A data processing method, apparatus and device

By silently collecting biometric features and performing identity authentication through the target application, the problem of cumbersome authorization operations between applications is solved, achieving seamless authorization and improving efficiency and user experience.

CN113515734BActive Publication Date: 2026-03-17TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-10-10
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

In existing technologies, authorization operations between applications require frequent switching, resulting in high resource consumption and a poor user experience.

Method used

The target application silently collects the user's biometric features from the third-party application, performs identity authentication, executes authorization operations, and returns the results without requiring user intervention or program switching.

Benefits of technology

It enables seamless authorization, reduces resource consumption, and improves authorization efficiency and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113515734B_ABST
    Figure CN113515734B_ABST
Patent Text Reader

Abstract

This application discloses a data processing method, apparatus, and device. The method includes: receiving an authorization operation request sent by a third-party application, the authorization operation request requesting a target application to perform a target operation, the authorization operation request carrying attribute information of the target operation; responding to the authorization operation request, silently collecting the biometric features of a first user on the third-party application side; authenticating the identity of the first user based on the first user's biometric features; if the first user's identity authentication is successful, silently executing the target operation based on the attribute information of the target operation carried in the authorization operation request, obtaining the target operation result; and returning the target operation result to the third-party application. Using this application embodiment simplifies the steps in the authorization operation, eliminates the need to switch applications, and achieves seamless authorization operations between applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, specifically to the field of data processing, and particularly to a data processing method, a data processing apparatus, and a data processing device. Background Technology

[0002] With the rapid development of computer technology, a massive number of applications have emerged on the internet. These applications offer different functionalities; for example, payment applications provide payment functions, video applications provide audio and video playback functions, and so on. Applications can extend their functionality through authorization operations. For instance, when a target application successfully authorizes a third-party application, the third-party application can share its content to the target application. Currently, when a target application authorizes a third-party application, it requires the user to be redirected from the third-party application to the target application's authorization confirmation page. The user then authorizes the application on this page, and after successful authorization, the user is redirected back to the third-party application. This authorization method is cumbersome, requires frequent switching between applications, consumes high resources, and provides a poor user experience. Summary of the Invention

[0003] This application provides a data processing method, apparatus, device, and medium that can simplify the steps in the authorization process, eliminate the need to switch applications, and achieve seamless authorization.

[0004] On one hand, embodiments of this application provide a data processing method, the method comprising:

[0005] Receive authorization operation requests sent by third-party applications. The authorization operation requests are used to request the target application to perform the target operation. The authorization operation requests carry the attribute information of the target operation.

[0006] In response to authorization requests, the biometrics of the first user on the third-party application side are silently collected.

[0007] The identity of the first user is authenticated based on the first user's biometric characteristics;

[0008] If the authentication of the first user is successful, the target operation will be silently executed according to the attribute information of the target operation carried in the authorization operation request, and the result of the target operation will be obtained.

[0009] The target operation result is returned to the third-party application.

[0010] In this embodiment, the target application can silently collect the biometric features of a first user from a third-party application, and compare the collected biometric features of the first user with the configured biometric features corresponding to the identifier of a second user currently logged into the target application. If the comparison is successful, the target application executes the target operation requested in the authorization operation request and returns the result of the target operation to the third-party application. During the above authorization operation, the collection of the first user's biometric features and the authentication of the first user's identity are both silently completed in the background by the target application. No user intervention is required, and there is no need to switch between the third-party application and the target application to quickly achieve seamless authorization. This effectively reduces resource consumption during the authorization process and improves authorization efficiency, thus significantly enhancing the user experience.

[0011] On one hand, embodiments of this application provide a data processing method, the method comprising:

[0012] Displays the operation page of the third-party application, which includes the authorization operation entry point for the target application;

[0013] When the authorization operation entry of the target application is triggered, an authorization operation request is silently sent to the target application. The authorization operation request is used to request the target application to execute the target operation. The authorization operation request carries the attribute information of the target operation. This allows the target application to respond to the authorization operation request, silently execute the target operation according to the attribute information of the target operation, and return the result of the target operation.

[0014] Based on the target operation result returned by the target application, the user is redirected from the operation interface of the third-party application to the result page of the third-party application, where the target operation result is displayed.

[0015] In this embodiment, an operation page of a third-party application is displayed, showing the authorization operation entry point of the target application. When the authorization operation entry point is triggered, an authorization operation request is silently sent to the target application, causing the target application to respond. Based on the target operation result returned by the target application, the third-party application is redirected from the operation interface to the result page. This authorization operation process is completed while the third-party application displays its operation interface. If the target application successfully executes the target operation, the third-party application can directly output the target execution result. That is, there is no switching or redirection between the third-party application and the target application during the authorization operation, and no user intervention is required. The entire authorization process is silently implemented in the background of the target application, thus achieving seamless authorization and effectively improving the user experience.

[0016] On one hand, embodiments of this application provide a data processing apparatus, the apparatus comprising:

[0017] The processing unit is used to receive authorization operation requests sent by third-party applications. The authorization operation requests are used to request the target application to perform a target operation, and the authorization operation requests carry attribute information of the target operation.

[0018] In response to authorization requests, the biometrics of the first user on the third-party application side are silently collected.

[0019] The identity of the first user is authenticated based on the first user's biometric characteristics;

[0020] If the authentication of the first user is successful, the target operation will be silently executed according to the attribute information of the target operation carried in the authorization operation request, and the result of the target operation will be obtained.

[0021] The communication unit is used to return the result of the target operation to a third-party application.

[0022] In one implementation, the target operation includes a sharing operation, and the attribute information of the sharing operation includes the link information to be shared; when the processing unit silently executes the target operation based on the attribute information of the target operation carried in the authorization operation request and obtains the target operation result, it is specifically used for:

[0023] Obtain the identifier of the second currently logged-in user in the target application;

[0024] Based on the second user's identifier, obtain the page corresponding to the second user in the target application. The page includes one or more of the following: a conversation page, a dynamic page, and a content communication page.

[0025] The link information is silently added to the page, and the sharing result is generated.

[0026] In one embodiment, the processing unit is further configured to:

[0027] Security level of obtaining link information;

[0028] If the security level of the link information is greater than or equal to the security level threshold, then the step of silently executing the target operation based on the attribute information of the target operation carried in the authorized operation request and obtaining the result of the target operation is triggered.

[0029] In one implementation, the target operation is a payment operation, and the attribute information of the payment operation includes the receiving account and the payment amount; when the processing unit silently executes the target operation based on the attribute information of the target operation carried in the authorization operation request and obtains the target operation result, it is specifically used for:

[0030] Obtain the identifier of the second currently logged-in user in the target application;

[0031] Based on the second user's identifier, obtain the second user's payment account in the target application;

[0032] The payment amount is silently deducted from the payment account, transferred to the receiving account, and a payment operation result is generated.

[0033] In one embodiment, the processing unit is further configured to:

[0034] Check the credit rating of the receiving account;

[0035] If the credit rating of the receiving account is greater than or equal to the credit rating threshold, then the step of silently executing the target operation based on the attribute information of the target operation carried in the authorized operation request and obtaining the result of the target operation is triggered.

[0036] In one implementation, a software development kit (SDK) corresponding to the authorized operation service interface of the target application is integrated into the third-party application. The third-party application runs the SSD to call the authorized operation service interface for cross-process communication with the target application. The processing unit is further configured to:

[0037] The authorization operation service interface being invoked receives authorization operation requests sent by third-party applications.

[0038] Among them, based on the authorized operation service interface and software development kit, third-party applications and target applications can communicate through cross-process communication.

[0039] In one embodiment, the processing unit is further configured to:

[0040] Obtain the list of authorized operation applications corresponding to the target application. The list of authorized operation applications contains the application identifier of at least one authorized operation application. An authorized operation application is an application that has the request permission for authorized operation services.

[0041] If a third-party application's application identifier exists in the list of authorized application operations, then the step of verifying the target user's identity information based on the target user's biometrics will be triggered.

[0042] If the application identifier of a third-party application is not found in the list of authorized operation applications, a notification message is sent to the third-party application through the authorized operation service interface. The notification message is used to inform the third-party application that it is not authorized to request the authorized operation service from the target application.

[0043] In one implementation, the biometric database refers to a cloud database used to store biometric features; the biometric features include at least one of the following: face images, facial texture features, and iris features;

[0044] When authenticating the identity of the first user based on the first user's biometrics, the processing unit specifically performs the following tasks:

[0045] Send an acquisition request to the cloud server, the acquisition request carrying the identifier of the second user currently logged in in the target application; the acquisition request is used to request the cloud server to retrieve and return N configured biometric features related to the identifier of the second user from the cloud database, where N is a positive integer;

[0046] Receive N configuration biometric features of the second user returned by the cloud server;

[0047] The biometric features of the first user are compared one by one with the N configured biometric features of the second user;

[0048] If one of the N configured biometric features of the second user matches the biometric feature of the first user, then the first user's identity authentication is successful.

[0049] If none of the N configured biometric features of the second user match the biometric features of the first user, then the authentication of the first user is determined to have failed.

[0050] In one implementation, the biometric database refers to a cloud database used to store biometric features; the biometric features include at least one of the following: face images, facial texture features, and iris features;

[0051] When authenticating the identity of the first user based on the first user's biometrics, the processing unit specifically performs the following tasks:

[0052] An authentication request is sent to the cloud server, carrying the biometrics of the first user and the identifier of the second user currently logged in to the target application; so that the cloud server retrieves N configured biometrics related to the identifier of the second user from the cloud database, and compares the biometrics of the first user with the N configured biometrics of the second user to obtain the authentication result of the first user;

[0053] Receive the authentication result of the first user returned by the cloud server.

