WO2020147586A1 - 风险交易处理方法、装置及设备 - Google Patents

风险交易处理方法、装置及设备 Download PDF

Info

Publication number
WO2020147586A1
WO2020147586A1 PCT/CN2020/070028 CN2020070028W WO2020147586A1 WO 2020147586 A1 WO2020147586 A1 WO 2020147586A1 CN 2020070028 W CN2020070028 W CN 2020070028W WO 2020147586 A1 WO2020147586 A1 WO 2020147586A1
Authority
WO
WIPO (PCT)
Prior art keywords
transaction
communication
data
information
user
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2020/070028
Other languages
English (en)
French (fr)
Inventor
陈春宝
陈卉佳
彭姝雯
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alibaba Group Holding Ltd
Original Assignee
Alibaba Group Holding Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alibaba Group Holding Ltd filed Critical Alibaba Group Holding Ltd
Publication of WO2020147586A1 publication Critical patent/WO2020147586A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4014Identity check for transactions
    • G06Q20/40145Biometric identity checks
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q40/00Finance; Insurance; Tax strategies; Processing of corporate or income taxes
    • G06Q40/04Trading; Exchange, e.g. stocks, commodities, derivatives or currency exchange

Definitions

  • This manual relates to the field of Internet transaction technology, especially to risk transaction processing methods, devices and equipment.
  • a risk transaction processing method including:
  • the target user After determining that the transaction initiated by the target user is a risky transaction, obtain communication information of the target user, and initiate communication based on the communication information;
  • the determining whether the transaction passes security authentication according to the interaction data includes:
  • the interaction data it is determined whether the communication counterparty user and the target user are the same user, so as to determine whether the transaction passes the security authentication.
  • the determining whether the transaction passes security authentication according to the interaction data includes:
  • the safety authentication data includes: authentication question data;
  • the determining whether the transaction passes security authentication according to the interaction data includes:
  • the authentication question data is set based on the corresponding answer data being a number.
  • the communication information includes a trusted mobile phone number
  • the initiating communication based on the communication information includes:
  • the trusted mobile phone number is determined based on the following information:
  • the method before the initiating communication, the method further includes:
  • the phone number that initiated the call is used to perform security authentication for the transaction.
  • Optional also includes:
  • the method further includes:
  • a risk transaction processing method including:
  • the communication advance notice information is displayed, and the communication advance notice information is used to indicate that the service party needs to initiate communication based on the communication information of the target user, and perform security authentication for the transaction.
  • Optional also includes:
  • a communication confirmation portal is displayed, through which a message indicating whether the user accepts the communication is obtained and sent to the server for the server to determine whether to initiate a communication.
  • the communication notice information includes:
  • the phone number that initiated the call is used to perform security authentication for the transaction.
  • a risk transaction processing device including:
  • the communication module is configured to: after determining that the transaction initiated by the target user is a risk transaction, obtain communication information of the target user, and initiate communication based on the communication information;
  • the data acquisition module is configured to: after establishing a communication connection with the communication peer, send security authentication data to the communication peer, and obtain interactive data fed back by the communication peer based on the security authentication data;
  • the authentication module is used to determine whether the transaction passes security authentication according to the interaction data.
  • the authentication module is used for:
  • the interaction data it is determined whether the communication counterparty user and the target user are the same user, so as to determine whether the transaction passes the security authentication.
  • the authentication module is used for:
  • the safety authentication data includes: authentication question data;
  • the authentication module is used for:
  • the authentication question data is set based on the corresponding answer data being a number.
  • the communication information includes a trusted mobile phone number
  • the communication module is used for:
  • the trusted mobile phone number is determined based on the following information:
  • the communication module is further configured to: before initiating the communication, make a pre-communication notice for one or more of the following information:
  • the phone number that initiated the call is used to perform security authentication for the transaction.
  • the device further includes a blocking module for:
  • the authentication module is also used for:
  • a risk transaction processing device including:
  • the obtaining module is used to: obtain transaction information of the transaction initiated by the target user;
  • the advance notice module is configured to: after determining that the transaction is a risky transaction based on the transaction information, display the communication advance notice information.
  • the communication advance notice information is used to instruct the service party to initiate a communication based on the target user’s communication information, and respond to this The transaction undergoes security certification.
  • the preview module is also used to:
  • a communication confirmation portal is displayed, through which a message indicating whether the user accepts the communication is obtained and sent to the server for the server to determine whether to initiate a communication.
  • the communication notice information includes:
  • the phone number that initiated the call is used to perform security authentication for the transaction.
  • a computer device including a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor implements the aforementioned Risk transaction processing method.
  • the user of the risk transaction can actively initiate communication, by sending security authentication data to the communication peer, to obtain the interactive data fed back by the communication peer based on the security authentication data, and determine the location based on the interactive data. State whether the transaction passed the security certification.
  • This embodiment provides an active security service in the transaction process, which can actively initiate communication to the user, and obtain the user's interaction data based on security authentication through the user's participation. On the one hand, it can alert the user and determine whether the transaction passes the security authentication. Directly release risks in the transaction process, reduce the magnitude of manual handling afterwards, and ease the pressure on the server; on the other hand, further security certification for risky transactions can reduce transaction risks.
  • Fig. 1A is a flowchart of a risk transaction processing method according to an exemplary embodiment of the present specification.
  • Fig. 1B is a schematic diagram of a risk transaction shown in this specification according to an exemplary embodiment.
  • Fig. 2A is a flowchart of another risk transaction processing method shown in this specification according to an exemplary embodiment.
  • FIG. 2B to FIG. 2D are schematic diagrams showing a risk transaction processing according to an exemplary embodiment of this specification.
  • Fig. 3 is a structural block diagram of a computer device where a risk transaction processing device is shown according to an exemplary embodiment of this specification.
  • Fig. 4 is a block diagram of a risk transaction processing device according to an exemplary embodiment of the present specification.
  • Fig. 5 is a block diagram of another risk transaction processing device shown in this specification according to an exemplary embodiment.
  • first, second, third, etc. may be used to describe various information in this specification, the information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other.
  • first information may also be referred to as second information, and similarly, the second information may also be referred to as first information.
  • word “if” as used herein can be interpreted as "when” or “when” or “in response to a determination”.
  • the risk control model identifies risks after the transaction is initiated
  • measures such as interception and blocking (such as freezing accounts, failed transactions), suspension confirmation (such as secondary identity authentication) or approval are adopted;
  • the user can provide evidence to the customer service phone, and the transaction can be re-initiated after passing.
  • the embodiments of this specification provide a more flexible method for processing risk transactions, which can initiate communication with users of risk transactions, and send security authentication data to the communication peer to obtain feedback from the communication peer based on the security authentication data. According to the interaction data, it is determined whether the transaction passes the security authentication.
  • FIG. 1A is a flowchart of a risk transaction processing method according to an exemplary embodiment of this specification, including the following steps:
  • step 102 after determining that the transaction initiated by the target user is a risky transaction, the communication information of the target user is obtained, and communication is initiated based on the communication information.
  • step 104 after the communication connection is established with the communication peer, the security authentication data is sent to the communication peer, and the interaction data fed back by the communication peer based on the security authentication data is obtained.
  • step 106 it is determined whether the transaction passes the security authentication according to the interaction data.
  • the solution of the embodiment of this specification can be applied to a business system that provides transaction services.
  • the execution subject of the above steps may specifically include a server or a client, and there is no restriction on whether it is executed only on one end.
  • the solution of this embodiment is to further authenticate the security of the transaction through active communication and interaction with the user after the risky transaction is discovered. Due to the active communication method, after determining that the transaction initiated by the target user is a risky transaction, the target user’s communication information can be obtained, and the communication can be initiated based on the communication information, which can alert the user and determine whether the transaction has passed security authentication. Directly release risks during the transaction, reduce the magnitude of manual handling afterwards, and ease the pressure on the server.
  • the way of initiating communication can be flexibly configured as required, and optionally, it can be voice communication to achieve the effect of voice interaction with the user. Specifically, it may be voice communication combined with video or pure voice communication.
  • the server can initiate network communication to the client. This method requires the client and the server to be in a connected state; as an example, the user initiates a transaction through a browser in a personal computer.
  • the solution in this embodiment may require the user Use the client terminal of a mobile device such as a smart phone to log in to the server, and the server obtains the communication information of the target user, which can specifically include the communication address of the user’s common device (such as IP address, device MAC address), and the server can be based on communication
  • the address initiates network communication to the client, such as a voice call or a video call.
  • the user can log in to the server to initiate a transaction, and the server can directly initiate voice communication to the client.
  • the communication information may be the user's trusted mobile phone number, and the server may initiate a call to the trusted mobile phone number.
  • this embodiment can be implemented by intelligent voice technology, and an intelligent call program can be pre-configured to automatically initiate a phone call, reducing manual pressure.
  • the user may have one or more mobile phone numbers.
  • the trusted mobile phone number of the target user can be determined to prevent call errors and ensure that the correct user can be called.
  • the selectable mobile phone number of the target user may be determined based on the following information: the mobile phone number bound to the account of the target user, the mobile phone number that has been in contact with the customer service, the home location information of the mobile phone number, or the binding duration of the mobile phone number.
  • the account of the target user may be bound to one or more mobile phone numbers, and the binding time of each mobile phone number can be obtained for comprehensive consideration; it can also be obtained by obtaining the historical contact records of the target user and customer service calls to use the historical contact records Obtain which phone number the target user uses to contact the customer service; as multiple mobile phone numbers of the target user are involved, further comprehensive consideration can be made based on the attribution information of the mobile phone number, and the mobile phone number that matches the user's common location will be more optional .
  • a trusted mobile phone model can be established as needed.
  • the trusted mobile phone model can be bound to the mobile phone according to the Alipay account, recent calls and customer service communication mobile phones, device fingerprints and mobile phone numbers when using the Alipay account Information such as the home location information of the mobile phone number and the binding time of the mobile phone number are used as features to determine the mobile phone number that the user is actually using, and to determine the call to the correct user.
  • the initiated communication may be able to successfully establish a communication connection, or may not be able to establish a communication connection.
  • a communication connection cannot be established with the communication peer one or more times, because the transaction cannot be authenticated safely through interaction with the user, the transaction can be directly blocked.
  • security authentication data may be sent to the communication peer, and interaction data fed back by the communication peer based on the security authentication data may be obtained.
  • the above processing takes into account that the risk control model is only judged based on transaction information, and the risk model does not directly determine the transaction as a risk transaction through user interaction. This embodiment hopes to interact with the user through active communication and through the user’s participation. Further more reliable security certification for transactions.
  • the security authentication may be a live authentication of the communication peer user, which may be determining whether the communication peer user and the target user are the same user, or The communication peer-side user inquires to further confirm the risk of the transaction and so on.
  • the security authentication data can be flexibly configured as required to obtain the interaction data fed back by the communication peer based on the security authentication data.
  • the communication peer may be required to speak to obtain the voice data of the communication peer as the interaction data.
  • the service party may obtain the user's voice data in advance in multiple ways to extract voice features that characterize the user's identity.
  • you can also make a video call with the communication peer collect video data by acquiring the camera, obtain the facial features of the user on the communication peer from the video data, and compare the facial features of the user on the communication peer to the target The user's facial features are matched, and it is determined whether the transaction passes the security authentication according to the matching result.
