WO2024208129A1 - 一种业务风控的方法、装置、存储介质及电子设备 - Google Patents

一种业务风控的方法、装置、存储介质及电子设备 Download PDF

Info

Publication number
WO2024208129A1
WO2024208129A1 PCT/CN2024/085162 CN2024085162W WO2024208129A1 WO 2024208129 A1 WO2024208129 A1 WO 2024208129A1 CN 2024085162 W CN2024085162 W CN 2024085162W WO 2024208129 A1 WO2024208129 A1 WO 2024208129A1
Authority
WO
WIPO (PCT)
Prior art keywords
data
sent
business
risk
information entropy
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2024/085162
Other languages
English (en)
French (fr)
Inventor
潘无穷
韦韬
翁海琴
李天一
卫振强
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alipay Hangzhou Information Technology Co Ltd
Original Assignee
Alipay Hangzhou Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alipay Hangzhou Information Technology Co Ltd filed Critical Alipay Hangzhou Information Technology Co Ltd
Publication of WO2024208129A1 publication Critical patent/WO2024208129A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q10/00Administration; Management
    • G06Q10/06Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling
    • G06Q10/063Operations research, analysis or management
    • G06Q10/0635Risk analysis of enterprise or organisation activities

Definitions

  • the present invention relates to the field of computer technology, and in particular to a method, device, storage medium and electronic device for business risk control.
  • This specification provides a method, device, storage medium and electronic device for business risk control to solve the problem of effectively controlling the risk of executed business when each participant participates in federated learning or multi-party secure computing.
  • This specification adopts the following technical solution:
  • This specification provides a method for business risk control, including: obtaining business data; determining data to be sent based on the business data; determining risk-free data from the data to be sent, and determining the remaining data in the data to be sent except the risk-free data, wherein the risk-free data is data that will not cause leakage of the business data after being sent to a recipient; determining a first information entropy based on the business data, and determining a second information entropy based on the business data and the remaining data, wherein the first information entropy is used to characterize the amount of information required to obtain the full amount of the business data when the recipient does not obtain the data to be sent, and the second information entropy is used to characterize the amount of information required to obtain the full amount of the business data after the recipient obtains the data to be sent; determining risk control information entropy based on the first information entropy and the second information entropy, wherein the risk control information en
  • determining risk-free data from the data to be sent specifically includes: determining data obtained by encrypting part of the business data contained in the data to be sent through a preset security protocol as risk-free data.
  • determining risk-free data from the data to be sent specifically includes: determining data obtained by encrypting part of the business data contained in the data to be sent using a private key as risk-free data.
  • determining risk-free data from the data to be sent specifically includes: determining data obtained by masking part of the business data contained in the data to be sent using random numbers as risk-free data.
  • determining the first information entropy according to the business data, and determining the second information entropy according to the business data and the remaining data specifically includes: adding the random number to the business data to determine the updated business data; determining the first information entropy according to the updated business data; determining the second information entropy according to the updated business data and the remaining data.
  • determining the risk-free data from the data to be sent specifically includes: determining data with a derivation relationship from the data to be sent; determining the data contained in the data to be sent that can be deduced based on the derivation relationship as risk-free data.
  • the present specification provides a device for business risk control, comprising: an acquisition module, used to acquire business data; a first determination module, used to determine data to be sent according to the business data; a second determination module, used to determine risk-free data from the data to be sent, and determine the remaining data in the data to be sent except the risk-free data, wherein the risk-free data is data that will not cause leakage of the business data after being sent to a recipient; a third determination module, used to determine a first information entropy according to the business data, and to determine a second information entropy according to the business data and the remaining data, wherein the first information entropy is used to characterize the amount of information required to obtain the full amount of the business data when the recipient does not obtain the data to be sent, and the second information entropy is used to characterize the amount of information required to obtain the full amount of the business data after the recipient obtains the data to be sent; a fourth determination module, used to determine risk control information entropy according to the first information en
  • the second determination module is specifically configured to determine data contained in the data to be sent, obtained by encrypting part of the business data through a preset security protocol, as risk-free data.
  • the second determination module is specifically configured to determine data obtained by encrypting part of the business data contained in the data to be sent using a private key as risk-free data.
  • the second determination module is specifically configured to determine data obtained by masking part of the business data contained in the data to be sent using random numbers as risk-free data.
  • the third determination module is specifically used to add the random number to the business data to determine the updated business data; determine the first information entropy based on the updated business data; and determine the second information entropy based on the updated business data and the remaining data.
  • the second determination module is specifically configured to determine data having a derivation relationship from the data to be sent; and determine the data contained in the data to be sent that can be deduced based on the derivation relationship as risk-free data.
  • This specification provides a computer-readable storage medium, which stores a computer program.
  • the computer program is executed by a processor, the above-mentioned business risk control method is implemented.
  • This specification provides an electronic device, including a memory, a processor, and a A computer program running on a processor, when the processor executes the program, implements the above-mentioned business risk control method.
  • At least one of the above technical solutions adopted in this specification can achieve the following beneficial effects:
  • business data is obtained, and data to be sent is determined based on the business data, and risk-free data is determined from the data to be sent, and the remaining data other than risk-free data in the data to be sent is determined.
  • Risk-free data is data that will not cause business data leakage after being sent to the recipient.
  • a first information entropy is determined, and according to the business data and the remaining data, a second information entropy is determined.
  • the first information entropy is used to characterize the amount of information required to know the full amount of business data when the recipient does not obtain the remaining data
  • the second information entropy is used to characterize the amount of information required for the recipient to know the full amount of business data after obtaining the remaining data.
  • the risk control information entropy is determined based on the first information entropy and the second information entropy, and business risk control is performed.
  • the risk control information entropy is used to characterize the amount of information leaked from the business data after the data to be sent is sent to the recipient.
  • the present application can effectively control the execution of the business according to the amount of business data that may be leaked after the data to be sent is sent to the recipient.
  • the present application removes the risk-free data contained in the data to be sent that will not cause business data leakage after being sent to the recipient, so as to ensure the accuracy of the amount of information leaked by the sender when sending the data to be sent (i.e., the risk control information entropy).
  • FIG1 is a flow chart of a business risk control method provided in this specification.
  • FIG2 is a schematic diagram of a device for a business risk control method provided in this specification.
  • FIG. 3 is a schematic diagram of an electronic device provided in this specification corresponding to FIG. 1 .
  • FIG1 is a flow chart of a business risk control method provided in this specification, including steps S100 to S110.
  • S102 Determine data to be sent according to the service data.
  • the execution subject of this application can be a terminal device used by each participant in a multi-party secure data transmission scenario such as multi-party secure computing and federated learning, or a server, where the terminal device can include mobile devices such as mobile phones and tablets.
  • the terminal device can include mobile devices such as mobile phones and tablets.
  • the terminal device uses the terminal device as an example to illustrate the business risk control method provided by this application.
  • the terminal device used by the sender can obtain local business data, which is the sender's private business data and cannot be known by other participants. After obtaining the business data, based on the business data, the terminal device can determine part of the data from the business data according to the rules agreed upon by each participant, and then process the data (such as encryption) to obtain the data to be sent. The terminal device used by the sender can then send the determined data to be sent to the receiver.
  • local business data which is the sender's private business data and cannot be known by other participants.
  • the terminal device can determine part of the data from the business data according to the rules agreed upon by each participant, and then process the data (such as encryption) to obtain the data to be sent.
  • the terminal device used by the sender can then send the determined data to be sent to the receiver.
  • S104 Determine risk-free data from the data to be sent, and determine remaining data in the data to be sent except the risk-free data, wherein the risk-free data is data that will not cause leakage of the business data after being sent to the recipient.
  • the sender's terminal device In order to determine the amount of information that may be leaked by the sender's terminal device when sending the data to be sent, it is necessary to assume that the receiver is a problematic (i.e. untrustworthy) party. Then, after the sender sends the data to be sent, the receiver may try to infer the sender's full business data based on the data to be sent. At this time, the sender will be at risk of information leakage.
  • the terminal device used by the sender needs to estimate the amount of data leaked from the sender's business data based on the business data and the data to be sent, and then perform business risk control based on the determined amount of data leaked from the sender.
  • the terminal device used by the sender can determine the first information entropy based on the service data, and the first information entropy is used to characterize the information required to obtain the full amount of service data assuming that the receiver has not obtained the data to be sent. Furthermore, the terminal device used by the sender can also determine a second information entropy based on the business data and the data to be sent, and the second information entropy is used to characterize the amount of information required for the receiver to obtain the full amount of business data after obtaining the data to be sent.
  • the terminal device used by the sender can determine the risk control information entropy based on the determined first information entropy and second information entropy, and the risk control information entropy is used to characterize the amount of information leaked in the business data after the data to be sent is sent to the recipient.
  • C represents business data
  • D represents data to be sent
  • H is the risk control information entropy
  • H(C) is the first information entropy, which represents the amount of information required to know the full amount of business data assuming that the receiver has not obtained the data to be sent
  • D) is the second information entropy, which represents the amount of information required for the receiver to know the full amount of business data after obtaining the data to be sent.
  • the terminal device used by the sender can estimate the amount of information leaked in the sender's business data after the sender sends the data to be sent to the receiver.
  • the subsequent terminal device can perform business risk control based on the risk control information entropy.
  • some interactive data in federated learning and multi-party secure computing may be encrypted or derived from other data. Such data will not lead to the leakage of business data and should not be involved in the calculation process of risk control information entropy. Therefore, when determining the risk control information entropy, the terminal device used by the sender can remove such risk-free data from the data to be sent, so that the final determined risk control information entropy is more accurate.
  • risk-free data that is determined from the data to be sent and will not cause business data leakage after being sent to the recipient can be divided into four categories.
  • the terminal device may determine that the data obtained by encrypting part of the business data contained in the data to be sent through a preset security protocol is risk-free data.
  • the preset security protocol may refer to the security protocol used in federated learning or multi-party secure computing, such as the MPC protocol (Mobility Personal Computer, MPC), etc. This specification does not limit the type of protocol.
