Mini‑program authorization processing

By initiating pre-authorization uniformly in the centralized scenario page of the parent application, the problem of poor user experience in multi-mini-program scenarios is solved, more efficient authorization processing is achieved, and user experience and security are improved.

WO2026037143A1PCT designated stage Publication Date: 2026-02-19ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/112499
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-13
Filing Date
2025-08-04
Publication Date
2026-02-19

AI Technical Summary

Technical Problem

In scenarios where a parent application integrates multiple mini-programs, the poor user experience caused by frequent authorization request pop-ups can negatively impact traffic acquisition and conversion, and may even lead to user churn.

Method used

In the centralized scenario page of the parent application, a unified pre-authorization request is initiated to the user to generate authorization data, and the authorization data is directly obtained when the user enters the specific mini program, avoiding repeated authorization requests in the mini program.

Benefits of technology

This reduces the intrusion of authorization pop-ups on users, improves user experience and security, and at the same time, unified control of authorization through the parent application prevents mini-programs from abusing permissions, thereby increasing user satisfaction and traffic conversion rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025112499_19022026_PF_FP_ABST
    Figure CN2025112499_19022026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in embodiments of the present disclosure are a mini-program authorization processing method, apparatus and device. The solution comprises: entering a centralized scenario page of a specified application, the centralized scenario page having respective entry points of a plurality of mini-programs integrated by the specified application; in the centralized scenario page, initiating to a current user a unified authorization request corresponding to the plurality of mini-programs; if the current user agrees to perform pre-authorization in response to the unified authorization request, triggering the generation of corresponding authorization data; and after the pre-authorization, if the current user enters a corresponding mini-program among the plurality of mini-programs from the corresponding entry point in the centralized scenario page, directly acquiring specified information of the current user in the corresponding mini-program on the basis of the authorization data, so as to perform a service of the corresponding mini‑program for the current user, without requesting authorization from the current user within the corresponding mini‑program.
Need to check novelty before this filing date? Find Prior Art

Description

Applet authorization processing TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of applets, and in particular, to applet authorization processing. BACKGROUND

[0002] With the development of Internet technology and the popularization of smart phones, more and more businesses are carried out through various applications, and some large and medium-sized comprehensive platform applications have also been generated.

[0003] Some sub-applications of the service provider to which the comprehensive platform application belongs, or applications of other small and medium-sized service providers, will provide services in the form of applets and be embedded in the comprehensive platform application. The comprehensive platform application is regarded as a parent application, and the applets can run relying on the parent application, so that the services can be provided to the user more lightweightly, and the user does not need to download and install these small application clients separately, thereby improving the user experience and helping to obtain more traffic through the parent application.

[0004] Under such a background, the parent application will often access many applets, and some users can also frequently access different applets in the parent application. The current applets usually need to provide authorization of geographic location, avatar nickname, mobile phone number, discount, message and the like when used by the user. The applet will request the user to authorize through a pop-up window. In this case, the user who accesses different applets in a short time will be frequently disturbed by the authorization request pop-up window of different applets, thereby affecting the user experience, and further affecting the effectiveness of the applet in obtaining and converting traffic, and even the parent application itself may also lose users.

[0005] Based on this, in the scenario where the parent application accesses multiple applets, a better user experience is needed for the applet authorization scheme. SUMMARY

[0006] One or more embodiments of the present disclosure provide an applet authorization processing method, device and equipment, and a storage medium, to solve the technical problem that in the scenario where the parent application accesses multiple applets, a better user experience is needed for the applet authorization scheme.

[0007] To solve the above technical problems, one or more embodiments of the present disclosure are implemented in the following manner. One or more embodiments of the present disclosure provide a mini-program authorization processing method, which includes: entering a centralized scene page of a specified application, the centralized scene page having entrances of a plurality of mini-programs respectively accessed by the specified application; in the centralized scene page, initiating a unified authorization request corresponding to the plurality of mini-programs to a current user; if the current user agrees to pre-authorization in response to the unified authorization request, triggering corresponding authorization data generation; after the pre-authorization, if the current user enters a corresponding mini-program from the entrances in the centralized scene page, directly obtaining specified information of the current user in the corresponding mini-program according to the authorization data, for performing a business of the corresponding mini-program for the current user, without requesting authorization of the current user in the corresponding mini-program.

[0008] One or more embodiments of the present disclosure provide a mini-program authorization processing apparatus, which includes: a centralized scene entering module, which enters a centralized scene page of a specified application, the centralized scene page having entrances of a plurality of mini-programs respectively accessed by the specified application; a unified authorization requesting module, which initiates a unified authorization request corresponding to the plurality of mini-programs to a current user in the centralized scene page; an authorization data triggering module, which triggers corresponding authorization data generation if the current user agrees to pre-authorization in response to the unified authorization request; and a mini-program shortcut processing module, which, after the pre-authorization, directly obtains specified information of the current user in a corresponding mini-program according to the authorization data if the current user enters the corresponding mini-program from the entrances in the centralized scene page, for performing a business of the corresponding mini-program for the current user, without requesting authorization of the current user in the corresponding mini-program.

[0009] One or more embodiments of the present disclosure provide a widget authorization processing device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform: entering a centralized scene page of a specified application, the centralized scene page having entrances of a plurality of widgets respectively accessed by the specified application; in the centralized scene page, initiating a unified authorization request corresponding to the plurality of widgets to a current user; if the current user agrees to pre-authorization in response to the unified authorization request, triggering corresponding authorization data generation; after the pre-authorization, if the current user enters a corresponding widget in the plurality of widgets from the entrance in the centralized scene page, directly obtaining specified information of the current user in the corresponding widget according to the authorization data, for performing a business of the corresponding widget for the current user, without requesting authorization of the current user in the corresponding widget.

