Data authorization method, device and system
By receiving and verifying authorization requirements information, generating and outputting authorization documents, the problem of data subject being unable to participate in data transaction circulation income, and improving data circulation efficiency and rationality of profit distribution.
Patent Information
- Application Number
- CN202310966126.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-02
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2043-08-02
AI Technical Summary
The existing data authorization technology cannot meet the income from data subjects participating in data transaction circulation, resulting in limited data circulation applications.
Provide a data authorization method, which receives authorization requirements information through the authorization service party, performs requirements verification and sends it to the data subject for authorization verification, generates authorization response information and outputs authorization files, and realizes the participation and profit distribution of the data subject party.
The data subject's participation in data authorization process has been realized, the data circulation efficiency has been improved, and the data subject has obtained reasonable returns.
Smart Images

Figure CN116720160B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a data authorization method, device and system. Background Art
[0002] Currently, data authorization technologies are all set up based on the profit distribution logic between data demanders and data suppliers. However, the subject that owns the data cannot understand the entire data authorization process and cannot guarantee that the data subject can participate in the data transaction circulation benefits through authorization. It can be seen that the existing authorization process cannot meet the current actual application needs, which affects the data circulation application. Summary of the Invention
[0003] In response to the above problems, the present invention provides a data authorization method, device and system, which enable the data subject to participate in the data authorization process and improve the efficiency of data circulation.
[0004] In order to achieve the above object, the present invention provides the following technical solutions:
[0005] A data authorization method, comprising:
[0006] In response to receiving the authorization requirement information from the authorization requester, performing requirement verification on the authorization requirement information;
[0007] If the requirement verification is passed, the authorization requirement information is sent to the data subject, so that the data subject can perform authorization verification on the authorization requirement information. If the data subject passes the authorization verification on the authorization requirement information, an authorization response information is generated;
[0008] Generate an authorization file based on the authorization response information;
[0009] The authorization document is output to the authorization requester, so that the authorization requester obtains the demand data based on the authorization document.
[0010] Optionally, in response to receiving the authorization requirement information from the authorization requester, performing requirement verification on the authorization requirement information includes:
[0011] In response to receiving authorization request information from an authorization requester, obtaining a data list from a data provider, wherein the data list represents data information that the data provider can provide;
[0012] Performing requirement verification on the authorization requirement information based on the data list;
[0013] If the data requirement range corresponding to the authorization requirement information is within the data range of the data list, it is determined that the authorization requirement information verification has passed.
[0014] Optionally, sending the authorization requirement information to the data subject includes:
[0015] Integrate the authorization demand information of each authorization demander to obtain integrated authorization demand information;
[0016] The integrated authorization requirement information is subjected to semantic field standardization processing, and the processed authorization requirement information is sent to the data subject.
[0017] Optionally, the method further includes:
[0018] Obtaining characteristic information of the authorization requester;
[0019] Performing attribute classification processing on the feature information to obtain attribute classification description information;
[0020] The attribute hierarchical description information is sent to the data subject, so that the data subject performs authorization verification on the authorization requirement information based on the attribute hierarchical description information.
[0021] Optionally, the method further includes:
[0022] In response to the authorization demander obtaining demand data based on the authorization document, revenue feedback information corresponding to the authorization demand information is generated, and the revenue feedback information is sent to the authorization service provider and the data subject.
[0023] A data authorization device, comprising:
[0024] a verification unit, configured to, in response to receiving authorization requirement information from an authorization requester, perform requirement verification on the authorization requirement information;
[0025] a sending unit, configured to send the authorization requirement information to the data subject if the requirement verification is passed, so that the data subject can perform authorization verification on the authorization requirement information, and generate authorization response information if the data subject passes the authorization verification on the authorization requirement information;
[0026] A generating unit, configured to generate an authorization file based on the authorization response information;
[0027] An output unit is used to output the authorization document to the authorization requester, so that the authorization requester obtains the demand data based on the authorization document.
[0028] Optionally, the verification unit includes:
[0029] A first obtaining subunit is configured to obtain a data list from a data provider in response to receiving authorization request information from an authorization requester, wherein the data list represents data information that the data provider can provide;
[0030] A first verification subunit, configured to perform requirement verification on the authorization requirement information based on the data list;
[0031] The determination subunit is configured to determine that the authorization requirement information verification has passed if the data requirement range corresponding to the authorization requirement information is within the data range of the data list.
