Identity profile processing method and apparatus

By creating identity profiles and granting subordinate permissions to users who are unable to register with their real names on their own, the service management challenges faced by elderly and minor users on smart terminals have been solved, achieving efficient service processing and information security management.

CN114491496BActive Publication Date: 2026-03-27ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-27
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

How to provide effective online services for users who cannot register with their real names on their own (such as the elderly and minors), especially to realize service management after real-name registration on smart terminals, and solve the obstacles to user information management.

Method used

By obtaining the profile creation request of the primary associated user, the user's identity profile is created and primary permissions are granted. The subordinate permissions of the subordinate associated users are determined, and the subordinate users are allowed to access the identity profile for service processing, thereby realizing service management for specific users.

Benefits of technology

It improves service processing efficiency for users who cannot manage their accounts independently, reduces barriers to information management, and ensures the privacy and security of user information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114491496B_ABST
    Figure CN114491496B_ABST
Patent Text Reader

Abstract

The embodiments of the present specification provide an identity archive processing method and device, wherein an identity archive processing method comprises: obtaining an archive creation request submitted by a main associated user for a specific user, creating an identity archive of the specific user based on identity information carried in the archive creation request; creating a user account for storing the identity archive, and opening a main authority of the user account to the main associated user; determining at least one subordinate associated user in a group of associated users for account co-management of the user account; opening a subordinate authority of the user account to the at least one subordinate associated user, and the main authority and the subordinate authority are used to access the identity archive when service proxy processing is performed for the specific user.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present document relates to the technical field of data processing, and particularly relates to an identity archive processing method and device. BACKGROUND

[0002] With the continuous development of the Internet and information technology, the quantity and update speed of various information are rapidly increasing. Interactive applications on the Internet are increasing. With the development of smart terminals, more and more services are based on smart terminals to be implemented through the Internet. In order to ensure the effectiveness of the information of users and the management of the Internet, real-name information registration is performed on users accessing the Internet, and services are provided to the users after the real-name registration. For some users who have obstacles in using smart terminals (such as the elderly) or cannot perform effective real-name registration (such as minors), how to provide effective online services is a focus of users. SUMMARY

[0003] One or more embodiments of the present specification provide an identity archive processing method. The identity archive processing method comprises: obtaining an archive creation request submitted by a master associated user for a specific user, and creating an identity archive of the specific user based on identity information carried in the archive creation request. A user account storing the identity archive is created, and the master authority of the user account is opened to the master associated user. At least one subordinate associated user in an associated user group is determined to perform account co-management on the user account. The subordinate authority of the user account is opened to the at least one subordinate associated user, and the master authority and the subordinate authority are used to access the identity archive when service processing is performed for the specific user.

[0004] One or more embodiments of the present specification provide a service processing method, comprising: obtaining a service processing request of an associated user sent by a service platform. The user account of a specific user opening an account authority of the associated user is queried in an associated user group to which the associated user belongs. According to the account authority, key identity information matching a service category carried in the service processing request is extracted in the user account. The key identity information is returned to the service platform, so that service processing of the specific user is performed according to the key identity information.

[0005] One or more embodiments of the present specification provide an identity archive processing apparatus, comprising: an archive creation module configured to obtain an archive creation request for a specific user submitted by a master associated user, and create an identity archive of the specific user based on identity information carried in the archive creation request; a master authority opening module configured to create a user account storing the identity archive, and open a master authority of the user account to the master associated user; a user determination module configured to determine at least one subordinate associated user in an associated user group that co-manages the user account; a subordinate authority opening module configured to open a subordinate authority of the user account to the at least one subordinate associated user, the master authority and the subordinate authority being used to access the identity archive when service proxy processing is performed for the specific user.

[0006] One or more embodiments of the present specification provide a service processing apparatus, comprising: a request obtaining module configured to obtain a service proxy request of an associated user sent by a service platform; an account querying module configured to query a user account of a specific user opening an account authority of the associated user in an associated user group to which the associated user belongs; an information extracting module configured to extract key identity information matching a service category carried in the service proxy request from the user account according to the account authority; and an information returning module configured to return the key identity information to the service platform, so as to perform service processing of the specific user according to the key identity information.

[0007] One or more embodiments of the present specification provide an identity archive processing device, comprising: a processor; and a memory configured to store computer executable instructions, the computer executable instructions, when executed, causing the processor to: obtain an archive creation request for a specific user submitted by a master associated user, and create an identity archive of the specific user based on identity information carried in the archive creation request; create a user account storing the identity archive, and open a master authority of the user account to the master associated user; determine at least one subordinate associated user in an associated user group that co-manages the user account; and open a subordinate authority of the user account to the at least one subordinate associated user, the master authority and the subordinate authority being used to access the identity archive when service proxy processing is performed for the specific user.

[0008] One or more embodiments of the present specification provide a service processing device, comprising: a processor; and a memory configured to store computer executable instructions that, when executed, cause the processor to: acquire a service processing request of an associated user sent by a service platform. Query a user account of a specific user who opens an account permission of the associated user in an associated user group to which the associated user belongs. According to the account permission, extract key identity information matching a service category carried in the service processing request in the user account. Return the key identity information to the service platform to perform service processing of the specific user according to the key identity information.

[0009] One or more embodiments of the present specification provide a storage medium for storing computer executable instructions, which, when executed by a processor, implement the following processes: acquiring an archive creation request for a specific user submitted by a master associated user, and creating an identity archive of the specific user based on identity information carried in the archive creation request. Create a user account for storing the identity archive, and open a master permission of the user account to the master associated user. Determine at least one subordinate associated user in an associated user group that co-manages the user account. Open a subordinate permission of the user account to the at least one subordinate associated user, and the master permission and the subordinate permission are used to access the identity archive when service processing is performed for the specific user.

[0010] One or more embodiments of the present specification provide another storage medium for storing computer executable instructions, which, when executed by a processor, implement the following processes: acquiring a service processing request of an associated user sent by a service platform. Query a user account of a specific user who opens an account permission of the associated user in an associated user group to which the associated user belongs. According to the account permission, extract key identity information matching a service category carried in the service processing request in the user account. Return the key identity information to the service platform to perform service processing of the specific user according to the key identity information. BRIEF DESCRIPTION OF DRAWINGS

[0011] In order to more clearly illustrate the technical solutions in the one or more embodiments of the present specification or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments described in the present specification, and those skilled in the art can also obtain other drawings according to these drawings without creative labor;

[0012] Figure 1An identity archive processing method processing flowchart provided for one or more embodiments of the present specification;

[0013] Figure 2 An identity archive processing method processing flowchart provided for one or more embodiments of the present specification applied to a minor user scenario;

[0014] Figure 3 A service processing method processing flowchart provided for one or more embodiments of the present specification;

[0015] Figure 4 A service processing method processing flowchart provided for one or more embodiments of the present specification applied to a service processing scenario;

[0016] Figure 5 An identity archive processing device schematic diagram provided for one or more embodiments of the present specification;

[0017] Figure 6 A service processing device schematic diagram provided for one or more embodiments of the present specification;

[0018] Figure 7 A structure schematic diagram of an identity archive processing equipment provided for one or more embodiments of the present specification;

[0019] Figure 8 A structure schematic diagram of a service processing equipment provided for one or more embodiments of the present specification. DETAILED DESCRIPTION

[0020] In order to make the person skilled in the art better understand the technical scheme in one or more embodiments of the present specification, the technical scheme in one or more embodiments of the present specification will be described clearly and completely below in conjunction with the drawings in one or more embodiments of the present specification. Obviously, the described embodiments are only part of the embodiments of the present specification, not all the embodiments. Based on one or more embodiments of the present specification, all other embodiments obtained by the person skilled in the art without creative labor should belong to the protection scope of the present document.