[0010] One or more embodiments of the present disclosure provide a non-volatile computer storage medium, storing computer executable instructions, the computer executable instructions being configured to: enter a centralized scene page of a specified application, the centralized scene page having entrances of a plurality of widgets respectively accessed by the specified application; in the centralized scene page, initiate a unified authorization request corresponding to the plurality of widgets to a current user; if the current user agrees to pre-authorization in response to the unified authorization request, trigger corresponding authorization data generation; after the pre-authorization, if the current user enters a corresponding widget in the plurality of widgets from the entrance in the centralized scene page, directly obtain specified information of the current user in the corresponding widget according to the authorization data, for performing a business of the corresponding widget for the current user, without requesting authorization of the current user in the corresponding widget.

[0011] The above at least one technical solution adopted by one or more embodiments of the present disclosure can achieve the following beneficial effects: considering that if the current user enters the centralized scene page of the specified application (as the parent application), there is a great probability that the user will enter the small program through the different small program entrances provided by the page, and it is also possible that the user will exit the small program back to the page and enter other small programs, so the user uses multiple different small programs in a short period of time. Therefore, when the user initially arrives at the centralized scene page, the user can be uniformly requested to perform pre-authorization on behalf of multiple small programs, and the user can be requested to authorize individually in the small program that the user may further enter from the page subsequently. Therefore, the disturbance of the authorization pop-up window to the user is greatly reduced. Furthermore, in the case that the user agrees to the pre-authorization, such authorization can be conveniently controlled by the parent application uniformly, the abuse of the small program can be prevented, and the small program can be allowed to use the authorized permission only when the user actually enters the small program from the centralized scene page. If the user has not entered the small program, the small program can be prevented from using the authorized permission even if the user has performed the pre-authorization. In addition, the validity of the pre-authorization can be converged to the jurisdiction range of the centralized scene page, so that the small program can be prevented from using the authorized permission if the user enters the small program from a channel other than the centralized scene page. Therefore, the security is improved. Therefore, the above solution can effectively improve the user experience and take into account the security. BRIEF DESCRIPTION OF DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the related art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only some embodiments described in the present disclosure, and for those skilled in the art, other drawings can also be obtained without creative labor.

[0013] FIG. 1 is a flowchart of a small program authorization processing method provided by one or more embodiments of the present disclosure;

[0014] FIG. 2 is a flowchart of a scheme for obtaining specified information of a user in a small program provided by one or more embodiments of the present disclosure;

[0015] FIG. 3 is a flowchart of a small program quick authorization processing scheme in an application scenario provided by one or more embodiments of the present disclosure;

[0016] FIG. 4 is a schematic diagram of some page effects of the scheme in FIG. 3 provided by one or more embodiments of the present disclosure;

[0017] FIG. 5 is a flowchart of a risk defense scheme cooperating with pre-authorization provided by one or more embodiments of the present disclosure;

[0018] FIG. 6 is a flow diagram of a user protection scheme for an applet according to one or more embodiments of the present disclosure;

[0019] FIG. 7 is a structural diagram of an applet authorization processing apparatus according to one or more embodiments of the present disclosure;

[0020] FIG. 8 is a structural diagram of an applet authorization processing device according to one or more embodiments of the present disclosure. DETAILED DESCRIPTION

[0021] Embodiments of the present disclosure provide an applet authorization processing method, apparatus, device, and storage medium.

[0022] In order to enable those skilled in the art to better understand the technical solutions in the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative labor should fall within the scope of protection of the present application.

[0023] As mentioned in the background, for some large and medium-sized comprehensive platform applications, users enter applets in a centralized scenario, which may have experience problems such as frequent pop-up windows, long and chaotic processes, etc. This also brings more negative effects, including: platform and merchant process loss, waste of operating costs, for example, when the applet is entered in a centralized scenario, when the applet is for a non-famous merchant, since the user does not understand the scene and has no brand endorsement, the authorization pass rate is low when the experience is poor; low platform satisfaction, affecting user revisit and retention, for example, a user with a known applet in a centralized entry has a demand, although the authorization pass rate may not be affected due to targeted consumption and brand endorsement, but compared to other platforms that may do better, it may affect the overall satisfaction of users with the platform, thereby affecting the competitiveness of the platform.

[0024] In order to solve these problems, the present application can quickly request pre-authorization from the user in the scenario of platform centralized traffic distribution, and try to avoid separate authorization requests by each applet, thereby reducing the disturbance of multiple pop-up windows, and without the need for applets to make cumbersome adaptation and modification, which helps to improve user experience, platform satisfaction, and conversion rate. Based on such overall ideas, the scheme of the present application will be further described below.

[0025] Regarding authorization, based on the legal and legitimate principles of personal information protection, the minimum necessary principle, the right to know and the right to autonomy of users, when a third party or other non-information holder needs to obtain the information left by the user in the current platform to complete the service, the full consent of the user is needed. For example, assuming that the user wants to use the car-hailing service provided by other platforms on the current platform, currently, the user generally has two choices, one is to choose to input a new mobile phone number to register a new account, and the other is to choose to quickly log in using the current platform account, in this case, the user agrees to authorize the account information of the current platform to the other platform.

[0026] FIG. 1 is a flowchart of a small program authorization processing method provided by one or more embodiments of the present disclosure. The execution subject of the flowchart can include the client of the specified application (here, the small program accessed in the client can also be considered as a whole with the client), and can also include the corresponding server. For the case of the client, the hardware execution subject also includes the device where the client is located, such as the user's smartphone, tablet computer, etc.

[0027] The flowchart in FIG. 1 includes the following steps.

[0028] S102: Enter the centralized scene page of the specified application, which has multiple small programs accessed by the specified application respectively.

[0029] In one or more embodiments of the present disclosure, the specified application can be the parent application mentioned in the background technology, and can be a large or medium-sized platform application with large traffic, which guides the flow of multiple small programs accessed by cooperation through one or more centralized scene pages to improve the access volume of users to these small programs.

[0030] The centralized scene mentioned here is essentially a centralized traffic distribution scene, which is a centralized traffic entrance provided by the platform for other cooperation parties. The centralized scene page can be the home page under the scene. For example, the business scene home pages of the consumption circle, citizen center, game center, medical center, etc. provided by a payment platform, which is similar to the public area after entering the commercial complex in the offline, and the user can freely choose to go to the store (similar to the small program) of his interest.

