A method, system and device for processing merchant registration information

By dynamically classifying the privacy levels of merchant registration information and implementing differentiated encryption and verification, the problems of insufficient security for highly sensitive information and imprecise compliance management in existing technologies are solved, achieving a balance between information security and compliance, and reducing the risk of leakage and system overhead.

CN122153965APending Publication Date: 2026-06-05GUANGZHOU HELIBAO PAYMENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGZHOU HELIBAO PAYMENT TECH CO LTD
Filing Date
2026-04-08
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

The current methods for processing merchant registration information lack the ability to dynamically determine privacy levels, resulting in insufficient security protection for highly sensitive information, excessive processing of ordinary information, and imprecise compliance management, which easily leads to risks of information leakage, tampering, and compliance penalties.

Method used

Privacy levels are dynamically assigned based on the type of registration information, and differentiated encryption is implemented. This is combined with compliance verification, including asymmetric encryption, symmetric encryption, and lightweight encryption, to ensure the security and compliance of information, and to carry out differentiated storage and destruction.

Benefits of technology

It achieves enhanced security protection for highly sensitive information, reduces the risk of leakage and tampering, avoids excessive processing of ordinary information, reduces system overhead, and improves registration processing efficiency and compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122153965A_ABST
    Figure CN122153965A_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a kind of processing method, system and equipment of merchant registration information, the method comprises: receiving the registration information of multiple types uploaded by merchant;According to the type of the registration information, dynamically determine the comprehensive sensitivity of each type registration information;According to the comprehensive sensitivity of each type registration information, determine the privacy level of each type registration information;According to the privacy level of each type registration information, the differential encryption processing is carried out to each type registration information, and encrypted registration information is obtained;The compliance verification is carried out to the encrypted registration information, and verification result is obtained;The verification result is fed back to the merchant.The present application can dynamically divide privacy level according to registration information type, implement differential encryption, both intensify security protection to high sensitive information, reduce the risk of leakage and tampering, avoid ordinary information excessive processing, reduce system overhead.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of merchant registration technology, and in particular to a method, system and device for processing merchant registration information. Background Technology

[0002] With the rapid development of the digital economy, the digitalization of merchant registration on various platforms is constantly improving. Merchants need to upload multiple types of information during the registration process. This information includes both publicly available basic business data and highly sensitive privacy and compliance data. The diversity of information types and the differences in sensitivity are significant.

[0003] Currently, most existing merchant registration information processing methods adopt a unified processing strategy, performing the same encryption, verification, and storage operations on all registration information. This not only fails to provide strong security protection for highly sensitive information, which can easily lead to data security risks such as information leakage and tampering, but also causes excessive processing of ordinary information, increasing the system's computing and storage costs and reducing registration processing efficiency.

[0004] Meanwhile, compliance and regulatory requirements for merchant registration information are becoming increasingly stringent. Multi-dimensional regulatory rules, including personal information protection, business compliance, and anti-money laundering, have placed more refined demands on the collection, storage, use, and destruction of information. However, existing technologies lack the ability to dynamically determine the privacy level of information and cannot achieve differentiated full lifecycle management based on factors such as information type, application scenario, and compliance risks, which can easily lead to compliance penalties for platforms.

[0005] Furthermore, existing merchant registration information verification processes mostly focus only on the authenticity of the information itself, without combining the compliance of the encrypted text for dual verification. The encryption and verification processes are disconnected, making it difficult to guarantee the integrity, validity, and traceability of the encrypted information. Moreover, the information storage and destruction processes are not linked to the privacy level, resulting in problems such as improper retention and incomplete destruction of sensitive information. Summary of the Invention

[0006] The technical problem to be solved by the embodiments of the present invention is to provide a method, system and device for processing merchant registration information, which can dynamically classify privacy levels according to the type of registration information and implement differentiated encryption, thereby strengthening the security protection of highly sensitive information, reducing the risk of leakage and tampering, and avoiding excessive processing of ordinary information, thus reducing system overhead.

[0007] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows: A method for processing merchant registration information includes: Receive various types of registration information uploaded by merchants; Based on the type of registration information, the overall sensitivity of each type of registration information is dynamically determined; The privacy level of each type of registration information is determined based on the overall sensitivity of the information. Based on the privacy level of each type of registration information, the registration information of each type is subjected to differentiated encryption processing to obtain encrypted registration information; The encrypted registration information is verified for compliance, and the verification result is obtained; The verification results are then fed back to the merchant.

[0008] Optionally, based on the type of registration information, the overall sensitivity of each type of registration information can be dynamically determined, including: according to Dynamically determine the overall sensitivity of each type of registration information; in, S i To assess the overall sensitivity of various types of registration information, i =1, 2, ..., n , n The number of registration information for each type, A i The baseline score for each type of registration information, B i Assign type weights to each type of registration information. C i Dynamic weights are assigned to different types of registration information for each scenario. D i The number of compliance risk factors for each type of registration information. E i To standardize the compliance risk coefficient for all types of registration information, F i The lifecycle value coefficient for each type of registration information.

[0009] Optionally, the privacy level of each type of registration information is determined based on the overall sensitivity of the information, including: according to Determine the privacy level of each type of registration information; in, S i To assess the overall sensitivity of various types of registration information, i =1, 2, ..., n , n The number of registration information for each type, H 1 is the first threshold. H 2 is the second threshold.

[0010] Optionally, based on the privacy level of each type of registration information, differentiated encryption processing is performed on each type of registration information to obtain encrypted registration information, including: If the privacy level of each type of registration information is core sensitive level, the registration information is processed using the first encryption strategy to obtain the first encrypted registration information; If the privacy level of each type of registration information is sensitive, the registration information is processed using a second encryption strategy to obtain second encrypted registration information; If the privacy level of each type of registration information is normal, the registration information is processed using a third encryption strategy to obtain third encrypted registration information; The first encrypted registration information, the second encrypted registration information, and the third encrypted registration information are integrated to obtain the encrypted registration information.

