Information query method and device, equipment and storage medium

By embedding third-party service controls in the system user interface and encrypting account information with public key information, the problem of sensitive information leakage in information sharing between different business systems is solved, and efficient and secure information query is achieved.

CN119051897BActive Publication Date: 2026-08-04CHINA CONSTRUCTION BANK +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA CONSTRUCTION BANK
Filing Date
2024-07-30
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

During the information sharing process between different business systems, there is a risk of sensitive information being leaked, resulting in low data security for information retrieval.

Method used

By embedding third-party service controls in the system's user interface, a request for encrypted account information is generated and sent. The information is encrypted using public key information, and the response information from the target server is received and displayed, enabling third-party information retrieval and avoiding the storage of sensitive user information in third-party services.

Benefits of technology

It improves the efficiency of information retrieval and data security, and prevents the leakage of sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119051897B_ABST
    Figure CN119051897B_ABST
Patent Text Reader

Abstract

The application provides an information query method and device, equipment and storage medium, and relates to the technical field of big data. The method comprises the following steps: displaying a user interface of a system, the user interface comprising at least one third-party service control; in response to a triggering operation on a target service control in the at least one third-party service control, generating first request information and sending the first request information to a target server corresponding to the target service control; the target service control interacts with the target server through a preconfigured interface; the first request information comprises account encryption information corresponding to a user in the target service control; the account encryption information is encrypted by public key information; receiving first response information sent by the target server; determining third-party information corresponding to the target service control according to the first response information; and displaying the third-party information on the user interface. The method improves the data security of information query.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of big data technology, and in particular to an information query method, apparatus, device and storage medium. Background Technology

[0002] Currently, the level of information digitization is increasing, allowing for the establishment of different business systems for different business operations.

[0003] Business systems can centrally store various business-related data for easy management and access; they can provide real-time data analysis to help enterprises quickly understand their business status; and they can facilitate the acquisition of business-related data and information exchange through information retrieval. As businesses become increasingly complex and the relationships between different business units become closer, it is necessary to use legal agreements to ensure timely information sharing and exchange between different business systems.

[0004] During the information sharing process between different business systems, there is a risk of sensitive information being leaked, resulting in low data security for information retrieval. Summary of the Invention

[0005] This application provides an information query method, apparatus, device, and storage medium to address the problem of low data security in information querying caused by the leakage of sensitive information in different business systems during information sharing.

[0006] Firstly, this application provides an information retrieval method, including:

[0007] The user interface of the display system includes at least one third-party service control;

[0008] In response to a trigger operation on a target service control in at least one third-party service control, a first request message is generated and sent to the target server corresponding to the target service control. The target service control interacts with the target server through a pre-configured interface. The first request message includes encrypted account information corresponding to the user in the target service control, and the encrypted account information is encrypted using public key information.

[0009] Receive the first response information sent by the target server;

[0010] Based on the first response information, the third-party information corresponding to the target service control is determined, and the third-party information is displayed on the user interface.

[0011] In one possible implementation, in response to a triggering operation on a target service control in at least one third-party service control, first request information is generated, including:

[0012] In response to a trigger operation on a target service control in at least one third-party service control, the user's user identifier is obtained;

[0013] Based on the user identifier, determine the account information corresponding to the user in the target service control;

[0014] Based on the account information, generate the first request information.

[0015] In one possible implementation, determining the user's account information corresponding to the target service control based on the user identifier includes:

[0016] Obtain the account mapping relationship between the system and at least one third-party service control, wherein the account mapping relationship includes multiple user identifiers, and the identifier and password of at least one third-party service control corresponding to each user identifier;

[0017] Based on the user identifier and the account mapping relationship, determine the account identifier and account password corresponding to the target service control;

[0018] Obtain permission mapping relationships, which include multiple user identifiers and permissions for at least one third-party service control corresponding to each user identifier;

[0019] Based on the user identifier and the permission mapping relationship, determine the user's access permissions in the target service control;

[0020] The account information includes the account identifier, the account password, and the access permissions.

[0021] In one possible implementation, the first request information is generated based on the account information, including:

[0022] Based on the access permissions, determine whether the user has the right to access the target service control;

[0023] If so, generate first request information based on the account identifier and the account password.

[0024] In one possible implementation, first request information is generated based on the account identifier and the account password, including:

[0025] Obtain the public key information corresponding to the system;

[0026] Based on the public key information, the account identifier and the account password are encrypted to determine the encrypted account information, thereby generating the first request information.

[0027] In one possible implementation, the method further includes:

[0028] Obtain the second request information sent by the first server, the second request information including sensitive user information;

[0029] Determine the first identifier corresponding to the user's sensitive information;

[0030] Based on the first identifier, a second response message is generated and sent to the first server.

[0031] In one possible implementation, determining the first identifier corresponding to the user sensitive information includes:

[0032] Obtain a user database, which includes sensitive user information of multiple users and a first identifier corresponding to each user;

[0033] Based on the user sensitive information and the user database, a first identifier corresponding to the user sensitive information is determined.

