A user data access method and device, computer equipment and storage medium
By generating identification and authorization codes through the session platform, a communication and transmission platform is established between users and third parties, and users are logged out when the access ends. This solves the security risks of user data access between the family health management system and third-party medical institutions, and improves the security and protection of data access.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHENZHEN HAIZHICHUANG TECH CO LTD
- Filing Date
- 2022-11-11
- Publication Date
- 2026-05-12
AI Technical Summary
In existing technologies, there are security risks in the access control of user data between family health management systems and third-party medical institutions. Third-party medical institutions may illegally access user privacy data and require multiple user authorizations, resulting in poor data security protection.
The system obtains user data information authorized by the user and access request information from third parties through the session platform, generates identification codes and authorization codes, establishes a communication and transmission platform between the user and the third party, and cancels the identification codes and authorization codes and closes the session platform when the access ends, thus ensuring the security of data access.
This approach ensures that third parties can access user data normally while improving the security of user data and avoiding issues such as unauthorized access and multiple authorizations.
Smart Images

Figure CN116032528B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology, and in particular to a user data access method, apparatus, computer equipment, storage medium, and computer program product. Background Technology
[0002] The family health management system connects with professional medical institutions, which then provide users with online consultations and health advice. During the consultation, users describe their symptoms and needs to the professional medical institution, which can then request access to the user's health and exercise data to provide more scientific diagnostic services.
[0003] Existing technologies primarily rely on user authorization access control between cloud platforms. After a family health system establishes a partnership with a third-party medical institution's system, a unique third-party business identifier (AppID) and access key (AuthorizationKey) are assigned to the third-party medical institution. When the third-party medical institution's system needs to access the user's personal privacy data (health and exercise data), it must redirect to a user authorization page. After the user clicks "agree" on the authorization page, a code and access token are generated. The third-party medical institution's system then uses the AppID, AuthorizationKey, and access token to request access to the user's personal privacy data (health and exercise data). The authorization management service controls access to the access token according to configured policies, such as single-time authorization, permanent authorization, or authorization within a certain time period. This access control strategy has certain shortcomings or security vulnerabilities. For example, the third-party medical institution's system could unauthorize the user's privacy data after the user's consultation; or the third-party medical institution's system might require multiple user authorizations, resulting in poor security protection for user data when accessing user data. Summary of the Invention
[0004] Therefore, it is necessary to provide a user data access method, apparatus, computer device, computer-readable storage medium, and computer program product to address the aforementioned technical problems.
[0005] Firstly, this application provides a method for accessing user data. The method includes:
[0006] Obtain user data information authorized by the user, as well as access request information from third parties; the access request information is the identifier of the target user data information requested by the third party to access the user.
[0007] Through the session platform, the target user data information is selected from the user data information according to the target user data information identifier, and the identification code of the target user data information and the authorization code for accessing the target user data information are generated.
[0008] Access the user's target user data information based on the identification code and the authorization code;
[0009] In response to the user's action of closing the session platform, the identification code and the authorization code are deactivated, and the session platform is closed.
[0010] Optionally, obtaining user data information authorized by the user and access request information from third parties includes:
[0011] Obtain the access request information from the third party; the access request information includes the identity information of the third party;
[0012] The identity information of the third party is transmitted to the user, and in response to the user's authorization operation, the user's authorized user data information is obtained.
[0013] Optionally, the user data information includes the user's address information, and the third party's access request information includes the third party's address information. After obtaining the user's authorized user data information and the third party's access request information, the process includes:
[0014] Based on the user's address information and the third party's address information, a communication transmission platform is established between the user and the third party;
[0015] The communication transmission platform is encrypted, and access identification information is generated between the user and the communication transmission platform, and between the third party and the communication platform, to obtain the session platform between the user and the third party; the access identification information is used to identify the user and the third party, and to enable the user and the third party to access the communication transmission platform.