[0032] Optionally, the sending unit includes:
[0033] The integration sub-unit is used to integrate the authorization demand information of each authorization demand party to obtain the integrated authorization demand information;
[0034] a processing subunit, configured to perform semantic field standardization processing on the integrated authorization requirement information, and send the processed authorization requirement information to the data subject;
[0035] Wherein, the sending unit further includes:
[0036] A second acquisition subunit is used to obtain characteristic information of the authorization requester;
[0037] A hierarchical processing subunit, configured to perform attribute hierarchical processing on the feature information to obtain attribute hierarchical description information;
[0038] The sending subunit is configured to send the attribute hierarchical description information to the data subject, so that the data subject performs authorization verification on the authorization requirement information based on the attribute hierarchical description information.
[0039] Optionally, the device further comprises:
[0040] The revenue sending unit is configured to generate revenue feedback information corresponding to the authorization demand information in response to the authorization demand party obtaining demand data based on the authorization file, and send the revenue feedback information to the authorization service party and the data subject party.
[0041] A data authorization system, comprising:
[0042] Authorization requester, data provider, authorization service provider and data subject, among which,
[0043] The authorization requester is configured to generate authorization request information and send the authorization request information to the authorization service provider;
[0044] The authorization service provider is configured to execute any one of the above-mentioned data authorization methods;
[0045] The data subject is used to perform authorization verification on the authorization requirement information;
[0046] The data provider is used to provide a data list, where the data list represents the data information that the data provider can provide.
[0047] Compared with the prior art, the present invention provides a data authorization method, device and system, which includes: in response to receiving authorization requirement information from the authorization requester, verifying the authorization requirement information; if the requirement verification passes, sending the authorization requirement information to the data subject, so that the data subject can perform authorization verification on the authorization requirement information; if the data subject passes the authorization verification on the authorization requirement information, generating authorization response information; generating an authorization file based on the authorization response information; outputting the authorization file to the authorization requester, so that the authorization requester can obtain the required data based on the authorization file. The present invention can execute the data authorization method through the authorization service party, and can send the authorization requirement information to the data subject for authorization verification, so that the data subject can participate in the entire authorization process, and realize the decoupling of the authorization flow and the data flow, promote data circulation, and improve the efficiency of data circulation. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0049] Figure 1 A flowchart of a data authorization method provided by an embodiment of the present invention;
[0050] Figure 2 A timing diagram of data authorization provided by an embodiment of the present invention;
[0051] Figure 3 A structural diagram of a data authorization device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0053] The terms "first," "second," and the like in the specification, claims, and accompanying drawings of the present invention are used to distinguish between different items, not to describe a specific order. Furthermore, the terms "including," "having," and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements and may include steps or elements that are not listed.
[0054] The present invention provides a data authorization method that can be applied to authorization service providers that provide authorization services, such as authorization service platforms and authorization servers. This method enables data subjects (such as individuals) to participate in data authorization for revenue generation, integrates and transfers data authorization requirements, and provides revenue feedback. This method effectively addresses the autonomy, right to know, and right to revenue of data subjects, such as enterprises and individuals, and maximizes data circulation while ensuring compliance.
[0055] See also Figure 1 , is a flow chart of a data authorization method provided by an embodiment of the present invention, which may include the following steps:
[0056] S101: In response to receiving authorization requirement information from an authorization requester, verify the authorization requirement information.
[0057] S102. If the requirement verification is passed, the authorization requirement information is sent to the data subject, so that the data subject can perform authorization verification on the authorization requirement information. If the data subject passes the authorization verification on the authorization requirement information, authorization response information is generated.
[0058] See also Figure 2 , a timing diagram of data authorization provided in an embodiment of the present invention. This method is applied to the authorization service provider, that is, the platform or server that provides data authorization. The authorization requester refers to any entity that requires data authorization, and can be either an external or internal requester. The external requester can be a data transaction service provider, acting as an agent in data circulation activities, or it can be an actual end-user client with data usage needs, solving the problem of difficulty in contacting the data subject to obtain authorization.
[0059] The authorization requester generates the authorization request information, which is used to request authorization for data acquisition and also includes information related to the data being requested. That is, the authorization request method needs to provide definite authorization request information, including specific information about the requester (i.e., the authorization requester, also known as the data requester), relevant information about the data provider (also known as the supplier), data field names, data caliber, rule requirements, data usage, data usage period, benefits, and other information. Among them, the demander includes the terminal's demanding customers, and the supplier includes the terminal's data collector, to ensure that the true source and actual destination of the data can be clearly identified during the authorization process; the data field list, with the help of the caliber, can clarify the content of the data to be authorized; the rule requirements are for marketing and other scenarios with clear population conditions, so as to distinguish whether the subject to be authorized meets the requirements, and avoid and reduce invalid authorization.
