User data authorization method and system based on trusted digital identity
Through the data authorization center system and the trusted digital identity authentication system, users initiate authorization requests and perform identity authentication in the third-party business system, generate authorization records and credential data, solving the problem of data leakage and authorization opacity in the prior art, and achieving efficient and secure user data authorization.
Patent Information
- Application Number
- CN202411974164.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-13
AI Technical Summary
The prior art lacks encryption protection for user input information in the user data authorization process of third-party applications, poses a risk of data leakage, and the authorization process is not transparent, users cannot understand the authorization content in detail, and cannot effectively monitor and manage access to user data by third-party applications.
Through the data authorization center system, users initiate authorization requests through third-party business systems. The data authorization center generates a unique authorization flow number and authorization page URL. The user confirms the authorization information on the authorization page and locally encrypts it through front-end encryption technology. Then, identity authentication is performed through a trusted digital identity authentication system. The data authorization center generates user authorization records, authorization authentication records and authorization credential data, and ensures the security of user data through a fine-grained access control mechanism and data recycling mechanism.
It realizes efficient authentication and authorization of third-party applications while ensuring the security and privacy of user data, providing users with a more secure and trustworthy authorization environment, and improving the security, credibility and convenience of user data authorization.
Smart Images

Figure CN119989400A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and mainly to a user data authorization method and system based on a trusted digital identity. Background Art
[0002] With the rapid development of Internet technology, third-party applications (such as social platforms, e-commerce platforms, etc.) are increasingly used in users' daily lives. These applications usually need to obtain certain personal information or permissions of users in order to provide more personalized services. However, with the frequent occurrence of data leakage and privacy leakage incidents, users have put forward higher requirements for the security and privacy protection of personal information. Therefore, how to achieve effective authentication and authorization of third-party applications while ensuring the security and privacy of user data has become an urgent problem to be solved.
[0003] For example, the Chinese invention patent with the publication number CN103888451B discloses an authentication authorization method, device and system. Among them, the authorization method includes: receiving an authentication request sent by a server of a third-party application, the authentication request carries the account information, third-party application information and the permission information to be obtained entered by the user on the login interface provided by the third-party application; parsing the authentication request to obtain the parsing result, interacting with the corresponding application according to the parsing result and the correspondence between the pre-stored account information and the long connection channel information, generating an authorization code, and sending the authorization code to the server of the third-party application; and receiving an information acquisition request containing the authorization code sent by the server of the third-party application, returning the corresponding user information to the server of the third-party application according to the information acquisition request, so that the server of the third-party application completes the authentication process according to the corresponding user information. The above invention can make the user login interface completely provided by the third-party application, and can ensure the security of the account and data, but the above invention lacks encryption protection for the user input information, there is a risk of data leakage, and it only relies on account information, and the security level is low; the authorization process is not transparent, and the user cannot understand the authorization content in detail. The above invention cannot effectively monitor and manage the access of the third-party application to the user data, and the user data may be retained in the third-party application for a long time, increasing the risk of leakage. Therefore, there is an urgent need for an authorization method that can achieve efficient authentication and authorization of third-party applications while ensuring user data security and privacy, and provide users with a more secure and reliable authorization environment. Summary of the invention
[0004] In order to solve the above problems existing in the prior art, the present application provides a user data authorization method and system based on trusted digital identity.
