Method, device and equipment for displaying mobile terminal operation data
By loading program plug-ins in third-party platform applications and using pre-negotiated keys to obtain tokens for authentication, the problem of privacy leakage of mobile terminal operation data in multi-operator cooperation is solved, and data privacy protection and secure display are achieved.
Patent Information
- Application Number
- CN202111556294.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-17
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2041-12-17
AI Technical Summary
In the existing technology, there is a privacy leakage problem in mobile terminal operation data in multi-operator cooperation, which fails to effectively protect user data privacy.
By loading program plug-ins provided by communication operators and service providers in third-party platform applications, using pre-negotiated keys to obtain tokens and perform authentication, mobile terminal and service data are only displayed in the program plug-ins, avoiding the display of data on the front end of third-party platform applications.
It effectively protects the privacy of mobile terminal operation data, prevents illegal users from obtaining it, improves user experience and ensures data security.
Smart Images

Figure CN114239023B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer technology, and in particular to a method, device, and equipment for displaying mobile terminal operation data, and a method, device, and equipment for displaying service data. Background Art
[0002] In our daily online lives, there are a large number of different applications, and most of these applications belong to different operators. To protect data privacy, the data of different operators is not interoperable. In addition, each operator does not want its data to be obtained by other operators.
[0003] In real life, a single user may use apps from multiple carriers. To increase user convenience, most carriers collaborate with each other, allowing them to display data from other carriers within a single app. For example, when a user uses a payment platform app, they can view their mobile phone bill consumption data. This process may involve the leakage of mobile terminal operational data from telecommunications carriers, which does not comply with data privacy protection requirements.
[0004] Based on this, a method for displaying mobile terminal operation data with privacy protection is needed to avoid leakage of mobile terminal operation data. Summary of the Invention
[0005] One or more embodiments of this specification provide a method, apparatus, and device for displaying mobile terminal operation data, which are used to solve the following technical problems:
[0006] There is a need for a privacy-preserving mobile terminal operation data display method to avoid leakage of mobile terminal operation data.
[0007] One or more embodiments of this specification adopt the following technical solutions:
[0008] One or more embodiments of this specification provide a method for displaying mobile terminal operation data, which is applied to a third-party platform application. The mobile terminal operation data is held by the communication operator used by the user. The method includes:
[0009] In response to a query request for the mobile terminal operation data, obtaining an identifier of the mobile terminal and an identifier of the user;
[0010] Obtaining a token from a program plug-in loaded on the third-party platform application according to a key pre-negotiated with the communication operator, the program plug-in being provided by the communication operator;
[0011] determining, based on the user identifier, whether authorization for the program plug-in has been obtained;
[0012] If so, the identifier of the mobile terminal, the identifier of the user, and the token are sent to the program plug-in so that the program plug-in can authenticate the token. If the authentication is successful, the program plug-in obtains the mobile terminal operation data at the back end of the communication operator and displays it to the user in the program plug-in.
[0013] One or more embodiments of this specification provide a method for displaying service data, which is applied to a third-party platform application. The service data is held by a service provider used by the user. The method includes:
[0014] In response to a query request for the service data, obtaining an identifier of the mobile terminal and an identifier of the user;
[0015] Obtaining a token from a program plug-in loaded on the third-party application according to a key pre-negotiated with the service provider, the program plug-in being provided by the service provider;
[0016] determining, based on the user identifier, whether authorization for the program plug-in has been obtained;
[0017] If so, the identifier of the mobile terminal, the identifier of the user, and the token are sent to the program plug-in so that the program plug-in authenticates the token. If the authentication is successful, the program plug-in obtains the service data on the back end of the service provider and displays it to the user in the program plug-in, so that the front end of the third-party platform application cannot read the displayed service data, and the service data is visible to the user on the front end of the third-party platform application.
[0018] One or more embodiments of this specification provide a device for displaying mobile terminal operation data, which is applied to a third-party platform application. The mobile terminal operation data is held by the communication operator used by the user. The device includes:
[0019] an identification obtaining unit, configured to obtain an identification of the mobile terminal and an identification of the user in response to a query request for the mobile terminal operation data;
[0020] a token acquisition unit, configured to acquire a token from a program plug-in loaded on the third-party platform application according to a key pre-negotiated with the communication operator, the program plug-in being provided by the communication operator;
[0021] an authorization determination unit, configured to determine whether authorization for the program plug-in has been obtained based on the user's identification;
[0022] If so, the data display unit sends the identifier of the mobile terminal, the identifier of the user, and the token to the program plug-in so that the program plug-in authenticates the token. If the authentication is successful, the program plug-in obtains the mobile terminal operation data at the back end of the communication operator and displays it to the user in the program plug-in.
[0023] One or more embodiments of this specification provide a device for displaying service data, which is applied to a third-party platform application. The service data is held by a service provider used by the user. The device includes:
[0024] an identification information acquiring unit, configured to acquire an identification of the mobile terminal and an identification of the user in response to a query request for the service data;
[0025] a plug-in token acquisition unit, which acquires a token from a program plug-in loaded on the third-party application according to a key pre-negotiated with the service provider, the program plug-in being provided by the service provider;
[0026] a plug-in authorization determination unit, configured to determine whether authorization for the program plug-in has been obtained based on the user's identification;
[0027] If so, the service data display unit sends the identifier of the mobile terminal, the identifier of the user, and the token to the program plug-in so that the program plug-in authenticates the token. If the authentication is successful, the program plug-in obtains the service data on the back end of the service provider and displays it to the user within the program plug-in, so that the front end of the third-party platform application cannot read the displayed service data, and so that the service data is visible to the user on the front end of the third-party platform application.
[0028] One or more embodiments of this specification provide a device for displaying mobile terminal operation data, which is applied to a third-party platform application. The mobile terminal operation data is held by the communication operator used by the user, including:
[0029] at least one processor; and,
[0030] a memory communicatively connected to the at least one processor; wherein,
[0031] The memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:
[0032] In response to a query request for the mobile terminal operation data, obtaining an identifier of the mobile terminal and an identifier of the user;
[0033] Obtaining a token from a program plug-in loaded on the third-party platform application according to a key pre-negotiated with the communication operator, the program plug-in being provided by the communication operator;
[0034] determining, based on the user identifier, whether authorization for the program plug-in has been obtained;
[0035] If so, the identifier of the mobile terminal, the identifier of the user, and the token are sent to the program plug-in so that the program plug-in can authenticate the token. If the authentication is successful, the program plug-in obtains the mobile terminal operation data at the back end of the communication operator and displays it to the user in the program plug-in.