[0011] Optionally, the first encrypted registration information, the second encrypted registration information, and the third encrypted registration information are integrated to obtain the encrypted registration information, including: Verify the validity of the first encrypted registration information, the second encrypted registration information, and the third encrypted registration information; The verified first encrypted registration information, second encrypted registration information, and third encrypted registration information are integrated into a unified data structure according to the type classification system of the registration information to obtain the encrypted registration information.

[0012] Optionally, the encrypted registration information is subjected to compliance verification to obtain the verification result, including: The encrypted registration information is then verified for format compliance to obtain a format compliance result. Based on the privacy level and type of the registration information, the encrypted registration information that passed the format compliance test is subjected to differential verification to obtain the verification result.

[0013] Optionally, the above methods also include: Based on the verification results and preset retention rules, the encrypted registration information is stored in a differentiated manner; When the preset destruction trigger conditions are met, the registration information is destroyed in a differentiated manner according to the privacy level of each type of registration information.

[0014] Embodiments of the present invention provide a merchant registration information processing system, comprising: The send / receive module is used to receive various types of registration information uploaded by merchants; The processing module is used to dynamically determine the overall sensitivity of each type of registration information based on the type of registration information; determine the privacy level of each type of registration information based on the overall sensitivity of the registration information; perform differentiated encryption processing on each type of registration information based on the privacy level of the registration information to obtain encrypted registration information; perform compliance verification on the encrypted registration information to obtain verification results; and feed back the verification results to the merchant.

[0015] Embodiments of the present invention also provide a computing device, comprising: One or more processors; A storage device for storing one or more programs that, when executed by one or more processors, cause the one or more processors to perform the method as described above.

[0016] Embodiments of the present invention also provide a computing device readable storage medium storing a program that, when executed by a processor, implements the method described above.

[0017] The above-described solutions of the embodiments of the present invention have at least the following beneficial effects: The above-described solution in this invention dynamically classifies privacy levels based on the type of registration information and implements differentiated encryption. This strengthens security protection for highly sensitive information, reduces the risk of leakage and tampering, and avoids excessive processing of ordinary information, reducing system overhead. Simultaneously, it combines privacy levels to achieve refined compliance management, reducing the risk of regulatory penalties; and it links encryption with compliance verification to ensure the integrity, validity, and traceability of encrypted information, achieving a balance between security, efficiency, and compliance in merchant registration information. Attached Figure Description

[0018] Figure 1 This is a flowchart illustrating the merchant registration information processing method provided in an embodiment of the present invention.

[0019] Figure 2 This is a schematic diagram of the modules of the merchant registration information processing system provided in an embodiment of the present invention. Detailed Implementation

[0020] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0021] like Figure 1 As shown, an embodiment of the present invention provides a method for processing merchant registration information, including: Step 11: Receive various types of registration information uploaded by merchants; Step 12: Dynamically determine the overall sensitivity of each type of registration information based on the type of registration information; Step 13: Determine the privacy level of each type of registration information based on the overall sensitivity of each type of registration information; Step 14: Based on the privacy level of each type of registration information, perform differentiated encryption processing on each type of registration information to obtain encrypted registration information; Step 15: Verify the compliance of the encrypted registration information and obtain the verification result; Step 16: Feedback the verification result to the merchant.

[0022] In this embodiment, privacy levels are dynamically categorized based on the type of registration information, and differentiated encryption is implemented. This strengthens security protection for highly sensitive information, reducing the risk of leakage and tampering, while avoiding excessive processing of ordinary information and reducing system overhead. Simultaneously, privacy levels enable refined compliance management, reducing the risk of regulatory penalties. Encryption and compliance verification are linked to ensure the integrity, validity, and traceability of encrypted information, achieving a balance between security, efficiency, and compliance in merchant registration information.

[0023] In an optional embodiment of the present invention, step 11 involves receiving various types of registration information uploaded by the merchant. Specifically, the types of registration information include license and qualification information, identity information, basic business information, and other supplementary information. The license and qualification information may include: business license information, business permit information, and industry qualification certificate information. The identity information may include: the ID card information of the legal representative / operator of the business entity, facial biometric information, communication information, and bank account information. The basic business information may include: the business entity name, business address information, business scope information, business scale information, and contact information. The other supplementary information may include: business transaction records, cooperation agreement information, and tax registration information.

[0024] In this embodiment, merchant registration information is finely categorized into four types, clearly defining the specific scope of each type of information. This provides a clear classification basis for information management, laying the foundation for subsequent dynamic determination of privacy levels and implementation of differentiated encryption verification, and avoiding the conflation of information. At the same time, accurately defining the content boundaries of different types of information improves the efficiency of information reception and processing, reduces information classification errors, and facilitates subsequent matching of compliance regulatory requirements by type, mitigating processing oversights and compliance risks caused by ambiguous information classification.