[0016] Optionally, the step of selecting target user data information from the user data information through the session platform based on the target user data information identifier, and generating an identification code for the target user data information and an authorization code for accessing the target user data information, includes:
[0017] Through the conversation platform, based on the target user data information identifier of the third party, the user data information corresponding to the target user data information identifier is selected from the user data information of the user to obtain the target user data information;
[0018] An identification identifier is added to each target user data information to obtain an identification identifier for each target user data information, and an identification code corresponding to each identification identifier is established to obtain an identification code for each target user data information;
[0019] The target user data information is encrypted, and an authorization code corresponding to the target user data information is generated; the authorization code is used to access the target user data information.
[0020] Optionally, accessing the user's target user data information based on the identification code and the authorization code includes:
[0021] Based on the authorization code, it is determined whether the third party can access the user data information;
[0022] If the third party has access to the user data information, the target user data information can be retrieved on the session platform based on the identification code.
[0023] Optionally, the step of deregistering the identification code and the authorization code, and closing the session platform in response to the user's operation of closing the session platform, includes:
[0024] In response to the user's action of closing the session platform, obtain the user's cancellation authorization information and send a service termination prompt message to the user and the third party;
[0025] Based on the cancellation authorization information, cancel the identification code and the authorization code, and close the session platform.
[0026] Secondly, this application also provides a user data access device. The device includes:
[0027] The acquisition module is used to acquire user data information authorized by the user and access request information from third parties; the access request information is the identifier of the target user data information requested by the third party to access the user.
[0028] The generation module is used to select target user data information from the user data information based on the target user data information identifier through the session platform, and generate an identification code for the target user data information and an authorization code for accessing the target user data information.
[0029] The access module is used to access the user's target user data information based on the identification code and the authorization code;
[0030] The logout module is used to log out the identification code and the authorization code in response to the user's operation of closing the session platform, and to close the session platform.
[0031] Optionally, the acquisition module is specifically used for:
[0032] Obtain the access request information from the third party; the access request information includes the identity information of the third party;
[0033] The identity information of the third party is transmitted to the user, and in response to the user's authorization operation, the user's authorized user data information is obtained.
[0034] Optionally, the user data information includes the user's address information, and the third party's access request information includes the third party's address information. The device further includes:
[0035] A module is established to establish a communication transmission platform between the user and the third party based on the user's address information and the third party's address information.
[0036] An encryption module is used to encrypt the communication transmission platform and generate access identification information between the user and the communication transmission platform, and between the third party and the communication platform, to obtain the session platform between the user and the third party; the access identification information is used to identify the user and the third party, and to enable the user and the third party to access the communication transmission platform.
[0037] Optionally, the generation module is specifically used for:
[0038] Through the conversation platform, based on the target user data information identifier of the third party, the user data information corresponding to the target user data information identifier is selected from the user data information of the user to obtain the target user data information;
[0039] An identification identifier is added to each target user data information to obtain an identification identifier for each target user data information, and an identification code corresponding to each identification identifier is established to obtain an identification code for each target user data information;
[0040] The target user data information is encrypted, and an authorization code corresponding to the target user data information is generated; the authorization code is used to access the target user data information.
[0041] Optionally, the access module is specifically used for:
[0042] Based on the authorization code, it is determined whether the third party can access the user data information;
[0043] If the third party has access to the user data information, the target user data information can be retrieved on the session platform based on the identification code.
[0044] Optionally, the cancellation module is specifically used for:
[0045] In response to the user's action of closing the session platform, obtain the user's cancellation authorization information and send a service termination prompt message to the user and the third party;
[0046] Based on the cancellation authorization information, cancel the identification code and the authorization code, and close the session platform.
[0047] Thirdly, this application provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the method described in any one of the first aspects.
[0048] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the steps of the method described in any one of the first aspects.
[0049] Fifthly, this application provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the steps of the method described in any one of the first aspects.
