User data access method and device, equipment and storage medium
By parsing the user authorization code to obtain authorization information and matching data access requests, the problem of lack of flexibility in user data access methods is solved, user customized control over data access is realized, and data security and the accuracy of authorization management are improved.
Patent Information
- Application Number
- CN202510863107.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-10-14
AI Technical Summary
The existing technology lacks a flexible authorization management mechanism for user data access, resulting in insufficient security of personal data and users being unable to effectively control the scope of data query and usage.
By parsing the authorization code of the target user, authorization information is obtained, including the identity of the requester, the purpose of data access, the type of accessible data, and data operation permissions. The metadata of the data access request is matched with the authorization information. If the match is successful, the target data is returned. The generated authorization code is designed according to the user's personalized needs to ensure that data access is within the authorized scope.
It realizes dynamic control based on user-defined authorization scope, improves user data security, avoids data abuse, and improves the flexibility and accuracy of authorization management.
Smart Images

Figure CN120785581A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a user data access method, apparatus, device and storage medium. Background Art
[0002] Personal information authorization refers to the process by which a data subject (user) explicitly authorizes the scope and conditions of data use when a personal information processor requests the processing of personal data. Currently, when information processors, such as financial and insurance institutions, request access to a user's personal data, they typically obtain authorization to process and use that data through facial recognition or signed informed consent forms. Once authorized, they can use the user's data.
[0003] However, users often have to scan their faces for authentication or sign informed consent forms due to the urgent need to conduct business. Therefore, they have no idea about the scope of data query and use after authorization, which poses a risk of personal data being abused. In addition, users' personal data covers all aspects, including marriage, housing, medical treatment, education, taxation, and other dimensions. In specific application scenarios, only specific dimensional data needs to be accessed according to the principle of minimum sufficient. For example, in underwriting and claims scenarios, only medical-related data needs to be accessed, without accessing other data such as marriage, education, and taxation. Therefore, relevant data access scenarios lack a flexible authorization management mechanism, and there is an urgent need for a solution that can dynamically control data access based on user needs. Summary of the Invention
[0004] The main purpose of this application is to provide a user data access method, device, equipment and storage medium, which can at least solve the problem that the user data access method in the related technology lacks flexibility in the authorization management mechanism, which is not conducive to ensuring the security of user personal data.
[0005] To achieve the above-mentioned purpose, the first aspect of the present application provides a user data access method, which includes: when receiving a data access request, parsing the authorization code corresponding to the target user to obtain the authorization information of the target user; wherein, the authorization information includes the identity information of the requester, the purpose of data access, the type of accessible data and the data operation authority; matching the data access meta-information corresponding to the data access request with the authorization information; if the match is successful, returning the target data associated with the data access meta-information to the data access request system.
[0006] The second aspect of the present application provides a user data access device, including: a parsing module, which is used to parse the authorization code corresponding to the target user when a data access request is received, and obtain the authorization information of the target user; wherein the authorization information includes the identity information of the requester, the purpose of data access, the type of accessible data and the data operation authority; a matching module, which is used to match the data access meta-information corresponding to the data access request with the authorization information; and a data return module, which is used to return the target data associated with the data access meta-information to the data access request system if the match is successful.
[0007] The third aspect of the present application provides an electronic device, comprising: a memory and a processor, wherein the processor is used to execute a computer program stored in the memory. When the processor executes the computer program, it implements the steps of the user data access method provided in the first aspect of the present application.
[0008] The fourth aspect of the present application provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of the user data access method provided in the first aspect of the present application are implemented.
[0009] As can be seen from the above, according to the user data access method, apparatus, device and storage medium provided by the present application, when a data access request is received, the authorization code corresponding to the target user is parsed to obtain the authorization information of the target user; wherein, the authorization information includes the identity information of the requester, the purpose of data access, the type of accessible data and the data operation authority; the data access meta-information corresponding to the data access request is matched with the authorization information; if the match is successful, the target data associated with the data access meta-information is returned to the data access request system. Through the implementation of the present application, when a data access request is received, the authorization information can be obtained by parsing the authorization code of the target user, so as to determine whether to return the target data required for the data access request based on the authorization information. The authorization code is designed and generated according to the user's personalized needs, so that the user can have control over the processing of his or her personal data, ensure that the access request complies with his or her customized authorization scope, and effectively improve the security of user data. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.