[0054] In one embodiment, the processing unit is further configured to:

[0055] Display the target application's configuration page, which contains the target application's biometric registration service interface and biometric deletion service interface;

[0056] When the biometric registration service interface is selected, the biometric registration page of the target application is displayed;

[0057] The biometric registration service page collects the configured biometrics of the user requesting registration from the target application side and obtains the identifier of the user requesting registration.

[0058] The configured biometric features of the user requesting registration and their associated identifier are stored in the biometric database.

[0059] When the biometric deletion service interface is triggered, obtain the identifier of the user requesting deletion from the target application side;

[0060] Query whether the biometric database stores the configuration biometrics associated with the identifier of the user requested for deletion;

[0061] If the biometric database stores configuration biometrics associated with the identifier of the user requesting deletion, then delete the configuration biometrics associated with the identifier of the user requesting deletion from the biometric database.

[0062] On one hand, embodiments of this application provide a data processing apparatus, the apparatus comprising:

[0063] The display unit is used to display the operation page of the third-party application, which includes the authorization operation entry point of the target application.

[0064] The processing unit is configured to, when the authorization operation entry of the target application is triggered, silently send an authorization operation request to the target application, the authorization operation request being used to request the target application to perform a target operation, the authorization operation request carrying attribute information of the target operation; so that the target application responds to the authorization operation request, silently performs the target operation according to the attribute information of the target operation, and returns the target operation result; and, based on the target operation termination returned by the target application, jumps from the operation interface of the third-party application to the result page of the third-party application, and displays the target operation result on the result page.

[0065] In one implementation, a software development kit (SDK) corresponding to the authorization operation service interface of the target application is integrated into the third-party application. The third-party application runs the SSD to call the authorization operation service interface for cross-process communication with the target application. When the processing unit sends an authorization operation request to the target application, it is specifically used for:

[0066] Run the software tool development kit to call the authorization operation service interface to send an authorization operation request.

[0067] On one hand, embodiments of this application provide a data processing device, the device comprising:

[0068] A processor, adapted to execute computer programs;

[0069] A computer-readable storage medium storing a computer program, which, when executed by a processor, implements the aforementioned data processing method.

[0070] On the other hand, embodiments of this application provide a computer-readable storage medium storing a computer program adapted to be loaded by a processor and executed by the above-described data processing method.

[0071] On the other hand, embodiments of this application provide a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the aforementioned data processing method.

[0072] In this embodiment, the target application can silently collect the biometric features of a first user from a third-party application, and compare the collected biometric features of the first user with the configured biometric features corresponding to the identifier of a second user currently logged into the target application. If the comparison is successful, the target application executes the target operation requested in the authorization operation request and returns the result of the target operation to the third-party application. During the above authorization operation, the collection of the first user's biometric features and the authentication of the first user's identity are both silently completed in the background by the target application. No user intervention is required, and there is no need to switch between the third-party application and the target application to quickly achieve seamless authorization. This effectively reduces resource consumption during the authorization process and improves authorization efficiency, thus significantly enhancing the user experience. Attached Figure Description

[0073] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0074] Figure 1 This application illustrates an exemplary embodiment of a data processing system architecture diagram.

[0075] Figure 2 A flowchart illustrating a data processing method provided in an exemplary embodiment of this application is shown;

[0076] Figure 3a This illustration shows a schematic diagram of an operation page provided in an exemplary embodiment of this application;

[0077] Figure 3b This illustration shows a schematic diagram of a result page provided by an exemplary embodiment of this application;

[0078] Figure 4 A flowchart illustrating a data processing method provided in an exemplary embodiment of this application is shown;

[0079] Figure 5a This illustration shows a schematic diagram of an authorized operation service provided by an exemplary embodiment of this application;

[0080] Figure 5b This illustration shows a schematic diagram of an exemplary embodiment of this application for updating biometric configuration;

[0081] Figure 5c This illustration shows a schematic diagram of a method for deleting configured biometrics according to an exemplary embodiment of this application;

[0082] Figure 6a This illustration shows a method for sharing operations provided by an exemplary embodiment of this application;

[0083] Figure 6b A schematic diagram illustrating a sharing operation provided by an exemplary embodiment of this application is shown;

[0084] Figure 6c This application illustrates a method for a payment operation according to an exemplary embodiment.

[0085] Figure 6d A schematic diagram illustrating a payment operation provided by an exemplary embodiment of this application is shown;

[0086] Figure 7 This invention provides a schematic diagram of the structure of a data processing apparatus according to an exemplary embodiment of the present application.

[0087] Figure 8 This invention provides a schematic diagram of the structure of another data processing apparatus according to an exemplary embodiment of the present application.

[0088] Figure 9 A schematic diagram of the structure of a data processing device provided in an exemplary embodiment of this application is shown. Detailed Implementation

[0089] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0090] This application relates to Artificial Intelligence (AI), which is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results. In other words, AI is a comprehensive technology within computer science that attempts to understand the essence of intelligence and produce a new kind of intelligent machine that can react in a way similar to human intelligence. AI studies the design principles and implementation methods of various intelligent machines, enabling them to have perception, reasoning, and decision-making functions. AI technology is a comprehensive discipline involving a wide range of fields, encompassing both hardware and software technologies. Fundamental AI technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing technology, operating / interactive systems, and mechatronics. AI software technologies mainly include computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0091] Computer vision (CV) is a science that studies how to enable machines to "see." More specifically, it refers to machine vision, which uses cameras and computers to replace human eyes in recognizing, tracking, and measuring targets, and then performs image processing to create images more suitable for human observation or transmission to instruments. As a scientific discipline, computer vision studies related theories and technologies, attempting to build artificial intelligence systems capable of extracting information from images or multidimensional data. Computer vision technologies typically include image processing, image recognition, image semantic understanding, image retrieval, OCR, video processing, video semantic understanding, video content / behavior recognition, 3D object reconstruction, 3D technology, virtual reality, augmented reality, simultaneous localization and mapping (SLAM), and common biometric recognition technologies such as facial recognition and fingerprint recognition.

[0092] This application relates to biometrics, specifically non-contact and non-sensory biometrics. Such biometrics may include, but are not limited to, facial images, facial texture features, iris features, etc. By recognizing a user's biometrics, the user's identity can be identified. For example, iris recognition technology is an identity verification technology based on the iris of the eye.

[0093] This application also relates to applications, which can refer to a client installed on a terminal. A client (also known as an application client or APP client) is a program installed and running on a terminal. Applications can also refer to installation-free applications, i.e., applications that can be used without downloading and installing; these applications are commonly known as mini-programs, which typically run as subroutines on the client. Applications can also refer to web applications opened through a browser; and so on. These various applications are categorized according to the application functions they provide. Application types may include, but are not limited to: instant messaging applications, payment applications, audio / video applications, game applications, office applications, etc.

[0094] To enrich the application's functionality, this application also supports authorization operations between applications. An authorization operation refers to the process by which a target application authorizes a third-party application. Specifically, the target application responds to the authorization request from the third-party application and executes the target operation to help the third-party application expand its application functionality. For example, a game application requests a payment application to perform a payment operation to help the game application complete a payment; similarly, a video / audio application requests an instant messaging application to perform a sharing operation to share content from a third-party application to the instant messaging application. This method of authorization operations between applications allows applications to obtain rich application functionality without developing all application functions; they only need to perform authorization operations.

[0095] Based on this, this application provides a data processing scheme. The scheme proposes that: a target application responds to an authorization request sent by a third-party application by silently collecting the biometric features of a first user from the third-party application; and authenticates the first user's identity based on the biometric features; when the first user's identity is successfully authenticated, the target operation is executed, and the result of the target operation is returned to the third-party application. Silent collection means that the entire process, from collecting the first user's biometric features to generating the target operation result, is completed in the background of the terminal where the target application is located. For the first user, this process is seamless (i.e., the user does not need to perform a confirmation authorization operation in the target application). In the above authorization operation, the collection of the first user's biometric features and the authentication process are both silently completed in the background of the target application. No user intervention is required, and there is no need to switch between the third-party application and the target application to quickly achieve seamless authorization, effectively reducing resource consumption and improving efficiency. This seamless authorization method effectively enhances the user experience.

[0096] Figure 1 This illustration shows a schematic diagram of the architecture of a data processing system provided in an exemplary embodiment of this application. Figure 1 As shown, the data processing system may include a terminal 101 and a server 102. The terminal 101 may include, but is not limited to, smartphones (such as Android phones, iOS phones, etc.), tablet computers, portable personal computers, mobile internet devices (MIDs), smart TVs, etc. This application embodiment does not limit the type of terminal. The terminal includes a display screen, which may be a physical screen, a touch screen, etc., and also includes biometric acquisition devices, such as a 3D camera for capturing the user's facial image. The server 102 may be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal and server can be directly or indirectly connected via wired or wireless communication, which is not limited herein.

[0097] The data processing scheme described in the above embodiments can be completed through interaction between terminal 101 and server 102. Terminal 101 can refer to the terminal corresponding to the user of the application. Terminal 101 can install and run at least one application, and the identifiers of multiple applications are displayed on the display screen of terminal 101, such as the identifier 1011 of a third-party application and the identifier 1012 of the target application. Server 102 can refer to a cloud server communicating with terminal 101. The cloud database 1021 in the cloud server stores the configured biometric features corresponding to the target application. A user's configured biometric features may include multiple features; for example, a user's configured biometric features may include a configured facial image, configured iris features, etc.

