviation of each feature dimension to obtain the co-occurrence pattern amplification factor; sum the directed deviations of all feature dimensions to obtain the basic deviation total score; and dynamically amplify and correct the basic deviation total score according to the co-occurrence pattern amplification factor to obtain the amplified deviation score. Obtain the number of valid records associated with the baseline vector of transaction behavior and the markers of users with insufficient baseline. Calculate the baseline confidence coefficient based on the number of valid records and the markers of users with insufficient baseline. Adjust the amplified deviation score according to the baseline confidence coefficient to obtain the behavior deviation score.

7. The secure withdrawal method for bank ATMs based on palm vein recognition according to claim 6, characterized in that, Methods for cross-validating behavioral deviation scores and identity matching scores include: Obtain the identity matching score, perform a reverse transformation on the identity matching score to obtain the identity uncertainty; perform a two-factor cross-risk assessment on the identity uncertainty and behavioral deviation score to obtain the cross-risk index; assess the basic cross-risk value and the joint anomaly coupling amount based on the identity uncertainty and behavioral deviation scores respectively; determine the cross-risk index based on the basic cross-risk value, the joint anomaly coupling amount, and the preset coupling amplification coefficient. The cross-risk index is adaptively adjusted based on the withdrawal amount input value: the baseline reference value of the withdrawal amount is obtained from the baseline reference vector, and the baseline discrete value of the withdrawal amount is obtained from the baseline discrete vector; the amount deviation multiple is calculated based on the withdrawal amount input value, the baseline reference value of the withdrawal amount, and the baseline discrete value of the withdrawal amount; the decision boundary adjustment factor is determined based on the amount deviation multiple; the cross-risk index is adaptively adjusted based on the decision boundary adjustment factor to obtain the adjusted cross-risk index.

8. The secure withdrawal method for bank ATMs based on palm vein recognition according to claim 7, characterized in that, Methods for generating transaction authorization decisions based on cross-validation results include: Preset direct authorization risk thresholds and transaction rejection risk thresholds, and compare them with the adjusted cross-risk index; determine the transaction authorization decision based on the comparison results. The transaction authorization decision includes direct authorization of cash disbursement, triggering secondary palm vein collection for transaction confirmation, and rejecting the transaction and triggering an alarm; when secondary palm vein collection for transaction confirmation is triggered, the secondary palm vein confirmation process is executed. The secondary palm vein confirmation process is as follows: First, it is determined whether the user's palm is detected within a preset waiting time. If not, the transaction authorization decision is updated to reject the transaction and an alarm is triggered. If yes, a near-infrared image of the secondary palm vein is acquired, and image quality verification is performed. If the image quality verification is successful, preprocessing, texture feature extraction, and normalization are performed on the near-infrared image of the secondary palm vein to obtain the secondary palm vein texture features. For the secondary palm vein texture features, the secondary template matching similarity between the feature and the standard template vector corresponding to the best matching template, as well as the consistency similarity between the feature and the palm vein texture features, are calculated and compared with the preset secondary confirmation template matching threshold and consistency threshold. Based on the comparison results, the transaction authorization decision is updated to directly authorize cash dispensing or reject the transaction and trigger an alarm.

9. The secure withdrawal method for bank ATMs based on palm vein recognition according to claim 8, characterized in that, The methods for processing transaction feedback based on transaction authorization decisions include: If the transaction authorization decision is to directly authorize cash disbursement, then baseline incremental correction is performed. The method for performing baseline incremental correction is as follows: a baseline update suitability determination is performed on the current transaction behavior feature vector to determine whether it is marked as a suitable correction vector; for a suitable correction vector, the corresponding adaptive update step size is found from the preset update step size mapping table based on the number of valid records and the behavior deviation score; based on the adaptive update step size, the baseline reference values ​​of each feature dimension in the baseline reference vector are incrementally updated, and the baseline discrete values ​​of each feature dimension in the baseline discrete vector are collaboratively updated. If the transaction authorization decision is to reject the transaction and trigger an alarm, then abnormal transaction risk control processing will be performed. The method for performing abnormal transaction risk control processing is as follows: generate an abnormal transaction risk control event record, perform risk level classification and labeling on the abnormal transaction risk control event record, and push the abnormal transaction risk control event record to the bank's security monitoring center in real time.

10. A secure withdrawal system for bank ATMs based on palm vein recognition, implementing the secure withdrawal method for bank ATMs based on palm vein recognition as described in any one of claims 1-9, characterized in that, include: The identity authentication module is used to collect the palm vein pattern features of users when they initiate a withdrawal request, match the palm vein pattern features with a pre-built registered palm vein template library, determine the user's identity and associate it with the corresponding bank account based on the matching results, and evaluate the identity matching score. The feature acquisition module is used to collect user transaction behavior data after the user enters the withdrawal operation interface, including the withdrawal amount input value, the duration of the operation interface, the key input rhythm interval sequence and whether the balance is checked, to form a feature vector of the current transaction behavior. The baseline extraction module is used to obtain the historical withdrawal records corresponding to the bank accounts associated with the user's identity, and extract the corresponding user's transaction behavior baseline vector from the historical withdrawal records; The cross-validation module is used to obtain the behavior deviation score by analyzing the deviation of each item based on the feature vector of the current transaction behavior and the baseline vector of the transaction behavior, and to cross-validate the behavior deviation score with the identity matching score, and generate a transaction authorization decision based on the cross-validation results; The transaction feedback module is used to execute transaction feedback processing based on transaction authorization decisions. Transaction feedback processing includes baseline incremental correction and abnormal transaction risk control processing.