  • the user on the communication peer side and the target user may be verified by means of question and answer, wherein the security authentication data may include: authentication question data; the determining whether the transaction passes the security authentication according to the interaction data includes : After obtaining the answer data sent by the communication peer end, according to the matching result of the answer data sent by the communication peer end and the answer data corresponding to the authentication question data, it is determined whether the transaction passes the security authentication.
  • the authentication question data may be a voice data characterizing the question. After the voice data is played, the user will answer the question.
  • the user may answer the question by voice in actual implementation, or the user may trigger the device The virtual keyboard is displayed for answering and so on.
  • the authentication question data in this embodiment can be set based on the corresponding answer data being numbers, for example, it can be authentication question data that characterizes asking for ID number, asking for random numbers, asking for age, etc., because the answer to such question data is Numbers can be easily entered by the user through the numeric keyboard, thereby improving processing efficiency.
  • the authentication question data can be a voice data that characterizes the user's ID number
  • the communication peer device can play the authentication question data
  • the communication peer device can also display a numeric keyboard for the user to input the corresponding answer
  • the server of the communication can obtain the answer data of the opposite end of the communication to identify whether the number entered by the user matches the ID number of the user who initiated the transaction through the answer data.
  • the authentication question data can be a voice data representing a random number, which can be generated in real time as needed, and intelligent voice technology can be used to generate voice data representing the random number, which can be played by the communication peer device
  • the authentication question data so that the user can input the corresponding random number after listening to the authentication question data;
  • the communication peer device can also display a numeric keyboard for the user to input;
  • the server that initiates the communication can obtain the communication peer
  • the answer data is used to identify whether the number entered by the user matches the generated random number through the answer data.
  • the communication counterparty user and the target user are the same user, whether the object initiating the transaction is a live user, or whether the target user actually initiates a transaction to prevent account embezzlement. It serves as a safety warning before the user actually makes a payment.
  • the server may further include: a pre-communication notice for one or more of the following information: initiation The phone number of the call, the trusted mobile phone number, the identity of the service party that initiated the call, or the call is used for security authentication for the transaction.
  • initiation The phone number of the call, the trusted mobile phone number, the identity of the service party that initiated the call, or the call is used for security authentication for the transaction.
  • the above reminder can be implemented in the device where the target user initiates the transaction.
  • Figure 1B it is a schematic diagram of a client provided in an embodiment of this specification. The target user uses the client to initiate a transaction, which can be displayed by the client.
  • the notice in Figure 1B shows "0571-88880123” which characterizes the phone number that initiated the call, "187****1234" which characterizes the trusted mobile phone number, and "187****1234" which characterizes the identity of the service party that initiated the call. "Alipay”, which characterizes that this call is used for transaction-specific security authentication, "To ensure transaction security, please use 187****1234 to answer Alipay calls and verify your identity according to the prompts.”
  • a window can be output on the service page to display the above reminder. Through the above reminder, the user can be informed that the server is about to initiate a communication to perform security authentication on the transaction, thereby increasing the probability of communication connection, improving communication efficiency, and preventing users from rejecting communication.
  • this specification does not limit the execution subject of the above risk transaction processing embodiment; the following further provides another risk transaction processing embodiment from the perspective of the client.
  • This embodiment can be applied to the client, when the user uses the client After the client initiates the transaction, the client can execute the method of the embodiment shown in FIG. 2A, which includes the following steps:
  • step 202 the transaction information of the transaction initiated by the target user is obtained.
  • step 204 after it is determined that the transaction is a risk transaction based on the transaction information, the communication advance notice information is displayed, and the communication advance notice information is used to indicate that the service party needs to initiate communication based on the communication information of the target user and respond to the transaction. Carry out safety certification.
  • This embodiment can be applied to a client that provides transaction functions.
  • the user can initiate a transaction through the client.
  • the client determines the target user’s account, transaction location, transaction time, and transaction amount.
  • the risk control model can be used to identify the risk and type of the transaction, where the risk identification process of the transaction can be executed on the client side or on the server side. If it is executed on the server, the client can receive the recognition result of the transaction from the server, and if it is executed on the client, the client can send the recognition result to the server.
  • the service party needs to further initiate communication for the transaction for security authentication.
  • the client can display the communication notice information, which is used to indicate that the server needs to initiate communication based on the target user's communication information, and perform security authentication for this transaction.
  • the communication advance notice information may be stored locally on the client side, or may be obtained from the server side.
  • the user uses the client to initiate a transaction.
  • the server can determine whether the transaction is suitable for communication authentication.
  • conditions Can include:
  • the risk control model determines that this transaction complies with the combination of fraud and theft or fraud scenarios, and the original core product is no longer valid;
  • the user who initiated the transaction has a trusted mobile phone number, which can ensure that the voice is dialed to the user himself.
  • the server can use the client to perform a pre-communication notice to notify the user that the server will interact with his phone, and the user decides whether to answer according to the environment.
  • the notification content may include:
  • the serving party's identity can be the name of the serving party, abbreviation or other names well known to the user.
  • the content of the copywriting is to remind that this call is used for transaction-specific security authentication.
  • this exchange is an identity verification to ensure the safety of funds.
  • Answer option optionally, this embodiment provides a communication confirmation portal through which a message indicating whether the user accepts the communication is obtained and sent to the server for the server to determine whether to initiate a communication; in Figure 2B , The communication confirmation entry includes an option of "answer immediately” and an option of "cannot answer". By providing this answer option, it can be triggered by the user to confirm that the user is willing to accept the incoming call.
  • the server After being connected, the server successfully establishes a communication connection with the communication peer, and can further interact with the user, including one or more of the following:
  • the server After the server generates a random number, it generates voice data representing the random number and sends it to the communication peer, so that the communication peer device can play the voice data, and the user enters the random number for the voice broadcast;
  • the server generates voice data that characterizes the ID number and sends it to the communication peer for playback, so that the user can input the ID number according to the voice prompt; or it can be used to compare the voice print after the user speaks.
  • authentication question data can be generated and sent to the communication peer to play, so that the user can speak according to the voice prompt to provide answer data, so as to further perform security authentication through the answer data;
  • the server processes the transaction according to the actual voice interaction, including:
  • the solution provided in this embodiment can be combined with risk prevention and control strategies to solve the difficulties of social work and fraud risk control.
  • Social worker deception and fraud caused by information leakage are the main causes of transaction risks.
  • Black industry gangs pretend to be merchants, public security law, or use fraudulent techniques such as increasing quotas, handling loans and large credit cards to defraud users of information such as SMS verification codes or ID documents. It is difficult to prevent such risks due to user participation by cheating or unconsciously helping the criminal group to pass the identity authentication.
  • risk control system due to the protection of the risk control system, users are in a state of unawareness and protection, and exposure continues to exist after risk exposure, which is prone to secondary risks.
  • risk control models detect transaction risks, due to the consideration of transaction experience, they may not block all of them or require identity authentication. In the case of low risk ratings, small amounts, or certain periods, some risks may be approved Transaction: For users who do not pay attention to the account, they cannot immediately perceive the risk, and the account has not been taken to strengthen the security measures. The risk control system may also judge this transaction as a safe transaction due to lack of user feedback, and it will happen again next time It may continue to approve at that time, resulting in a secondary risk.
  • the scheme of this embodiment can use authentication technologies such as voiceprint, voice+X (X can be a random number, ID card, security issue, etc.) in the above embodiment to authenticate transactions safely through actively initiated communication, so that black production gangs The security certification cannot be bypassed.
  • Direct communication through voice interaction can arouse users' safety awareness and further reduce the chance of users being cheated.
  • voice authentication technology can reduce the failure rate of security verification and improve user payment experience.
  • the account security level can be increased through active reminders. Aiming at a large number of low-immune accounts, people who are vulnerable to scams/frauds, and people exposed to daily risks, due to lack of suitable access methods, they will be ignored until risk occurs.
  • voice to carry out due diligence reminders and active communication is helpful in advance Resolve risks while enhancing users’ sense of security.
  • the active and secure service provided by the solution in this embodiment is compared with the traditional risk identification process—account management and control—the defensive risk control process in which users prove themselves or call evidence, through active reminders beforehand, active communication during the event, and afterwards follow up with caring active security services, establish a closed-loop risk control process involving user participation, and solve risk control problems such as information leakage and social worker deception.
  • this specification also provides embodiments of the risk transaction processing device and the terminal to which it is applied.
  • the embodiments of the risk transaction processing apparatus in this specification can be applied to computer equipment, such as servers or terminal equipment.
  • the device embodiments can be implemented by software, or by hardware or a combination of software and hardware. Taking software implementation as an example, as a logical device, it is formed by reading the corresponding computer program instructions in the non-volatile memory into the memory by the processor that processes the file where it is located.
  • FIG. 3 a hardware structure diagram of the computer equipment where the risk transaction processing device is located in this manual, except for the processor 310, memory 330, network interface 320, and non-volatile memory shown in Figure 3
  • the server or electronic device where the device 331 is located in the embodiment may also include other hardware generally according to the actual function of the computer device, which will not be repeated here.
  • Fig. 4 is a block diagram of a risk transaction processing device according to an exemplary embodiment of the present specification, and the device includes:
  • the communication module 41 is configured to: after determining that the transaction initiated by the target user is a risk transaction, obtain communication information of the target user, and initiate communication based on the communication information;
  • the data acquisition module 42 is configured to: after establishing a communication connection with the communication peer, send security authentication data to the communication peer, and obtain interactive data fed back by the communication peer based on the security authentication data;
  • the authentication module 43 is configured to determine whether the transaction passes security authentication according to the interaction data.
  • the authentication module is used for:
  • the interaction data it is determined whether the communication counterparty user and the target user are the same user, so as to determine whether the transaction passes the security authentication.
  • the authentication module is used for:
  • the safety authentication data includes: authentication question data;
  • the authentication module is used for:
  • the authentication question data is set based on the corresponding answer data being a number.
  • the communication information includes a trusted mobile phone number
  • the communication module is used for:
  • the trusted mobile phone number is determined based on the following information:
  • the communication module is further configured to: before initiating the communication, give a pre-communication reminder to one or more of the following information:
  • the phone number that initiated the call is used to perform security authentication for the transaction.
  • the device further includes a blocking module for:
  • the authentication module is also used for:
  • Fig. 5 is a block diagram of a risk transaction processing device shown in this specification according to an exemplary embodiment, and the device includes:
  • the obtaining module 51 is configured to: obtain transaction information of a transaction initiated by a target user;
  • the advance notice module 52 is configured to: after determining that the transaction is a risky transaction based on the transaction information, display the communication advance notice information, where the communication advance notice information is used to indicate that the service party needs to initiate communication based on the target user’s communication information, and to Security certification for this transaction.
  • the preview module is also used to:
  • a communication confirmation portal is displayed, through which a message indicating whether the user accepts the communication is obtained and sent to the server for the server to determine whether to initiate a communication.
  • the communication notice information includes:
  • the phone number that initiated the call is used to perform security authentication for the transaction.
  • the device embodiment since it basically corresponds to the method embodiment, please refer to the part of the description of the method embodiment for related parts.
  • the device embodiments described above are merely illustrative.
  • the modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in One place, or it can be distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the objectives of the solution in this specification. Those of ordinary skill in the art can understand and implement it without creative work.