[0031] The respective entrance of the small program is usually presented in the form of a corresponding icon, card or text link in the centralized scene page, and the user can jump into the corresponding small program by clicking. It should be noted that after jumping into the small program, the user is generally still in the specified application, but according to different cooperation modes and technical implementation modes, the user can also be separated from the specified application, in which case the execution subject of the scheme can be increased based on the cooperation between applications or the assistance on the operating system level to continue to implement the scheme of the present application.

[0032] S104: In the centralized scene page, a unified authorization request corresponding to the plurality of applets is initiated to the current user.

[0033] In one or more embodiments of the present disclosure, in the centralized scene page, a pop-up window is popped up to the current user, and the unified authorization request corresponding to the plurality of applets is initiated through the pop-up window, so that the current user authorizes by interacting with the pop-up window. In addition to the pop-up window, other ways such as banners, markers, additional small screen notifications, etc. can also be used. Of course, these methods may actually disturb the user to some extent, but the present application is to exchange this possible disturbance for the subsequent need not to disturb the user multiple times in different applets, so it is very cost-effective overall.

[0034] In one or more embodiments of the present disclosure, the authorization requested by the unified authorization request is called pre-authorization, that is, the authorization performed before the current user enters each applet, but it needs to be noted that although the authorized permission is unified for the plurality of applets, it is also controlled by the specified application. That is, in essence, the user is authorizing the specified application, and the specified application can control when the permission takes effect and which applet the permission takes effect according to the needs, so as to avoid authorization generalization and multiple applets abusing the permission. In addition, even the specified application itself can limit the specific conditions under which the specified application can use the permission according to the pre-negotiation with the user or the security policy of the platform itself.

[0035] S106: If the current user agrees to pre-authorization in response to the unified authorization request, trigger corresponding authorization data generation.

[0036] Taking the pop-up window for unified authorization request as an example, the current user can indicate the agreement of pre-authorization or the rejection of pre-authorization by clicking the corresponding button in the pop-up window. If the user agrees, the authorization data for describing this agreement authorization or as authorization credentials will be generated accordingly, so as to be used for subsequent verification of permission. The authorization data can be generated on the current user terminal or on the corresponding server, which can depend on whether the subsequent verification is local or remote. The authorization data can indicate the authorized state, and can also indicate which centralized scene or which centralized scene page is authorized, and can also indicate more aspects according to needs, such as indicating the authorization validity time range, the authorization business range, etc.

[0037] S108: After the pre-authorization, if the current user enters a corresponding applet in the plurality of applets from the portal in the centralized scene page, the specified information of the current user is directly obtained in the corresponding applet according to the authorization data, for the current user to perform the business of the corresponding applet, without requesting authorization of the current user in the corresponding applet.

[0038] The specified information is information that needs to obtain the authorization of the current user to obtain, which is usually information related to the privacy of the user, such as the geographic location, avatar nickname, mobile phone number, and discount of the user. In the case where the pre-authorization is not performed, if the current user enters the corresponding applet in the plurality of applets from the portal in the centralized scene page, the applet needs to initiate an authorization request (usually in the form of a pop-up window) to the user in the applet to obtain the specified information of the current user, as described in the background art. After the user agrees to the authorization, the specified information of the current user can be obtained. In step S108, the "directly obtaining" means that the current user does not need to be disturbed (such as a pop-up window) in the corresponding applet to request authorization, and the specified information of the current user can be obtained. Based on the verification of the authorization data, the specified information of the current user can be obtained if the verification is passed.

[0039] Further, the specified information can be information that is dynamically updated in a timely manner, such as real-time geographic location, real-time order information, and real-time behavior operation of the user, so that the applet can more targetedly cater to the user situation to provide instant service.

[0040] In one or more embodiments of the present disclosure, the specified application mentioned above can control the authorized permission. For example, after the pre-authorization, the corresponding applet is not allowed to directly obtain the specified information of the current user before the current user enters the corresponding applet from the portal in the centralized scene page, and the specified information of the current user can be obtained only after entering. In addition, if the current user enters the corresponding applet from other channels other than the centralized scene page, the use of the authorized permission can also be not allowed. In this case, the pre-authorization performed by the user is actually more strictly for the centralized scene page, which helps to protect the information security of the user.

[0041] Through the method of FIG. 1, it is considered that if the current user enters the centralized scene page of the specified application (as the parent application), there is a great probability to enter the small program through the different small program entrances provided by the page, and it is also possible to exit the small program back to the page, enter other small programs, and thus use multiple different small programs in a short time. Therefore, when the user initially arrives at the centralized scene page, the pre-authorization can be uniformly requested from the user on behalf of multiple small programs, and the authorization can be requested from the user individually in the small program that the user may further enter from the page subsequently, so that the disturbance of the authorization pop-up window to the user is greatly reduced. Furthermore, in the case where the user agrees to the pre-authorization, such authorization can be conveniently controlled by the parent application, so as to prevent the abuse of the small program, and only when the user actually enters a certain small program from the centralized scene page, the small program can be allowed to use the authorized permission, and if the user has not entered the small program, the small program can still be prevented from using the authorized permission even if the user has performed the pre-authorization. In addition, the validity of the pre-authorization can be converged to the jurisdiction range of the centralized scene page, so that the small program can still be prevented from using the authorized permission if the user enters the small program from a channel other than the centralized scene page. Therefore, the security is improved, and the above scheme can effectively improve the user experience and take into account the security.

[0042] Based on the method of FIG. 1, the present disclosure further provides some specific embodiments and extension schemes of the method, which are described below.

[0043] One or more embodiments of the present disclosure provide a flowchart of a scheme for obtaining specified information of a user in a small program, as shown in FIG. 2.

[0044] The flow in FIG. 2 includes the following steps.

[0045] S202: After the pre-authorization, the corresponding authorization data generated is determined, and the corresponding authorization data includes the correspondence between the user identifier of the current user, the centralized scene identifier corresponding to the centralized scene page, and the authorized state information.

[0046] The corresponding small program identifier can also be added to the above correspondence, so as to be able to maintain the above correspondence individually for a certain small program.