  • MPC Mobility Personal Computer
  • the terminal device can determine this part of the data included in the data to be sent as risk-free data.
  • the terminal device may also determine that the data obtained by encrypting part of the business data contained in the data to be sent using the private key is risk-free data.
  • the terminal device can determine the part of the data to be sent. Risk-free data.
  • the encryption algorithm may include: Hash-based Message Authentication Code (HAMC), Message-Digest Algorithm MD5 (MD5), etc. This specification does not limit the specific encryption algorithm used.
  • HAMC Hash-based Message Authentication Code
  • MD5 Message-Digest Algorithm MD5
  • the terminal device uses a private key to perform partial business data
  • the private key must be held solely by the sender. This ensures that the business data will not be leaked after the risk-free data determined in this way is obtained by the receiver.
  • the terminal device may also determine the data obtained by masking part of the business data contained in the data to be sent using random numbers as risk-free data.
  • this masking can also be regarded as a encryption method, and the data obtained after masking part of the business data with a random number can also be determined as risk-free data.
  • the terminal device can only use random numbers for encryption once.
  • the random numbers are only held by the sender and can be regarded as the sender's private data.
  • the terminal device can add the random numbers to the business data to determine the updated business data.
  • the terminal device can subsequently determine the first information entropy based on the updated business data, and determine the second information entropy based on the updated business data and the data to be sent.
  • the terminal device can also determine data with a derivation relationship from the data to be sent, and determine the data contained in the data to be sent that can be deduced based on the derivation relationship as risk-free data.
  • the terminal device can determine A as risk-free data.
  • the terminal device can determine the data contained in the data to be sent that can be deduced based on the derivation relationship as risk-free data.
  • S106 Determine a first information entropy based on the business data, and determine a second information entropy based on the business data and the remaining data, wherein the first information entropy is used to characterize the amount of information required for the receiver to obtain the full amount of the business data when the receiver has not obtained the data to be sent, and the second information entropy is used to characterize the amount of information required for the receiver to obtain the full amount of the business data after obtaining the data to be sent.
  • S108 Determine risk control information entropy according to the first information entropy and the second information entropy, where the risk control information entropy is used to characterize the amount of information of the business data leaked after the data to be sent is sent to a recipient.
  • S110 Execute business risk control according to the risk control information entropy.
  • the terminal device used by the sender can more accurately determine the second information entropy based on the business data and the remaining data, and then determine the risk control information entropy based on the first information entropy and the second information entropy.
  • the risk control information entropy is used to characterize the amount of information leaked in the business data after the data to be sent is sent to the recipient.
  • C represents business data
  • D′ represents the remaining data in the data to be sent
  • H is the risk control information entropy
  • H(C) is the first information entropy, which represents the amount of information required to know the full amount of business data assuming that the receiver has not obtained the data to be sent
  • D′) is the second information entropy, which represents the amount of information required to know the full amount of business data of the sender assuming that the receiver has obtained the remaining data.
  • the receiver learns that the amount of information required to obtain the sender's full business data is 100MB without obtaining the data to be sent, and that the receiver learns that the amount of information required to obtain the sender's full business data is 30MB after obtaining the remaining data in the data to be sent, then the amount of business data leaked after the sender sends the data to be sent to the receiver is 70MB.
  • the terminal device can also determine the first information entropy and the second information entropy based on the sender's business data and the data to be sent, and then determine the risk control information entropy used to characterize the amount of information required for the receiver to obtain the full amount of business data after obtaining the data to be sent based on the first information entropy and the second information entropy.
  • the terminal device After determining the risk control information entropy in this way, the terminal device can perform risk control based on the risk control information entropy based on the amount of information leaked in the business data after the sender sends the data to be sent to the receiver.
  • the risk control information entropy can be displayed to the user, so that the user can decide whether to send the data to be sent to the recipient based on the risk control information entropy.
  • the terminal device can also perform business risk control in other ways. For example, if the terminal device determines through the risk control information entropy that the amount of information leaked by the sender exceeds a preset threshold, or determines that the risk control information entropy does not fall within the preset security information entropy range, the terminal device used by the sender can prevent the data to be sent from being sent.
  • the recipient mentioned above in this specification may be multiple recipients.
  • the data to be sent is the sum of the data sent by the sender to all recipients.
  • the terminal device used by the sender can determine the time to send the data to the receiver after sending it to the receiver through the business risk control method provided in this manual. The amount of information that may be leaked.
  • the business risk control method provided in this specification can also be used to evaluate the security of the security protocol or encryption algorithm used in multi-party secure data transmission scenarios (such as multi-party secure computing or federated learning).
  • the terminal device can send the amount of information to the relevant maintenance personnel or trusted personnel in federated learning or multi-party secure computing, so that the relevant maintenance personnel can evaluate whether the security protocol or encryption algorithm used is safe based on the amount of information that may be leaked by the sender, and then adjust the security protocol or encryption algorithm, which is conducive to ensuring the security of the private data of each participant.
  • the present application can determine, based on the business data and the data to be sent, a first information entropy used to characterize the amount of information required for the recipient to obtain the full amount of business data when the recipient has not obtained the data to be sent, and determine a second information entropy used to characterize the amount of information required for the recipient to obtain the full amount of business data after obtaining the data to be sent. Then, based on the first information entropy and the second information entropy, determine the risk control information entropy used to characterize the amount of information leaked in the business data after the data to be sent is sent to the recipient, and then perform effective risk control on the execution of the business based on the risk control information entropy.
  • the present application removes the risk-free data contained in the data to be sent that will not cause business data leakage after being sent to the recipient, so as to ensure the accuracy of the amount of information leaked by the sender when sending the data to be sent (i.e., risk control information entropy).
  • FIG2 is a schematic diagram of a business risk control device provided in this specification, comprising: an acquisition module 200, used to acquire business data; a first determination module 202, used to determine the data to be sent according to the business data; a second determination module 204, used to determine the risk-free data from the data to be sent, and determine the remaining data in the data to be sent except the risk-free data, wherein the risk-free data is data that will not cause the business data to be leaked after being sent to the recipient; a third determination module 206, used to determine the first information entropy according to the business data, and determine the information entropy according to the business data and the remaining data; , determine a second information entropy, the first information entropy is used to characterize the amount of information required for the recipient to obtain the full amount of the business data when the recipient has not obtained the data to be sent, and the second information entropy is used to characterize the amount of information required for the recipient to obtain the full amount of the business data after obtaining the data to
  • the second determining module 204 is specifically configured to: The data obtained after the security protocol encrypts part of the business data is determined to be risk-free data.
  • the second determination module 204 is specifically configured to determine data obtained by encrypting part of the business data contained in the data to be sent using a private key as risk-free data.
  • the second determination module 204 is specifically configured to determine data obtained by masking part of the business data contained in the data to be sent using random numbers as risk-free data.
  • the third determination module 206 is specifically used to add the random number to the business data to determine the updated business data; determine the first information entropy based on the updated business data; and determine the second information entropy based on the updated business data and the remaining data.
  • the second determination module 204 is specifically configured to determine data with a derivation relationship from the data to be sent; and determine the data contained in the data to be sent that can be deduced based on the derivation relationship as risk-free data.
  • This specification also provides a computer-readable storage medium, which stores a computer program.
  • the computer program can be used to execute a business risk control method provided in FIG. 1 above.
  • FIG. 3 also provides a schematic structural diagram of an electronic device corresponding to Figure 1, as shown in Figure 3.
  • the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and of course may also include hardware required for other services.
  • the processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the business risk control method of Figure 1 above.
  • this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc., that is to say, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
  • a programmable logic device such as a field programmable gate array (FPGA)
  • FPGA field programmable gate array
  • HDL Hardware Description Language
  • ABEL Advanced Boolean Expression Language
  • AHDL Altera Hardware Description Language
  • HDCal JHDL
  • Lava Lava
  • Lola MyHDL
  • PALASM RHDL
  • VHDL Very-High-Speed Integrated Circuit Hardware Description Language
  • Verilog Verilog
  • the controller may be implemented in any suitable manner, for example, the controller may take the form of a microprocessor or processor and a computer readable medium storing a computer readable program code (e.g., software or firmware) executable by the (micro)processor, a logic gate, a switch, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320, and the memory controller may also be implemented as part of the control logic of the memory.
  • a computer readable program code e.g., software or firmware
  • the controller may be implemented in the form of a logic gate, a switch, an application specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, such a controller may be considered as a hardware component, and the means for implementing various functions included therein may also be considered as a structure within the hardware component. Or even, the means for implementing various functions may be considered as both a software module for implementing the method and a structure within the hardware component.
  • a typical implementation device is a computer.
  • the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
  • this specification may be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
  • computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
  • These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that implements the functions specified in one or more processes in the flowchart and/or one or more boxes in the block diagram.
  • These computer program instructions may also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and/or one or more boxes in the block diagram.
  • a computing device includes one or more processors (CPU), input/output interfaces, network interfaces, and memory.
  • processors CPU
  • input/output interfaces network interfaces
  • memory volatile and non-volatile memory
  • Memory may include non-permanent storage in a computer-readable medium, in the form of random access memory (RAM) and/or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of a computer-readable medium.
  • RAM random access memory
  • ROM read-only memory
  • flash RAM flash memory
  • Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information.
  • Information can be computer readable instructions, data structures, program modules or other data.
  • Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.
  • computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
  • this specification may be provided as methods, systems or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
  • computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
  • program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types.
  • This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network.
  • program modules may be located in local and remote computer storage media including storage devices.