[0034] In one possible implementation, the user interface further includes a user-added control, and the method further includes:

[0035] In response to a trigger operation on the user addition control, a user addition interface is displayed, which includes multiple user information input controls and a confirmation control;

[0036] In response to input operations on the plurality of user information input controls, newly added sensitive user information is obtained;

[0037] In response to the triggering operation of the confirmation control, a new user identifier is generated, and the new user sensitive information is desensitized to obtain the corresponding desensitized user information;

[0038] The newly added user identifier, the newly added sensitive user information, and the de-identified user information are stored in the user database. The user database includes sensitive user information for multiple users, de-identified user information for each user, and user identifier for each user.

[0039] In one possible implementation, the user interface further includes a user query control, and the method further includes:

[0040] In response to input operations on the user query control, query information is obtained, including user identifier or user sensitive information;

[0041] Based on the query information, display the user's anonymized information corresponding to the query information.

[0042] Secondly, this application provides an information query device, comprising:

[0043] The first display module is used to display the system's user interface, which includes at least one third-party service control.

[0044] The processing module is configured to respond to a trigger operation on a target service control in at least one third-party service control, generate first request information, and send the first request information to the target server corresponding to the target service control. The target service control interacts with the target server through a pre-configured interface. The first request information includes encrypted account information corresponding to the user in the target service control, and the encrypted account information is encrypted using public key information.

[0045] The receiving module is used to receive the first response information sent by the target server;

[0046] The second display module is used to determine the third-party information corresponding to the target service control based on the first response information, and to display the third-party information on the user interface.

[0047] In one possible implementation, the processing module is specifically used for:

[0048] In response to a trigger operation on a target service control in at least one third-party service control, the user's user identifier is obtained;

[0049] Based on the user identifier, determine the account information corresponding to the user in the target service control;

[0050] Based on the account information, generate the first request information.

[0051] In one possible implementation, the processing module is specifically used for:

[0052] Obtain the account mapping relationship between the system and at least one third-party service control, wherein the account mapping relationship includes multiple user identifiers, and the identifier and password of at least one third-party service control corresponding to each user identifier;

[0053] Based on the user identifier and the account mapping relationship, determine the account identifier and account password corresponding to the target service control;

[0054] Obtain permission mapping relationships, which include multiple user identifiers and permissions for at least one third-party service control corresponding to each user identifier;

[0055] Based on the user identifier and the permission mapping relationship, determine the user's access permissions in the target service control;

[0056] The account information includes the account identifier, the account password, and the access permissions.

[0057] In one possible implementation, the processing module is specifically used for:

[0058] Based on the access permissions, determine whether the user has the right to access the target service control;

[0059] If so, generate first request information based on the account identifier and the account password.

[0060] In one possible implementation, the processing module is specifically used for:

[0061] Obtain the public key information corresponding to the system;

[0062] Based on the public key information, the account identifier and the account password are encrypted to determine the encrypted account information, thereby generating the first request information.

[0063] In one possible implementation, the apparatus further includes a first query module, the first query module being used for:

[0064] Obtain the second request information sent by the first server, the second request information including sensitive user information;

[0065] Determine the first identifier corresponding to the user's sensitive information;

[0066] Based on the first identifier, a second response message is generated and sent to the first server.

[0067] In one possible implementation, the first query module is specifically used for:

[0068] Obtain a user database, which includes sensitive user information of multiple users and a first identifier corresponding to each user;

[0069] Based on the user sensitive information and the user database, a first identifier corresponding to the user sensitive information is determined.

[0070] In one possible implementation, the user interface further includes a user addition control, and the device further includes an addition module, which is specifically used for:

[0071] In response to a trigger operation on the user addition control, a user addition interface is displayed, which includes multiple user information input controls and a confirmation control;

[0072] In response to input operations on the plurality of user information input controls, newly added sensitive user information is obtained;

[0073] In response to the triggering operation of the confirmation control, a new user identifier is generated, and the new user sensitive information is desensitized to obtain the corresponding desensitized user information;

[0074] The newly added user identifier, the newly added sensitive user information, and the de-identified user information are stored in the user database. The user database includes sensitive user information for multiple users, de-identified user information for each user, and user identifier for each user.

[0075] In one possible implementation, the user interface further includes a user query control, and the device further includes a second query module, which is specifically used for:

[0076] In response to input operations on the user query control, query information is obtained, including user identifier or user sensitive information;

[0077] Based on the query information, display the user's anonymized information corresponding to the query information.

[0078] Thirdly, embodiments of this application provide an electronic device, including: at least one processor and a memory; the memory stores computer execution instructions; the at least one processor executes the computer execution instructions stored in the memory, causing the at least one processor to perform the information query method as described in the first aspect and various possible designs of the first aspect.

[0079] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions. When a processor executes the computer-executable instructions, it implements the information query method described in the first aspect and various possible designs of the first aspect.

[0080] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the information query method described in the first aspect and various possible designs of the first aspect.