[0047] The pre-authorization is by default for the centralized scene identifier corresponding to all the mini-programs in the centralized scene, but not all of them can be trusted by the user, and even some mini-programs can be disliked by the user, so the user can be provided with separate management means. For example, after pre-authorization, the user can be displayed with authorization setting options corresponding to a plurality of mini-programs, and if the user receives an operation of the authorization setting options, the authorization is canceled for any one of the plurality of mini-programs, it is determined that the pre-authorization is invalid for the any one of the plurality of mini-programs (for example, the identifier of the any one of the plurality of mini-programs can be removed from the above correspondence), so that the any one of the plurality of mini-programs is not allowed to directly obtain the specified information of the user according to the authorization data, and the other mini-programs in the plurality of mini-programs that have not been canceled are still allowed to directly obtain the specified information of the user according to the authorization data; similarly, the user can also make the above setting in advance.

[0048] S204: When entering the corresponding mini-program in the plurality of mini-programs from the entrance in the centralized scene page, the centralized scene identifier corresponding to the centralized scene page is sent to the server, so that the server is checked.

[0049] The server can check whether the received corresponding centralized scene identifier matches the generated authorization data, and determine whether to allow the corresponding mini-program to directly obtain the information of the user according to the matching result. For example, if it is determined through matching that the centralized scene identifier contained in the generated authorization data is the corresponding centralized scene identifier currently received by the server, and both sides such as the user identifier, the authorization range, etc. match, the corresponding mini-program can be allowed to directly obtain the information of the user, otherwise it can be rejected. The action of the check can also be performed on the user terminal, and for this case, the authorization data can be saved on the user terminal in advance, so that efficient checking can be performed.

[0050] The check here can also be simplified, for example, only the centralized scene corresponding to the received centralized scene identifier is checked to support pre-authorization, and if it supports, the check is passed. Thus, it can be more efficient to determine whether the current mini-program entry channel is the channel (i.e., from a specific centralized scene) targeted by the present solution.

[0051] S206: When entering the corresponding mini-program in the plurality of mini-programs from the entrance in the centralized scene page, an authorization request is initiated through the corresponding mini-program without a pop-up window.

[0052] In one or more embodiments of the present disclosure, the authorization request initiated by the corresponding applet here is for the specified application and is unobtrusive to the current user. In the implementation of the present solution, the authorization request popup of the corresponding applet can be intercepted first, and then it is decided whether the intercepted popup needs to be displayed to the user according to whether the pre-authorization is performed. Thus, in the implementation of the present solution, the corresponding applet can be avoided as much as possible to cooperate with the improvement, and only the specified application itself needs to be improved, which is more friendly to the service providers of multiple applets.

[0053] S208: In response to the authorization request, the user whether has been authorized and the authorization range of the requested authorization are verified according to the user identifier and the authorized state information contained in the generated authorization data on the local or the server.

[0054] The verification in steps S204 and S208 can be performed together or at different times.

[0055] S210: If yes, the information of the user is sent to the corresponding applet.

[0056] If the verification fails, the corresponding applet popup can be allowed to request authorization from the current user.

[0057] Through the solution of FIG. 2, the experience of whether the user can be disturbed by the authorization request in the applet can be controlled finely and reliably by maintaining the corresponding relationship reflecting the pre-authorization situation and performing corresponding verification when the user actually enters the applet. Meanwhile, if necessary, the user can also actively control in advance to improve his experience.

[0058] According to the above description, one or more embodiments of the present disclosure also provide a flowchart of a small program quick authorization processing solution in an application scenario and some page effect schematic diagrams of the solution, which are shown in FIGS. 3 and 4, respectively.

[0059] In the solution, one or more centralized scenarios, such as “xx store” and “consumption circle”, can be determined in advance in the app (i.e., the specified application) and access to multiple merchant applets. The corresponding distinguishing identifier, such as the centralized scenario channel identifier, can be set for each centralized scenario, such as A, B, C, etc. When the user jumps from the centralized scenario main page to the applet, the corresponding scenario channel identifier can be carried by the current client to the server.

[0060] Initially, it is assumed that the user has not yet been authorized, at this time when entering the centralized scene, the app can arouse the quick authorization management pop-up window to request the user to perform the unified pre-authorization in the scene. If the user agrees to authorize, a quick authorization relationship can be created for the user as the above authorization data, saved locally or on the server, and the quick authorization relationship is exemplarily includes: scene channel identifier (A / B / C) + user identifier + opening state + pop-up window exemption authorization range. If the user refuses to authorize, the pop-up window is closed.

[0061] After the user agrees to authorize, if the user has not yet jumped into a certain merchant applet from the entering centralized scene, the merchant applet still cannot obtain the user data corresponding to the permission (i.e. the specified information described above). That is, for the merchant applet, the permission has not yet taken effect in essence, thereby helping to reduce the risk of merchants abusing user data.

[0062] When the user jumps into a certain merchant applet from the centralized scene, the merchant applet initiates an authorization request, the system checks whether the user has opened the quick authorization and the authorization range contains the request range of the merchant, and checks the success. Then directly return the user data corresponding to the permission, otherwise, the authorization request pop-up window can be aroused for the user to confirm the authorization.

[0063] In the effect schematic diagram of FIG. 4, some information is shielded without affecting understanding, and according to from left to right, four subgraphs can be seen. In the first graph, the user is in the main page of a centralized scene named “xx store”, and the quick authorization management pop-up window has been aroused in the page. As can be seen from the pop-up window, the requested permission range includes the user's geographic location and the discount information in the app (also prompts the expected use of these information), and the user can click the “allow” button to indicate agreement to authorize. If the user agrees to authorize, the page in the second graph will be displayed, and in the page, it is also prompted that the user can manage the quick authorization as needed, for example, through the quick authorization switch to cancel the quick authorization at any time. The third graph exemplarily shows the access path from which the quick authorization management page can be reached, and the fourth graph shows the quick authorization switch in the quick authorization management page. Of course, according to the foregoing description, if necessary, more fine-grained quick authorization switches for each applet can also be added in the quick authorization management page.

