Authorization information query method and device, equipment and medium
After identity verification, an authorization information page is displayed, which supports querying and revoking authorized information. This solves the problem of users having difficulty managing personal information authorization and achieves transparent information management and improved compliance.
Patent Information
- Application Number
- CN202610788321.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-02
- Publication Date
- 2026-08-25
AI Technical Summary
In existing applications, users face difficulties in querying and managing authorized information during personal information authorization management, leading to high compliance risks and increased user disputes.
An authorization information query method and apparatus are provided. After identity verification, an authorization information page is displayed, including information of authorized users. The method supports querying, revocation, and historical record management, and adopts a reverse query mechanism and full lifecycle tracking.
It enables transparent management of users' authorization of personal information, reduces compliance risks, enhances user trust, meets legal compliance requirements, and improves data authorization transparency and user control.
Smart Images

Figure CN122634616A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, device, and medium for querying authorization information. Background Technology
[0002] Most applications on the market currently adopt a one-time privacy policy consent model for personal information authorization management. When users use the app for the first time, they need to read and agree to a lengthy privacy policy document, which typically lists in an enumerated manner the types of personal information the app may collect in different business scenarios, information collected by third-party SDKs, and information sharing situations. However, after completing the one-time authorization, it is difficult for users to query and manage the authorization status of their authorized user information. Summary of the Invention
[0003] This invention provides a method, apparatus, computer device, and medium for querying authorization information, with the aim of querying and managing the authorization status of authorized user information.
[0004] Firstly, a method for querying authorization information is provided, including: Displays an authorization query page, including an authorization information query control; In response to the authorization information query control being triggered, an identity verification prompt message is displayed, which is used to indicate the identity verification method; In response to receiving the user identity information corresponding to the authentication prompt, authentication is performed based on the user identity information; If the user identity information passes the authentication, an authorization information page corresponding to the user identity information is displayed. The authorization information page includes at least one piece of authorized user information corresponding to the user identity information.
[0005] Secondly, an authorization information query device is provided, comprising: The first page display module is used to display the authorization query page, which includes an authorization information query control; The verification prompt module is used to display an identity verification prompt message in response to the triggering of the authorization information query control. The identity verification prompt message is used to indicate the identity verification method. The authentication module is used to perform authentication based on the user identity information corresponding to the received authentication prompt information. An information display module is used to display an authorization information page corresponding to the user identity information when the user identity information passes the authentication. The authorization information page includes at least one piece of authorized user information corresponding to the user identity information, and the authorization information page also includes an authorization record query control. The information query module is used to respond to the triggering of the authorization record query control, obtain the user information to be queried for authorization record query, and query at least one authorization record corresponding to the user information to be queried; The second page display module is used to display the query results page, which includes at least one authorized record corresponding to the user information to be queried.
[0006] Thirdly, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described authorization information query method.
[0007] Fourthly, a computer-readable storage medium is provided, which stores a computer program that, when executed by a processor, implements the steps of the above-described authorization information query method.
[0008] The aforementioned methods, devices, computer equipment, and storage media for querying authorized information enable the establishment of a reverse query mechanism centered on information items and a visualized tracking system for the entire lifecycle of authorization records. This allows users to readily and intuitively grasp the authorization status of each piece of personal information. On one hand, this helps financial institutions meet compliance requirements under the Personal Information Protection Law and regulations regarding "providing convenient channels for withdrawing consent," effectively reducing compliance risks and user disputes. On the other hand, by enhancing data authorization transparency and user control, it strengthens user trust and willingness to use the service, creating a differentiated competitive advantage. Simultaneously, it promotes an overall improvement in industry privacy protection levels, laying a crucial technological foundation for the compliant circulation of data elements and the construction of a trustworthy digital financial ecosystem. Attached Figure Description
[0009] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0010] Figure 1 This is a schematic diagram illustrating the application environment of an authorization information query method according to an embodiment of the present invention. Figure 2 This is a flowchart illustrating an authorization information query method according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of an authorization information query device in one embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of a computer device according to an embodiment of the present invention; Figure 5 This is another structural schematic diagram of a computer device according to one embodiment of the present invention. Detailed Implementation
[0011] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0012] Figure 1 This is a schematic diagram illustrating the application environment of an authorization information query method according to an embodiment of the present invention. The authorization information query method provided in this embodiment of the present invention can be applied to, for example... Figure 1 In this application environment, the client communicates with the server via a network. In this embodiment, the client is a user terminal, allowing the user to interact with the client to query authorized user information. After verifying the user's identity, the client can retrieve the authorized user information and other relevant information from the server.