[0025] In an optional embodiment of the present invention, step 12, dynamically determining the comprehensive sensitivity of each type of registration information based on the type of registration information, includes: Step 121, according to Dynamically determine the overall sensitivity of each type of registration information; in, S i To assess the overall sensitivity of various types of registration information, i =1, 2, ..., n , n The number of registration information for each type, A i The baseline score for each type of registration information, B i Assign type weights to each type of registration information. C i Dynamic weights are assigned to different types of registration information for each scenario. D i The number of compliance risk factors for each type of registration information. E i To standardize the compliance risk coefficient for all types of registration information, F i The lifecycle value coefficient for each type of registration information; Specifically A i The information is categorized into 5 levels (2-10) based on its core attributes, which forms the basis of inherent sensitive attributes. B i Set a fixed weight (0.4-0.9) for major categories to emphasize their importance; C i The scene fluctuation coefficient is 0.5-1.5, and the highest value is taken when multiple scenes are superimposed. D i Counted by the actual number of associated compliance risk factors; E i The fixed baseline coefficient is 0.2 (which can be adjusted according to the risk control level). F i Assign values ​​based on the information lifecycle (1.0-2.0), with higher coefficients for longer lifecycles; The scenarios for each type of registration information can include: industry-specific scenarios, registration processing scenarios, merchant entity scenarios, compliance and supervision scenarios, information usage scenarios, and system operation scenarios. The compliance risk factors for each type of registration information may include: personal information protection risk factors, business compliance risk factors, tax compliance risk factors, industry regulatory risk factors, anti-money laundering risk control risk factors, and data security risk factors. The lifecycle of each type of registration information may include: one-time verification period, short-term retention period, long-term validity period, and permanent retention period.

[0026] In this embodiment, a multi-dimensional quantitative formula is used to calculate comprehensive sensitivity, incorporating influencing factors such as inherent information attributes, type weights, scenarios, compliance risks, and lifecycles into the evaluation. This transforms sensitivity assessment from a subjective qualitative approach to an objective quantitative one, resulting in more accurate, quantifiable, and traceable results. The assignment and definition of each factor are clearly defined. A i , B i Anchoring information based on sensitive attributes, C i Dynamically adjusts to adapt to different scenarios. D i , E i Quantify the impact of compliance risks. F i By linking the lifecycle value of information, it covers all aspects of information characteristics from multiple dimensions, avoiding the one-sidedness of single-dimensional assessment. At the same time, the factor parameters can be flexibly adjusted to adapt to changes in different industries and regulatory requirements, making sensitivity determination dynamically adaptable. This provides a quantitative basis for the subsequent accurate classification of privacy levels, ensuring the rationality of differentiated privacy protection strategies from the source.

[0027] In an optional embodiment of the present invention, step 13, determining the privacy level of each type of registration information based on the overall sensitivity of the registration information, includes: Step 131, according to Determine the privacy level of each type of registration information; in, S i To assess the overall sensitivity of various types of registration information, i =1, 2, ..., n , n The number of registration information for each type, H 1 is the first threshold. H 2 is the second threshold.

[0028] In this embodiment, the quantified overall sensitivity is divided into three privacy levels using dual thresholds, providing a clear and unified quantitative standard for level determination. This three-level classification adapts to the protection needs of information with varying degrees of sensitivity. The distinction between core sensitive, sensitive, and ordinary levels accurately corresponds to subsequent differentiated encryption, verification, and storage strategies, establishing a clear level framework for differentiated management throughout the entire process. Furthermore, the thresholds can be flexibly adjusted to adapt to different business scenarios and regulatory requirements, improving the adaptability of level determination.

[0029] In an optional embodiment of the present invention, step 14 involves performing differentiated encryption processing on the registration information of each type according to the privacy level of each type of registration information to obtain encrypted registration information, including: Step 141: If the privacy level of each type of registration information is core sensitive level, the registration information is processed using the first encryption strategy to obtain the first encrypted registration information. Specifically, an asymmetric encryption algorithm (such as SM2 / SM4 combination) is used for full-field encryption, and irreversible desensitization processing is performed on key identifier fields. During the encryption process, a unique encryption identifier, encryption timestamp, and merchant entity association code are added to the information. After encryption is completed, a unique verification digest is generated. After verification, the first encrypted registration information is formed, and the encryption algorithm, key version, operation nodes, and other full-process logs are recorded. It can be done The first encrypted registration information is obtained; in, EC s This is the first encrypted registration information. I s For core sensitive original information, E all This is a full-field encryption function. T s To I s Irreversible desensitization of key identifier fields Asy It is an asymmetric encryption algorithm. K uni To ensure full-process encrypted log verification, a dedicated verification digest of logs containing information such as encryption algorithm, key version, and operation node is used for verification. Des Additional processing is applied to encrypted information, including adding a unique encrypted identifier, an encrypted timestamp, and a business entity association code; Step 142: If the privacy level of each type of registration information is sensitive, the registration information is processed using a second encryption strategy to obtain second encrypted registration information. Specifically, a general symmetric encryption algorithm is used for overall encryption, and the core subfields are partially masked and desensitized. After encryption, a simplified verification code is generated. After verifying that the data integrity is normal, the second encrypted registration information is formed. The encryption range and masking rules are marked for this type of information, and the corresponding privacy level label is associated with it. At the same time, the usage record of the encryption key is retained. It can be done The second encrypted registration information is obtained. in, EC m This is the second encrypted registration information. I m This is sensitive raw information. E wh For sensitive raw information I m The overall encryption function, M s To I mPartial masking and desensitization of core subfields. Sym It is a general symmetric encryption algorithm. K sim This is a simplified verification code, generated after verifying data integrity, and it also retains a record of encryption key usage. Lab This process involves labeling encrypted information, including the encryption range, masking rules, and privacy level tags. Step 143: If the privacy level of each type of registration information is ordinary, the registration information is processed using a third encryption strategy to obtain third encrypted registration information. Specifically, a lightweight symmetric encryption algorithm or format encryption method is used for basic processing, without additional desensitization, and only the information is encrypted to prevent tampering. After completion, the data format and integrity are quickly verified. Once verified, the third encrypted registration information is formed, and it is marked with a basic encryption identifier and privacy level. Log recording is simplified, and only the encryption operation time and basic node information are retained. It can be done The second encrypted registration information is obtained. in, EC m This is the second encrypted registration information. I m This is sensitive raw information. E wh For sensitive raw information I m The overall encryption function, M s To I m Partial masking and desensitization of core subfields. Sym It is a general symmetric encryption algorithm. K sim This is a simplified verification code, generated after verifying data integrity, and it also retains a record of encryption key usage. Lab This process involves labeling encrypted information, including the encryption range, masking rules, and privacy level tags. Step 144: Integrate the first encrypted registration information, the second encrypted registration information, and the third encrypted registration information to obtain the encrypted registration information; including: Step 1441: Verify the validity of the first encrypted registration information, the second encrypted registration information, and the third encrypted registration information; Step 1442: The verified first encrypted registration information, second encrypted registration information, and third encrypted registration information are integrated into a unified data structure according to the type classification system of the registration information to obtain the encrypted registration information; Specifically, the verification codes / digests of the first, second, and third encrypted registration information are first uniformly verified to confirm that the encrypted information is unaltered and complete. Then, according to the classification system of merchant registration information types, the three types of encrypted information are integrated into a unified encrypted data structure, retaining the original type identifier, privacy level label, and encryption strategy type for each piece of encrypted information. After integration, a unified verification master code for the overall encrypted registration information is generated, and an integrated list is also generated to record the quantity of each type of encrypted information and the associated merchant identifier, forming a complete and traceable encrypted registration information dataset.