Landscapes

  • Business, Economics & Management (AREA)
  • Human Resources & Organizations (AREA)
  • Engineering & Computer Science (AREA)
  • Strategic Management (AREA)
  • Entrepreneurship & Innovation (AREA)
  • Economics (AREA)
  • Operations Research (AREA)
  • Game Theory and Decision Science (AREA)
  • Development Economics (AREA)
  • Marketing (AREA)
  • Educational Administration (AREA)
  • Quality & Reliability (AREA)
  • Tourism & Hospitality (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

本说明书公开了一种业务风控的方法、装置、存储介质以及电子设备,获取业务数据,根据业务数据,确定待发送数据;从待发送数据中确定出无风险数据,并确定待发送数据中除无风险数据以外的剩余数据。无风险数据为发送给接收方后不会导致业务数据泄露的数据。根据业务数据,确定第一信息熵,以及根据业务数据和剩余数据,确定第二信息熵,第一信息熵用于表征在接收方未获取剩余数据的情况下获知全量业务数据所需的信息量,第二信息熵用于表征接收方在获取到剩余数据后获知全量业务数据所需的信息量。根据第一信息熵和第二信息熵,确定风控信息熵,执行业务风控,其中,风控信息熵用于表征将待发送数据发送给接收方后业务数据被泄露的信息量。