[0081] The information query method, apparatus, device, and storage medium provided in this application, through a user interface of a display system, the user interface including at least one third-party service control, generates first request information in response to a trigger operation on a target service control among the at least one third-party service controls, and sends the first request information to a target server corresponding to the target service control. The target service control interacts with the target server through a pre-configured interface. The first request information includes encrypted account information corresponding to the user in the target service control, which is encrypted using public key information. The system receives a first response information sent by the target server, determines the third-party information corresponding to the target service control based on the first response information, and displays the third-party information on the user interface. In this way, third-party services can be embedded in the system, and the query of third-party information can be realized through controls in the system. Furthermore, the request information is encrypted account information, eliminating the need to store sensitive user information in the third-party service, thus improving both information query efficiency and data security. Attached Figure Description

[0082] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0083] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of this application;

[0084] Figure 2 A flowchart illustrating an information query method provided in an embodiment of this application;

[0085] Figure 3 A flowchart illustrating another information query method provided in an embodiment of this application;

[0086] Figure 4 A flowchart illustrating another information query method provided in this application embodiment;

[0087] Figure 5 A flowchart illustrating another information query method provided in an embodiment of this application;

[0088] Figure 6 A schematic diagram of a user addition interface provided in an embodiment of this application;

[0089] Figure 7 This is a schematic diagram of the structure of an information query device provided in an embodiment of this application;

[0090] Figure 8 This is a schematic diagram of another information query device provided in an embodiment of this application;

[0091] Figure 9This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0092] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0093] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0094] It should be noted that the collection, storage, use, processing, transmission, provision, and disclosure of financial data or user data involved in the technical solution of this application all comply with the provisions of relevant laws and regulations and do not violate public order and good morals. It should also be noted that certain software, components, models, and other existing industry solutions may be mentioned in the embodiments of this application. These should be considered exemplary and their purpose is merely to illustrate the feasibility of implementing the technical solution of this application, but does not imply that the applicant has already used or necessarily used such solutions.

[0095] Currently, the level of information digitization is increasing, allowing for the establishment of different business systems for different business operations.

[0096] Business systems can centrally store various business-related data for easy management and access; they can provide real-time data analysis to help enterprises quickly understand their business status; and they can facilitate the acquisition of business-related data and information exchange through information retrieval. As businesses become increasingly complex and the relationships between different business units become closer, it is necessary to use legal agreements to ensure timely information sharing and exchange between different business systems.

[0097] During the information sharing process between different business systems, there is a risk of sensitive information being leaked, resulting in low data security for information retrieval.

[0098] To address the aforementioned technical problems, this application provides an information query method. The method involves displaying a system user interface, which includes at least one third-party service control. In response to a trigger operation on a target service control within the at least one third-party service control, a first request is generated and sent to a target server corresponding to the target service control. The target service control interacts with the target server through a pre-configured interface. The first request includes encrypted account information corresponding to the user within the target service control. The method also receives a first response from the target server to determine the third-party information corresponding to the target service control. This approach allows for the embedding of third-party services within the system, enabling the querying of third-party information through system controls. Furthermore, since the request information is encrypted account information, there is no need to store sensitive user information in the third-party service, thus improving both information query efficiency and data security.

[0099] Below, in conjunction with Figure 1 The application scenarios of this application will be explained.

[0100] Figure 1 This is a schematic diagram illustrating an application scenario provided by an embodiment of this application. Please refer to... Figure 1 The network architecture on which this application is based includes at least electronic devices 101 and servers 102. The number of electronic devices 101 can be one or more, and the number of servers 102 can be one or more.

[0101] The electronic device 101 can be any type of terminal, such as a mobile phone, computer, tablet, wearable device, etc. This application embodiment does not specifically limit the electronic device. The electronic device 101 may include a user interface for an information query system, allowing users to obtain query results through the user interface.

[0102] Server 102 can be equipped with an information query system and a corresponding database, which can store a large amount of business data and user information, etc. Server 102 can establish communication connections with other servers. Server 102 can interact with other servers, send request information to obtain third-party information from other servers, and the third-party information can be displayed as query results.

[0103] Server 102 can be a cloud server, a distributed system server, or a server integrated with blockchain; no specific limitations are made here. The instruction processing system can be written in languages ​​such as C / C++, Java, Shell, or Python; no specific limitations are made here.

[0104] Electronic device 101 establishes a communication connection with server 102, and server 102 establishes communication connections with other servers. For example, electronic device 101 can establish a communication connection with server 102 through protocols such as Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol over Secure Socket Layer (HTTPS), without being specifically limited here.

[0105] The technical solutions shown in this application will now be described in detail through specific embodiments. It should be noted that the following embodiments may exist independently or in combination with each other; for the same or similar content, the description will not be repeated in different embodiments.

[0106] Figure 2 This is a flowchart illustrating an information query method provided in an embodiment of this application. The executing entity in this embodiment can be a server or an information query system set within a server. The information query system can be implemented through software or a combination of software and hardware. Please refer to... Figure 2 The method includes:

[0107] S201, Display system user interface.

[0108] The system can be a system for information retrieval.