[0005] The technical solution of this application is as follows:
[0006] A user data authorization method based on a trusted digital identity, the method comprising:
[0007] The user initiates an authorization request for the user's personal data to the data authorization center system through a third-party business system, and the authorization request includes the authorization data items required by the user and business context information;
[0008] The data authorization center system receives the authorization request and obtains the user's authorization status. If the user's authorization status is unauthorized, the data authorization center system generates a unique authorization serial number and generates an authorization page URL address according to a preset security policy. The authorization serial number is embedded in the authorization page URL address, and the authorization page URL address is returned to the third-party business system;
[0009] The third-party business system redirects the user to the authorization page URL address, and the user views and confirms the authorization data items, authorization time and business matters on the authorization page, wherein the authorization page partially encrypts the identity information entered by the user through the front-end encryption technology;
[0010] After the user confirms the authorization, the trusted digital identity authentication system and CTID platform will be used for trusted digital identity authentication. If the trusted digital identity authentication is successful, the authentication result and authentication credential number will be returned;
[0011] The data authorization center system confirms the authorization based on the authentication credential number and the authorization serial number, and generates a user authorization record, an authorization authentication record and authorization credential data. The user authorization record includes the authorization record ID, the digital identity identifier BID, the authorization data item, the authorization validity period, the authorization method, the authorization time, the authorized business items, the third-party business system information, the creation time and the authorization serial number after the authorization is confirmed; the authorization authentication record includes the authentication record ID, the digital identity identifier BID, the user authorization record ID, the authentication credential number, the authentication time, the authentication mode, the authentication device information and the creation time; the authorization credential data is the credential data generated when the data authorization center system generates the user authorization record and the authorization authentication record, including the credential record ID, the digital identity identifier BID, the authorization record ID, the user authorization record information signature value, the authentication record ID, the authorization authentication record signature value, the authorization credential record signature value and the creation time, and the signature value is generated using the national secret SM2 signature algorithm;
[0012] The data authorization center system packages the authorization data items confirmed by the user to generate an authorization data packet, and returns the authorization serial number after confirmation to the third-party business system through a secure communication protocol. The third-party business system obtains the user's authorization data packet based on the authorization serial number after confirmation.
[0013] As a preferred implementation of the present invention, the preset security policy includes:
[0014] When generating the authorization page URL address, add the current timestamp and a randomly generated nonce value, and set the expiration time; use the national secret SM3 algorithm to hash the parameters in the generated authorization page URL address, generate a signature, and attach the signature to the authorization page URL address;
[0015] When the third-party business system receives the authorization page URL address, it verifies the expiration time through the current timestamp in the authorization page URL address, checks whether the nonce value is a unique value, and recalculates the signature using the same parameters and national secret SM3 algorithm as the authorization page URL address, and compares the recalculated signature with the signature in the authorization page URL address. If the expiration time, nonce value and signature are all verified, the third-party business system redirects the user to the authorization page URL address.
[0016] As a preferred implementation of the present invention, the authorization page partially encrypts the identity information input by the user through the front-end encryption technology as follows:
[0017] Use Web CryptoAPI or the national encryption SM4 algorithm to encrypt the identity information entered by the user, and transmit the encrypted identity information to the data authorization center system via the HTTPS protocol.
[0018] As a preferred embodiment of the present invention, the trusted digital identity authentication is performed by the trusted digital identity authentication system and the CTID platform as follows:
[0019] When a user applies for a trusted digital identity for the first time, he / she uploads his / her identity information and portrait data through the user terminal. The trusted digital identity authentication system calls the CTID platform to download the trusted digital identity credential factor file based on the identity information and portrait data.
[0020] When performing trusted digital identity authentication, the user terminal collects the user's portrait data again, and uploads the re-collected portrait data and the trusted digital identity credential factor file to the trusted digital identity authentication system. The trusted digital identity authentication system calls the CTID platform to perform trusted digital identity authentication and check whether the portrait data and the trusted credential factor file are consistent with those provided during the first application.
[0021] As a preferred embodiment of the present invention, the method also includes the data authorization center system verifying the authentication credential number through a trusted digital identity authentication system before confirming the authorization based on the authentication credential number and the authorization serial number, and confirming the authorization if the verification passes.
[0022] As a preferred implementation of the present invention, the method further includes setting a fine-grained access control mechanism in the data authorization center system, and the fine-grained access control mechanism includes:
[0023] Classify and label user data, and set different access permissions based on the sensitivity level of user data;
[0024] The data authorization center system monitors the access behavior of third-party business systems in real time. When abnormal access behavior is detected in the third-party business system, the data authorization center system automatically adjusts the user's access rights;
[0025] The data authorization center system records the access information of each visit and stores it in the form of logs. It regularly reviews the logs to detect abnormal access behaviors and automatically adjusts the user's access rights based on the review results.
[0026] The data authorization center system controls and manages access to third-party business systems through the API gateway and user access rights.