Description

一种业务风控的方法、装置、存储介质及电子设备 技术领域
本说明书涉及计算机技术领域,尤其涉及一种业务风控的方法、装置、存储介质及电子设备。
背景技术
随着互联网技术的快速发展,隐私数据的保护和业务风控越来越受到大众的关注。在这一驱动下,推出了诸如联邦学习、多方安全计算等相关技术,通过这些技术,可以在实现业务目的的情况下,尽可能降低用户私有数据泄露的情况发生。
然而,基于联邦学习、多方安全计算等相关技术来执行业务的过程中,依然会存在私有数据泄露的情况,因此,如何对基于这些相关技术而执行的业务进行有效地风控,则是一个亟待解决的问题。
发明内容
本说明书提供一种业务风控的方法、装置、存储介质及电子设备,以解决在各个参与方参与联邦学习或多方安全计算时,对执行的业务进行有效地风控的问题。
本说明书采用下述技术方案:本说明书提供了一种业务风控的方法,包括:获取业务数据;根据所述业务数据,确定待发送数据;从所述待发送数据中确定出无风险数据,并确定所述待发送数据中除所述无风险数据以外的剩余数据,所述无风险数据为发送给接收方后不会导致所述业务数据泄露的数据;根据所述业务数据,确定第一信息熵,以及根据所述业务数据和所述剩余数据,确定第二信息熵,所述第一信息熵用于表征在所述接收方未获取所述待发送数据的情况下获知全量所述业务数据所需的信息量,所述第二信息熵用于表征所述接收方在获取到所述待发送数据后获知全量所述业务数据所需的信息量;根据所述第一信息熵和所述第二信息熵,确定风控信息熵,所述风控信息熵用于表征将所述待发送数据发送给接收方后所述业务数据被泄露的信息量;根据所述风控信息熵,执行业务风控。
可选地,从所述待发送数据中确定出无风险数据,具体包括:将所述待发送数据中包含的通过预设的安全协议对部分所述业务数据进行加密后得到的数据,确定为无风险数据。
可选地,从所述待发送数据中确定出无风险数据,具体包括:将所述待发送数据中包含的使用私有密钥对部分所述业务数据进行加密后得到的数据,确定为无风险数据。
可选地,从所述待发送数据中确定出无风险数据,具体包括:将所述待发送数据中包含的使用随机数对部分所述业务数据进行掩盖后得到的数据,确定为无风险数据。
可选地,根据所述业务数据,确定第一信息熵,以及根据所述业务数据和所述剩余数据,确定第二信息熵,具体包括:将所述随机数添加到所述业务数据中,确定更新后业务数据;根据所述更新后业务数据,确定第一信息熵;根据所述更新后业务数据和所述剩余数据,确定第二信息熵。可选地,从所述待发送数据中确定出无风险数据,具体包括:从所述待发送数据中确定出存在推导关系的数据;将所述待发送数据中包含的基于所述推导关系能够被推出的数据,确定为无风险数据。
本说明书提供了一种业务风控的装置,包括:获取模块,用于获取业务数据;第一确定模块,用于根据所述业务数据,确定待发送数据;第二确定模块,用于从所述待发送数据中确定出无风险数据,并确定所述待发送数据中除所述无风险数据以外的剩余数据,所述无风险数据为发送给接收方后不会导致所述业务数据泄露的数据;第三确定模块,用于根据所述业务数据,确定第一信息熵,以及根据所述业务数据和所述剩余数据,确定第二信息熵,所述第一信息熵用于表征在所述接收方未获取所述待发送数据的情况下获知全量所述业务数据所需的信息量,所述第二信息熵用于表征所述接收方在获取到所述待发送数据后获知全量所述业务数据所需的信息量;第四确定模块,用于根据所述第一信息熵和所述第二信息熵,确定风控信息熵,所述风控信息熵用于表征将所述待发送数据发送给接收方后所述业务数据被泄露的信息量;执行模块,用于根据所述风控信息熵,执行业务风控。
可选地,第二确定模块具体用于,将所述待发送数据中包含的通过预设的安全协议对部分所述业务数据进行加密后得到的数据,确定为无风险数据。
可选地,第二确定模块具体用于,将所述待发送数据中包含的使用私有密钥对部分所述业务数据进行加密后得到的数据,确定为无风险数据。
可选地,第二确定模块具体用于,将所述待发送数据中包含的使用随机数对部分所述业务数据进行掩盖后得到的数据,确定为无风险数据。
可选地,第三确定模块具体用于,将所述随机数添加到所述业务数据中,确定更新后业务数据;根据所述更新后业务数据,确定第一信息熵;根据所述更新后业务数据和所述剩余数据,确定第二信息熵。
可选地,第二确定模块具体用于,从所述待发送数据中确定出存在推导关系的数据;将所述待发送数据中包含的基于所述推导关系能够被推出的数据,确定为无风险数据。
本说明书提供了一种计算机可读存储介质,所述存储介质存储有计算机程序,所述计算机程序被处理器执行时实现上述业务风控的方法。
本说明书提供了一种电子设备,包括存储器、处理器及存储在存储器上并可在处理 器上运行的计算机程序,所述处理器执行所述程序时实现上述业务风控的方法。
本说明书采用的上述至少一个技术方案能够达到以下有益效果:在本说明书提供的业务风控方法,获取业务数据,根据业务数据,确定待发送数据,从待发送数据中确定出无风险数据,并确定待发送数据中除无风险数据以外的剩余数据,无风险数据为发送给接收方后不会导致业务数据泄露的数据。根据业务数据,确定第一信息熵,以及根据业务数据和剩余数据,确定第二信息熵,第一信息熵用于表征在接收方未获取剩余数据的情况下获知全量业务数据所需的信息量,第二信息熵用于表征接收方在获取到剩余数据后获知全量业务数据所需的信息量。根据第一信息熵和第二信息熵确定风控信息熵,执行业务风控,风控信息熵用于表征将待发送数据发送给接收方后业务数据被泄露的信息量。
从上述方法中可以看出,本申请可以根据确定出的将待发送数据发送给接收方后可能泄露的业务数据的数据量的大小,来对业务的执行进行有效风控。并且,在计算发送方可能泄露的业务数据的数据量大小时,本申请将待发送数据中包含的发送给接收方后不会导致业务数据泄露的无风险数据从中剔除,这样能够保证确定出的发送待发送数据时发送方所泄露的信息量(即风控信息熵)的准确性。
附图说明
此处所说明的附图用来提供对本说明书的进一步理解,构成本说明书的一部分,本说明书的示意性实施例及其说明用于解释本说明书,并不构成对本说明书的不当限定。在附图中:
图1为本说明书中提供的一种业务风控的方法的流程示意图;
图2为本说明书提供的一种业务风控的方法的装置的示意图;
图3为本说明书提供的一种对应于图1的电子设备的示意图。
具体实施方式
为使本说明书的目的、技术方案和优点更加清楚,下面将结合本说明书具体实施例及相应的附图对本说明书技术方案进行清楚、完整地描述。显然,所描述的实施例仅是本说明书一部分实施例,而不是全部的实施例。基于本说明书中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本说明书保护的范围。
以下结合附图,详细说明本说明书各实施例提供的技术方案。
图1为本说明书中提供的一种业务风控的方法的流程示意图,包括步骤S100至步骤S110。
S100:获取业务数据。
S102:根据所述业务数据,确定待发送数据。
在相关技术中,在联邦学习和多方安全计算的过程中,各个参与方之间可能需要进行大量的数据交互以执行业务,在一个参与方发送数据给其他参与方的过程中,可能会导致自身私有数据的泄露,基于此,本申请应用于多方安全计算和联邦学习等多方安全数据传输的场景中,在各个参与方在进行数据交互以执行业务时,对可能泄露的数据进行有效的风险控制。
本申请的执行主体可以是参与多方安全计算和联邦学习等多方安全数据传输场景中的各个参与方所使用的终端设备,也可以是服务器,其中,终端设备可以包括诸如手机、平板电脑等移动设备。为了便于阐述,下面以终端设备为执行主体为例,对本申请提供的业务风控的方法进行说明。
在实际应用中,联邦学习和多方安全计算过程中有很多参与方,按照数据的传输方向,可以将参与方分为发送方和接收方,而在发送方向接收方发送数据以进行业务处理时,需要对业务的执行进行风控。
具体地,发送方所使用的终端设备可以获取本地的业务数据,该业务数据为发送方的私有业务数据,其他参与方不能获悉。在获取到业务数据后,基于业务数据,终端设备可以按照各个参与方约定好的规则,从业务数据中确定出部分数据,再对这部分数据进行数据处理(如加密处理)后,得到待发送数据,后续发送方所使用的终端设备可以将确定出的待发送数据发送给接收方。
S104:从所述待发送数据中确定出无风险数据,并确定所述待发送数据中除所述无风险数据以外的剩余数据,所述无风险数据为发送给接收方后不会导致所述业务数据泄露的数据。
为了确定发送方的终端设备在发送待发送数据时可能会泄露的信息量,需要假设接收方是存在问题(即不可信)的一方,那么发送方将待发送数据发送后,接收方可能会试图根据待发送数据来推测发送方的全量业务数据,此时发送方会存在一定的信息泄露的风险。
因此,发送方所使用的终端设备需要根据业务数据以及待发送数据,来估算出发送方业务数据泄露的数据量大小,再根据确定出的发送方泄露的数据量大小,来执行业务风控。
在本说明书中,发送方所使用的终端设备可以根据业务数据,确定出第一信息熵,第一信息熵用于表征假定在接收方未获取待发送数据的情况下获知全量业务数据所需 的信息量。进一步地,发送方所使用的终端设备还可以根据业务数据和待发送数据,确定出第二信息熵,第二信息熵用于表征假定接收方在获取到待发送数据后获知全量业务数据所需的信息量。