[0021] An identity archive processing method embodiment provided by the present specification:

[0022] Referring to Figure 1 , which shows an identity archive processing method processing flowchart provided by the present embodiment, referring to Figure 2 , which shows an identity archive processing method processing flowchart provided by the present embodiment applied to a minor user scenario.

[0023] Referring to Figure 1The identity archive processing method provided in this embodiment specifically comprises steps S102 to S108.

[0024] In step S102, an archive creation request submitted by a main associated user for a specific user is obtained, and an identity archive of the specific user is created based on identity information carried in the archive creation request.

[0025] The identity archive processing method provided in this embodiment creates an identity archive of a specific user by a main associated user online, and manages the identity archive according to the main authority of the main associated user on the identity archive. Specifically, subordinate authorities of the identity archive of the specific user can be opened to a plurality of subordinate associated users, so that the associated users with the main authority or the subordinate authority of the identity archive can access the identity archive when providing services to the specific user, thereby improving the efficiency of providing services to the specific user who does not have the self-management authority of the account and reducing the obstacle of information management of the specific user.

[0026] In actual application, a user who does not have the self-management authority of the account can be managed by parents and the like. In this embodiment, the specific user includes a user who does not have the self-management authority of the account, for example, a minor user and an elderly user. The specific user can be created and managed by a guardian user. The user who initiates the archive creation of the specific user is the main associated user of the specific user. In addition, in order to improve the efficiency of providing services to the specific user, a plurality of family members can be opened to have the subordinate authority of the identity archive of the specific user. The family members opened to have the subordinate authority of the identity archive of the specific user are the subordinate associated users. It should be noted that, in order to ensure the privacy of the specific user and prevent the identity archive of the specific user from being spread to other users to cause information leakage of the specific user, in this embodiment, the subordinate associated users opened to have the subordinate authority of the specific user are the associated users in the associated user group of the main associated user of the specific user.

[0027] The identity archive refers to an information set composed of basic information of a user. In this embodiment, the identity information included in the identity archive includes but is not limited to the name, the group role, the feature, the date of birth, the identity certificate identifier, the social security identifier, the student identifier, and the home address. The user account is an application account created based on the archive request and used to store the identity archive of the specific user. In order to improve the effectiveness of the management of the user account, the user account of the specific user is not opened to have a specific authority, for example, a payment authority for a specific service (for example, a game hall payment). Specifically, the services to which the user account of the specific user is not opened to have the authority are determined according to actual scenes, which are not limited in this embodiment.

[0028] In a specific implementation, in order to facilitate the management of users in the same group (family, institution), the users in the same group are managed in the form of a group. Specifically, in a case where it is detected that a target user (primary associated user or secondary associated user) accesses a group service, it is verified whether the target user has group information. If yes, the target user can invite a secondary associated user or a primary associated user to join the group. If no, the target user creates a group and invites a secondary associated user or a primary associated user to join the group. In a case where a primary associated user and a secondary associated user join the same group, the primary associated user and the secondary associated user constitute an associated user group under the group identifier of the group.

[0029] For example, a secondary associated user invites a primary associated user. The secondary associated user accesses a group service and verifies whether the secondary associated user is associated with a target group. If yes, a group invitation is sent to the primary associated user according to an invitation request of the secondary associated user to the primary associated user, and an association relationship between the primary associated user and the secondary associated user under the group identifier of the target group is established in a case where the primary associated user agrees to the invitation. If no, a target group is created, a group invitation is sent to the primary associated user according to an invitation request of the secondary associated user to the primary associated user, and an association relationship between the primary associated user and the secondary associated user under the group identifier of the target group is established in a case where the primary associated user agrees to the invitation.

[0030] After the primary associated user joins the group, a file creation request submitted by the primary associated user for a specific user is obtained, and an identity file of the specific user is created according to identity information carried in the file creation request.

[0031] For example, access of a user u1 (father) to a family group service is obtained, a family identifier is generated according to a family group creation request submitted by the user u1, and after it is detected that the user u1 submits an invitation request for a user u2 (mother), family group invitation information is sent to the user u2, and an association relationship between the user u1 and the user u2 is established under the family identifier according to a consent instruction of the user u2. That is, the user u1 and the user u2 are associated users in an associated user group under the family identifier. The user u2 submits a file creation request for a user c, and submits a name, a date of birth, a role, an identity certificate identifier, a social security certificate identifier, and a student certificate identifier of the user c. An identity file of the user c is created according to the submitted identity information of the user c.

[0032] In step S104, a user account in which the identity file is stored is created, and the primary associated user is enabled to have a primary authority for the user account.

[0033] In the embodiment, the main associated user who creates the identity profile has main authority on the identity profile, and the main authority includes access authority on the identity profile and management authority on the subordinate associated users of the identity profile. After determining the co-management (subordinate association) user for co-management of the identity profile, the subordinate association authority of the subordinate associated user on the identity profile is opened. The subordinate authority includes access authority on the identity profile.

[0034] In implementation, in order to effectively store the created identity profile of the specific user, a user account is created for the specific user after the identity profile is created. However, the specific user does not have autonomous association authority on the user account, so that the specific user does not have specific authority when using the user account. That is, after the user account is created, the specific user can log in and use the user account, but the authority for the specific service is not opened.

[0035] After the user account for storing the identity profile is created, the main authority of the user account is opened to the main associated user, so that the main associated user can access the identity profile of the specific user when the specific user is serviced. In order to improve management efficiency, after the user account is created, the index of the user account and the identity profile identifier is established in the index table, and the main authority and the subordinate authority of the user account of the main associated user and the subordinate associated user are the main authority and the subordinate authority of the identity profile of the main associated user and the subordinate associated user.

[0036] In step S106, at least one subordinate associated user in the associated user group is determined to co-manage the user account.

[0037] In order to improve the co-management ability of other associated users in the associated user group to which the main associated user belongs, the co-management user (subordinate associated user) can be added to co-manage the user account. In implementation, the main associated user invites the associated user in the associated user group to become a co-management user, and the associated user in the associated user group can also become a co-management user of the user account under the authorization of the main associated user.

[0038] In the first optional implementation provided by the embodiment, the co-management account for co-managing the user account is determined in the following manner:

[0039] The authority authorization instruction of the main associated user on the identity profile stored in the user account is obtained.

[0040] The associated user group is queried based on the authority authorization instruction, and the main associated user is returned.

[0041] The at least one subordinate associated account selected by the main associated user in the associated user group is obtained.

[0042] Specifically, the main associated user group authorizes the user account, and invites the associated user in the associated user group to co-manage the user account.

[0043] Continuing with the above example, after the user u2 creates the identity profile of the user c, the user account of the user c is generated, and an index relationship between the user account identifier and the identity profile identifier is established. The identity profile is stored in the user account, the main associated relationship between the associated account identifier of the user u2 and the user account identifier is established, and the main authority of the user account is opened to the user u2. After the user u2 creates the user account of the user c, the user u1 in the associated user group under the family identifier is invited to co-manage the identity profile of the user c. After the invitation is successful, the subordinate associated relationship between the associated account identifier of the user u1 and the user account identifier is also established, and the co-management authority of the user account of the user u1 is opened.

[0044] In the second optional implementation provided by the embodiment, the co-management account is determined in the following manner:

[0045] Obtaining a permission authorization request of the candidate associated user based on the associated user group for the user account;

[0046] Sending an authorization reminder to the main associated user based on the permission authorization request;

[0047] According to the confirmation instruction submitted by the main associated user based on the authorization reminder, the candidate associated user is determined as a subordinate associated user.