[0050] The aforementioned user data access method, apparatus, computer equipment, and storage medium acquire user data information authorized by the user and access request information from a third party. The access request information is an identifier of the target user data information requested by the third party to access the user. Through a session platform, target user data information is selected from the user data information based on the target user data information identifier, and an identification code and an authorization code for accessing the target user data information are generated. The target user data information is accessed based on the identification code and the authorization code. In response to the user closing the session platform, the identification code and the authorization code are deactivated, and the session platform is closed. By establishing a user data access channel through the session platform and closing the session platform upon termination of user data access, unauthorized access to user data information by third parties is prevented. This ensures that third parties can access user data information normally while improving the security of user data access. Attached Figure Description
[0051] Figure 1 This is an application environment diagram of a user data access method in one embodiment;
[0052] Figure 2 This is a flowchart illustrating a user data access method in one embodiment;
[0053] Figure 3 This is a flowchart illustrating an example of user data access in one embodiment;
[0054] Figure 4 This is a structural block diagram of a user data access device in one embodiment;
[0055] Figure 5 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0056] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0057] The user data access method provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, the terminal communicates with a cloud-based home health management system. This system, in turn, communicates with a professional medical institution system (a third party) and a home control network (the user). The home control network transmits user data to the system via multiple user data transmission devices. These devices can be, but are not limited to, smart blood pressure monitors, smart blood glucose meters, smart treadmills, smart rehabilitation machines, and smart sleep bags. The terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, and tablets. The server 104 can be a standalone server or a server cluster. The terminal establishes a user data access channel through a session platform and closes the platform upon termination of user data access, preventing unauthorized access to user data by third parties. This ensures that third parties can access user data normally while enhancing the security of user data access.
[0058] In one embodiment, such as Figure 2 As shown, a user data access method is provided. Taking the application of this method to a terminal as an example, the method includes the following steps:
[0059] Step S201: Obtain user data information authorized by the user and access request information from third parties.
[0060] The access request information is the identifier of the target user data information of the user to whom the third party requests access.
[0061] In this embodiment, the terminal responds to the user's authorization operation, obtains the user data information authorized by the user, and obtains the access information requested by the third party by accepting the application information of the third party. The third party can be any third-party user that meets the above requirements. The third-party user can be a service provider user, a business consulting user, a transaction user, etc.
[0062] For example, if the third party is a third-party medical institution's system, when a user accesses the third-party medical institution's system, they are redirected to the user authorization service module. The user authorization service module generates a user authorization page, prompting the user to request access to the third-party platform's personal privacy data category. With the user's consent, the terminal connects to various smart health devices in the home through the home health management system using a home control gateway, including smart blood pressure monitors, smart blood glucose meters, smart treadmills, smart rehabilitation machines, smart sleep belts, etc. The home control gateway connects to the cloud-based home health management system. The smart health devices collect the user's physical health, exercise, and rehabilitation data, and send the data to the home control gateway. The home control gateway then sends the data to the cloud-based home health system, thereby obtaining the user's data information.
[0063] Step S202: Through the session platform, select the target user data information based on the target user data information identifier in the user data information, and generate the identification code of the target user data information and the authorization code for accessing the target user data information.
[0064] In this embodiment, after acquiring user data information and access request information, the terminal establishes a session platform. Based on the target user data information identifier in the access request information, it queries the target user data information from the aggregated user data, adds an identification code to each target user data information, and generates an authorization code for accessing each target user data information. The session platform is a communication platform capable of providing two-way data transmission and can only save transmitted data while running. When access to the session platform is closed, neither users nor third parties can log in to the session platform or retrieve its data information. Furthermore, the session platform only allows access to users authorized by the session platform and third parties authorized by the session platform.
[0065] Step S203: Access the user's target user data information based on the identification code and the authorization code.
[0066] In this embodiment, the terminal determines whether the third party can access user data information based on the authorization code transmitted by the third party. If the third party can access the user data information, the terminal retrieves the target user data information of that user from the session platform based on the identification code. The specific access process will be described in detail later.
