Personal sensitive data authorization acquisition method and device, electronic equipment and storage medium

By combining a unified identity authentication platform with biometric data entry devices, and using a signature encryption mechanism to verify and authorize user identities online, the problem of unauthorized access to sensitive data interfaces after a business application system is compromised is solved, thus achieving secure protection of user data and stable processing under high concurrency environments.

CN116383866BActive Publication Date: 2026-07-24DIGITAL GUANGDONG NETWORK CONSTR CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
DIGITAL GUANGDONG NETWORK CONSTR CO LTD
Filing Date
2023-01-28
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

In existing technologies, once a business application system is compromised by hackers, the sensitive data interfaces of the government big data sharing platform can be accessed without authorization, leading to security risks.

Method used

By using a unified identity authentication platform to collect users' biometric features through biometric input devices, generating encrypted signature information and signing it with a private key, combined with a public key encryption mechanism, the platform enables online verification and authorization of users' identities, ensuring secure access to the data sharing platform.

Benefits of technology

It enables rapid online verification of user identity, builds a complete identity authentication and authorization chain, protects user data privacy and security, reduces the security risk of unauthorized access to interfaces, and adapts to the processing needs of high-concurrency environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116383866B_ABST
    Figure CN116383866B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses a kind of personal sensitive data authorization acquisition methods, belong to authentication authorization technical field.The method includes: in response to the access request initiated by user to business application system, biological characteristic collection and verification are carried out to user by preset biological characteristic input device using unified identity authentication platform;After verification, signature encryption information and random code are obtained from biological characteristic input device;According to signature encryption information and random code, basic information and first encrypted message are obtained from unified identity authentication platform;First encrypted message is decrypted using biological characteristic input device to obtain second encrypted message;And the personal sensitive data of user is obtained from data sharing platform using second encrypted message and basic information.The embodiment of the present application can quickly carry out online verification of user identity, and more effectively protect the security of sensitive data of user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of authentication and authorization technology, and in particular to a method, apparatus, electronic device, and storage medium for authorized acquisition of personal sensitive data. Background Technology

[0002] When processing transactions through a business application system, the system needs to obtain sensitive personal information such as electronic certificates and health codes from the government big data sharing platform. Current technology uses the business application system to control the collection of biometric features, such as facial recognition, for user authorization confirmation, while the data sharing platform manages interface calls through application identity authentication. If the business application system is compromised by hackers, it could directly access the government big data sharing platform's interfaces to obtain sensitive user data without facial recognition authorization, creating security risks such as unauthorized access to sensitive data. Summary of the Invention

[0003] This invention provides a method, apparatus, electronic device, and storage medium for authorizing the acquisition of personal sensitive data. It can authorize the acquisition of personal sensitive data by a business application system from a data sharing platform based on the collected user biometric features by using a biometric data entry device storing public and private key pairs. This enables rapid online verification of user identity and more effectively protects the security of users' sensitive data.

[0004] In a first aspect, embodiments of the present invention provide a method for authorized acquisition of personal sensitive data, comprising: responding to a user's access request to a business application system, collecting and verifying the user's biometric features using a preset biometric input device through a unified identity authentication platform; after successful verification, obtaining signature encryption information and a random code from the biometric input device, wherein the signature encryption information includes a signature encryption string obtained by encrypting the random code using the biometric input device and signing the encrypted random code using a private key stored in the biometric input device; based on the signature encryption information and the random code, obtaining the user's basic information and a first encrypted message provided after authentication and authorization of the business application system using a public key corresponding to the private key from the unified identity authentication platform; encrypting a second encrypted message using the public key to obtain the first encrypted message, wherein the second encrypted message includes the encrypted user's basic information; decrypting the first encrypted message using the biometric input device to obtain the second encrypted message; and obtaining the user's personal sensitive data from a data sharing platform using the second encrypted message and the basic information.