[0011] Figure 1 A schematic diagram of the basic flow of a user data access method provided in one embodiment of the present application;
[0012] Figure 2 A detailed flowchart of a user data access method provided in one embodiment of the present application;
[0013] Figure 3 A schematic diagram of a module of a user data access device provided in one embodiment of the present application;
[0014] Figure 4 A schematic diagram of the structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0015] In order to make the purpose, features, and advantages of the invention of this application more obvious and easy to understand, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.
[0016] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of this application, the meaning of "plurality" is two or more, unless otherwise clearly specified.
[0017] In order to solve the problem that the authorization management mechanism of the user data access method in the related art lacks flexibility and is not conducive to ensuring the security of user personal data, an embodiment of the present application provides a user data access method, such as Figure 1 This is a basic flow chart of the user data access method provided in this embodiment. The user data access method includes the following steps:
[0018] Step 101: When a data access request is received, the authorization code corresponding to the target user is parsed to obtain the authorization information of the target user.
[0019] Specifically, in this embodiment, when a request for access to the target user's data is received from the data access request system, the target user's authorization code is obtained and the authorization code is parsed to obtain the target user's authorization information. In this embodiment, the user's authorization information can be sent to the data access requester in the form of an authorization code. The authorization code can be set according to the user's personalized needs, allowing the user to control the scope of the authorized data and have real-time decision-making power over the processing of their personal data. The authorization information includes the identity information of the requester who is allowed to access personal data (such as the name of the institution), the type of data allowed to be accessed and the scope of access to this type of data (such as diagnostic information in medical data), the purpose of data access (such as credit assessment, research), the validity period and timestamp of the access permission, an encrypted digital signature (used to ensure that the content of the authorization code has not been tampered with), and data operation permissions (such as read-only).
[0020] In some implementations of this embodiment, before parsing the authorization code corresponding to the target user, the method further includes: obtaining authorization information set by the target user and synchronizing the authorization information to a preset access control list; and generating an authorization code corresponding to the target user based on the authorization information in the access control list.
[0021] In this embodiment, to ensure that users can customize the scope of personal data authorization and improve authorization control, an authorization code (e.g., a QR code) can be generated based on the user's authorization preferences for personal data. This authorization QR code can be applied to the authorization scenario, allowing the data access requester to access their personal data. Specifically, the authorization code contains user authorization information, which includes: the identity information of the requester who is allowed to access personal data (e.g., the name of the institution), the type of data allowed to be accessed and the access scope of this type of data (e.g., diagnostic information in medical data), the purpose of restricting data access (e.g., credit assessment, research), the validity period and timestamp of the access rights, an encrypted digital signature (used to ensure that the content of the authorization code is not tampered with), and restricted access actions (e.g., read-only). The above authorization information can be managed through Access Control Lists (ACLs), which can be extended through ODRL policies to more accurately meet permission management requirements.
[0022] User-defined authorization information can be personalized through the user interface using a data privacy vocabulary. For example, a table generated using the DPV (Data Privacy Vocabulary) allows for the selection, management, and control of personal information authorization subjects, authorization purposes, and permission scopes. After the user performs operations through the user interface, these operations are synchronized to the ACL. For example, for medical data, the information included in the user interface operations is shown in Table 1 below.
[0023] Table 1
[0024]
[0025]
[0026] The data privacy vocabulary includes signals such as those shown in Table 2 below.
[0027] Table 2
[0028]
[0029] Step 102: Match the data access meta-information corresponding to the data access request with the authorization information.
[0030] Specifically, in this embodiment, after parsing the authorization code corresponding to the target user and obtaining the target user's authorization information, the data access requester's desired access items are further matched with the authorization information to determine whether the data access requester's request exceeds the target user's authorization scope. Data access metadata includes the data requester's identity, the purpose of data use, and the type of data required for access.
[0031] In some implementations of this embodiment, before matching the data access meta-information corresponding to the data access request with the authorization information, it also includes: obtaining the digital signature information and timestamp in the authorization information; verifying the legitimacy of the digital signature information and timestamp; when the verification passes, executing the matching of the data access meta-information corresponding to the data access request with the authorization information.