[0109] The user interface (UI) is the interface displayed after a user logs into the system. The UI is determined based on the user's login information. Different users have different user permissions; these permissions are determined through the user's login information, and the UI corresponding to those permissions is displayed accordingly.

[0110] The user interface may include at least one third-party service control. This third-party service control can be used to send requests to the server corresponding to the third-party system to query third-party information. The third-party information may be relevant information stored in the third-party system.

[0111] It can respond to user input and confirmation actions on the login control, obtain the user's login information, and display the system's user interface after the user's login information is verified.

[0112] S202. In response to a trigger operation on a target service control in at least one third-party service control, generate first request information and send the first request information to the target server corresponding to the target service control.

[0113] The target service control can be any one of at least one third-party service control. The target service control can interact with the target server through a pre-configured interface. The target service control can be used to provide the target service.

[0114] The triggering action can be an interaction between the user and the field control through mouse clicks, screen touch, or other input devices.

[0115] The first request information may include the encrypted account information corresponding to the user in the target service control.

[0116] Account encryption information can be encrypted using public key information. This information can include an encrypted account identifier and an encrypted account password.

[0117] The target server can be the server corresponding to the target service control.

[0118] Optionally, in response to a trigger operation on a target service control in at least one third-party service control, the system may obtain account information corresponding to the target service control, generate first request information based on the account information, and send the first request information to the target server corresponding to the target service control.

[0119] Optionally, in response to a trigger operation on a target service control in at least one third-party service control, the system obtains the account identifier, account password, and access permissions corresponding to the target service control, generates first request information based on the account identifier, account password, and access permissions, and sends the first request information to the target server corresponding to the target service control.

[0120] It should be noted that, in response to a triggering operation on at least one third-party service control, a first request message can be generated and sent to the target server corresponding to the target service control, according to any feasible implementation method. This disclosure does not limit this.

[0121] S203, Receive the first response information sent by the target server.

[0122] The first response message can be information sent by the target server. The first response message includes relevant information about the target service.

[0123] It can obtain the message information sent by the target server, parse and process the message information, and obtain the first response information sent by the target server.

[0124] S204. Based on the first response information, determine the third-party information corresponding to the target service control and display the third-party information on the user interface.

[0125] Third-party information can be used to represent user-related information stored in a third-party system within the target service.

[0126] The first response information can be parsed and processed to determine the third-party information corresponding to the target service control, and the third-party information can be displayed on the user interface.

[0127] For example, assuming the target service control is a recipe management service, the first request information may include the encrypted account information corresponding to the user in the recipe management service control, and the third-party information may be recipe management information about the user.

[0128] The information query method provided in this embodiment displays a user interface of the system, which includes at least one third-party service control. In response to a trigger operation on a target service control within the at least one third-party service control, a first request message is generated and sent to the target server corresponding to the target service control. The target service control interacts with the target server through a pre-configured interface. The first request message includes encrypted account information corresponding to the user in the target service control, which is encrypted using public key information. The method receives a first response message from the target server, determines the third-party information corresponding to the target service control based on the first response message, and displays the third-party information on the user interface. This allows for the embedding of third-party services within the system, enabling the querying of third-party information through system controls. Furthermore, since the request information is encrypted account information, there is no need to store sensitive user information in the third-party service, thus improving both the efficiency and data security of information queries.

[0129] Below, in conjunction with Figure 3 The process of generating first request information in response to a trigger operation on a target service control in at least one third-party service control is further explained.

[0130] Figure 3 This is a flowchart illustrating another information query method provided in an embodiment of this application. Based on the above embodiments, see [link to relevant documentation]. Figure 3 The method includes:

[0131] S301. In response to a trigger operation on a target service control in at least one third-party service control, obtain the user's user identifier.

[0132] User identifiers are used to verify user identity and determine which users have the necessary permissions to access the system or use specific services. Each user's user identifier is unique within the system.

[0133] In response to a trigger operation on a target service control in at least one third-party service control, obtain the user's system information and determine the user's user identifier based on the system information.

[0134] S302. Obtain the account mapping relationship between the system and at least one third-party service control.

[0135] Account mapping relationships can be pre-stored. An account mapping relationship may include multiple user identifiers, and the identifier and password of at least one third-party service control corresponding to each user identifier.

[0136] Below, we will illustrate the account mapping relationship with examples from Table 1.

[0137] Table 1

[0138]

[0139] The user identifier's account information may include account information for one or more service controls. The number of service controls can be determined based on the user's system information.

[0140] S303. Based on the user identifier and account mapping relationship, determine the account identifier and account password corresponding to the target service control.

[0141] Based on the user identifier, the target account information corresponding to the user identifier can be determined in the account mapping relationship. Based on the target account information and the target service control, the account identifier and account password corresponding to the target service control can be determined.

[0142] S304. Obtain permission mapping relationship.

[0143] The permission mapping relationship can be pre-stored. The permission mapping relationship can include multiple user identifiers and permissions of at least one third-party service control corresponding to each user identifier.