[0036] One or more embodiments of this specification provide a device for displaying service data, which is applied to a third-party platform application. The service data is held by a service provider used by the user, including:
[0037] at least one processor; and,
[0038] a memory communicatively connected to the at least one processor; wherein,
[0039] The memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:
[0040] In response to a query request for the service data, obtaining an identifier of the mobile terminal and an identifier of the user;
[0041] Obtaining a token from a program plug-in loaded on the third-party application according to a key pre-negotiated with the service provider, the program plug-in being provided by the service provider;
[0042] determining, based on the user identifier, whether authorization for the program plug-in has been obtained;
[0043] If so, the identifier of the mobile terminal, the identifier of the user, and the token are sent to the program plug-in so that the program plug-in authenticates the token. If the authentication is successful, the program plug-in obtains the service data on the back end of the service provider and displays it to the user in the program plug-in, so that the front end of the third-party platform application cannot read the displayed service data, and the service data is visible to the user on the front end of the third-party platform application.
[0044] One or more embodiments of this specification provide a non-volatile computer storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured to:
[0045] In response to a query request for the mobile terminal operation data, obtaining an identifier of the mobile terminal and an identifier of the user;
[0046] Obtaining a token from a program plug-in loaded on the third-party platform application according to a key pre-negotiated with the communication operator, the program plug-in being provided by the communication operator;
[0047] determining, based on the user identifier, whether authorization for the program plug-in has been obtained;
[0048] If so, the identifier of the mobile terminal, the identifier of the user, and the token are sent to the program plug-in so that the program plug-in can authenticate the token. If the authentication is successful, the program plug-in obtains the mobile terminal operation data at the back end of the communication operator and displays it to the user in the program plug-in.
[0049] One or more embodiments of this specification provide a non-volatile computer storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured to:
[0050] In response to a query request for the service data, obtaining an identifier of the mobile terminal and an identifier of the user;
[0051] Obtaining a token from a program plug-in loaded on the third-party application according to a key pre-negotiated with the service provider, the program plug-in being provided by the service provider;
[0052] determining, based on the user identifier, whether authorization for the program plug-in has been obtained;
[0053] If so, the identifier of the mobile terminal, the identifier of the user, and the token are sent to the program plug-in so that the program plug-in authenticates the token. If the authentication is successful, the program plug-in obtains the service data on the back end of the service provider and displays it to the user in the program plug-in, so that the front end of the third-party platform application cannot read the displayed service data, and the service data is visible to the user on the front end of the third-party platform application.
[0054] At least one of the above technical solutions adopted in the embodiments of this specification can achieve the following beneficial effects:
[0055] The embodiments of this specification load the communication operator's program plug-in into a third-party platform application. During the user's query request for mobile terminal operation data, the mobile terminal operation data is always held by the communication operator and is not exposed to the third-party platform application, thereby protecting the privacy of the mobile terminal operation data to a large extent.
[0056] In addition, the embodiment of this specification obtains a token from the program plug-in based on the key approved by the communication operator. In the subsequent process, the user's identification, the mobile terminal identification and the token are sent to the program plug-in together. If the token is authenticated successfully, it means that the user has the right to obtain the mobile terminal operation data through the user's identification and the mobile terminal identification, and to display the mobile terminal operation data to the user. The above token authentication process can effectively prevent illegal users from impersonating others to obtain other people's mobile terminal operation data, so as to avoid the leakage of mobile terminal operation data. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are only some of the embodiments described in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without inventive work. In the drawings:
[0058] Figure 1 A flowchart of a method for displaying mobile terminal operation data provided in one or more embodiments of this specification;
[0059] Figure 2 A flowchart of a communication operator requiring real-time token authentication for one or more embodiments of this specification;
[0060] Figure 3 A flowchart of a communication operator that does not require token real-time authentication for one or more embodiments of this specification;
[0061] Figure 4 A schematic diagram showing the effect of displaying mobile terminal operation data according to one or more embodiments of this specification;
[0062] Figure 5 A flowchart of a method for displaying service data provided in one or more embodiments of this specification;
[0063] Figure 6 A schematic diagram of the structure of a device for displaying mobile terminal operation data provided in one or more embodiments of this specification;
[0064] Figure 7 A schematic diagram of the structure of a device for displaying service data provided in one or more embodiments of this specification;
[0065] Figure 8 A schematic diagram of the structure of a device for displaying mobile terminal operation data provided in one or more embodiments of this specification;
[0066] Figure 9 This is a structural diagram of a service data display device provided in one or more embodiments of this specification. DETAILED DESCRIPTION
[0067] The embodiments of this specification provide a method, device, and equipment for displaying mobile terminal operation data, and a method, device, and equipment for displaying service data.
[0068] In real life, the same user may use applications from multiple operators. To increase user convenience, most operators have cooperative relationships with each other. This is a common practice in reality. That is, data that does not belong to an application can be displayed in an application (which can be regarded as a third-party platform application, and the following explanation mainly uses third-party platform applications). For example, when a user uses a payment platform application, they can view the user's mobile phone bill consumption data. This process may involve the leakage of mobile terminal operation data, which does not meet the requirements of data privacy protection.
[0069] To help those skilled in the art better understand the technical solutions in this specification, the following will provide a clear and complete description of the technical solutions in the embodiments of this specification, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this specification without creative work should fall within the scope of protection of this specification.
[0070] Figure 1 This is a flow chart illustrating a method for displaying mobile terminal operation data, provided in one or more embodiments of this specification. This process is executed on a third-party platform application. The third-party platform application can be a payment platform application, an instant messaging platform application, or a platform application that integrates information from various applications. Furthermore, the mobile terminal operation data is held by the user's telecommunications operator. This process primarily protects the privacy of mobile terminal operation data. Certain input parameters or intermediate results in the process allow for manual adjustment to help improve accuracy.