[0027] As a preferred embodiment of the present invention, the method also includes setting a data recovery mechanism in the data authorization center system. Specifically, when the user cancels the authorization or the authorization validity period expires, the data authorization center system notifies the third-party business system through a data authorization change message. The third-party business system receives the data authorization change message and deletes the user's authorized data packet.
[0028] The present invention also provides a user data authorization system based on a trusted digital identity, the system comprising a user terminal and a data authorization center system, interacting with a third-party business system, a trusted digital identity authentication system and a CTID platform, wherein:
[0029] The user terminal is used to initiate an authorization request, display an authorization page and authenticate a trusted digital identity. The initiation of an authorization request is specifically a user initiating an authorization request for personal data to a third-party business system through a user terminal; the display of an authorization page is specifically receiving and displaying an authorization page generated by a data authorization center system; the trusted digital identity authentication is specifically a user interacting with a trusted digital identity authentication system and a CTID platform through a user terminal to perform a trusted digital identity authentication, and returning the authentication result and authentication credential number to the data authorization center system;
[0030] The data authorization center system includes an authorization request processing module, an authorization page management module, a trusted digital identity authentication module, an authorization confirmation and recording module, an authorization data transmission module, an access control and monitoring module, and a data recovery management module, wherein:
[0031] The authorization request processing module is used to receive the authorization request and obtain the authorization status of the user. If the authorization status of the user is unauthorized, the data authorization center system generates a unique authorization serial number; and generates an authorization page URL address according to a preset security policy, the authorization page URL address is embedded with the authorization serial number, and returns the authorization page URL address to the third-party business system;
[0032] The authorization page management module is used to generate an authorization page for the user to view and confirm the authorization data items, authorization time and business matters, wherein the authorization page partially encrypts the identity information input by the user through the front-end encryption technology;
[0033] The trusted digital identity authentication module is used to verify the authentication credential number through the trusted digital identity authentication system, and confirm the authorization if the verification passes;
[0034] The authorization confirmation and recording module is used to confirm the authorization based on the authentication credential number and the authorization serial number, and generate a user authorization record, an authorization authentication record and an authorization credential data. The user authorization record includes an authorization record ID, a digital identity identifier BID, an authorization data item, an authorization validity period, an authorization method, an authorization time, authorized business items, third-party business system information, a creation time and an authorization serial number after the authorization is confirmed; the authorization authentication record includes an authentication record ID, a digital identity identifier BID, a user authorization record ID, an authentication credential number, an authentication time, an authentication mode, authentication device information and a creation time; the authorization credential data is the credential data generated when the data authorization center system generates a user authorization record and an authorization authentication record, including a credential record ID, a digital identity identifier BID, an authorization record ID, a user authorization record information signature value, an authentication record ID, an authorization authentication record signature value, an authorization credential record signature value and a creation time, and the signature value is generated using the national secret SM2 signature algorithm;
[0035] The authorization data transmission module is used to package the authorization data items confirmed by the user to generate an authorization data packet, and return the authorization serial number after the confirmation of authorization to the third-party business system through a secure communication protocol. The third-party business system obtains the user's authorization data packet according to the authorization serial number after the confirmation of authorization;
[0036] The access control and monitoring module implements a fine-grained access control mechanism, classifies and marks user data, and sets different access rights according to the sensitivity level of the data; monitors the access behavior of third-party business systems in real time, detects abnormal access behavior and automatically adjusts the user's access rights; records the access information of each visit and stores it in the form of logs, regularly reviews the logs to detect abnormal access behavior, and automatically adjusts the user's access rights according to the review results;
[0037] The data recovery management module has a data recovery mechanism set up inside. When the user cancels the authorization or the authorization expires, a data authorization change message is generated. The third-party business system is notified through the data authorization change message. After receiving the change message, the third-party business system deletes the user's authorized data packet.
[0038] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, a user data authorization method based on a trusted digital identity as described in any embodiment of the present invention is implemented.
[0039] The present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a user data authorization method based on a trusted digital identity as described in any embodiment of the present invention.