[0032] Specifically, after obtaining the authorization information of the target user, the legitimacy of the authorization code can be verified first, and the data access meta-information can be matched only when the authorization code is legal, to ensure the accuracy of the authorization scope. The legitimacy of the authorization code can be determined based on whether the target authorization information meets the preset rules. The target authorization information can be the digital signature and timestamp of the target user. For the digital signature, it can be compared with the pre-shared legal signature, for example, by calculating the similarity to ensure the legitimacy of the digital signature; for the timestamp (such as the time when the authorization code is generated), it can be verified whether it is within the valid date range. If it is, the timestamp is determined to be legal. When the selected target authorizations all meet the requirements, it can be determined that the authorization code is legal. In addition, when the authorization code is illegal, the user can be prompted to update the authorization code to ensure the accuracy of the authorization scope.
[0033] Step 103: If the match is successful, the target data associated with the data access meta-information is returned to the data access request system.
[0034] Specifically, in this embodiment, if the data access meta-information corresponding to the data access request matches the user's authorization information, the corresponding target data can be directly accessed and returned to the data access request system. This ensures that the data obtained by the data access requester is within the authorized scope of the target user. Furthermore, through the authorization code, the target user can customize the authorization scope and clearly understand the scope of their own data authorization, thus preventing the misuse of personal data and effectively improving user data security.
[0035] In some implementations of this embodiment, the data access meta-information includes the type of data requested for access; returning the target data associated with the data access meta-information to the data access request system includes: retrieving the corresponding target data from the data storage unit of the target user based on the type of data requested for access; returning the target data to the data access request system, and recording all information of the current access event and the authorization event to a preset storage unit.
[0036] Specifically, in this embodiment, when the data access metadata of the data access request system matches the user's authorization information, the target data of the corresponding data type will be called from the target user's data storage center. The data storage center is used to store data generated by users in handling various business operations or data uploaded by users. The data storage center adopts distributed storage for different types of data and divides them into PODs (Plain Old Data) for different business scenarios according to the data type. At the same time, fast and accurate access can be achieved through tree-type connection methods. In addition, for each data call, the data call details such as the authorization time, the identity of the data requester, the call data type, and the usage will be recorded to provide audit and traceability functions. The data call details can be encrypted and stored to ensure that the records cannot be tampered with. By recording each authorization and access item, users can be provided with information such as the call status of the corresponding data, the number of calls, the identity of the caller, etc., so that users can clearly understand the authorization and access status of their own data.
[0037] Furthermore, in some implementations of this embodiment, after recording the current access event and authorization event to a preset storage unit, it also includes: when an audit trail request is received, obtaining the permission information of the operator corresponding to the audit trail request; performing a legitimacy verification on the permission information; when the legitimacy verification passes, returning the permission information and the query result corresponding to the audit trail request; wherein the query result includes information on the access event and the authorization event.
[0038] Specifically, in the embodiment, when the user needs to query the authorization and access history, identity verification is performed through a username and password, a fingerprint, and the like. If the verification is passed, the query result can be returned according to the query data type and the permission range corresponding to the user. The query result can be displayed in the form of a user interface, and the query result includes the authorization time, the calling condition, the calling times, and the identity of the caller.
[0039] In some other embodiments of the embodiment, after the data access meta-information corresponding to the data access request is matched with the authorization information, the method further includes: if the matching fails, generating an authorization request according to the target data access meta-information for which the matching fails; and returning the data associated with the target data access meta-information to the data access request system when the authorization request is passed.
[0040] Specifically, in the embodiment, when the data access meta-information to be accessed by the data access request system does not match the user authorization information, further authorization is needed, for example, an authorization confirmation prompt is generated to remind the target user to perform secondary authorization confirmation. The authorization confirmation prompt will clearly indicate the newly added access data item, for example, “the current E application program wants to access (read / write / share / control) your X data POD by R unit for Y purpose, this request does not meet your preferences, do you allow access to X data for Y purpose?”, and the user can process the authorization. If the target user confirms the authorization, the corresponding target data can be called. In this way, it is possible to obtain the required data within the authorization range as much as possible, and to ensure the business development of the data request party and the security of the user data.
[0041] Further, in some other embodiments of the embodiment, after the data associated with the target data access meta-information is returned to the data access request system, the method further includes: selecting a corresponding update strategy according to the importance level of the data access request; and updating the authorization code according to the update strategy and the permission type corresponding to the target data access meta-information.
