Credit investigation authorization method and device, equipment, storage medium and program product

By creating a distributed ledger in a blockchain network to record credit authorization information and achieve atomic updates and evidence storage, the credibility and compliance issues of credit authorization methods are resolved, the transparency and compliance of credit authorization are improved, and customer trust and dispute resolution efficiency are enhanced.

CN121860640APending Publication Date: 2026-04-14INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-31
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

The existing credit reporting authorization methods lack credibility and compliance, and there are problems such as forged authorization, decoupling of authorization and query, data silos, and insufficient customer participation.

Method used

By creating a distributed ledger in the blockchain network to record credit authorization records, including customer identity information, authorization scope and validity period, and based on the consensus mechanism to ensure data immutability, atomic updates and notarization are achieved. Combined with customer digital signatures and audit channels of regulatory agencies, the legality and transparency of authorization are ensured.

Benefits of technology

It improves the credibility and compliance of credit authorization, prevents forged authorization, ensures that each query corresponds to a valid authorization, enhances customers' transparency and trust in the authorization process, simplifies dispute resolution, and improves compliance and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121860640A_ABST
    Figure CN121860640A_ABST
Patent Text Reader

Abstract

The invention provides a credit investigation authorization method and device, equipment, a storage medium and a program product, and relates to the technical field of financial science and technology or the technical field of block chains. The method comprises the following steps: receiving a credit investigation authorization request transaction and creating a credit investigation authorization record in a distributed account book, wherein the credit investigation authorization record comprises customer identity information, a credit investigation authorization range and a credit investigation authorization validity period; receiving a credit investigation query request transaction and judging whether the credit investigation query request transaction conforms to a preset credit investigation authorization verification rule or not according to the credit investigation authorization record; and under the condition that the credit investigation query request transaction accords with a preset authorization verification rule, atomically updating the state of the credit investigation authorization record to be used, and generating a credit investigation query evidence. According to the credit investigation authorization method, the credibility and compliance of credit investigation authorization can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of financial technology or blockchain technology, and in particular to a credit authorization method, apparatus, device, storage medium and program product. Background Technology

[0002] In financial lending, credit reporting authorization is a core component of risk control and compliance review. When a customer applies for a loan, credit card, or credit assessment service, financial institutions need to obtain their credit report from a credit reporting agency to assess credit risk. This process relies on the customer's explicit authorization for credit reporting inquiries.

[0003] Currently, customers typically complete authorization by signing paper authorization forms offline or checking electronic agreements online, and financial institutions store the authorization information in their internal business systems. The credibility and compliance of this credit authorization method need to be improved. Summary of the Invention

[0004] This application provides a credit investigation authorization method, apparatus, device, storage medium, and program product to improve the credibility and compliance of credit investigation authorization.

[0005] Firstly, this application provides a credit authorization method, comprising: receiving a credit authorization request transaction and creating a credit authorization record in a distributed ledger, the credit authorization record including customer identity information, credit authorization scope and credit authorization validity period; receiving a credit inquiry request transaction and determining whether the credit inquiry request transaction conforms to preset credit authorization verification rules based on the credit authorization record; if the credit inquiry request transaction conforms to the preset authorization verification rules, atomically updating the status of the credit authorization record to "used" and generating a credit inquiry certificate.

[0006] In one possible embodiment, determining whether a credit inquiry request transaction complies with preset credit authorization verification rules based on the credit authorization record includes: matching the credit authorization scope and validity period in the credit authorization record with the financial institution identity information and inquiry purpose information in the credit inquiry request transaction; if the inquiry purpose information matches the credit authorization scope and the time of the credit inquiry request transaction is within the credit authorization validity period of the credit authorization record, then it is determined that the credit inquiry request transaction complies with the preset credit authorization verification rules.

[0007] In one possible embodiment, matching the credit authorization scope in the credit authorization record includes: matching a preset business type template based on the query purpose information, wherein the business type template contains a credit authorization scope field corresponding to the query purpose information; and dynamically adjusting the matching rules for the credit authorization scope based on the customer credit rating in the credit query request transaction.

[0008] In one possible embodiment, after updating the status of the credit authorization record to "used", the credit authorization method further includes: pushing a credit authorization status change notification to the client terminal node.