[0064] Through the scheme of FIG. 3, since the number of centralized scenes is limited and controllable, the problem of high technical cost of data expansion can be avoided, and the practicability of the scheme is good.

[0065] In one or more embodiments of the present disclosure, in the case of pre-authorization, the user actually transfers more security responsibility to the designated application side. In order to enable the user to more clearly perceive and respond to risks, one or more embodiments of the present disclosure also provide a flowchart of a risk defense scheme cooperating with pre-authorization, as shown in FIG. 5.

[0066] The flowchart in FIG. 5 includes the following steps.

[0067] S502: After obtaining the specified information of the current user in the corresponding applet according to the authorization data, detecting a business opportunity node related to the specified information of the current user in the corresponding applet.

[0068] After the corresponding applet obtains the specified information of the current user, it will execute one or more business processes with a time sequence according to the user's immediate operation and the business logic of the applet. The currently executed business process can be divided into multiple business opportunity nodes in a set manner (for example, according to different business data used, according to different functions called, according to different business types of returned data, according to different user interface elements interacted, etc.).

[0069] The present scheme mainly focuses on the business opportunity nodes related to the specified information, such as the business opportunity nodes that directly or indirectly use the specified information, which are regarded as related business opportunity nodes.

[0070] S504: According to the time sequence relationship of each business opportunity node, a user information risk link is generated.

[0071] In one or more embodiments of the present disclosure, by arranging and linking each business opportunity node according to the time sequence relationship (wherein link branches can appear to cover the business behavior in the corresponding applet for a longer time range), a visual and as simple as possible user information risk link is generated. The business behavior reflected on the user information risk link for the specified information may contain potential risks, and therefore, can be given to the user as a reference to enable the user to more clearly understand where the specified information is used.

[0072] In actual applications, the professional degree of the manifestation of the user information risk link may be different, and thus may not be fully understood by users. Therefore, intelligent analysis can be used to help generate a user information risk link that is more user-friendly. For example, if the unified authorization request carries the intended use of the specified information of the current user (for example, the first subgraph in FIG. 4), the detected business opportunity nodes can be matched and analyzed with the intended use to obtain a use deviation result, and the user information risk link can be generated based on the use deviation result and the time sequence relationship of the business opportunity nodes.

[0073] S506: In response to the request of the current user, the information risk link is displayed to the current user.

[0074] The information risk link can not be displayed by default, and the user can actively operate to call up the information risk link if the user wants to observe. Alternatively, the information risk link can be actively displayed to the user when it is automatically detected that there is a risk.

[0075] S508: A risk blocking point indicated by the current user in the information risk link is received.

[0076] Not only does the foregoing provide a means for the user to discover risks, but also further provides a solution for flexibly and timely dealing with risks. The user can select a business opportunity node that the user considers to be at risk or that the system prompts to be at risk in the information risk link, and then the business opportunity node is selected as a risk blocking point.

[0077] S510: The path after the risk blocking point in the information risk link is blocked, and the business involved in the information risk link is rolled back to the risk blocking point or before the risk blocking point in the corresponding applet.

[0078] To more reliably protect user privacy and more minimally affect business rollback, one or more embodiments of the present disclosure further provide a flowchart of a user protection scheme of a parent application for an applet, as shown in FIG. 6.

[0079] The flowchart in FIG. 6 includes the following steps.

[0080] S602: Before directly obtaining the specified information of the current user in the corresponding applet according to the authorization data, a corresponding disguised user is generated for the current user and disguised feature information of the disguised user is generated based on the business characteristics of the corresponding applet and the specified original information of the current user through the specified application.

[0081] In one or more embodiments of the present disclosure, the specified application remaps the real account of the current user to generate a new account to represent the current user, i.e., a disguised user. Moreover, according to the business characteristics of the corresponding applet, the specified original information of the current user is also disguised as much as possible to obtain the disguised characteristic information of the disguised user under the condition that the corresponding applet is basically sufficient to normally conduct business. For example, for a food delivery applet, the user's food delivery address is required at the minimum, and other information can be blurred or confused with other users as much as possible, and the food delivery address can also be lightly blurred (e.g., blurred to the floor without specific to the house number; for example, blurred to a dynamic address accepted by a user within dozens of meters or even tens of meters of the actual food delivery address; etc.), thereby achieving disguise.

[0082] S604: In the corresponding applet, the specified information of the current user is directly obtained according to the authorization data, and in the corresponding applet, the disguised characteristic information of the disguised user is directly obtained according to the authorization data, for the current user to conduct the business of the corresponding applet.

[0083] In this way, for the specified application, the corresponding applet can not only normally complete the business, but also avoid accurately grasping the user information. Moreover, assuming that the above-mentioned risk blocking rollback operation is supported, the specified application can generate two or more disguised users for the same applet of the same user, and generate disguised characteristic information for them respectively, and initially only one of the disguised users is provided to the applet. If the disguised user has a risk blocking rollback, the remaining business logic is copied or replaced to a remaining disguised user, so that the applet continues to complete the business for the remaining disguised user. Of course, in this scheme, the remaining disguised user can also be replaced by a real user, for example, a real user can be enabled for the applet after determining a high probability of no risk. In this way, the disguised user can help the real user to explore the risk and more reliably establish a high probability of no risk business path, so that the applet can conduct business, thereby being able to more strongly protect user privacy and security.

[0084] Based on the same idea, one or more embodiments of the present disclosure also provide a device and equipment corresponding to the above-mentioned method, as shown in FIG. 7 and FIG. 8. The device and equipment can correspondingly execute the above-mentioned method and related optional solutions.

[0085] FIG. 7 is a structural schematic diagram of an applet authorization processing apparatus provided by one or more embodiments of the present disclosure, the apparatus comprising: a centralized scene entering module 702, entering a centralized scene page of a specified application, the centralized scene page having entrances of a plurality of applets respectively accessed by the specified application; a unified authorization request module 704, in the centralized scene page, initiating a unified authorization request corresponding to the plurality of applets to a current user; an authorization data triggering module 706, if the current user agrees to pre-authorization in response to the unified authorization request, triggering corresponding authorization data generation; and an applet shortcut processing module 708, after the pre-authorization, if the current user enters a corresponding applet from the entrances in the centralized scene page, directly obtaining specified information of the current user in the corresponding applet according to the authorization data, for performing a business of the corresponding applet for the current user, without requesting authorization of the current user in the corresponding applet.