[0071] Here, relative to third-party platform applications, the first party refers to users, and the second party refers to communication operators. Mobile terminal operation data may involve the privacy of users or communication operators. The mobile terminal operation data itself is held by the communication operators and does not belong to third-party platform applications.
[0072] S102 : In response to a query request for mobile terminal operation data, obtain an identifier of the mobile terminal and an identifier of the user.
[0073] The query request in the embodiments of this specification is a query request sent by a user to a corresponding mobile operator, and may be for querying the user's mobile phone balance, mobile phone bill consumption data, remaining mobile data usage, etc. The query request may be triggered by the user accessing a designated query page on the front end of a third-party platform application.
[0074] In the embodiment of this specification, after responding to a query request for mobile terminal operation data, the user's identifier can be obtained at the front end of the third-party platform application. The front end of the third-party platform application is the interface visible to the user at the third-party platform application. Then, a request is made from the front end of the third-party platform application to the back end of the third-party platform application, and the back end of the third-party platform application returns the identifier of the mobile terminal bound to the user's identifier. The back end of the third-party platform application is the server side. The identifier of the mobile terminal here can be the user's mobile phone number, and the user's identifier can be the user's name, a user-defined name, or the user's mobile phone number (the user's identifier and the mobile terminal identifier can be shared).
[0075] S104: Obtain a token from a program plug-in loaded on a third-party platform application according to a key pre-negotiated with the communication operator, where the program plug-in is provided by the communication operator.
[0076] The key here is, for example, AppSecret, which needs to be stored on the server side of the third-party platform application. The key can be sent in advance to the communication operator to which the program plug-in belongs. In the subsequent process, the program plug-in of the communication operator can return a token to the requesting third-party platform application based on the key.
[0077] In the embodiment of this specification, the action of obtaining a token may be triggered based on a query request, or may be triggered after determining in a subsequent process that authorization for the program plug-in has been obtained. The step numbers written in the embodiment of this specification do not necessarily indicate the order of execution.
[0078] When the embodiment of this specification performs the action of obtaining a token, it can specifically make a request from the backend of the third-party platform application to the backend of the communication operator based on the key pre-negotiated with the communication operator, obtain the token returned by the backend of the communication operator, and then return the token to the frontend of the third-party platform application as a token corresponding to the query request.
[0079] It should be noted that the aforementioned program plug-in can be a program written in accordance with a certain standard application programming interface. It can only run under the third-party platform application specified by the program and cannot run independently of the designated third-party platform application. This is because the program plug-in needs to call function libraries or data provided by the third-party platform application.
[0080] To subsequently send the mobile terminal ID, user ID, and token to the plug-in and display the mobile terminal data to the user, you need to confirm in advance whether you have obtained authorization for the plug-in. To do this, you need to perform the following steps:
[0081] S106: Determine whether authorization for the program plug-in is obtained based on the user's identification.
[0082] In the embodiments of this specification, a third-party platform application backend can request authorization for a program plug-in from the third-party platform application's authorization center based on the user's ID. The authorization center can then authorize the user's query request. Only after authorization can the mobile terminal's ID, the user's ID, and the token be sent to the program plug-in; otherwise, subsequent steps cannot be performed. The authorization result is then returned to the third-party platform application frontend, allowing the third-party platform application frontend to determine whether authorization for the program plug-in has been obtained.
[0083] S108, if yes, the mobile terminal identifier, the user identifier, and the token are sent to the program plug-in so that the program plug-in can authenticate the token. If the authentication is successful, the program plug-in obtains the mobile terminal operation data from the backend of the communication operator and displays it to the user in the program plug-in.
[0084] If it is determined that authorization for the program plug-in has been obtained, the front end of the third-party platform application can send the mobile terminal identification, the user identification, and the token to the program plug-in, and then the program plug-in authenticates the token. During authentication, the program plug-in can verify the data in the token. After the verification is passed, it means that the authentication is successful, and the mobile terminal operation data that the user wants to query is obtained from the back end of the communication operator through the program plug-in. The back end of the communication operator can be the server of the communication operator. The back end of the communication operator finally sends the mobile terminal operation data to the program plug-in to display it to the user. Successful authentication means that it has the right to obtain the corresponding mobile terminal operation data through the user's identification and the mobile terminal identification. The above token authentication process can effectively prevent illegal users from impersonating others to obtain other people's mobile terminal operation data, so as to avoid leakage of mobile terminal operation data.
[0085] The embodiments of this specification can display mobile terminal operation data to users in a program plug-in at the front end of a third-party platform application, so that the front end of the third-party platform application cannot read the displayed mobile terminal operation data, and the mobile terminal operation data at the front end of the third-party platform application is visible to users.
[0086] It should be noted that after authentication is passed, the backend of the communication operator returns the user's privacy information. The entire process of this information does not pass through the server of the third-party platform application, and is only displayed in the front-end loading mode of the third-party platform application. The process between the program plug-in and the backend of the communication operator belongs to the operator's server, thereby achieving the effect of data shielding, and can help make the program plug-in imperceptible to the user, making the user's operation in the third-party platform application smoother and simpler, and the visual experience is better.
[0087] It's important to note that when a plug-in displays mobile terminal operation data to users, it doesn't redirect to another page, making it invisible to the user, significantly improving the user experience. Furthermore, it prevents telecom operators' mobile terminal operation data from being accessed by third-party platform applications, protecting the privacy of that data.
[0088] It should be noted that different communication operators use different methods when displaying the mobile terminal operation data queried by users. Some communication operators require token-based authentication for each user query, and only after completing the authentication can the relevant mobile terminal operation data be queried; while some communication operators do not require token-based authentication when the user queries, but only require the authorization center to perform corresponding authorization, thereby allowing the user's identification and mobile terminal identification to be sent to the program plug-in, and then query the relevant mobile terminal operation data.
[0089] Based on this, according to the key pre-negotiated with the communication operator, before obtaining the token from the program plug-in loaded on the third-party platform application, it is determined in advance whether the communication operator needs to authenticate the query request based on the token. If it is determined that the communication operator needs to authenticate the query request based on the token, continue to execute S104.
