IP Library Granted Patent US 11,570,194
Granted Patent B2
US 11,570,194 · App. 16/722,943 · Granted Jan 31, 2023

Identifying high risk computing operations

Inventors: Jupeng Xia (Hangzhou, CN); Caiwei Li (Hanzhou, CN)
Assignee: Advanced New Technologies Co., Ltd.
H04L63/1433G06Q20/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,570,194
App. No.
16/722,943
Granted
Jan 31, 2023
Kind
B2
Abstract

This specification discloses techniques for risk identification. One example method includes receiving, by a client device, a risk identification request identifying a requested service operation and service data associated with the requested service operation; retrieving, by the client device, service data corresponding to the risk identification request; determining, by the client device, service indicator data associated with the service data; analyzing, by the client device, one or more of the service data and the service indicator based on a risk identification rule or a risk identification model to produce a risk result; and determining, by the client device, whether the requested service operation is a high risk operation based at least in part on the risk result.

Claims (62)

1. A computer-implemented method for risk identification, the method comprising:

receiving, by a client device and from a server device, a risk identification model;

receiving, by the client device, a request to perform a service operation;

in response to the requested service operation, receiving, by the client device, a risk identification request associated with the requested service operation, wherein the requested service operation comprises a payment operation;

retrieving, by the client device and based on the requested service operation, service data corresponding to the risk identification request, wherein the service data comprises a payment amount;

determining, by the client device, service indicator data associated with the service data, wherein the service indicator data comprises a variance of a plurality of payment amounts of a plurality of service operations requested in a predetermined time window, wherein the plurality of payment amounts comprise the payment amount;

performing, by the client device and based on the risk identification model, logic analysis on the service indicator data;

performing, by the client device and based on the risk identification model, probability analysis on at least one of the service data and the service indicator data to obtain a risk probability;

determining, by the client device, that the requested service operation is a high risk operation based at least in part on a result of the logic analysis and the risk probability, wherein the result of the logic analysis indicates that (i) the variance of the plurality of payment amounts is less than a first predetermined threshold and (ii) a quantity of the plurality of service operations is greater than a second predetermined threshold; and

in response to the determining that the requested service operation is a high risk operation, restricting, by the client device, an operation permission of the requested service operation.

2. The method according to claim 1 , wherein the determining the service indicator data associated with the service data comprises:

generating, by the client device, the service indicator data based on the service data.

3. The method according to claim 2 , further comprising:

in response to the generating, by the client device, the service indicator data based on the service data, reporting, by the client device, the service indicator data to the server device.

4. The method according to claim 1 , wherein the determining the service indicator data comprises:

reporting, by the client device, the service data to the server device; and

receiving, by the client device, the service indicator data calculated by the server device based on the service data.

5. The method according to claim 1 , wherein the service indicator data comprises at least one of a frequency feature of the requested service operation, a running environment feature of the client device, a count value, a sum value, a first value, a last value, a distinction value, an average value, a standard deviation, a maximum value, or a minimum value of data generated by the requested service operation in the predetermined time window.

6. The method according to claim 1 , wherein the determining that the requested service operation is a high risk operation comprises:

receiving, by the client device, an additional result of logic analysis performed by the server device on the service data and the service indicator data based on a risk identification rule, and determining whether the requested service operation is a high risk operation based on the additional result of the logic analysis.

7. The method according to claim 1 , wherein the determining that the requested service operation is a high risk operation comprises:

receiving, by the client device, a result of probability analysis performed by the server device on the service data and the service indicator data based on the risk identification model, and determining whether the requested service operation is a high risk operation based on the result of the probability analysis.

8. The method according to claim 1 , wherein the determining that the requested service operation is a high risk operation is based at least in part on configuration data, wherein the configuration data comprises at least one of service indicator update data, a risk identification rule, or a risk-free list.

9. The method according to claim 1 , further comprising:

in response to the determining that the requested service operation is a high risk operation, determining a processing method for the requested service operation based on a risk identification result indicating whether the requested service operation is a high risk operation.

10. The method according to claim 1 , wherein the restricting the operation permission of the requested service operation is performed in response to receiving a restriction request from the server device.

11. The method according to claim 10 , further comprising:

removing the restriction on the operation permission of the requested service operation in response to receiving a restriction removal verification request.