[0144] Permissions can be adjusted at preset intervals based on actual needs.

[0145] Below, we will illustrate the permission mapping relationship with reference to Table 2.

[0146] Table 2

[0147]

[0148] S305. Determine the user's access permissions in the target service control based on the user identifier and permission mapping relationship.

[0149] Based on the user identifier, the access permission information corresponding to the user identifier can be determined in the permission mapping relationship. Based on the access permission information and the target service control, the user's corresponding access permission in the target service control can be determined.

[0150] S306. Based on access permissions, determine whether the user has the right to access the target service control.

[0151] If so, then execute S307;

[0152] If not, then execute S308.

[0153] For example, if the access permission is "no access", then it is determined that the user does not have permission to access the target service control; if the access permission is "right access", then it is determined that the user has permission to access the target service control.

[0154] S307. Generate the first request information based on the account identifier and account password.

[0155] The account identifier and password can be encrypted to obtain encrypted account information, and the first request information can be generated based on the encrypted account information.

[0156] Optionally, the first request information can be generated based on the account identifier and password in the following way: obtain the public key information corresponding to the system; encrypt the account identifier and password based on the public key information to determine the encrypted account information, and generate the first request information.

[0157] Public key information can be a digital certificate issued by a trusted certificate authority, and it can include the public key and the identity information of its owner.

[0158] Public key information can be used to encrypt account-related information to generate a first request message, which is then sent to the target server.

[0159] Correspondingly, the target server can store the private key information corresponding to the public key information. The private key information can be used to decrypt information encrypted with the corresponding public key.

[0160] S308. Display access restriction information on the user interface.

[0161] Access restriction information can be used to indicate that a user does not have permission to access the target service control.

[0162] If it is determined that a user does not have permission to access the target service control, access restriction information can be displayed on the user interface.

[0163] The implementation details of each step in this application embodiment can be found in the description of the corresponding steps or operations in the above method embodiments; repeated content will not be repeated.

[0164] The information query method provided in this embodiment obtains a user's identifier in response to a trigger operation on a target service control within at least one third-party service control. It then obtains an account mapping relationship between the system and at least one third-party service control, where the account mapping relationship includes multiple user identifiers and the identifier and password of at least one third-party service control corresponding to each user identifier. Based on the user identifier and the account mapping relationship, it determines the account identifier and password corresponding to the target service control. Next, it obtains a permission mapping relationship, which includes multiple user identifiers and the permissions of at least one third-party service control corresponding to each user identifier. Based on the user identifier and the permission mapping relationship, it determines the user's access permissions within the target service control. The account information includes the account identifier, password, and access permissions. Based on the access permissions, it determines whether the user has the right to access the target service control. If so, it generates first request information based on the account identifier and password. This allows embedding third-party services within the system, enabling the querying of third-party information through system controls. Furthermore, the request information is encrypted account information, eliminating the need to store sensitive user information in the third-party service. This improves both the efficiency and data security of information queries.

[0165] In one possible implementation, the information query method further includes a second request message sent by the first server to query the user identifier corresponding to the user's sensitive information.

[0166] Below, in conjunction with Figure 4 The process of querying the user identifier corresponding to the user's sensitive information by responding to the second request information sent by the first server will be further explained.

[0167] Figure 4 This is a flowchart illustrating another information query method provided in an embodiment of this application. Based on the above embodiments, see [link to relevant documentation]. Figure 4 The method includes:

[0168] S401. Obtain the second request information sent by the first server.

[0169] The first server can be any server corresponding to a third-party service. The first server does not store any user-sensitive information. User-sensitive information may include name, age, ID number, mobile phone number, etc., and there are no restrictions on this.

[0170] The second request information may include sensitive user information. This second request information can be used to query the first identifier corresponding to the sensitive user information. The first identifier can be used to represent the user's identity information within the system where the first server resides.

[0171] Optionally, the system on which the first server is located can be any third-party system.

[0172] It can receive message information sent by the first server, parse and process the message information, and obtain the second request information sent by the first server.

[0173] S402. Determine the first identifier corresponding to the user's sensitive information.

[0174] The system can determine whether sensitive user information exists in the corresponding database. If it does, the user identifier corresponding to the sensitive user information can be determined.

[0175] Optionally, the first identifier corresponding to the user's sensitive information can be determined by: obtaining the user database; and determining the first identifier corresponding to the user's sensitive information based on the user's sensitive information and the user database.

[0176] The user database may include sensitive user information for multiple users, as well as a primary identifier for each user. The primary identifier can be used to represent the user's identity information within the system where the primary server resides.

[0177] S403. Generate a second response message based on the first identifier and send the second response message to the first server.

[0178] The second response information may include encrypted information corresponding to the first identifier.

[0179] The first identifier can be encrypted to generate a second response message, which is then sent to the first server.

[0180] The implementation details of each step in this application embodiment can be found in the description of the corresponding steps or operations in the above method embodiments; repeated content will not be repeated.