[0030] In this embodiment, differentiated encryption is implemented according to privacy levels. Core sensitive information uses high-strength asymmetric encryption + irreversible desensitization, sensitive information uses symmetric encryption + partial masking, and ordinary information uses only lightweight encryption. This approach accurately protects highly sensitive information while avoiding resource waste caused by over-encryption of low-sensitivity information, balancing security and efficiency. After encryption, a unique identifier, timestamp, and verification code are added. During integration, unified verification is performed, and a total verification code and list are generated, ensuring traceability and verifiability throughout the encryption process and preventing data tampering or loss. The tiered encryption strategy adapts to the protection needs of different levels of information, while unified integration ensures the integrity of the data structure, providing a secure and standardized encrypted data foundation for subsequent information storage, use, and verification, significantly reducing the risk of information leakage and tampering.

[0031] In an optional embodiment of the present invention, step 15, which involves verifying the compliance of the encrypted registration information to obtain a verification result, includes: Step 151: Perform format compliance verification on the encrypted registration information to obtain format compliance results. Specifically, perform format compliance verification on the encrypted registration information by first extracting the ciphertext structure, encryption strategy identifier, check code format, required fields, log association information, and other format features of each encrypted information. Compare these features item by item with the preset encrypted information format specification library for each privacy level to verify core indicators such as ciphertext length, identifier matching degree, field integrity, and check code validity. Classify and record the verification results: Information marked as passing is pushed to Step 152 for differentiated verification; Information marked as failing generates a structured anomaly report, specifying the anomaly type, anomaly fields, and compliance standards. Classify and process the anomaly according to its level. Severe format anomalies (ciphertext failure, check code error, etc.) are returned to the encryption stage for targeted reprocessing. Minor format anomalies (non-core log missing, etc.) trigger the automatic completion mechanism in the encryption stage. After completion, a second format verification is completed. If the second verification passes, it is pushed to Step 152; if it still fails, it is returned and the anomaly details are fed back. Step 152: Based on the privacy level and type of the registration information, perform differentiated verification on the encrypted registration information whose format compliance result is passed, and obtain the verification result; Specifically, if the type of registration information is identity information and the privacy level is core sensitive level, then the compliance of the national cryptographic level asymmetric encryption algorithm of the registration information, the integrity of the execution of the irreversible desensitization rules, the consistency of the association between the encrypted unique identifier and the merchant entity, the integrity of the encryption process log, and the verification that the core fields have not been tampered with after the ciphertext is decrypted and match the official filing information are verified. If the registration information is of the type of certificate or qualification and the privacy level is core sensitive level, then verify the consistency between the encrypted registration information and the original filing information of the pre-approval license for special industries, verify the verifiability of the encrypted core fields such as the scope of the certificate or qualification and the validity period, check the access control record of the encryption key, and verify the effectiveness of the anti-tampering verification code. If the type of the registration information is other supplementary and the privacy level is core sensitive level, then verify the integrity of the encrypted encapsulation of the registration information, check the compliance of the desensitization of core numerical fields such as large-amount business transactions and core tax data, and verify the accuracy of the association between the encrypted data and the merchant entity. If the type of the registration information is other supplementary and the privacy level is sensitive, then verify the effectiveness of the symmetric encryption algorithm of the registration information, check the masking and anonymization range of core fields such as regular business transactions and cooperation agreements, verify the effectiveness of the ciphertext anti-tampering verification code, and check the integrity of the encrypted basic log. If the type of registration information is a certificate or qualification certificate and the privacy level is sensitive, then verify the normal decryptability of the ciphertext after symmetric encryption of the registration information, verify the compliance of masking and desensitization of fields such as certificate number and registration address, and verify the matching of encrypted information with fields in the basic business registration database. If the registration information is classified as basic business information and its privacy level is sensitive, then verify the lightweight symmetric encryption and anti-tampering effect of the registration information, check the partial masking and anonymization of core fields such as core contact information and store detailed address, and verify the matching between information identifiers and actual content. If the registration information is of the basic business type and the privacy level is the ordinary level, then verify the light encryption or format encryption anti-tampering effect of the registration information, check the matching of basic identifiers such as privacy level and type encoding with the actual information, and verify that the ciphertext can be deciphered normally and that no required fields are missing. If the registration information is of the type of certificate or qualification and the privacy level is ordinary, then verify the compatibility of the encryption format of the registration information with the preset algorithm, check the integrity of information such as store filing photos and ordinary industry filing receipts, and confirm that the information is not missing or tampered with. If the type of the registration information is other supplementary and the privacy level is normal, then verify the effectiveness of the lightweight encryption of the registration information, check the matching of information such as registration verification code receipt and simplified filing materials with the merchant registration process stage, and verify that there are no redundant or invalid fields; Overall verification result determination: If any type of verification fails in the core sensitive information, the overall verification is directly determined to fail, and a detailed anomaly report is generated; if all core sensitive information passes, and only minor anomalies exist in sensitive information, the overall verification is determined to pass, and a rectification prompt is marked; if serious anomalies such as encryption failure or data tampering occur in sensitive information, the overall verification is determined to fail; if both core sensitive information and sensitive information pass, and only ordinary information has anomalies, the overall verification is determined to pass, and only the anomaly details are recorded for subsequent optimization.

