An authentication and authorization method and apparatus

Through the bank server, it obtains its authentication method and performs authentication based on the information of the target tax bureau, and solves the compatibility problem of the differentiated authentication methods of tax bureaus in the "bank-tax interaction" business, realizing the authorization authentication of user terminals and the secure transmission of tax data.

CN113269624BActive Publication Date: 2025-06-24SHENZHEN WEIZHONG TAXATION INFORMATION SERVICE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110499555.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-05-08
Publication Date
2025-06-24
Estimated Expiration
2041-05-08

AI Technical Summary

Technical Problem

In the ‘bank-tax interaction’ business, when national banks conduct business in various places, there are differences in the certification and authorization requirements of local tax bureaus, resulting in compatibility problems.

Method used

Receive the tax data collection request sent by the user terminal through the bank server, and obtain its authentication method based on the information of the target tax bureau, including the first authentication method (local authentication of the bank server and auxiliary authentication of the remote tax bureau server) and the second authentication method (remote tax bureau server authentication), and conduct the corresponding authentication process according to the authentication method to determine whether the user terminal is an authorized user.

Benefits of technology

It solves the compatibility problem of the differentiated certification methods of tax bureaus in the "bank-tax interaction" business, ensures the authorization and authentication of user terminals, and realizes the safe and efficient transmission of tax data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113269624B_ABST
    Figure CN113269624B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose an authentication and authorization method and apparatus. The implementation of the method includes: a bank server receives a tax data collection request sent by a user terminal; the bank server obtains the authentication method of the target tax bureau according to the target tax bureau information, and the authentication method includes a first authentication method or a second authentication method; determine whether the user terminal is an authorized user according to the authentication process corresponding to the authentication method; if the user terminal is an authorized user, the bank server obtains the tax data of the authorized user and sends it to the user terminal. By using the method of the embodiments of the present application, the problem of differences in the authentication methods of local tax bureaus during business communication in the "bank-tax interaction" business is solved by accommodating the personalized authentication and authorization requirements of local tax bureaus in the "bank-tax interaction" business.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of big data processing, and particularly to an authentication and authorization method and apparatus. Background Art

[0002] With the continuous improvement of China's economic level, the "Silver-Tax Interaction" (interaction between banks and tax authorities) business used to solve the enterprise financing problem has also developed significantly. Currently, for a national bank to carry out the "Silver-Tax Interaction" business in various places, it is necessary to achieve technical docking according to the personalized requirements of different local tax bureaus in accordance with the technical docking requirements of local tax bureaus. Therefore, there are differences in the authentication and authorization requirements of different local tax bureaus, which in turn lead to compatibility problems in the personalized authentication and authorization requirements for different local tax bureaus in the "Silver-Tax Interaction" business. Summary of the Invention

[0003] The embodiments of this application provide an authentication and authorization method and apparatus. The bank server obtains the authentication method of the target tax bureau according to the target tax bureau information in the tax data collection request sent by the user terminal, so as to meet the compatibility problem of the authentication and authorization methods for different tax bureaus in the "Silver-Tax Interaction" business.

[0004] In a first aspect, the embodiments of this application provide an authentication and authorization method, which is applied to a bank server. The bank server is connected to at least one remote tax bureau server. The method includes:

[0005] The bank server receives a tax data collection request sent by the user terminal, and the tax data collection request includes target tax bureau information;

[0006] The bank server obtains the authentication method of the target tax bureau according to the target tax bureau information. The authentication method includes a first authentication method or a second authentication method. The first authentication method is local authentication by the bank server and assisted authentication by the remote tax bureau server, and the second authentication method is authentication by the remote tax bureau server;

[0007] Determine whether the user terminal is an authorized user according to the authentication process corresponding to the authentication method;

[0008] If the user terminal is an authorized user, the bank server obtains the tax data of the authorized user and sends it to the user terminal.

[0009] In a possible example, when the authentication method is the second authentication method, after the bank server receives the verification information sent by the user terminal and before forwarding the verification information to the target remote tax bureau server, the method further includes:

[0010] Statistical access frequency of the target remote tax bureau server within a first time period to obtain an access frequency weight value;

[0011] Obtain the database capacity of the target remote tax bureau server to obtain the database capacity weight value;

[0012] Multiply the access frequency weight value by the database capacity weight value to obtain the target tax bureau level;

[0013] If the target tax bureau level is greater than or equal to the preset tax bureau level, use the first security level encryption algorithm to encrypt the verification information. The first security level encryption algorithm includes the Advanced Encryption Standard (AES) algorithm;

[0014] If the target tax bureau level is less than the preset tax bureau level, use the second security level encryption algorithm to encrypt the verification information. The second security level encryption algorithm includes the Data Encryption Standard (DES) algorithm, and the security level of the first security level encryption algorithm is higher than that of the second security level encryption algorithm.

[0015] In a second aspect, an authentication and authorization device provided by an embodiment of the present application is applied to a bank server, and the bank server is connected to at least one remote tax bureau server. The device includes:

[0016] A receiving unit, configured to receive, by the bank server, a tax data collection request sent by a user terminal, where the tax data collection request includes target tax bureau information;

[0017] An obtaining unit, configured to obtain, by the bank server according to the target tax bureau information, an authentication method of the target tax bureau. The authentication method includes a first authentication method or a second authentication method. The first authentication method is local authentication by the bank server and auxiliary authentication by the remote tax bureau server, and the second authentication method is authentication by the remote tax bureau server;

[0018] A determining unit, configured to determine whether the user of the user terminal is an authorized user according to the authentication process corresponding to the authentication method;

[0019] An invoking unit, configured to, if the user of the user terminal is an authorized user, invoke the tax data of the authorized user from the target remote tax bureau server corresponding to the target tax bureau and send it to the bank server.