[0060] When the authorization service provider receives the authorization request information from the authorization requester, it needs to verify the authorization request information. The verification may include the identity verification of the authorization requester and the rationality verification of the request.
[0061] In one embodiment, in response to receiving the authorization requirement information from the authorization requester, performing requirement verification on the authorization requirement information includes:
[0062] In response to receiving authorization request information from an authorization requester, obtaining a data list from a data provider, wherein the data list represents data information that the data provider can provide;
[0063] Performing requirement verification on the authorization requirement information based on the data list;
[0064] If the data requirement range corresponding to the authorization requirement information is within the data range of the data list, it is determined that the authorization requirement information verification has passed.
[0065] It should be noted that after the authorization requester has an authorization request, he or she can check the corresponding data list of the data provider to determine whether the necessary authorization requirements are met. The authorization service provider can also perform this process. By verifying whether the authorization requester meets the data provider's data list, the effectiveness of data authorization can be promoted, and the problem of subsequent data being unable to be authorized when the authorization requester omits verification can be avoided, thereby improving the processing efficiency of data authorization. Among them, the data list is a directory of data fields obtained and aggregated from various data providers by the authorization service provider under a legal framework. Its essence is the data product directory and other related data range information of the data provider.
[0066] If the authorization requester's authorization request information meets the data range that can be provided by the data list, the requirement verification is passed and the authorization request information is sent to the data subject. If it is not met, a message indicating that the verification failed can be fed back to the authorization requester so that the authorization requester can adjust the authorization request information based on the feedback information.
[0067] Once the requirement verification is passed, the authorization requirement information can be sent to the data subject, who will perform authorization verification and generate corresponding authorization response information.
[0068] Furthermore, in order to facilitate the data subject to perform authorization verification, the authorization requirement information can be processed before being sent to the data subject to make it easier for the data subject to perform authorization verification of the authorization requirement information. Specifically, unified field processing and field merging can be performed.
[0069] In one embodiment, sending the authorization requirement information to the data subject includes:
[0070] Integrate the authorization demand information of each authorization demander to obtain integrated authorization demand information;
[0071] The integrated authorization requirement information is subjected to semantic field standardization processing, and the processed authorization requirement information is sent to the data subject.
[0072] Integration of authorization demand information refers to the integration of the same data authorization demands of multiple data demanders, so that subsequent authorized persons can choose to authorize multiple demanders in batches. Semantic field standardization refers to the processing of demand information through semantic mapping. That is, in the context of big data, different demanders use different systems, resulting in large differences in the naming of data fields. In order to ensure that the data subject can clearly understand the meaning of the data fields in the authorization demand information, a standard data semantic library can be built in the authorization service provider. Through daily and continuous maintenance of all personal data fields, the original field name provided by the demander, data semantic mapping, and the addition of field aliases in the authorization service process are used. The alias is uniformly maintained as the standard field name in the authorization service.
[0073] In addition to processing the authorization requirement information, the characteristic information of the authorization requester can also be processed to facilitate the authorization verification of the data subject. In an embodiment of the present invention, it also includes: obtaining the characteristic information of the authorization requester; performing attribute grading processing on the characteristic information to obtain attribute grading description information; sending the attribute grading description information to the data subject, so that the data subject can perform authorization verification on the authorization requirement information based on the attribute grading description information.
[0074] Specifically, even if the data subject understands the meaning of the fields to be authorized, it is difficult for them to quickly establish an in-depth understanding of the fields and extend their associated cognition. They may authorize without sufficient understanding, which may lead to future disputes. In order to provide the data subject with an understanding of the authorization requirement information, descriptions of the fields to be authorized in the authorization requirement information can be added through classification and grading. Among them, classification is based on the multi-dimensional attributes of the person to be authorized (i.e., the party requesting authorization), such as biometrics, specific identity, medical health, financial accounts, whereabouts and other information defined in the Personal Information Protection Law. Grading refers to the grading of the privacy level of personal data, such as distinguishing from extremely sensitive, sensitive, relatively sensitive, low sensitivity, and non-sensitive perspectives, so that the person to be authorized can fully realize the sensitivity of the data to be authorized.