[0040] Compared with the prior art, the present invention has the following beneficial effects:
[0041] 1) The present invention provides a user data authorization method and system based on a trusted digital identity. The user initiates an authorization request to the data authorization center through a third-party business system. The request contains the authorization data items and business context information required by the user. After receiving the request, the data authorization center determines whether the user needs to confirm the authorization based on the user's authorization status, and generates a unique authorization serial number and authorization page URL. The authorization page URL ensures security and timeliness by adding a timestamp, nonce value, and a signature generated by the national secret SM3 algorithm;
[0042] 2) The present invention provides a user data authorization method and system based on a trusted digital identity. The user confirms the authorization information on the authorization page, and partially encrypts the input identity information through the front-end encryption technology, and then transmits it through the HTTPS protocol; then, the user performs identity authentication through the trusted digital identity authentication system and the CTID platform to ensure the authenticity of the user and the legitimacy of the data; after the authentication is passed, the data authorization center generates user authorization records, authorization authentication records and authorization credential data, and these records are signed by the national secret SM2 signature algorithm to ensure the integrity and non-tamperability of the data;
[0043] 3) The present invention provides a user data authorization method and system based on trusted digital identity, which further ensures the security of user data through fine-grained access control mechanism and data recovery mechanism. The fine-grained access control mechanism sets different access rights according to the data sensitivity level, monitors and automatically adjusts the access rights in real time; the data recovery mechanism automatically notifies the third-party business system to delete the relevant data package when the user cancels the authorization or the authorization expires, which comprehensively improves the security, reliability and convenience of user data authorization from a technical perspective. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 It is a method flow chart of an embodiment of the present invention. DETAILED DESCRIPTION
[0045] The specific implementation modes of the present invention are described below so that those skilled in the art can understand the present invention. However, it should be clear that the present invention is not limited to the scope of the specific implementation modes. For those of ordinary skill in the art, as long as various changes are within the spirit and scope of the present invention as defined and determined by the attached claims, these changes are obvious, and all inventions and creations utilizing the concept of the present invention are protected.
[0046] The present invention provides the following technical solution: a user data authorization method and system based on trusted digital identity.
[0047] Embodiment 1:
[0048] This embodiment provides a user data authorization method based on a trusted digital identity, the method comprising:
[0049] S1. The user initiates an authorization request for the user's personal data to the data authorization center system through a third-party business system. The authorization request includes the authorization data items required by the user and business context information;
[0050] S2. The data authorization center system receives the authorization request and obtains the authorization status of the user. If the authorization status of the user is unauthorized, the data authorization center system generates a unique authorization serial number and generates an authorization page URL address according to a preset security policy. The authorization serial number is embedded in the authorization page URL address, and the authorization page URL address is returned to the third-party business system;
[0051] S21. The preset security policy includes:
[0052] When generating the authorization page URL address, add the current timestamp and a randomly generated nonce value, and set the expiration time; use the national secret SM3 algorithm to hash the parameters in the generated authorization page URL address, generate a signature, and attach the signature to the authorization page URL address;
[0053] When the third-party business system receives the authorization page URL address, it verifies the expiration time through the current timestamp in the authorization page URL address, checks whether the nonce value is a unique value, and recalculates the signature using the same parameters and the national secret SM3 algorithm as the authorization page URL address, and compares the recalculated signature with the signature in the authorization page URL address. If the verification of the expiration time, nonce value, and signature are all passed, the third-party business system redirects the user to the authorization page URL address;
[0054] S3. The third-party business system redirects the user to the authorization page URL address, and the user views and confirms the authorization data items, authorization time and business matters on the authorization page.
[0055] S31, the authorization page partially encrypts the identity information input by the user through the front-end encryption technology, specifically, uses Web CryptoAPI or the national encryption SM4 algorithm to encrypt the identity information input by the user, and transmits the encrypted identity information to the data authorization center system through the HTTPS protocol;
[0056] S4. After the user confirms the authorization, the trusted digital identity authentication system and CTID platform are used to perform the trusted digital identity authentication. If the trusted digital identity authentication is passed, the authentication result and authentication credential number are returned;
[0057] S41. When a user applies for a trusted digital identity for the first time, the user uploads the identity information and portrait data using the user terminal. The trusted digital identity authentication system calls the CTID platform to download the trusted digital identity credential factor file based on the identity information and portrait data.