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Engineering & Computer Science (AREA)
  • Finance (AREA)
  • Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • Development Economics (AREA)
  • Technology Law (AREA)
  • Marketing (AREA)
  • Economics (AREA)
  • Computer Security & Cryptography (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Hardware Redundancy (AREA)
  • Lift-Guide Devices, And Elevator Ropes And Cables (AREA)
  • Telephonic Communication Services (AREA)

Abstract

一种风险交易处理方法、装置及设备,能够对风险交易的用户发起通信,通过向通信对端发送安全认证数据,以获取通信对端基于所述安全认证数据反馈的交互数据,并根据所述交互数据确定所述交易是否通过安全认证。能够主动向用户发起通信,通过用户的参与获取到用户基于安全认证的交互数据,一方面可以警示用户并确定交易是否通过安全认证,在交易过程中直接释放风险,减少事后再人工处置的量级,缓解服务端压力;另一方面对风险交易进一步安全认证,能够降低交易风险。

Description

风险交易处理方法、装置及设备 技术领域
本说明书涉及互联网交易技术领域,尤其涉及风险交易处理方法、装置及设备。
背景技术
随着网络技术的发展,用户通过网络进行交易变得越来越方便,网络交易在给用户带来便利的同时,也带来了一定的风险。网络交易等业务系统中
通常会有一套风险防控体系,在识别出用户的交易具有风险后,用户的交易会被阻断。基于此,需要提供一种更灵活的风险交易处理方案。
发明内容
为克服相关技术中存在的问题,本说明书提供了风险交易处理方法、装置及设备。
根据本说明书实施例的第一方面,提供一种风险交易处理方法,所述方法包括:
确定目标用户发起的交易为风险交易后,获取所述目标用户的通信信息,基于所述通信信息发起通信;
在与通信对端建立通信连接后,向所述通信对端发送安全认证数据,获取所述通信对端基于所述安全认证数据反馈的交互数据;
根据所述交互数据确定所述交易是否通过安全认证。
可选的,所述根据所述交互数据确定所述交易是否通过安全认证,包括:
根据所述交互数据确定通信对端侧用户与所述目标用户是否为同一用户,以确定所述交易是否通过安全认证。
可选的,所述根据所述交互数据确定所述交易是否通过安全认证,包括:
获取通信对端侧的语音数据后,获取所述语音数据的声纹特征与所述目标用户的声纹特征的匹配结果,根据匹配结果确定所述交易是否通过安全认证。
可选的,所述安全认证数据包括:认证问题数据;
所述根据所述交互数据确定所述交易是否通过安全认证,包括:
获取通信对端侧的答案数据后,根据所述通信对端侧的答案数据与所述认证问题数据对应答案数据的匹配结果,确定所述交易是否通过安全认证。
可选的,所述认证问题数据基于对应答案数据为数字而设定。
可选的,所述通信信息包括可信手机号码;
所述基于所述通信信息发起通信,包括:
向所述可信手机号码发起呼叫。
可选的,所述可信手机号码基于如下信息确定:
与目标用户的账户绑定的手机号码、与客服联系过的手机号码、手机号码的归属地信息或手机号码的绑定时间。
可选的,在所述发起通信前,还包括:
对如下一种或多种信息进行通信前的预告:
发起呼叫的电话号码、所述可信手机号码、发起呼叫的服务方标识或本次呼叫用于进行针对交易的安全认证。
可选的,还包括:
若与通信对端一次或多次无法建立通信连接,阻断所述交易。
可选的,所述方法还包括:
若所述交易通过安全验证,执行交易流程;
若所述交易未通过验证,阻止所述交易。
根据本说明书实施例的第二方面,提供一种风险交易处理方法,包括:
获取目标用户发起的交易的交易信息;
在基于所述交易信息确定所述交易为风险交易后,展示通信预告信息,所述通信预告信息用于指示服务方需要基于目标用户的通信信息发起通信,并对本次交易进行安全认证。
可选的,还包括:
展示通信确认入口,通过所述通信确认入口获取指示用户是否接受通信的消息并发送给服务方,以供服务方确定是否发起通信。
可选的,所述通信预告信息包括:
发起呼叫的电话号码、所述可信手机号码、发起呼叫的服务方标识或本次呼叫用于进行针对交易的安全认证。
根据本说明书实施例的第三方面,提供一种风险交易处理装置,包括:
通信模块,用于:确定目标用户发起的交易为风险交易后,获取所述目标用户的通信信息,基于所述通信信息发起通信;
数据获取模块,用于:在与通信对端建立通信连接后,向所述通信对端发送安全认证数据,获取所述通信对端基于所述安全认证数据反馈的交互数据;
认证模块,用于:根据所述交互数据确定所述交易是否通过安全认证。
可选的,所述认证模块,用于:
根据所述交互数据确定通信对端侧用户与所述目标用户是否为同一用户,以确定所述交易是否通过安全认证。
可选的,所述认证模块,用于:
获取通信对端侧的语音数据后,获取所述语音数据的声纹特征与所述目标用户的声纹特征的匹配结果,根据匹配结果确定所述交易是否通过安全认证。
可选的,所述安全认证数据包括:认证问题数据;
所述认证模块,用于:
获取通信对端侧的答案数据后,根据所述通信对端侧的答案数据与所述认证问题数据对应答案数据的匹配结果,确定所述交易是否通过安全认证。
可选的,所述认证问题数据基于对应答案数据为数字而设定。
可选的,所述通信信息包括可信手机号码;
所述通信模块,用于:
向所述可信手机号码发起呼叫。
可选的,所述可信手机号码基于如下信息确定:
与目标用户的账户绑定的手机号码、与客服联系过的手机号码、手机号码的归属地信息或手机号码的绑定时间。
可选的,所述通信模块,还用于:在发起所述通信前,对如下一种或多种信息进行通信前的预告:
发起呼叫的电话号码、所述可信手机号码、发起呼叫的服务方标识或本次呼叫用于进行针对交易的安全认证。
可选的,所述装置还包括阻断模块,用于:
若与通信对端一次或多次无法建立通信连接,阻断所述交易。
可选的,所述认证模块,还用于:
若所述交易通过安全验证,执行交易流程;
若所述交易未通过验证,阻止所述交易。
根据本说明书实施例的第四方面,提供一种风险交易处理装置,所述装置包括:
获取模块,用于:获取目标用户发起的交易的交易信息;
预告模块,用于:在基于所述交易信息确定所述交易为风险交易后,展示通信预告信息,所述通信预告信息用于指示服务方需要基于目标用户的通信信息发起通信,并对本次交易进行安全认证。
可选的,所述预告模块还用于:
展示通信确认入口,通过所述通信确认入口获取指示用户是否接受通信的消息并发送给服务方,以供服务方确定是否发起通信。
可选的,所述通信预告信息包括:
发起呼叫的电话号码、所述可信手机号码、发起呼叫的服务方标识或本次呼叫用于进行针对交易的安全认证。
根据本说明书实施例的第五方面,提供一种计算机设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,其中,所述处理器执行所述程序时实现前述风险交易处理方法。
本说明书的实施例提供的技术方案可以包括以下有益效果:
本说明书实施例中,能够对风险交易的用户主动发起通信,通过向通信对端发送安全认证数据,以获取通信对端基于所述安全认证数据反馈的交互数据,并根据所述交互数据确定所述交易是否通过安全认证。本实施例提供了一种在交易过程中的主动安全 服务,能够主动向用户发起通信,通过用户的参与获取到用户基于安全认证的交互数据,一方面可以警示用户并确定交易是否通过安全认证,在交易过程中直接释放风险,减少事后再人工处置的量级,缓解服务端压力;另一方面对风险交易进一步安全认证,能够降低交易风险。
应当理解的是,以上的一般描述和后文的细节描述仅是示例性和解释性的,并不能限制本说明书。
附图说明
此处的附图被并入说明书中并构成本说明书的一部分,示出了符合本说明书的实施例,并与说明书一起用于解释本说明书的原理。
图1A是本说明书根据一示例性实施例示出的一种风险交易处理方法的流程图。
图1B是本说明书根据一示例性实施例示出的一种风险交易示意图。
图2A是本说明书根据一示例性实施例示出的另一种风险交易处理方法的流程图。
图2B至图2D是本说明书根据一示例性实施例示出的一种风险交易处理示意图。
图3是本说明书根据一示例性实施例示出的一种风险交易处理装置所在计算机设备的结构框图。
图4是本说明书根据一示例性实施例示出的一种风险交易处理装置的框图。
图5是本说明书根据一示例性实施例示出的另一种风险交易处理装置的框图。
具体实施方式
这里将详细地对示例性实施例进行说明,其示例表示在附图中。下面的描述涉及附图时,除非另有表示,不同附图中的相同数字表示相同或相似的要素。以下示例性实施例中所描述的实施方式并不代表与本说明书相一致的所有实施方式。相反,它们仅是与如所附权利要求书中所详述的、本说明书的一些方面相一致的装置和方法的例子。
在本说明书使用的术语是仅仅出于描述特定实施例的目的,而非旨在限制本说明书。在本说明书和所附权利要求书中所使用的单数形式的“一种”、“所述”和“该”也旨在包括多数形式,除非上下文清楚地表示其他含义。还应当理解,本文中使用的术语“和/或”是指并包含一个或多个相关联的列出项目的任何或所有可能组合。
应当理解,尽管在本说明书可能采用术语第一、第二、第三等来描述各种信息,但这些信息不应限于这些术语。这些术语仅用来将同一类型的信息彼此区分开。例如,在不脱离本说明书范围的情况下,第一信息也可以被称为第二信息,类似地,第二信息也可以被称为第一信息。取决于语境,如在此所使用的词语“如果”可以被解释成为“在……时”或“当……时”或“响应于确定”。
移动互联、密码技术、大数据和人工智能等新技术的快速发展,丰富了支付手段也提高了支付效率,但同时带来了新的风险隐患,对交易风险防控提出了更高要求。目前交易风险包括有欺诈类风险,主要是非本人交易和本人恶意进行的不当交易,例如账户盗用、伪卡欺诈、失窃卡欺诈、非面欺诈、营销欺诈、商户合谋等;还有一类是合规风险,主要是违反法律法规或监管要求的不当交易,例如洗钱、电信诈骗、非法集资、套现或移机切机等。
为应对这些风险,业务系统可以通过交易行为分析、机器学习等方式不断优化风控模型,提高欺诈交易拦截成功率和安全防护能力;在流程上通常采取防御型管控措施,以交易风险管控为例:
1)交易发起后风控模型识别风险;
2)根据风险类型和风险评级采取拦截阻断(如冻结账户、失败交易)、挂起确认(如二次身份认证)或批准通过等措施;
3)对于被阻断的交易,用户可向客服电话举证,通过后可重新发起交易。
基于此,本说明书实施例提供一种更为灵活的风险交易处理方法,能够对风险交易的用户发起通信,通过向通信对端发送安全认证数据,以获取通信对端基于所述安全认证数据反馈的交互数据,并根据所述交互数据确定所述交易是否通过安全认证。接下来对本说明书实施例进行详细说明。
如图1A所示,图1A是本说明书根据一示例性实施例示出的一种风险交易处理方法的流程图,包括以下步骤:
在步骤102、确定目标用户发起的交易为风险交易后,获取所述目标用户的通信信息,基于所述通信信息发起通信。
在步骤104、在与通信对端建立通信连接后,向所述通信对端发送安全认证数据,获取所述通信对端基于所述安全认证数据反馈的交互数据。
在步骤106、根据所述交互数据确定所述交易是否通过安全认证。
本说明书实施例的方案可应用于提供交易服务的业务系统中,上述步骤的执行主体具体可以包括服务端或客户端,并且不限制是否只在其中一端执行。本实施例方案是在发现风险交易后,通过与用户的主动通信交互来进一步对交易进行安全认证。由于采用了主动通信的方式,在确定目标用户发起的交易为风险交易后,可以获取所述目标用户的通信信息,基于所述通信信息发起通信,可以警示用户并确定交易是否通过安全认证,在交易过程中直接释放风险,减少事后再人工处置的量级,缓解服务端压力。
其中,发起通信的方式可以根据需要灵活配置,可选的,可以是语音通信,以达到与用户语音交互的效果。具体的,可以是结合视频的语音通信,也可以是单纯的语音通信。实际实现时,可以是服务端向客户端发起网络通信,此种方式需要客户端与服务端处于连接状态;作为例子,用户通过个人计算机中的浏览器发起交易,本实施例的方案可以要求用户利用智能手机等移动设备的客户端登录服务端,并由服务端获取该目标用户的通信信息,具体可以包括用户的常用设备的通信地址(如IP地址、设备MAC地址),服务端可以基于通信地址向客户端发起网络通信,例如语音通话或视频通话等方式。或者,也可以是用户登录服务端发起交易,服务端可以直接向客户端发起语音通信。
在另一些例子中,通信信息可以是用户的可信手机号码,服务端可以向所述可信手机号码发起呼叫。可选的,本实施例可以通过智能语音技术实现,可以预先配置智能呼叫程序,以用于自动发起电话呼叫,减少人工压力。可选的,用户可能有一个或多个手机号码,本实施例方案中,可以确定目标用户的可信手机号码,以防止呼叫错误、确保能够呼叫给正确的用户。可选的,目标用户的可选手机号码可以基于如下信息确定:与目标用户的账户绑定的手机号码、与客服联系过的手机号码、手机号码的归属地信息或手机号码的绑定时长。作为例子,目标用户的账户可能绑定过一个或多个手机号码,可以获取各个手机号码的绑定时间综合考虑;还可以是获取目标用户与客户服务电话的历史联系记录,以通过历史联系记录获取目标用户利用哪个电话号码与客服联系;由于涉及到目标用户的多个手机号码,还可以根据手机号码的归属地信息进一步综合考虑,与用户的常用所在地相匹配的手机号码会更为可选。实际应用中,作为一个可选的方式,可以根据需要建立可信手机模型,该可信手机模型可以根据支付宝账户绑定手机、近期来电和客服沟通手机、支付宝账户使用时的设备指纹、手机号码的归属地信息、手机号码的绑定时间等信息作为特征,用以判断用户当前真正在使用的手机号码,确定呼叫给正确的用户。
可以理解,发起的通信可能能够成功建立通信连接,也可能无法建立通信连接。可选的,若与通信对端一次或多次无法建立通信连接,因为无法通过与用户交互而对交易进行安全认证,可以直接阻断所述交易。
在能够成功建立通信连接的情况下,可以向所述通信对端发送安全认证数据,获取所述通信对端基于所述安全认证数据反馈的交互数据。上述处理是考虑到风控模型只是基于交易信息而做出的判断,风险模型并未经过用户交互而将交易直接判定为风险交易,本实施例希望能够通过主动通信与用户交互、通过用户的参与进一步对交易进行更为可靠的安全认证。可选的,考虑到实际盗刷或诈骗等场景的特点,安全认证可以是对通信对端用户进行活体认证,可以是确定通信对端侧用户与所述目标用户是否为同一用户,可以是对通信对端侧用户进行询问以对交易进一步确认风险等等。作为例子,可以基于问答用户的个人身份信息、可以询问用户是否是本人的正常交易、可以对交易发起对象进行活体认证或可以获取用户的生物特征(如人脸特征或声纹特征等)等多种方式,实际应用中可以根据需要灵活配置安全认证数据的实现方式,以获取所述通信对端基于所述安全认证数据反馈的交互数据。