[0086] Optionally, the authorization data triggering module 706, after the pre-authorization, does not allow the corresponding applet to directly obtain the specified information of the current user before the current user enters the corresponding applet from the entrances in the centralized scene page.

[0087] Optionally, the unified authorization request module 704, in the centralized scene page, pops up a window to the current user, initiates a unified authorization request corresponding to the plurality of applets through the popped window, so that the current user performs authorization by interacting with the popped window; and the applet shortcut processing module 708, in the corresponding applet, directly obtains the information of the user according to the authorization data, without popping up a window to request authorization of the current user in the corresponding applet to obtain the specified information of the current user.

[0088] Optionally, the applet shortcut processing module 708, when entering the corresponding applet from the entrances in the centralized scene page, sends a centralized scene identifier corresponding to the centralized scene page to a server, so that the server checks whether the received corresponding centralized scene identifier matches the generated authorization data, and determines whether to allow the corresponding applet to directly obtain the information of the user according to the matching result.

[0089] Optionally, the corresponding authorization data comprises a correspondence between a user identifier of the current user, a centralized scene identifier corresponding to the centralized scene page, and authorized state information; the applet shortcut processing module 708 initiates an authorization request through the corresponding applet without a corresponding pop-up window when entering the corresponding applet in the plurality of applets from the entrance in the centralized scene page; and in response to the authorization request, the user information is sent to the corresponding applet according to the user identifier and the authorized state information contained in the generated authorization data.

[0090] Optionally, the authorization data triggering module 706 displays authorization setting options corresponding to the plurality of applets to the current user after the pre-authorization; and if it is received that the current user sets to cancel authorization for any applet in the plurality of applets by operating the authorization setting options, it is determined that the pre-authorization is invalid for the any applet, so that the any applet is not allowed to directly obtain the specified information of the current user according to the authorization data, and other applets in the plurality of applets that have not been canceled are still allowed to directly obtain the specified information of the current user according to the authorization data.

[0091] Optionally, the applet shortcut processing module 708 detects a business time node involving the specified information of the current user in the corresponding applet after directly obtaining the specified information of the current user according to the authorization data in the corresponding applet; generates a user information risk link according to the time sequence relationship of each business time node; and displays the information risk link to the current user in response to a request of the current user.

[0092] Optionally, the unified authorization request carries an intended use of the specified information of the current user; the applet shortcut processing module 708 matches and analyzes each business time node and the intended use to obtain a use deviation result; and generates a user information risk link according to the use deviation result and the time sequence relationship of each business time node.

[0093] Optionally, the applet shortcut processing module 708 receives a risk blocking point indicated by the current user in the information risk link after displaying the information risk link to the current user; blocks a path in the information risk link after the risk blocking point, and rolls back a business involved in the information risk link to the risk blocking point or before the risk blocking point in the corresponding applet.

[0094] Optionally, the applet shortcut processing module 708, before directly obtaining the specified information of the current user in the corresponding applet according to the authorization data, generates a corresponding pseudo user for the current user and generates pseudo feature information of the pseudo user according to the business characteristics of the corresponding applet and the specified original information of the current user through the specified application; and the directly obtaining the specified information of the current user in the corresponding applet according to the authorization data specifically includes: directly obtaining the pseudo feature information of the pseudo user in the corresponding applet according to the authorization data, for the current user to perform the business of the corresponding applet.

[0095] FIG. 8 is a structural schematic diagram of an applet authorization processing device provided by one or more embodiments of the present disclosure, the device comprising: at least one processor; and a memory in communication connection with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform: entering a centralized scene page of a specified application, the centralized scene page having entrances of a plurality of applets respectively accessed by the specified application; in the centralized scene page, initiating a unified authorization request corresponding to the plurality of applets to a current user; if the current user agrees to perform pre-authorization in response to the unified authorization request, triggering corresponding authorization data generation; after the pre-authorization, if the current user enters a corresponding applet in the plurality of applets from the entrance in the centralized scene page, directly obtaining specified information of the current user in the corresponding applet according to the authorization data, for the current user to perform the business of the corresponding applet, without requesting authorization of the current user in the corresponding applet.

[0096] Based on the same idea, one or more embodiments of the present disclosure also provide a non-volatile computer storage medium storing computer executable instructions configured to: enter a centralized scene page of a specified application, the centralized scene page having entrances of a plurality of applets respectively accessed by the specified application; in the centralized scene page, initiate a unified authorization request corresponding to the plurality of applets to a current user; if the current user agrees to perform pre-authorization in response to the unified authorization request, trigger corresponding authorization data generation; after the pre-authorization, if the current user enters a corresponding applet in the plurality of applets from the entrance in the centralized scene page, directly obtain specified information of the current user in the corresponding applet according to the authorization data, for the current user to perform the business of the corresponding applet, without requesting authorization of the current user in the corresponding applet.

[0097] In the 1990s, it was quite obvious to distinguish whether an improvement in a technology was in hardware (e.g., improvement in circuit structures of diodes, transistors, switches, etc.) or in software (improvement in method flow). However, as technology has evolved, many improvements in method flow today can be considered as direct improvements in hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structures by programming the improved method flow into hardware circuits. Therefore, it cannot be said that an improvement in a method flow cannot be implemented by hardware entity modules. For example, a programmable logic device (PLD) (e.g., a field programmable gate array (FPGA)) is an integrated circuit whose logic function is determined by user programming of the device. A digital system is "integrated" on a PLD by the designer programming it, rather than by asking a chip manufacturer to design and fabricate a custom integrated circuit chip. Moreover, instead of manually fabricating integrated circuit chips, this programming is now mostly implemented by "logic compiler" software, which is similar to software compilers used in program development, and the original code before compilation is also written in a specific programming language, which is called a hardware description language (HDL), and there are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc., and the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should be aware that, as long as the method flow is logically programmed in the above-mentioned hardware description languages and programmed into an integrated circuit, a hardware circuit implementing the logical method flow can be easily obtained.