[0098] exist Figure 1In the data processing system shown, the data processing scheme proposed in this application mainly includes the following steps: ① When the authorized operation entry of the target application displayed by the third-party application 1011 in terminal 101 is selected, the third-party application 1011 sends an authorized operation request to the target application 1012; wherein, the authorized operation request is used to request the target application to perform a target operation (such as a sharing operation, a payment operation, etc.). ② In response to the received authorized operation request, the target application 1012 silently collects the biometric features of the first user on the side of the third-party application 1011; for example, in response to the authorized operation request sent by the third-party application, the target application calls the camera of the terminal 101 where the target application 1012 is located in the background to collect the face image of the first user. ③ The target application authenticates the identity of the first user based on the collected biometric features of the first user; specifically, the target application can obtain the configured biometric features of the currently logged-in second user in the target application from the cloud database 1021 in server 102, and compare the configured biometric features of the second user with the biometric features of the first user; or, terminal 101 sends the biometric features of the first user to server 102, and correspondingly, server 102 performs the operation of authenticating the identity of the first user. ④ If the authentication of the first user is successful, the target application 1012 silently executes the target operation according to the attribute information of the target operation carried in the authorization operation request, obtains the target operation result, and returns the target operation result to the third-party application 1011. ⑤ After receiving the target operation result, the third-party application 1011 jumps from the operation interface to the result page and displays the target operation result on the result page.

[0099] In this embodiment, the target application can silently collect the biometric features of a first user from a third-party application, and compare the collected biometric features of the first user with the configured biometric features corresponding to the identifier of a second user currently logged into the target application. If the comparison is successful, the target application executes the target operation requested in the authorization operation request and returns the result of the target operation to the third-party application. During the above authorization operation, the collection of the first user's biometric features and the authentication of the first user's identity are both silently completed in the background by the target application. No user intervention is required, and there is no need to switch between the third-party application and the target application to quickly achieve seamless authorization. This effectively reduces resource consumption during the authorization process and improves authorization efficiency, thus significantly enhancing the user experience.

[0100] Based on the above description, the data processing scheme proposed in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0101] Please see Figure 2 , Figure 2 This illustration shows a flowchart of a data processing method provided in an exemplary embodiment of this application; the data processing method can be... Figure 1 The third-party application 1011 included in the terminal 101 in the system shown executes the method, which includes, but is not limited to, steps S201-S203:

[0102] S201. Display the operation page of the third-party application, which includes the authorization operation entry point for the target application.

[0103] An operation page can refer to a page provided by a third-party application for the user to perform a target operation. This target operation can be a sharing operation, a payment operation, etc. Accordingly, operation pages can include, but are not limited to, sharing pages, payment pages, etc. Please see... Figure 3a , Figure 3a This illustration shows a schematic diagram of an operation page provided by an exemplary embodiment of this application; as shown Figure 3a As shown, the service page 3011 of the third-party application displays at least one page element (such as an image element, video element, text element, etc.), and a sharing icon 301 is displayed in the area where some page elements are located. When the sharing icon 301 is triggered, it indicates that the user wishes to share the page element, and an operation page 302 is displayed. The operation page 302 contains at least one authorization operation entry for the application, such as application authorization operation entry 3021, application authorization operation entry 3022, and application authorization operation entry 3023, etc. If the authorization operation entry of the target application is selected, it indicates that the user wishes to share the page element to the selected target application. It should be noted that the operation page 302 can be displayed as a window on the service page, or it can be displayed as a separate page covering the service page. This embodiment of the application does not limit this.

[0104] S202. When the authorization operation entry of the target application is triggered, a silent authorization operation request is sent to the target application. The authorization operation request is used to request the target application to perform the target operation.

[0105] The authorization request is used to request authorization services from the target application. The authorization request carries attribute information of the target operation; for example, if the target operation includes a sharing operation, the attribute information of the sharing operation may include, but is not limited to, the link information to be shared. Specifically, when the authorization operation entry point of the target application is selected in the third-party application, the third-party application sends an authorization request to the target application, causing the target application to respond to the authorization request and silently execute the target operation according to the attribute information of the target operation, thus obtaining the result of the target operation. The above process of the target application authorizing the third-party application is completed in the background of the terminal, without requiring page switching between the third-party application and the target application, thus enabling the target application to authorize the third-party application.

[0106] In one implementation, the third-party application integrates a software development kit (SDK) corresponding to the authorization operation service interface of the target application. This allows the third-party application to communicate across processes with the target application by calling the authorization operation service interface. Specifically, when the authorization operation entry point of the target application is triggered on the login screen of the third-party application, the third-party application runs the SSD to call the authorization operation service interface and sends the authorization operation request to the target application through the interface, thus enabling cross-process communication between applications.

[0107] It should be noted that after receiving an authorization request from a third-party application, the target application will respond to the authorization request by executing a series of authorization processes. The specific implementation process of the target application responding to the authorization request can be found in the relevant description of the implementation process in the following embodiments.

[0108] S203. Based on the target operation result returned by the target application, jump from the operation interface of the third-party application to the result page of the third-party application, and display the target operation result on the result page.

[0109] After the target application responds to the authorization request, the third-party application receives the target operation result returned by the target application. At this point, the third-party application is redirected from the operation interface to the result page, which displays the target operation result. This result indicates whether the target application's authorization operation to the third-party application was successful or failed. If the target operation result indicates that the target application's authorization operation to the third-party application was successful, the result interface can display the third-party application's service page (such as the third-party application's main page); if the target operation result indicates that the target application's authorization operation to the third-party application failed, a prompt message is displayed on the result page to remind the user that the authorization operation failed (such as payment failure, sharing failure, etc.).

[0110] Please see Figure 3b , Figure 3b This illustration shows a schematic diagram of a result page provided by an exemplary embodiment of this application; as shown Figure 3b As shown, when the authorization operation entry of the target application is selected in operation page 302, the third-party application calls the software development kit to call the authorization operation service interface to send an authorization operation request to the target application. Correspondingly, the target application responds to the authorization operation request and returns the target operation result to the third-party application. When the target operation result indicates that the target application has successfully authorized the third-party application, the third-party application switches from operation page 302 to service page 3011 (i.e., the result page). When the target operation result indicates that the target application has failed to authorize the third-party application, the third-party application switches from operation page 302 to the result page, and the result page displays a prompt message 303 (such as "XX operation failed!") to inform the user that the target application's authorization of the third-party application has failed.

[0111] In this embodiment, the operation page of the third-party application displays at least one authorization operation entry point for the application. When the authorization operation entry point of the target application is selected, the third-party application runs a software development kit to call the authorization operation service interface and send the authorization operation request to the target application. The target application silently responds to the authorization operation request sent by the third-party application in the background and returns the target operation result to the third-party application. In summary, by adopting the data processing scheme provided in this embodiment, seamless authorization of third-party applications can be achieved without page switching between applications or complex operations by the user, effectively reducing resource consumption in the authorization operation process and making the application authorization operation process not only secure but also convenient.

[0112] Please see Figure 4 , Figure 4 This illustration shows a flowchart of a data processing method provided in an exemplary embodiment of this application; the data processing method can be... Figure 1 The target application 1012 contained in terminal 101 of the system shown is executed, and the method includes, but is not limited to, steps S401-S405:

[0113] S401: Receive an authorization operation request sent by a third-party application.

[0114] The target application can encapsulate open platform capabilities into a Software Development Kit (SDK) for integration by third-party applications. An SDK is a collection of development tools used to build application software for specific software packages, frameworks, hardware platforms, and operating systems. This collection includes documentation, examples, and tools to assist in developing a particular type of software. The SDK also includes Application Programming Interfaces (APIs), which are predefined functions used for data communication. APIs are used to connect different components of the system. For example, in this application, the SDK includes an authorization operation service interface. After obtaining authorization, a third-party application can access a set of routines in the target application through this interface without needing to access the source code or understand the details of the internal workings. Thus, after the third-party application integrates the SDK corresponding to the target application's authorization operation service interface, when the SDK in the third-party application is triggered, the target application's authorization operation service interface is invoked, thereby enabling cross-process communication between the target and third-party applications. Thus, the method of receiving the authorization operation request sent by the third-party application described in step S401 may include: the target application receiving the authorization operation request sent by the third-party application through the authorization operation service interface. In summary, based on the authorization operation service interface and the software development kit (SDK), the third-party application and the target application can communicate through inter-process communication (IPC). This IPC method enables message communication between various applications within the same terminal. For example, in the Android system, IPC is implemented through the Interface Definition Language (AIDL) to achieve inter-process communication between applications.

[0115] It is understandable that a vast number of third-party applications can integrate the software development kit (SDK) provided by the target application. However, not every third-party application that integrates the SSD has the permission to request the authorization operation service provided by the target application. Therefore, after receiving the authorization operation request from the third-party application via the invoked authorization operation service interface, the target application will also verify the third-party application's request permissions. Specifically, it retrieves a list of authorization operation applications corresponding to the target application from the terminal's local database or the cloud database of the cloud server. This list contains the application identifier of at least one authorization operation application, where an authorization operation application refers to an application with the permission to request authorization operation services. If the application identifier of the third-party application is not found in the list, a notification message is sent to the third-party application through the authorization operation service interface. This notification message informs the third-party application that it has no right to request authorization operation services from the target application. If the application identifier of the third-party application is found in the list, it triggers the authentication of the first user's identity based on their biometrics. For example, suppose third-party applications A, B, C, and D all integrate the software development kit (SDK) provided by the target application. If the application identifiers of third-party applications A, B, and C are in the list of authorized operation applications corresponding to the target application, it means that if third-party applications A, B, and C integrate the SSD, these third-party applications can request authorized operation services from the target application. If the identifier of third-party application D is not in the list of authorized operation applications, it means that although third-party application D integrates the SSD of the target application, third-party application D still does not have the permission to request authorized operation services from the target application.

