City platform and method based on national network identity authentication public service

By leveraging the city platform based on the national network identity authentication public service, user identity authentication, data request contract generation and storage, business data token generation, and data aggregation have been achieved. This has solved the problems of fragmented identity authentication and opaque data authorization in the city platform, and improved the intelligence and efficiency of business processing.

CN120639467BActive Publication Date: 2026-05-01ZHEJIANG JIUWEI TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZHEJIANG JIUWEI TECHNOLOGY CO LTD
Filing Date
2025-07-18
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

When existing city platforms are integrated with the national online identity authentication public service, they face challenges such as fragmented and inconsistent user identity authentication, insufficient security, cumbersome and inefficient business processing procedures, and a lack of a unified, transparent and traceable data authorization mechanism, which poses risks of data abuse and privacy leaks.

Method used

By leveraging the city platform based on the national network identity authentication public service, and employing modules for user identity authentication, business request and contract generation, contract authorization and notarization, business data token generation, and data aggregation, a transparent and traceable authorization mechanism is constructed to ensure the compliance and security of data access.

Benefits of technology

It simplified business processes, solved the problems of duplicate authorization and data silos, improved the intelligence and efficiency of business processing on the city platform, and ensured users' control over their data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639467B_ABST
    Figure CN120639467B_ABST
Patent Text Reader

Abstract

The application discloses a kind of city platform and method based on national network identity authentication public service, it is related to wisdom city field, it first utilizes national network identity authentication public service to complete user identity authentication to establish trusted access foundation, when user handles business, constructs data request contract and is authorized after user confirmation and is stored, forms transparent authorized mechanism of traceability. Then, based on the authorized range of user, the data token of limited access is generated, based on the unified data aggregation service, the required cross-source data is obtained, the on-demand aggregation and safe flow of data are realized, and the audit result is obtained by automatically auditing the aggregated data through business logic. Finally, the audit result is returned to the user. In this way, the business process can be simplified, the problem of repeated authorization and data silos can be solved, while the user data control right is guaranteed, and the intelligence and efficiency of city platform business handling are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Urban Platform and Methods Based on National Network Identity Authentication Public Service Technical Field

[0001] This application relates to the field of smart cities, and more specifically, to a city platform and method based on national network identity authentication public services. Background Technology

[0002] With the deepening of digital government construction and the popularization of smart city concepts, urban services are gradually developing towards online, integrated, and intelligent directions. Against this backdrop, building a secure, efficient, and convenient urban service platform to meet the increasingly diverse needs of citizens has become a crucial issue in urban governance. The National Network Identity Authentication Public Service, as a national-level infrastructure, aims to provide unified, authoritative, and reliable identity authentication capabilities, possessing irreplaceable advantages in ensuring cyberspace security and improving the efficiency of government services. Deeply integrating urban platforms with the National Network Identity Authentication Public Service can not only effectively solve the problems of fragmentation, inconsistency, and insufficient security in user identity authentication of traditional urban service platforms, but also provide citizens with a more convenient and reliable "one-stop" service experience.

[0003] However, existing city platforms often face numerous challenges when integrating with national online identity authentication public services. For example, in complex scenarios involving multi-departmental data sharing and cross-business collaborative processing, simple identity authentication alone cannot fully meet business needs. Under the current model, when users handle services requiring multi-party data support, such as talent introduction subsidies, they still need to repeatedly submit materials and authorize multiple departments, and even face data silos and information barriers, resulting in cumbersome and inefficient business processes. More importantly, there is a lack of a unified, transparent, and traceable mechanism for data authorization and use. Users often passively accept data authorization terms, making it difficult to control the scope, flow, and purpose of their personal data use, let alone achieve refined "minimum necessary" authorization, posing potential risks of data abuse and privacy leaks. Traditional business processing typically relies on manual review and offline circulation, which is not only time-consuming and labor-intensive, but also makes it difficult to achieve automated data aggregation and intelligent review, thus hindering the development of city service platforms towards higher levels of intelligence and refinement.

[0004] Therefore, there is an urgent need for an optimized city platform and method based on national network identity authentication public services. Summary of the Invention

[0005] This application is made in order to solve the above-mentioned technical problems.

[0006] According to one aspect of this application, a city platform based on a national online identity authentication public service is provided, comprising:

[0007] The user identity authentication module is used to respond to login requests initiated by users on the city platform client, perform user identity authentication based on the national network identity authentication public service, and generate a platform master access token after successful identity authentication;

[0008] The business request and contract generation module is used to respond to a user clicking to apply for talent introduction subsidies. The city platform client initiates a business request to the backend business acceptance service, wherein the business acceptance service generates a data request contract draft in response to the business request.

[0009] The contract authorization and evidence storage module is used to display the draft data request contract on the city platform client, and in response to the user clicking the "agree to authorize" button, submit the draft data request contract to the authorization and evidence storage chain of the city platform and return the authorization receipt.

[0010] A business data token generation module is used to generate a business data token in response to receiving the authorization receipt, wherein the audience of the business data token is limited to the data aggregation service;

[0011] The data aggregation module is used to respond to the acquisition of the business data token. The business acceptance service calls the interface of the platform's unified data aggregation service and receives and aggregates data from different data sources based on the authorized data range field in the business data token to obtain an aggregated data packet.

[0012] The data review module is used by the business acceptance service to review the aggregated data packets based on business logic to obtain review results;

[0013] The review result return module is used to return the review result to the city platform client.

[0014] According to another aspect of this application, a service method based on a city platform for national network identity authentication public services is provided, comprising:

[0015] In response to a user's login request initiated by the city platform client, the system performs user authentication based on the national network identity authentication public service and generates a platform master access token upon successful authentication.

[0016] In response to a user clicking to apply for talent introduction subsidies, the city platform client initiates a business request to the backend business acceptance service, wherein the business acceptance service generates a draft data request contract in response to the business request.

[0017] The draft data request contract is displayed on the city platform client, and in response to the user clicking the "agree to authorize" button, the draft data request contract is submitted to the city platform's authorization storage chain and an authorization receipt is returned.

[0018] In response to receiving the authorization receipt, a business data token is generated, the audience of which is limited to the data aggregation service;

[0019] In response to obtaining the business data token, the business acceptance service calls the interface of the platform's unified data aggregation service and receives and aggregates data from different data sources based on the authorized data range field in the business data token to obtain an aggregated data packet.

[0020] The service processing service reviews the aggregated data packets based on business logic to obtain a review result;

[0021] The review results are returned to the city platform client.

[0022] Compared with existing technologies, this application provides a city platform and method based on the national network identity authentication public service. First, it utilizes the national network identity authentication public service to complete user identity authentication to establish a trusted access foundation. When a user conducts business, a data request contract is constructed and, after user confirmation and authorization, is stored as evidence, forming a transparent and traceable authorization mechanism. Next, a data token with limited access is generated based on the user's authorization scope. The required cross-source data is obtained based on a unified data aggregation service, realizing on-demand data aggregation and secure flow. Then, the aggregated data is automatically reviewed through business logic to obtain the review result, which is finally returned to the user. This simplifies business processes, solves the problems of duplicate authorization and data silos, while ensuring user data control and improving the intelligence and efficiency of business processing on the city platform. Attached Figure Description

[0023] The above and other objects, features, and advantages of this application will become more apparent from the more detailed description of the embodiments of this application in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the embodiments of this application to explain this application and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.

[0024] Figure 1 is a block diagram of a city platform based on a national network identity authentication public service according to an embodiment of this application.