[0067] For example, the terminal uses a session platform to identify the authorization code in the session text transmitted to the session platform by a professional medical institution system (i.e., a third party), determines whether the professional medical institution system can access the user's user data information, and if the professional medical institution system can access the user's user data information, the terminal uses the session platform to identify the identification code in the session text transmitted to the session platform by the professional medical institution system, and retrieves the target user data information corresponding to the identification code in the user's user data information through the cloud-based Jiating Health Management System, and transmits the target user data information to the professional medical institution system through the session platform, so that the professional medical institution system can obtain the user's target user data information.
[0068] Specifically, the establishment of a session can be a remote online consultation service for family health management. The family health management system connects with professional medical institutions, which then provide users with online consultations and health advice. During the consultation, users describe their symptoms and consultation needs to the professional medical institutions. The professional medical institutions can then request access to the user's health and exercise data from third parties to provide more scientific diagnostic services based on this data.
[0069] In other embodiments, a conversation is established during a user's consultation with a professional medical institution. Keywords from this conversation are automatically read, and through automatic keyword identification and analysis, the necessary third-party stored user data is automatically retrieved. For example, if a user mentions "my blood sugar has been abnormal lately," and the keyword "blood sugar" is identified, the platform automatically retrieves the user's blood sugar data from a smart blood glucose meter. Since a single blood sugar reading may not provide sufficient information for the doctor, the platform automatically retrieves the user's blood pressure data from a smart blood pressure monitor, providing the doctor with comprehensive diagnostic data for a more scientific and efficient diagnostic service. In other embodiments, various types of user data can be automatically retrieved depending on the user's specific symptoms.
[0070] In step S204, in response to the user's operation of closing the session platform, the identification code and authorization code are deregistered, and the session platform is closed.
[0071] In this embodiment, in response to the user's action of closing the session platform, the terminal refuses the user and third parties further access to the session platform and deletes the cached data of the user and third parties on the session platform. Finally, the terminal cancels the identification code and authorization code, completing this user data access process.
[0072] Based on the above solution, a user data access channel is established through a session platform, and the session platform is closed when the user data access ends, thus preventing third parties from illegally accessing user data. This ensures that third parties can access user data normally while improving the security of user data when accessing user data.
[0073] Optionally, obtaining user data information authorized by the user and access request information from a third party includes: obtaining access request information from a third party; the access request information includes the identity information of the third party; transmitting the identity information of the third party to the user, and in response to the user's authorization operation, obtaining user data information authorized by the user.
[0074] In this embodiment, the terminal obtains access request information transmitted by a third party. This access request information includes the third party's identity information. The terminal transmits this third party's identity information to the user and, in response to the user's authorization, obtains the user's authorized user data information. The third party's identity information includes the third party's platform verification information, the third party's personal ID, and the third party's identity verification information. After receiving the third party's identity information, the terminal can transmit this information to the user's client through encrypted transmission or by creating a one-way data transmission channel.
[0075] Based on the above scheme, the terminal obtains user data information authorized by the user by sending the identity information of a third party to the user, ensuring that the third party authorized by the user is the target third party selected by the user, thereby improving the security protection of user data information.
[0076] Optionally, the user data information includes the user's address information, and the third party's access request information includes the third party's address information. After obtaining the user's authorized user data information and the third party's access request information, the process includes: establishing a communication transmission platform between the user and the third party based on the user's address information and the third party's address information; encrypting the communication transmission platform and generating access identification information between the user and the communication transmission platform, and between the third party and the communication platform, to obtain a session platform between the user and the third party; the access identification information is used to identify the user and the third party, and to enable the user and the third party to access the communication transmission platform.
[0077] In this embodiment, the terminal establishes a communication data transmission channel between the user and the third party based on the user's address information and the third party's address information, and uses this communication data transmission channel as a communication transmission platform. The terminal encrypts the communication transmission platform using a data encryption algorithm and generates access identification information between the user and the communication transmission platform, and between the third party and the communication platform, thus obtaining a session platform between the user and the third party. The access identification information is used to identify the user and the third party, enabling them to access the communication transmission platform. The data encryption algorithm can be, but is not limited to, any algorithm that satisfies the above steps.