[0042] Specifically, in the embodiment, when the user authorizes the authorization matters outside the authorization information, the new authorization matters are also synchronized to the authorization code, and a corresponding update strategy is selected according to the importance level of the data access request. According to the update strategy, the new authorization matters are permanently or only recorded in the ACL table or the DPV table.
[0043] Based on the technical solutions of the embodiments of the present application, when a data access request is received, the authorization code corresponding to the target user is parsed to obtain the authorization information of the target user; wherein the authorization information includes requester identity information, data access purpose, accessible data type and data operation permission; the data access meta information corresponding to the data access request is matched with the authorization information; if the matching is successful, the target data associated with the data access meta information is returned to the data access request system. Through the implementation of the solutions of the present application, when a data access request is received, the authorization information can be obtained by parsing the authorization code of the target user, so as to judge whether the target data required by the data access request is returned according to the authorization information. The authorization code is generated according to the personalized needs of the user, so that the user has control over the processing of his personal data, ensures that the access request meets the self-defined authorization range, and effectively improves the security of user data.
[0044] Figure 2 The method in the embodiment of the present application provides a refined user data access method, and the user data access method comprises:
[0045] Step 201, obtaining the authorization information formulated by the target user, and synchronizing the authorization information to a preset access control list;
[0046] Step 202, generating the authorization code corresponding to the target user based on the authorization information in the access control list;
[0047] Step 203, when a data access request is received, parsing the authorization code corresponding to the target user to obtain the authorization information of the target user;
[0048] Step 204, verifying the legality of the digital signature information and the timestamp in the authorization information;
[0049] Step 205, when the verification is passed, matching the data access meta information corresponding to the data access request with the authorization information;
[0050] Step 206, if the matching is successful, returning the target data associated with the data access meta information to the data access request system;
[0051] Step 207, if the matching fails, generating an authorization request according to the target data access meta information that fails to match;
[0052] Step 208, when the authorization request is passed, returning the data associated with the target data access meta information to the data access request system.
[0053] Specifically, in the embodiment, according to the ACL rule and the authorization preference setting of the individual, a two-dimensional code with specific individual authorization information can be generated in real time, and the data user obtains the authorization information. By realizing the real-time generation of the individual authorization two-dimensional code, the authorization two-dimensional code is applied to the authorization scene for individual information access, and the problem of complicated authorization procedures can be effectively solved. When receiving a data access request, the authorization code of the user is parsed, the authorization information is extracted and the legality is verified. If the verification is passed, the data access request party needs to access the matter and the authorization information is matched to judge whether the request of the data access request party exceeds the authorization range of the target user. If the data access request corresponds to the data access meta information matching the authorization information of the user, the corresponding target data can be directly called, and the target data is returned to the data access request system. Therefore, it can be ensured that the data obtained by the data access request party is within the authorization range of the target user, and the target user can define the authorization range and clearly understand the data authorization range, avoid misuse of personal data, and effectively improve the security of user data. If the data access request system needs to access the data access meta information that does not match the user authorization information, further authorization is needed, and if the target user confirms the authorization, the corresponding target data can be called. Therefore, it can be ensured that the required data is obtained as much as possible within the authorization range, and the business development of the data request party and the security of the user data are ensured.
[0054] It should be understood that the size of the serial number of each step in the embodiment does not mean the order of the execution of the steps, and the execution order of each step should be determined according to its function and inherent logic, and should not constitute the only limitation on the implementation process of the embodiment of the application.
[0055] Based on the above technical solutions of the embodiment of the application, the access control list (ACL) rule is embedded in the dynamic two-dimensional code to realize the customized authorization management of individual data. The user can fine-tune the authorization according to the specific data needs of different scenes, avoid the privacy risks caused by "one-size-fits-all authorization", and improve the flexibility and accuracy of the authorization. By combining the user preference settings, the authorization process is automated and intelligent. For requests that meet the user's preferences, the system can automatically authorize without repeated confirmation; for requests that do not meet the preferences, the user is prompted to authorize again, and the new decision is supported to be included in the preference rule optimization to improve the user experience.
[0056] Figure 3 A user data access device is provided for an embodiment of the application. The user data access device can be applied to the user data access method described above. As shown in Figure 3 The user data access device mainly includes:
[0057] The parsing module 301 is configured to parse the authorization code corresponding to the target user to obtain authorization information of the target user when receiving the data access request, wherein the authorization information comprises requester identity information, data access purpose, accessible data type, and data operation permission.
