Risk analysis interval determination method, electronic device and computer-readable storage medium
By dynamically adjusting the risk analysis interval of the POS machine, based on the relationship between the risk value and the preset interval, the problem of insufficient flexibility in the traditional POS machine risk analysis interval method is solved, thereby improving the security of funds during the transaction process.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2026-04-02
AI Technical Summary
Traditional POS machine risk analysis intervals are inflexible and cannot effectively address abnormal transaction risks in a rapidly changing payment environment, resulting in low fund security.
By acquiring the client's risk value and preset risk analysis interval, the risk analysis interval is dynamically adjusted. The target interval is negatively correlated with the risk value, and positively correlated with the preset risk interval, thereby improving the flexibility of the risk analysis initiation time.
It improves the flexibility of risk analysis, reduces financial risks during the transaction process, and enhances the security of the trading environment.
Smart Images

Figure CN2025095843_02042026_PF_FP_ABST
Abstract
Description
Risk analysis interval determination method, electronic device, and computer-readable storage medium
[0001] The present application claims priority to the Chinese patent application No. 202411401146.7, filed on September 30, 2024, and entitled "Risk analysis interval determination method, electronic device, and computer-readable storage medium", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the technical field of data analysis, and in particular to a risk analysis interval determination method, an electronic device, and a computer-readable storage medium. BACKGROUND
[0003] A POS (Point of Sales) machine is an indispensable terminal device in modern commercial transactions, and has functions of fund processing and transaction. The POS machine is widely used in supermarkets, department stores, catering enterprises, convenience stores and other commercial scenarios. While improving the convenience of transactions, the POS machine also faces a series of potential security risks, such as pseudo-card fraud, illegal transactions, and illegal card swiping.
[0004] In order to effectively respond to these risks, the server can evaluate the current payment environment of the POS machine. Once the risk analysis result shows that there is an abnormal transaction, the POS machine takes corresponding preventive measures, such as suspending the transaction, issuing a warning pop-up window, and other preventive measures, to block possible abnormal transactions, thereby protecting the fund safety of merchants and consumers. In the traditional technical solution, a preset risk analysis interval is usually set, and the POS machine can periodically initiate a risk analysis request to the server to evaluate the current payment environment. However, abnormal transactions requiring immediate intervention may also occur within the preset risk analysis interval. The traditional risk analysis initiation method has low flexibility in the rapidly changing payment environment, and the fund safety in the transaction process is not high. SUMMARY
[0005] The embodiments of the present application provide a risk analysis interval determination method, an electronic device, and a computer-readable storage medium, which can improve the flexibility of the risk analysis initiation time, thereby reducing the transaction risk and improving the fund safety in the transaction process.
[0006] In a first aspect, the embodiments of the present application provide a risk analysis interval determination method, applied to a payment risk management server, the payment risk management server being in a secure communication connection state with a client, the method comprising: obtaining a risk value of the client and a preset risk analysis interval, the risk value being a risk value carried by a previous risk analysis result corresponding to the client, the risk value being a weighted sum of a plurality of sub-risk values, a plurality of risk items corresponding to the plurality of sub-risk values one by one, the plurality of risk items being different from each other; determining a target interval according to the preset risk analysis interval and the risk value, the target interval being negatively correlated with the risk value, and the target interval being positively correlated with the preset risk interval.
[0007] In some embodiments, the risk value is a sum of the plurality of sub-risk values, the risk value is a positive number, the target interval is proportional to the preset risk interval, and the target interval is inversely proportional to the risk value.
[0008] In some embodiments, before obtaining the risk value of the client and the preset risk analysis interval, the method further comprises: sending a first risk analysis request to the client, the first risk analysis request being used to obtain configuration information of the client; obtaining a plurality of risk items corresponding to the configuration information in response to the received configuration information; sending a first risk collection request to the client, the first risk collection request carrying the plurality of risk items, the first risk collection request being used to instruct the client to collect a plurality of analysis data corresponding to the plurality of risk items, the plurality of analysis data being used to perform risk analysis on the client; performing risk analysis on the client according to the plurality of analysis data in response to the received plurality of analysis data, obtaining a risk analysis result, the risk analysis result carrying the risk value; sending the risk analysis result to the client and storing the risk analysis result.
[0009] In some embodiments, if the risk value is greater than a preset maximum risk threshold, the risk analysis result carries a first termination instruction, the first termination instruction being used to instruct the client to terminate a current transaction; if the risk value is greater than a preset minimum risk threshold and less than or equal to the preset maximum risk threshold, the risk analysis result carries first prompt information, the first prompt information being used to prompt the client that the current transaction has a transaction risk.
[0010] In some embodiments, sending the first risk analysis request to the client comprises: sending the first risk analysis request to the client and recording a time when the first risk analysis request is sent as a first time; after determining the target interval according to the preset risk analysis interval and the risk value, the method further comprises: sending a second risk analysis request to the client at a second time, the second risk analysis request being used to obtain configuration information of the client, the second time being separated from the first time by the target interval, and the second time being a time after the first time.
[0011] In some embodiments, after determining the target interval according to the preset risk analysis interval and the risk value, the method further comprises: determining whether the target interval is greater than the preset risk analysis interval; and if the target interval is greater than the preset risk analysis interval, replacing the target interval with the preset risk analysis interval.
[0012] In some embodiments, the method further comprises: sending a state request to the client at the end of the preset connection period, the state request being used to obtain a transaction state of the client, the transaction state being a payment state or an idle state; receiving the transaction state sent by the client; and if the transaction state indicates that the transaction state of the client is the payment state, sending the first risk analysis request to the client.