[0116] The authorization operation service provided by the target application mentioned above can be understood as a process derived from the target application and running on the terminal. The authorization operation service is used to detect whether the target application can execute the target operation requested by the third-party application using an authorization method. It should be noted that the authorization operation service mentioned in this application embodiment may include a biometric identification service and an operation service; wherein, the biometric identification service can be used to authenticate the identity of the first user, and when the first user's identity is successfully authenticated, the target application calls the operation service to execute the target operation. Different operation services correspond to different target operations; for example, when the target operation includes a sharing operation, the operation service may be a sharing service; or, when the target operation includes a payment operation, the operation service may be a payment service; and so on.

[0117] It should be noted that, in addition to the biometric identification functions described above, the biometric update and deletion functions are also provided under the authorized operation service. Please refer to [link to relevant documentation]. Figure 5a , Figure 5a This illustration shows a schematic diagram of an authorized operation service provided by an exemplary embodiment of this application; as shown Figure 5a As shown, when the target application receives an authorization request from a third-party application through the authorization operation service interface, the terminal starts and runs the authorization operation service to enable it to provide the aforementioned functions. The biometric update and deletion functions provided by the biometric identification service are described in detail below.

[0118] In one implementation, the biometric identification service provides a biometric update function (or biometric registration function). This biometric update function can update or add the configuration biometrics of a second user stored in the cloud database. Updating can refer to updating the biometrics of the same user previously stored in the cloud database to newly collected configuration biometrics. Adding can refer to storing newly collected configuration biometrics of a user in the cloud database when the user's configuration biometrics are not yet stored there (e.g., when a user's configuration biometrics have been deleted from the cloud database). Please refer to [link to relevant documentation]. Figure 5b , Figure 5b This illustration shows a schematic diagram of an exemplary embodiment of this application providing a method for updating biometric configuration; as shown... Figure 5b As shown, by calling the biometric registration service interface provided by the target application, the biometric service update function can be executed in the terminal to upload the collected biometrics of the current user to the cloud database to update or add the configured biometrics in the cloud database.

[0119] Specifically, the terminal displays the target application's configuration page, which includes the target application's biometric registration service interface. When the biometric registration service interface is selected, the target application's biometric registration page is output, and the configuration biometrics of the user requesting registration are collected from the target application's side on the biometric registration page, along with the user's identifier. The configuration biometrics of the user requesting registration are then associated with the user's identifier and stored in the cloud database. The biometric registration page is used to collect the user's configuration biometrics; the user's identifier can refer to the account obtained when the user successfully registers with the target application (e.g., a registered QQ account, WeChat account, etc.). It should be noted that when the collected user's configuration biometrics are uploaded to the cloud database, the cloud database uses the user's identifier as an index (i.e., key) to associate the user's identifier with the user's configuration biometrics. This allows for faster retrieval of the user's configuration biometrics in the cloud database by using the user's identifier as the index.

[0120] In another implementation, the biometric identification service also provides a biometric deletion service, which allows the deletion of a user's configured biometrics stored in a cloud database. Specifically, the configuration page includes a biometric deletion interface. When this interface is selected, the system retrieves the identifier of the user requesting deletion from the target application side; it then queries the cloud database to see if a configured biometric matches the identifier of the user requesting deletion. If such a matching biometric exists in the cloud database, the configured biometric associated with that identifier is deleted from the cloud database. See also... Figure 5c , Figure 5c This illustration shows a schematic diagram of a method for deleting configured biometrics, provided by an exemplary embodiment of this application.

[0121] It should be noted that the cloud database may also record the environment identifier used during registration for each configured biometric feature. When the cloud server receives a request from a terminal to delete a configured biometric feature, it first verifies the permission of the environment identifier. If the permission verification for the environment identifier is successful, the subsequent operation of deleting the configured biometric feature from the cloud database is executed. The environment identifier can include the terminal identifier of the terminal to which the target application belongs when the user updates or adds configured biometric features in the target application. For example, if the terminal is a mobile phone, the terminal identifier can be the International Mobile Equipment Identity (IMEI), also known as the mobile phone serial number, etc., which is used to uniquely identify a mobile phone. Specifically, based on the environment identifier corresponding to the configured biometric feature associated with the user's identifier requesting deletion, the security of the current environment of the user requesting deletion is checked. If the current environment is secure, the step of deleting the configured biometric feature associated with the user's identifier requesting deletion from the cloud database is executed. One method for detecting the security of the current environment may be to compare the current environment identifier of the user requesting deletion with the environment identifier stored in the cloud database when the user registered. If the current environment identifier of the user requesting deletion matches the environment identifier stored in the cloud database when the user registered, the comparison is successful; otherwise, the comparison fails. This ensures that the user requesting deletion from the cloud database is the user who registered and configured biometrics, thus improving the security of facial images in the cloud database.

[0122] S402. In response to an authorization operation request, silently collect the biometric features of the first user on the third-party application side.

[0123] S403. Authenticate the identity of the first user based on the first user's biometric characteristics.

[0124] In steps S402-S403, when the target application receives an authorization operation request sent by the third-party application, it silently collects the biometric features of the first user on the third-party application side and authenticates the identity of the first user based on the biometric features.

[0125] The authentication of the first user's identity based on their biometrics can be performed on the terminal side. Specifically, the terminal sends a request to the cloud server, which carries the identifier of the currently logged-in second user in the target application. The request requests the cloud server to retrieve and return N configured biometric features related to the second user's identifier from the cloud database, where N is a positive integer. For example, the second user may have uploaded various types of biometric features (such as facial images, iris features, etc.) to the cloud database over a historical period, allowing the cloud database to store multiple configured biometric features related to the second user's identifier. The cloud server returns the N configured biometric features of the second user to the terminal, enabling the terminal to compare the collected first user's biometric features with each of the N configured biometric features of the second user. If any of the N configured biometric features of the second user matches the first user's biometric features, the first user's authentication is successful; otherwise, the first user's authentication fails.

[0126] For example, the cloud server returns N configured biometric features to the terminal for the second user, namely the second user's face image (or face data), the second user's iris feature, and the second user's facial texture feature. The terminal device only has the function of collecting face images and not iris or facial texture features. Therefore, the biometric feature collected for the first user is the first user's face image. Then, the first user's face image is compared one by one with the second user's face image (or face data), the second user's iris feature, and the second user's facial texture feature. If the first user's face image matches the second user's face image, the first user's authentication is successful. Conversely, if the terminal receives N configured biometric features but no face image is found (or the second user's configured face image is different from the first user's face image), the first user's authentication fails.

[0127] It is understandable that the process of authenticating the first user's identity based on the first user's biometrics, as described above, can also be executed on the cloud server side. Specifically, the terminal sends an authentication request to the cloud server, which carries the first user's biometrics and the identifier of the second user currently logged in to the target application. Correspondingly, the cloud server can retrieve N configured biometrics related to the second user's identifier from the cloud database based on the second user's identifier, and compare the first user's biometrics with the second user's N configured biometrics to obtain the first user's authentication result. The cloud server then returns the first user's authentication result to the terminal.

[0128] S404. If the authentication of the first user is successful, the target operation is silently executed according to the attribute information of the target operation carried in the authorization operation request, and the result of the target operation is obtained.

[0129] It is understood that the target operation executed by the target application will vary depending on the attribute information of the target operation carried in the authorization operation request; common target operations may include, but are not limited to, sharing operations, payment operations, etc. The following descriptions take sharing operations and payment operations as examples, respectively, and do not limit the embodiments of this application.

[0130] In one implementation, the target operation includes a sharing operation, and the attribute information of the sharing operation includes the link information to be shared. The process of silently executing the target operation based on the attribute information carried in the authorization operation request to obtain the target operation result may include: the target application obtaining the identifier of the second user currently logged into the target application, and obtaining the page corresponding to the second user in the target application based on the second user's identifier. The page corresponding to the second user in the target application may include one or more of the following: a chat page, a dynamic page, and a content exchange page; the target application silently adds the link information to the page and generates the sharing operation result (i.e., the target operation result). For example, if the target application is a WeChat client, the page corresponding to the second user in the WeChat client could be a Moments page, a friend's chat page, a favorites page, etc. Please see [link to relevant documentation]. Figure 6a , Figure 6a This illustration shows a schematic diagram of a sharing operation method provided by an exemplary embodiment of this application; as shown Figure 6a As shown, after the target application receives the authorization operation request sent by the third-party application, it authenticates the identity of the first user through the biometric identification service. If the first user's identity is successfully authenticated, the sharing service is called to perform the sharing operation, and the generated sharing operation result is returned to the third-party application.

[0131] Understandably, before performing a sharing operation, the target application can verify the link information to be shared to ensure its security. Specifically, the target application can obtain the security level of the link information to be shared, for example, by obtaining the security level from a security monitoring website or by checking the security certificate of a third-party application; compare the security level of the link information with a security level threshold; if the security level of the link information is greater than or equal to the security level threshold, it indicates that the link information is safe and compliant, and the application will trigger the silent execution of the target operation based on the attribute information of the target operation carried in the authorization operation request; if the security level of the link information is less than the security level threshold, it indicates that the link information is insecure, and the application will generate a target operation result indicating that the target operation failed.