[0032] In this embodiment, format compliance verification is performed first. Anomalies are screened by comparing against a specification library, categorized by level, and handled with automatic completion and targeted reprocessing. This ensures the standardization of encrypted information formats from the source, reducing the invalidity of subsequent verifications. Then, differentiated in-depth verification is conducted by combining privacy level and information type. Verification dimensions and standards are customized for different combinations, achieving precise and refined verification and avoiding oversights caused by a one-size-fits-all approach. Simultaneously, a tiered overall judgment rule is established: strict control for core sensitive levels, flexible handling for sensitive levels, and lenient recording for ordinary levels. This approach safeguards the core bottom line of data security and compliance while improving overall verification efficiency. Verification records and anomaly reports are retained throughout the entire process, ensuring traceability of verification and providing data support for subsequent encryption and management optimization.

[0033] In an optional embodiment of the present invention, in step 16, the verification result is fed back to the merchant. Specifically, the overall verification conclusion (pass / fail) of the encrypted registration information and the detailed verification results of each type of information are integrated, and a standardized verification feedback report is generated according to a preset template. The report clearly marks the type of abnormal information, the privacy level, and the specific abnormal problem. The feedback report is pushed to the corresponding merchant's operation interface / person in charge through the original channel through which the merchant uploaded the registration information (online self-registration terminal / offline counter / third-party agent terminal), and the result notification is sent to the contact information reserved by the merchant at the same time. If the verification is passed, the report informs the merchant of the subsequent registration process nodes and operation requirements. If the verification fails, the submission channel and feedback time limit for rectification information are specified. The system records the time, channel, merchant's viewing status, and notification delivery status of the result feedback throughout the process, forming a feedback log for retention to ensure that the feedback process is traceable.

[0034] In this embodiment, the standardized feedback report clearly presents the verification conclusions and anomaly rectification requirements, allowing merchants to quickly understand the issues and handling directions, thus improving rectification efficiency. Notifications are sent via the original upload channel and using pre-reserved contact information to ensure timely and accurate delivery of results, avoiding information transmission errors. Clearly defined follow-up processes or rectification channels for "pass" and "fail" results ensure a smoother merchant registration process. The entire feedback process is recorded and logged, enabling traceability of feedback, facilitating subsequent verification and process optimization, and providing more complete end-to-end management of merchant registration information processing.

[0035] In an optional embodiment of the present invention, the method further includes: Step 17: Based on the verification results and preset retention rules, store the encrypted registration information in a differentiated manner; Specifically, encrypted registration information that passes verification is stored in different tiers according to privacy level: core sensitive information is stored in physically isolated encrypted storage servers, using ciphertext for independent storage and with multi-access control; sensitive information is stored in a dedicated encrypted database, with database sharding and table partitioning and access log auditing enabled; and ordinary information is stored in a regular encrypted storage area with basic anti-tampering protection enabled. Storage periods are matched according to information type and lifecycle: information with a one-time verification period is only temporarily stored in the cache and is cleared according to regulations after verification; information with a short retention period is marked with a storage expiration time and is automatically archived upon expiration; information with a long validity period and a permanent retention period is stored according to type and data backups are performed regularly. For encrypted registration information that fails verification, in addition to retaining the abnormal verification report, the encrypted registration information will only be temporarily stored in the rectification area. After the merchant completes the rectification and passes the verification, it will be officially stored according to the above rules. If it is not processed within the rectification period, the temporary storage area will be cleared according to the regulations. When storing all encrypted registration information, the original type identifier, privacy level label, encryption policy type and verification result identifier will be retained to achieve accurate traceability and management of stored information. Step 18: When the preset destruction trigger condition is met, the registration information is destroyed in a differentiated manner according to the privacy level of each type of registration information. Specifically, the system monitors the storage status of encrypted registration information. When preset destruction trigger conditions are met (including information lifecycle expiration, merchant registration failure exceeding the rectification period, merchant completion of deregistration, and destruction instructions required by regulators), differentiated destruction processing is performed based on the three privacy levels of the registration information: core sensitivity level, sensitive level, and ordinary level, combined with the information type. Core sensitive information (identity information, core certificates, core supplementary information): The ciphertext in the storage medium is overwritten multiple times using an irreversible data overwriting algorithm. At the same time, all associated encrypted logs, access records, and backup data are deleted. After destruction, a destruction verification report is generated to confirm that the data cannot be recovered. Sensitive information (ordinary licenses, routine supplements, sensitive basic business information): perform direct deletion of encrypted data + clean up database indexes, delete local cache and non-core backups, and check the data access link after destruction to ensure that there are no residual data fragments; For general information (basic business operations, simplified supplementary information, and general licenses): a standard data deletion mechanism is used to clean up encrypted information in the storage area, and the storage ledger is updated synchronously to mark the destruction completion status; after all levels of information are destroyed, a destruction log is generated that includes the information type, privacy level, destruction time, destruction method, operator, and verification result, and is linked to and retained in the merchant's registration file; the destruction log of core sensitive information must undergo multiple audits and confirmations to ensure that the destruction process complies with compliance requirements.