[0013] In some embodiments, the sending of the first risk analysis request to the client comprises: receiving a risk analysis instruction input by a user, the risk analysis instruction carrying an identity identifier of the client; and in response to the risk analysis instruction, sending the first risk analysis request to the client according to the identity identifier of the client.
[0014] In a second aspect, an embodiment of the present application provides a risk analysis interval determination apparatus. The risk analysis interval determination apparatus can be a payment risk management server, and the payment risk management server is in a secure communication connection state with a client. The apparatus comprises:
[0015] An obtaining module is configured to obtain a risk value of the client and a preset risk analysis interval. The risk value is a risk value carried by a last risk analysis result corresponding to the client. The risk value is a weighted sum of a plurality of sub-risk values. A plurality of risk items are in one-to-one correspondence with the plurality of sub-risk values. The plurality of risk items are all different.
[0016] A calculating module is configured to determine a target interval according to the preset risk analysis interval and the risk value. The target interval is negatively correlated with the risk value, and the target interval is positively correlated with the preset risk interval.
[0017] In a third aspect, an embodiment of the present application provides an electronic device. The electronic device comprises a processor and a memory. The processor is configured to execute a computer program stored in the memory to implement the method in any one of the first aspect.
[0018] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium. The computer readable storage medium stores a computer program. When the computer program is executed by a processor, the method in any one of the first aspect is implemented.
[0019] In the technical scheme provided in the embodiments of the present application, the payment risk management server can obtain a risk value carried by a previous risk analysis result of the client and a preset risk analysis interval, and determine a target interval according to the preset risk analysis interval and the risk value. The target interval is negatively correlated with the risk value, and the target interval is positively correlated with the preset risk interval. In the embodiments of the present application, the risk value can be used to represent the risk of the client at the previous risk analysis, so as to determine the risk trend of the client. According to the calculation principle that the target interval is negatively correlated with the risk trend of the client and the target interval is positively correlated with the preset risk interval, the payment risk management server can determine the target interval according to the preset risk analysis interval and the risk value. In this way, the flexibility of the risk analysis initiation time is improved, the transaction risk is reduced, and the security of the fund in the transaction process is improved. BRIEF DESCRIPTION OF DRAWINGS
[0020] In order to more clearly illustrate the technical scheme in the embodiments of the present application, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0021] FIG. 1 is a system architecture schematic diagram of a risk analysis interval determination method provided by an embodiment of the present application;
[0022] FIG. 2 is a data interaction schematic diagram of a risk analysis interval determination method provided by an embodiment of the present application;
[0023] FIG. 3 is a data interaction schematic diagram of another risk analysis interval determination method provided by an embodiment of the present application;
[0024] FIG. 4 is a flow schematic diagram of a risk analysis interval determination method provided by an embodiment of the present application;
[0025] FIG. 5 is a function relationship schematic diagram of a risk analysis interval determination method provided by an embodiment of the present application;
[0026] FIG. 6 is another function relationship schematic diagram of a risk analysis interval determination method provided by an embodiment of the present application;
[0027] FIG. 7 is a structure schematic diagram of a risk analysis interval determination apparatus provided by an embodiment of the present application;
[0028] FIG. 8 is a structure schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0029] In the following description, for purposes of explanation and not limitation, specific details are set forth such as particular architectures, techniques, etc. in order to provide a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application can be practiced in other embodiments that depart from these specific details. In other instances, detailed descriptions of well-known methods, devices, circuits, and
[0030] It is to be understood that the terminology "includes", "has", "holds", "contains" or "comprising", "including", "having" and the like, when used in the present specification and in the accompanying claims, are used in the sense of "including but not limited to", "including but not limited to", "including but not limited to" and "including but not limited to" respectively, and should be construed as specifically setting forth the stated features, integers, steps or components but not precluding one or more additional features, integers, steps, components and / or groups thereof.
[0031] It is also to be understood that the terminology "and / or" when used in the present specification and in the accompanying claims, refers to one and / or other of the associated listed items, as well as to all possible combinations of the associated listed items.
[0032] As used in the present specification and in the accompanying claims, the term "if" can be interpreted as meaning "when" or "once" or "in response to a determination" or "in response to detecting" depending on the context. Similarly, the phrase "if it is determined" or "if [a described condition or event] is detected" can be interpreted to mean "once it is determined" or "in response to a determination" or "once [the described condition or event] is detected" or "in response to detecting [a described condition or event]", depending on the context.
[0033] In addition, in the description of the application in the specification and in the attached claims, the terms "first", "second", "third", etc. are used only to distinguish descriptions and cannot be understood as indicating or implying relative importance.
[0034] Reference in the specification to "one embodiment" or "some embodiments" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. The appearances of the phrase "in one embodiment" or "in some embodiments" in various places in the specification are not necessarily all referring to the same embodiment, although it can. The terms "including", "containing", "comprising", "having" and variations thereof in the specification are meant to encompass the terms "including but not limited to", "including but not limited to", "including but not limited to" and "including but not limited to", respectively, unless otherwise expressly specified.
[0035] The payment risk management server is one of important infrastructures for ensuring payment security. The payment risk management server can identify potential payment risks and take corresponding measures for risk prevention and control to ensure the security and stability of the payment process by monitoring and analyzing multi-dimensional information such as transaction data, user behavior, and payment environment of a payment terminal device such as a POS (Point of Sale) and a COTS (Commercial Off-The-Shelf).
