Authorization method and device based on service scene, equipment and medium

By introducing dynamic authorization condition codes and authorization-free scenario codes, the problem of efficiency impacted by authorization scenarios in counter operations has been solved, streamlining and optimizing business scenarios, reducing the burden on authorization personnel, and improving business processing efficiency.

CN121544264APending Publication Date: 2026-02-17CHINA CONSTRUCTION BANK +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511747025.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-26
Publication Date
2026-02-17

AI Technical Summary

Technical Problem

There are many authorized business scenarios in counter operations, which affect the operating experience of branch staff, occupy a lot of human resources, and affect the efficiency of business processing.

Method used

By introducing dynamic authorization condition codes and authorization-free scenario codes, it is possible to determine whether a business scenario triggers dynamic authorization, generate and send a dynamic authorization code, verify its validity, and then execute the transaction logic, thereby simplifying and optimizing the business scenario.

Benefits of technology

Reduce the workload of authorized personnel, improve the efficiency of business processing, and streamline and optimize the authorization of counter services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121544264A_ABST
    Figure CN121544264A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of financial service processing, discloses an authorization method, device and equipment based on a service scene and a medium, and is used for solving the problem that a large number of authorization service scenes exist in counter operation, so that the operation experience of website employees is influenced, and the service handling efficiency is influenced. Comprises: scene information of a service scene is received; the scene information comprises a transaction message of a pre-judged transaction and a universal domain; the universal domain comprises at least one group of authorization information array, and the authorization information array comprises a dynamic authorization condition code and an authorization-free scene code; according to pre-configured authorization-free configuration information and the at least one group of authorization information array, judging whether the service scene triggers dynamic authorization; if the dynamic authorization is triggered, sending a generated dynamic authorization code to the terminal equipment, so that the terminal equipment sends a transaction message of a main transaction carrying the dynamic authorization code; and verifying the validity of the dynamic authorization code, executing the business logic of the main transaction after the dynamic authorization code passes, obtaining a transaction result, and sending the transaction result to the terminal equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of financial business processing technology, specifically to an authorization method, apparatus, device, and medium based on a business scenario. Background Technology

[0002] Counter service risk control is a set of risk control measures used in banking business processes, based on authorization review and approval. For different business scenarios, authorization review conditions are configured, and then specific personnel conduct the review and inspection. Counter operations involve numerous authorization scenarios, which not only affect the user experience of branch staff but also consume significant human resources and impact business processing efficiency.

[0003] To further reduce the burden on grassroots staff, promote the transformation of risk control from manual to automated processes, improve the real-time risk prevention and control level of the system, enhance the efficiency and effectiveness of counter authorization processing, and continuously improve the level of intensive operation and user experience, we will continue to promote the construction of basic authorization functions, optimize authorization process control, streamline and optimize counter business authorization matters, and reduce the workload of authorization personnel.

[0004] Therefore, there is an urgent need to design a dynamic authorization mode that is based on business scenarios, can be configured, and is reusable, so as to simplify and optimize the authorization of counter business and reduce the workload of authorization personnel. Summary of the Invention

[0005] This application provides an authorization method, apparatus, device, and medium based on business scenarios to address the problem that numerous authorization business scenarios exist in counter operations, which not only affect the operational experience of branch staff but also consume a large amount of human resources and affect business processing efficiency.

[0006] In a first aspect, embodiments of this application provide an authorization method based on a business scenario, the method comprising: Receive scenario information of the business scenario; the scenario information includes a transaction message for predicting a transaction, and a general field corresponding to the transaction message for predicting a transaction; the general field includes at least one set of authorization information arrays, the authorization information arrays include dynamic authorization condition codes and authorization-free scenario codes corresponding to the dynamic authorization condition codes; Based on the authorization-free configuration information in the pre-configured authorization parameter table and the at least one set of authorization information arrays in the scenario information, determine whether the business scenario triggers dynamic authorization; If the business scenario triggers dynamic authorization, a dynamic authorization code is generated and sent to the terminal device so that the terminal device can send a transaction message of the main transaction carrying the dynamic authorization code. The validity of the dynamic authorization code carried in the transaction message of the main transaction is verified, and the business logic of the main transaction is executed after the verification is successful to obtain the transaction result of the main transaction; the transaction result is then sent to the terminal device.

[0007] In this embodiment of the application, when determining whether a business scenario triggers dynamic authorization, a dynamic authorization condition code and an authorization-free scenario code corresponding to the dynamic authorization condition code are introduced. This enables conditional release of dynamic authorization control for business scenarios, exempting some transactions from dynamic authorization in specific scenarios, simplifying and optimizing counter business authorization matters, reducing the workload of authorization personnel, and improving business processing efficiency.

