Electronic license authorization method and device, equipment and storage medium
By generating a list of certificates and licenses and allowing users to selectively authorize them, the problem of over-authorization caused by existing electronic certificate authorization methods is solved, and a safer and more compliant certificate retrieval process is achieved.
Patent Information
- Application Number
- CN202511750498.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-26
- Publication Date
- 2026-03-03
AI Technical Summary
Existing electronic certificate authorization methods typically involve online "package" authorization, leading to over-authorization, increased risk of leakage, and non-compliance.
By responding to user requests for business processing, the system determines the electronic certificates required for the pending business, generates a certificate list, and allows users to selectively authorize certificates, generating an authorized certificate list. The authorized business party then retrieves the required certificates from the electronic certificate management platform. This process, combined with identity verification and validity period management, avoids one-time authorization.
It improves the security and data compliance of electronic certificate authorization, avoids over-authorization and information leakage, and enhances data protection in government systems.
Smart Images

Figure CN121598352A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to data security technology, and more particularly to an electronic certificate authorization method, apparatus, device, and storage medium. Background Technology
[0002] With the promotion of digital government, electronic certificates have been widely used in various government services. To facilitate users and improve the efficiency of government systems, electronic certificates are stored through an electronic certificate management platform. When the government system needs to use a user's electronic certificate, it can directly retrieve it from the electronic certificate management platform based on the user's identity information, without requiring the user to submit the electronic certificate each time.
[0003] Existing authorization methods are usually online "blanket" authorizations, which means that users authorize all certificates and licenses at once after logging in. The scope of required matters is unclear, leading to over-authorization, increasing the risk of leakage, and being identified as obtaining more than necessary information during compliance audits. Summary of the Invention
[0004] This invention provides an electronic certificate authorization method, apparatus, device, and storage medium to avoid over-authorization and information leakage caused by authorizing all certificates at once, thereby improving security and data compliance.
[0005] In a first aspect, the present invention provides an electronic certificate authorization method, comprising:
[0006] In response to a user's business processing request, determine the electronic certificates required for the pending business;
[0007] Generate a list of the required electronic certificates and return it to the user terminal;
[0008] Receive the certificate authorization list returned by the user terminal, the certificate authorization list includes at least one electronic certificate in the certificate authorization list, and the electronic certificate in the certificate authorization list is an electronic certificate authorized by the user;
[0009] The authorized service provider retrieves the electronic certificates from the certificate authorization list from the electronic certificate management platform to process the pending service.
[0010] Optionally, in response to a user's business processing request, determine the electronic certificates required for the pending business, including:
[0011] Parse the pending tasks included in the pending business from the business processing request;
[0012] Identify the electronic certificates required for the tasks to be completed.
[0013] Optionally, generate a list of required electronic certificates, including:
[0014] Generate a task column and an electronic certificate column, wherein the task column includes a first cell for filling the task to be done, and the electronic certificate column includes a second cell for filling the electronic certificates required for the task to be done;
[0015] Fill the to-do list into the first cell of the item column;
[0016] Fill the corresponding second cell with the electronic certificates required for the pending items;
[0017] An authorization component is generated at a preset location in the second cell for users to select authorization options.
[0018] Optionally, before the authorized business handler retrieves the electronic certificates from the certificate authorization list in the electronic certificate management platform to handle the pending business, the following steps are also included:
[0019] Determine whether the user terminal has applied for the electronic certificates in the certificate authorization list;
[0020] If so, the authorized business handler shall execute the step of retrieving the electronic certificates from the certificate authorization list in the electronic certificate management platform to handle the pending business;
[0021] If not, an application entry is generated and returned to the user terminal. The application entry is used to guide the user terminal to the application page for the certificate to be applied for.
[0022] After receiving a successful application feedback from the application page, the authorized service provider retrieves the electronic certificates from the certificate authorization list in the electronic certificate management platform to process the pending business. The successful application feedback indicates that the user has applied for electronic certificates from the electronic certificate management platform and agrees to view and authorize electronic certificates on the user's end.