[0005] Secondly, embodiments of the present invention provide a personal sensitive data authorization acquisition device, comprising: a collection module, configured to respond to a user's access request to a business application system, and collect and verify the user's biometric features using a preset biometric feature input device through a unified identity authentication platform; a first acquisition module, configured to, after successful verification, acquire signature encryption information and a random code from the biometric feature input device, wherein the signature encryption information includes a signature encryption string obtained by encrypting the random code by the biometric feature input device and signing the encrypted random code using a private key stored in the biometric feature input device; a second acquisition module, configured to, based on the signature encryption information and the random code, acquire basic information of the user provided after authentication and authorization of the business application system using a public key corresponding to the private key and a first encrypted message from the unified identity authentication platform; the first encrypted message is obtained by encrypting a second encrypted message using the public key, wherein the second encrypted message includes the encrypted basic information of the user; a decryption module, configured to decrypt the first encrypted message using the biometric feature input device to obtain the second encrypted message; and a third acquisition module, configured to acquire the user's personal sensitive data from a data sharing platform using the second encrypted message and the basic information.

[0006] Thirdly, embodiments of the present invention also provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the personal sensitive data authorization acquisition method as described in any of the embodiments of the present invention.

[0007] Fourthly, embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method for authorized acquisition of personal sensitive data as described in any of the embodiments of the present invention.

[0008] This invention provides a method, apparatus, electronic device, and storage medium for authorized acquisition of personal sensitive data. It utilizes a biometric data entry device storing a private key and the user's real biometric features through a unified identity authentication platform. Based on the user's biometric features collected when logging into the business application system, it re-authorizes the business application system's acquisition of personal sensitive data from the data sharing platform. This enables rapid online verification of user identity, constructing a complete business chain of identity authentication and user authorization. Security is ensured through user signature authorization and encryption mechanism protection, protecting interface-level privilege escalation security and user data privacy. Furthermore, considering the data sharing platform's role as a public support service, it requires high-concurrency processing capabilities. Attached Figure Description

[0009] Figure 1 This is a flowchart illustrating a method for authorizing the acquisition of personal sensitive data provided in an embodiment of the present invention;

[0010] Figure 2 This is another flowchart illustrating the method for authorized acquisition of personal sensitive data provided in this embodiment of the invention;

[0011] Figure 3 This is a schematic diagram of a personal sensitive data authorization acquisition device provided in an embodiment of the present invention;

[0012] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0013] When processing transactions through a business application system, the system needs to obtain sensitive personal information such as electronic certificates and health codes from the government big data sharing platform. Current technology uses the business application system to control the collection of biometric features, such as facial recognition, for user authorization confirmation, while the data sharing platform manages interface calls through application identity authentication. If the business application system is compromised by hackers, it could directly access the government big data sharing platform's interfaces to obtain sensitive user data without facial recognition authorization, creating security risks such as unauthorized access to sensitive data.

[0014] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present invention, and not all of the structures.

[0015] Figure 1 This is a flowchart illustrating a method for authorized acquisition of sensitive human data provided in an embodiment of the present invention. This method can be executed by a device for authorized acquisition of sensitive human data provided in this embodiment, which can be implemented in software and / or hardware. In a specific embodiment, the device can be integrated into an electronic device, such as a computer or server. The following embodiments will illustrate this using the integration of the device into an electronic device as an example. (Reference) Figure 1 The method may specifically include the following steps:

[0016] Step 101: In response to the user's access request to the business application system, the user's biometric features are collected and verified through the unified identity authentication platform using a preset biometric input device.

[0017] Specifically, the above-mentioned user verification also authorizes the biometric data entry device. This ensures that the user is a genuine and legitimate user and facilitates the use of genuine and legitimate authorized biometric data entry devices to authenticate and authorize the process by which business application systems obtain sensitive personal data from the data sharing platform.

[0018] Specifically, the aforementioned business application systems can be government business application systems, and the aforementioned unified identity authentication platform can be a provincial unified identity authentication platform.

[0019] Specifically, the aforementioned business application systems and data sharing platforms can be integrated using the OAuth2 specification.