[0020] In a third aspect, an authentication and authorization device provided by an embodiment of the present application includes:

[0021] A processor, a memory, and a communication interface, which are interconnected and complete communication with each other;

[0022] The memory stores executable program code, and the communication interface is used for wireless communication;

[0023] The processor is used to retrieve the executable program code stored in the memory, and cause the executable program code to execute some or all of the steps described in any method of the first aspect of the embodiments of the present application.

[0024] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium. A computer program for electronic data exchange is stored in the computer-readable storage medium. The computer program includes execution instructions, and the execution instructions are used to execute some or all of the steps described in any method of the first aspect of the embodiments of the present application.

[0025] In a fifth aspect, an embodiment of the present application provides a computer program product. The computer program product includes a computer program, and the computer program is operable to cause a computer to execute some or all of the steps described in any method of the first aspect of the embodiments of the present application. The computer program product may be a software installation package.

[0026] It can be seen that in the embodiments of the present application, the bank server receives a tax data collection request sent by the user terminal. The bank server obtains the authentication method of the target tax bureau according to the target tax bureau information. The authentication method includes a first authentication method or a second authentication method. The first authentication method is local authentication by the bank server and auxiliary authentication by the remote tax bureau server. The second authentication method is authentication by the remote tax bureau server. Whether the user terminal is an authorized user is determined according to the authentication process corresponding to the authentication method. If the user terminal is an authorized user, the bank server obtains the tax data of the authorized user and sends it to the user terminal. By being compatible with the personalized authentication and authorization requirements of local tax bureaus in the "bank-tax interaction" business, the problem of differences in the authentication methods of local tax bureaus in the business communication process of the "bank-tax interaction" business is solved. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0028] Figure 1A It is a structural deployment diagram of an authentication and authorization system applied in the embodiments of the present application;

[0029] Figure 1B It is a schematic flowchart of an authentication and authorization method provided by an embodiment of the present application;

[0030] Figure 2 It is an example schematic diagram of an authentication and authorization method provided by an embodiment of the present application;

[0031] Figure 3AIt is a schematic structural diagram of an authentication and authorization device provided by an embodiment of the present application;

[0032] Figure 3B It is a specific refined structural diagram of an optimization unit provided by an embodiment of the present application;

[0033] Figure 4 It is a schematic structural diagram of another authentication and authorization device provided by an embodiment of the present application. Detailed implementation manners

[0034] To enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0035] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps is not limited to the listed steps, but optionally further includes steps not listed, or optionally further includes other steps inherent to these processes, methods, products or devices.

[0036] Referring to "embodiment" herein means that a specific feature, structure or characteristic described in connection with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein may be combined with other embodiments.

[0037] The devices involved in the embodiments of the present application will be introduced below with reference to the accompanying drawings.

[0038] Figure 1A It is a structural deployment diagram of an authentication and authorization system applied in an embodiment of the present application. As Figure 1A shown, the authentication and authorization system includes a user terminal module, a bank server module, and a remote tax bureau server module. The functions of each module can be implemented by a separate server, or the functions of multiple modules can be implemented by one server. Multiple servers implementing the functions of different modules are communicatively connected to each other.

[0039] Among them, the user terminal module is used to send a tax data collection request and verification information to the bank server module, and is also used to receive the tax data sent by the bank server module.

[0040] Among them, the bank server module is used to receive the tax data collection request sent by the user terminal module, obtain the authentication method of the target tax bureau according to the target tax bureau information included in the tax data collection request, determine whether the user terminal module is an authorized user according to the authentication process corresponding to the authentication method, and if the user terminal module is an authorized user, the bank server module obtains the tax data of the authorized user and sends it to the user terminal.

[0041] Among them, the remote tax bureau server module is used to send the tax data of the authorized user to the bank server after determining that the user terminal module is an authorized user according to the authentication process corresponding to the authentication method.

[0042] An embodiment of the present application provides an authentication and authorization method, which is applied to a bank server. The bank server is connected to at least one remote tax bureau server. The specific method is that the bank server receives a tax data collection request sent by the user terminal, the bank server obtains the authentication method of the target tax bureau according to the target tax bureau information, determines whether the user terminal is an authorized user according to the authentication process corresponding to the authentication method, and if the user terminal is an authorized user, the bank server obtains the tax data of the authorized user and sends it to the user terminal. The following will describe the embodiments of the present application in detail with reference to the accompanying drawings.

[0043] Please refer to Figure 1B , Figure 1B which is a schematic flowchart of an authentication and authorization method provided by an embodiment of the present application. As Figure 1B shown, the authentication and authorization method described in the embodiment of the present application includes the following steps:

[0044] 101: The bank server receives a tax data collection request sent by the user terminal, and the tax data collection request includes target tax bureau information;

[0045] Among them, the tax bureau data requested to be collected by the tax data collection request includes tax data such as balance sheets, income statements, and tax returns.

[0046] Among them, the target tax bureau information includes target tax bureau related information such as the location of the target tax bureau and the authentication method of the target tax bureau.

[0047] 102: The bank server obtains the authentication method of the target tax bureau according to the target tax bureau information. The authentication method includes a first authentication method or a second authentication method. The first authentication method is local authentication by the bank server and auxiliary authentication by the remote tax bureau server, and the second authentication method is authentication by the remote tax bureau server;

[0048] Among them, the first authentication method is local authentication by the bank server and auxiliary authentication by the remote tax bureau server. That is to say, in the first authentication method, local authentication is first performed by the bank server, and then auxiliary authentication is performed by the remote tax bureau server. There are differences in the verification content of the verification information initiated by the user terminal between the bank server and the remote tax bureau server. The verification content verified by the bank server is more than that verified by the remote tax bureau server.