[0023] Optionally, in addition to receiving the list of authorized certificates returned by the user terminal, the method also includes:
[0024] Send an authorization confirmation request to the user terminal;
[0025] Receive authorization confirmation information returned by the user terminal, the authorization confirmation information including the user's identity information;
[0026] The user's identity information is verified;
[0027] When the identity verification is successful, the authorized business handler shall retrieve the electronic certificates from the certificate authorization list from the electronic certificate management platform to handle the pending business.
[0028] Optionally, the certificate authorization list includes the authorization validity period of the authorized electronic certificates. The authorized business handler retrieves the electronic certificates from the certificate authorization list from the electronic certificate management platform to handle the pending business, including:
[0029] Determine whether the current time of accessing the electronic certificate is within the validity period of the authorization;
[0030] If so, the authorized business handler shall retrieve the electronic certificates from the certificate authorization list in the electronic certificate management platform to handle the pending business;
[0031] If not, a notification message indicating that the authorization has expired will be returned to the business processing party.
[0032] Optionally, after the authorized service provider retrieves the electronic certificates from the certificate authorization list from the electronic certificate management platform to process the pending service, the process further includes:
[0033] The hash value of the business processing record is calculated using a hash function and used as the summary information of the business processing record, which includes the certificate and license authorization list and the authorization confirmation information;
[0034] The digest information is signed to obtain a digital signature;
[0035] The digital signature and the business transaction record are broadcast to each node on the government blockchain.
[0036] Secondly, the present invention also provides an electronic certificate authorization device, comprising:
[0037] The electronic certificate determination module is used to determine the electronic certificates required for the pending business in response to the user's business processing request.
[0038] The certificate list generation module is used to generate a list of the required electronic certificates and return it to the user terminal.
[0039] The authorization list receiving module is used to receive the certificate authorization list returned by the user terminal. The certificate authorization list includes at least one electronic certificate in the certificate authorization list. The electronic certificate in the certificate authorization list is an electronic certificate authorized by the user.
[0040] The certificate authorization module is used to authorize the business handler to retrieve the electronic certificates from the certificate authorization list from the electronic certificate management platform to handle the pending business.
[0041] Thirdly, the present invention also provides an electronic device, comprising:
[0042] One or more processors;
[0043] Storage device for storing one or more programs;
[0044] When the one or more programs are executed by the one or more processors, the one or more processors implement the electronic certificate authorization method as described in the first aspect of the present invention.
[0045] Fourthly, the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the electronic certificate authorization method as described in the first aspect of the present invention.
[0046] The electronic certificate authorization method provided by this invention, in response to a user's business processing request, determines the electronic certificates required for the pending business, generates a list of required electronic certificates, and returns it to the user. The method also receives a certificate authorization list returned by the user, whereby the certificate authorization list includes at least one electronic certificate from the list. These electronic certificates are those authorized for use by the user. The authorized business handler retrieves the electronic certificates from the certificate authorization list from the electronic certificate management platform to process the pending business. This invention improves security and data compliance by returning a list of required electronic certificates to the user and allowing the user to selectively authorize certificates based on actual needs. This avoids over-authorization and information leakage caused by authorizing all certificates at once.
[0047] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0048] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0049] Figure 1 A flowchart of an electronic certificate authorization method provided by the present invention;
[0050] Figure 2 This is a schematic diagram of the structure of an electronic certificate authorization device provided by the present invention;
[0051] Figure 3 This is a schematic diagram of the structure of an electronic device provided by the present invention.
[0052] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0053] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0054] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be used interchangeably where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices. The acquisition, storage, use, and processing of data in the technical solutions of this application are all authorized by the user and comply with relevant national laws and regulations.
[0055] Figure 1 This is a flowchart of an electronic certificate authorization method provided by the present invention. This embodiment is applicable to the process of authorizing the use of required electronic certificates by users in government affairs, avoiding over-authorization. This method can be executed by the electronic certificate authorization device provided by the present invention. This device can be implemented by software and / or hardware, and is usually configured in an electronic device, which can be a server of the business system, such as... Figure 1 As shown, the electronic certificate authorization method includes the following steps:
[0056] S101. In response to the user's business processing request, determine the electronic certificates required for the pending business.