[0036] In the conventional technical solution, the payment terminal device (hereinafter referred to as "client") such as a POS and a COTS can initiate a risk analysis request to the payment risk management server (hereinafter referred to as "server") at regular intervals. The server performs risk analysis on the client after receiving the risk analysis request. According to the risk analysis result, the server takes corresponding risk defense measures and risk control measures to improve the security of the transaction environment of the payment terminal device such as a POS and a COTS.
[0037] However, there is a risk of abnormal transactions within the preset risk analysis interval. The conventional technical solution cannot prevent abnormal transaction risks occurring within the preset risk analysis interval. The flexibility of the risk analysis initiation mode is low, and the security of the payment risk management server is not high.
[0038] Therefore, the embodiments of the present application provide a risk analysis interval determination method to improve the flexibility of the risk analysis initiation time, thereby reducing transaction risks, improving the security of funds during transactions, and improving the security of the risk management server.
[0039] The technical solutions of the embodiments of the present application will be described below in conjunction with examples in the drawings.
[0040] FIG. 1 is a schematic diagram of a system architecture of a risk analysis interval determination method according to an embodiment of the present application. As shown in FIG. 1, the system architecture of the risk analysis interval determination method can include two parts of a client and a server. The client and the server are in a communication connection state. For example, the client and the server can be connected in communication through a secure channel. The client can be installed with an application program for interacting with the server. The application program can include a development tool library for collecting a plurality of analysis data and sending the plurality of analysis data to the server for risk analysis by the server.
[0041] The service end can include a test module, a monitoring module, an application access module, a message agent module and an encryption machine module. The test module can be used to analyze a plurality of analysis data to determine a risk analysis result. The monitoring module is used to monitor a plurality of risk items and send monitoring results of the plurality of risk items to the test module. The application access module is used to access the test module by the application. The message agent module is used to receive a risk analysis instruction sent by the test module and send the risk analysis instruction to a message queue. The encryption machine module is used to generate random numbers and asymmetric keys.
[0042] FIG. 2 is a data interaction schematic diagram of a risk analysis interval determination method provided by an embodiment of the present application. As shown in FIG. 2, the data interaction process of the risk analysis interval determination method provided by the present application can be that a service end, a client end and an application development end, a user can execute an application development process through the application development end. The service end can include a risk management system, a security management system and a development system. The data interaction process of the risk analysis interval determination method provided by the present application can include the following processes:
[0043] A1: The application development end sends an account registration request to the security management system of the service end.
[0044] The account registration request is used to register an account of a developed application on the service end, so as to realize subsequent development of the application.
[0045] A2: The security management system of the service end responds to the received account registration request, executes an account registration process, and sends account registration success information to the application development end and sends resources required for developing the application to the development system.
[0046] The risk management system is used to execute the account registration process to realize registration of the application development account. The resources required for developing the application can include an SDK (Software Development Kit, software development tool library).
[0047] A3: The application development end sends an application development request to the development system of the service end according to the account registration success information.
[0048] In the embodiment of the present application, the application development end can send an application development request to the development system of the service end to instruct the development system to execute an application development process to obtain an application package.
[0049] A4: The development system of the service end sends the application package to the security management system of the service end.
[0050] In the embodiment of the present application, after obtaining the application package, the development system of the service end sends the application package to the security management system, so that the client end can obtain and download the application package.
[0051] A5: The security management system of the server responds to the received application package and records the application package.
[0052] In the embodiment, the security management system of the server can perform the application package recording process through interaction with the risk management system.
[0053] A6: The risk management system of the server sends a ciphertext to the security management system, and the ciphertext represents that the application package has been recorded successfully.
[0054] A7: The client sends an application acquisition request to the security management system of the server to acquire the application package.
[0055] A8: The security management system of the server responds to the received application acquisition request and sends the application package to the client.
[0056] A9: The client responds to the received application package, installs the application package, and sends an initialization verification request to the security management system of the server.
[0057] A10: The security management system of the server responds to the received initialization verification request, generates an identity identifier, and sends the identity identifier to the client.
[0058] After the server receives the initialization verification request, the server can determine whether the current application is a recorded application according to the initialization verification request. If the current application is a recorded application, the server generates a unique identity identifier, which is a random number. The server sends the identity identifier to the client. After the client receives the identity identifier, the client establishes a communication connection with the server according to the identity identifier. The server can perform risk analysis on the client in the communication connection state and generate a risk analysis result.
[0059] FIG. 3 is a data interaction diagram of another risk analysis interval determination method provided by the embodiment. As shown in FIG. 3, the process of establishing a secure communication connection between the client and the server can include the following steps:
[0060] B1: The client sends an access preparation request to the server, and the access preparation request is used to request to establish a communication connection with the server.
[0061] B2: The server responds to the received access preparation request and performs access preparation processing.
[0062] In the embodiment, the server can determine whether the current access environment is in a secure state according to the access preparation request. If the determination result is that the current access environment is in a secure state, the server outputs secure access information.
[0063] B3: The server sends the secure access information to the client.
[0064] B4: The client generates a key pair in response to the received secure access information.
[0065] The key pair can include a public key and a private key, and the key pair is used to mark the initialization verification request to implement establishment of the communication connection.
[0066] B5: The client signs the initialization verification request by using the private key in the key pair.
[0067] B6: The client sends the initialization verification request and the public key to the server.
[0068] B7: The server determines whether the current application is a registered application according to the initialization verification request in response to the received initialization verification request.
[0069] B8: If the current application is a registered application, the server verifies the received public key and the initialization verification request.
[0070] B9: If the verification result of the public key and the initialization verification request is passed, the server generates a certificate according to the public key and the initialization verification request.