[0009] In one possible embodiment, pushing a credit authorization status change notification to the client terminal node includes: generating notification content containing the transaction hash value of the credit inquiry request and the identity information of the financial institution when the status of the credit authorization record is updated to "used"; and sending the notification content to the client terminal node through an encrypted communication protocol.

[0010] In one possible embodiment, after generating the credit inquiry certificate, the credit authorization method further includes: granting regulatory agency nodes access to the credit inquiry certificate through a blockchain explorer.

[0011] In one possible embodiment, granting regulatory agency nodes access to credit information inquiry and evidence storage via a blockchain explorer includes: setting the access permission field for credit information inquiry and evidence storage to include the identification information of the regulatory agency node when generating the credit information inquiry and evidence storage; and verifying the legitimacy of the regulatory agency node's query request.

[0012] In one possible embodiment, before creating the credit authorization record, the credit authorization method further includes: generating a customer digital signature through a customer terminal node; the customer digital signature is used to embed the credit authorization record.

[0013] Secondly, this application provides a credit authorization device, comprising: a credit authorization record creation module, used to receive credit authorization request transactions and create credit authorization records in a distributed ledger, the credit authorization record including customer identity information, credit authorization scope and credit authorization validity period; a verification module, used to receive credit inquiry request transactions and determine whether the credit inquiry request transaction conforms to preset credit authorization verification rules based on the credit authorization record; and a processing module, used to atomically update the status of the credit authorization record to "used" and generate credit inquiry evidence if the credit inquiry request transaction conforms to the preset authorization verification rules.

[0014] Thirdly, this application provides an electronic device, including: a processor and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the method as described in any of the first aspects.

[0015] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any of the first aspects.

[0016] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method of any one of the first aspects.

[0017] In this embodiment, by receiving credit authorization request transactions and creating credit authorization records in the distributed ledger, based on the immutability of the distributed ledger, each node in the blockchain network stores an immutable credit authorization record to ensure the credibility of data such as customer identity information, authorization scope, and validity period. By receiving credit inquiry request transactions and determining whether the credit inquiry request transaction conforms to preset credit authorization verification rules based on the credit authorization record, the legality of the credit inquiry request transaction can be verified, ensuring that each credit inquiry request transaction strictly corresponds to a valid credit authorization record. By atomically updating the status of the credit authorization record to "used" and generating credit inquiry evidence when the credit inquiry request transaction conforms to the preset authorization verification rules, the status update of the credit authorization record and the generation of credit inquiry evidence can be bound as an inseparable operation. This achieves technical-level compliance assurance of "no authorization, no inquiry".

[0018] The entire process described above ensures data consistency through a distributed ledger consensus mechanism, and all operations are irreversible, forming a complete chain of credit authorization and credit inquiry behaviors. This immutable on-chain record provides credible evidence for auditing and dispute resolution, thereby mitigating compliance risks arising from the separation of credit authorization and credit inquiry. The atomic transaction between updating the credit authorization record and generating evidence for the credit inquiry achieves a technical-level compliance guarantee of "no authorization, no inquiry." This enhances the credibility and compliance of credit authorization, increasing customer transparency and trust in the credit authorization process. Attached Figure Description

[0019] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0020] Figure 1 This is a schematic diagram illustrating an application scenario of the credit investigation and authorization method according to an embodiment of this application;

[0021] Figure 2 This is a flowchart of the credit investigation and authorization method according to an embodiment of this application;

[0022] Figure 3 This is a schematic diagram of a credit investigation and authorization device according to an embodiment of this application;

[0023] Figure 4 This is a schematic diagram of an electronic device according to an embodiment of this application.

[0024] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0025] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0026] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation access points for users to choose to authorize or refuse.

[0027] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.

[0028] It should be noted that the credit authorization methods, devices, equipment, storage media and program products provided in this application can be used in the fields of financial technology or blockchain technology, or in any field other than the fields of financial technology or blockchain technology. This application does not limit the application fields of the credit authorization methods, devices, equipment, storage media and program products.

[0029] Figure 1 This is a schematic diagram illustrating an application scenario of the credit investigation and authorization method according to an embodiment of this application.

[0030] like Figure 1As shown, customer 1 provides financial credit services through financial application 3 installed on customer terminal node 2. For example, financial application 3 provides an interactive interface for functions such as credit authorization creation, credit inquiry monitoring, and credit authorization revocation, and the aforementioned interactive interface provides digital signature generation functionality.