[0048] Specifically, after the user account is created, the associated user group is written, and the main associated user and the (candidate) associated user other than the specific user in the associated user group initiate a permission authorization request for the co-management authority of the user account to the main associated user. After the main associated user agrees or confirms, the candidate associated user is determined as a co-management user (subordinate associated user) for the account co-management of the user account. In the embodiment, the subordinate associated user can be one or more.

[0049] Step S108, opening subordinate authority of the user account to the at least one subordinate associated user.

[0050] In specific implementation, after determining the at least one subordinate associated user, the subordinate authority of the user account is opened to the at least one subordinate associated user. The main authority and the subordinate authority are used to access the identity profile when the service is processed on behalf of the specific user.

[0051] After the main authority is opened to the main associated user and the subordinate authority is opened to the at least one subordinate associated user, the main associated user or any subordinate associated user can process the service on behalf of the specific user. In an optional implementation provided by the embodiment, the service is processed in the following manner:

[0052] obtaining a service processing request of a target associated user sent by the service platform; the target associated user includes the primary associated user or any subordinate associated user;

[0053] extracting key identity information in the identity profile that matches a service category carried in the service processing request based on account permissions of the target associated user on the user account;

[0054] returning the key identity information to the service platform to enable the service platform to perform service processing on the specific user based on the key identity information.

[0055] In order to further improve the perception of the primary associated user and the at least one subordinate associated user on the service of the specific user, an optional embodiment provided by the embodiment further performs the following operations:

[0056] obtaining a service processing result sent by the service platform after performing service processing;

[0057] determining the user account based on an identity of the specific user carried in the service processing result;

[0058] querying the primary associated user and the at least one subordinate associated user having account permissions of the user account and sending the service processing result.

[0059] The service platform is a platform of a service application, and the service application includes a sub-application carried in a third-party application and also includes an independent application installed on a terminal device.

[0060] Specifically, the target associated user (the primary associated user or the subordinate associated user) initiates a service processing request through a service application, the service application sends the service processing request of the target associated user, after obtaining the service processing request of the target associated user synchronized by the service application, the target associated user's associated user account identifier carried in the service processing request is queried to obtain a user account list with account authority of the target associated user, and the identity profile stored in each user account in the user account list is sent to the target associated user, so that the target associated user selects the identity profile of a specific user for service processing from the identity profile, after obtaining the identity profile of the specific user selected by the target associated user in the identity profile for service processing, the service category carried in the service processing request is extracted in the selected identity profile to obtain key identity information, and the key identity information is returned to the service platform, and the service platform processes the specific user based on the key information. In order to improve the perception degree of the primary associated user and the subordinate associated user with account authority of the user account of the specific user to the service processing result of the specific user, the service processing result sent by the service platform after processing the specific user is obtained, and then the service processing result is broadcast to the associated user group to which the specific user belongs, or is sent to the primary associated user or the subordinate associated user with account authority of the user account of the specific user.

[0061] Continue with the above example, user u1 has co-management authority of the user account of user c, user u2 has primary authority of the user account of user c, user u1 processes hospital registration for user c, user u1 accesses the service platform provided by the hospital, initiates a registration processing request, obtains the registration processing request sent by the service platform, queries the user account of user u1 with primary authority and co-management authority according to the associated account identifier of user u1 carried in the registration processing request, and reads the identity profile stored in the user account, and sends the identity profile to user u1. User u1 selects the identity profile of user c in the identity profile for submission. After detecting that user u1 selects the identity profile of user c, the name, identity certificate identifier and social guarantee certificate identifier in the identity profile are read according to the registration type and sent to the service platform, so that the service platform registers user c. Get the registration result returned by the service platform in the case of successful registration, and send the registration result to user u1 and user u2 through the way of station message.

[0062] In this embodiment, the primary associated user can manage the subordinate associated user of the user account, such as adding and deleting. The adding process is described above in the process of inviting the subordinate associated user to co-manage the user account by the primary associated user. In an optional implementation provided by this embodiment, the authority of the subordinate associated account is released by the following method:

[0063] According to the permission management instruction of the main associated user to the user account, a list of associated users with subordinate permissions of the user account is queried;

[0064] Based on the permission release instruction of the main associated user to a target associated user in the list of associated users, the subordinate permission of the target associated user to the user account is released.

[0065] Specifically, according to the permission release instruction submitted by the target associated user in the list of associated users of the user account, the subordinate permission of the target associated user to the user account is released. After the subordinate permission of the target associated user to the user account is released, the target associated user needs to obtain the authorization of the main associated user when accessing the identity file.

[0066] When a specific user has the ability or permission to independently manage an account, the user account is authenticated. After the user account is authenticated, the main associated user transfers the user account to the specific user. In an optional implementation provided by the embodiment, the user account is authenticated in the following manner:

[0067] According to the authentication type carried in the authentication request submitted by the specific user through the user account, authentication information of the specific user is collected;

[0068] According to the authentication information, it is judged whether the specific user meets the authentication condition corresponding to the authentication type;

[0069] If yes, the user account is marked as an authenticated account;

[0070] If no, no processing is performed.

[0071] Specifically, according to the authentication type selected by the specific user, authentication information of the specific user is collected, and the specific user is authenticated according to the collected authentication information. It is judged whether the specific user meets the account independent management. If yes, the user account is marked as an authenticated account and the permissions not opened in the user account are opened. If no, no processing is performed. The authentication type includes a face recognition authentication type and / or a bank card authentication type.

[0072] In an optional implementation provided by the embodiment, after the specific user authenticates the user account and passes the authentication, the main permission of the main associated user to the user account is realized in the following manner:

[0073] According to the permission transfer request of the main associated user to the identity file, it is verified whether the specific user meets the account self-management condition;

[0074] If yes, the main permission and the subordinate permission are released, and the self-management permission of the specific user to the identity file is opened;

[0075] If no, a failure transfer failure reminder is sent to the master associated user based on the verification failure reason;

[0076] The account self-management condition includes that the user account is marked as an authentication account.

[0077] Optionally, after the self-management permission is opened to the specific user, the specific user updates the identity profile; after the master permission and the subordinate permission are released, the master associated user and / or the subordinate associated user access the identity profile after obtaining the profile authorization of the specific user.

[0078] After the master associated user submits a permission transfer request for the identity profile, it is verified whether the user account corresponding to the profile request is an authentication account. If yes, the master permission and the subordinate permission for the user account are released, and the self-management permission of the specific user for the identity profile is opened.

[0079] For example, user c authenticates the user account by binding a bank card to the user account, and obtains the permission transfer request of user u2 for the master permission of the identity profile. First, it is determined whether the user account corresponding to the identity profile is an authentication account. If yes, the co-management permission of user u1 for the user account is released, the master permission of user u2 for the user account is released, and the release result is sent to user u1 and user u2. At the same time, the self-management permission of user c for the user account is opened. After the self-management permission of user c for the user account is opened, user c can update the identity profile, and store the updated identity profile in the user account. In order to improve the perception degree of user c for the source of the identity profile, the identity profile is marked, the historical creator of the identity profile is marked as user u2, and the historical co-manager is marked as user u1.

[0080] The application of the identity profile processing method provided in the embodiment in the scenario of a minor user is taken as an example to further illustrate the identity profile processing method provided in the embodiment, which is described with reference to Figure 2 The identity profile processing method applied in the scenario of a minor user specifically includes steps S202 to S216.

[0081] Step S202, obtaining a profile creation request for a minor user submitted by a master associated user.

[0082] The master associated user includes a guardian or a family member of the minor user.

[0083] Step S204, creating an identity profile of the minor user based on the identity information carried in the profile creation request.