[0036] In this embodiment, differentiated storage is implemented based on privacy level, verification results, and lifecycle. Dedicated storage tiers and timeframes are matched to different levels of information. Core sensitive information is physically isolated to enhance security, and temporary information is promptly cleaned up. This ensures data storage security while avoiding resource waste, and all information identifiers are retained for accurate traceability. Upon triggering the destruction condition, differentiated destruction is performed according to privacy level. Core sensitive information is irreversibly and completely erased. Each level retains standardized destruction logs, and core-level data undergoes multiple reviews to ensure compliant destruction. The entire storage and destruction process is linked to privacy levels, enabling differentiated management of merchant information throughout its lifecycle. This mitigates the risks of improper retention and incomplete destruction of sensitive information, meeting regulatory compliance requirements.

[0037] Example 1 This embodiment uses the registration of individual catering businesses handled at offline counters as an application scenario, specifically including: Step 21: Receive various types of registration information uploaded by merchants through offline counters, including identity information such as legal person's ID card, facial recognition information, and legal person's bank card; licenses and qualifications such as business license and food business license; basic business information such as merchant name, business address, business scope, and store contact information; and other supplementary information such as store lease contract, tax registration information, and registration application receipt. Step 22: Based on the type of registration information, dynamically determine the overall sensitivity of each type of registration information and classify its privacy level; in this embodiment, the formula for calculating the overall sensitivity is: Among them, the uniform coefficient of compliance risk E i The value is set to 0.2; this sets the first threshold for privacy level determination. H 1=30, second threshold H 2=60, which is the overall sensitivity. S i ≥60 is the core sensitivity level, 30≤ S i <60 is considered a sensitive level. S i <30 is considered a standard level; Assign values ​​to each type of information and calculate the overall sensitivity: For corporate bank card information, benchmark score A i =10, type weight B i =0.9, scene dynamic weight C i =1.5, number of compliance risk factors D i =6, Lifetime Value Coefficient F i =2.0, substituting into the calculation yields S i =10×0.9×1.5×(1+6×0.2)×2.0=59.4, which is classified as a core sensitive level; Based on the legal representative's ID card information, the benchmark score A i =10, type weight B i =0.9, scene dynamic weight C i =1.5, number of compliance risk factors D i =5, Lifetime Value Coefficient F i =2.0, substituting into the calculation yields S i =10×0.9×1.5×(1+5×0.2)×2.0=54.0, which is classified as sensitive. Based on business license information, benchmark score A i =9, type weight B i =0.8, scene dynamic weight C i =1.5, number of compliance risk factors D i =4, Lifetime Value Coefficient F i =1.8, substituting into the calculation, we get S i =9×0.8×1.5×(1+4×0.2)×1.8=34.0, which is classified as sensitive. Based on food business license information, the benchmark score A i =9, type weight B i =0.8, scene dynamic weight C i =1.5, number of compliance risk factors D i =5, Lifetime Value Coefficient Fi =1.8, substituting into the calculation, we get S i =9×0.8×1.5×(1+5×0.2)×1.8=38.9, which is classified as sensitive. Based on business address information, the benchmark score A i =3, type weight B i =0.5, scene dynamic weight C i =1.0, Number of compliance risk factors D i =1, Lifetime Value Coefficient F i =1.2, substituting into the calculation yields S i =3×0.5×1.0×(1+1×0.2)×1.2=2.16, therefore it is classified as ordinary level; Based on merchant name information, the benchmark score A i =2, type weight B i =0.4, scene dynamic weight C i =1.0, Number of compliance risk factors D i =1, Lifetime Value Coefficient F i =1.0, substituting into the calculation yields S i =2×0.4×1.0×(1+1×0.2)×1.0=0.96, which is classified as ordinary level; Regarding store lease contract information, benchmark score A i =6, type weight B i =0.6, scene dynamic weight C i =1.2, Number of compliance risk factors D i =3, Life Cycle Value Coefficient F i =1.5, substituting into the calculation, we get S i =6×0.6×1.2×(1+3×0.2)×1.5=9.72, which is classified as sensitive. In summary, the following information is classified as core sensitive: legal entity bank cards and facial recognition information within the identity information category; legal entity ID cards, business licenses and food business permits within the certificate and qualification category, and store lease contracts within the other supplementary category are sensitive; and merchant names, business addresses, business scope, store contact information, and registration application receipts within the basic business category are ordinary. Step 23: Based on the privacy level of each type of registration information, perform differentiated encryption processing on each type of registration information to obtain encrypted registration information; core sensitive information is fully encrypted using an asymmetric encryption algorithm combining SM2 and SM4, with irreversible desensitization processing on key fields, adding a unique encryption identifier, encryption timestamp, and merchant entity association code, generating a national cryptographic-level verification digest, and recording the entire process encryption log; sensitive information is fully encrypted using a general symmetric encryption algorithm, with masking and desensitization processing on document numbers and key contract information, generating a simplified verification code, and retaining key usage records; ordinary information is basic tamper-proof encryption using a lightweight symmetric encryption algorithm, without additional desensitization processing, marked with a basic encryption identifier, and simplified log recording; the above three types of encrypted information are validated, and after successful validation, they are integrated into a unified data structure according to the registration information type classification system, generating a unified verification master code to form complete encrypted registration information; Step 24: Perform compliance verification on the encrypted registration information and obtain the verification results. First, perform format compliance verification on all encrypted registration information, extracting features such as ciphertext structure, check code format, required fields, and encryption strategy identifiers, and comparing them item by item with the preset specification library to confirm that the ciphertext length, identifier matching degree, field integrity, and check code validity all meet the requirements, and the format compliance result is passed. Then, perform differentiated in-depth verification based on the privacy level and type of the registration information. For core sensitive information, verify the compliance of the encryption algorithm, the integrity of the irreversible desensitization rule execution, the consistency of the encryption identifier and the merchant entity association, and the integrity of the full-process encryption log. For sensitive information, verify the effectiveness of the symmetric encryption algorithm, the compliance of the mask desensitization range, the effectiveness of the ciphertext anti-tampering check code, and the integrity of the basic log. For ordinary information, verify the lightweight encryption anti-tampering effect, the basic identifier matching, and the decipherability of the ciphertext. After verification, all information is found to be normal, and the overall verification result is passed. Step 25: Feedback the verification results to the merchant; the offline counter staff will issue a paper verification report to the merchant and send a verification result notification to the merchant's registered mobile phone number at the same time, informing the merchant that they can complete the registration and filing and activate their business rights. The system records the feedback time, feedback method and merchant confirmation result, forming a traceable feedback log. Step 26: Based on the verification results and preset retention rules, differentiate the storage of encrypted registration information; core sensitive information is stored in a physically isolated encrypted storage server, with dual-access control set up, permanent retention and regular data backup; sensitive information is stored in a dedicated encrypted database, using a sharded database and table approach with access log auditing enabled, and archiving time is marked according to short-term retention periods; ordinary information is stored in a regular encrypted storage area, with basic anti-tampering protection enabled, and is retained long-term during the merchant's lifetime; all stored information retains type identifiers, privacy level labels, encryption policy types and verification result identifiers, enabling accurate traceability and management of stored information; Step 27: When the preset destruction trigger conditions are met, the registration information is destroyed in a differentiated manner according to the privacy level of each type of registration information. If the catering merchant subsequently completes the deregistration and triggers the destruction instruction, for core sensitive information, an irreversible data overwrite algorithm is used to overwrite the encrypted text in the storage medium multiple times, while deleting all associated encrypted logs, access records, and backup data. After destruction, a destruction verification report is generated and undergoes multiple reviews. For sensitive information, encrypted data is directly deleted and database indexes are cleaned up, while local cache and non-core backups are deleted, and the data access link is checked to ensure no residue remains. For ordinary information, a standard data deletion mechanism is used to clean up the encrypted information in the storage area, and the storage ledger is updated synchronously and the destruction completion status is marked. After all levels of information are destroyed, a destruction log containing the information type, privacy level, destruction time, destruction method, operator, and verification result is generated and stored in association with the merchant's deregistration file.