[0031] When customer 1 provides financial credit services through financial application 3, credit authorization can be performed using the credit authorization method of this application embodiment. The credit authorization method of this application embodiment is implemented based on a blockchain network. The blockchain network is a consortium blockchain network jointly maintained by client node 2, financial institution node 4, credit reporting agency node 5, and regulatory agency node 6. The aforementioned nodes in the blockchain network employ a consensus mechanism to ensure data consistency and immutability.

[0032] In a blockchain network, a distributed ledger is deployed on each node. The distributed ledger is used to record and store data related to credit authorization. The distributed ledger is deployed with smart contracts, which are code that implements the credit authorization method described in the embodiments of this application below.

[0033] Among them, Node 4 of the financial institution communicates between the financial institution's internal system and the blockchain network through the financial institution's business system interface. Through the financial institution's business system interface, when the financial institution needs to authorize credit information inquiries, it can invoke a smart contract to authorize credit information inquiries and record the credit information inquiry authorization behavior.

[0034] Related technology 1 relies on the financial institution's business system to complete credit authorization. The specific process is as follows:

[0035] Credit information authorization: Customers complete credit information authorization by signing paper documents offline or checking electronic agreements online. Credit information authorization information (such as customer identity information, scope of credit information authorization and validity period of credit information authorization) is recorded in the database of the financial institution's business system.

[0036] Credit authorization verification: Financial institutions use their internal systems to verify the validity of credit authorization.

[0037] Credit Inquiry Execution: After the validity of the credit authorization is verified, the financial institution sends an inquiry request to the credit reporting agency to obtain the customer's credit report.

[0038] The limitations of the relevant technologies are mainly reflected in the following aspects:

[0039] The credibility of credit authorization information is low: paper authorization documents that record credit authorization information are easy to forge, and electronic authorization documents that record credit authorization information rely on the storage of a single system and lack a decentralized and reliable verification mechanism.

[0040] Decoupling credit authorization and credit inquiry: Credit authorization verification and credit inquiry are two independent operations, lacking atomic binding at the technical level, which may lead to violations. For example, violations such as "unauthorized inquiry" or "one authorization for multiple inquiries" may occur, making subsequent auditing difficult.

[0041] Data silos: Credit authorization information and credit inquiry records are scattered across different systems, lacking a unified auditing channel. This leads to inefficient dispute resolution requiring multi-party coordination. For example, if a customer questions an unauthorized credit inquiry, dispute resolution requires coordination among financial institutions, credit reporting agencies, and other parties, cross-verifying logs and database records from their respective systems. This process is cumbersome, time-consuming, and labor-intensive, and logs from different parties may be out of sync or incomplete, making it difficult to determine liability.

[0042] Insufficient customer involvement: Customers cannot monitor the credit authorization status and credit inquiry behavior in real time, and can only be passively informed through after-the-fact notifications, lacking dynamic control capabilities.

[0043] The credit investigation authorization method, apparatus, equipment, storage medium, and program products provided in this application are intended to solve at least one of the above-mentioned technical problems in the related technologies.

[0044] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0045] Figure 2 This is a flowchart illustrating the credit authorization method according to an embodiment of this application. This credit authorization method is executed by a blockchain network, specifically by each node in the blockchain network; the following explanation will use the blockchain network execution as an example.

[0046] like Figure 2 As shown, the credit investigation authorization method of this application embodiment includes steps S110 to S130.

[0047] S110, Receive credit authorization request transactions and create credit authorization records in the distributed ledger.

[0048] Credit authorization records include customer identity information, scope of credit authorization, and validity period of credit authorization.

[0049] Distributed ledger refers to a system composed of multiple nodes (such as...) Figure 1The system depicted (as shown) is an immutable electronic record system jointly maintained by client terminal node 2, financial institution node 4, credit reporting agency node 5, and regulatory agency node 6. The distributed ledger is used to store credit authorization records and evidence of credit inquiries. The distributed ledger includes the blockchain ledger in a consortium blockchain network.

[0050] Credit authorization records refer to electronic storage units of credit authorization information initiated by customers, which include fields such as customer identity information, scope of credit authorization, and validity period of credit authorization.

[0051] For example, a customer initiates a credit application and generates a credit authorization transaction through a financial application installed on the customer's terminal node. The customer's terminal node sends the credit authorization transaction to the blockchain network. The blockchain network creates a credit authorization record in the distributed ledger based on the credit authorization request transaction.