作为例子,可以要求通信对端侧发声,以获取通信对端侧的语音数据作为交互数据,通过获取所述语音数据的声纹特征与所述目标用户的声纹特征的匹配结果,根据匹配结果确定所述交易是否通过安全认证。可选的,服务方可以预先通过多种方式获取用户的语音数据,以提取出表征用户身份的语音特征。通过上述方式,可以判断通信对端侧是否是活体、判断通信对端侧的用户与发起交易的用户是否是同一用户。
在另一些例子中,还可以与通信对端侧视频通话,通过获取摄像头采集视频数据,从视频数据中获取通信对端侧用户的人脸特征,将通信对端侧用户的人脸特征与目标用户的人脸特征匹配,根据匹配结果确定所述交易是否通过安全认证。
可选的,可以通过问答的方式对通信对端侧用户与目标用户进行验证,其中,安全认证数据可以包括:认证问题数据;所述根据所述交互数据确定所述交易是否通过安全认证,包括:获取通信对端侧发送的答案数据后,根据所述通信对端侧发送的答案数据与所述认证问题数据对应的答案数据的匹配结果,确定所述交易是否通过安全认证。可选的,认证问题数据可以是一表征问题的语音数据,播放该语音数据后,由用户对该问题进行回答,可选的,实际实现时可以由用户通过语音回答,也可以由用户触发设备展示的虚拟键盘进行回答等。可选的,本实施例的认证问题数据可以基于对应答案数据为数字而设定,例如可以是表征询问身份证号码、询问随机数、询问年龄等认证问题数 据,由于此类问题数据的答案是数字,可以令用户便捷地通过数字键盘输入,从而可提高处理效率。
作为例子,认证问题数据可以是一表征询问用户身份证号码的语音数据,通信对端侧设备可以播放该认证问题数据,通信对端侧设备还可以展示数字键盘,以供用户输入对应答案;发起通信的服务端可以获取通信对端侧的答案数据,以通过答案数据识别出用户所输入的数字是否与发起交易的用户的身份证号码匹配。
在另一些例子中,认证问题数据可以是一表征随机数的语音数据,该随机数可以根据需要实时生成,并可利用智能语音技术生成表征该随机数的语音数据,通信对端侧设备可以播放该认证问题数据,以使用户收听到该认证问题数据后,可以输入对应的随机数;通信对端侧设备还可以展示数字键盘,以供用户输入;发起通信的服务端可以获取通信对端侧的答案数据,以通过答案数据识别出用户所输入的数字是否与生成的随机数匹配。
通过上述方式,可以确定通信对端侧用户与所述目标用户是否为同一用户,可以确定发起交易的对象是否为活体用户,也可以确定目标用户是否真的有发起交易防止账户盗用,还可以在用户真正付款前起到安全警示的作用。
可选的,为了提高通信效率、防止用户未接受服务方发起的通信,本实施例中,在所述发起通信前,还可以包括:对如下一种或多种信息进行通信前的预告:发起呼叫的电话号码、所述可信手机号码、发起呼叫的服务方标识或本次呼叫用于进行针对交易的安全认证。可选的,上述提醒可以在目标用户发起交易的设备中实现,例如,如图1B所示,是本说明书实施例提供的一客户端示意图,目标用户采用客户端发起交易,可以由客户端展示上述预告,其中,图1B的预告中示出了表征发起呼叫的电话号码的“0571-88880123”,表征可信手机号码的“187****1234”,表征发起呼叫的服务方标识的“支付宝”,表征本次呼叫用于进行针对交易的安全认证的“为保障交易安全,请使用187****1234接听支付宝来电,并根据提示验证身份”等信息。在另一些例子中,若目标用户采用浏览器登录服务页面发起交易,可以在服务页面中输出一窗口以展示上述提醒。通过上述提醒,可以使用户获知服务方即将发起通信以对交易进行安全认证,从而可以提高通信连接的概率,提高通信效率,防止用户拒绝通信。
由前述描述可知,本说明书对上述风险交易处理实施例的执行主体并未限制;接下来从客户端的角度进一步提供另一风险交易处理实施例,该实施例可应用于客户端,当用户使用客户端发起交易后,客户端可执行如图2A所示实施例的方法,包括如下步 骤:
在步骤202中,获取目标用户发起的交易的交易信息。
在步骤204中,在基于所述交易信息确定所述交易为风险交易后,展示通信预告信息,所述通信预告信息用于指示服务方需要基于目标用户的通信信息发起通信,并对本次交易进行安全认证。
本实施例可应用于提供交易功能的客户端中,用户可以通过客户端发起交易,客户端通过检测用户发起的交易操作后,确定目标用户的账户、以及交易地点、交易时间、交易金额等交易相关信息。利用上述交易信息,可以利用风控模型识别交易的风险及类型,其中,上述对交易的风险识别过程可以是在客户端本端执行,也可以是在服务端执行。若是在服务端执行,客户端可以接收服务端对该笔交易的识别结果,若是在客户端执行,客户端可以向服务端发送识别结果。在确定该笔交易为风险交易后,服务方需要进一步对本次交易发起通信以进行安全认证。为了保证能够顺利与用户通信,本实施例中客户端可以展示通信预告信息,用于指示服务方需要基于目标用户的通信信息发起通信,并对本次交易进行安全认证。其中,该通信预告信息可以是存储在客户端本地,也可以是从服务端侧获取到。
结合图2B至图2D所示的风险交易处理示意图进一步描述,本实施例中用户利用客户端发起交易,服务方在确定交易发起后,可以判断本次交易是否适用通信认证,可选的,条件可以包括:
1)风控模型判断本笔交易具有高风险,按照原有流程本次交易将被直接阻断拦截;
2)风控模型确定本次交易符合骗盗结合或欺诈场景,原有核身产品不再有效;
3)发起交易的用户具有可信手机号码,能确保语音拨给用户本人。
可选的,在通信发起之前,服务端可以利用客户端进行通信前的预告提醒,以通知用户服务方将与其电话交互,由用户根据所处环境决定是否接听,通知内容可以包括:
1)发起呼叫的电话号码,以防诈骗电话趁机而入。
2)用户的可信手机号码,以便用户提前准备接听。
3)发起呼叫的服务方标识,以使用户获知呼入者为服务方;可选的,服务方标识可以是服务方的名称、简称或其他等为用户熟知的名称。
4)文案内容,以对本次呼叫用于进行针对交易的安全认证进行提示,例如本次交 互是为保障资金安全而做的身份核实。
5)接听选项;可选的,本实施例提供有通信确认入口,通过所述通信确认入口获取指示用户是否接受通信的消息并发送给服务方,以供服务方确定是否发起通信;在图2B中,该通信确认入口包括“立即接听”选项及“无法接听”选项,通过提供该接听选项,可以供用户触发,以确定用户愿意接受来电呼入。
接通后,服务端与通信对端成功建立了通信连接,进一步可以与用户交互,包括如下一种或多种:
1)需要与用户确认交易,服务端生成随机数后生成表征该随机数的语音数据并发送给通信对端,以使通信对端设备能够播放该语音数据后,用户输入语音播报的随机数;
2)身份核实,例如服务端生成表征询问身份证号码的语音数据并发送给通信对端播放,使用户可以按语音提示输入身份证号;或者,可以是让用户说话后通过声纹比对,可选的,还可以生成认证问题数据并发送给通信对端播放,使用户可以按语音提示说话以提供答案数据,以通过答案数据进一步进行安全认证;
3)用户问答,如用户有其他问题可直接语音交互或选择进入人工服务。
其中,如未接通,可以重新拨打一次或多次,重播一次或多次后仍未接通则按原有流程操作,对交易阻断拦截,进入服务环节。
最后,服务端根据实际的语音交互情况对该笔交易进行处理,包括:
1)核实通过,提示交易成功,执行交易流程;
2)核实不通过,提示交易失败并指引用户按照固有安全方式重新发起交易;
3)核实不通过,也根据风险情况继续阻断拦截,引导进入人工审核。
本实施例提供的方案可以与风险防控策略相结合而解决社工、欺诈类风控难点。因信息泄露导致的社工欺骗和欺诈是交易风险的主要成因,黑产团伙冒充商家、公检法或采用提升额度、办理贷款及大额信用卡等骗术骗取用户短信验证码或身份证件等信息,用户在被骗或者无意识情况下帮助黑产团伙通过身份认证,这类风险由于用户参与其中,防范难度较大。