[0013] In this invention, the client can interact with the user through applications containing a large amount of the user's private data, such as financial service applications and smart medical services. The client can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The server can be implemented using a standalone server or a server cluster consisting of multiple servers. The invention will be described in detail below through specific embodiments.
[0014] Please see Figure 2 As shown, Figure 2 This is a schematic diagram of the authorization information query process of an authorization information query method according to an embodiment of the present invention, including the following steps S10-S60.
[0015] Step S10: Display the authorization query page, which includes the authorization information query control.
[0016] In one possible implementation, the client can display an authorization query page, including an authorization information query control, through system applications or other applications. This page is used to query the authorization information of system users for each application installed on the current system, as well as the authorization information of system users for each functional module within the current application.
[0017] Optionally, the authorization information query control can be an entry control such as a query button. Users can trigger the control by clicking it to interact with the client. For example, in this embodiment, if a financial application installed on the client displays an authorization query page including the authorization information query control, the user can access the authorization query function entry point through human-computer interaction to display the authorization query page. For instance, the user can identify the "My"—"Privacy Center" or "Security Center" menu in the financial application as the authorization query page, with the "Personal Information Authorization Query" entry point serving as the authorization information query control.
[0018] Step S20: In response to the authorization information query control being triggered, display an authentication prompt message.
[0019] In one possible implementation, when a user triggers the authorization information query control on the authorization query page by clicking or other means, the client displays an authentication prompt. This authentication prompt prompts the user to authenticate and specifies the corresponding authentication method. The display format of this authentication prompt can be the same or different for different types of authentication methods.
[0020] Optionally, the authentication methods in this application embodiment may include password verification, verification code verification, fingerprint recognition verification, and facial recognition verification, etc., and users can choose one of at least two authentication methods for authentication. The authentication prompt information may be displayed in the form of a pop-up window, a page redirection, etc.
[0021] Step S30: In response to receiving the user identity information corresponding to the authentication prompt information, perform authentication based on the user identity information.
[0022] In one possible implementation, upon receiving the user's identity information corresponding to the authentication prompt, the client performs authentication based on that information. The method and content of obtaining the user's identity information differ depending on the authentication method. For example, in password verification, the user's identity information is the preset password entered by the user. In CAPTCHA verification, the user's identity information is the dynamic CAPTCHA received on the user's mobile phone. In fingerprint recognition or interview recognition verification, the user's identity information is the user's fingerprint or facial image collected by a sensor.
[0023] Step S40: If the user's identity information passes the authentication, display the authorization information page corresponding to the user's identity information.
[0024] In one possible implementation, after verifying that the user's identity information has been authenticated, the client displays an authorization information page corresponding to the user's identity information on the front-end page. This authorization information page includes at least one piece of authorized user information corresponding to the user's identity information. Additionally, the authorization information page may also include at least one piece of unauthorized but authorizable user information corresponding to the user's identity information. This authentication process ensures that only the account holder can query their own authorization information.
[0025] Optionally, the authorization information page may also include the authorization status of each user's information, indicating whether each user's information has been authorized. Each user's information can be displayed as a list of personal information items, which may include multi-level categories. For example, it may include primary categories such as basic identity information (including name, ID number, and mobile phone number), account information (including bank card number and account number), device information (including MAC address, IMEI, and IDFA), location information, contacts, and biometric information. When a user clicks on user information that includes a subcategory, the subcategory can be further displayed as a secondary category. Alternatively, the authorization information page may also include a search box, allowing users to quickly locate the desired user information by entering keywords.
[0026] Step S50: In response to the authorization record query control being triggered, obtain the user information to be queried for authorization record query, and query at least one authorization record corresponding to the user information to be queried.