[0057] In this embodiment of the invention, the server of the business system responds to the user's business processing request and determines the electronic certificates required for the pending business. For example, the user can launch the webpage or mini-program of the business processing provider by scanning a QR code or actively initiating the request, access the business system's server, and initiate a business processing request on the webpage or mini-program page. The business processing request may include the business ID of the pending business. After obtaining the business ID, the required electronic certificates can be determined based on the business ID. For example, a pending business may require one or more electronic certificates; this invention does not limit this.
[0058] In some embodiments of the present invention, a pending business may include one or more pending items, and each pending item may require one or more electronic certificates. Different pending items may require partially identical electronic certificates, which is not limited in this embodiment. For example, upon receiving a business processing request, the business ID of the pending business is parsed from the request, and then the pending items included in the pending business are determined based on the business ID, and the electronic certificates required for each pending item are determined.
[0059] S102. Generate a list of required electronic certificates and return it to the user.
[0060] After determining the electronic certificates required for the pending business, a list of required electronic certificates is generated and returned to the user. For example, the certificate list includes fields for the electronic certificates required for the pending business, such as "ID card" and "business license," but this invention does not limit this to specific fields.
[0061] In some embodiments of the present invention, the list of certificates is usually included in the authorization agreement. That is, after determining the electronic certificates required for the pending business, an authorization agreement including the list of certificates is generated. The authorization agreement may also include other business-related information, such as the basic information of the authorizing party and the authorized party, the authorized matters, the authorization validity period, etc. The present invention does not limit this.
[0062] Table 1 shows a certificate list provided by the present invention. As shown in Table 1, in some embodiments of the present invention, the certificate list includes a task column and an electronic certificate column. The task column includes a first cell for filling in pending tasks, and the electronic certificate column includes a second cell for filling in the electronic certificates required for the pending tasks. When generating the certificate list of required electronic certificates, the task column and the electronic certificate column are generated first. Then, the pending tasks are filled into the first cell of the task column, and the electronic certificates required for the pending tasks are filled into the corresponding second cells. An authorization component for user authorization selection is generated at a preset position of the electronic certificate in the second cell. For example, the authorization component can be a checkbox, allowing the user to select the electronic certificates they want to authorize according to the actual situation. For instance, a pending task requires certificate A, certificate B, and certificate C, but the user already carries the physical certificate B offline. Therefore, the user can choose to authorize certificate B offline instead of selecting certificate B online, thus avoiding excessive online authorization of certificate B.
[0063] Table 1
[0064]
[0065] S103. Receive the certificate authorization list returned by the user terminal. The certificate authorization list includes at least one electronic certificate in the certificate authorization list. The electronic certificate in the certificate authorization list is an electronic certificate authorized by the user.
[0066] After the user selectively authorizes the certificates in the certificate list according to the actual situation, a certificate authorization list is generated and returned to the server of the business system through the user's client. The server of the business system receives the certificate authorization list returned by the user's client. The certificate authorization list includes at least one electronic certificate in the certificate list, and the electronic certificate in the certificate authorization list is the electronic certificate authorized by the user.
[0067] For example, the certificate authorization list can be formed by the user selecting the electronic certificates to be authorized based on the certificate list in the aforementioned embodiment.
[0068] For example, as mentioned above, the list of licenses and permits is usually included in the authorization agreement; therefore, the license and permit authorization list is included in the authorization agreement after the user has authorized the license.
[0069] In some embodiments of the present invention, after receiving the certificate authorization list returned by the user terminal, before the authorized business handler retrieves the electronic certificates in the certificate authorization list from the electronic certificate management platform to handle pending business, the following may also be included:
[0070] Determine whether the user has applied for electronic certificates listed in the certificate authorization list.