[0052] For example, after a credit authorization record is successfully created in the distributed ledger, the record is marked as valid. Following successful creation of the credit authorization record in the distributed ledger, the blockchain network can also send information indicating the successful creation of the credit authorization record to relevant parties such as customers, financial institutions, credit reporting agencies, and regulatory agencies.

[0053] S120. Receive credit inquiry request transactions and determine whether the credit inquiry request transactions comply with the preset credit authorization verification rules based on the credit authorization records.

[0054] For example, when a financial institution's business system deployed on a financial institution node needs to query credit information, it can generate a credit information query request transaction. The financial institution node sends the credit information query request transaction to the blockchain network. The blockchain network responds to the credit information query request transaction, determines whether the credit information query request transaction conforms to the preset credit information authorization verification rules based on the credit authorization records, and completes the authorization verification.

[0055] S130. If the credit inquiry request transaction meets the preset authorization verification rules, atomically update the status of the credit authorization record to "used" and generate a credit inquiry certificate.

[0056] Credit inquiry evidence storage refers to the electronic evidence that records credit inquiry requests, including the hash value of the credit inquiry request, timestamp, and the identity of the operator.

[0057] For example, after the blockchain network completes step S130, the financial institution can request the customer's credit information from the credit reporting agency based on the credit inquiry record.

[0058] For example, if a credit inquiry request transaction does not meet the preset authorization verification rules, the blockchain network can update the status of the credit authorization record to abnormal.

[0059] Atomically updating the status of a credit authorization record to "used" and generating a credit query certificate can be understood as an atomic transaction. In this embodiment, by atomically updating the status of a credit authorization record to "used" and generating a credit query certificate, the update of the credit authorization status and the generation of the credit query certificate can be bound into an indivisible operation. The credit query certificate enables the traceability of credit query behavior. An atomic transaction is an indivisible transaction.

[0060] For example, if either the status update of the credit authorization record or the generation of credit inquiry evidence fails, the atomic transaction is rolled back to prevent invalid credit inquiry request transactions from being executed.

[0061] In one possible embodiment, upon receiving a credit authorization revocation request transaction, the blockchain network can update the status of the credit authorization record to revocation and generate a credit authorization revocation certificate, which is then saved to the distributed ledger.

[0062] In this embodiment, by receiving credit authorization request transactions and creating credit authorization records in the distributed ledger, based on the immutability of the distributed ledger, each node in the blockchain network stores an immutable credit authorization record to ensure the credibility of data such as customer identity information, authorization scope, and validity period. By receiving credit inquiry request transactions and determining whether the credit inquiry request transaction conforms to preset credit authorization verification rules based on the credit authorization record, the legality of the credit inquiry request transaction can be verified, ensuring that each credit inquiry request transaction strictly corresponds to a valid credit authorization record. By atomically updating the status of the credit authorization record to "used" and generating credit inquiry evidence when the credit inquiry request transaction conforms to the preset authorization verification rules, the status update of the credit authorization record and the generation of credit inquiry evidence can be bound as an inseparable operation. This achieves technical-level compliance assurance of "no authorization, no inquiry".

[0063] The entire process described above ensures data consistency through a distributed ledger consensus mechanism, and all operations are irreversible, forming a complete chain of credit authorization and credit inquiry behaviors. This immutable on-chain record provides credible evidence for auditing and dispute resolution, thereby mitigating compliance risks arising from the separation of credit authorization and credit inquiry. The atomic transaction between updating the credit authorization record and generating evidence for the credit inquiry achieves a technical-level compliance guarantee of "no authorization, no inquiry." This enhances the credibility and compliance of credit authorization, increasing customer transparency and trust in the credit authorization process.

[0064] like Figure 2 As shown, in one possible embodiment, before creating the credit authorization record in step S110, the credit authorization method further includes step S101.

[0065] S101. Generate customer digital signatures through customer terminal nodes.

[0066] A customer digital signature is an electronic signature used to verify a customer's identity. Customer digital signatures are also used to embed credit authorization records.

[0067] For example, a customer digital signature can be generated by executing an asymmetric encryption algorithm on a customer terminal node. For instance, a customer digital signature can be obtained by hashing information such as customer identity information, credit authorization scope, and credit authorization validity period using the customer's private key.