[0008] In one possible embodiment, determining whether the business scenario triggers dynamic authorization based on the unauthorized configuration information in the pre-configured authorization parameter table and the at least one set of authorization information arrays in the scenario information includes: Based on the unlicensed configuration information in the pre-configured dynamic authorization condition code parameter table and the dynamic authorization condition code in the scenario information, determine whether the dynamic authorization condition code parameter table includes the dynamic authorization condition code in the scenario information; If the dynamic authorization condition code parameter table includes the dynamic authorization condition code in the scenario information, then based on the authorization-free configuration information in the pre-configured authorization-free scenario code parameter table and the authorization-free scenario code in the scenario information, it is determined whether the business scenario triggers dynamic authorization.

[0009] In one possible embodiment, determining whether the business scenario triggers dynamic authorization based on the authorization-free configuration information in the pre-configured authorization-free scenario code parameter table and the authorization-free scenario code in the scenario information includes: If the unauthorized scenario code parameter table includes the unauthorized scenario code corresponding to the dynamic authorization condition code, then it is determined that the business scenario does not trigger dynamic authorization. If the unauthorized scenario code parameter table does not include the unauthorized scenario code corresponding to the conditional dynamic authorization code, then the business scenario is determined to trigger dynamic authorization.

[0010] In one possible embodiment, the method further includes: Receive the transaction message of the main transaction; the transaction message of the main transaction carries the authorized user information of the main transaction; The validity of the authorized user information of the main transaction is verified, and the business logic of the main transaction is executed after the verification is passed to obtain the transaction result of the main transaction.

[0011] In one possible embodiment, if the business scenario triggers multiple dynamic authorizations, the unauthorized scenario codes corresponding to the multiple dynamic authorizations are the same.

[0012] In one possible embodiment, the method further includes: The preset input format of at least one set of authorization information arrays corresponding to the predicted transaction is encapsulated in the general field corresponding to the transaction message of the predicted transaction, and the encapsulated preset input format is stored in the database; the preset input formats corresponding to different predicted transactions are different; the preset input formats of the at least one set of authorization information arrays are the same.

[0013] Secondly, this application provides an authorization device based on a business scenario, the device comprising: A receiving unit is used to receive scenario information of a business scenario; the scenario information includes a transaction message for predicting a transaction and a general field corresponding to the transaction message for predicting a transaction; the general field includes at least one set of authorization information arrays, the authorization information arrays include dynamic authorization condition codes and authorization-free scenario codes corresponding to the dynamic authorization condition codes; The prediction unit is used to determine whether the business scenario triggers dynamic authorization based on the authorization-free configuration information in the pre-configured authorization parameter table and the at least one set of authorization information arrays in the scenario information. The authorization unit is used to generate a dynamic authorization code and send the dynamic authorization code to the terminal device if the business scenario triggers dynamic authorization, so that the terminal device can send a transaction message of the main transaction carrying the dynamic authorization code; The transaction unit is used to verify the validity of the dynamic authorization code carried in the transaction message of the main transaction, and after the verification is successful, execute the business logic of the main transaction to obtain the transaction result of the main transaction; and send the transaction result to the terminal device.

[0014] In one possible embodiment, the prediction unit is specifically used for: Based on the unlicensed configuration information in the pre-configured dynamic authorization condition code parameter table and the dynamic authorization condition code in the scenario information, determine whether the dynamic authorization condition code parameter table includes the dynamic authorization condition code in the scenario information; If the dynamic authorization condition code parameter table includes the dynamic authorization condition code in the scenario information, then based on the authorization-free configuration information in the pre-configured authorization-free scenario code parameter table and the authorization-free scenario code in the scenario information, it is determined whether the business scenario triggers dynamic authorization.

[0015] In one possible embodiment, the prediction unit is specifically used for: If the unauthorized scenario code parameter table includes the unauthorized scenario code corresponding to the dynamic authorization condition code, then it is determined that the business scenario does not trigger dynamic authorization. If the unauthorized scenario code parameter table does not include the unauthorized scenario code corresponding to the conditional dynamic authorization code, then the business scenario is determined to trigger dynamic authorization.

[0016] In one possible embodiment, the transaction unit is further configured to: Receive the transaction message of the main transaction; the transaction message of the main transaction carries the authorized user information of the main transaction; The validity of the authorized user information of the main transaction is verified, and the business logic of the main transaction is executed after the verification is passed to obtain the transaction result of the main transaction.

[0017] In one possible embodiment, the device further includes a packaging unit, the packaging unit being used for: The preset input format of at least one set of authorization information arrays corresponding to the predicted transaction is encapsulated in the general field corresponding to the transaction message of the predicted transaction, and the encapsulated preset input format is stored in the database; the preset input formats corresponding to different predicted transactions are different; the preset input formats of the at least one set of authorization information arrays are the same.

[0018] Thirdly, this application provides an electronic device, comprising: Memory, used to store program instructions; A processor is configured to invoke program instructions stored in the memory and execute the steps included in the business scenario-based authorization method described in any one of the first aspects according to the obtained program instructions.