[0020] Specifically, the process of responding to a user's access request to the business application system and using a preset biometric input device through the unified identity authentication platform to collect and verify the user's biometric features may include the following: after the user enters the URL of the business application system and opens the webpage, a "Digital Key Authentication" selection button pops up on the page. After clicking to select "Digital Key Authentication", the business application system jumps to the unified identity authentication platform. The unified identity authentication platform calls the local driver of the biometric input device and activates the biometric input device to collect and verify the user's fingerprint.

[0021] Optionally, the process of collecting and verifying a user's biometric features using a pre-set biometric data entry device includes: collecting a first biometric feature to be verified from the user using the biometric data entry device; and verifying the user's identity based on the user's real biometric features pre-stored in the biometric data entry device and the first biometric feature to be verified. This allows the use of a biometric data entry device that has been pre-authenticated and stores the biometric features of real users to verify whether the user initiating the access request is a genuine and legitimate user based on real-time collected biometric features.

[0022] Specifically, the aforementioned biometrics can be a user's fingerprints, palm prints, finger veins, palm veins, face, iris, signature, or voice, etc.

[0023] Preferably, the aforementioned biometric input device can be a fingerprint mouse.

[0024] In practical applications, the aforementioned pre-set biometric data entry device can be obtained by users after their identity has been verified by on-site staff at the offline service hall of the digital government. The application process involves inputting the user's biometric information into the device, and generating a public-private key pair via the SE security chip within the device. The private key, located in the security chip of the fingerprint mouse and inaccessible externally, only provides encryption, decryption, and signature capabilities. The public key is provided securely to the unified identity authentication platform supporting the digital government's public capabilities and bound to the user's account. Specifically, after receiving the biometric data entry device, the user connects it to their preferred personal computer, and the device automatically installs the driver.

[0025] Step 102: After successful verification, the signature encryption information and random code are obtained from the biometric data entry device. The signature encryption information includes a signature encryption string obtained by encrypting the random code using the biometric data entry device and signing the encrypted random code using the private key stored in the biometric data entry device. Step 102 enables the retrieval of the user's basic information and the first encrypted message from the unified identity authentication platform based on the signature encryption information and the random code.

[0026] In an optional embodiment of the present invention, the aforementioned signature encryption information includes a signature device number obtained by signing the serial number information of the aforementioned biometric data entry device using the aforementioned private key. This facilitates the acquisition of the user's basic information and the first encrypted message from the unified identity authentication platform based on the signature device number information.

[0027] Optionally, the aforementioned signature encryption information may also include signed device identification information obtained by signing other device identification information of the aforementioned biometric data entry device using the aforementioned private key.

[0028] In an optional specific embodiment of the present invention, the process of obtaining the user's basic information and the first encrypted message provided after authenticating and authorizing the business application system using the public key corresponding to the private key from the unified identity authentication platform based on the signature encryption information and the random code includes: adding the identification mark of the business application system to the random code to obtain a marked random code; and obtaining the user's basic information and the first encrypted message provided after authenticating and authorizing the business application system using the public key corresponding to the private key from the unified identity authentication platform based on the signature encryption information and the marked random code.

[0029] Specifically, the aforementioned random code can be a random challenge code string.

[0030] In an optional specific embodiment of the present invention, after successful verification, the biometric data entry device obtains authorization from a genuine and legitimate user. The biometric data entry device can locally generate and encrypt a random challenge code string, then add information such as the mouse device number to the encrypted random challenge code string, and sign it using the private key of the biometric data entry device.

[0031] Step 103: Based on the signature encryption information and the random code, obtain the user's basic information and the first encrypted message provided after authentication and authorization of the business application system using the public key corresponding to the private key from the unified identity authentication platform. The first encrypted message is used to encrypt a second encrypted message using the public key, and the second encrypted message includes the encrypted user's basic information. This step obtains the user's sensitive personal information from the data sharing platform based on the user's basic information and the second encrypted message decrypted from the first encrypted message.

[0032] Specifically, the basic information of the user mentioned above can include the user's account information and the user's identity information. The identity information can specifically include: the ID number and ID type that identify the user.