[0084] Step S206, creating a user account for storing the identity profile, and opening a master permission for the user account to the master associated user.

[0085] Step S208, obtaining a co-management user invited by the main associated user in the associated user group to co-manage the user account.

[0086] Step S210, opening the co-management permission of the co-management user to the user account.

[0087] Step S212, verifying whether the user account is an independent account according to the permission transfer request of the main associated user to the identity profile;

[0088] If yes, steps S214 to S216 are executed;

[0089] If no, a failure reminder is sent to the main associated user.

[0090] Step S214, canceling the main permission of the main associated user to the user account, and the co-management permission of the co-management user to the user account.

[0091] Step S216, opening the self-management permission of the minor user to the user account, and updating and storing the identity profile according to the instruction submitted by the minor user.

[0092] It should be noted that after the user account becomes an independent account, the minor user becomes an adult user.

[0093] The service processing method provided in the specification:

[0094] Referring to Figure 3 , a service processing method processing flowchart provided by the embodiment is shown; see Figure 4 , a service processing method processing flowchart applied to a service processing scenario provided by the embodiment is shown.

[0095] Referring to Figure 3 , the service processing method provided by the embodiment specifically includes steps S302 to S308.

[0096] Step S302, obtaining a service processing request of an associated user sent by a service platform.

[0097] The service processing method provided by the embodiment avoids that a specific user corresponding to a user account cannot independently perform service access, specifically, after obtaining a service processing request of an associated user sent by a service platform, first, a specific user with account authority of the associated user is determined to the user account, and key identity information required by a service type corresponding to the service processing request is extracted from an identity profile stored in the user account, and the key identity information is returned to the service platform, so that the service platform processes the specific user based on the key identity information. In this way, the perception of service processing for specific users without independent account management capabilities is improved.

[0098] The service platform includes a platform for processing services; for example, a hospital platform, a children's palace platform, etc. The associated user includes a user with master authority and subordinate authority over the identity profile.

[0099] In practical applications, users without independent account management capabilities can be managed by parents and the like; in the embodiment, the specific user includes a user without independent account management capabilities; for example, a minor user and an elderly user. The specific user can be created and managed by a guardian user; the user initiating the creation of the profile of the specific user is the primary associated user of the specific user; in addition, in order to improve the efficiency of service processing for the specific user, multiple family members with subordinate authority over the identity profile of the specific user can be opened; wherein the family members with subordinate authority over the identity profile of the specific user are subordinate associated users. It should be noted that in order to protect the privacy of the specific user and prevent the identity profile of the specific user from being spread to other users and causing information leakage of the specific user, in the embodiment, the subordinate associated user with subordinate authority over the specific user is an associated user in the associated user group of the primary associated user of the specific user.

[0100] Based on this, in an optional implementation of the embodiment, before obtaining the service processing request of the associated user sent by the service platform, the following operations are further performed:

[0101] Create an identity profile of the specific user based on the identity information carried in the profile creation request and create the user account for storing the identity profile;

[0102] Open the master authority of the primary associated user to the user account, so that the primary associated user accesses the identity profile when processing the service of the specific user.

[0103] Further, in order to improve the co-management capability of the user account by other associated users in the associated user group to which the main associated user belongs, a co-management user (subordinate associated user) can be added to co-manage the user account. In specific implementation, the main associated user invites an associated user in the associated user group to become a co-management user, and the associated user in the associated user group can also become a co-management user of the user account with the authorization of the main associated user.

[0104] In an optional implementation of the embodiment, after the main authority of the user account by the main associated user is opened, the main associated user can invite an associated user in the associated user group to co-manage the user account, that is, to determine a co-management account (subordinate associated user) for co-managing the user account. Specifically, the co-management of the user account by the associated user in the associated user group is implemented in the following manner:

[0105] Determine at least one subordinate associated user in the associated user group for co-managing the user account.

[0106] Open subordinate authority of the user account to the at least one subordinate associated user, so that each subordinate associated user accesses the identity archive when providing service to the specific user based on the subordinate authority.

[0107] In addition, the embodiment can also be initiated by an associated user in the associated user group.

[0108] The identity archive refers to an information set composed of basic information of a user. In the embodiment, the identity information contained in the identity archive includes but is not limited to: name, group role, feature, date of birth, identity credential identifier, social security identifier, student identifier, and home address. The user account is an application account created based on an archive request and used to store the identity archive of a specific user. In order to improve the effectiveness of user account management, the user account of the specific user is not opened to a specific authority, for example, payment authority for a specific service (such as a game hall payment). Specifically, the service for which the user account of the specific user is not opened to the authority is determined according to the actual scene, which is not limited in the embodiment.

[0109] In specific implementation, in order to improve the processing efficiency of the guardian or family member for the online service of the elderly user or the minor user who does not have independent account management capability, the embodiment creates the identity archive and the user account of the specific user by the associated user who has independent account management capability.

[0110] In order to facilitate the management of users in the same group (family, institution), the users in the same group are managed in the form of a group. Specifically, in the case of detecting that a target user (primary associated user or secondary associated user) accesses a group service, it is verified whether the target user has group information. If yes, the target user can invite the secondary associated user or the primary associated user to join the group. If no, the target user creates a group and invites the secondary associated user or the primary associated user to join the group. In the case of the primary associated user and the secondary associated user joining the same group, the primary associated user and the secondary associated user constitute an associated user group under the group identifier of the group.

[0111] Taking the case of the secondary associated user inviting the primary associated user as an example, the secondary associated user accesses the group service, and it is verified whether the secondary associated user is associated with the target group. If yes, a group invitation is sent to the primary associated user according to the invitation request of the secondary associated user to the primary associated user, and the association relationship between the primary associated user and the secondary associated user under the group identifier of the target group is established in the case of the primary associated user agreeing to the invitation. If no, the target group is created, a group invitation is sent to the primary associated user according to the invitation request of the secondary associated user to the primary associated user, and the association relationship between the primary associated user and the secondary associated user under the group identifier of the target group is established in the case of the primary associated user agreeing to the invitation.

[0112] After the primary associated user joins the group, the profile creation request submitted by the primary associated user for a specific user is obtained, and the identity profile of the specific user is created according to the identity information carried in the profile creation request.

[0113] For example, the access of user u1 (father) to the family group service is obtained, the family identifier is generated according to the family group creation request submitted by user u1, and after detecting that user u1 submits an invitation request for user u2 (mother), the family group invitation information is sent to user u2. According to the consent instruction of user u2, the association relationship between user u1 and user u2 under the family identifier is established. That is, user u1 and user u2 are associated users in the associated user group under the family identifier. User u2 submits a profile creation request for user c, and submits the name, birth date, role, identity credential identifier, social security credential identifier, and student credential identifier of user c. The identity profile of user c is created according to the submitted identity information of user c.

[0114] In this embodiment, the primary associated user who creates the identity profile has a primary permission for the identity profile, and the primary permission includes an access permission for the identity profile and a management permission for the secondary associated user of the identity profile. After determining a co-management (secondary associated) user for co-managing the identity profile, the secondary associated user is opened for co-management (secondary) permission for the identity profile. The secondary permission includes an access permission for the identity profile.

[0115] In implementation, in order to effectively store the created identity profile of the specific user, a user account is created for the specific user after the identity profile is created, but the specific user does not have the self-association right to the user account, so that the specific user does not open the specific right when using the user account. That is, after the user account is created, the specific user can log in and use the user account, but the right for the specific service is not opened.