[0027] In one possible implementation, the authorization information page also includes an authorization record query control. Users can trigger this control to query authorization records for at least one authorized user. In other words, when the authorization record query control is triggered by the user, the client determines the user information to be queried based on the user's action and retrieves at least one authorization record corresponding to that user information. Then, a query results page is displayed, showing at least one authorization record corresponding to the user information being queried.
[0028] Optionally, the client can query at least one authorization record corresponding to the user information to be queried by sending a query request to the server, thereby obtaining at least one authorization record corresponding to the user information to be queried from the server. The query request generated by the client terminal may include: a user identifier, i.e., an encrypted user ID, a code of the user information to be queried, such as "ID_CARD_NUMBER", and a query timestamp. This query request can be sent to the server through an encrypted channel using national cryptographic SSL or international TLS protocols.
[0029] Step S60: Display the query results page, which includes at least one authorization record corresponding to the user information to be queried.
[0030] In one possible implementation, after receiving a query request, the server can verify the request's legitimacy (including user identity verification and request replay protection verification) and parse out the user identifier and the user information to be queried. The server can query a metadata database to obtain the mapping relationship between user information and authorization records. Using the parsed user information to be queried as an index, the server retrieves all processing activity records related to each user information in the authorization information metadata database. Each processing activity record may include at least one of the following: business scenario identifier, information usage purpose, processing method, authorized object type, name and identifier of the authorized object, default authorization validity period, and compliance basis for the processing behavior.
[0031] Optionally, the business scenario identifier may include account opening scenario, subscription scenario, and card binding scenario; the purpose of information use may include identity verification, risk assessment, etc.; the processing method may include collection and storage, collection without storage, and transmission to a third party, etc.; the authorized object type may include the App itself, third-party SDK, and cooperating financial institutions, etc.; the default authorization validity period may include one-time validity, 7 days, and permanent, etc.; the compliance basis for the processing behavior may include business necessity and user consent, etc.
[0032] Furthermore, the server can also query the user authorization record database to obtain the user's actual authorization status. The server uses a composite index of the user identifier and the user information to be queried to retrieve all authorization records for that user in the user authorization record database. Each authorization record includes: a unique authorization record ID, an information item identifier, a business scenario identifier, the authorization time, the start and end dates of the authorization validity period, and the current authorization status (valid / expired / revoked / pending confirmation). If a record's status is "revoked," the revocation time and reason for revocation must also be recorded (user-initiated revocation / authorization expired / re-authorization after system changes).
[0033] After the query process is completed on the server side, the query results are aggregated to generate a complete authorization status report for the user's information to be queried. This report may include basic information: information item name, information item category, and current overall authorization status; a scenario authorization list: listing the authorized objects, purpose of use, authorization time, authorization validity period, and current status of the information item in each scenario in tabular form; a third-party sharing list: listing which third-party organizations the information item has been shared with, the purpose of sharing, the sharing time, and whether it is still being shared; and historical change records: displaying key change events in the authorization record of the information item in a timeline format. The query results are received and displayed on the client terminal. The client receives the query results in JSON format returned by the server, parses them, and then displays the query results page to the user in a visual manner on the interface.
[0034] Optionally, the query results page may display the following: Information Item Summary Card: Displaying the information item name, overall authorization status (e.g., "2 scenarios authorized", "1 authorization about to expire"), and the time of the most recent authorization activity; Scenario Authorization Details Table: Listing detailed information for each scenario in tabular form, with each row containing columns such as "Scenario Name", "Purpose of Use", "Authorization Time", "Validity Period", "Current Status", and "Operation"; Third-Party Sharing List: Displaying a separate list of third-party organizations that have shared this information item, including organization name, sharing purpose, sharing time, and sharing scope; Timeline View: Displaying key authorization events for this information item in a timeline format (initial authorization, authorization extension, authorization expiration, authorization revocation, etc.), allowing users to intuitively understand the authorization evolution process of the information item.