[0058] The matching module 302 is configured to match the data access meta-information corresponding to the data access request with the authorization information.
[0059] The data returning module 303 is configured to return the target data associated with the data access meta-information to the data access request system if the matching is successful.
[0060] In some embodiments of the present embodiment, the user data access device further comprises a generating module configured to obtain the authorization information formulated by the target user, and synchronize the authorization information to a preset access control list; and generate the authorization code corresponding to the target user based on the authorization information in the access control list.
[0061] In some embodiments of the present embodiment, the parsing module is further configured to obtain digital signature information and a timestamp in the authorization information; perform legality verification on the digital signature information and the timestamp; and perform the matching of the data access meta-information corresponding to the data access request with the authorization information when the verification is passed.
[0062] In some embodiments of the present embodiment, the data access meta-information comprises a data type requested to be accessed; and the data returning module is specifically configured to retrieve corresponding target data from a data storage unit of the target user according to the data type requested to be accessed; return the target data to the data access request system; and record all information of a current access event and an authorization event to a preset storage unit.
[0063] Further, in some embodiments of the present embodiment, the data returning module is further configured to obtain permission information of an operator corresponding to an audit tracking request when receiving the audit tracking request; perform legality verification on the permission information; return the permission information and a query result corresponding to the audit tracking request when the legality verification is passed; and the query result comprises information of the access event and the authorization event.
[0064] Further, in some other embodiments of the present embodiment, the data returning module is further configured to generate an authorization request according to the target data access meta-information for which the matching fails if the matching fails; and return data associated with the target data access meta-information to the data access request system when the authorization request is passed.
[0065] In some embodiments of the present embodiment, the user data access apparatus further comprises an updating module configured to select a corresponding updating strategy according to the importance level of the data access request, and update the authorization code according to the updating strategy and the permission type corresponding to the target data access meta information.
[0066] It should be noted that the user data access method in the foregoing embodiments can be implemented based on the user data access apparatus provided in the present embodiment. For the convenience and brevity of description, the specific working process of the user data access apparatus described in the present embodiment can refer to the corresponding process in the foregoing method embodiments, which will not be described herein again.
[0067] Based on the technical solutions of the foregoing embodiments of the present application, when a data access request is received, the authorization information of a target user is obtained by analyzing the authorization code corresponding to the target user, wherein the authorization information comprises requester identity information, data access purpose, accessible data type and data operation permission; the data access meta information corresponding to the data access request is matched with the authorization information; if the matching is successful, the target data associated with the data access meta information is returned to the data access request system. Through the implementation of the present application, when a data access request is received, the authorization information can be obtained by analyzing the authorization code of the target user, so as to determine whether to return the target data required by the data access request according to the authorization information. The authorization code is generated according to the personalized needs of the user, so that the user has control over the processing of his / her personal data, ensures that the access request meets the self-defined authorization range, and effectively improves the security of user data.
[0068] Figure 4 An electronic device is provided for an embodiment of the present application. The electronic device can be used to implement the user data access method in the foregoing embodiments, and mainly comprises:
[0069] The memory 401, the processor 402 and the computer program 403 stored in the memory 401 and executable on the processor 402 are communicatively connected. When the processor 402 executes the computer program 403, the method in the foregoing embodiments is implemented. The number of processors can be one or more.
[0070] The memory 401 can be a high-speed random access memory (RAM, Random Access Memory) or a non-volatile memory such as a disk memory. The memory 401 is used to store executable program codes, and the processor 402 is coupled with the memory 401.
[0071] Furthermore, the embodiment of the present application also provides a computer-readable storage medium, which can be set in the above electronic device. The computer-readable storage medium can be the above Figure 4 Memory in the illustrated embodiment.
[0072] The computer-readable storage medium stores a computer program that, when executed by a processor, implements the user data access method in the aforementioned embodiment. Furthermore, the computer-readable storage medium may be any medium capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), RAM, a magnetic disk, or an optical disk.
[0073] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.
[0074] Modules described as separate components may or may not be physically separate, and components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of these modules may be selected to achieve the purpose of this embodiment based on actual needs.