[0019] Fourthly, this application provides a computer-readable storage medium storing a computer program, the computer program including program instructions, which, when executed by a computer, cause the computer to perform the authorization method based on the business scenario described in any one of the first aspects.

[0020] Fifthly, this application provides a computer program product comprising: computer program code, which, when executed on a computer, causes the computer to perform the authorization method based on a business scenario as described in the first aspect.

[0021] The technical effects of any of the implementation methods in the second to fifth aspects can be found in the technical effects of the current implementation method in the first aspect, and will not be repeated here. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 A schematic diagram illustrating an application scenario of an authorization method based on a business scenario provided in this application embodiment; Figure 2 A flowchart illustrating an authorization method based on a business scenario provided in this application embodiment; Figure 3 An interactive diagram illustrating an authorization method based on a business scenario provided in an embodiment of this application; Figure 4 A structural diagram of an authorization device based on a business scenario provided in an embodiment of this application; Figure 5 This is a structural diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Unless otherwise specified, the embodiments and features in the embodiments of this application can be arbitrarily combined with each other. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.

[0025] The terms "first" and "second" in the specification, claims, and accompanying drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising" and any variations thereof are intended to cover non-exclusive protection. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. The term "multiple" in this application can mean at least two, for example, two, three, or more, and the embodiments of this application do not impose limitations.

[0026] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of this application, including various details to aid understanding. These embodiments should be considered merely exemplary. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of this application. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description. It should be noted that in the embodiments of this application, certain existing industry solutions such as software, components, and models may be mentioned. These should be considered exemplary, intended only to illustrate the feasibility of implementing the technical solutions of this application, and do not imply that the applicant has already used or necessarily used such solutions.

[0027] The acquisition, transmission, storage, and use of data in this application all comply with the requirements of relevant national laws and regulations.

[0028] Before introducing the business scenario-based authorization method provided in the embodiments of this application, the technical background of the embodiments of this application will be described in detail below for ease of understanding.

[0029] Counter service risk control is a set of risk control measures used in banking business processes, based on authorization review and approval. For different business scenarios, authorization review conditions are configured, and then specific personnel conduct the review and inspection. Counter operations involve numerous authorization scenarios, which not only affect the user experience of branch staff but also, if the volume of authorizations is large, consume significant human resources and impact business processing efficiency.

[0030] To further reduce the burden on grassroots staff, promote the transformation of risk control from manual to automated processes, improve the real-time risk prevention and control level of the system, enhance the efficiency and effectiveness of counter authorization processing, and continuously improve the level of intensive operation and user experience, we will continue to promote the construction of basic authorization functions, optimize authorization process control, streamline and optimize counter business authorization matters, and reduce the workload of authorization personnel.

[0031] For example, by establishing customer identification capabilities to identify business scenarios initiated by the customer themselves, authorization for identity verification can be canceled in scenarios where the customer or their guardian handles the transaction.

[0032] Therefore, there is an urgent need to design a dynamic authorization mode that is based on business scenarios, can be configured, and is reusable, so as to simplify and optimize the authorization of counter business and reduce the workload of authorization personnel.

[0033] In view of this, embodiments of this application provide an authorization method, apparatus, device and medium based on business scenarios to solve the problem that there are a large number of authorization business scenarios in counter operations, which not only affect the operating experience of branch employees, but also occupy a lot of human resources and affect the efficiency of business processing.

[0034] The inventive concept of this application can be summarized as follows: This application receives scenario information of a business scenario; the scenario information includes a transaction message for predicting a transaction and a general field; the general field includes at least one set of authorization information arrays, the authorization information arrays include dynamic authorization condition codes and authorization-free scenario codes; based on the pre-configured authorization-free configuration information and at least one set of authorization information arrays, it determines whether the business scenario triggers dynamic authorization; if dynamic authorization is triggered, the generated dynamic authorization code is sent to the terminal device, so that the terminal device sends a transaction message of the main transaction carrying the dynamic authorization code; the validity of the dynamic authorization code is verified, and after passing the verification, the business logic of the main transaction is executed to obtain the transaction result, which is then sent to the terminal device.

[0035] Therefore, by introducing dynamic authorization condition codes and corresponding exemption scenario codes when determining whether a business scenario triggers dynamic authorization, it is possible to conditionally relax dynamic authorization control for business scenarios, exempt some transactions from dynamic authorization in specific scenarios, simplify and optimize counter business authorization matters, reduce the workload of authorization personnel, and improve business processing efficiency.

[0036] After introducing the inventive concept of this application, the following will be combined with... Figure 1 The application scenarios of the embodiments of this application will be introduced.

[0037] Reference Figure 1 This is an application scenario diagram of an authorization method based on a business scenario provided in an embodiment of this application. For example... Figure 1 As shown, the scenario includes: terminal device 110 and server 120, and terminal device 110 and server 120 can communicate with each other through a communication network.