[0049] Exemplarily, when the authentication method is the first authentication method, the verification information input by the user terminal locally on the bank server includes the enterprise name, unified social credit code, legal representative information, and mobile phone information. Among them, the legal representative information includes the legal representative's name and legal representative's ID number, and the mobile phone information includes the legal representative's mobile phone number and the SMS verification code received by the mobile phone number; after the local authentication by the bank server, that is, after the bank server verifies the above verification information and passes, the remote tax bureau server performs auxiliary authentication on the legal representative information and mobile phone information in the verification information, that is, the remote tax bureau server matches and verifies the legal representative information and mobile phone information in the verification information with the reserved legal representative information and mobile phone information of the user terminal. If they are consistent, the authentication passes.

[0050] Among them, the second authentication method is remote tax bureau server authentication, which means that in the second authentication method, the bank server does not verify the verification information initiated by the user terminal, and the user terminal directly inputs the verification information on the remote tax bureau server, and the remote tax bureau server performs the verification alone.

[0051] Exemplarily, when the authentication method is the second authentication method, the verification information input by the user terminal at the corresponding position on the remote tax bureau server is the social credit code, the legal representative's mobile phone number, and the target tax bureau login password. The remote tax bureau server performs matching verification on the above verification information. If they are consistent, the authentication passes.

[0052] 103: Determine whether the user terminal is an authorized user according to the authentication process corresponding to the authentication method;

[0053] Among them, determining whether the user terminal is an authorized user according to the authentication process corresponding to the authentication method is specifically as follows: If the authentication method is the first authentication method, the user terminal is determined to be an authorized user only when the verification information sent by the user terminal passes both the local authentication by the bank server and the auxiliary authentication by the remote tax bureau server; if the authentication method is the second authentication method, the user terminal is determined to be an authorized user when the verification information sent by the user terminal passes the authentication by the remote tax bureau server.

[0054] 104: If the user terminal is an authorized user, the bank server obtains the tax data of the authorized user and sends it to the user terminal.

[0055] Among them, the bank server obtains the tax data of the authorized user and sends it to the user terminal. After determining that the user terminal is an authorized user, the remote tax bureau server retrieves the tax data of the authorized user and sends it to the bank server. After obtaining the tax data of the authorized user, the bank server sends it to the user terminal.

[0056] It can be seen that in the embodiment of the present application, by the bank server receiving the tax data collection request sent by the user terminal, the bank server obtains the authentication method of the target tax bureau according to the target tax bureau information. The authentication method includes the first authentication method or the second authentication method. The first authentication method is the local authentication of the bank server and the auxiliary authentication of the remote tax bureau server. The second authentication method is the authentication of the remote tax bureau server. According to the authentication process corresponding to the authentication method, it is determined whether the user terminal is an authorized user. If the user terminal is an authorized user, the bank server obtains the tax data of the authorized user and sends it to the user terminal. By being compatible with the personalized authentication and authorization requirements of local tax bureaus in the "bank-tax interaction" business, the problem of differences in the authentication methods of local tax bureaus in the business communication process of the "bank-tax interaction" business is solved.

[0057] In a possible example, the above-mentioned first authentication method specifically includes: the bank server receives the verification information sent by the user terminal, and the verification information includes the legal representative information and the mobile phone information; the bank server verifies the verification information. If the verification is passed, the bank server sends the verification information to the target remote tax bureau server; the legal representative information is matched with the preset legal representative information through the target remote tax bureau server, and the mobile phone information is matched with the preset mobile phone information; if the legal representative is consistent with the preset legal representative information and the mobile phone information is consistent with the preset mobile phone information, the bank server determines that the user of the user terminal is an authorized user through the target remote tax bureau server.

[0058] Among them, the legal representative information includes the legal representative's name and the legal representative's ID number, and the mobile phone information includes the legal representative's mobile phone number and the SMS verification code received by the mobile phone number.

[0059] Among them, the bank server verifies the verification information, which means that the bank server confirms that the verification information sent by the user terminal is correct.

[0060] Among them, the legal representative information is matched with the preset legal representative information through the target remote tax bureau server, and the mobile phone information is matched with the preset mobile phone information. The purpose is to let the target remote tax bureau server verify whether the legal representative information and mobile phone information input by the user terminal are consistent with the reserved tax bureau registration information. If the legal representative information and mobile phone information input by the user terminal are inconsistent with the preset legal representative information and preset mobile phone information reserved in the target remote tax bureau server, it indicates that the user terminal is not the person himself / herself who holds the tax data, or the enterprise business information of the user terminal has changed but has not been updated in the tax bureau registration information in time. While ensuring the security of tax data, it also urges enterprise users to update the enterprise business information in the tax bureau registration information in time.

[0061] It can be seen that in the embodiment of the present application, through the first authentication method of local authentication by the bank server and auxiliary authentication by the remote tax bureau server, the bank institution and the tax bureau institution verify the verification information sent by the user terminal. Through two-layer verification, it not only ensures the security of authentication and authorization, but also can play a role in reminding users to update the reserved tax bureau registration information in time, so as to ensure the compliance of tax information.

[0062] In a possible example, the above-mentioned second authentication method specifically includes: the bank server receives the verification information sent by the user terminal and forwards the verification information to the target remote tax bureau server; the target remote tax bureau server verifies the verification information; if the verification information passes the verification, the bank server determines that the user of the user terminal is an authorized user through the target remote tax bureau server.

[0063] Among them, the verification information is the social credit code, the legal representative's mobile phone number, and the target tax bureau login password.

[0064] It can be seen that in the embodiment of the present application, through the second authentication method of authentication by the remote tax bureau server, the tax bureau institution verifies the verification information sent by the user terminal, which is compatible with the local tax bureau authentication and authorization requirements that only allow authentication through the tax bureau.