[0033] Specifically, when users log in to business application systems, they no longer need to directly enter a password. Instead, they use a pre-set biometric identification device that stores the user's fingerprint information and exclusive private key as an electronic key to retrieve account information and basic user information from the unified identity authentication platform to complete the login process, making it more secure and convenient. Furthermore, logging in and authorizing the access to sensitive user information through the unified identity authentication platform can provide verifiable evidence in the event of information security disputes between business application systems and users, avoiding the risks associated with proof of chain of evidence.

[0034] In an optional specific embodiment of the present invention, the aforementioned public key is obtained by the unified identity authentication platform from the stored data of the unified identity authentication platform based on the signature device number information and the index relationship between the public key stored by the unified identity authentication platform and the device number of the biometric data entry device.

[0035] Optionally, the aforementioned public key can also be obtained by the unified identity authentication platform from its stored data based on the signature device identification information and the index relationship between the public key stored by the unified identity authentication platform and the identification information of the biometric data entry device.

[0036] Specifically, when a user applies for a biometric data entry device, the device's serial number or other identification information can be stored in the unified identity authentication platform and bound to the public key generated by the biometric data entry device and the corresponding user account.

[0037] In an optional specific embodiment of the present invention, the process of obtaining the user's basic information and the first encrypted message provided after authenticating and authorizing the business application system using the public key corresponding to the private key from the unified identity authentication platform based on the signature encryption information and the random code includes: obtaining the user's basic information through the backend interface of the unified identity authentication platform based on the identity authorization code; the identity authorization code is generated by the unified identity authentication platform to authenticate and authorize the business application system by comparing the random code received from the business application system with the random code obtained by verifying and decrypting the signature encryption information using the public key, and is generated after the authentication and authorization are passed.

[0038] In an optional specific embodiment of the present invention, the aforementioned identity authorization code is generated by the unified identity authentication platform by comparing the random code obtained based on the marked random code with the random code obtained by verifying and decrypting the signature encryption information using the public key to authenticate and authorize the business application system, and is generated after the authentication and authorization are passed.

[0039] Optionally, the aforementioned identity authorization code is generated by the unified identity authentication platform after it calls the digital key service platform to authenticate and authorize the business application system by comparing the random code received from the business application system with the random code obtained by verifying and decrypting the signature encryption information using the public key.

[0040] In an optional specific embodiment of the present invention, the process of obtaining the user's basic information through the backend interface of the unified identity authentication platform based on the identity authorization code includes: obtaining the user's basic information through the backend interface of the unified identity authentication platform based on the identity authorization code, the system interface password pre-assigned by the unified identity authentication platform to the business application system, and the application identifier of the business application system.

[0041] Optionally, after receiving the identity authorization code, the business application system uses the system interface password pre-assigned to it by the unified identity authentication platform, as well as the application identifier, to authenticate itself. Only after successful authentication and obtaining the access token can the business application system retrieve the user's contact information from the authorization interface of the unified identity authentication platform using the identity authorization code.

[0042] Optionally, the first encrypted message is obtained by the unified identity authentication platform calling the digital key service platform to encrypt the second encrypted message, and then signed.

[0043] Optionally, the second encrypted message is obtained by using a Chinese national standard symmetric encryption algorithm, such as SM4.

[0044] In an optional specific embodiment of the present invention, the second encrypted message includes: a first authorization timestamp when the encrypted unified identity authentication platform authenticates and authorizes the business application system, so as to facilitate the acquisition of the user's sensitive data from the government data sharing platform based on the first authorization timestamp.

[0045] Step 104: Use a biometric input device to decrypt the first encrypted message to obtain a second encrypted message, so as to more securely obtain the user's sensitive personal information from the data sharing platform based on the second encrypted message and the user's basic information.

[0046] Specifically, when an application system requests access to sensitive personal data, the data sharing platform uses a biometric data entry device authorized by the user to authenticate the identity of the business application system that has been logged in with biometrics. This can confirm the user's true intent and avoid the security risk of unauthorized access to the data interface.