[0035] In other embodiments, users can also trigger at least one authorization record on the query results page by clicking or other means. In response to the triggering of an authorization record, the client can also display authorization details information for that record. These details include at least one of the following: business scenario identifier, purpose of information use, processing method, type of authorized object, name and identifier of the authorized object, default authorization validity period, and compliance basis for the processing behavior. Optionally, the authorization details may also include at least one of the following: unique authorization record ID, information item identifier, business scenario identifier, authorization time, start and end dates of authorization validity period, and current authorization status. Furthermore, when a user triggers any authorization record, the complete original authorization agreement corresponding to that record can be displayed, which may include information about the authorizing parties, authorized information items and scope, purpose of use, authorization period, rights and obligations of both parties, and method for revoking authorization.
[0036] For at least one authorization record retrieved by the user, the user can revoke the completed authorization record as needed. To prevent accidental activation, this embodiment of the application can also provide secondary confirmation when the user initiates the revocation of an authorization record. For example, the query results page includes a revocation authorization control. When the revocation authorization control is triggered, the client can identify the corresponding authorization record to be revoked and display the revocation confirmation control for that record. Furthermore, the authorization record to be revoked is revoked when the revocation confirmation control is triggered.
[0037] For example, users can choose the granularity of revocation according to their needs on the query results page. For instance, they can revoke at the information item level: by clicking the "Revoke All Authorizations" button at the bottom of the summary card of the information item for the user information to be revoked, all authorizations for that information item in all scenarios and all third parties will be revoked at once. At the scenario level: by clicking the "Revoke Authorization" button to the right of any scenario's row in the scenario authorization details table, the authorization for that information item in a specific business scenario will be revoked. At the third-party level: by clicking the "Revoke Sharing" button to the right of any third party's row in the third-party sharing list, the authorization to share that information item with that third party will be revoked. Batch revocation: users can select the checkboxes before multiple authorization records and then click the "Batch Revocation" button to revoke the selected multiple authorizations at once.
[0038] When a user initiates a revocation request, the client sends the request and triggers secondary confirmation. The client generates a revocation request containing: a user identifier, a list of unique authorization record IDs (single or multiple records), the revocation type (information item level / scenario level / third-party level / batch), and a revocation timestamp. A secondary confirmation interface can be displayed as a revocation confirmation control via a pop-up window to clearly inform the user of the consequences of revoking the authorization (e.g., "After revocation, the transfer function will no longer use facial recognition verification and will require password verification instead"). The user reads this and confirms whether to proceed with the revocation. If the user confirms, the client sends the revocation request to the server.
[0039] Upon receiving a revocation request, the server can perform secondary identity verification on the user who sent the request: For revocation operations involving sensitive information (such as ID card information or biometric information), the user is required to provide secondary verification (such as SMS verification code or biometric identification) to confirm that the operation was initiated by the user. Simultaneously, the server verifies the validity of the authorization record ID in the request: whether it exists, belongs to the user, and is currently valid. If the authorization record has expired (e.g., expired or revoked), an error message is returned. Furthermore, a business impact assessment is performed: the impact of revoking the authorization on the user's current functionality is evaluated. If revocation would render a core function unavailable, the server returns a warning message before revocation, requiring the client to remind the user again.
[0040] After passing the above verifications, the server updates the authorization status of the corresponding record in the user authorization record database to "revoked," records the revocation time and reason, and synchronously updates the permission control table of the business systems that depend on this authorization. Optionally, a new "revocation" event record is also added to the authorization event log database, including information such as the revocation operation time, revocation method, and revocation granularity. Furthermore, relevant business systems are notified: an authorization revocation notification is sent to business systems that depend on this authorization (such as risk control engines, push services, and third-party shared interfaces), requiring them to immediately cease information processing activities based on this authorization.
[0041] After the revocation process is completed, the server sends the revocation result to the client. The client receives the revocation result returned by the server, updates the status of the corresponding authorization record in the interface to "revoked", and displays a "revocation successful" message.
[0042] In other embodiments, besides user-initiated revocation of authorization records, this application embodiment can also provide proactive warnings. That is, the server can scan the user authorization record database at preset time intervals to find authorization records that meet preset conditions and push warning notifications to the client. These warning notifications prompt the user whether to revoke the authorization record.