[0071] In this embodiment of the invention, the electronic certificate management platform is a government service platform based on digital technology. Its core objective is to digitize traditional paper certificates (such as business licenses, ID cards, driver's licenses, permits, etc.) to form electronic certificates, and to achieve online management, sharing, and application throughout their entire lifecycle. For example, for each user, the electronic certificate management platform creates a personal digital space for that user to record the electronic certificates that the user has applied for. In this embodiment of the invention, it is determined whether the user has applied for the electronic certificates on the certificate authorization list in the digital space.
[0072] If so, the authorized business handler will proceed with the steps of retrieving the electronic certificates from the certificate authorization list in the electronic certificate management platform to handle pending business.
[0073] If not, an application entry point is generated and returned to the user's device. This entry point guides the user to the application page for the certificate / license to be applied for. For example, if the user has not applied for a specific electronic certificate / license from the authorization list, an application component is generated on the authorization page as the application entry point. After the user clicks the application component, the page redirects to the application page for the certificate / license to be applied for. The user can initiate an application request on the application page to apply for the electronic certificate / license from the electronic certificate / license management platform and record it in their personal digital space. After confirming a successful application, the application page sends a success notification to the authorization page via inter-page communication technology.
[0074] 4. After receiving the successful application feedback from the application page, the authorized business handler will proceed with the steps of retrieving the electronic certificates from the certificate authorization list in the electronic certificate management platform to handle pending business. The successful application feedback indicates that the user has applied for electronic certificates from the electronic certificate management platform and agrees to view and authorize electronic certificates on the user's end.
[0075] In some embodiments of the present invention, receiving the certificate authorization list returned by the user terminal may also include:
[0076] 1. Send an authorization confirmation request to the user's client.
[0077] In this embodiment of the invention, the server of the business system sends an authorization confirmation request to the user terminal, requesting the user's authorization confirmation.
[0078] 2. Receive authorization confirmation information returned by the user client. The authorization confirmation information includes the user's identity information.
[0079] Upon receiving an authorization confirmation request, the user uses their own identity information to confirm authorization, generates authorization confirmation information, and sends it to the business system's server. The business system's server receives the authorization confirmation information returned by the user and extracts the user's identity information from it.
[0080] This invention can use the user's authorization confirmation as evidence. In the event of subsequent authorization disputes, this evidence can be invoked to ensure that the authorization process reflects the user's own will and avoid disputes.
[0081] For example, in a specific embodiment of the present invention, the server of the business system sends a face verification request to the user as an authorization confirmation request. After receiving the user's consent, the server calls the user's camera to capture a face image.
[0082] 3. Verify the user's identity information.
[0083] The system receives authorization confirmation information from the user's terminal, extracts the user's identity information from it, and then verifies the user's identity. For example, in one specific embodiment of the invention, the collected facial image is verified to determine if it belongs to the user. If it does, the verification passes; otherwise, the verification fails.
[0084] When identity verification is successful, the authorized party retrieves the electronic certificates from the certificate authorization list in the electronic certificate management platform to process the pending business. When identity verification fails, an authorization failure message is returned to the user.
[0085] It should be noted that, in some embodiments of the present invention, the above-mentioned electronic certificate application process and authorized identity verification process are optional execution steps. In another embodiment of the present invention, the electronic certificate application process can be executed first, and then the authorized identity verification process can be executed.
[0086] S104. Authorized business handlers can retrieve electronic certificates from the certificate authorization list from the electronic certificate management platform to handle pending business.
[0087] In this embodiment of the invention, after receiving the certificate authorization list returned by the user, the authorized business handler retrieves the electronic certificates from the certificate authorization list from the electronic certificate management platform to process the pending business. The business handler can be a third-party service provider, which is not limited herein.
[0088] In some embodiments of the present invention, as described above, the certificate authorization list (or authorization agreement) includes the authorization validity period of the authorized electronic certificates. Retrieving the electronic certificates from the certificate authorization list from the electronic certificate management platform to process the pending business includes:
[0089] 1. Determine whether the current time of accessing the electronic certificate is within the authorization validity period.