[0181] The information query method provided in this embodiment obtains second request information sent by a first server. This second request information includes sensitive user information. Based on the sensitive user information, a user identifier corresponding to the sensitive user information is determined. Based on the user identifier, second response information is generated and sent to the first server. This allows for the embedding of third-party services in the main system. The servers corresponding to these third-party services do not store sensitive user information. If the server needs to determine the user identifier corresponding to the sensitive user information, it can interact with the main system to obtain the user identifier, thus improving the data security of information queries.

[0182] In one possible implementation, the information query method further includes adding new users and de-identifying sensitive user information of the new users. Below, in conjunction with... Figure 5 The above process will be further explained.

[0183] Figure 5This is a flowchart illustrating another information query method provided in an embodiment of this application. Based on the above embodiments, see [link to relevant documentation]. Figure 5 The user interface also includes a user-added control, which includes the following methods:

[0184] S501. In response to the trigger operation of the user adding control, display the user adding interface.

[0185] The user addition control can be used to add new users to the system.

[0186] The user addition interface can be used to obtain user information for newly added users.

[0187] The user creation interface can include multiple user information input controls and confirmation controls.

[0188] Multiple user information input controls may include sub-controls for name information input, date of birth input, gender information input, etc., and are not limited here.

[0189] It can respond to user actions that trigger the user's new control, determine the user's identifier, and based on the user identifier, determine whether the user has permission to add new users. If so, display the user addition interface.

[0190] S502, In response to input operations on multiple user information input controls, obtain newly added sensitive user information.

[0191] Sensitive user information may include user name, date of birth, gender, ID number, etc., and is not limited here.

[0192] Users can input information into multiple user information input controls, and the system can retrieve newly added sensitive user information in response to input into these controls.

[0193] S503. In response to the trigger operation of the confirmation control, generate the newly added user identifier and perform desensitization processing on the newly added user sensitive information to obtain the corresponding desensitized user information.

[0194] The newly added user identifier can be used to represent the identity information of the new user.

[0195] De-identification can be used to protect certain parts of a user's sensitive information and prevent that information from being leaked.

[0196] Users can trigger the confirmation control. In response to the triggering operation of the confirmation control, a new user identifier is generated, and new sensitive user information is identified. The new sensitive user information is then de-identified to obtain the corresponding de-identified user information.

[0197] S504. Store the newly added user identifier, newly added sensitive user information, and de-identified user information in the user database.

[0198] The user database may include sensitive user information for multiple users, de-identified user information for each user, and a user identifier for each user.

[0199] In one possible implementation, the information query method further includes a user information query process, which can query user de-identified information in the following way: in response to input operation on the user query control, obtain query information; and display the user de-identified information corresponding to the query information based on the query information.

[0200] The query information may include user identifiers or sensitive user information. User-de-identified information may be all de-identified information for that user, or only a portion of that user's de-identified information.

[0201] Below, in conjunction with Figure 6 The processes S501-S504 will be explained.

[0202] Figure 6 This is a schematic diagram of a user addition interface provided in an embodiment of this application. Please refer to [link / reference]. Figure 6 This includes interface 601 and interface 602.

[0203] Please refer to interface 601, which includes multiple user information input controls and confirmation controls. In response to input operations on the multiple user information input controls and in response to triggering operations on the confirmation controls, newly added user sensitive information and newly added user identifiers are obtained.

[0204] Please refer to interface 602, which includes the de-identified user information obtained after de-identifying the newly added sensitive user information. The newly added user identifier, the newly added sensitive user information, and the de-identified user information are stored in the user database.

[0205] The implementation details of each step in this application embodiment can be found in the description of the corresponding steps or operations in the above method embodiments; repeated content will not be repeated.

[0206] The information query method provided in this embodiment displays a user addition interface in response to a trigger operation on a user addition control. The user addition interface includes multiple user information input controls and a confirmation control. In response to input operations on the multiple user information input controls, newly added sensitive user information is obtained. In response to a trigger operation on the confirmation control, a newly added user identifier is generated. The newly added sensitive user information is then anonymized to obtain corresponding anonymized user information. The newly added user identifier, newly added sensitive user information, and anonymized user information are stored in a user database. The user database includes sensitive user information for multiple users, anonymized user information for each user, and a user identifier for each user. This allows for the setting of user addition controls and the anonymization of newly added sensitive user information within the main system, improving the data security of information queries.

[0207] Figure 7 This is a schematic diagram of the structure of an information query device provided in an embodiment of this application. Please refer to [link / reference]. Figure 7 The device 700 includes a first display module 701, a processing module 702, a receiving module 703, and a second display module 704, wherein...

[0208] The first display module 701 is used to display the system's user interface, which includes at least one third-party service control.

[0209] The processing module 702 is configured to generate first request information in response to a trigger operation on a target service control in at least one third-party service control, and send the first request information to the target server corresponding to the target service control. The target service control interacts with the target server through a pre-configured interface. The first request information includes encrypted account information corresponding to the user in the target service control, and the encrypted account information is encrypted using public key information.