[0075] After the processed and analyzed authorization request information is sent to the data subject, the data subject can authorize only those requests for which they intend to authorize, based on the received request list containing the various authorization request information. For requests for which they intend to authorize, the individual (i.e., if the data subject is an individual) should review the rule requirements and self-check whether they meet the corresponding rule requirements. This can avoid and mitigate situations where the authorizer is unable to receive benefits after authorization, provided the requester only pays for valid authorization and data that meets the valid rules. In other words, if the individual confirms that they do not meet the requester's rule requirements, authorization can be declined. This non-authorization, when not necessary, also protects personal privacy. Authorization verification by the data subject can utilize relevant authentication methods, such as existing technologies like three-factor authentication and facial recognition, to ensure the authenticity and validity of the authorized individual and ensure that subsequent benefits are fed back to the authentic authorized individual. Individuals confirm authorization, provided they clearly understand the source, field name, statistical caliber, type, purpose, and sensitivity of the data to be authorized. The authorizing subject can then generate an authorization response and send it to the authorization service provider.
[0076] S103. Generate an authorization file based on the authorization response information;
[0077] S104: Output the authorization file to the authorization requester, so that the authorization requester obtains the required data based on the authorization file.
[0078] After receiving the authorization response from the data subject, the authorization service provider generates an authorization document. This document is then passed to the authorization requester, who uses it to generate a data request and send it to the data provider, who then responds. In other words, during the data flow, the authorization requester, acting as the principal, retrieves data either offline or through its internal systems, either through the authorized requester or the actual end-user behind it. This process is independent of the authorization system and can be completed independently. After obtaining the data, the requester verifies the data content and quality, verifying that the authorized entity meets the pre-defined rules. If there are no rules, after obtaining the authorization document, the payment feedback process proceeds directly. If there are rules, the authorization requester determines whether to award revenue based on the data. This determination is then fed back to the authorization service provider, who then provides feedback to the authorized service provider and the data subject based on the original revenue.
[0079] Correspondingly, the embodiment of the present invention further includes: in response to the authorization demander obtaining demand data based on the authorization file, generating revenue feedback information corresponding to the authorization demand information, and sending the revenue feedback information to the authorization service provider and the data subject.
[0080] At present, authorization technologies are all based on the results of their own business extensions, and are authorized for their respective companies and business fields. There is a lack of universal authorization methods and systems that are separated from business scenarios. The present invention proposes a highly independent personal data authorization method and system, which is oriented towards all corporate entities and all business needs in the market, separates the authorization flow from the data flow, provides professional and refined authorization services, and promotes the circulation of data elements more efficiently. At the same time, in order to improve the usability of the method, the process integrates the needs and supplies of multiple parties by building a semantic library, and enhances the data subject's cognition of the authorized data by classifying data and grading sensitivity, thereby ensuring that the data subject understands the true authorization intention expression correctly.
[0081] The current authorization technology is designed based on the profit distribution logic between the supply and demand sides. Individuals who own the data cannot participate in the profit distribution. The present invention proposes a data authorization method and system for individuals to participate in profit distribution, enriching the participants in the profit flow, connecting the profit flow with the authorization flow, and ensuring the real authorized individuals and corresponding profits through strict authentication of individual subjects. At the same time, in order to ensure that the authorized individual subjects effectively obtain profits, a set of rules is formed based on the actual needs of the demand side. The authorized individual subjects as data subjects conduct self-inspection before authorization, and voluntarily give up authorization if they do not meet the demand side's conditions, thereby reducing the situation where invalid customers do not get any profits after authorization.
[0082] See also Figure 3In an embodiment of the present invention, a data authorization device is further provided. The device can be applied to an authorization service provider and can include:
[0083] The verification unit 201 is configured to verify the authorization requirement information received from the authorization requester;
[0084] The sending unit 202 is configured to send the authorization requirement information to the data subject if the requirement verification is passed, so that the data subject can perform authorization verification on the authorization requirement information, and generate authorization response information if the data subject passes the authorization verification on the authorization requirement information;
[0085] A generating unit 203 is configured to generate an authorization file based on the authorization response information;
[0086] The output unit 204 is configured to output the authorization file to the authorization requester, so that the authorization requester obtains the required data based on the authorization file.
[0087] The embodiment of the present invention provides a data authorization device, comprising: a verification unit that verifies the authorization requirement information in response to receiving authorization requirement information from an authorization requester; a sending unit that sends the authorization requirement information to a data subject if the requirement verification passes, so that the data subject verifies the authorization requirement information, and generates authorization response information if the data subject verifies the authorization requirement; a generation unit that generates an authorization file based on the authorization response information; and an output unit that outputs the authorization file to the authorization requester so that the authorization requester obtains the required data based on the authorization file. The present invention can execute the data authorization method through an authorization service provider, and can send the authorization requirement information to the data subject for authorization verification, so that the data subject can participate in the entire authorization process, and realizes the decoupling of the authorization flow and the data flow, promotes data circulation, and improves the efficiency of data circulation.