[0025] Figure 2 is a schematic diagram of data flow in a city platform based on a national network identity authentication public service according to an embodiment of this application.

[0026] Figure 3 is a block diagram of the user identity authentication module in a city platform based on the national network identity authentication public service according to an embodiment of this application.

[0027] Figure 4 is a block diagram of the business request and contract generation module in the city platform based on the national network identity authentication public service according to an embodiment of this application.

[0028] Figure 5 is a block diagram of the contract authorization and evidence storage module in the city platform based on the national network identity authentication public service according to an embodiment of this application.

[0029] Figure 6 is a block diagram of the data aggregation module in a city platform based on national network identity authentication public service according to an embodiment of this application.

[0030] Figure 7 is a flowchart of a service method for a city platform based on a national network identity authentication public service, according to an embodiment of this application. Detailed Implementation

[0031] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0032] To address the problems mentioned above, this application proposes a city platform based on the national network identity authentication public service. Figure 1 is a block diagram of the city platform based on the national network identity authentication public service according to an embodiment of this application. Figure 2 is a data flow diagram of the city platform based on the national network identity authentication public service according to an embodiment of this application. As shown in Figures 1 and 2, the city platform 100 based on the national network identity authentication public service includes: a user identity authentication module 110, used to perform user identity authentication based on the national network identity authentication public service in response to a login request initiated by a user on the city platform client, and generate a platform master access token after successful identity authentication; a business request and contract generation module 120, used to initiate a business request to the backend business acceptance service in response to a user clicking to apply for talent introduction subsidies, wherein the business acceptance service generates a draft data request contract in response to the business request; and a contract authorization and evidence storage module 130, used to display the draft data request contract on the city platform client, and in response to a user clicking the "agree to authorize" button, to store the draft data request contract. The document is submitted to the authorization storage chain of the city platform and an authorization receipt is returned; the business data token generation module 140 is used to generate a business data token in response to receiving the authorization receipt, the audience of which is limited to the data aggregation service; the data aggregation module 150 is used to call the interface of the platform's unified data aggregation service in response to obtaining the business data token and receive and aggregate data from different data sources based on the authorized data range field in the business data token to obtain an aggregated data packet; the data review module 160 is used for the business acceptance service to review the aggregated data packet based on business logic to obtain a review result; the review result return module 170 is used to return the review result to the city platform client.

[0033] In the aforementioned city platform based on the national network identity authentication public service, the user identity authentication module 110 is used to respond to login requests initiated by users on the city platform client, perform user identity authentication based on the national network identity authentication public service, and generate a platform master access token upon successful authentication. It should be understood that the national network identity authentication public service, as a national-level infrastructure, possesses unified and authoritative identity verification capabilities, and can provide identity authentication results recognized at the national level. Therefore, when users log in to the city platform client, completing identity authentication based on the national network identity authentication public service can establish a reliable identity foundation for subsequent operations such as data authorization and cross-source data access in business processing, ensuring the uniqueness and authenticity of user identities, guaranteeing the security and compliance of platform business processing, and avoiding various business risks caused by unreliable identity authentication. By generating a platform master access token, the user's identity information and login status are recorded in a standardized form, providing a unified identity credential for users to initiate business requests and perform data authorization within the platform. This eliminates the cumbersome process of users repeatedly performing identity authentication when handling different businesses, simplifies operation steps, and improves the user experience.

[0034] Specifically, in one specific embodiment, Figure 3 is a block diagram of a user identity authentication module in a city platform based on the national network identity authentication public service according to an embodiment of this application. As shown in Figure 3, the user identity authentication module 110 includes: a platform redirection unit 111, used to redirect to the national network identity authentication public service in response to a login request initiated by a user on the city platform client; a face recognition authentication unit 112, used by the national network identity authentication public service to perform user identity authentication through face recognition; an authorization code generation and return unit 113, used by the national network identity authentication public service to generate an authorization code and return the authorization code to the city platform client in response to successful identity authentication; an authorization code transmission unit 114, used by the city platform client to send the authorization code to the identity authentication service; and an authorization code verification unit 115, used by the identity authentication service to verify the validity of the authorization code to the national network identity authentication public service through backend signals, and to generate the platform master access token after successful verification.

[0035] Specifically, the platform redirection unit 111 is used to respond to a login request initiated by a user on the city platform client and redirect to the national online identity authentication public service. In particular, by redirecting to the national online identity authentication public service, a nationally authoritative authentication source is introduced to replace the city platform's own authentication process, ensuring that the user's identity authentication process complies with national standards and improving the credibility and universality of the authentication results. At the same time, it avoids the city platform from repeatedly building its own identity authentication system, reducing development and maintenance costs, providing a unified identity benchmark for users to conduct various business transactions within the platform, reducing business blockages caused by inconsistent authentication standards, and promoting the standardization and efficiency of the platform's authentication process.

[0036] Specifically, in one possible embodiment, the platform redirection unit 111 operates as follows: After the user clicks the login icon on the city platform client, the client immediately responds to the operation and initiates the redirection process through the built-in security SDK. The client first verifies the security of the device environment. After confirming that there are no abnormalities, it automatically opens the dedicated interface of the national network identity authentication public service and guides the user to the secure operation interface of the public service through system-level page switching. During the redirection process, the client does not transmit any sensitive user information, but only sends platform identification information to the public service to indicate the source of the redirection. The user can clearly see the official authentication mark on the public service interface, confirming that they have entered a national authoritative authentication environment. The entire redirection process is smooth and without unnecessary operations, ensuring a consistent user experience.

[0037] Specifically, the facial recognition authentication unit 112 is used by the National Public Service for Network Identity Authentication to authenticate users' identities through facial recognition. It should be understood that, because facial recognition is based on biometrics, it possesses uniqueness and cannot be copied, directly linking to a user's true identity, and is convenient to operate, requiring no additional information from the user. Therefore, using facial recognition for user identity authentication can fully utilize the biometric information in the authoritative database of the National Public Service for Network Identity Authentication to achieve high-precision identity verification. Specifically, through biometric comparison, the authenticity of the user's identity is accurately verified, preventing identity theft and forgery. Leveraging the convenience of facial recognition improves the user authentication experience, reduces the complexity of user operations, ensures the accuracy and legal validity of the comparison results, and provides a reliable basis for identity verification for subsequent platform operations.

[0038] Specifically, in one possible embodiment, the facial recognition authentication unit 112 is implemented as follows: After receiving the user's entry instruction, the user is first prompted to place their face within the acquisition frame, ensuring sufficient lighting and no facial obstruction. After the user completes the operation as prompted, the server acquires facial images in real time, extracting key biometric features such as eye distance, nose shape, and jawline. Subsequently, the system performs multi-dimensional comparisons between the extracted feature points and the user's biometric data stored in the national population database, including feature point matching degree and dynamic liveness detection, such as blinking and head turning verification. If the comparison result meets the preset threshold and passes the liveness detection, the system determines that the identity authentication is successful. If the comparison fails or the liveness detection fails, the user is prompted to repeat the operation or use other authentication methods. The entire process is conducted in an encrypted environment to ensure that biometric information is not leaked.