[0098] The controller can be implemented in any suitable way, for example, the controller can take the form of a microprocessor or processor and a computer readable medium storing computer readable program code, such as software or firmware, executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20 and Silicone Labs C8051F320, the memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that, in addition to being implemented in pure computer readable program code, the controller can also be implemented to perform the same functions in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers and embedded microcontrollers, etc. by logically programming the method steps. Therefore, such a controller can be considered as a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can even be considered as both a software module implementing a method and a structure within a hardware component.

[0099] The systems, apparatuses, modules or units illustrated by the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0100] For the sake of description, the above apparatuses are described in various units by functions respectively. Of course, the functions of each unit can be implemented in the same or multiple software and / or hardware in implementing the present disclosure.

[0101] Those skilled in the art will understand that the embodiments of the present disclosure can be provided as a method, a system or a computer program product. Therefore, the embodiments of the present disclosure can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.

[0102] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.

[0103] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks.

[0104] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.

[0105] In one typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0106] The memory can include non-persistent memory and / or volatile memory, such as random access memory (RAM) and / or cache memory, for storing, in general, data and / or program instructions. The memory can also include non-volatile memory, such as read-only memory (ROM), electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or non-volatile random access memory (NVRAM) for storing, in general, data and / or program instructions. The memory is an example of computer readable media.

[0107] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.

[0108] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to encompass non-exclusive inclusion, such that processes, methods, articles or devices that include a list of elements not only include those elements, but also include other elements not explicitly listed or inherent to such processes, methods, articles or devices. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or device including the element.

[0109] The present disclosure can be described in the general context of computer-executable instructions, such as program modules, being executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform particular tasks or implement particular abstract data types. The present disclosure can also be practiced in distributed computing environments where tasks are performed by remote processing devices that are connected through a communication network. In a distributed computing environment, program modules can be located in both local and remote computer storage media including storage devices.

[0110] The various embodiments in the present disclosure are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other, and each embodiment focuses on the difference from other embodiments. In particular, for the device, equipment, and non-volatile computer storage medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.

[0111] The above describes particular embodiments of the present disclosure. Other embodiments are within the scope of the following claims. In some cases, the actions or steps recited in the claims can be performed in a different order and still achieve desirable results. Additionally, the processes depicted in the figures do not necessarily require the particular order shown or sequential order in order to achieve the desired results. In some implementations, multitasking and parallel processing can be advantageous or necessary.

[0112] The above merely provides one or more embodiments of the present disclosure and is not intended to limit the present disclosure. One of ordinary skill in the art can make various modifications and changes to the one or more embodiments of the present disclosure. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the one or more embodiments of the present disclosure shall be included in the scope of the claims of the present disclosure.

Claims

1. A method for applet authorization processing, comprising: entering a centralized scene page of a specified application, the centralized scene page having entrances of a plurality of applets respectively accessed by the specified application; in the centralized scene page, initiating a unified authorization request corresponding to the plurality of applets to a current user; if the current user agrees to pre-authorization in response to the unified authorization request, triggering corresponding authorization data generation; after the pre-authorization, if the current user enters a corresponding applet from the entrances in the centralized scene page, directly obtaining specified information of the current user in the corresponding applet according to the authorization data for the current user to conduct a business of the corresponding applet without requesting authorization to the current user in the corresponding applet. 2.The method of claim 1, after the pre-authorization, the method further comprising: before the current user enters the corresponding applet from the entrances in the centralized scene page, the corresponding applet is not allowed to directly obtain the specified information of the current user. 3.The method of claim 1, the initiating a unified authorization request corresponding to the plurality of applets to a current user in the centralized scene page, specifically comprising: in the centralized scene page, a pop-up window is popped up to the current user, and the unified authorization request corresponding to the plurality of applets is initiated through the pop-up window so that the current user conducts authorization by interacting with the pop-up window; the directly obtaining specified information of the current user in the corresponding applet according to the authorization data, specifically comprising: in the corresponding applet, the information of the user is directly obtained according to the authorization data without a pop-up window requesting authorization to obtain the specified information of the current user in the corresponding applet. 4.The method of claim 1, the entering a corresponding applet from the entrances in the centralized scene page, specifically comprising: when entering the corresponding applet from the entrances in the centralized scene page, a centralized scene identifier corresponding to the centralized scene page is sent to a server so that the server checks whether the received corresponding centralized scene identifier matches the generated authorization data, and determines whether to allow the corresponding applet to directly obtain the information of the user according to the matching result. 5.The method of claim 4, the corresponding authorization data comprises a corresponding relationship among a user identifier of the current user, a centralized scene identifier corresponding to the centralized scene page, and an authorized state information; the obtaining specified information of the current user in the corresponding applet according to the authorization data, specifically comprising: when entering the corresponding applet from the entrances in the centralized scene page, an authorization request is initiated through the corresponding applet without a corresponding pop-up window. In response to the authorization request, the local or the server verifies whether the user corresponding to the authorization request has been authorized and whether the authorization scope of the requested authorization is reasonable according to the user identifier and the authorized state information contained in the generated authorization data; If yes, the information of the user is sent to the corresponding applet.

6. The method of claim 1, after the pre-authorization, the method further comprises: showing the current user with authorization setting options corresponding to the plurality of applets; If it is received that the current user sets the cancellation of authorization for any applet in the plurality of applets by operating the authorization setting option, it is determined that the pre-authorization is invalid for the any applet, so that the any applet is not allowed to directly obtain the specified information of the current user according to the authorization data, while the other applets in the plurality of applets which have not been cancelled are still allowed to directly obtain the specified information of the current user according to the authorization data.

7. The method of claim 1, after the direct acquisition of the specified information of the current user in the corresponding applet according to the authorization data, the method further comprises: detecting a business time node involving the specified information of the current user in the corresponding applet; generating a user information risk link according to the time sequence relationship of each business time node; in response to the request of the current user, showing the information risk link to the current user.