[0038] This invention achieves registration information management through refined classification, dynamic privacy level determination, and differentiated processing throughout the entire process. First, information is classified and its overall sensitivity is quantified to accurately determine three privacy levels. Then, differentiated encryption and verification strategies are matched, balancing the security protection of highly sensitive information with the processing efficiency of ordinary information, avoiding resource waste. Simultaneously, differentiated storage and destruction are implemented based on verification results, achieving full lifecycle management of information and aligning with multi-dimensional compliance and regulatory requirements. Full-process log retention and traceability address the security risks and compliance vulnerabilities of traditional unified processing, reduce system computing and storage costs, improve registration processing efficiency, and allow merchants to clearly understand verification results and rectification directions, thus optimizing the registration experience.

[0039] like Figure 2 As shown, an embodiment of the present invention provides a merchant registration information processing system 20, comprising: The transceiver module 21 is used to receive various types of registration information uploaded by merchants; The processing module 22 is used to dynamically determine the overall sensitivity of each type of registration information based on the type of registration information; determine the privacy level of each type of registration information based on the overall sensitivity of the registration information; perform differentiated encryption processing on each type of registration information based on the privacy level of each type of registration information to obtain encrypted registration information; perform compliance verification on the encrypted registration information to obtain verification results; and feed back the verification results to the merchant.

[0040] Optionally, based on the type of registration information, the overall sensitivity of each type of registration information can be dynamically determined, including: according to Dynamically determine the overall sensitivity of each type of registration information; in, S i To assess the overall sensitivity of various types of registration information, i =1, 2, ..., n , n The number of registration information for each type, A i The baseline score for each type of registration information, B i Assign type weights to each type of registration information. C i Dynamic weights are assigned to different types of registration information for each scenario. D i The number of compliance risk factors for each type of registration information. E i To standardize the compliance risk coefficient for all types of registration information, F i The lifecycle value coefficient for each type of registration information.

[0041] Optionally, the privacy level of each type of registration information is determined based on the overall sensitivity of the information, including: according to Determine the privacy level of each type of registration information; in, S i To assess the overall sensitivity of various types of registration information, i =1, 2, ..., n , n The number of registration information for each type, H 1 is the first threshold. H 2 is the second threshold.

[0042] Optionally, based on the privacy level of each type of registration information, differentiated encryption processing is performed on each type of registration information to obtain encrypted registration information, including: If the privacy level of each type of registration information is core sensitive level, the registration information is processed using the first encryption strategy to obtain the first encrypted registration information; If the privacy level of each type of registration information is sensitive, the registration information is processed using a second encryption strategy to obtain second encrypted registration information; If the privacy level of each type of registration information is normal, the registration information is processed using a third encryption strategy to obtain third encrypted registration information; The first encrypted registration information, the second encrypted registration information, and the third encrypted registration information are integrated to obtain the encrypted registration information.

[0043] Optionally, the first encrypted registration information, the second encrypted registration information, and the third encrypted registration information are integrated to obtain the encrypted registration information, including: Verify the validity of the first encrypted registration information, the second encrypted registration information, and the third encrypted registration information; The verified first encrypted registration information, second encrypted registration information, and third encrypted registration information are integrated into a unified data structure according to the type classification system of the registration information to obtain the encrypted registration information.

[0044] Optionally, the encrypted registration information is subjected to compliance verification to obtain the verification result, including: The encrypted registration information is then verified for format compliance to obtain a format compliance result. Based on the privacy level and type of the registration information, the encrypted registration information that passed the format compliance test is subjected to differential verification to obtain the verification result.