[0116] After the user account storing the identity profile is created, the master right to the user account is opened to the master-association user, so that the master-association user accesses the identity profile of the specific user when the specific user is serviced to be processed. In order to improve the management efficiency, after the user account is created, the index of the user account and the identity profile identifier is established in the index table, and the master right and the subordinate right of the user account of the master-association user and the subordinate-association user are the master right and the subordinate right of the identity profile of the master-association user and the subordinate-association user.

[0117] In implementation, after the at least one subordinate-association user is determined, the subordinate right to the user account is opened to the at least one subordinate-association user. The master right and the subordinate right are used to access the identity profile when the specific user is serviced to be processed.

[0118] After the master right is opened to the master-association user and the subordinate right is opened to the at least one subordinate-association user, the master-association user or any subordinate-association user can process the specific user to be serviced.

[0119] Step S304, querying the user account of the specific user opening the account right of the association user in the association user group to which the association user belongs.

[0120] In implementation, in order to improve the perception degree of the association user to the account right, in an optional embodiment provided by the embodiment, the following operations are performed in the process of querying the user account:

[0121] Querying at least one candidate specific user opening the right in the association user group;

[0122] Reading the identity profile of the at least one candidate specific user and sending to the association user;

[0123] Obtaining the specific user selected by the association user in the at least one candidate specific user, and determining the user account of the specific user.

[0124] Specifically, the target associated user (the primary associated user or the subordinate associated user) initiates a service processing request through a service application, the service application sends the service processing request of the target associated user, after obtaining the service processing request of the target associated user synchronized by the service application, the target associated user's associated user account identifier carried in the service processing request is queried to obtain a user account list of the target associated user having an account permission, and the identity profile stored in each user account in the user account list is sent to the target associated user, so that the target associated user selects the identity profile of a specific user for service processing from the identity profile.

[0125] Taking the above example, the user u1 has a co-management permission for the user account of the user c, the user u2 has a primary permission for the user account of the user c, the user u1 performs a hospital registration processing for the user c, the user u1 accesses a service platform provided by the hospital, initiates a registration processing request, obtains the registration processing request sent by the service platform, queries the user account of the user u1 having the primary permission and the co-management permission according to the associated account identifier of the user u1 carried in the registration processing request, reads the identity profile stored in the user account, and sends the identity profile to the user u1, and the user u1 selects the identity profile of the user c in the identity profile for submission.

[0126] In step S306, according to the account permission, the key identity information matching the service category carried in the service processing request is extracted from the user account.

[0127] After obtaining the identity profile of the specific user selected by the target associated user in the identity profile for service processing, the key identity information is extracted from the selected identity profile according to the service category carried in the service processing request.

[0128] In step S308, the key identity information is returned to the service platform, so that the service processing of the specific user is performed according to the key identity information.

[0129] In specific implementation, the key identity information is returned to the service platform, and the service processing of the specific user is performed by the service platform based on the key information. In order to improve the perception degree of the primary associated user and the subordinate associated user having the account permission for the user account of the specific user on the service processing result of the specific user, in an optional implementation provided by the embodiment, after the key identity information is returned to the service platform, the following operations are further performed:

[0130] Obtain the service processing result returned by the service platform;

[0131] Query the candidate associated user in the associated user group having the permission for the user account;

[0132] sending the service processing result to the candidate associated user.

[0133] Specifically, the service processing result sent by the service platform after the service platform processes a specific user is acquired, and then the service processing result is broadcast to an associated user group to which the specific user belongs, or is sent to a master associated user or a subordinate associated user who has an account authority for the user account of the specific user.

[0134] Continuing with the above example, after detecting that the user u1 selects the identity profile of the user c, the name, identity certificate identifier, and social guarantee certificate identifier in the identity profile are read according to the registration type, and are sent to the service platform, so that the service platform registers the user c. The registration result returned by the service platform in the case of successful registration is acquired, and the registration result is sent to the user u1 and the user u2 by means of an internal message.

[0135] When the specific user has the ability or authority to independently manage the account, the user account is authenticated, and after the user account is authenticated, the master associated user transfers the user account to the specific user. In an optional implementation provided by the embodiment, the user account is authenticated in the following manner:

[0136] Based on the authentication type carried in the authentication request, authentication information of the specific user is collected;

[0137] According to the authentication information, it is judged whether the specific user meets the authentication condition corresponding to the authentication type;

[0138] If yes, the user account is marked as an authenticated account.

[0139] If no, no processing is performed.

[0140] Specifically, according to the authentication type selected by the specific user, authentication information of the specific user is collected, and the specific user is authenticated according to the collected authentication information. It is judged whether the specific user meets the independent account management. If yes, the user account is marked as an authenticated account and the authority not opened in the user account is opened. If no, no processing is performed. The authentication type includes a face recognition authentication type and / or a bank card authentication type.

[0141] In an optional implementation provided by the embodiment, after the specific user authenticates the user account and passes the authentication, the master associated user realizes the master authority of the user account in the following manner:

[0142] An authority transfer request for the identity profile submitted by a master associated user who has a master authority for the user account is acquired;

[0143] It is verified whether the specific user meets the independent management condition for the user account.

[0144] If yes, the master authority and the subordinate authority to the user account are released, and the specific user is opened to the management authority for the identity profile;

[0145] If no, a failed transfer failure prompt is sent to the master associated user based on the verification failure reason;

[0146] The independent management condition includes that the user account is marked as an authenticated account.

[0147] Optionally, after the specific user is opened to the self-management authority, the specific user updates the identity profile; and after the master authority and the subordinate authority are released, the master associated user and / or the subordinate associated user access the identity profile after obtaining the profile authorization of the specific user.

[0148] After the master associated user submits the authority transfer request for the identity profile, it is verified whether the user account corresponding to the profile request is an authenticated account. If yes, the master authority and the subordinate authority to the user account are released, and the specific user is opened to the self-management authority for the identity profile.

[0149] For example, the user c authenticates the user account by binding a bank card to the user account, obtains the master authority transfer request for the identity profile submitted by the user u2, first determines whether the user account corresponding to the identity profile is an authenticated account. If yes, the co-management authority of the user u1 to the user account is released, the master authority of the user u2 to the user account is released, and the release result is sent to the user u1 and the user u2. At the same time, the self-management authority of the user c to the user account is opened. After the self-management authority of the user c to the user account is opened, the user c can update the identity profile, and store the updated identity profile in the user account. In order to improve the perception degree of the user c to the source of the identity profile, the identity profile is marked, the historical creator of the identity profile is marked as the user u2, and the historical co-manager is marked as the user u1.

[0150] The service processing method provided in the embodiment is further described below by taking the application of the service processing method in a service processing scenario as an example. Referring to FIG. 4, Figure 4 The service processing method applied in the service processing scenario specifically includes steps S402 to S416.

[0151] In step S402, a service processing request of an associated user sent by a service platform is obtained.

[0152] In step S404, a user account of at least one specific user of the associated user group to which the associated user belongs is queried.

[0153] The account authority includes a main authority and a co-management authority.

[0154] In step S406, the identity profile stored in the at least one user account is sent to the associated user.

[0155] In step S408, the identity profile selected by the associated user for service processing is obtained.

[0156] In step S410, the key identity information in the identity profile is extracted according to the service category corresponding to the service processing request.

[0157] In step S412, the key identity information is returned to the service platform, so that the service platform performs service processing on the corresponding specific user.

[0158] In step S414, the service result returned by the service platform after service processing is obtained.

[0159] In step S416, the authority associated user having the account authority of the identity profile of the specific user is determined, and the service result is sent to the authority associated user.

[0160] The authority associated user includes the associated user in step S402.

[0161] It should be noted that if the service result contains private data that cannot be transmitted outside the service platform, a service completion reminder returned by the service platform after service processing is obtained, and is sent to the authority associated user having the account authority of the identity profile, so that the authority associated user views the service result through the service platform.