[0039] Specifically, the authorization code generation and return unit 113 is used to generate an authorization code and return it to the city platform client in response to successful identity authentication. It should be understood that the authorization code, as a temporary, one-time credential, can replace sensitive information in transmitting authentication results. It proves that the user has passed national-level identity authentication while avoiding direct exposure of user identity data. Simultaneously, the authorization code has timeliness and uniqueness, effectively preventing the reuse or abuse of credentials and ensuring the security and controllability of authentication result transmission. This application controls the scope and timeliness of authentication results through the timeliness and uniqueness of the authorization code, achieving secure transmission of authentication results, eliminating the risk of leakage of sensitive identity information during transmission, and providing a reliable basis for subsequent verification.

[0040] Specifically, in one possible embodiment, the authorization code generation and return unit 113 is implemented as follows: After confirming that the user's identity authentication has been passed, the National Network Identity Authentication Public Service immediately initiates the authorization code generation mechanism. The system randomly generates a string containing uppercase and lowercase letters, numbers, and special symbols, with a length of 32 characters. The system also binds a unique user identifier and a generation timestamp to this authorization code. The system sets the validity period of the authorization code to 5 minutes and marks it as a one-time use code. After generation, the server sends the authorization code to the city platform client through an encrypted communication channel. During transmission, an SSL encryption protocol is used to ensure that the data is not intercepted or tampered with. After receiving the authorization code, the city platform client immediately stores it in its local secure cache and marks it as pending processing. Simultaneously, it clears any historical authorization codes that may exist in the cache to prevent misuse.

[0041] Specifically, the authorization code transmission unit 114 is used by the city platform client to send the authorization code to the identity authentication service. That is, it securely transmits the authorization code obtained from the front end to the identity authentication service on the platform's backend and initiates the authorization code validity verification process, providing a prerequisite for the subsequent generation of the platform's master access token. Through backend service processing and verification, it ensures that the authorization code has not been tampered with, is within its validity period, and corresponds to the correct user identity, thus guaranteeing the legitimacy of identity identifiers within the platform. This achieves secure transmission of the authorization code from the client to the backend service, ensuring that the verification process takes place in a trusted platform environment and reducing potential security vulnerabilities from frontend processing. After receiving the authorization code, the backend identity authentication service can immediately initiate interactive verification with national public services, propelling the authentication process to the next stage and laying the foundation for generating the platform's master access token, ensuring the continuity and security of the entire process.

[0042] Specifically, in one possible embodiment, the authorization code transmission unit 114 is implemented as follows: After obtaining the authorization code in its local secure cache, the city platform client automatically initiates a communication connection with the platform's identity authentication service. The client first performs Base64 encoding on the authorization code, and then sends the encoded authorization code to the designated interface of the identity authentication service through the platform's dedicated encrypted communication protocol. During the transmission process, the client also attaches auxiliary information such as its own device identifier and application version number for the identity authentication service to verify the legitimacy of the request. Upon receiving the request, the identity authentication service first verifies whether the client's device identifier and application version are in the trusted list. After confirming that they are correct, it decodes the authorization code and temporarily stores it, awaiting subsequent verification interaction with the national network identity authentication public service. The entire transmission process is completed within 1 second, ensuring that the authorization code is processed within its validity period.

[0043] Specifically, the authorization code verification unit 115 is used by the identity authentication service to verify the validity of the authorization code with the national network identity authentication public service through backend signals, and generates the platform master access token upon successful verification. Specifically, by interacting with the backend of the national network identity authentication public service, the authenticity, timeliness, and relevance of the authorization code are verified to ensure that it corresponds to a genuine and valid user identity. After successful verification, a platform master access token containing information such as the user's unique identifier, authentication time, and validity period is generated as the user's unified identity credential within the platform. This eliminates the need for repeated identity authentication in subsequent business transactions, significantly improving business processing efficiency.

[0044] Specifically, in one possible embodiment, the authorization code verification unit 115 is implemented as follows: After receiving the authorization code, the city platform's identity authentication service immediately sends a verification request to the national network identity authentication public service through a dedicated backend channel. The request includes the authorization code to be verified, the platform identifier, and a timestamp, and is signed using a predefined encryption algorithm to ensure that the request has not been tampered with. After receiving the request, the national network identity authentication public service verifies the signature's legality and then queries its internal records to verify the validity of the authorization code, including whether it is within its validity period, whether it has been used, and whether it corresponds to the correct user. After successful verification, the national public service returns a verification result containing the user's unique identifier. After receiving the result and confirming its correctness, the identity authentication service generates a platform master access token: this token uses JWT format, contains the user's unique ID within the platform, the authentication time, and the token's validity period, and is signed using the platform's private key. After generation, the identity authentication service returns the token to the city platform client, which stores the token for use as an identity identifier in subsequent business requests.

[0045] In the aforementioned city platform based on the national network identity authentication public service, the business request and contract generation module 120 is used to respond to a user clicking to apply for talent introduction subsidies. The city platform client initiates a business request to the backend business acceptance service, whereby the business acceptance service generates a draft data request contract in response to the business request. Specifically, when a user clicks the application button, the city platform client initiates a business request to the backend to start a standardized processing procedure. Simultaneously, the business acceptance service generates a draft data request contract, specifying the data types, sources, and scope required to complete the business, ensuring the data request is standardized and targeted, and providing specific authorization content as a basis for subsequent user authorization.

[0046] Specifically, in one specific embodiment, Figure 4 is a block diagram of the business request and contract generation module in a city platform based on a national network identity authentication public service according to an embodiment of this application. As shown in Figure 4, the business request and contract generation module 120 includes: a business request initiation unit 121, used to initiate a business request to the backend business acceptance service by the city platform client carrying the platform master access token in response to a user clicking to apply for talent introduction subsidies; a user identity verification unit 122, used to verify the user's identity based on the platform master access token after the business acceptance service receives the business request; a data requirement template loading unit 123, used to load a data requirement template corresponding to the service ID from the configuration center based on the service ID in the business request; and a data request contract draft generation unit 124, used to generate the data request contract draft for the business request by calling the authorization center service in conjunction with the data requirement template.

[0047] Specifically, the business request initiation unit 121 is used to respond to a user clicking to apply for talent introduction subsidies. The city platform client, carrying the platform's main access token, initiates a business request to the backend business processing service. It should be understood that by initiating a business request carrying the platform's main access token, the user's talent introduction subsidy application request is transmitted from the client to the backend business processing service. Simultaneously, the platform's main access token serves as an identity credential, ensuring that the backend service can identify the requester as a legitimate user who has passed national authentication. This successfully establishes a connection between the business request and the user's legitimate identity, eliminating the possibility of unauthenticated users initiating business and ensuring the security of business processing.

[0048] Specifically, in one possible embodiment, the implementation process of the business request initiation unit 121 is as follows: After the user clicks the option to apply for talent introduction subsidies in the talent service section of the city platform client, the client immediately retrieves the platform's main access token from its local secure storage area. The client encrypts the token and embeds it into the header information of the business request, while also encapsulating the business operation identifier triggered by the user. Subsequently, the client sends the request to the designated interface of the backend business acceptance service through the platform's dedicated encrypted communication channel. The transmission process uses an end-to-end encryption protocol to prevent data interception or tampering. The request only contains the token and the business identifier, without carrying other sensitive information. After receiving the request, the backend service can initially verify the legitimacy of the request source through the token. The entire process is completed without the user's awareness, ensuring the smoothness and security of business initiation.

[0049] Specifically, the user identity verification unit 122 is used by the business acceptance service to verify the user's identity based on the platform master access token after receiving the business request. Specifically, by verifying the validity of the platform master access token, such as signature legality, validity period, and user identifier consistency, it confirms that the user initiating the talent introduction subsidy application request is a legitimate user who has passed national certification, ensuring that the business operation matches the real identity. Furthermore, the token verification process is efficient and requires no user participation, does not increase the operational burden, and provides a clear and unique user identifier for subsequent steps, enabling data requests, authorizations, and audits to be accurately linked to specific users, improving the accuracy and reliability of business processing, and providing identity traceability evidence for compliance audits.