[0065] In a possible example, before the bank server receives the verification information sent by the user terminal and sends it to the target remote tax bureau server, the above method further includes: the bank server generates the first behavioral watermark information according to the authentication process of the user terminal, and the behavioral watermark information includes at least one of the following: source address IP, message authentication code MAC, behavioral time, request content; determine the legality of the authentication process according to the first behavioral watermark information.

[0066] Among them, the source address IP refers to the IP address of the user terminal.

[0067] Among them, the message authentication code MAC is used to prevent the information sent by the user terminal from being tampered with without the authorization of the user terminal.

[0068] Among them, the behavior time refers to the time node when the behavior of the user terminal occurs.

[0069] Among them, the request content refers to the tax data content requested by the user terminal for collection.

[0070] Among them, determining the legality of the authentication process according to the first behavior watermark information means that the first behavior watermark information is used for electronic archiving of the authentication process of the user terminal, and the authentication process of the user terminal can be retrieved as electronic evidence in financial arbitration.

[0071] It can be seen that in the embodiment of the present application, before the bank server receives the verification information sent by the user terminal and sends it to the target remote tax bureau server, the bank server generates the first behavior watermark information according to the authentication process of the user terminal, and the first behavior watermark information electronically archives the authentication process of the user terminal, and determines the legality of the authentication process according to the first behavior watermark information, which ensures the security of the authentication authorization process.

[0072] In a possible example, before the target remote tax bureau server corresponding to the target tax bureau retrieves the tax data of the authorized user and sends it to the bank server, the above method further includes: the target remote tax bureau server generates a behavior log according to the behavior of the user terminal, and sends the behavior log to the bank server; the bank server generates the second behavior watermark information of the user terminal according to the behavior log; the bank server matches the first behavior watermark information with the second behavior watermark information, and determines that the first behavior watermark information and the second behavior watermark information match successfully.

[0073] Exemplarily, the bank server matches the first behavior watermark information with the second behavior watermark information, specifically by matching the source address IP in the first behavior watermark information with the source address IP of the second behavior watermark information. When the two match, it indicates that the same user terminal is operating during the authentication process, preventing others outside the tax data holder from performing authentication operations, thereby realizing the security control of the authentication process. Please refer to Figure 2 , Figure 2 is an example schematic diagram of an authentication authorization method provided by the embodiment of the present application. As Figure 2As shown, the source address IP in the watermark information of the first line is 183.15.178.**, and the source address IP in the watermark information of the second line is 219.136.38.**, that is, the source address IP of the first line is inconsistent with the source address IP of the second line in the watermark information. That is, in this case, the user terminal operator may change, and there is a certain risk. Then, it is considered that the watermark information of the first line does not match the watermark information of the second line.

[0074] It can be seen that in the embodiment of the present application, before the target remote tax bureau server corresponding to the target tax bureau retrieves the tax data of the authorized user and sends it to the bank server, the target remote tax bureau server generates a behavior log according to the behavior of the user terminal and sends the behavior log to the bank server. The bank server generates the second behavior watermark information of the user terminal according to the behavior log and matches the first behavior watermark information with the second behavior watermark information. By determining that the first behavior watermark information matches the second behavior watermark information successfully, the security of the authentication process of the user terminal is ensured. Even if the bank does not verify the verification information sent by the user terminal, it can also play a role in security control of the authentication process of the user terminal, guarantee the security of user access, and further reduce the risks existing in the authentication and authorization process.

[0075] In a possible example, the above method further includes: the bank server obtains the user terminal behavior data of the target remote tax bureau server, and the user terminal behavior data includes the first-level behavior data and the second-level behavior data of at least one user terminal; according to the first-level behavior data and the second-level behavior data, the authentication method loss rate = (1 - second-level behavior data / first-level behavior data) * 100%; if the authentication method loss rate is greater than the preset authentication method loss rate, an optimization suggestion is generated and sent to the target remote tax bureau server, and the optimization suggestion is used to optimize and adjust the authentication method of the target tax bureau corresponding to the target remote tax bureau server.

[0076] Exemplarily, the first-level behavior data of the target remote tax bureau server is the number of authenticated user arrivals, the second-level behavior data is the tax data feedback volume. The number of authenticated user arrivals is 10,000, and the tax data feedback volume corresponding to the 10,000 user arrivals is 5,000. The preset authentication method loss rate is 30%. Then, the authentication method loss rate = (1 - 5,000 / 10,000) * 100% = 50% which is greater than 30% i.e., greater than the preset authentication method loss rate. At this time, an optimization suggestion is generated and sent to the target remote tax bureau server.

[0077] It can be seen that in the embodiments of the present application, based on the user terminal behavior data, the loss rate of the authentication method is obtained, and according to the relationship between the loss rate of the authentication method and the preset loss rate of the authentication method, it is determined whether to generate an optimization suggestion for the target remote server to optimize and adjust the authentication method of the corresponding target tax bureau, thereby providing a useful reference for the target tax bureau in the iterative upgrade of the user authentication and authorization process, and further ensuring the authentication and authorization passing rate of the "Silver Tax Interaction" service.

[0078] In a possible example, the above method further includes: if the authentication method is the first authentication method, the optimization suggestion is used to suggest that the target remote tax bureau server change the authentication method from the first authentication method to the second authentication method; if the authentication method is the second authentication method, the optimization suggestion is used to suggest that the target remote tax bureau server change the authentication method from the second authentication method to the first authentication method and / or used to suggest optimizing and adjusting the verification information that needs to be verified by the target remote tax bureau server.

[0079] Among them, optimizing and adjusting the verification information that needs to be verified by the target remote server may be to delete the verification items that cause the increase in the loss rate of the authentication method.