[0090] In the case where the communication operator does not need to perform token-based authentication for query requests, the embodiment of this specification requests authorization from the third-party platform application upon receiving the authorization instruction for the program plug-in issued by the user. In this case, the program plug-in does not need to be authenticated, and the user only needs to reach an authorization agreement with the third-party platform application to execute each query request to the communication operator. However, the services provided by the communication operator are also for users who have reached an authorization agreement with the third-party platform application. It is best for the communication operator to know in advance which users have reached an authorization agreement with the third-party platform application, and to avoid leaking irrelevant information. Irrelevant information may refer to the mobile terminal operation data corresponding to users who have not reached an authorization agreement with the third-party platform application.
[0091] To solve the above problem, the embodiment of this specification can determine whether the request for authorization is the first execution based on the user's identification. If so, the authorization information generated by the third-party platform application is obtained; the authorization information is sent to the program plug-in, so that the program plug-in obtains the user's identification and the mobile terminal's identification from the third-party platform application based on the authorization information. The authorization information may include an authorization code, which can be an authorization verification code that is only used for the first authorization and has a certain time limit. After obtaining the authorization code, the program plug-in needs to send it to the third-party platform application within the specified time limit to obtain the user's identification and the mobile terminal's identification. After the above operation, the program plug-in saves the record of the first request for authorization. If the user requests authorization again, the user's identification and the mobile terminal's identification can be directly sent to the program plug-in. If it is determined that the request for authorization is not the first execution based on the user's identification, the user's identification and the mobile terminal's identification can be directly sent to the program plug-in.
[0092] In the embodiment of this specification, when the communication operator does not need to perform token-based authentication for the query request, specifically, when the front end of the third-party platform application receives the authorization instruction for the program plug-in issued by the user, it requests authorization from the authorization center of the third-party platform application. After the authorization is successfully authorized by the authorization center, it is determined whether the request for authorization is the first execution based on the user's identity. If so, an authorization code is sent to the front end of the third-party platform application; the front end of the third-party platform application sends the authorization code to the program plug-in; the program plug-in sends the authorization code to the gateway of the third-party platform application, so that the gateway of the third-party platform application generates an authorization token based on the authorization code. The authorization token can be stored for a long time to indicate that the user has performed the first authorization, and the authorization token can be used for later verification. Afterwards, the gateway of the third-party platform application sends the authorization token to the program plug-in; the program plug-in sends the authorization token to the gateway of the third-party platform application, so that the gateway of the third-party platform application obtains the user's identity and the mobile terminal's identity based on the authorization token, and sends the user's identity and the mobile terminal's identity to the program plug-in.
[0093] When the third-party platform application's gateway obtains the user's and mobile terminal's IDs, it can parse the authorization token to obtain the user's ID. The gateway can then retrieve the mobile terminal's ID, which is bound to the user's ID, from the third-party platform application's backend. The authorization token is obtained based on the authorization code, which contains the user's ID.
[0094] The embodiments of this specification are intended to solve the problem of preventing the leakage of mobile terminal operation data of mobile operators. In addition to the above solutions, mini-programs can also be used. It should be noted that mini-programs are different from the program plug-ins mentioned above. Mini-programs can be templates pre-configured by communication operators based on third-party platform applications and generated according to their respective needs. The mini-programs produced can be connected to the mobile terminal applications of communication operators, and will not cause leakage when displaying mobile terminal operation data. However, the mini-program is mounted on a third-party platform application, and the user needs to jump to a page each time he uses it. The page after the jump is set by the communication operator.
[0095] This shows a significant difference between mini-programs and plug-ins. A plug-in interface doesn't require a redirect, but rather sits at the front end of the third-party platform application. Compared to mini-programs, plug-ins can significantly reduce the response time for displaying operational data on mobile terminals.
[0096] The embodiments of this specification also provide a method for displaying mobile terminal operation data. After the user enters the recharge center of the payment platform application for mobile phone bill recharge, he or she must first click to agree to the payment platform application to load the program plug-in authorization on behalf of the communication operator. After successful authorization, the payment platform application loads the corresponding configuration according to the different security level requirements of different communication operators. The following is an introduction to two types of communication operators:
[0097] One is the communication operator that requires real-time token authentication, see Figure 2The specific flow chart shown is as follows: 1: The user enters the recharge center front end, at which time the user's ID (uid) can be obtained; 1.1: The recharge center back end obtains the bound mobile phone number from the recharge center front end; 1.2: The recharge center front end checks the authorization of the recharge center back end and obtains a token; 1.2.1: The recharge center back end obtains authorization from the authorization center; 1.2.2: The authorization center returns the authorization result to the recharge center back end (the authorization result is authorized or not authorized); 1.2.3: The recharge center back end exchanges the token from the program plug-in back end according to the AppSecret; 1.2.4: The program plug-in back end returns the token to the recharge center back end; 1.3: Recharge in progress The backend of the recharge center returns the token and authorization result to the frontend of the recharge center; 1.4: Determine the authorization logic. If authorized, execute 1.4.1; if not authorized, execute 1.4.2; 1.4.1: Authorized, the recharge center frontend passes the uid, mobile phone number and token to the program plug-in; 1.4.1.1: The program plug-in authenticates the program plug-in backend and pulls the display data; 1.4.1.2: The program plug-in backend returns the result to the program plug-in; 1.4.1.3: Filter the display data on the frontend of the recharge center, where the data is displayed in the program plug-in; 1.4.1.4: Display the balance data to the user; 1.4.2: Unauthorized, ask the user for authorization and return the token.
[0098] In the above process, after authentication is passed, the program plug-in returns the user's private information. This information does not pass through the payment platform application server throughout the entire process and is only displayed in the recharge center front-end loading mode. The process between the program plug-in and the program plug-in back-end belongs to the communication operator's server, thereby achieving the effect of data shielding.
[0099] The other type is a communication operator that does not require real-time token authentication and only requires the user to authorize the payment platform application. Figure 3 The specific flow chart shown is as follows: 2: The user clicks authorization at the front end of the recharge center; 2.1: The front end of the recharge center requests authorization from the authorization center; 2.2: The authorization is successful, and the authorization center returns auth_code (authorization code) to the front end of the recharge center; 2.3: For the first authorization, the auth_code is passed to the program plug-in at the front end of the recharge center; 2.3.1: Determine whether it is the first authorization; 2.3.2: For the first authorization, the program plug-in sends the auth_code to the gateway of the payment platform application and exchanges it for auth_token (authorization token) at the gateway; 2.3.3: The gateway returns auth_token to the program plug-in; 2.3.4: The program plug-in sends auth_token to the gateway, and exchanges it for user information (uid and mobile phone number) based on the auth_token; 2.3.5: The gateway returns uid and mobile phone number to the program plug-in; 2.3.6: Display the user balance according to the user information; 2.3.7: Display the balance data to the user.