[0050] Specifically, in one possible embodiment, the user identity verification unit 122 is implemented as follows: After receiving a user's business request, the backend business acceptance service immediately extracts the platform master access token from the request header. The server uses a preset public key to verify the digital signature of the token, confirming that the token has not been tampered with during transmission. Subsequently, the server parses the user unique identifier, authentication time, and validity period fields in the token to check whether the token is within the valid time range. At the same time, the server queries the locally stored user identity mapping database to verify whether the user identifier in the token is consistent with the authenticated user information recorded in the system. If all verification items pass, the server confirms that the business request was initiated by a legitimate user and records the user identifier in the business processing context for subsequent operations. If the verification fails, the server rejects the request and returns an authentication failure message to the client. The entire verification process is completed in milliseconds and does not affect the user experience.

[0051] Specifically, the data requirement template loading unit 123 is used by the business acceptance service to load a data requirement template corresponding to the service ID in the business request from the configuration center. It should be understood that the service ID, as a unique identifier for the business type, ensures the standardization and accuracy of data requirements by loading templates using the service ID, enabling centralized management and dynamic updates of data requirements. Specifically, based on the service ID in the business request, the corresponding predefined data requirement template is accurately loaded, clearly defining the data sources required to complete the talent introduction subsidy application, such as education departments, human resources and social security departments, and specific data items, such as academic qualifications and social security records, ensuring the data request is targeted and necessary. Templated data requirements enable business processing to follow a unified standard, providing a standardized data foundation for the subsequent generation of data request contract drafts, facilitating dynamic updates based on policy adjustments, ensuring that data requests always comply with business specifications, and providing clear guidance for subsequent user authorization and data aggregation.

[0052] Specifically, in one possible embodiment, the data requirement template loading unit 123 is implemented as follows: First, the business acceptance service extracts a service ID from the received business request. This service ID is a string of characters uniquely corresponding to the talent introduction subsidy business. Next, the server sends a loading request to the configuration center through an internal communication interface. The request includes the service ID and the server's identity verification information. After the configuration center verifies the server's identity, it retrieves the data requirement template associated with that service ID. The template clearly records the data sources required to complete the talent introduction subsidy application, such as the education department, the human resources and social security bureau, and the housing and urban-rural development commission, as well as specific data items, such as educational background information, social security payment records for the past 6 months, and current property information.

[0053] Specifically, the data request contract draft generation unit 124 is used by the business acceptance service to call the authorization center service and combine the data requirement template to generate the data request contract draft for the business request. Specifically, the authorization center service transforms the data requirement template into a user-understandable data request contract draft, clearly displaying the data source, specific data items, purpose of use, and validity period required to complete the talent introduction subsidy application, enabling users to clearly understand the authorized content. This achieves transparency and standardization of data requests, providing a clear basis for subsequent user confirmation of authorization, ensuring compliance of the authorization process, and unifying the contract format to facilitate subsequent evidence preservation and traceability, promoting the data authorization process towards transparency and standardization, and reducing business disputes caused by unclear authorization.

[0054] Specifically, in one possible embodiment, the implementation process of the data request contract draft generation unit 124 is as follows: The business acceptance service calls the dedicated interface of the authorization center service to completely transmit the loaded data requirement template to the authorization center. After receiving the template, the authorization center service parses the technical department identifiers, such as the corresponding education department, human resources and social security department, etc., and converts them into full names that are easy for users to understand; at the same time, it describes the data items in plain language, such as educational information, social security records for the past 6 months, etc. According to the characteristics of the talent introduction subsidy business, it automatically generates a description of the purpose of data use, such as "used to verify your eligibility for talent introduction subsidy application", sets the contract validity period to single use, and generates a unique contract identifier. The authorization center integrates this information into a structured contract draft, which includes contract ID, user ID, data source and corresponding data items, purpose of use and validity period, etc., and uses concise language without technical jargon.

[0055] In the aforementioned city platform based on the national network identity authentication public service, the contract authorization and evidence storage module 130 is used to display the draft data request contract on the city platform client and, in response to the user clicking the "agree to authorize" button, submit the draft data request contract to the city platform's authorization evidence storage chain and return an authorization receipt. Specifically, by displaying the draft data request contract on the city platform client, users are clearly aware of the data sources, specific data items, and data usage purposes required to complete the talent introduction subsidy application, ensuring that users make authorization decisions with full knowledge. Simultaneously, the user clicking the "agree to authorize" button triggers the contract evidence storage process, submitting the draft contract to the city platform's authorization evidence storage chain. The immutability of the evidence storage chain records the authorization behavior, forming a legally valid authorization certificate. This provides verifiable authorization evidence for subsequent data aggregation and access processes, ensuring the compliance and traceability of data use.

[0056] Specifically, in one specific embodiment, Figure 5 is a block diagram of the contract authorization and evidence storage module in a city platform based on a national network identity authentication public service according to an embodiment of this application. As shown in Figure 5, the contract authorization and evidence storage module 130 includes: an informed consent action generation unit 131, used to generate a user informed consent action in response to a user clicking the consent authorization button; an informed consent and token sending unit 132, used to send the user informed consent action together with the platform master access token to the authorization center service; and an authorization evidence storage submission unit 133, used by the authorization center service to encapsulate the user informed consent action and the data request contract draft into a transaction and submit it to the authorization evidence storage chain of the city platform.

[0057] Specifically, the informed consent action generation unit 131 is used to generate a user informed consent action in response to the user clicking the consent / authorization button. It should be understood that converting the user's click of the consent / authorization button into structured data containing information such as contract identifier, user identity identifier, authorization decision, and timestamp, generates a structured informed consent action. This allows the system to accurately capture the user's authorization intent, avoiding misjudgments of the authorization content in subsequent stages due to ambiguity in the authorization record. This clearly records the user's willingness to consent to a specific data request contract, making the authorization action resolvable and explicit. It provides a standardized data foundation for subsequent transmission to the authorization center for service and evidence storage, ensuring that the system can accurately understand and process the user's authorization decision.

[0058] Specifically, the informed consent and token sending unit 132 is used to send the user's informed consent action along with the platform master access token to the authorization center service. That is, by sending the user's informed consent action, the user's decision to agree to the data request contract is conveyed. Simultaneously, the platform master access token is carried for the authorization center service to verify the sender's legitimate identity, ensuring that the authorization action reflects the genuine intent of a nationally certified user. This provides the authorization center service with credible identity evidence and clear authorization content for processing authorization documentation, achieving dual confirmation of identity authenticity and authorization intent.

[0059] Specifically, the authorization and evidence submission unit 133 is used by the authorization center service to encapsulate the user's informed consent action and the draft data request contract into a transaction and submit it to the authorization and evidence chain of the city platform. Specifically, the authorization center service integrates the user's informed consent action containing the authorization decision and the draft data request contract containing the authorization content into an immutable transaction. Utilizing the characteristics of the authorization and evidence chain, this transaction is permanently recorded, achieving solidified evidence of the authorization behavior. This ensures the traceability of the authorization content, user decisions, and related identity information, providing verifiable authorization credentials for data aggregation services to access cross-departmental data, and guaranteeing the compliance of data use.