[0080] It can be seen that in the embodiments of the present application, if the authentication method is the first authentication method, the optimization suggestion is used to suggest that the target remote tax bureau server change the authentication method from the first authentication method to the second authentication method; if the authentication method is the second authentication method, at this time, the optimization suggestion may be to suggest that the target remote tax bureau server change the authentication method from the second authentication method to the first authentication method, or it may also be to suggest optimizing and adjusting the tax bureau verification information that needs to be verified, such as canceling the verification items that cause a relatively large loss rate of the authentication method, thereby providing a useful reference for the target tax bureau in the iterative upgrade of the user authentication and authorization process, and further ensuring the authentication and authorization passing rate of the "Silver Tax Interaction" service.

[0081] In a possible example, the target tax bureau information includes the location of the target tax bureau. Obtaining the authentication method of the target tax bureau according to the target tax bureau information includes: determining whether the target tax bureau is in a first type of region according to the location of the target tax bureau, where the first type of region is a first-level administrative region whose economic production capacity reaches a first preset threshold; if not, the authentication method corresponding to the target tax bureau is the first authentication method; if so, obtaining the usage probabilities of the first authentication method and the second authentication method for the tax bureaus within the first-level administrative region, and determining the authentication method with a higher usage probability as the authentication method corresponding to the target tax bureau; or determining whether the target tax bureau is in a second type of region within the first type of region according to the location of the target tax bureau, where the second type of region is a second-level administrative region whose economic production capacity reaches a second preset threshold, and the management scope of the second-level administrative region is smaller than that of the first-level administrative region; if so, the authentication method corresponding to the target tax bureau is the second authentication method; if not, the authentication method corresponding to the target tax bureau is the first authentication method.

[0082] Among them, the economic production capacity includes the gross domestic product (GDP).

[0083] Among them, the management scope of the second-level administrative region being smaller than that of the first-level administrative region means that the administrative division level of the second-level administrative region is lower than that of the first-level administrative region.

[0084] Among them, obtaining the usage probabilities of the first authentication method and the second authentication method for the tax bureaus within the first-level administrative region, and determining the authentication method with a higher usage probability as the authentication method corresponding to the target tax bureau, specifically, counting at least one tax bureau within the first-level administrative region, and counting the authentication methods used by each tax bureau among the at least one tax bureau, obtaining the number of tax bureaus using the first authentication method and the number of tax bureaus using the second authentication method. If the number of tax bureaus using the first authentication method is larger, it is considered that the usage probability of the first authentication method for the tax bureaus within the first-level administrative region is higher than that of the second authentication method, and vice versa.

[0085] Exemplarily, the first preset threshold is 4,000 billion yuan, the first-level administrative region is a province, and the economic production capacity (i.e., GDP) of the province where the target tax bureau is located is 3,000 billion yuan, which is less than the first preset threshold. It is determined that the target tax bureau is not in the first type of region. The first type of region can be marked as, for example, "rich region" or "region with a large economic volume", etc. Then, at this time, the authentication method corresponding to the target tax bureau is the first authentication method. This is because the economic production capacity of the province where the target tax bureau is located is less than the first preset threshold, and it can be estimated that the tax and financial verification volume of the target tax bureau is relatively small. Therefore, it is speculated that the target tax bureau is suitable for the first authentication method, that is, through unified local bank authentication combined with remote tax bureau assisted authentication, the authentication requirements of the target tax bureau can be met.

[0086] If the economic production capacity of the province where the target tax bureau is located is greater than or equal to the first preset threshold, the target tax bureau is in the first type of region. At this time, the authentication method used by the target tax bureau is determined according to the usage probabilities of the first authentication method and the second authentication method by the tax bureaus within the first-level administrative region where the target tax bureau is located. This is because the province where the target tax bureau is located is not the first type of region, but the economic development within the prefecture-level cities in this province is unbalanced, and there may be "regions with large economic volumes". Therefore, the target tax bureau can determine the authentication method it adopts according to the probability of the authentication method used within this province.

[0087] Alternatively, it is also possible to further determine the economic volume of the prefecture-level city where the target tax bureau is located, and then determine the authentication method of the target tax bureau based on the economic volume of the prefecture-level city. Exemplarily, the first preset threshold is 4,000 billion yuan, the first-level administrative region is a province, the second preset threshold is 300 billion yuan, the second-level administrative region is a prefecture-level city, and the economic production capacity (i.e., GDP) of the province where the target tax bureau is located is 1,100,000 billion yuan, which is greater than the first preset threshold. At this time, it can be determined whether the target tax bureau is in the second type of region within the first type of region according to the location of the target tax bureau. The economic production capacity of the prefecture-level city where the target tax bureau is located is 250 billion yuan, which is less than the second preset threshold. It is determined that the target tax bureau is not in the second type of region within the first type of region. Then, the authentication method corresponding to the target tax bureau at this time is the first authentication method. This is because the economic production capacity of the province where the target tax bureau is located is greater than the first preset threshold, but the economic production capacity of the prefecture-level city where it is located is less than the second preset threshold. It can be estimated that the amount of fiscal and tax verification of the target tax bureau is relatively small. Therefore, it is speculated that the target tax bureau is suitable for the first authentication method, that is, through unified local bank authentication combined with remote tax bureau assisted authentication, the authentication requirements of the target tax bureau can be met. On the contrary, if the economic production capacity of the province where the target tax bureau is located is greater than the first preset threshold and the economic production capacity of the prefecture-level city where it is located is greater than the second preset threshold, it can be estimated that the amount of fiscal and tax verification of the target tax bureau is relatively large. Therefore, it is speculated that the target tax bureau is suitable for the second authentication method, that is, the target tax bureau is authenticated through the personalized authentication method of the tax bureau itself.