[0045] Optionally, the processing module 22 described above is also used for: Based on the verification results and preset retention rules, the encrypted registration information is stored in a differentiated manner; When the preset destruction trigger conditions are met, the registration information is destroyed in a differentiated manner according to the privacy level of each type of registration information.

[0046] It should be noted that this device is a device corresponding to the above method. All implementation methods in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.

[0047] Embodiments of the present invention also provide a computing device, including: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method described above. All implementations in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.

[0048] Embodiments of the present invention also provide a computing device readable storage medium storing instructions that, when executed on a computing device, cause the computing device to perform the method described above. All implementations in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.

[0049] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this invention can be implemented in electronic hardware, or a combination of computing device software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0050] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0051] In the embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0052] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0053] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0054] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computing device-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computing device software product is stored in a storage medium and includes several instructions to cause a computing device (which may be a personal computing device, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0055] Furthermore, it should be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent solutions of the present invention. Moreover, the steps performing the above-described series of processes can naturally be executed in the order described, but are not necessarily required to be executed in chronological order; some steps can be executed in parallel or independently of each other. Those skilled in the art will understand that all or any step or component of the method and apparatus of the present invention can be implemented in any computing device (including processors, storage media, etc.) or network of computing devices, in hardware, firmware, software, or a combination thereof. This is something that those skilled in the art can achieve using basic programming skills after reading the description of the present invention.

[0056] Therefore, the object of the present invention can also be achieved by running a program or a set of programs on any computing device. The computing device can be a known general-purpose device. Therefore, the object of the present invention can also be achieved simply by providing a program product containing program code implementing the method or apparatus. That is, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any known storage medium or any storage medium developed in the future. It should also be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent to the present invention. Furthermore, the steps performing the above series of processes can naturally be performed in the order described, but are not necessarily required to be performed in chronological order. Some steps can be performed in parallel or independently of each other.

[0057] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for processing merchant registration information, characterized in that, include: Receive various types of registration information uploaded by merchants; Based on the type of registration information, the overall sensitivity of each type of registration information is dynamically determined; The privacy level of each type of registration information is determined based on the overall sensitivity of the information. Based on the privacy level of each type of registration information, the registration information of each type is subjected to differentiated encryption processing to obtain encrypted registration information; The encrypted registration information is verified for compliance, and the verification result is obtained; The verification results are then fed back to the merchant.

2. The method for processing merchant registration information according to claim 1, characterized in that, Based on the type of registration information, the overall sensitivity of each type of registration information is dynamically determined, including: according to Dynamically determine the overall sensitivity of each type of registration information; in, S i To assess the overall sensitivity of various types of registration information, i =1, 2, ..., n , n The number of registration information for each type, A i The baseline score for each type of registration information, B i Assign type weights to each type of registration information. C i Dynamic weights are assigned to different types of registration information for each scenario. D i The number of compliance risk factors for each type of registration information. E i To standardize the compliance risk coefficient for all types of registration information, F i The lifecycle value coefficient for each type of registration information.

3. The method for processing merchant registration information according to claim 2, characterized in that, Based on the overall sensitivity of each type of registration information, the privacy level of each type of registration information is determined, including: according to Determine the privacy level of each type of registration information; in, S i To assess the overall sensitivity of various types of registration information, i =1, 2, ..., n , n The number of registration information for each type, H 1 is the first threshold. H 2 is the second threshold.

4. The method for processing merchant registration information according to claim 3, characterized in that, Based on the privacy level of each type of registration information, differentiated encryption processing is performed on each type of registration information to obtain encrypted registration information, including: If the privacy level of each type of registration information is core sensitive level, the registration information is processed using the first encryption strategy to obtain the first encrypted registration information; If the privacy level of each type of registration information is sensitive, the registration information is processed using a second encryption strategy to obtain second encrypted registration information; If the privacy level of each type of registration information is normal, the registration information is processed using a third encryption strategy to obtain third encrypted registration information; The first encrypted registration information, the second encrypted registration information, and the third encrypted registration information are integrated to obtain the encrypted registration information.

5. The method for processing merchant registration information according to claim 4, characterized in that, The encrypted registration information is obtained by integrating the first encrypted registration information, the second encrypted registration information, and the third encrypted registration information, including: Verify the validity of the first encrypted registration information, the second encrypted registration information, and the third encrypted registration information; The verified first encrypted registration information, second encrypted registration information, and third encrypted registration information are integrated into a unified data structure according to the type classification system of the registration information to obtain the encrypted registration information.

6. The method for processing merchant registration information according to claim 1, characterized in that, The encrypted registration information is verified for compliance, and the verification results are obtained, including: The encrypted registration information is then verified for format compliance to obtain a format compliance result. Based on the privacy level and type of the registration information, the encrypted registration information that passed the format compliance test is subjected to differential verification to obtain the verification result.

7. The method for processing merchant registration information according to claim 1, characterized in that, Also includes: Based on the verification results and preset retention rules, the encrypted registration information is stored in a differentiated manner; When the preset destruction trigger conditions are met, the registration information is destroyed in a differentiated manner according to the privacy level of each type of registration information.

8. A system for processing merchant registration information, characterized in that, include: The send / receive module is used to receive various types of registration information uploaded by merchants; The processing module is used to dynamically determine the overall sensitivity of each type of registration information based on the type of registration information; determine the privacy level of each type of registration information based on the overall sensitivity of the registration information; perform differentiated encryption processing on each type of registration information based on the privacy level of the registration information to obtain encrypted registration information; perform compliance verification on the encrypted registration information to obtain verification results; and feed back the verification results to the merchant.

9. A computing device, characterized in that, include: One or more processors; A storage device for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to implement the method as described in any one of claims 1 to 7.

10. A computing device readable storage medium, characterized in that, The computing device readable storage medium stores a program that, when executed by a processor, implements the method as described in any one of claims 1 to 7.