[0058] When conducting trusted digital identity authentication, the user terminal collects the user's portrait data again, and uploads the re-collected portrait data and the trusted digital identity credential factor file to the trusted digital identity authentication system. The trusted digital identity authentication system calls the CTID platform to perform trusted digital identity authentication and checks whether the portrait data and the trusted credential factor file are consistent with those provided during the first application;
[0059] S5. The data authorization center system confirms the authorization based on the authentication credential number and the authorization serial number;
[0060] S51. The data authorization center system verifies the authentication credential number through the trusted digital identity authentication system, and confirms the authorization if the verification passes;
[0061] S52. The data authorization center system ensures the traceability of user authorization behavior by generating user authorization records, authorization authentication records and authorization credential data, and ensures that the authorization and authentication records are not tampered with. Specifically:
[0062] The data authorization center system records the user's authorization behavior in detail. The user authorization record includes the authorization record ID, digital identity identifier BID, authorization data item, authorization validity period, authorization method (single authorization / regular authorization), authorization time, authorized business items, third-party business system information, creation time and authorization serial number after confirmation of authorization. The user authorization record ensures that every authorization behavior can be accurately tracked and recorded;
[0063] In order to prevent the record data from being tampered with, the data authorization center system will generate authorization credential data according to a specific algorithm when generating user authorization records and authorization authentication records. These credential data include credential record ID, digital identity identifier BID, authorization record ID, user authorization record information signature value, authentication record ID, authorization authentication record signature value, authorization credential record signature value and creation time;
[0064] Furthermore, the specific algorithm is specifically to use the national secret SM2 signature algorithm when generating the signature value, which is a highly secure encryption algorithm that can effectively prevent data from being tampered with. In this way, any illegal modification of the authorization record or authentication record will be immediately detected, thereby ensuring the integrity and security of the data;
[0065] Since all authorization and authentication behaviors are recorded in detail and these records are encrypted and protected by the SM2 signature algorithm, the specific authorization and authentication behaviors can be traced back through these records at any time, ensuring the traceability of user authorization behaviors;
[0066] S6. The data authorization center system packages the authorization data items confirmed by the user to generate an authorization data packet, and returns the authorization serial number after the confirmation of authorization to the third-party business system through a secure communication protocol. The third-party business system obtains the user's authorization data packet according to the authorization serial number after the confirmation of authorization;
[0067] S7. Preferably, in the entire user data authorization process, especially in the authorization request and data access stages, the data authorization center system is provided with a fine-grained access control mechanism, which is used to ensure that the third-party business system can only access its authorized data, and can adjust the access rights in a timely manner when abnormal behavior is detected, specifically:
[0068] The fine-grained access control mechanism includes:
[0069] Classify and label user data, and set different access permissions based on the sensitivity level of user data;
[0070] The data authorization center system monitors the access behavior of third-party business systems in real time. When abnormal access behavior is detected in the third-party business system, the data authorization center system automatically adjusts the user's access rights;
[0071] The data authorization center system records the access information of each visit and stores it in the form of logs. It regularly reviews the logs to detect abnormal access behaviors and automatically adjusts the user's access rights based on the review results.
[0072] The data authorization center system controls and manages access to third-party business systems through the API gateway and user access rights;
[0073] S8. Preferably, when the user cancels the authorization or the authorization expires, the data authorization center system is provided with a data recovery mechanism, which is used to ensure that the third-party business system no longer holds the user's authorization data, thereby protecting the user's data privacy and security. Specifically:
[0074] When the user cancels the authorization or the authorization expires, the data authorization center system notifies the third-party business system through a data authorization change message. The third-party business system receives the data authorization change message and deletes the user's authorized data packet.