[0071] B10: If the verification result of the public key and the initialization verification request is passed, the server sends the certificate to the client.
[0072] B11: The client determines the validity of the certificate by using the secure configuration module in response to the received certificate, and saves the certificate if the certificate is determined to be a valid certificate, so as to establish a secure connection with the server.
[0073] FIG. 4 is a flow diagram of a risk analysis interval determination method provided by an embodiment of the present application. As shown in FIG. 4, the risk analysis interval determination method provided by the present application can include the following steps:
[0074] Step S401: Obtain a risk value of a client and a preset risk analysis interval, wherein the risk value is a risk value carried by a last risk analysis result corresponding to the client, the risk value is a weighted sum of a plurality of sub-risk values, a plurality of risk items are in one-to-one correspondence with the plurality of sub-risk values, and the plurality of risk items are different from each other.
[0075] The risk analysis interval determination method provided by the embodiment of the present application can be applied to a payment risk management server, i.e., a server, and the server and the client are in a secure communication connection state. The client can be a POS, a COTS, or the like.
[0076] In the embodiment of the present application, the preset risk analysis interval can be a fixed value, for example, the preset risk analysis interval of the POS, the COTS, or the like can be 5 minutes. The preset risk analysis interval can also be other time values, and the specific value of the preset risk analysis interval is not limited in the present application.
[0077] The server can send a risk analysis request to the payment terminal device such as POS and COTS every 5 minutes to determine the risk value of the payment terminal device such as POS and COTS at the current time. After calculating the current risk value of the payment terminal device such as POS and COTS, the risk value is stored, and a plurality of risk values corresponding to a plurality of time nodes can be recorded. For example, for the first POS machine, the plurality of risk values corresponding to the first POS machine stored by the server can include: time node 17:25-risk value 9.5, time node 17:30-risk value 9.2, time node 17:35-risk value 9.7, time node 17:40-risk value 9.4, …, time node 19:35-risk value 9.5. If the current time is 19:40, the last time the server initiates risk analysis is 19:35, and the risk value carried by the last risk analysis result obtained by the server is 9.5.
[0078] In some embodiments, the initiator of the risk analysis request can also be the client (POS machine), and the application does not limit the initiator of the risk analysis request.
[0079] The application takes the server as an example of the initiator of the risk analysis request, and exemplarily describes the process of calculating the risk analysis result by the server.
[0080] For example, taking the client as the first POS machine, the interaction process between the server and the client (first POS machine) when the server obtains the risk value of the first POS machine in the last risk analysis process can include the following steps:
[0081] C1: The server sends a first risk analysis request to the client, and the first risk analysis request is used to obtain configuration information of the client.
[0082] In the embodiment of the application, the server can record the time when the first risk analysis request is successfully sent to the client as the first time after sending the first risk analysis request to the client. The time when the first risk analysis request is sent to the client (first POS machine) can also be recorded as the first time, which is not limited in the application.
[0083] C2: The client obtains the configuration information in response to the received first risk analysis request, and sends the configuration information to the server.
[0084] After receiving the first risk analysis request, the client (first POS machine) obtains the configuration information of the current device (first POS machine). The configuration information can include one or more of the device model, software version, and processor category of the first POS machine, and the application does not limit the content of the configuration information.
[0085] In the embodiment of the present application, the client can be in a communication connection state with the external card reader, and obtain the configuration information through the external card reader. For example, the client can be in a Bluetooth communication connection state with the external card reader. In the embodiment of the present application, the process of establishing a communication connection state between the client and the external card reader can refer to steps B1 to B11 described above, which will not be repeated here.
[0086] C3: The server obtains a plurality of risk items corresponding to the configuration information in response to the received configuration information.
[0087] In the embodiment of the present application, a preset risk item correspondence table can be provided, and a plurality of different risk items can be provided in the preset risk item correspondence table. The server can obtain a plurality of risk items corresponding to the configuration information from the preset risk item correspondence table according to the received configuration information. For example, the server can determine a plurality of risk items corresponding to the device model of the client according to the device model of the client in the configuration information.
[0088] For example, the preset risk item correspondence table can be as shown in Table 1, including risk item name, collection specification, risk analysis method and device model. The risk item name corresponds to the collection specification and the risk analysis method one by one. The collection specification is used to represent the analysis data content to be collected corresponding to the risk item, and the risk analysis method is the method for the server to analyze the risk item.
[0089] Table 1
[0090] As shown in Table 1, the server can determine 18 risk items corresponding to the model A according to the device model of the client in the configuration information, which are: whether Root or jailbreak, whether emulator, whether cloned device, whether there is non-secure application, whether low version system, whether downgraded system, whether tampered system, whether network change, central processing, memory, battery, whether Hook application, whether record application, whether tampered application, whether risk application, whether load unnecessary class library, security random number health check and application security key consistency.
[0091] C4: The server sends a first risk collection request to the client, the first risk collection request carries a plurality of risk items, and the first risk collection request is used to instruct the client to collect a plurality of analysis data corresponding to the plurality of risk items, and the plurality of analysis data is used for risk analysis of the client.
[0092] For example, the plurality of analysis data can be the analysis data corresponding to the collection specification, as shown in Table 1. For example, if the plurality of risk items includes "whether Root or jailbroken", the required data in the corresponding collection specification is the data information corresponding to the device information, Root and jailbroken flag.
[0093] C5: In response to the received first risk collection request, the client collects a plurality of analysis data corresponding to a plurality of risk items, and sends the plurality of analysis data to the server.