[0068] In this embodiment, the digital signature function of the client terminal node ensures the credibility of information such as customer identity, credit authorization scope, and credit authorization validity period, thereby ensuring the unforgeability of the credit authorization record. The customer's digital signature is used to embed the credit authorization record, and the blockchain network can verify the validity of the customer's digital signature in subsequent steps to ensure the unforgeability of the credit authorization record.

[0069] In one possible embodiment, step S120, determining whether a credit inquiry request transaction conforms to a preset credit authorization verification rule based on the credit authorization record, includes: matching the credit authorization scope and validity period in the credit authorization record based on the financial institution identity information and inquiry purpose information in the credit inquiry request transaction; if the inquiry purpose information matches the credit authorization scope and the time of the credit inquiry request transaction is within the credit authorization validity period of the credit authorization record, then it is determined that the credit inquiry request transaction conforms to the preset credit authorization verification rule.

[0070] Financial institution identity information refers to the unique identifier of the financial institution that initiates the credit inquiry request transaction, such as the financial institution code or digital certificate.

[0071] The purpose of the inquiry indicates the specific business scenario in which the financial institution initiates the credit inquiry request, such as loan approval or credit card application.

[0072] Credit authorization scope refers to the types of credit information that a customer is explicitly allowed to access in their credit authorization records, such as personal credit reports or business operation data.

[0073] The credit reporting authorization validity period refers to the authorized usage time range set in the credit reporting right record.

[0074] For example, the blockchain network first extracts the identity information of the financial institution making the credit inquiry request transaction to confirm its legality. Then, it parses the purpose of the inquiry in the transaction and compares it with the scope of credit authorization in the credit authorization record to determine whether the purpose of the inquiry is within the scope of the customer's authorization. Additionally, the blockchain network can verify whether the time of the credit inquiry request transaction is within the validity period of the credit authorization in the credit authorization record. Furthermore, if all conditions are met, the blockchain network determines that the credit inquiry request transaction complies with preset authorization verification rules. If the purpose of the inquiry does not match the scope of the credit authorization, or if the time of the credit inquiry request transaction is not within the validity period of the credit authorization in the credit authorization record, the blockchain network determines that the credit inquiry request transaction does not comply with the preset authorization verification rules.

[0075] In this embodiment, the blockchain network analyzes the financial institution's identity information and query purpose information in the credit inquiry request transaction and matches them with the credit authorization scope and validity period in the credit authorization record. This ensures strict consistency between the credit inquiry request transaction and the credit authorization scope and validity period. Dual verification of the financial institution's identity information and query purpose information prevents unauthorized credit inquiries by financial institutions or abuse of customer-authorized credit scope. Furthermore, strict verification of the credit authorization validity period prevents the misuse of expired credit authorizations, further improving the accuracy and compliance of credit authorization verification.

[0076] In one possible embodiment, matching the credit authorization scope in the credit authorization record includes: matching a preset business type template based on the query purpose information; and dynamically adjusting the matching rules for the credit authorization scope based on the customer's credit rating in the credit query request transaction.

[0077] The business type template includes a credit authorization scope field corresponding to the query target information.

[0078] Business type templates refer to the preset credit authorization scope configuration rules. For example, the business type template corresponding to the purpose of the loan approval query is the asset certificate and debt record, and the business type template corresponding to the purpose of the credit card application query is the consumption record.

[0079] Customer credit rating refers to a customer's credit score or risk rating in the credit reporting system. Customer credit ratings include, for example, high risk, medium risk, and low risk.

[0080] For example, when the query purpose information indicates loan approval, the query purpose information is matched with the credit authorization scope field of asset proof and liability records according to a preset business type template. When the customer's credit rating is high-risk, the matching rules for the credit authorization scope can be dynamically adjusted to restrict credit query requests that indicate loan approval to access only certain sensitive data.

[0081] In this embodiment, the matching rules for the scope of credit reporting authorization are dynamically adjusted by using business type templates or customer credit ratings. This makes the matching rules for the scope of credit reporting authorization more closely match actual business needs, improves the flexibility and risk control capabilities of credit reporting authorization, and reduces the risk of privacy leakage caused by customers' excessively broad credit reporting authorization scope.

[0082] like Figure 2 As shown, in one possible embodiment, after updating the status of the credit authorization record to "used" in step S130, the credit authorization method further includes step S140.