[0100] It should be noted that the program plug-in can be a balance inquiry program plug-in. The permission management of the recharge center front-end, recharge center back-end, authorization center and payment platform application gateway belongs to the payment platform application, and the rights management of the program plug-in and the program plug-in back-end belongs to the communication operator.
[0101] The effect diagram of the mobile terminal operation data display provided by one or more embodiments of this specification is shown in Figure 4 The recharge center in the figure can show that the current user's mobile terminal number is 11111111111 (this number is a schematic number), the call balance is 137.32 yuan, the remaining traffic is 38.89GB, and the remaining voice is 495 minutes. The figure also shows various call recharge options.
[0102] The above solution is about the display method of mobile terminal operation data of communication operators. The embodiments of this specification are not limited to this and can also be applied in a wider range of scenarios.
[0103] Based on this, a flowchart of a method for displaying service data provided by one or more embodiments of this specification is shown in FIG. Figure 5 This method can be applied to third-party platform applications. The service data is held by the service provider used by the user (for example, e-commerce platform service providers, online game platform service providers, etc.). The specific steps include:
[0104] S502: In response to a query request for service data, obtain an identifier of the mobile terminal and an identifier of the user.
[0105] S504: Obtain a token from a program plug-in loaded on a third-party application according to a key pre-negotiated with the service provider, where the program plug-in is provided by the service provider.
[0106] S506: Determine whether authorization for the program plug-in is obtained based on the user's identification.
[0107] S508, if yes, the mobile terminal identifier, the user identifier, and the token are sent to the program plug-in so that the program plug-in authenticates the token. If the authentication is successful, the program plug-in obtains the service data from the service provider's backend and displays it to the user in the program plug-in, so that the front end of the third-party platform application cannot read the displayed service data, and the service data on the front end of the third-party platform application is visible to the user.
[0108] A schematic diagram of a mobile terminal operation data display device provided in one or more embodiments of this specification is provided. Figure 6The device is applied to third-party platform applications, and the mobile terminal operation data is held by the communication operator used by the user. It specifically includes: an identification acquisition unit 602, a token acquisition unit 604, an authorization judgment unit 606 and a data display unit 608.
[0109] The identification acquisition unit 602 acquires the identification of the mobile terminal and the identification of the user in response to a query request for the mobile terminal operation data.
[0110] The token acquisition unit 604 acquires a token from a program plug-in loaded on a third-party platform application according to a key pre-negotiated with the communication operator, where the program plug-in is provided by the communication operator.
[0111] The authorization determination unit 606 determines whether authorization for the program plug-in is obtained according to the user's identification.
[0112] If so, the data display unit 608 sends the mobile terminal identification, user identification, and token to the program plug-in so that the program plug-in can authenticate the token. If the authentication is successful, the program plug-in obtains the mobile terminal operation data from the back end of the communication operator and displays it to the user in the program plug-in.
[0113] Furthermore, the query request is triggered by the user entering a designated query page on the front end of the third-party platform application.
[0114] When the identification acquisition unit 602 acquires the identification of the mobile terminal and the identification of the user, it specifically includes:
[0115] Obtain the user's ID on the front end of the third-party platform application;
[0116] A request is made from the front end of the third-party platform application to the back end of the third-party platform application, and the back end of the third-party platform application returns an identifier of the mobile terminal bound to the identifier of the user.
[0117] Furthermore, when the token acquisition unit 604 acquires a token from a program plug-in loaded on a third-party platform application according to a key pre-negotiated with a communication operator, the following steps are specifically performed:
[0118] Based on the key pre-negotiated with the communication operator, the backend of the third-party platform application makes a request to the backend of the communication operator and obtains the token returned by the backend of the communication operator;
[0119] The token is returned to the front-end of the third-party platform application as a token corresponding to the query request.
[0120] Furthermore, when the authorization determination unit 606 determines whether authorization for the program plug-in is obtained based on the user's identification, the following steps are specifically performed:
[0121] Based on the user's ID, the backend of the third-party platform application requests authorization for the program plug-in from the authorization center of the third-party platform application;
[0122] The authorization result is returned to the front end of the third-party platform application, so that the front end of the third-party platform application determines whether authorization for the program plug-in is obtained.
[0123] Furthermore, before the token acquisition unit 604 acquires the token from the program plug-in loaded on the third-party platform application according to the key pre-negotiated with the communication operator, the apparatus further includes: an authentication determination unit 610 .
[0124] The authentication determination unit 610 determines that the communication operator needs to perform authentication based on a token for the query request.
[0125] Furthermore, when the communication operator does not need to perform token-based authentication for the query request, the apparatus further includes: an authorization request unit 612 , a first authorization determination unit 614 , an authorization information acquisition unit 616 and an information acquisition unit 618 .
[0126] When the authorization request unit 612 receives the authorization instruction for the program plug-in from the user, it requests authorization from the third-party platform application;
[0127] The first authorization determination unit 614 determines whether the authorization request is executed for the first time based on the user's identification;
[0128] If so, the authorization information acquisition unit 616 acquires the authorization information generated by the third-party platform application;
[0129] The information acquisition unit 618 sends the authorization information to the program plug-in, so that the program plug-in acquires the user's identifier and the mobile terminal's identifier from the third-party platform application according to the authorization information.
[0130] Furthermore, the authorization information includes an authorization code. In the case where the communication operator does not need to authenticate the query request based on a token, it specifically includes:
[0131] When the authorization request unit 612 receives the authorization instruction for the program plug-in from the user at the front end of the third-party platform application, it requests authorization from the authorization center of the third-party platform application;
[0132] After the authorization is successfully obtained by the authorization center, the first authorization determination unit 614 determines whether the authorization request is for the first time based on the user's identification. If so, the authorization information acquisition unit 616 sends an authorization code to the front end of the third-party platform application;
[0133] The information acquisition unit 618 sends the authorization code to the program plug-in at the front end of the third-party platform application, and the program plug-in sends the authorization code to the gateway of the third-party platform application, so that the gateway of the third-party platform application generates an authorization token based on the authorization code, and sends the authorization token to the program plug-in, and the program plug-in sends the authorization token to the gateway of the third-party platform application, so that the gateway of the third-party platform application obtains the user's identification and the mobile terminal identification according to the authorization token, and sends the user's identification and the mobile terminal identification to the program plug-in.