[0060] Specifically, in one possible embodiment, the implementation process of the authorization and evidence submission unit 133 is as follows: After receiving and verifying the user's informed consent action and the platform's master access token, the authorization center service retrieves the corresponding data request contract draft from the system database based on the contract identifier therein. The server integrates the user's identity identifier, authorization decision, and timestamp from the user's informed consent action with the contract identifier, data source, specific data items, and purpose of use information from the data request contract draft, and generates structured transaction data according to the transaction format specified by the authorization and evidence chain. Subsequently, the server uses the platform's private key to digitally sign the transaction data to ensure the integrity and legality of the transaction source. After signing, the server submits the transaction to the city platform's authorization and evidence chain through the node access interface of the authorization and evidence chain. The evidence chain nodes verify the format, signature, and legality of the transaction. After verification, the transaction is included in the consensus process. After consensus is achieved, the transaction is written into a block and a unique transaction hash is generated. The authorization center service receives the transaction hash and success status information returned by the evidence chain as the basis for generating the authorization receipt. The entire encapsulation and submission process is completed in an encrypted environment to ensure the security and integrity of the transaction data.

[0061] In the aforementioned city platform based on the national network identity authentication public service, the business data token generation module 140 is used to generate a business data token in response to receiving the authorization receipt. The audience of the business data token is limited to the data aggregation service. It should be understood that by strictly limiting the audience of the business data token to the data aggregation service, it ensures that only this service can use the token for data access, preventing unauthorized use by other services. Simultaneously, the business data token must contain the user-authorized data source and specific data items, enabling each data source to clearly identify the access scope. This provides a standardized access credential for the data aggregation service, enabling efficient connection to data sources from various departments. Furthermore, timeliness control reduces the risk of misuse after token theft, ultimately achieving controllability, compliance, and accuracy of data access, and ensuring the security of user data during cross-departmental transfers.

[0062] Specifically, in one possible embodiment, the implementation process of the business data token generation module 140 is as follows: First, the service parses the contract identifier in the authorization receipt and retrieves the corresponding user authorization information from the system database. Then, the service generates a structured business data token according to a preset format, which includes the user's unique identifier within the platform, the token's generation time, and a 5-minute validity period. In the token's key fields, the recipient of the business data token is explicitly specified as the platform's unified data aggregation service, ensuring that other services cannot parse or use the token. Simultaneously, the business data token details the specific access scope corresponding to each data source, such as the education department's academic qualification information query interface and the human resources and social security department's social security record interface for the past 6 months, ensuring that each data source can accurately identify access boundaries. During the generation process, the service uses the platform's dedicated private key to digitally sign the token to prevent content tampering. After generation, the authorization center service sends the token to the business acceptance service, which then transmits it to the data aggregation service as the sole credential for subsequent data access. The entire process is completed in an encrypted environment, ensuring the security of token generation and transmission.

[0063] In the aforementioned city platform based on the national network identity authentication public service, the data aggregation module 150, in response to obtaining the business data token, calls the interface of the platform's unified data aggregation service and receives and aggregates data from different data sources based on the authorized data range field in the business data token to obtain an aggregated data packet. It should be understood that the business data token clearly defines the authorized data range, and the platform's unified data aggregation service has the ability to adapt to multiple data source interfaces, centrally handling permission verification and data format conversion. Therefore, this application avoids direct interaction between the business acceptance service and various data sources by calling the aggregation service interface through the business acceptance service, simplifying the system architecture and reducing adaptation costs. Simultaneously, by utilizing the authorization information in the business data token, it ensures that the aggregation service only obtains data within the user's authorized range, guaranteeing the compliance of data access. The resulting aggregated data packet integrates various information required for processing talent introduction subsidies, with a unified and complete format, providing a reliable data foundation for the business acceptance service to conduct audits based on business logic, reducing audit delays caused by missing data or format issues, and promoting the development of business processing flows towards efficiency and compliance.

[0064] Specifically, in one specific embodiment, Figure 6 is a block diagram of a data aggregation module in a city platform based on a national network identity authentication public service according to an embodiment of this application. As shown in Figure 6, the data aggregation module 150 includes: a token verification unit 151, used by a business acceptance service to verify the signature, timeliness, and whether the audience of the business data token is itself; a data range parsing unit 152, used by the business acceptance service to parse the content of the authorized access data range field from the business data token after successful verification; a data request unit 153, used to initiate requests to different data sources and receive data from different data sources based on the content of the authorized access data range field; and a data integration unit 154, used to integrate the data from different data sources to obtain the aggregated data packet.

[0065] Specifically, the token verification unit 151 is used by the business acceptance service to verify the signature, timeliness, and whether the audience of the business data token is itself. That is, by verifying the signature legality, timestamp validity, and audience identifier of the business data token, the authenticity, validity, and relevance of the token are confirmed, providing a secure and reliable premise for subsequent data access operations based on the token, ensuring the compliance and security of data access behavior, and preventing unauthorized data flow due to token issues.

[0066] Specifically, in one possible embodiment, the token verification unit 151 is implemented as follows: After receiving the business data token, the business acceptance service immediately initiates the verification process. First, the service calls the built-in signature verification module to decrypt and verify the digital signature of the token using a preset public key, confirming that the token content has not been tampered with during transmission. Then, the service extracts the expiration timestamp from the token and compares it with the current system time to ensure that the token is still within the set validity period, such as 5 minutes. Finally, the service parses the audience field in the token, verifies whether the service identifier recorded in this field matches its own service identifier, and confirms that it is the legitimate recipient of the token. If all three verifications pass, the service determines the token is valid and continues subsequent operations. If any verification fails, the service immediately refuses to use the token, records an exception log, and terminates the data access process.

[0067] Specifically, the data range parsing unit 152 is used to parse the content of the authorized data range field from the business data token after successful verification. That is, by parsing the authorized data range field, the data sources authorized by the user, the specific data items corresponding to each data source, and access constraints are extracted. The encoded information is transformed into structured data that the business acceptance service can understand. The specific data range information obtained after parsing allows the business acceptance service to clearly understand the details of the data that the user is allowed to access, avoiding out-of-range data requests due to ambiguous permissions, and ensuring user data privacy and compliance. At the same time, clear data item guidance ensures that subsequent requests to each data source are accurate and complete, reducing business processing delays caused by data omissions or redundancy, and laying the foundation for efficient data aggregation.

[0068] Specifically, in one possible embodiment, the data range parsing unit 152 is implemented as follows: After confirming the validity of the business data token, the business acceptance service calls the parsing module to process the authorized data range field in the token. This field is stored in structured encoding form. The parsing module converts the encoding into readable information through preset mapping rules: the data sources are determined to include education departments, human resources and social security bureaus, and housing and urban-rural development commissions; the corresponding data items are educational level information, social security payment details for the past 6 months, and current property ownership status; and all data items are limited to necessary information related to talent introduction subsidy applications. After parsing, the service organizes this information into an internal data structure, and each data source and its corresponding data item are clearly marked, providing clear guidance for subsequent data requests to various departments.

[0069] Specifically, the data request unit 153 is used to initiate requests to different data sources and receive data from different data sources based on the content of the authorized data range field. That is, for each data source's interface specifications and authentication requirements, it constructs request information conforming to its standards, such as carrying platform authentication credentials and user authorization identifiers, and initiates a backend-to-backend secure call to request the corresponding data items. This ensures that each data source can verify the legality of the request and return the required data, achieving accurate acquisition of cross-departmental data. The acquired data from different data sources comprehensively covers the information required for business review, providing a reliable foundation for subsequent data integration. Simultaneously, the smooth acquisition of cross-departmental data breaks down data silos and improves the efficiency of business processing.