[0075] In addition, the functional modules in the various embodiments of the present application may be integrated into a processing module, or each module may exist physically separately, or two or more modules may be integrated into a single module. The above-mentioned integrated modules may be implemented in the form of hardware or software functional modules.
[0076] The integrated module, if implemented in the form of a software function module and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a readable storage medium, including a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application. The aforementioned readable storage medium includes various media that can store program codes, such as U disk, mobile hard disk, ROM, RAM, magnetic disk, or optical disk.
[0077] It should be noted that, for the foregoing method embodiments, in order to facilitate description, they are all described as a combination of a series of actions, but those skilled in the art should know that the present application is not limited to the order of the actions described, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0078] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.
[0079] The above is the description of the user data access method, device, equipment and storage medium provided by the present application. For those skilled in the art, according to the idea of the embodiments of the present application, there will be changes in specific implementation and application range. In conclusion, the content of the specification should not be understood as a limitation of the present application.
Claims
1. A user data access method, characterized in that: include: When a data access request is received, the authorization code corresponding to the target user is parsed to obtain the authorization information of the target user; wherein the authorization information includes the identity information of the requester, the purpose of data access, the type of accessible data, and the data operation authority; Matching the data access meta-information corresponding to the data access request with the authorization information; If the match is successful, the target data associated with the data access meta-information is returned to the data access request system.
2. The user data access method according to claim 1, characterized in that: Before parsing the authorization code corresponding to the target user, the method further includes: Acquire the authorization information specified by the target user and synchronize the authorization information to a preset access control list; Based on the authorization information in the access control list, an authorization code corresponding to the target user is generated.
3. The user data access method according to claim 1, characterized in that: Before matching the data access meta-information corresponding to the data access request with the authorization information, the method further includes: Obtaining the digital signature information and timestamp in the authorization information; Performing legitimacy verification on the digital signature information and the timestamp; When the verification is passed, the step of matching the data access meta-information corresponding to the data access request with the authorization information is performed.
4. The user data access method according to claim 1, wherein: The data access meta-information includes the type of data requested for access; The step of returning the target data associated with the data access meta-information to the data access request system includes: Retrieving corresponding target data from the data storage unit of the target user according to the type of data requested for access; The target data is returned to the data access request system, and all information of the current access event and the authorization event is recorded in a preset storage unit.
5. The user data access method according to claim 4, characterized in that: After recording the current access event and the authorization event in the preset storage unit, the method further includes: When an audit trail request is received, obtaining permission information of an operator corresponding to the audit trail request; Verifying the legitimacy of the permission information; When the legitimacy verification passes, the permission information and the query result corresponding to the audit trail request are returned; wherein the query result includes information on access events and authorization events.
6. The user data access method according to claim 1, characterized in that: After matching the data access meta-information corresponding to the data access request with the authorization information, the method further includes: If the match fails, generating an authorization request based on the target data access meta-information that failed to match; When the authorization request is approved, the data associated with the target data access meta-information is returned to the data access request system.
7. The user data access method according to claim 6, characterized in that: After returning the data associated with the target data access meta-information to the data access request system, the method further includes: Selecting a corresponding update strategy according to the importance level of the data access request; The authorization code is updated according to the update policy and the permission type corresponding to the target data access meta-information.
8. A user data access device, characterized in that: include: A parsing module is used to parse the authorization code corresponding to the target user when receiving a data access request to obtain the authorization information of the target user; wherein the authorization information includes the identity information of the requester, the purpose of data access, the type of accessible data, and the data operation permissions; a matching module, configured to match the data access meta-information corresponding to the data access request with the authorization information; The data returning module is configured to return the target data associated with the data access meta-information to the data access request system if the match is successful.
9. An electronic device, characterized in that: Comprising a memory and a processor, wherein: The processor is configured to execute a computer program stored in the memory; When the processor executes the computer program, the steps of the user data access method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the user data access method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
User authorization method, application terminal, open platform and system
CN102664933A
Fine-grained cloud platform security access control method based on user identity capacity
CN104009987A
Blockchain-based visa information system, and blockchain-based visa information processing method
CN108023894A
Open platform authentication and authorization method and device and storage medium
CN113312653A
Multi-type database-oriented sensitive data operation intelligent management method
CN115906030A
Cited By
Personal health data management method and personal health data bank system
CN121792038A
Information management method and device, equipment and storage medium
CN121814472A