[0132] Please see Figure 6b , Figure 6b The illustration shows a schematic diagram of a sharing operation provided by an exemplary embodiment of this application; as shown Figure 6b As shown, after the authorization operation entry 3022 of the target application in the operation page of the third-party application is selected, the target application responds to the authorization operation request sent by the third-party application, and after successfully authenticating the identity of the first user, shares the link information 601 to the second user's page in the target application, for example: Figure 6b The target application shown refers to the second user's Moments page. A link is added to the Moments page. When the link is clicked, the user can switch to a page in the third-party application that contains the linked content. For the third-party application, after the target application completes the target operation, the third-party application directly switches from the operation page to the result page, which saves the application from frequent switching.

[0133] In another implementation, the target operation includes a payment operation, and the attribute information of the payment operation includes the receiving account and the payment amount. Therefore, the process of silently executing the target operation based on the attribute information carried in the authorization request to obtain the target operation result may include: obtaining the identifier of the currently logged-in second user in the target application; obtaining the second user's payment account in the target application based on the second user's identifier; silently deducting the payment amount from the payment account, transferring the deducted payment amount to the receiving account, and generating the payment operation result. Please refer to [link to relevant documentation]. Figure 6c , Figure 6c This application illustrates a method for a payment operation according to an exemplary embodiment; as shown below. Figure 6cAs shown, after the target application receives the authorization request sent by the third-party application, it calls the biometric identification service to authenticate the identity of the first user. If the first user's identity is successfully authenticated, it calls the payment service to perform the payment operation and returns the payment operation result to the third-party application.

[0134] Understandably, the target application can verify the payment account before executing the payment operation to ensure the security of the payment environment. Specifically, the target application checks the credit rating of the receiving account; if the credit rating of the receiving account is greater than or equal to the credit rating threshold, it triggers a step of silently executing the target operation based on the attribute information of the target operation carried in the authorization operation request, and obtaining the target operation result; if the credit rating of the receiving account is less than the credit rating threshold, the generated target operation result indicates that the payment operation failed.

[0135] Please see Figure 6d , Figure 6d The illustration shows a schematic diagram of a payment operation provided by an exemplary embodiment of this application; as shown... Figure 6d As shown, the operation page of the third-party application displays a payment information area 602 and a payment method area 603. The payment information area 602 displays information such as the payment amount and payment account, while the payment method area 603 displays at least one authorized operation entry point for the application. When the authorized operation entry point of the target application is selected, the target application silently performs the payment operation (i.e., silently deducts the payment amount from the payment account and transfers the payment amount to the payment account) and returns the payment operation result to the third-party application. When the payment operation result indicates that the payment operation is successful, the third-party application switches from the operation page to the service page 3011. When the payment operation result indicates that the payment operation fails, the third-party application displays a prompt message to inform the user of the payment failure. It is understood that the page style of the third-party application described above is only an example, and this application embodiment does not limit the page style of the third-party application.

[0136] It should be noted that, in addition to the security checks on link information and payment accounts described above, there are many other ways to ensure the security of the target operation execution environment (such as the sharing environment and payment environment). This application embodiment uses the verification of the security of link information and payment accounts as an example for introduction, and does not limit the embodiments of this application.

[0137] S405. Return the target operation result to the third-party application.

[0138] The target application can return the target operation result to the third-party application through the authorization operation service interface. The target operation result can be used to prompt the user whether the target application's authorization of the third-party application was successful or failed.

[0139] In this embodiment, the target application can silently collect the biometric features of a first user from a third-party application, and compare the collected biometric features of the first user with the configured biometric features corresponding to the identifier of a second user currently logged into the target application. If the comparison is successful, the target application executes the target operation requested in the authorization operation request and returns the result of the target operation to the third-party application. During the above authorization operation, the collection of the first user's biometric features and the authentication of the first user's identity are both silently completed in the background by the target application. No user intervention is required, and there is no need to switch between the third-party application and the target application to quickly achieve seamless authorization. This effectively reduces resource consumption during the authorization process and improves authorization efficiency, thus significantly enhancing the user experience.

[0140] The methods of the embodiments of this application have been described in detail above. In order to facilitate better implementation of the above solutions of the embodiments of this application, the apparatus of the embodiments of this application is provided below.

[0141] Please see Figure 7 , Figure 7 The diagram shows a structural schematic of a data processing apparatus provided in an exemplary embodiment of this application. The data processing apparatus can be mounted on the data processing device where the third-party application is located in the above method embodiment. The data processing apparatus can be a plug-in in the data processing device. Figure 7 The data processing apparatus shown can be used to perform the above. Figure 2 The described method embodiments include some or all of the functionalities. The detailed descriptions of each unit are as follows:

[0142] Display unit 701 is used to display the operation page of a third-party application, the operation page including the authorization operation entry of the target application;

[0143] The processing unit 702 is configured to silently send an authorization operation request to the target application when the authorization operation entry of the target application is triggered. The authorization operation request is used to request the target application to perform a target operation and carries the attribute information of the target operation. This enables the target application to respond to the authorization operation request, silently perform the target operation according to the attribute information of the target operation, and return the target operation result. Furthermore, based on the target operation result returned by the target application, the processing unit 702 jumps from the operation interface of the third-party application to the result page of the third-party application and displays the target operation result on the result page.

[0144] In one implementation, a software development kit (SDK) corresponding to the authorized operation service interface of the target application is integrated into a third-party application. The third-party application runs the SSD to call the authorized operation service interface to communicate with the target application across processes.

[0145] When processing unit 702 sends an authorization operation request to the target application, it specifically performs the following functions:

[0146] Run the software tool development kit to call the authorization operation service interface to send an authorization operation request.

[0147] According to one embodiment of this application, Figure 2 The data processing method shown may involve some steps that can be derived from... Figure 7 The data processing apparatus shown is executed by each unit within it. For example, Figure 2 Step 201 shown can be performed by Figure 7 The display unit 701 shown executes the steps 202-203, which can be performed by... Figure 7 The processing unit 702 shown is executed. Figure 7 The data processing apparatus shown can be constructed by combining each unit individually or entirely into one or more other units, or one or more of the units can be further divided into multiple functionally smaller units. This achieves the same operation without affecting the technical effects of the embodiments of this application. The above-mentioned units are based on logical function division. In practical applications, the function of one unit can be implemented by multiple units, or the function of multiple units can be implemented by one unit. In other embodiments of this application, the data processing apparatus may also include other units. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented collaboratively by multiple units.

[0148] According to another embodiment of this application, the following can be executed by running on a general-purpose computing device, such as a computer, which includes processing elements and storage elements such as a central processing unit (CPU), random access memory (RAM), and read-only memory (ROM). Figure 2 The computer program (including program code) for each step involved in the corresponding method shown, to construct such... Figure 7 The data processing apparatus shown herein, and the data processing method for implementing the embodiments of this application, are described. A computer program may be recorded on, for example, a computer-readable recording medium, loaded onto the aforementioned computing device via the computer-readable recording medium, and executed therein.

[0149] Based on the same inventive concept, the principle and beneficial effects of the data processing device provided in the embodiments of this application in solving the problem are similar to the principle and beneficial effects of the data processing method in the embodiments of this application in solving the problem. For the sake of brevity, the principle and beneficial effects of the method implementation can be referred to.

[0150] Please see Figure 8 , Figure 8 The present application provides a schematic diagram of the structure of another data processing apparatus provided in an exemplary embodiment. The data processing apparatus can be mounted on the data processing device where the target application is located in the above method embodiment. The data processing apparatus can be a plug-in in the data processing device. Figure 8 The data processing apparatus shown can be used to perform the above. Figure 4 The described method embodiments include some or all of the functionalities. The detailed descriptions of each unit are as follows:

[0151] The processing unit 801 is configured to receive an authorization operation request sent by a third-party application, the authorization operation request being used to request the target application to perform a target operation, the authorization operation request carrying attribute information of the target operation; in response to the authorization operation request, silently collect the biometric features of a first user on the third-party application side; authenticate the identity of the first user based on the first user's biometric features; if the identity authentication of the first user is successful, silently execute the target operation based on the attribute information of the target operation carried in the authorization operation request, and obtain the target operation result;

[0152] The communication unit 802 is used to return the target operation result to a third-party application.

[0153] In one implementation, the target operation includes a sharing operation, and the attribute information of the sharing operation includes the link information to be shared; when the processing unit 801 silently executes the target operation according to the attribute information of the target operation carried in the authorization operation request and obtains the target operation result, it is specifically used for:

[0154] Obtain the identifier of the second currently logged-in user in the target application;

[0155] Based on the second user's identifier, obtain the page corresponding to the second user in the target application. The page includes one or more of the following: a conversation page, a dynamic page, and a content communication page.

[0156] The link information is silently added to the page, and the sharing result is generated.

[0157] In one embodiment, the processing unit 801 is further configured to:

[0158] Security level of obtaining link information;

[0159] If the security level of the link information is greater than or equal to the security level threshold, then the target operation will be silently executed by triggering the attribute information of the target operation carried in the root authorization operation request to obtain the result of the target operation.

[0160] In one implementation, the target operation is a payment operation, and the attribute information of the payment operation includes the receiving account and the payment amount.