[0088] It can be seen that in the embodiments of the present application, the area where the target tax bureau is located is determined by the economic production capacity of the location of the target tax bureau. First, it is determined whether the target tax bureau is in the first type of area. If it is not in the first type of area, the authentication method corresponding to the target tax bureau is the first authentication method. If it is in the first type of area, the authentication method with a higher usage probability for the first authentication method and the second authentication method among the tax bureaus within the first-level administrative region is obtained as the authentication method corresponding to the target tax bureau. Or it is further determined whether the target tax bureau is in the second type of area where the management scope is smaller than the first-level administrative region. If it is in the second type of area, the authentication method corresponding to the target tax bureau is the second authentication method. If it is not in the second type of area, the authentication method corresponding to the target tax bureau is the first authentication method. For the target tax bureau with a higher economic production capacity at the location, the authentication method is determined to be the second authentication method in which the tax bureau needs to perform more information verification items, and the tax bureau uses a more stringent authentication method to ensure the security of important tax data.

[0089] In a possible example, when the authentication method is the second authentication method, after the bank server receives the verification information sent by the user terminal and before forwarding the verification information to the target remote tax bureau server, the above method further includes:

[0090] Count the access frequency of the target remote tax bureau server within the first time period to obtain the access frequency weight value;

[0091] Obtain the database capacity of the target remote tax bureau server to obtain the database capacity weight value;

[0092] Multiply the access frequency weight value by the database capacity weight value to obtain the target tax bureau level;

[0093] If the target tax bureau level is greater than or equal to the preset tax bureau level, encrypt the verification information using the first security level encryption algorithm, and the first security level encryption algorithm includes the Advanced Encryption Standard (AES) algorithm;

[0094] If the target tax bureau level is less than the preset tax bureau level, encrypt the verification information using the second security level encryption algorithm, and the second security level encryption algorithm includes the Data Encryption Standard (DES) algorithm. The security level of the first security level encryption algorithm is higher than that of the second security level encryption algorithm.

[0095] Among them, the access frequency is the number of times the tax data collection request initiated by the user terminal accesses the target tax bureau corresponding to the target remote tax bureau server, and the access frequency weight value = access frequency / the first time period.

[0096] Among them, obtaining the database capacity of the target remote tax bureau server can be to obtain the number of enterprises in the location of the target tax bureau in industrial and commercial information databases such as the enterprise credit information publicity system for judgment. If the number of enterprises in the location of the target tax bureau is larger, the database capacity of the target remote tax bureau server is larger.

[0097] Among them, the security level of the first security level encryption algorithm is higher than that of the second security level encryption algorithm, which means that the cracking difficulty of the first security level encryption algorithm is greater than that of the second security level encryption algorithm. The cracking difficulty can depend on the length of the key. For example, the key length of the Advanced Encryption Standard (AES) algorithm can be 128 bits, 192 bits, or 256 bits, while the key length of the Data Encryption Standard (DES) algorithm is 56 bits. Then, the key length of the Advanced Encryption Standard (AES) algorithm is longer than that of the Data Encryption Standard (DES) algorithm and is more difficult to crack.

[0098] It can be seen that in the embodiments of the present application, the target tax bureau level is obtained through the access frequency and database capacity of the target remote tax bureau server, and different security level encryption algorithms are used to encrypt the verification information sent by the user terminal according to the size relationship between the target tax bureau level and the preset tax bureau level. When the target tax bureau level is relatively high, the first security level encryption algorithm with a greater cracking difficulty is used, and when the target tax bureau level is relatively low, the second security level encryption algorithm with a smaller cracking difficulty but faster encryption and decryption speed is used, which can not only ensure the security of the authentication and authorization process but also ensure the working efficiency of the authentication and authorization process.

[0099] Consistent with the above Figure 1B shown embodiment, please refer to Figure 3A , Figure 3A is a schematic structural diagram of an authentication and authorization device provided by an embodiment of the present application, as Figure 3A shown:

[0100] An authentication and authorization device is applied to a bank server. The bank server is connected to at least one remote tax bureau server. The device includes:

[0101] 301: A receiving unit, configured to receive, by the bank server, a tax data collection request sent by a user terminal, where the tax data collection request includes target tax bureau information;

[0102] 302: An obtaining unit, configured to obtain, by the bank server, an authentication method of the target tax bureau according to the target tax bureau information. The authentication method includes a first authentication method or a second authentication method. The first authentication method is local authentication by the bank server and auxiliary authentication by the remote tax bureau server, and the second authentication method is authentication by the remote tax bureau server;

[0103] 303: A determining unit, configured to determine whether the user of the user terminal is an authorized user according to the authentication process corresponding to the authentication method.

[0104] 304: Retrieval unit, configured to, if the user of the user terminal is an authorized user, retrieve the tax data of the authorized user from the target remote tax bureau server corresponding to the target tax bureau and send it to the bank server.

[0105] It can be seen that in the embodiment of the present application, the bank server is made to receive the tax data collection request sent by the user terminal through the receiving unit, and the bank server is made to obtain the authentication method of the target tax bureau according to the target tax bureau information through the obtaining unit. The authentication method includes the first authentication method or the second authentication method. The first authentication method is local authentication by the bank server and auxiliary authentication by the remote tax bureau server, and the second authentication method is authentication by the remote tax bureau server. The determination unit determines whether the user terminal is an authorized user according to the authentication process corresponding to the authentication method. When the user terminal is an authorized user, the retrieval unit makes the bank server obtain the tax data of the authorized user and send it to the user terminal. By accommodating the personalized authentication and authorization requirements of local tax bureaus in the "bank-tax interaction" business, the problem of differences in the authentication methods of local tax bureaus during the business communication process in the "bank-tax interaction" business is solved.