[0043] Optionally, authorization records that meet preset conditions may include authorization records with a remaining validity period of less than or equal to a preset threshold (e.g., 7 days, 3 days, 1 day) and a current status of "valid". Other options include authorization records where the frequency of a particular information item's recent calls has significantly increased compared to the historical average frequency (e.g., exceeding 2 standard deviations). Finally, authorization records where the usage scenario or shared object of a particular information item has changed since the user last viewed it.
[0044] When an authorization record that meets the triggering conditions is detected, the server pushes a warning notification to the client. The notification may include the warning type ("Authorization is about to expire," "Abnormal authorization usage frequency," "Authorization scope has changed"), the name of the relevant information item, the specific warning content, and suggested actions (such as "We suggest you check and confirm whether to renew"). The client displays the warning via in-app push notification or system notification. After the user clicks on the warning notification, they are automatically redirected to the authorization query page for that information item, where they can view details and decide whether to renew or revoke the authorization.
[0045] In some embodiments, the authorization query page displayed on the client also includes an authorization history query control, which allows for batch queries of authorization history by triggering the authorization history query control. That is, when the authorization history query control is triggered, the client can obtain authorization history query information including query conditions, and based on the query conditions, obtain and display the user's authorization event log. The authorization event log includes at least one authorization event, which may include at least one of the following: event identifier, event type, event occurrence time, associated information item identifier, associated business scenario identifier, associated authorization object, and event details description.
[0046] For example, users can access the authorization history function by triggering an authorization history query control. This control can be triggered by the user clicking the "View All Authorization History" or "Authorization Timeline" button on the authorization query page. After the user triggers the control, the client sends a history query request to the server. Request parameters may include: user ID, query time range (optional, such as "Last 30 Days", "Last Six Months", "All"), and authorization status filter conditions (optional, such as "All", "Valid", "Expired", "Revoked"). The server retrieves all authorization event records for the user from the authorization event log database based on the user ID and time range. Each event record includes: a unique event ID, event type (authorization / revocation / change / expiration reminder), event occurrence time, associated information item identifier, associated business scenario identifier, associated authorization object, and event details description (e.g., "User actively revoked authorization", "Authorization automatically expired").
[0047] Optionally, after receiving the authorization event returned by the server, the client can display it in a visual timeline. The timeline can be horizontal or vertical, arranged in reverse chronological order, with each event occupying a node on the timeline. Different types of events are identified by different icons (e.g., "Agree" with a green checkmark icon, "Revoke" with a red prohibition icon, and "Expiration" with an orange clock icon). Users can click on any node to expand the details card, displaying complete information about the event, including: the event occurrence time, the ID of the authorization record involved, the name of the associated information item, the name of the associated scenario, the associated authorization object, the specific content of the event, and the event triggering method (user-initiated operation / system-automatic trigger). For authorization events that are about to expire, this embodiment of the application can provide a warning on the timeline with special markings (e.g., yellow background, countdown text).
[0048] Based on this timeline, users can intuitively understand the entire process of a specific information item from its initial authorization to its current status, including: when the information item was first authorized, when the scope of authorization changed (such as authorization to a new third party), and when the authorization expired or was revoked. System-triggered authorization changes (such as requiring users to re-authorize after a privacy policy update) will also be recorded on the timeline. Furthermore, to ensure the integrity and immutability of the authorization event log, the server should digitally sign or store each authorization event log entry on the blockchain. When a user has doubts about the legality of a certain authorization, they can request to retrieve the stored record for verification, providing objective evidence for subsequent dispute resolution.
[0049] In some embodiments, this application can also dynamically generate a dynamic authorization agreement during the user information authorization process, thereby improving upon the fixed privacy policy document and introducing a dynamically assembleable authorization agreement generation mechanism. When a user queries the authorization status of a specific information item and initiates a new authorization request, the system generates a concise, focused, and easy-to-understand dynamic authorization agreement in real time based on the current information item, application scenario, third-party entity, and other information.
[0050] Optionally, the dynamic authorization agreement can also be generated through an authorization query page. This page includes an "Add Authorization" control; when the user triggers the control, the corresponding authorization request is retrieved, and a dynamic authorization agreement is generated based on that request. The dynamic authorization agreement is then displayed, and upon confirmation, a corresponding authorization record is generated and a success message is displayed.