[0161] When processing unit 801 silently executes the target operation based on the attribute information of the target operation carried in the authorized operation request and obtains the result of the target operation, it is specifically used for:

[0162] Obtain the identifier of the second currently logged-in user in the target application;

[0163] Based on the second user's identifier, obtain the second user's payment account in the target application;

[0164] The payment amount is silently deducted from the payment account, transferred to the receiving account, and a payment operation result is generated.

[0165] In one embodiment, the processing unit 801 is further configured to:

[0166] Check the credit rating of the receiving account;

[0167] If the credit rating of the receiving account is greater than or equal to the credit rating threshold, then the step of silently executing the target operation based on the attribute information of the target operation carried in the authorized operation request and obtaining the result of the target operation is triggered.

[0168] In one implementation, a software development kit (SDK) corresponding to the authorized operation service interface of the target application is integrated into the third-party application. The third-party application runs the SSD to call the authorized operation service interface for cross-process communication with the target application. The processing unit 801 is further configured to:

[0169] The authorization operation service interface being invoked receives authorization operation requests sent by third-party applications.

[0170] Among them, based on the authorized operation service interface and software development kit, third-party applications and target applications can communicate through cross-process communication.

[0171] In one embodiment, the processing unit 801 is further configured to:

[0172] Obtain the list of authorized operation applications corresponding to the target application. The list of authorized operation applications contains the application identifier of at least one authorized operation application. An authorized operation application is an application that has the request permission for authorized operation services.

[0173] If a third-party application's application identifier exists in the list of authorized application operations, then the step of verifying the target user's identity information based on the target user's biometrics will be triggered.

[0174] If the application identifier of a third-party application is not found in the list of authorized operation applications, a notification message is sent to the third-party application through the authorized operation service interface. The notification message is used to inform the third-party application that it is not authorized to request the authorized operation service from the target application.

[0175] In one implementation, the biometric database refers to a cloud database used to store biometric features; the biometric features include at least one of the following: face images, facial texture features, and iris features;

[0176] When authenticating the identity of the first user based on the first user's biometric characteristics, the processing unit 801 is specifically used for:

[0177] Send an acquisition request to the cloud server, the acquisition request carrying the identifier of the second user currently logged in in the target application; the acquisition request is used to request the cloud server to retrieve and return N configured biometric features related to the identifier of the second user from the cloud database, where N is a positive integer;

[0178] Receive N configuration biometric features of the second user returned by the cloud server;

[0179] The biometric features of the first user are compared one by one with the N configured biometric features of the second user;

[0180] If one of the N configured biometric features of the second user matches the biometric feature of the first user, then the first user's identity authentication is successful.

[0181] If none of the N configured biometric features of the second user match the biometric features of the first user, then the authentication of the first user is determined to have failed.

[0182] In one implementation, the biometric database refers to a cloud database used to store biometric features; the biometric features include at least one of the following: face images, facial texture features, and iris features;

[0183] When authenticating the identity of the first user based on the first user's biometric characteristics, the processing unit 801 is specifically used for:

[0184] An authentication request is sent to the cloud server, carrying the biometrics of the first user and the identifier of the second user currently logged in to the target application; so that the cloud server retrieves N configured biometrics related to the identifier of the second user from the cloud database, and compares the biometrics of the first user with the N configured biometrics of the second user to obtain the authentication result of the first user;

[0185] Receive the authentication result of the first user returned by the cloud server.

[0186] In one embodiment, the processing unit 801 is further configured to:

[0187] Display the target application's configuration page, which contains the target application's biometric registration service interface and biometric deletion service interface;

[0188] When the biometric registration service interface is selected, the biometric registration page of the target application is displayed;

[0189] The biometric registration service page collects the configured biometrics of the user requesting registration from the target application side and obtains the identifier of the user requesting registration.

[0190] The configured biometric features of the user requesting registration and their associated identifier are stored in the biometric database.

[0191] When the biometric deletion service interface is triggered, obtain the identifier of the user requesting deletion from the target application side;

[0192] Query whether the biometric database stores the configuration biometrics associated with the identifier of the user requested for deletion;

[0193] If the biometric database stores configuration biometrics associated with the identifier of the user requesting deletion, then delete the configuration biometrics associated with the identifier of the user requesting deletion from the biometric database.

[0194] According to one embodiment of this application, Figure 4 The data processing method shown may involve some steps that can be derived from... Figure 8 The data processing apparatus shown is executed by each unit within it. For example, Figure 4 Steps 401-404 shown can be derived from... Figure 8 The processing unit 801 shown executes the step 405, which can be performed by... Figure 8 The communication unit 802 shown is executed. Figure 8The data processing apparatus shown can be constructed by combining each unit individually or entirely into one or more other units, or one or more of the units can be further divided into multiple functionally smaller units. This achieves the same operation without affecting the technical effects of the embodiments of this application. The above-mentioned units are based on logical function division. In practical applications, the function of one unit can be implemented by multiple units, or the function of multiple units can be implemented by one unit. In other embodiments of this application, the data processing apparatus may also include other units. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented collaboratively by multiple units.

[0195] According to another embodiment of this application, the following can be executed by running on a general-purpose computing device, such as a computer, which includes processing elements and storage elements such as a central processing unit (CPU), random access memory (RAM), and read-only memory (ROM). Figure 4 The computer program (including program code) for each step involved in the corresponding method shown, to construct such... Figure 8 The data processing apparatus shown herein, and the data processing method for implementing the embodiments of this application, are described. A computer program may be recorded on, for example, a computer-readable recording medium, loaded onto the aforementioned computing device via the computer-readable recording medium, and executed therein.

[0196] Based on the same inventive concept, the principle and beneficial effects of the data processing device provided in the embodiments of this application in solving the problem are similar to the principle and beneficial effects of the data processing method in the embodiments of this application in solving the problem. For the sake of brevity, the principle and beneficial effects of the method implementation can be referred to.

[0197] Please see Figure 9 , Figure 9This illustration shows a schematic diagram of a data processing device provided in an exemplary embodiment of this application. The data processing device includes at least a processor 901, a communication interface 902, and a memory 903. The processor 901, communication interface 902, and memory 903 can be connected via a bus or other means; this embodiment uses a bus connection as an example. The processor 901 (or Central Processing Unit, CPU) is the computing and control core of the data processing device. It can parse various instructions within the terminal device and process various data from the terminal device. For example, the CPU can parse power-on / off commands sent by the user to the terminal device and control the terminal device to perform power-on / off operations; it can also transmit various interactive data between internal structures of the terminal device, and so on. The communication interface 902 may optionally include a standard wired interface or a wireless interface (such as Wi-Fi, mobile communication interface, etc.), and can be used to send and receive data under the control of the processor 901; the communication interface 902 can also be used for data transmission and interaction within the terminal device. The memory 903 is a storage device in the terminal device used to store programs and data. It is understood that the memory 903 here may include the built-in memory of the terminal device, or it may include the extended memory supported by the terminal device. The memory 903 provides storage space for storing the operating system of the terminal device, which may include, but is not limited to, Android, iOS, Windows Phone, etc., and this application does not limit this.

[0198] In one embodiment, the data processing device may be Figure 1 The terminal where the third-party application resides. In this case, the processor 901 performs the following operations by running the executable program code in the memory 903:

[0199] Displays the operation page of the third-party application, which includes the authorization operation entry point for the target application;

[0200] When the authorization operation entry of the target application is triggered, an authorization operation request is silently sent to the target application. The authorization operation request is used to request the target application to execute the target operation. The authorization operation request carries the attribute information of the target operation. This allows the target application to respond to the authorization operation request, silently execute the target operation according to the attribute information of the target operation, and return the result of the target operation.

[0201] Based on the target operation result returned by the target application, the user is redirected from the operation interface of the third-party application to the result page of the third-party application, where the target operation result is displayed.

[0202] In one implementation, a software development kit (SDK) corresponding to the authorization operation service interface of the target application is integrated into a third-party application. The third-party application runs the SSD to call the authorization operation service interface for cross-process communication with the target application. When the processor 901 sends an authorization operation request to the target application, it is specifically used for:

[0203] Run the software tool development kit to call the authorization operation service interface to send an authorization operation request.

[0204] In one embodiment, the data processing device may be Figure 1 The terminal where the target application resides. In this case, processor 901 performs the following operations by running the executable program code in memory 903:

[0205] The system receives an authorization request from a third-party application. The authorization request requests the target application to perform a target operation and carries the attribute information of the target operation. In response to the authorization request, the system silently collects the biometric features of the first user from the third-party application. The system authenticates the identity of the first user based on the biometric features. If the authentication of the first user is successful, the system silently executes the target operation based on the attribute information of the target operation carried in the authorization request and obtains the result of the target operation.

[0206] The target operation result is returned to the third-party application.

[0207] In one implementation, the target operation includes a sharing operation, and the attribute information of the sharing operation includes the link information to be shared; the processor 801 silently executes the target operation according to the attribute information of the target operation carried in the authorization operation request, and the specific implementation of obtaining the target operation result is as follows:

[0208] Obtain the identifier of the second currently logged-in user in the target application;

[0209] Based on the second user's identifier, obtain the page corresponding to the second user in the target application. The page includes one or more of the following: a conversation page, a dynamic page, and a content communication page.

[0210] The link information is silently added to the page, and the sharing result is generated.

[0211] In one implementation, the processor 801, by running executable program code in the memory 803, also performs the following operations:

[0212] Security level of obtaining link information;

[0213] If the security level of the link information is greater than or equal to the security level threshold, then the target operation will be silently executed by triggering the attribute information of the target operation carried in the root authorization operation request to obtain the result of the target operation.