[0075] Embodiment 2:
[0076] This embodiment provides a user data authorization system based on a trusted digital identity, the system includes a user terminal and a data authorization center system, and interacts with a third-party business system, a trusted digital identity authentication system, and a CTID platform, wherein:
[0077] The user terminal is used to initiate an authorization request, display an authorization page and authenticate a trusted digital identity. The initiation of an authorization request is specifically a user initiating an authorization request for personal data to a third-party business system through a user terminal; the display of an authorization page is specifically receiving and displaying an authorization page generated by a data authorization center system; the trusted digital identity authentication is specifically a user interacting with a trusted digital identity authentication system and a CTID platform through a user terminal to perform a trusted digital identity authentication, and returning the authentication result and authentication credential number to the data authorization center system;
[0078] The data authorization center system includes an authorization request processing module, an authorization page management module, a trusted digital identity authentication module, an authorization confirmation and recording module, an authorization data transmission module, an access control and monitoring module, and a data recovery management module, wherein:
[0079] The authorization request processing module is used to receive the authorization request and obtain the authorization status of the user. If the authorization status of the user is unauthorized, the data authorization center system generates a unique authorization serial number; and generates an authorization page URL address according to a preset security policy, the authorization page URL address is embedded with the authorization serial number, and returns the authorization page URL address to the third-party business system;
[0080] The authorization page management module is used to generate an authorization page for the user to view and confirm the authorization data items, authorization time and business matters, wherein the authorization page partially encrypts the identity information input by the user through the front-end encryption technology;
[0081] The trusted digital identity authentication module is used to verify the authentication credential number through the trusted digital identity authentication system, and confirm the authorization if the verification passes;
[0082] The authorization confirmation and recording module is used to confirm the authorization based on the authentication credential number and the authorization serial number, and generate a user authorization record, an authorization authentication record and an authorization credential data. The user authorization record includes an authorization record ID, a digital identity identifier BID, an authorization data item, an authorization validity period, an authorization method, an authorization time, authorized business items, third-party business system information, a creation time and an authorization serial number after the authorization is confirmed; the authorization authentication record includes an authentication record ID, a digital identity identifier BID, a user authorization record ID, an authentication credential number, an authentication time, an authentication mode, authentication device information and a creation time; the authorization credential data is the credential data generated when the data authorization center system generates a user authorization record and an authorization authentication record, including a credential record ID, a digital identity identifier BID, an authorization record ID, a user authorization record information signature value, an authentication record ID, an authorization authentication record signature value, an authorization credential record signature value and a creation time, and the signature value is generated using the national secret SM2 signature algorithm;
[0083] The authorization data transmission module is used to package the authorization data items confirmed by the user to generate an authorization data packet, and return the authorization serial number after the confirmation of authorization to the third-party business system through a secure communication protocol. The third-party business system obtains the user's authorization data packet according to the authorization serial number after the confirmation of authorization;
[0084] The access control and monitoring module implements a fine-grained access control mechanism, classifies and marks user data, and sets different access rights according to the sensitivity level of the data; monitors the access behavior of third-party business systems in real time, detects abnormal access behavior and automatically adjusts the user's access rights; records the access information of each visit and stores it in the form of logs, regularly reviews the logs to detect abnormal access behavior, and automatically adjusts the user's access rights according to the review results;
[0085] The data recovery management module has a data recovery mechanism set up inside. When the user cancels the authorization or the authorization expires, a data authorization change message is generated. The third-party business system is notified through the data authorization change message. After receiving the change message, the third-party business system deletes the user's authorized data packet.
[0086] Embodiment 3:
[0087] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, a user data authorization method based on a trusted digital identity as described in Example 1 of the present invention is implemented.
[0088] Embodiment 4:
[0089] The present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a user data authorization method based on a trusted digital identity as described in Example 1 of the present invention.