[0051] Specifically, when a user initiates an "Add Authorization" operation by triggering an authorization control on the authorization query page (e.g., agreeing to use a certain information item in a new scenario), or triggers an authorization request while using a business function (e.g., requesting authorization to use facial information when using facial recognition login), the client sends an authorization request to the server, which receives the request. The request includes: requester information (scenario identifier / third-party identifier), a list of requested information items, the purpose of the request, and a suggested validity period. Based on this authorization request, the server extracts relevant information from the authorization information metadata database and assembles it into a simplified dynamic authorization agreement. This agreement may include: an agreement title (e.g., "Facial Information Use Authorization Letter (Facial Recognition Login Scenario)"), authorization subject (user) information (user name (anonymized display), user identifier (anonymized display), authorized entity information (scenario name / third-party organization name), contact information, compliance qualifications for processing personal information, a list of authorized information items (clearly listing the names and specific scope of personal information items involved in this authorization), and a description of the purpose of authorization (explaining the specific use of the information item in easy-to-understand language). Business Purpose, Authorization Period Options: Provide multiple period options for users to choose from (e.g., "One-time Validity", "7 Days", "30 Days", "Permanent", "Ask on Each Use"), Information Processing Method Description: Explain how the information will be processed (e.g., "Used only for this identity verification, not retained", "Encrypted storage for subsequent business"), Information Sharing Description: If sharing with third parties is involved, clearly list the recipient's name and the scope of sharing, User Rights Description: Inform users that they can revoke the authorization at any time and provide the method and path for revocation, Summary of Rights and Obligations of Both Parties: Concisely summarize the protection obligations of the authorized entity and the rights of the user, as well as the agreement's generation and effective dates.
[0052] After generating the dynamic license agreement, the server sends it to the client. The server can send the dynamic agreement to the client in either easy-to-read HTML or structured JSON format. Upon receiving the dynamic agreement, the client displays it to the user in a clear and easy-to-read interface, without any additional terms. The agreement page may include the agreement text area, a license period selector (displaying options as a drop-down list or radio button), an agreement signing button (such as "I agree" or "Confirm Authorization"), and a rejection button (such as "Disagree" or "Cancel"). After fully reading the dynamic license agreement, the user selects the license period and clicks the "Confirm Authorization" button. Alternatively, the user can click "Disagree" to reject the authorization request.
[0053] After the user clicks "Confirm," the client generates an authorization confirmation request, which includes: user identifier, unique protocol identifier (generated by the server), the authorization period selected by the user, the user's consent timestamp, and the method of consent (e.g., "Check Agree" or "Click Confirm"). Further, the client can send an authorization confirmation request to the server. Upon receiving the request, the server adds an authorization record to the user authorization record database, including: unique authorization record ID, user identifier, information item identifier, business scenario identifier, authorized object identifier, authorization time, authorization validity period (calculated based on the start and end times selected by the user), authorization status ("Valid"), and the notarized hash value of the original authorization protocol. Simultaneously, an "Authorization" event is recorded in the authorization event log. The server then synchronizes this authorization information to the relevant business systems, making the authorization take effect immediately. After receiving the authorization success response, the client displays an "Authorization Successful" message on the interface and can optionally redirect back to the authorization query page for the user to confirm that the new authorization record has appeared in the query results.
[0054] Based on the aforementioned technical features, this application establishes a reverse query mechanism centered on information items, visualized tracking of authorization records throughout the entire lifecycle, refined authorization revocation and dynamic management, and configurable dynamic authorization protocol generation. This enables users to intuitively and readily grasp the authorized recipients, purposes of use, validity periods, and historical change records of each piece of personal information. It also supports flexible revocation of authorization based on information items, scenarios, or third-party granularity. This transforms the original static model of "one-time packaged consent, easy authorization but difficult revocation" into a dynamic governance system with active user participation, traceability, and management. On the one hand, it helps financial institutions meet the compliance requirements of the Personal Information Protection Law and regulations regarding "providing convenient ways to withdraw consent," effectively reducing compliance risks and user disputes. On the other hand, by improving data authorization transparency and user control, it enhances user trust and willingness to use, creating a differentiated competitive advantage. Simultaneously, it promotes the overall improvement of industry privacy protection levels, laying a key technical foundation for the compliant circulation of data elements and the construction of a trustworthy digital financial ecosystem.