另外,由于风控系统的保护,用户处于无感知被保护状态,风险暴露后敞口持续存在,容易发生二次风险。一些风控模型在侦测到交易风险之后,出于交易体验的考虑,有可能并非全部进行阻断或者要求身份认证,在风险评级较低、金额较小或特定时期, 可能会批准通过一部分风险交易;对于不关注账户的用户来说并不能马上感知到风险,未对账户做出加强安全的措施,风控系统也可能因缺乏用户反馈而将本次交易判定为安全交易,下一次再发生时可能会继续批准,从而发生二次风险。
本实施例方案通过主动发起的通信,可以采用声纹、语音+X(X可以是上述实施例中的随机数、身份证或安保问题等)等认证技术对交易进行安全认证,让黑产团伙无法绕过安全认证。通过语音交互的直接沟通能唤起用户安全意识,进一步降低用户被骗的几率。语音认证技术相较密码可以降低安全验证失败率,提升用户支付体验。
本实施例通过主动提醒可以提升账户安全水位。针对大量存在的低免疫账户和易被骗/诈人群、每日风险暴露人群,因缺少合适的触达方式而放置不理直至发生风险,借助语音开展尽责提醒和主动沟通,有助于在事前化解风险,同时增强用户安全感。
对于骗盗结合等风险类型,由于支付过程中缺乏有效的风险释放渠道,往往采取失败交易或冻结账户的措施,用户事后来电举证以恢复账户,审核负荷就传递到了服务端,对服务方造成了一定的人工压力。本实施例在交易过程中主动发起通信进行认证,能够释放风险、减少拦截阻断交易外,对于已经冻结账户的用户可以及时通过语音外呼引导至自助服务渠道,因此可以有效缓解服务端资源压力。
传统的风险交易直接会被阻断或挂起,部分用户误以为网络或者账户出现了问题,在服务方没有及时提醒和沟通的情况下,用户可能会采用其他渠道完成本次交易,甚至后续也不再使用该账户,从而造成一定的用户流失。本实施例根据测算,被拦截阻断交易的用户中30%将转为睡眠(一个月内不再发生交易),而80%的风险可以在支付过程中沟通、确认,但因客服人力有限,本实施例采用主动发起通信的方式能及时解决风险交易问题,借助语音技术能够解决上述弊端,进而可以提升用户活跃率。
本实施例方案提供了的主动安全的服务,相对传统的识别风险——账户管控——用户通过核身或来电举证的防御型风控流程相比,通过事前主动提醒、事中主动沟通和事后跟进关怀的主动式安全服务,建立起用户参与的闭环风控流程,解决信息泄露、社工欺骗等风控难题。
与前述风险交易处理方法的实施例相对应,本说明书还提供了风险交易处理装置及其所应用的终端的实施例。
本说明书风险交易处理装置的实施例可以应用在计算机设备上,例如服务器或终端设备。装置实施例可以通过软件实现,也可以通过硬件或者软硬件结合的方式实现。 以软件实现为例,作为一个逻辑意义上的装置,是通过其所在文件处理的处理器将非易失性存储器中对应的计算机程序指令读取到内存中运行形成的。从硬件层面而言,如图3所示,为本说明书风险交易处理装置所在计算机设备的一种硬件结构图,除了图3所示的处理器310、内存330、网络接口320、以及非易失性存储器340之外,实施例中装置331所在的服务器或电子设备,通常根据该计算机设备的实际功能,还可以包括其他硬件,对此不再赘述。
如图4所示,图4是本说明书根据一示例性实施例示出的一种风险交易处理装置的框图,所述装置包括:
通信模块41,用于:确定目标用户发起的交易为风险交易后,获取所述目标用户的通信信息,基于所述通信信息发起通信;
数据获取模块42,用于:在与通信对端建立通信连接后,向所述通信对端发送安全认证数据,获取所述通信对端基于所述安全认证数据反馈的交互数据;
认证模块43,用于:根据所述交互数据确定所述交易是否通过安全认证。
可选的,所述认证模块,用于:
根据所述交互数据确定通信对端侧用户与所述目标用户是否为同一用户,以确定所述交易是否通过安全认证。
可选的,所述认证模块,用于:
获取通信对端侧的语音数据后,获取所述语音数据的声纹特征与所述目标用户的声纹特征的匹配结果,根据匹配结果确定所述交易是否通过安全认证。
可选的,所述安全认证数据包括:认证问题数据;
所述认证模块,用于:
获取通信对端侧的答案数据后,根据所述通信对端侧的答案数据与所述认证问题数据对应答案数据的匹配结果,确定所述交易是否通过安全认证。
可选的,所述认证问题数据基于对应答案数据为数字而设定。
可选的,所述通信信息包括可信手机号码;
所述通信模块,用于:
向所述可信手机号码发起呼叫。
可选的,所述可信手机号码基于如下信息确定:
与目标用户的账户绑定的手机号码、与客服联系过的手机号码、手机号码的归属地信息或手机号码的绑定时间。
可选的,所述通信模块,还用于:在发起所述通信前,对如下一种或多种信息进行通信前的提醒:
发起呼叫的电话号码、所述可信手机号码、发起呼叫的服务方标识或本次呼叫用于进行针对交易的安全认证。
可选的,所述装置还包括阻断模块,用于:
若与通信对端一次或多次无法建立通信连接,阻断所述交易。
可选的,所述认证模块,还用于:
若所述交易通过安全验证,执行交易流程;
若所述交易未通过验证,阻止所述交易。
如图5所示,图5是本说明书根据一示例性实施例示出的一种风险交易处理装置的框图,所述装置包括:
获取模块51,用于:获取目标用户发起的交易的交易信息;
预告模块52,用于:在基于所述交易信息确定所述交易为风险交易后,展示通信预告信息,所述通信预告信息用于指示服务方需要基于目标用户的通信信息发起通信,并对本次交易进行安全认证。
可选的,所述预告模块还用于:
展示通信确认入口,通过所述通信确认入口获取指示用户是否接受通信的消息并发送给服务方,以供服务方确定是否发起通信。
可选的,所述通信预告信息包括:
发起呼叫的电话号码、所述可信手机号码、发起呼叫的服务方标识或本次呼叫用于进行针对交易的安全认证。
上述风险交易处理装置中各个模块的功能和作用的实现过程具体详见上述风险交易处理方法中对应步骤的实现过程,在此不再赘述。
对于装置实施例而言,由于其基本对应于方法实施例,所以相关之处参见方法实 施例的部分说明即可。以上所描述的装置实施例仅仅是示意性的,其中所述作为分离部件说明的模块可以是或者也可以不是物理上分开的,作为模块显示的部件可以是或者也可以不是物理模块,即可以位于一个地方,或者也可以分布到多个网络模块上。可以根据实际的需要选择其中的部分或者全部模块来实现本说明书方案的目的。本领域普通技术人员在不付出创造性劳动的情况下,即可以理解并实施。
上述对本说明书特定实施例进行了描述。其它实施例在所附权利要求书的范围内。在一些情况下,在权利要求书中记载的动作或步骤可以按照不同于实施例中的顺序来执行并且仍然可以实现期望的结果。另外,在附图中描绘的过程不一定要求示出的特定顺序或者连续顺序才能实现期望的结果。在某些实施方式中,多任务处理和并行处理也是可以的或者可能是有利的。
本领域技术人员在考虑说明书及实践这里申请的发明后,将容易想到本说明书的其它实施方案。本说明书旨在涵盖本说明书的任何变型、用途或者适应性变化,这些变型、用途或者适应性变化遵循本说明书的一般性原理并包括本说明书未申请的本技术领域中的公知常识或惯用技术手段。说明书和实施例仅被视为示例性的,本说明书的真正范围和精神由下面的权利要求指出。
应当理解的是,本说明书并不局限于上面已经描述并在附图中示出的精确结构,并且可以在不脱离其范围进行各种修改和改变。本说明书的范围仅由所附的权利要求来限制。
以上所述仅为本说明书的较佳实施例而已,并不用以限制本说明书,凡在本说明书的精神和原则之内,所做的任何修改、等同替换、改进等,均应包含在本说明书保护的范围之内。