[0106] In a possible example, please refer to Figure 3A , Figure 3A which is a schematic structural diagram of an authentication and authorization device provided by an embodiment of the present application. As Figure 3A shown, the above device further includes:

[0107] 305: Data unit, configured to obtain the user terminal behavior data of the target remote tax bureau server by the bank server. The user terminal behavior data includes the first-level behavior data and the second-level behavior data of at least one user terminal;

[0108] 306: Calculation unit, configured to obtain the authentication method churn rate = (1 - second-level behavior data / first-level behavior data) * 100% according to the first-level behavior data and the second-level behavior data;

[0109] 307: Optimization unit, configured to, if the authentication method churn rate is greater than the preset authentication method churn rate, generate an optimization suggestion and send it to the target remote tax bureau server. The optimization suggestion is used to optimize and adjust the authentication method of the target tax bureau corresponding to the target remote tax bureau server.

[0110] Specifically, the embodiments of the present application can divide the authentication and authorization device into functional units according to the above method examples. For example, each functional unit can be corresponding to each function, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. It should be noted that the division of units in the embodiments of the present application is illustrative, only a logical function division, and there may be other division methods in actual implementation.

[0111] In a possible example, please refer to Figure 3B , Figure 3B which is a specific refinement structure diagram of an optimization unit provided by the embodiments of the present application. As Figure 3B shown, the optimization unit includes:

[0112] 3071: The first authentication method optimization module, which is used to, if the authentication method is the first authentication method, the optimization suggestion is used to suggest that the target remote tax bureau server change the authentication method from the first authentication method to the second authentication method;

[0113] 3072: The second authentication method optimization module, which is used to, if the authentication method is the second authentication method, the optimization suggestion is used to suggest that the target remote tax bureau server change the authentication method from the second authentication method to the first authentication method and / or used to suggest optimizing and adjusting the verification information that needs to be verified for the target remote tax bureau server.

[0114] Consistent with the above Figure 1B shown embodiment, please refer to Figure 4 , Figure 4 which is a schematic structural diagram of another authentication and authorization device provided by the embodiments of the present application. As Figure 4 shown:

[0115] An authentication and authorization device includes:

[0116] A processor, a memory, and a communication interface. The processor, the memory, and the communication interface are interconnected and complete the communication work with each other;

[0117] The memory stores executable program code, and the communication interface is used for wireless communication;

[0118] The processor is used to retrieve the executable program code stored on the memory and execute some or all of the steps of any authentication and authorization method recorded in the above method embodiments. The above computer includes an electronic terminal device.

[0119] Among them, the memory can be a volatile memory such as a dynamic random access memory (DRAM), or a non-volatile memory such as a mechanical hard disk. The above-mentioned memory is used to store a set of executable program codes, and the above-mentioned processor is used to call the executable program codes stored in the memory, and can execute some or all of the steps of any one of the authentication and authorization methods described in the above-mentioned authentication and authorization method embodiments.

[0120] The above wireless communication can use any communication standard or protocol, including but not limited to GSM (Global System of Mobile communication), GPRS (General Packet Radio Service), CDMA2000 (Code Division Multiple Access 2000), WCDMA (Wideband Code Division Multiple Access), TD-SCDMA (Time Division-Synchronous Code Division Multiple Access), FDD-LTE (Frequency Division Duplexing-Long Term Evolution), and TDD-LTE (Time Division Duplexing-Long Term Evolution), etc.

[0121] An embodiment of the present application provides a computer-readable storage medium. A computer program for electronic data exchange is stored in the computer-readable storage medium. The computer program includes execution instructions for executing some or all of the steps of any one of the authentication and authorization methods described in the above-mentioned authentication and authorization method embodiments. The above computer includes an electronic terminal device.

[0122] An embodiment of the present application provides a computer program product. The computer program product includes a computer program that can operate to cause a computer to execute some or all of the steps of any one of the authentication and authorization methods described in the above method embodiments. The computer program product can be a software installation package.

[0123] It should be noted that, for the embodiments of any of the foregoing authentication and authorization methods, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential to this application.

[0124] The embodiments of this application have been introduced in detail above. Specific examples are used in this article to elaborate on the principle and implementation manner of an authentication and authorization method and device of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of an authentication and authorization method and device of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.

[0125] This application is described with reference to the flowcharts and / or block diagrams of the methods, hardware products, and computer program products of the embodiments of this application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in one or more processes in the flowchart and / or one or more blocks in the block diagram.

[0126] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in one or more processes in the flowchart and / or one or more blocks in the block diagram. The memory can include: a flash drive, a read-only memory (abbreviation: ROM), a random access memory (abbreviation: RAM), a magnetic disk, or an optical disc, etc.

[0127] Although the present application has been described in connection with various embodiments, those skilled in the art will understand and realize other variations of the disclosed embodiments by viewing the drawings, the disclosure, and the appended claims during the implementation of the claimed present application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plurality. Certain measures are recited in mutually different dependent claims, but this does not mean that these measures cannot be combined to produce a good effect.

[0128] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the method embodiments of any of the above authentication and authorization methods can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable memory, which can include: a flash drive, a read-only memory (abbreviation: ROM), a random access memory (abbreviation: RAM), a magnetic disk, or an optical disc, etc.

[0129] It can be understood that any product that is controlled or configured to execute the processing method of the flowchart described in an embodiment of an authentication and authorization method of the present application, such as the device and computer program product of the above flowchart, belongs to the scope of the related products described in the present application.

[0130] Obviously, those skilled in the art can make various changes and modifications to an authentication and authorization method and device provided by the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these changes and modifications.