那么,发送方所使用的终端设备可以根据确定出的第一信息熵和第二信息熵,来确定出风控信息熵,风控信息熵用于表征将待发送数据发送给接收方后业务数据被泄露的信息量。
具体公式参考如下:H=H(C)-H(C|D)
其中,C表示业务数据,D表示待发送数据,H是风控信息熵,H(C)为第一信息熵,表征假定在接收方未获取待发送数据的情况下获知全量业务数据所需的信息量,H(C|D)为第二信息熵,表征接收方在获取到待发送数据后获知全量业务数据所需的信息量。
通过这种方式,发送方所使用的终端设备可以估算出发送方将待发送数据发送给接收方后发送方业务数据被泄露的信息量大小,而在确定出风控信息熵后,后续终端设备可以根据风控信息熵执行业务风控。
但是,在实际应用中,联邦学习和多方安全计算中有些交互的数据可能是经过加密,或是能够通过其他数据推导得到的,这样的数据不会导致业务数据被泄露,是不应该参与到风控信息熵的计算过程中的。所以,在确定风控信息熵时,发送方所使用的终端设备可以将这种无风险数据从待发送数据中剔除,以使最终确定出的风控信息熵更加准确。
在本说明书中,从待发送数据中确定发送给接收方后不会导致业务数据泄露的无风险数据可以分为四种情况。
具体地,终端设备可以将待发送数据中包含的通过预设的安全协议对部分业务数据进行加密后得到的数据,确定为无风险数据。
其中,预设的安全协议可以是指联邦学习或多方安全计算中所采用的安全协议,如MPC协议(Mobility Personal Computer,MPC)等,本说明书不对协议的类型进行限制。
例如,若待发送数据中包含的部分数据,是发送方所使用的终端设备通过安全协议进行加密后得到的,那么,终端设备可以将待发送数据中包含的这部分数据,确定为无风险数据。
当然,终端设备也可以将待发送数据中包含的使用私有密钥对部分业务数据进行加密后得到的数据,确定为无风险数据。
例如,若待发送数据中包含的部分数据,是终端设备通过一些加密算法对部分业务数据进行加密后得到的,那么,终端设备可以将待发送数据中包含的这部分数据,确定 为无风险数据。
其中,加密算法可以包括:散列消息认证算法(Hash-based Message Authentication Code,HAMC)、消息摘要算法(Message-Digest Algorithm MD5,MD5)等。本说明书不对具体的所采用的加密算法进行限定。
值得说明的是,终端设备在使用私有密钥对部分业务数据进行时,私有密钥必须由发送方独自持有,这样可以保证通过这种方式确定出的无风险数据被接收方获取后,也不会泄露业务数据。
此外,终端设备还可以将待发送数据中包含的使用随机数对部分业务数据进行掩盖后得到的数据,确定为无风险数据。
例如,若待发送数据中的部分数据,是由终端设备将部分业务数据加上或减去一个随机数后得到的,由于随机数只由发送方单独持有,这种掩盖也可以视为一种加密方式,使用随机数对部分业务数据进行掩盖后得到的数据也可以确定为无风险数据。
需要说明的是,由于使用随机数多次加密不安全,终端设备使用随机数加密只能进行一次。并且,终端设备使用随机数对部分业务数据进行掩盖时,随机数只由发送方单独持有,可以视为发送方的私有数据,终端设备可以将随机数添加到业务数据中,确定更新后业务数据。后续终端设备可以根据更新后业务数据,确定第一信息熵,以及根据更新后业务数据和待发送数据,确定第二信息熵。
除此之外,终端设备还可以从待发送数据中确定出存在推导关系的数据,并将待发送数据中包含的基于推导关系能够被推出的数据,确定为无风险数据。
例如,若待发送数据中包含有A、B、C三个数据,且三个数据之间存在着这样的推导关系:A=B+C,根据B和C以及推导关系能够推导出A,那么,终端设备可以将A确定为无风险数据。
上述推导关系只是一个示例,若待发送数据中包含的数据存在类似的推导关系,那么终端设备可以将待发送数据中包含的基于推导关系能够被推出的数据确定为无风险数据。
S106:根据所述业务数据,确定第一信息熵,以及根据所述业务数据和所述剩余数据,确定第二信息熵,所述第一信息熵用于表征在所述接收方未获取所述待发送数据的情况下获知全量所述业务数据所需的信息量,所述第二信息熵用于表征所述接收方在获取到所述待发送数据后获知全量所述业务数据所需的信息量。
S108:根据所述第一信息熵和所述第二信息熵,确定风控信息熵,所述风控信息熵用于表征将所述待发送数据发送给接收方后所述业务数据被泄露的信息量。
S110:根据所述风控信息熵,执行业务风控。
通过上述方法,从待发送数据中确定无风险数据和除无风险数据以外的剩余数据后,发送方所使用的终端设备可以基于业务数据和剩余数据,更加准确地确定出第二信息熵,进而根据第一信息熵和第二信息熵,确定出风控信息熵,风控信息熵用于表征将待发送数据发送给接收方后业务数据被泄露的信息量。
具体公式参考如下:H=H(C)-H(C|D′)
其中,C表示业务数据,D′表示待发送数据中的剩余数据,H是风控信息熵,H(C)是第一信息熵,表征假定在接收方未获取待发送数据的情况下获知全量业务数据所需的信息量,H(C|D′)是第二信息熵,表示假定接收方在获取到剩余数据后获知发送方全量业务数据所需的信息量。
例如,假设接收方在未获取待发送数据的情况下获知发送方全量业务数据所需的信息量为100MB,接收方在获取到待发送数据中的剩余数据后获知发送方全量业务数据所需的信息量为30MB,那么发送方将待发送数据发送给接收方后业务数据被泄露的信息量为70MB。
需要说明的是,上述示例是基于发送方泄露的具体数据量的大小来进行说明的,在本说明书中,终端设备也可以根据发送方的业务数据和待发送数据确定出第一信息熵和第二信息熵,再根据第一信息熵和第二信息熵确定用于表征接收方在获取到待发送数据后获知全量业务数据所需信息量的风控信息熵。
通过这种方式确定出风控信息熵后,终端设备可以基于发送方将待发送数据发送给接收方后业务数据被泄露的信息量,进而基于风控信息熵执行风控。
具体的,在终端设备确定出风控信息熵后,可以将风控信息熵展示给用户,以使用户基于该风控信息熵,决定是否将待发送数据发送给接收方。
除此之外,终端设备也可以通过其他方式来执行业务风控。例如,若终端设备通过风控信息熵确定发送方所泄露的信息量超过了预设阈值,或是确定出风控信息熵未落入预设的安全信息熵范围内,此时发送方所使用的终端设备可以阻止发送该待发送数据。
需要说明的是,实际上在联邦学习和多方安全计算的过程中,可能会存在一个参与方发送数据,多个参与方接收数据的情况,所以,本说明书中上述提到的接收方可以是多个接收方,此时上述待发送数据即为发送方发送给所有接收方数据的总和。
在这种情况下,假设多个接收方在分别接收到发送方发送的数据后,共同联合起来试图根据接收到的数据来推测发送方的全量业务数据,此时,发送方所使用的终端设备可以通过本说明书提供的业务风控的方法,确定出将发送待发送数据发送给接收方后自 身可能泄露的信息量。
值得说明的是,本说明书提供的业务风控的方法,也可以用于评估在多方安全数据传输场景中(如多方安全计算或联邦学习)中所使用的安全协议或加密算法的安全性。在确定出发送待发送数据时发送方所泄露的信息量后,终端设备可以将该信息量发送给联邦学习或多方安全计算中的相关维护人员或可信任的人员,以使相关维护人员可以根据发送方可能泄露的信息量,来评估所使用的安全协议或加密算法是否安全,进而对安全协议或加密算法进行调整,这样有利于保证各个参与方私有数据的安全性。
从上述方法中可以看出,本申请可以根据业务数据和待发送数据确定用于表征接收方未获取待发送数据的情况下获知全量业务数据所需信息量的第一信息熵,以及确定用于表征接收方在获取到待发送数据后获知全量业务数据所需信息量的第二信息熵,进而根据第一信息熵和第二信息熵,确定用于表征将待发送数据发送给接收方后业务数据被泄露信息量的风控信息熵,再基于风控信息熵对业务的执行进行有效风控。
这样有利于参与方在参与联邦学习或多方安全计算的过程中,能够获知自身将待发送数据发送给接收方后泄露信息量的大小,进而控制泄露的信息量。并且,在确定发送方可能泄露的业务数据的数据量大小时,本申请将待发送数据中包含的发送给接收方后不会导致业务数据泄露的无风险数据从中剔除,这样能够保证确定出的发送待发送数据时发送方所泄露的信息量(即风控信息熵)的准确性。
以上为本说明书的一个或多个实施例提供的业务风控的方法,基于同样的思路,本说明书还提供了相应的业务风控的装置,如图2所示。
图2为本说明书提供的一种业务风控装置的示意图,包括:获取模块200,用于获取业务数据;第一确定模块202,用于根据所述业务数据,确定待发送数据;第二确定模块204,用于从所述待发送数据中确定出无风险数据,并确定所述待发送数据中除所述无风险数据以外的剩余数据,所述无风险数据为发送给接收方后不会导致所述业务数据泄露的数据;第三确定模块206,用于根据所述业务数据,确定第一信息熵,以及根据所述业务数据和所述剩余数据,确定第二信息熵,所述第一信息熵用于表征在所述接收方未获取所述待发送数据的情况下获知全量所述业务数据所需的信息量,所述第二信息熵用于表征所述接收方在获取到所述待发送数据后获知全量所述业务数据所需的信息量;第四确定模块208,用于根据所述第一信息熵和所述第二信息熵,确定风控信息熵,所述风控信息熵用于表征将所述待发送数据发送给接收方后所述业务数据被泄露的信息量;执行模块210,用于根据所述风控信息熵,执行业务风控。