[0047] Step 105: Use the second encrypted message and basic information to obtain the user's sensitive personal data from the data sharing platform. This enables the security endorsement based on the entire business chain of identity authentication and user authorization, through user signature authorization and encryption mechanism, protecting interface-level unauthorized access security and user data privacy. In addition, the data sharing platform, as a public support service, needs to achieve high-concurrency processing capabilities.

[0048] Specifically, the aforementioned data sharing platform can be a government data sharing platform.

[0049] In an optional embodiment of the present invention, the process of obtaining a user's sensitive personal data from a data sharing platform using a second encrypted message and basic information includes: sending a sensitive personal data acquisition request to the data sharing platform so that the data sharing platform returns the sensitive personal data. The sensitive personal data acquisition request carries a second encrypted message, the user's basic information, and a preset application account and corresponding password for logging into the data sharing platform for the business application system. The sensitive personal data is initially authenticated by the data sharing platform using the application account and corresponding password to authenticate the business application system. After successful initial authentication, the second encrypted message is decrypted, and the basic information obtained from the decryption, along with the basic information carried in the sensitive personal data acquisition request, is used to perform final authentication of the business application system. Finally, the sensitive personal data is retrieved based on the basic information after successful final authentication.

[0050] Specifically, the process of the aforementioned data sharing platform decrypting the second encrypted message includes calling the encryption machine to decrypt the encrypted message.

[0051] In an optional specific embodiment of the present invention, before performing final application identity authentication, the government data sharing platform determines whether the first timestamp has expired; if the first timestamp has not expired, the government data sharing platform determines that the final application identity authentication has passed; otherwise, the government data sharing platform determines that the final application identity authentication has failed.

[0052] In an optional embodiment of the present invention, the request for obtaining personal sensitive data also carries a second authorized timestamp when the first encrypted message is decrypted using a biometric input device to obtain the second encrypted message; before decrypting the second encrypted message, the government data sharing platform determines whether the second authorized timestamp has expired; if the second authorized timestamp has expired, the government data sharing platform refuses to return the personal sensitive data; otherwise, the government data sharing platform begins to execute the step of decrypting the second encrypted message.

[0053] The following further describes a method for authorizing the acquisition of personal sensitive data in another embodiment. In this specific embodiment, step 104, which involves decrypting the first encrypted message using a biometric input device to obtain the second encrypted message, includes:

[0054] 1041, Use a biometric data entry device to collect the user's biometric data to obtain a second biometric data to be verified;

[0055] 1042, verify the user's identity based on the user's real biometric features pre-stored in the biometric data entry device and the second biometric feature to be verified; and

[0056] 1043. After successful verification, a second encrypted message is obtained from the biometric data entry device. The second encrypted message is obtained by the biometric data entry device using its private key to decrypt the first encrypted message.

[0057] Specifically, in this embodiment of the invention, user login authorization is performed once by collecting the user's biometrics when the user logs into the business application system, and then again by collecting the user's biometrics when the business application system obtains sensitive data, thereby fully ensuring the user's true intentions and protecting the user's privacy and security.

[0058] Figure 3 This is a structural diagram of a human sensitive data authorization acquisition device provided in an embodiment of the present invention. This device is suitable for executing the human sensitive data authorization acquisition method provided in an embodiment of the present invention. Figure 3 As shown, the device may specifically include:

[0059] The data acquisition module 301 is used to respond to the user's access request to the business application system and to collect and verify the user's biometric features through a unified identity authentication platform using a preset biometric feature input device.

[0060] The first acquisition module 302 is used to acquire signature encryption information and a random code from the biometric data entry device after the verification is passed. The signature encryption information includes a signature encryption string obtained by encrypting the random code by the biometric data entry device and signing the encrypted random code with the private key stored in the biometric data entry device.

[0061] The second acquisition module 303 is used to acquire, based on the signature encryption information and the random code, the basic information of the user provided after the business application system is authenticated and authorized using the public key corresponding to the private key, and a first encrypted message from the unified identity authentication platform; the first encrypted message is obtained by encrypting a second encrypted message using the public key, and the second encrypted message includes the encrypted basic information of the user.