[0038] In one alternative implementation, the communication network can be a wired network or a wireless network. Therefore, the terminal device 110 and the server 120 can be connected directly or indirectly via wired or wireless communication. For example, the terminal device 110 can be indirectly connected to the server 120 via a wireless access point, or the terminal device 110 can be directly connected to the server 120 via the Internet; this application does not impose any limitations on this.

[0039] In this application embodiment, the terminal device 110 includes, but is not limited to, mobile phones, tablets, laptops, desktop computers, e-book readers, smart voice interaction devices, smart home appliances, vehicle terminals, and other devices; various clients can be installed on the terminal device, which can be applications (such as browsers, game software, etc.), or web pages, mini-programs, etc.

[0040] Server 120 is a backend server corresponding to the client installed in terminal device 110. Server 120 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.

[0041] It should be noted that the authorization method based on business scenarios in this application embodiment can be deployed in an electronic device, which can be a server or a terminal device.

[0042] Among them, the server can be Figure 1 The server 120 shown can also be used for output. Figure 1 Other servers besides server 120 shown.

[0043] Specifically, after the terminal device receives the business scenario, it processes and generates scenario information. This scenario information is used to determine whether the business scenario triggers dynamic authorization. Then, the scenario information is sent to the backend server. After receiving the scenario information, the backend server executes the authorization method based on the business scenario provided in this application embodiment to determine whether the business scenario triggers dynamic authorization. When the business scenario triggers dynamic authorization, a dynamic authorization code is generated and sent to the terminal device.

[0044] After receiving the dynamic authorization code, the terminal device triggers a pop-up window. After the teller authorizes the business, it calls the main transaction of the product component and sends the transaction message of the main transaction carrying the dynamic authorization code to the backend server. The backend server verifies the validity of the dynamic authorization code carried in the transaction message of the main transaction, and executes the business logic of the main transaction after the verification is successful to obtain the transaction result of the main transaction; then the transaction result is sent to the terminal device.

[0045] Among them, the terminal equipment can be Figure 1 The terminal device 110 shown can also be used for output. Figure 1 Other terminal devices besides terminal device 110 shown.

[0046] Specifically, after the terminal device receives the business scenario, the front-end channel integration layer processes and generates scenario information. This scenario information is used to determine whether the business scenario triggers dynamic authorization. Then, the scenario information is sent to the back-end product service layer. After receiving the scenario information, the back-end executes the business scenario-based authorization method provided in this application embodiment to determine whether the business scenario triggers dynamic authorization. When the business scenario triggers dynamic authorization, a dynamic authorization code is generated and sent to the front-end channel integration layer.

[0047] After receiving the dynamic authorization code, the front-end channel integration layer triggers a pop-up window. After the teller's business authorization, it calls the main transaction of the product component and sends the transaction message of the main transaction carrying the dynamic authorization code to the back-end. The backend verifies the validity of the dynamic authorization code carried in the transaction message of the main transaction, and executes the business logic of the main transaction after the verification is successful to obtain the transaction result of the main transaction; then the transaction result is sent to the channel integration layer of the front end.

[0048] Figure 1 The examples shown are merely illustrative; in reality, the number of terminal devices 110 and servers 120 is not limited and is not specifically limited in this embodiment.

[0049] In this embodiment of the application, when there are multiple servers 120, the multiple servers 120 can form a blockchain, and the server 120 is a node on the blockchain; as disclosed in the authorization method based on business scenarios in this embodiment of the application, the authorization-free configuration information in the pre-configured authorization parameter table can be stored on the blockchain.

[0050] The following describes the authorization method based on business scenarios provided by exemplary embodiments of this application, in conjunction with the application scenarios described above and with reference to the accompanying drawings. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principles of this application, and the implementation of this application is not limited in any way in this respect.

[0051] refer to Figure 2 , Figure 2 An exemplary authorization method based on a business scenario is provided in this application embodiment. This method can be executed by an electronic device and includes the following steps: Step S201: Receive scenario information of the business scenario; the scenario information includes the transaction message of the predicted transaction and the general field corresponding to the transaction message of the predicted transaction; the general field includes at least one set of authorization information array, the authorization information array includes dynamic authorization condition code and the unauthorized scenario code corresponding to the dynamic authorization condition code.

[0052] Specifically, the terminal device or the front-end channel integration layer determines the business scenario, and then processes the business scenario to generate transaction characteristics (scenario information) to determine whether the business scenario is authorized, such as: the person or guardian handles it.

[0053] The scenario information sent by the terminal device or the channel integration layer at the front end includes the transaction message for predicting the transaction, as well as the general field (COM5 field) corresponding to the transaction message; dynamic authorization condition codes and the corresponding no-authorization scenario codes are added to the general field. The dynamic authorization condition codes and the corresponding no-authorization scenario codes included in the general field sent by the front-end component serve as information for the back-end product components to perform no-authorization judgment.