[0210] The receiving module 703 is used to receive the first response information sent by the target server;

[0211] The second display module 704 is used to determine the third-party information corresponding to the target service control based on the first response information, and to display the third-party information on the user interface.

[0212] In one possible implementation, the processing module 702 is specifically used for:

[0213] In response to a trigger operation on a target service control in at least one third-party service control, the user's user identifier is obtained;

[0214] Based on the user identifier, determine the account information corresponding to the user in the target service control;

[0215] Based on the account information, generate the first request information.

[0216] In one possible implementation, the processing module 702 is specifically used for:

[0217] Obtain the account mapping relationship between the system and at least one third-party service control, wherein the account mapping relationship includes multiple user identifiers, and the identifier and password of at least one third-party service control corresponding to each user identifier;

[0218] Based on the user identifier and the account mapping relationship, determine the account identifier and account password corresponding to the target service control;

[0219] Obtain permission mapping relationships, which include multiple user identifiers and permissions for at least one third-party service control corresponding to each user identifier;

[0220] Based on the user identifier and the permission mapping relationship, determine the user's access permissions in the target service control;

[0221] The account information includes the account identifier, the account password, and the access permissions.

[0222] In one possible implementation, the processing module 702 is specifically used for:

[0223] Based on the access permissions, determine whether the user has the right to access the target service control;

[0224] If so, generate first request information based on the account identifier and the account password.

[0225] In one possible implementation, the processing module 702 is specifically used for:

[0226] Obtain the public key information corresponding to the system;

[0227] Based on the public key information, the account identifier and the account password are encrypted to determine the encrypted account information, thereby generating the first request information.

[0228] Figure 8 This is a schematic diagram of another information query device provided in an embodiment of this application. Figure 7 Based on the illustrated embodiments, please refer to Figure 8 The information query device 700 further includes a first query module 705. The first query module 705 is used for:

[0229] Obtain the second request information sent by the first server, the second request information including sensitive user information;

[0230] Determine the first identifier corresponding to the user's sensitive information;

[0231] Based on the first identifier, a second response message is generated and sent to the first server.

[0232] In one possible implementation, the first query module 705 is specifically used for:

[0233] Obtain a user database, which includes sensitive user information of multiple users and a first identifier corresponding to each user;

[0234] Based on the user sensitive information and the user database, a first identifier corresponding to the user sensitive information is determined.

[0235] In one possible implementation, the user interface further includes a user addition control, and the device further includes an addition module 706, which is specifically used for:

[0236] In response to a trigger operation on the user addition control, a user addition interface is displayed, which includes multiple user information input controls and a confirmation control;

[0237] In response to input operations on the plurality of user information input controls, newly added sensitive user information is obtained;

[0238] In response to the triggering operation of the confirmation control, a new user identifier is generated, and the new user sensitive information is desensitized to obtain the corresponding desensitized user information;

[0239] The newly added user identifier, the newly added sensitive user information, and the de-identified user information are stored in the user database. The user database includes sensitive user information for multiple users, de-identified user information for each user, and user identifier for each user.

[0240] In one possible implementation, the user interface further includes a user query control, and the device further includes a second query module 707, which is specifically used for:

[0241] In response to input operations on the user query control, query information is obtained, including user identifier or user sensitive information;

[0242] Based on the query information, display the user's anonymized information corresponding to the query information.

[0243] It should be noted that the division of the various modules in the above device is merely a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. These modules can be implemented entirely in software via processing element calls; they can be fully implemented in hardware; or some modules can be implemented in software via processing element calls, while others are implemented in hardware. Each module can be a separate processing element, or it can be integrated into a chip within the device. Alternatively, it can be stored as program code in the device's memory, and its functions can be called and executed by a processing element. Furthermore, these modules can be fully or partially integrated together, or they can be implemented independently. The processing element here can be an integrated circuit with signal processing capabilities. During implementation, each step of the above method or each of the above modules can be completed through integrated logic circuits in the processor element or through software instructions.

[0244] Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 9 As shown, the electronic device may include: a transceiver 901, a processor 902, and a memory 903.

[0245] Processor 902 executes computer execution instructions stored in memory, causing processor 902 to perform the scheme in the above embodiments. Processor 902 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0246] The memory 903 is connected to the processor 902 via the system bus and completes communication between them. The memory 903 is used to store computer program instructions.

[0247] Transceiver 901 can be used to obtain the task to be run and its configuration information.

[0248] The system bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The system bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in the diagram, but this does not indicate that there is only one bus or one type of bus. Transceivers are used to enable communication between database access devices and other computers (e.g., clients, read-write libraries, and read-only libraries). Memory may include random access memory (RAM) and may also include non-volatile memory.

[0249] The electronic device provided in this application embodiment can be the terminal device described in the above embodiments.

[0250] This application also provides a chip for executing instructions, which is used to execute the information query method described in the above embodiments.

[0251] This application also provides a computer-readable storage medium storing computer instructions. When the computer instructions are executed on a computer, the computer performs the technical solution of the information query method described in the above embodiments.

[0252] This application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when the at least one processor executes the computer program, it can implement the technical solution of the information query method in the above embodiments.