[0090] The above descriptions are merely embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A user data authorization method based on a trusted digital identity, characterized in that: The method comprises: The user initiates an authorization request for the user's personal data to the data authorization center system through a third-party business system, and the authorization request includes the authorization data items required by the user and business context information; The data authorization center system receives the authorization request and obtains the user's authorization status. If the user's authorization status is unauthorized, the data authorization center system generates a unique authorization serial number and generates an authorization page URL address according to a preset security policy. The authorization serial number is embedded in the authorization page URL address, and the authorization page URL address is returned to the third-party business system; The third-party business system redirects the user to the authorization page URL address, and the user views and confirms the authorization data items, authorization time and business matters on the authorization page, wherein the authorization page partially encrypts the identity information entered by the user through the front-end encryption technology; After the user confirms the authorization, the trusted digital identity authentication system and CTID platform will be used for trusted digital identity authentication. If the trusted digital identity authentication is successful, the authentication result and authentication credential number will be returned; The data authorization center system confirms the authorization based on the authentication credential number and the authorization serial number, and generates a user authorization record, an authorization authentication record and authorization credential data. The user authorization record includes the authorization record ID, the digital identity identifier BID, the authorization data item, the authorization validity period, the authorization method, the authorization time, the authorized business items, the third-party business system information, the creation time and the authorization serial number after the authorization is confirmed; the authorization authentication record includes the authentication record ID, the digital identity identifier BID, the user authorization record ID, the authentication credential number, the authentication time, the authentication mode, the authentication device information and the creation time; the authorization credential data is the credential data generated when the data authorization center system generates the user authorization record and the authorization authentication record, including the credential record ID, the digital identity identifier BID, the authorization record ID, the user authorization record information signature value, the authentication record ID, the authorization authentication record signature value, the authorization credential record signature value and the creation time, and the signature value is generated using the national secret SM2 signature algorithm; The data authorization center system packages the authorization data items confirmed by the user to generate an authorization data packet, and returns the authorization serial number after confirmation to the third-party business system through a secure communication protocol. The third-party business system obtains the user's authorization data packet based on the authorization serial number after confirmation.
2. A user data authorization method based on a trusted digital identity according to claim 1, characterized in that: The preset security policy includes: When generating the authorization page URL address, add the current timestamp and a randomly generated nonce value, and set the expiration time; use the national secret SM3 algorithm to hash the parameters in the generated authorization page URL address, generate a signature, and attach the signature to the authorization page URL address; When the third-party business system receives the authorization page URL address, it verifies the expiration time through the current timestamp in the authorization page URL address, checks whether the nonce value is a unique value, and recalculates the signature using the same parameters and national secret SM3 algorithm as the authorization page URL address, and compares the recalculated signature with the signature in the authorization page URL address. If the expiration time, nonce value and signature are all verified, the third-party business system redirects the user to the authorization page URL address.
3. According to claim 1, a user data authorization method based on a trusted digital identity is characterized in that: The authorization page partially encrypts the identity information entered by the user through the front-end encryption technology as follows: Use Web Crypto API or the national encryption SM4 algorithm to encrypt the identity information entered by the user, and transmit the encrypted identity information to the data authorization center system via the HTTPS protocol.
4. According to claim 1, a user data authorization method based on a trusted digital identity is characterized in that: The specific steps of trusted digital identity authentication through the trusted digital identity authentication system and CTID platform are as follows: When a user applies for a trusted digital identity for the first time, he / she uploads his / her identity information and portrait data through the user terminal. The trusted digital identity authentication system calls the CTID platform to download the trusted digital identity credential factor file based on the identity information and portrait data. When performing trusted digital identity authentication, the user terminal collects the user's portrait data again, and uploads the re-collected portrait data and the trusted digital identity credential factor file to the trusted digital identity authentication system. The trusted digital identity authentication system calls the CTID platform to perform trusted digital identity authentication and check whether the portrait data and the trusted credential factor file are consistent with those provided during the first application.
5. A user data authorization method based on a trusted digital identity according to claim 4, characterized in that: The method also includes the data authorization center system verifying the authentication credential number through a trusted digital identity authentication system before confirming the authorization based on the authentication credential number and the authorization serial number, and confirming the authorization if the verification passes.
6. A user data authorization method based on a trusted digital identity according to claim 5, characterized in that: The method further includes setting a fine-grained access control mechanism in the data authorization center system, wherein the fine-grained access control mechanism includes: Classify and label user data, and set different access permissions based on the sensitivity level of user data; The data authorization center system monitors the access behavior of third-party business systems in real time. When abnormal access behavior is detected in the third-party business system, the data authorization center system automatically adjusts the user's access rights; The data authorization center system records the access information of each visit and stores it in the form of logs. It regularly reviews the logs to detect abnormal access behaviors and automatically adjusts the user's access rights based on the review results. The data authorization center system controls and manages access to third-party business systems through the API gateway and user access rights.