可选地,所述第二确定模块204具体用于,将所述待发送数据中包含的通过预设的 安全协议对部分所述业务数据进行加密后得到的数据,确定为无风险数据。
可选地,所述第二确定模块204具体用于,将所述待发送数据中包含的使用私有密钥对部分所述业务数据进行加密后得到的数据,确定为无风险数据。
可选地,所述第二确定模块204具体用于,将所述待发送数据中包含的使用随机数对部分所述业务数据进行掩盖后得到的数据,确定为无风险数据。
可选地,所述第三确定模块206具体用于,将所述随机数添加到所述业务数据中,确定更新后业务数据;根据所述更新后业务数据,确定第一信息熵;根据所述更新后业务数据和所述剩余数据,确定第二信息熵。
可选地,所述第二确定模块204具体用于,从所述待发送数据中确定出存在推导关系的数据;将所述待发送数据中包含的基于所述推导关系能够被推出的数据,确定为无风险数据。
本说明书还提供了一种计算机可读存储介质,该存储介质存储有计算机程序,计算机程序可用于执行上述图1提供的一种业务风控的方法。
本说明书还提供了图3所示的一种对应于图1的电子设备的示意结构图。如图3,在硬件层面,该电子设备包括处理器、内部总线、网络接口、内存以及非易失性存储器,当然还可能包括其他业务所需要的硬件。处理器从非易失性存储器中读取对应的计算机程序到内存中然后运行,以实现上述图1的业务风控的方法。当然,除了软件实现方式之外,本说明书并不排除其他实现方式,比如逻辑器件抑或软硬件结合的方式等等,也就是说以下处理流程的执行主体并不限定于各个逻辑单元,也可以是硬件或逻辑器件。
在20世纪90年代,对于一个技术的改进可以很明显地区分是硬件上的改进(例如,对二极管、晶体管、开关等电路结构的改进)还是软件上的改进(对于方法流程的改进)。然而,随着技术的发展,当今的很多方法流程的改进已经可以视为硬件电路结构的直接改进。设计人员几乎都通过将改进的方法流程编程到硬件电路中来得到相应的硬件电路结构。因此,不能说一个方法流程的改进就不能用硬件实体模块来实现。例如,可编程逻辑器件(Programmable Logic Device,PLD)(例如现场可编程门阵列(Field Programmable Gate Array,FPGA))就是这样一种集成电路,其逻辑功能由用户对器件编程来确定。由设计人员自行编程来把一个数字系统“集成”在一片PLD上,而不需要请芯片制造厂商来设计和制作专用的集成电路芯片。而且,如今,取代手工地制作集成电路芯片,这种编程也多半改用“逻辑编译器(logic compiler)”软件来实现,它与程序开发撰写时所用的软件编译器相类似,而要编译之前的原始代码也得用特定的编程语言来撰写,此称之为硬件描述语言(Hardware Description Language,HDL),而HDL也并 非仅有一种,而是有许多种,如ABEL(Advanced Boolean Expression Language)、AHDL(Altera Hardware Description Language)、Confluence、CUPL(Cornell University Programming Language)、HDCal、JHDL(Java Hardware Description Language)、Lava、Lola、MyHDL、PALASM、RHDL(Ruby Hardware Description Language)等,目前最普遍使用的是VHDL(Very-High-Speed Integrated Circuit Hardware Description Language)与Verilog。本领域技术人员也应该清楚,只需要将方法流程用上述几种硬件描述语言稍作逻辑编程并编程到集成电路中,就可以很容易得到实现该逻辑方法流程的硬件电路。
控制器可以按任何适当的方式实现,例如,控制器可以采取例如微处理器或处理器以及存储可由该(微)处理器执行的计算机可读程序代码(例如软件或固件)的计算机可读介质、逻辑门、开关、专用集成电路(Application Specific Integrated Circuit,ASIC)、可编程逻辑控制器和嵌入微控制器的形式,控制器的例子包括但不限于以下微控制器:ARC 625D、Atmel AT91SAM、Microchip PIC18F26K20以及Silicone Labs C8051F320,存储器控制器还可以被实现为存储器的控制逻辑的一部分。本领域技术人员也知道,除了以纯计算机可读程序代码方式实现控制器以外,完全可以通过将方法步骤进行逻辑编程来使得控制器以逻辑门、开关、专用集成电路、可编程逻辑控制器和嵌入微控制器等的形式来实现相同功能。因此这种控制器可以被认为是一种硬件部件,而对其内包括的用于实现各种功能的装置也可以视为硬件部件内的结构。或者甚至,可以将用于实现各种功能的装置视为既可以是实现方法的软件模块又可以是硬件部件内的结构。
上述实施例阐明的系统、装置、模块或单元,具体可以由计算机芯片或实体实现,或者由具有某种功能的产品来实现。一种典型的实现设备为计算机。具体的,计算机例如可以为个人计算机、膝上型计算机、蜂窝电话、相机电话、智能电话、个人数字助理、媒体播放器、导航设备、电子邮件设备、游戏控制台、平板计算机、可穿戴设备或者这些设备中的任何设备的组合。
为了描述的方便,描述以上装置时以功能分为各种单元分别描述。当然,在实施本说明书时可以把各单元的功能在同一个或多个软件和/或硬件中实现。
本领域内的技术人员应明白,本说明书的实施例可提供为方法、系统、或计算机程序产品。因此,本说明书可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本说明书可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本说明书是参照根据本说明书实施例的方法、设备(系统)、和计算机程序产品的 流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
在一个典型的配置中,计算设备包括一个或多个处理器(CPU)、输入/输出接口、网络接口和内存。
内存可能包括计算机可读介质中的非永久性存储器,随机存取存储器(RAM)和/或非易失性内存等形式,如只读存储器(ROM)或闪存(flash RAM)。内存是计算机可读介质的示例。
计算机可读介质包括永久性和非永久性、可移动和非可移动媒体可以由任何方法或技术来实现信息存储。信息可以是计算机可读指令、数据结构、程序的模块或其他数据。计算机的存储介质的例子包括,但不限于相变内存(PRAM)、静态随机存取存储器(SRAM)、动态随机存取存储器(DRAM)、其他类型的随机存取存储器(RAM)、只读存储器(ROM)、电可擦除可编程只读存储器(EEPROM)、快闪记忆体或其他内存技术、只读光盘只读存储器(CD-ROM)、数字多功能光盘(DVD)或其他光学存储、磁盒式磁带,磁带磁磁盘存储或其他磁性存储设备或任何其他非传输介质,可用于存储可以被计算设备访问的信息。按照本文中的界定,计算机可读介质不包括暂存电脑可读媒体(transitory media),如调制的数据信号和载波。
还需要说明的是,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、商品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、商品或者设备所固有 的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括要素的过程、方法、商品或者设备中还存在另外的相同要素。
本领域技术人员应明白,本说明书的实施例可提供为方法、系统或计算机程序产品。因此,本说明书可采用完全硬件实施例、完全软件实施例或结合软件和硬件方面的实施例的形式。而且,本说明书可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本说明书可以在由计算机执行的计算机可执行指令的一般上下文中描述,例如程序模块。一般地,程序模块包括执行特定任务或实现特定抽象数据类型的例程、程序、对象、组件、数据结构等等。也可以在分布式计算环境中实践本说明书,在这些分布式计算环境中,由通过通信网络而被连接的远程处理设备来执行任务。在分布式计算环境中,程序模块可以位于包括存储设备在内的本地和远程计算机存储介质中。
本说明书中的各个实施例均采用递进的方式描述,各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于系统实施例而言,由于其基本相似于方法实施例,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
以上为本说明书的实施例,并不用于限制本说明书。对于本领域技术人员来说,本说明书可以有各种更改和变化。凡在本说明书的精神和原理之内所作的任何修改、等同替换、改进等,均应包含在本说明书的权利要求范围之内。