[0134] Furthermore, when the data display unit 608 displays the data to the user in the program plug-in, it specifically includes:
[0135] At the front end of the third-party platform application, the mobile terminal operation data is displayed to the user in the program plug-in, so that the front end of the third-party platform application cannot read the displayed mobile terminal operation data, and the mobile terminal operation data is visible to the user at the front end of the third-party platform application.
[0136] Furthermore, the mobile terminal operation data includes the mobile phone call balance.
[0137] A schematic diagram of a service data display device provided in one or more embodiments of this specification is shown in FIG. Figure 7 , applied to third-party platform applications, the service data is held by the service provider used by the user, specifically including: identification information acquisition unit 702, plug-in token acquisition unit 704, plug-in authorization judgment unit 706 and service data display unit 708.
[0138] The identification information acquisition unit 702 acquires the identification of the mobile terminal and the identification of the user in response to a query request for service data;
[0139] The plug-in token acquisition unit 704 acquires a token from a program plug-in loaded on a third-party application according to a key pre-negotiated with the service provider. The program plug-in is provided by the service provider.
[0140] The plug-in authorization determination unit 706 determines whether authorization for the program plug-in is obtained based on the user's identification;
[0141] If so, the service data display unit 708 sends the mobile terminal identifier, the user identifier, and the token to the program plug-in so that the program plug-in authenticates the token. If the authentication is successful, the program plug-in obtains the service data from the service provider's backend and displays it to the user within the program plug-in, so that the front end of the third-party platform application cannot read the displayed service data, and so that the service data on the front end of the third-party platform application is visible to the user.
[0142] A schematic diagram of a mobile terminal operation data display device provided in one or more embodiments of this specification is provided. Figure 8 , applied to third-party platform applications, mobile terminal operation data is held by the communication operator used by the user, including:
[0143] at least one processor; and,
[0144] a memory communicatively connected to at least one processor; wherein,
[0145] The memory stores instructions executable by at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:
[0146] In response to a query request for mobile terminal operation data, obtaining an identifier of the mobile terminal and an identifier of the user;
[0147] Obtain a token from a program plug-in loaded on a third-party platform application based on a key pre-negotiated with the communication operator. The program plug-in is provided by the communication operator.
[0148] Determine whether authorization for the program plug-in is obtained based on the user's identification;
[0149] If so, the mobile terminal identification, user identification, and token are sent to the program plug-in so that the program plug-in can authenticate the token. If the authentication is successful, the program plug-in obtains the mobile terminal operation data from the back end of the communication operator and displays it to the user in the program plug-in.
[0150] A schematic diagram of a service data display device provided in one or more embodiments of this specification is shown in FIG. Figure 9 , applied to third-party platform applications, service data is held by the service provider used by the user, including:
[0151] at least one processor; and,
[0152] a memory communicatively connected to at least one processor; wherein,
[0153] The memory stores instructions executable by at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:
[0154] In response to a query request for service data, obtaining an identifier of the mobile terminal and an identifier of the user;
[0155] Obtain a token from a program plug-in loaded on a third-party application based on a key pre-negotiated with the service provider. The program plug-in is provided by the service provider.
[0156] Determine whether authorization for the program plug-in is obtained based on the user's identification;
[0157] If so, the mobile terminal's identifier, the user's identifier, and the token are sent to the program plug-in so that the program plug-in can authenticate the token. If the authentication is successful, the program plug-in obtains the service data from the service provider's backend and displays it to the user within the program plug-in, so that the front end of the third-party platform application cannot read the displayed service data, and the service data on the front end of the third-party platform application is visible to the user.
[0158] One or more embodiments of this specification further provide a non-volatile computer storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured to:
[0159] In response to a query request for mobile terminal operation data, obtaining an identifier of the mobile terminal and an identifier of the user;
[0160] Obtain a token from a program plug-in loaded on a third-party platform application based on a key pre-negotiated with the communication operator. The program plug-in is provided by the communication operator.
[0161] Determine whether authorization for the program plug-in is obtained based on the user's identification;
[0162] If so, the mobile terminal identification, user identification, and token are sent to the program plug-in so that the program plug-in can authenticate the token. If the authentication is successful, the program plug-in obtains the mobile terminal operation data from the back end of the communication operator and displays it to the user in the program plug-in.
[0163] One or more embodiments of this specification further provide a non-volatile computer storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured to:
[0164] In response to a query request for service data, obtaining an identifier of the mobile terminal and an identifier of the user;
[0165] Obtain a token from a plug-in loaded on a third-party application using a key pre-negotiated with the service provider. The plug-in is provided by the service provider.
[0166] Determine whether authorization for the program plug-in is obtained based on the user's identification;
[0167] If so, the mobile terminal's identifier, the user's identifier, and the token are sent to the program plug-in so that the program plug-in can authenticate the token. If the authentication is successful, the program plug-in obtains the service data from the service provider's backend and displays it to the user within the program plug-in, so that the front end of the third-party platform application cannot read the displayed service data, and the service data on the front end of the third-party platform application is visible to the user.
[0168] In the 1990s, technological improvements could be clearly distinguished as either hardware improvements (for example, improvements to circuit structures like diodes, transistors, and switches) or software improvements (improvements to process flows). However, with the advancement of technology, many process flow improvements today can now be considered direct improvements to hardware circuit structures. Designers almost always create the corresponding hardware circuit structure by programming the improved process flow into the hardware circuit. Therefore, it cannot be said that a process flow improvement cannot be implemented using hardware modules. For example, a programmable logic device (PLD), such as a field programmable gate array (FPGA), is an integrated circuit whose logical function is determined by user programming. Designers can "integrate" a digital system on a PLD through their own programming, without having to hire a chip manufacturer to design and manufacture a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly done using "logic compiler" software. This is similar to the software compiler used when developing programs. Before compilation, the original code must also be written in a specific programming language, called a hardware description language (HDL). There is not just one HDL, but many, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art will also understand that by simply programming the method flow in one of these hardware description languages and then programming it into an integrated circuit, a hardware circuit that implements the logic method flow can be easily obtained.