7. A user data authorization method based on a trusted digital identity according to claim 6, characterized in that: The method also includes setting a data recovery mechanism in the data authorization center system. Specifically, when the user cancels the authorization or the authorization expires, the data authorization center system notifies the third-party business system through a data authorization change message. The third-party business system receives the data authorization change message and deletes the user's authorized data packet.
8. A user data authorization system based on a trusted digital identity, characterized in that: The system includes a user terminal and a data authorization center system, which interacts with a third-party business system, a trusted digital identity authentication system, and a CTID platform, wherein: The user terminal is used to initiate an authorization request, display an authorization page and authenticate a trusted digital identity. The initiation of an authorization request is specifically a user initiating an authorization request for personal data to a third-party business system through a user terminal; the display of an authorization page is specifically receiving and displaying an authorization page generated by a data authorization center system; the trusted digital identity authentication is specifically a user interacting with a trusted digital identity authentication system and a CTID platform through a user terminal to perform a trusted digital identity authentication, and returning the authentication result and authentication credential number to the data authorization center system; The data authorization center system includes an authorization request processing module, an authorization page management module, a trusted digital identity authentication module, an authorization confirmation and recording module, an authorization data transmission module, an access control and monitoring module, and a data recovery management module, wherein: The authorization request processing module is used to receive the authorization request and obtain the authorization status of the user. If the authorization status of the user is unauthorized, the data authorization center system generates a unique authorization serial number; and generates an authorization page URL address according to a preset security policy, the authorization page URL address is embedded with the authorization serial number, and returns the authorization page URL address to the third-party business system; The authorization page management module is used to generate an authorization page for the user to view and confirm the authorization data items, authorization time and business matters, wherein the authorization page partially encrypts the identity information input by the user through the front-end encryption technology; The trusted digital identity authentication module is used to verify the authentication credential number through the trusted digital identity authentication system, and confirm the authorization if the verification passes; The authorization confirmation and recording module is used to confirm the authorization based on the authentication credential number and the authorization serial number, and generate a user authorization record, an authorization authentication record and an authorization credential data. The user authorization record includes an authorization record ID, a digital identity identifier BID, an authorization data item, an authorization validity period, an authorization method, an authorization time, authorized business items, third-party business system information, a creation time and an authorization serial number after the authorization is confirmed; the authorization authentication record includes an authentication record ID, a digital identity identifier BID, a user authorization record ID, an authentication credential number, an authentication time, an authentication mode, authentication device information and a creation time; the authorization credential data is the credential data generated when the data authorization center system generates a user authorization record and an authorization authentication record, including a credential record ID, a digital identity identifier BID, an authorization record ID, a user authorization record information signature value, an authentication record ID, an authorization authentication record signature value, an authorization credential record signature value and a creation time, and the signature value is generated using the national secret SM2 signature algorithm; The authorization data transmission module is used to package the authorization data items confirmed by the user to generate an authorization data packet, and return the authorization serial number after the confirmation of authorization to the third-party business system through a secure communication protocol. The third-party business system obtains the user's authorization data packet according to the authorization serial number after the confirmation of authorization; The access control and monitoring module implements a fine-grained access control mechanism, classifies and marks user data, and sets different access rights according to the sensitivity level of the data; monitors the access behavior of third-party business systems in real time, detects abnormal access behavior and automatically adjusts the user's access rights; records the access information of each visit and stores it in the form of logs, regularly reviews the logs to detect abnormal access behavior, and automatically adjusts the user's access rights according to the review results; The data recovery management module has a data recovery mechanism set up inside. When the user cancels the authorization or the authorization expires, a data authorization change message is generated. The third-party business system is notified through the data authorization change message. After receiving the change message, the third-party business system deletes the user's authorized data packet.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the user data authorization method based on a trusted digital identity as described in any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, a user data authorization method based on a trusted digital identity as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Authentication authorization method, device and system
CN103888451B
Cited By
Data processing method and system for multi-factor authentication and block chain evidence storage
CN121333591A