[0094] For example, the first risk item in the plurality of risk items received by the client is "whether Root or jailbroken", and the analysis data corresponding to the first risk item collected by the client includes: basic information of the device, such as device name, device model, serial number, manufacturer, date of manufacture, etc. Technical parameters of the device, such as device specifications, performance indicators, and use environment. Use and management information of the device, such as purchase date, supplier information, use department, maintenance record, fault record, etc. Additional information of the device, such as device location, warranty period, software version, etc. Whether the device has Root permission, and whether the device is jailbroken.
[0095] C6: In response to the received plurality of analysis data, the server performs risk analysis on the client according to the plurality of analysis data, and obtains a risk analysis result, wherein the risk analysis result carries a risk value.
[0096] In an embodiment of the present application, the server can analyze the plurality of analysis data one by one according to the plurality of analysis data corresponding to the plurality of risk items, and obtain a plurality of risk sub-values corresponding to the plurality of analysis data, and the sum of the plurality of risk sub-values is the risk value of the risk analysis result.
[0097] For example, the calculation formula of the risk value f(r) can be Formula 1:
[0098] Wherein, n represents the number of the plurality of risk items, r i represents the risk sub-value corresponding to the i-th analysis data.
[0099] For example, continuing to refer to Table 1, the number of the plurality of risk items is 18, and the server can receive 18 pieces of analysis data. The server can analyze the 18 risk items one by one according to the 18 pieces of analysis data. For the first risk item "whether Root or jailbroken", the first analysis data corresponding to the first risk item contains Root = true and jailbroken = false, and the server can determine that the client has obtained the Root permission but the client is not jailbroken. The server can determine that the sub-risk value corresponding to the first analysis data is 1. For the second risk item "whether an emulator", the second analysis data corresponding to the second risk item carries the information that the device is an emulator, and the server can determine that the sub-risk value corresponding to the second analysis data is 1. For the eighteenth risk item "application security key consistency", the eighteenth analysis data corresponding to the eighteenth risk item carries the information that the application security key fingerprint is consistent with the system record, and the server can determine that the sub-risk value corresponding to the eighteenth analysis data is 0. The server analyzes the 18 risk items one by one, and adds the 18 sub-risk values. It can be known that the risk value is 9.5, and the server can determine that the risk analysis result carries the risk value 9.5.
[0100] C7: The server sends the risk analysis result to the client and stores the risk analysis result.
[0101] After the server sends the risk analysis result to the client, the server can also store the risk analysis result to facilitate obtaining the risk value.
[0102] In the embodiments of the present application, a preset risk threshold interval can be preset. If the risk value is greater than a preset maximum risk threshold in the preset risk threshold interval, the risk analysis result carries a first termination instruction, and the first termination instruction is used to instruct the client to terminate the current transaction. If the risk value is greater than a preset minimum risk threshold and less than or equal to the preset maximum risk threshold in the preset risk threshold interval, the risk analysis result carries a first prompt information, and the first prompt information is used to prompt the client that the current transaction has a transaction risk. If the risk value is less than or equal to the preset minimum risk threshold in the preset risk threshold interval, the risk analysis result does not carry any instruction or prompt information.
[0103] For example, the preset risk threshold interval is (7, 15]. If the risk value is 17, the risk analysis result carries the first termination instruction. If the risk value is 9.5, the risk analysis result carries the first prompt information. If the risk value is 6, the risk analysis result does not carry any instruction or prompt information.
[0104] S402: Determine a target interval according to a preset risk analysis interval and a risk value, the target interval is negatively correlated with the risk value, and the target interval is positively correlated with the preset risk interval.
[0105] In the embodiments of the present application, in order to shorten the interval of risk analysis when the risk trend of the POS machine rises, that is, to shorten the risk analysis interval, so as to reduce the fund safety of the merchant and the consumer in the high-risk situation. When the risk trend of the POS machine decreases, the interval of risk analysis is extended, that is, the risk analysis interval is extended, so as to save computing power, reduce operation and maintenance cost, and improve risk analysis efficiency. It can be known that the target interval (risk analysis interval) is negatively correlated with the risk trend of the POS machine. In the embodiments of the present application, the risk trend can be represented by the risk value of the client. In the embodiments of the present application, the risk trend of the POS machine can be represented by the risk value of the client.
[0106] Therefore, the calculation formula of the target interval f(x) can be Formula Two:
[0107] Wherein, x represents the risk trend, that is, the risk value f(r) in Formula One, b represents the preset risk analysis interval, and a is a preset value.
[0108] In the embodiments of the present application, when the risk value x is positive, the target interval f(x) is proportional to the preset risk analysis interval, and the target interval f(x) is inversely proportional to the risk value x.
[0109] For example, when the preset risk analysis interval b is 5 and the preset value a is 1, the functional relationship between the target interval f(x) and the risk value x can be as shown in FIG. 5, which is a functional relationship diagram of one of the risk analysis interval determination methods provided by the embodiments of the present application. The horizontal axis represents the risk value x, and the vertical axis represents the target interval f(x).
[0110] In the embodiments of the present application, when the risk value x is positive, the functional relationship between the target interval f(x) and the risk value x can be as shown in FIG. 6, which is another functional relationship diagram of the risk analysis interval determination method provided by the embodiments of the present application. The horizontal axis represents the risk value x, and the vertical axis represents the target interval f(x). As shown in FIG. 6, the closer the risk value x is to 0, the closer the target interval f(x) is to the maximum value b, that is, the preset risk analysis interval. The larger the risk value x is, the smaller the target interval f(x) is. When the preset risk analysis interval b is 5 and the risk value x is 0, the target interval f(x) is the same as the preset risk analysis interval b.