[0090] In this embodiment of the invention, when an electronic certificate needs to be accessed, it is determined whether the current time of accessing the electronic certificate is within the authorization validity period. For example, the authorization validity period can be set to 24 hours, meaning that after user authorization, the electronic certificate must be accessed and used to process business within 24 hours, avoiding prolonged authorization that could lead to the leakage and misuse of the electronic certificate.
[0091] 2. If so, the authorized business handler shall retrieve the electronic certificates from the certificate authorization list in the electronic certificate management platform to handle pending business.
[0092] If so, the authorized party will retrieve the electronic certificates from the certificate authorization list in their personal digital space on the electronic certificate management platform and process the pending business according to the order of pending matters.
[0093] 3. If not, return a notification message indicating that the authorization has expired to the authorized service provider.
[0094] If not, return a message to the user indicating that the authorization has expired.
[0095] In some embodiments of the present invention, the authorization records uploaded to the government blockchain can be stored as evidence to facilitate traceability of the authorization process and prevent tampering and disputes. For example, a hash function is used to calculate the hash value of the business processing record as a summary of the record. The business processing record includes a list of authorized certificates and authorization information and authorization confirmation information. The summary information is signed to obtain a digital signature. The digital signature and the business processing record are packaged and broadcast to all nodes on the government blockchain. Leveraging the immutability and traceability of the blockchain, the entire process of generating, storing, using, and updating on-chain government data is traceable, ensuring data security. Each node on the blockchain, upon receiving the packaged data of the digital signature and the business processing record, decrypts the digital signature to obtain the original hash value. Furthermore, the same hash function is used to calculate a new hash value for the business processing record. The original hash value and the new hash value are compared. If they are the same, the data is considered tamper-proof, and the packaged data is written into an empty block, completing the on-chain process.
[0096] The electronic certificate authorization method provided by this invention, in response to a user's business processing request, determines the electronic certificates required for the pending business, generates a list of required electronic certificates, and returns it to the user. The method also receives a certificate authorization list returned by the user, whereby the certificate authorization list includes at least one electronic certificate from the list. These electronic certificates are those authorized for use by the user. The authorized business handler retrieves the electronic certificates from the certificate authorization list from the electronic certificate management platform to process the pending business. This invention improves security and data compliance by returning a list of required electronic certificates to the user and allowing the user to selectively authorize certificates based on actual needs. This avoids over-authorization and information leakage caused by authorizing all certificates at once.
[0097] Figure 2 This is a schematic diagram of the structure of an electronic certificate authorization device provided by the present invention, as shown below. Figure 2 As shown, the electronic certificate authorization device includes:
[0098] The electronic certificate determination module 201 is used to determine the electronic certificates required for the pending business in response to the business processing request from the user terminal.
[0099] The certificate list generation module 202 is used to generate a certificate list of the required electronic certificates and return it to the user terminal;
[0100] The authorization list receiving module 203 is used to receive the certificate authorization list returned by the user terminal. The certificate authorization list includes at least one electronic certificate in the certificate authorization list. The electronic certificate in the certificate authorization list is an electronic certificate authorized by the user.
[0101] The certificate authorization module 204 is used to authorize the business handler to retrieve the electronic certificates from the certificate authorization list from the electronic certificate management platform to handle the pending business.
[0102] In some embodiments of the present invention, the electronic certificate determination module 201 includes:
[0103] The pending task determination submodule is used to parse out the pending tasks included in the pending business from the business processing request;
[0104] The Electronic Certificate Confirmation Submodule is used to determine the electronic certificates required for the pending tasks.
[0105] In some embodiments of the present invention, the certificate list generation module 202 includes:
[0106] The table generation submodule is used to generate an item column and an electronic certificate column. The item column includes a first cell for filling in the pending items, and the electronic certificate column includes a second cell for filling in the electronic certificates required for the pending items.
[0107] The first fill submodule is used to fill the to-do items into the first cell of the item column;
[0108] The second fill submodule is used to fill the electronic certificates required for the pending items into the corresponding second cell;
[0109] The authorization component generation submodule is used to generate an authorization component for users to select and authorize at a preset location of the electronic certificate in the second cell.