Claims

1. A authentication and authorization method, which is applied to a bank server, and the bank server is connected to at least one remote tax bureau server, characterized in that, The method includes: The bank server receives a tax data collection request sent by the user terminal. The tax data collection request includes an authentication method for the target tax bureau. The authentication method includes a first authentication method or a second authentication method. The first authentication method is local authentication by the bank server and assisted authentication by the remote tax bureau server. The second authentication method is authentication by the remote tax bureau server. Specifically, the second authentication method includes: The bank server generates first behavioral watermark information based on the authentication process of the user terminal. The behavioral watermark information includes at least one of the following: source address IP, message authentication code MAC, behavioral time, and request content. Determine the legality of the authentication process based on the first behavioral watermark information. The bank server receives the verification information sent by the user terminal and forwards the verification information to the target remote tax bureau server. The target remote tax bureau server verifies the verification information. If the verification information passes the verification, the bank server determines, through the target remote tax bureau server, that the user of the user terminal is an authorized user. Determine whether the user terminal is an authorized user according to the authentication process corresponding to the authentication method. If it is determined that the user terminal is an authorized user according to the second authentication method, the method further includes: the bank server receives the behavioral log generated by the target remote tax bureau server based on the behavior of the user terminal, and generates second behavioral watermark information of the user terminal according to the behavioral log. The bank server matches the first behavioral watermark information with the second behavioral watermark information and determines that the first behavioral watermark information matches the second behavioral watermark information successfully. The bank server obtains the tax data of the authorized user and sends it to the user terminal.

2. The method according to claim 1, characterized in that, Specifically, the first authentication method includes: The bank server receives the verification information sent by the user terminal. The verification information includes legal representative information and mobile phone information. The bank server verifies the verification information. If the verification passes, the bank server sends the verification information to the target remote tax bureau server. The target remote tax bureau server matches the legal representative information with the preset legal representative information and matches the mobile phone information with the preset mobile phone information. If the legal representative is consistent with the preset legal representative information and the mobile phone information is consistent with the preset mobile phone information, the bank server determines, through the target remote tax bureau server, that the user of the user terminal is an authorized user.

3. The method according to claim 1 or 2, characterized in that, Specifically, the second authentication method includes: The bank server receives the verification information sent by the user terminal and forwards the verification information to the target remote tax bureau server. The target remote tax bureau server verifies the verification information. If the verification information passes the verification, the bank server determines, through the target remote tax bureau server, that the user of the user terminal is an authorized user.

4. The method according to claim 1, wherein The method further includes: The bank server obtains the user terminal behavior data of the target remote tax bureau server, where the user terminal behavior data includes the first-level behavior data and the second-level behavior data of at least one user terminal; According to the first-level behavior data and the second-level behavior data, the authentication method churn rate = (1 - second-level behavior data / first-level behavior data) * 100%; If the authentication method churn rate is greater than the preset authentication method churn rate, an optimization suggestion is generated and sent to the target remote tax bureau server, and the optimization suggestion is used to optimize and adjust the authentication method of the target tax bureau corresponding to the target remote tax bureau server.

5. The method according to claim 1, wherein The target tax bureau information includes the location of the target tax bureau, and obtaining the authentication method of the target tax bureau according to the target tax bureau information includes: Determining whether the target tax bureau is in a first type of area according to the location of the target tax bureau, where the first type of area is a first-level administrative area whose economic production capacity reaches a first preset threshold; If not, the authentication method corresponding to the target tax bureau is the first authentication method; If so, obtain the usage probabilities of the first authentication method and the second authentication method for the tax bureaus within the scope of the first-level administrative area, and determine the authentication method with a higher usage probability as the authentication method corresponding to the target tax bureau; or Determining whether the target tax bureau is in a second type of area within the first type of area according to the location of the target tax bureau, where the second type of area is a second-level administrative area whose economic production capacity reaches a second preset threshold, and the management scope of the second-level administrative area is smaller than that of the first-level administrative area; If so, the authentication method corresponding to the target tax bureau is the second authentication method; If not, the authentication method corresponding to the target tax bureau is the first authentication method.

6. A certification and authorization device is applied to a bank server, and the bank server is connected to at least one remote tax bureau server. It is characterized in that, The device includes: A receiving unit, configured to receive, by the bank server, a tax data collection request sent by a user terminal, where the tax data collection request includes an authentication method of a target tax bureau, and the authentication method includes a first authentication method or a second authentication method. The first authentication method is local authentication by the bank server and auxiliary authentication by the remote tax bureau server, and the second authentication method is authentication by the remote tax bureau server. The second authentication method specifically includes: the bank server generates first behavior watermark information according to the authentication process of the user terminal, and the behavior watermark information includes at least one of the following: source address IP, message authentication code MAC, behavior time, and request content; determining the legality of the authentication process according to the first behavior watermark information; the bank server receives the verification information sent by the user terminal and forwards the verification information to the target remote tax bureau server; verifying the verification information through the target remote tax bureau server; if the verification information passes the verification, the bank server determines, through the target remote tax bureau server, that the user of the user terminal is an authorized user; A determining unit, configured to determine whether the user of the user terminal is an authorized user according to the authentication process corresponding to the authentication method; A retrieval unit, configured to, if it is determined according to the second authentication method that the user of the user terminal is an authorized user, the bank server receives a behavior log generated by the target remote tax bureau server based on the behavior of the user terminal, and generates second behavior watermark information of the user terminal according to the behavior log; The bank server matches the first behavior watermark information with the second behavior watermark information, and determines that the matching between the first behavior watermark information and the second behavior watermark information is successful; The target remote tax bureau server corresponding to the target tax bureau retrieves the tax data of the authorized user and sends it to the bank server.

7. An authentication and authorization device, characterized in that, The device includes: A processor, a memory, and a communication interface, the processor, the memory, and the communication interface are interconnected and complete communication work with each other; The memory stores executable program code, and the communication interface is used for wireless communication; The processor is configured to retrieve the executable program code stored on the memory and execute the method according to any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, A computer program for electronic data exchange is stored in the computer-readable storage medium, and the computer program includes execution instructions for executing the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Enterprise identity authentication method and system

    CN106529979A