[0111] When the time of the last risk analysis is N, the time of the next risk analysis is f(x)+N. For example, when the time of the last risk analysis is 19:35, the target interval f(x) is 4, and the time of the next risk analysis can be determined as 19:39, that is, the first time is 19:35 and the second time is 19:39.
[0112] In the embodiments of the present application, the preset value a can also be other values, that is, when the risk value x and the preset risk analysis interval b are determined values, the value of the target interval f(x) depends on the preset value a, and the preset value a can be set according to the risk scenario and the POS. In the embodiments of the present application, the server can set different preset values a according to the actual risk analysis scenario and / or the categories of different POSs, COTS and the like payment terminals, and the specific values of the preset value a are not limited herein.
[0113] In the technical solutions provided by the embodiments of the present application, the payment risk management server can obtain the risk value carried by the last risk analysis result of the client and the preset risk analysis interval, and determine the target interval according to the preset risk analysis interval and the risk value. The target interval is negatively correlated with the risk value, and the target interval is positively correlated with the preset risk interval. In the embodiments of the present application, the risk value can be used to represent the risk of the client at the last risk analysis, so as to determine the risk trend of the client. According to the calculation principle that the target interval is negatively correlated with the risk trend of the client and the target interval is positively correlated with the preset risk interval, the payment risk management server can determine the target interval according to the preset risk analysis interval and the risk value. Thus, the flexibility of the risk analysis initiation time is improved, the transaction risk is reduced, and the security of the funds in the transaction process is improved.
[0114] In the embodiments of the present application, after determining the target interval according to the preset risk analysis interval and the risk value, it can be further judged whether the target interval is greater than the preset risk analysis interval. If the target interval is greater than the preset risk analysis interval, the preset risk analysis interval is used to replace the target interval.
[0115] For example, according to the calculation formula of the target interval f(x) If the preset value a is a negative number and the absolute value of the preset value a is less than x, the target interval f(x) is greater than the preset risk analysis interval b, and the server can replace the target interval f(x) with the preset risk analysis interval b. For example, if the target interval f(x) is 8 and the preset risk analysis interval b is 5, the target interval f(x) can be set to 5.
[0116] In the technical solutions provided by the embodiments of the present application, when the target interval is greater than the preset risk analysis interval, the preset risk analysis interval is used to replace the target interval, which can avoid the situation that the preset risk analysis interval is too long and the transaction risk is too high, thereby further improving the security of the funds.
[0117] In the embodiments of the present application, the payment risk management server and the client are in a secure communication connection state, the payment risk management server can monitor the transaction state of the client in real time, and initiate the first risk analysis request according to the transaction state of the client. The specific interaction process between the payment risk management server and the client can include the following steps:
[0118] D1: The payment risk management server sends a state request to the client at the end of a preset connection period, the state request being used to acquire a transaction state of the client, the transaction state being a payment state or an idle state.
[0119] D2: The client acquires the transaction state in response to the received state request, and sends the transaction state to the payment risk management server.
[0120] D3: The payment risk management server receives the transaction state sent by the client, and judges whether the transaction state is the payment state, and sends a first risk analysis request to the client if the transaction state is the payment state.
[0121] In the embodiments of the present application, if the payment risk management server determines that the transaction state is a non-payment state, the payment risk management server does not send the first risk analysis request to the client.
[0122] In the technical scheme provided by the embodiments of the present application, the payment risk management server (server) can monitor the transaction state of the client in real time, and send the first risk analysis request to the client when the transaction state of the client is the payment state, so as to evaluate the current payment environment. The payment risk management server (server) obtains the risk analysis result, and sends the first termination instruction or the first prompt information when the risk analysis result is abnormal, so as to block the abnormal transaction that may exist, thereby protecting the fund safety of the merchant and the consumer.
[0123] In the technical scheme provided by the embodiments of the present application, the user can also send the first risk analysis request to any client that establishes a secure communication connection with the payment risk management server through the payment risk management server, so as to evaluate the payment environment in front of the client. Specifically, the user can input the identity identifier of the client into the payment risk management server (server) to initiate the risk analysis instruction to the payment risk management server. After receiving the risk analysis instruction input by the user, the payment risk management server sends the first risk analysis request to the client in response to the risk analysis instruction according to the identity identifier of the client. The technical scheme provided by the present application can improve the flexibility of the risk analysis initiation mode, thereby further improving the security of the payment environment.
[0124] It should be understood that, without logical conflicts, each of the above embodiments can be combined with each other to adapt to actual application requirements. The specific embodiments or implementation schemes obtained by the combination still belong to the protection scope of the present application.
[0125] Corresponding to the risk analysis interval determination method in the above embodiment, an embodiment of the present application provides a risk analysis interval determination apparatus 70, which can be realized by software, hardware or a combination of both as part of or all of a computer device, for executing the steps in the risk analysis interval determination method in the above embodiment.
[0126] FIG. 7 shows a structural schematic diagram of a risk analysis interval determination apparatus provided by an embodiment of the present application. The risk analysis interval determination apparatus can be a payment risk management server. The payment risk management server is in a secure communication connection state with a client. For ease of illustration, only parts related to the embodiments of the present application are shown.
[0127] Referring to FIG. 7, the risk analysis interval determination apparatus 70 includes an acquisition module 710 and a calculation module 720.
[0128] The acquisition module 710 is configured to acquire a risk value of the client and a preset risk analysis interval. The risk value is a risk value carried by a last risk analysis result corresponding to the client. The risk value is a weighted sum of a plurality of sub-risk values. A plurality of risk items are in one-to-one correspondence with the plurality of sub-risk values. The plurality of risk items are different from each other.