[0078] Based on the above solution, by generating access identification information and establishing a session platform, it is ensured that the session platform can only identify the user and the third-party platform, thereby improving the security protection of the user's data information.
[0079] Optionally, through a session platform, target user data information is selected from the user data information based on the target user data information identifier, and an identification code and an authorization code for accessing the target user data information are generated. This includes: selecting the user data information corresponding to the target user data information identifier from the user's user data information based on the third party's target user data information identifier through the session platform; adding an identification identifier to each target user data information to obtain the identification identifier for each target user data information, and establishing an identification code corresponding to each identification identifier to obtain the identification code for each target user data information; encrypting each target user data information and generating an authorization code corresponding to the target user data information; the authorization code is used to access the target user data information.
[0080] In this embodiment, the terminal, through a session platform, selects the user data information corresponding to the target user data information identifier from the user's user data information based on the third party's target user data information identifier, thereby obtaining the target user data information. For each target user data information, the terminal adds an identification identifier, affixing it to each piece of target user data information, and obtaining the identification identifier for each target user data information based on each identifier and its corresponding identification code. Similarly, through the above steps, the terminal obtains the identification identifier for each target user data information. The terminal establishes an identification code corresponding to each identification identifier, obtaining the identification code for each target user data information. The terminal encrypts each target user data information and generates an authorization code corresponding to that target user data information. The authorization code is used to access the target user data information.
[0081] Based on the above scheme, by using identification codes and authorization codes, the extent to which third parties can access user data information is restricted, thereby improving the security protection of user data information.
[0082] Optionally, the user's target user data information can be accessed based on the identification code and the authorization code, including: determining whether a third party can access the user data information based on the authorization code; and if the third party can access the user data information, retrieving the target user data information on the session platform based on the identification code.
[0083] In this embodiment, in response to an authorization operation from a third party, the terminal obtains the identification code and authorization code transmitted by the third party, and determines whether the third party can access the user's user data information based on the authorization code. If the authorization code cannot access the user's user data information, the terminal refuses the third party's access and sends a text message such as "Authorization failed, access unavailable" to the third party's display. If the authorization code can access the user's user data information, the terminal searches the user's user data information for a target user data information corresponding to the identification code. If no target user data information corresponding to the identification code is found in the user's user data information, the terminal refuses the third party's access and sends a text message such as "Query unsuccessful" to the third party's display. If target user data information corresponding to the identification code is found in the user's user data information, the terminal sends the target user data information corresponding to the identification code to the third party.
[0084] Based on the above scheme, the identity of third parties is verified through multiple methods, including authorization codes and identification codes, and their access permissions are restricted to prevent third parties from obtaining all user data information, thereby further improving the security of user data information.
[0085] Optionally, the method of canceling the identification code and authorization code and closing the session platform in response to the user's operation of closing the session platform includes: obtaining the user's cancellation authorization information and sending a service termination prompt message to the user and third parties in response to the user's operation of closing the session platform; canceling the identification code and authorization code and closing the session platform according to the cancellation authorization information.
[0086] In this embodiment, in response to the user's operation to close the session platform, the terminal obtains the user's logout authorization information and sends a service termination prompt to the user and the third party. Based on the logout authorization information, the terminal cancels the identification code and authorization code of the target user data information, and closes the session platform, completing the access process for the user data information. After closing the session platform, neither the user nor the third party can log in to the session platform again or retrieve the previously transmitted target user data information from it.
[0087] Based on the above solution, by closing the session platform and canceling the authorization code and identification code after completing the user data access process, the security protection of user data information is improved by preventing third parties from accessing the platform multiple times to obtain target user data information.
[0088] This application also provides an example of user data access, such as Figure 3 As shown, the specific processing procedure includes the following steps:
[0089] Step S301: Obtain access request information from a third party.
[0090] In step S302, the identity information of the third party is transmitted to the user, and in response to the user's authorization operation, the user's authorized user data information is obtained.