[0070] Specifically, in one possible embodiment, the data request unit 153 is implemented as follows: The business acceptance service prepares request information for each data source based on the parsed data range. When requesting the education department, the service uses the mTLS client certificate pre-agreed between the platform and the department for authentication. The request header carries a digest of the business data token to prove the legitimacy of the authorization, and the request content explicitly points to the academic level information. When requesting social security payment details for the past 6 months from the Human Resources and Social Security Bureau, the service transmits request parameters signed by the platform through a dedicated API gateway, along with a description of the user's authorization range. When requesting property ownership status from the Housing and Urban-Rural Development Commission, the service uses a token verification mechanism recognized by the department to ensure the credibility of the request source. After receiving the request, each data source verifies the authentication information and authorization range, and returns the corresponding data after confirming that it is correct. The service receives and temporarily stores this data.

[0071] Specifically, the data integration unit 154 is used to integrate data from different data sources to obtain the aggregated data package. It should be understood that due to differences in data formats, field naming, and structural specifications from different data sources—for example, educational information returned by the education department is presented in XML format, while social security records from the human resources and social security department use a JSON structure—directly using these heterogeneous data would make it difficult to unify the review logic of the business acceptance service, increasing the complexity of the review process and the probability of errors. At the same time, the original data may contain redundant information unrelated to the business; if not integrated and cleaned, this would affect review efficiency. Therefore, it is necessary to integrate the data to form a data package with a unified format. Specifically, heterogeneous data from different data sources is converted into a unified data format, such as standardized JSON; fields are named in a standardized manner; redundant information is removed; and missing association identifiers, such as unique user IDs, are added to ensure that the data remains consistent in structure and field meaning. This provides a data package with a unified structure and accurate content for the business acceptance service to review based on business logic, reducing review obstacles caused by differences in data formats. The aggregated data packets have a unified format, standardized fields, and complete content, eliminating data heterogeneity between different data sources. This allows business processing services to directly perform review logic processing based on a unified structure, significantly improving review efficiency. The removal of redundant information reduces data processing volume and lowers system resource consumption. Meanwhile, unified association identifiers ensure accurate binding of each data item to the user's identity, avoiding data confusion and providing a data foundation for the accuracy of subsequent review results.

[0072] Specifically, in one possible embodiment, the data integration unit 154 is implemented as follows: After the business acceptance service receives data from the education department, the human resources and social security bureau, and the housing and urban-rural development commission, firstly, the XML-formatted academic information returned by the education department is converted into JSON format, and core fields such as highest academic qualification and graduating institution are extracted and mapped to standardized fields "academic level" and "graduating institution name". Next, the social security record JSON data from the human resources and social security bureau is processed, and fields such as continuous payment months and payment status are standardized to social security continuous payment duration and social security status. Then, the housing information data from the housing and urban-rural development commission is converted, and the property ownership field is clarified as whether the user owns a home. During the integration process, all redundant fields unrelated to the talent introduction subsidy review are removed, such as course grade records from the education department, and a unique user identifier within the platform is attached to each data item. The final aggregated data package is presented in a unified JSON format, containing standardized fields such as academic level, continuous social security payment duration, and whether the user owns a home, with a clear structure and accurate content.

[0073] In the aforementioned city platform based on the national network identity authentication public service, the data review module 160 is used by the business acceptance service to review the aggregated data packet based on business logic to obtain a review result. In a specific example of this application, the data review module 160 includes: the business acceptance service performing parallel verification on the aggregated data packet based on business logic to determine whether the user meets all the conditions for talent introduction subsidies to obtain the review result. Specifically, the business acceptance service loads preset talent introduction subsidy application conditions, such as a doctoral degree or above, continuous social security contributions for the past 6 months, and no local property ownership, etc., and compares and verifies each data item in the aggregated data packet with these conditions one by one to determine whether the user meets all the requirements, and finally generates a clear review result, such as approval, need for supplementary materials, or rejection, to achieve standardization and automation of the review process, ensure that the results comply with policy regulations, and provide a basis for subsequent feedback to the user.

[0074] Specifically, in one possible embodiment, the data verification module 160 operates as follows: First, it extracts the educational background information from the data packet and compares it with the policy requirement of a doctoral degree or higher to confirm that the user's educational background meets the criteria. Next, the module parses the social security records to verify whether the social security payment status for the past six months is continuous and without interruption, meeting the policy requirement of continuous social security payments for at least six months. Subsequently, the module verifies the property information to confirm that the user currently does not own any property locally, thus meeting the requirement of being a "household without property." During the comparison process, if any data item fails to meet the criteria, such as a one-month interruption in social security payments, the module automatically marks the anomaly and generates a verification result requiring supplementary explanations of social security payments. If all data meets the policy requirements, the module generates a verification approval conclusion and associates it with the corresponding policy provisions. The entire verification process is executed automatically by the system without manual intervention, and all comparison results are recorded in the business log to ensure traceability.

[0075] Specifically, in another preferred embodiment, the business processing service first performs parallel verification on the aggregated data packet based on the rules in the business logic to obtain multiple rule verification results. This maximizes the efficiency and response speed of data review, ensuring comprehensive coverage of all relevant rules in the shortest possible time. The effect is a significant reduction in waiting time for business processing, improved platform capabilities for handling complex businesses, a faster service experience for citizens, and reduced processing pressure on the backend system. For the Boolean results obtained by the rule engine verifying data line by line / in parallel, a simple logical "AND" operation may not be able to obtain accurate status judgments. In particular, the logical "AND" for Boolean results can only handle "true" or "false" cases that conform to the rules, but cannot obtain specific business rule details. Furthermore, the status includes not only "pass" and "reject" but also the possible "pending manual review" status. That is, there is a conflict between the precise logic of Boolean results and the logic of status judgment with ambiguous boundaries, thus reducing the corresponding accuracy.

[0076] Preferably, an encoder-decoder model is designed to map different logical forms by combining rule semantics with rule results. Through semantic encoding, the Boolean verification result of each rule, combined with the predefined business semantics of that rule (e.g., whether the rule concerns education level, social security contribution years, or place of residence), is transformed into a high-dimensional, continuous rule verification result encoding feature vector. This feature vector is not merely a simple mapping of 0 or 1, but contains deep semantic information such as the rule's type, weight, and associated data fields. This allows the system to understand the true meaning of the rule, rather than simply its superficial pass or fail. In this way, discrete Boolean results lacking contextual information are elevated to a continuous, semantically rich intermediate logical form, providing richer and more expressive foundational data for subsequent intelligent analysis and decision-making.

[0077] Specifically, the encoder model adopts a Transformer-based architecture, which demonstrates superior performance in handling complex semantic understanding and feature encoding tasks. Leveraging its self-attention mechanism, the Transformer architecture allows the model to simultaneously focus on different positional information within the input sequence while processing sequential data, accurately grasping global semantic relationships. Specifically, the encoder performs semantic encoding on the verification result of each rule. First, it semantically encodes the verification result of each rule, extracting meta-information such as rule type (e.g., education level, social security, real estate), rule weight, and associated data fields. The embedding layer transforms the rule type into a 128-dimensional semantic vector. Combining the rule weight and data field features, a 193-dimensional initial feature vector is generated. This is then processed by a two-layer fully connected network to obtain a 128-dimensional standardized rule feature vector. Finally, the output rule Boolean type result is given a semantic space probabilistic representation. If the verification result conforms to the rule and is "true," then the probabilistic representation is... The probability representation of a valid result being "false" (i.e., the number of rules that meet the criteria divided by the total number of rules) is as follows: This is to unify the Boolean type results from the simple rule engine and the professional rule engine under the association probabilistic fuzzy bound, so as to promote robust classification through probabilistic numerical representation of classes.