Claims (16)

  1. 一种风险交易处理方法,包括:
    确定目标用户发起的交易为风险交易后,获取所述目标用户的通信信息,基于所述通信信息发起通信;
    在与通信对端建立通信连接后,向所述通信对端发送安全认证数据,获取所述通信对端基于所述安全认证数据反馈的交互数据;
    根据所述交互数据确定所述交易是否通过安全认证。
  2. 根据权利要求1所述的方法,所述根据所述交互数据确定所述交易是否通过安全认证,包括:
    根据所述交互数据确定通信对端侧用户与所述目标用户是否为同一用户,以确定所述交易是否通过安全认证。
  3. 根据权利要求1所述的方法,所述根据所述交互数据确定所述交易是否通过安全认证,包括:
    获取通信对端侧的语音数据后,获取所述语音数据的声纹特征与所述目标用户的声纹特征的匹配结果,根据匹配结果确定所述交易是否通过安全认证。
  4. 根据权利要求1所述的方法,所述安全认证数据包括:认证问题数据;
    所述根据所述交互数据确定所述交易是否通过安全认证,包括:
    获取通信对端侧的答案数据后,根据所述通信对端侧的答案数据与所述认证问题数据对应答案数据的匹配结果,确定所述交易是否通过安全认证。
  5. 根据权利要求4所述的方法,所述认证问题数据基于对应答案数据为数字而设定。
  6. 根据权利要求1所述的方法,所述通信信息包括可信手机号码;
    所述基于所述通信信息发起通信,包括:
    向所述可信手机号码发起呼叫。
  7. 根据权利要求5所述的方法,所述可信手机号码基于如下信息确定:
    与目标用户的账户绑定的手机号码、与客服联系过的手机号码、手机号码的归属地信息或手机号码的绑定时间。
  8. 根据权利要求5所述的方法,在所述发起通信前,还包括:
    对如下一种或多种信息进行通信前的预告:
    发起呼叫的电话号码、所述可信手机号码、发起呼叫的服务方标识或本次呼叫用于进行针对交易的安全认证。
  9. 根据权利要求1所述的方法,还包括:
    若与通信对端一次或多次无法建立通信连接,阻断所述交易。
  10. 根据权利要求1所述的方法,所述方法还包括:
    若所述交易通过安全验证,执行交易流程;
    若所述交易未通过验证,阻止所述交易。
  11. 一种风险交易处理方法,包括:
    获取目标用户发起的交易的交易信息;
    在基于所述交易信息确定所述交易为风险交易后,展示通信预告信息,所述通信预告信息用于指示服务方需要基于目标用户的通信信息发起通信,并对本次交易进行安全认证。
  12. 根据权利要求11所述的方法,还包括:
    展示通信确认入口,通过所述通信确认入口获取指示用户是否接受通信的消息并发送给服务方,以供服务方确定是否发起通信。
  13. 根据权利要求11所述的方法,所述通信预告信息包括:
    发起呼叫的电话号码、所述可信手机号码、发起呼叫的服务方标识或本次呼叫用于进行针对交易的安全认证。
  14. 一种风险交易处理装置,包括:
    通信模块,用于:确定目标用户发起的交易为风险交易后,获取所述目标用户的通信信息,基于所述通信信息发起通信;
    数据获取模块,用于:在与通信对端建立通信连接后,向所述通信对端发送安全认证数据,获取所述通信对端基于所述安全认证数据反馈的交互数据;
    认证模块,用于:根据所述交互数据确定所述交易是否通过安全认证。
  15. 一种风险交易处理装置,包括:
    获取模块,用于:获取目标用户发起的交易的交易信息;
    预告模块,用于:在基于所述交易信息确定所述交易为风险交易后,展示通信预告信息,所述通信预告信息用于指示服务方需要基于目标用户的通信信息发起通信,并对本次交易进行安全认证。
  16. 一种计算机设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,其中,所述处理器执行所述程序时实现如权利要求1至13任一所述的方法。
PCT/CN2020/070028 2019-01-15 2020-01-02 风险交易处理方法、装置及设备 Ceased WO2020147586A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910035166.XA CN110046902A (zh) 2019-01-15 2019-01-15 风险交易处理方法、装置及设备
CN201910035166.X 2019-01-15

Publications (1)

Publication Number Publication Date
WO2020147586A1 true WO2020147586A1 (zh) 2020-07-23

Family

ID=67274125

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/070028 Ceased WO2020147586A1 (zh) 2019-01-15 2020-01-02 风险交易处理方法、装置及设备

Country Status (3)

Country Link
CN (1) CN110046902A (zh)
TW (1) TWI790401B (zh)
WO (1) WO2020147586A1 (zh)

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112053159A (zh) * 2020-08-06 2020-12-08 中信银行股份有限公司 交易数据验证方法、装置、风险控制服务器及业务服务器
CN113379325A (zh) * 2021-07-06 2021-09-10 中国工商银行股份有限公司 风险控制处理方法及装置
CN113918989A (zh) * 2021-09-30 2022-01-11 中国工商银行股份有限公司 保护用户个人隐私信息的方法、装置、电子设备和介质
CN114066584A (zh) * 2021-11-05 2022-02-18 支付宝(杭州)信息技术有限公司 用于区块链的风险防控的方法及装置
CN114445084A (zh) * 2022-01-24 2022-05-06 支付宝(杭州)信息技术有限公司 具有隐私保护的极速风控智能预测方法和系统
CN115239495A (zh) * 2022-07-25 2022-10-25 中国银行股份有限公司 风控模型处理方法及装置
CN115346533A (zh) * 2022-08-12 2022-11-15 携程旅游信息技术(上海)有限公司 基于声纹的账号判别方法、系统、电子设备和介质
CN116228420A (zh) * 2023-02-28 2023-06-06 江苏苏宁银行股份有限公司 一种银行客户端的信息风险防控系统、方法及装置
CN116600294A (zh) * 2023-04-27 2023-08-15 中国工商银行股份有限公司 对象身份的验证方法、装置、电子设备及存储介质
CN119599671A (zh) * 2024-11-08 2025-03-11 中国建设银行股份有限公司 交易试算方法、装置、电子设备及存储介质