[0110] In some embodiments of the present invention, the electronic certificate authorization device further includes:
[0111] The judgment module is used to determine whether the user terminal has applied for the electronic certificates in the certificate authorization list before the authorized business handler calls the electronic certificates in the certificate authorization list from the electronic certificate management platform to handle the pending business.
[0112] The first execution module is used to execute the steps of the authorized business handler calling the electronic certificates in the certificate authorization list from the electronic certificate management platform to handle the pending business when the user has applied for the electronic certificates in the certificate authorization list.
[0113] The application entry generation module is used to generate an application entry when the user has not applied for the electronic certificates in the certificate authorization list and return it to the user. The application entry is used to guide the user to jump to the application page of the certificate to be applied for.
[0114] The second execution module is used to execute the steps of the authorized business handler calling the electronic certificates in the certificate authorization list from the electronic certificate management platform to handle the pending business after receiving the application success feedback returned by the application page. The application success feedback indicates that the user has applied for electronic certificates from the electronic certificate management platform and agrees to view and authorize electronic certificates on the user terminal.
[0115] In some embodiments of the present invention, the electronic certificate authorization device further includes:
[0116] The authorization confirmation request sending module is used to send an authorization confirmation request to the user terminal while receiving the list of authorized certificates returned by the user terminal;
[0117] The authorization confirmation information receiving module is used to receive authorization confirmation information returned by the user terminal, wherein the authorization confirmation information includes the user's identity information;
[0118] The identity verification module is used to verify the user's identity information.
[0119] The third execution module is used to execute the steps of the authorized business handler calling the electronic certificates in the certificate authorization list from the electronic certificate management platform to handle the pending business when the identity verification is passed.
[0120] In some embodiments of the present invention, the certificate authorization list includes the authorization validity period of the authorized electronic certificates, and the certificate authorization module 204 includes:
[0121] The validity period determination submodule is used to determine whether the current time of calling the electronic certificate is within the authorization validity period;
[0122] The certificate retrieval submodule is used to, at the current time of retrieval of electronic certificates and within the authorization validity period, allow the authorized business handler to retrieve electronic certificates from the certificate authorization list from the electronic certificate management platform to handle the pending business.
[0123] The prompt submodule is used to return a prompt message indicating that the authorization has expired to the business operator when the current time of calling the electronic certificate is not within the authorization validity period.
[0124] In some embodiments of the present invention, the electronic certificate authorization device further includes:
[0125] The hash calculation module is used to calculate the hash value of the business processing record as the summary information of the business processing record after the authorized business handler calls the electronic certificate from the certificate authorization list in the electronic certificate management platform to process the pending business. The business processing record includes the certificate authorization list and the authorization confirmation information.
[0126] The digital signature module is used to sign the digest information to obtain a digital signature;
[0127] The broadcast module is used to broadcast the digital signature and the business processing record to various nodes on the government blockchain.
[0128] The aforementioned electronic certificate authorization device can execute the electronic certificate authorization method provided in the foregoing embodiments of the present invention, and has the corresponding functional modules and beneficial effects for executing the electronic certificate authorization method.
[0129] Figure 3This is a schematic diagram of an electronic device provided by the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0130] like Figure 3 As shown, the electronic device includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer programs stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0131] Multiple components in the electronic device are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, optical disk, etc.; and a communication unit 19, such as a network card, modem, wireless transceiver, etc. The communication unit 19 allows the electronic device to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0132] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as the electronic certificate authorization method.
[0133] In some embodiments, the electronic certificate authorization method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on an electronic device via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the electronic certificate authorization method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the electronic certificate authorization method by any other suitable means (e.g., by means of firmware).
[0134] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0135] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0136] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0137] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0138] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0139] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0140] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the electronic certificate authorization method provided in any embodiment of this application.
[0141] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages or a combination thereof. Programming languages include object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0142] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0143] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for authorizing electronic certificates, characterized in that, include: In response to a user's business processing request, determine the electronic certificates required for the pending business; Generate a list of the required electronic certificates and return it to the user terminal; Receive the certificate authorization list returned by the user terminal, the certificate authorization list includes at least one electronic certificate in the certificate authorization list, and the electronic certificate in the certificate authorization list is an electronic certificate authorized by the user; The authorized service provider retrieves the electronic certificates from the certificate authorization list from the electronic certificate management platform to process the pending service.