[0083] S140: Push a notification of credit authorization status change to the customer terminal node.

[0084] For example, an event detection function unit deployed in the blockchain network detects credit authorization status change events and triggers a notification mechanism. Specifically, the event detection function unit detects credit authorization status change events in the blockchain network in real time. When the credit authorization status is updated to "used," the event detection function unit triggers a notification mechanism, packages the credit authorization status change event into a notification message, and pushes it to the client through the communication interface of the client terminal node.

[0085] For example, after receiving a notification of a change in credit authorization status, the client terminal node can parse the event content and display it to the client, such as displaying a message saying "Your authorization has been used".

[0086] In this embodiment, by pushing a notification of a change in credit authorization status to the customer's terminal node, the customer can be informed of the change in credit authorization status immediately, thereby achieving dynamic monitoring of the credit authorization usage process. This improves upon the problem that customers can only passively learn about the credit authorization status through post-event notifications, enhancing their right to know and control over the use of credit data.

[0087] In one possible embodiment, step S140 of pushing the credit authorization status change notification to the client terminal node includes: when the status of the credit authorization record is updated to "used", generating notification content containing the transaction hash value of the credit query request and the identity information of the financial institution; and sending the notification content to the client terminal node through an encrypted communication protocol.

[0088] Encrypted communication protocols are used to ensure the security of data transmission. Examples of encrypted communication protocols include Hypertext Transfer Protocol Secure (HTTPS) and Transport Layer Security (TLS).

[0089] In this embodiment, when the credit authorization record's status is updated to "used," a notification is generated containing the transaction hash value of the credit inquiry request and the financial institution's identity information. Based on the uniqueness of the hash value, the credit inquiry request transaction can be accurately linked; the financial institution's identity information allows the customer to easily identify the party making the credit inquiry. Sending the notification content to the customer's terminal node via an encrypted communication protocol ensures that the notification content is only visible to the customer and cannot be tampered with. This enhances the customer's privacy during the credit authorization process and improves the security of credit authorization.

[0090] like Figure 2 As shown, in one possible embodiment, after generating credit information query and storage in step S130, the credit information authorization method further includes step S150.

[0091] S150. Grant regulatory agency nodes access to credit information inquiry and evidence storage through a blockchain explorer.

[0092] A blockchain explorer is a tool used to query transaction and block information on a blockchain. A blockchain explorer includes a visual query interface based on the application programming interfaces (APIs) of each node in the blockchain network.

[0093] Regulatory agency nodes refer to blockchain network nodes maintained by regulatory agencies to supervise the compliance of credit authorization processes.

[0094] For example, after generating the credit inquiry certificate, the blockchain explorer automatically adds the query permission for the credit inquiry certificate to the access list of the regulatory agency node. The regulatory agency node can enter the hash value or authorization identifier of the credit inquiry certificate through the blockchain explorer to view the complete content of the credit inquiry certificate, related parties, and other information.

[0095] In this embodiment, the access control function of the blockchain explorer is used to open access to credit information inquiry and evidence storage to regulatory agency nodes, providing a transparent audit channel for regulatory agencies. This can improve the complexity of cross-system data verification, allowing regulatory agencies to directly access on-chain credit information inquiry and evidence storage as audit evidence, thereby improving the efficiency and credibility of dispute resolution, and enhancing the compliance of the credit information authorization process.

[0096] In one possible embodiment, step S150, granting the regulatory agency node access permission for credit inquiry and evidence storage via a blockchain explorer, includes: setting the access permission field for credit inquiry and evidence storage to include the identification information of the regulatory agency node when generating the credit inquiry and evidence storage; and verifying the legality of the regulatory agency node's query request.

[0097] For example, when generating a credit inquiry record, the record includes an access permission field, which records the identifiers of permitted nodes (such as the identifiers of regulatory agency nodes). When a regulatory agency node initiates a credit inquiry request transaction, the blockchain network can verify whether the identifier information of the party making the credit inquiry request is in the access permission field to verify the legitimacy of the regulatory agency node's query request. If the identifier information of the party making the credit inquiry request is in the access permission field, the query is allowed; otherwise, it is rejected.