Families Citing this family (16)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110046902A (zh) * 2019-01-15 2019-07-23 阿里巴巴集团控股有限公司 风险交易处理方法、装置及设备
CN110598982B (zh) * 2019-08-07 2022-02-22 创新先进技术有限公司 基于智能交互的主动风控方法和系统
US11086991B2 (en) 2019-08-07 2021-08-10 Advanced New Technologies Co., Ltd. Method and system for active risk control based on intelligent interaction
CN110570189B (zh) * 2019-08-15 2023-06-16 创新先进技术有限公司 账户风险防控方法和系统
CN111062770B (zh) * 2019-10-31 2023-07-18 支付宝(杭州)信息技术有限公司 商户识别方法、设备及计算机可读介质
CN110929010A (zh) * 2019-11-28 2020-03-27 中国银行股份有限公司 风险用户身份判断方法及装置
CN111553701A (zh) * 2020-05-14 2020-08-18 支付宝(杭州)信息技术有限公司 一种基于会话的风险交易确定方法和装置
CN111709746A (zh) * 2020-06-09 2020-09-25 支付宝(杭州)信息技术有限公司 一种风险处理方法、装置和电子设备
CN111667274A (zh) * 2020-06-16 2020-09-15 中国银行股份有限公司 一种认证方法及相关设备
CN112036861B (zh) * 2020-08-31 2024-05-10 百富计算机技术(深圳)有限公司 一种安全设备
CN115619406B (zh) * 2021-07-14 2025-12-02 广州腾讯科技有限公司 一种交易对象的识别方法、交易处理的方法、装置及设备
CN113869999A (zh) * 2021-08-23 2021-12-31 合肥工业大学 基于市场大数据及交易双方信用风险的综合风险预警系统
CN113705535A (zh) * 2021-09-18 2021-11-26 中国银行股份有限公司 帮助老年人使用atm交易方法、相关装置及存储介质
CN114529391B (zh) * 2022-01-28 2024-11-12 中银金融科技有限公司 一种可疑洗钱团伙信息识别方法及系统
CN114663095A (zh) * 2022-03-21 2022-06-24 中国建设银行股份有限公司 一种咨询业务的处理方法、装置、设备、介质及产品
CN116151832B (zh) * 2023-04-18 2023-07-21 支付宝(杭州)信息技术有限公司 一种交互式风控系统及方法

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1801228A (zh) * 2005-12-16 2006-07-12 北京邮电大学 基于交互式语音响应对银行卡交易实时授权的方法
US20140297522A1 (en) * 2009-05-29 2014-10-02 Jpmorgan Chase Bank, N.A. System and Method for Risk Evaluation in EFT Transactions
CN104753868A (zh) * 2013-12-30 2015-07-01 腾讯科技(深圳)有限公司 一种安全验证方法、业务服务器及安全验证系统
CN110046902A (zh) * 2019-01-15 2019-07-23 阿里巴巴集团控股有限公司 风险交易处理方法、装置及设备

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103020820A (zh) * 2011-09-20 2013-04-03 深圳市财付通科技有限公司 一种交易支付方法和系统
CN104715371A (zh) * 2013-12-16 2015-06-17 黄金富知识产权咨询(深圳)有限公司 一种采用声纹鉴别身份的安全支付方法和相应系统
CN105307158B (zh) * 2014-07-25 2019-01-29 北京科能腾达通信技术有限公司 一种通信终端的手机号码的身份验证方法
CN105357006A (zh) * 2014-08-20 2016-02-24 中兴通讯股份有限公司 一种基于声纹特征进行安全认证的方法及设备
CN106204046A (zh) * 2016-06-29 2016-12-07 北京小米移动软件有限公司 订单支付的方法及装置
CN108681899A (zh) * 2018-05-18 2018-10-19 中国联合网络通信集团有限公司 支付方法及支付系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1801228A (zh) * 2005-12-16 2006-07-12 北京邮电大学 基于交互式语音响应对银行卡交易实时授权的方法
US20140297522A1 (en) * 2009-05-29 2014-10-02 Jpmorgan Chase Bank, N.A. System and Method for Risk Evaluation in EFT Transactions
CN104753868A (zh) * 2013-12-30 2015-07-01 腾讯科技(深圳)有限公司 一种安全验证方法、业务服务器及安全验证系统
CN110046902A (zh) * 2019-01-15 2019-07-23 阿里巴巴集团控股有限公司 风险交易处理方法、装置及设备

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112053159A (zh) * 2020-08-06 2020-12-08 中信银行股份有限公司 交易数据验证方法、装置、风险控制服务器及业务服务器
CN113379325A (zh) * 2021-07-06 2021-09-10 中国工商银行股份有限公司 风险控制处理方法及装置
CN113918989A (zh) * 2021-09-30 2022-01-11 中国工商银行股份有限公司 保护用户个人隐私信息的方法、装置、电子设备和介质
CN114066584A (zh) * 2021-11-05 2022-02-18 支付宝(杭州)信息技术有限公司 用于区块链的风险防控的方法及装置
CN114445084A (zh) * 2022-01-24 2022-05-06 支付宝(杭州)信息技术有限公司 具有隐私保护的极速风控智能预测方法和系统
CN115239495A (zh) * 2022-07-25 2022-10-25 中国银行股份有限公司 风控模型处理方法及装置
CN115346533A (zh) * 2022-08-12 2022-11-15 携程旅游信息技术(上海)有限公司 基于声纹的账号判别方法、系统、电子设备和介质
CN116228420A (zh) * 2023-02-28 2023-06-06 江苏苏宁银行股份有限公司 一种银行客户端的信息风险防控系统、方法及装置
CN116600294A (zh) * 2023-04-27 2023-08-15 中国工商银行股份有限公司 对象身份的验证方法、装置、电子设备及存储介质
CN119599671A (zh) * 2024-11-08 2025-03-11 中国建设银行股份有限公司 交易试算方法、装置、电子设备及存储介质

Also Published As

Publication number Publication date
TW202029692A (zh) 2020-08-01
TWI790401B (zh) 2023-01-21
CN110046902A (zh) 2019-07-23

Similar Documents

Publication Publication Date Title
TWI790401B (zh) 風險交易處理方法、裝置及設備
US8914645B2 (en) Systems and methods for identifying biometric information as trusted and authenticating persons using trusted biometric information
US9143506B2 (en) Systems and methods for identifying biometric information as trusted and authenticating persons using trusted biometric information
EP2460307B1 (en) System and method for strong remote identity proofing
EP2062210B1 (en) Transaction authorisation system & method
US8407112B2 (en) Transaction authorisation system and method
CN105577664B (zh) 密码重置方法及系统、客户端及服务器
US20160323450A1 (en) Call center sms verification system and method
US8572398B1 (en) Systems and methods for identifying biometric information as trusted and authenticating persons using trusted biometric information
KR20040037074A (ko) 전자 메시징을 이용한 금융 거래 시스템 및 방법
US20090006254A1 (en) Virtual prepaid or credit card and process and system for providing same and for electronic payments
CN103020820A (zh) 一种交易支付方法和系统
US12393935B2 (en) Secure transactions over communications sessions
US10929850B2 (en) System for managing personal identifiers and financial instrument use
US20140330689A1 (en) System and Method for Verifying Online Banking Account Identity Using Real-Time Communication and Digital Certificate
JP4746643B2 (ja) 本人確認システムおよび方法
US9025746B2 (en) System and method for visual caller identification
KR20220070417A (ko) 안전 거래 인증 서비스 제공 시스템
CN111222789A (zh) 一种提升业务信息确认效率的方法、装置、计算机设备、和可读存储介质
CN115001806B (zh) 手机银行登录授权方法及装置
JP2001331756A (ja) カード支払自動決済システム
CN113487329A (zh) 基于区块链的银行终端交易系统及方法
EP2891128A1 (en) Methods and systems for managing communication streams
US20250190988A1 (en) Secure voice payments for call-based transactions
US20240154957A1 (en) Real-name information package and real-name information security protection method

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20740809

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20740809

Country of ref document: EP

Kind code of ref document: A1