[0162] The identity profile processing device provided in the present specification implements, for example:

[0163] In the above embodiment, an identity profile processing method is provided, and a corresponding identity profile processing device is also provided, which will be described below with reference to the accompanying drawings.

[0164] Reference Figure 5 which shows a schematic diagram of an identity profile processing device provided in the present embodiment.

[0165] Since the device embodiment corresponds to the method embodiment, the description is relatively simple, and the related parts can be referred to the above-mentioned corresponding description of the method embodiment. The device embodiments described below are only schematic.

[0166] The present embodiment provides an identity profile processing device, which comprises:

[0167] The archive creation module 502 is configured to obtain an archive creation request for a specific user submitted by a master associated user, and create an identity archive of the specific user based on identity information carried in the archive creation request;

[0168] The master authority opening module 504 is configured to create a user account for storing the identity archive, and open master authority of the user account to the master associated user;

[0169] The user determination module 506 is configured to determine at least one subordinate associated user in an associated user group for account co-management of the user account;

[0170] The subordinate authority opening module 508 is configured to open subordinate authority of the user account to the at least one subordinate associated user, and the master authority and the subordinate authority are used to access the identity archive when service processing is performed for the specific user.

[0171] The service processing apparatus provided in the specification implements, for example:

[0172] In the above embodiment, a service processing method is provided, and a service processing apparatus corresponding thereto is also provided, which will be described below with reference to the accompanying drawings.

[0173] Reference Figure 6 which shows a schematic diagram of a service processing apparatus provided in the embodiment.

[0174] Since the device embodiment corresponds to the method embodiment, the description is relatively simple, and the related parts can be referred to the above-mentioned corresponding description of the method embodiment. The device embodiments described below are only schematic.

[0175] The service processing apparatus provided in the embodiment includes:

[0176] The request obtaining module 602 is configured to obtain a service processing request of an associated user sent by a service platform;

[0177] The account query module 604 is configured to query a user account of a specific user who opens account authority of the associated user in an associated user group to which the associated user belongs;

[0178] The information extraction module 606 is configured to extract key identity information matching a service category carried in the service processing request in the user account according to the account authority;

[0179] The information returning module 608 is configured to return the key identity information to the service platform, so as to perform service processing of the specific user according to the key identity information.

[0180] The identity archive processing device provided in the specification implements, for example, the following:

[0181] Corresponding to the above-described identity archive processing method, based on the same technical concept, one or more embodiments of the specification also provide an identity archive processing device for executing the above-provided identity archive processing method, Figure 7 A structural schematic diagram of an identity archive processing device provided for one or more embodiments of the specification.

[0182] The identity archive processing device provided in the embodiment includes:

[0183] As Figure 7 shown, the identity archive processing device can have a large difference due to different configurations or performances, and can include one or more processors 701 and memories 702, and the memories 702 can store one or more storage applications or data. Among them, the memory 702 can be temporary storage or persistent storage. The application stored in the memory 702 can include one or more modules (not shown in the figure), and each module can include a series of computer executable instructions in the identity archive processing device. Further, the processor 701 can be configured to communicate with the memory 702 and execute a series of computer executable instructions in the memory 702 on the identity archive processing device. The identity archive processing device can also include one or more power supplies 703, one or more wired or wireless network interfaces 704, one or more input / output interfaces 705, one or more keyboards 706, etc.

[0184] In a specific embodiment, the identity archive processing device includes a memory, and one or more programs, wherein one or more programs are stored in the memory, and one or more programs can include one or more modules, and each module can include a series of computer executable instructions in the identity archive processing device, and the configuration of the one or more processors to execute the one or more programs includes computer executable instructions for:

[0185] Obtaining an archive creation request for a specific user submitted by a main associated user, creating an identity archive of the specific user based on identity information carried in the archive creation request;

[0186] Creating a user account for storing the identity archive, and opening a main authority of the user account to the main associated user;

[0187] Determining at least one subordinate associated user in the associated user group for account co-management of the user account;

[0188] enable the at least one subordinate associated user to have subordinate rights to the user account, the primary rights and the subordinate rights being used to access the identity profile when service processing is performed for the particular user.

[0189] The service processing device provided in the specification implements, for example:

[0190] According to the same technical concept as described above, one or more embodiments of the specification also provide a service processing device for executing the service processing method provided above, Figure 8 A structural schematic diagram of a service processing device provided for one or more embodiments of the specification.

[0191] The service processing device provided in the embodiment includes:

[0192] As Figure 8 shown, the service processing device can have a large difference due to different configurations or performances, and can include one or more processors 801 and memories 802, and the memories 802 can store one or more storage applications or data. Among them, the memory 802 can be temporary storage or persistent storage. The application stored in the memory 802 can include one or more modules (not shown in the figure), and each module can include a series of computer executable instructions in the service processing device. Further, the processor 801 can be configured to communicate with the memory 802 and execute a series of computer executable instructions in the memory 802 on the service processing device. The service processing device can also include one or more power supplies 803, one or more wired or wireless network interfaces 804, one or more input / output interfaces 805, one or more keyboards 806, etc.

[0193] In one specific embodiment, the service processing device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs can include one or more modules, and each module can include a series of computer executable instructions in the service processing device, and the one or more processors are configured to execute the one or more programs include computer executable instructions for:

[0194] Obtaining the service processing request of the associated user sent by the service platform;

[0195] Querying the user account of the specific user who opens the account rights of the associated user in the associated user group to which the associated user belongs;

[0196] According to the account authority, extract key identity information matching a service category carried in the service processing request in the user account;

[0197] Return the key identity information to the service platform for service processing of the specific user according to the key identity information.

[0198] The storage medium provided by the present specification implements, for example, the following:

[0199] According to the above description, based on the same technical concept, one or more embodiments of the present specification also provide a storage medium.

[0200] The storage medium provided by the present embodiment is used to store computer executable instructions, and the computer executable instructions realize the following processes when executed by a processor:

[0201] Obtain an archive creation request for a specific user submitted by a main associated user, and create an identity archive of the specific user based on identity information carried in the archive creation request;

[0202] Create a user account for storing the identity archive, and open a main authority of the user account to the main associated user;

[0203] Determine at least one subordinate associated user in the associated user group for account co-management of the user account;

[0204] Open a subordinate authority of the user account to the at least one subordinate associated user, and the main authority and the subordinate authority are used to access the identity archive when processing service on behalf of the specific user.

[0205] It should be noted that the embodiments of the storage medium in the present specification and the embodiments of the identity archive processing method in the present specification are based on the same inventive concept, so the specific implementation of this embodiment can refer to the foregoing implementation of the corresponding method, and the repeated parts will not be described again.

[0206] The storage medium provided by the present specification implements, for example, the following:

[0207] According to the above description, based on the same technical concept, one or more embodiments of the present specification also provide a storage medium.

[0208] The storage medium provided by the present embodiment is used to store computer executable instructions, and the computer executable instructions realize the following processes when executed by a processor:

[0209] Obtain a service processing request of an associated user sent by a service platform;

[0210] querying, in a group of associated users to which the associated user belongs, a user account of a specific user who opens an account permission of the associated user;

[0211] extracting, in the user account according to the account permission, key identity information matching a service category carried in the service processing request;

[0212] returning the key identity information to the service platform to perform service processing of the specific user according to the key identity information.

[0213] It should be noted that the embodiments of the storage medium in the present specification are based on the same inventive concept as the embodiments of the service processing method in the present specification, and therefore the specific implementation of the embodiments can be referred to the implementation of the corresponding method described above, and the repeated parts will not be described herein.