[0088] Optionally, the verification unit includes:
[0089] A first obtaining subunit is configured to obtain a data list from a data provider in response to receiving authorization request information from an authorization requester, wherein the data list represents data information that the data provider can provide;
[0090] A first verification subunit, configured to perform requirement verification on the authorization requirement information based on the data list;
[0091] The determination subunit is configured to determine that the authorization requirement information verification has passed if the data requirement range corresponding to the authorization requirement information is within the data range of the data list.
[0092] Optionally, the sending unit includes:
[0093] The integration sub-unit is used to integrate the authorization demand information of each authorization demand party to obtain the integrated authorization demand information;
[0094] a processing subunit, configured to perform semantic field standardization processing on the integrated authorization requirement information, and send the processed authorization requirement information to the data subject;
[0095] Wherein, the sending unit further includes:
[0096] A second acquisition subunit is used to obtain characteristic information of the authorization requester;
[0097] A hierarchical processing subunit, configured to perform attribute hierarchical processing on the feature information to obtain attribute hierarchical description information;
[0098] The sending subunit is configured to send the attribute hierarchical description information to the data subject, so that the data subject performs authorization verification on the authorization requirement information based on the attribute hierarchical description information.
[0099] Optionally, the device further comprises:
[0100] The revenue sending unit is configured to generate revenue feedback information corresponding to the authorization demand information in response to the authorization demand party obtaining demand data based on the authorization file, and send the revenue feedback information to the authorization service party and the data subject party.
[0101] Correspondingly, an embodiment of the present invention further provides a data authorization system, including:
[0102] Authorization requester, data provider, authorization service provider and data subject, among which,
[0103] The authorization requester is configured to generate authorization request information and send the authorization request information to the authorization service provider;
[0104] The authorization service provider is configured to execute any one of the above-mentioned data authorization methods;
[0105] The data subject is used to perform authorization verification on the authorization requirement information;
[0106] The data provider is used to provide a data list, where the data list represents the data information that the data provider can provide.
[0107] Specifically, the data provider is used to provide the authorization service with a data list (such as a field directory), ensuring that the authorization content provided by the authorization service can facilitate the authorization requester to truly connect with the data provider for data transactions.
[0108] Furthermore, after the authorization demander obtains authorization, the data transaction can be freely connected by the demander and the data provider. Data requests and responses can be freely implemented by both parties outside the authorization system, and then the results can be recorded on the authorization system to realize the subsequent distribution of authorization benefits.
[0109] For details on the data authorization system, please refer to the present invention. Figure 1 and Figure 2 The description of the corresponding embodiments will not be repeated here in detail.
[0110] Based on the foregoing embodiments, an embodiment of the present invention provides a computer-readable storage medium, which stores one or more programs. The one or more programs can be executed by one or more processors to implement the steps of any of the above data authorization methods.
[0111] An embodiment of the present invention further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the steps of the data authorization method are implemented when the processor executes the program.
[0112] It should be noted that the above-mentioned processor or CPU can be at least one of an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a central processing unit (CPU), a controller, a microcontroller, and a microprocessor. It is understandable that the electronic device that implements the above-mentioned processor function can also be other electronic devices, which are not specifically limited in the embodiments of the present application.
[0113] It should be noted that the above-mentioned computer storage medium / memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory (Flash Memory), a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); it can also be various terminals including one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.
[0114] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.
[0115] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0116] In addition, the functional units in the embodiments of the present application can all be integrated into one processing module, or each unit can be a separate unit, or two or more units can be integrated into one unit; the above-mentioned integrated unit can be implemented in the form of hardware or in the form of hardware plus software functional units. It can be understood by ordinary technicians in this field that all or part of the steps of the above-mentioned method embodiments can be completed by hardware related to program instructions, and the above-mentioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiments; and the above-mentioned storage medium includes: mobile storage devices, read-only memory (ROM), random access memory (RAM), disks or optical disks, etc. Various media that can store program codes.
[0117] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.