[0169] The controller can be implemented in any suitable manner. For example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that in addition to implementing the controller in a purely computer-readable program code format, the controller can be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be considered as structures within the hardware component. Or even, the devices for implementing various functions can be considered as both software modules that implement the method and structures within the hardware component.
[0170] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0171] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0172] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, the embodiments of this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0173] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0174] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0175] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0176] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0177] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0178] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0179] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0180] This specification may be described in the general context of computer-executable instructions, such as program modules, executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in both local and remote computer storage media, including storage devices.
[0181] The various embodiments in this specification are described in a progressive manner. Similar portions between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from the other embodiments. In particular, the device, apparatus, and non-volatile computer storage medium embodiments are generally similar to the method embodiments, so their descriptions are relatively simplified. For relevant details, refer to the descriptions of the method embodiments.
[0182] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0183] The foregoing description is merely one or more embodiments of this specification and is not intended to limit this specification. It will be apparent to those skilled in the art that various modifications and variations may be made to one or more embodiments of this specification. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of one or more embodiments of this specification are intended to be within the scope of the claims of this specification.
Claims
1. A method for displaying mobile terminal operation data, applied to a third-party platform application, wherein the mobile terminal operation data is held by the communication operator used by the user, the method comprising: In response to a query request for the mobile terminal operation data, obtaining an identifier of the mobile terminal and an identifier of the user; Obtaining a token from a program plug-in loaded on the third-party platform application according to a key pre-negotiated with the communication operator, the program plug-in being provided by the communication operator; determining, based on the user identifier, whether authorization for the program plug-in has been obtained; If so, the identifier of the mobile terminal, the identifier of the user, and the token are sent to the program plug-in so that the program plug-in can authenticate the token. If the authentication is successful, the program plug-in obtains the mobile terminal operation data at the back end of the communication operator and displays it to the user in the program plug-in.
2. The method according to claim 1, wherein the query request is triggered by the user entering a designated query page on the front end of the third-party platform application; The obtaining of the identifier of the mobile terminal and the identifier of the user specifically includes: Obtaining the user's identifier on the front end of the third-party platform application; A request is made from the front end of the third-party platform application to the back end of the third-party platform application, and the back end of the third-party platform application returns an identifier of the mobile terminal bound to the identifier of the user.
3. The method according to claim 1, wherein obtaining a token from a program plug-in loaded on the third-party platform application based on a key pre-negotiated with the communication operator specifically comprises: Making a request from the backend of the third-party platform application to the backend of the communication operator according to a key pre-negotiated with the communication operator, and obtaining a token returned by the backend of the communication operator; The token is returned to the front end of the third-party platform application as a token corresponding to the query request.
4. The method according to claim 1, wherein determining whether authorization for the program plug-in is obtained based on the user identification specifically comprises: Requesting authorization for the program plug-in from the backend of the third-party platform application to the authorization center of the third-party platform application according to the user identification; The authorization result is returned to the front end of the third-party platform application, so that the front end of the third-party platform application determines whether authorization for the program plug-in is obtained.
5. The method according to claim 1, before obtaining a token from a program plug-in loaded on the third-party platform application based on a key pre-negotiated with the communication operator, the method further comprises: It is determined that the communication operator needs to perform token-based authentication for the query request.
6. The method according to claim 1, wherein when the communication operator does not need to perform token-based authentication for the query request, the method further comprises: Upon receiving an authorization instruction for the program plug-in issued by the user, requesting authorization from the third-party platform application; Determining whether the authorization request is being executed for the first time based on the user identifier; If so, obtain authorization information generated by the third-party platform application; The authorization information is sent to the program plug-in, so that the program plug-in obtains the user identifier and the mobile terminal identifier from the third-party platform application according to the authorization information.
7. The method according to claim 6, wherein the authorization information comprises an authorization code; When the communication operator does not need to perform token-based authentication on the query request, the method specifically includes: When the front end of the third-party platform application receives the authorization instruction for the program plug-in issued by the user, requesting authorization from the authorization center of the third-party platform application; After the authorization center successfully authorizes, it determines whether the authorization request is executed for the first time based on the user's identifier. If so, it sends the authorization code to the front end of the third-party platform application; Sending the authorization code to the program plug-in at the front end of the third-party platform application; The program plug-in sends the authorization code to the gateway of the third-party platform application, so that the gateway of the third-party platform application generates an authorization token according to the authorization code, and sends the authorization token to the program plug-in; The program plug-in sends the authorization token to the gateway of the third-party platform application, so that the gateway of the third-party platform application obtains the user's identification and the mobile terminal's identification according to the authorization token, and sends the user's identification and the mobile terminal's identification to the program plug-in.
8. The method according to claim 1, wherein presenting to the user in the program plug-in specifically comprises: At the front end of the third-party platform application, the mobile terminal operation data is displayed to the user in the program plug-in, so that the front end of the third-party platform application cannot read the displayed mobile terminal operation data, and the mobile terminal operation data is visible to the user at the front end of the third-party platform application.
9. The method according to any one of claims 1 to 8, wherein the mobile terminal operation data includes a mobile phone charge balance.
10. A method for displaying service data, applied to a third-party platform application, wherein the service data is held by a service provider used by the user, the method comprising: In response to a query request for the service data, obtaining an identifier of the mobile terminal and an identifier of the user; Obtaining a token from a program plug-in loaded on the third-party application according to a key pre-negotiated with the service provider, the program plug-in being provided by the service provider; determining, based on the user identifier, whether authorization for the program plug-in has been obtained; If so, the identifier of the mobile terminal, the identifier of the user, and the token are sent to the program plug-in so that the program plug-in authenticates the token. If the authentication is successful, the program plug-in obtains the service data on the back end of the service provider and displays it to the user in the program plug-in, so that the front end of the third-party platform application cannot read the displayed service data, and the service data is visible to the user on the front end of the third-party platform application.