[0214] The above describes specific embodiments of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the acts or steps recited in the claims can be performed in an order other than the order in which they are recited and still achieve desirable results. In addition, the processes depicted in the figures do not necessarily require the particular order shown, or sequential order, to achieve the desired results. In certain implementations, multitasking and parallel processing can be advantageous or possible.

[0215] In the 1930s, it was clear to distinguish whether an improvement in a technology was in hardware (e.g., improvement in circuit structure of diodes, transistors, switches, etc.) or in software (e.g., improvement in method flow). However, as technology has evolved, many improvements in method flow today can be considered as direct improvements in hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement in a method flow cannot be implemented by a hardware entity module. For example, a programmable logic device (PLD) (e.g., a field programmable gate array (FPGA)) is an integrated circuit whose logic function is determined by user programming of the device. A digital system is "integrated" on a PLD by the designer programming it, rather than by asking a chip manufacturer to design and fabricate a custom integrated circuit chip. Moreover, instead of manually fabricating an integrated circuit chip, this programming is now mostly implemented by "logic compiler" software, which is similar to software compilers used in program development, and the original code to be compiled is written in a specific programming language, called a hardware description language (HDL), of which there are many, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc., the most commonly used being VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. It should be clear to those skilled in the art that, by simply logically programming a method flow in one of the above hardware description languages and programming it into an integrated circuit, a hardware circuit implementing the logical method flow can be easily obtained.

[0216] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. Memory controllers can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.

[0217] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0218] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing the embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.

[0219] Those skilled in the art will understand that one or more embodiments of this specification can be provided as a method, system, or computer program product. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0220] The specification is presented with reference to flow diagrams and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the specification. It will be understood that each block of the flow diagrams and / or block diagrams, and combinations of blocks in the flow diagrams and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing element or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagrams and / or block diagrams in the specification can present a method, apparatus or computer program product according to embodiments of the specification. Flow diagrams and / or block diagrams can also present a method, apparatus or computer program product to achieve functions specified in flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagrams and / or block diagrams in the specification can present a method, apparatus or computer program product according to embodiments of the specification. Flow diagrams and / or block diagrams can also present a method, apparatus or computer program product to achieve functions specified in flow diagrams and / or block diagrams block or blocks.

[0221] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagrams and / or block diagrams in the specification can present a method, apparatus or computer program product according to embodiments of the specification. Flow diagrams and / or block diagrams can also present a method, apparatus or computer program product to achieve functions specified in flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagrams and / or block diagrams in the specification can present a method, apparatus or computer program product according to embodiments of the specification. Flow diagrams and / or block diagrams can also present a method, apparatus or computer program product to achieve functions specified in flow diagrams and / or block diagrams block or blocks.

[0222] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagrams and / or block diagrams in the specification can present a method, apparatus or computer program product according to embodiments of the specification. Flow diagrams and / or block diagrams can also present a method, apparatus or computer program product to achieve functions specified in flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagrams and / or block diagrams in the specification can present a method, apparatus or computer program product according to embodiments of the specification. Flow diagrams and / or block diagrams can also present a method, apparatus or computer program product to achieve functions specified in flow diagrams and / or block diagrams block or blocks.

[0223] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0224] The memory can include non-persistent memory and / or persistent memory, such as flash memory, read-only memory (ROM), and / or volatile or non-volatile random access memory (RAM), among others. The memory is an example of computer-readable media.

[0225] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.

[0226] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to encompass non-exclusive inclusion, such that processes, methods, articles or devices that comprise a list of elements do not only include those elements, but also include other elements not expressly listed, or inherent to such processes, methods, articles or devices. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0227] One or more embodiments of the present specification can be described in the general context of computer-executable instructions being executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform particular tasks or implement particular abstract data types. One or more embodiments of the present specification can also be practiced in a distributed computing environment, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.

[0228] Each embodiment in the present specification is described in a progressive manner, and the same or similar parts between each embodiment can be referred to each other, and each embodiment focuses on the difference from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.

[0229] The above merely provides the example of the present document and is not intended to limit the present document. For those skilled in the art, the present document can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present document shall be included in the scope of claims of the present document.

Claims

1. A method for processing identity records, comprising: Obtain a profile creation request for a specific user submitted by the primary associated user, and create an identity profile for the specific user based on the identity information carried in the profile creation request; The specific user in question does not have the ability to manage their account independently. Create an application account for the specific user to store the identity profile, and grant the primary associated user master permissions to the application account; Obtain permission authorization requests for the application account submitted by candidate associated users based on associated user groups; send authorization reminders to the main associated user based on the permission authorization requests; and determine the candidate associated users as subordinate associated users based on the confirmation instructions submitted by the main associated user based on the authorization reminders. Grant subordinate permissions to at least one associated user for the application account. The primary and secondary permissions are used to extract key identity information matching the service category from the identity profile when performing service processing for the specific user, so that the service platform can perform service processing for the specific user based on the key identity information.

2. The identity file processing method according to claim 1 further includes: Based on the permission transfer request for the identity profile submitted by the primary associated user, verify whether the specific user meets the conditions for self-management of the account; If so, then the primary and secondary permissions are revoked, and self-management permissions for the identity profile are granted to the specific user.

3. The identity profile processing method according to claim 2, before the step of verifying whether the specific user meets the conditions for self-management of the account based on the permission transfer request for the identity profile submitted by the primary associated user, further includes: Based on the authentication type carried in the authentication request submitted by the specific user through the application account, the authentication information of the specific user is collected; Based on the authentication information, determine whether the specific user meets the authentication conditions corresponding to the authentication type; If so, mark the application account as an authenticated account; The conditions for self-management of the account include: the application account is marked as an authenticated account.

4. In the identity file processing method according to claim 2, after granting the self-management permission to the specific user, the specific user updates the identity file; After the primary and secondary permissions are revoked, the primary associated user and / or the secondary associated user can access the identity file after obtaining the file authorization of the specific user.

5. The identity file processing method according to claim 1, wherein the service processing includes: Obtain the service processing request sent by the service platform to the target associated user; The target associated user includes the primary associated user or any subordinate associated user; Based on the target associated user's account permissions for the application account, extract key identity information from the identity profile that matches the service category carried in the service processing request; The key identity information is returned to the service platform so that the service platform can process services for the specific user based on the key identity information.

6. The identity file processing method according to claim 5 further includes: Obtain the service processing result sent by the service platform after performing service processing; The application account is determined based on the identity identifier of the specific user carried in the service processing result; Query the primary associated user and the at least one subordinate associated user who have the account permissions of the application account and send the service processing result.

7. The identity profile processing method according to claim 1, after the step of granting subordinate permissions to at least one subordinate associated user for the application account is executed, it further includes: Based on the primary associated user's permission management instructions for the application account, query the list of associated users who have subordinate permissions for the application account; Based on the permission removal instruction from the primary associated user to the target associated user in the associated user list, the subordinate permissions of the target associated user to the application account are removed.

8. A service processing method, comprising: Get the service processing request sent by the service platform for the associated user; Query the application account of the specific user to whom the associated user belongs within the associated user group; The application account storage is based on the identity information carried in the profile creation request for the specific user submitted by the primary associated user; the specific user does not have the ability to manage the account independently; the account permissions include the primary permissions of the primary associated user who created the application account and the subordinate permissions of the subordinate associated users confirmed by the primary associated user. The subordinate associated user submits a permission authorization request for the application account through a candidate associated user based on the associated user group, and the authorization is confirmed by the main associated user. Based on the account permissions, extract key identity information from the application account that matches the service category carried in the service processing request; The key identity information is returned to the service platform so that service processing for the specific user can be performed based on the key identity information.