[0098] In this embodiment of the application, by setting the access permission field of the credit inquiry evidence to include the identification information of the regulatory agency node and the verification of the legality of the query request of the regulatory agency node when generating the credit inquiry evidence, it can be ensured that the regulatory agency node can only access the credit inquiry evidence within its permission scope, prevent unauthorized access, and provide compliance and security for the credit authorization process.

[0099] In summary, the credit investigation and authorization method of this application embodiment has at least one of the following technical effects:

[0100] 1. Based on customer digital signatures and credit inquiry evidence storage, it can improve the situation of forged credit authorization and tampering with credit authorization, and enhance the credibility of credit authorization.

[0101] 2. By atomically updating the status of the credit inquiry authorization record to "used" and generating a credit inquiry certificate when the credit inquiry request transaction meets the preset authorization verification rules, the update of the credit authorization record status and the generation of the credit inquiry certificate can be bound as an inseparable operation. This achieves technical-level compliance assurance of "no inquiry without authorization".

[0102] 3. By pushing notifications of changes in credit authorization status to customer terminal nodes, customers can be informed of changes in credit authorization status immediately, thereby enabling dynamic monitoring of the credit authorization usage process. This improves upon the situation where customers can only passively learn about credit authorization status through after-the-fact notifications, enhancing their right to know and control over the use of credit data.

[0103] 4. The credit authorization implemented through the blockchain network in the above embodiments can simplify the complex cross-system log verification of multiple parties into the verification of a single, trusted on-chain record, reducing the cost of dispute evidence collection and the time for dispute resolution, and has higher dispute handling efficiency.

[0104] 5. By granting regulatory agencies access to credit information inquiry and evidence storage through a blockchain explorer, a global and transparent audit channel is provided to regulatory agencies, enhancing the compliance of the credit information authorization process.

[0105] Figure 3 This is a schematic diagram of the credit investigation and authorization device according to an embodiment of this application. Figure 3As shown, the credit authorization device provided in this application embodiment includes: a credit authorization record creation module 210, a verification module 220, and a processing module 230.

[0106] The credit authorization record creation module 210 is used to receive credit authorization request transactions and create credit authorization records in the distributed ledger. The credit authorization record includes customer identity information, credit authorization scope and credit authorization validity period.

[0107] The verification module 220 is used to receive credit inquiry request transactions and determine whether the credit inquiry request transactions comply with the preset credit authorization verification rules based on the credit authorization records.

[0108] The processing module 230 is used to atomically update the status of the credit authorization record to "used" and generate a credit query certificate when the credit query request transaction meets the preset authorization verification rules.

[0109] In one possible embodiment, the verification module includes: a matching submodule, used to match the credit authorization scope and credit authorization validity period in the credit authorization record based on the financial institution identity information and query purpose information in the credit query request transaction; and a verification submodule, used to determine that the credit query request transaction conforms to the preset credit authorization verification rules if the query purpose information matches the credit authorization scope and the time of the credit query request transaction is within the credit authorization validity period of the credit authorization record.

[0110] In one possible embodiment, the matching submodule includes: a business type template matching unit, used to match a preset business type template according to the query purpose information, wherein the business type template contains a credit authorization scope field corresponding to the query purpose information; and a matching rule adjustment unit, used to dynamically adjust the matching rules of the credit authorization scope according to the customer credit rating in the credit query request transaction.

[0111] In one possible embodiment, the credit authorization device further includes a push module for pushing a notification of a change in credit authorization status to the client terminal node.

[0112] In one possible embodiment, the push module includes: a notification content generation submodule, used to generate notification content containing the transaction hash value of the credit inquiry request and the identity information of the financial institution when the status of the credit authorization record is updated to "used"; and a sending submodule, used to send the notification content to the client terminal node through an encrypted communication protocol.

[0113] In one possible embodiment, the credit authorization device further includes a query permission opening module, which is used to open query permissions for credit inquiry and evidence storage to regulatory agency nodes through a blockchain explorer.

[0114] In one possible embodiment, the query permission opening module includes: a setting submodule, used to set the access permission field of the credit query evidence to include the identification information of the regulatory agency node when generating the credit query evidence; and a query request legality verification submodule, used to verify the legality of the query request of the regulatory agency node.

[0115] In one possible embodiment, the credit authorization device further includes: a customer digital signature generation module, used to generate a customer digital signature through a customer terminal node; the customer digital signature is used to embed a credit authorization record.