[0055] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0056] In one embodiment, an authorization information query device is provided, which corresponds one-to-one with the authorization information query method in the above embodiments. For example... Figure 3 As shown, the authorization information query device includes a first page display module 30, a verification prompt module 31, an identity verification module 32, and an information display module 33. Detailed descriptions of each functional module are as follows: The first page display module 30 is used to display an authorization query page including an authorization information query control; Verification prompt module 31 is used to display identity verification prompt information in response to the authorization information query control being triggered, the identity verification prompt information being used to prompt the identity verification method; The authentication module 32 is used to perform authentication based on the user identity information corresponding to the received authentication prompt information. Information display module 33 is used to display an authorization information page corresponding to the user identity information when the user identity information passes the authentication. The authorization information page includes at least one piece of authorized user information corresponding to the user identity information, and the authorization information page also includes an authorization record query control. The information query module 34 is used to respond to the triggering of the authorization record query control, obtain the user information to be queried for authorization record query, and query at least one authorization record corresponding to the user information to be queried; The second page display module 35 is used to display a query result page that includes at least one authorized record corresponding to the user information to be queried.
[0057] In one possible implementation, the authorization record is displayed in at least one of the following formats: summary card, authorization details table, third-party shared list, and timeline view.
[0058] In one possible implementation, the device further includes: The authorization information display module is used to display the authorization details of the authorization record in response to the authorization record being triggered. The authorization details include at least one of the following: business scenario identifier, information use purpose, processing method, type of authorized object, name and identifier of authorized object, default authorization validity period, and compliance basis of processing behavior.
[0059] In one possible implementation, the query results page includes a revocation authorization control, and the device further includes: The revocation initiation module is used to determine the corresponding authorization record to be revoked in response to the triggering of the revocation authorization control; The revocation confirmation module is used to display the revocation confirmation control corresponding to the authorization record to be revoked; The cancellation operation module is used to cancel the authorization record to be revoked in response to the cancellation confirmation control being triggered.
[0060] In one possible implementation, the authorization query page further includes an authorization history query control, and the device further includes: The historical query module is used to respond to the triggering of the authorization history query control, obtain authorization history query information including query conditions, and obtain the user's authorization event log based on the query conditions, wherein the authorization event log includes at least one authorization event; The log display module is used to display the user's authorization event logs.
[0061] In one possible implementation, the authorization event includes at least one of the following: event identifier, event type, event occurrence time, associated information item identifier, associated business scenario identifier, associated authorization object, and event details description.
[0062] In one possible implementation, the authorization query page further includes an authorization control, and the device further includes: The protocol request module is used to respond to the addition of the authorization control being triggered, obtain the corresponding trigger authorization request, and generate the corresponding dynamic authorization protocol based on the trigger authorization request; The protocol display module is used to display the dynamic authorization protocol; The authorization success module is used to generate a corresponding authorization record and display an authorization success message in response to the confirmation of the dynamic authorization protocol.
[0063] Specific limitations regarding the authorization information query device can be found in the limitations of the authorization information query method described above, and will not be repeated here. Each module in the aforementioned authorization information query device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0064] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 4 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used to communicate with external clients via a network connection. When executed by the processor, the computer program implements the functions or steps of an authorization information query method on the server side.
[0065] In one embodiment, a computer device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 5 As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When executed by the processor, the computer program implements the client-side functions or steps of an authorization information query method.
[0066] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps: In response to receiving a user question that includes text information and image information, the text information and the image information are respectively text-encoded and visual-encoded to obtain text features and visual features; The text features and the visual features are fused to obtain the fused features; Based on the fusion features, match at least one relevant node in a pre-determined target knowledge graph; A structured question-answer report is generated based on the user's historical related questions and at least one related node.