9. The service processing method according to claim 8, wherein querying the application account of a specific user whose account permissions have been activated in the associated user group to which the associated user belongs includes: In the associated user group, query at least one candidate specific user for whom the associated user has been granted permission; Read the identity profile of the at least one candidate specific user and send it to the associated user; Obtain the specific user selected by the associated user from the at least one candidate specific user, and determine the application account of the specific user.

10. The service processing method according to claim 8, after the step of returning the key identity information to the service platform to perform service processing for the specific user based on the key identity information, it further includes: Obtain the service processing result returned by the service platform; Query the candidate associated users in the associated user group who have the account permissions for the application account; The service processing result is sent to the candidate associated user.

11. The service processing method according to claim 8, before the step of obtaining the service proxy processing request of the associated user sent by the service platform is executed, it further includes: Obtain the profile creation request for the specific user submitted by the primary associated user; An identity profile of the specific user is created based on the identity information carried in the profile creation request, and an application account is created to store the identity profile. Enable the primary associated user's primary permissions for the application account, so that the primary associated user can access the identity profile when performing service delegation for the specific user.

12. The service processing method according to claim 11, after the step of granting the primary associated user master permissions for the application account, so that the primary associated user can access the identity profile when performing service processing for the specific user, further includes: Obtain permission authorization requests for the application account submitted by candidate associated users based on associated user groups; send authorization reminders to the main associated user based on the permission authorization requests; and determine the candidate associated users as subordinate associated users based on the confirmation instructions submitted by the main associated user based on the authorization reminders. Grant subordinate permissions to at least one subordinate user to the application account, so that each subordinate user can access the identity profile when providing services to the specific user based on the subordinate permissions.

13. The service processing method according to claim 8, further comprising: Obtain the authentication request submitted by the specific user through the application account; Based on the authentication type carried in the authentication request, the authentication information of the specific user is collected; Based on the authentication information, determine whether the specific user meets the authentication conditions corresponding to the authentication type; If so, the application account will be marked as an authenticated account.

14. The service processing method according to claim 13, wherein the identity profile of the specific user is used for permission transfer in the following manner: Obtain the permission transfer request for the identity profile submitted by the primary associated user who has primary permissions to the application account; Verify whether the specific user meets the conditions for independent management of the application account; If so, then remove the primary permissions and subordinate permissions to the application account, and grant the specific user management permissions for the identity profile.

15. An identity file processing device, comprising: The profile creation module is configured to obtain a profile creation request for a specific user submitted by the primary associated user, and create an identity profile for the specific user based on the identity information carried in the profile creation request; the specific user does not have the ability to manage their own account. The master permission activation module is configured to create an application account for the specific user that stores the identity profile, and to grant the main associated user master permissions to the application account. The user identification module is configured to obtain permission authorization requests for the application account submitted by candidate associated users based on associated user groups, send authorization reminders to the main associated user based on the permission authorization requests, and identify the candidate associated users as subordinate associated users according to the confirmation instructions submitted by the main associated user based on the authorization reminders. The subordinate permission activation module is configured to grant subordinate permissions to at least one subordinate associated user for the application account. The primary permission and the subordinate permission are used to extract key identity information that matches the service category from the identity profile when performing service processing for the specific user, so that the service platform can perform service processing for the specific user based on the key identity information.

16. A service processing apparatus, comprising: The request retrieval module is configured to retrieve service requests sent by the service platform for associated users. The account query module is configured to query the application account of a specific user who has opened account permissions in the associated user group to which the associated user belongs; The application account storage is based on the identity information carried in the profile creation request for the specific user submitted by the primary associated user; the specific user does not have the ability to manage the account independently; the account permissions include the primary permissions of the primary associated user who created the application account and the subordinate permissions of the subordinate associated users confirmed by the primary associated user. The subordinate associated user submits a permission authorization request for the application account through a candidate associated user based on the associated user group, and the authorization is confirmed by the main associated user. The information extraction module is configured to extract key identity information matching the service category carried in the service processing request from the application account based on the account permissions. The information return module is configured to return the key identity information to the service platform so as to perform service processing for the specific user based on the key identity information.

17. An identity file processing device, comprising: processor; as well as, A memory configured to store computer-executable instructions, which, when executed, cause the processor to: Obtain a profile creation request for a specific user submitted by the primary associated user, and create an identity profile for the specific user based on the identity information carried in the profile creation request; the specific user does not have the ability to manage their own account. Create an application account for the specific user to store the identity profile, and grant the primary associated user master permissions to the application account; Obtain permission authorization requests for the application account submitted by candidate associated users based on associated user groups; send authorization reminders to the main associated user based on the permission authorization requests; and determine the candidate associated users as subordinate associated users based on the confirmation instructions submitted by the main associated user based on the authorization reminders. Grant subordinate permissions to at least one associated user for the application account. The primary and secondary permissions are used to extract key identity information matching the service category from the identity profile when performing service processing for the specific user, so that the service platform can perform service processing for the specific user based on the key identity information.

18. A service processing device, comprising: processor; as well as, A memory configured to store computer-executable instructions, which, when executed, cause the processor to: Get the service processing request sent by the service platform for the associated user; Query the application account of the specific user to whom the associated user belongs within the associated user group; The application account storage is based on the identity information carried in the profile creation request for the specific user submitted by the primary associated user; the specific user does not have the ability to manage the account independently; the account permissions include the primary permissions of the primary associated user who created the application account and the subordinate permissions of the subordinate associated users confirmed by the primary associated user. The subordinate associated user submits a permission authorization request for the application account through a candidate associated user based on the associated user group, and the authorization is confirmed by the main associated user. Based on the account permissions, extract key identity information from the application account that matches the service category carried in the service processing request; The key identity information is returned to the service platform so that service processing for the specific user can be performed based on the key identity information.

19. A storage medium for storing computer-executable instructions, which, when executed by a processor, perform the following process: Obtain a profile creation request for a specific user submitted by the primary associated user, and create an identity profile for the specific user based on the identity information carried in the profile creation request; the specific user does not have the ability to manage their own account. Create an application account for the specific user to store the identity profile, and grant the primary associated user master permissions to the application account; Obtain permission authorization requests for the application account submitted by candidate associated users based on associated user groups; send authorization reminders to the main associated user based on the permission authorization requests; and determine the candidate associated users as subordinate associated users based on the confirmation instructions submitted by the main associated user based on the authorization reminders. Grant subordinate permissions to at least one associated user for the application account. The primary and secondary permissions are used to extract key identity information matching the service category from the identity profile when performing service processing for the specific user, so that the service platform can perform service processing for the specific user based on the key identity information.

20. A storage medium for storing computer-executable instructions, which, when executed by a processor, perform the following process: Get the service processing request sent by the service platform for the associated user; query, in a group of associated users to which the associated user belongs, an application account of a specific user who opens an account permission of the associated user; The application account storage is based on the identity information carried in the profile creation request for the specific user submitted by the primary associated user; the specific user does not have the ability to manage the account independently; the account permissions include the primary permissions of the primary associated user who created the application account and the subordinate permissions of the subordinate associated users confirmed by the primary associated user. The subordinate associated user submits a permission authorization request for the application account through a candidate associated user based on the associated user group, and the authorization is confirmed by the main associated user. Based on the account permissions, extract key identity information from the application account that matches the service category carried in the service processing request; The key identity information is returned to the service platform so that service processing for the specific user can be performed based on the key identity information.

Citation Information

Patent Citations

  • Security configuration lifecycle account protection for minors

    CN112334895A

  • Family account service processing method and device, electronic equipment and readable storage medium

    CN113971555A