[0214] In one implementation, the target operation is a payment operation, and the attribute information of the payment operation includes the receiving account and the payment amount.

[0215] The processor 801 silently executes the target operation based on the attribute information of the target operation carried in the authorized operation request, and the specific implementation method for obtaining the target operation result is as follows:

[0216] Obtain the identifier of the second currently logged-in user in the target application;

[0217] Based on the second user's identifier, obtain the second user's payment account in the target application;

[0218] The payment amount is silently deducted from the payment account, transferred to the receiving account, and a payment operation result is generated.

[0219] In one implementation, the processor 801, by running executable program code in the memory 803, also performs the following operations:

[0220] Check the credit rating of the receiving account;

[0221] If the credit rating of the receiving account is greater than or equal to the credit rating threshold, then the step of silently executing the target operation based on the attribute information of the target operation carried in the authorized operation request and obtaining the result of the target operation is triggered.

[0222] In one implementation, a software development kit (SDK) corresponding to the authorized operation service interface of the target application is integrated into the third-party application. The third-party application runs the SSD to call the authorized operation service interface for cross-process communication with the target application. The processor 801 also performs the following operations by running the executable program code in the memory 803:

[0223] The authorization operation service interface being invoked receives authorization operation requests sent by third-party applications.

[0224] Among them, based on the authorized operation service interface and software development kit, third-party applications and target applications can communicate through cross-process communication.

[0225] In one implementation, the processor 801, by running executable program code in the memory 803, also performs the following operations:

[0226] Obtain the list of authorized operation applications corresponding to the target application. The list of authorized operation applications contains the application identifier of at least one authorized operation application. An authorized operation application is an application that has the request permission for authorized operation services.

[0227] If a third-party application's application identifier exists in the list of authorized application operations, then the step of verifying the target user's identity information based on the target user's biometrics will be triggered.

[0228] If the application identifier of a third-party application is not found in the list of authorized operation applications, a notification message is sent to the third-party application through the authorized operation service interface. The notification message is used to inform the third-party application that it is not authorized to request the authorized operation service from the target application.

[0229] In one implementation, the biometric database refers to a cloud database used to store biometric features; the biometric features include at least one of the following: face images, facial texture features, and iris features;

[0230] The specific implementation method of processor 801 authenticating the identity of the first user based on the first user's biometric characteristics is as follows:

[0231] Send an acquisition request to the cloud server, the acquisition request carrying the identifier of the second user currently logged in in the target application; the acquisition request is used to request the cloud server to retrieve and return N configured biometric features related to the identifier of the second user from the cloud database, where N is a positive integer;

[0232] Receive N configuration biometric features of the second user returned by the cloud server;

[0233] The biometric features of the first user are compared one by one with the N configured biometric features of the second user;

[0234] If one of the N configured biometric features of the second user matches the biometric feature of the first user, then the first user's identity authentication is successful.

[0235] If none of the N configured biometric features of the second user match the biometric features of the first user, then the authentication of the first user is determined to have failed.

[0236] In one implementation, the biometric database refers to a cloud database used to store biometric features; the biometric features include at least one of the following: face images, facial texture features, and iris features;

[0237] The specific implementation method of processor 801 authenticating the identity of the first user based on the first user's biometric characteristics is as follows:

[0238] An authentication request is sent to the cloud server, carrying the biometrics of the first user and the identifier of the second user currently logged in to the target application; so that the cloud server retrieves N configured biometrics related to the identifier of the second user from the cloud database, and compares the biometrics of the first user with the N configured biometrics of the second user to obtain the authentication result of the first user;

[0239] Receive the authentication result of the first user returned by the cloud server.

[0240] In one implementation, the processor 801, by running executable program code in the memory 803, also performs the following operations:

[0241] Display the target application's configuration page, which contains the target application's biometric registration service interface and biometric deletion service interface;

[0242] When the biometric registration service interface is selected, the biometric registration page of the target application is displayed;

[0243] The biometric registration service page collects the configured biometrics of the user requesting registration from the target application side and obtains the identifier of the user requesting registration.

[0244] The configured biometric features of the user requesting registration and their associated identifier are stored in the biometric database.

[0245] When the biometric deletion service interface is triggered, obtain the identifier of the user requesting deletion from the target application side;

[0246] Query whether the biometric database stores the configuration biometrics associated with the identifier of the user requested for deletion;

[0247] If the biometric database stores configuration biometrics associated with the identifier of the user requesting deletion, then delete the configuration biometrics associated with the identifier of the user requesting deletion from the biometric database.

[0248] Based on the same inventive concept, the principle and beneficial effects of the application login device provided in the embodiments of this application are similar to the principle and beneficial effects of the data processing method in the embodiments of this application. For details, please refer to the principle and beneficial effects of the method implementation. For the sake of brevity, they will not be repeated here.

[0249] This application also provides a computer-readable storage medium storing a computer program adapted to be loaded by a processor and executed by the data processing method described in the above-described method embodiments.

[0250] This application also provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the aforementioned data processing method.

[0251] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0252] The steps in the method of this application embodiment can be adjusted, combined, or deleted according to actual needs.

[0253] The modules in the device of this application embodiment can be merged, divided, and deleted according to actual needs.

[0254] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc.

[0255] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Those skilled in the art will understand that all or part of the processes for implementing the above embodiments and equivalent variations made in accordance with the claims of this application are still within the scope of this application.

Claims

1. A data processing method, characterized by, The application comprises: When an authorized operation entry of a target application in a third-party application is selected, the target application receives an authorized operation request sent by the third-party application, the authorized operation request is used to request an authorized operation service from the target application, the authorized operation request is used to request the target application to execute a target operation, and attribute information of the target operation is carried in the authorized operation request; The authorized operation service comprises a biometric identification service and an operation service; The biometric identification service is used to authenticate the identity of a first user on the side of the third-party application, and the operation service is used to execute the target operation in the target application; The target application responds to the authorized operation request by the biometric identification service to silently collect the biometric feature of the first user on the side of the third-party application; The target application authenticates the identity of the first user according to the biometric feature of the first user; a configuration biometric feature used for the authentication is stored in a biometric feature library, the biometric feature library records a terminal identifier of a terminal to which the target application belongs when the configuration biometric feature is registered; and a process of deleting the configuration biometric feature in the biometric feature library comprises: when a biometric feature deletion service interface included in a configuration page of the target application is selected, detecting the security of a current environment in which a user requesting deletion is located according to an environmental identifier corresponding to the configuration biometric feature associated with the identity of the user requesting deletion, and if the security is good, deleting the configuration biometric feature associated with the identity of the user requesting deletion from the biometric feature library; If the authentication of the identity of the first user is successful, the target application executes the target operation according to the attribute information of the target operation carried in the authorized operation request by the operation service to obtain a target operation result; wherein the target operation comprises a sharing operation and a payment operation, the sharing operation refers to sharing content in the third-party application in the target application, and the payment operation refers to deducting a payment amount generated in the third-party application from a payment account of a second user currently logged in the target application and transferring the payment amount to a payment account; The target application returns the target operation result to the third-party application.

2. The method of claim 1, wherein, The target operation comprises a sharing operation, and the attribute information of the sharing operation comprises link information to be shared; The target operation result is obtained by executing the target operation according to the attribute information of the target operation carried in the authorized operation request, comprising: Obtaining the identity of the second user currently logged in the target application; According to the identity of the second user, obtaining a page corresponding to the second user in the target application, the page comprising one or more of the following: a conversation page, a dynamic page and a content exchange page; The link information is silently added to the page to generate a sharing operation result.

3. The method of claim 2, wherein, Before the step of performing the target operation according to the attribute information of the target operation carried in the authorized operation request in silence to obtain a target operation result, the method further comprises: obtaining a security level of the link information; if the security level of the link information is greater than or equal to a security level threshold, triggering the step of performing the target operation according to the attribute information of the target operation carried in the authorized operation request in silence to obtain a target operation result.

4. The method of claim 1, wherein, The target operation is a payment operation, and the attribute information of the payment operation includes a payment account and a payment amount. The step of performing the target operation according to the attribute information of the target operation carried in the authorized operation request in silence to obtain a target operation result comprises: obtaining an identifier of a second user currently logged in the target application program; obtaining a payment account of the second user in the target application program according to the identifier of the second user; deducting the payment amount from the payment account in silence, transferring the deducted payment amount to the payment account, and generating a payment operation result.

5. The method of claim 4, wherein, Before the step of performing the target operation according to the attribute information of the target operation carried in the authorized operation request in silence to obtain a target operation result, the method further comprises: detecting a credit level of the payment account; if the credit level of the payment account is greater than or equal to a credit level threshold, triggering the step of performing the target operation according to the attribute information of the target operation carried in the authorized operation request in silence to obtain a target operation result.

6. The method of claim 1, wherein, The third-party application program integrates a software development kit corresponding to the authorization operation service interface of the target application program, and the third-party application program runs the software development kit to call the authorization operation service interface to communicate with the target application program across processes; The method further comprises: receiving the authorized operation request sent by the third-party application program based on the called authorization operation service interface; wherein, based on the authorization operation service interface and the software development kit, the third-party application program and the target application program can communicate through a cross-process communication mode.