[0078] Then, the multiple rule verification results are encoded to obtain a multiple rule verification result encoding feature vector. The number of rule verification results that are determined to conform to the rule is divided by the total number of rule verification results to obtain a probabilistic value. Furthermore, a rule verification result encoding feature vector is generated for each rule verification result. In response to the rule verification result encoding feature vector corresponding to the rule verification result that conforms to the rule, it is activated by a probabilistic activation function and then multiplied by the probabilistic value, i.e. Furthermore, in response to the rule verification result encoding feature vector corresponding to the rule verification result that does not conform to the rule, the feature vector is activated by the probabilistic activation function and then multiplied by the difference between the probabilistic values ​​and the result. This is to obtain multiple confidence-adjusted feature vectors. For the first Adjust the feature vector based on confidence level. It is the sigmoid activation function. For the first The rule verification result is encoded into a feature vector. for The corresponding probabilistic numerical values. That is, in order to introduce probabilistic fuzzy boundaries for the same rule semantics, i.e. Intervals, to facilitate binary confidence levels Fuzzy association. This allows the model to more flexibly evaluate the compliance of individual rules, avoiding the situation where an entire business is rejected simply because a non-critical rule is not met. Furthermore, it allows the semantic feature vector of each rule to carry richer contextual information, more accurately reflecting its contribution and certainty in the entire business review, and providing a more reliable basis for subsequent refined decision-making.

[0079] For the confidence-adjusted semantic encoding vector, for example denoted as Calculate the confidence loss value of each confidence-adjusted feature vector in the plurality of confidence-adjusted feature vectors:

[0080]

[0081] here, This represents taking the base-2 logarithm of each eigenvalue of the eigenvector, and... The first norm of a vector serves to balance the information loss of rule semantics under Boolean probabilistic fuzzy bounds. It is the sigmoid activation function. For the first The rule verification result is encoded into a feature vector. For the first Adjust the feature vector based on confidence level. This is a function for calculating the confidence loss value. This optimizes and improves the reliability of the encoded feature vector in the final rule verification result, providing high-quality input for the decoder to output the final review result.

[0082] In this way, the confidence loss value can be used as the center point, the probabilistic bound can be used as the range parameter, and the confidence membership function can be introduced to correct the semantic encoding vector. That is, semantic encoding correction is performed based on the confidence loss value and the probabilistic value to obtain multiple optimized rule verification result encoding feature vectors.

[0083]

[0084] in, For the first The optimized rule verification result encodes the feature vector. For the first Adjust the feature vector based on confidence level. The function for calculating the confidence loss value. For the first The rule verification result is encoded into a feature vector. for The corresponding probabilistic values.

[0085] This improves the deterministic application of confidence scores to semantic quantification rules. Specifically, the Boolean output is as a whole associated with and fuzzified through confidence scores, and then the fuzzy membership function of confidence scores is used to quantify the deterministic application of fuzzification rules to semantics. This allows the rules to be demarcated based on confidence scores around the confidence score loss value, thereby performing semantic fuzzy associations within the rule decision boundary defined by the Boolean rule fuzzification parameters. As a result, the accuracy of the fuzzy correspondence in the decoder output is improved.

[0086] Finally, the optimized rule verification results encoded into feature vectors are input into the decoder to obtain the review result. The decoder employs a multi-layer fully connected neural network architecture with an attention mechanism. First, the attention layer processes the input optimized feature vectors, assigning weights based on the correlation between each vector and the business objective. For example, in talent introduction subsidy review, the weight of optimized vectors related to education level may be higher than that related to real estate, thus generating a weighted fusion global feature vector. Next, the global feature vector enters a two-layer hidden layer with 64 neurons per layer and using the ReLU activation function, undergoing nonlinear transformation to extract higher-order semantic features. Finally, the output layer uses a softmax function to map the processed features into a probability distribution of three results: "approved," "awaiting manual review," and "approved." The highest probability value is taken as the final review result. Specifically, the decoder comprehensively analyzes and performs pattern recognition on these complex, high-dimensional optimized rule verification result encoded feature vectors, mapping them to a clear and concise business review result, such as approved, awaiting manual review, or approved. By learning from a large amount of business rules and historical review data, the decoder can understand the final business decision represented by different combinations of semantic feature vectors. This achieves a seamless connection from underlying data verification to final business decision-making, enabling the city platform to automatically output accurate and intelligent review results, greatly improving the intelligence level and efficiency of business processing, effectively solving the problems of time-consuming, labor-intensive, and inefficient manual review in the traditional model, and ultimately providing citizens with a convenient and reliable "one-stop" service experience.

[0087] In the aforementioned city platform based on the national network identity authentication public service, the review result return module 170 is used to return the review result to the city platform client. That is, the review result generated by the business acceptance service is transmitted to the city platform client in a clear and easy-to-understand format and displayed to the user through the client interface, reducing the time cost and operational complexity of information retrieval and significantly improving the user experience. The specific explanations included in the result, such as the reason for rejection and the requirements for supplementary materials, provide users with clear action guidance, avoiding duplicate applications or invalid operations due to ambiguous information. At the same time, the timeliness of result feedback enhances users' trust in the platform service, promotes a closed-loop business process from application to result feedback, and improves the service quality and efficiency of the city platform.

[0088] Specifically, in one possible embodiment, the implementation process of the review result return module 170 is as follows: After the business acceptance service generates the review result, it immediately performs structured processing on the result, integrating the conclusion of approval, the basis (such as meeting the requirements for education, social security, and property ownership), and subsequent explanations (such as the subsidy will be issued to your linked bank card within 15 working days) into a standardized data format. The service transmits this data to the city platform client through an encrypted communication channel, and the transmission process uses end-to-end encryption to ensure information security. After receiving the data, the client parses and converts it into a user-friendly display format, displaying "Approval Approved" with a prominent title on the application page, followed by a detailed explanation: "Your education is a doctorate, you have continuously paid social security for the past 6 months, and you do not own property in the local area, which meets the application conditions for talent introduction subsidies. The subsidy will be issued to the bank card ending in XXXX within 15 working days. Please check your account." At the same time, the client provides an entry to view details, where users can click to view the complete review basis and policy terms. If the review result requires supplementary materials, the client will list the specific materials and upload entry, guiding the user to complete the supplementary operation.

[0089] In summary, the city platform based on the national network identity authentication public service, as described in this application, first utilizes the national network identity authentication public service to complete user identity authentication to establish a trusted access foundation. When a user conducts business, a data request contract is constructed and stored after user confirmation and authorization, forming a transparent and traceable authorization mechanism. Next, a data token with limited access is generated based on the user's authorization scope. The required cross-source data is obtained based on a unified data aggregation service, realizing on-demand data aggregation and secure data flow. Then, the aggregated data is automatically reviewed through business logic to obtain the review result, which is finally returned to the user. This simplifies business processes, solves the problems of duplicate authorization and data silos, while ensuring user data control and improving the intelligence and efficiency of city platform business processing.

[0090] Furthermore, a service method based on a city platform for national network identity authentication public services is also provided.