[0091] Step S303: Based on the user's address information and the third party's address information, establish a communication transmission platform between the user and the third party.
[0092] Step S304: Encrypt the communication transmission platform and generate access identification information between the user and the communication transmission platform, as well as between the third party and the communication platform, to obtain the session platform between the user and the third party.
[0093] Step S305: Through the session platform, based on the target user data information identifier of the third party, select the user data information corresponding to the target user data information identifier from the user's user data information to obtain the target user data information.
[0094] Step S306: Add identification identifiers to each target user data information to obtain identification identifiers for each target user data information, and establish identification codes corresponding to each identification identifier to obtain identification codes for each target user data information.
[0095] Step S307: Encrypt the data information of each target user and generate an authorization code corresponding to the target user data information.
[0096] Step S308: Through the session platform, based on the target user data information identifier of the third party, select the user data information corresponding to the target user data information identifier from the user's user data information to obtain the target user data information.
[0097] Step S309: Add identification identifiers to each target user data information to obtain identification identifiers for each target user data information, and establish an identification code corresponding to each identification identifier to obtain the identification code for each target user data information.
[0098] Step S310: Encrypt the data information of each target user and generate an authorization code corresponding to the target user data information.
[0099] Step S311: Determine whether the third party can access user data information based on the authorization code.
[0100] Step S312: If a third party can access user data information, retrieve the target user data information on the session platform based on the identification code.
[0101] Step S313: In response to the user's operation of closing the session platform, obtain the user's cancellation authorization information and send a service termination prompt message to the user and third parties.
[0102] Step S314: Based on the deregistration authorization information, deregister the identification code and authorization code, and close the session platform.
[0103] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0104] Based on the same inventive concept, this application also provides a user data access device for implementing the user data access method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more user data access device embodiments provided below can be found in the limitations of the user data access method described above, and will not be repeated here.
[0105] In one embodiment, such as Figure 4 As shown, a user data access device is provided, including: an acquisition module 410, a generation module 420, an access module 430, and a logout module 440, wherein:
[0106] The acquisition module 410 is used to acquire user data information authorized by the user and access request information from a third party; the access request information is the identifier of the target user data information requested by the third party to access the user.
[0107] The generation module 420 is used to select target user data information from the user data information based on the target user data information identifier through the session platform, and generate an identification code for the target user data information and an authorization code for accessing the target user data information.
[0108] Access module 430 is used to access the user's target user data information based on the identification code and the authorization code;
[0109] The deregistration module 440 is used to deregister the identification code and the authorization code and close the session platform in response to the user's operation of closing the session platform.
[0110] Optionally, the acquisition module 410 is specifically used for:
[0111] Obtain the access request information from the third party; the access request information includes the identity information of the third party;
[0112] The identity information of the third party is transmitted to the user, and in response to the user's authorization operation, the user's authorized user data information is obtained.
[0113] Optionally, the user data information includes the user's address information, and the third party's access request information includes the third party's address information. The device further includes:
[0114] A module is established to establish a communication transmission platform between the user and the third party based on the user's address information and the third party's address information.
[0115] An encryption module is used to encrypt the communication transmission platform and generate access identification information between the user and the communication transmission platform, and between the third party and the communication platform, to obtain the session platform between the user and the third party; the access identification information is used to identify the user and the third party, and to enable the user and the third party to access the communication transmission platform.
[0116] Optionally, the generation module 420 is specifically used for:
[0117] Through the conversation platform, based on the target user data information identifier of the third party, the user data information corresponding to the target user data information identifier is selected from the user data information of the user to obtain the target user data information;
[0118] An identification identifier is added to each target user data information to obtain an identification identifier for each target user data information, and an identification code corresponding to each identification identifier is established to obtain an identification code for each target user data information;
[0119] The target user data information is encrypted, and an authorization code corresponding to the target user data information is generated; the authorization code is used to access the target user data information.
[0120] Optionally, the access module 430 is specifically used for:
[0121] Based on the authorization code, it is determined whether the third party can access the user data information;
[0122] If the third party has access to the user data information, the target user data information can be retrieved on the session platform based on the identification code.