[0253] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or modules, and may be electrical, mechanical, or other forms.

[0254] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to implement the solution of this embodiment according to actual needs.

[0255] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing unit, or each module can exist physically separately, or two or more modules can be integrated into one unit. The unit composed of the above modules can be implemented in hardware or in the form of hardware plus software functional units.

[0256] The integrated modules described above, implemented as software functional modules, can be stored in a computer-readable storage medium. These software functional modules, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods of the various embodiments of this application.

[0257] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.

[0258] The memory may include high-speed RAM, and may also include non-volatile storage (NVM), such as at least one disk storage device, and may also be a USB flash drive, external hard drive, read-only memory, disk or optical disc, etc.

[0259] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0260] The aforementioned storage medium can be implemented from any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium accessible to general-purpose or special-purpose computers.

[0261] An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. The storage medium can also be a component of the processor. The processor and storage medium can reside in an application-specific integrated circuit (ASIC). Alternatively, the processor and storage medium can exist as discrete components in an electronic control unit or main control device.

[0262] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0263] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. An information search method characterized by comprising: include: The user interface of the display system includes at least one third-party service control; In response to a trigger operation on a target service control in at least one third-party service control, obtain the user identifier of the current user; Based on the user identifier and the pre-stored account mapping relationship, determine the account identifier and account password corresponding to the target service control; The account mapping relationship includes multiple user identifiers, and the identifier and password of at least one third-party service control corresponding to each user identifier; Based on the account identifier and the account password, a first request message is generated and sent to the target server corresponding to the target service control. The target service control interacts with the target server through a pre-configured interface. The first request message includes encrypted account information corresponding to the user in the target service control. The encrypted account information is encrypted using public key information. The encrypted account information includes an encrypted account identifier and an encrypted account password. Receive the first response information sent by the target server; Based on the first response information, the third-party information corresponding to the target service control is determined, and the third-party information is displayed on the user interface.

2. The method of claim 1, wherein, Based on the account identifier and the account password, generate first request information, including: Obtain permission mapping relationships, which include multiple user identifiers and permissions for at least one third-party service control corresponding to each user identifier; Based on the user identifier and the permission mapping relationship, determine the user's access permissions in the target service control; Based on the access permissions, determine whether the user has the right to access the target service control; If so, generate first request information based on the account identifier and the account password.

3. The method according to claim 2, characterized in that, Based on the account identifier and the account password, generate first request information, including: Obtain the public key information corresponding to the system; Based on the public key information, the account identifier and the account password are encrypted to determine the encrypted account information, thereby generating the first request information.

4. The method of claim 1, wherein, The method further includes: Obtain the second request information sent by the first server, the second request information including sensitive user information; Determine the first identifier corresponding to the user's sensitive information; Based on the first identifier, a second response message is generated and sent to the first server.

5. The method according to claim 4, characterized in that, Determining the first identifier corresponding to the user sensitive information includes: Obtain a user database, which includes sensitive user information of multiple users and a first identifier corresponding to each user; Based on the user sensitive information and the user database, a first identifier corresponding to the user sensitive information is determined.

6. The method according to any one of claims 1 to 5, characterized in that, The user interface also includes a user addition control, and the method further includes: In response to a trigger operation on the user addition control, a user addition interface is displayed, which includes multiple user information input controls and a confirmation control; In response to input operations on the plurality of user information input controls, newly added sensitive user information is obtained; In response to the triggering operation of the confirmation control, a new user identifier is generated, and the new user sensitive information is desensitized to obtain the corresponding desensitized user information; The newly added user identifier, the newly added sensitive user information, and the de-identified user information are stored in the user database. The user database includes sensitive user information for multiple users, de-identified user information for each user, and user identifier for each user.

7. The method of claim 6, wherein, The user interface also includes a user query control, and the method further includes: In response to input operations on the user query control, query information is obtained, including user identifier or user sensitive information; Based on the query information, display the user's anonymized information corresponding to the query information.

8. An information inquiry apparatus characterized by comprising: include: The first display module is used to display the system's user interface, which includes at least one third-party service control. The processing module is configured to, in response to a trigger operation on a target service control in at least one third-party service control, obtain the user identifier of the current user; and determine the account identifier and account password corresponding to the target service control based on the user identifier and a pre-stored account mapping relationship. The account mapping relationship includes multiple user identifiers, and the identifier and password of at least one third-party service control corresponding to each user identifier; based on the account identifier and the account password, a first request message is generated and sent to the target server corresponding to the target service control. The target service control interacts with the target server through a pre-configured interface. The first request message includes encrypted account information corresponding to the user in the target service control, which is encrypted using public key information; the encrypted account information includes an encrypted account identifier and an encrypted account password. The receiving module is used to receive the first response information sent by the target server; The second display module is used to determine the third-party information corresponding to the target service control based on the first response information, and to display the third-party information on the user interface.

9. An electronic device, comprising: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-7.

10. A computer readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-7.

11. A computer program product, characterised in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-7.