11. A device for displaying mobile terminal operation data, applied to a third-party platform application, wherein the mobile terminal operation data is held by the communication operator used by the user, the device comprising: an identification obtaining unit, configured to obtain an identification of the mobile terminal and an identification of the user in response to a query request for the mobile terminal operation data; a token acquisition unit, configured to acquire a token from a program plug-in loaded on the third-party platform application according to a key pre-negotiated with the communication operator, the program plug-in being provided by the communication operator; an authorization determination unit, configured to determine whether authorization for the program plug-in is obtained based on the user's identification; If so, the data display unit sends the identifier of the mobile terminal, the identifier of the user, and the token to the program plug-in so that the program plug-in authenticates the token. If the authentication is successful, the program plug-in obtains the mobile terminal operation data at the back end of the communication operator and displays it to the user in the program plug-in.
12. The apparatus according to claim 11, wherein the query request is triggered by the user entering a designated query page on the front end of the third-party platform application; When the identification acquisition unit executes the acquisition of the identification of the mobile terminal and the identification of the user, the method specifically includes: Obtaining the user's identifier on the front end of the third-party platform application; A request is made from the front end of the third-party platform application to the back end of the third-party platform application, and the back end of the third-party platform application returns an identifier of the mobile terminal bound to the identifier of the user.
13. The apparatus according to claim 11, wherein the token acquisition unit executes the step of acquiring a token from a program plug-in loaded on the third-party platform application based on a key pre-negotiated with the communication operator, specifically comprising: Making a request from the backend of the third-party platform application to the backend of the communication operator according to a key pre-negotiated with the communication operator, and obtaining a token returned by the backend of the communication operator; The token is returned to the front end of the third-party platform application as a token corresponding to the query request.
14. The apparatus according to claim 11, wherein the authorization determination unit determines whether authorization for the program plug-in is obtained based on the user identification, specifically comprising: Requesting authorization for the program plug-in from the backend of the third-party platform application to the authorization center of the third-party platform application according to the user identification; The authorization result is returned to the front end of the third-party platform application, so that the front end of the third-party platform application determines whether authorization for the program plug-in is obtained.
15. The apparatus according to claim 11, before the token acquisition unit executes the step of acquiring a token from a program plug-in loaded on the third-party platform application based on a key pre-negotiated with the communication operator, the apparatus further comprises: The authentication determination unit determines that the communication operator needs to perform authentication based on a token for the query request.
16. The apparatus according to claim 11, wherein when the communication operator does not need to perform token-based authentication for the query request, the apparatus further comprises: an authorization request unit, which, upon receiving an authorization instruction for the program plug-in issued by the user, requests authorization from the third-party platform application; a first authorization determination unit, configured to determine, based on the user identifier, whether the authorization request is being executed for the first time; If yes, the authorization information obtaining unit obtains the authorization information generated by the third-party platform application; The information acquisition unit sends the authorization information to the program plug-in, so that the program plug-in acquires the user identifier and the mobile terminal identifier from the third-party platform application according to the authorization information.
17. The apparatus according to claim 16, wherein the authorization information comprises an authorization code; When the communication operator does not need to perform token-based authentication on the query request, the method specifically includes: The authorization request unit, when receiving the authorization instruction for the program plug-in issued by the user at the front end of the third-party platform application, requests authorization from the authorization center of the third-party platform application; The first authorization judgment unit, after the authorization center successfully authorizes, determines whether the requested authorization is executed for the first time based on the user's identifier. If so, the authorization information acquisition unit sends the authorization code to the front end of the third-party platform application; The information acquisition unit sends the authorization code to the program plug-in at the front end of the third-party platform application, and the program plug-in sends the authorization code to the gateway of the third-party platform application, so that the gateway of the third-party platform application generates an authorization token according to the authorization code, and sends the authorization token to the program plug-in, and the program plug-in sends the authorization token to the gateway of the third-party platform application, so that the gateway of the third-party platform application obtains the user identification and the mobile terminal identification according to the authorization token, and sends the user identification and the mobile terminal identification to the program plug-in.
18. The device according to claim 11, wherein the data display unit performs the display to the user in the program plug-in, specifically comprising: At the front end of the third-party platform application, the mobile terminal operation data is displayed to the user in the program plug-in, so that the front end of the third-party platform application cannot read the displayed mobile terminal operation data, and the mobile terminal operation data is visible to the user at the front end of the third-party platform application.
19. The device according to any one of claims 11 to 18, wherein the mobile terminal operation data comprises a mobile phone charge balance.
20. A device for displaying service data, applied to a third-party platform application, wherein the service data is held by a service provider used by the user, the device comprising: an identification information acquiring unit, configured to acquire an identification of the mobile terminal and an identification of the user in response to a query request for the service data; a plug-in token acquisition unit, which acquires a token from a program plug-in loaded on the third-party application according to a key pre-negotiated with the service provider, the program plug-in being provided by the service provider; a plug-in authorization determination unit, configured to determine whether authorization for the program plug-in has been obtained based on the user's identification; If so, the service data display unit sends the identifier of the mobile terminal, the identifier of the user, and the token to the program plug-in so that the program plug-in authenticates the token. If the authentication is successful, the program plug-in obtains the service data on the back end of the service provider and displays it to the user within the program plug-in, so that the front end of the third-party platform application cannot read the displayed service data, and so that the service data is visible to the user on the front end of the third-party platform application.
21. A device for displaying mobile terminal operation data, used in third-party platform applications, wherein the mobile terminal operation data is held by the communication operator used by the user, comprising: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to: In response to a query request for the mobile terminal operation data, obtaining an identifier of the mobile terminal and an identifier of the user; Obtaining a token from a program plug-in loaded on the third-party platform application according to a key pre-negotiated with the communication operator, the program plug-in being provided by the communication operator; determining, based on the user identifier, whether authorization for the program plug-in has been obtained; If so, the identifier of the mobile terminal, the identifier of the user, and the token are sent to the program plug-in so that the program plug-in can authenticate the token. If the authentication is successful, the program plug-in obtains the mobile terminal operation data at the back end of the communication operator and displays it to the user in the program plug-in.
Citation Information
Patent Citations
User privacy protection method, equipment and system for location business
CN102457805A
Providing method and system of mobile phone client-side location services
CN102984646A