[0062] Decryption module 304 is used to decrypt the first encrypted message using the biometric input device to obtain the second encrypted message; and

[0063] The third acquisition module 305 is used to acquire the user's sensitive personal data from the data sharing platform using the second encrypted message and the basic information. Those skilled in the art will understand that, for the sake of convenience and brevity, the above-described division of functional modules is merely an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the described functional modules can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0064] The unified identity authentication platform can utilize biometric data entry devices that store private keys and users' real biometric features to reauthorize the actions of business application systems in obtaining sensitive personal data from the data sharing platform based on the user's biometric features collected when the user logs into the business application system. This enables rapid online verification of user identity and constructs a complete business chain for identity authentication and user authorization. Security is guaranteed through user signature authorization and encryption mechanism, protecting interface-level unauthorized access and user data privacy. In addition, the data sharing platform, as a public support service, needs to achieve high-concurrency processing capabilities.

[0065] This invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the personal sensitive data authorization acquisition method provided in any of the above embodiments.

[0066] This invention also provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the method for authorized acquisition of personal sensitive data provided in any of the above embodiments.

[0067] The following is for reference. Figure 4 It shows a schematic diagram of the structure of a computer system 400 suitable for implementing an electronic device according to embodiments of the present invention. Figure 4 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments of the present invention.

[0068] like Figure 4As shown, the computer system 400 includes a central processing unit (CPU) 401, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 402 or programs loaded from storage section 408 into random access memory (RAM) 403. The RAM 403 also stores various programs and data required for the operation of the system 400. The CPU 401, ROM 402, and RAM 403 are interconnected via a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.

[0069] The following components are connected to I / O interface 405: an input section 406 including a keyboard, mouse, etc.; an output section 407 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 408 including a hard disk, etc.; and a communication section 409 including a network interface card such as a LAN card, modem, etc. The communication section 409 performs communication processing via a network such as the Internet. A drive 410 is also connected to I / O interface 405 as needed. A removable medium 411, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 410 as needed so that computer programs read from it can be installed into storage section 408 as needed.

[0070] In particular, according to the embodiments disclosed in this invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 409, and / or installed from removable medium 411. When the computer program is executed by central processing unit (CPU) 401, it performs the functions defined above in the system of this invention.

[0071] It should be noted that the computer-readable medium shown in this invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0072] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0073] The modules and / or units described in the embodiments of the present invention can be implemented in software or hardware. The described modules and / or units can also be housed in a processor; for example, a processor can be described as including a gradient acquisition module, a first acquisition module, a second acquisition module, a decryption module, and a third acquisition module. The names of these modules do not necessarily limit the module itself.

[0074] In another aspect, the present invention also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist alone and not assembled into the device.

[0075] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method for authorized acquisition of personal sensitive data, characterized in that, include: In response to a user's access request to the business application system, the system uses a pre-set biometric data entry device through a unified identity authentication platform to collect and verify the user's biometric features. After successful verification, signature encryption information and a random code are obtained from the biometric data entry device. The signature encryption information includes a signature encryption string obtained by encrypting the random code by the biometric data entry device and signing the encrypted random code using the private key stored in the biometric data entry device. Based on the signature encryption information and the random code, obtain from the unified identity authentication platform the user's basic information and the first encrypted message provided after authenticating and authorizing the business application system using the public key corresponding to the private key; The first encrypted message is obtained by encrypting the second encrypted message using the public key, and the second encrypted message includes the encrypted basic information of the user; The first encrypted message is decrypted using the biometric data entry device to obtain the second encrypted message; as well as The user's sensitive personal data is obtained from the data sharing platform using the second encrypted message and the basic information.

2. The method for authorized acquisition of personal sensitive data according to claim 1, characterized in that, The process of collecting and verifying the user's biometric features using a preset biometric data entry device includes: The biometric data acquisition device is used to collect the user's biometric data to obtain a first biometric feature to be verified. The user's identity is verified based on the user's real biometrics pre-stored in the biometrics input device and the first biometric feature to be verified.