8. The method of claim 7, the unified authorization request carries an intended use of the specified information of the current user; the generating of the user information risk link according to the time sequence relationship of each business time node specifically comprises: matching and analyzing each business time node with the intended use to obtain a use deviation result; generating a user information risk link according to the use deviation result and the time sequence relationship of each business time node.

9. The method of claim 7, after the showing of the information risk link to the current user, the method further comprises: receiving a risk blocking point indicated by the current user in the information risk link; blocking the path in the information risk link after the risk blocking point, and rolling back the business involved in the information risk link to the risk blocking point or before it in the corresponding applet.

10. The method of claim 1 or 7, before the direct acquisition of the specified information of the current user in the corresponding applet according to the authorization data, the method further comprises: generating a corresponding pseudo user for the current user and generating pseudo feature information of the pseudo user according to the business characteristics of the corresponding applet and the specified original information of the current user through the specified application; the direct acquisition of the specified information of the current user in the corresponding applet according to the authorization data specifically comprises: directly acquiring the pseudo feature information of the pseudo user in the corresponding applet according to the authorization data, for the business of the corresponding applet for the current user.

11. An applet authorization processing apparatus, comprising: a centralized scene entering module, entering a centralized scene page of a specified application, the centralized scene page having entrances of a plurality of applets respectively accessed by the specified application; a unified authorization request module, initiating a unified authorization request corresponding to the plurality of applets to a current user in the centralized scene page; an authorization data triggering module, triggering corresponding authorization data generation if the current user agrees to pre-authorization in response to the unified authorization request; an applet shortcut processing module, after the pre-authorization, if the current user enters a corresponding applet of the plurality of applets from the entrance in the centralized scene page, directly obtaining specified information of the current user in the corresponding applet according to the authorization data, for performing a business of the corresponding applet for the current user, without requesting authorization of the current user in the corresponding applet.

12. The apparatus of claim 11, the authorization data triggering module, before the current user enters the corresponding applet from the entrance in the centralized scene page, does not allow the corresponding applet to directly obtain the specified information of the current user.

13. The apparatus of claim 11, the unified authorization request module, in the centralized scene page, pops up a window to the current user, and initiates a unified authorization request corresponding to the plurality of applets through the popped window, so that the current user performs authorization by interacting with the popped window; the applet shortcut processing module, in the corresponding applet, directly obtains the information of the user according to the authorization data, without popping up a window to request authorization of the current user to obtain the specified information of the current user in the corresponding applet.

14. The apparatus of claim 11, the applet shortcut processing module, when entering the corresponding applet of the plurality of applets from the entrance in the centralized scene page, sends a centralized scene identifier corresponding to the centralized scene page to a server, so that the server checks whether the received corresponding centralized scene identifier matches the generated authorization data, and determines whether to allow the corresponding applet to directly obtain the information of the user according to the matching result.

15. The apparatus of claim 14, the corresponding authorization data includes a corresponding relationship among a user identifier of the current user, a centralized scene identifier corresponding to the centralized scene page, and authorized state information; the applet shortcut processing module, when entering the corresponding applet of the plurality of applets from the entrance in the centralized scene page, initiates an authorization request through the corresponding applet without corresponding pop-up windows; in response to the authorization request, the server or locally checks whether the user corresponding to the authorization request has been authorized and whether the authorization range of the requested authorization is reasonable according to the user identifier and the authorized state information contained in the generated authorization data; if so, the information of the user is sent to the corresponding applet. 16.The apparatus of claim 11, wherein the authorization data triggering module, after the pre-authorization, displays authorization setting options corresponding to the plurality of applets to the current user; and if it is received that the current user sets de-authorization for any of the plurality of applets by operating an authorization setting option, determines that the pre-authorization is invalid for the any of the plurality of applets, so that the any of the plurality of applets is not allowed to directly acquire the specified information of the current user according to the authorization data, while other applets of the plurality of applets that have not been de-authorized are still allowed to directly acquire the specified information of the current user according to the authorization data. 17.The apparatus of claim 11, wherein the applet shortcut processing module, after the corresponding applet directly acquires the specified information of the current user according to the authorization data, detects business time nodes involving the specified information of the current user in the corresponding applet; generates a user information risk link according to a time sequence relationship of the business time nodes; and displays the information risk link to the current user in response to a request of the current user. 18.The apparatus of claim 17, wherein the unified authorization request carries an intended use of the specified information of the current user; and the applet shortcut processing module matches and analyzes each of the business time nodes with the intended use to obtain a use deviation result; and generates a user information risk link according to the use deviation result and the time sequence relationship of the business time nodes. 19.The apparatus of claim 17, wherein the applet shortcut processing module, after displaying the information risk link to the current user, receives a risk blocking point indicated by the current user in the information risk link; blocks a path in the information risk link after the risk blocking point, and rolls back a business involving the information risk link in the corresponding applet to the risk blocking point or before the risk blocking point. 20.The apparatus of claim 11 or 17, wherein the applet shortcut processing module, before the corresponding applet directly acquires the specified information of the current user according to the authorization data, generates a corresponding pseudo user for the current user and generates pseudo characteristic information of the pseudo user according to a business feature of the corresponding applet and the specified original information of the current user through the specified application. 21.An applet authorization processing device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform: ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ Enter a centralized scene page of a specified application, the centralized scene page having entrances of a plurality of applets respectively accessed by the specified application; In the centralized scene page, initiate a unified authorization request corresponding to the plurality of applets to a current user; If the current user agrees to pre-authorization in response to the unified authorization request, trigger corresponding authorization data generation; After the pre-authorization, if the current user enters a corresponding applet from the plurality of applets from the entrance in the centralized scene page, directly obtain specified information of the current user in the corresponding applet according to the authorization data, for the current user to perform a business of the corresponding applet, without requesting authorization to the current user in the corresponding applet.

Citation Information

Patent Citations

  • Risk detection method, device and equipment based on applet dynamic and static analysis

    CN113672919A

  • Method for managing permission request of application software

    CN116010990A

  • Data access processing method and device

    CN118051943A

  • Small program authorization processing method, device and equipment

    CN119066677A

  • Account authorization mapping

    US20230093470A1