[0116] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 4 As shown, this application embodiment provides an electronic device including a processor 301 and a memory 302. Optionally, the device further includes a communication component 303. The processor 301, memory 302, and communication component 303 are connected via a bus 304.

[0117] In the specific implementation process, the memory 302 stores code, and the processor 301 runs the code stored in the memory 302 to execute the method of the above method embodiment.

[0118] The specific implementation process of processor 301 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0119] In the above Figure 4 In the illustrated embodiments, it should be understood that the processor 301 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0120] The memory 302 may include high-speed RAM memory, and may also include non-volatile memory (NVM), such as at least one disk storage.

[0121] Bus 304 can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Bus 304 can be divided into address bus, data bus, control bus, etc. For ease of illustration, the bus 304 in the accompanying drawings of this application is not limited to only one bus or one type of bus.

[0122] This application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the methods described in the above-described method embodiments.

[0123] The aforementioned computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0124] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0125] This application provides a computer program product, including a computer program that, when executed by a processor, implements the methods provided in any of the embodiments described above.

[0126] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.

[0127] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0128] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.

[0129] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.

[0130] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.

[0131] If the integrated unit / module is implemented as a software program module and sold or used as an independent financial product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software financial product. This computer software financial product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0132] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.

[0133] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0134] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A credit investigation authorization method, characterized in that, include: The system receives credit authorization requests and creates credit authorization records in a distributed ledger. These credit authorization records include customer identity information, the scope of credit authorization, and the validity period of credit authorization. Receive credit inquiry request transactions and determine whether the credit inquiry request transactions comply with preset credit authorization verification rules based on the credit authorization records; If the credit inquiry request transaction meets the preset authorization verification rules, the status of the credit authorization record is atomically updated to "used" and a credit inquiry certificate is generated.

2. The method according to claim 1, characterized in that, The step of determining whether the credit inquiry request transaction conforms to the preset credit authorization verification rules based on the credit authorization record includes: Based on the financial institution's identity information and the purpose of the inquiry in the credit inquiry request transaction, the scope and validity period of the credit authorization in the credit authorization record are matched; If the query purpose information matches the credit authorization scope and the time of the credit query request transaction is within the credit authorization validity period of the credit authorization record, then the credit query request transaction is determined to comply with the preset credit authorization verification rules.

3. The method according to claim 2, characterized in that, The scope of credit authorization in the credit authorization record being matched includes: The query purpose information is matched with a preset business type template, which includes a credit authorization scope field corresponding to the query purpose information; The matching rules for the scope of credit information authorization are dynamically adjusted based on the customer's credit rating in the credit information inquiry request transaction.

4. The method according to any one of claims 1-3, characterized in that, After updating the status of the credit authorization record to "used", the method further includes: Push notifications of changes in credit authorization status to client terminal nodes.

5. The method according to claim 4, characterized in that, The notification of credit authorization status change to the client terminal node includes: When the status of the credit authorization record is updated to "used", a notification is generated containing the transaction hash value of the credit inquiry request and the identity information of the financial institution. The notification content is sent to the client terminal node using an encrypted communication protocol.

6. The method according to any one of claims 1-3, characterized in that, After generating the credit inquiry evidence, the method further includes: The blockchain explorer grants regulatory agency nodes access to query the credit information and evidence.

7. The method according to claim 6, characterized in that, The provision of access to the credit information inquiry and evidence storage to regulatory agency nodes via a blockchain explorer includes: When generating the credit inquiry evidence, the access permission field of the credit inquiry evidence is set to include the identification information of the regulatory agency node; Verify the legitimacy of the query request from the regulatory agency node.

8. The method according to any one of claims 1-3, characterized in that, Before creating the credit authorization record, the method further includes: A customer digital signature is generated through a customer terminal node; the customer digital signature is used to embed the credit authorization record.

9. A credit authorization device, characterized in that, include: The credit authorization record creation module is used to receive credit authorization request transactions and create credit authorization records in the distributed ledger. The credit authorization record includes customer identity information, credit authorization scope, and credit authorization validity period. The verification module is used to receive credit inquiry request transactions and determine whether the credit inquiry request transaction conforms to the preset credit authorization verification rules based on the credit authorization record. The processing module is used to atomically update the status of the credit inquiry request transaction to "used" and generate a credit inquiry certificate when the credit inquiry request transaction meets the preset authorization verification rules.

10. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 8.

12. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 8.