[0123] Optionally, the deregistration module 440 is specifically used for:
[0124] In response to the user's action of closing the session platform, obtain the user's cancellation authorization information and send a service termination prompt message to the user and the third party;
[0125] Based on the cancellation authorization information, cancel the identification code and the authorization code, and close the session platform.
[0126] Each module in the aforementioned user data access device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can invoke and execute the operations corresponding to each module.
[0127] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 5As shown, the computer device includes a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a user data access method. The display screen can be an LCD screen or an e-ink display screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad located on the computer device's casing, or an external keyboard, touchpad, or mouse.
[0128] Those skilled in the art will understand that Figure 4 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0129] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.
[0130] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps in the above-described method embodiments.
[0131] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above-described method embodiments.
[0132] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0133] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0134] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0135] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for accessing user data, characterized in that, The method includes: Obtain user data information authorized by the user, as well as access request information from third parties; the access request information is the identifier of the target user data information requested by the third party to access the user. Through the session platform, the target user data information is selected from the user data information according to the target user data information identifier, and the identification code of the target user data information and the authorization code for accessing the target user data information are generated. Access the user's target user data information based on the identification code and the authorization code; In response to the user's action of closing the session platform, the identification code and the authorization code are deactivated, and the session platform is closed; The user data information includes the user's address information, and the third party's access request information includes the third party's address information. After obtaining the user's authorized user data information and the third party's access request information, the process includes: establishing a communication transmission platform between the user and the third party based on the user's address information and the third party's address information; encrypting the communication transmission platform and generating access identification information between the user and the communication transmission platform, and between the third party and the communication transmission platform, to obtain a session platform between the user and the third party; the access identification information is used to identify the user and the third party, and to enable the user and the third party to access the communication transmission platform.
2. The method according to claim 1, characterized in that, The acquisition of user data information authorized by the user and access request information from third parties includes: Obtain the access request information from the third party; the access request information includes the identity information of the third party; The identity information of the third party is transmitted to the user, and in response to the user's authorization operation, the user's authorized user data information is obtained.
3. The method according to claim 1, characterized in that, The step of selecting target user data information from the user data information through the session platform based on the target user data information identifier, and generating an identification code for the target user data information and an authorization code for accessing the target user data information, includes: Through the conversation platform, based on the target user data information identifier of the third party, the user data information corresponding to the target user data information identifier is selected from the user data information of the user to obtain the target user data information; An identification identifier is added to each target user data information to obtain an identification identifier for each target user data information, and an identification code corresponding to each identification identifier is established to obtain an identification code for each target user data information; The target user data information is encrypted, and an authorization code corresponding to the target user data information is generated; the authorization code is used to access the target user data information.
4. The method according to claim 1, characterized in that, The step of accessing the user's target user data information based on the identification code and the authorization code includes: Based on the authorization code, it is determined whether the third party can access the user data information; If the third party has access to the user data information, the target user data information can be retrieved on the session platform based on the identification code.
5. The method according to claim 1, characterized in that, The step of responding to the user's action of closing the session platform, deregistering the identification code and the authorization code, and closing the session platform includes: In response to the user's action of closing the session platform, obtain the user's cancellation authorization information and send a service termination prompt message to the user and the third party; Based on the cancellation authorization information, cancel the identification code and the authorization code, and close the session platform.
6. A user data access device, employing the method as described in claim 1, characterized in that, The device includes: The acquisition module is used to acquire user data information authorized by the user and access request information from third parties; the access request information is the identifier of the target user data information requested by the third party to access the user. The generation module is used to select target user data information from the user data information based on the target user data information identifier through the session platform, and generate an identification code for the target user data information and an authorization code for accessing the target user data information. The access module is used to access the user's target user data information based on the identification code and the authorization code; The logout module is used to log out the identification code and the authorization code in response to the user's operation of closing the session platform, and to close the session platform.
7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 5.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.