[0054] It is important to note that the general field of the transaction message includes multiple arrays of authorization information, namely multiple sets of dynamic authorization condition codes and corresponding exemption scenario codes. Each exemption scenario occupies one array of authorization information (conditional dynamic authorization code + exemption scenario code).

[0055] For example, the front-end channel integration layer determines the business scenario. If the transaction is handled by the individual or their guardian, it dynamically authorizes the transaction and the main transaction, and carries the agreed-upon values ​​in the dynamic authorization condition code and the no-authorization scenario code included in the general field of the message. For example, the agreed-upon value of the dynamic authorization condition code is "YACA0192NOAH", and the agreed-upon value of the no-authorization scenario code is "BRJHR01".

[0056] Step S202: Based on the unauthorized configuration information in the pre-configured authorization parameter table and at least one set of authorization information arrays in the scenario information, determine whether the business scenario triggers dynamic authorization.

[0057] The pre-configured authorization parameter table includes a dynamic authorization condition code parameter table and an authorization-free scenario code parameter table.

[0058] Specifically, business personnel maintain the authorization parameter table online in the parameter management component interface, configuring the authorization-free configuration information required, including dynamic authorization condition codes and authorization-free scenario codes, forming a correspondence between the financial institution code, the component transaction code, the dynamic authorization condition code, and the authorization-free scenario code. This application supports business personnel in flexibly configuring this correspondence.

[0059] The unlicensed configuration information in the pre-configured dynamic authorization condition code parameter table is shown in Table 1.

[0060] Table 1

[0061] The unlicensed configuration information in the pre-configured dynamic licensing condition code parameter table is shown in Table 2.

[0062] Table 2

[0063] For example, for a transaction involving "replacement of a pre-issued bank card," the dynamic authorization condition code is "YACA01922923," indicating that a new card is being issued and a channel reservation is in place, requiring authorization. The corresponding authorization-free scenario code is "!='BRJHR01'." If at least one set of authorization information in the scenario information includes the above information, it means that when the individual or their guardian handles the transaction, dynamic authorization will no longer be required for the "new card issuance and channel reservation" scenario of a pre-issued bank card issuance transaction.

[0064] In one possible embodiment, determining whether a business scenario triggers dynamic authorization based on the unauthorized configuration information in the pre-configured authorization parameter table and at least one set of authorization information arrays in the scenario information can be performed as follows: Based on the license-free configuration information in the pre-configured dynamic authorization condition code parameter table and the dynamic authorization condition codes in the scenario information, determine whether the dynamic authorization condition code parameter table includes the dynamic authorization condition codes in the scenario information. If the dynamic authorization condition code parameter table includes the dynamic authorization condition code in the scenario information, then based on the authorization-free configuration information in the pre-configured authorization-free scenario code parameter table and the authorization-free scenario code in the scenario information, it is determined whether the business scenario triggers dynamic authorization.

[0065] In one possible embodiment, based on the authorization-free configuration information in the pre-configured authorization-free scenario code parameter table and the authorization-free scenario code in the scenario information, it is determined whether the business scenario triggers dynamic authorization, including: If the no-authorization scenario code parameter table includes the no-authorization scenario code corresponding to the dynamic authorization condition code, then it is determined that the business scenario will not trigger dynamic authorization. If the no-authorization scenario code parameter table does not include the no-authorization scenario code corresponding to the conditional dynamic authorization code, then the business scenario will trigger dynamic authorization.

[0066] In one possible implementation, the platform component provides unauthorized common processing for each product component: first, it subscribes to the dynamic authorization condition code parameter table and the unauthorized scenario code parameter table; then, when processing the authorization return response, if a dynamic authorization condition code exists in the general field of the transaction message, it adds reading the unauthorized scenario code parameter table (resident in memory) and automatically filters the unauthorized scenario codes that meet the dynamic authorization condition codes, thereby achieving the unauthorized effect.

[0067] Specifically, the product platform components provide unauthorized public processing. It subscribes to an authorization parameter table and then reads the dynamic authorization condition codes and the corresponding unauthorized scenario codes from the general field of the transaction message during a transaction.

[0068] When a dynamic authorization condition code exists in the authorization parameter table in the general domain, read the authorization exemption configuration information in the authorization exemption scenario code parameter table. If the authorization exemption configuration information in the authorization exemption scenario code parameter table includes the authorization exemption scenario code corresponding to the dynamic authorization condition code, then enable dynamic authorization for the business scenario.

[0069] When authorizing a pre-transaction or the main transaction, the platform component checks whether the general field of the transaction message contains a fixed dynamic authorization condition code "YACA0192NOAH". If so, it checks each transaction against the corresponding transaction code and the no-authorization scenario code of the component transaction. If the transaction code and the no-authorization scenario code of the component transaction match the no-authorization scenario code "BRJHR01" sent in the general field, dynamic authorization is not triggered, and the dynamic authorization code is not sent to external channels. Otherwise, dynamic authorization is triggered, a dynamic authorization code is generated, and the dynamic authorization code is sent.