[0129] The calculation module 720 is configured to determine a target interval according to the preset risk analysis interval and the risk value. The target interval is negatively correlated with the risk value. The target interval is positively correlated with the preset risk interval.
[0130] In some embodiments, the risk value is a sum of the plurality of sub-risk values. The risk value is a positive number. The target interval is directly proportional to the preset risk interval. The target interval is inversely proportional to the risk value.
[0131] The calculation module 720 is further configured to: send a first risk analysis request to the client. The first risk analysis request is used to acquire configuration information of the client. In response to the received configuration information, acquire a plurality of risk items corresponding to the configuration information. Send a first risk collection request to the client. The first risk collection request carries the plurality of risk items. The first risk collection request is used to instruct the client to collect a plurality of analysis data corresponding to the plurality of risk items. The plurality of analysis data is used to perform risk analysis on the client. In response to the received plurality of analysis data, perform risk analysis on the client according to the plurality of analysis data to obtain a risk analysis result. The risk analysis result carries the risk value. Send the risk analysis result to the client and store the risk analysis result.
[0132] The computing module 720 is further configured to: if the risk value is greater than a preset maximum risk threshold, the risk analysis result carries a first termination instruction, the first termination instruction being used to instruct the client to terminate the current transaction; and if the risk value is greater than a preset minimum risk threshold and less than or equal to the preset maximum risk threshold, the risk analysis result carries a first prompt information, the first prompt information being used to prompt the client that the current transaction has a transaction risk.
[0133] The computing module 720 is further configured to: send a first risk analysis request to the client, and record a time when the first risk analysis request is sent as a first time; and after determining the target interval according to the preset risk analysis interval and the risk value, the computing module 720 is further configured to: send a second risk analysis request to the client at a second time, the second risk analysis request being used to acquire the configuration information of the client, the second time being separated from the first time by the target interval, and the second time being a time after the first time.
[0134] The computing module 720 is further configured to: determine whether the target interval is greater than the preset risk analysis interval; and if the target interval is greater than the preset risk analysis interval, replace the target interval with the preset risk analysis interval.
[0135] The computing module 720 is further configured to: send a state request to the client at an end time of the preset connection period, the state request being used to acquire a transaction state of the client, the transaction state being a payment state or an idle state; receive the transaction state sent by the client; and if the transaction state indicates that the transaction state of the client is the payment state, send the first risk analysis request to the client.
[0136] The computing module 720 is further configured to: receive a risk analysis instruction input by a user, the risk analysis instruction carrying an identity identifier of the client; and in response to the risk analysis instruction, send the first risk analysis request to the client according to the identity identifier of the client.
[0137] It should be noted that the information interaction, execution process and the like among the above apparatuses / units are based on the same concept as the method embodiments of the present application, and the specific functions and the technical effects brought by the same can be referred to the method embodiments part, and will not be described here.
[0138] It should be understood that the size of the serial number of each step in the above embodiments does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0139] Based on the same inventive concept, the embodiments of the present application also provide an electronic device.
[0140] FIG. 8 is a structural schematic diagram of an electronic device provided in an embodiment of the present application. As shown in FIG. 8, the electronic device 80 of this embodiment includes at least one processor 810 (only one processor is shown in FIG. 8), a memory 820, and a communication module 840, and the memory 820 stores a computer program 830 which can run on the processor 810. The processor 810 implements the steps in the risk analysis interval determination method embodiments described above, for example, steps S401-S402 shown in FIG. 4, when executing the computer program 830. Alternatively, the processor 810 implements the functions of the modules / units in the various device embodiments described above, for example, the functions of the modules 710-720 shown in FIG. 7, when executing the computer program 830, and the communication module 840 can be a separate communication unit for communicating with an external server or terminal device.
[0141] The electronic device 80 can include, but is not limited to, the processor 810 and the memory 820. Those skilled in the art can understand that FIG. 8 is merely an example of the electronic device 80 and does not limit the electronic device 80, which can include more or fewer components than those shown, or combine some components, or different components, for example, the electronic device 80 can also include an input sending device, a network access device, a bus, etc.
[0142] The processor 810 can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic components, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0143] The memory 820 can be an internal storage unit of the electronic device 80, such as a hard disk or a memory of the electronic device 80 in some embodiments. The memory 820 can also be an external storage device of the electronic device 80, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device 80. The memory 820 can also include both the internal storage unit and the external storage device of the electronic device 80. The memory 820 is used to store an operating system, an application program, a boot loader, data, and other programs, such as program codes of the computer program 830, etc. The memory 820 can also be used to temporarily store data that has been transmitted or will be transmitted.
[0144] In addition, it can be clearly understood by those skilled in the art that, for the convenience and brevity of description, only the division of the above functional units and modules is taken as an example, and in actual application, the above functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. The functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0145] The embodiments of the present application provide a computer readable storage medium, which stores a computer program. When the computer program is executed on an electronic device, the electronic device executes the steps in each of the method embodiments.
[0146] The embodiments of the present application provide a chip, which includes a processor and a memory. The memory stores a computer program. When the computer program is executed by the processor, the steps in each of the method embodiments are implemented.
[0147] The embodiments of the present application provide a computer program product. When the computer program product is executed on an electronic device, the electronic device executes the steps in each of the method embodiments.
[0148] It should be appreciated that a processor as referred to herein can be a Central Processing Unit (CPU), a general purpose processor, a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or the like. The general purpose processor can be a microprocessor or the processor can be any conventional processor.