7. The method of claim 6, wherein, After the step of receiving the authorized operation request sent by the third-party application program based on the called authorization operation service interface, the method further comprises: obtaining an authorization operation application program list corresponding to the target application program, the authorization operation application program list containing application identifiers of at least one authorization operation application program, and the authorization operation application program being an application program having a request right of an authorization operation service; if the application identifier of the third-party application program exists in the authorization operation application program list, triggering the step of verifying the identity of the first user according to the biological characteristics of the first user; if the application identifier of the third-party application program does not exist in the authorization operation application program list, sending a notification message to the third-party application program through the authorization operation service interface, and the notification message is used to notify the third-party application program that it has no right to request the authorization operation service from the target application program.

8. The method of claim 1, wherein, The biometric feature library refers to a cloud database for storing biometric features; the biometric features include at least one of the following: a face image, a faceprint feature, and an iris feature; The identity of the first user is authenticated according to the biometric feature of the first user, and the identity authentication of the first user includes: An acquisition request is sent to a cloud server, and the acquisition request carries an identifier of a second user currently logged in the target application program; the acquisition request is used to request the cloud server to retrieve and return N configuration biometric features related to the identifier of the second user from the cloud database, N being a positive integer; The N configuration biometric features of the second user returned by the cloud server are received; The biometric feature of the first user is compared with the N configuration biometric features of the second user one by one; If there is a biometric feature matching the biometric feature of the first user in the N configuration biometric features of the second user, it is determined that the identity authentication of the first user is successful; If there is no biometric feature matching the biometric feature of the first user in the N configuration biometric features of the second user, it is determined that the identity authentication of the first user fails.

9. The method of claim 1, wherein, The biometric feature library refers to a cloud database for storing biometric features; the biometric features include at least one of the following: a face image, a faceprint feature, and an iris feature; The identity of the first user is authenticated according to the biometric feature of the first user, and the identity authentication of the first user includes: An identity authentication request is sent to a cloud server, and the identity authentication request carries a biometric feature of the first user and an identifier of a second user currently logged in the target application program; so that the cloud server retrieves N configuration biometric features related to the identifier of the second user from the cloud database, and compares the biometric feature of the first user with the N configuration biometric features of the second user to obtain an identity authentication result of the first user; The identity authentication result of the first user returned by the cloud server is received.

10. The method of claim 1, wherein, The method further includes: A configuration page of the target application program is displayed, and the configuration page includes a biometric feature registration service interface and a biometric feature deletion service interface of the target application program; When the biometric feature registration service interface is selected, a biometric feature registration page of the target application program is displayed; Configuration biometric features of a user requesting registration on the side of the target application program are collected in the biometric feature registration service page, and an identifier of the user requesting registration is obtained; The configuration biometric features of the user requesting registration and the identifier of the user requesting registration are stored in the biometric feature library in association; When the biometric feature deletion service interface is triggered, an identifier of a user requesting deletion on the side of the target application program is obtained; It is queried whether configuration biometric features associated with the identifier of the user requesting deletion are stored in the biometric feature library; If the biometric feature library stores configuration biometric features associated with the identifier of the user requesting deletion, the configuration biometric features associated with the identifier of the user requesting deletion are deleted from the biometric feature library.

11. A data processing method, characterized by, It includes: Display an operation page of a third-party application, the operation page including an authorization operation entry of a target application; When the authorization operation entry of the target application is triggered, a silent authorization operation request is sent to the target application, the authorization operation request being used to request an authorization operation service from the target application, the authorization operation request being used to request the target application to perform a target operation, and the authorization operation request carrying attribute information of the target operation; wherein the authorization operation service includes a biometric identification service and an operation service; the biometric identification service is used to authenticate the identity of a first user on the side of the third-party application, and the operation service is used to execute the target operation in the target application; so that the target application, through the biometric identification service, silently collects the biometric features of the first user on the side of the third-party application in response to the authorization operation request, authenticates the identity of the first user according to the biometric features of the first user, and, after successful identity authentication, executes the target operation according to the attribute information of the target operation carried in the authorization operation request through the operation service, obtains and returns a target operation result; wherein the configuration biometric features used for the authentication are stored in a biometric feature library, and the biometric feature library records the terminal identifier of the terminal to which the target application belongs when the configuration biometric features are registered; the process of deleting the configuration biometric features in the biometric feature library includes: when a biometric feature deletion service interface included in the configuration page of the target application is selected, detecting the security of the current environment in which the user requesting deletion is located according to the environmental identifier corresponding to the configuration biometric features associated with the identifier of the user requesting deletion, and if it is safe, deleting the configuration biometric features associated with the identifier of the user requesting deletion from the biometric feature library; According to the target operation result returned by the target application, jump from the operation interface of the third-party application to the result page of the third-party application, and display the target operation result in the result page; wherein the target operation includes a sharing operation and a payment operation, the sharing operation refers to sharing content in the third-party application in the target application, and the payment operation refers to deducting a payment amount generated in the third-party application from a payment account of a second user currently logged in in the target application, and transferring the payment amount to a payment account.

12. The method of claim 11, wherein, The third-party application integrates a software development kit corresponding to the authorization operation service interface of the target application, and the third-party application runs the software development kit to call the authorization operation service interface to communicate with the target application across processes; The sending of the authorization operation request to the target application includes: Running the software development kit to call the authorization operation service interface to send the authorization operation request.

13. A data processing apparatus, characterized by: includes: The processing unit is configured to, when an authorized operation entry of a target application in a third-party application is selected, receive an authorized operation request sent by the third-party application, the authorized operation request being used to request an authorized operation service from the target application, the authorized operation request being used to request the target application to perform a target operation, and the authorized operation request carrying attribute information of the target operation; The authorized operation service includes a biometric feature identification service and an operation service; The biometric feature identification service is configured to authenticate the identity of a first user on the third-party application side, and the operation service is configured to execute the target operation in the target application; The target application is configured to, in response to the authorized operation request, collect a biometric feature of the first user on the third-party application side in silence through the biometric feature identification service; The target application is configured to authenticate the identity of the first user according to the biometric feature of the first user, and a configuration biometric feature used for the authentication is stored in a biometric feature library, the biometric feature library recording a terminal identifier of a terminal to which the target application belongs when the configuration biometric feature is registered; and a process of deleting the configuration biometric feature in the biometric feature library includes: when a biometric feature deletion service interface included in a configuration page of the target application is selected, detecting the security of a current environment in which a user requesting deletion is located according to an environment identifier corresponding to the configuration biometric feature associated with the identity of the user requesting deletion, and if the security is met, deleting the configuration biometric feature associated with the identity of the user requesting deletion from the biometric feature library; If the authentication of the identity of the first user is successful, the target application is configured to execute the target operation in silence according to the attribute information of the target operation carried in the authorized operation request through the operation service, to obtain a target operation result; wherein the target operation includes a sharing operation and a payment operation, the sharing operation refers to sharing content in the third-party application in the target application, and the payment operation refers to deducting a payment amount generated in the third-party application from a payment account of a second user currently logged in the target application, and transferring the payment amount to a payment account; The communication unit is configured to return the target operation result to the third-party application by the target application.

14. A data processing apparatus, characterized by The display unit is configured to display an operation page of a third-party application, the operation page including an authorized operation entry of a target application. ​ The processing unit is configured to send a silent authorization operation request to the target application when an authorized operation entry of the target application is triggered, the authorization operation request being used to request an authorization operation service from the target application, the authorization operation request being used to request the target application to perform a target operation, and the authorization operation request carrying attribute information of the target operation; wherein the authorization operation service comprises a biometric identification service and an operation service; the biometric identification service is configured to authenticate the identity of a first user on the third-party application side, and the operation service is configured to perform the target operation in the target application; so that the target application collects the biometric feature of the first user on the third-party application side in response to the authorization operation request through the biometric identification service, authenticates the identity of the first user according to the biometric feature of the first user, and performs the target operation according to the attribute information of the target operation carried in the authorization operation request through the operation service after the identity authentication is successful, to obtain and return a target operation result; wherein the configuration biometric feature used for the authentication is stored in a biometric feature library, and the biometric feature library records a terminal identifier of a terminal to which the target application belongs when the configuration biometric feature is registered; the process of deleting the configuration biometric feature in the biometric feature library comprises: when a biometric feature deletion service interface included in a configuration page of the target application is selected, detecting the security of a current environment in which a user requesting deletion is located according to an environmental identifier corresponding to the configuration biometric feature associated with the identifier of the user requesting deletion, and if the security is safe, deleting the configuration biometric feature associated with the identifier of the user requesting deletion from the biometric feature library; According to the target operation result returned by the target application, jump from an operation interface of the third-party application to a result page of the third-party application, and display the target operation result in the result page; wherein the target operation comprises a sharing operation and a payment operation, the sharing operation refers to sharing content in the third-party application in the target application, and the payment operation refers to deducting a payment amount generated in the third-party application from a payment account of a second user currently logged in the target application, and transferring the payment amount to a payment account.

15. A data processing device, characterized by Comprise: A processor adapted to execute a computer program; A computer readable storage medium having a computer program stored therein, the computer program being executed by the processor to implement the data processing method of any one of claims 1-10, or to implement the data processing method of claim 11 or 12.

16. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, the computer program being adapted to be loaded and executed by the processor to implement the data processing method of any one of claims 1-10, or to implement the data processing method of claim 11 or 12.

17. A computer program product, characterised in that, The computer program product comprises computer instructions stored in a computer readable storage medium; a processor of a computer device executes the computer instructions to implement the data processing method according to any one of claims 1-10, or to implement the data processing method according to claim 11 or 12.

Citation Information

Patent Citations

  • Application access method and device

    CN108647510A

  • Third-party account login method, device and system

    CN108650246A

  • Authorization login method, device and system of application

    CN111538965A