[0070] If a business scenario triggers multiple dynamic authorizations, the unauthorized scenario codes corresponding to the multiple dynamic authorizations are the same.

[0071] Specifically, when multiple dynamic authorizations are triggered in a single business transaction, as long as the corresponding dynamic authorization supports authorization exemption for the corresponding business scenario, the same authorization exemption scenario code will be reused for authorization exemption processing.

[0072] In one possible implementation, the method further includes: The preset input format of at least one set of authorization information arrays corresponding to the predicted transaction is encapsulated in the general field corresponding to the transaction message of the predicted transaction, and the encapsulated preset input format is stored in the database; the preset input formats corresponding to different predicted transactions are different; the preset input formats of at least one set of authorization information arrays are the same.

[0073] Specifically, each product component can pre-determine its own input format with the front-end channel integration layer, which will then encapsulate it in the general field of the message and send it up, and store it in the database.

[0074] Step S203: If the business scenario triggers dynamic authorization, a dynamic authorization code is generated and sent to the terminal device so that the terminal device can send a transaction message of the main transaction carrying the dynamic authorization code.

[0075] Step S204: Verify the validity of the dynamic authorization code carried in the transaction message of the main transaction, and execute the business logic of the main transaction after the verification is successful to obtain the transaction result of the main transaction; send the transaction result to the terminal device.

[0076] In one possible implementation, the method further includes: Receive the transaction message from the main transaction; the transaction message from the main transaction carries the authorized user information of the main transaction; Verify the validity of the authorized user information for the main transaction, and execute the business logic of the main transaction after the verification is successful to obtain the transaction result of the main transaction.

[0077] Specifically, after receiving the dynamic authorization code, the front-end channel integration layer triggers a pop-up window, where teller transactions are authorized. Following authorization, the corresponding main transaction in the back-end product component is invoked, and the dynamic authorization code and authorized user information are added to the main transaction's transaction message. The transaction message is then sent to the back-end, where the product component verifies the validity of the authorized user information. Upon successful verification, the main transaction's business logic is executed, resulting in the transaction outcome. This outcome is then sent to the front-end channel integration layer, completing the transaction.

[0078] To facilitate understanding of the business scenario-based authorization method provided in this application, the following will be combined with... Figure 3 The interactive diagram of the authorization method based on business scenarios shown further illustrates this solution.

[0079] In the channel integration layer, a business scenario is triggered. Then, in step S1, the employee channel application judges the business scenario and generates scenario information. In step S2, the employee channel service sends the scenario information of the general domain to the debit card through the application integration layer for authorization-free prediction.

[0080] Among them, the general field (com5) corresponding to the transaction message of the predicted transaction carries a pre-defined value, such as the dynamic authorization code and the unauthorized scenario code corresponding to the dynamic authorization code.

[0081] In step S3, after the debit card performs an authorization-free prediction and determines that the business scenario triggers dynamic authorization, a dynamic authorization code is generated and sent to the distributed banking core platform.

[0082] In step S4, the distributed banking core platform sends the dynamic authorization code to the employee channel service through the application integration layer.

[0083] In step S5, after the teller's business authorization, the employee channel service calls the main transaction corresponding to the product component in the backend and sends the transaction message of the main transaction to the distributed bank core platform through the application integration layer and debit card.

[0084] The general field (com5) corresponding to the transaction message of the main transaction carries agreed values, such as dynamic authorization code and authorized user information.

[0085] In step S6, the distributed bank core platform verifies the validity of the dynamic authorization code carried in the transaction message of the main transaction, and executes the business logic of the main transaction after the verification is passed to obtain the transaction result of the main transaction; the transaction result is sent to the employee channel service through the application integration layer.

[0086] In this application, the distributed banking core platform will also synchronize and store parameters such as the authorization-free configuration information, dynamic authorization condition code, and authorization-free scenario code from the pre-configured authorization parameter table into the parameter management.

[0087] Therefore, in this embodiment of the application, when determining whether a business scenario triggers dynamic authorization, a dynamic authorization condition code and an authorization-free scenario code corresponding to the dynamic authorization condition code are introduced. This can enable conditional release of dynamic authorization control for business scenarios, exempt some transactions from dynamic authorization in specific scenarios, simplify and optimize counter business authorization matters, reduce the workload of authorization personnel, and improve business processing efficiency.

[0088] Furthermore, the solution proposed in this application can be reused for similar needs in the future. Only the authorization-free configuration information needs to be set and the authorization-free scenario code needs to be agreed upon with the front-end channel. This allows for flexible adaptation and rapid response to business development, reducing the risk of system modification.