Claims (14)

  1. 一种业务风控的方法,包括:
    获取业务数据;
    根据所述业务数据,确定待发送数据;
    从所述待发送数据中确定出无风险数据,并确定所述待发送数据中除所述无风险数据以外的剩余数据,所述无风险数据为发送给接收方后不会导致所述业务数据泄露的数据;
    根据所述业务数据,确定第一信息熵,以及根据所述业务数据和所述剩余数据,确定第二信息熵,所述第一信息熵用于表征在所述接收方未获取所述待发送数据的情况下获知全量所述业务数据所需的信息量,所述第二信息熵用于表征所述接收方在获取到所述待发送数据后获知全量所述业务数据所需的信息量;
    根据所述第一信息熵和所述第二信息熵,确定风控信息熵,所述风控信息熵用于表征将所述待发送数据发送给接收方后所述业务数据被泄露的信息量;
    根据所述风控信息熵,执行业务风控。
  2. 如权利要求1所述的方法,从所述待发送数据中确定出无风险数据,包括:
    将所述待发送数据中包含的通过预设的安全协议对部分所述业务数据进行加密后得到的数据,确定为无风险数据。
  3. 如权利要求1所述的方法,从所述待发送数据中确定出无风险数据,包括:
    将所述待发送数据中包含的使用私有密钥对部分所述业务数据进行加密后得到的数据,确定为无风险数据。
  4. 如权利要求1所述的方法,从所述待发送数据中确定出无风险数据,包括:
    将所述待发送数据中包含的使用随机数对部分所述业务数据进行掩盖后得到的数据,确定为无风险数据。
  5. 如权利要求4所述的方法,根据所述业务数据,确定第一信息熵,以及根据所述业务数据和所述剩余数据,确定第二信息熵,包括:
    将所述随机数添加到所述业务数据中,确定更新后业务数据;
    根据所述更新后业务数据,确定第一信息熵;
    根据所述更新后业务数据和所述剩余数据,确定第二信息熵。
  6. 如权利要求1所述的方法,从所述待发送数据中确定出无风险数据,包括:
    从所述待发送数据中确定出存在推导关系的数据;
    将所述待发送数据中包含的基于所述推导关系能够被推出的数据,确定为无风险数 据。
  7. 一种业务风控的装置,包括:
    获取模块,用于获取业务数据;
    第一确定模块,用于根据所述业务数据,确定待发送数据;
    第二确定模块,用于从所述待发送数据中确定出无风险数据,并确定所述待发送数据中除所述无风险数据以外的剩余数据,所述无风险数据为发送给接收方后不会导致所述业务数据泄露的数据;
    第三确定模块,用于根据所述业务数据,确定第一信息熵,以及根据所述业务数据和所述剩余数据,确定第二信息熵,所述第一信息熵用于表征在所述接收方未获取所述待发送数据的情况下获知全量所述业务数据所需的信息量,所述第二信息熵用于表征所述接收方在获取到所述待发送数据后获知全量所述业务数据所需的信息量;
    第四确定模块,用于根据所述第一信息熵和所述第二信息熵,确定风控信息熵,所述风控信息熵用于表征将所述待发送数据发送给接收方后所述业务数据被泄露的信息量;
    执行模块,用于根据所述风控信息熵,执行业务风控。
  8. 如权利要求7所述的装置,第二确定模块用于,将所述待发送数据中包含的通过预设的安全协议对部分所述业务数据进行加密后得到的数据,确定为无风险数据。
  9. 如权利要求7所述的装置,第二确定模块用于,将所述待发送数据中包含的使用私有密钥对部分所述业务数据进行加密后得到的数据,确定为无风险数据。
  10. 如权利要求7所述的装置,第二确定模块用于,将所述待发送数据中包含的使用随机数对部分所述业务数据进行掩盖后得到的数据,确定为无风险数据。
  11. 如权利要求10所述的装置,第三确定模块用于,将所述随机数添加到所述业务数据中,确定更新后业务数据;根据所述更新后业务数据,确定第一信息熵;根据所述更新后业务数据和所述剩余数据,确定第二信息熵。
  12. 如权利要求7所述的装置,第二确定模块用于,从所述待发送数据中确定出存在推导关系的数据;将所述待发送数据中包含的基于所述推导关系能够被推出的数据,确定为无风险数据。
  13. 一种计算机可读存储介质,所述存储介质存储有计算机程序,所述计算机程序被处理器执行时实现上述权利要求1~6任一项所述的方法。
  14. 一种电子设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,所述处理器执行所述程序时实现上述权利要求1~6任一项所述的方法。
PCT/CN2024/085162 2023-04-04 2024-04-01 一种业务风控的方法、装置、存储介质及电子设备 Ceased WO2024208129A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202310396957.1A CN116151627B (zh) 2023-04-04 2023-04-04 一种业务风控的方法、装置、存储介质及电子设备
CN202310396957.1 2023-04-04

Publications (1)

Publication Number Publication Date
WO2024208129A1 true WO2024208129A1 (zh) 2024-10-10

Family

ID=86340982

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2024/085162 Ceased WO2024208129A1 (zh) 2023-04-04 2024-04-01 一种业务风控的方法、装置、存储介质及电子设备

Country Status (2)

Country Link
CN (1) CN116151627B (zh)
WO (1) WO2024208129A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN120074947A (zh) * 2025-04-23 2025-05-30 山东宏业发展集团有限公司 一种智能化电子信息交换处理方法及系统

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116151627B (zh) * 2023-04-04 2023-09-01 支付宝(杭州)信息技术有限公司 一种业务风控的方法、装置、存储介质及电子设备
CN120074743A (zh) * 2023-11-30 2025-05-30 华为技术有限公司 一种通信方法
CN117313063B (zh) * 2023-11-30 2024-03-22 浙江尚链信息科技有限责任公司 一种基于多方安全计算的数据响应监测管理方法及系统