2. The electronic certificate authorization method according to claim 1, characterized in that, In response to a user's service request, determine the electronic certificates required for the pending service, including: Parse the pending tasks included in the pending business from the business processing request; Identify the electronic certificates required for the tasks to be completed.
3. The electronic certificate authorization method according to claim 2, characterized in that, Generate a list of required electronic certificates, including: Generate a task column and an electronic certificate column, wherein the task column includes a first cell for filling the task to be done, and the electronic certificate column includes a second cell for filling the electronic certificates required for the task to be done; Fill the to-do list into the first cell of the item column; Fill the corresponding second cell with the electronic certificates required for the pending items; An authorization component is generated at a preset location in the second cell for users to select authorization options.
4. The electronic certificate authorization method according to any one of claims 1-3, characterized in that, Before the authorized service provider retrieves the electronic certificates from the certificate authorization list from the electronic certificate management platform to process the pending service, the process also includes: Determine whether the user terminal has applied for the electronic certificates in the certificate authorization list; If so, the authorized business handler shall execute the step of retrieving the electronic certificates from the certificate authorization list in the electronic certificate management platform to handle the pending business; If not, an application entry is generated and returned to the user terminal. The application entry is used to guide the user terminal to the application page for the certificate to be applied for. After receiving a successful application feedback from the application page, the authorized service provider retrieves the electronic certificates from the certificate authorization list in the electronic certificate management platform to process the pending business. The successful application feedback indicates that the user has applied for electronic certificates from the electronic certificate management platform and agrees to view and authorize electronic certificates on the user's end.
5. The electronic certificate authorization method according to any one of claims 1-3, characterized in that, In addition to receiving the list of authorized certificates returned by the user terminal, the system also includes: Send an authorization confirmation request to the user terminal; Receive authorization confirmation information returned by the user terminal, the authorization confirmation information including the user's identity information; The user's identity information is verified; When the identity verification is successful, the authorized business handler shall retrieve the electronic certificates from the certificate authorization list from the electronic certificate management platform to handle the pending business.
6. The electronic certificate authorization method according to any one of claims 1-3, characterized in that, The certificate authorization list includes the authorization validity period of the authorized electronic certificates. Authorized business operators retrieve the electronic certificates from the certificate authorization list from the electronic certificate management platform to process the pending business, including: Determine whether the current time of accessing the electronic certificate is within the validity period of the authorization; If so, the authorized business handler shall retrieve the electronic certificates from the certificate authorization list in the electronic certificate management platform to handle the pending business; If not, a notification message indicating that the authorization has expired will be returned to the business processing party.
7. The electronic certificate authorization method according to claim 5, characterized in that, After the authorized service provider retrieves the electronic certificates from the certificate authorization list from the electronic certificate management platform to process the pending service, the process also includes: The hash value of the business processing record is calculated using a hash function and used as the summary information of the business processing record, which includes the certificate and license authorization list and the authorization confirmation information; The digest information is signed to obtain a digital signature; The digital signature and the business transaction record are broadcast to each node on the government blockchain.
8. An electronic certificate authorization device, characterized in that, include: The electronic certificate determination module is used to determine the electronic certificates required for the pending business in response to the user's business processing request. The certificate list generation module is used to generate a list of the required electronic certificates and return it to the user terminal. The authorization list receiving module is used to receive the certificate authorization list returned by the user terminal. The certificate authorization list includes at least one electronic certificate in the certificate authorization list. The electronic certificate in the certificate authorization list is an electronic certificate authorized by the user. The certificate authorization module is used to authorize the business handler to retrieve the electronic certificates from the certificate authorization list from the electronic certificate management platform to handle the pending business.
9. An electronic device, characterized in that, include: One or more processors; Storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the electronic certificate authorization method as described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the electronic certificate authorization method as described in any one of claims 1-7.