[0089] Based on the same inventive concept, this application provides an authorization device based on a business scenario. Please refer to... Figure 4 The device includes: The receiving unit 401 is used to receive scenario information of the business scenario; the scenario information includes the transaction message of the predicted transaction and the general field corresponding to the transaction message of the predicted transaction; the general field includes at least one set of authorization information array, the authorization information array includes dynamic authorization condition code and the unauthorized scenario code corresponding to the dynamic authorization condition code; The prediction unit 402 is used to determine whether the business scenario triggers dynamic authorization based on the unauthorized configuration information in the pre-configured authorization parameter table and at least one set of authorization information arrays in the scenario information. The authorization unit 403 is used to generate a dynamic authorization code and send the dynamic authorization code to the terminal device if the business scenario triggers dynamic authorization, so that the terminal device can send a transaction message of the main transaction carrying the dynamic authorization code; Transaction unit 404 is used to verify the validity of the dynamic authorization code carried in the transaction message of the main transaction, and execute the business logic of the main transaction after the verification is successful to obtain the transaction result of the main transaction; and send the transaction result to the terminal device.

[0090] In one possible embodiment, the prediction unit 402 is specifically used for: Based on the dynamic authorization condition code parameter table included in the unauthorized configuration information in the pre-configured authorization parameter table, and the dynamic authorization condition code in the scenario information, determine whether the dynamic authorization condition code parameter table includes the dynamic authorization condition code in the scenario information; If the dynamic authorization condition code parameter table includes the dynamic authorization condition code in the scenario information, then based on the authorization exemption scenario code parameter table included in the authorization exemption configuration information in the pre-configured authorization parameter table, and the authorization exemption scenario code in the scenario information, it is determined whether the business scenario triggers dynamic authorization.

[0091] In one possible embodiment, the prediction unit 402 is specifically used for: If the no-authorization scenario code parameter table includes the no-authorization scenario code corresponding to the dynamic authorization condition code, then it is determined that the business scenario will not trigger dynamic authorization. If the no-authorization scenario code parameter table does not include the no-authorization scenario code corresponding to the conditional dynamic authorization code, then the business scenario will trigger dynamic authorization.

[0092] In one possible embodiment, transaction unit 404 is further configured to: Receive the transaction message from the main transaction; the transaction message from the main transaction carries the authorized user information of the main transaction; Verify the validity of the authorized user information for the main transaction, and execute the business logic of the main transaction after the verification is successful to obtain the transaction result of the main transaction.

[0093] In one possible embodiment, the device further includes a packaging unit 405, which is used for: The preset input format of at least one set of authorization information arrays corresponding to the predicted transaction is encapsulated in the general field corresponding to the transaction message of the predicted transaction, and the encapsulated preset input format is stored in the database; the preset input formats corresponding to different predicted transactions are different; the preset input formats of at least one set of authorization information arrays are the same.

[0094] The authorization device based on business scenarios provided in this application embodiment and the authorization method based on business scenarios in the above embodiments have the same beneficial effects, and will not be described in detail here.

[0095] Having introduced the business scenario-based authorization method and business scenario-based authorization apparatus according to exemplary embodiments of this application, the electronic device provided according to embodiments of this application will now be described.

[0096] Based on the same inventive concept, embodiments of this application provide an electronic device that can implement the business scenario-based authorization method discussed above. Please refer to... Figure 5 The device includes a memory 501, one or more processors 502, and a bus 503.

[0097] The memory 501 is used to store computer programs executed by the processor 502. The memory 501 may mainly include a program storage area and a data storage area. The program storage area may store the operating system and programs required to run instant messaging functions, etc.; the data storage area may store various instant messaging information and operation instruction sets, etc.

[0098] Memory 501 may be volatile memory, such as random-access memory (RAM); memory 501 may also be non-volatile memory, such as read-only memory, flash memory, hard disk drive (HDD), or solid-state drive (SSD); or memory 501 may be any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory 501 may be a combination of the above-mentioned memories.

[0099] The processor 502 may include one or more central processing units (CPUs) or digital processing units, etc. The processor 502 is used to implement the business scenario-based authorization method in the above embodiments when invoking the computer program stored in the memory 501.

[0100] This application embodiment does not limit the specific connection medium between the memory 501 and the processor 502 described above. This application embodiment... Figure 5 The memory 501 and the processor 502 are connected via a bus 503, and the bus 503 is in Figure 5 The connections between other components are shown in thick lines only and are not intended to be limiting. The 503 bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, Figure 5 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0101] Based on the same inventive concept, embodiments of this application provide a computer-readable storage medium. The computer program product includes computer program code, which, when executed on a computer, causes the computer to perform any of the business scenario-based authorization methods discussed above. Since the principle by which the above-described computer-readable storage medium solves the problem is similar to that of the business scenario-based authorization method, the implementation of the above-described computer-readable storage medium can be found in the implementation of the method; repeated details will not be elaborated further.