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2006054638A (ja) * 2004-08-11 2006-02-23 Research Organization Of Information & Systems 量子鍵配送方法および通信装置
CN112765559A (zh) * 2020-12-29 2021-05-07 平安科技(深圳)有限公司 联邦学习的过程中模型参数的处理方法、装置及相关设备
US20220014501A1 (en) * 2018-11-13 2022-01-13 Wenspire Method and device for monitoring data output by a server
CN115062299A (zh) * 2022-07-26 2022-09-16 华控清交信息科技(北京)有限公司 一种针对数据泄露的安全性检测方法、装置及电子设备
CN115134067A (zh) * 2022-06-29 2022-09-30 蚂蚁区块链科技(上海)有限公司 检测隐私数据泄漏的方法
CN116151627A (zh) * 2023-04-04 2023-05-23 支付宝(杭州)信息技术有限公司 一种业务风控的方法、装置、存储介质及电子设备

Family Cites Families (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9166999B1 (en) * 2014-07-25 2015-10-20 Fmr Llc Security risk aggregation, analysis, and adaptive control
US20170124492A1 (en) * 2015-10-28 2017-05-04 Fractal Industries, Inc. System for automated capture and analysis of business information for reliable business venture outcome prediction
US11366909B2 (en) * 2016-06-10 2022-06-21 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
CN108280769A (zh) * 2018-02-01 2018-07-13 阿里巴巴集团控股有限公司 理赔业务的数据处理方法、装置、电子设备、服务器
CN109359470B (zh) * 2018-08-14 2020-09-01 阿里巴巴集团控股有限公司 多方安全计算方法及装置、电子设备
CN110147967B (zh) * 2019-05-28 2023-05-30 创新先进技术有限公司 风险防控方法及装置
CN111046425B (zh) * 2019-12-12 2021-07-13 支付宝(杭州)信息技术有限公司 多方联合进行风险识别的方法和装置
CN111080123A (zh) * 2019-12-14 2020-04-28 支付宝(杭州)信息技术有限公司 用户风险评估方法及装置、电子设备、存储介质
CN111222165B (zh) * 2020-01-10 2022-09-23 北京百度网讯科技有限公司 基于区块链的多方计算方法、装置、设备和介质
CN111160814A (zh) * 2020-04-01 2020-05-15 支付宝(杭州)信息技术有限公司 基于多方安全计算的用户风险评估方法、装置和系统
CN111538875B (zh) * 2020-04-27 2023-07-14 支付宝(杭州)信息技术有限公司 业务指标采集方法、装置及风控设备
CN111966715B (zh) * 2020-08-17 2024-06-07 支付宝(杭州)信息技术有限公司 一种业务处理方法、装置、电子设备和存储介质
CN112465393B (zh) * 2020-12-09 2022-07-08 南威软件股份有限公司 基于关联分析FP-Tree算法的企业风险预警方法
CN114692717A (zh) * 2020-12-31 2022-07-01 华为技术有限公司 树模型训练方法、装置和系统
CN113159781B (zh) * 2021-03-25 2022-06-07 支付宝(杭州)信息技术有限公司 保护隐私数据的风险检测方法和装置
CN113312667B (zh) * 2021-06-07 2022-09-02 支付宝(杭州)信息技术有限公司 一种风险防控方法、装置及设备
CN115174212A (zh) * 2022-07-05 2022-10-11 北京威努特技术有限公司 一种利用熵技术甄别网络数据传输是否加密的方法
CN115640998A (zh) * 2022-10-21 2023-01-24 杭州安恒信息技术股份有限公司 一种风险评估方法、装置、设备及存储介质
CN115545720B (zh) * 2022-11-29 2023-03-10 支付宝(杭州)信息技术有限公司 一种模型训练的方法、业务风控的方法及装置

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2006054638A (ja) * 2004-08-11 2006-02-23 Research Organization Of Information & Systems 量子鍵配送方法および通信装置
US20220014501A1 (en) * 2018-11-13 2022-01-13 Wenspire Method and device for monitoring data output by a server
CN112765559A (zh) * 2020-12-29 2021-05-07 平安科技(深圳)有限公司 联邦学习的过程中模型参数的处理方法、装置及相关设备
CN115134067A (zh) * 2022-06-29 2022-09-30 蚂蚁区块链科技(上海)有限公司 检测隐私数据泄漏的方法
CN115062299A (zh) * 2022-07-26 2022-09-16 华控清交信息科技(北京)有限公司 一种针对数据泄露的安全性检测方法、装置及电子设备
CN116151627A (zh) * 2023-04-04 2023-05-23 支付宝(杭州)信息技术有限公司 一种业务风控的方法、装置、存储介质及电子设备

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
ANONYMOUS: "Measurement of Information-Entropy", JIANSHU, 1 June 2019 (2019-06-01), XP093220078, Retrieved from the Internet <URL:www.jianshu.com/p/9f1bb824f912> *
PENG CHANGGEN, DING HONG-FA; ZHU YI-JIE; TIAN YOU-LIANG; FU ZU-FENG: "Information Entropy Models and Privacy Metrics Methods for Privacy Protection", JOURNAL OF SOFTWARE, vol. 27, no. 8, 1 January 2016 (2016-01-01), pages 1891 - 1903, XP093220079, ISSN: 1000-9825, DOI: 10.13328/j.cnki.jos.005096] *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN120074947A (zh) * 2025-04-23 2025-05-30 山东宏业发展集团有限公司 一种智能化电子信息交换处理方法及系统

Also Published As

Publication number Publication date
CN116151627B (zh) 2023-09-01
CN116151627A (zh) 2023-05-23

Similar Documents

Publication Publication Date Title
WO2024208129A1 (zh) 一种业务风控的方法、装置、存储介质及电子设备
CN107196989B (zh) 一种业务请求的处理方法及装置
CN110162551B (zh) 数据处理方法、装置和电子设备
TW202103034A (zh) 資料處理方法、裝置和電子設備
CN113708930B (zh) 隐私数据的数据比较方法、装置、设备及介质
CN113821817B (zh) 基于区块链的数据处理方法、装置、设备及系统
CN111342966B (zh) 一种数据的存储方法、数据的恢复方法、装置及设备
CN113935737B (zh) 基于区块链的随机数生成方法及装置
TW201923647A (zh) 可溯源的多方數據處理方法、裝置及設備
CN107277028B (zh) 在应用间传输聊天表情的方法及装置、设备、存储介质
US10790961B2 (en) Ciphertext preprocessing and acquisition
CN117201034A (zh) 一种数字签名的方法、装置、存储介质及电子设备
TW202018645A (zh) 基於區塊鏈的資料處理方法、裝置和伺服器
WO2021017424A1 (zh) 数据预处理方法、密文数据获取方法、装置和电子设备
WO2025035679A1 (zh) 一种数据聚合的方法、装置、存储介质及电子设备
US11194824B2 (en) Providing oblivious data transfer between computing devices
WO2024152798A1 (zh) 一种数据风险评估的方法、装置、存储介质及电子设备
WO2024187902A1 (zh) 一种模型训练方法、装置、存储介质以及电子设备
CN113673844B (zh) 一种信息反馈方法、装置及设备
CN118611927A (zh) 一种数据传输方法、装置、存储介质及电子设备
WO2025077658A1 (zh) 一种业务执行方法、装置、存储介质及电子设备
CN116226902A (zh) 一种数据查询方法、装置、存储介质及电子设备
CN116629381A (zh) 一种联邦迁移学习方法、装置、存储介质及电子设备
CN111460514A (zh) 数据匹配方法、装置和电子设备
CN114599032B (zh) 基于盐值加密的短信传输方法、装置、设备和介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24784213

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 24784213

Country of ref document: EP

Kind code of ref document: A1