[0149] It should also be appreciated that a memory as referred to herein can be a volatile or non-volatile memory, or can include both volatile and non-volatile memory. Non-volatile memory can be Read-only Memory (ROM), Programmable ROM (PROM), Erasable PROM (EPROM), Electrically EPROM (EEPROM), or flash memory. Volatile memory can be Random access Memory (RAM), which is used as external cache. By way of example, and not limitation, many forms of RAM are available, for example, Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).
[0150] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of each functional unit and module is exemplified, and in actual application, the above-mentioned functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be realized in the form of hardware or software. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction, and do not limit the protection scope of the present application. The specific working process of the unit and module in the above system can refer to the corresponding process in the foregoing method embodiment, which will not be described here.
[0151] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described or recorded in detail in a certain embodiment can be referred to the related description of other embodiments.
[0152] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0153] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the system embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division, and actual implementation can have another division manner. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.
[0154] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0155] In addition, each of the function units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.
[0156] The integrated unit, if realized in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, all or part of the processes in the above-mentioned embodiment methods can be completed by instructing related hardware through a computer program, and the computer program can be stored in a computer readable storage medium. When the computer program is executed by a processor, the steps of each method embodiment described above can be implemented. The computer program includes computer program code, which can be in the form of source code, object code, executable files or some intermediate forms. The computer readable medium at least includes any entity or device capable of carrying the computer program code to the large screen device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium. For example, U disk, mobile hard disk, magnetic disk or optical disk, etc. In some jurisdictions, according to legislation and patent practice, the computer readable medium can not be an electrical carrier signal and a telecommunication signal.
[0157] Finally, it should be noted that: the above is only a specific embodiment of the present application, but the protection scope of the present application is not limited to this, any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method of risk analysis interval determination, characterized by, The method is applied to a payment risk management server in a secure communication connection with a client, and comprises: obtaining a risk value of the client and a preset risk analysis interval, the risk value being a risk value carried by a last risk analysis result corresponding to the client, the risk value being a weighted sum of a plurality of sub-risk values, a plurality of risk items corresponding to the plurality of sub-risk values one by one, and the plurality of risk items being different from each other; determining a target interval according to the preset risk analysis interval and the risk value, the target interval being negatively correlated with the risk value, and the target interval being positively correlated with the preset risk interval.
2. The method of claim 1, wherein, The risk value is the sum of the plurality of sub-risk values, the risk value is a positive number, the target interval is proportional to the preset risk interval, and the target interval is inversely proportional to the risk value.
3. The method of claim 1, wherein, Before obtaining the risk value of the client and the preset risk analysis interval, the method further comprises: sending a first risk analysis request to the client, the first risk analysis request being used to obtain configuration information of the client; obtaining the plurality of risk items corresponding to the configuration information in response to the received configuration information; sending a first risk collection request to the client, the first risk collection request carrying the plurality of risk items, the first risk collection request being used to instruct the client to collect a plurality of analysis data corresponding to the plurality of risk items, the plurality of analysis data being used for risk analysis of the client; performing risk analysis on the client according to the plurality of analysis data to obtain a risk analysis result, the risk analysis result carrying the risk value, in response to the received plurality of analysis data; sending the risk analysis result to the client and storing the risk analysis result.
4. The method of claim 3, wherein, The method further comprises: if the risk value is greater than a preset maximum risk threshold, the risk analysis result carries a first termination instruction, the first termination instruction being used to instruct the client to terminate a current transaction; if the risk value is greater than a preset minimum risk threshold and less than or equal to the preset maximum risk threshold, the risk analysis result carries a first prompt information, the first prompt information being used to prompt the client that there is a transaction risk in the current transaction.
5. The method of claim 3, wherein, The method further comprises: sending the first risk analysis request to the client and recording a time when the first risk analysis request is sent as a first time; after determining the target interval according to the preset risk analysis interval and the risk value, the method further comprises: sending a second risk analysis request to the client at a second time, the second risk analysis request being used to obtain configuration information of the client, the second time being separated from the first time by the target interval, and the second time being a time after the first time.
6. The method of claim 1, wherein, After determining the target interval according to the preset risk analysis interval and the risk value, the method further comprises: determining whether the target interval is greater than the preset risk analysis interval; if the target interval is greater than the preset risk analysis interval, the preset risk analysis interval is used to replace the target interval.
7. The method according to any one of claims 1 to 6, characterized in that, The method further comprises: sending a state request to the client at a termination time of a preset connection period, the state request being used to acquire a transaction state of the client, the transaction state being a payment state or an idle state; receiving the transaction state sent by the client; if the transaction state represents that the transaction state of the client is the payment state, sending the first risk analysis request to the client.
8. The method of claim 7, wherein, The sending of the first risk analysis request to the client comprises: receiving a risk analysis instruction input by a user, the risk analysis instruction carrying an identity identifier of the client; in response to the risk analysis instruction, sending the first risk analysis request to the client according to the identity identifier of the client.
9. An electronic device, comprising: The computer program is executed by the processor to implement the method as claimed in any one of claims 1 to 8.
10. A computer-readable storage medium storing a computer program, the computer program comprising instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 9. The computer program is executed by the processor to implement the method as claimed in any one of claims 1 to 8.
Citation Information
Patent Citations
Risk identification method of electronic equipment and server
CN111104664A
Abnormity detection method, abnormity detection device and terminal equipment
CN111556059A
Access control method and device, equipment and storage medium
CN115374426A
Risk analysis interval determination method, electronic equipment and computer readable storage medium
CN119379294A
Risk management system and method
US20240289719A1