[0102] Based on the same inventive concept, this application also provides a computer program product, which includes computer program code. When the computer program code is run on a computer, it causes the computer to execute any of the business scenario-based authorization methods discussed above. Since the principle by which the above computer program product solves the problem is similar to that of the business scenario-based authorization method, the implementation of the above computer program product can refer to the implementation of the method, and repeated details will not be elaborated further.

[0103] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0104] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0105] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0106] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of user-operated steps to be executed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0107] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A service scenario based authorization method, characterized by, The method comprises: receiving scene information of a service scenario; the scene information comprises a transaction message of a pre-judgment transaction and a general domain corresponding to the transaction message of the pre-judgment transaction; the general domain comprises at least one set of authorization information arrays, and each authorization information array comprises a dynamic authorization condition code and an authorization-free scene code corresponding to the dynamic authorization condition code; judging whether the service scenario triggers dynamic authorization according to authorization-free configuration information in a preconfigured authorization parameter table and the at least one set of authorization information arrays in the scene information; if the service scenario triggers dynamic authorization, generating a dynamic authorization code and sending the dynamic authorization code to a terminal device, so that the terminal device sends a transaction message of a main transaction carrying the dynamic authorization code; verifying the validity of the dynamic authorization code carried in the transaction message of the main transaction, and executing service logic of the main transaction after verification to obtain a transaction result of the main transaction; and sending the transaction result to the terminal device.

2. The method of claim 1, wherein, The judging whether the service scenario triggers dynamic authorization according to authorization-free configuration information in a preconfigured authorization parameter table and the at least one set of authorization information arrays in the scene information comprises: judging whether the dynamic authorization condition code parameter table comprises the dynamic authorization condition code in the scene information according to authorization-free configuration information in a preconfigured dynamic authorization condition code parameter table and the dynamic authorization condition code in the scene information; if the dynamic authorization condition code parameter table comprises the dynamic authorization condition code in the scene information, judging whether the service scenario triggers dynamic authorization according to authorization-free configuration information in a preconfigured authorization-free scene code parameter table and the authorization-free scene code in the scene information.

3. The method of claim 2, wherein, The judging whether the service scenario triggers dynamic authorization according to authorization-free configuration information in a preconfigured authorization-free scene code parameter table and the authorization-free scene code in the scene information comprises: if the authorization-free scene code parameter table comprises the authorization-free scene code corresponding to the dynamic authorization condition code, it is determined that the service scenario does not trigger dynamic authorization; if the authorization-free scene code parameter table does not comprise the authorization-free scene code corresponding to the conditional dynamic authorization code, it is determined that the service scenario triggers dynamic authorization.

4. The method of claim 1, wherein, The method further comprises: receiving a transaction message of the main transaction; the transaction message of the main transaction carries authorization user information of the main transaction; verifying the validity of the authorization user information of the main transaction, and executing service logic of the main transaction after verification to obtain a transaction result of the main transaction.

5. The method of claim 1, wherein, If the service scenario triggers multiple dynamic authorizations, the authorization-free scene codes corresponding to the multiple dynamic authorizations are the same.

6. The method of claim 1, wherein, The method further comprises: packaging a preset input format of at least one set of authorization information arrays corresponding to a pre-judgment transaction in a general domain corresponding to a transaction message of the pre-judgment transaction, and storing the packaged preset input format in a database; the preset input format corresponding to different pre-judgment transactions is different; the preset input format of the at least one set of authorization information arrays is the same.

7. A service scenario based authorization apparatus, characterized by, The device comprises: The receiving unit is configured to receive scene information of a service scene; the scene information comprises a transaction message of a pre-judgment transaction and a general domain corresponding to the transaction message of the pre-judgment transaction; the general domain comprises at least one set of authorization information arrays, and each authorization information array comprises a dynamic authorization condition code and an authorization-free scene code corresponding to the dynamic authorization condition code; The pre-judgment unit is configured to determine whether the service scene triggers dynamic authorization according to authorization-free configuration information in a preconfigured authorization parameter table and the at least one set of authorization information arrays in the scene information; The authorization unit is configured to generate a dynamic authorization code and send the dynamic authorization code to a terminal device if the service scene triggers dynamic authorization, so that the terminal device sends a transaction message of a main transaction carrying the dynamic authorization code; The transaction unit is configured to verify the validity of the dynamic authorization code carried in the transaction message of the main transaction, and execute service logic of the main transaction to obtain a transaction result of the main transaction after the verification is passed; and send the transaction result to the terminal device.

8. An electronic device, comprising: The memory is configured to store program instructions; The processor is configured to invoke the program instructions stored in the memory, and execute the service scene-based authorization method according to the obtained program instructions. The computer readable storage medium stores a computer program, and the computer program comprises program instructions; when the program instructions are executed by a computer, the computer executes the service scene-based authorization method.

9. A computer-readable storage medium, characterized in that, The computer program product comprises computer program codes; when the computer program codes are executed on a computer, the computer executes the service scene-based authorization method.

10. A computer program product, characterised in that, ​