[0118] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A data authorization method, characterized in that: The method comprises: In response to receiving the authorization requirement information from the authorization requester, performing requirement verification on the authorization requirement information; If the requirement verification is passed, the authorization requirement information is sent to the data subject, so that the data subject can perform authorization verification on the authorization requirement information. If the data subject passes the authorization verification on the authorization requirement information, an authorization response information is generated; Generate an authorization file based on the authorization response information; Outputting the authorization document to the authorization requester, so that the authorization requester obtains the required data based on the authorization document; The step of sending the authorization requirement information to the data subject includes: Integrate the authorization demand information of each authorization demander to obtain integrated authorization demand information; Performing semantic field standardization on the integrated authorization demand information and sending the processed authorization demand information to the data subject; wherein, using data semantic mapping to add field aliases in the authorization service process to the original field names provided by the authorization demander, the aliases are uniformly maintained as standard field names in the authorization service to construct a standard data semantic library; performing semantic field standardization on the integrated authorization demand information based on the standard data semantic library; The method further comprises: Obtaining characteristic information of the authorization requester; Performing attribute classification processing on the feature information to obtain attribute classification description information; The attribute hierarchical description information is sent to the data subject, so that the data subject performs authorization verification on the authorization requirement information based on the attribute hierarchical description information.
2. The method according to claim 1, characterized in that The step of performing requirement verification on the authorization requirement information in response to receiving the authorization requirement information from the authorization requester includes: In response to receiving authorization request information from an authorization requester, obtaining a data list from a data provider, wherein the data list represents data information that the data provider can provide; Performing requirement verification on the authorization requirement information based on the data list; If the data requirement range corresponding to the authorization requirement information is within the data range of the data list, it is determined that the authorization requirement information verification has passed.
3. The method according to claim 1, characterized in that The method further comprises: In response to the authorization demander obtaining demand data based on the authorization document, revenue feedback information corresponding to the authorization demand information is generated, and the revenue feedback information is sent to the authorization service provider and the data subject.
4. A data authorization device, characterized in that: The device comprises: a verification unit, configured to, in response to receiving authorization requirement information from an authorization requester, perform requirement verification on the authorization requirement information; a sending unit, configured to send the authorization requirement information to the data subject if the requirement verification is passed, so that the data subject can perform authorization verification on the authorization requirement information, and generate authorization response information if the data subject passes the authorization verification on the authorization requirement information; A generating unit, configured to generate an authorization file based on the authorization response information; an output unit, configured to output the authorization document to the authorization requester, so that the authorization requester obtains the demand data based on the authorization document; Wherein, the sending unit includes: The integration sub-unit is used to integrate the authorization demand information of each authorization demand party to obtain the integrated authorization demand information; The processing subunit is configured to perform semantic field standardization processing on the integrated authorization demand information and send the processed authorization demand information to the data subject; wherein, the original field name provided by the authorization demander is used to add a field alias in the authorization service process using data semantic mapping, and the alias is uniformly maintained as the standard field name in the authorization service to construct a standard data semantic library; and the semantic field standardization processing is performed on the integrated authorization demand information based on the standard data semantic library; Wherein, the sending unit further includes: A second acquisition subunit is used to obtain characteristic information of the authorization requester; A hierarchical processing subunit, configured to perform attribute hierarchical processing on the feature information to obtain attribute hierarchical description information; The sending subunit is configured to send the attribute hierarchical description information to the data subject, so that the data subject performs authorization verification on the authorization requirement information based on the attribute hierarchical description information.
5. The device according to claim 4, characterized in that The verification unit includes: A first obtaining subunit is configured to obtain a data list from a data provider in response to receiving authorization request information from an authorization requester, wherein the data list represents data information that the data provider can provide; A first verification subunit, configured to perform requirement verification on the authorization requirement information based on the data list; The determination subunit is configured to determine that the authorization requirement information verification has passed if the data requirement range corresponding to the authorization requirement information is within the data range of the data list.
6. The device according to claim 4, characterized in that The device further comprises: The revenue sending unit is configured to generate revenue feedback information corresponding to the authorization demand information in response to the authorization demand party obtaining demand data based on the authorization file, and send the revenue feedback information to the authorization service party and the data subject party.
7. A data authorization system, characterized in that: include: Authorization requester, data provider, authorization service provider and data subject, among which, The authorization requester is configured to generate authorization request information and send the authorization request information to the authorization service provider; The authorization service provider is configured to execute the data authorization method according to any one of claims 1 to 3; The data subject is used to perform authorization verification on the authorization requirement information; The data provider is used to provide a data list, where the data list represents the data information that the data provider can provide.
Citation Information
Patent Citations
Data use authorization method and equipment based on authorization center
CN114491626A