[0091] Figure 7 is a flowchart of a service method for a city platform based on the national network identity authentication public service according to an embodiment of this application. As shown in Figure 7, the service method for a city platform based on the national network identity authentication public service includes the following steps: S1, in response to a login request initiated by a user on the city platform client, user identity authentication is performed based on the national network identity authentication public service, and a platform master access token is generated after successful identity authentication; S2, in response to a user clicking to apply for talent introduction subsidies, the city platform client initiates a business request to the backend business acceptance service, wherein the business acceptance service generates a draft data request contract in response to the business request; S3, the draft data request contract is displayed on the city platform client, and in response to the user clicking the "agree to authorize" button, the draft data request contract is sent to the backend business acceptance service. S4. The draft contract is submitted to the authorization storage chain of the city platform and an authorization receipt is returned; S5. In response to receiving the authorization receipt, a business data token is generated, and the audience of the business data token is limited to the data aggregation service; S6. In response to obtaining the business data token, the business acceptance service calls the interface of the platform's unified data aggregation service and receives and aggregates data from different data sources based on the authorized data range field in the business data token to obtain an aggregated data packet; S7. The business acceptance service reviews the aggregated data packet based on business logic to obtain a review result; S8. The review result is returned to the city platform client.

[0092] As described above, the service method of the city platform based on the national network identity authentication public service according to the embodiments of this application can be implemented in various wireless terminals. In one possible implementation, the service method of the city platform based on the national network identity authentication public service according to the embodiments of this application can be integrated into the wireless terminal as a software module and / or hardware module. For example, the service method of the city platform based on the national network identity authentication public service can be a software module in the operating system of the wireless terminal, or it can be an application developed for the wireless terminal; of course, the service method of the city platform based on the national network identity authentication public service can also be one of the many hardware modules of the wireless terminal.

[0093] Alternatively, in another example, the service method of the city platform based on the national network identity authentication public service and the wireless terminal can also be separate devices, and the service method of the city platform based on the national network identity authentication public service can be connected to the wireless terminal via wired and / or wireless networks, and transmit interactive information in accordance with the agreed data format.

[0094] Here, those skilled in the art will understand that the specific operations of each step in the service method of the city platform based on the national network identity authentication public service have been described in detail in the above description of the city platform based on the national network identity authentication public service with reference to Figures 1 to 6, and therefore, the repeated description will be omitted.

Claims

1. A city platform based on national network identity authentication public service, characterized in that, include: The user identity authentication module is used to respond to login requests initiated by users on the city platform client, perform user identity authentication based on the national network identity authentication public service, and generate a platform master access token after successful identity authentication; The business request and contract generation module is used to respond to a user clicking to apply for talent introduction subsidies. The city platform client initiates a business request to the backend business acceptance service, whereby the business acceptance service generates a draft data request contract in response to the business request. The contract authorization and notarization module is used to display the draft data request contract on the city platform client and, in response to the user clicking the "agree to authorization" button, submit the draft data request contract to the city platform's authorization notarization chain and return an authorization receipt. The business data token generation module is used to: in response to receiving the authorization receipt, the authorization center service generates a business data token based on the contract content of the draft data request contract. The business data token includes a data scope field and an audience field for authorized access. The data aggregation module is used to: in response to obtaining the business data token, the business acceptance service calls the platform's unified data aggregation service interface and, based on the business data... The authorized access data range field in the token receives and aggregates data from different data sources to obtain an aggregated data packet, including: a token verification unit, used by the business acceptance service to verify the signature, validity period, and whether the audience is itself of the business data token; a data range parsing unit, used by the business acceptance service to parse the content of the authorized access data range field from the business data token after successful verification; a data request unit, used to initiate requests to different data sources and receive data from different data sources based on the content of the authorized access data range field; a data integration unit, used to integrate the data from different data sources to obtain the aggregated data packet; a data review module, used by the business acceptance service to review the aggregated data packet based on business logic to obtain a review result; and a review result return module, used to return the review result to the city platform client.

2. The city platform based on national network identity authentication public service as described in claim 1, characterized in that, The user authentication module includes: a platform redirection unit, used to redirect to the national network identity authentication public service in response to a login request initiated by a user on the city platform client; a face recognition authentication unit, used by the national network identity authentication public service to authenticate the user's identity through face recognition; an authorization code generation and return unit, used to generate an authorization code and return the authorization code to the city platform client in response to successful identity authentication; an authorization code transmission unit, used by the city platform client to send the authorization code to the identity authentication service; and an authorization code verification unit, used by the identity authentication service to verify the validity of the authorization code to the national network identity authentication public service through backend signals, and to generate the platform master access token after successful verification.

3. The city platform based on national network identity authentication public service as described in claim 1, characterized in that, The business request and contract generation module includes: a business request initiation unit, used to respond to a user clicking to apply for talent introduction subsidies, whereby the city platform client, carrying the platform's main access token, initiates a business request to the backend business acceptance service; a user identity verification unit, used by the business acceptance service to verify the user's identity based on the platform's main access token after receiving the business request; a data requirement template loading unit, used by the business acceptance service to load a data requirement template corresponding to the service ID in the business request from the configuration center; and a data request contract draft generation unit, used by the business acceptance service to call the authorization center service and combine the data requirement template to generate the data request contract draft for the business request.

4. The city platform based on national network identity authentication public service as described in claim 1, characterized in that, The contract authorization and notarization module includes: an informed consent action generation unit, used to generate a user informed consent action in response to the user clicking the consent authorization button; an informed consent and token sending unit, used to send the user informed consent action together with the platform master access token to the authorization center service; and an authorization notarization submission unit, used by the authorization center service to encapsulate the user informed consent action and the data request contract draft into a transaction and submit it to the authorization notarization chain of the city platform.

5. The city platform based on national network identity authentication public service as described in claim 1, characterized in that, The data review module is used to: perform parallel verification of the aggregated data packets based on business logic by the business acceptance service to determine whether the user meets all the conditions for the talent introduction subsidy in order to obtain the review result.

6. A service method for an urban platform based on national network identity authentication public services, characterized in that, include: In response to a user's login request initiated by the city platform client, the system performs user authentication based on the national network identity authentication public service and generates a platform master access token upon successful authentication. In response to a user clicking to apply for a talent introduction subsidy, the city platform client initiates a business request to the backend business processing service. The business processing service generates a draft data request contract in response to the business request; displays the draft data request contract on the city platform client; and in response to the user clicking the "agree to authorization" button, submits the draft data request contract to the city platform's authorization storage chain and returns an authorization receipt. In response to receiving the authorization receipt, the authorization center service generates a business data token based on the contract content of the draft data request contract. The business data token includes a data scope field and an audience field for authorized access. In response to obtaining the business data token, the business processing service calls the platform's unified data aggregation service interface and, based on the... The authorized access data scope field in the business data token receives and aggregates data from different data sources to obtain an aggregated data packet. This includes: the business acceptance service verifying the signature, validity period, and whether the audience of the business data token is itself; after successful verification, the business acceptance service parses the content of the authorized access data scope field from the business data token; based on the content of the authorized access data scope field, it initiates requests to different data sources and receives data from different data sources; it integrates the data from different data sources to obtain the aggregated data packet; the business acceptance service reviews the aggregated data packet based on business logic to obtain a review result; and it returns the review result to the city platform client.

Citation Information

Patent Citations

  • Identity data access control method, device and system

    CN109635536A

  • Data processing method and device based on trusted execution environment, equipment and medium

    CN116980163A