3. The method for authorized acquisition of personal sensitive data according to claim 1, characterized in that, The signature encryption information includes a signature device number information obtained by signing the serial number information of the biometric data entry device using the private key; The public key is obtained by the unified identity authentication platform from its stored data based on the signature device number information and the index relationship between the public key stored by the unified identity authentication platform and the device number of the biometric data entry device.

4. The method for authorized acquisition of personal sensitive data according to claim 1, characterized in that, The process of obtaining the user's basic information and the first encrypted message from the unified identity authentication platform based on the signature encryption information and the random code, after authenticating and authorizing the business application system using the public key corresponding to the private key, includes: The signature encryption information and the random code are sent to the unified identity authentication platform, so that the unified identity authentication platform returns the identity authorization code and the first encrypted message; and The user's basic information is obtained through the backend interface of the unified identity authentication platform based on the identity authorization code; The identity authorization code is generated by the unified identity authentication platform to authenticate and authorize the business application system by comparing the random code with the random code obtained by verifying and decrypting the signature encryption information using the public key, and is generated after the authentication and authorization are successful.

5. The method for authorized acquisition of personal sensitive data according to claim 4, characterized in that, The process of obtaining the user's basic information after authenticating and authorizing the business application system using the public key corresponding to the private key from the unified identity authentication platform based on the signature encryption information and the random code includes: Based on the identity authorization code, the system interface password pre-assigned to the business application system by the unified identity authentication platform, and the application identifier of the business application system, the user's basic information is obtained through the backend interface of the unified identity authentication platform.

6. The method for authorized acquisition of personal sensitive data according to claim 1, characterized in that, The process of obtaining the user's sensitive personal data from the data sharing platform using the second encrypted message and the basic information includes: Send a request to the data sharing platform to obtain personal sensitive data, so that the data sharing platform returns the personal sensitive data; The personal sensitive data acquisition request carries the second encrypted message, the user's basic information, and the preset application account and corresponding password for logging into the data sharing platform by the business application system; The personal sensitive data is obtained by the data sharing platform through preliminary application identity authentication of the business application system based on the application account and corresponding password. After the preliminary application identity authentication is passed, the second encrypted message is decrypted and the business application system is then subjected to final application identity authentication based on the basic information obtained from the decryption and the basic information carried in the personal sensitive data acquisition request. Finally, the data is obtained by querying the basic information after the final application identity authentication is passed.

7. The method for authorized acquisition of sensitive human data according to claim 1, characterized in that, The process of decrypting the first encrypted message using the biometric data entry device to obtain the second encrypted message includes: The biometric data acquisition device is used to collect the user's biometric data to obtain a second biometric feature to be verified. The user's identity is verified based on the user's real biometric features pre-stored in the biometric data entry device and the second biometric feature to be verified; and After successful verification, the second encrypted message is obtained from the biometric data entry device. The second encrypted message is obtained by the biometric data entry device decrypting the first encrypted message using the private key.

8. A device for authorizing the acquisition of personal sensitive data, characterized in that, include: The data collection module is used to respond to the user's access request to the business application system and collect and verify the user's biometric features using a preset biometric data entry device through a unified identity authentication platform. The first acquisition module is used to acquire signature encryption information and random code from the biometric data entry device after verification. The signature encryption information includes a signature encryption string obtained by encrypting the random code by the biometric data entry device and signing the encrypted random code using the private key stored in the biometric data entry device. The second acquisition module is used to obtain, based on the signature encryption information and the random code, the basic information of the user provided after authenticating and authorizing the business application system using the public key corresponding to the private key and the first encrypted message from the unified identity authentication platform. The first encrypted message is obtained by encrypting the second encrypted message using the public key, and the second encrypted message includes the encrypted basic information of the user; The decryption module is used to decrypt the first encrypted message using the biometric input device to obtain the second encrypted message; as well as The third acquisition module is used to acquire the user's sensitive personal data from the data sharing platform using the second encrypted message and the basic information.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method for authorized acquisition of personal sensitive data as described in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the program implements the method for authorized acquisition of personal sensitive data as described in any one of claims 1 to 7.