12. The computer-implemented method of claim 1 , wherein the service indicator data comprises the quantity of the plurality of service operations, and wherein the result of the logic analysis further indicates that the payment amount is greater than a third predetermined threshold.

13. The computer-implemented method of claim 1 , comprising:

receiving, by the client device and from the server device, a risk-free list, wherein the service data comprises a user account, and wherein the determining that the requested service operation is a high risk operation comprises determining, by the client device, that the user account is not in the risk-free list.

14. The computer-implemented method of claim 1 , wherein the service indicator data comprises an attenuation degree of a battery of the client device.

15. A non-transitory, computer-readable medium storing one or more instructions that, when executed by a computer system, cause the computer system to perform operations comprising:

receiving, by a client device and from a server device, a risk identification model;

receiving, by the client device, a request to perform a service operation;

in response to the requested service operation, receiving, by the client device, a risk identification request associated with the requested service operation, wherein the requested service operation comprises a payment operation;

retrieving, by the client device and based on the requested service operation, service data corresponding to the risk identification request, wherein the service data comprises a payment amount;

determining, by the client device, service indicator data associated with the service data, wherein the service indicator data comprises a variance of a plurality of payment amounts of a plurality of service operations requested in a predetermined time window, wherein the plurality of payment amounts comprise the payment amount;

performing, by the client device and based on the risk identification model, logic analysis on the service indicator data;

performing, by the client device and based on the risk identification model, probability analysis on at least one of the service data and the service indicator data to obtain a risk probability;

determining, by the client device, that the requested service operation is a high risk operation based at least in part on a result of the logic analysis and the risk probability, wherein the result of the logic analysis indicates that (i) the variance of the plurality of payment amounts is less than a first predetermined threshold and (ii) a quantity of the plurality of service operations is greater than a second predetermined threshold; and

in response to the determining that the requested service operation is a high risk operation, restricting, by the client device, an operation permission of the requested service operation.

16. The non-transitory, computer-readable medium according to claim 14 , wherein the determining the service indicator data associated with the service data comprises:

generating, by the client device, the service indicator data based on the service data.

17. The non-transitory, computer-readable medium according to claim 15 , the operations further comprising:

in response to the generating, by the client device, the service indicator data based on the service data, reporting, by the client device, the service indicator data to the server device.

18. The non-transitory, computer-readable medium according to claim 14 , wherein the determining the service indicator data comprises:

reporting, by the client device, the service data to the server device; and

receiving, by the client device, the service indicator data calculated by the server device based on the service data.

19. The non-transitory, computer-readable medium according to claim 14 , wherein the service indicator data comprises at least one of a frequency feature of the requested service operation, a running environment feature of the client device, a count value, a sum value, a first value, a last value, a distinction value, an average value, a standard deviation, a maximum value, or a minimum value of data generated by the requested service operation in the predetermined time window.

20. A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:

receiving, by a client device and from a server device, a risk identification model;

receiving, by the client device, a request to perform a service operation;

in response to the requested service operation, receiving, by the client device, a risk identification request associated with the requested service operation, wherein the requested service operation comprises a payment operation;

retrieving, by the client device and based on the requested service operation, service data corresponding to the risk identification request, wherein the service data comprises a payment amount;

determining, by the client device, service indicator data associated with the service data, wherein the service indicator data comprises a variance of a plurality of payment amounts of a plurality of service operations requested in a predetermined time window, wherein the plurality of payment amounts comprise the payment amount;

performing, by the client device and based on the risk identification model, logic analysis on the service indicator data;

performing, by the client device and based on the risk identification model, probability analysis on at least one of the service data and the service indicator data to obtain a risk probability;

determining, by the client device, that the requested service operation is a high risk operation based at least in part on a result of the logic analysis and the risk probability, wherein the result of the logic analysis indicates that (i) the variance of the plurality of payment amounts is less than a first predetermined threshold and (ii) a quantity of the plurality of service operations is greater than a second predetermined threshold; and

in response to the determining that the requested service operation is a high risk operation, restricting, by the client device, an operation permission of the requested service operation.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2020
From: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053754/0625 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2020
From: ALIBABA GROUP HOLDING LIMITED
To: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053743/0464 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2020
From: XIA, JUPENG; LI, CAIWEI
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 051639/0712 →