[0067] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor: In response to receiving a user question that includes text information and image information, the text information and the image information are respectively text-encoded and visual-encoded to obtain text features and visual features; The text features and the visual features are fused to obtain the fused features; Based on the fusion features, match at least one relevant node in a pre-determined target knowledge graph; A structured question-answer report is generated based on the user's historical related questions and at least one related node.
[0068] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.
[0069] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0070] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0071] It should be noted that any AI models, software tools, or components not belonging to this company appearing in the embodiments of this application are merely illustrative examples and do not represent actual use. All user personal information involved in the embodiments of this application has been authorized (with the knowledge and consent) by the relevant parties or has been fully authorized by all parties, and the executing entity may obtain it through various legal and compliant means. The collection, storage, use, processing, transmission, provision, and disclosure of the information, data, and signals involved all comply with relevant laws and regulations and do not violate public order and good morals.
[0072] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A method for querying authorization information, characterized in that, include: Displays an authorization query page, including an authorization information query control; In response to the authorization information query control being triggered, an identity verification prompt message is displayed, which is used to indicate the identity verification method; In response to receiving the user identity information corresponding to the authentication prompt, authentication is performed based on the user identity information; When the user identity information passes the authentication, the authorization information page corresponding to the user identity information is displayed. The authorization information page includes at least one item of authorized user information and authorization record query control corresponding to the user identity information. In response to the triggering of the authorization record query control, the system obtains the user information to be queried for authorization record query and queries at least one authorization record corresponding to the user information to be queried. The page displays the query results, including at least one authorization record corresponding to the user information to be queried.
2. The method according to claim 1, characterized in that, The authorization records are displayed in at least one of the following ways: summary card, authorization details table, third-party shared list, and timeline view.
3. The method according to claim 2, characterized in that, The method further includes: In response to the authorization record being triggered, the authorization details information of the authorization record is displayed. The authorization details information includes at least one of the following: business scenario identifier, information use purpose, processing method, authorized object type, name and identifier of authorized object, default authorization validity period, and compliance basis for processing behavior.
4. The method according to claim 2, characterized in that, The query results page includes a revocation authorization control, and the method further includes: In response to the triggering of the authorization revocation control, the corresponding authorization record to be revoked is determined; Display the revocation confirmation control corresponding to the authorization record to be revoked; In response to the triggering of the cancellation confirmation control, the authorization record to be revoked is cancelled.
5. The method according to claim 1, characterized in that, The authorization query page also includes an authorization history query control, and the method further includes: In response to the triggering of the authorization history query control, authorization history query information including query conditions is obtained, and the user's authorization event log is obtained based on the query conditions, wherein the authorization event log includes at least one authorization event; Display the user's authorization event log.
6. The method according to claim 5, characterized in that, The authorized event includes at least one of the following: event identifier, event type, event occurrence time, associated information item identifier, associated business scenario identifier, associated authorized object, and event details description.
7. The method according to claim 1, characterized in that, The authorization query page also includes adding an authorization control, and the method further includes: In response to the triggering of the added authorization control, the corresponding authorization request is obtained, and a corresponding dynamic authorization protocol is generated based on the authorization request. Display the dynamic authorization protocol; In response to the confirmation of the dynamic authorization protocol, a corresponding authorization record is generated and an authorization success message is displayed.
8. An authorization information query device, characterized in that, include: The first page display module is used to display the authorization query page, which includes an authorization information query control; The verification prompt module is used to display an identity verification prompt message in response to the triggering of the authorization information query control. The identity verification prompt message is used to indicate the identity verification method. The authentication module is used to perform authentication based on the user identity information corresponding to the received authentication prompt information. The information display module is used to display the authorization information page corresponding to the user identity information when the user identity information passes the authentication. The authorization information page includes at least one item of authorized user information and authorization record query control corresponding to the user identity information. The information query module is used to respond to the triggering of the authorization record query control, obtain the user information to be queried for authorization record query, and query at least one authorization record corresponding to the user information to be queried; The second page display module is used to display the query results page, which includes at least one authorized record corresponding to the user information to be queried.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the authorization information query method as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the authorization information query method as described in any one of claims 1 to 7.